2024-03-01

Security (b)log: Updates

 

Image from Pixabay

Two weeks ago I promised here, as an incentive to myself, to give my smart equipment some attention. I was to investigate if they needed a software update and do so if necessary. This week I will report on my search. I also mention company and brand names; not as an advertisement or to criticize them, but because it's nice in case you have those things yourself.

My search started at the front door: at the modem/router. That is from my internet provider Ziggo and is called Connectbox Giga (a rebranded Arris TG3492). If you log in to the modem's management page, you can find out which software version it is running. It just doesn't say from when that software is, or it must be hidden in the very long version number (AR01.04.092.09_ 071423 _7248.SIP.10.LG.X2). I asked the Ziggo community how you can find out which is the current version. They say that this is the correct one, but I’m afraid that if you want to check it yourself you will probably have to get that information from the manufacturer.

Then the LG dryer. The accompanying app displays the version of four pieces of software under device information, and says: “Software is up to date”. Apparently the app checks this online itself. I just can't tell from when those updates are. I mean: if that software has never been updated after it was released - years ago - then my software is indeed up to date, but there is probably quite a bit of room for improvement in the meantime. And perhaps such a necessary improvement was related to the security of the device. But that remains guesswork. I want to act as a normal user here and will therefore not go all the way as to find out exactly from when version SAA39935009.0000B455 of 'Firmware 0' is. They could easily add that to the already provided information.

The Bosch dishwasher lets you choose between automatically downloading software (including installation, I hope) and confirming the individual steps (download/installation). It also shows a version number somewhere, but it is not clear whether this concerns software or the device itself, and from when that version is. There is also something that I have not seen before on a device: the validity period of a certificate. You know certificates from websites, from the lock that indicates that the site is secured, and from the s in https. I am positively surprised that this device apparently uses a certificate for communications security.

Next candidate: Philips Hue smart lamps. The accompanying app says: “Everything is updated”. The automatic updates option is turned on and you can even choose the time at which the updates should be performed. Furthermore, each device has a version number, but here too it is not clear from when that version is.

The stereo system also has a few components that are connected to the WiFi network: the Yamaha receiver and, since last week, two wireless surround speakers from the same brand. The latter's installation manual states that you must ensure that all components have the latest firmware version. During the installation of the speakers, the app indeed indicated that a new version had to be installed, which then happened. The app says about the receiver: “Firmware is up to date”. Unfortunately, again without a date, only - in a different place in the app - a version number.

Finally, there are the solar panels. We have two different installations: the first works via the SolarEdge app, the second uses Enlighten/Enphase. SolarEdge does not provide a version number, but – yes, finally! – the date of the last update. That was February 18 of this year, so very recently. It also means that the updates are done automatically, because I didn't do anything. Enlighten provides information about two types of devices. The gateway, which communicates with me, shows a firmware version number and a date when it was last connected to the Enphase cloud. It is not clear whether updates are checked. The micro inverters (each panel has one, rather than a central inverter) all have two firmware version numbers and a communication date, and again it is not clear whether they are related.

Conclusion of this operation: it seems as if everything is fine, but it is not certain, except for the SolarEdge panels and (to a slightly lesser degree of certainty) the modem. Manufacturers still have some work to do to provide consumers with real information and to take away the bad feeling that I am being lulled to sleep with the meaningless term 'up to date'.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2024-02-16

Pension

 

Image from Pixabay

Despite the fact that, all being well and regulations unchanged, I should be enjoying my retirementa for already more than six months in ten years' time, I still feel so young that I unemotionally archive mail from the pension fund. There is a vague realization that I should be more interested in my financial future, but at the same time there’s also resignation; On the one hand, based on the general feeling that everything has been well arranged for me, and on the other hand, because it is probably too late to take additional measures, should I want to do so.

A while ago I spoke with a colleague about the involvement of non-peers in the subject of information security. Or rather: about the lack of involvement. He made a striking comparison (thanks Hugo!): would you listen with interest to a pension advisor, or would you rather think: here's my money, do the right things with it?

