Παρασκευή 28 Αυγούστου 2015

Tell Me Who You Are, and I Will Tell You Your Lock Pattern


You are predictable, your passwords are predictable, and so are your PINs. This simple fact is often exploited by hackers, as well as the agencies watching you. But what about your Android lock patterns? Can who you are reveal what patterns you create?

Pattern unlock is one of the entry protection mechanisms in Android system for unlocking the screen. It was introduced by Google in 2008. By connecting 4–9 dots in a 3 x 3 grid, the user can set up an unlock pattern which is equivalent to a password or a PIN. As an alternative to the traditional password/PIN, the visual pattern has gained its popularity because of the potential advantages in memorability and convenience of input. However, the limited pattern space and existing attacks such as shoulder surfing, or smudge attack make this mechanism weak in security.

A recent study by Marte Loge, as part of her MSc thesis, presents the results from a set of 3400 users and their selected lock patterns.
"Humans are predictable, we're seeing the same aspects used when creating a pattern locks [as are used in] pin codes and alphanumeric passwords."
Lock patterns, for Android, can contain a minimum of four nodes and a maximum of nine, making there 389,112 possible combinations. In a similar fashion as passwords, the number of possible combinations grows exponentially with the length, at least up to a point.

Loge asked subjects to create three ALPs, one for an imaginary shopping app, a second for an imaginary banking app, and the last to unlock a smartphone. Sadly, the minimum four-node pattern was the most widely created one by both male and female subjects, followed by five-node ALPs. For reasons Loge still can't explain, eight-node patterns were the least popular, attracting significantly fewer subjects than nine-node choices, even though both offered the same number of possible combinations.

The minimal use of eight-node patterns, by both males and females, was a surprise. Both sexes were two to four times more likely to choose a nine-node pattern rather than one with eight nodes, even though both provided precisely the same number of possible combinations. Another unexpected finding, left-handed users tended to pick the same starting places as their right-handed counterparts.

Males were much more likely than females to choose long and complex patterns, with young males scoring the highest. The slide below illustrates the overall breakdown between men's and women's choices differently.

Loge said the number of nodes isn't the only thing that determines how susceptible an ALP is to guessing attacks. The specific sequence of nodes is also key in how complex a pattern is. Assigning the nine nodes the same digits found on a standard phone interface, the combination 1, 2, 3, 6 will receive a lower complexity score than the combination 2, 1, 3, 6, since the latter pattern changes direction.

A team of researchers formalized this scoring system in a 2014 paper titled Dissecting pattern unlock: The effect of pattern strength meter on pattern selection. They analyzed the characteristics of all valid patterns and proposed a way to quantitatively evaluate their strengths. They also designed two types of pattern strength meters as visual indicators of pattern strength.

Data breaches over the years have repeatedly shown some of the most common passwords are "1234567", "password", and "letmein". Loge said many ALPs suffer a similar form of weakness. More than 10% of the ones she collected were fashioned after an alphabetic letter, which often corresponded to the first initial of the subject or of a spouse, child, or other person close to the subject. The discovery is significant, because it means attackers may have a one-in-ten chance of guessing an ALP with no more than about 100 guesses. The number of guesses could be reduced further if the attacker knows the names of the target or of people close to the target.

Loge had several suggestions for ways to make lock patterns more secure. The first, naturally, is to choose one with more nodes and a higher complexity score. Another is to incorporate crossovers, since it makes it harder for an attacker looking over the target's shoulder to trace the precise sequence. Better yet, she suggested people open the Security category in their Android settings and turn off the "make pattern visible" option. This will prevent the drawing of lines that connect each pattern node, making shoulder surfing even more difficult.

Full disk encryption won't save you if your lock pattern is L - as in "loser"

Τετάρτη 29 Ιουλίου 2015

Stagefright: The Latest Android Phobia


Zimperium zLabs, discovered what they believe to be the worst Android vulnerabilities discovered to date. The vulnerability, nicknamed 'Stagefright', it is a media library that processes several popular media formats. Since media processing is often time-sensitive, the library is implemented in native code (C++) that is more prone to memory corruption than memory-safe languages like Java.

