Welcome to the Aconiac Security Group Blog

This blog includes company news, company statements, tutorials, guides and much more. So please add this blog to your RSS reader and let us help you to become better security professionals.
Disclaimer: The views of individual bloggers may not be the views of Aconiac as a whole.

The official Aconiac company blog

Archive for 'News'

Hoodgate's LogoPresenting a new company venture from Aconiac: the mobile security company Hoodgate.

For several years now,  smart phones have increased in popularity and will continue to do so for years to come. We are truly only in the beginning of this development and can expect to see even faster and better systems in the future.

One thing that is however still lacking is effective handling of mobile security for a company with more than a few employees. Most available solutions are monolithic solutions where a company buys a software suite with some number of features (anti-virus, anti-spam, locking mechanism etc.) and then has to manually install this suite onto every single employee’s phone one by one, and subsequently if any additions are made to the software later on, in most cases you’d have to do the same manual reinstall all over again. In the end this can lead to enormous financial costs for a company, simply in shear terms of man-hours used!

Hoodgate is adopting another solution to the problem! Hoodgate will be offering a service where you, as a customer, can handle all your employee’s phones through a central control panel. Through this control panel you can then create a “Mobile Security Policy” for your company.

A “Mobile Security Policy” is basically the features you want to have, e.g. the ability to find a given phone through GPS, encrypted e-mails, remote lock of the phone (in case of theft), voice logging, and much more. Once you have a customer profile you can easily buy new features, remove old or order specially developed ones, and all these changes to your “Mobile Security Policy” are automatically sent to all your employee’s phones, ultimately making management of security for your mobile workforce much easier and cheaper. It is then the Hoodgate software on these phones that take in updates and synchronizes with the company “Mobile Security Policy” stored with Hoodgate online, rather than your system administrators having to do it manually.

Hoodgate is just starting up now, and does not at the moment have a finished product. We will however be making regular updates on how the development is going, and try to continually involve future customers in the development, in order to make as good a product as humanly possible.

The platforms we intend to support are the following:

With development prioritizes more or less in that order, so that the primary platform is Android.

All the plans above are of course still preliminary and open for change, and you can easily have a say in those changes and speak your mind to us. All you have to do is comment on this blog post, contact us directly or on one of the social networks we’re on (links are farther down). We’re very curious to hear what you think, even if you’re the type of guy/girl who loves to point out flaws in plans or designs – a real hacker type person! Feel free to contact us and point out what we’ve done wrong or haven’t thought about. In the end your opinions might very well result in an even better final product.

The company website can be found at http://www.hoodgate.com/ although it’s still very preliminary. As we state several times on the page: We’d rather use our time developing the software you need rather than worry about website details at the moment. The short comings on the site will however be handled within the near future.

You can also find us at other places on the web. We invite you to get involved and get your voice heard. We’re listening!:

Join us on FacebookFollow us on TwitterSubscribe to us on YouTube

It’s been a while since we posted anything on the blog and there’s actually a very good reason for that! We’ve been very busy handling customers and finding a new office to move into. Now, after several months of looking, we’ve moved into our new offices at Møllevangs Allé 142, 8200 Århus N..

From here we will keep on doing our work, but more importantly we will be creating a new sister company focused on developing security solutions for the mobile worker. While employees working from home was one of the big threats to a company’s security infrastructure a few years ago, now and in the future we will see that mobile employees are much more at risk of being used as entrances to the company’s infrastructure. For example by hackers hacking into (or stealing) laptops, cell phones, PDA’s etc. Most of these mobile workstations still lack crucial security and many companies are running huge risks each and every day – we hope to change that sometime in the near future. But until then, feel free to contact us concerning your company’s security policies on mobile employees.

In conclusion, here’s a few pictures from our new offices:

We have now released a native Microsoft Windows installer for the second release of our application Aconiac Password Generator, release 1.2.
It’s available at our website for download, alongside a cross-platform version for Mac, Linux, BSD etc. We are currently working on releasing a bunch of other native installers for Mac, Ubuntu Linux, Redhat/Fedora and more, however with clients needing to be serviced, it might be a few weeks before these will be finished. If you have experience packaging software for these systems and would like to help, please feel free to contact us.

The download page for Aconiac Password Generator can be found here

Aconiac at CeBIT 2009

Of all the trade fairs in the world, none quite rivals CeBIT when it comes to sheer size. With over 20 years of experience, it is still the world’s largest trade fair and showcases some of the up-and-coming home and office solutions in IT and Telecommunications.