Oh, there you caught me. I've never talked to a pension advisor before. From the age of 25, pension contributions are deducted from my salary and the pension fund regularly lets me know how I am doing. If I retire at the normal age, I will receive this amount of money every month, and if I die, my surviving relatives will also receive something; that kind of information. I take a quick glance at it and at most think: “Well well!” and proceed to the order of the day. So I'm quite literally saying: here's my money, do the right things with it.

Do pension advisors ever complain that people show far too little interest in their pensions? That it would be in their own interest to look into it and take the right measures? And that few people have the sense to worry about this at a young age? If I had to arrange a supplement to my pension now, it would probably be unaffordable. However, if you start in your early years, you can spread your investment over many years.

In any case, information security professionals regularly complain that people show too little interest in their security. They live in the vague hope that everything will be more or less well arranged. The internet connection at home costs money, so the provider must have supplied a secure modem, right? And that WiFi connection of your dishwasher, dryer and air conditioning from a renowned brand, isn’t that just fine? The apps on your phone and the websites you visit all have a privacy policy, so you don't have to worry about that, do you? These are all assumptions that appease our conscience, if we think of them at all.

Reality is more stubborn. A device is relatively safe if it has had the latest update in which the manufacturer has fixed the known errors. If you do not have that update, your device carries vulnerabilities that can be exploited by attackers. You can easily ensure that you always have the latest updates on your laptop and phone by having everything happen automatically. Of course, if a program or app asks you to do something to effect the update, you still have to actually do it.

There are also people at work who think that the people from the security team will take care of things. That is true to a certain extent: we write down what you should do and not do to keep things safe. We call that policies, standards, regulations – whatever the name. After that, however, it is up to those who are responsible for their part of the equation to also take responsibility for the information security aspect (and privacy, and continuity). And so they have to think at an early stage about what all these regulations mean for their field of work and actually do something with them.

I know, this is easier said than done. My devices at home also feel neglected. It is quite a job to do something about it, which makes it easy to hide behind the argument “not right now, it takes too much time”. But sometimes you just have to make that time. You know what? I have next week off, but we're not going away. I hereby promise our smart devices that I will check whether there is anything to update (which remains to be seen) and if so, that I will do so.

It would be so much easier if many more devices did an automatic update. Then you don't have to figure out where to get your updates from and how to install them. I think many non-ICT professionals shy away from the latter in particular. Hopefully manufacturers will do more to help us with this. And the European Cyber Resilience Act will force them into this. We want security by design: take all this into account from the start and pay attention to it throughout the entire lifespan of the product.

Still wanted: pension by design …

There will be no fresh Security (b)log next week.

 

And in the big bad world...

2024-02-09

Kafka upside down

 

Image from Pixabay

Last summer I visited countries where I do not speak the language. In some countries I couldn't even read the writing. In one of those countries I bought a backpack with a card attached to it. “ATTENTION!” it said on the front. But the back was printed with characters that I wasn’t able to interpret.

Thanks to the wonderful technology of Google Lens, I was able to find out what was so urgently requiring my attention. It says that the backpack may become discolored, that I should avoid washing and ironing, that I should use “accessories such as closures, hooks, buttons, metal fittings, belt straps, buckles and rings” properly or they may break, and finally, that the product does not protect the contents in the event of a fall or impact; the manufacturer is especially concerned about my precision instruments, precious metals and fragile objects.

A couple of months ago, I asked you in the Security (b)log whether you know Franz Kafka's novel Der Prozess (The Trial). I assume you've read it by now. And then you may recognize a Kafkaesque trait in the text of that backpack card: you have to use the backpack accessories correctly, but it does not say what the correct way is. For me,  backpacks leave me sometimes wonder what that strap or loop is for, let alone whether I know how to use the thing properly. And it also strikes me as rather vague that I should 'avoid' something – what if I do it anyway? Admittedly, I wouldn't have thought of ironing a backpack, but my previous backpack regularly ended up in the washing machine (and it survived).

