<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: earthquake]]></title>
    <link>http://securityratty.com/tag/earthquake</link>
    <description></description>
    <pubDate>Sun, 18 May 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[An insecurity in OpenID, not many dead]]></title>
      <link>http://securityratty.com/article/36f416e51d88cd2db5ed822a7ed3835a</link>
      <guid>http://securityratty.com/article/36f416e51d88cd2db5ed822a7ed3835a</guid>
      <description><![CDATA[Back in May it was realised that , thanks to an ill-advised change to some random number generation code, for over 18 months Debian systems had been generating crypto keys chosen from a set of 32,768...]]></description>
      <content:encoded><![CDATA[<p>Back in May <a href="http://www.debian.org/security/2008/dsa-1571">it was realised that</a>, thanks to an ill-advised change to some random number generation code, for over 18 months Debian systems had been generating crypto keys chosen from a set of 32,768 possibilities, rather than from billions and billions. Initial interest centred around the weakness of SSH keys, but in practice lots of different applications were at risk (<a href="http://wiki.debian.org/SSLkeys">see long list here</a>).</p>
<p>In particular, SSL certificates (as used to identify https websites) might contain one of these weak keys &#8212; and so it would be possible for an attacker to successfully impersonate a secure website. Of course the attacker would need to persuade you to mistakenly visit their site &#8212; but it just so happens that one of the more devastating attacks on DNS has <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447">recently been discovered</a>; so that&#8217;s not as unlikely as it must have seemed back in May.</p>
<p>Anyway, my old friend <a href="http://en.wikipedia.org/wiki/Ben_Laurie">Ben Laurie</a> (who is with Google these days) and I have been trawling the Internet to determine how many certificates there are containing these weak keys &#8212; and there&#8217;s a lot: around 1.5% of the certs we&#8217;ve examined.</p>
<p>But more of that another day! because earlier this week, Ben spotted that one of the weak certs was for Sun&#8217;s &#8220;OpenID&#8221; website, and that two more OpenID sites were weak as well (by weak we mean that a database lookup could reveal the private key!)</p>
<p>OpenID, for those who are unfamiliar with it, is a scheme for allowing you to prove your identity to site A (viz: provide your user name and password) and then use that identity on site B. There&#8217;s a queue of people offering the first bit, but rather less offering the second : because it means you rely on someone else&#8217;s due diligence in knowing who their users are &#8212; where &#8220;who&#8221; is a hard sort of thing to get your head around in an online environment.</p>
<p>The problem that Ben and I have identified (<a href="http://www.links.org/files/openid-advisory.txt">advisory here</a>), is that an attacker can poison a DNS cache so it serves up the wrong IP address for openid.sun.com. Then, even if the victim is really cautious and uses https and checks the cert, their credentials can be phished. Thereafter, anyone who trusts Sun as an identity provider could be very disappointed. There&#8217;s other attacks as well, but you&#8217;ve probably got the general idea by now.</p>
<p>In principle Sun should make a replacement certificate and that should be it (and so they have &#8212; <a href="http://blogs.sun.com/racingsnake/entry/one_factor_trust_multi_factor">read Robin Wilton&#8217;s comments here</a>). Except that they need to put the old certificate onto a Certificate Revocation List (CRL) because otherwise it will still be trusted from now until it expires (a fair while off). Sadly, many web browsers, and most of the OpenID codebases haven&#8217;t bothered with CRLs (or they don&#8217;t enable their checking by default so it&#8217;s as if it wasn&#8217;t there for most users).</p>
<p>One has to conclude that Sun (and the other two providers) should not be trusted by anyone for quite a while to come. But does that matter ? Since OpenID didn&#8217;t promise all that much anyway, does a serious flaw (which does require a certain amount of work to construct an attack) make any difference? At present this looks like the modern equivalent of a <a href="http://www.mantex.co.uk/reviews/oxf-misquot.htm">small earthquake in Chile</a>.</p>
]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 21:33:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openid">openid</category>
      <category domain="http://securityratty.com/tag/openid codebases">openid codebases</category>
      <category domain="http://securityratty.com/tag/certs">certs</category>
      <category domain="http://securityratty.com/tag/weak certs">weak certs</category>
      <category domain="http://securityratty.com/tag/weak">weak</category>
      <category domain="http://securityratty.com/tag/openid sites">openid sites</category>
      <category domain="http://securityratty.com/tag/sun">sun</category>
      <category domain="http://securityratty.com/tag/suns openid website">suns openid website</category>