CeBit Entrance

Coming up to the CeBIT entrance

Sadly however, CeBIT has been experiencing decreased visitor numbers for the last few years and this year was obviously no exception – especially not given the economic circumstances of these times. None the less, Aconiac decided to attend the conference as a visitor and see what other companies have come up with these days.

For all you readers that happen to not know, CeBIT consists of a number of halls, where every hall has a few different fields of interest. There are halls with Server Technologies, Business Storage, Virtualization etc, and there are other halls with e.g. Telematics & Navigation, Automotive Solutions, Transport & Logistics, Satelite Navigation etc. etc. All in all there are a total of 26 different halls, sporting over 100 different subjects – so there should be something for almost any interest! On top of this there is an abundance of kiosks, bistros and the like, so you have to actively try to avoid eating in order to go hungry all day! A whole day is by the way also basically how long it takes to get around to every hall!

The new CeBIT Security World exhibit.

The new CeBIT Security World exhibit.

One hall was especially interesting for us, since it was CeBIT’s new Security World hall. According to the plan, this should include Anti-Malware Solutions, Security Tools & Services, Biometrics, Card Technologies, Network Security, Video Surveillance and more. But we’ll get back to that specific hall later. Let’s first take a look at what was interesting at CeBIT this year!

Now obviously, the economic crisis has effectively removed many of the fun things from the fair, but curtain things have however remained. And there were a few items we found especially cool this year.

Two of these items came from Asus, whom have gained extended world-wide focus after the release of the first Asus Eee computers and subsequent popularity increases of such products. They’ve now come up with a couple of completely new computers. Both of which change the way we do personal computing, if they ever gain extensive popularity.

Asus' cool book laptop

Asus' cool book laptop

The first, and probably most interesting, is this Asus book-like laptop. What makes this interesting is the fact that the laptop actually doesn’t have a keyboard of any kind – it instead has two screens! What this does is that software on the laptop can activate the bottom screen, which is actually a touchscreen, and put up a virtual keyboard on that screen. This way, you will be able to use the laptop just like any other laptop (We however weren’t allowed to touch it, so I’m not sure if the virtual keyboard is even a feasible tool to use for anything serious).

Asus' book laptop - flipped

Asus' book laptop - flipped

But not only can you use it as a normal laptop, it also makes a new and unique operation possible – It can function as a book!
If you turn the laptop around, an accelerometer in the laptop detects this and immediately turns the virtual keyboard into an actual screen, so that you can use it to open .pdf files (and the like) and simply start reading! Products like this might very well be the early products that end up replacing printed media completely, even though that’s probably still quite some time in the future.

But again: We weren’t allowed to touch it, so it’s very hard to know how easy it actually was to use. Whether or not it is a product one would actually use is quite difficult to answer, so please don’t just go out and buy it just because we said it was cool! It might be a very good product and it might also not at all be!

Another cool product from Asus was this keyboard computer. So what do I mean by keyboard computer? Well, it’s actually quite literal! A computer stuffed completely into a small keyboard, so that you only have to bring the keyboard, find a big screen and plug yourself in to that screen, and you’re ready to go!

Keyboard as an entire computer

Keyboard as an entire computer

Whether or not this product is just a weird idea or it’s the future of laptops – well who knows? Personally I don’t believe this will be a hit, simply because the screen is missing. If you don’t have a big screen anywhere near you, you have to use the small screen in the right bottom corner – Not really a fantastic solution, because how often do you actually have a spare screen with you everywhere? The keyboard computer will probably only function as a replacement for large home computer systems, where computing power is not of much concern to the family members.

So all in all this exact product is probably not going to make much of a change! And sadly there weren’t much else innovative at CeBIT this year. It seems the financial crisis has taken away much of the interesting stuff and kept all the, at times, irritating sales personnel that’s scattered all over the place to try and sell you one electronic product after another!

So bummed out due to the lack of interesting products, we tried to figure out what to do next. After a bit of food and a small beer, we decided to take a look at the new and “fantastic” Security World hall.

Kaspersky Labs

Kaspersky Labs

Sadly however, our hopes of interesting exhibitors and good products was kinda beat down. There wasn’t really anything fantastic or innovating in the entire hall and most exhibitors were also quite unknown to us. Not that being unknown is necessarily a bad thing, but if you’re a anti-virus company and you’re completely unknown, you’ve also never been critically evaluated in international tests and therefore never had your products tested up against its competitors. This is by all means a bad thing! However, in regards to anti-virus, the master was however still there – Kaspersky!

