<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: schematics]]></title>
    <link>http://securityratty.com/tag/schematics</link>
    <description></description>
    <pubDate>Sat, 05 Apr 2008 10:13:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Protect Any Hard Drive With This Drive Enclosure]]></title>
      <link>http://securityratty.com/article/1301ccecec7fc545a77d882af117f93b</link>
      <guid>http://securityratty.com/article/1301ccecec7fc545a77d882af117f93b</guid>
      <description><![CDATA[Maybe you're a spy or you've got schematics for the next hot gadget locked away on your hard drive, but either way you're going to want to lock your files...]]></description>
      <content:encoded><![CDATA["Maybe you're a spy or you've got schematics for the next hot gadget locked away on your hard drive, but either way you're going to want to lock your files down. "]]></content:encoded>
      <pubDate>Thu, 15 May 2008 07:17:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hard drive">hard drive</category>
      <category domain="http://securityratty.com/tag/hot gadget">hot gadget</category>
      <category domain="http://securityratty.com/tag/spy">spy</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/lock">lock</category>
      <category domain="http://securityratty.com/tag/schematics">schematics</category>
      <source url="http://digg.com/security/Protect_Any_Hard_Drive_With_This_Drive_Enclosure">Protect Any Hard Drive With This Drive Enclosure</source>
    </item>
    <item>
      <title><![CDATA[Adding webwise.net into the CNI]]></title>
      <link>http://securityratty.com/article/734438b0e8cd30dd719fca4bc57e17bd</link>
      <guid>http://securityratty.com/article/734438b0e8cd30dd719fca4bc57e17bd</guid>
      <description><![CDATA[The way in which the Phorm system works (see yesterdays blog post ) creates an interesting, and possibly unexpected, risk for the ISPs that decide to go ahead and deploy the system
Quite clearly , web...]]></description>
      <content:encoded><![CDATA[<p>The way in which the Phorm system works (see <a href="http://www.lightbluetouchpaper.org/2008/04/04/the-phorm-webwise-system/">yesterday&#8217;s blog post</a>) creates an interesting, and possibly unexpected, risk for the ISPs that decide to go ahead and deploy the system.</p>
<p><a href="http://www.cl.cam.ac.uk/~rnc1/080404phorm.pdf">Quite clearly</a>, web browsing from within these ISPs now depends on the correct functioning of the &#8220;Layer 7 switch&#8221; and Phorm&#8217;s &#8220;Anonymiser&#8221; machine. This should not be too much of a concern. Network engineers are used to designing out &#8220;<a href="http://craighuggart.typepad.com/tech_yourself_to_rest/2007/06/never-rely-on-a.html">single points of failure</a>&#8220;. Thus, for example, the <a href="http://www.theregister.co.uk/2008/02/29/phorm_documents/">BT schematics</a> obtained by The Register show parallel systems and cross-coupling of components, so that a single failure will not take out the system. Add in the fact that what are apparently single machines will almost certainly be clusters fronted by intelligent load-balancing devices, and the system is expensive, but extremely resilient.</p>
<p>However, there&#8217;s another rather less obvious issue that needs to be addressed.</p>
<p>The bouncing of all web requests back and forth with HTTP 307 redirections means that the system is critically dependent upon the correct resolving of the <a href="http://www.whois.ws/whois-net/ip-address/webwise.net/">webwise.net</a> domain. If, for whatever reason, the domain name system (DNS) didn&#8217;t return the correct answer when asked for the IP address of webwise.net, then everyone at that ISP would find that their browsing was seriously affected.</p>
<p>If the incorrect address came back as <a href="http://tools.ietf.org/rfc/rfc3330.txt">127.0.0.1</a> then the customers wouldn&#8217;t be able to reach any websites at all &#8212; if it came back as the IP address of a machine in downtown St Petersburg, then that site could redirect their web sessions at will &#8212; and there&#8217;s likely <a href="http://www.sptimes.ru/index.php?action_id=2&#038;story_id=23314">some criminals in that city</a> with some innovative ideas of what could happen next.</p>
<p>So the webwise.net domain has suddenly been promoted to become part of the <a href="http://www.cpni.gov.uk/">Critical National Infrastructure</a> (CNI).</p>
<p>The domain is currently hosted at <a href="http://www.godaddy.com/">GoDaddy</a>, an american registrar. Last summer the rock-phish gang spent a week running phishing attacks not just against banks, as they usually do, but <a href="http://www.castlecops.com/Citizens_Bank_GoDaddy_Rock_Phish_Royal_Bank_of_Scotland_phish522534.html"> also against GoDaddy</a>. The immediate reaction was that the criminals wanted to use captured credentials to purchase domain names for free &#8212; but wiser heads pointed out that with the login details for a GoDaddy account you were in <a href="http://blog.internetidentity.com/blog/_archives/2007/8/3/3142735.html">full control of any domain names that had already been bought</a> : the security of the websites of thousands of major companies (and a great many banks) was resting on the security of eight-character registrar login passwords.</p>
<p>However, firms that have considered the risk don&#8217;t buy $10 domain names, but spend rather more, and their registrar will insist on rigorous security checks before altering any details. We must obviously assume that webwise.net is not at risk from registrar phishing in this simplistic way.</p>
<p>The more likely way of subverting what webwise.net resolves to is called &#8220;DNS cache poisoning&#8221;. There are several ways of doing this (this <a href="http://en.wikipedia.org/wiki/DNS_cache_poisoning">Wikipedia article</a> provides a helpful summary), most of which shouldn&#8217;t work if the ISP has configured their DNS server correctly.</p>
<p>However fundamental weaknesses in the DNS protocol (relying on 16bit values matching to show authenticity) means that DNS forgery attacks can only be made harder, not prevented altogether. Making it harder may currently be sufficient to make phishing attackers use simpler methods &#8212; but if the prize is the disruption of web browsing for millions of people&#8230;?</p>
<p>There are things that the ISPs can do to improve security &#8212; such as each of them making themselves authoritative for webwise.net, which should address the DNS forgery issue. Let&#8217;s hope that they haven&#8217;t overlooked this.</p>
<p>[[with acknowledgments to Matt Johnson and others involved in understanding this particular design risk]]</p>
]]></content:encoded>
      <pubDate>Sat, 05 Apr 2008 10:13:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domain names">domain names</category>
      <category domain="http://securityratty.com/tag/purchase domain names">purchase domain names</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/dns forgery issue">dns forgery issue</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/dns forgery attacks">dns forgery attacks</category>
      <category domain="http://securityratty.com/tag/webwise">webwise</category>
      <category domain="http://securityratty.com/tag/net domain">net domain</category>
      <source url="http://www.lightbluetouchpaper.org/2008/04/05/adding-webwisenet-into-the-cni/">Adding webwise.net into the CNI</source>
    </item>
  </channel>
</rss>
