Showing posts with label twitter. Show all posts
Showing posts with label twitter. Show all posts

18 January 2015

Hacker cons and speech codes

A woman who uses the Twitter handle @avriette ("jane, the destroyer") had a problem with a talk at Shmoocon. @avirette tweeted
@avirette: So there was a talk at #shmoocon that was unnecessarily sexist (& gross really). I spoke out about it. People thanked me for doing so.
She followed up:
@avirette: People told me in person, in DM. The speaker(s) denied it was sexist rather than owning it and apologising.
@avirette: This is the reason people don't speak up. Nobody believes anything will be done, that anyone will change. This is why we need rules.
(bold is my emphasis)

Someone using the Twitter handle @ZeroFox (I am told that this acount is run by a woman who does marketing for ZeroFox) responded to one of her tweets and offered for the speakers to meet her in the hotel lobby to discuss the talk. She refused:
@ZeroFox: are you at the conference? We're in the hotel lobby and happy to grab a coffee and get your feedback
@avirette: you could have presented that talk very differently Try, next time, imagining there are women in the room.
I responded to her tweet:
@theprez98: Didn't see it, not taking sides...but the speaker offered to meet you to discuss. Doesn't seem unreasonable.
I recognize that everyone is not going to like everything. Some people are going to disagree over whether something is "sexist" or not. And to repeat what I said in my tweet, I didn't see the talk. I'm not taking a position on whether the talk was sexist or not. But there's a larger issue here. What I don't want is "rules." I assume she means speech codes (see this blog post on the evil of speech codes by Rob Graham), but I can't really ask her because she blocked me (and by the way, if by "rules" she doesn't mean "speech codes," then I'm happy make a change to this blog post). Here is a screenshot of her tweets:


Does @avriette think that she is doing her cause any good by branding a speaker's talk as sexist and then refusing her apparently good-faith effort to meet with her to discuss the issue she had? I certainly don't.

Dear @avriette, if you happen to read this: if you believe that the talk you saw was sexist, I'm in no position to question your sincerity. But I don't think you did yourself (or other women with similar concerns) any favors today. That's my $0.02.

12 November 2012

Twitter sniff test for fake followers (read: @GregoryDEvans)

There are a number of ways to look at someone's Twitter account to see if they have artificially inflated their followers (i.e., buying follower lists), but I wanted to add one of my own. This isn't a definite test, but should give you a good sense of whether someone's followers are legit.

It's a very simple ratio of followers to lists. In the case of my account, it's 2,295 (as of 11/12/12). Now figure the number of lists the account is on (this isn't displayed directly by number on Twitter, but is displayed on Tweetdeck or other similar Twitter clients). Again, on my account, it's 141 lists. So 2,295:141 reduces to about 16.3:1. In my experience, I have found that a range of 10-25:1 is very common among most people. I don't have enough data to know how well this ratio scales to significantly higher number of followers, but the ratios to tend to be higher; in the range of 40-100:1.


The idea here is that your legitimate, engaged followers are likely to put you on their lists, while fake followers don't actually do anything.

For this blog post, I looked at (an admittedly small sample of) ten people I follow, who have followers from under 100 to over 100,000. In all but one case, the ratio was between 10-25 to 1 (in the one off case, it was 6:1, an argument for more engaged followers, not less).

Now let's take a look at one example, the infamous @GregoryDEvans. He has 42,331 followers but is only on 45 lists. A ratio of 940:1! Realistically, he should be on 2,500-3,000+ lists (and even here, he is on several lists that are unique to his situation). Fake followers, anyone?

Feel free to punch holes in this test. Any ideas?

06 June 2012

A phone call, a death threat, and WTF just happened?!

A few nights ago, my wife answered my cell phone and the caller (whose ID was either unknown or blocked) asked for me by name. I wasn't immediately available so she asked if she could take a message. The caller did in fact, leave a message (paraphrased):

"You tell that fuckin' asshole that I can have him and his whole family murdered."

Yikes.

I reported the phone call to the police.

But who was it?

