BTemplates.com

Powered by Blogger.

Pageviews past week

Quantum mechanics

Auto News

artificial intelligence

About Me

Recommend us on Google!

Information Technology

Popular Posts

Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Saturday, June 18, 2011

Crypto-currency Security under Scrutiny



Reports that $500,000 worth of Bitcoin currency was stolen from one user's computer this week has highlighted the poor security of the digital cash and the systems available for managing it. For the currency to gain large-scale popularity, it may need to create or work with financial institutions—making Bitcoin less distinct from the conventional currencies some users hope to supplant.
An alleged robbery suggests Bitcoin—an anonymous,
decentralized currency may need bank-like institutions after all.

To use Bitcoin, a person downloads the official software client, which connects over the Internet to a global network of other copies of the program. Together, these implement the mathematical scheme that ensures that bitcoins can be transferred, created, and verified without any need for a central authority such as a bank (read How Bitcoin works).

That official client stores the security needed to use a stash of bitcoins with minimal security, in an unprotected file known as wallet.dat. In a forum post this week, a bitcoin user whose screen name was "allinvain" claimed that a remote attacker gained access to his or her wallet file and stole over 25,000 bitcoins. The value of a single bitcoin at the time of writing (just over $19) makes the alleged heist worth nearly $500,000, although in practice converting such a large number of bitcoins at once would be tricky. It is impossible for the alleged victim to know who stole the money because the cryptographic architecture of Bitcoin is designed to preserve the anonymity of people transferring the currency. Today the security company Symantec reported it had caught a piece of malicious software that infects computers over the Internet and attempts to steal wallet files.

The vulnerability highlighted by the controversy is very real, says Jeff Garzik, one of the lead developers of the official Bitcoin client and one of a few individuals who are the closest thing the currency has to official spokespeople. Today, anyone able to access the machines of Bitcoin users, either directly or remotely—via malicious software—can grab their wallet files, he acknowledges.



An upgraded version of the client, which will encrypt a person's wallet and ask for a password each time it is accessed, will be released in "just a week or two," says Garzik.

Yet users will still essentially be maintaining their own bank vaults on their computers. "[Wallet encryption] does nothing against many modern malware techniques, such as keystroke logging," says Garzik. He advises Bitcoin users to keep encrypted backups of their wallet files away from the Internet, for example on a USB stick, since the file is needed only when sending money to others.

This may be an option for technically minded early adopters. But if the currency is to be used more widely, a new generation of simple and secure tools for using bitcoins is needed, says Amir Taaki, who leads a U.K.-based consultancy of software developers working on a range of technologies for use with Bitcoin, which operates the exchange site Britcoin.

"Bitcoin is in the very early stages as a piece of software, and if you're a regular home user, then it's not for you at the moment," says Taaki. "It started as a plaything, and now we're at the stage that for Bitcoin to grow, it needs the software used to get money in and out to be more solid and secure."

Earning wider trust will likely require the Bitcoin ecosystem to become more like that of a conventional currency. Taaki and Garzik both say that in the future, there will be established, trustworthy exchanges to look after users' bitcoins, and online services to manage and disburse their cash.

That might go against the libertarian aspirations of some Bitcoin users, who are attracted by its decentralized nature and lack of any controlling authority. Yet the currency will still offer those features, says Patrick Strateman, a developer working on building more robust, secure software for bitcoin exchange sites. "The big difference here is that people will have a real option," says Strateman. "Everyone has the options offered by the old system, plus they have new options as well." Even if many users turn to bank-like organizations to keep their bitcoins safe, it will still be possible to use the less controlled (if riskier) methods that prevail today, he says.

Bitcoin exchanges would benefit from becoming friendlier to investigations of fraudulent transactions, says Taaki, though their doing so would make them even more like conventional banks. Claims by two U.S. senators last week that bitcoins' "untraceable" nature facilitated the purchase of illicit drugs were unfounded, says Taaki: the Bitcoin protocol is built around a public record of every transaction made with the currency. That log, called the "block chain," is maintained and stored by all Bitcoin clients and can be used to trace the movement of any and all bitcoins. But it records only the cryptic public keys that swapped funds, not the identities of the people using them. For example, an online version of the block chain can be used to see how the address "1KPTdMb6p7H3YCwsyFqrEmKGmsHqe1Q3jg" received 25,000 bitcoins this week, the transaction that allinvain complained about.

