Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, March 4, 2013

Security Conscious: Google Two Factor Authentication with 3rd Party Sites

I'm sure many of you are aware that Google offer an option to enable two-factor authentication in order to access their services. If aren't familiar with the system, or simply haven't enabled it on your account(s) already, then I strongly recommend that you read Google's guide on the subject and enable it for any accounts you may have registered.

I have been using the two-factor authentication mechanism for some time now in conjunction with Google's own Authenticator app. One particularly nice feature is that if you have the Barcode Reader app installed, you can quickly configure the reader for each of your accounts by scanning a QR code generated during the set up.

But Wait... There's More!

I recently logged into my Dropbox account in order to remove some devices that I no longer used and I noticed that there was an option to enable two-factor authentication. At first I thought it would consist of a message sent to me (via email or SMS) whenever I attempted to log in, but I discovered I was able to use the Google Authenticator app here too; I simply scanned the QR code when presented, input the code displayed on my phone and my account was secured!

It didn't stop there either; I was also able to secure my Guild Wars 2 account using the exact same method! I wonder if there are any other services/companies out there using this authentication mechanism that I may have missed? I know that Blizzard now offer their own free app to authenticate to Battle.net, but I'd rather have a single app to install.

Saturday, August 11, 2012

Low Cost CCTV Solution

Over the past several months, I have implemented and refined a home-security system built around the open source application, ZoneMinder. It started with a fairly simple requirement: being able to investigate any alerts generated by our ADT monitored alarm system.

The Software

  • Ubuntu - I opted for this distro because there was the potential for the system to double as a media centre. I honestly believe that Canonical have done a great job making a Linux distribution for everyone to use and I wanted to make sure any non-techies using the machine wouldn't be (completely) lost!
  • ZoneMinder - after installing Ubuntu, installing ZoneMinder was a breeze; it's available via the standard package repositories.
  • MySQL - required for ZoneMinder's database. Installing the application via apt meant that this was installed and the relevant DB creation was taken care of automatically.
  • Apache - required for ZoneMinder's web interface. Again, this was automatically installed an configured as part of the apt installation routine.

The Hardware

  • Samsung X60 - I bought this machine back in 2005 (my first laptop purchase) and for a couple of years it was my primary machine for work and gaming. However, it soon became obsolete and was added to a pile of spares. I set up the laptop underneath the TV in our lounge, using the docking station I had purchased with the machine. This meant I could connect the machine to the TV, which prompted the choice of Ubuntu as the OS (see above).
  • Logitech Quickcam 4000 - this device was directed towards the centre of the living room. Not only did this provide ZoneMinder with a great view over the main thoroughfare of the house, but when not monitoring the room the camera could be used by Skype, turning the sofa into a comfy video-calling booth.
  • Logitech QuickCam Express - I positioned this to face the rear of the house; covering the back door.

With the system installed and configured and both of the cameras in place, I had a view over most the lower floor of our home. However, this was only the start; I had previously considered using a smartphone as a wifi-enabled network webcam, and I thought it would be perfect if I could hook one up to the ZoneMinder server. Sure enough, after a bit of searching online, I came across a guide on Google+ for re-purposing an Android smartphone as a remotely accessible camera, by simply serving the camera feed over HTTP. The only caveat: the software (IP Webcam) required the device be running Android 2.2 (Froyo) or higher. The two devices I had earmarked for use were an old T-Mobile G1/HTC Dream and a HTC Hero, which were only officially upgraded to 1.6 (Donut) and 2.1 (Eclair) respectively. To get around this issue I simply installed the most stable version of Cyanogenmod for both devices, Cyanogenmod 6 (Android 2.2/Froyo) on the G1/Dream and Cyanogenmod 7 (Android 2.3/Gingerbread) on the Hero.

Using the remote monitor feature in ZoneMinder, I was quickly able to configure both devices as wifi cameras and I positioned them in windows to cover the front and rear exterior of the property. With all the cameras in place, it was possible to fine-tune ZoneMinder's configuration:

  • Monitor Calibration - to ensure a negligible number of false alarms, I found I had to adjust the sensitivity of the monitors/cameras and set "preclusive" zones; a region whereby any detected motion negates any potential alarms from being fired. This was mainly to compensate for changes in lighting conditions (when the Sun is obscured by a cloud, for example).
  • Secure Remote Access - using port forwarding on my home router, and configuring Apache to serve the ZoneMinder control panel over HTTPS, I was able to view the monitors when outside of the house.
  • Emailing Alerts - having ZoneMinder generate email alerts should certain conditions be met (enough alarms being triggered, for example).