I have no idea, but I can speculate (and I say speculate because I have no evidence to back this up). As many of you know, I post a lot of politically-related things on Twitter and Facebook. And as many of you know, political discussions online are often very toxic. Recently, they've spilled over into real life: several conservative bloggers have been SWATted. Now I don't blog nearly as often as some of these folks, nor do I don't have nearly the audience (and I consider myself more of a libertarian than a conservative, but that's really not important). But I think (and again, I am only speculating) that I probably said something on Twitter that tweaked someone and they felt the need to respond. With a life threatening phone call. A little overboard, don't you think?

I served nearly 9 years in the Navy, fighting for this country, so that we can enjoy the freedom of speech. Nice way to repay me, thank you very much. Either way, and regardless of the reason why someone did it, I won't allow anonymous threats from a coward to intimidate me or my family.

17 April 2012

Vacations and social media opsec

I just returned from five days of vacation in Florida. Chances are that (unless you follow me on Foursquare and scrutinize my check-ins) you probably didn't know I was gone. We posted no pictures of our vacation activities, didn't make any comments or posts related to what we were doing. One exception that I noted above was Foursquare, where I did check in partly to record our trail of activities and also because I have less followers there and was less concerned about word getting out.

Sites like Please Rob Me (if perhaps a bit over-hyped) highlight the concerns about posting your activities on social media. Especially important is when you're away from home for an extended period of time. Thus, this was a deliberate strategy that Tracy and I followed explicitly for this purpose.

But this is probably not enough. I post a lot on both Twitter and Facebook and if I suddenly disappeared for a while, someone might take notice of that, too. So, step two: Using Buffer (or some other similar application), each night I scheduled a series of tweets and posts spread out during the next day on subjects that I usually talk about. From a third party perspective, things ought to seem just plain ordinary. So when you thought I was tweeting about some infosec article, I was probably riding a roller coaster. :-)

The idea here wasn't or isn't to trick anyone or orchestrate some elaborate deception campaign, just to be careful about what you're posting in similar circumstances; and follow that up with the same sort of content and material that people already expect of you.

Now that we're home again, you can expect to see pictures from the vacation in the near future. I also have some notes about some of our interesting experiences over the last week to flesh out into blog posts.

Now, I need some sleep...

18 March 2012

MS12-020, exploits, and words mean things

On Friday, Core Security announced that they had released an exploit for CVE-2012-0002 (patched by Microsoft as MS12-020):
I thought this was great news. I am currently working on a client engagement with a lot of RDP on their network and we use Core as one of our tools. Time to pwn, right?

Not quite.

As subsequent tweets made more clear, the Core exploit was a denial of service module, not code execution. This got me thinking--what does it mean when you call something an exploit? I am a moderately-experienced penetration tester, and I think there's probably a misunderstanding about what this means. To me, an exploit is something that results in arbitrary code execution. Maybe a denial of service that results in a BSoD is an exploit, technically, but that's not what I expect the word to mean.

I hadn't thought about it much this weekend until HD Moore of Rapid 7/Metasploit summed up my feelings earlier today:
So, what do you think?

Is a denial of service module an exploit? Does it really matter, or are we splitting hairs?

EDITED TO ADD: And to add to HD's tweet: what exactly does commercial grade mean in reference to a DoS module? Does it give you an extra special BSoD? It seems the words in Core's original tweet are specifically designed as marketing pull, and as a result, imply that the module is a code execution exploit when it is not. The tweet clarifications made it obvious to me that others were as confused as I was.

Lastly, "Enjoy!" seems to suggest that we will like the result. I don't know about other penetration testers, but I can't think of any clients who have ever asked me to run DoS modules against their systems, and even if they asked me to do it, I'd probably advise them against it. What about you?

10 January 2011

NYT article on "secret subpoenas" misses the issue entirely

This article in the New York Times is, frankly speaking, terrible (emphases are mine):
THE news that federal prosecutors have demanded that the microblogging site Twitter provide the account details of people connected to the WikiLeaks case, including its founder, Julian Assange, isn’t noteworthy because the government’s request was unusual or intrusive. It is noteworthy because it became public.
For the Twitter request, the government obtained a secret subpoena from a federal court. Twitter challenged the secrecy, not the subpoena itself, and won the right to inform the people whose records the government was seeking. WikiLeaks says it suspects that other large sites like Google and Facebook have received similar requests and simply went along with the government.
This kind of order is far more common than one may think, and in the case of terrorism and espionage investigations the government can issue them without a court order. The government says more than 50,000 of these requests, known as national security letters, are sent each year, but they come with gag orders that prevent those contacted from revealing what the agency has been seeking or even the existence of the gag orders.
Let me rephrase the relevant parts into an explanation:
The government issued or obtained a secret subpoena (without a court order), known as a national security letter, to compel Twitter to provide the details of people connected to the Wikileaks case.
Uh, no. Not even close.

