Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, November 05, 2012

Mac OS Security: Gatekeeper (2)

I remember that one of WWDC 2010 session videos has a show on this topic with demos. The demo was a quick one, but it is very impressive. I have done some tests on this feature. Here are my hands-on tests.

App Store Only

First, I tried to set up my Security to Mac App Store only. This is the most restrictive option. With this simple setting, I could not download any apps from browser.

Identified Developers

This is the recommended option for most users: Mac App Store and Identified Developers. This means you can download apps from web, but those apps have to have authorized developer IDs. According to Apple, an developers ID certificate can be obtained from none-Apple Agents, such as Google, Microsoft.

I set up this option in my Mac. Then I can download any apps from Web. Only apps with identified developer IDs can be opened. For example, I downloaded a free app NetNewsWire.app, which is an app signed with Apple Developer ID. After downloading, the following warning message is display for the first time to run it:


No Open for None Identified Apps

For example, I tried to download MesaSQLite from CNET downloads. For the time bing, this app has no Apple Developer ID signed. Therefore, I could not run this app on my Mac.

No Open for Other Macs

I tried to copy this app to another Mac. Still I cannot run it. It seems that the Mac OS quarantined the app upon its download.

Anywhere

This is the most open option, as same as previous Mac OS or Windows. You can download any apps from Web and use them. The interesting thing is that I tried to temporally set to this option to get apps which I trust with no harm. Then I reset option to Identified Developers. The file I got from anywhere are free to be copied to another Mac by USB, Airdrop or network shared drivers. Therefore, Gatekeeper is only for web browsers.

Authenticated Developer ID

The key point in Gatekeeper is the concept to sign an app with an authenticated developer ID. In the WWDC demo, one interesting demo is a hijacked app. That is, to modify an app, either signed or none-signed. For those apps, Gatekeeper would identify them as potential malicious apps.

To test this case, I opened the content of the app NetNewWire by Show Package Contents from its context menu. I copied one image to the root of its content. Then I uploaded it to my Dropbox's Public area. From there I downloaded the app again. Here is the image of original app, on the left, and modified app, on the right side, on my Mac:

No matter my Gatekeeper setting is Anywhere or not, I just cannot run this app. This app is quarantined by OS upon its download. Nor I can run this by copy to another Mac (I mean copy the downloaded app).

However, if I modify the app on my Mac, I can still run it and I can copy it to another Mac. Gatekeeper is just a security gate at browser between Mac and Web.

I think Apple's Gatekeeper strategy is an innovation change in OS level. It is a very effective way to protect Mac users from attacks by malicious apps, which most sneaked in, either accidentally or social engineered downloading from web browser.

Gatekeeper is just the forefront tier of Mac OS security layers. For developers, this is a big change and it will be new trend we have to face to. If you sign your app with your ID, your app will be treated as good citizen in binary world, or white list, until you intentionally make crime, attack user computers or steal private information, for example.

This is analogous to the case of border gates of US, Canada or any country in the World, passport is a practical identify as to citizenship when you across border gates. This is by far the most effective and less costly way to protect countries. Just image how you can secure your country if you have to check periodically each one in your country to see if they are not malicious. In theory, the strategy of internally up-to-bottom thoroughly checking periodically may be the most secure method, but impossible in practice.

Reference


Read More...

Sunday, October 21, 2012

Mac OS Security: Gatekeeper (1)

Mac Mountain Lion OS 10.8.2 introduced some new changes in the area of OS security. In this blog I am going to explore the first one: Gatekeeper. It is a very interesting concept. Security concern has been with computer OS since it started. How to protect user data, information, and their privacy has become one of most important issues in personal computers. Even Apple's Mac OS has been very strong in terms of fighting computer virus or malware, with the population of Internet, Apple has realized the potential danger of malware invading Mac OS. Macs still takes very  small market share, comparing to Microsoft Windows. This has been used as an excuse for Mac not having much malware attach. However, Apple is aware the potential attack, and has been keeping very close eyes on the battles of malware against to personal computers.

Based on the information from the past WWDC, there some seminars on Mac security issues. I noticed that Apple has learned lessons in this battle. In this battle, most security focuses have been mainly on defensive side. For example, wildly used anti-virus softwares are always one step behind malware. As a result, Windows treats apps from Internet as potential malware and prompt daunting warning messages to let user to make decision to accept them or not. Apple thinks that this would be a never-win-war.

In Mountain Lion OS, Apple introduced Gatekeeper concept. This is based on a very different concept. In stead of black-kist strategy, Apple implements white-list strategy. This is very analogous to security gate in reality. Security guard will allow any one to enter as long as they have proper id card. Alarm will be on if a faulty or unauthorized id is present. As a part of Gatekeeper strategy, Apple asks all the Mac application developers to apply for Apple developer's id. Apple recomments developers to sign their applications with their ids.

Hence Mountain Lion OS introduced a big change. In order to smooth the transition to this new security practice, the new Mac OS provides three convenient options for Mac users to install apps:

  • Mac App Store 
  • Mac App Store and identified developers
  • Anywhere
With those options, users can temporally loose control on Gatekeeper if they want to install known apps without developer id. You can keep your gate door wide open by allowing Any one, but I think most people will choose the first or second option.


I think this will be a new change in app development. Any developer will require to obtain his/her id if he/she wants to distribute apps through internet.

Read More...

Sunday, December 18, 2011

Using LDAP to Authenticate Windows Users

Here are some my programming notes about using LDAP library to authenticate Windows Users.

