Thursday, July 7, 2016

Thoughts on Hillary Clinton Private Server

As some of you may know I am not exactly a Hillary fan. It's not because of political bias or because I vote for a single party (I Vote bipartisan). It's a matter of people that seem to be to big for Jail.

But I wanted to stop and make a really important argument today that Hillary isn't the only one that used a personal email address. The committee hearing can be seen below: (Warning it is 4 hours long)




I will remind people the Chairman that was grilling Comey today uses a gmail address for official business.

At one point during the hearing other members of congress challenged each other to not use personal email addresses to conduct business. At that point when the comment was made I turned off my laptop thinking we are really screwed when it comes to some people that are supposed to be protecting the countries information assets.

Classified vs. Non-Classified
Classified emails are simply marked with a header labeled (C). What escapes me is there seems to be no data leak protection on email sent to external email addresses that are marked as classified.

"In total, the investigation found 110 emails in 52 email chains containing information that was classified at the time it was sent or received. Eight chains contained top secret information, the highest level of classification, 36 chains contained secret information, and the remaining eight contained confidential information. Most of these emails, however, did not contain markings clearly delineating their status."

We all should wonder how many classified emails are leaving the security of their systems unchecked?


Saturday, January 30, 2016

Chromebook Security:A real life story

I've never taken the time to blog about anything personal or work related for that as both of those things I would rather keep private. But this story is just to good to not tell. Back in late November my mom asked for a laptop for Christmas. My parents were leaving on a long four month vacation and she wanted something that she could do video conferencing on for family back home. After asking what all she needed to do with it I opted to get a Chromebook for her.

So I configured it appropriately with an EFF Guide. Which is located here:
https://www.eff.org/deeplinks/2015/11/guide-chromebook-privacy-settings-students

and here:

https://www.eff.org/deeplinks/2015/11/guide-google-account-privacy-settings-students

And was literally all set within a matter of a few minutes.

Here is where things got fun. So I chatted with both my parents over google hangouts one evening and my mom oddly enough said she had to call a company because she was a pop up displayed she was infected with a virus. At first I was taken back a little.... and after I had her repeat the statement she said yes it was infected with a virus so she called the number on the screen. A popup similar to this:



The next thing I asked was what did they say and I shit you not word for word in a heavy thick Indian accent. "Well since you have a chromebook there is nothing I can do. Just throw it in the trash and get a real computer."

Then the guy hung up. My parents said they just powered the laptop down and the message went away. They now know to call me instead of something like this again.

I am now a believer in Chromebook security.  Especially when something stupid like this happens.

Friday, January 22, 2016

So WTF Google?

Update: My Chrome browser has been updated this evening. No alerts about my centos7 systems no longer being supported. All is right again with the world. 


I run a small number of Cent OS 7 desktops in a virtualized environment. After updating to the latest version of google chrome I was met with a nasty message that my Linux system will no longer be supported.

So wtf google?

I'm running a current centos 7 64 bit Linux workstation and you are dumping support for it?

So I am taking to google's support page and I take a look at what is supported.


Pushing chrome support out of centos and RHEL  seems like a mistake for corporate customers. I can understand discontinuing support for 32 bit Linux. But a current major distro that is 64 bit.... Hopefully someone at google will see this after I tweet this for some clarification.

Sunday, January 10, 2016

Guidance for Protected Browsing

This is some best practice guidance for google chrome. This should be done first before any browsing is to be done.

Works best if you compartmentalize your browsing through a virtual machine or read only cd media.
Virtualbox is free for personal use - https://www.virtualbox.org/wiki/Downloads


EFF guide to chromebook privacy
https://www.eff.org/deeplinks/2015/11/guide-chromebook-privacy-settings-students

@attrc HowTo: Privacy & Security Conscious Browsing
https://gist.github.com/atcuno/3425484ac5cce5298932


Use the following Chrome Add on's as a minimum
HTTPS Everywhere
Privacy Badger
Ublock Origin


Use a VPN before browsing use

Under Chrome Content settings set plugins to do this:


If you want to get into hardcore mode go to chrome://plugins
Disable adobe flash player

You may find your browsing experience doesn't require flash for daily use.

Use a chromebook and do all the above. Chromebooks work great because users can install extensions only. Executables and such won't run on chromebooks. The risk of malware is low.

Compartmentalize

Compartmentalize

Compartmentalize

I can't stress it enough when it comes to your personal data.


Monday, January 4, 2016

Windows 10 Security Guidance for Enterprise users

Update security compliance direct from Microsoft. As of 1-22-16.

