<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Web Security Blog</title>
	<atom:link href="http://securetty0.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securetty0.wordpress.com</link>
	<description>Web Security with a focus on Ruby on Rails, Linux &#38; PHP</description>
	<lastBuildDate>Mon, 08 Mar 2010 01:13:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='securetty0.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Web Security Blog</title>
		<link>http://securetty0.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://securetty0.wordpress.com/osd.xml" title="Web Security Blog" />
	<atom:link rel='hub' href='http://securetty0.wordpress.com/?pushpress=hub'/>
		<item>
		<title>XBox Security Hardware Chip Hacked</title>
		<link>http://securetty0.wordpress.com/2010/03/08/xbox-hardware-chip-hacked/</link>
		<comments>http://securetty0.wordpress.com/2010/03/08/xbox-hardware-chip-hacked/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 01:11:22 +0000</pubDate>
		<dc:creator>whatevergoeson</dc:creator>
				<category><![CDATA[hacks]]></category>

		<guid isPermaLink="false">http://securetty0.wordpress.com/?p=25</guid>
		<description><![CDATA[An Infineon-based chip that Microsoft uses to ensure licensing compliance on XBox third-party manufacturers has recently been hacked. According to The Record, &#60;&#60;Hardware hacker Christopher Tarnovsky just wanted to break Microsoft&#8217;s grip on peripherals for its Xbox 360 game console. In the process, he cracked one of the most heavily fortified chips ever put into [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=25&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An Infineon-based chip that Microsoft uses to ensure licensing compliance on XBox third-party manufacturers has recently been hacked.</p>
<p>According to The Record,</p>
<p>&lt;&lt;Hardware hacker Christopher Tarnovsky just wanted to break Microsoft&#8217;s grip on peripherals for its Xbox 360 game console. In the process, he cracked one of the most heavily fortified chips ever put into a consumer device.</p>
<p>The attack by the former US Army computer-security specialist is notable because it goes where no hacker has gone before: into the widely used Infineon SLE 66PE, a microcontroller that carries the TPM, or <a href="http://www.trustedcomputinggroup.org/certification/tpm_certification" target="_blank">Trusted Platform Module</a> (<a href="http://www.trustedcomputinggroup.org/certification/tpm_certification" target="_blank">http://www.trustedcomputinggroup.org/certification/tpm_certification</a>) designation of security. The hack means he can access sensitive data and algorithms locked away in the chip&#8217;s digital vault and even make counterfeit clones that could fool the many devices that rely on it.</p>
<p>&#8220;I can get inside this chip without killing it and I can get through all the security countermeasures it has in place, physical and in software,&#8221; Tarnovsky, who is principal engineer for Flylogic, told <em>The Register</em> in an interview that covered many of the behind-the-scenes elements of the hack.</p>
<p>Its genesis came when Tarnovsky learned that manufacturers of video game controllers had to obtain a license from Microsoft for the peripherals to work on the Xbox 360. The requirement offended his sense of fair play, so he put his reverse engineering muscle to breaking it.</p>
<p>&#8220;I was very surprised they would put a security chip in a wired controller, as well as a wireless controller,&#8221; he said. &#8220;It&#8217;s very monopolistic what they&#8217;ve done. They have a right to do it, but I have a right to break it too.&#8221;</p>
<p>After dissecting a controller, he found that the chip that allowed it to communicate with the Xbox was made by Infineon. He eventually purchased dozens of related microcontrollers on the Hong Kong surplus market for 15 cents apiece.</p>
<p>He then employed an electron microscope called a focused ion beam workstation (price tag $250,000 used) that allowed him to view the chip in the nanometer scale so he could manipulate its individual wires using microscopic needles.</p>
<p>It took Tarnovsky four months to develop techniques for probing the chip and another two months to apply them to breaking the 66PE.</p>
<p>What he found was a chip that was locked down with multiple levels of defenses. Optical sensors, for instance, were designed to detect ambient light from luminous sources. And a wire mesh that covered the microcontroller was aimed at disabling the chip should any of its electrical circuits be disturbed.</p>
<p>&#8220;One wrong move and I vaporize a track on the chip,&#8221; Tarnovsky said.</p>
<p>Indeed, some 50 of the chips were vaporized in the course of the hack. But over time, he learned how to use the needles to penetrate the chip&#8217;s inner recesses so he could tap sensitive data that remains unencrypted so it can be processed.</p>
<p>Using the tungsten as microscopic bridges, Tarnovsky said, he can digitally clone chips used to prevent piracy of satellite TV service, to disable unauthorized cartridges in printers &#8211; or to make Xbox game controllers.</p>
<p>&#8220;You could counterfeit this chip,&#8221; he said, although he stressed he had no plans to use the hack for illegal purposes.</p>
<p>In a statement sent to Infineon customers last week, the company noted the time and expense required for Tarnovsky to crack the chip. But the company went on to say it was a sign of attacks to come and said engineers were already working on a more secure successor to the 66PE.</p>