One final step I took to improve the remote viewing capabilities of my Android phone was to install the Lite version of IP Camera Viewer. This little app allows you to set up multiple camera feeds (not just those of ZoneAlarm) to view on your phone. You are able to view each feed independently, or as a matrix/grid. While it doesn't react to any of ZoneMinders alarms, it does provide a really quick and easy way to check up on home should an alert be received.

Tuesday, November 1, 2011

Asinine AV "Alerts"

Being the "go-to" guy for most of my friends and family when they have a problem with their computer, I have seen some machines in terrible states. On the odd occasion I've had to open up the computer, they are usually filled with dust that clogs fans, heat sinks and exhaust ports. However, most of the time, the problem is software based, specifically the operating system.

Given the amount of malware that exists in the wild, it seems almost inevitable that the average consumer will eventually fall prey to some form of malicious software, whether delivered via a link in an email from a "friend", clicking a tempting ad on a torrent site, or even simply being unfortunate enough to navigate to a page containing an xss exploit. Some of the pop-ups masquerading as messages generated by the OS can be very convincing as well and scare users into clicking them by suggesting that their machine is "at risk".

While I despair at the number of ways a user can be trick into infecting their machine, I also find myself frustrated at the anti-virus companies themselves, for I have found they too can be responsible for helping a user compromise their machine. I'm talking about the stream of alerts and warnings that are generated by free security products, designed to coax a user away from the free product and onto a subscription-based version.

Obviously, it's in the AV companies interest to have more customers paying for their security tools and suites, so I understand the motive for embedding such messages into a free product. However, in my experience, once an AV suite's free trial expires the user will rarely fork out money to continue with the subscription. This is also an issue for free trials of AV suites that are bundled with machines. Essentially, the user continually ignores the warnings that their free trial has expired, which prevents them from downloading any additonal virus signatures or upgrades. The longer the user leaves it, the greater the risk of infection as their AV suite becomes more out of date.

I think what I find most disturbing about this trend is the wording used in these messages seem geared towards scaring users into upgrading. With phrases like "your PC is not fully protected" being presented to the user, alongside exclamation point warning signs, it's easy to become convinced that your machine is unsafe. This seems rather too close to the same tactics employed by FakeAV virus writers.

In my opinion, I think AV vendors should take two courses of action:
  1. If they are going to advertise their subscription-based product in the free application, then they should make it clearer that this is an advert and warn the user that agreeing to switch product will eventually require them to part with some money.
  2. If an upgrade does occur, it shouldn't have to be a manual process to re-install the free version of the product. Instead of preventing the software from receiving new virus definitions and attempting to warn the user if the danger, wouldn't it be easier to disable the components that make it a paid-for product?
I regularly recommend (and install) free security products, but I find it difficult explaining to people what alerts they should pay attention to and those they should ignore. As it stands currently, I tend towards ZoneAlarm (free edition) for the firewall and recently I switched my allegiance from AVG to Antivir, because of two events (coincidently, the same two events that spurred me onto getting this post published):

The first was a system tray alert from AVG informing me that it had protected me from over 400 threats this month, which I found rather alarming; both myself and my partner are careful users of the web and both of us tend to discuss any strange incidents that may occur during our day-to-day computer usage. I was fairly sure that with over 400 threats having been eliminated over the past month, there should have been some alerts from the AV software, and so I checked the application's event log to see when the system had been protected - nothing. There were no virus alerts that I could see, nor were there any viruses in the "Vault"; a quarantine area for suspicious files.

The final straw was during an upgrade to AVG Free 2012, I was prompted by the following dialog box to choose which version of the application to install:


First, if I had wanted to opt for the "full" version, I would have downloaded the relevant installer/paid for the product! However, I decided to investigate their claim that "you can always switch to basic protection later", in case it actually met my expectations as set out above. As I suspected; the only course of action was to completely un-install and re-install! I'm now keeping my fingers crossed that I don't have a similar experience with Antivir; otherwise I'll have to find another AV product to switch to!

Wednesday, October 7, 2009

Wireless Security

Wireless technology based on the various IEEE 802.11 standards is becoming ubiquitous in the home and workplace. While most offices will have I.T. staff who understand the security implications of implementing a wireless network, there are still many businesses that have poorly configured equipment, resulting in a vulnerable system.

