<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ipods]]></title>
    <link>http://securityratty.com/tag/ipods</link>
    <description></description>
    <pubDate>Mon, 07 Jan 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Kill Switches and Remote Control]]></title>
      <link>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</link>
      <guid>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.

OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 

Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 

The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.

Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?

How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?

It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.

And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music to a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 

"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.

This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/06/securitymatters_0626">originally appeared</a> in Wired.com.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JiKwGJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JiKwGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aXm5MJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aXm5MJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 02:48:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/devices inevitably">devices inevitably</category>
      <category domain="http://securityratty.com/tag/digital manners policies">digital manners policies</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/kill_switches_a.html">Kill Switches and Remote Control</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: I've Seen the Future, and It Has a Kill Switch]]></title>
      <link>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</link>
      <guid>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[<p>It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.
</p><p>
OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 
</p><p>
Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 
</p><p>
The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.
</p><p>
Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?
</p><p>
How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?
</p><p>
It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.
</p><p>
And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 
</p><p>
"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.
</p>
<p>
---
</p>
<p><em>Bruce Schneier is chief security technology officer of BT, and author of</em> Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2e7004605a2cfdb2dff6647568035341" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2e7004605a2cfdb2dff6647568035341" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TdV5GI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TdV5GI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hCKWyi"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hCKWyi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=P6GE7i"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=P6GE7i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=YY5ZlI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=YY5ZlI" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=rAla0I"><img src="http://feeds.wired.com/~f/wired/politics/security?i=rAla0I" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=DKXIgi"><img src="http://feeds.wired.com/~f/wired/politics/security?i=DKXIgi" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IE7M8i"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IE7M8i" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=swX5hI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=swX5hI" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/320220918" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/320220920" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <category domain="http://securityratty.com/tag/difficult">difficult</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/320220920/securitymatters_0626">Security Matters: I've Seen the Future, and It Has a Kill Switch</source>
    </item>
    <item>
      <title><![CDATA[Last HOPE Radio]]></title>
      <link>http://securityratty.com/article/8da45af79b97174e7dd9dde6e2d03763</link>
      <guid>http://securityratty.com/article/8da45af79b97174e7dd9dde6e2d03763</guid>
      <description><![CDATA[Keeping tabs on the upcoming Last Hope conference this July
From the Last Hope
For Immediate Release
THE LAST HOPE TO FEATURE HACKER RADIO
At The Last HOPE conference, hackers will broadcast their...]]></description>
      <content:encoded><![CDATA[<p>Keeping tabs on the upcoming Last Hope conference this July.</p>
<p>From the Last Hope:</p>
<blockquote><p>For Immediate Release</p>
<p>THE LAST HOPE TO FEATURE HACKER RADIO</p>
<p>At The Last HOPE conference, hackers will broadcast their minds and their iPods.</p>