<p>&#8220;In contrast to conventional solutions, the SLE 78 family now utilizes encryption even in the CPU itself, leaving no plaintext for the attacker,&#8221; the release stated. &#8220;Technical advances of that scale are only possible if the CPU itself is designed &#8216;from the scratch&#8217; by the hardware manufacturer with security in mind, right from the beginning.&#8221;</p>
<p>The physical attack on the 66PE is similar to hacks cryptographers have recently waged on proprietary encryption algorithms in <a href="http://www.theregister.co.uk/2010/02/08/dect_phone_encryption_cracked/" target="_blank">cordless phones</a>(<a href="http://www.theregister.co.uk/2010/02/08/dect_phone_encryption_cracked/" target="_blank">http://www.theregister.co.uk/2010/02/08/dect_phone_encryption_cracked/</a>) and the <a href="http://www.theregister.co.uk/2008/03/12/mifare_classic_smartcard_crack/" target="_blank">world&#8217;s most popular smartcard</a> (<a href="http://www.theregister.co.uk/2008/03/12/mifare_classic_smartcard_crack/" target="_blank">http://www.theregister.co.uk/2008/03/12/mifare_classic_smartcard_crack/</a>). In all of them, the secret formula was lifted after sanding down the chips&#8217; silicon and examining its circuitry using an electron or optical microscope.</p>
<p>&#8220;More and more things are moving to hardware, and as things move to hardware, people are analyzing these devices and getting the algorithms out and putting them back in the software,&#8221; Tarnovsky said.</p>
<p>While the risks of physical attacks are in many cases inevitable, he said the cracking of the 66PE was aided by its abundant supply on international surplus markets, which is something Infineon may want to consider as it readies its new generation of ultra-secure microcontrollers.</p>
<p>&#8220;If this is supposed to be such a secure device and it&#8217;s <a href="http://www.commoncriteriaportal.org/thecc.html" target="_blank">common-criteria certified</a> (<a href="http://www.commoncriteriaportal.org/thecc.html" target="_blank">http://www.commoncriteriaportal.org/thecc.html</a>), why are they available on the used surplus market?&#8221; he said. &#8220;This device should not have been readily available for a researcher like me.&#8221; ® &gt;&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securetty0.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securetty0.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securetty0.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=25&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securetty0.wordpress.com/2010/03/08/xbox-hardware-chip-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bc41ebab54cc0e0fbe99d753876d45ce?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">whatevergoeson</media:title>
		</media:content>
	</item>
		<item>
		<title>Top technology and security trends for 2010</title>
		<link>http://securetty0.wordpress.com/2010/01/31/top-technology-and-security-trends-for-2010/</link>
		<comments>http://securetty0.wordpress.com/2010/01/31/top-technology-and-security-trends-for-2010/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 20:30:12 +0000</pubDate>
		<dc:creator>whatevergoeson</dc:creator>
				<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://securetty0.wordpress.com/?p=11</guid>
		<description><![CDATA[A recent article in Baseline magazine talks about the 10 technology trends predicted for 2010. http://www.baselinemag.com/c/a/IT-Management/10-Trends-for-2010-Piecing-Together-a-Technology-Strategy-190963/ Security is ranked at number 7 in terms of concerns but not in terms of spending. Thus, over 70 percent of the surveyed companies expect little or no further investment in security, in an environment in which security risks [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=11&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste" style="text-align:justify;">A recent article in Baseline magazine talks about the 10 technology trends predicted for 2010.</div>
<div id="_mcePaste" style="text-align:justify;">http://www.baselinemag.com/c/a/IT-Management/10-Trends-for-2010-Piecing-Together-a-Technology-Strategy-190963/</div>
<p style="text-align:justify;">
<div id="_mcePaste" style="text-align:justify;">Security is ranked at number 7 in terms of concerns but not in terms of spending. Thus, over 70 percent of the surveyed companies expect little or no further investment in security, in an environment in which security risks are estimated to be on an exponential increase. According to statistics by Association for Computer Operations Management (AFCOM), 20 percent of data centers don&#8217;t even have time to screen employees. The lack of spending is justified partly by the recessionary environment, and partly by an reactive attitude when things aren&#8217;t taken seriously until disaster strikes. Security is, in that area, similar to other fields of IT.</div>
<p style="text-align:justify;">
<div style="text-align:justify;">Another, more detailed, look into this subfield is provided by an article in InfoWorld that looks at the top security predictions for 2010.</div>
<div id="_mcePaste" style="text-align:justify;">http://www.infoworld.com/t/business/top-security-predictions-2010-523?source=rss_infoworld_news</div>
<p style="text-align:justify;">
