So, I too received, after waiting for almost a year from the time I joined the original group buy, for my Flipper Zero. I have already started playing with it, but that will be the subject for another post. For now you will have to make do with its glorious pre-8bit artwork.
Monday, May 23, 2022
Thursday, March 31, 2022
Facebook, Ireland, and GDPR inconsistencies
Early this month Meta Platforms, Facebook's parent company, was fined € 17 million by the Irish Data Protection Commission (DPC) fined after concluding the American business failed to comply with GDPR requirements in 12 breach notifications between June and December of 2018, and which affected 30 million Facebook users.
Meta has downplayed the severity of the violation in an emailed statement:
"This fine is about record keeping practices from 2018 that we have since updated, not a failure to protect people's information."However, this lack of "record keeping" means Facebook is not documenting/proving they are protecting people's information. And that not only violates the principle of Due Care but also infringes GDPR Articles 5(2) and 24(1).
But, this is not important.
This is not the first time Meta had been fined for GDPR violations, nor it is the largest fine it has received; the € 60 million penalty from Jan 2022 and the € 225 million from Sept 2021 top that by such a long margin they are in a different league.
And this is not important either.
It is significant that the Irish GPC fined it; that does not happen very often. Ireland is the European headquarters of most of the American companies, including the 10 tech giants -- Apple, Google, Twitter, etc -- with an European presence. Since 2018, an average of 10,000 complaints per year have been filed with the Irish GPC. According to the Irish Data Protection Commissioner Helen Dixon, of those thousands of complaints, two were issued decisions in 2020, and she expected up to six decisions to be made in 2021, or 0.07% of all GDPR complaints.
Then we have the issue of the fines. Per the GDPR, they can be up to 4% of a firm’s global revenue. While Dixon said any fine would reflect the significant number of users affected, in June 2018 Facebook reported a bug caused 14 Million users to share friends-only content with strangers. Then September 2018 thr social medial giant disclosed a major hack which could have compromised up to 50 million user accounts. Later it claimed this hack resulted in a data breach where the data of only 30 Million users was stolen. Finally in December of that year another bug compromised 5.6 Million users.
And yet the Irish DPA decided € 17 million was enough to reflect the significant number of users affected.
Max Schrems, who has stated that
The [Irish] DPC simply interprets the word "handle" to mean that the DPC can also simply dispose of complaints on the fundamental right to privacy. She openly argued “In fact, there is no obligation on the DPC under the 2018 Act to produce a decision in the case of any complaint.”has also accused the Irish DPC of advising Facebook on how to bypass GDPR by redefining their agreement with the user as a "contract," which would make the GDPR "consent" requirement no longer applicable.
But, this too it also not important.
What is important anyway?
This show a clear inconsistency between the how Ireland and the rest of the EU handles GDPR complaints. The Irish DPA is the lead supervisory authority for cross-border cases that fall into its jurisdiction. Given its past history, it is probable it may not side with the Austrian and the French Data Protection Authorities regarding Google Analytics.
This regulatory discrepancy creates an incentive for companies which want to use Google Analytics and other means of data transfer between the US and EU that are considered against the GDPR to set up shop in Dublin. While this may be good for the Irish economy,
- How will this different interpretation of the GDPR articles play out given that one of the goals of the GDPR is to regulate the processing personal data within the entire European Union?
- Is this even an inconsistency or do EU members have some latitude to interpret GDPR articles based on local laws? Remember that when the French Data Protection Authority decided that Google Analytics was not GDPR compliant, the Austrian one had already made the same decision. That seems to imply there is some jurisdiction independence across the EU, and perhaps the Google Analytics ruling will only become applicable to the entire EU/EEA if enough Data Protection Authorities decide to support that.
- Will other European countries invoke Article 65(1)(a) and request the European Court of Justice, or the European Data Protection Board, to intervene and enforce some kind of legal consistency for all member countries?
Saturday, March 12, 2022
Phishing Is Too Easy - 2
A long while ago I posted here about how easy it was to phish. Yes, it was that long; where has time gone?
