Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Ransoming Local and State Governments plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses why State and Local governments are getting ransomware and who is actually at fault.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple’s T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, Tyler technologies, you might not have heard of them, but you've almost certainly use them. And we'll tell you why they got nailed by these human-operated ransomware pieces that are floating around there as part of phishing expeditions. Here we go.

    Hey, thanks for joining me. This is Craig Peterson of course.

    Tyler technologies, you might not have heard of these people. They are the largest provider of software to the United States public sector.  At the end of September, Tyler technologies disclosed that they had been nailed by a ransomware attack.

    Its customers, which are public sector companies, Or not obviously not companies, but organizations like towns, counties, States, it's customers reported finding suspicious log-ins and. What is called the RATS on their networks? A rat is a remote access tool. Remember I've told you how we found Chinese back doors on networks, time and time again and we continue to find them. Those are rats. Those are remote access tools.

     What happens is your network gets infected bad guys, gets onto your computers and they install software that gives them remote access. Isn't that just phenomenal? Oh, we have the majority of states here in the country that are using Tyler technology services and software. Some of those, at least I have found remote access tools on their networks. That is a very bad thing apparently.

    According to security affairs.co, apparently Tyler notified law enforcement about it. It took place on September 23rd and they brought in a forensics firm to investigate the incident and trying to figure out what did the bad guys get.

    That is a very big question. Did you know that if you are a business, you are required to be able to figure this out? Under certain federal contracts or DOD particularly you are required to keep long-term logs. Those you have to have logs of everything that's been happening on your network for the term of the contract. I think it's plus three years, depending on the contract, that is a long time.

    That's a lot of logs gets pretty expensive, pretty fast. When you're a company like Tyler technologies you'd think they would have some absolutely amazing logging software. But do they? No. No, of course not.

    I see this all the time. We've got to be careful people. We've got to keep the logs that come in from our firewalls, the logs on our computers. They need to be basically vacuumed up and put into a database for at least a few weeks so that an investigation can occur. If something were to happen.

    One of the things that we've got to keep in mind too, is that from the time the machine is infected until the time they are moving around in the network right now is about a week. You have five to seven days to notice that you've been infected and to shut it down before they start expanding.

    So having a few weeks worth of detailed logs of everything going in and out of your firewall and everything going on your computers can quickly Put an end to the types of hacks that Tyler experienced.

     As I said, depending on the regulations you're under, you could be in trouble. I had probably about a dozen people this week asked me for my audit kit. So if you'd like a copy of my audit kit, if you are in a state or a local government, or you are in business, I have an audit kit that covers everything, all of the major stuff anyway.

    FINRA requirements. If you are a financial organization dealing with personal information, identifiable information, et cetera, just send me an email in the subject line. Just say audit. Kit. I'll email one out to you so that you have that I'm not charging for any of this stuff.

     It is a checkmark thing. This thing's over 300 pages just long. Okay. It has all of these different standards in it, but it's something you can use. You can sit down and go through it with your IT provider or your internal IT people.

    Or you can sit around at the conference room table with your senior managers and go through it because there are different sections in it.

    So the very first section is just general high-level stuff to make sure that you're going, to have general compliance. And then it gets right into the national Institute of standards, technology stuff, the NIST 800-171, and some of the other sections that are needed. So it even goes to absolute detail here bit by bit if you want that.

    So I can send that to you if you want. I'd be glad to. It's a PDF. I found a lot of people had it bounce, though. I think the majority of them, cause it was a huge and like 20 megabytes, which is crazy. So I compressed it. I use PDF Expert on my Mac to compress it down to about 12 megabytes, which is still too big to send by email.

    As a general rule email shouldn't be used for anything that big and by the way, a lot of email filters we'll assume if it's a big piece of email, a big attachment like that it's malware.

     I'll probably just send you a link to my Dropbox account so you can pull it right out of there when you want. Anyhow, that's just me,  M E at craigpeterson.com audit kit. Be glad to send it to you.

    It's useful for home users as well. You're not going to, of course, delve into all of the more detailed stuff for specialized businesses, but you are going to be able to have the nice high-level stuff that is going to help you out.

    Immediately after this attack friends over at Tyler technologies said that the incident only impacted the internal network and phone systems. Yet, it looks like they got the ransom X ransomware. This is human-operated, ransomware. This is the type of stuff I've been talking about.

    It's a RAT. It's remote access. It allows them to get in, like a Chinese back door. With human-operated ransomware, they get onto the computers and they start poking around.

    Back in June this year. Ransom X again was used in an attack on the Texas department of transportation. In September effected systems over at IPG photonics, which is this high-performance laser developer. Bleeping Computer, which is a great site for keeping up on some of this stuff is also talking about now how Tyler technologies paid a ransom to receive the decryption key and recover encrypted files.

    Now you might ask yourself, how do they figure out what ransom they should charge, right?

    A home user's not going to be able to afford the same ransom that a city can afford and just ask Atlanta. How many times have they had ransomware and paid ransoms and been down for months, some of their systems, just crazy. They do it with this type of ransomware, where you've got a human-looking around figuring out what is this? Is this a business? This, a home user. Okay. So we'll charge them a couple of hundred bucks. Oh, this is a city. So let's spread laterally. Let's poke around. Let's see what the weaknesses are in their internal networks.

    Remember I said earlier in the show, that we run sometimes through firewalls here at five or six times, that's called ZeroTrust and that's to stop these attacks.  We gotta be able to stop them. We absolutely have to be able to stop them.

    All right. Crazy times we live in, you're listening to Craig Peterson. 

    I'm feisty stick around. Cause coming up, we're going to talk about the five G in the U S of A.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    9 min
  • 5G Speeds and What is Really going on plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses 5G and explains how it works why what you may have heard about 5G speeds might have a bit misleading.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple's T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Are you as excited about five G as I am? I got some good news and I got some bad news and we're going to explain 5g here because five G, isn't five G, isn't five G. Why is Europe so much faster?

    Hey everybody. Thanks for tuning in. You're listening to Craig Peterson.

    five G held open a couple of different promises. One of the big promises of five G was that it could handle way more devices than 4g can handle.

    It isn't just because it's using IPV six. For those of you who are a little more technical, five G is designed to handle microdevices by the billions. So we're talking about having your coat, for instance, hooked up to the five G network. You might have the new Apple watch six and that Apple watch six has built into it a cell modem. Exactly. So it doesn't need your phone anymore. Your iPhone, it can talk directly to the cell towers. It can take a phone call, can send a phone call. Let's just like Dick Tracy. You can even have videos, so cool. You open up your camera and you can see what your camera sees right there on your watch and you can control your camera. I am just so impressed by it. It Is such a cool device as well as being just an amazing device for tracking all your health, but I digress.

    So in the five G world, the idea is that you could have millions of devices, just the Apple watch, which is not 5g by the way the watch six is not 5g, but you could have millions of these devices in the 4g world.

    It was never really intended to, for an individual to basically have a couple of dozen or a few dozen or more devices. To start thinking about it, you've got a smart car. It could have one or more five G modems in it so that it can call into the dealer in advance and say, Hey, I'm having this problem that you could have a technician diagnose it remotely, which is already happening, Then you have your, Levi trucker jacket on, which is also getting the weather report. To know if it should be heating itself up charging itself, you're just everything. You name it? I'm just, I'm thinking about all the devices. You won't in the future be able to buy a laptop that does not have internet built into it that doesn't need wifi anymore. The other side of five G when we're talking about not needing wifi anymore is the speed. Five G is promising up to gigahertz bandwidth, which is wow. Gigabit bandwidth is absolutely amazing. How fast is your internet on your phone right now? So what you can do is on your phone, or even on your regular laptop, desktop tablet, whatever. See if you can find an app called speed, test.net speed test.net and not just the app, but see if there is just the website. So if you're on a regular computer, I can just go to the web, and then at speed test.net, I'm going to pull it up right now. Speed test. I have that right. They're actually on my phone.

