Disable Java in your browsers now

Java is a computer language for getting things done. If you have Java installed on your computer, you have enabled your computer to “talk” this language, which is a good thing.

Problem is, nowadays Java is used primarily to remotely take control of your computer by criminals and use your resources and information to make money. This is a bad thing.

Therefore, I will echo the advice of most computer security experts and suggest that you disable Java for your browsers (Firefox, Internet Explorer, Chrome etc) now.

Windows users are the ones most at risk – there are known exploit kits out there that actively exploit Java to take control of your computer. First, check if you have Java installed on your computer – is there a “Java” icon in Windows’ Control Panel? If not, you have nothing to worry about as you don’t have Java on your computer.

If, as most people, you do have Java installed, don’t worry, it’s easy to secure it: Two steps:

  1. Update your installation of Java to the latest version released by Oracle here: http://java.com/en/download/manual.jsp – After downloading and installing it, you will have the latest and more secure Java for your computer to use.
  2. Disable the use of Java in your browsers, by going to Control Panel, then “Java”, and then in the “Security” tab un-ticking the box before “Enable Java content in the browser“.Disabling Java for browsers

That’s all you need to do.

Note: GNU/Linux and Mac users, you are not out of danger – the same vulnerability can be used to exploit your systems too, so it’s recommended that you disable Java in your browsers as well. See my advice from 2011 about “How much Java do you need?” and Brian Krebs’ recent FAQ for more.

Loz Kaye

Reblogged from Hiyashi's Blog:

Too often the discourse around media convergence is about utilising cutting-edge, networked computing technologies to deliver, produce and consume media content. We are constantly being reminded that we will be prosuming media on connected multiple platforms, sharing and remixing content and information, interacting with authors and celebrities on the social web, being recommended / directed / given access to quality media content that meets our tastes and preferences.

Read more… 805 more words

Government requests for your personal data

The latest Google Transparency report makes a sobering read. It documents how governments are ordering Google to hand over user data (i.e. everything that Google knows about you, which is a lot*)

For per-country statistics for User Data Requests click here. Sample to pique your interest:

US authorities asked for the personal data of 16,281 users/accounts in the first six months of 2012. Google will not say exactly how many they handed over, but 90% is implied to be a reasonable estimate.

Citizens of other countries, please refer to the report before celebrating too much.

* Some things Google knows about you, and will continue knowing for the foreseeable future (remember, computers don’t forget what you clicked on 6 years ago):

  • Every email you have ever sent.
  • Every email you have ever received.
  • Every link you have ever clicked in an email
  • Everything you have typed in the Google “chat” box, and everything your chatting partner said.
  • Everything you have searched for on the web, while being logged in to your Google account.
  • Google maps
  • Picasa & Google albums
  • …and much more, even about your connections’ connections, to a surprising degree – check out your Google profile (note: you have to be logged in to Google for this to work) for more.

Some excerpts from Evgeny Morozov’s “The Net Delusion”

Evgeny Morozov’s “The Net Delusion: How not to liberate the world” is a refreshing note of realism amongst the cheerleading majority that promise us that “the Internet” or “information” will somehow magically transform our lives for the better.

Here are a few excerpts from the book which I found particularly pertinent:

Chapter “Orwell’s favourite lolcat” (Morozov’s book chapters are too funny and to the point to not mention)

On the “mash-up” of attitudes towards “freedom” between West and Rest (here personified in China):

[...]as the writer Naomi Klein puts it, “China is becoming more like [the West] in very visible ways (Starbucks, Hooters, cellphones that are cooler than ours), and [the West is] becoming more like China in less visible ones (torture, warrantless wiretapping, indefinite detention, though not nearly on the Chinese scale).”

On the modus operandi of modern dictatorships:

It seems fairly noncontroversial that most modern dictators would prefer a Huxleyan world to an Orwellian one, if only because controlling people through entertainment is cheaper and doesn’t involve as much brutality. When the extremely restrictive Burmese government permits – and sometimes even funds – hip-hop performances around the country, it’s not 1984 that inspires them.

Chapter “Censors and Sensibilities”
On how most citizens of “The Rest” do not necessarily share the ill-defined dreams of “democracy” as portrayed in the West:

Most citizens of modern-day Russia or China do not go to bed reading Darkness at Noon only to wake up to the jingle of Voice of America or Radio Free Europe; chances are that much like their Western counterparts, they, too, wake up to the same annoying Lady Gaga song blasting from their iPhones. While they might have a strong preference for democracy, many of them take it to mean orderly justice rather than the presence of free elections and other institutions that are commonly associated with the Western model of liberal democracy. For many of them, being able to vote is not as valuable as being able to receive education or medical care without having to bribe a dozen greedy officials. Furthermore, citizens of authoritarian do not necessarily perceive their undemocratically installed governments to be illegitimate, for legitimacy can be derived from things other than elections; jingoist nationalism (China), fear of a foreign invasion (Iran), fast rates of economic development (Russia), low corruption (Belarus), and efficiency of government services (Singapore) have all been successfully co-opted for these purposes.

