Nicely timed to drop on the final day of Windows 7 support, Windows 10 received a fix to an extremely serious flaw in crypt32.dll. This flaw was reported by the good guys at the NSA. (We know it was the good guys, because they reported it rather than used it to spy on us.) Its really bad. If youre running Windows 10, go grab the update now. OK, youre updated? Good, lets talk about it now.
The flaw applies to X.509 keys that use elliptic curve cryptography. Weve discussed ECC in the past, but lets review. Public key encryption is based on the idea that some calculations are very easy to perform and verify, but extremely difficult to calculate the reverse operation.
The historic calculation is multiplying large primes, as its unreasonably difficult to factorize that result by a conventional computer. A true quantum computer with enough qubits will theoretically be able to factorize those numbers much quicker than a classical computer, so the crypto community has been searching for a replacement for years. The elliptic curve is the solution that has become the most popular. An agreed-upon curve and initial vector are all that is needed to perform the ECC calculation.
There are potential weaknesses in ECC. One such weakness is that not all curves are created equal. A well constructed curve results in good cryptography, but there are weak curves that result in breakable encryption.
With that foundation laid, the flaw itself is relatively easy to understand. An X.509 certificate can define its own curve. The Windows 10 implementation doesnt properly check the curve that is specified. A malicious curve is specified that is similar to the expected curve similar enough that the checks in crypt32 dont catch it.
Imagine this scenario. You get an email, click a link, and immediately realize that this isnt the page you thought it was. Close that tab, and all is well, right? You didnt actually fall for the fishing scam. Well, [Alex Birsan] has bad news, in the form of a clever attack based off a Cross-Site Script Inclusion (XSSI) vulnerability in the Paypal login flow.
XSSI is similar to its other cross-site scripting brethren, but rather than running malicious code on a target web page, it runs a script from another web service on a malicious web page. Its pretty common to include a JavaScript script from a different domain. The difference here is that not all JS scripts are intended to be included in other pages. Paypal had such a script. Visiting a malicious web page could load that script in your browser, and if youve ever logged in to Paypal, it would contain a set of valid session keys. The attacker could make a few password attempts using those credentials, which triggered a CAPTCHA request.
That CAPTCHA request is important. When the CAPTCHA form is filled, it launched a self-submitting form that contained the plain text username and password. Yikes! Once a user logged back in to Paypal, that CAPTCHA page could be run again, with the stolen session key, and the username and password easily recovered by the attacker. Thankfully, [Alex] disclosed the vulnerability to Paypal, who fixed it and paid him a nice tidy sum for his work.
Brought to us by Phoronix, Intel is in the process of mitigating a problem in their integrated GPU cores. Even in Intels disclosure, there isnt a whole lot of detail, but it seems to be another information leak in the same vein as Meltdown and Spectre.
The solution, at least in the Linux kernel, is to reset the iGPU between context switches. On 7th generation processors in particular, the performance hit to GPU is pretty severe. Considering the less than stellar video performance of those chips, losing 50% performance to this mitigation is quite the blow.
Use a cable modem? Theres a decent chance it has a Broadcom chip in it, and is vulnerable to Cablehaunt. A group of researchers found a way to download the current modem settings, which started a hunt for vulnerabilities. They found a spectrum analyzer page that responds to JSON requests. Naturally, the JSON parser isnt written defensively. A long enough value in a request overflows the buffer, and the processor and microkernel that system runs doesnt have any modern mitigation. Getting from access to the open port to malicious modification is a nearly trivial task. Check out the page for more details, as well as instructions for how to test your modem.
At this point, if you have any Cisco equipment you can put your hands on, unplug it now before the long weekend of patching that you have ahead of you. [Steven Seeley] did an audit of the Cisco Data Center Network Manager. While he found multiple security problems, the glaring issue is a hardcoded authentication key. Yes, another Cisco product had a backdoor left in a production unit. There are deserialization bugs, SQL injection vulnerabilities, and plenty more to wade through, so go check it out if you want the gritty details.