<p>In the center of the summer&#8217;s top hacker event will be a small isolation booth. &#8220;Radio Statler!&#8221; as the station is called, will send out a three day broadcast of all-original material. From the center of Manhattan, around the clock, discussions of the past, present, and future of technology, creativity, and humanity itself will be transmitted.</p>
<p>The first night of the conference, July 18th, the station will carry a program called Digital Music Night, hosted by Peter Kirn, editor of createdigitalmusic.com. The three hour live concert will feature a convergence of artists and musicians using custom, original tools for performing live in new and bizarre ways, including:</p>
<p>   * Houseplants hooked up to live computer visuals and music<br />
   * A mutant trumpet, halfway between the digital and acoustic worlds<br />
   * Packets of data visualized as three-dimensional eye candy<br />
   * An animated digital art sketchpad controlled by Wii remote<br />
   * A set of digital gloves for gestural DJing<br />
   * A robotic drummer<br />
   * Computer-generated vocals that sing your spam folder to you<br />
   * Live digital art made from vintage game consoles and computers</p>
<p>The station will give additional talk and interview time to the conference&#8217;s speakers, broadcast the keynotes and other popular seminars, and offer attendees who don&#8217;t speak at the podium a chance to share their ideas. Many hackers who already do their own podcasts are being asked to contribute and do special programs for the conference.</p>
<p>Program and content submissions are still being taken, volunteers are being sought, and the organizers are looking for promotional sponsors to help cover the cost of broadcasting. More information can be found at http://radio.hope.net/ or by emailing projects@hope.net.
</p></blockquote>
<p>Damn, I&#8217;ll have to break out Garageband or maybe I&#8217;ll have to submit one of <a href="http://mescaline.liquidmatrix.org">these tracks</a>? HA!</p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=oeF2rP"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=oeF2rP" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=w9prcI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=w9prcI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=sg8Ebi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=sg8Ebi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ThkKXi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ThkKXi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=DVf0ci"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=DVf0ci" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=GxEAEi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=GxEAEi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/305262215" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 07:32:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/live">live</category>
      <category domain="http://securityratty.com/tag/live computer visuals">live computer visuals</category>
      <category domain="http://securityratty.com/tag/hope">hope</category>
      <category domain="http://securityratty.com/tag/digital">digital</category>
      <category domain="http://securityratty.com/tag/digital gloves">digital gloves</category>
      <category domain="http://securityratty.com/tag/live digital art">live digital art</category>
      <category domain="http://securityratty.com/tag/radio">radio</category>
      <category domain="http://securityratty.com/tag/digital art sketchpad">digital art sketchpad</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/305262215/">Last HOPE Radio</source>
    </item>
    <item>
      <title><![CDATA[Are your digital devices Certified Pre-0wned?]]></title>
      <link>http://securityratty.com/article/95751c95a8406869ae2dbe324ea5e7cd</link>
      <guid>http://securityratty.com/article/95751c95a8406869ae2dbe324ea5e7cd</guid>
      <description><![CDATA[I took part in the L0pht Reunion Panel at the Source Boston conference in Cambridge, MA last Friday. It was a lot of fun to get back together with the band and pontificate with no holds barred about...]]></description>
      <content:encoded><![CDATA[<p>I took part in the <a href="http://www.sourceboston.com/blog/?p=27">L0pht Reunion Panel</a> at the <a href="http://www.sourceboston.com/">Source Boston</a> conference in Cambridge, MA last Friday.  It was a lot of fun to get back together with the &#8220;band&#8221; and pontificate with no holds barred about the latest security threats, just <a href="http://www.nytimes.com/library/magazine/home/19991003mag-hackers.html">like we did in the old days</a>.</p>
<p>One of the questions asked of the panel by moderator <a href="http://mffitzgerald.com/">Michael Fitzgerald</a> (who did a kick-ass job) was,  &#8220;What scares you the most these days?&#8221;. My answer was the proliferation of of inexpensive digital devices made in China that we plug into our computers.  The malware problem is getting tricky to dodge.  First you <a href="http://en.wikipedia.org/wiki/Melissa_(computer_worm)">couldn&#8217;t open email attachments</a> you weren&#8217;t expecting. Then you had to worry about <a href="http://news.bbc.co.uk/2/hi/technology/6645895.stm">surfing even trusted websites</a> with JavaScript turned on, even with the latest patched browsers. Now you have to worry about <a href="http://news.yahoo.com/s/ap/20080314/ap_on_hi_te/factory_installed_viruses">plugging in the shiny new digital toy</a> you got as a gift. Perhaps its a digital picture frame, digital camera, music player or silly programmable gizmo. Welcome to the age of factory installed malware &#8211;the age of devices coming <em>Certified Pre-0wned</em>.</p>