But Taaki says his Britcoin exchange will help authorities interpret the block chain in cases like money-laundering investigations, and could even correlate it with records of the identities of users of the exchange. The operator of the Mt Gox exchange, the largest bitcoin exchange in the world, has made a similar pledge, says Taaki. "We don't want Bitcoin to be outlawed by well-meaning but ignorant regulators."


Sunday, April 4, 2010

Spammers Turn to Social Networks : They get results by exploiting a social network's trusting environment


As users have flocked to social networks, so, inevitably, have spammers. And according to a recent experiment, users are much more receptive to spam sent via a social network than over e-mail.


A group led by George Petre at BitDefender, an antivirus software company based in Bucharest, Romania, performed an experiment to test the effectiveness of spamming techniques geared toward a social networking site. They found it surprisingly easy to entice Facebook users to "friend" people they didn't know; they also found that many users were willing to click on links without knowing who sent them or where they led.
Me
Fake friends: This screenshot shows real
users who befriended a bogus Facebook
user created by George Petre and colleagues.
Credit: BitDefender


Speaking last week at the MIT Spam Conference in Cambridge, MA, Petre described how spammers exploit social networks via messaging systems by enticing users to click on links, and by gathering personal information to target mail-outs.

Most social networks have internal messaging systems for communication between members. Petre's group examined that of Facebook, which boasts 5 percent of the world's population as its users. While Facebook has an antispam engine, the group found that it was better at filtering out phishing e-mails than preventing spam messages from getting through.

The group started by creating fake profiles to trick users into friending them. They created three profiles, one containing almost no information about the user, one with some information, and one with detailed information. They used those profiles to join popular groups and began sending out friend requests.

Within 24 hours, 85 users had accepted a request from the first profile, 108 from the second, and 111 from the third. Petre says that acceptances began to accelerate, since more than 50 percent of the time, users would accept the request if they shared a "mutual friend" with the fake profile. In some cases, he says, users would send a message asking for more information about how they knew this supposed new friend. The researchers didn't respond to these requests, but in many cases, Petre says, users accepted the request anyway.

The researchers then posted a link without any explanation to the fake profiles' walls, using a URL shortener to obscure where the link went. Almost 25 percent of the profiles' "friends" visited the link, Petre says.

To send messages to large numbers of people, Petre says, spammers often trick users into joining groups and befriending fake profiles. For example, in the aftermath of the Haitian earthquake, fraudsters started a group on Facebook that claimed the social networking company would donate money to relief efforts for each user who joined. The group collected nearly two million members in the five days before Facebook discovered the activity and suspended the group. While active, Petre says, the group was used to send spam messages to the group's members.

Spammers can also blast messages to users who have accepted friend requests from them. Petre found that scammers use social games to make contacts with legitimate users. In many of these games, such as Farmville, users get ahead by having friends on the network who play the same game. As a result, there are lots of groups on Facebook devoted to helping users connect with others players. This provides a way for spammers to find users to connect with.

Once connected, spammers can also do more than just send spam messages. They can gather data on users, and those users' contacts, to create more targeted fraudulent messages. Scammers also post links to profiles that aim to entice users to view advertising or visit compromised phishing or malware websites. While spammers could, in theory, use scripts to harvest e-mail addresses from other users' profiles, Facebook has implemented several protections that make this difficult to do without getting caught and suspended.

"Social networking spam may be more dangerous than regular old spam because it creates a trust factor not available through blindly sending out mass e-mail," says Garth Bruen, creator of software called Knujon, which classifies and tracks spam. By mining social networks, he says, criminals can get access to personal details such as where a person lives, where they go out to drink, or what movies they like. "It is very good intel for establishing trust with strangers," he says. Though Bruen notes that working within a social network costs spammers more resources than traditional methods, he believes the payout could be much bigger.

Kathy Liszka, a professor of computer science at the University of Akron and the chair of the MIT Spam Conference, says that fighting spam is no longer just about mathematics and statistics. Spam and malware companies today are actively recruiting people with backgrounds in psychology, she says, and Petre's work shows that social networks provide fertile ground for spammers to try more sophisticated forms of manipulation. Liszka says, "If we don't get up on the psychology aspect, we're going to start losing ground again."