    So it's by. and they'll go and try and find the optimal server, and then you can hit the go button. So now it'll connect to that server. It's going to download some big files and it's going to upload some big files and it's looking at a couple of different things. It's looking at ping time, which is how fast it can get from you to the remote server and then back and that's in milliseconds. Typically it's also measuring jitter and jitters important if you are using it for video conferencing. So if you've had problems with the phone that kind of breaking up a little bit sounding were dropping. That's probably a jitter problem. Speed tests will tell you about your jitter and w how much loss you've had, how much data loss, how many packets just did not make it to the other end.

    So I'm running it right now. No. I don't want you guys to get upset with me, but I've got fiber lines coming in here, dedicated fiber business fiber lines. So my phone right now is showing a download speed of 229 million bits per second. So 229 megabits upload of 236 megabits. So that's called symmetrical.

    It's basically the same speed. Up as it is down. A lot of us, if we're using cable modems, we'll have something called asymmetrical and our work upload speed will be about a 10th of our download speed. That's absolutely normal and sometimes it'll be faster than that, but these cable modems and some of the other services are designed for basically for web browsing. When you look at the TCP protocol overhead, it's about the same as that, about 10% up versus your downloads. So three milliseconds, Andy is my pink time, which is really quite fast. I remember for my first ethernet networks, we had 10 megabits thick wired ethernet. And I'm trying to remember, I think a hundred milliseconds was wow on a local network.

    So this is three milliseconds and my jitter is 0.23 milliseconds. So excellent lines. And these types of speeds that we're talking about here on fiber for me are the types of speed that they want to get to with five G. Think about that, think about being able to get these quarter gigabit or all the way up to gigabits speeds just on your smartphone or your laptop or your I pad or your car or whatever it might be.

    That's the other big promise of five G right? There's a company out there called open signal and I'm looking into some of the five G's statistics. They checked average speeds in a dozen countries. These are based on people going to like speed test.net type stuff. It's just, it's not a great sampling.

    It's people who self-identified right. Put up their hands. Yeah. I want to be involved, but these were conducted between May 16 and August 14. So over the course of a few months, And the United States came in deadline last of the 12 countries in five G speeds with 10 of the 11 other countries posting five G speeds that at least doubled those of the US. So the question is why is the average five-speed in the United States about 50 megabits per second. Okay. Why are these other countries out more than a hundred megabits? A second? it has to do with the providers who are the providers that actually have five G here in the US and which of those providers are able to have a big enough footprint that people can relate.

    Tested. the only provider that pretty much has coast to coast, five G right now is T-Mobile and T-Mobile's a company that I use and it's not the best for general coverage, is up in Lincoln, New Hampshire here last weekend and there are a lot of areas where I had no coverage. Verizon has a lot of coverage all over, even in some of these weaker areas and they tend to be more expensive.

    M,y T-Mobile plan is a business plan. And then I don't get paid by any of these guys on getting kickbacks nothing. Okay. Okay. So what you're getting from me is my absolute truth here. What I have seen well, Teen mobile is using a lower frequency that is being used in these other countries like Taiwan, South Korea, Saudi Arabia, who had some of the best speeds out there, and Australia as well.

    And remember, these are self-selected people, right? These are people that know they have 5g. They tend to be a little more techie, which means they are probably in larger urban areas. That's where the problem starts coming in. T-Mobile's 5g at a lower frequency, more easily penetrates glass and walls, right? Wood walls, drywall, et cetera. That's typically what I want.

    Versus Verizon, that's running at much higher frequencies. And last I checked, I think they were suing because they were upset that the FCC sold and gave these frequencies to T-Mobile, but they are running on much higher frequencies, which means they can deliver higher bandwidth because that frequency gives them the ability to have a lot more variants in their signal, which ultimately translates into more bandwidth for you.

    Now, I have an advanced class amateur radio license if you've listened for a while. And so I studied this stuff and I know a fair amount about it, frankly. I was one of the first people involved in packet radio here in the United States, way back when I still have some old equipment. So I, this is stuff that I know about. So the Verizon just signals cannot pay trade as well, which means they're going to have even. More cell sites in the five G world.

    We're not talking about cell sites that are on these huge towers. As much as we're talking about cell sites that are mounted on buildings and even homes all over creation. Verizon's other problem right now is they don't have a whole lot of coverage. They've got five G coverage in some major cities and even then it's only in some areas of those major cities.

    So once Verizon's totally rolled out, if you're living in a fairly populated area, you're probably going to get a faster data path through Verizon, then you'd get through T-Mobile. However, with T-Mobile, you're going to be more likely to have a signal pretty much anywhere because the T-Mobile signals also go further because they're lower frequencies.

    So think about that. People my age. Do you remember am and listening to am at night and you got the bounce off the ionosphere and is really cool? You could listen to somebody on the other side of the country and sometimes even on the other side of the world. It was so cool. I still have short wave radios I listen to.

    It still blows my mind. It's something I've loved since I was a little kid. I and made my first little cat's whisker radio, crystal radio way back when.

    So that's, what's going to happen here. We'll see how things actually end up flushing out. But the other side of this is based on the type of phone you have, you may be restricted to a specific carrier. So we're going back to the old days. Because the frequencies are so far apart and the less expensive phones they're going to be dedicated to certain carriers. So keep that in mind as well. When you're looking to buy your new phone.

    All right, stick around. We are going to be back here. We're going to talk about an unfixable flaw that Apple has this hardware security where it's going. Verizon sent out a new wake up call, Android malware, some new tricks on that front, and you can find it all [email protected].

    Stick around.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • 5G Speeds and What is Really going on plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses 5G and explains how it works why what you may have heard about 5G speeds might have a bit misleading.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple’s T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Are you as excited about five G as I am? I got some good news and I got some bad news and we're going to explain 5g here because five G, isn't five G, isn't five G.  Why is Europe so much faster?

    Hey everybody. Thanks for tuning in. You're listening to Craig Peterson.

    five G held open a couple of different promises. One of the big promises of five G was that it could handle way more devices than 4g can handle.

     It isn't just because it's using IPV six. For those of you who are a little more technical, five G is designed to handle microdevices by the billions. So we're talking about having your coat, for instance, hooked up to the five G network. You might have the new Apple watch six and that Apple watch six has built into it a cell modem. Exactly. So it doesn't need your phone anymore. Your iPhone, it can talk directly to the cell towers. It can take a phone call, can send a phone call. Let's just like Dick Tracy. You can even have videos, so cool. You open up your camera and you can see what your camera sees right there on your watch and you can control your camera. I am just so impressed by it. It Is such a cool device as well as being just an amazing device for tracking all your health, but I digress.

    So in the five G world, the idea is that you could have millions of devices, just the Apple watch, which is not 5g by the way the watch six is not 5g, but you could have millions of these devices in the 4g world.

    It was never really intended to, for an individual to basically have a couple of dozen or a few dozen or more devices. To start thinking about it, you've got a smart car. It could have one or more five G modems in it so that it can call into the dealer in advance and say, Hey, I'm having this problem that you could have a technician diagnose it remotely, which is already happening,  Then you have your, Levi trucker jacket on, which is also getting the weather report. To know if it should be heating itself up charging itself, you're just everything. You name it? I'm just, I'm thinking about all the devices. You won't in the future be able to buy a laptop that does not have internet built into it that doesn't need wifi anymore.  The other side of five G when we're talking about not needing wifi anymore is the speed. Five G is promising up to gigahertz bandwidth, which is wow. Gigabit bandwidth is absolutely amazing. How fast is your internet on your phone right now? So what you can do is on your phone, or even on your regular laptop, desktop tablet, whatever. See if you can find an app called speed, test.net speed test.net and not just the app, but see if there is just the website. So if you're on a regular computer, I can just go to the web, and then at speed test.net, I'm going to pull it up right now. Speed test. I have that right. They're actually on my phone.

    So it's by.  and they'll go and try and find the optimal server, and then you can hit the go button. So now it'll connect to that server. It's going to download some big files and it's going to upload some big files and it's looking at a couple of different things. It's looking at ping time, which is how fast it can get from you to the remote server and then back and that's in milliseconds. Typically it's also measuring jitter and jitters important if you are using it for video conferencing. So if you've had problems with the phone that kind of breaking up a little bit sounding were dropping. That's probably a jitter problem. Speed tests will tell you about your jitter and w how much loss you've had, how much data loss, how many packets just did not make it to the other end.