<p>The Associated Press <a href="http://news.yahoo.com/s/ap/20080314/ap_on_hi_te/factory_installed_viruses">writes</a>:</p>
<blockquote><p>Recent cases reviewed by The Associated Press include some of the most widely used tech devices: Apple iPods, digital picture frames sold by <span class="yshortcuts" id="lw_1205492037_0">Target</span> and <span class="yshortcuts" id="lw_1205492037_1">Best Buy stores</span> and TomTom navigation gear.</p>
<p>In most cases, Chinese factories — where many companies have turned to keep prices low — are the source.</p></blockquote>
<p>We all know malware is starting to fly under the radar of black list style detection.  Low volume malware is flooding the AV labs&#8217; capability to build detection for it. The digital picture frame sold at Sam&#8217;s club was infected with previously unknown malware that stole passwords and turned off AV software.</p>
<p>An additional threat that has been reported is devices have been found infecting the flash memory cards that are often inserted to upload photos.  <a href="http://isc.sans.org/diary.html?storyid=3995">From SANS</a>:</p>
<blockquote><p><span></span>“Recently I found a virus on it called Troj_Agent.SAO, which is what Trend Micro named it.<span>  </span>Anytime you plug a removable device into it, it would create two files Autorun.inf and autorun.exe.<span>  </span>The exe would place itself in the recycler\recycler folder and the .inf would place itself on the root of the removable drive as a hidden file.<span>  </span>At first I thought this virus came in on one of our employee’s pen drive but after further investigation I discovered that the files that the virus uses were created on the kiosk the day it was shipped out to us.<span>  </span>Also our vendor is using this kiosk in some of their stores at the moment and there have been reports that the kiosks have given their customers a virus. “<span> </span></p></blockquote>
<p>We are back to the days of the floppy or &#8220;sneaker net&#8221; attack vector. Do you know who has touched your SD card or USB drive? Don&#8217;t use it in public.  Don&#8217;t share it with multiple machines. Dan Geer told me he once tossed a USB drive into an audience with the slides for a presentation he just delivered on it.  About 10 people passed it around and copied off the slides.  It came back with a virus on it.  And this was at a security conference.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Mar 2008 13:11:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/low volume malware">low volume malware</category>
      <category domain="http://securityratty.com/tag/drive">drive</category>
      <category domain="http://securityratty.com/tag/tech devices">tech devices</category>
      <category domain="http://securityratty.com/tag/usb drive">usb drive</category>
      <category domain="http://securityratty.com/tag/previously unknown malware">previously unknown malware</category>
      <category domain="http://securityratty.com/tag/digital picture frame">digital picture frame</category>
      <category domain="http://securityratty.com/tag/inexpensive digital devices">inexpensive digital devices</category>
      <source url="http://www.veracode.com/blog/?p=82">Are your digital devices Certified Pre-0wned?</source>
    </item>
    <item>
      <title><![CDATA[Throw away your digital picture frames]]></title>
      <link>http://securityratty.com/article/bb80f799aeb703e8ac04ecfa35c60af3</link>
      <guid>http://securityratty.com/article/bb80f799aeb703e8ac04ecfa35c60af3</guid>
      <description><![CDATA[Surely time itself has warped and it's suddenly April 1st. Come on, if you read the following, wouldn't you first think it was a hoax, as did I
Virus from China, the gift that keeps on giving
An...]]></description>
      <content:encoded><![CDATA[<p>Surely time itself has warped and it's suddenly April 1st. Come on, if you read the following, wouldn't you first think it was a hoax, as did I?</p> <blockquote> <p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/02/15/BU47V0VOH.DTL" target="_blank">Virus from China, the gift that keeps on giving</a></p> <p>An insidious computer virus recently discovered on digital photo frames has been identified as a powerful new Trojan Horse from China that collects passwords for online games -- and its designers might have larger targets in mind.  <p>"It is a nasty worm that has a great deal of intelligence," said Brian Grayek, who heads product development at Computer Associates, a security vendor that analyzed the Trojan Horse... The authors of the new Trojan Horse are well-funded professionals whose malware has "specific designs to capture something and not leave traces," Grayek said. "This would be a nuclear bomb" of malware.