Even kids can do surveillance! ..

Even kids can do surveillance! ..

One thing that was kinda interesting though, was the surveillance part of the hall. Here you could get any form of spy equipment, cameras, microphones etc. Even kids could apparently use this stuff, as was apparent from the little guy playing around with the 10-20 cameras mounted all over this exhibit! I really like that picture actually! It quite effectively shows where we’re going in our society if people don’t soon get up off of there asses and start fighting the extreme surveillance trend that has been going on since 2001.

So all in all the Security World exhibit was kinda disappointing. Not only were there not really any innovative products, many of the things you would expect, wasn’t there either. Why wasn’t e.g. HP there with WebInspect and DevInspect? Or RSA? Or Tennable Security? Or, in more of a open source direction, OpenBSD? Many of the relevant groups and companies where not represented. (To be fair, BSD was in another hall, but in another capacity)

We care!

We care!

After the day went to an end, we drifted over to Munchenhalle, which is basically a classical German Tyrolean restaurant thing where people go after CeBIT to eat and .. well.. get stinking drunk! So we did exactly that and got to do a bunch of stuff like dance the bogey bogey, buy a Tyrolean hat for 20 Euros, spoke Danish with a Vietnamese guy and even sang happy birthday to a Chinese guy.. So no matter how good CeBIT is during the day, it usually always ends well ;-)

But in all seriousness again! Sadly I’m afraid the economic crisis scared some of the biggest companies away, which inevitably lowered the relevance of many of the halls. Now, to be fair, CeBIT usually has an over representation of companies selling their normal products, compared to companies showing off their new innovative products. However before it’s been somewhat of another ratio! Basically, we decided a good characterization is this: CeBIT usually consists of a turd covered in sprinkles.. in order to get the sprinkles you need to get a bit of the turd! However now CeBIT is more like a turd consisting of 10% embedded sprinkles.. now you actually have to eat the entire turd to get the damn sprinkles.. and even then, there are way to few sprinkles ;-)

See you next year at CeBIT

See you next year at CeBIT

So with that disgusting analogy, I leave you with whatever you were doing and will simply say:

Cheers, hopefully we’ll see you next year at CeBIT!

Twitter birdYes, Aconiac has now officially started twittering!

Now you’re probably thinking: “Why? oh why God?”. Especially if you’re the typical European or business professional. However after having looked into the matter, we have found good use of Twitter and can see how it has it’s place in the future business market – so that is really why!

So what will be twittering?  Well, we thought long and hard about what content could be efficiently distributed in 140 characters, since this is, by all common standards, a very limited text amount. Ultimately we came to the conclusion, that security tips & tricks, news and facts were of most interest and it is therefore this we will be twittering in the future with our “Did you know?” posts.

If this has peaked your interest, please go to http://twitter.com/AconiacSecurity and follow our posts there.

As a final note: We’ve added a “Tweet this” button to all posts, so that you can easily post our blog posts titles and links to your Twitter account.

NOTE: This news item was originally posted on February 14, 2009.

Since we often get contacted concerning different types of partnership deals, we have now chosen to create a service for this purpose.

Further description of the service can be found here.

NOTE: This news item was originally posted on January 4, 2009

Since many of our clients have turned out to be fully capable of correcting their security issues themselves or really just wanted to get their own security corrections checked, we have now launched a service that can fulfil this need.

This service is Vulnerability Testing and is basically like Security Testing, however without Aconiac correcting the security issues and without Aconiac needing to have access to specifications about the system. A vulnerability test is therefore a real simulated attack from a hacker, so that companies can find whatever security issues a hacker would have found.

The service is sold at a fixed price of 540€ excl. VAT, with the sole exception that if your system is abnormally large or complex, Aconiac may deny to do the service at the fixed price and will instead suggest other solutions, like e.g. a real security test.

Further description of the service can be found here.

NOTE: This news item was originally posted on January 2, 2009

Aconiac Password Generator has, for some time, lacked a proper and easy way of installing the application. We have therefore now released a version with the Java Web Start technology. Java Web Start makes it easy to install the application on any system and even makes automatic updates of the application for the user – ultimately resulting in a more automated and easy process. Download the application by pressing the big green button on the product page.

