Italian Digital Signature Software Exposed to Man-in-the-middle Attack?

An independent researcher compiled a list of known Apple OSX-related vulnerabilities, including one that affects the Sparkle Updater Framework.

I’ve just checked my Mac with this command

find /Applications -name Sparkle.framework

and found that DikeX, the old version of the digital-signature tool released by Infocert S.p.a., uses Sparkle. I don’t know if the software is plagued by the bug, but this is exactly the point: nobody from Infocert just warned users with a single word about.

Why Him? (Marco Carrai, Matteo Renzi and Cybersecurity in Italy)

The appointment made by Italian PM Matteo Renzi of Marco Carrai as head of the Italian cybersecurity raised a storm of criticism and concern among the IT Security “professionals” that started complaining about his lack of competence, conflict of interest and so on.

Many of the complaints (a few of them I’ve heard privately, from people that called me for that purpose), though look more like a “why him and not me?” or “what does he have more than me?” instead of a serious analysis of Carrai’s adequacy-for-the-job.

He might not be the right person for such a role, but he is trusted by the prime minister and that is all that matters.

Not the first time, not the last time but – above all – not the first critical sector where such things happens.

 

Why Italy Already Lost the World(Cyber)War

We (Italians) can of course continue to lure ourselves into believing that dealing with “password policies”, “critical infrastructure committees” and “mandatory security measures” – just to name a few buzzwords – is enough to grant a decent level of security for our networks.

We can continue, after twenty years, to listen at – and say – the very same bull… stuff we used to say in the pre-internet era about ICT security (don’t use easy passwords, don’t write it on a post-it, use an anti-virus, etc.)

We can, definitely, keep going in waiting for the next “IT guru” or “magic box” that will make the bad guys disappear from our computers.

But we still continue using flawed software and operating systems without making the software houses pay for their faults (disguised as “features”.)

We still buy things and boxes (read: hardware) believing that just because of that “we are safe”.

And we still keep a blind eye to the actual quality of the IT security in public institutions.

Two options as a conclusion: we’re either stronger than we appear to be or we are incredibly lucky.

But luck doesn’t last forever, and we need to be lucky every single minute of the day, while the attackers, just once.

The Web is ISIS’s Nuclear Bomb

The Web is ISIS’s Nuclear Bomb. This is what Loretta Napoleoni, author of books on the economic side of terrorism, wrote in an article for the leftwinger Italian newspaper Il Fatto Quotidiano.

Napoleoni claims that – as the Marxist ideology did in the past with the “word-of-mouth” or, better, “word-of-book” – ISIS’s propaganda gets its power from a new “ideology-spreading-tool”: the Internet, and thank to the Internet will last, no matter what:

Even though, hypothetically, we should succeed in taking out all of ISIS’s warriors by bombing them and killing al Baghdadi, the ideology that these people have created and their universal message will last on the Internet. 1

I don’t have enough authority to challenge the curious association Napoleoni did between Karl Marx philosophy and ISIS’s vision of the Islamic religion, but I find grossly superficial and offensive for the victims of (every) war to compare “the Web” to a nuclear bomb.

As I wrote in a post, war is made of bullets, and bullets hurt as do (nuclear) bombs. Bombs make carnage, slaughters, shred a human being in pieces, burn, annihilate, vaporize, wipe communities, blindly kill innocents, pollute lands for centuries or millennia (ask Hiroshima and Nagasaki survivors for additional info, just in case.) E-mail, newsgroups, chats, FTP (yes, Napoleoni, the Internet is not only made by HTTP) are tool of freedom designed by free people to give humans a free chance to communicate with no physical and social barrier.

Those like Napoleoni – and her cultural associates, member of the “Internet-as-a-threat Club” – should simply accept the fact that ideas are countered (and sometimes, fought) with ideas and that the worst way to challenge a disturbing statement is to censor it.

The idea that a sole statement might change somebody’s personal philosophy up to turning him into a human bomb carrier is simply wrong. Change of mind happens by way of? tragedies, loneliness, apartheid and injustice and not because of a tweet.

As per the “Internet Patrolling” advocated (not only) by Napoleoni – though sadly labelled by her as ineffective – again, let’s go back to basics: as the East Germany, Russian and Italian political police history show, to fight an enemy and prevent attacks there is no substitute for an actual, massive, ruthless and pervasive physical control. But t this is disturbing and, rightly so, nobody in the Western world is available to give a government so much power.

And here comes the brilliant solution: let’s fall back on the Internet and blame “the Web” as a radicalization tool.

No, Napoleoni, ideologies will not last because of a blog. They will stand until there will be inequality in world, it means until the end of time.

  1. Orginal text in Italian: Anche se, ipoteticamente, riuscissimo a stanare con le bombe tutti i guerrieri dello Stato Islamico e a far fuori al Baghdadi, l?ideologia che costoro hanno creato ed il loro messaggio universale in rete rimarr?

War is fought with bullets

True, the monumental unscrupulousness of the ICT business (which sells systems
without concerns for the security side), and the na?vet? of its clients (trusting hardware instead of good practice and appropriate security processes) built today’s western digital infrastructure as a Colossus with feet of clay.

True, this made the Western World a soft target for computer-related criminals and terrorists.

True, a lot of damage can be done in a short time by a committed digital strike.

But don’t forget that war is fought with bullets, real bullets.

And bullets do hurt.