    So I'm running it right now. No. I don't want you guys to get upset with me, but I've got fiber lines coming in here, dedicated fiber business fiber lines. So my phone right now is showing a download speed of 229 million bits per second. So 229 megabits upload of 236 megabits. So that's called symmetrical.

    It's basically the same speed. Up as it is down. A lot of us, if we're using cable modems, we'll have something called asymmetrical and our work upload speed will be about a 10th of our download speed. That's absolutely normal and sometimes it'll be faster than that, but these cable modems and some of the other services are designed for basically for web browsing. When you look at the TCP protocol overhead, it's about the same as that, about 10% up versus your downloads. So three milliseconds, Andy is my pink time, which is really quite fast. I remember for my first ethernet networks, we had 10 megabits thick wired ethernet. And I'm trying to remember, I think a hundred milliseconds was wow on a local network.

    So this is three milliseconds and my jitter is 0.23 milliseconds. So excellent lines. And these types of speeds that we're talking about here on fiber for me are the types of speed that they want to get to with five G. Think about that, think about being able to get these quarter gigabit or all the way up to gigabits speeds just on your smartphone or your laptop or your I pad or your car or whatever it might be.

    That's the other big promise of five G right? There's a company out there called open signal and I'm looking into some of the five G's statistics. They checked average speeds in a dozen countries. These are based on people going to like speed test.net type stuff. It's just, it's not a great sampling.

    It's people who self-identified right. Put up their hands. Yeah. I want to be involved, but these were conducted between May 16 and August 14. So over the course of a few months, And the United States came in deadline last of the 12 countries in five G speeds with 10 of the 11 other countries posting five G speeds that at least doubled those of the US. So the question is why is the average five-speed in the United States about 50 megabits per second. Okay. Why are these other countries out more than a hundred megabits? A second? it has to do with the providers who are the providers that actually have five G here in the US and which of those providers are able to have a big enough footprint that people can relate.

    Tested. the only provider that pretty much has coast to coast, five G right now is T-Mobile and T-Mobile's a company that I use and it's not the best for general coverage, is up in Lincoln, New Hampshire here last weekend and there are a lot of areas where I had no coverage. Verizon has a lot of coverage all over, even in some of these weaker areas and they tend to be more expensive.

    M,y T-Mobile plan is a business plan. And then I don't get paid by any of these guys on getting kickbacks nothing. Okay. Okay. So what you're getting from me is my absolute truth here. What I have seen well, Teen mobile is using a lower frequency that is being used in these other countries like Taiwan, South Korea, Saudi Arabia, who had some of the best speeds out there, and Australia as well.

    And remember, these are self-selected people, right? These are people that know they have 5g. They tend to be a little more techie, which means they are probably in larger urban areas. That's where the problem starts coming in. T-Mobile's 5g at a lower frequency, more easily penetrates glass and walls, right? Wood walls, drywall, et cetera. That's typically what I want.

    Versus Verizon, that's running at much higher frequencies. And last I checked, I think they were suing because they were upset that the FCC sold and gave these frequencies to T-Mobile, but they are running on much higher frequencies, which means they can deliver higher bandwidth because that frequency gives them the ability to have a lot more variants in their signal, which ultimately translates into more bandwidth for you.

    Now, I have an advanced class amateur radio license if you've listened for a while. And so I studied this stuff and I know a fair amount about it, frankly. I was one of the first people involved in packet radio here in the United States, way back when I still have some old equipment. So I, this is stuff that I know about. So the Verizon just signals cannot pay trade as well, which means they're going to have even. More cell sites in the five G world.

    We're not talking about cell sites that are on these huge towers. As much as we're talking about cell sites that are mounted on buildings and even homes all over creation. Verizon's other problem right now is they don't have a whole lot of coverage. They've got five G coverage in some major cities and even then it's only in some areas of those major cities.

    So once Verizon's totally rolled out, if you're living in a fairly populated area, you're probably going to get a faster data path through Verizon, then you'd get through T-Mobile. However, with T-Mobile, you're going to be more likely to have a signal pretty much anywhere because the T-Mobile signals also go further because they're lower frequencies.

    So think about that. People my age. Do you remember am and listening to am at night and you got the bounce off the ionosphere and is really cool? You could listen to somebody on the other side of the country and sometimes even on the other side of the world. It was so cool. I still have short wave radios I listen to.

    It still blows my mind. It's something I've loved since I was a little kid. I and made my first little cat's whisker radio, crystal radio way back when.

     So that's, what's going to happen here. We'll see how things actually end up flushing out. But the other side of this is based on the type of phone you have, you may be restricted to a specific carrier. So we're going back to the old days. Because the frequencies are so far apart and the less expensive phones they're going to be dedicated to certain carriers. So keep that in mind as well. When you're looking to buy your new phone.

    All right, stick around. We are going to be back here. We're going to talk about an unfixable flaw that Apple has this hardware security where it's going. Verizon sent out a new wake up call, Android malware, some new tricks on that front, and you can find it all [email protected].

    Stick around.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Uncovering the Mystery of Disk Encryption plus more on this Tech Talk with Craig Peterson Podcast

    Craig helps to unravel the mystery behind disk encryption and tells you what you need to know.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple's T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, welcome back in this hour, we are going to be talking about security, hardware, security. You might not be aware of it. we're going to be talking about trusted platforms and hardware, encryption, and keys because this is the only thing that's really going to protect you.

    Thanks for listening. I'm Craig Peterson.

    Let's talk about that security. That's what we're going to kick off this hour with. And we're going to get into our new Verizon security report on payment, and then we'll get into some Android stuff, but. We had this week and announcement here. And this is about Apple. Apple has built hardware security inside most of its devices that includes the iPhones and include your Macs and Mac pros. You name it, really the iMacs, the Mac minis. They all have the hardware. Inside of them to help provide security. Now in the Apple world, it is a chip that Apple makes it's called a T2 security chip, and that makes sure that people cannot get onto your computer.

    The whole idea is if they have physical access to the computer, they cannot get inside. They can't make it boot off an external drive. They can't do just a whole ton of things get real deep system access. Back in the day, you used to boot off of read-only memory. Or proms, programmable read-only memory, those BIOSes that was in so many of the consumer pieces of equipment out there, and even some of the prosumer stuff that many businesses use. Those BIOSes were really cool, but they weren't secure at all. The hard disks that machine could easily be removed and put onto another machine, they didn't even have to be booted up. You could just have another machine of a, for instance, my Mac, I can take a disk from a Windows computer. I have a device sitting there that's hooked up full time. That allows me to just plug a hard disc. just, you just slide it, And while the machine is up and running and it will Mount that disk. And let me do whatever I need to do investigative work or whatever, it might be very cool devices.

    I can have two of those disks that I just plugin. I also use them for my video, where I am recording directly to SSDs. I move SSDs around, which is much faster than trying to push them over gigabit ethernet. So Apple has decided that this T2 chip is a good thing and it uses the T2 chip for a few different things.

    Once we're talking about your hard disc itself, the newer hard disks at the higher end and have the ability. To encrypt the data on the disc, which is, it's good. It's great. But that data that's encrypted on that disk can be read by the operating system. And that's the whole idea, right? If you can't read the disk, what good is it for you?

    So any data that's stored on that encrypted data is still available for your programs and is still available for hackers. So the disc encryption I'm talking about right now at the kind of the low end of all of this security stuff. It's designed so that when your computer is life it's over, or maybe the hard disc crashes, there's a little jumper that you can pull, or maybe there are the jumpers you short out on the disk.

    Just look it up online, do it. In fact, go search for your disc model number and you pull that jumper or you short out those terms and what happens at that point is your disk is now complete. Erased, but it's not really erased. It's like your iPhone. Have you been to the Apple store? You're trading in your iPhone.

    You want to get a brand new iPhone? Isn't this great. They have you turn off. Find my iPhone. That's the first thing they have you do. And then they say to erase the iPhone. And have you noticed it takes what? Five, 10 seconds. To erase the iPhone. How can you possibly erase hundreds of megabytes or gigabytes of data in five to 10 seconds?

    You cannot. So what's happening inside the iPhone is similar to what's happening with these basic encrypted disks. Okay. Everything that's written to these disks and everything written to your iPhone is encrypted. So if you want to make all of the data that's on that disk inaccessible or basically useless.

