 |
|
security from key-loggers
05-24-2008, 11:28 AM
|
#1
|
|
Thinks s/he gets paid by the post
Join Date: Dec 2004
Location: Cowtown, Alberta
Posts: 2,402
|
There has been discussing here earlier on the risk from key-loggers, particularly when globe-trotting.
I just ran across this link which may be of interest:
John Barnett's Windows XP Help and Support
I have not evaluated this software, just reporting it.
Cheers,
Gypsy
__________________
"Ain't got no money for no old-age pension;
I'm so broke, I can't pay attention!"
|
|
|
05-24-2008, 12:04 PM
|
#2
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
I've been reading up a little bit on some of the next wave of spy/malware. Turns out that almost everything has a little cpu and updatability of firmware these days. Even the smart battery in your laptop has a little ATmega406 cpu and some updatable firmware and can access some system resources to signal battery conditions.
With smart disk drive controllers, little limited cpu's in the keyboard controller, etc its only a matter of time before a piece of bad code can slip something into a piece of hardware in your system that would be almost completely undetectable by any operating system or virus detection product.
Its even highly plausible for the systems cpu microcode/firmware to be altered such that the cpu itself could perform logging or do damage to the system without the underlying software even being aware of the malwares presence.
It may simply be coming to the point where its almost implausible to protect yourself, and just not "going to the bad parts of town" or "associating with the wrong elements" will be the only way to largely avoid trouble.
Something like keyscrambler is great until someone puts something undetectable and invasive on your network cards firmware, run by the network cards microcontroller with full access to system memory and the disk drive or has a cpu based rootkit that says its doing something to protect you when its doing the opposite.
__________________
Many an optimist has become rich by buying out a pessimist
|
|
|
05-24-2008, 04:26 PM
|
#3
|
|
Thinks s/he gets paid by the post
Join Date: Mar 2007
Posts: 1,503
|
This kind of ties in with the suspicion that chip makers may be inserting back doors into the chips themselves.
IEEE Spectrum: The Hunt for the Kill Switch
Last September, Israeli jets bombed a suspected nuclear installation in northeastern Syria. Among the many mysteries still surrounding that strike was the failure of a Syrian radar—supposedly state-of-the-art—to warn the Syrian military of the incoming assault. It wasn't long before military and technology bloggers concluded that this was an incident of electronic warfare—and not just any kind.
Post after post speculated that the commercial off-the-shelf microprocessors in the Syrian radar might have been purposely fabricated with a hidden “backdoor” inside. By sending a preprogrammed code to those chips, an unknown antagonist had disrupted the chips' function and temporarily blocked the radar.
__________________
Feral Engineer
|
|
|
05-24-2008, 05:14 PM
|
#4
|
|
Full time employment: Posting here.
Join Date: May 2006
Posts: 672
|
Can anyone guarantee that the OP's link is legitimate? I'm not accusing Gypsy of being dishonest at all. But since we are talking about security issues how do we know:
1) That Gypsy is not being spoofed?
2) That the link to John Barnett's site has not been compromised after the posting?
3) That John Barnett's site has not been hacked and compromised?
4) That the software is legitimate?
5) That the software is not prehaps selectively choosing victims?
I could go on but hope I've made the point that choosing your trusted source is a challenge  .
|
|
|
05-25-2008, 06:09 PM
|
#5
|
|
Thinks s/he gets paid by the post
Join Date: Nov 2005
Location: North of Montana
Posts: 1,460
|
Quote:
Originally Posted by cute fuzzy bunny
I've been reading up a little bit on some of the next wave of spy/malware. Turns out that almost everything has a little cpu and updatability of firmware these days. Even the smart battery in your laptop has a little ATmega406 cpu and some updatable firmware and can access some system resources to signal battery conditions.
With smart disk drive controllers, little limited cpu's in the keyboard controller, etc its only a matter of time before a piece of bad code can slip something into a piece of hardware in your system that would be almost completely undetectable by any operating system or virus detection product.
Its even highly plausible for the systems cpu microcode/firmware to be altered such that the cpu itself could perform logging or do damage to the system without the underlying software even being aware of the malwares presence.
It may simply be coming to the point where its almost implausible to protect yourself, and just not "going to the bad parts of town" or "associating with the wrong elements" will be the only way to largely avoid trouble.
Something like keyscrambler is great until someone puts something undetectable and invasive on your network cards firmware, run by the network cards microcontroller with full access to system memory and the disk drive or has a cpu based rootkit that says its doing something to protect you when its doing the opposite.
|
A secure computer for you:
If only I could put a pancake tinfoil hat on it.
__________________
“You can fool too many of the people too much of the time.” – James Thurber
|
|
|
05-24-2008, 05:18 PM
|
#6
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
Heyyy...are you the real lsbcal?
__________________
Many an optimist has become rich by buying out a pessimist
|
|
|
05-24-2008, 05:29 PM
|
#7
|
|
Full time employment: Posting here.
Join Date: May 2006
Posts: 672
|
I could be a spoof, but then why would I be saying such smart things?
|
|
|
05-25-2008, 05:37 PM
|
#8
|
|
Moderator Emeritus
Join Date: Feb 2004
Location: Oahu
Posts: 17,531
|
Quote:
Originally Posted by travelover
Post after post speculated that the commercial off-the-shelf microprocessors in the Syrian radar might have been purposely fabricated with a hidden “backdoor” inside. By sending a preprogrammed code to those chips, an unknown antagonist had disrupted the chips' function and temporarily blocked the radar.
|
Way too complicated. Even Tom Clancy would be embarrassed.
I'd hesitate to credit to military infowarfare tactics or espionage anything that could also be ascribed to sleeping bored & badly-trained watchstanders...
__________________
*
*
For more info see "About Me" in my profile.
|
|
|
05-25-2008, 06:05 PM
|
#9
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
My guess is someone forgot to turn it back on when they were done washing the bird poop off of it.
__________________
Many an optimist has become rich by buying out a pessimist
|
|
|
05-25-2008, 06:17 PM
|
#10
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
Google 'arce bad peripherals'. Or 'rutkowska blue pill red pill'
__________________
Many an optimist has become rich by buying out a pessimist
Last edited by cute fuzzy bunny; 05-25-2008 at 06:26 PM.
|
|
|
05-25-2008, 06:39 PM
|
#11
|
|
Thinks s/he gets paid by the post
Join Date: Nov 2005
Location: North of Montana
Posts: 1,460
|
Still googling 'CFB breaks HTTPS'
Refer to messages 25 thru 27 in this thread, done it yet? Link please.
__________________
“You can fool too many of the people too much of the time.” – James Thurber
|
|
|
05-25-2008, 08:11 PM
|
#12
|
|
Thinks s/he gets paid by the post
Join Date: Jan 2008
Posts: 2,020
|
Quote:
Originally Posted by kumquat
Still googling 'CFB breaks HTTPS'
Refer to messages 25 thru 27 in this thread, done it yet? Link please.
|
I did read up on wep key cracking after that and went to a more secure scheme before not needing wireless at all and just going back to hardwire.
I'm still not concerned about SSL in general, aside from the talk about servers not being properly decomissioned before they're sold. However, there is a serious flaw in OpenSSL on Debian and all derivitives thereof... or any OpenSSL keys that have been exchanged with those distros. Debian OpenSSL Predictable PRNG Toys The recommendation is to re-encrypt anything stored with those weak SSH/SSL keys.
Anyway, boy, this is all way OT.
|
|
|
05-25-2008, 06:44 PM
|
#13
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
Hmm, most of the security guys I know like it when people hear about what can go wrong and how to protect themselves.
The good ones anyhow.
Let me know when you figure out why the DOD doesnt allow SSL for any information top secret or higher...
__________________
Many an optimist has become rich by buying out a pessimist
|
|
|
05-25-2008, 07:57 PM
|
#14
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Jul 2003
Location: north of Kansas City
Posts: 6,191
|
Sooo - a bad toupe and fake mustache in an internet cafe would be a dead give away - or would it be the throw away rubber gloves worn while typing.
heh heh heh - ok so I'm not a bottle blond from Missouri with bacon breath.  .
All of which begs the question - what does the ordinary smuck(aka non geek) do when he wants to pay bills(the usual suspects), do his taxes and maybe check his IRA accounts on line?
You are not paranoid if they really ARE out to get you?? - or what?
Last edited by unclemick; 05-25-2008 at 08:02 PM.
Reason: second thought.
|
|
|
05-25-2008, 11:17 PM
|
#15
|
|
Thinks s/he gets paid by the post
Join Date: Nov 2005
Location: North of Montana
Posts: 1,460
|
Quote:
Originally Posted by cute fuzzy bunny
Hmm, most of the security guys I know like it when people hear about what can go wrong and how to protect themselves.
The good ones anyhow.
Let me know when you figure out why the DOD doesnt allow SSL for any information top secret or higher...
|
Thanks for the link.
