Category Archives: Security

aka infosec

Firefox 55

Besides fixing twenty-nine security vulnerabilities, Firefox 55 adds support for the virtual reality technology WebVR, some new performance-related settings, and improvements to address bar functionality. The sidebar can now be on the right side of the browser, instead of only on the left. The Print Preview function now includes options for simplifying what’s printed. Starting Firefox with multiple tabs is now much faster. The Flash plugin is now ‘click to activate’ and only works with regular web and secure web URLs.

The default installation process has been modified, to simplify and ‘streamline’ installation for most users. Traditional, full installers are still available. The somewhat-less-likely-to-crash 64-bit version of Firefox is now installed by default on 64-bit systems with at least 2 GB of RAM.

Mozilla steadfastly refuses to mention version numbers in Firefox release announcements (including the one for Firefox 55), or to announce all new versions. Their rationale seems to be that the information exists somewhere, therefore they have done their job. Combined with the unpredictability of Firefox’s internal update mechanism, this is an ongoing frustration for some users (possibly only me).

On that subject, I’m still waiting for my installation of Firefox to notice that a new version is available. Firefox 55 includes changes to the browser’s built-in update process, but it’s not clear whether those changes will actually improve things. From the release notes: “Modernized application update UI to be less intrusive and more aligned with the rest of the browser. Only users who have not restarted their browser 8 days after downloading an update or users who opted out of automatic updates will see this change.

Update 2017Aug13: According to denizens of Mozilla’s official #firefox IRC channel, the Firefox update servers have been disabled because of some problems with Firefox 55. Of course, Firefox will continue to tell you that “Firefox is up to date”, which can mean several different things. There’s no word on when the update servers will be back online, or what the problems are, but a search of the bug list for Firefox shows a likely candidate: Tabs are all restored as blank frequently after restart of [sic] applying Firefox 55 update. Apparently after upgrading to Firefox 55, some users are having problem restoring tabs, and in some cases, profile information is lost. Recommendation: don’t jump the gun and install Firefox 55 manually. Wait for the next version, which will likely be 55.0.1 or 55.0.2.

Update 2017Aug15: A new post on the Mozilla blog (64-bit Firefox is the new default on 64-bit Windows) confirms that 64-bit Firefox is now the default for 64-bit Windows systems, and that the 64-bit version is much more stable than its 32-bit equivalent. It goes on to say that to get the 64-bit version, you can either download and install it manually, or “You can wait. We intend to migrate the remaining 64-bit Windows users to a 64-bit version of Firefox with a future release.” No word on just how long we’ll have to wait.

Update 2017Aug17: Today, my install of Firefox started showing 55.0.2 as the latest version on its Help > About dialog. I went ahead and let it update itself, and now I’m running the 32 bit version of 55.0.2. According to the release notes, Firefox 55.0.1 fixes the bug in the tab restoration process that was introduced in 55.0. Firefox 55.0.2 fixes a problem with profiles that was introduced in 55.0.

Patch Tuesday for August 2017

It’s once again time for the monthly headache otherwise known as Patch Tuesday.

As you’re no doubt aware from my previous whining, Microsoft no longer publishes a bulletin for each update, and finding useful information in the Security Update Guide is awkward at best. It feels like Microsoft is trying to get everyone to just give up and enable auto-update. Of course with Windows 10 you no longer have a choice: you get updates when Microsoft wants you to have them. Which is one of the reasons I don’t use that particular O/S.

From my analysis of the Security Update Guide‘s entries for August 2017, it appears that we have thirty-nine updates, addressing fifty-three vulnerabilities in Internet Explorer, Edge, Windows, SharePoint, Adobe Flash Player, and SQL Server. Eighteen of the updates are flagged as Critical. Time to fire up Windows Update on all your Windows 8.1 and Windows 7 computers.

Adobe released updates for Flash and Reader today. The Reader update (Reader DC/Continuous: 2017.012.20093; Reader 2017: 2017.011.30059; Reader DC/Classic: 2015.006.30352) addresses sixty-seven vulnerabilities. The Flash update (version addresses two vulnerabilities. Anyone still using Flash or Reader, especially as web browser plugins, should install the new versions as soon as possible.

Patch Tuesday for June 2017

In a somewhat surprising move, Microsoft is releasing more updates for Windows XP today. To be clear, Microsoft had already created these updates for corporate (paying) clients. All they’re doing is making those updates available to the rest of us. While the updates are welcome to those still running Windows XP, one wonders how paying customers feel about it.

