Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, December 24, 2013

Would You Like Some Great Tips in Building Secure mHealth Apps?

                                        presentermedia.com

Several  informative tips were shared by a Health IT developer on how to maintain the security of Medical apps. Developers can benefit from the information that was presented in the article.




1. At the very basic level, don’t trust the user. Nearly half feel PINs and passwords are too cumbersome, a third aren’t concerned with risks and 55 percent of adults use the same password for everything. A five-digit pin has 5,904,900,000 combinations, while a pattern combination only has 15,120 combinations, yet pattern locks are still a very common practice among consumers.

2. Do your research and stay current. Security firm viaForensics openly publishes its benchmark list ofmobile security best practices in addition to its research and How-Tos. Jonathan Zdziarski’s Hacking and Securing iOS Apps is another great comprehensive resource. Think of mobile app security in terms of the onion model, and layer security measures to help make exploitation cost prohibitive. This includes keeping your OS and environment up to date.

3. Leverage jailbreak detection. Jailbreaking is a means to provide root access to the mobile OS, allowing the user to download additional applications, extensions and themes that are not available through the official Apple App Store. This also allows a range of exploits both on the device itself and through applications that are downloaded through third party stores. According to a recent study from Axran, more than 50 percent of the 100 top apps in the Apple App Store have been cracked and republished for jailbroken phones on other app markets. In addition to revenue loss, IP theft, fraud and brand erosion for the original company, these apps put the user at risk of malware infection, data interception and identity theft. It’s important that mobile apps be able to defend themselves against static and dynamic analysis at runtime and be made resistant to tampering and reverse-engineering attacks.

4. Know what resources are available. There are a number of tools in the infosec community that can be openly leveraged to help mitigate risks. Despite being relatively new, the iMAS library provides iOS developers with a set of easy-to-use tools to accomplish various security tasks in their apps. On the webdev side, Fiddler is a popular tool for debugging and security tracking. For the beginner, OWASP’s iGoat tool is an intentionally flawed app allowing the developer to explore and implement fixes to common security problems in a safe learning environment.

5. Allow for strong user passwords and authentication. Never store passwords in plain text format, as it undercuts any other security measures. Instead, salt and hash passwords and force users to reset forgotten passwords instead of going through a retrieval process. Additionally, avoid limiting the password length or variety, and if an arbitrary length must be used, use something well beyond the norm. When it comes to loading login pages, load the forms over HTTPS and post to HTTPS as well. Loading over HTTPS and then posting with HTTPS still leaves the login form vulnerable and open to MITM attacks. Better yet? HTTPS everywhere.

6. Implement robust data encryption and transfer protocols. In terms of cryptography, avoid storing any data directly on the device if relying on iOS’ AES 256 encryption, as it can be retrieved rather easily. Instead, developers should leverage database encryption like SQLCipher and transfer information with HTTPS and SSL pinning to prevent MITM attacks. On the server side, use tools like Nessus for vulnerability tracing and the NIST vulnerability checklist database and standards when configuring servers and web frameworks.

7. Establish a bug bounty program, and open disclosure policies. What is particularly surprising from the last two weeks was the initial lack of interest in security practices within the health IT and mHealth communities and the lack of interest in peer review when it comes to public security audits. Security strategy doesn’t end with deployment. Keep lines of communication with users and developers open and honest. It’s interesting to note that Silicon Valley has cultivated a robust white-hat community, encouraging exploit bounties for discovery, while enterprise health IT and the mhealth community lag behind. Bugcrowd’s current list of available security bounty programs includes companies such as Amazon, Apple, Facebook, Oracle and IBM to smaller startups like Spotify and Gittip, but no pure healthcare platforms. Typical bounty programs focus on specific aspects of a program or on either security mitigation bypass or defense and may range in reward from $300 to $50,000 or more (as is the case for Microsoft’s program). For many, though, it’s not about the
For many, though, it’s not about the money, and more about the challenge, recognition and community.
8. Know the applicable regulations. Understand what regulatory standards your app may be held to, and thoroughly vet potential partner companies for adherence. This is particularly important in the changing healthcare landscape, where subtle differences in branding and marketing may dictate different levels of government compliance and run the potential for significant fines in the event of a data breach. Also note that security is only one tool for ensuring privacy, and in addition to a comprehensive security strategy, mhealth developers must address the concerns of privacy regulations such as COPPA and HIPAA.