      <category domain="http://securityratty.com/tag/trusts sun">trusts sun</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/">An insecurity in OpenID, not many dead</source>
    </item>
    <item>
      <title><![CDATA[Global Dispatches]]></title>
      <link>http://securityratty.com/article/e9f9fa0e8267d86fda48f5690ae4efc8</link>
      <guid>http://securityratty.com/article/e9f9fa0e8267d86fda48f5690ae4efc8</guid>
      <description><![CDATA[Chinese police arrested a 19-year-old man for allegedly issuing a fake online earthquake warning; Citrix disclosed plans to open a second R&amp;D facility in...]]></description>
      <content:encoded><![CDATA[Chinese police arrested a 19-year-old man for allegedly issuing a fake online earthquake warning; Citrix disclosed plans to open a second R&D facility in India.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=zRf1S7"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=zRf1S7" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/317817870" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 02:23:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake online earthquake">fake online earthquake</category>
      <category domain="http://securityratty.com/tag/chinese police">chinese police</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/citrix">citrix</category>
      <category domain="http://securityratty.com/tag/facility">facility</category>
      <category domain="http://securityratty.com/tag/19-year-old">19-year-old</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/317817870/article.do">Global Dispatches</source>
    </item>
    <item>
      <title><![CDATA[New Malware Spam Reporting Bogus Beijing Earthquake Targets Olympic Games Fans]]></title>
      <link>http://securityratty.com/article/0ac962c0942bbcdbc1bac735c77561bc</link>
      <guid>http://securityratty.com/article/0ac962c0942bbcdbc1bac735c77561bc</guid>
      <description><![CDATA[Botnet operators are using false reports about an earthquake near Beijing that could disrupt the Olympic games to spread malware. Unsolicited emails discovered to be a part of a new malicious spam...]]></description>
      <content:encoded><![CDATA[Botnet operators are using false reports about an earthquake near Beijing that could disrupt the Olympic games to spread malware. Unsolicited emails discovered to be a part of a new malicious spam campaign that claims another earthquake has just occurred in China, and could derail the upcoming Olympic Games.
Samples of the bogus alert doing the [...]]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 18:49:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/olympic games">olympic games</category>
      <category domain="http://securityratty.com/tag/earthquake">earthquake</category>
      <category domain="http://securityratty.com/tag/malicious spam campaign">malicious spam campaign</category>
      <category domain="http://securityratty.com/tag/botnet operators">botnet operators</category>
      <category domain="http://securityratty.com/tag/spread malware">spread malware</category>
      <category domain="http://securityratty.com/tag/bogus alert">bogus alert</category>
      <category domain="http://securityratty.com/tag/false reports">false reports</category>
      <category domain="http://securityratty.com/tag/claims">claims</category>
      <category domain="http://securityratty.com/tag/samples">samples</category>
      <source url="http://cyberinsecure.com/new-malware-spam-reporting-bogus-beijing-earthquake-targets-olympic-games-fans/">New Malware Spam Reporting Bogus Beijing Earthquake Targets Olympic Games Fans</source>
    </item>
    <item>
      <title><![CDATA[China Quake Hacker Caught]]></title>
      <link>http://securityratty.com/article/d3e180d72ba44bd428c987a2a1b476b4</link>
      <guid>http://securityratty.com/article/d3e180d72ba44bd428c987a2a1b476b4</guid>
      <description><![CDATA[How stoopid did this guy have to be to think, gee, I should put a fake earthquake warning up and then follow through on it? How did he think it would be funny
From Network World
A 19-year old Chinese...]]></description>
      <content:encoded><![CDATA[<p>How stoopid did this guy have to be to think, &#8220;gee, I should put a fake earthquake warning up&#8221; and then follow through on it? How did he think it would be funny?</p>
<p>From Network World:</p>
<blockquote><p>A 19-year old Chinese man is in police custody after allegedly hacking into a provincial seismological bureau&#8217;s Web site to place a false earthquake warning, Chinese state media reported Monday.</p>
<p>The teenager, identified only by his surname Chen, altered the Web site of the Guangxi Seismological Bureau to warn residents in southwestern China to prepare for an impending earthquake expected to measure 9.0 on the Richter scale, according to a report on China Central Television&#8217;s Web site. </p>
<p>Such a posting could have caused a panic. On May 12 an earthquake measuring 7.8 struck China&#8217;s Sichuan province, killing over 70,000 people and leaving millions homeless. Following the quake, many people have fallen prey to rumors that earthquakes can now be predicted in a manner similar to weather forecasts, although there was no warning of the Sichuan quake. </p></blockquote>
