Home Blog Page 272

Mozilla Doubles Payouts for Bug Hunters

Mozilla-Firefox

Mozilla recently announced that it has doubled the rewards for its bug bounty program to draw more eyeballs from the bug-hunting community. The web browser developer also stated that it has added new sites and services to the list as part of its bug bounty program. The latest move is intended to observe 15 years of the 1.0 release of Firefox.

In addition, the company also tripled payouts to US$ 15,000 for remote code execution on critical sites.

“To celebrate the 15 years of the 1.0 release of Firefox, we are making significant enhancements to the web bug bounty program. We are doubling all web payouts for critical, core and other Mozilla sites as per the Web and Services Bug Bounty Program page,” Mozilla said in a statement.

“As we are constantly improving the services behind Firefox, we also need to ensure that sites we consider critical to our mission get the appropriate attention from the security community,” the statement added.

According to Mozilla, the new sites that qualify for the bug bounty program include Autograph, Lando, Phabricator, and Taskcluster.

In a similar security news, the Coinbase security team and a security researcher Samuel D. Gross from Google discovered a “Zero-day” vulnerability in the Mozilla Firefox browser, which can be used to launch a cyber-attack using JavaScript objects.

Mozilla announced that it has patched its Firefox browser’s vulnerability in response to a spear-phishing campaign targeting employees of cryptocurrency exchange Coinbase. The company has released the latest version of the Firefox browser and urged the users to update their browsers.

The hackers have attempted to phish Coinbase staff with emails containing links to malicious websites. The malware can automatically download, if the links were clicked using the Firefox browser, and run malware on the system, stealing browser passwords and other sensitive information, according to Coinbase.

Docker Patches Critical Copy Vulnerability

cybersecurity

In July this year, researchers discovered a critical Docker copy command vulnerability that gave attackers complete root control of the host and its associated containers. This copy (cp) command is used to copy files and folders to and from the containers, and the local file system.

Docker Copy Vulnerability

Researchers said that previously compromised containers were targeted by this attack. When a user runs a malicious container image from an untrusted source and executes the vulnerable cp command to copy files out of the compromised container, the attacker can escape and take full root access control of the host and all its associated containers.

As per the Palo Alto Networks report, “To copy files out of the container, Docker uses a helper process called docker-tar. “docker-tar” works by chrooting into the container, archiving the requested files and directories in it, and then passing back the resulting tar file to the Docker daemon, which is responsible for extracting it to the target directory on the host.”

The problem is that docker-tar isn’t containerized. It runs in host namespaces with all root capabilities. Thus, by injecting code into docker-tar, a malicious container gets full access. The two possible attack scenarios are that a Docker user copies some files from either:

  • A container running a malicious image with bad libnss_*.so libraries.
  • A compromised container where an attacker replaced the libnss_*.so libraries.

Both scenarios grant the attacker root access rights to the host.

The Fix Issued

The Docker Copy Vulnerability has been fixed and the details can be tracked under CVE-2019-14271. The severity of this vulnerability can be seen from the fact that its CVSS base score is 9.8, which makes it a highly critical issue. Docker has asked its users to upgrade themselves to version 19.03.1 and above, since the vulnerability has been patched in the said version.

Preventive Actions

As a precautionary measure, researchers suggested not running untrusted images, and when root is not required containers should be run as non-root users. This way, even if an attacker compromises the container, he cannot overwrite the container’s libraries as they are owned by the root.

Earlier in April this year, Docker had reported that hackers had accessed one of its Docker Hub databases and stolen sensitive data from around 190,000 user accounts. Docker hub is the official cloud repository for Docker container images that allows users to create a test, store, and distribute container images.

At that time, Docker said, “We are enhancing our overall security processes and reviewing our policies. Additional monitoring tools are now in place. Our investigation is still ongoing, and we will share more information as it becomes available”

Android Flaw Allows Attackers to Exploit Your Smartphones’ Camera

Vulnerability in Android Smartphones

Security researchers discovered the existence of vulnerabilities in Google and Samsung smartphones which allow attackers to exploit phone cameras.

