Tech.Rocks Summit 2021

Lessons From Billions of Breached Records

Tech.Rocks Summit 2021 · 9 décembre 2021 · 29 min · en anglais

Résumé

Les leçons tirées de milliards d'enregistrements exposés lors de fuites de données, par le fondateur de Have I Been Pwned.

Summary

Lessons learned from billions of records exposed in data breaches, from the founder of Have I Been Pwned.

Thèmes : Sécurité

Page du Tech.Rocks Summit 2021

Transcript complet

Transcription automatique, à relire : les noms propres peuvent être mal orthographiés.

Tout droit venu d'Australie, voici Troy Hunt, fondateur d'Avibin Pound, qui nous partagera les leçons tirées des milliards de dossiers hackés. Expert en cybersécurité, place à Troy. G'day everyone and hi from Australia. This is Troy Hunt coming to you from the other side of the world. I'm sorry I cannot be there in person. We're not allowed to go anywhere at the moment. We're basically locked down in, well, let's be honest, locked down in paradise. It's fine. Don't be upset for me. I will be able to come and hopefully visit you sometime, maybe next year, hopefully not too far away. But for now, we're going to make the most of the constraints that we're all working in, and I'm going to try and give you as much information as I can about hackers and data breaches and all things have I been pining security. So I... Used to do this talk and originally I called it something like lessons from 2 billion breached records and that was fine and then it was 3 billion and then 5 billion and I think I stopped when I got to about 10 billion because I was like this is just getting stupid

where is the ceiling on data breaches and breached records So instead, these days it's lessons from billions of rich records. Until it becomes tens or hundreds of billions. And then I'll figure out another title. We have a lot of data breaches. They are absolutely nonstop. Multiple times a day I get people sending me data from new data breaches that not only I didn't know about, but the companies impacted don't know about. And the way I've come to know so much about data breaches is through running this service, which is Have I Been Pwned? Now, if you've never seen Have I Been Pwned before, it's a data breach aggregation service. And what that means is when there's a data breach, let's say a data breach like LinkedIn or Dropbox. I've been in both of those myself. Many of you would have been as well. The very, very well-known 100 million plus record incidents. Website is breached, data floats around out there, getting exchanged between other people, very often people who want to do you harm.

Sooner or later, someone sends it to me and I load it into here and I make it searchable. Now, at present, there are 568 websites, 11.6 billion breached accounts. By the time you go and check the website, it will be more. That's just the nature of how it works. And I started this service back in 2013. And when I started, I thought, oh, this will be a bit of fun. Some of my mates will use this. And, you know, it'll be a good community service. Good for people to figure out where they've been breached. You know, where should you change your password? Don't use the same password in multiple places. All the things that people are going to learn and do with this thing. Not everybody thought it was going to be legitimate. And like I sort of get this tweet in a way, you know, it's got a funny name. The website's got a funny name. Like, how do I know that I can trust with my email address? But on the other hand, at the time, I remember thinking, well, I've got like 155 million of them already.

That's what I started with, 155 million email addresses. I don't really need a few more entered into a website form. Now, of course, things did escalate rather quickly, as they say after that, and as we now know, it is a much, much larger service. But that's where it began. And one of the things that I found very interesting about running this service is just how much things have changed over time, how much my life has changed over time, and particularly the places that I've gone as a result of running, as I said before, a little service I thought some of my mates would use. The seminal moment where it just seemed to be, this is the strangest possible place I could have ended up, was when I was here in Congress in the US. This is 2017. And I went to Congress, which was very exciting for me because it's a long way, well, okay, everything's a long way away from Australia, but it was especially exciting because I had to get dressed up. Now, just to put it in context, I got dressed up for you today.

I put on a shirt. Like, I live on a beach. This is not normal. I would normally dress in a way that's not really suitable for running presentations like this. Particularly when I went to Congress, I had to go and buy a suit and a shirt and a tie. I even had to buy the shoes. But I didn't want to be too serious about it either. So I went out there and I said, look, has anyone got socks? You know, has anyone got like cool conference swag socks or something like that that's just a bit of fun? And I did get some socks. And you can see me wearing my colorful blue and orange socks here next to the very serious looking gentleman to my left. The socks I got sent were from Sophos. And they say, for those about to code, we salute you. And if that was it, it would be an interesting story and I'd move on to the next thing. But then it got even weirder because you can now buy a stock photo of my socks off Shutterstock for $199. How weird is that?