    All you have to do is destroy the key that was used to encrypt it. So think of a door that cannot possibly be breached and a key. There's only one key. You can't pick the lock. Okay. Oh, maybe this isn't the best of analogies, but if that key is destroyed, it's impossible at that point on to open that door.

    It's not like a real door where maybe you could take blow torches to a metal door or something right there. You can always get in, but it is completely effectively destroyed. The data that's on that device. If the encryption is good, looks like just random data. There's no difference between completely random and.

    It has everybody's social security number, income, and addresses in the whole United States encrypted on it. Okay. So that's the low end. On your iPhone. When you go ahead and you erase your iPhone when you're trading it in or. If you have one of these encrypted hard disks where you just pull that jumper, it now destroys the key.

    That key now in both cases makes that disk, the data on the disc useless. Now that's cool. And the next time that disk is powered up, it's going to generate a brand new key and it's going to be hopefully pretty darn random. And now you can use it again, assuming the disc isn't bad. if you took it out, cause it was just totaled.

    So that's a very basic layer, but just like your iPhone, that encrypted disc has data, that's readable on it up until the time that you destroyed the data by destroying the key. You're with me so far. That's the very basics of how this all works. Now there's something called TPM, which stands for trusted platform module.

    This is an international standard that's been out now. It is a standard that describes a secure cryptoprocessor. That's what Apple's T2 security chip is all about. Now, the problem that came up this last week, this week, in fact, is that there is a flaw in Apple's trusted T2 security chip. And it's the flaw that apparently researchers have been using for more than a year to jailbreak older models of iPhones.

    We've heard I heard about this. We've heard that the FBI was able to get into iPhone and get at the data that's in them. There are well, there's one primary company it's over in Israel that sells a device that lets the police break into iPhones. I'm just talking about iPhones right now. Many of the Android devices are very easy to break into as well, but Apple is really trying to make these things secure.

    That's why they came up with this chip of their own, which is really a kind of a trusted platform module. So they have been using this flaw in order to jailbreak into the iPhones. And the way that this T2 chip is vulnerable is a problem. And the slightly bigger problem is that this particular problem is ultimately unfixable.

    In every Mac that has a T2 inside, that is a lot that T2 chip launched in 2017 and it created some limitations. Many people have used macs to run Linux for many years. It's a great little Linux computer. We know that PC magazine had on its front cover or was a PC world. The cover said the best PC for windows is a Mac because they were just that solid. But because of the T2 chip, when it was introduced in 2017, all of a sudden problems started to arise for people. they effectively hacking their Macs.

    Apple added the chip so that it had a trusted mechanism to secure the device. The biggest reason for adding this chip or a TPM, this trusted platform module, which is available on many windows, computers is encrypted data storage. Now, in some cases, the TPM or the T2 chip.

    Apple is also used for touch ID and activation log that all works with Apples find my iPhone type services. So this vulnerability is known as checkM8 and the jailbreakers as we mentioned, they've been exploiting problems with Apples, A5 through A 11 chipsets that's from 2011 to 2017.

    Now the same group that developed the tool for iOS has released support for a T2 bypass. This is not good people. It just plain old is not good. Now we're going to. Pick this up. When we come back, I'm going to talk about the trusted platform, modules of vendors that are using it over on the windows space, how Apple's using it, how this whole black box things work works, and we're going to move up.

    We talked about the hardware-based disc encryption. That's right there on the hard disc. We're going to move up the stack and talk about other types of encryption, including encryption. On the fly and encryption at rest, both are important concepts to understand when we're talking about security and system integrity.

    Hey, you're listening to Craig Peterson. Stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Uncovering the Mystery of Disk Encryption plus more on this Tech Talk with Craig Peterson Podcast

    Craig helps to unravel the mystery behind disk encryption and tells you what you need to know.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple’s T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, welcome back in this hour, we are going to be talking about security, hardware, security. You might not be aware of it. we're going to be talking about trusted platforms and hardware, encryption, and keys because this is the only thing that's really going to protect you.

     Thanks for listening. I'm Craig Peterson.

    Let's talk about that security. That's what we're going to kick off this hour with. And we're going to get into our new Verizon security report on payment, and then we'll get into some Android stuff, but. We had this week and announcement here. And this is about Apple. Apple has built hardware security inside most of its devices that includes the iPhones and include your Macs and Mac pros. You name it, really the iMacs, the Mac minis. They all have the hardware. Inside of them to help provide security. Now in the Apple world, it is a chip that Apple makes it's called a T2 security chip, and that makes sure that people cannot get onto your computer.

    The whole idea is if they have physical access to the computer, they cannot get inside. They can't make it boot off an external drive. They can't do just a whole ton of things get real deep system access. Back in the day, you used to boot off of read-only memory. Or proms, programmable read-only memory, those BIOSes that was in so many of the consumer pieces of equipment out there, and even some of the prosumer stuff that many businesses use. Those BIOSes were really cool, but they weren't secure at all.  The hard disks that machine could easily be removed and put onto another machine, they didn't even have to be booted up. You could just have another machine of a, for instance, my Mac, I can take a disk from a Windows computer. I have a device sitting there that's hooked up full time. That allows me to just plug a hard disc. just, you just slide it, And while the machine is up and running and it will Mount that disk. And let me do whatever I need to do investigative work or whatever, it might be very cool devices.

     I can have two of those disks that I just plugin. I also use them for my video, where I am recording directly to SSDs. I move SSDs around, which is much faster than trying to push them over gigabit ethernet. So Apple has decided that this T2 chip is a good thing and it uses the T2 chip for a few different things.

    Once we're talking about your hard disc itself, the newer hard disks at the higher end and have the ability. To encrypt the data on the disc, which is, it's good. It's great. But that data that's encrypted on that disk can be read by the operating system. And that's the whole idea, right? If you can't read the disk, what good is it for you?

    So any data that's stored on that encrypted data is still available for your programs and is still available for hackers. So the disc encryption I'm talking about right now at the kind of the low end of all of this security stuff. It's designed so that when your computer is life it's over, or maybe the hard disc crashes, there's a little jumper that you can pull, or maybe there are the jumpers you short out on the disk.

    Just look it up online, do it. In fact, go search for your disc model number and you pull that jumper or you short out those terms and what happens at that point is your disk is now complete. Erased, but it's not really erased. It's like your iPhone. Have you been to the Apple store? You're trading in your iPhone.

    You want to get a brand new iPhone? Isn't this great. They have you turn off. Find my iPhone. That's the first thing they have you do. And then they say to erase the iPhone. And have you noticed it takes what? Five, 10 seconds. To erase the iPhone. How can you possibly erase hundreds of megabytes or gigabytes of data in five to 10 seconds?

    You cannot. So what's happening inside the iPhone is similar to what's happening with these basic encrypted disks. Okay. Everything that's written to these disks and everything written to your iPhone is encrypted. So if you want to make all of the data that's on that disk inaccessible or basically useless.

    All you have to do is destroy the key that was used to encrypt it. So think of a door that cannot possibly be breached and a key. There's only one key. You can't pick the lock. Okay. Oh, maybe this isn't the best of analogies, but if that key is destroyed, it's impossible at that point on to open that door.

    It's not like a real door where maybe you could take blow torches to a metal door or something right there. You can always get in, but it is completely effectively destroyed.  The data that's on that device. If the encryption is good, looks like just random data. There's no difference between completely random and.

    It has everybody's social security number, income, and addresses in the whole United States encrypted on it. Okay. So that's the low end. On your iPhone. When you go ahead and you erase your iPhone when you're trading it in or. If you have one of these encrypted hard disks where you just pull that jumper, it now destroys the key.

    That key now in both cases makes that disk, the data on the disc useless. Now that's cool. And the next time that disk is powered up, it's going to generate a brand new key and it's going to be hopefully pretty darn random. And now you can use it again, assuming the disc isn't bad. if you took it out, cause it was just totaled.

    So that's a very basic layer, but just like your iPhone, that encrypted disc has data, that's readable on it up until the time that you destroyed the data by destroying the key. You're with me so far. That's the very basics of how this all works. Now there's something called TPM, which stands for trusted platform module.