9. Assign responsibility. Make one person in your team responsible for security, privacy and compliance at every stage of development. There’s a tendency to assume someone else is automatically handling security (be an OS, a device manufacturer or another team member, etc.), but holding a single person accountable helps bring the priority forward. This person will be instrumental in understanding the limitations of platform security measures, libraries, APIs and any third party code your app may employ.

10. Be an example. For users, particularly health IT and mhealth community members, be an example of good personal security practices and hold the companies you use to a higher standard. Critically evaluate the necessity of permissions you grant a program, and don’t install apps outside of official OS app stores. Watch out for claims that seem too good to be true or are built on closed, untested or in-house security protocols. Update passwords often, and use a password manager like LastPass and two-factor authentication when available. Enable remote wipe on your device and back up your information regularly. Also consider developing an alternative fake personal dataset since, thanks to Facebook, everyone knows your favorite pet, first car and mother’s maiden name. You’ll know you’re paying enough attention to mobile security when the thought of installing that hot new app makes you a little twitchy.

Monday, November 18, 2013

Check Out the Lastest News on SILO for Web Application Security

                                               authenic8.com

In this age of security leaks and hackers businesses are always looking for promising systems that can protect data and employee devices.

A new company, Authenic8 , has developed the product "Silo". This Silo app has a highly secure containment.  Silo stands out because mobile employees it is valuable when using personal devices over insecure networks.

Authentic8 stated the following their launch of Silo.  "Each time they launch Silo, users get a freshly built browsing environment with SSO links to provisioned apps. All web code is contained within Silo, meaning apps are insulated from exploits, and business data is kept separate from personal browsing. Users interact with a benign display of the web app, keeping all web code off the device. And at session end Silo is destroyed along with all transient browsing data, leaving the device and server stateless. With Silo, your web apps live beyond the reach of network, client-side or web borne exploits."

Ken Hess for Consumerization asked the team of  Authentic8 the following question.:
"What happens if the user hits a site that's been compromised? Can it have any negative affect on the user's device?"
The team answered:
The answer is, "No". And the reason is that your web application isn't running on your device. It runs in the cloud, in a sandboxed environment. Your device is not directly attached to the web service in any way. So, imagine the worst, most devious virus or malware possible that's infected a site that you have setup to access in Silo.

 Watch a video demonstration of Authenic8's Silo in action.

http://www.zdnet.com/authentic8s-silo-the-ultimate-security-solution-7000023271/

Wednesday, November 6, 2013

Crummy Passwords is the Reason that Adobe was HACKED!

                                           news.mindprocessors.com 

This following article should be a wake-up call to computer users in selecting their passwords. Knowing that persons use the same password for every login that they use is opening the door for security breaches and hackers getting your personal information. 




Despite the endless warnings, despite all the advice, despite the plethora of useful articles on the matter, it seems computer users everywhere just can’t help creating really crummy passwords.

Analysis of user passwords gathered from the recent Adobe attack reveal a Top 20 list full of easy-to-remember but equally easy-to-guess passwords, with “123456” topping the chart.

The Adobe hack affected 38 million accounts, though this figure relates only to active users. The security breach actually hit more than 150 million accounts, though most are no longer used.

Adobe has changed passwords on affected accounts and contacted users to let them know how to reset their account with a personally chosen password. It also instructed users to change their passwords on any other website where they may have used the same user ID and password as their Adobe account.

Some of the stolen data has started to show up across the Web, with Internet security researcher Jeremi Gosney uncovering a mass of passwords, despite the U.S. software giant saying they were protected by encryption. However, an Adobe spokesperson said last week that up to now there have been no reports of suspicious activity on user accounts affected by the security breach.

Now that you know “123456” topped the list of 1.9 million passwords, perhaps you can guess what came in at number 2…..“123456789.” Number 3 will be enough to make any Web security advisor consider giving up the day job in despair: “password.”