First, as both Christopher Soghoian and I have noted, it is not a subpoena, but a court order, and it makes a difference.

Second, as you can see below, the order is authorized by Title 18, United States Code, Section 2703(d).  National Security Letters are authorized by Title 18, U.S.C., Section 2709.  The difference is huge.  The Twitter court order (see below) is authorized by 2703(d) and signed by a federal magistrate.  Section 2709 National Security Letters are administrative subpoenas by the FBI and not signed by a magistrate or judge.

Third, there are distinct words in the order below:
...the Court finds that the applicant has offered specific and articulable facts showing that there are reasonable grounds to believe that the records or other information sought are relevant and material to an ongoing criminal investigation.
This is not just legal mumbo jumbo.  These words are carefully selected because they represent the legal standard required to issue a court order.  In fact, the "specific and articulable facts" standard of 2703(d) derives from the Supreme Court's decision in Terry v. Ohio, 392 U.S. 1.  A subpoena, even under 2703(d), would require a lower legal standard called reasonableness.

The entire article is based on the misunderstood claim that the Twitter court order is a National Security Letter administrative subpoena.  I am neither a lawyer, nor a journalist, but it doesn't take a genius to figure out that the New York Times misses the issue entirely.

Twitter 2703d Court Order

09 January 2011

On defining "subpoena"

I'm working on something more substantive right now in relation to the Wikileaks / Twitter / court order situation, but for now I'll point you to Christopher Soghoian's post at his slight paranoia blog.  I don't necessarily agree with everything he says, but he attempts to cover the issue.

I do, however, have to raise an objection to his description of a subpoena.  He's trying to make the point that the media has referred to the court order as a subpoena when it is in fact a court order, because he thinks the distinction is relevant (and he's right).  He then goes on to define subpoena:
Subpoenas are essentially letters written by law enforcement officers, on official agency letterhead, and have not been reviewed or signed by a judge.
I contend that this is inaccurate, at least in part.  A subpoena is an order to compel testimony or produce evidence.  When it comes from a court, it is a judicial subpoena.  What he describes comes from an agency; it is an administrative subpoena (such as National Security Letters) that does not require a signature (but even then, the Patriot Act allowed for judicial oversight of NSLs).  So in fact it is important to distinguish between whether or not the subpoena originates from a court (judicial) or from an agency (administrative, the power of which must be expressly authorized by Congress).

A subpoena is considered the least intrusive method of obtaining information, so it has the lowest standard (what the courts call "reasonableness").  A court order requires that the government show "specific and articulable facts showing that there are reasonable grounds to believe that the contents of a wire or electronic communication, or the records or other information sought, are relevant and material to an ongoing criminal investigation."  Note that a court order is considered more intrusive than a subpoena but less intrusive than a search warrant.  A search warrant is the most intrusive method, and requires probable cause.  With each higher method of intrusion, the government is required to meet a higher standard, but gains access to additional information.

Neither Chris nor myself are lawyers; so I guess we'll leave it to them to sort out. :-)

16 December 2009

Are health care mandates constitutional?

One of the provisions of the current health care reform bills being considered is a so-called health care mandate, which would require people to purchase some level of coverage or pay a fine.

Last night, I posted on Twitter:
Someone please tell me where in the Constitution it allows Congress to force me to buy something or become a criminal, just for being alive.

And so I ask again, where is this provision?

The few answers that can be found are pretty weak. Congress trots out the commerce clause for just about everything, so that's a popular answer. The congressional power of taxation is also cited, which is pretty interesting in and of itself. If Congress justifies a mandate by claiming their power to tax, are they willing to come full circle to admit that the mandate itself is a tax? If so, how does this impact the President's pledge to not raise taxes on the middle class?