How on earth did I end up here? I still don't know. So Have I Been Pwned has turned into something much bigger than what I expected. Now, in the course of running Have I Been Pwned, I've had a lot of exposure to hackers. And I want to talk about the impressions of hackers for a moment, what we think of them and who they actually are. Because it turns out there's a big gap between them. And of course, hackers are those responsible for feeding a lot of data ultimately through to have a been pwned. I really hope they're not hacking for have a been pwned because the whole point of have a been pwned is to try and minimize the damage caused by hacking. But when they do hack and they leak the data, it obviously goes into my service. And just to give everyone a very clear picture of who a hacker is, I went to Google Images and did a search. I think we know this already, right? Like we know that a hacker wears a hoodie. It's a very, very well established fact. We know that hackers like green, particularly bright green and binary as well.

Now we've all seen enough CSI cyber and enough news stories and frankly enough advertising by infosec companies to understand all of these facts. So we know it's a little bit of a, it's almost a bit of a joke, isn't it? So why is it there? Why does it happen? It creates an emotion. It creates a sense of mystique, of fear, uncertainty. And if you're trying to get people to read your news story, that's good. If you're trying to sell your cyber thing to protect people from the evil cyber hacker, it's also good. But it's not really consistent with reality. Let's talk about reality. Let's talk about TalkTalk, which is a very, very large British telco, well over a billion pounds of value in this company. And they had a large data breach in 2015. And it was so large that they said, The TalkTalk hack cost them 77 million pounds.

That's a very, very substantial data breach. Now, at the time of the breach, of course, there was a lot of commentary from people about what they thought happened. A lot of commentary. from not just the company, but people like me who get called up and asked to make comments on noteworthy incidents. And a detective made a comment. And before I show you this, I kid you not, this is real. If you don't believe me, take a photo of it when it comes up and go and Google it afterwards. This is a real thing. A detective made a comment and they said, we believe the attackers are Russian Islamic cyber jihadis. I just saw this and I went, what? Are they any of these things? Maybe Russian. I'm not quite sure what their religion has to do with it. Maybe they're cyber. Who knows? Who knows? It was an odd term, but it does mean it's a term that does create a bit of emotion, doesn't it? Some of these things do sound a little bit scary when they're represented that way.

And we come back again to the representation of data breaches usually being inconsistent with the reality. The reality is it was this guy. It's unclear whether or not he's wearing a hoodie. And the reason why it's unclear is because this is a child. It's a 17-year-old boy who hacked TalkTalk. Imagine that. A 17-year-old child is able to do 77 million pounds worth of damage to a huge... Telecommunications company. How does this happen? There's a massive imbalance between the resources needed by an attacker to bring down an organization of sufficient scale. Now, they do take things quite seriously in the UK. They took his iPhone away. And, you know, now that I think about it, I think taking an iPhone away from a 17-year-old child is probably about a fate worth and death as far as they're concerned.

So maybe that was actually a pretty severe punishment for the guy. So let's have a look at another example of data breaches. And this is one that's very close to home for me for a couple of reasons. Now, the first one is it's in Australia. So this is the Australian Red Cross Blood Service. And a few years ago, someone who's obviously a hacker because he has a hoodie, So someone popped up and they said, hey, I've got donateblood.com.au. It's got 1.3 million Australians in there. Here's what the data looks like. And for the most part, this is very normal data breach style data. Name, first name, address. It's just a MySQL create statement. So you can recreate the data in your own environment. Blood type is a bit unusual, but then again, it's a blood donation service. Yeah, I can see why they would need to collect that. And the guy said, look, it doesn't contain passwords, so he doesn't know if I want it. Now, look, I don't really care about passwords for have I been pwned.

