Ñо¿ÍŶÓÑÝʾʹÓà MITM Èƹý FIDO2 ÍøÂçµöÓã·À»¤
Ðû²¼Ê±¼ä 2024-05-075ÔÂ6ÈÕ£¬FIDO2 ÊÇÎÞÃÜÂëÉí·ÝÑéÖ¤µÄÏÖ´úÉí·ÝÑéÖ¤×éÊõÓï¡£¿ìËÙÉí·ÝÔÚÏß (FIDO) ÁªÃË¿ª·¢ËüÀ´È¡´ú´«Í³ÒÑÖªÃÜÂëµÄʹÓ㬲¢ÌṩһÖÖʹÓÃÎïÀí»òǶÈëʽÃÜÔ¿½øÐÐÉí·ÝÑéÖ¤µÄÄþ¾²ÒªÁì¡£ÖÚËùÖÜÖª£¬FIDO2 ¿ÉÒÔ±£»¤ÈËÃÇÃâÊÜÖмäÈË (MITM)¡¢ÍøÂçµöÓãºÍ»á»°½Ù³Ö¹¥»÷¡£FIDO2 Éí·ÝÑéÖ¤Á÷³ÌÓÉÓÃÓÚ¿Í»§¶ËÒÀÀµ·½ (RP)£¨¼´ÔÆÓ¦Ó÷¨Ê½Í¨ÐÅ£©µÄ WebAuthn API ¹æ·¶ºÍÓÃÓÚÓ²¼þͨÐŵĿͻ§¶Ëµ½Éí·ÝÑéÖ¤Æ÷ (CTAP) ÐÒé×é³É¡£Õû¸ö¹ý³ÌÓÉä¯ÀÀÆ÷¹ÜÀí£¬°üÂÞÁ½¸öÉí·ÝÑéÖ¤²½Ö裺É豸ע²áºÍÉí·ÝÑéÖ¤¡£Ö®ËùÒÔÕâÑù½á¹¹£¬ÊÇÒòΪ FIDO2 »ùÓÚ¹«Ô¿¼ÓÃÜ»úÖÆ¡£¿Í»§¶ËÔÚ´Ë´¦Éú³É˽ԿºÍ¹«Ô¿£¬²¢½«ºóÕß·¢ËÍ»Ø RP ÒÔÔڵǼʱ½øÐÐÇ©ÃûÑéÖ¤¡£FIDO ¿ÉÒÔÓÃ×÷µ¥¸öÓ¦Ó÷¨Ê½»òÁªºÏÓ¦Ó÷¨Ê½µÄÉí·ÝÑéÖ¤ÒªÁì¡£¶ÔÓÚÄÇЩ²»ÖªµÀµÄÈËÀ´Ëµ£¬ÁªºÏÊÇÖ¸Óɵ¥¸öÉí·ÝÌṩÉÌ (IdP) ¹ÜÀíµÄ¶à¸ö²»Ïà¹ØÓ¦Ó÷¨Ê½µÄµ¥µãµÇ¼ (SSO)¡£
https://securityboulevard.com/2024/05/using-mitm-to-bypass-fido2-phishing-resistant-protection/
2. ¹ú¼ÊÌØÉâ×éÖ¯½«Ó¡¶ÈÄáÎ÷ÑÇÁÐΪ¼äµýÈí¼þÖÐÐÄ
5ÔÂ6ÈÕ£¬¹ú¼ÊÌØÉâ×éÖ¯Äþ¾²ÊµÑéÊÒµÄ×îÐÂÑо¿±íÃ÷£¬Ó¡¶ÈÄáÎ÷ÑÇÊǼà¿Ø¹¤¾ßºÍ¹©Ó¦É̵ÄÐÂÐËÖÐÐÄ¡£¸Ã×éÖ¯·¢ÏÖÁË´Ó 2017 Ä굽ȥÄê´ÓÒÔÉ«ÁС¢Ï£À°¡¢Ð¼ÓƺÍÂíÀ´Î÷Ñǵȹú¼ÒÏòÓ¡¶ÈÄáÎ÷ÑÇÏúÊÛºÍÔËÊä¸ß¶ÈÇÖÈëÐÔ¼äµýÈí¼þºÍÆäËû¼à¿Ø¼¼ÊõµÄÖ¤¾Ý¡£¾Ý±¨µÀ£¬ÕâЩ¼à¿Ø¹¤¾ßÊôÓÚ¡°Q Cyber Technologies£¨Óë NSO Group Ïà¹Ø£©¡¢Intellexa ²ÆÍÅ¡¢Saito Tech£¨Ò²³ÆΪ Candiru£©¡¢FinFisher ¼°ÆäÈ«×Ê×Ó¹«Ë¾ Raedarius M8 Sdn Bhd ºÍ Wintego