If there are businesses still in the dark when it comes to wireless networking, what about the average home user? Almost all wireless access points purchased by consumers will work "out-of-the-box", providing an easy way to extend the range of your home network. However, it is highly unlikely that the configuration used will include any network authentication or encryption, allowing anybody to connect and use the networks resources (Internet, file-shares, printers, etc.). If the unauthorised user is of the Black Hat persuasion, they may attempt to compromise any system they find on the network - a home P.C. would provide a wealth of information about the owners of the network.

In order to protect a wireless network, it is necessary to understand the configuration options available.


Change Default SSID

The Service Set Identifier (SSID) of a wireless network is the network name - on most access points, the default is simply the make and/or model of the device. It is prudent to change this to something unique and that doesn't make it possible to identify the owner of the wireless network.

Disable SSID Broadcast

It is possible to disable the broadcast of your SSID - however, due to the nature of wireless networks, it is still possible to extract this information from the packets of data being exchanged between machines on the network through the air. Therefore, this is not a security option and can be disregarded when configuring a router.
In fact, it has been shown that configuring a wireless network to not broadcast it's SSID can actually have an impact on it's performance - read this pdf.

MAC Filtering

All network adapters have a quasi-unique address encoded into the hardware that takes the form xx:xx:xx:xx:xx:xx, with each "xx" a hexadecimal value between 00 and FF - this is the card's MAC address. It is possible to configure most wireless access points with a list of MAC addresses, and either permit or deny access to network cards with corresponding addresses. However, as it is possible to change the MAC address of a network card using a machine's operating system, this would not take long for a determined hacker to bypass.

WEP - Wired Equivalent Privacy / Wireless Encryption Protocol

Despite the name, WEP does not offer the same level of privacy as a wired network - in fact, it's far from it. Essentially, WEP encrypts traffic on a wireless network using either a 40 bit or 104 bit key. Client machines can also be forced to authenticate to the network using the key (Shared Key authentication); however, it is more secure to have no network authentication (Open authentication), and rely on the encrypted traffic to secure access to the LAN's resources. This may seem counter-intuitive, but it is very easy to derive the network key by capturing the entire authentication "handshake" that occurs between the access point and client machine.
WEP has been proven to be extremely easy to crack, in fact, this author was able to crack a network that he had "protected" using WEP with a 40 bit key in approximately 10 minutes. Where possible, WEP should be avoided in favour of stronger forms of authentication and encryption.
To find out more about WEP, follow this link.

WPA2 - Wi-Fi Protected Access

WPA was created after the flaws in WEP were uncovered - it implements most of the IEEE 802.11i standard - it was originally intended as an temporary solution while the standard was still in it's draft stages. A second version, WPA2, implements the entire standard, but does not work with some older network cards. Networks that implement either of these benefit from much stronger client authentication and data encryption than those that rely on WEP. To authenticate to the network, WPA/WPA2 provide a myriad of Extensible Authentication Protocol (EAP) options, which allows authentications to be passed off to a dedicated machine - each user of the network can use a different set of credentials. However, this is not practical for the home, or for small businesses, so another method of authentication is available - the Pre-Shared Key (PSK). This just requires that an arbitrary, pre-determined, key be input to each station on the network, which is then used to authenticate when joining the wireless LAN. When using this mode of authentication, it is important that the key used should be composed of at least 20 characters, and consisting of lower and upper case characters, numbers and symbols (e.g. !,=,+) - otherwise, the key is vulnerable to discovery by brute-force attacks.



It is possible to implement any combination of these methods to protect your wireless network; apart from WEP and WPA, which are mutually exclusive. However, as mentioned previously, MAC filtering and disabling the SSID broadcast are extremely easy to bypass, and should only be used in tandem with WEP or WPA, if used at all. An optimal configuration for a consumer would be to simply change your SSID from it's default value and implement some form of WPA-PSK; ideally WPA2-PSK, as long as all your hardware supports it.

If you possess both the knowledge and resources, it is highly recommended you opt for the WPA2-Enterprise solution using the EAP-TLS method of authentication. This is the most secure of all the EAP methods, using SSL certificates to authenticate the client machines to the network, but also the server to the client; preventing man-in-the-middle style attacks where a malicious user sets up a rogue AP. This method requires the most configuration, as a certificate authority must be use to issue certificates for all the devices that wish to use the wireless network.
The other EAP methods are slightly easier to configure, however, it's important to note that if you intend to use MSCHAP as the inner authentication method, you will need Active Directory as your directory server. This is because the passwords supplied by an MSCHAP client are an NTLM hash, which can only be interpreted by Microsoft's directory service.

Wireless security is an important subject, however, it's not one that's well understood by most end-users. Hopefully this article will have helped explain the options available to people. Feel free to contact the author if there are any questions you may have regarding the subject.