I don't need passwords to answer that question. Have I been pwned? All I need to do is collect an email address. Because if I have your email address and you put the email address in, I can answer the question. I don't need to go and say, well, then these were all the different things for your record in particular, which were breached. So I was interested in this because not only was it in Australia, but the second reason it was particularly relevant is I had donated blood before. So I was curious, what if I have been pwned? Again, like I'd already been pwned lots, Dropbox, LinkedIn, so on and so forth. That guy comes back and goes, yeah, here's your data. And I wasn't really happy about that. And look, I have been pwned. I'm in have I been pwned about 25 times now. And it happens over and over and over again. Now, I give the whole data breach thing and the security thing a lot of thought. I cannot stop me from being pwned. The only thing I can do is mitigate the damage when it happens.

Unique passwords, for example. So this was my data. I redacted my data birth, but it was the correct data birth. Everything else there is exactly as it appeared. And he said he was just scanning IPs. And I later learned what he was doing is he was just working through the IPv4 address range, making requests to port 80, and then seeing if there was a directory listing that exposed any interesting files like database backups. He was convinced he wasn't a bad guy, despite the hoodie. He said he was just doing it for curiosity. He wants other people to see how bad it is. And this is what the data looked like. Just sitting there as a database backup in a file path. Now, there was one other thing that made this data particularly volatile. And if we think about the process of collecting blood from someone, when I donated blood, I went to a blood bank just like this at my place of work, and I had to fill out a form.

And in the form is information about information about out eligibility criteria. Because any sort of blood donation service needs to figure out, are you a good fit to take something out of your body and put it into someone else's body? Now, many of these eligibility criteria questions are quite expected, but one of them was particularly sensitive. And it asked people in the last 12 months, have you engaged in at-risk sexual behavior? Now that is interesting for two reasons. Number one, my understanding of it, and as I learned later on, is just a very, very polite way of asking if you'd slept with a prostitute, which is very personal information. But number two, it's also very relevant information. I'm all for data minimization and only collecting what we need. But if I was to be a recipient of blood, I would want to know that important questions like this were answered by the person whose blood is going to enter my body. All of that was exposed in the data breach.

Enormously, enormously sensitive information. So data breaches are occurring through security vulnerabilities. In this case, it was misconfiguration, insufficient permissions, lack of firewall, stupidity. Let's just add that in there as well. There's always stupidity somewhere. But we're also seeing those same underlying problems prevail in other areas as well. So things like IoT. Let's talk about IoT because it's getting really, really interesting. This is a TikTok track, children's tracking watch. And I had a good look at these in 2019, this one in particular. And I investigated this in conjunction with a friend of mine in the UK, a guy called Ken Munro. He runs a penetration testing company called Pen Test Partners. And Ken had said to me, look, I think these watches are going to be terrible. They're sold in Australia. You're in Australia. You should go and get one and we'll test it.

So I'm always interested whenever someone is sort of alluding to vulnerabilities with an organization. If I go to their website, what do I see? So I go to the TikTok track website and I immediately saw a padlock and I knew that everything would be okay. That's not how it works, by the way. Bitmaps of padlocks don't work. Stop doing that stuff. TikTok track software is custom built and securely hosted in Brisbane, Queensland. Now, Brisbane, Queensland is about 100 kilometers that way from me now. So it's very close to home, and I'm a very proud Queenslander. I love our state. We've got the Great Barrier Reef and amazing things like that. If ever I was recommending a beach to someone, I would recommend they come to Queensland. If I was talking about where to securely host your data, that's probably like further down the list. And it's not that there's particularly anything wrong with that, but there's nothing particularly right about it either.

And what we learned as we proceeded is that this company was trying very hard to lean on the Aussiness of the service. We're so Australian. You can trust us so much. No, it doesn't work that way. I like the byline. We take the security of your data seriously. And when I saw that, I just had all the face palms because almost without exception, every single data breach I see begins with that sentence. Hi, Troy. We take the security of your data seriously. By the way, we lost your data. Oh, great. Thanks. So it's a term that is very close to my heart. So I'm looking at this going, you'd have to be crazy to like get one of these and put it on your child. So anyway, I got one and put it on my child. YOLO. Let's just see what happens. How weird can it get? This is my daughter, Elle, and she was six years old when we did this. And I got her one of these watches.