The flaw, which primarily stems from permission bypass issues, could allow attackers to secretly take photos, record videos, eavesdrop on conversations, and track user location, even if the phone is locked, the screen is off, or the app is closed.

According to Erez Yalon, the Director of Security Research at Checkmarx, the vulnerability, tracked as CVE-2019-2234, in pre-installed camera apps on millions of Android devices could be exploited by attackers to bypass restrictions and access the device camera without the user’s knowledge.

The researcher stated that they investigated the security of smartphone cameras by exploring the Google Camera app on a Google Pixel 2XL and Pixel 3. The research team also found that the same vulnerabilities impact the camera apps of other Android-based smartphones like Samsung phones.

“After a detailed analysis of the Google Camera app, our team found that by manipulating specific actions and intents, an attacker can control the app to take photos and/or record videos through a rogue application that has no permissions to do so. Additionally, we found that certain attack scenarios enable malicious actors to circumvent various storage permission policies, giving them access to stored videos and photos, as well as GPS metadata embedded in photos, to locate the user by taking a photo or video and parsing the proper EXIF data. This same technique also applied to Samsung’s Camera app,” the researcher said in a statement.

Even Google confirmed the existence of vulnerabilities and released a fix for the same.

“We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure. The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners.”

A similar research revealed that Facebook is accessing the iPhone’s camera without a user ‘s permission. The issue came to light after a user going by the name Joshua Maddux reported the unusual behavior. Maddux took to Twitter to display the issue, which occurs in the Facebook app for iOS.

Facebook also confirmed the issue, calling it a bug. “We recently discovered our iOS app incorrectly launched in the landscape. In fixing that last week in v246 we inadvertently introduced a bug where the app partially navigates to the camera screen when a photo is tapped,” Facebook VP of Integrity Guy Rosen tweeted. “We have no evidence of photos/videos uploaded due to this.”

The Importance of Data Erasure to Safeguard Data Security

Data Erasure, Privacy

By Sunil Chandna, Co-Founder and CEO, Stellar 

Data is growing at an incredible pace and this trend is expected to go steeper in the coming years. As per a recently published industry study, 2.5 quintillion bytes of data are created every day in the world and 90 percent of this entire data was created in the preceding two years alone! Further, the Data Age 2025 report predicted that the global data sphere will grow from 33 Zettabytes (ZB) in 2018 to 175 ZB by 2025, indicating a 430 percent growth in 7 years.

Rise of ‘digital social’ culture, high-speed Internet, technologies such as IoT, AI and resultant industry shifts such as digital transformation underpin this stupendous growth of data.

Today, enterprises in virtually every industry including Banking & Finance, Healthcare, Online Commerce, and Entertainment collect and store customer data; this data is used for designing personalized user/customer experiences or is stored as a part of the documentation.

Notably, this data–stored on servers, external hard drives desktop/laptop, etc.–grows in a sizable chunk with time. Dedicated IT asset managers are hired for managing these IT assets through their lifecycle & end-of-life. Storage space and IT management costs add up to a sizable expense for a business.

One thing stands out in this story: much of this company/customer data–collected, stored or transacted online—is ‘sensitive & confidential’, meaning, its unwanted exposure or leakage can result in loss of business, customers, money, reputation, and even litigation!

Data protection laws across the globe such as GDPR, SOX, and GBLA have placed a great onus on organizations to secure their “data-bearing” devices from a privacy standpoint. Failing to comply with these statutory regulations can result in huge penalties and long-term impact on business. For instance, violation of HIPPA can result in fines of up to US$50,000 per violation for willful neglect, with a maximum USD1.5 million per year for violations of an identical provision. Similarly, failure to comply with EU-GDPR provisions can result in fines of up to 20 million euros, or in the case of an undertaking, 4 percent of annual global turnover.

Privacy, a top priority

Given the sensitivity of the data, securing data privacy has become a top priority for companies.

While businesses spend millions of dollars and follow rigorous protocols to secure data on actively used devices, they are yet to observe the same rigor for securing devices that have reached the end of their primary use life term.

Despite the growing urgency around data privacy, awareness is surprisingly low on the fact that data stored on devices continues to face significant threats even beyond their intended use term. These threats at the IT asset disposal stage persists on account of ‘residual data’ that gets retained on the outbound media due to inadequate sanitization prior to disposal.