I'm not going to lecture you further about Kafka now. No, I'm going to turn Kafka upside down. In his novel you have to adhere to rules that you do not know and if you break those rules, you are punished. Kafka upside down is when you know the rules all too well and at the same time you know that if you stick to them, sooner or later something will happen that is very detrimental to you. What would you do if a law were introduced that required you to drive a car at a minimum speed of 100 km/h (62 mph) in built-up areas (and 50 km/h in a residential area)? Are you going to stick to this, even though you know for sure that in the best case scenario you will end up in the hospital, or will you accept,  for the sake of self-preservation, that you will be fined?

Earlier this week, intelligence services in the Netherlands revealed that Chinese state hackers hacked into a Defense network. They were able to enter through a known (!) vulnerability in American-made security equipment. Continuing to use something with a known vulnerability is like knowing that the left headlight of your car is not working, but still driving in the dark - because replacing the light yourself is no longer possible in many modern cars, the garage is already closed and you really have to go somewhere. And you continue to use that network equipment the same way, because, well, you need that network anyway and you can't easily replace it. Regardless of the question of whether another product is completely safe.

I don't know how they figured out that China is the culprit; attribution of cyber attacks is a difficult matter. Anyway, the report states that the intelligence services determined “with high confidence ” that it must have been China – spy talk for “we actually know for sure”. And it is not the first time that the West has pointed the finger at China in such cases. So we are more or less certain that China is spying on us.

If a Dutch government institution wants to purchase a service or product, it must follow the Public Procurement Act 2012: if the value of the contract exceeds a certain amount, a European tender must be carried out. So you cannot just go to a supplier and place your order. You must describe in a thick document what you need and what requirements you set for it. You cannot “target” that document to a specific product by including requirements that you know only your favorite product meets. Companies from all over the EU may register for such a tender.

Suppose you are a government service and you want to, say, purchase cell phones. There are Chinese mobile phones on the market that meet all your requirements and they are cheaper than the competition's products. There is a good chance that European companies will offer those Chinese mobile phones. The competitive pricing forces you to do business with that company. The contractor may be little more than a box pusher who outsources technical support to the manufacturer. And before you know it, you not only have Chinese equipment in your organisation, but also the accompanying Chinese personnel. Both the equipment and the maintenance technician may do things that were not included in your package of requirements, but are included in those of the Chinese government.

You dutifully complied with all the rules, but in doing so you brought in the Trojan horse with full consciousness. That's Kafka, upside down.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2024-02-02

Ingredients

 

Image by author

Ingredients: white beans 61%, water, tomato purée 16%, sugar, sea salt, natural vinegar, corn starch, natural herbal flavoring. Thus the back label of the jar, which on the front is called 'white beans in tomato sauce'. Does this product fit into a low-salt diet? I wouldn’t know, because luckily my health doesn't have to worry about that. But if it ever becomes necessary, I would like to read on the label of any product whether it contains salt, and preferably how much.

It's purely a coincidence that I'm back in the canning business just like last week - I'm not considering switching to that industry, nor have I been asked to promote their products (eat fresh vegetables, people!). But I'm a fan of metaphors, and a jar of vegetables turns out to be a rewarding object.

Usually you won't care what else is in a jar of white beans in tomato sauce besides white beans and tomato sauce, unless you have a specific reason, such as a doctor's recommendation. And then you're happy that it's all on the label.

And what turns out? It’s just the same in ICT. As long as everything goes well, no one cares which programming language, which framework and which libraries are used, which open source components are included or which platform the system runs on. But when word starts circulating that a certain, widely used ingredient contains a serious vulnerability, you all of a sudden want to know whether that ingredient is in your systems. Because you want to switch to a low-salt diet if necessary, or you want to replace the sea salt with regular table salt, or perhaps you need to switch - temporarily or permanently - to green beans.