    This is an international standard that's been out now. It is a standard that describes a secure cryptoprocessor. That's what Apple's T2 security chip is all about. Now, the problem that came up this last week, this week, in fact, is that there is a flaw in Apple's trusted T2 security chip. And it's the flaw that apparently researchers have been using for more than a year to jailbreak older models of iPhones.

    We've heard I heard about this. We've heard that the FBI was able to get into iPhone and get at the data that's in them. There are well, there's one primary company it's over in Israel that sells a device that lets the police break into iPhones.  I'm just talking about iPhones right now. Many of the Android devices are very easy to break into as well, but Apple is really trying to make these things secure.

    That's why they came up with this chip of their own, which is really a kind of a trusted platform module. So they have been using this flaw in order to jailbreak into the iPhones. And the way that this T2 chip is vulnerable is a problem. And the slightly bigger problem is that this particular problem is ultimately unfixable.

    In every Mac that has a T2 inside, that is a lot that T2 chip launched in 2017 and it created some limitations. Many people have used macs to run Linux for many years. It's a great little Linux computer. We know that PC magazine had on its front cover or was a PC world. The cover said the best PC for windows is a Mac because they were just that solid. But because of the T2 chip, when it was introduced in 2017, all of a sudden problems started to arise for people. they effectively hacking their Macs.

    Apple added the chip so that it had a trusted mechanism to secure the device. The biggest reason for adding this chip or a TPM, this trusted platform module, which is available on many windows, computers is encrypted data storage. Now, in some cases, the TPM or the T2 chip.

    Apple is also used for touch ID and activation log that all works with Apples find my iPhone type services. So this vulnerability is known as checkM8 and the jailbreakers as we mentioned, they've been exploiting problems with Apples, A5 through A 11 chipsets that's from 2011 to 2017.

    Now the same group that developed the tool for iOS has released support for a T2 bypass. This is not good people. It just plain old is not good. Now we're going to. Pick this up. When we come back, I'm going to talk about the trusted platform, modules of vendors that are using it over on the windows space, how Apple's using it, how this whole black box things work works, and we're going to move up.

    We talked about the hardware-based disc encryption. That's right there on the hard disc. We're going to move up the stack and talk about other types of encryption, including encryption. On the fly and encryption at rest, both are important concepts to understand when we're talking about security and system integrity.

    Hey, you're listening to Craig Peterson. Stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Apple's T2 Vulnerabilities plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses the vulnerabilities in Apple's T2 Chip.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple's T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, if encryption has been really messing you. I'm trying to figure out how do I make these things safe? What is data at rest? What is Data-in-flight? How come we have disc encryption at the hardware level? What does it mean to have a TPM, the T2 what's Apple doing that's what we're talking about right now.

    Hi everybody. Craig Peterson here. Welcome back. So glad to have you. I appreciate you being with me today and by the way, you can get all of this background information by going online. If you are on my email list over the weekend.

    I will send out an email that has all of the articles I'm talking about here today. So go to Craig peterson.com/subscribe. All right.

    We were just talking about the whole T2 problem that Apple has on their hands right now on macs. This new jailbreak now is allowing researchers to probe this T2 chip and explore all of the security features. That is not a good thing. You can even use it to run Linux on the T2, because this chip, the security module is a computer. You can play doom on the Mac book pros, touch bar doing this. This jailbreak could really be weaponized by malicious hackers as well to disable macOS security features like the system integrity protection, which is used to stop people from modifying files that should not be modified.

    It also could turn off secure boot and install Mount malware, which is a real problem. We've got, these machines are no longer using the bios. Now they're using more advanced stuff, the UEFI stuff. That is also an operating system in and of itself, much more advanced than we had ever seen before with bios.

    Now there is another T2 vulnerability that was publicly disclosed in July by a Chinese researcher group. This particular jailbreak could also be used to obtain file vault encryption keys, and to decrypt user data. This is good. Okay. Because the vulnerability is unmatchable because this flaw is at a low level.

    It is in the hardware inside this T2 chip. It is an unchangeable code. In the hardware, it's the firmware. Now the T2 chip, as you can probably tell, is designed and intended to be a lockbox inside the macs. Something where information can be restored, where information can be read from it's used to generate a cryptographically secure key.

    It's used to hold those keys. Handling things like lost mode enforcement, where a computer is lost and you have to log in using your Apple account in order to get it back online. It's bad. Integrity checking all of these different privileges. So it is a very big deal that this chip has been compromised.

    Now the good news is longer term. There's a couple of pieces, but one is now we know about it. We know how these groups were breaking into Apple equipment. They did not expose it. Under President Trump, the national security agency has been ordered to release information about vulnerabilities that it finds.

    And the idea there is, okay, NSA, you have all of these cooked up vulnerabilities that allow you to get into windows machines and iMacs and phones, et cetera. if you can figure it out, odds are good that the Chinese, the Russians, the North Koreans, maybe some others like Iran, odds are good that they can figure it out as well.

    So NSA, you need to tell the vendors of these different pieces of hardware and software, when you find a vulnerability. if you ask me, I suspect that the NSA and CIA keep a few of these hacks in their back hip pocket, but they actually have been following President Trump's directive, which is absolutely phenomenal in my mind. It's, it is silly slash stupid to have these government agencies know about problems, like what we're talking about right now, this T2 chip problem. How long have government agencies known about it? We don't know because this has been reported by two different security researchers at this point. So that's good news. Frankly, because in future versions, we'll have this fixed as time goes on, everything's going to get locked down better and better, but there are some important limitations of this jailbreak as well.

    So this is not a full-blown security crisis. So the first is that an attacker would need physical access in order to target your Mac computer or your iPhone. So that's number one, they have to have their hands on it. So the tool can only run off of another device over the USB port to use the buses inside the mac to get to the T2 chip.

    So that means that hackers can't remotely infect macs. They can't mass infect every Mac that has a T2 check chip in it. They could jailbreak a target device and then disappear. Here is the good news the compromise if they were to break in and put some malware into your Mac, it isn't persistent. In other words, when that T2 chip is rebooted, the jailbreak goes away.

    Then the compromise that they did to that T2 chip goes away. I should point out too, that at least right now, I suspect Apple's probably going to be able to come up with a patch for this in the operating system. But right now it's important to note that, T2 chip itself does not necessarily reboot every time the device does. So to make certain that you, that your Mac has not been compromised.

    So if you're going to China and I'm dead serious about this, China's known to sneak into hotel rooms and steal everything that they can that's on your computers. If they have to they'll steal it in an encrypted fashion. That's the whole idea behind the trusted platform stuff in the T2 chips.

    To be certain that it has not been compromised by jailbreak the T2 chip has to be restored to Apple default. So the jailbreak does not give an attacker instant access to encrypted data. It could allow hackers to install key loggers or other malware. They could later grab decryption keys or it could make it easy brute force attack it.

    But this particular hack we're talking about right now, this is the check RA1N or check rain. It's not a silver bullet there. When we look at this as a whole, the T2 chip compared with other vulnerabilities, there are other vulnerabilities, plenty of them.

    Most of them are sitting at the keyboard. It's the wetware two and me a 60 plus percent of the time when there is a hack of some sort it's because of something you or I did. So remember that there's plenty of other vulnerabilities. This is a difficult one. I would turn off my computer, my Mac entirely, boot it from scratch every time that should get that T2 chip to reboot.

    I think that's an important thing. So anytime someone else may have access to your Mac, just shut it down. That's important too because there are other hack techniques that include freezing the memory on the computer. They can just use canned air, hold it upside down so that liquid comes out, spray it on the memory.

    Pull the memory, which you cannot do by the way in the latest Mac books, it is soldered on, but pull the memory and get direct access to it. It will keep some of the keys in memory. That's a very difficult way to do it. Apple has some things still built in that are still functional that can and will stop that type of a hack.

    Okay. And when we get back, we're going to talk more about the hardware security, what you can do, the different levels of it, and everything else. Your listening to Craig, Peterson.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Apple's T2 Vulnerabilities plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses the vulnerabilities in Apple's T2 Chip.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple’s T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, if encryption has been really messing you. I'm trying to figure out how do I make these things safe? What is data at rest? What is Data-in-flight? How come we have disc encryption at the hardware level? What does it mean to have a TPM, the T2  what's Apple doing that's what we're talking about right now.