When servers, laptops, smartphones, etc. are lined up for any secondary transaction such as returning leased IT assets, hardware refresh, reselling, donation, etc. they must be sanitized to permanently remove all traces of data and thereby safeguard data security.

Stellar Data Recovery Inc. conducted the world’s largest study to ascertain the awareness levels amongst device owners, regarding usage of secure data wiping methods at the time of selling old storage devices. It also aimed to create awareness about data privacy risks when file deletion or drive formatting is used with an incorrect assumption as a permanent data removal action.

This investigation study of 311 used devices including hard drives, smartphones, and memory cards has revealed that 7 out of 10 devices contain residual data in the form of PII (Personal Identifiable Information) and confidential data. Surprisingly, 45 percent of these vulnerable devices were disposed of without any sort of sanitization; the data was present ‘as is’ that could be accessed by connecting the devices to a host machine! The remaining 25 percent (or 1 in 4) of the unsecured devices were disposed of after deletion or formatting. Data from these devices could be easily recovered by using any D-I-Y data recovery software.

This study further accentuates the need for taking effective data sanitization methods at the time of disposal of legacy IT assets to safeguard data security and avoid the huge risks associated with leakage of residual data both for organizations and individuals alike.

Data Erasure: The masterstroke for effective media sanitization

The most common media sanitization methods used by organizations are data erasure tools or trusting the ITADS (IT Asset Disposition Vendors) for wiping the data. The ITAD route is more common for various reasons. For instance, Hardware Asset Disposal is a specialized job, and it requires infrastructure and capacity, may offer more choices for sanitization, and is an established line of service for managing used or end-of-life assets.

However, in contrast to numerous choices of ITADs, there are compelling arguments in favor of ‘Data Erasure’ software as a key enabler for IT Asset Managers, namely:

  1. On-premises media sanitization: Data erasure software, sometimes called disk wipe software; enables organizations to sanitize their storage media on-premises, which is a powerful proposition to enforce the data security protocols for regulatory compliance within the office. Use of data erasure software is an emerging practice in the media sanitization realm, which complements the prevalent media sanitization practices such as shredding, degaussing (which doesn’t work on SSDs) and the likes. Software-based data erasure ensures foolproof data security, regardless of the physical state and circumstances of a storage media in the chain of custody.
  1. Secure data destruction with strong regulatory compliance: Modern data erasure software sanitizes media effectively and in line with global erasure standards. This helps organizations attain compliance with data security and privacy regulations such as SOX, GLB, HIPAA, ISO27001, EU-GDPR, and PCI-DSS. Further, data erasure software generates automated erasure reports and certificates that are tamper-proof and therefore serve as trusted audit trails at any given point in time for compliance requirements.
  1. Reduces TCO (Total Cost of Ownership), Ecofriendly, and Socially Responsible: Data erasure software allows recycling, re-allocation, or redistribution of devices. It helps to increase efficiency and decrease costs.

Clearly, data erasure software is an eco-friendly solution to fill the white spaces in media sanitization and complement the status quo, so as to empower IT asset managers for their evolved needs and roles.

To sum up, data erasure software is available on-premises, reduces TCO, drives compliance, and is simpler to use, and a great solution to protect our mother earth from e-waste pollution. It has all the ingredients needed for the making of a data privacy champion!

Sunil Chandna, Co-Founder and CEO, Stellar Data Recovery is a corporate professional with a career spanning over 25 years in diverse roles. Sunil has been steering the company up the growth ladder since 1993, he is responsible for defining and delivering the business strategy and providing overall leadership for Stellar’s operations in India and abroad. 

Stellar is a global Data Care Corporation, with expertise in Data Recovery, Data Erasure, Mailbox Conversion, and File Repair software and services. BitRaser is a product from Stellar, which helps in permanent erasure of data from all types of storage media, with no traces of data left behind. The product is compliant with global data erasure standards and helps safeguard data privacy. 

Disclaimer: CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Mispadu Malvertising Trojan: An Un-Happy Meal for McDonalds

Malware

Beware! The Mispadu Trojan is collecting victim’s payment-card and online banking details by malvertising as McDonalds free meal coupon ads.

