Fox News 'hacker' turns out to be journalist whose lawyers say was doing his job
- Reference: 1708948085
- News link: https://www.theregister.co.uk/2024/02/26/in_brief_security/
- Source link:
Tim Burke was arrested on Thursday and [1]charged with one count of conspiracy, six counts of accessing a protected computer without authorization, and seven counts of intercepting or disclosing wire, oral or electronic communications for his supposed role in the theft of unedited video streams from Fox News.
Among the videos allegedly stolen from Fox by Burke were unaired antisemitic remarks by rapper Kanye West, and others. Burke accessed the footage using compromised credentials, and then altered recordings to mask their origin, the indictment claims.
[2]
Burke's lawyers countered the charges, asserting he engaged in no hacking and committed no crimes; he merely followed a link to the feeds without ever being asked to input any credentials.
[3]
[4]
"While we, like anyone else, condemn computer hacking, we emphatically insist that the facts of this case will demonstrate that there was, in fact, no hacking whatsoever," Burke's lawyers told the Tampa Bay Times. They further argued that publishing his findings is protected by the first amendment since Burke was acting as a journalist.
The Electronic Frontier Foundation (EFF) agrees, saying in a statement yesterday that it wants the US Justice Department to explain how what Burke did was an actual violation of the Computer Fraud and Abuse Act (CFAA), as the indictment alleges.
[5]
"The law remains vague, too often allowing prosecutors and private parties to claim that individuals knew or should have known what they were doing was unauthorized, even when no technical barrier prevented them from accessing a server or website," the EFF [6]said .
What Burke did may be permissible under the Justice Department's [7]decision not to prosecute good faith violations of the CFAA too, though as we noted in previous coverage if access was in any way unauthorized the good faith exception wouldn't apply.
Critical vulnerabilities of the week
There weren't that many to report this past week, aside from a few vulnerabilities in ICS products, which isn't exactly a shock – flaws in those things are everywhere.
CVSS 9.8 – [8]CVE-2023-21554 : Several models of Mitsubishi electrical discharge machines are subject to a vulnerability in Microsoft Message Queueing services that could allow an attacker to tamper with devices, execute remote code and the like.
CVSS-9.8 – [9]Multiple CVEs : The Ethercat plugin for Zeek network security monitoring software contains OOB read/write vulnerabilities in GitHub commits d78dda6 and prior. This could be used to trigger RCE.
CVSS 9.4 – [10]Multiple CVEs : Commend WS203VICM video door stations running software versions 1.7 and prior are weakly encoding passwords, improperly controlling access and are vulnerable to argument injection.
Apple's app approval process fails again, leading to crypto theft
It's apparently faster for a scammer to create a spoof app and get it through Apple's App Store approval process than it is for legitimate devs nowadays, a case in point being what happened to Rabby Wallet this past week.
Rabby, a cryptocurrency wallet that's still undergoing App Store approval, had an impersonator make it into the App Store, with subsequent [11]reports by a number of people who reported having their accounts emptied after installing the fake app. Rabby was forced to take to social media to say that a fake app was out there, and [12]restating that the real Rabby Wallet is still under review.
[13]Feds post $15 million bounty for info on ALPHV/Blackcat ransomware crew
[14]Mon Dieu! Nearly half the French population have data nabbed in massive breach
[15]SBF likely off the hook for misplaced FTX funds after cops bust SIM swap ring
[16]Tesla hacks make big bank at Pwn2Own's first automotive-focused event
This is the second time this month that we've reported on fake iOS apps making it through the approval process and fooling iPhone users – not a great look for a supposedly safe, locked-down ecosystem like Apple's.
Just like in the previous case with [17]LastPass , keep an eye on the developer name, reviews, and the like when downloading anything.
EV chargers pulled from UK shelves for not meeting cybersecurity requirements
The UK Office for Product Safety and Standards (OPSS) has told EV charger maker Wallbox to stop selling its Copper SB car chargers because they don't comply with UK cybersecurity laws, The Telegraph [18]reported .
According to the outlet, the concern was over the possibility that Copper SB chargers, which can be controlled with a smartphone app, could potentially be exploited to turn them all on at the same time, causing a sudden drain on the power grid.
Wallbox was granted a temporary waiver to continue selling the products until June, at which time the devices will be taken off the market because Wallbox "cannot implement the Cybersecurity requirements in full on this product because of a hardware and operating system limitation," the company [19]told [PDF] the OPSS.
