Showing posts with label google. Show all posts
Showing posts with label google. Show all posts

Wednesday, September 3, 2014

Improving the security of mobiles and services

After the recent debacle where pictures has been leaked from Apple's iCloud, by using iBrute and EPPB to attack specific users iCloud acounts there is clearly a need to address weak security in synchronization protocols used by mobiles for backing up and synchronizing data to the cloud.

Since these apps, our built in services, on the phone relies on static information to identify and authenticate seamlessly it is relatively easy to reverse engineer the protocol and emulate an individual device. These apps and services operates on the user's behalf and can not rely on multi factor authentication (MFA) requiring user intevention.

I will here propose a solution based on a integrated chip (IC) for generating OTPs (one time passwords) to introduce some randomness to the identity information submitted from the mobile.

When the user installs and app or activates a service on the phone, the app/service registers itself as a OTP consumer to the mobile OS. The OS must be able to uniquely identify an app/service in order to prevent impersonation from other apps. No token should be required to store by the app. Most app developers are not security experts and will probably not be able to secure such a token properly.

When the app logs in to the remote service for the first time, an OTP sequence is set up in the onboard chip. The chip generates touples of passwords, one part as the actual password, and a second to use as salt for a hashing algorithm. The remote side must set up the same OTP sequence, and the process should be confirmed by the user who identifies with username, password and ideally a MFA token entered by the user. This could be a OTP generated by Google Authenticator or similar. Steve Gibsons SQRL will also be an excellent confirmation. This requires the user to create the account beforehand, or the app does this during first time login. Devices added to the account can be revoked access if they are stolen, and when devices are added the user is properly notified in a separate channel (e.g. email, SMS)

When the app or service want to communicate with the remote end this sequence will occur:
  1. App/service request OTP from IC
  2. IC generates OTP touple and hashes the first part using salt from the second part
  3. The hash is returned to the app (the app never sees the real OTP)
  4. The app supplies the hash value as part of communication setup process
  5. The remote side also generates same OTP touple as the mobile and calculates the hash
  6. Hashes are compared.
  7. A succesful compare allow for proceeding the operation.
 This will make it impossible to emulate a device by using static information. The hashing is there to obfuscate the original OTP, in order to make it even harder to guess the next password.

The proposed solution may also be used where the user is active, but as a added layer of security. Recently Tesla Motors announced that the iPhone could be used as a FOB (and probably Android/Windows devices later, guessing). If the setup process used the onboard screen of the car, scanning a QR code on the screen, the risk of illegitimate access and use of the car is minimized. This is probably just the beginning of use cases for mobiles giving access to valuable items, and security issues lies ahead.

This solution only help protect to use of a service from a mobile, not the content stored on the service providers storage. These will to varying degrees be vulnerable to other attacks, so don't put anything on a service providers storage that must absolutely not leak into the wrong hands.

This idea is free to use, but oh, I'm saving money for a Model S ;)

Monday, August 15, 2011

Patent dowry

Patents, that are originally meant to promote innovation and protect investments, has become a strategical asset in the game of alliances. For Google it has become an urgent matter to strengthen the Android ecosystem with a patent portfolio, not innovations. I guess it is important to the Android partners that they are "protected" by patents. Not necessarily things they have invented. Just any patents that can be used in the war against the other players.

Google providing a patent portfolio is merely a dowry to make the Android ecosystem attractive and protect it's inhabitants. Innovation has become a minor variable in the equation. Innovating mostly pays off in lawsuits these days, because there is always someone who has bought or patented something the innovation resembles. The genius working alone that need to protect her or his ideas is a myth. Innovation happens in teams and cooperation with other entities, and is mostly empiric.

What really happens now is patents are collected in portfolios and presented as a deck, either to be attractive or frightening. Entities are forced to join conglomerates and consortiums in search of protection. If this game is allowed to proceed any longer it will be hard, and even impossible to enter the market. An idea that competes with the existing products will not have a chance. Innovation and the free market suffers. More or less willingly cartels are born through consolidation as a result of the patent wars.

Apple is already in bed with media industry, network providers, so we already have conglomerate of corporations controlling a large part of media consumption. Now with Google buying Motorola hardware a manufacturer is the same entity controlling the largest switch (search engine) of the Internet. These entities become very powerful. As long as they behave nicely, this is not a serious problem. But this system is vulnerable in two ways. First, how can such powerful entities restrict themselves so that this power is not misused? Secondly they have a soft underbelly, as they will probably be investigated in terms of antitrust. But governments have recently become very interested in how the Internet and electronic communications can be surveilled and even controlled.

Will governments regulate or exploit the opportunity? As long as the patent war proceeds, the conglomerates will not dissolve. It is their survival strategy. But it undermines the original design of the Internet with distributed control. It does not matter if the Internet is technically controlled in a distributed manner, when the information flow is centralized.

The situation will then resemble some of the pre antitrust cases in the information technology industry. But this time it is driven by patents.