<p>I mean seriously. 70,000 people perished in the actual earthquake a month ago.</p>
<p>What a dumbass.</p>
<p><a href="http://www.networkworld.com/news/2008/061708-china-quake-site-hacker.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=4DWtlH"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=4DWtlH" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=lNimgI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=lNimgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=1mf7Ei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=1mf7Ei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=0sxFqi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=0sxFqi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=nL5ixi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=nL5ixi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=V1rw2i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=V1rw2i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/315340306" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 19 Jun 2008 06:59:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/earthquake">earthquake</category>
      <category domain="http://securityratty.com/tag/actual earthquake">actual earthquake</category>
      <category domain="http://securityratty.com/tag/false earthquake">false earthquake</category>
      <category domain="http://securityratty.com/tag/quake">quake</category>
      <category domain="http://securityratty.com/tag/fake earthquake">fake earthquake</category>
      <category domain="http://securityratty.com/tag/guangxi seismological bureau">guangxi seismological bureau</category>
      <category domain="http://securityratty.com/tag/sichuan quake">sichuan quake</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/315340306/">China Quake Hacker Caught</source>
    </item>
    <item>
      <title><![CDATA[China quake fake in police custody]]></title>
      <link>http://securityratty.com/article/d20eb8e499b6d81edca362cebe0b2de7</link>
      <guid>http://securityratty.com/article/d20eb8e499b6d81edca362cebe0b2de7</guid>
      <description><![CDATA[A 19-year-old computer intruder who broke into a provincial seismological bureau's Web site to place a false earthquake warning could have caused widespread panic in the rattled Sichuan...]]></description>
      <content:encoded><![CDATA[A 19-year-old computer intruder who broke into a provincial seismological bureau's Web site to place a false earthquake warning could have caused widespread panic in the rattled Sichuan region.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=xGuVZy"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=xGuVZy" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/313626181" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 05:24:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/provincial seismological bureau">provincial seismological bureau</category>
      <category domain="http://securityratty.com/tag/19-year-old computer intruder">19-year-old computer intruder</category>
      <category domain="http://securityratty.com/tag/false earthquake">false earthquake</category>
      <category domain="http://securityratty.com/tag/sichuan region">sichuan region</category>
      <category domain="http://securityratty.com/tag/widespread panic">widespread panic</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/313626181/article.do">China quake fake in police custody</source>
    </item>
    <item>
      <title><![CDATA[China quake site hacker caught]]></title>
      <link>http://securityratty.com/article/762bddbdd7910ee1c84b42a3d5621b5e</link>
      <guid>http://securityratty.com/article/762bddbdd7910ee1c84b42a3d5621b5e</guid>
      <description><![CDATA[A 19-year old Chinese man is in police custody after allegedly hacking into a provincial seismological bureau's Web site to place a false earthquake warning, Chinese state media reported...]]></description>
      <content:encoded><![CDATA[A 19-year old Chinese man is in police custody after allegedly hacking into a provincial seismological bureau's Web site to place a false earthquake warning, Chinese state media reported Monday.]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/provincial seismological bureau">provincial seismological bureau</category>
      <category domain="http://securityratty.com/tag/police custody">police custody</category>
      <category domain="http://securityratty.com/tag/false earthquake">false earthquake</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/19-year">19-year</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://www.networkworld.com/news/2008/061708-china-quake-site-hacker.html?fsrc=rss-security">China quake site hacker caught</source>
    </item>
    <item>
      <title><![CDATA[FBI warns of e-mail scams offering to help Chinese quake victims]]></title>
      <link>http://securityratty.com/article/99d914860b1cc534f4c63dd3841ec229</link>
      <guid>http://securityratty.com/article/99d914860b1cc534f4c63dd3841ec229</guid>
      <description><![CDATA[The FBI is warning Americans who want to send donations in the wake of this month's earthquake in China to beware of a rising number of e-mail relief...]]></description>