[20]
We note, as did the Telegraph and Wallbox, that there's no evidence of a flaw in Copper SB hardware that could cause a grid stress attack – merely that the hardware can't be secured up to modern UK standards. ®
Get our [21]Tech Resources
[1] https://www.tampabay.com/news/tampa/2024/02/22/tim-burke-fox-news-indicted-tucker-carlson-federal-charges/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZdzDumW47fMNOW@9pnRbYwAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdzDumW47fMNOW@9pnRbYwAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdzDumW47fMNOW@9pnRbYwAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdzDumW47fMNOW@9pnRbYwAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.eff.org/deeplinks/2024/02/justice-department-even-following-its-own-policy-cybercrime-prosecution-journalist
[7] https://www.theregister.com/2022/05/20/cfaa_rule_change/
[8] https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-03
[9] https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02
[10] https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-01
[11] https://discussions.apple.com/thread/255482851?answerId=260185331022&sortBy=best#260185331022
[12] https://twitter.com/Rabby_io/status/1758476458559738181
[13] https://www.theregister.com/2024/02/19/infosec_news_in_brief/
[14] https://www.theregister.com/2024/02/12/infosec_news_roundup/
[15] https://www.theregister.com/2024/02/05/sbf_off_the_hook_for/
[16] https://www.theregister.com/2024/01/29/infosec_news_roundup_in_brief/
[17] https://www.theregister.com/2024/02/08/lastpass_lookalike_apple_app_store/
[18] https://www.telegraph.co.uk/news/2024/02/21/car-charger-withdrawn-hackers-could-attack-national-grid/
[19] https://assets.publishing.service.gov.uk/media/64b69f3361adff000d01b2b0/evscp-undertaking-wallbox-04.pdf
[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdzDumW47fMNOW@9pnRbYwAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[21] https://whitepapers.theregister.com/
Re: and then altered recordings to mask their origin,
What exactly did he change, and why?
He may just have done something as simple as removed Fox's logo from the footage?
Re: and then altered recordings to mask their origin,
Yeah, you are probably right. I had misread it as if he changed something at the remote end, but apparently all he did was download a video from a webserver. Probably all the videos on their site had a sequential ID, or something.
Still a bit daft of him to edit them before reposting though. If he had simply posted the videos as-found from a publicly accessible URL, then he would have a good defence.
Re: and then altered recordings to mask their origin,
It was further part of the conspiracy that, prior to distributing some of the intercepted contents, BURKE took steps to conceal that the intercepted contents had been originally retrieved from the StreamCo- Net by, among other conduct, altering the appearance and metadata of the wire, oral, and/or electronic video communications by re-recording the intercepted communications onto a secondary device and distributing said altered versions of the video communications, rather than the original intercepted contents;
( https://storage.courtlistener.com/recap/gov.uscourts.flmd.424438/gov.uscourts.flmd.424438.1.0_2.pdf )
There appears to be no reference to evidence of intention here. Re-encoding could be done for many reasons.
It may not matter too much. The indictment has twitter exchanges of them using stolen credentials to access a passworded FTP. If that sticks (his defence is that he believed the credentials were public and the owner invited others to use them) then whether the obscure URIs they got from there which linked to the video (which may or may not have been 'obfuscated with intent') constitute a separate hack is a legal curiosity and a probably quite minor sentencing issue in practice?
As an aside, I'm always a bit alarmed the way these sort of cases stack up the counts (14 counts: conspiracy, 6 of accessing, 7 of interception). To the layman this is just 2 guys engaging in ONE casual hack. It's a bit like you rob a convenience store cash register and the Feds are like: 45 counts of aggravated theft of a dime, 24 counts of aggravated theft of a quarter, 6 counts aggravated theft of a 20 dollar note, etc..
I guess we're just missing some smart ass pointing out these 14 counts are potentially 250 years in prison, or whatever.
Temporary Waiver
> Wallbox was granted a temporary waiver to continue selling the products until June, at which time the devices will be taken off the market because Wallbox "cannot implement the Cybersecurity requirements in full on this product because of a hardware and operating system limitation," the company told [PDF] the OPSS
This makes no sense... they seem to be saying that it's not possible to update the product to comply with requirements - and yet they'll be allowed to continue selling them for a few more months?
Surely that means that some poor sod is going to get sold a charger that's got known, unfixable security issues (and then be told, shortly after, that it's EOL and won't be fixed). Unless there's something that's not beenn mentioned, granting a waiver seems like a terrible idea in this case
Re: Temporary Waiver
Since there is an App to track charging there is a Cloud to control it and each box is uniquely identifiable to the loud services. How can you turn ALL on at once?
Re: Temporary Waiver
"How can you turn ALL on at once?"
From the server.
Re: Temporary Waiver
If it was -just- the server, then this could be fixed, by fixing the server.
But if it's a lack of security in the protocol, then one could simply hijack a DNS record and point all the wallboxes to a new server, which says IF gridfrequency < 50 then ON, else OFF
Re: Temporary Waiver
That would be my guess too: I've seen IoT stuff in the past where the hardware simply doesn't have the oomph to do TLS.
Re: Temporary Waiver
Depends on how naive it's been implemented.
If, for example, it's listening for a UDP packet containing the text TURN ON without any authorisation checking, you could send such a packet to every IP assigned to the UK in a couple of minutes.
If controlled by a simple Web API, similarly so.
If its polling the server for a command everycouple of minutes, DNS poisoning or take over to point to your server that always answers "Turn On" regardless who's asking.
