Apple Ransomware Reveals Cert Problem

Researchers last week discovered the first ransomware in the wild aimed at Apple's hardware platform. While the threat was subdued quickly, it exposed the weakness of digital certificates in authenticating software to devices.
The ransomware appeared as a legitimate application because it contained a digital certificate stolen from a bona fide Mac developer in Turkey.
The certificate was used to sign an application of another developer and post a malicious update at the developer's website.
"Apple doesn't control what Mac software can be signed with what certificate," noted Ryan Olson, threat intelligence director of Unit 42 at Palo Alto Networks, which discovered the ransomware.
"Apple just wants to confirm that the software has been signed with a certificate," he told TechNewsWorld. "That limitation is in place in the iOS App Store."
Kind of Useless
"Certificates are kind of useless," said Chet Wisniewski, a security adviser atSophos.
"It's a nice idea, but the problem with managing the back-end certificate database and making sure the bad guys don't get them is pretty much impossible," he told TechNewsWorld.
"We're seeing people stealing legitimate certificates from legitimate developers who are insecure," Wisniewski added.
Theft, though, may be the hard way to obtain a certificate for malicious purposes.
"If I want to start selling and developing Mac software tomorrow, it takes all of five minutes to ask Apple for a certificate," Wisniewski said. "How does Apple know if I'm a good guy or a bad guy?"
Big Deal
Stolen certificates have played a role in some high-profile cyberattacks.
"Some of the most important cases in malware history have dealt with stolen certificates," said Liviu Arsene, a senior threat analyst at Bitdefender.
"Stuxnet and most advanced persistent threats rely on some form of valid certificate to get installed on machines," he told TechNewsWorld.
Certificates tell the machine that an application that wants to run on it is legitimate and need not be scrutinized by any defenses running on the machine.
"That's a big deal," Arsene noted. "That's why developers are encouraged to make sure they don't lose them and make sure they keep them safe in containers."
Nevertheless, certificates remain a choice target for criminals and spies.
"The certificate thing is a very low barrier, and we've seen it defeated at every level," Wisniewski said.
"It's super easy for criminals to bypass," he added.
Multifactor Authentication
One of the largest contributors to data breaches is compromised credentials. There's no easier way for a hacker to crack a network than masquerading as a legitimate user of that network.
However, even if a person's credentials have been compromised, multifactor authentication can foil a bandit attempting to use those credentials to compromise a network.
That form of authentication combines something you know (a username and password, for example) with something you have (a token, magnetic card or phone) or something you are (a fingerprint, iris or voice).
As effective as multifactor authentication is, though, it can create friction for users, which has proved to be a challenge for enterprises.
Cloud Solution
"Implementing multifactor authentication in the enterprise has been an uphill battle," said Chris Webber, a senior product marketing manager at Centrify. Multifactor authentication can create a burden for IT. An organization needs back-end structure to support it. IT needs to issue tokens to users and create a system to replace tokens that have been lost or are unavailable for immediate use.
In addition, there's been user resistance. "Users are sometimes not ready for it," Webber told TechNewsWorld.
"They find it too cumbersome. The CISOs I've talked to say their users just staged a revolt when they tried to implement multifactor authentication for security," he said.
"There's always a trade-off between convenience and security, and it can be too inconvenient for rank-and-file users," Webber added.
One way to make multifactor authentication more palatable to both IT and users is to move it to the cloud. With a cloud setup, there's no back-end hassle for IT to deal with, and people can use their cellphones as a token.
"Cloud availability means you don't need any dedicated infrastructure or servers on your premises, but it also means it works for things that are in the cloud, behind the firewall, on servers and in Infrastructure as a Service," Webber noted. "It's an everywhere solution."
Labels: Apple, Arizona, Computer Repair, Computers, Macintosh, News, Problem Solved, Scottsdale, technology, The PC Fixers, Windows