Security baseline for Windows 10 (build 10240) – FINAL/Update 1-22-16
http://blogs.technet.com/b/secguide/archive/2016/01/22/security-baseline-for-windows-10-v1507-build-10240-th1-ltsb-update.aspx

Security baseline for Windows 10 (v1511, "Threshold 2") -- FINAL 1-22-16
http://blogs.technet.com/b/secguide/archive/2016/01/22/security-baseline-for-windows-10-v1511-quot-threshold-2-quot-final.aspx


If you want to compare GPO sets you should look at this tool called Microsoft Policy Analyzer
http://blogs.technet.com/b/secguide/archive/2016/01/22/new-tool-policy-analyzer.aspx

LGPO.EXE Tool (Automates the management of local group policy. Best for non domain joined computers)
http://blogs.technet.com/b/secguide/archive/2016/01/21/lgpo-exe-local-group-policy-object-utility-v1-0.aspx

For more Microsoft Security guidance you can follow their blog.
http://blogs.technet.com/b/secguide/

Tuesday, December 29, 2015

Bitlocker Derp with Intercept article

A day ago The Intercept came out with an article on bitlocker that had me slowly rolling my eyes. The article in question is right here:
https://theintercept.com/2015/12/28/recently-bought-a-windows-computer-microsoft-probably-has-your-encryption-key/

This article has many correct points although I was shocked that this was news to everyone after seeing a twitter storm again on backdoors against encryption. However there are inaccuracies that really should be corrected.

First incorrect statement:

"In order to generate a new disk encryption key, this time without giving a copy to Microsoft, you need decrypt your whole hard disk and then re-encrypt it, but this time in such a way that you’ll actually get asked how you want to backup your recover key."

Answer:
This statement is not correct. In short.. no.. you do not need to decrypt your entire hard disk. A few things have to be present first if Microsoft does indeed have your encryption key.
1. Are you signed in under a Microsoft account? If the answer is yes... then read step 2.

2. Is my disk encrypted? How do I know if it is encrypted?
Open a command elevated administrator command prompt window and type the following command:
manage -bde -status

As you can see the disk is encrypted with XTS-AES 128. This is Microsoft default in build 10586.

3. Check onedrive to see if my bitlocker backup key exists.
http://go.microsoft.com/fwlink/?LinkId=237614

If you see something like this. Then you will need to delete it. This is what your recovery key looks like.

**Please note this is not my bitlocker recovery key. This was done on a test virtual machine for demonstration purposes.


How to generate a new recovery key without re-encrypting your entire computer.
1. Type in the following command in a elevated administrator command prompt. This will temporarily suspend bitlocker on your pc. This does not decrypt your box. It just suspends the key protectors on your box such as a numerical password or TPM chip,

manage-bde -protectors -disable %systemdrive%

2. Next type the following. This will delete your drives current recovery password.

manage-bde -protectors -delete %systemdrive% -type RecoveryPassword

3. Add a new recovery password. This will regenerate a new one for you.

manage-bde -protectors -add %systemdrive% -RecoveryPassword

Here is a snapshot of this 3 shot flow and where you can clearly see a brand new recovery key has been generated and the old one discarded.


4. Once you store the new key somewhere else. Preferably in encrypted form away from your computer. You need to re-enable bitlocker protection with the following command.

manage-bde -protectors -enable %systemdrive%

Other thoughts:
If you have a modern computer. The worst thing you could do is use an open source product such as veracrypt to utilize full disk encryption on your machine. In order to use something like veracrypt you will have to completely decrypt your hard drive. Actually scratch that. You will have to format your OS. Dump off UEFI mode in the bios. So you will lose boot integrity and validity. Then you will have to format your hard disk partition into a non GPT format. Veracrypt doesn't support that yet.


Warning: All that will separate you from your adversary is a password in this scenario. Make it a damn good one.


I received some other twitter comments...which I won't post... that were completely out of this world. There are alot..... I mean alot of people that have little understanding of how bitlocker works and exactly what Microsoft is backing up to the cloud.

Microsoft backs up recovery keys only.....I repeat recovery keys only. There is no other encryption key that gets backed up or magically generated.

Windows AES128 Default.... change it
A word of warning on default encryption with Microsoft Windows. Microsoft defaults to AES128. On newer Windows 10 builds the default is XTS-AES-128. Everyone should be using at minimum AES256. This is very easy to change with group policy (or local group policy) assuming you have not encrypted your computer yet.

do a search for the following:
GPEDIT.MSC

Navigate to:
Computer Configuration/Administrative Templates/Windows Components/Bitlocker Drive Encryption

Go to the following policy:
"Choose drive encryption method and cipher strength". In this example I am using Windows version 1511 and later. Do the following below.




Attacking Bitlocker Encryption
Attacking encryption is best done by attacking the random number generator. While the RNG for Bitlocker could be in question you are provided with some very good protection if you are using UEFI secure boot and have a TPM chip.

If someone attempts to clone your hard drive. Without these protectors present they would immediately need to know your 48 digit recovery key.

Remember that physical access is needed in order to use a bitlocker recovery key!!!

Choose your encryption snake oil wisely.




Root