Search Term:
Your Ad Here
Showing posts with label computer technology. Show all posts
Showing posts with label computer technology. Show all posts

Informatics students discover, alert Facebook to threat allowing access to private data, bogus messaging

http://cdn.physorg.com/newman/gfx/news/informaticss.jpg
A Facebook security vulnerability discovered by a pair of doctoral students at Indiana University Bloomington's School of Informatics and Computing that allowed malicious websites to uncover a visitor's real name, access their private data and post bogus content on their behalf has been repaired, Facebook has confirmed.
The vulnerability discovered by Rui Wang and Zhou Li enabled malicious websites to impersonate legitimate websites, and then obtain the same data access permissions on Facebook that those legitimate websites had received.
Wang and Li said the vulnerability occurred when a user informed Facebook of his or her willingness to share information with popular websites like ESPN.com or YouTube. Whenever a website makes such a request to Facebook via the user's browser, Facebook passes a secret random string called an authentication token back to the requestor for identification. Whoever holds that authentication token can convince Facebook that they are, say, ESPN.com and then gain unfettered access to the shared data.
Facebook confirmed the discovery and in a statement said the problem was repaired and that the belief was that no sites had been compromised.
"Researchers at Indiana University reported a vulnerability in our Platform code to us, and we worked quickly with them to resolve it. It was fixed shortly after it was reported. We're not aware of any cases in which it was used maliciously," the statement said. "We thank the researchers at Indiana University for bringing this to our attention, and for demonstrating the value of responsible disclosure."
The researchers identified a flaw in the way the token was transmitted using two Flash objects: one inside Facebook's iframe passes the token to the second, which in this case would be embedded at ESPN.com. The transfer mode can be selected through "transport='flash'" with the security guarantee being that both flash objects are supposed to come from the same domain (i.e., Facebook) before they can talk.
The researchers found, however, that such a same-domain assumption is not always valid because Adobe Flash allows cross-domain communication with an unpredictable domain name that is prepended by an underscore symbol in the connection name. This allows an attacker website to steal an authentication token by choosing the transport='flash,' replacing the receiver flash with its own and then initiating a cross-domain communication with the flash inside the Facebook-controlled iframe to get the token and send it to the attacker's flash.
"This vulnerability has several implications," Wang said. "Basically, any user with a valid Facebook session loses anonymity and privacy to any website, even one with embarrassing or sensitive content."
Facebook allows some websites like bing.com to directly access a user's public data without explicit consent. This enables the malicious website impersonating that site to do the same. Moreover, if the user has ever granted any website, such as The New York Times, YouTube, Farmville or ESPN, the permission to connect to their Facebook account, further damage can be inflicted, including disclosure of private data that the user does not want to share with others, and impersonation of the user to post bogus news or comments on friends' walls. This form of propagation resembles the famous MySpace worm released in 2005, they said.
"Our attack utilized a feature of Adobe Flash called unpredictable communication, and an important distinction between an unpredictable communication and a normal communication is that the former is done through a connection where the name starts with an underscore symbol," Li said. "Therefore, Facebook could check for this symbol to determine if a potentially malicious website tries to do unpredictable communication."
And that is exactly what Facebook started to do once they were alerted to the problem by Wang and Li, who were working under the supervision of School of Informatics and Computing Associate Professor XiaoFeng Wang and Shuo Chen, a researcher in Microsoft Research's Internet Services Research Center.
XiaoFeng Wang, the students' adviser, said Facebook relies on same-domain communications that allow websites to specify Adobe Flash as the communication mechanism.
"In a normal situation, two flash objects can only do same-domain communications, and, in fact, security of Facebook's authentication crucially depends on same-domain restrictions," he explained. "However, Facebook allowed the Adobe Flash communication mechanism but did not disallow the unpredictable domain names. This is how a malicious website could establish a channel to enable two flash objects in different domains to communicate."
To portray the seriousness of the vulnerability, the team made a video demo that can be viewed here.
Facebook officials noted that a contact form at both the Facebook Help Center and from the "Whitehats" tab on the Facebook Security Page are available in the rare instances in which vulnerabilities are found.
"We also recently rewrote our responsible disclosure policy to make it even easier for researchers to let us know when they find a vulnerability, so we can fix it quickly and before it's exploited. Our new policy was praised by the Electronic Frontier Foundation in a recent blog post here," the statement said.