Crummy passwords



Here are the rest of the top 20 most popular passwords gathered from the Adobe hack: adobe123 / 12345678 / qwerty / 1234567 / 111111 / photoshop / 123123 / 1234567890 / 000000 / abc123 / 1234 / adobe1 / macromedia / azerty / iloveyou / aaaaaa / 654321

The thing is, if someone uses a number like “123456” for their password on one site, it’s a safe bet they use the same number on all the websites for which they have accounts, as you’d only get confused if you had a different number for each site – unless, of course, you keep all your passwords in a big red notebook with “MY PASSWORDS” written on the front. And those who have “adobe123″ as their password no doubt also use “facebook123”, “twitter123”… you get the idea.

Gosney said he’s currently unable to verify the passwords he uncovered, though he’s “fairly confident” of the list’s accuracy. To find out more about how he collected the data, and to see the top 100 passwords as selected by Adobe users, click here.

Meanwhile, if, after looking through the list above, a bead of sweat has formed on your brow as you start to realize how ridiculously simple your passwords are (or should we say “password is”?), then check out this article to find out how to create something a little more secure. Or get an app to help you.

Wednesday, September 25, 2013

Advice to Protect eCommerce Website Availablilty and Security in the Holiday Shopping SeasonRe

                                         Gareth Hoyle


Retailers cannot afford for their eCommerce website to have any malfunctions during the upcoming Holiday season. What should these internet retailers do to ensure that they do not lose money due to security problems or a website outage?  Great advice on the internet has been found to share!

Prepare for the Worst and Plan for the Best

To ensure website availability and security , online retailers must prepare for the worst through escalation and incident response planning by outlining standard operating procedures for down time, including establishing and training incident-response teams. They should also monitor their site diligently to determine service health
and identify anomalies quickly and accurately, as well as provide failover to back-up IP addresses to ensure the site is always available.


Improve Your Infrastructure

Optimize the scalability and performance of your internet infrastructure with demonstrated management of increased traffic load coming your way during the holiday shopping season. Whether you manage your site internally of through a vendor, a track record maintaining satisfactory service levels during the rest of the year may not be a reliable indicator that service level can be maintained during the peak holiday traffic season. If scalability and performance of your infrastructure are not optimized, it could damage you sales revenue and reputation at the worst possible time.


Don't Forget About DDoS

With the increase in size and complexity of distributed denial of service (DDoS) attacks, companies should consider leveraging upstream service providers to protect both Web servers and DNS. If either goes down, a company could be out of business. A cloud-based approach to both DNS management and DDoS protection provides a cost-effective alternative to maintaining uptime.

\
Implement Security Best Practices By Partnering With a Security Provider for Holistic Support

Not all ecommerce sites can develop an internal cyber intelligence capability. Security service providers can help to quickly identify and understand the various security incidents and their implications,determine effective mitigation and remediation tactics, and develop a clear plan to enhance security.

There are very good security support providers out there on the web.  Do research based on product reviews and pricing that you can afford.


http://www.circleid.com/posts/20130925_tips_protect_ecommerce_website_availability_security_in_holiday/


Thursday, August 29, 2013

How Will "Trsst" Standout Over "Twitter" in It's Development?






                                          Michael Powers is the Developer Behind Trsst





'The PRISM revelations have made people more concerned about privacy and security. So now is the time to give people an alternative’


— Michael Powers





Michael Powers wants to do what so many others have failed to do: build an online social network that’s outside the grip of any one company — and that people like you will actually use.

We’ve seen countless underground hackers build decentralized alternatives to Facebook and Twitter over the years, but so far these open source contraptions have failed to attract anything close to the number of people who use Facebook and Twitter and other commercial services almost constantly. But Powers, a serial entrepreneur based in Washington, D.C., thinks he can finally crack the code.

His project is called Trsst, a name that’s meant to engender a sense of trust, and after a summer when NSA leaker Edward Snowden opened the curtain on modern government surveillance, the Trsst message is particularly timely. “The PRISM revelations have made people more concerned about privacy and security,” Powers says. “So now is the time to give people an alternative.”

Although Powers hopes to make the system as easy to use as Twitter, it includes some pretty geeky tools under the hood, including many that provide added security. For example, all “direct messages” sent through Trsst will be encrypted, and all messages can be “signed” so that you’ll know the messages are authentic and haven’t been tampered with.

