Firefox disables “opportunistic encryption” to fix HTTPS-crippling bug

The "opportunistic encryption" feature added to Firefox last week has been disabled to fix a critical security bug that allowed malicious websites to bypass HTTPS protections, Mozilla officials said.

Now, Mozilla developers have disabled opportunistic crypto in the just-released Firefox 37.0.1 after they discovered that the implementation released last week introduced a critical bug. The vulnerability, which resides in functionality related to opportunistic crypto, in some cases gave attackers an easy way to present fake TLS certificates that wouldn't be detected by the browser. The flaw in the HTTP alternative services implemented in version 37 could be triggered by a malicious website by embedding an "Alt-Svc" header in the responses sent to vulnerable visitors. As a result, warnings of invalid TLS certificates weren't displayed, a shortcoming that allowed attackers with a man-in-the-middle position to impersonate HTTPS-protected sites by replacing the original certificate with their own forged credential.

"There was a Firefox implementation problem with Alt-Svc," Chad Weiner, Mozilla's director of product management, wrote in a statement sent to Ars. "Opportunistic Encryption is a related, but separate, feature that depends on Alt-Svc. Opportunistic Encryption was disabled because of its use of Alt-Svc. We plan to re-enable this feature once weve had time to fully investigate the issue."

Mozilla provided a bare-bones description of the vulnerability here. In a post published Tuesday, the Sophos Naked Security blog offered a more thorough description of the bug and the risk it posed:

A security researcher worked out a way to bypass HTTPS certificate validation if a web server redirected you via the Alt-Svc header.

That's very bad, and here's why.

If you had a phishing site that pretended to be yourbank.example, and handled HTTP connections directly, you'd have difficulty presenting a legitimate-looking connection.

You'd either have to use HTTP and hope your victims wouldn't notice the lack of a secure connection, or use HTTPS and hope they wouldn't notice the certificate warnings telling them that you probably weren't the lawful owner and operator of the yourbank.example domain.

Some users would probably end up getting tricked anyway, but well-informed users ought to spot the ruse at once, and remove themselves from harm's way.

But this Alt-Svc bug could be used by crooks to redirect victims to a secure connection (thus making the connection "look right") without producing a certificate warning to say that the site looked like an imposter.

Original post:
Firefox disables “opportunistic encryption” to fix HTTPS-crippling bug

Vormetric secures AWS S3 & Box data

The new Vormetric Cloud Encryption Gateway will encrypt data before it is put into cloud storage.

Vormetric has announced the release of the Vormetric Cloud Encryption Gateway, which extends the company's data security platform with protection for data in cloud storage environments.

The new product is designed to make sure that the use of cloud storage solutions can be fully embraced without the fear over lack of security controls for regulated and sensitive data.

The Cloud Encryption Gateway offers organisations compliant Box and S3 services to both employees and partners.

Garrett Bekker, senior analyst in the information security practice at 451 Research, said: "Unstructured data has no permanent home. Depending on the latest 'project du-jour' it can live in an on-premise data centre, a big-data repository, and increasingly in the cloud within popular SaaS apps or file synch-and-share (FSS) offerings like Box."

"However, the cloud security marketplace is currently composed of mainly point products that address only a few of these potential scenarios. Vendors who can address a wide range of use cases and address both cloud and on-premise repositories of unstructured data should be well received by enterprise customers."

One of the benefits of this new platform is that it encrypts data before it is saved to cloud storage, while the encryption keys and access policies are under enterprise control.

The main components of the product are that it provides encryption and policy enforcement and it is paired with a Vormetric Data Security Managment.

These will both be available as virtual appliances and the DSM can also be deployed as a FIPS 140-2 Level 2 or Level 3 certified hardware appliance.

Derek Tumulak, VP of product management for Vormetric, said: "Enterprise users love cloud file storage and sharing solutions, but in using them often violate IT security and compliance rules. IT organisations can take back control by offering users the services they want, but in a way that meets enterprise security needs."