    Hi everybody. Craig Peterson here. Welcome back. So glad to have you.  I appreciate you being with me today and by the way, you can get all of this background information by going online. If you are on my email list over the weekend.

    I will send out an email that has all of the articles I'm talking about here today. So go to Craig peterson.com/subscribe. All right.

    We were just talking about the whole T2 problem that Apple has on their hands right now on macs. This new jailbreak now is allowing researchers to probe this T2 chip and explore all of the security features. That is not a good thing. You can even use it to run Linux on the T2, because this chip, the security module is a computer. You can play doom on the Mac book pros, touch bar doing this. This jailbreak could really be weaponized by malicious hackers as well to disable macOS security features like the system integrity protection, which is used to stop people from modifying files that should not be modified.

    It also could turn off secure boot and install Mount malware, which is a real problem. We've got, these machines are no longer using the bios. Now they're using more advanced stuff, the UEFI stuff. That is also an operating system in and of itself, much more advanced than we had ever seen before with bios.

    Now there is another T2 vulnerability that was publicly disclosed in July by a Chinese researcher group. This particular jailbreak could also be used to obtain file vault encryption keys, and to decrypt user data. This is good. Okay. Because the vulnerability is unmatchable because this flaw is at a low level.

    It is in the hardware inside this T2 chip. It is an unchangeable code. In the hardware, it's the firmware. Now the T2 chip, as you can probably tell, is designed and intended to be a lockbox inside the macs. Something where information can be restored, where information can be read from it's used to generate a cryptographically secure key.

    It's used to hold those keys. Handling things like lost mode enforcement, where a computer is lost and you have to log in using your Apple account in order to get it back online. It's bad. Integrity checking all of these different privileges. So it is a very big deal that this chip has been compromised.

    Now the good news is longer term. There's a couple of pieces, but one is now we know about it. We know how these groups were breaking into Apple equipment. They did not expose it. Under President Trump, the national security agency has been ordered to release information about vulnerabilities that it finds.

    And the idea there is, okay, NSA, you have all of these cooked up vulnerabilities that allow you to get into windows machines and iMacs and phones, et cetera. if you can figure it out, odds are good that the Chinese, the Russians, the North Koreans, maybe some others like Iran, odds are good that they can figure it out as well.

    So NSA, you need to tell the vendors of these different pieces of hardware and software, when you find a vulnerability. if you ask me, I suspect that the NSA and CIA keep a few of these hacks in their back hip pocket, but they actually have been following President Trump's directive, which is absolutely phenomenal in my mind.  It's, it is silly slash stupid to have these government agencies know about problems, like what we're talking about right now, this T2 chip problem. How long have government agencies known about it? We don't know because this has been reported by two different security researchers at this point. So that's good news. Frankly, because in future versions, we'll have this fixed as time goes on, everything's going to get locked down better and better, but there are some important limitations of this jailbreak as well.

    So this is not a full-blown security crisis. So the first is that an attacker would need physical access in order to target your Mac computer or your iPhone. So that's number one, they have to have their hands on it. So the tool can only run off of another device over the USB port to use the buses inside the mac to get to the T2 chip.

    So that means that hackers can't remotely infect macs. They can't mass infect every Mac that has a T2 check chip in it. They could jailbreak a target device and then disappear. Here is the good news the compromise if they were to break in and put some malware into your Mac, it isn't persistent. In other words, when that T2 chip is rebooted, the jailbreak goes away.

    Then the compromise that they did to that T2 chip goes away. I should point out too, that at least right now, I suspect Apple's probably going to be able to come up with a patch for this in the operating system. But right now it's important to note that, T2 chip itself does not necessarily reboot every time the device does. So to make certain that you, that your Mac has not been compromised.

    So if you're going to China and I'm dead serious about this, China's known to sneak into hotel rooms and steal everything that they can that's on your computers.  If they have to they'll steal it in an encrypted fashion.  That's the whole idea behind the trusted platform stuff in the T2 chips.

     To be certain that it has not been compromised by jailbreak the T2 chip has to be restored to Apple default. So the jailbreak does not give an attacker instant access to encrypted data. It could allow hackers to install key loggers or other malware. They could later grab decryption keys or it could make it easy brute force attack it.

    But this particular hack we're talking about right now, this is the check RA1N or check rain. It's not a silver bullet there.  When we look at this as a whole, the T2 chip compared with other vulnerabilities, there are other vulnerabilities, plenty of them.

    Most of them are sitting at the keyboard. It's the wetware two and me a 60 plus percent of the time when there is a hack of some sort it's because of something you or I did. So remember that there's plenty of other vulnerabilities. This is a difficult one. I would turn off my computer, my Mac entirely, boot it from scratch every time that should get that T2 chip to reboot.

    I think that's an important thing. So anytime someone else may have access to your Mac, just shut it down. That's important too because there are other hack techniques that include freezing the memory on the computer. They can just use canned air, hold it upside down so that liquid comes out, spray it on the memory.

    Pull the memory, which you cannot do by the way in the latest Mac books, it is soldered on, but pull the memory and get direct access to it. It will keep some of the keys in memory. That's a very difficult way to do it. Apple has some things still built in that are still functional that can and will stop that type of a hack.

    Okay. And when we get back, we're going to talk more about the hardware security, what you can do, the different levels of it, and everything else. Your listening to Craig, Peterson.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Using TPM to Secure Windows and Linux Operating Systems plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses the uses of TPM in securing Windows and Linux

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple's T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to delve now into the idea behind keeping your data safe on your disks and what are the different regulations about it? Cause there's a few right now that you need to know about.

    Hi everybody. Welcome back, Craig Peterson

    We're talking today, at least this hour about security because of a major security problem that was announced this week, about Apple's security chip, the T2 chip. not a very good thing, frankly and so going through all of this right now and we're going to move upscale just slightly here.

    I love this quote here. It was in ARS Technica this week, and it is from a gentleman who worked for the NSA his name's Patrick Wardle. He's an Apple security researcher at the enterprise management firm JAMF JAMF. I've talked about them on the show before they have some great management software.

    He's also a former NSA researcher. And he said I had already assumed that since T2 was vulnerable to CheckM8 Check M eight. It was toast.

    He said, okay, there really isn't much that Apple can do to fix it. It's not the end of the world, but this Chip, which was supposed to provide all this extra security is now pretty much moot. So it's, an interesting time here.

    Wardle points out that for companies that manage their devices using Apple's activation lock and find my features, the jailbreak could be particularly problematic, both in terms of possible device theft and other insider threats. He knows that the jailbreak tool could be a valuable jumping-off point for attackers looking to take a shortcut to develop potentially powerful attacks Quote you likely could weaponize this and create a lovely in-memory implant that by design disappears. On reboot. By the way, that is a very common method now for much of the smell where it's memory resident, there's no sign of it on disc. It never hits the disc. So your antivirus software, ain't gonna find it because when it scans the disc, it's just not there. It's just amazing. So the bottom line here is building in hardware security mechanism is always a double-edged sword. That is true, not just of the Apple side, but over on the windows side and the union Linux sides, there's something called a trusted platform module also called TPM. This is an ISO standard here. It's standard for a secure cryptoprocessor. Just like that T2, it is a processor. It is a computer and it's designed physically to be almost impenetrable. I call it elephant snot. It's that really hard epoxy that they put onto the chips so that you can't get into the chip without destroying it. There are other methods for it as well, to try and keep that data safe.

    But it's been around now for quite a few years, the most recent edition of it came out in about 2016. There've been a few errata, but it is designed to have a hardware, random number generator. Now that's important because having a secure cryptographic key, it means you have to have a very good source to generate that key with, and that means a very good, random number generator. Most processors aren't that great, man. I could talk for hours about the problems we've had over the years of these types of things. That's the whole idea behind the trusted platform module. It can also store those keys. It can also identify itself and the computer uniquely, which is very handy when you are trying to log in, you can use the TPM to help to identify the machine. It has bind keys. It's public key cryptography. It's an RSA key and ceiling as well. So it allows the TPM to be used or not be used. I'm trying to keep this pretty simple. Department of Defense is now specifying that all new computer assets that are purchased by the DOD must include a TPM or a trusted again remember platform module that is version 1.2 or higher. There are details on that. You can look those up, but I've gotten to say no matter who you are, what business you're in, you really should make sure the computer you buy has a TPM in it. Now we have seen security problems with TPMS by certain vendors. They've fixed them, just like this T2 problem with Apple. I'm sure it'll be fixed. By the way, the T1 chip from Apple does not have this problem, it's just the T2 chip, but the whole TPM is really there to help ensure the integrity of the platform. In other words, the operating system, the hard desk, the encryption for the heart.