</p></blockquote> <p>Mocmex is its name. Reportedly, it can evade hundreds of anti-malware and firewall products, including the Windows Firewall. I suspect that this succeeds only when users are logged in as administrators, so here's yet another reason to stop doing this altogether, as is the US Government with its new <a href="http://fdcc.nist.gov/" target="_blank">Federal Desktop Core Configuration</a> for Windows XP and Windows Vista.</p> <p>The virus actually propagates to just about any kind of removable USB storage device, jumping from various well-concealed hiding places on your PC whenever such a device is inserted. Picture frames are implicated because the virus apparently originated in the factory where the frames were built (in turn sold by Best Buy, Sam's Club, Target, and Costco, but now discontinued). Amazingly, according to the UK security firm Prevx, over 67,500 variants of this thing exist!</p> <p>Even more amazing:</p> <blockquote> <p>[Mocmex] isn't the only piece of malware involved. Deborah Hale of Sans said the researchers also found four other, older Trojans on each frame, which may serve as markers for botnets -- networks of infected PCs that are remotely controlled by hackers.  <p>There is W32.Rajump, which deposits the same piece of malware that infected some of Apple's video iPods during manufacturing in October 2006. It gathers IP addresses and port numbers from infected PCs and ships them out, according to Symantec. One destination is registered to a service in China that allows people to conceal their own IP addresses.  <p>Then there is a generic Trojan; a Trojan that opens a back door on PCs and displays pop-up ads; and a Trojan that spreads itself through portable devices like Mocmex does.</p></blockquote> <p>More reasons to <a href="http://blogs.technet.com/steriley/archive/2007/10/30/more-on-autorun.aspx" target="_blank">disable Autorun</a>, I suppose. Yet this isn't a cure-all: if you're logged in as administrator, the virus helpfully re-enables Autorun. Sheesh! If you own one of these frames, SANS suggests that you take it to a friend who has a Mac or Linux box and plug it in there. Yeah, that's good advice; there exist no viruses for these operating systems, correct? It's irrelevant which operating system you're using -- if you run with full privileges, you'll get 0wn3d soon enough.</p> <p>It's fascinating that the thing targets online games, although it could certainly harvest just about any private information stored on your PC. Mining online game accounts might be pretty profitable, you know. Consider the number of people who pay real money for virtual (=fake) stuff in World of Warcraft, Runescape, and whatever else. I suppose losing their passwords to picture frames might help such people regain a tenuous foothold on reality.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=2909038" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 19 Feb 2008 00:36:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/frames">frames</category>
      <category domain="http://securityratty.com/tag/picture frames">picture frames</category>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/generic trojan">generic trojan</category>
      <category domain="http://securityratty.com/tag/digital photo frames">digital photo frames</category>
      <category domain="http://securityratty.com/tag/trojan horse">trojan horse</category>
      <category domain="http://securityratty.com/tag/virus apparently">virus apparently</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/02/18/throw-away-your-digital-picture-frames.aspx">Throw away your digital picture frames</source>
    </item>
    <item>
      <title><![CDATA[Student antics with cell phones, iPods means heartburn for school IT staff]]></title>
      <link>http://securityratty.com/article/4566f6416f9eca73af29a43d9a3953ea</link>
      <guid>http://securityratty.com/article/4566f6416f9eca73af29a43d9a3953ea</guid>
      <description><![CDATA[Student antics with cell phones, iPods, and social-networking sites means heartburn for school IT staff charged with network...]]></description>
      <content:encoded><![CDATA[Student antics with cell phones, iPods, and social-networking sites means heartburn for school IT staff charged with network security.]]></content:encoded>
      <pubDate>Mon, 07 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/student antics">student antics</category>
      <category domain="http://securityratty.com/tag/cell phones">cell phones</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/staff">staff</category>
      <category domain="http://securityratty.com/tag/ipods">ipods</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/heartburn">heartburn</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://www.networkworld.com/news/2008/010808-schools-cell-phones.html?fsrc=rss-security">Student antics with cell phones, iPods means heartburn for school IT staff</source>
    </item>
  </channel>
</rss>