Go here to read the rest:
Vormetric secures AWS S3 & Box data

Growing Threat of Cyber Attacks & Quantum Computers Drives the Quantum Cryptography Market, According to a New Report …

San Jose, California (PRWEB) April 07, 2015

Follow us on LinkedIn Quantum Cryptography (QC), a technique that harnesses the quantum-mechanical properties of light for creating secure encryption, is assuming ever more importance in the light of the string of major cyber attacks on government agencies and public utilities. Moreover, the vulnerability of conventional cryptographic approaches to rapid advancements in mathematical algorithms, and imminent threat of quantum computers, is spurring the development and commercialization of Quantum Cryptography techniques.

The QC concept has matured considerably, migrating from laboratory to proof-of-concept demonstrations and commercialized products since emerging in the 1980s. However, real-world deployment of the technology remains limited due partly to technological restrictions, high cost of switching to quantum systems, side channel attack risks, and difficulties in integrating the technology into existing communication networks. Quantum Key Distribution (QKD) technology is already finding application in the government and research sectors. While terrestrial QKD has already become a reality in some countries, the range of transmissions is constrained by geographic factors associated with the management of qubits relatively fragile state over long distances. Though satellite QKD networks are yet to crystallize, a number of countries are undertaking ambitious plans to set up a satellite network exclusively for QKD transmission. A number of challenges related to atmospheric turbulence, extreme power consumption, background noise, and low accuracy rate, remain to be addressed prior to implementing satellite QKD links.

The early adopters of quantum cryptographic technique include governments, military agencies or armed forces, and research institutes. Given the pace of technological advancement in recent years, the target market for quantum cryptography is poised to grow rapidly in the near term, expanding beyond the present niche areas to encompass several commercial entities, such as large and medium-sized financial companies, banks, police and gaming houses, public utilities, law and accountancy firms, power stations, and airports. Quantum cryptography in financial services market would enable safer data recovery and interconnectivity between the wholesale banks. As hardware and software costs decrease, quantum cryptography is also expected to find application in the field of e-commerce, e-government, e-health, and intelligent transport systems. QC can also be applied for transmission of biometric information

As stated by the new market research report on Quantum Cryptography, European banking establishments and government agencies have been using practical QKD systems for several years. However, the low range and lack of scalability confined the technology to research and military institutions in the United States.Backed by huge governmental funding, China is fast overtaking advanced countries in developing a nationwide quantum cryptography system.

Major players covered in the market include Alcatel-Lucent SA, HP Laboratories, ID Quantique SA, International Business Machines Corp., MagiQ Technologies Inc., Nippon Telegraph and Telephone Corp., Nucrypt LLC, Oki Electric Industry Company Ltd., QinetiQ Group PLC, QuintessenceLabs Inc., Raytheon BBN Technologies, SeQureNet SarL, Toshiba Corp., and Universal Quantum Devices, among others.

The research report titled Quantum Cryptography: A Global Strategic Business Report announced by Global Industry Analysts Inc., provides a comprehensive review of market trends, issues, drivers, mergers, acquisitions and other strategic industry activities of global companies. The single segment report provides market estimates and projections in US$ million for the global market for the analysis period 2012-2020.

For more details about this comprehensive market research report, please click here

About Global Industry Analysts, Inc. Global Industry Analysts, Inc., (GIA) is a leading publisher of off-the-shelf market research. Founded in 1987, the company currently employs over 800 people worldwide. Annually, GIA publishes 1500+ full-scale research reports and analyzes 40,000+ market and technology trends while monitoring more than 126,000 Companies worldwide. Serving over 9500 clients in 27 countries, GIA is recognized today, as one of the world's largest and reputed market research firms.

Global Industry Analysts, Inc. Telephone: 408-528-9966 Fax: 408-528-9977 Email: press(at)StrategyR(dot)com Web Site: http://www.StrategyR.com/

Continue reading here:
Growing Threat of Cyber Attacks & Quantum Computers Drives the Quantum Cryptography Market, According to a New Report ...