    So if you're using BitLocker on Windows, it works best with a TPM. So BitLocker and windows will encrypt the desk using the key that is generated by and stored in the TPM on the machine.

    So write that one down and in my cybersecurity mastery course. We talk about BitLocker and how to use it and TPMs and how to just select those.

    Also nowadays, you're going to find the newer computers no longer have bios in them. You probably already figured that one out. Most of you guys, right? You are the best and brightest out there. But they have UAF, I mentioned earlier, that's the unified extensible firmware phase to boot.

    So the UEFI works with the TPM to create this kind of circle of trust crust if you will. It's absolutely phenomenal. So Linux has its own little thing called the unified keys set up. I already mentioned BitLocker's private core and various other things. Full disk encryption. Very important.

    There are utilities to do that again on Apple. It's very easy to set up full disk encryption in all these cases here where you should be using your TPM or T2 chip in order to do that. The authentic catered mechanism. It just me authentication mechanism in. The software can be hacked in hardware.

    Usually can't be hacked. What have we just been talking about for the last half hour? yeah. Hacking the hardware. But that's what the TPMS is all about. That's what gene to do. There's discreet, TPMS, there's TPMS that are built right onto the motherboard. And, there are also some that run as software-only solutions inside the CPU itself.

    That's part of their trusted execution environment. Not really fond of those. But now, you know what to look for. There are other things as well that we go through a lot of other things in the cybersecurity mastery course. But, one more thing before we go. And that is we talked about encryption on the hard disk level.

    So the physical hard disk itself can have encryption, which is great, but that encryption is really only useful for when you are getting rid of that disk. So you destroyed the key by removing a jumper or shorting out a jumper and now that disks data is effectively destroyed. And the disk can actually be reused again.

    Certain standards, federal government standards. we have a system that literally melts the aluminum platters right down. It's Kiln. I forgot what you call these things, but a very hot, yeah. Over a thousand degrees, but for a regular business computer, you're not going to have to worry about that.

    You need to also have a TPM and make sure that on top of that you are using BitLocker or some other type of encryption. And when you get. Way up there into the CMMC as part of the department of defense standards or the 800-171 standards from NIST, then you have to have special key management remotely that has a different key for every desk.

    And it gets pretty complicated pretty quickly, but the whole idea is to secure your data and remember. Just because it's all encrypted doesn't mean it's safe from hackers.

    We should talk about that at some point, but when we get back, we're going to talk about, but our final two final do articles of the day, listening to Craig Peterson, and you'll find me online at craigpeterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Using TPM to Secure Windows and Linux Operating Systems plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses the uses of TPM in securing Windows and Linux

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple’s T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to delve now into the idea behind keeping your data safe on your disks and what are the different regulations about it? Cause there's a few right now that you need to know about.

    Hi everybody. Welcome back, Craig Peterson 

    We're talking today, at least this hour about security because of a major security problem that was announced this week, about Apple's security chip, the T2 chip.  not a very good thing, frankly and so going through all of this right now and we're going to move upscale just slightly here.

    I love this quote here. It was in ARS Technica this week, and it is from a gentleman who worked for the NSA his name's Patrick Wardle. He's an Apple security researcher at the enterprise management firm JAMF JAMF.  I've talked about them on the show before they have some great management software.

    He's also a former NSA researcher. And he said I had already assumed that since T2 was vulnerable to CheckM8 Check M eight. It was toast.

    He said, okay, there really isn't much that Apple can do to fix it. It's not the end of the world, but this Chip, which was supposed to provide all this extra security is now pretty much moot. So it's, an interesting time here.

    Wardle points out that for companies that manage their devices using Apple's activation lock and find my features, the jailbreak could be particularly problematic, both in terms of possible device theft and other insider threats. He knows that the jailbreak tool could be a valuable jumping-off point for attackers looking to take a shortcut to develop potentially powerful attacks Quote you likely could weaponize this and create a lovely in-memory implant that by design disappears. On reboot. By the way, that is a very common method now for much of the smell where it's memory resident, there's no sign of it on disc. It never hits the disc. So your antivirus software, ain't gonna find it because when it scans the disc, it's just not there. It's just amazing. So the bottom line here is building in hardware security mechanism is always a double-edged sword. That is true, not just of the Apple side, but over on the windows side and the union Linux sides, there's something called a trusted platform module also called TPM. This is an ISO standard here. It's standard for a secure cryptoprocessor. Just like that T2, it is a processor. It is a computer and it's designed physically to be almost impenetrable. I call it elephant snot. It's that really hard epoxy that they put onto the chips so that you can't get into the chip without destroying it. There are other methods for it as well, to try and keep that data safe.

    But it's been around now for quite a few years, the most recent edition of it came out in about 2016. There've been a few errata, but it is designed to have a hardware, random number generator. Now that's important because having a secure cryptographic key, it means you have to have a very good source to generate that key with, and that means a very good, random number generator. Most processors aren't that great, man. I could talk for hours about the problems we've had over the years of these types of things. That's the whole idea behind the trusted platform module. It can also store those keys. It can also identify itself and the computer uniquely, which is very handy when you are trying to log in, you can use the TPM to help to identify the machine. It has bind keys. It's public key cryptography. It's an RSA key and ceiling as well. So it allows the TPM to be used or not be used. I'm trying to keep this pretty simple. Department of Defense is now specifying that all new computer assets that are purchased by the DOD must include a TPM or a trusted again remember platform module that is version 1.2 or higher.  There are details on that. You can look those up, but I've gotten to say no matter who you are, what business you're in, you really should make sure the computer you buy has a TPM in it. Now we have seen security problems with TPMS by certain vendors. They've fixed them, just like this T2 problem with Apple. I'm sure it'll be fixed. By the way, the T1 chip from Apple does not have this problem, it's just the T2 chip, but the whole TPM is really there to help ensure the integrity of the platform. In other words, the operating system, the hard desk, the encryption for the heart.

    So if you're using BitLocker on Windows, it works best with a TPM. So BitLocker and windows will encrypt the desk using the key that is generated by and stored in the TPM on the machine.

    So write that one down and in my cybersecurity mastery course. We talk about BitLocker and how to use it and TPMs and how to just select those.

    Also nowadays, you're going to find the newer computers no longer have bios in them. You probably already figured that one out. Most of you guys, right? You are the best and brightest out there. But they have UAF, I mentioned earlier, that's the unified extensible firmware phase to boot.

    So the UEFI works with the TPM to create this kind of circle of trust crust if you will. It's absolutely phenomenal. So Linux has its own little thing called the unified keys set up. I already mentioned BitLocker's private core and various other things. Full disk encryption. Very important.

    There are utilities to do that again on Apple. It's very easy to set up full disk encryption in all these cases here where you should be using your TPM or T2 chip in order to do that. The authentic catered mechanism. It just me authentication mechanism in. The software can be hacked in hardware.

    Usually can't be hacked. What have we just been talking about for the last half hour? yeah. Hacking the hardware. But that's what the TPMS is all about. That's what gene to do. There's discreet, TPMS, there's TPMS that are built right onto the motherboard. And, there are also some that run as software-only solutions inside the CPU itself.

    That's part of their trusted execution environment. Not really fond of those. But now, you know what to look for. There are other things as well that we go through a lot of other things in the cybersecurity mastery course. But, one more thing before we go. And that is we talked about encryption on the hard disk level.

    So the physical hard disk itself can have encryption, which is great, but that encryption is really only useful for when you are getting rid of that disk. So you destroyed the key by removing a jumper or shorting out a jumper and now that disks data is effectively destroyed. And the disk can actually be reused again.

    Certain standards, federal government standards. we have a system that literally melts the aluminum platters right down. It's Kiln. I forgot what you call these things, but a very hot, yeah. Over a thousand degrees, but for a regular business computer, you're not going to have to worry about that.

