Your Hard Drive is Listening! - China Rejects Trash, Takes IDs - FCC's Opaque Neutrality Stance - Facebook, passwords exposed, again, of course - Take Another Little Peek at my Heart o Book reviews, Conference Reports and Commentary and News items from past Cipher issues are available at the Cipher website * Conference and Workshop Announcements o Calendar of events o Upcoming calls-for-papers and events * Staying in Touch o Information for subscribers and contributors o Recent address changes * Links for the IEEE Computer Society TC on Security and Privacy o Becoming a member of the TC o TC Officers o TC publications for sale ==================================================================== Letter from the Editor ==================================================================== Dear Readers: The 40th Symposium on Security and Privacy will be held May 20-22 at the San Francisco Hyatt. Registration is open, and the schedule should be available Real Soon. The website lists a chair for the 40th celebration, and we suspect that the Tuesday evening reception will have some kind of festivities. There are also co-located workshops starting on Thursday of that week. The 40th Symposium follows 9 years after the 30th Anniversay celebration of the Symposium, when it was still held in Oakland. Anniversaries use 1-based counting, meeting numbers use 0-based counting, and the difference between the two systems causes computer scientists as much angst as Daylight Savings Time. The decade boundaries cause people to think about the history of the fields of security and privacy and to wonder about the lasting contributions. I have been mulling over a somewhat contrarian view of things: "Cybersecurity is not very important" by Andrew Odlyzko. The paper has attracted a good deal of commentary in the short time that it has been available. Perhaps cybersecurity is less a matter of science and more a matter of practicality. Maybe we should not expect research to have widespread impacts, maybe incremental progress is the best we can do. It's complicated. "On a clear disk, You can seek forever." P. J. Denning In a clear text, You can seek out Facebook, And see all the user passwords Outshining every star. In a clear text, You can read sooner or later, All accounts and user data, Forever and ever and ever more. (Lerner and Lane, sorry about this) Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== Listing of academic positions available by Cynthia Irvine ==================================================================== New since Cipher E147 Posted January 2019 University of Lusembourg Interdisciplinary Centre for Security, Reliability and Trust 2 PhD positions in "Security and privacy of resource constrained devices" and "Risk analysis and regulatory compliance of DLTs for transaction and management of securities" Closes April 2019 URL of position descriptions: http://www.luxli.lu/2018/11/02/two-phd-positions-at-the-university-of-luxembourg/ http://cisr.nps.edu/jobscipher.html -------------- This job listing is maintained as a service to the academic community. If you have an academic position in computer security and would like to have in it included on this page, send the following information: Institution, City, State, Position title, date position announcement closes, and URL of position description to: irvine@cs.nps.navy.mil ==================================================================== News Briefs ==================================================================== Cryptographers Angry at US Visa Issuance Dysfunction Adi Shamir visa snub: US govt slammed after the S in RSA blocked from his own RSA conf https://www.theregister.co.uk/2019/03/05/rsa_cofounder_us_visa_row/ The Register Mar 6, 2019 By Iain Tomson Summary: Adi Shamir, the "S" in "RSA", looks forward to attending the annual RSA conference each year in San Francisco. This year he did not hear anything about his visa applicaiton, so he could not travel from Israel to California to appear in person. He did address the conference via Skype, and he suggested that if researchers could not travel to the US, then events should be held elsewhere. There was widespread speculation about the visa situation. Some people suspected that the US government shutdown had created a large backlog of paperwork. One said that it appeared that "no one is is in charge." --------------------------------------- Shh! Your Hard Drive is Listening! From hard drive to over-heard drive: Boffins convert spinning rust into eavesdropping mic https://www.theregister.co.uk/2019/03/07/hard_drive_eavesdropping/ The Register Mar 7, 2019 By Thomas Claburn Summary: Modern hard drives are magnificent pieces of machinery with precision engineering. One group of researchers wondered if the drives might be multi-purpose. Perhaps the delicate electronics could sense more than just the data on the drive. Could ambient sound waves deflect the read heads enough to serve as a sound sensor? The answer, surprisingly, is yes. Although the drive heads do not respond well enough to serve as a reliable microphone, they definitely respond to loud sounds, and that is detectable using extended features of the drive's firmware. Speak softly. --------------------------------------- China Rejects Trash, Takes IDs HMD admits the Nokia 7 Plus was sending personal data to China HMD calls the event "an error" and has issued a patch. https://arstechnica.com/gadgets/2019/03/hmd-admits-the-nokia-7-plus-was-sending-personal-data-to-china/ Ars Technica 3/22/2019 By Ron Amadeo Summary: An app that was installed on a batch of Nokia phones had a disturbing and unadvertised feature: it sent data about the phone usage to a server in China. All parties involved insist it was an innocent error. [Ed. And it won't happen again (until the next time).] --------------------------------------- FCC's Opaque Neutrality Stance FCC has to pay journalist $43,000 after hiding net neutrality records FCC pays journalist's legal fees after failing to comply with records request. https://arstechnica.com/tech-policy/2019/03/fcc-has-to-pay-journalist-43000-after-hiding-net-neutrality-records/ Ars Technica 3/22/2019 By Jon Brodkin Summary: Net neutrality is a policy that the FCC ended last year, after soliciting, and then apparently ignoring, public comments. The FCC maintained that millions of the comments were from fake accounts. A journalist requested the data from the FCC website that allegedly substantiated the claim, but the FCC was not forthcoming. A lawsuit was filed to force the revelation of the data, and a court granted a partial victory to the litigant. --------------------------------------- Facebook, passwords exposed, again, of course Facebook apps logged users' passwords in plaintext, because why not Unencrypted user credentials stored on Facebook internal servers as far back as 2012. https://arstechnica.com/information-technology/2019/03/facebook-developers-wrote-apps-that-stored-users-passwords-in-plaintext/ Ars Technica By Sean Gallagher 3/21/2019 Summary: Despite the widespread availablity of technology for storing passwords securely, Facebook engineers decided that there was no need to protect passwords inside the company's network enclave. This left the passwords visible to thousands of Facebook employees over a period of many years. --------------------------------------- Take Another Little Peek at my Heart HOT WIRE MY HEART - Critical flaw lets hackers control lifesaving devices implanted inside patients Implanted devices from Medtronic can have their firmware rewritten, DHS warns. https://arstechnica.com/information-technology/2019/03/critical-flaw-lets-hackers-control-lifesaving-devices-implanted-inside-patients/ Ars Technica By Dan Goodin 3/21/2019 Summary: There are many people alive today because they carry implanted medical devices in their bodies. The devices have computers and wireless communication capabilities. Unsurprisingly, if they are devoid of standard security protections, they are completely hackable. The Conexus Radio Frequency Telemetry Protocol, which is Medtronic's proprietary means for the monitors to wirelessly connect to implanted devices, has a "raft" of security weaknesses that leave them open to everything from privacy violations to complete reprogramming by anyone within wireless range. 