__________________
“You can fool too many of the people too much of the time.” – James Thurber
|
|
|
05-26-2008, 09:28 PM
|
#16
|
|
Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Join Date: Dec 2003
Location: Losing my whump
Posts: 22,526
|
Quote:
Originally Posted by kumquat
Thanks for the link.
|
Here's your link:
http://i43.photobucket.com/albums/e3...kidfinger2.jpg
If I remember right, the topic was either whether it was perfectly safe to use any random internet cafe's internet to do major financial transactions or whether to use any open access point available to do the same.
Some folks said "Yeah sure! I do it all the time! Its okay!". And they also run naked across the highway with a bag over their head and nothing bad has EVER happened!!!.
Its my recommendation to do neither. No encryption or security is foolproof.
Now if you always use SSL, and you always have your updates applied, and you always have your firewall on and set right, and...and...and... :
I'm happy with people being aware of what can go wrong and to use proper safeguards and be just a little bit more careful than they need to be.
Seems you have some other agenda. In this case, its taking off with somones topic to apparently address some earlier perceived injury with no interest in educating your fellow forum members in security related matters.
Oh, and by the way, your investing related advice also sucks.
__________________
Many an optimist has become rich by buying out a pessimist
Last edited by cute fuzzy bunny; 05-26-2008 at 09:35 PM.
|
|
|
05-31-2008, 05:56 PM
|
#17
|
|
Recycles dryer sheets
Join Date: Feb 2006
Posts: 123
|
Type your password with extra characters in it and then use the mouse to highlight and delete the extra characters. For example, you might type passFROGword and then highlight and delete the middle four dots. Or type p1a2s3s4w5o6r7d8 and delete every other dot. A keylogger would still record all of the keystrokes that make up your password, but they'll be mixed with other unrelated keystrokes.
__________________
The best argument against democracy is a five-minute conversation with the average voter.
Winston Churchill
|
|
|
05-31-2008, 06:14 PM
|
#18
|
|
Full time employment: Posting here.
Join Date: May 2006
Posts: 672
|
Mark, this is a good way to do it, thanks. What I've often done is to type the last part of password and then move curser and type the first part. I always assume my machine is bugged. Goes along with a suspicious nature  .
|
|
|
05-25-2008, 11:55 PM
|
#19
|
|
Thinks s/he gets paid by the post
Join Date: Jan 2008
Posts: 2,020
|
Ok, first, SSL 2.0 and 3.0 support multiple ciphers. The client and server will negotiate to the strongest cipher they both speak. So, to say that SSL has been broken is a misnomer, or to say that DoD doesn't allow SSL is a misnomer. In the first case, when I posted the link on OpenSSL being compromised, the issue is that the universe of randomness (2^15 'random' numbers) that's introduced into the cipher key is extremely small. As such, the keys are easily guessable. In the second case, well, I can't find anything on DoD's site about what they will or won't allow for ciphers. Failing that, I'm going off of NIST's site and their list of approved ciphers:
NIST.gov - Computer Security Division - Computer Security Resource Center
One of the more common SSL ciphers, SHA-1 (FIPS 180-1) is not on the list. SHA-1 is potentially vulnerable to a collision attack, but I'm not sure if I'd worry just yet.
|
|
|
05-26-2008, 03:02 AM
|
#20
|
|
Thinks s/he gets paid by the post
Join Date: Dec 2004
Location: Cowtown, Alberta
Posts: 2,402
|
Quote:
Can anyone guarantee that the OP's link is legitimate? I'm not accusing Gypsy of being dishonest at all. But since we are talking about security issues how do we know:
1) That Gypsy is not being spoofed?
2) That the link to John Barnett's site has not been compromised after the posting?
3) That John Barnett's site has not been hacked and compromised?
4) That the software is legitimate?
5) That the software is not prehaps selectively choosing victims?
I could go on but hope I've made the point that choosing your trusted source is a challenge .
|
Ya got me! I am actually a sleeper for the KGB (except they changed their phone number and I am stuck here).
Or maybe I'm the guy who put the bug in the printers that were sent to Saddam that disabled their radar in Desert Storm. I forget.
Your point is a good one. It appears to me that a number of little anti-malware software review sites are actually run by the guys whose software is top-rated on that site. It is easy to imagine constructing such a self-serving website to distribute spyware. It would be hard work, though. I have a hard time imagining someone working so hard to get into jail.
__________________
"Ain't got no money for no old-age pension;
I'm so broke, I can't pay attention!"
|
|
|
 |
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Hybrid Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
» Recent Threads
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|

|