Systems¡±µÈ¹«Ë¾¡£¹ú¼ÊÌØÉâ×éÖ¯»¹Ïêϸ½éÉÜÁËÓëÕë¶ÔÓ¡¶ÈÄáÎ÷ÑǸöÈ˵ļäµýÈí¼þƽ̨Ïà¹ØµÄÖÖÖÖ¶ñÒâÓòÃûºÍÍøÂç»ù´¡ÉèÊ©¡£¹ú¼ÊÌØÉâ×éÖ¯ÌåÏÖ£¬ËäÈ»ÕâЩÓòÃûÄ£·ÂÁËÕþµ³ºÍýÌå»ú¹¹£¬µ«Ä¿Ç°Éв»Çå³þËÊÇÕæÕýµÄÄ¿±ê¡£¹ú¼ÊÌØÉâ×éÖ¯µÄ³ÂË߳ƣ¬¼äµýÈí¼þÀúÀ´±»Õþ¸®ÊµÌåÓÃÀ´Õë¶ÔÃñ¼äÉç»áºÍ¼ÇÕߣ¬Òò´Ë¶ÔÓÚ¹«ÃñȨÀûÊܵ½ÇÖ·¸µÄÓ¡¶ÈÄáÎ÷ÑÇÀ´Ëµ£¬ÕâÊÇÌرðÁîÈ˵£Óǵġ£
https://www.darkreading.com/cybersecurity-operations/amnesty-international-cites-indonesia-as-spyware-hub
3. ·¨¹Ù¿¼ÂǶԹȸèÆÆ»µÄÚ²¿ÁÄÌì¼Ç¼½øÐÐÖƲÃ
5ÔÂ4ÈÕ£¬Ôڹȸ袶ϰ¸ÉóÅеĵڶþÌì½á°¸³Â´Ê¼´½«½áÊøʱ£¬ÃÀ¹úµØÓò·¨¹Ù°¢Ã×ÌØ¡¤Ã·Ëþ (Amit Mehta) ȨºâÁËÊÇ·ñÓ¦¸Ã¶ÔÃÀ¹ú˾·¨²¿Ëù˵µÄ¹È¸è¡°ÀýÐС¢¶¨ÆÚºÍÕý³£Ïú»Ù¡±Ö¤¾Ý½øÐÐÖƲ᣹ȸ豻ָ¿ØÖƶ¨ÁËÒ»ÏîÕþ²ß£¬Ö¸Ê¾Ô±¹¤ÔÚÌÖÂÛÃô¸Ð»°ÌâʱĬÈϹرÕÁÄÌì¼Ç¼£¬°üÂ޹ȸèµÄÊÕÈë·ÖÏíºÍÒƶ¯Ó¦Ó÷¨Ê½·Ö·¢ÐÒé¡£ÃÀ¹ú˾·¨²¿ºÍÖÝ×ܼì²ì³¤ÈÏΪ£¬ÕâЩÐÒéÖ¼ÔÚά³Ö¹È¸èÔÚËÑË÷ÁìÓòµÄ¢¶Ïְλ¡£¾ÝÃÀ¹ú˾·¨²¿³Æ£¬¹È¸è²»½öÔÚÊÓ²ìÆÚ¼ä¶øÇÒÔÚËßËÏÆÚ¼äÏú»ÙÁËDZÔÚµÄÊýÊ®Íò¸öÁÄÌì»á»°¡£ÔÚÃÀ¹ú˾·¨²¿·¢ÏÖ¸ÃÕþ²ßºó£¬¹È¸è²ÅÍ£Ö¹ÁËÕâÖÖ×ö·¨¡£Ë¾·¨²¿µÄÂÉʦ¿ÏÄá˼¡¤¶¡Ôó (Kenneth Dintzer) ÖÜÎå¸æËß÷Ëþ£¬Ë¾·¨²¿ÈÏΪ·¨ÔºÓ¦¸ÃµÃ³öÕâÑùµÄ½áÂÛ£ºÓëÀúÊ·½øÐн»Á÷±íÃ÷ÁËÒþ²ØÐÅÏ¢µÄ·´¾ºÕùÒâͼ£¬ÒòΪËûÃÇÖªµÀ×Ô¼ºÎ¥·´ÁË·´Â¢¶Ï·¨¡£
https://arstechnica.com/tech-policy/2024/05/judge-mulls-sanctions-over-googles-shocking-destruction-of-internal-chats/
4. 2023ÄêGoogle×èÖ¹228Íò¸ö¶ñÒâappÔÚGoogle PlayÐû²¼