Mispadu is a banking trojan that according to the research team at ESET, is specifically targeting the Latin American countries of Brazil and Mexico, and stealing victim’s payment-card and online banking details. Trojans are not new to the banking sector, but the way they are luring users in their trap is something that’s worth noting. Attackers are taking advantage of the holiday season that is just around the corner and using Facebook’s sponsored ads as a medium for forcing a call to action from users.

ESET researchers also found that Mispadu is spreading via spam emails. These malvertisings offer fake discount coupons for McDonalds with the call out, “Use them on any September day! Independence coupons. Get yours now.” As soon as the user clicks the ad, they’re redirected to a fake McDonalds website with a button that says, “I want! / Generate coupon.” Clicking this in turn downloads a ZIP archive on the victim’s machine.

The Zipped folder contains an MSI installer. When the victim clicks this a chain of three subsequent VBS scripts start executing. Researchers said that the first script (unpacker) decrypts and executes the second script (downloader) from its internal data. The downloader script retrieves the third script (loader) and further executes it. The loader script acts as the malware’s AI. It checks the victim’s machine location, whether it is from the targeted Latin American region and for certain internal conducive virtual environments. If this is not found, then the loader quits and aborts the process. But if it’s a match, then Bingo. It loads three things;

  • Mispadu banking trojan
  • A DLL injector used for trojan’s execution, and
  • Legit supporting DLLs

The loader script finally completes the malware installation by decrypting the banking trojan and executing it.

Information collected by Mispadu

It collects the following information from its victims:

  • OS version
  • Computer name
  • Language ID
  • Diebold Warsaw GAS Tecnologia installation check (an application, popular in Brazil, to protect access to online banking)
  • List of installed common Latin American banking applications
  • List of installed security products

Recently, researchers uncovered a mass malware attack where the authors were said to be motivated by their political beliefs. This malware was designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or sends messages to specific numbers, according to the researchers.

Macy’s Hit by Magecart Card-Skimming Attack

New Programming Language

Macy’s, an American department store chain, stated that its customers have been hit by an attack that affected countless numbers of credit cards. The retailer stated that unknown intruders planted a card-stealing malware script on its payment site and collected customer details.

According to an official statement, the attackers installed a Magecart script on the checkout page of its website and siphoned off customers’ payment card details between October 7 and October 15,  this year.

The compromised data included customers’ names, addresses, phone numbers, credit card numbers, card verification codes, and expiration dates.

“On October 15, 2019, we were alerted to a suspicious connection between macys.com and another website. Our security teams immediately began an investigation. Based on our investigation, we believe that on October 7, 2019, an unauthorized third-party added unauthorized computer code to two pages on macys.com,” Macy’s said in a statement.

“The unauthorized code was highly specific and only allowed the third-party to capture information submitted by customers on macys.com and the checkout page–if credit card data was entered and the “place order” button was hit; and the wallet page was accessed through My Account. Our teams successfully removed the unauthorized code on October 15, 2019,” the statement added.

Macy’s clarified that the attack only affected its webpage users and not the users who made purchases using its mobile application. Security experts opined that the attack appears to be a Magecart operation.

In Magecart attacks, hackers gain access to a company’s online store website by compromising it and hiding malicious code in it. The malicious code then collects the payment card information from users while making purchases on the infected site. It’s said that hackers either sell the stolen card data on the darknet or use it to make fraudulent purchases.

Recently, the FBI issued a warning for public and private enterprises in the United States about Magecart attacks, also called e-skimming or web skimming attacks, which are carried out by exploiting security flaws in open-source online stores.

The FBI stated that Magecart attacks have been active since 2016, but they’ve increased in 2018 and 2019, and even using diversified attack methodology to launch attacks. The FBI also suggested security guidelines for businesses to protect themselves from cyber-attacks, which include: Update and patch all systems with the latest security software; Change default login credentials on a regular basis; and Educate employees about safe cyber practices.

Ransomware Hits Louisiana State Government Systems

Hive Ransomware

The Louisiana state government fell victim to a ransomware attack again. John Bel Edwards, Governor of Louisiana, revealed that a ransomware infection had taken down the government’s IT systems and websites.