Chapter “Hugo Chavez Would Like to Welcome You to the Spinternet”

On enforced jingoist nationalism in China:

In 2009 millions of customers of the state-controlled China Mobile, who perhaps were not feeling patriotic enough on the country’s National Day, woke up to discover that the company replaces their usual ringback tone with a patriotic tune sang by the popular actor Jackie Chan and a female actress.[...] These days even the website of China’s Defense Ministry has a section with music downloads; one can enjoy jingoistic music all one wants.”

On propaganda reusing the West’s “liberating” technologies:

The use of text messaging for propaganda purposes – known as “red-texting” – reveals another creative streak among China’s propaganda virtuosos. The practice may have grown out of a competition organized by one of China’s mobile phone operators to compose the most eloquent Party-admiring text message. Fast forward a few years, and senior telecom officials in Beijing are already busily attending “red-texting” symposia.
“I really like these words of Chairman Mao: ‘The world is ours, we should unite for achievements. Responsibility and seriousness can conquer the world and the Chinese Communist Party members represent these qualities.’ These words are incisive and inspirational.” This is a text message that thirteen million mobile phone users in the Chinese city of Chongqing received one day in April 2009. Sent by Bo Xilai, the aggressive secretary of the city’s Communist Party who is speculated to have strong ambitions for a future in national politics, the messages were then forwarded another sixteen millions times. Not so bad for an odd quote from a long-dead Communist dictator.

Chapter “Why the KGB wants you to join Facebook”

On why databases are better (at their job) than Stasi officers:

The Lives of Others, a 2006 Oscar-winning German drama, with its sharp portrayal of pervasive surveillance activities of the Stasi, GDR’s secret police, helps to put things into perspective. Focusing on the meticulous work of a dedicated Stasi officer who has been assigned to snoop on the bugged apartment of a brave East German dissident, the film reveals just how costly surveillance used to be. Recording tape had to be bought, stored and processed; bugs had to be installed one by one; Stasi officers had to spend days and nights on end glued to their headphones, waiting for their subjects to launch into an antigovernment tirade or inadvertently disclose other members of their network. And this line of work also took a heavy psychological toll on its practitioners: the Stasi anti-hero of the film, living alone and given to bouts of depression, patronizes prostitutes – apparently at the expense of his understanding employer.
As the Soviet Union began crumbling, a high-ranking KGB officer came forward with a detailed description of how much effort it took to bug an apartment:

“Three teams are usually required for that purpose: One team monitors the place where that citizen works; a second team monitors the place where the spouse works. Meanwhile, a third team enters the apartment and establishes observation posts one floor above and one floor below the apartment. About six people enter the apartment wearing soft shoes; they move aside a bookcase, for example, cut a square opening in the wallpaper, drill a hole in the wall, place the bug inside, and glue the wallpaper back. The artist on the team airbrushes the spot so carefully that one cannot notice any tampering. The furniture is replaced, the door is closed, and the wiretappers leave.”

Given such elaborate preparations, the secret police had to discriminate and go only for well-known high-priority targets. The KGB may have been the most important institution of the Soviet regime, but its resources were still finite; they simply could not afford to bug everyone who looked suspicious. Despite such tremendous efforts, surveillance did not always work as planned. Even the toughest security offices – like the protagonist of the German film – had their soft spots and often developed feelings of empathy for those under surveillance, sometimes going so far as to tip them off about upcoming searches and arrests. The human factor could thus ruin months of diligent surveillance work.
The shift of communications into the digital realm solves many of the problems that plagued surveillance in the analog age. Digital surveillance is much cheaper: Storage space is infinite, equipment retails for next to nothing, and digital technology allows doing more with less. Moreover, there is no need to read every single word in an email to identify its most interesting parts; one can simply search for certain keywords – “democracy”, “opposition”, “human rights”, or simply the names of the country’s opposition leaders – and focus only on particular segments of the conversation. Digital bugs are also easier to conceal. While seasoned dissidents knew they constantly had to search their own apartments looking for the bug or, failing that, at least tighten their lips, knowing that the secret police was listening, this is rarely an option with digital surveillance. How do you know that someone else is reading your email?

