Friday, 30 August 2013

Security researchers prove Dropbox is hackable

Dropbox logo
Developers have released a paper detailing how to bypass two-factor authentication security in cloud storage service Dropbox.
The paper was released by Openwall's Dhiru Kholia and Code Painters' Przemyslaw Wegrzyn and details techniques to sneak past Dropbox's two-factor authentication to intercept SSL data from the company's servers. The two researchers claim to have discovered the exploit by reverse engineering Dropbox's source code.
"We show how to unpack, decrypt and decompile Dropbox from scratch and in full detail. This paper presents new and generic techniques to reverse engineer frozen Python applications," wrote Kholia and Przemyslaw.
The pair claim to have bypassed Dropbox's security using a custom-built, open-source Dropbox client. They said the technique is fairly basic but dangerous as, if misused, hackers can steal data from Dropbox and hijack unwary users' accounts.
"Our work uses various code-injection techniques and monkey-patching to intercept SSL data in [the] Dropbox client. We have used these techniques successfully to snoop on SSL data in other commercial products as well," read the paper.
Last year Dropbox was forced to add two-factor authentication after millions of its users were spammed following a successful cyber attack on its systems.
A Dropbox spokesperson told to V3 the company is aware of the research, but downplayed its significance, clarifying the exploit only works if the user's main machine is already compromised.
"We appreciate the contributions of these researchers and everyone who helps keep Dropbox safe. However, we believe this research does not present a vulnerability in the Dropbox client. In the case outlined here, the user's computer would first need to have been compromised in such a way that it would leave the entire computer, not just the user's Dropbox, open to attacks across the board," said the spokesperson.

The paper added: "We hope that our work inspires the security community to write an open-source Dropbox client, refine the techniques presented in this paper and conduct research into other cloud-based storage systems."
Kholia and Wegrzyn are two of many to publicly publish exploits on big-name services and technologies in recent weeks. Renowned hackers Charlie Miller and Chris Valasek released tools capable of hijacking control of moving cars to the general public at the Defcon expo in Las Vegas at the beginning of August.

Aberdeen Council fined £100,000 by ICO after children’s data posted online

money-pound-notes2
The Information Commissioner’s Office (ICO) has fined Aberdeen City Council £100,000 after a member of staff inadvertently posted data relating to the care of vulnerable children online.
The incident occurred in November 2011 when a member of staff accessed a batch of documents on their home computer from the council's network. These documents were then automatically uploaded to the web by a program installed on the machine.
The information was subsequently found in February 2012 by a council member who was mentioned in one of the documents that had been uploaded. They informed the council and the data was removed and the ICO informed.
The member of staff responsible told the ICO the software that uploaded the data must have been installed by the previous owner of the computer as she was not aware of what had happened.
“The employee told the data controller that the computer is second hand and that it must have been installed by a previous owner,” the report by the ICO reads.
The report also noted that the council had no relevant home-working policy and no sufficient measures in place to restrict the access of sensitive information from the council’s network.
Ken Macdonald, assistant commissioner for Scotland at the ICO, said the incident should make all social work departments in councils "sit up and take notice" of the issues raised around home working and data protection.
“As more people take the opportunity to work from home, organisations must have adequate measures in place to make sure the personal information being accessed by home workers continues to be kept secure,” he said.
“In this case Aberdeen City Council failed to monitor how personal information was being used and had no guidance to help home workers look after the information.”
Aberdeen City Council said it takes data protection extremely seriously, which is why it reported the matter to the ICO itself when it came to light, and claimed it was making improvements on its policies. The council made no direct comment on the fine.
"A data protection audit report on the City Council by the ICO this summer found that a comprehensive suite of up-to-date data policies are in place, strong arrangements are in place concerning a wide range of routine data-sharing, and the content of data protection and information security training material used by Aberdeen City Council is detailed and thorough."
The fine is the latest of many to be imposed by the ICO against councils for poor data-handling procedures, with Islington Council fined £70,000 for an issue relating to Excel that caused 2,000 residents' details to be leaked online.