    You need to also have a TPM and make sure that on top of that you are using BitLocker or some other type of encryption. And when you get. Way up there into the CMMC as part of the department of defense standards or the 800-171 standards from NIST, then you have to have special key management remotely that has a different key for every desk.

    And it gets pretty complicated pretty quickly, but the whole idea is to secure your data and remember. Just because it's all encrypted doesn't mean it's safe from hackers. 

    We should talk about that at some point, but when we get back, we're going to talk about, but our final two final do articles of the day, listening to Craig Peterson, and you'll find me online at craigpeterson.com.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Business PCI Compliance and Android Ransomware plus more on this Tech Talk with Craig Peterson Podcast

    Craig discusses PCI DSS Compliance in businesses and the increasing problem with Android ransomware.

    For more tech tips, news, and updates, visit - CraigPeterson.com

    ---

    Trojan Malware Targets Trump Supporters

    Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

    Tyler Technologies finally paid the ransom to receive the decryption key

    5G in the US averages 51Mbps while other countries hit hundreds of megabits

    Apple's T2 security chip has an unfixable flaw

    Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

    Android Ransomware Has Picked Up Some Ominous New Trick

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] If you have a business that takes credit cards if you. Ever go into a business or use a business online that takes credit cards. There are some special rules that you need to follow called the PCI standards. We'll talk about it.

    Hi, welcome back. This is Craig Peterson here.

    Verizon. I'm not sure if you've seen these before, but Verizon has security reports. It has a number of different reports and they tend to all come out annually and here within the last couple of weeks, Verizon released their payment security report for this year,. It is an annual report and it's having a look at how organizations are maintaining compliance with something called the payment card industry data security standard, or PCI DSS.

    Now we have a client I'm thinking of right now that's a small a doctor's office and they, of course, have to take credit cards and they had their credit card processing suspended by the credit card processor. I'm thinking of another one as well, which is a pizza joint. They too had credit card processing threatened for suspension. In their case, they had a couple of weeks to clean up their act and both cases. They pulled us in to help straighten things out.

    But what was interesting about the doctor's office is they sent a physical copy of the PCI agreement, the payment card industry agreement, so that if they wanted to accept credit cards, they had to sign this agreement. Now, first of all, in this day and age, that's remarkable in and of itself, right?

    We get PDFs, but how many of us just pencil whip, PDFs, or click whip, I guess PDFs, most of us. It's really rare that we read the contract and it's interesting to know too, that not only was it a physical copy, but this thing it was hundreds and hundreds of pages long. It was huge. It was absolutely huge.

    So they had to sign a physical copy of this thing. What happens is if you are accepting the payment cards, in other words, credit cards, and someone reports that there is an unauthorized charge on that card. The guys and gals at the payment card industry, start to look at your business. Now we had a case right here by my house.

    It was a Wendy's,I think it was and apparently, the manager of the Wendy's and the employees were skimming credit cards. So you'd go in, you'd give them the credit card. They'd run it and give you the card back. Wow. They didn't just run it for your lunch. They made a copy of the credit card.

    Okay. Now that's part of the reason we've got these smart chips on credit cards. Europe is way ahead of us on using those smart cards. And frankly, it's a risk, right? It's risk tolerance.

    How much risk tolerance does Visa or MasterCard or whoever have and how much risk tolerance do the businesses have that accept the cards and then how much risk tolerance do you have?

    In this case with Wendy's, they got a lot of complaints about that Wendy's store, where the cards we're all used at some point over the course of the last number of weeks and were used elsewhere as well. The owners of the cards had reported some of these transactions at other places as not right being made by them. Now the credit card companies will go ahead and give you a credit on your bill, so you don't have to pay that contested portion.

    But then, and they start looking into it a little bit more seriously. In the case of the doctor's office, they did get suspended at least for a short while. The pizza joint, we got them up to standards within the two week period that they had. So they didn't get suspended. Because what would happen to a business if that card is card processing suspended, it'd be really bad.

    Now you and I, we have to deal with the fallout as consumers because we used our card and the card might've been duplicated by someone working in that store. Our card number may be stored on a computer. In the case of another doctor's office, that's exactly what was happening.

    The card number was being stored. then that information was then being sent off for processing, and then they would repeatedly enter the card information. Now there are some sites that have these virtual terminals that you can use, which is really great, where you are typing in the card number. But remember if your computer has a keystroke tracker, a key logger on it, and you're typing in credit card numbers. That's easily recognizable and you're going to get in trouble with the payment card industry, It's a very bad thing all the way around. So be very careful.

    There are a whole bunch of security instances where this has happened and the Verizon payment security report is showing businesses just are not compliant. According to the data that they gathered here in 2019, less than 30% of organizations achieved compliance during interim compliance validation. That's like the pizza shop I was talking about, all we had to do with them was move them up to prosumer hardware. We had to get them to upgrade some of their software on their computers and change the software they were using because OMG. It was just crazy, the software. I couldn't believe what it was doing, but we got them all in all setup, all taken care of her. But less than 30% of the businesses that had to comply during the interim compliance validation period did not meet the compliance.

    My bottom line here is to start now because Man oh Man applying quick fixes instead of creating and executing an overall strategy is really going to affect your compliance with PCI or any of the other standards out there, any of them. Just like the pizza shop and the doctor's office, I just mentioned, in both cases, we had to upgrade their systems, move things around, split up their network, have better encryption on the Wi-Fi, split off a customer network. So there's no way for any of them to get back and forth, and firewall some of their internal systems. So keep that in mind as well.

    We're not going to get into the whole electronic voting thing, which also showed up in this Verizon report.

    We only have a couple more minutes, so let's get into the Android, part here. this is an important one as well because we're seeing some new tricks.

    Wired has an article by Lily Hay Newman saying she's calling them foreboding. Isn't it? here's what's happening. First of all, it's far more common on PCs, but as some of the newer research is showing that mobile ransomware has undergone an, a real evolution here.

    We've seen it to the point recently where you go to a website and that website now uses your Android phone to start Bitcoin mining. Remember that? So if your Android phone is getting like really hot. It might be making money for somebody else they're using your computing power, but there's a lot of other things that are harmful.

    Now, of course, in Bitcoin mining, it could burn up your Android phone and that's happened more than once. This silly thing gets so hot, it just melts down. But along with all kinds of types of PC malware used in these types of attacks against hospitals, municipal government, and any institution that can't tolerate downtime.

    There's another platform that's really getting hit hard recently with ransomware and that's android phones. New research from Microsoft is also showing the criminal hackers are really putting time and resources into refining mobile ransomware tools. So why do you invest money? Because you're making money?

    So the fact that they're investing money into coming up with new ransomware tools means. It's making the money. People are paying the ransoms.

    There is some new software you might not be familiar with it. Of course, Microsoft has a windows defender. It's been on windows for a bit. Now it's actually quite good.

    Microsoft also has released Microsoft defender for Linux, which really shocked me. I haven't tried it yet. And Microsoft defender on mobile. They've looked at a lot of different Android ransomware families, and apparently, they've added some really clever tricks, including a new note delivery mechanism. They've got improved techniques to avoid detection and they've even got machine learning built into the ransomware, that's attacking Android phones. That can be used to really fine-tune the attacks for different peoples android devices. So be extra careful out there, everybody.

    We talked about in the first hour an attack that's going on right now, that's primarily directed at Republicans, but I think a lot of Democrats and independents would also open these emails and opening these files it's a very dangerous place out there. Use filters, use some of the anti-malware software. On an iPhone, there really isn't any. You certainly don't need it as much, at least at this point. On Android, however, there is some great anti-ransomware software and you might just try Microsoft defender, which is a basic stopgap for you.

    But, do be careful out there, everybody.

    All right. So keep an eye out for my emails.

    We've got more coming out here. I'm trying to go up to two a week, maybe even three a week, doing a little training. You might have noticed the last three weeks, my emails have looked different and I dropped some of the information in it because I think it was just visually confusing.

    So make sure you are on my email list. Get my newsletter. Get all of this free training. All of this information that you need as a home user or a business user, or a business owner.

    Go to Craig peterson.com/subscribe. Craig Peterson that's SON.com/subscribe and have a great week.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…