For ICT, what the label is for foodstuffs is the SBOM: the Software Bill of Materials, the list of components that are incorporated into the product. When it was announced in December 2021 that Log4j contained a serious vulnerability, the world was in turmoil. Log4j is like a type of salt that is used in many products. If one day you hear that contaminated salt has been used, as a manufacturer you immediately want to know which of your products contain that salt, so that you can recall the right products from the supermarkets and stop your production process until you have a shipment of clean salt.

I recently learned that the administrators of some systems assume that Security knows which components are in which product and will alert them if something is wrong with one of them. But of course it doesn't work that way. The Food and Consumer Product Safety Authority doesn’t know which canning factory products contain salt either. They can only sound the alarm if a bad batch has been delivered. It is then up to the manufacturer to determine which products the salt may have ended up in and to take the correct measures. It is the same with us, in IT. Security knows if something is wrong, but the administrator needs to know whether his system is affected and whether he needs to take action. Of course, coordination will always take place in major situations, but you remain responsible for your own system.

The attentive reader may have noticed that above I always talked about systems and products, while the s in SBOM stands for software. But why limit an ingredients list to software? Hardware components can also be vulnerable, as Meltdown and Spectre, both vulnerabilities in certain CPUs, made painfully clear in 2018. Of course you want to know whether you have equipment that contains the vulnerable processors. Well, fortunately there is also such a thing as the HBOM: the Hardware Bill of Materials. Ideally, you would like to see all the components in there, down to the smallest chip. I just don't know whether manufacturers would be happy to cooperate, because competitors are of course reading along. That does not necessarily have to be a problem, if you can rely on the manufacturers having  their BOMs in order and also having linked their customer base to them and that communication is well organized. You can agree all this contractually. In your CBOM.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2024-01-26

Drained weight

 

Image from Unsplash

It's crazy that as a citizen you have to worry about your privacy. In the past, when Roger Moore still was James Bond, you only had to worry about external interest in your doings if you were a special company or a government. But nowadays? Everything has a privacy policy these days. And that means that your privacy is at stake everywhere. Otherwise that policy would not be necessary.

Well, the tone has been set for European Privacy Day, January 28. Apparently that day is necessary, too. Witness also this musing of Omri Elisha, professor of anthropology in New York:

We memorized phone numbers.
We memorized driving directions.
No one knew what we looked like.
No one could reach us.
We were god.

In those days, as a child you played outside with your friends, randomly ringing their doorbells or finding them somewhere outside. As a boy you wore rubber boots and preferred to play at the local mud puddle. At most you had a watch and a time when your mother told you to be home (and hopefully there was time taken into account to get you to the table clean). Yes, we were those gods, we just didn't realize it.

As a parent I look at this differently. It's quite nice to have your children under the digital button - at least when they respond to you. Are you worried because they are not home yet, or do you want them to run an errand? Sending an app usually works wonders. Are they going somewhere? They can then text that they have arrived safely, or they share their live location so that you know where they are in case of emergency. It also works the other way around: if help is needed, mom and dad are easily accessible. The price for this comforting technology is privacy. But because the children of this century don't know any better, they don't miss it.

Nowadays one hardly buys any device with a power plug that is not subject to a privacy policy. If you do not agree to it, you cannot use it. Not a soul reads it, everyone blindly agrees. If only because they are always those long, tough stories. You almost wish it just said: All data that this product collects about you and your environment may be used at the sole discretion of the manufacturer and all its business partners. I know of one case where this actually happens. If you travel to the US and come from a friendly country, you do not need a visa. Instead, you can simply apply for an ESTA (Electronic System for Travel Authorization) online. If you enter that process, you will receive an unmistakable security notification, which starts as follows:

You are about to access a Department of Homeland Security computer system. This computer system and data therein are property of the US Government and provided for official US Government information and use. There is no expectation of privacy when you use this computer system. The use of a password or any other security measure does not establish an expectation of privacy.

It's that simple: don’t expect any privacy when using this system. Even security measures that might give the impression of privacy are not there for your privacy. It reminds me of the greeting of the Borg in Star Trek (see this Security (b)log). Fortunately, how different things are with our own government, where people generally do their utmost to guarantee our privacy.