And you'll see the watch actually says Gator. And the way it works is that Gator is a Chinese company which makes the hardware, and then they ship it out to different companies that then want to make the APIs and the client apps and things like that. And TikTok track it simply. bought the watches from Gator, and then built all of their own infrastructure around it. And this is where the problems began because when I got the watch, Ken and I started looking at the traffic going backwards and forwards, not just from the watch, but also from the mobile devices running the mobile app. And what we found was an API that looks like this. Now this is a get request for a path that has an OData filter in it. And the filter says family identifier equals 3497. Now this number is particularly important. Because Ken is a smart guy and Ken can count, he changed the number. And he got a different family.

That's it. Very, very classic bug, it's known as insecure direct object reference. There is a reference from something that is able to be tampered with, and that cascades down and pulls a different record out of the database. When that response comes back, it looks like this. This is everything that came back from my family. It's a JSON response. Got my email address in there. First name, last name. It's all there. It was much worse than just this as well, because it wasn't just this API. There are other APIs too. There was an API to relocate a child. And again, you could change the number in the URL. APIs to pull back all sorts of other personal information and also APIs to define which parents are allowed to call the child. More specifically, which phone numbers are allowed to call the child? Because it would be weird if just anyone could call the child's watch. And actually, that's another important point.

This is not just a watch. It's a phone. It's basically like my Apple Watch, except pink and ugly and really, really big and very, very cheap, unlike my Apple Watch. But it has a SIM card. It has GPS. It has a speaker. It has a microphone. So this was a real mess. And we see these sorts of vulnerabilities over and over and over again. And one of the problems that we consistently have in the industry is how do we, after either seeing a security vulnerability like this or receiving breached data, like with the Red Cross, how do we get in touch with the company? How do we do responsible disclosure? Now, very often, my responsible disclosure ends up looking like this. This is not good. I hate this. I really hate having to go to Twitter and ask people for security content. Now, just to be clear about when this happens, someone sent me that.

or have found a vulnerability on their website or in their mobile app or their kids tracking watch, whatever it may be. And I try to get in touch with them. So I go to the website. Can I find, let's say, any sort of vulnerability disclosure policy? Tesla has a good one. If anyone wants to see a good vulnerability disclosure policy, Google theirs. Is there a bug bounty? And it's not that I want to make money from this, but bug bounties demonstrate that an organization has thought through the fact that they might have security vulnerabilities and they have now created a formal way to report them. There's almost never any of those things. Okay, so is there a contact us form? Is there an email address? Is there anything I can use to get in touch with them? Are there social media accounts? And I try these channels and very often it's like crickets. Nothing comes back. So that's when I end up here on Twitter. The problem is, as soon as I tweet this, nobody has any doubt whatsoever about what is going on.

And I'm really conscious of this because what I'm doing is I'm like shining the light on that company going, hey, in this case, Daily Objects, they've had a data breach. I'm trying to find someone to report it to and I can't find anyone. I like Brett's description here. It's a career goal. It's interesting, isn't it? People just never want to hear from me. Not like that anyway. So we need better ways. Like we need better ways of doing disclosure. One of the ways that we have, which is fantastic in many ways, is this, security.txt, a proposed standard which allows websites to define security policies. Now, this is great. And if you've ever seen a robots.txt before, it's very, very similar. It sits there on a path in your website. In this case, it sits in the .well-known directory. And then it is just text. It's human readable text. Mine looks like this. Here's my email address.

Here is my Twitter account. Here's my Keybase account. Now, because my Keybase account is there, that has my public key. So if people want to encrypt their communications, that's very easy for them to do. What I love about this is it's just a text file. That's all it is. So anyone can create this. It's basically free. Like how long did it take me to write that? It's a really good thing that we'd like to see more websites have. Now, there are thousands, probably tens of thousands of websites out there that have these already. Some of the world's largest websites run security.txt files. Pretty much every Google site does. Dropbox does. The BBC does. There are many of them out there. But there are problems. One of the problems, and this is a true story, I did some training for a bank recently, and I showed them security.txt during the training, and they were very excited. They're like, wow, this is free, and it's great. People can get in touch with us. We're going to go and do this as soon as we finish the training.