Here’s Microsoft’s explanation: “In reviewing the updates for this month, some vulnerabilities were identified that pose elevated risk of cyber attacks by government organizations, sometimes referred to as nation-state actors or other copycat organizations.” What that probably means is that Microsoft believes — along with the rest of us — that last month’s WannaCry threat was only the beginning of the havoc coming our way in the wake of The Shadow Brokers‘ leaks. The bit about ‘government organizations’ is presumably to get people to take notice.

That announcement is also somewhat misleading, in that it talks about ‘enabling Windows Update’ in supported versions of Windows, when in fact they’re referring to automatic updates. Further, automatic updates in Windows 10 cannot be disabled.

From the June 2017 security update release announcement: “we recommend those on older platforms, such as Windows XP, prioritize downloading and applying these critical updates, which can be found in the Download Center (or alternatively in the Update Catalog).”

The Download Center site doesn’t work particularly well in Internet Explorer 8, the version my poor old Windows XP Virtual Machine is stuck with. The page does show a prompt to try Edge, which is not particularly helpful as Edge won’t run on Windows XP. Okay, how about the Update Catalog? All I get there is ‘The website has encountered a problem’.

The Download Center works a lot better in Chrome, but clicking the Microsoft Update link only tells me that I have to use Internet Explorer for that. Entering the Windows category just invites me to visit the Update Catalog. That site also seems to work with Chrome, but it’s basically just a search form. What do I search for to get the available updates for Windows XP? Searching for ‘Windows XP’ produces 870 results. Sorting the list by date shows the most recent update was in 2014.

A post on the Technet site provides additional information about the vulnerabilities: Microsoft Security Advisory 4025685 – Guidance related to June 2017 security update release. Fifteen vulnerabilities are addressed, almost all of which are flagged as Critical. But there’s nothing on that page about how to install the updates on Windows XP.

The general guidance page links to additional guidance pages, one for supported versions, and another for older versions of Windows.

The page for older versions starts by pointing out that “All security updates Microsoft provides do not check Windows Genuine Advantage status.” That means even people running bootleg copies of Windows XP can install these updates. It goes on to say “For customers on these older platforms, the following table provides information to manually download applicable security updates.”

So installing these updates on Windows XP involves manually downloading them with the links provided on the Microsoft security advisory 4025685: Guidance for older platforms page. Some of the links go to the Update Catalog, and some involve additional navigation, but I was able to use Chrome to download and install all twelve of the updates linked from the guidance page on my WinXP VM. Not exactly convenient, and certainly not fast, but it did work.

Microsoft security advisory 4025685: Guidance for supported platforms includes a summary of the month’s updates for supported software. Numerous vulnerabilities are addressed, affecting the usual software: Windows, Office, Internet Explorer, Edge, Silverlight, Skype and Flash. Extracting the complete details from the Security Update Guide is still annoyingly awkward, and the release notes are rather light on details.

Chrome 59.0.3071.86

With thirty security fixes in Chrome 59.0.3071.86, I would expect Google to emphasize the need for users to update as soon as possible. Instead, the release announcement says “This will roll out over the coming days/weeks.” Presumably Google feels that the fixed security issues are too obscure to represent any imminent threat.

To be fair, personal experience has shown that Chrome is great at detecting updates, often very soon after they become available. Visiting the About page is usually enough to trigger an update. Click the three-vertical-dots menu button, then choose Help > About.

If you have several hours to kill, you might want to check out the change log for Chrome 59.0.3071.86, which by my count contains 10,911 entries.

Google improves GMail security

I’ve tried other search services, but I always end up back at Google, because the search results are consistently better. Google does collect information about its users, and uses that information to target advertising. Google also looks at the content of GMail messages for the same reason. If that bothers you, there are ways to prevent it, or you can stop using Google’s products and services.

That said, in all my years of using Google’s services, I’ve never encountered anything that made me want to stop using them. Google does occasionally annoy me by dropping services like Reader, and Google’s advertising is ridiculously overpriced, but on balance the company provides far more benefit than any potential harm.

For example, Google spends enormous amounts of time and resources on making the web safer for everyone. Much of that effort goes unheralded, but occasionally we catch glimpses in the form of blog posts, like this one, describing recent improvements to GMail security. Compare that with Yahoo’s recent track record, which clearly shows that user security and privacy are not a priority at that company.

Timeline: NSA hacking tool to WannaCry

A recent Washington Post article is helping to answer some questions about Microsoft’s actions in recent months. Here’s a timeline of events:

2012 (or possibly earlier): The NSA identifies a vulnerability in Windows that affects all existing versions of the operating system, and has the potential to allow almost unfettered access to affected systems. A software tool — an exploit — is developed either for, or by, the NSA. The tool is called EternalBlue. People at the NSA worry about the potential damage if the tool or the vulnerability became public knowledge. They decide not to tell anyone, not even Windows’ developer, Microsoft.