In this way, Trsst is less like Diaspora and more like Mailpile — an open source email client with an emphasis on security that recently raised $100,000. “We want the average user to encrypt more,” Powers says. “If everyone encrypted everything then the bad guys wouldn’t know where to look.”

It’s important to note, however, that nothing offers perfect privacy. Rainey Reitman, the director of the activism team at the Electronic Frontier Foundation, says that common email encryption systems may keep the contents of messages protected, but they might expose other information, such as when and to whom messages were sent. Other tools, such as the OffTheRecord chat system or The New Yorker’sDeadDrop file-sharing system, may be better for some tasks.

Others worry about trying to bolt encryption systems onto existing systems like RSS. “I’m happy it’s focused on decentralized and federated communication, because that is essential for spreading out risk,” says Brett Slatkin, an engineer at Google and co-developer of the open source cloud storage system Camlistore. “I’m worried they’re trying to build too much all at once. Security is extremely hard to get right and you need to vet a design like this.”

But Powers is at least starting in the right place. Trsst is more of a protocol than a piece of software. It’s an extension to existing standards, a system for sending messages between autonomous servers. “It’s not rocket science. It’s basic 10-year-old technology, but it’s about how you combine them,” he says.

That may leave you wondering why he needs $48,000 to build it. Powers says the main reason he’s raising money is not to pay his salary — though he does have quite a bit of technical work to do, even if he is drawing on older work. He says he’s raising funds because he wants to make sure there’s really a demand for a system like Trsst.

“If you believe in it,” he sats, “back it.”

http://www.wired.com/wiredenterprise/2013/08/trsst/











Monday, August 12, 2013

Web Developers Are Happy Today To Hear the News of Apple Restores Website Outage

Can you imagine that Apple,the tech giant, had an outage with the their software developer's website?  On Saturday the portal which is essential for developers was back online after 23 days.




                                                                  Business Insider







Apple sent out an email to all registered developers, apologizing for the service outage.

The final restoration comes five days after Apple announced plans to have the portal at full capacity by the end of the week.

Developers now can check the status page via a link on the homepage to confirm that all functions essential for software development are back online.

According to the email sent to developers, to make up for the prolonged outage of some of the services, Apple will extend all memberships, which are usually for a year, by one month.

Apple’s software developer’s website, which also hosts its iOS and OS X beta downloads, went down on July 18 and a few days after, the company acknowledged that there had been a security breach.

No sensitive personal information was accessed, Apple said at the time, but it could not rule out that the intruders had gained access to developers’ names and mailing and email addresses.

The outage caused outrage in the developer community, for many of them were unable to enable new devices to run pre-release versions of Apple's software or test out new apps.

The downtime also came as Apple pushed developers to test and create software for upcoming versions of iOS and Mac OS X, both of which are expected this fall.

Apple began to bring back many key services on July 26, after more than a week of downtime. Essential services for software development on iOS, Mac, and Safari platform, were given the priority in restoration, alongside downloads for upcoming versions of Apple's desktop and mobile software.

Apple has yet to reveal the identity of those responsible for the self-imposed downtime, but one researcher claimed responsibility shortly after the outage began in July, saying that it was just a test for security instead of an intended crime.
 http://www.globaltimes.cn/content/803291.shtml#.UgjprW2HoSI


Thursday, August 8, 2013

A Web Developer Finds a Big Security Leak With a Top Web Browser





The very popular Google Chrome does not provide the password protection that is needed for your security. Sure it's great that when using Chrome they save your password so when you choose to visit a social media site you do not have to type password again. This service for users comes with security problems.
The security problem is that when another person uses your computer they have access to all of your saved passwords. On August 7th Elliot Kember,a web developer, reported the security problem in a blog post.

To understand how easily it is for anyone can get your passwords in chrome then just follow these directions.

Copy and paste "chrome://settings/passwords" into Chrome and hit "Enter," to see Chrome's page for managing passwords. This window will pop up:


   You should never allow anyone that you do not trust to have access to your computer. We all haveinformation that we want guarded from others.  Being informed  is your saving grace.