Anyway, some phishers seem to have decided that embeding malicious code as payloads into either the email itself (thanks to HTML-aware emails) or into attached documents -- Microsoft Word/Excel/Powerpoint documents, PDF files, or even some image formats -- was a bit too time consuming. Or, it was being picked up by the usual mail scanners and deleted. So, what can they do? Well, elicit the help from the user! Ok, you may argue that all phishing campaigns rely on social engineering, and you would be correct. But, how can that be craft to evade scanners once the users are conned? Let me answer that by presenting this gem of phishing email, which I added to my collection a few days ago:
At first glance, it seems this email will be innefective, as it starts rather carelessly:
- The return address is a typical quasi-randomly created Gmail one; they could not be bothered with making it sound like it came from a billing department as it claims to be.
- Also notice they do not even specify the company they are hailing from; they just said something about a Billing Department.
- This email from some billing department from an unknown company is about the purchase of McAFEE Total 360.
What seems to be carelessness is actually genius. You see, most people who read this email will not pay attention to the return email address and lack of a business name. All they will focus on is the 3rd item listed above: they just received what seems to be a bill for a software they can't remember ordering. What to do?
There is a phone number prominiently on the bottom of the email. That is the clever move. I expect the next moves to play out as follows:
- Customer's (the mark) mind will focus on, as mentioned above, the fact they are seeing an unexpected $300 bill. Why did they receive it? Was that an accident? Did someone with a similar name ordered it? This is the fear component of the phishing email.
- It says the charge mode is "Auto Debit!" I too have no idea of what "Auto-Debit" means. Maybe they wanted to say auto renewal using a debit card. But the point is these words create a sense of urgency, which is another component of a good phishing email.
- So, they call the phone number to fing what is going on. The person on the other end, who is an Eastern European man called Peggy (bonus points if you know which old ad I am alluding to), will maybe ask for the mark's personal (before you get excited, GDPR does not apply to criminals since by definition they do not follow the law) and credit/debit card information to "confirm" (read: store and sell) if that was the card used. However, it would make more sense if he...
- Peggy will probably ask the mark to go to a website and then download and install something in the mark's computer (ideally a work one) to check if the McAFEE program is installed and then uninstall it. As expected, that is a trojan horse to help deploy the real payload. The good thing about being on the phone is that Peggy can help the mark work around the malware protection software in place so the trojan can be successfully installed.
Recommendation
If you receive such email, take a break before acting on it. Then, if you received it at work, reach out to your IT security people and ask for help. Relying on software to magically find and delete such emails does not work all the time. You the user is the most important line of defense.
Thursday, February 24, 2022
Thoughts on taking the CISSP exam - 2
Plan Your Dive, Dive By Your Plan
That is the motto of the Divers Alert Network, and I think it is very appropriate here... and on job interviews.
One thing I did not add to the original post on taking the CISSP exam is that on the day before the exam, I drove to it about the same time I expected to leave. Reason is that I wanted to know where the place was and how long it would take so I would be there 30min or so before it started. In other words, I wanted to eliminate a source of pre-test stress.
Without further ado, here are the real pictures I took that day:
- First, here is the building. After driving there on the day before, I decided to leave home 15 minutes earlier to account for the traffic I saw. Also, I am glad I did the dry run since on the exam day, when I drove into the road that leads to the parking lot the building is located, it was packed. I then realized by looking at the vehicles they were going to the construction site I noticed in the previous day, so I was able to go around them instead of sitting there and missing my appointment.
If you are not driving there, it is even more important to figure out how to get to the test site well in advance. Imagine if you need to take a few trains and maybe a subway or a tram in the process? Are they schedule reliable? If you miss one of those public transports, how long will you have to wait until the next?
- Once inside, I was very happy to find out there was a nice sign pointing to where the Pearson VUE office was. Nice touch, Pearson VUE!
- The actually office where the exam took place was down the corridor. I also took the opportunity to find out where the bathroom is. Remember you can take bathroom breaks; it might be wise to find its location so you do not waste valuable exam time hunting for it when you really need to go.