John Bel Edwards tweeted details about the attack, saying the attack impacted the public state government’s email, website, and other online applications.

“Today, we activated the state’s cybersecurity team in response to an attempted ransomware attack that is affecting some state servers. The Office of Technology Services identified a cybersecurity threat that affected some, but not all state servers,” John Bel Edwards said in a Twitter post.

“OTS immediately initiated its security protocols and, out of an abundance of caution, took state servers down, which impacted many state agencies’ e-mail, websites, and other online applications. The service interruption was due to OTS’ aggressive response to prevent additional infection of state servers and not due to the attempted ransomware attack,” Edwards added.

According to official reports, the attack affected websites for the Office of the Governor, Louisiana State Legislature, Office of Motor Vehicles, Department of Corrections, the Louisiana Division of Administration, and the Department of Transportation & Development.

The Louisiana government issued a state of emergency after a wave of ransomware attacks hit school districts in July this year. The incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their network systems.

“The state was made aware of a malware attack on a few north Louisiana school systems and we have been coordinating a response ever since,” Gov. Edwards said. “This is exactly why we established the Cyber Security Commission, focused on preparing for, responding to, and preventing cybersecurity attacks, and we are well-positioned to assist local governments as they battle this current threat.”

“Multiple factor authentication can protect users from hacking attempts”

Tarun Wig

Tarun Wig is a young entrepreneur with over a decade of industry experience. He’s the co-founder of Innefu Labs and his expertise lies in innovating cutting edge technologies to assist law enforcement agencies and protect users as well as organizations from cybersecurity attacks. He is a well-known and active participant in cybersecurity communities in India.

He’s also a co-founder and former director of a cybersecurity company he acquired in 2008. Innefu Labs is an AI-driven technology product company with capabilities in Data Analytics/Information Security/Video & Image Analytics.

In an exclusive interaction with CISO MAG’s Rudra Srinivas, Tarun Wig narrates his journey, the vision of the company, its product lineup, and ethics.

You have more than 12 years of experience in information security, working with government agencies and large corporates. You are also co-founder and former director of a cybersecurity company acquired in 2008. Tell us about your journey. What was your idea behind Innefu Labs? What’s your mission and vision for the company?

Innefu Labs started nine years ago with an idea to develop technology which could bring change into how organizations handle data. While most of the organizations in the country were focused on providing services, we wanted to focus on developing state-of-the-art products indigenously in the country. Out of this thought, Innefu was born:  an AI-driven company developing cutting edge technology to carry out Predictive Intelligence and Cyber Security solutions.

Idea: When we started up, we realized that there was no support system in place to help Government organizations for collaborating intelligence insights from different government departments. The government departments like Indian Army, Intelligence agencies, and Police departments have multiple data at their disposal, but not compiled together. We felt that this is what we needed to work upon and help to strengthen the governments, security agencies, large enterprises, and retails chains to become smarter and secure. Now, with our AI tools, we can collaborate and create a sensible database that could be used by all.

Mission:  To develop customer-oriented state-of-the-art technologies with exemplary support to ensure that we don’t have even one unhappy customer

Vision:  To make governments, security agencies, large enterprises & retail chains become smarter and secure.

The company started with a team of ten people working out of the living room of a house and today, it is more than 120 people strong with clients spread across three different continents. Today serves four out of the top 10 corporates in the country apart from serving some of the largest and most critical Law Enforcement and Intelligence organizations in South East Asia. We have a 120-member strong team spread across two locations in Delhi with a satellite office in Mumbai.

You have a large clientele from the Indian defense sector like DRDO, Indian Army, CRPF, among several others. These agencies witness a large amount of cyber espionage and state-sponsored attacks. Tell us how your company differentiates itself from other global information security that is already established in India?

Global security organizations are focused on very generic areas like cloud security, security devices, etc. We at Innefu are focused on niche and specific areas in defense, paramilitary and law enforcement agencies.

We help organizations carry out explorative investigations and predictive analytics using our analytical tools based on data from various sources like their own internal intelligence documents, their internal databases, open-source intelligence databases, by fusing these datasets together. Our tools help them arrive at actionable intelligence and insights.