Chelsea Manning Is Tweeting From Military Prison

Manning sent this photo to a supervisor in 2010 with the caption "this is my problem." Three years later Manning publicly identified as female and said she wanted to be known as Chelsea Manning.

Reuters

Chelsea Manning, the U.S. soldier who is serving a 35-year prison sentence for leaking thousands of classified documents to Wikileaks, has launched a Twitter account. Manning said she will be using a phone to dictate her tweets to communications firm Fitzgibbon Media, reports CNN. Her first tweet went up Friday afternoon, and by Saturday morning she already had more than 30,000 followers.

Manning said she wants to tweet as often as possible but not about frivolous issues. "I'm hoping to stay connected w/ this account as much as poss., but would rather tweet about more meaningful things than not #lessismore," her second tweet said.

Manning also expressed hope she will be able to hold conversations with her followers through the platform. "It will be hard, but I don't want this Twitter feed to be a one-way street/conversation," Manning posted.

Manning was convicted in 2013 of charges related to releasing State Department cables and military records and will be eligible for parole after serving eight years, notes the Wall Street Journal. Shortly after her conviction, Manning, who was then known as Bradley, announced she would seek hormone therapy. A Kansas judge, meanwhile, agreed to her request to change her name to Chelsea.

Originally posted here:
Chelsea Manning Is Tweeting From Military Prison

Chelsea Manning and the Call of America’s Conscience by …

April 5th marked the five year anniversary of WikiLeaks publication of the Collateral Murder Video. The footage of a secret US military video depicted an Apache helicopter killing Iraqi civilians, including two Reuters journalists. It provided an uncensored view of modern war for the world to see. The light that shone in the darkness was the conscience of a young woman. Chelsea Manning (formally Bradley Manning) is now serving 35 years behind bars for her great public service.

After witnessing Manning confess to her role as WikiLeaks whistleblower at the court-martial proceeding in Fort Meade, Maryland, attorney and President Emeritus of the Center for Constitutional Rights, Michael Ratner said that locking her up for even a day is to lock up the conscience of our nation.

Mannings disclosure of secret government documents exposed Americas illegal wars in Afghanistan and Iraq. The Guantanamo Files revealed the state of Americas offshore gulags and violations of universal human rights according to the Geneva Convention. The secret US embassy cables let us see corrupted diplomacy serving corporate global hegemony through coercion and manipulation. Mannings conscience shed light on the real actions of the US government behind a faade of democracy. Yet, the ugly face of empire was not the only thing she showed us.

This conscience of America reminds us of the ideals that founded this country. For her, the enlistment oath she took went beyond the Constitution to the spirit of equality inherent in the Declaration of Independence. She once spoke of her deeply felt connection to all people in the world, i cant separate myself from others . . . i feel connected to everybody . . . like they were distant family.

This deep bond to others allowed her to feel the words enshrined in the sacred document and to recognize when these truths were violated. This made it possible for her to witness what was really happening behind modern war that was shrouded by the euphemism of collateral damage. This was expressed in her words; were human . . . and were killing ourselves. She was able to recognize the victims of US propaganda wars and began to see those who had been branded enemy combatants as human beings like herself.

In her courageous act of releasing these documents, she demonstrated her loyalty to the core principle of this country. At the providence inquiry for her formal plea of guilty, she read aloud a statement describing facts regarding the incident in the Iraq suburb of New Baghdad. By upholding the self-evident Truth that all Men are created equal, she aimed to account for the actions of the helicopter crew on July 12, 2007.

By calling it seemingly delightful bloodlust, she noted this to be the most alarming aspect of the video and described how the soldiers dehumanized the individuals they were engaging, and seemed to not value human life by referring to them as quote dead bastards and congratulating each other on the ability to kill in larger numbers.

She explained how when a seriously wounded man on the ground was trying to crawl to safety, instead of calling for medical attention, one of the crew members asked for the wounded person to pick up a weapon so that he would have a reason to engage. She described this incident as similar to a child torturing ants with a magnifying glass.