I recently wanted to return a product. The webshop was to send me a DHL shipping label. I received an email from DHL containing not only my shipping label, but also those of a few other customers. The webshop itself had not received those labels. It’s just a small thing, but it does indicate how easily personal data can leak.

The drained weight is stated on vegetable jars - how many grams of vegetables are in it, without the liquid? Perhaps websites should also place such a notice: given our security level, there is a 5/25/50/75/100% chance that your data will go down the drain.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2024-01-19

Stairway to poetry

 

Image from author

The Hague, Ministry of Justice and Security. From the top floor, the 36th, you have a magnificent view of the surrounding area. Even on a meteorologically challenging day like last Monday, with alternating sun, snow showers and strong winds. If you have a meeting here, you have to accept some loss of time due to looking outside. But there is more to experience.

A stairwell in an office building is often boring, because, especially in a high-rise building, hardly anyone goes there. But there, at Turfmarkt, they wrote sayings on the risers of the stairs. The following is written on the stairs between the 35th and 36th floor: Accidents are just around the corner. Happiness is everywhere else.

For people like me, who are professionally concerned with anything that can go wrong, this puts things into perspective, perhaps even more than for 'ordinary' people. We are looking around the corner, searching and picking, while in general we see relatively little serious misery. Yes, there are regular news reports about data breaches, ransomware and DDoS attacks, and criminal phishing actions, but most of the time, they are not disruptive. Even in Ukraine, which has been suffering from war violence for two years now and where the cyber part of the war started much earlier, the digital society is still up and running. It seams unbreakable. So you might think that in general, we don’t go around that corner, but instead we go everywhere else.

Whenever something like this comes up, I like to recall the year 2000, or more precisely: the turn into the new millennium. That is almost a quarter of a century behind us, which means that there is now a working generation that has not experienced this transition. Well, guys, there was a lot of fuss going on, and that fuss had a name: the millennium bug. While you may be reading this blog on your smartphone, which is in fact a pretty powerful computer, it's hard to imagine that computer memory was a scarce resource in the last century. Today a gigabyte is the smallest unit we talk about, but back then it was kilobytes. That makes a difference of six zeros, or a factor of a million. While you can now buy a 64 GB USB thumb drive for less than a tenner, we used to have to make do with 512 KB floppy disks, which you bought in boxes of ten. The next generation, which could store 1.44 MB (more than twice as much!), felt like a major leap forward. When installing an application on your PC, you were a disk jockey: those products came on a stack of floppy that you had to insert one by one. Downloading had yet to be invented.

Storage memory was in short supply, and it was skimped on wherever possible. For example on date fields. Why would you write 1977 if 77 was sufficient? This was common even in the real world: I learned the date format 24-5-'65 at school. The apostrophe indicated the century, but you could just as easily leave it out. In computers it would save you two positions for each date. But as the turn of the century approached, a problem came into view. Suddenly 31 would no longer necessarily mean 1931, but could also be 2031. Computers would choke on this, for example if they had to sort data. Heaven and earth were moved to avert disaster. In the Netherlands, an estimated nine billion euros were spent on this, and worldwide three hundred billion dollars, according to Wikipedia.

When the gunpowder fumes from the fireworks had dissipated, it turned out that very little had gone wrong. Then there was a lot of criticism: did we spend all that money for nothing? I still get quite excited about so much naivety. Why do you think things went so well? Because of that great effort of course! It's as clear as day: there’s a problem, you solve it, danger averted. At this level of abstraction it doesn't get any harder than this.