If, for some reason, you do not want to use the Java Web Start version, it is of course still possible to download the application from SourceForge.net

NOTE: This news item was originally posted on December 30, 2008

Security threats in 2009

2008 will soon be over and a new and exciting year lies in front of us. 2008 was an interesting year for computer security. We saw, once again, escalating threats towards companies from almost all fronts. Especially the leaks of unencrypted data in England, the automated SQL injection mass-attacks and the attacks on social network services were some of the big public problems in 2008.
But then how will 2009 be? Now, it’s obviously very hard to predict the future in such a dynamic world, however we have made an effort to come up with our ideas for what might be, the 10 biggest security threats in 2009:

  1. Weak economy

    The economic crisis, which right now is devastating many businesses all over the world, will most likely result in companies having to cut down on expenses. In these kinds of expense cuts, typically what gets cut first is the administrative expenses like e.g. computer security and preventive measures. We can therefore expect to see an increase in the amount of security issues in software and systems developed in 2009.

  2. Lack of education

    One of the greatest threats towards security in a company is and will always be education. This has been, in our minds, the biggest issue in 2008 and actually have always been the biggest issue. Users of IT solutions do not understand the security problems in such a way, that they can effectively protect themselves. We will therefore, once again this year, probably see an increase in successful hacker attacks – attacks that largely could be prevented by increased education.

  3. Mobile devices

    Employees are becoming more and more mobile as each day passes. One of the big things that really got a boost in 2008 was mobile broadband. This technology specifically, can lead to employees beginning to do their jobs outside of the company’s secure parameters. A trend that could ultimately lead to catastrophic data leakage, that is if it is not prevented by good policies and encryption.

  4. Outsourcing

    Due to the economic crisis, a lot of companies will probably begin to outsource certain tasks to cheaper labor in other countries. This act however has a lot of serious security implications, since the company now no longer has control of how its data is handled. It is therefore extremely important, that companies make a proper security policy with their outsourcing partner and that this policy is actually followed.

  5. Espionage

    The time when hackers were just small kids in a basement is, by far, over. Today several indications are showing that hacking has, in several cases, been used by e.g. China to attack government institutions in the USA. This type of attack, which for the record can have catastrophic consequences, will likely escalate in 2009, where we will see even more examples of this form of Internet warfare.

  6. Anonymity/Privacy

    While nations all over the world are using more and more censorship and surveillance, many freedom-loving employees will begin to work harder to secure their privacy and the right to free speech. This will probably manifest itself in an increased use of software to break blocking mechanisms and hide information about the user. With this increased usage, it will become much harder for companies to identify malicious users, since it will now not only be the criminals who are attempting to hide from identification.

  7. Apple’s Mac OS X

    While viruses and spyware are everyday fears of Windows users, Apple’s Mac OS X has up until now avoided most problems. They’ve actually avoided it so well, that many Mac users are now, mistakenly, believing Mac OS X can not be infected with malicious software, like e.g. a virus. Apple had a record high sale of Macs in 2008 and as their market share increases, so will the number of attacks on the platform increase. Sooner or later it will therefore become a security risk to have an unprotected Mac OS X on the company network and companies should therefore implement effective security policies for Mac users.

  8. Insecure websites

    A lot of companies and government institutions still have websites with several security issues of varying types. With the increasing economic crisis and the likewise increasing amount of computer criminals, it is very likely many more companies will be attacked from the web this year. Even many more than earlier years.

  9. SMS Scams (SMiShing)

    With the expanded use of SMSs for almost any thinkable communication, criminals will soon begin to notice the possibilities in the use of SMS to scam individuals and companies. Most do not know, that it is extremely easy to fake an SMS so that it seems as if the SMS is from “Mom” or “The Boss”. This makes it easy for criminals to scam people into wiring funds or giving out passwords.

  10. Social networks

    Social networks are not as big of a threat as some security companies would have you believe, however there are several dangers you should take seriously as a company owner. Like e.g. in 2008 there were several attempts at spreading viruses through Facebook and especially MSN Messenger is often a target for computer criminals. All of these attacks can however generally be avoided with simple education of one’s employees. We don’t recommended blocking the access to social networks for your employees, even though we know certain companies do this today.

NOTE: This news item was orignally posted on December 3, 2008

Since our password generator has always been free and is fairly simple software, we have now decided to release the software as open source under the so called 3-clause BSD license.

This means that if you need a password generation feature for your software, you can actually take our code and use it directly in your code without paying us a dime. Just as long as you write publicly that you are using our code.

You can read more about the BSD license on Wikipedia

The code is stored on SourceForge.Net and there is a direct link to the project here on the website