Incidentally, there was a water fountain across the corridor from the bathroom.
- During exam day, I had no problem getting there ahead of time. In fact, I was so ahead of time the suit was still locked. By then a few more candidates, for other exams it turned out, had showed up. We chatted a bit until they let us in. And it was smooth sailing until the exam started.
TL;DR: Make your life easier! Eliminate as many variables before the exam as you can.
Sunday, February 20, 2022
GDPR, France, Schrems II, and Google Analytics
If you grew up in The United States, you may recognize the picture below and remember television ads (yes, I have watched network television with commercials) that would push some trinket (think on the lines of a "belt that doubles as straw" or "self-cleaning shoe rack" which in fact is really complicated). When it came the time in the ad to say how much it was and how to order it, there was always a "But wait! There is more!" segment where they would bundle more junk in hopes the viewers would think they are getting a deal.
With that piece of Americana in mind, we will start this article asking if you remember when we talked about the Austrian Data Privacy Authority (DSB) decided Google Analytics is not GDPR-compliant. You do? Great!
But wait! There is more!
Earlier this month the French Data Privacy Authority (Commission Nationale de l'Informatique et des Libertés, or CNIL for those like me who are not typing-trained) concluded, after receiving a complaint from the NYOB association regarding a French website using Google Analytics, that data transfers performed by Google Analytics are illegal in France. The reasoning is the same as their Austrian counterpart: Schrems II, as in there are not enough safeguards to protect this data collected from European Union residents from US intelligence agencies.
Workarounds
We mentioned them before, so let's just focus on the most important ones:
- Stop using Google Analytics; it violates GDPR Article 44. Google Ireland does not cut it.
- If you really need the functionality provided by Google Analytics, find a tool that transfer data outside the EU.
- Any data collected by a Google Analytics-like but GDPR-friendly program should either be immediately anonymized (before being fed to the analytics program), has a Legitimate Purpose as defined in GDPR Article 6, or requires explicit consent from the data subject.
According to the CNIL ruling, the French website in question has 1 month to comply.
Given that NYOB filed complaints the 27 European Union Member States and the three other states belonging to the European Economic Area (EEA), expect more of these decsions to come.
Saturday, February 5, 2022
GDPR, Austria, Schrems II, and Google Analytics
By now you may have learned that if you are an European company, or a company which does business with European residents, you really should not be using Google Analytics. Case in point happened in Oct 2nd 2020 when, according to The Register, the Austrian Data Protection Authority (Datenschutzbehörde or DSB) received a NOYB-sponsored complaint regarding NetDoktor, a website which offers medical knowledge and health information. It also has versions of this website in English (TLD ".uk") and Danish (TLD ".dk") languages; there may be more but I could not be bothered to look for them. Because this Hubert Burda Media-owned website is financed through advertising and licensing, it chose to Google Analytics probably (educated guess here!) to track what each of its users have done during their visit:
- Identifiers
- IP address
- Browser version, operating system, and other system identifying parameters
- Which pages were read
- How much time was spent on each page
Per the General Data Protection Regulation (GDPR), this kind of personal data collection is not viewed as a Legitimate Purpose as defined in Article 6, so it needs to have explicit permission from the data subject. One should also notice that because of the service provided by this website, the personal data collected using Google Analytics, unless properly anonymized, may be used to infer the medical condition -- which is one of the special categories of personal data per GDPR -- of the data subject.
It gets better:
- Google is an American company, so it must follow the US CLOUD Act of 2018 and section 702 of the FISA Amendments Act of 2008, which allows US intelligence agencies to collect any personal data stored in servers owned by US businesses that are identified as "electronic communication service provider" by 50 U.S. Code § 1881(b)(4) without the need of a warrant.
- Google cannot protect the personal data being collected by Google Analytics in the NetDoktor website to satisfy the Article 44 (transfer of data to be processed on a country outside the European Union or European Economic Area).
- Google cannot base the data transfer on standard data protection clauses as the US does not ensure adequate protection
- And that means this personal data transfer between NetDoktor and Google violates the Schrems II decision of 2020, where the European Court of Justice (ECJ) declared the Privacy Shield mechanism was not a valid means of transfer data between EU/EEA and the US.