These issues in Stagefright code critically expose 95% of Android devices, an estimated 950 million devices. Attackers only need your mobile number, using which they can remotely execute code via a specially crafted media file delivered via MMS.

Android devices since version 2.2 are vulnerable. Devices running Android versions prior to Jelly Bean (roughly 11% of devices) are at the worst risk due to inadequate exploit mitigations.

The Stagefright vulnerability was assigned with the following CVEs:
  • CVE-2015-1538 
  • CVE-2015-1539 
  • CVE-2015-3824 
  • CVE-2015-3826 
  • CVE-2015-3827 
  • CVE-2015-3828 
  • CVE-2015-3829 
Fixes for these issues require an OTA firmware update for all affected devices. The bug was reported by Zimperium zLabs, in April in order to give Google enough time to fix the problem and send patches out to its partners. The security company says that Google has done so -- but that most manufacturers have not reissued them to users, working to the traditionally slow pace of Android phone partners. Devices older than 18 months are unlikely to receive an update at all.

Risk mitigation

Consider changing the settings on your Android apps that use MMS, like Messaging and Hangouts. Deselect “automatically retrieve MMS messages.” In the meantime, consider using alternate messaging services.

Other than that, keep your phone number private. Researchers plan to present more details at the Black Hat conference next month.

Image credit: Stagefright, Zimperium blog

Πέμπτη 15 Ιανουαρίου 2015

Who's the BOSS in Android Privacy

An Unlocked Android Phone with Tor included that does everything you need it to & more.
BOSS phone is the first of its kind. It has the size, power, and versatility capable of replacing your laptop, tablet, and current phone, while keeping your data incredibly private and secure. BOSS Phone can hold multiple SIM cards at the same time, while it’s equipped with expandable memory and unlocked for global GSM.

The creators of BOSS ask for financial support through a popular crowd-funding site. Just before I posted this, they had collected marginally over 20000 USD, about 14% percent of what they ask until 02MAR2015. We wish them good luck!

Specs (as provided by the manufacturer)

  • Super HD resolution (1200x1920 on a vast 7" display) 
  • Full access to Millions of Apps in the Play Store
  • Cutting edge Android 5.0 Lollipop Operating System
  • Bluetooth enabled for all accessories (ie. headsets, speakers)
  • Mediatek Octacore Cortex A7 chipset (top of the line with higher benchmarks, better power consumption, and lower temperatures)
  • Fully compatible Global 4G LTE and 3G for when you need it
  • Full compatibility with all Apple music and Apple TV using included apps right out of box
  • Lightning fast gaming and graphics supported by one of the fastest processors on the market 
  • Durable form factor that looks and feels great

BOSS Phone was developed by David Briggs and Nick Spriggs, Co-Founders of Briggs & Spriggs, beginning in May of 2014, after David was unable to upload a video to YouTube while attending his brother’s wedding in Turkey, due to the government’s Internet filters. Briggs began researching a geographically anonymous operating system that could easily integrate with a new kind of cellular device: the result was The Onion Router, also known as Tor. Tor was originally designed for and deployed by the U.S. Navy to improve Internet privacy via a network of virtual tunnels that prevents third party surveillance of your Internet connection, geographic location, and sites visited.

In addition to its unrivaled security features, built on top of Android’s latest Lollipop OS, BOSS Phone’s Dual SIM capability supports two different phone numbers, from the same or two different countries/carriers, with endless customization in terms of text, talk, and data plans. Boss Phone’s 7” design and Wi-Fi connectivity makes it the ideal device for watching videos, using social media, reading emails, and browsing the web. 

BOSS Phone is the first phone of its kind on the market. Unlocked for multiple carriers, while featuring a huge, stunning display that is easy to see and type on, dual SIM capabilities (for those who require 2 phone numbers or travel globally), and some of the most secure network-based privacy available on the market!  