EternalBlue finds its way into the toolkit of an elite hacking outfit known as Equation Group. Although it’s difficult to know for certain, this group is generally assumed to be operating under the auspices of the NSA. Equation Group may work for the NSA as contractors, or they may simply be NSA employees. Regardless, the group’s actions seem to align with those of the NSA: their targets are generally in places like Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali.

Early to mid-2016: A hacking group calling themselves The Shadow Brokers somehow gains access to NSA systems or data, and obtains copies of various NSA documents and tools. Among those tools is EternalBlue.

August, 2016: The Shadow Brokers begin publishing their NSA haul on public services like Tumblr.

January 7, 2017: The Shadow Brokers begin selling tools that are related to EternalBlue.

Late January to early February 2017: The NSA finally tells Microsoft about the vulnerability exploited by EternalBlue. We don’t know exactly when this happened, but it clearly happened. The NSA was Microsoft’s source for this vulnerability.

February 14, 2017: Microsoft announces that February’s Patch Tuesday updates will be postponed. Their explanation is vague: “we discovered a last minute issue that could impact some customers.

Late February 2017: The Windows SMB vulnerability exploited by EternalBlue is identified publicly as CVE-2017-0144.

March 14, 2017: March’s Patch Tuesday updates from Microsoft include a fix for CVE-2017-0144, MS17-010. The update is flagged as Critical and described as Security Update for Microsoft Windows SMB Server (4013389). Nothing in Microsoft’s output on March 14 calls special attention to this update.

April 14, 2017: The Shadow Brokers release 300 megabytes of NSA material on Github, including EternalBlue.

May 12, 2017: WannaCry ransomware infection wave begins. The malware uses EternalBlue to infect vulnerable computers, mostly Windows 7 PCs in Europe and Asia. Infected computers clearly had not been updated since before March 14, and were therefore vulnerable to EternalBlue.

It’s now clear that the NSA is the real problem here. They had several opportunities to do the right thing, and failed every time, until it was too late. The NSA’s last chance to look at all good in this matter was after the vulnerability was made public, when they should have made the danger clear to the public, or at least to Microsoft. Because, after all, they knew exactly how useful EternalBlue would be in the hands of… just about anyone with bad intent.

Everyone involved in this mess acted foolishly. But whereas we’ve grown accustomed to corporations caring less about people than about money, government institutions — no matter how necessarily secretive — should not be allowed to get away with what the NSA has done. Especially when you consider that this is just the tip of the iceberg. For every WannaCry, there are probably a thousand other threats lurking out there, all thanks to the clowns at the NSA.

Ars Technica’s analysis.

Techdirt’s analysis.

WannaCry update

According to Kaspersky Labs, almost all of the computers infected with WannaCry (WCry, WannaCrypt) were running Windows 7. A small percentage (less than 1%) were running Windows XP.

Microsoft released updates in March 2017 which — if installed — protect Windows 7 computers from WannaCry infections. So all those Windows 7 WannaCry infections were only possible because users failed to install updates. This is a good argument for either enabling automatic updates, or being extremely diligent about installing updates as soon as they become available.

A researcher at Quarkslab discovered a method for decrypting files encrypted with WannaCry, although it only works on Windows XP, and only if the computer has not been restarted since the files were encrypted.

Building on the discoveries of Quarkslab, researchers at Comae Technologies and elsewhere developed a tool that can decrypt files encrypted by WannaCry on Windows 7 as well as XP. The new tool — dubbed wanakiwi by its developers — uses the same technique as its predecessor and has the same limitation: it doesn’t work if the infected computer has been restarted since encryption occurred.

The Register points out that while the NSA was hoarding exploits, Microsoft was doing something similar with patches. Microsoft is in fact still creating security updates for Windows XP and other ‘unsupported’ software; they just don’t normally make those updates available to the general public. Instead, they are only provided to enterprise customers, which pay substantial fees for the privilege. When Microsoft released the Windows XP patch in response to the WannaCry threat, the patch was already developed; all Microsoft had to do was make it available to the general public. Sure, developing updates costs money, and Microsoft wants to recover those costs somehow, but it seems clear that we would all be better off if they made all updates available to everyone.

Bruce Schneier provides a useful overview of WannaCry, and how best to protect yourself. From the article: “Criminals go where the money is, and cybercriminals are no exception. And right now, the money is in ransomware.”

Update 2017May21: Analysts have confirmed that WannaCry’s initial infections were accomplished by scanning the Internet for computers with open Server Message Block ports, then using the EternalBlue SMB exploit to install the ransomware. Once installed on any computer, WannaCry spread to other vulnerable computers on the same local network (LAN). Earlier assumptions about WannaCry using spam and phishing emails to spread were not accurate.