Back to the stairs of the ministry. That saying is wrong. An accident being just around the corner means that mischief is very likely to happen. The second sentence of the stair writings, on the other hand, pretends that hardly any accidents really happen and that most things go well. The fact that things are going relatively well in the digital society is due to all the measures taken to prevent problems, and to a quick, adequate response if something does happen. The saying on the stairs should therefore read: Accidents are just around the corner. Grab a broom and sweep that corner clean.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2024-01-12

Rainbow

 

Image from Pixabay

Recently, there was a newspaper article about armored passenger cars. Or rather: about the 'best secured passenger car in the world'. Due to all the extras, the colossus weighs around 4,500 kg (9,900 lbs), which means you are not allowed to drive it with a regular passenger car driving license in the Netherlands. Part of the weight is in the windows, which are up to ten centimeters (four inches) thick. But of course, quite thick steel is also involved. The doors alone weigh 200 kg (440 lbs). Per piece, that is. The car is made in Sindelfingen, Germany and is called Mercedes S680 Guard.

But rest assured, this did not suddenly become a car blog after the New Year. No, the trigger for writing a blog in response to that newspaper article was a German word from that article: Beschussamt. Chances are you don't even know how to pronounce that (‘be’ like in begin, ‘schuss’ like shoes, but shorter, ’amt’ with the British a in tomato), let alone what it means. Let's start at the back: an 'Amt' is as much as a service or authority. And 'Beschuss' means shelling. So in a literal translation you end up with something like 'shelling service'. The newspaper found a neater translation: firearms authority.

What does a firearms authority have to do with cars? Well, my own translation wasn't so bad in that respect: they are literally shooting at those cars. Because those cars want to be certified, of course, and you obviously won't get that certification just because the brochure states that the vehicle can withstand bullets from a Kalashnikov. They would like to see that with their own eyes at the Beschussamt, and moreover, there are formal standards for the protection factor of a car. And that is why they empty their weapons at those cars and then investigate what they have done to it.

I can now go in two directions with my blog: I can talk about certification, or about testing. You know what, I’ll do the second; just because it's more fun. With those cars, the bullets can come from two sides: from the good guys (the Beschussamt) and from the bad guys (anyone against whom the person being transported in such a car wants to protect themselves). You can look at IT systems in a similar way. Although bullets are not usually literally fired at them, there are two parties that are interested in the resistance that the system offers. On the right side we have the owner of the system, and on the wrong side everyone that owner wants to protect his system against.

But wait a minute; there are more parties on the right side. There is also a whole army of volunteers who look for weaknesses in systems and, if found, dutifully report them to the owner, without abusing the vulnerability found. They are traditionally called white hat hackers, by analogy with the color of the hats of the good guys in spaghetti westerns. A more modern term for this is ethical hacker. Whatever you call them, these people can try to penetrate that system completely without the knowledge of the owner of a system.

A system owner can of course also order his system to be tested. He can have this carried out by his own employees, but an entire industry has also emerged around testing systems: you can simply hire ethical hackers (although it is very pleasant and useful to have a few of them on your payroll). Whoever does it, they perform a so-called pen test. That has nothing to do with stationery, but is short for penetration test – they try to get into your system. You also come across the name A&P test; this stands for attack & penetration – of course a pen test involves an attack.

First you need to decide what their starting point will be: do they get virtually nothing upfront, do they get some more information and an account, or do they get full access and technical and design information? Like everything in this life, pen tests also come in colors: the first kind of test is called a black box (the system to be tested is largely a black box for the hacker, so he knows nothing and doesn’t have access), the second is a gray box pen test and the latter is called white box or – much nicer but not a color – crystal box. Why would you do the latter? There's no point in that, if the hacker already knows everything and gets free access, is there? Well yes, actually: the system is tested with knowledge that a malicious outsider does not have. That can certainly be useful.

 

There are even more colors that are used when conducting exercises. The attackers are on the red team, the defenders on the blue team. And then there is a hybrid called, yes, purple team; In that composition, attackers and defenders learn from each other. During such an exercise, the red team can, for example, perform a crystal box pen test, which will hopefully be seen and averted by the blue team, after which they, as a purple team, discuss what they encountered. You see, the industry has managed to come up with a nice set of terms that are incomprehensible to outsiders. And I haven't even highlighted all the colors and all the aspects.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

Ants and lemons

Image: Unsplash Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also ro...