View post:
This Week In Security: Windows 10 Apocalypse, Paypal Problems, And Cablehaunt - Hackaday
- Two Quantum Computers Face-Off for the First Time in History! - Interesting Engineering [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Split decision in first-ever quantum computer faceoff | Science | AAAS - Science Magazine [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- How to defend against quantum computing attacks - ScienceBlog.com - ScienceBlog.com (blog) [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Researchers Have Directly Tested Two Quantum Computing ... - Futurism [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Scientists reveal new super-fast form of computer that 'grows as it ... - Phys.Org [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Andreas Antonopoulos: Bitcoin's Design Can Withstand Quantum Computer Attack - CryptoCoinsNews [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- IBM QISKit Aims to Enable Cloud-basaed Quantum Computation - InfoQ.com [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Legacy of brilliant young scientist is a major leap in quantum ... - Phys.Org [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- IBM Q is the first initiative to build commercial quantum computing systems - BetaNews [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- IBM To Commercialize Quantum Computing - ADT Magazine [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Quantum computer learns to 'see' trees - Science Magazine [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- David Deutsch and His Dream Machine - The New Yorker [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Quantum computers are here -- but what are they good for? - PCWorld [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- IBM's first commercial quantum computer could shake-up chemistry ... - Chemistry World (subscription) [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Quantum computing takes a massive step forward thanks to ... - TechRadar [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Better than Quantum Computing: The EU Launches a Biocomputer ... - Labiotech.eu (blog) [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- In a few years new Quantum computers from IBM, Google and Microsoft will accelerate breakthroughs in chemistry and ... - Next Big Future [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Research project successful: Volkswagen IT experts use quantum ... - Automotive World (press release) [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Rechargeable 'spin battery' promising for spintronics and quantum ... - Phys.Org [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- The First Quantum Computer You Own Could Be Powered by a Time Crystal - Futurism [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Microsoft to double headcount of Sydney quantum computing lab ... - Computerworld Australia [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Could Time Crystals Hold The Key To Building The First Quantum Computer? - Wall Street Pit [Last Updated On: April 22nd, 2017] [Originally Added On: April 22nd, 2017]
- Microsoft boosts Aussie quantum computing team - ARN - ARNnet [Last Updated On: April 26th, 2017] [Originally Added On: April 26th, 2017]
- Will Google Be The First To Achieve Quantum Computing Supremacy? - Wall Street Pit [Last Updated On: April 26th, 2017] [Originally Added On: April 26th, 2017]
- Computing on the boundary between conventional and quantum - Electronics Weekly [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Quantum cryptography - Wikipedia [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Beyond classical computing without fault-tolerance: Looking for the ... - Phys.Org [Last Updated On: April 30th, 2017] [Originally Added On: April 30th, 2017]
- Quantum Computing | D-Wave Systems [Last Updated On: April 30th, 2017] [Originally Added On: April 30th, 2017]
- quantum computer - WIRED [Last Updated On: April 30th, 2017] [Originally Added On: April 30th, 2017]
- World's First Quantum Computer Is Here - Wall Street Pit - Wall Street Pit [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- China adds a quantum computer to high-performance computing arsenal - PCWorld [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- The Quantum Computer Revolution Is Closer Than You May Think - National Review [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- China builds five qubit quantum computer sampling and will scale to 20 qubits by end of this year and could any beat ... - Next Big Future [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- Researchers seek to advance quantum computing - The Stanford Daily [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- New Materials Could Make Quantum Computers More Practical - Tom's Hardware [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Nanofridge could keep quantum computers cool enough to calculate - New Scientist [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Home News Computer Europe Takes Quantum Computing to the Next Level With this Billion Euro... - TrendinTech [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Quantum Computing Demands a Whole New Kind of Programmer - Singularity Hub [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Refrigerator for quantum computers discovered - Science Daily [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Scientists Invent Nanoscale Refrigerator For Quantum Computers - Wall Street Pit [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- IBM builds two new Quantum Computing processors - Enterprise Times [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Quantum Computers Sound Great, But Who's Going to Program Them? - TrendinTech [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- IBM makes a leap in quantum computing power - PCWorld [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- IBM's Newest Quantum Computing Processors Have Triple the Qubits of Their Last - Futurism [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- IBM scientists demonstrate ballistic nanowire connections, a potential future key component for quantum computing - Phys.Org [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- The route to high-speed quantum computing is paved with error | Ars ... - Ars Technica UK [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Researchers push forward quantum computing research - The ... - Economic Times [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- US playing catch-up in quantum computing - The Register-Guard [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- IBM Q Offers Quantum Computing as a Service The Merkle - The Merkle [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Graphene Just Brought Us One Step Closer to Practical Quantum Computers - Futurism [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- How quantum computing increases cybersecurity risks | Network ... - Network World [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Is the US falling behind in the race for quantum computing? - AroundtheO [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Artificial intelligence and quantum computing aid cyber crime fight - Financial Times [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Google Plans to Demonstrate the Supremacy of Quantum ... - IEEE Spectrum [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Top 5: Things to know about quantum computers - TechRepublic [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- AI and Quantum Computers Are Our Best Weapons Against Cyber Criminals - Futurism [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Scientists claim to have invented the world's first quantum-proof ... - ScienceAlert [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Microsoft, Purdue Tackle Topological Quantum Computer - HPCwire - HPCwire (blog) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- MIT Just Unveiled A Technique to Mass Produce Quantum Computers - Futurism [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Here's How We Can Achieve Mass-Produced Quantum Computers - ScienceAlert [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Research collaborative pursues advanced quantum computing - Phys.Org [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Telstra just wants a quantum computer to offer as-a-service - ZDNet [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- D-Wave partners with U of T to move quantum computing along - Financial Post [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Doped Diamonds Push Practical Quantum Computing Closer to Reality - Motherboard [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Team develops first blockchain that can't be hacked by quantum computer - Siliconrepublic.com [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Are Enterprises Ready to Take a Quantum Leap? - IT Business Edge [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Scientists May Have Found a Way to Combat Quantum Computer Blockchain Hacking - Futurism [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Microsoft and Purdue work on scalable topological quantum computer - Next Big Future [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- From the Abacus to Supercomputers to Quantum Computers - Duke Today [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Quantum Computers Will Analyze Every Financial Model at Once - Singularity Hub [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Quantum Computing Technologies markets will reach $10.7 billion by 2024 - PR Newswire (press release) [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- KPN CISO details Quantum computing attack dangers - Mobile World Live [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Get ahead in quantum computing AND attract Goldman Sachs - eFinancialCareers [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Toward optical quantum computing - MIT News [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Quantum Machine Learning Computer Hybrids at the Center of New Start-Ups - TrendinTech [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Israel Enters Quantum Computer Race, Placing Encryption at Ever-Greater Risk - Sputnik International [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Prototype device enables photon-photon interactions at room ... - Phys.Org [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- The Quantum Computer Factory That's Taking on Google and IBM - WIRED [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- 6 Things Quantum Computers Will Be Incredibly Useful For - Singularity Hub [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Volkswagen buys D-Wave quantum computers which sell for $15 million each - Robotics and Automation News (press release) (registration) [Last Updated On: July 2nd, 2017] [Originally Added On: July 2nd, 2017]