This request came from my ASP.Net project, which is hosted on intranet IIS server. The first login page is to authenticate Windows users in the company.  I need a library to do the job.  I tried some codes created long time before, but I found that the codes is not completed.  The authentication works only in Visual Studio, but not at an IIS server after deployment. I need to fix the issue.

I found that there are many ways to do that.  One is based on our existing codes with Novel.Directory.Ldap library, another on System.DirectoryServices. I tried both in one test console application.

Here some some references and constants used in the console application:

using System;
using Novell.Directory.Ldap;
using System.Collections.Generic;
using System.DirectoryServices;
using System.DirectoryServices.Protocols;
using AD_LdapConnection = System.DirectoryServices.Protocols.LdapConnection;
using ND_LdapConnection = Novell.Directory.Ldap.LdapConnection;
using System.Net;
...
private const string LDAPHOST = "xxxx.yy.zzzz.com";
private const int LDAPPORT = 389;
private const string DOMAINNAME = "yy";
private const string CN_NAME_SUFIX = "@yy.zzzz.com";

Novel.Directory.Ldap


The first one is base on Novel.Directory.Ldap:

private static bool Authenticate(string username, string pwd)
{
  bool bRet = false;
  bool connected = false;

  // connect to LDAP server
  ND_LdapConnection ldapConnLogin = new ND_LdapConnection();
  try
  {
    Console.WriteLine("Start authenticating...\nConnecting to {0}, port: {1}",
      LDAPHOST, LDAPPORT);
    ldapConnLogin.Connect(LDAPHOST, LDAPPORT);
    connected = ldapConnLogin.Connected;
    if (connected)
    {
      Console.WriteLine("Connected: {0}", connected);

      string cn = string.Format(
        "{0}{1}", username, CN_NAME_SUFFIX);
      Console.WriteLine("Binding with {0}", cn);
      ldapConnLogin.Bind(cn, pwd);
      bRet = ldapConnLogin.Bound;
      Console.WriteLine("Bound: {1}", bRet);
    }
  }
  catch (Exception ex)
  {
    string msg = string.Format(" Error message or code: {0}", ex.Message);

    Console.WriteLine(msg);
    bRet = false;
  }
  finally
  {
    if (ldapConnLogin != null && connected)
    {
      ldapConnLogin.Disconnect();
    }
    ldapConnLogin = null;
  }

  return bRet;
}

This methods depends on ldap host name, port number, and cn name(in a format like email address in our company). One thing interesting is that the exception thrown from the binding call are error codes in Message, and no implementation of ToString() method.

System.DirectoryServices


The second method is Microsoft .Net library APIs in System.DirectoryServices. The following codes are much simpler and works in the same way to authenticate a Windows user:

private static bool Authendicate2(string domain, string userName, string password)
{
  bool validation = false;
  try
  {
    Console.WriteLine("Authenticating user by AD library...");
    var ldc = new AD_LdapConnection(
        new LdapDirectoryIdentifier(LDAPHOST, false, false));
    NetworkCredential nc = new NetworkCredential(userName, password, domain);
    Console.WriteLine("Created credencial object.");
    ldc.Credential = nc;
    ldc.AuthType = AuthType.Negotiate;
    Console.WriteLine("Binding credencial...");
    ldc.Bind(nc);
    // user has authenticated at this point, as the credentials were used to login to the dc. 
    Console.WriteLine("Binding credencial is done.");
    validation = true;
  }
  catch (Exception ex)
  {
    Console.WriteLine("Exception: {0}", ex.Message);
    validation = false;
  }
  return validation;
}

References

Read More...

Thursday, November 22, 2007

Internet Security Issue

Internet is so convenient and useful. It opens a wide door to the world. For most people, it is an important part of their lifes. However, Internet security is a problem for most people who use Internet, especially who use it doing emails, banking and evening personal stuff in their local computer. Most people don't know about it and don't know how to protect their private information.

As a programmer, I realized it and I found it so easy to get some personal private information by writing a simple program, for example, login id and password. For window users, there are some window API functions which can be used to monitor process and keyboard. They are part of Windows' core and available for all windows platforms. A programmer can easily write a program by including those APIs to log keyboard and mouse activities without user's notice (in background).

For example, I wrote a program just for personal test purpose and as a demo to show to my friends. It is a console application. When you start it in a console, it starts to monitor keyboard and mouse activities and print out keys and mouse click on the console. I tried it to login many secured programs such log in and web sites. I can see their login ids and password!

The following is a snap-shot of a case: login to a bank's web site:



You can see that login id is "watchme", then tab to the password text box with "password".

You can image that this feature can be enhanced to work with some process monitors to monitor specified process and steal your personal information (I also verified that there are Windows APIs available to check current process and their titles such browser changes). Some virus or unknown programs can be easily installed in one's machine with those kind of spies.

How can you protect yourself? As a demo shown above, I always advice people don't type in your personal information in a regular habit: login id, tab or mouse click, and then password! You can make fool of these monitor programs. Don't type in your login and password continuously and correctly! You may purposely type in wrong ones or partial ones. Jump around between login and password, even browser tabs. Type something on the page. Make it hard for the spy programs to get your personal information! As well, change your login password regularly.

Some web sites provide more security options for users. For example, in above demo, there is an optional description for you to type in anything. After login the site, this site may ask you additional questions you have previously set if you login from a new location (which may be inconvenient for many users). All these efforts are made to protect you.

Read More...