As a result, the DSB declared this data transfer illegal.
Some EU and US companies may have tried to work around these limitations by using Standard Contractual Clauses to transfer data between them. That does not satisfy Schrems II.
What can I do as a US business?
The ideal solution is for the US to adopt privacy laws that are closer to those in the EU. Until that happens,
- What if I run a website that is not offering a product or a service specifically directed to an EU or EEA resident, like a blog? Even though technically you would not be subject to Article 3 of GDPR, you have no reason to collect any personal data. Let's use Blogger, which is owned by Google, as an example. According to google's documentation, to use analytics with blogger you must
- Sign up for an analytics account
- Add analytics tracking to blogger.
Continuing with the Blogger theme, is Google honoring your decision not to collect data? i.e. does it collect any other additional data from the blog users it has not divulged to the blog owner? Good question; IMHO the onus here would be with Google.
- What if I am providing services/products targeted at EU/EEA residents? You fall into Article 3, so
- Minimize the amount of personal data you have to collect. Remember you are still subject to the CLOUD Act.
- Avoid using cookies or other form of analytics to collect data you do not need to provide the service to your customers. Remember the Legitimate Purpose (Article 6).
- If you really need the functionality provided by Google Analytics, find a tool that transfer data outside the EU.
- Anonymize any data you can as soon as possible. Rememeber anonymization is not tokenization or pseudo-anonymization.
- Process and store any personal data in an EU server, ideally one not owned by an American company identified as "electronic communication service provider" by 50 U.S. Code § 1881(b)(4).
TL;DR
Don't use Google Analytics.
Thursday, January 27, 2022
BadUSB, or There and Back Again
In that often misunderstood time between mullets and the switch to laptops without normal USB ports (I am looking at you, Apple), a traditional part of an on-premises pentesting was to grab all those USB drives you got from those many conferences you attended, wipe them to remove the informercials, white papers, and and other cruft, put a little script that would be called when the drive was automounted in a Windows or Mac (primarily Windows because it was easier), and then drop them on the parking lot of the company you are doing your engagement on.
The script was pretty simple: when run it would collect the IP, some computer info, and username. And then it would send that info to a collecting site (cannot call it C&C because it is not doing that much work), which would then parse all the info in a nice spreadsheet which you would then bring to your meeting with your customer as the list of users that may need some security retraining. After all, if a pentester can do that, so can a malicious attacker (are there non-malicious attackers?). It is a nice way to deploy a virus, or a program to help the attacker to get a foothold in the system.
Those were simpler times.
Talks were given and dongles were created to avert such an attack because, well, it was easier to buy them than asking IT department to push a group policy to disable automount. Or telling users not to mount any USB device they find on their computers.
But, we are talking about BadUSB! Yes, and it was first mentioned in 2014. The short version is that thanks to the typical development methodologies similar to those used in IoT development, namely get a product out there as quickly and cheaply as possiblw with complete disregard to supply chain security or security testing in general, a lot of USB devices are built on controllers which can be reprogrammed in the field. And reprogrammed they are, this time carrying malicious payloads like programs to spy on the user or get a foothold on the system.
Sounds familiar? I think so. Adding your code to the USB device's hardware to it is but an evolution of the principle of having code in a USB drive that is run when it automounts.
Fast forward almost a decade and we begin the year with the FBI sending warnings about this new attack vector called BadUSB that groups like FIN7 created to deploy ransomware even though they have been doing that for many years now.
There is no one-size-fits-all technical solution for BadUSB, not that have stopped vendors peddling software to address it. We will go over detailed a plan of action to minimize the effectiveness in a future article, but it sufices to say the old adage of "select your partners and wear protection" still applies. Also, end users are one of the most important lines of defense in the security domain. Work with them, empower them to understand and make the call; it can work if you do it right. Make the presentation enjoyable and memorable. I mean, if I could make that work at a medical institution to the point our box of found USB drives had to be replaced with a bucket, so can you.


