Despite the plethora of advice about designing security from the beginning, all software has bugs, and none moreso than communication protocols. Our news items for this issue have examples of the endless battles to make computing secure. For example, the world of operating system security was shaken by the discovery of side channel attacks on Intel and AMD processors that reveals supposedly protected information on shared servers and even web browsers. Spectre and Meltdown are interesting exploits, but it seems that the remedies slow down most operating systems, so we can expect some forthcoming design proposals for hardware that diminishes side channels without sacrificing speed. As usual, the upcoming months are jam-packed with conferences for researchers to share their findings. Attend and listen or read the proceedings at your leisure, the security world is always changing. Be aware, be vigilant, and may your data be safe. Be careful taking risks with stocks, Through a financial institution. Lest you succumb, Defenses stunned, To speculative execution. Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== Commentary and Opinion ==================================================================== Book reviews from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/BookReviews.html, and conference reports are archived at http://www.ieee-security.org/Cipher/ConfReports.html ____________________________________________________________________ Book Review By Sven Dietrich Jan. 29, 2018 ____________________________________________________________________ Attacking Network Protocols by James Forshaw No Starch Press 2017. ISBN 978-1-59327-750-5 336 pp. James Forshaw of Project Zero at Google authored this book. His presentation about the background materials for understanding network protocols makes for an easy read from start to finish. The book starts off with an introduction to networking basics before going onto how to capture application traffic, understanding network protocol structures, and using advanced concepts to capture traffic. One chapter covers analyzing traffic from the wire using tools such as WireShark (an entertaining task, from my personal experience). What makes this book exciting and relevant is the occasional interspersing with useful and directly applicable pieces of code (you can even download a ZIP archive with the code pieces from the book website) to support your traffic analysis inner geek. Also covered are the topics of reverse engineering applications, looking at network protocol security and its implementation. Then it segues into vulnerabilities, fuzzing, and finding and exploiting bugs (which after all is something many of us cherish). Overall, this is a compact book for the novice in traffic analysis wanting to make a foray into playing with packets and different capture environments, be it scripting, proxies, or more challenging Python code. There are ten chapters about feeling the network pulse and application analysis (static and dynamic), and topping it off is a network analysis toolkit in the Appendix. Whether you're a pen tester, fuzzer, or a serene developer seeking understanding of what not to do, this book is an excellent beginner's guide. I hope you will enjoy reading this book as much as I did. James Forshaw is a well-respected security practitioner, has made his share of contributions deserving of bug bounty, and in this book he gives an introduction to the best practices for attacking network protocols. ----------------------------------------- Sven Dietrich reviews technology and security books for IEEE Cipher. Some companies are raising a lot of venture capital to achieve that goal for corporate clients. Some seek to provide an isolated environment with a strong "gatekeeper" for all web transactions. ----------------------- US Points WannaCry Finger at (surprise) North Korea U.S. declares North Korea carried out massive WannaCry cyberattack https://www.washingtonpost.com/world/national-security/us-set-to-declare-north-korea-carried-out-massive-wannacry-cyber-attack/2017/12/18/509deb1c-e446-11e7-a65d-1ac0fd7f097e_story.html By Ellen Nakashima and Philip Rucker The Washington Post Dec 19, 2017 Summary: North Korea's cybercrime capabilities have grown rapidly, and the US acknowledged this in attributing the WannaCry ransomware attack to the reclusive country. The attack caused a great deal of damage in Europe, though it may not have garnered much ransom payment. There are few ways to increase pressure against North Korea without causing even more suffering to the general populace which seems to face constant food shortages and forced labor. ----------------------- Watching the Inauguration Through Hacked Police Cameras? Romanian hackers took over D.C. surveillance cameras just before presidential inauguration, federal prosecutors say https://www.washingtonpost.com/local/public-safety/romanian-hackers-took-over-dc-surveillance-cameras-just-before-presidential-inauguration-federal-prosecutors-say/2017/12/28/7a15f894-e749-11e7-833f-155031558ff4_story.html By Rachel Weiner The Washington Post Dec 28, 2017 Summary: A year ago two Romanians manged to take over nearly 200 DC police cameras. Their motive seemed to be establishing a spam botnet, but it left the surveillance system inoperative during the presidential inauguration. The alleged culprits are facing extradition from Romania to the US. It is possible that they simply unleashed the malware and had no idea where it landed. The Internet of Things is sometimes a welcoming Petri dish. ----------------------- From the DNC to the US Senate, Russian Hackers Push the Boundaries Russian hackers who compromised DNC are targeting the Senate, company says https://www.washingtonpost.com/world/national-security/russian-hackers-who-compromised-the-dnc-are-targeting-the-us-senate/2018/01/12/7e9169ce-f7a9-11e7-91af-31ac729add94_story.html By Shane Harris The Washington Post Jan 12, 2018 Summary: The security firm Trend Micro reports that the Russian hacking group that stole Democratic Nation Committee emails and gave them to Wikileaks is actively preparing for the November midterm elections. The group known as Fancy Bear (aka Pawn Storm) is using spear phishing emails to direction Senate staffers to websites that mimic trusted sites for Senate documents and email. This allows the hackers to steal login credentials from unwary users. ----------------------- Be Secure, Be Slow Here's how, and why, the Spectre and Meltdown patches will hurt performance https://arstechnica.com/gadgets/2018/01/heres-how-and-why-the-spectre-and-meltdown-patches-will-hurt-performance/ By Peter Bright Ars Technica Jan 11, 2018 Summary: Modern computers speculate. They execute computer instructions before they are needed, while something slower is going on, and if the result is needed, it can be used immediately. This clever technique of speculative execution makes software run fast but not securely. The computer retains information about the side effects of the execution, even if the result is not used because of permission violations. This can cause a significant leakage of information on a shared server or in a browser with compromised Javascript code. Two ways of exploiting this principle emerged recently. The attacks, named Spectre and Meltdown, require fundamental changes in operating systems, and those changes, which are just now emerging as patches, make computer systems run noticeably more slowly. 