On wholesale surveillance using cameras and face recognition software:

[...]the Chinese government keeps installing video cameras in its most troubling cities. Not only do such cameras remind passersby about the panopticon they inhabit, they also supply the secret police with useful clues[...]. Such revolution in video surveillance did not happen without some involvement from Western partners.
Researchers at the University of California at Los Angeles, funded in part by the Chinese government, have managed to build surveillance software that can automatically annotate and comment on what it sees, generating text files that can later be searched by humans, obviating the need to watch hours of video footage in search of one particular frame. (To make that possible, the researchers had to recruit twenty graduates of local art colleges in China to annotate and classify a library of more than two million images.) Such automation systems help surveillance to achieve the much needed scale, for as long as the content produced by surveillance cameras can be indexed and searched, one can continue installing new surveillance cameras.
[...]
The face-recognition industry is so lucrative that even giants like Google can’t resist getting into the game, feeling the growing pressure from saller players like Face.com, a popular tool that allows users to find and automatically annotate unique faces that apepar throughout their photo collections. In 2009 Face.com launched a Facebook application that first asks users to identify a Facebook friend of theirs ina photo and then proceeds to search the social networking site for other pictures in which that friend appears. By eary 2010, the company boasted of scanning 9 billion pictures and identifying 52 million individuals. This is the kind of productivity that would make the KGB envious.

(ed: Note that automatic face recognition technology is now a standard feature of Facebook, as well as popular products like Google’s Picasa and Google Web albums)

On government “open-source” surveillance via social sites like Facebook:

One gloomy day in 2009, the young Belarusian activist Pavel Lyashkovich learned the dangers of excessive social networking the hard way. A freshman at a public university in Minsk, he was unexpectedly called to the dean’s office, where he was met by two suspicious-looking men who told him they worked for the KGB, one public organization that the Belarusian authorities decided not to rename even after the fall of communism (they’re a brand-conscious bunch).
The KGB officers asked Pavel all sorts of detailed questions about his trips to Poland and Ukraine as well as his membership in various antigovernment movements.
Their extensive knowledge of the internal affairs of the Belarusian opposition – and particularly of Pavel’s own involvement in them, something he didn’t believe to be common knowledge – greatly surprised him. But then it all became clear, when the KGB duo loaded his page on vkontakte.ru, a popular Russian social networking site, pointing out that he was listed as a “friend” by a number of well-known oppositional activists. Shortly thereafter, the visitors offered Lyashkovich to sign an informal “cooperation agreement” with their organization. He declined – which may eventually cost him dearly, as many students sympathetic to the opposition and unwilling to cooperate with authorities have been expelled from universities in the past. We will never know how many other new suspects the KGB added to its list by browsing Lyashkovich’s profile.

On using “technology” as the proposed solution to anything, denying our responsibility for real decisions and action:

Since technology, like gas, will fill any conceptual space provided, Leo Marx, professor emeritus at the Massachusetts Institute of Technology, describes it as a “hazardous concept” that may “stifle and obfuscate analytic thinking”. He notes, “Because of its peculiar susceptibility to reification, to being endowed with the magical power of an autonomous entity, technology is a major contributant to that gathering sense… of political impotence. The popularity of the belief that technology is the primary force shaping the postmodern world is a measure of our.. neglect of moral and political standards, in making decisive choices about the direction of society.”

Highly recommended to help us re-focus on the things that matter and stop waving around the “technology, technology, technology!” magic wand, hoping that it fixes the world.

Private online communications part 2 – text chatting

When you use Google Talk to chat with your friends, Google records everything you say. Facebook does the same. Others probably do the same. The only way to ensure you are only communicating with your friends, without your every word being recorded and kept by corporations or governments, is to use OTR. OTR stands for Off The Record. It’s a genius protocol that gives you many desirable properties, like

  • Encryption
  • Authentication
  • Deniability
  • Perfect forward secrecy

To understand the value of each of the above properties, please check out the OTR website at http://www.cypherpunks.ca/otr/

Here’s a quick video tutorial on how to use OTR with Jitsi, using your Google account. You can do exactly the same with your Facebook, Yahoo!, MSN, ICQ, AIM, XMPP or Jabber account!

Private online communication – a matter of decency

I feel there is something inherently indecent about having a private conversation, while someone else is listening in. With modern Internet communication, that “someone else” is usually a corporation or a government.

It’s not the-STASI-is-listening-so-we-better-behave feeling that bugs me. It’s more the “I am a decent human being and I have the right to share my thoughts with my loved ones, and just with them!” feeling.

In that spirit, I encourage as many people as possible to use tools like Jitsi. Not allowing others to snoop on your private life is a matter of human decency, and you deserve it.

Get Jitsi:

Use Jitsi for private voice calls that do not allow eavesdropping:

Anyone with a Google account can make encrypted, private voice calls by using Jitsi as shown above. If you don’t have a Google account, you use any of the (many) other services Jitsi supports (MSN, Yahoo!, AIM, ICQ, SIP, XMPP, but not Facebook – they don’t support secure calls).

Spread the word!

Regarding the CISSP

Reblogged from - ex[b10w]sive security -:

There's been quite a lot of conversation on Twitter by the InfoSec community about the CISSP. Most of the hubbub has been generated by the Skytalk given by Timmay and a little help from Jericho at attrition.org. I was one of the fortunate folks to have a (nearly) front-row seat for this talk and I'll be the first to say that I agree 100% with what was said.

Read more… 984 more words

Good analysis of the "Why you should not get a CISSP" Twitter storm kicked up by the recent DEFCON talk of the same title.