Re: Temporary Waiver
Surely that means that some poor sod is going to get sold a charger that's got known, unfixable security issues (and then be told, shortly after, that it's EOL and won't be fixed). Unless there's something that's not beenn mentioned, granting a waiver seems like a terrible idea in this case
No - your concerns would be valid if what the article says was all of the context, but there's a bit more here. The non-compliant Wallbox Plus charger hasn't been sold new since 30 December 2022 when the security requirement of the UK's 2021 EV Charging Regulations came into force. This undertaking (which I think dates back to July 2023 anyway) allows Wallbox to replace with new any failed Wallbox Plus chargers under warranty up until the end of June of this year. In terms of the risks of that approach, the non-compliant chargers are already out there because their design pre-dates the UK charging point regulations. If there's warranty claims or repairs after June of this year, then Wallbox either need to try and agree another enforcement undertaking with OPSS, replace the faulty charger with a compliant product (eg their own Wallbox Max which I believe is compliant), or repair it without replacement. Either way the risk to owners, users or the grid is negligible because the numbers will be so small, and I'd guess the chances of a manufacturer wanting to do outright replacement with new on products over 18 months old is negligible anyway.
https://assets.publishing.service.gov.uk/media/64b69f2071749c000d89edc9/evscp-undertaking-wallbox-03.pdf
A correct headline would be "Manufacturer complies fully with UK changes in law; Regulator agrees pragmatism for warranty on older products" .
Or maybe "In the year before last's news, EV chargers pulled from UK shelves end 2022 for not meeting new cybersecurity requirements" But those wouldn't get you clicking on the article and commenting here.
Re: Temporary Waiver
> The non-compliant Wallbox Plus charger hasn't been sold new since 30 December 2022 .... This undertaking allows Wallbox to replace with new any failed Wallbox Plus chargers under warranty up until the end of June of this year
Ahh, that makes *much* more sense, thanks!
How can firmware enable all units to start together?
Surely that is a cloud service.
The Scot in my handle means I would wait 12 hours for charging to start for1/4 cost of other times.
Re: How can firmware enable all units to start together?
I doubt that the problem is the control system and the grid - a far more likely failing is regulations 2 or 3 of Schedule 1 of the regs (link below), and I'm guessing it is something like a default password or secure updating. Think about all the Internet of Tat stuff that comes with passwords like Admin, or password. And if that's baked into the firmware of each unit, then it's problematic and expensive to change, with the result the makers won't do it.
https://www.legislation.gov.uk/uksi/2021/1467/schedule/1/made
I could of course ask the people in the office exactly what the issue was, but no, I'm not doing that.
Wallbox
https://wallbox.com/en_uk/wallbox-copper
Looks pretty new for an "end-of-life" 22kW charger ...
Makes me wonder what the "cybersecurity requirements" that they are unable to meet are.. Unsecured bootloader allowing unsigned firmware updates, perhaps? Or no support for encryption in the underlying protocol for their "remote operation"?
Also, I find it quite amusing that listed under "discontinued products", is "Ethics Channel"
https://support.wallbox.com/en/ethics-channel/
Re: Wallbox
Seeing that it's "controlled" with a smart phone it probably means it's actually controlled with a server which isn't secured.
Re: Wallbox
If that is so, does it mean that customers' existing units will stop working soon?
"Alexa, open my wallbox" ... "Sorry Dave, but this service has been discontinued. You can purchase a new cloud-device from Amazon! Would you like me to add it to your basket?"
Popcorn icon needed.
Re: Wallbox
"If that is so, does it mean that customers' existing units will stop working soon?"
Shouldn't stop charging, all that's been stopped is the new sale of non-compliant products. It's like the vast majority of changes to mandatory standards - they don't have to be applied to existing setups unless you renew the system. Same is true for building and electrical regs.
Re: Wallbox
"could potentially be exploited to turn them all on at the same time, causing a sudden drain on the power grid."
This would only be an issue if vehicles were plugged in and actually required charging (otherwise there would be no load). Heaven forbid that owners would actually need to go to work in the morning ...
To be honest, if the grid is that susceptible to load variation I'd not be looking at the chargers but the National Grid resilience plans.
Re: Wallbox
> I'd not be looking at the chargers but the National Grid resilience plans.
NG resilience plans: Rely on demand-side response i.e. smart chargers and smart meters, to turn off or on loads when needed. Power stations? Nah, we'll keep closing them
Re: Wallbox
As I understand it, you plug in your car as soon as you get home, but it doesn't necessarily start charging straight away,
But you can press a button to tell it you really need your car recharged as soon as possible, and then it will start charging straight away; but you will probably pay a higher per kWh price for the electricity if you do that.
I suppose the test for hacking Fox has to be would they have done it to someone else and called it journalism?
"Rabby, a cryptocurency wallet..."
"... that's still undergoing App Store approval, had an impersonator make it into the App Store, with subsequent reports by a number of people who reported having their accounts emptied after installing the fake app."
A spokesman for Rabby added "Have these people no shame? Scamming people is our job!"
and then altered recordings to mask their origin,
Er, what?
How can anyone claim that this is "legitimate investigative journalism"? What exactly did he change, and why?