Internet technology is a tool for political change in Arab world

 http://ifikra.files.wordpress.com/2010/08/blackberry_ban_arab_world.png
The revolts in Tunisia, Egypt and Yemen are driven by deep dissatisfaction with authoritarian regimes, but Internet technology has played a crucial role as a 21st-century weapon for democracy movements, experts say.
http://asiancorrespondent.com/wp-content/uploads/2011/02/us-internet-map.jpg

Inspired by the recent overthrow of the Zine El Abidine Ben Ali dictatorship in Tunisia, citizen activists on Thursday escalated their protests in Egypt and Yemen, denouncing their respective governments. And social media played the dual role of a virtual town square where protest leaders rally the masses and counter government disinformation.
Services such as Twitter and Facebook are "playing an increasingly large role in almost any mass protest around the world," said John Palfrey, a law professor at Harvard University who studies limits on Internet expression. "We will see more of this."
 http://globalvoicesonline.org/wp-content/uploads/2011/02/faceook.jpg
The demonstrations in Egypt, where the government completely shut down the Internet late Thursday, "were started primarily by the April 6 Movement, which was basically a Facebook campaign that started in 2008 and called for protests about workers' rights," said Lina Khatib, a Stanford University expert on Arab reform who was in Cairo on Thursday before leaving for Paris.
During the latest unrest, Twitter became an instant information tool, she said: "People were spreading the news on Twitter. They would alert people where demonstrators were gathering."
But it is long-simmering anger against authoritarian governments that is sending
 unarmed protesters against police and soldiers."What has already happened in Tunis and may be happening right now in Cairo and Tripoli is a revolution that uses social media, but is not a revolution caused by social media," said Clay Shirky, a professor at New York University's Graduate Interactive Telecommunications Program.
Most of the Egyptian protesters have probably never used the Internet. But Internet-savvy elites were the catalyst for the demonstration, Khatib said.
"The reason why it was so effective is because of what happened in Tunisia," she said. "They saw it on TV. They heard about it. It was the first time a civilian uprising had torn down a regime in the Arab world."
Technology's role in organizing opposition has not been lost on the governments of that volatile region.
In Cairo, by late Thursday phone service was cut, Twitter and Facebook were blocked and a media blackout was in place, Khatib said. "The government knew people would be coordinating their movements to join the demonstration," she said.
Egypt is far from alone in seeing the Internet and other new technology as threats. The number of countries censoring or blocking at least some Internet content has increased from two about 10 years ago to three dozen now, Palfrey said.
http://www.foreignpolicy.com/files/fp_uploaded_images/100422_iStock_000002242947Small.jpg
Iran, for example, blocked access to Facebook for fear it was being used to help facilitate street protests over the disputed presidential election in 2009, and the Palo Alto company said it saw its traffic from Iran drop in half. The Chinese government, beginning with the 2008 Summer Olympics, began applying even more controls to the Internet. Facebook, Twitter and YouTube are blocked by the communist government.
Facebook said in a statement Thursday: "We are aware of reports of disruption to service and have seen a drop in traffic from Egypt." San Francisco-based Twitter, which did not comment directly on the blocking of its service, said in a tweet, "We believe that the open exchange of info & views benefits societies & helps govts better connect w/ their people."
The Obama administration has taken a more aggressive stance against Internet censorship than previous administrations, Palfrey said.
On Wednesday, U.S. Secretary of State Hillary Clinton urged Egypt "not to prevent peaceful protests or block communications, including on social media."
But the uprising in Egypt, a longtime ally of the United States, puts President Barack Obama in a tough situation, and it's unclear how much pressure he will ultimately apply on Egyptian President Hosni Mubarak, Khatib said.
http://api.ning.com/files/8tug*KtCql*RsFyFF57kFq8RmdPo*WcSSNEMUahjwrgO0ZzvYt-2FCoh-CYHl*KylqeNV9V9poHFzd81wknk5VswqnyMkvei/arab_world_today.jpg
"For the U.S., this is a test: Who do you really care about most?" she said. "The leaders in the Arab world, who are your allies, or the people who are calling for the same values you are supposed to represent?"
Jacob Appelbaum, a San Francisco programmer with the longtime open-source Tor Project, a program that cloaks the identity of users that is popular with corporations and free-speech activists alike, cautioned against "cyberutopia." The very technology used by democracy advocates can also be used to trap them, he said.
"The unblocking of Twitter may not be a good thing," Appelbaum said, unless protesters use a cloaking service. "It seems good on its face. But if the regime does not fall, it could hunt down everyone who uses Twitter."
 http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/2011/2/22/1298407617013/Opposition-supporters-tal-007.jpg
Web hosting