The idea of a mandate is not a new one. During the health care debate in 1994, such a mandate was also discussed. At the time, the non-partisan Congressional Budget Office wrote:
"The government has never required people to buy any good or service as a condition of lawful residence in the United States."

Further, it was "an unprecedented form of federal action." This article from the New York Times (and reposted on SFGate.com) is one of the few that is at least willing to talk about the issue of constitutionality. The last sentence is enlightening: "If the individual mandate were found to be unconstitutional, the health care overhaul as it is now structured by many committees in Congress would almost certainly collapse."

So for those of you that support the administration's health care reform plans, I'd be interested to hear your justifications for why Congress has the power to require me to buy something as a condition of living in the United States.

02 December 2009

"Your account has been locked. Please contact your system administrator."

When I arrived at work this morning I attempted to log onto my desktop and got the dreaded "Your account has been locked. Please contact your system administrator."

Calling the "help desk" the technician cheerfully confirmed that my account had indeed been locked, and that there was a note not to enable it, but to contact the "security center."

Calling the "security center" the person answering the phone also confirmed that my account had been locked (thanks!) and claimed that it had been done on behalf of someone in another security office.

Calling the next security office it was confirmed a third time that my account had been locked, and the kind gentleman let me know that he would have it unlocked in no time.

But wait, I asked. What had I done to warrant my account being locked? He said he was looking into it. Really? They lock my account, is readily prepared to unlock it, but is still looking into why it was locked in the first place?

About ten minutes later my phone rang and the nice lady on the other end told me she was writing up an "incident report." Oh, great. Well, I figured, I would at least figure out what I had done wrong.

She asked me if I had visited a site called CoTweet. Well, of course I had. I use CoTweet at work to manage my Twitter account, and had been using it every day for at least six months or so. She kindly informed me that CoTweet was on the "prohibited sites" list. She then asked, "What do you use the site for? Is it work-related?" I explained that I use CoTweet (or Twitter for that matter) to keep in contact with other people in the security community. And that yes, it was work-related, but if they insisted, I could live without going to this site (while you might see this as backing down, from my perspective as a contractor it would not be a good idea to pick such a fight with a client's IT staff).

The phone call was short and sweet, and I politely mentioned that if CoTweet was indeed prohibited they should actually block it, which they do not. (Some other sites like Facebook and YouTube are in fact blocked, but neither CoTweet, nor Twitter for that matter, are blocked). She finished up the incident report and my account was active again within 15 minutes or so.

The incident brings up a few questions:

1. Why lock someone's account but not provide them with the information that it had actually been locked, and a means to contact someone for it to be unlocked? I had to figure out everything myself, which clearly wasn't rocket science, but surely there should be some notification procedure in place.

2. Why isn't Twitter, or CoTweet, actually blocked? If you were to go to Facebook, YouTube, or any number of other sites, you would be greeted with a bright red warning screen (affectionately called the "red screen of death") explaining that the site was blocked (incidentally, this seems to happen fairly regularly for most users; mostly by accident, and doesn't ever seen to result in any "incidents"). However, Twitter is generally accessible (at least it has been; lately it errors out but the RSOD is never displayed); and CoTweet works.

3. What sites are actually on the prohibited list? Clearly the blocked sites are on this list, but apparently other non-blocked sites (like Twitter and CoTweet) are also on the list). You might be wondering at this point (as I was), would it be possible to see this list so that we know what sites to avoid? Well, of course not. No one has ever claimed to have seen such a prohibited list, but it apparently does exist. I am not suggesting that my place of work does not have the right to block whatever sites they see fit; they clearly do have this right. But I think they also have a responsibility to their users to let them know the specific policy. Social networking sites are embraced by some businesses, but under fire by many others. So I understand the issues with these sites. But educating your users on such policies is key.

One could argue that Twitter is not really necessary, or "work-related," but I find it invaluable on a number of fronts. With Twitter and CoTweet effectively out of bounds (and third party clients like TweetDeck would just been seen as attempting to bypass their apparent restrictions, or a violation by installing unapproved software. So for the time being (during the day at least), I'm out...