Our understanding of the defense and law enforcement domain helps us focus on the needs of our customers. Hence our product caters to specific needs rather than a generic need.

Also, how do your Identity Verification products prevent external vectors from entering these heavily guarded defense environments, considering the fact that in most cases you are the ones guarding the entry to these forts?

Innefu’s AI Vision is an image and video analytics solution based on ML and AI models. The system takes live Feeds from CCTV cameras, traffic cameras, recorded video feeds or any other source. It analyzes video footage in real-time and detects abnormal activities on the user applied rules like Intrusion Detection, Person/Object Identification, etc. making the surveillance system more useful, efficient and reliable. The solution analyses the feed from CCTV cameras, recorded videos, and static images to automatically identify and raise alerts on missing children, identifying criminals, crowd formation, trespassing, breach, object identification, tailgating.

One of your AI tools was used to identify 3,000 missing children within four days. It was also identified as one of the first-ever deployment of AI tools for social welfare. Tell us how “AI Vision” was used here. How else can this tool be used to prevent cyber-attacks and cybercrimes?

Innefu’s Prophecy AI Vision is a state of art Facial Biometrics solution by optimized deep learning algorithms to identify or verify a person from a digital image or from a video feed. The process involves clicking a picture of a kid on the street and automatically matching it with a database of missing children, for real-time information and alerts.

How do you think security teams and public safety professionals will find Innefu Labs as beneficial and explore newer avenues of cybersecurity that have not been tapped?

We use AI in National security which is a unique field and we use our own analytical tools for carrying out predictive intelligence which helps in exploring newer avenues of cybersecurity.

Your Unified Authentication platform, AuthShield, integrates facial and thumbprint biometrics with standard 2FA solutions including push notifications, OTP’s, SMS and Email OTP’s, etc. Can you brief us on this platform?

AuthShield is a multifactor authentication solution for identity and application security. Since passwords have shortcomings, multiple factors of authentication can protect users from hacking attempts.

AuthShield authenticates and verifies the user based on:

  • Something only the user knows (User ID and Password)
  • Something only the user has (Smartphone/ Hard Token)
  • Something the user is (Biometrics)

AuthShield performs two-factor authentication through a secure randomly generated OTP or through One-touch authentication or biometrics. With thumbprint biometrics, the physical identity of the user is mapped to the server and increases the security. With one-touch (Push Notifications), OTP’s, the user’s identity is mapped to the registered devices and authenticates the user based on a unique challenge-response mechanism.

Anytime the user wishes to log in, the user receives a one-touch notification on their registered device. The one-touch notification follows a PKI encryption standard to ensure that the challenge sent to the user is encrypted in nature and can only be decrypted by the registered device of the user.

We have also read that your multifactor authentication even includes voice recognition. Do you think the current two-factor authentication systems are becoming outdated and are not up to speed with the emerging threat landscape? Do you also feel voice, facial, and fingerprint biometrics are where the industry should be headed?

The traditional two-factor authentication methods like OTP etc. have been around for a while but, due to the emerging threat landscape, the hackers are becoming smarter. Due to this, the industry is headed towards biometrics authentication in the form of voice, facial, fingerprint, iris, etc. because biometrics provides an advanced foolproof method of authentication when coupled with traditional methods.

Rudra Srinivas is part of the editorial team at CISO MAG and writes News, Features, and Interviews.

Australia Releases “Code of Practice” to Secure IoT Devices

Cryptocurrency scams in Australia

The government of Australia recently released a draft Code of Practice for securing the Internet of Things (IoT) devices. The government stated the draft, Voluntary Code of Practice: Securing the Internet of Things for Consumers, is under public consultation running until March 1, 2020.

It’s said that the Code of Practice will apply to all IoT devices available in Australia, including smart TVs, smartwatches, speakers, and other smart devices.

“Many of these devices have poor cybersecurity settings, leaving Australians vulnerable to cyber- attacks. Cyber-attacks can have serious privacy and security consequences for individuals, our economy and national security. We need to act now to address the cybersecurity risks,” the government said in a statement.

“The Government expects devices are designed with basic cybersecurity features so that Australian consumers can work and live securely online,” the statement added.