It's great because I left happy, feeling like I've made a difference in the world. And then I saw these people at a conference a few weeks later and I was like, hey, how did that security text here go? You got it up? They're like, ah, the lawyers don't like it. They think people are going to try and hack us. I'm just like, oh my God. Have you looked at your logs any time recently? But that is a barrier. It is a barrier when you have legal people and PR people to deal with. There's another problem, and I wrote about this quite recently. This is also in my security.txt. Don't even think about contacting me for a big bounty. Now, this is not a typo. I want to talk about big bounties. I want to talk about the problem that this is creating for us in the industry. Now, I think one of the best ways that I can illustrate this is to share a photo that someone else tweeted a long time ago, because this is a beautiful demonstration of a big bounty. A bug bounty is literally someone begging for a bounty.

There is no bug bounty. There's probably no vulnerability disclosure. There is no formal construct there, but they are reaching out very often by finding people's contact details in a security.txt file, and they are begging for a bounty. I want to show you what that looks like, and then we'll talk about the problems it's creating in this industry. I got this very recently. Hello, I'm Hamad, White Hat Hacker. I've identified a vulnerability in your web application. Now this is concerning for me. Now keep in mind, he sends this to a lot of people. So it's concerning for other people as well. Waiting for your positive response. Best regards, Hamad. I get these a lot. And I knew what it would be. It would be like the fortune cookie said, like a two permissive SPF record or something like that. Very often it is your website is at risk of a clickjacking attack because you don't have a cross frame origins response header or a frame ancestors content security policy or something very benign.

Easily fixed but not worthy of someone cashing in on. So Hamad and I had a little bit to and fro. I was bored. And I was like, oh no, what is it? Can you give me some details about this? And then he starts asking for money and we go backwards and forwards a bit more until it gets to the point where he says, my skills is not free. Hamad wanted to cash in on me. And I still don't know what it was he found. I'm sure it is something, and I'm equally sure it doesn't matter. The problem that this is now creating for our industry is that there are so many big bounty hunters out there sending through so much rubbish that it creates a lot of noise. And it's this old analogy of signal to noise ratio. When there's that much noise, how do people focus on the signal? When there are people sending big bounties like this, is it any wonder that when I try to reach out to an organization about something serious, as in, I have 100 million records of your data, I'd like to talk to somebody about it for free,

That creates a problem. So do use a security check. See, I'd really love to drive everyone in that direction. And do be conscious of the big bounty hunter. And if you want to know more about my very candid thoughts on that, just Google my name and big bounties. You'll find a long blog post on it. So we've talked a lot about disclosure in this and the difficulty of disclosing legitimately to organizations and then how it's made even harder by people like Ahmad. I want to leave you with one final example, which I just think is a lovely, lighthearted way to end talks. But it does demonstrate precisely the problem that we're dealing with in this industry about responsible and accurate disclosure to organizations. And it all begins with this padlock. Now this is a biometric padlock and the value proposition of the biometric padlock is that you do not need a key because it's basically always stuck to the end of your hand. You don't need a pin, you can't forget it, you just need your finger.

Now there is a YouTube account called the Lock Picking Lawyer, and this is a fantastic channel. It's amazing what this guy does. He's basically a physical penetration tester. He just checks how easy it is to break locks. I find it fascinating. There's usually nothing digital about it, and even though this looks like it might be a digital device, It can actually be opened very, very simply. So here's what happened. First of all, it's got a screw. Imagine that. What's the first thing you'd do if you saw a screw on the side of a padlock and you're trying to open the padlock? Well, a lockpicking lawyer gets his screwdriver out and he undoes the screw and the padlock falls apart. Which is not good. Padlocks aren't meant to do this. So because he's a responsible guy, he gets in touch with the company and he sends them out an email. He says, look, I got my screwdrivers out. I got your padlock, undid the screw, screw came out, padlock came undone. This isn't good. The company responded in the most epic of ways, which is a perfect, perfect illustration of the challenges that we are dealing with in cybersecurity trying to do responsible disclosure.

They said, the padlock is invincible. to people who do not have a screwdriver. And here we are, folks. This is where we are in the industry at the moment. This is the problem with our data breaches and disclosure. Look, I really hope you enjoyed the talk. There's loads and loads and loads of more material about all these things on my blog if you'd like to read more and an endless stream of info circulated things on my Twitter. But right now, I believe I am ready to start answering some questions from folks.