BOSS Phone is being manufactured with user privacy as a focus. The devices will be tested by Tor/Guardian project to determine that the included software is configured correctly. 

The company hopes that BOSS Phone will be the first device certified by the Anonymity experts at The Guardian Project. BOSS is the first phone to ever be manufactured with the inclusion of rooted TOR. BOSS Phone’s embedded privacy firmware will operate at the root level, providing unprecedented levels of privacy. This special network and browser are used by everyday people, the military, journalists, law enforcement, activists, and anyone who wants absolutely secure communications and Internet browsing. 
BOSS Phone will be fully certified by the Anonymity experts at The Guardian Project.

Παρασκευή 31 Οκτωβρίου 2014

Android Lollipop Security Features

Google is reportedly offering data encryption in its upcoming Android platform – Android L(ollipop), by default. Though Google has been providing data encryption capability since past three years, it had been kept optional. The company assures users that keys/passcodes are not stored online or anywhere off your device, so Google has no way to share them. It is, however, widely accepted that majority of the users were unaware of this option. Hence, now users don’t even have to bother about turning it on, with default settings in place. The new security strategy comes hot on the heels of Apple announcing that users' data on iOS 8 is protected by passwords that even Apple cannot access. Expanded deployment of encryption by Google and Apple, however, will have the most direct impact on law enforcement officials, who  have long warned that restrictions on their access to electronic devices make it much harder for them to prevent and solve crimes. Google does not have the ability to deliver its updated operating system, called the “L-release,” quickly to most users. Several different manufacturers make smartphones and tablets that use the Android operating system, and those devices are sold by many cellular carriers worldwide. This results in what experts call “fragmentation” – meaning there are hundreds of different versions of Android worldwide, many several years old, making it difficult to keep them current with the latest security features. The newest Android devices will likely ship with default encryption in a few days, but it will take many months and probably years before most Android devices have encryption by default.


The latest version of the mobile OS has amped up its deployment of Security Enhanced Linux (SE Android) in order to bring security policy enforcement to the kernel level, and has also switched device encryption on by default.
You can authorize apps with high-level permissions and deep down they’re being granted a lot more access than necessary. With SE Android, Google is expanding and getting more fine-grained controls and containment,” said Zach Lanier, senior security researcher with Duo Labs, the research division of Duo Security. With SE Android, you’re much closer to having a real sandbox.

SE Linux has been in Android since version 4.4, but now all application enforcement is being pulled into the OS kernel. Google lead security engineer for Android Adrian Ludwig said this makes security auditing and monitoring easier on the device.
With Android 5.0, SELinux Enforcing mode is required for all applications on all devices,” Ludwig said. “Multiple vulnerabilities have been prevented since we first introduced SELinux last year; by strengthening it even more, Android becomes a top choice for enterprise customers that have really strict security standards, such as the government.

There are also rumors about multiple accounts per device, that would allow users to separate business form personal functions. The new Android for Work solution (which incorporates Samsung KNOX features) will address these issues by creating an encrypted storage and a virtual environment, basically, a smartphone inside a smartphone. After launching Android for Work, a user will see a “business home screen” with company-approved apps and can perform his/her duties using encrypted data and an encrypted Internet connection. One click ― and his/her personal home screen and apps are back. Private and work-related apps and data are fully isolated, e.g. the company email app cannot read users’ personal address book or photo library, and vice versa.

Google developers briefly mentioned something called Universal Data Controls, a centralized tool helping a user identify items like which apps, what kind of his/her personal data and what should be blocked for an individual’s smartphone. Unfortunately, there are few details on the subject. We will have to wait a few more days to take a closer look at this function.

If you're buying a Nexus 6 or Nexus 9, you can get Android Lollipop from November 3rd (if you're in the UK, you'll be able to pre-order in November and receive your phablet or tablet within a few weeks). But if you already have a Nexus 5, 7 or 10 you should get it in a free over-the-air update in the "coming weeks" according to Google's blog