The Code of Practice is based on thirteen principles which include:

  • No duplicated default or weak passwords
  • Implement a vulnerability disclosure policy
  • Keep software securely updated
  • Securely store credentials
  • Ensure that personal data is protected
  • Minimize exposed attack surfaces
  • Ensure communication security
  • Ensure software integrity
  • Make systems resilient to outages
  • Monitor system telemetry data
  • Make it easy for consumers to delete personal data
  • Make installation and maintenance of devices easy
  • Validate input data

The government stated the draft is its initial step to improve the security of IoT devices in the country. It helps raise awareness of security safeguards associated with IoT devices, build consumer confidence in IoT technology, and allow Australians to obtain the benefits of IoT adoption.

“This Code of Practice is a voluntary suite of measures that the Australian Government recommends for the industry as the standard for IoT devices. The Australian Government will continue to work with industry to provide better protection for consumers, including through complementary initiatives to lift security in IoT devices for consumers and specific higher-risk sectors,” the statement added.

Recently, the Australian government announced that it’s going to spend AU$8.5 million to create a national freight data hub. The government stated the new data hub helps businesses and governments make better operational decisions.

“A well-designed hub will improve access to and sharing of valuable freight location and performance data,” said Michael McCormack, the Deputy Prime Minister of Australia.

The funding will be divided into two parts, in which AU$5.2 million will be allocated for designing the national freight data hub, including arrangements for data protection, data collection, confidentiality, dissemination, and hosting. And the remaining AU$3.3 million will be used to establish a freight data exchange pilot.

Disney Plus Hacking: Child’s Play for Hackers

Disney

No this isn’t just another Disney Sci-fi cartoon or movie narrative. Disney plus has been hacked in the real world. After months of anticipation, Disney launched its Netflix competitor Disney Plus (better known as Disney+) on November 12, 2019 in the U.S., Canada and Netherlands. Disney+ is a subscription-based video on-demand streaming service owned by the Walt Disney Direct-to-Consumer & the International division of The Walt Disney Company.

The Story

Unlike others, this Disney fairytale didn’t last for long. Hours after the launch, subscribers started complaining about not being able to log in to their Disney+ accounts. Soon the word spread out and after repeated reports of such incidences it was found that thousands of Disney Plus Accounts were up for sale on the dark web for costs ranging from US$3 per account to US$11 – which, is much more than the actual subscription cost of US$7 for a legit Disney+ account. Subscribers reported that hackers logged them out of all devices, and even changed the registered email address and password making the previous login credentials void.

The Villain

This hacking incidence could very well haunt Disney, as back in March this year, Disney had urged its shareholders to vote against a cybersecurity and privacy proposal that would have led to a new privacy and cybersecurity metrics being linked to senior executive compensation. Owing to Disney’s appeal, just 26 percent of its shareholders voted “Yes” for the implementation; the rest were “No” votes cast by shareholders, board members—or by default. As of today, the ballot is sealed, and the proposal stands defeated. But could this be one of the curses behind this hacking?

Another interesting analysis pointed out the lack of Multi-Factor Authentication (MFA) security feature in Disney+ services. MFA is a method in which access is granted only after two or more authentication criterions are met while signing into a service. A unique password could be the first authentication layer, and the second layer could be a randomly generated code sent to the user’s mobile phone or registered email address, which is then entered during login process.

The Climax

This has already been described at the beginning of the story in bold words – “Disney Plus Hacked”. But what Disney can do is have an alternative ending, perhaps taking a cue from one of their fairy tale stories, which have happy endings. How can they do it?

It needs to immediately roll-out a two/multi-factor authentication (2FA/MFA) feature to keep unaffected user accounts safe and secure. This also helps restrict the password reuse of affected users. Next, they need to provide 24/7 support to all affected users for regaining their account access control. In case this is not possible, then Disney must provide them an alternate Disney+ access. Disney also needs to strengthen and prioritize their cybersecurity and privacy policies because managing security and credibility of online content is no child’s play but a top priority for such digital content giants.

These measures don’t guarantee a “happily ever after” for Disney but it could be a step towards attaining it.

For the time being – That’s all Folks!