Cybersecurity Tips

Share this post

🔑 FIDO's time to shine and NPM wild wild west - Newsletter #3

cyb3rsecurity.tips

🔑 FIDO's time to shine and NPM wild wild west - Newsletter #3

Also the privacy struggles of the European Union to protect children and not brake encryption

Nuno
Jun 6, 2022
1
Share this post

🔑 FIDO's time to shine and NPM wild wild west - Newsletter #3

cyb3rsecurity.tips

Happy Monday,

After a couple of weeks of vacation, we’re back in business. This month, we take a look at a FIDO initiative at Big Tech and how package managers are broken. On Privacy, we try to understand the EU initiative to fight child sexual abuse images that could mean breaking end-to-end encryption.

This month's Cybersecurity weather forecast

  • The Russia - Ukraine conflict is still causing damage on both sides. This time the Russians are linked to a new Brexit leak. We should expect more activity coming that way as the war continues (more than 100 days now).

  • There was a 150% rise in ransomware attacks from April 2020 to July 2021. ENISA has described the threat picture as the “golden era of ransomware”. This is partly due to attackers’ many monetisation options. This means that Ransomware still represents a high risk.


Thank you for reading Cybersecurity Tips. This post is public so feel free to share it.

Share


Apple, Google, and Microsoft pledge to extend FIDO support

Apple, Google, and Microsoft will roll out no-password login options over the coming year, per the Fast Identity Online (FIDO) Alliance. This is a joint effort to fight the password-only login that is reported by Apple as “one of the biggest security problems on the web”.

https://i.pinimg.com/originals/0a/a9/52/0aa952dca107a1bd568deced9f39b3fe.jpg

First of all, what is FIDO?

The FIDO ("Fast IDentity Online") Alliance is an open industry association whose mission is to develop and promote authentication standards that "help reduce the world’s over-reliance on passwords". They have developed a standard together with the World Wide Web Consortium that allows websites and apps to offer “consistent, secure, and easy passwordless sign-ins to consumers across devices and platforms”.

And how does it work?

FIDO uses the principles of public-key cryptography to enable passwordless and multi-factor authentication in a range of contexts. A user’s phone can store a unique FIDO-compliant passkey and will share it with a website for authentication only when the phone is unlocked.

Here’s an example of how it would work, assuming you are registering on a new website:

  1. When you register on a new website, a key pair is generated: a public key shared with the website and a private key that stays on your phone.

  2. When you try to log in, the website will ask you to confirm on your phone.

  3. If you have the right key, it will allow you in.

Trivia: one survey found that while 85% of respondents wanted to use fewer passwords, 72% believed others would stick with passwords because it’s familiar.

Sources:

  • Apple

  • FIDO Alliance

Pwn the world

This is frightening but cool:

Twitter avatar for @cyb3rops
Florian Roth 🏔 @cyb3rops
Pwn the world mastodon.social/@lrvick/108274

Image
10:54 AM ∙ May 10, 2022
973Likes235Retweets

It’s not clear which “foreach” package he’s talking about because the top one has 130 dependents and not 36k, but it’s still something to think about. As someone says in the comments: this YOLO package management systems are fundamentally flawed.

EU’s problem with privacy to protect children

Privacy activists are sounding the alarm over the European Commission's plans to attack online child abuse, warning that it would result in "mass surveillance".

A member of the European Digital Rights group posted on Twitter that the proposal looks “shameful” and “entirely unfitting for any free democracy.”

Twitter avatar for @ilumium
Jan Penfrat @ilumium@mastodon.cloud @ilumium
Here is the first leak I've seen from the Commission's upcoming "we-will-break-into-everyone's-private-chats" law. #CSAM This looks like a shameful general #surveillance law entirely unfitting for any free democracy.
Twitter avatar for @moritzkoerner
Moritz Körner @moritzkoerner
đŸ’„ Zensursula ist zurĂŒck! Von der Leyen will staatliche SchnĂŒffelsoftware bereitstellen und Unternehmen verpflichten, ihre User zu ĂŒberwachen. Sie will Netzsperren in allen EU-Staaten und mit Hilfe einer europĂ€ischen Big-Brother-Agentur die Onlinewelt ĂŒberwachen. Hier im Detail: https://t.co/Rzuh9VtCtJ
12:04 PM ∙ May 10, 2022
17Likes9Retweets

The problem

The new law obliges companies to detect, report and remove child sexual abuse, a demand that comes with the responsibility to monitor encrypted content. This means that companies would be obliged to create backdoors on the end-to-end encryption mechanisms, which are available in tools like WhatsApp.

For Zach Meyers, Senior Research Fellow at the Centre for European Reform (CER) think tank, the Commission's plan "clearly undermines end-to-end encryption."

"Once a “backdoor” to undermine encryption exists, that will create both new security vulnerabilities for hackers, and inevitable political pressure to expand the “backdoor” so that it covers more than just child sexual abuse material over time," Meyers added.

Sources:

  • Bloomberg

  • Euronews


🍗 Nuggets

  • A Guide to Zero Downtime Migrations

  • The Heroku incident is still ongoing. They’ve also learnt something from it

  • Top-500 NPM package maintainers now require 2FA

  • OVH Cloud fire class action reaches 140 clients, seeks more than €10m - we wrote about this a month ago

  • Thousands of popular websites see what you type before you hit submit


⏭ Next week

Are you trying to remain private while surfing the web? If so, to what extent should you be doing it? what efforts are enough and what not? we will review some methods, techniques and tips to keep your privacy online.

Share this post

🔑 FIDO's time to shine and NPM wild wild west - Newsletter #3

cyb3rsecurity.tips
Previous
Next
Comments
TopNewCommunity

No posts

Ready for more?

© 2023 Nuno Batista
Privacy ∙ Terms ∙ Collection notice
Start WritingGet the app
Substack is the home for great writing