Manning also questioned the attitude and actions of the soldiers in the helicopter at the time of the second engagement on the video; the aerial cannon shooting of the unarmed bongo truck (a van with two adults and two kids in it) that had stopped to help a wounded man. She expressed how deeply saddened she was by the aerial weapons teams lack of concern for human life and their response of the discovery of injured children in the van, showing no remorse or sympathy for those they killed or injured.

In her request for a presidential pardon, Manning wrote how her time in Iraq made her question the morality of Americas military presence since 9/11 and she realized that in our efforts to meet the risks posed to us by the enemy, we had forgotten our Humanity.

Here is the original post:
Chelsea Manning and the Call of America’s Conscience by ...

Chelsea Manning to tweet from prison

By Faith Karimi CNN

(CNN) -- Imprisoned soldier Chelsea Manning can now communicate with the world -- in 140 characters or less.

Manning, who is serving a 35-year prison sentence for leaking thousands of classified documents, appears to have joined Twitter this week.

In a series of tweets, the prisoner formerly known as Bradley Manning said she will be using a voice phone to dictate her tweets to communications firm Fitzgibbon Media, which will post them on her behalf.

She is not allowed Internet access in prison, according to The Guardian.

"It will be hard, but I don't want this Twitter feed to be a one-way street/conversation," Manning posted to her nearly 26,000-plus followers.

Manning was sentenced in 2013, and in August of that year, she said she wanted to transition to a female.

The Fort Leavenworth Disciplinary Barracks in Kansas, where she is serving her sentence, has authorized hormone therapy for her treatment.

Manning said she suffers from gender dysphoria. Her lawyers describe it as "the medical diagnosis given to individuals whose gender identity -- their innate sense of being male or female -- differs from the sex they were assigned at birth, causing clinically significant distress."

Last year, a Kansas judge granted her request to be formally known as Chelsea Elizabeth Manning.

More:
Chelsea Manning to tweet from prison

Guerrilla artists install Edward Snowden sculpture in …

And just like that, it was gone. New York City park officials spent Monday dismantling an anonymous artists' installation at Brooklyn's Fort Greene Park

New Yorkers on their morning walks today were surprised to see a monument to controversialNational Security Agency whistleblower Edward Snowdeninstalled in a Brooklyn park.

The guerrilla artists fastened the carefully crafted bust of Mr. Snowden in Fort Greene Parkon the Prison Ship Martyrs Monument, which is dedicated to 11,000 prisoners of war who died as captives aboard British ships during the Revolutionary War. The choice of location was not a coincidence.

"We feel that Snowden's actions really continue that story," the artists anonymously told Mashable. "It is built upon a set of ideals to live freely, not be confined or surveilled or monitored by your government. You cant have freedom of expression to pursue liberty if you feel like you're doing it under a watchful eye."

The artists think Snowden will in time come to be seen as a hero, despite being characterized as a criminal by many, like many of America's revolutionary Patriots.

"All too often, figures who strive to uphold these ideals have been cast as criminals rather than in bronze," the artists told Animal.

The statue appeared in the park the morning after HBOs aired comedian John Olivers interview with Snowden, which was filmed in Russia where Snowden has been in hiding since fleeing the United States in 2013.

The artists, two of whom concocted the idea and a third who created the sculpture, spent nearly a year on the project. The bust was designed specifically for the Prison Ship Martyrs Monument and weighed 100 pounds. Their hope was that the city would leave the statue in place and allow the conversation about Snowden, security and transparency to continue. However, this plan has already failed.

The letters at the bottom of the pedestal, which spelled out Snowdens name, were removed and the statue was covered with a tarp upon discovery this morning. Later in the day the bust was removed because, according to park officials, the installation of unapproved artwork in city parks is illegal.

Twitter was quick to notice the irony of the transparency advocate's statue being concealed from the public.

Continued here:
Guerrilla artists install Edward Snowden sculpture in ...

Edward Snowden monument unveiled, then covered up, in Brooklyn park

Brooklyn hipster artistsstrike again?

A public monument to Edward Snowden was unveiled at a New York park early Monday only to be covered up by park officials later in the day. The work of art included a sculpted bust of the National Security Agency document leaker, according to photographs posted on blogs and news sites.