<div style="text-align:justify;">This time, the study finds a slight overall increase (10%) in funding allocated to security as one of the top trends.</div>
<div id="_mcePaste" style="text-align:justify;">New compliance measures driven by government regulation is another trend that is sure to happen, given the recent financial meltdown.</div>
<div id="_mcePaste" style="text-align:justify;">Mobile security will become worse, as the number of mobile devices proliferate. The recent announced introduction of the Apple iPad tablet is just one of the major mobile events that we are seeing, that expand the reach of mobile devices.</div>
<div id="_mcePaste" style="text-align:justify;">As cloud computing becomes more widely adopted, it will likely see significant enhacements this year such as encryption and possible &#8220;pay per minute&#8221; security features from cloud providers such as Amazon EC2.</div>
<div id="_mcePaste" style="text-align:justify;">Desktop Virtualization appears as the 6th trend, as employers start consolidating desktop environments into virtual machines that can be more easily managed and controlled.</div>
<div id="_mcePaste" style="text-align:justify;">Government pressure on individuals to provide confidential details is seen as the seventh prevailing trend for 2010.</div>
<div id="_mcePaste" style="text-align:justify;">The death of the nationwide identity (Real ID) concept is predicted and ranked at number 8 due to the serious security risks such a system would entail which will only become more obvious.</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securetty0.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securetty0.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securetty0.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=11&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securetty0.wordpress.com/2010/01/31/top-technology-and-security-trends-for-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bc41ebab54cc0e0fbe99d753876d45ce?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">whatevergoeson</media:title>
		</media:content>
	</item>
		<item>
		<title>Hackers Network Led to Losses in the &#8220;Tens of Millions&#8221;</title>
		<link>http://securetty0.wordpress.com/2010/01/22/crackdown-on-bad-hackers/</link>
		<comments>http://securetty0.wordpress.com/2010/01/22/crackdown-on-bad-hackers/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 21:02:23 +0000</pubDate>
		<dc:creator>whatevergoeson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securetty0.wordpress.com/?p=3</guid>
		<description><![CDATA[A couple of news sources reported recently on the apprehension of hackers behind a 2000+ member hackers forum that went by the name DarkMarket According to http://www.scmagazineus.com/darkmarket-mastermind-pleads-guilty/article/161483/ &#8220;A Sri Lankan man living in London admitted this week to being the mastermind behind the online hacker forum DarkMarket, which has been called one of the most [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=3&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of news sources reported recently on the apprehension of hackers behind a 2000+ member hackers forum that went by the name DarkMarket</p>
<p>According to http://www.scmagazineus.com/darkmarket-mastermind-pleads-guilty/article/161483/</p>
<p style="padding-left:30px;">&#8220;A Sri Lankan man living in London admitted this week to being the mastermind behind the online hacker forum DarkMarket, which has been called one of the most nefarious criminal websites in the world. [...]</p>
<p style="padding-left:30px;">The cases resulted from an <a href="http://www.scmagazineus.com/border-crossing-fighting-international-cybercrime/article/148562/">international investigation</a> involving the FBI, the U.S. Secret Service and SOCA, and has been heralded as one of the biggest anti-cybercrime success stories to date, resulting in more than 60 arrests worldwide.&#8221;</p>
<p>According to the financial times:</p>
<p style="padding-left:30px;">&#8220;DarkMarket was set up by Mr Subramaniam and others in late 2005 as a private online community where trusted members could sell credit card and bank account details in the same way as legal goods are traded on auction sites such as Ebay. The US Federal Bureau of Investigation and the UK’s Serious Organised Crime Agency estimate the information sold by the forum’s 2,000 criminal members led to losses of tens of millions of pounds for banks and individuals.&#8221;</p>
<p>One thing people should be aware of is that, while this is one of the most publicized cases, many similar underground forums exists. Online fraud is estimated to cost the world over 75 billion dollars per year. Seeing the tip of the iceberg helps to bring awareness to businesses about the importance of information security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securetty0.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securetty0.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securetty0.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securetty0.wordpress.com&amp;blog=11598604&amp;post=3&amp;subd=securetty0&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securetty0.wordpress.com/2010/01/22/crackdown-on-bad-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bc41ebab54cc0e0fbe99d753876d45ce?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">whatevergoeson</media:title>
		</media:content>
	</item>
	</channel>
</rss>