4ÔÂ29ÈÕ£¬ 2023 Ä꣬ÎÒÃÇ×èÖ¹ÁË 228 Íò¸öÎ¥·´Õþ²ßµÄÓ¦Ó÷¨Ê½ÔÚ Google Play ÉÏÐû²¼£¬²¿ÃŹ鹦ÓÚÎÒÃǶÔеĺ͸ïеÄÄþ¾²¹¦Ð§¡¢Õþ²ß¸üÐÂÒÔ¼°ÏȽøµÄ»úÆ÷ѧϰºÍÓ¦Ó÷¨Ê½ÉóºËÁ÷³ÌµÄͶ×Ê¡£ÎÒÃÇ»¹¼ÓÇ¿ÁË¿ª·¢ÕßÈëÖ°ºÍÉóºËÁ÷³Ì£¬ÔÚ¿ª·¢ÕßÊ״ν¨Á¢Æä Play ÕÊ»§Ê±ÐèÒª¸ü¶àÉí·ÝÐÅÏ¢¡£¼ÓÉ϶ÔÉó²é¹¤¾ßºÍÁ÷³ÌµÄͶ×Ê£¬ÎÒÃǸüÓÐЧµØʶ±ðÁ˲»Á¼ÐÐΪÕߺÍÆÛÕ©ÍŻ²¢½ûÖ¹ÁË 33.3 Íò¸ö²»Á¼ÕÊ»§½øÈë Play£¬ÕâЩÕÊ»§ÒÑÈ·ÈÏΪ¶ñÒâÈí¼þ£¬¶øÇÒÂÅ´ÎÑÏÖØÎ¥·´Õþ²ß¡£´ËÍ⣬½ü 20 Íò¸öÓ¦Ó÷¨Ê½Ìá½»±»¾Ü¾ø»òÐÞ¸´£¬ÒÔÈ·±£ÕýȷʹÓúǫ́λÖûò¶ÌÐÅ·ÃÎʵÈÃô¸ÐȨÏÞ¡£ÎªÁË×ÊÖú´ó¹æÄ£±£»¤Óû§Òþ˽£¬ÎÒÃÇÓë SDK ÌṩÉ̺Ï×÷£¬ÏÞÖÆÃô¸ÐÊý¾Ý·ÃÎʺ͹²Ïí£¬´Ó¶øÔöÇ¿Ó°Ïì 79 Íò¶à¸öÓ¦Ó÷¨Ê½µÄÁè¼Ý 31 ¸ö SDK µÄÒþ˽״¿ö¡£ÎÒÃÇ»¹ÏÔ×ÅÀ©Õ¹ÁËGoogle Play SDK Ë÷Òý£¬¸ÃË÷ÒýÏÖÔÚº¸ÇÁË Android Éú̬ϵͳÖнü 600 Íò¸öÓ¦Ó÷¨Ê½ËùʹÓÃµÄ SDK¡£ÕâÒ»Ãû¹óµÄ×ÊÔ´¿É×ÊÖú¿ª·¢ÈËÔ±×ö³ö¸üºÃµÄ SDK Ñ¡Ôñ¡¢Ìá¸ßÓ¦Ó÷¨Ê½ÖÊÁ¿²¢×îºéÁ÷ƽµØ½µµÍ¼¯³É·çÏÕ¡£
https://security.googleblog.com/2024/04/how-we-fought-bad-apps-and-bad-actors-in-2023.html
5. Á½¸ö¼«ÓÒÒíýÌåÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ºÍÆÆ»µ
5ÔÂ3ÈÕ£¬Á½¼Ò¼«ÓÒÒíýÌåÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ºÍÆÆ»µ£¬¶©ÔÄÕߺÍÆäÄÚ²¿ÍøÕ¾Êý¾Ý±»Ð¹Â¶£¬ÕâÊÇÒ»´ÎÃ÷ÏÔ³öÓÚÕþÖζ¯»úµÄ¹¥»÷µÄÒ»²¿ÃÅ¡£Ä¿Ç°ÉÐδ¹ûÈ»Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬µ«ÕâÖÁÉÙÊDZ¾ÖܵڶþÆð¿´ËƳöÓÚÕþÖζ¯»úµÄºÚ¿Í¹¥»÷¡£¹ýÈ¥Ôø·¢¶¯¹ý³öÓÚÕþÖζ¯»úµÄ¹¥»÷µÄÍøÂç·¸×ï×éÖ¯SiegedSecÉù³Æ¶ÔÎÛÃûÕÑÖøµÄ Westboro ½þÐÅ»á½ÌÌ÷¢¶¯Á˹¥»÷¡£Ã»Óм£Ïó±íÃ÷ÕâÁ½ÆðʼþÓйØÁª¡£Human Events ÊÇÒ»¼Ò½¨Á¢ÓÚ 1944 ÄêµÄÊؾÉÅÉÐÂÎÅ»ú¹¹£¬ÓÚ 2022 Äê 5 ÔÂÊÕ¹ºÁËPost Millennial¡£ÕâÁ½¸ö×éÖ¯µÄÍøÕ¾¾ùÖ¸³ö£¬ËüÃÇÊÇÓÉÕþÖÎýÌ幫˾ (Political Media, Inc. ) Éè¼ÆºÍά»¤µÄ£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒλÓÚ¸¥¼ªÄáÑÇÖݵġ°ÖÐÓÒÒíÐÂýÌå×Éѯ¹«Ë¾¡±£¬ÌṩµÄ·þÎñ°üÂÞÄÚÈݹÜÀíϵͳ¡¢ÍøÒ³Éè¼Æ¡¢µç×ÓÓʼþ·þÎñºÍÓªÏú¡£
https://cyberscoop.com/far-right-websites-hacked-and-defaced/
6. Å·ÖÞÐ̾¯×éÖ¯¹Ø±Õ12¸öթƺô½ÐÖÐÐIJ¢´þ²¶¶à¸öÏÓÒÉÈË
5ÔÂ3ÈÕ£¬Å·ÖÞÐ̾¯×éÖ¯Áìµ¼µÄÒ»ÏîÃûΪ¡°Å˶àÀ¡±µÄÐж¯ÒѾ¹Ø±ÕÁËÊ®¼¸¸öµç»°Õ©ÆÖÐÐÄ£¬²¢´þ²¶ÁË 21 ÃûÏÓÒÉÈË¡£¾¯·½Ô¤¼Æ£¬ÕâÒ»Ðж¯×èÖ¹ÁË·¸×ï·Ö×Ó´ÓÊܺ¦ÕßÉíÉÏÆÈ¡Áè¼Ý 1000 ÍòÅ·Ôª¡£¸Ã·¸×ïÍøÂçÔÚ°¢¶û°ÍÄáÑÇ¡¢²¨Ë¹ÄáÑǺͺÚÈû¸çάÄÇ¡¢¿ÆË÷ÎÖºÍÀè°ÍÄÛÔËÓªºô½ÐÖÐÐÄ£¬Ã¿Ìì½Óµ½¡°Êýǧ¸ö¡±Õ©Æµç»°£¬°üÂÞ¼Ù¾¯²ìµç»°¡¢Í¶×ÊթƺÍÀËÂþÕ©Æ¡£Èç¹û²»Êǵ¹úµÄÒ»ÃûÒøÐгöÄÉÔ±£¬ÇÔÔô¿ÉÄÜ»áÆ×߸ü¶àµÄÊܺ¦Õß¡£Å˶àÀÐж¯Ê¼ÓÚ 2023 Äê 12 Ô£¬ÆäʱһÃûÖ÷¹ËÒªÇó¸¥À³±¤µÄÒ»Ãû³öÄÉÔ±ÌáÈ¡Áè¼Ý 100,000 Å·Ôª£¨107,247 ÃÀÔª£©µÄÏÖ½ð¡£ÕâÒ»ÇëÇóÉæ¼°µ½ÒøÐÐÊÂÇéÈËÔ±£¬ËûÃǺܿì¾ÍµÃÖª¸Ã¿Í»§ÂäÈëÁ˼پ¯²ìµÄƾ֡£ÕâÖÖÀàÐ͵ÄÆÛÕ©Éæ¼°·¸×ï·Ö×Ó×Ô³ÆÊÇÖ´·¨ÈËÔ±£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Ò»´ó±ÊÇ®¡ª¡ªÍ¨³£ÊǻѳÆËûÃÇ´í¹ýÁËÐé¼ÙµÄ¿ªÍ¥ÈÕÆÚ£¬ÏÖÔÚÃæÁÙ´þ²¶Á³ý·ÇËûÃÇÖ§¸¶·£¿î£¬»òÕßÆäËûһЩ±àÔìµÄ¹ÊÊ¡£
https://www.theregister.com/2024/05/03/operation_pandora_europol/