A group of unidentified artists revealed the monument at the Fort Greene Park in Brooklyn. An onlinevideo from the site Animal New York appears to show the individuals working late at night and into the morning to place the Snowden bust on top of a column.

It appears that the shrine was created on the site of an existing park structure that features a bronze eagle. A voice on the video says the bust of Snowden was mounted in a fashion that it could be removed "without doing permanent damage to the structure."

The video says that the Snowden bust was placed on top of the park's Prison Ship Martyrs Monument, a memorial to Revolutionary War soldiers.

Park officials later covered up the bust with a blue tarp-like sheet. Some photos posted on Twitter show officials removing the covered Snowden head from the monument.

A representative for the New York City Department of Parks and Recreation confirmed that the Snowden art work was taken down.

"Parks and NYPD have removed the sculpture. The erection of any unapproved structure or artwork in a city park is illegal," said Maeri Ferguson of the Parks' press office.

Snowden worked as a contractor for the NSA before he leaked a trove of classified documents that revealed extensive government cyberspying on American citizens. Currently a fugitive from U.S. officials, Snowden is believed to be in Russia, where he has been given asylum.

Twitter:@DavidNgLAT

Read more:
Edward Snowden monument unveiled, then covered up, in Brooklyn park

Snowden First Look: Joseph Gordon-Levitt and Shailene Woodley Film on Location in Washington, D.C.

Edward Snowden didn't leak this picture.

On Monday, Open Road Films released a promotional photo of Joseph Gordon-Levitt and Shailene Woodley in director Oliver Stone's highly anticipated biopic, Snowden, via its social media accounts.

The first look at the pair together shows Gordon-Levitt, who plays Edward Snowden, and Woodley, who plays the whistleblower's girlfriend, Lindsay Mills, walking near the Washington Monument in Washington, D.C. Stone's thriller tells the story of Snowden, a former National Security Agency contractor who leaked sensitive documents that revealed U.S. government surveillance information.

Last month, the studio released the first promotional still of Gordon-Levitt dressed in army gear.

"This is gonna be Oliver's twentieth film," Gordon-Levitt tweeted at the time. "And I feel so sincerely privileged that he asked me to play this part."

Stone is a three-time Academy Award winner as well as a military veteran. He is best known for directing Born on the Fourth of July, Platoon and Midnight Express.

NEWS: Shailene Woodley is not a "total pothead"

Last month, while promoting Insurgent, Woodley called Snowden "a hero."

"I define a hero as somebody, who against the judgment of other people, if they believe something will positively impact the world and they choose to do it and honor their integrity, that's what I sort of consider a hero, no matter how big or mall a feat they create," the actress told E! News. "And in that light, absolutely I think that Edward Snowden is a hero."

Woodley hasn't been able to meet Snowden, but she'd like the chance.

See more here:
Snowden First Look: Joseph Gordon-Levitt and Shailene Woodley Film on Location in Washington, D.C.

Edward Snowden didn’t even read all the top-secret files he leaked

British comedian travelled to Moscow to interview the whistleblower Questions why the former CIA systems administrator leaked the files Gets him to explain the security threat in the context of nude pictures Describes Snowden as America's most famous 'hero and/or traitor' Snowden, at moments, is stunned into silence by the line of questioning

By Ian Drury And Daniel Bates For The Daily Mail

Published: 01:03 EST, 6 April 2015 | Updated: 05:22 EST, 7 April 2015

582 shares

1k

View comments

Traitor Edward Snowden has revealed he did not read all the top-secret intelligence documents he leaked a move which put lives at risk from terrorists.

In a television interview the fugitive squirmed as he admitted only evaluating the files stolen from GCHQ and the US National Security Agency.

The former US spy also acknowledged there had been a f***-up when newspapers that were handed the classified material failed to redact sensitive details exposing operations against Al Qaeda.

Scroll down for video

Read the original:
Edward Snowden didn't even read all the top-secret files he leaked