To begin with, selling and buying patents should not be allowed as this fuels the patent war. But I guess it is much more complicated to fix this problem now than ever. Big patent owners will not like the idea of their patent portfolio, expensively procured, should only be used to protect innovative ideas for a short period of time.

PS! I listened to the JavaPosse #360 Newscast while writing this. It has some interesting points about these issues, recorded almost a week before Google buying Motorola, and as such is free of speculations over why.

Further reading
Patents, Schmatents!

Thursday, July 7, 2011

Chaos is good - and why we should trust Google

Google, the search engine, does not own content it directs users to, with some exceptions. I do not trust Google everything, and I do not say they always adheres to their own "do no evil" mantra. But when it comes to limiting the powers of traditional content owners it does a decent job. Google is the net neutrality's best bet. I will explain why I think this is so.

Google plays the same role as the phone catalog, but in a much broader sense. It helps users find what they look for. If the dispatcher(s) of the Internet is agnostic to newcomers and established content providers this will help innovation, education and general informing the global community. At the same time this degree of centralization represented by the mighty Google,  is vulnerable. Misused or controlled neutral dispatching is broken and value limited.

A neutral dispatcher is important in ensuring net neutrality. Except from paid search rankings, Google's page ranking algorithm favors paths to content users prefers. I guess we are lucky to have Google. Google is no saint, and is not defending net neutrality out of pure values and standards. But it is important to their business and current position. They depend on users looking for content in a chaotic ever growing amount of content. Google creates value from chaos. Chaos is to their advantage. Content providers and owners, the kind that is lobbying against net neutrality, want control and order. E.g. Apple, married to AT&T in the US, wants you to find what you look for inside iTunes, and is does a heck of a good job providing a streamlined user experience.

Google, a strong player that does not have specific interests in providing owned content (Youtube beeing an important exception, but it is a free service and content is user provided) and with no network preferences they effectively have become kind of net neutrality guarantor. Because of their unique position in the information industry, it is their interest that the net is neutral towards all content providers.

As a consequence Google has never been closely related to content producers and network providers. Content providers even accuse Google of copyright infringements, even traffic is directed their way via the search engine.

With Android Google have become related to device manufacturers. But one should note that none of these, or at least to a small degree, has, produces or provides content. They compete on producing devices suitable for content consumption and to some degree content production.

Apple and Sony are examples of the opposite type of device manufacturers, with Sony Ericsson in a limbo position providing Android handsets. Sony Ericsson's Android handsets are typically more customized than other Android handsets. Apple is closely related to content providers through iTunes and AT&T on the network side for exclusive deal on the iPhone.

Content owners will want to shortcut the neutral dispatcher to gain advantages over other content providers. Ultimately main players in the information industry want to control distribution, and even consumer devices. By controlling the networks used for distribution and devices, they can direct, and even filter content available. This is called walled gardens, and what traditional content providers want. I interpret what happens in OECD as a content provider control coup towards network services. Content providers utilize their powers over governments to gain some (initial?) control over network services.

The architecture of the Internet, as Licklider and the other founders designed it premiered distributed media control. The design was in direct opposite of how AT&T and telephone networks was designed, and AT&T still struggles with this.

But Google can not alone defend against the forces trying to divide and conquer the Internet. Even Google will have to change business strategy if net neutrality is lost. Google is wholly dependant on the prosumer (producing consumers) and others betting on the open and neutral web (which of course is in their own interest too).

The World Wide Web and http protocol is used for providing, finding and consuming content. An open WWW is mutual dependant on net neutrality. Net neutrality is an important foundation for WWW as we know it, and at the same time helps defending against centralized control. The reason for this is the hyperlinking nature of WWW.

So what can net neutrality defenders do? The decisions needed is often counterintuitive, since you often will have to choose chaos over order and not first class content providers that only accepts exclusive deals. Prosumers must put an effort in putting all kind of common knowledge on the web under a sharing license e.g. Creative Commons to prohibit evasive copyrighting of stuff of interest to everyone. Digital tool makers must strive to give prosumers tools to mass produce good quality content. Prosumers should link to relevant content, that help glue the Internet. Network service providers must not make exclusive deals with content providers or let them to close to their operations.

Content makers should also consider what will serve them best in the long run: a close marriage with media conglomerates that was formed during the 90's or a model with room for all players in the content industries. In contrast to the job
market 20 years ago, the options are no much more dynamic. Lock-in is not a good thing when tools are democratized to a level where everybody can produce something (talent or not). A large part of the content industries will benefit from net neutrality in the long run, but established entities will often fight against it.

Governments must regulate to by intervening using antitrust  laws, but when one studies the history of media industries it is revealed that they are slow movers and too vulnerable to lobbying. The book The Masterswitch, by Tim Wu, describes the phenomena of media- and content industries since the inception of telephony and is an important contribution in the net neutrality debate.