      <content:encoded><![CDATA[The FBI is warning Americans who want to send donations in the wake of this month's earthquake in China to beware of a rising number of e-mail relief scams.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=lkQvMx"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=lkQvMx" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/295368451" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/e-mail relief scams">e-mail relief scams</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/earthquake">earthquake</category>
      <category domain="http://securityratty.com/tag/beware">beware</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/donations">donations</category>
      <category domain="http://securityratty.com/tag/americans">americans</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/295368451/article.do">FBI warns of e-mail scams offering to help Chinese quake victims</source>
    </item>
    <item>
      <title><![CDATA[FBI warns of China earthquake e-mail scams]]></title>
      <link>http://securityratty.com/article/4e4cde7e99db981e380ab3b89a9e61f3</link>
      <guid>http://securityratty.com/article/4e4cde7e99db981e380ab3b89a9e61f3</guid>
      <description><![CDATA[It's become a familiar pattern: after the tragedy, the...]]></description>
      <content:encoded><![CDATA[It's become a familiar pattern: after the tragedy, the spam.]]></content:encoded>
      <pubDate>Tue, 20 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/familiar pattern">familiar pattern</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/tragedy">tragedy</category>
      <source url="http://www.networkworld.com/news/2008/052108-fbi-warns-of-china-earthquake.html?fsrc=rss-security">FBI warns of China earthquake e-mail scams</source>
    </item>
    <item>
      <title><![CDATA[FBI warns of scams offering to help Chinese quake victims]]></title>
      <link>http://securityratty.com/article/ecf3796e96e28c75f76c20ee69ee240f</link>
      <guid>http://securityratty.com/article/ecf3796e96e28c75f76c20ee69ee240f</guid>
      <description><![CDATA[The FBI is warning Americans looking to send donations in the aftermath of the massive May 12 earthquake in China to beware of a rising number of e-mail scams that tout &quot;relief&quot;...]]></description>
      <content:encoded><![CDATA[The FBI is warning Americans looking to send donations in the aftermath of the massive May 12 earthquake in China to beware of a rising number of e-mail scams that tout "relief" efforts.]]></content:encoded>
      <pubDate>Tue, 20 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/e-mail scams">e-mail scams</category>
      <category domain="http://securityratty.com/tag/massive">massive</category>
      <category domain="http://securityratty.com/tag/relief">relief</category>
      <category domain="http://securityratty.com/tag/americans">americans</category>
      <category domain="http://securityratty.com/tag/efforts">efforts</category>
      <category domain="http://securityratty.com/tag/earthquake">earthquake</category>
      <category domain="http://securityratty.com/tag/beware">beware</category>
      <category domain="http://securityratty.com/tag/donations">donations</category>
      <source url="http://www.networkworld.com/news/2008/052108-fbi-warns-of-scams-offering.html?fsrc=rss-security">FBI warns of scams offering to help Chinese quake victims</source>
    </item>
    <item>
      <title><![CDATA[Hacker compromised Red Cross earthquake relief site]]></title>
      <link>http://securityratty.com/article/4d6bbfb5eae634074f1dc88fd8908d09</link>
      <guid>http://securityratty.com/article/4d6bbfb5eae634074f1dc88fd8908d09</guid>
      <description><![CDATA[Hurricane Katrina proved a fertile ground for fraudsters to scam money off those willing to help the needy. Now the China earthquake has bread a new variant of the morally reprehensible, with donated...]]></description>
      <content:encoded><![CDATA[Hurricane Katrina proved a fertile ground for fraudsters to scam money off those willing to help the needy. Now the China earthquake has bread a new variant of the morally reprehensible, with donated funds being siphoned off one charity site.]]></content:encoded>
      <pubDate>Sun, 18 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/china earthquake">china earthquake</category>
      <category domain="http://securityratty.com/tag/charity site">charity site</category>
      <category domain="http://securityratty.com/tag/hurricane katrina">hurricane katrina</category>
      <category domain="http://securityratty.com/tag/fertile ground">fertile ground</category>
      <category domain="http://securityratty.com/tag/scam money">scam money</category>
      <category domain="http://securityratty.com/tag/funds">funds</category>
      <category domain="http://securityratty.com/tag/fraudsters">fraudsters</category>
      <category domain="http://securityratty.com/tag/reprehensible">reprehensible</category>
      <category domain="http://securityratty.com/tag/bread">bread</category>
      <source url="http://www.networkworld.com/news/2008/051908-hacker-compromised-red-cross-earthquake.html?fsrc=rss-security">Hacker compromised Red Cross earthquake relief site</source>
    </item>
  </channel>
</rss>
