Thursday, April 22, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Some Fortinet products shipped with hardcoded encryption keys

November 26, 2019
in Internet Security
Some Fortinet products shipped with hardcoded encryption keys
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Image: Fortinet, ZDNet

Fortinet, a vendor of cyber-security products, took between 10 and 18 months to remove a hardcoded encryption key from three products that were exposing customer data to passive interception.

The hardcoded encryption key was found inside the FortiOS for FortiGate firewalls and the FortiClient endpoint protection software (antivirus) for Mac and Windows.

You might also like

Instagram debuts new tool to stop abusive message salvos made through new accounts

Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case

New Australian cyber package includes AU$37.5m Indo-Pacific investment

These three products used a weak encryption cipher (XOR) and hardcoded cryptographic keys to communicate with various FortiGate cloud services.

The hardcoded keys were used to encrypt user traffic for the FortiGuard Web Filter feature, FortiGuard AntiSpam feature, and FortiGuard AntiVirus feature.

A threat actor in a position to observe a user or a company’s traffic would have been able to take the hardcoded encryption keys and decrypt this weakly encrypted data stream. Depending on what product a company was using, the attacker would have learned:

– Full HTTP or HTTPS links for users’ web surfing activity (sent for testing to the Web Filter feature)
– Email data sent for testing to the AntiSpam feature)
– Antivirus data (sent for testing to the (Fortinet cloud) AntiVirus feature)

But besides sniffing a user’s traffic, the attacker could have also used the same hardcoded encryption key to alter and re-encrypt responses, neutering alerts for malware detections or bad URLs.

It took months to get this fixed

The issues were discovered in May 2018 by Stefan Viehböck, a security researcher for SEC Consult. The process of reporting and having these issues fixed by Fortinet has been abnormally long and slow.

For example, while most companies acknowledge bug reports on the same day, it took three weeks until a Fortinet employee got on the case.

Fixing the bugs took even longer. Fortinet removed the encryption key from recent versions of FortiOS only in March 2019, ten months after the initial report.

It then took another eight months to remove the encryption keys from older versions, with the last patch being released earlier this month.

Below are the impacted Fortinet products:

  • FortiOS 6.0.6 and below
  • FortiClientWindows 6.0.6 and below
  • FortiClientMac 6.2.1 and below

System administrators are advised to apply the following patches to remove the hardcoded encryption keys:

  • FortiOS 6.0.7 or 6.2.0
  • FortiClientWindows 6.2.0
  • FortiClientMac 6.2.2

A Fortinet spokesperson did not reply to a request for comment before this article’s publication. Viehböc’s write-up and demo code is available on the SEC Consult website. Fortinet’s security advisory is available here.

Credit: Zdnet

Previous Post

Why did your chatbot fail miserably ?

Next Post

The Magic of Generative Adversarial Network (GANs)

Related Posts

Instagram debuts new tool to stop abusive message salvos made through new accounts
Internet Security

Instagram debuts new tool to stop abusive message salvos made through new accounts

April 21, 2021
Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case
Internet Security

Facebook cracks down on posts urging violence, mockery ahead of Chauvin verdict in George Floyd case

April 21, 2021
New Australian cyber package includes AU$37.5m Indo-Pacific investment
Internet Security

New Australian cyber package includes AU$37.5m Indo-Pacific investment

April 21, 2021
Google issues Chrome update patching seven security vulnerabilities
Internet Security

Google issues Chrome update patching seven security vulnerabilities

April 21, 2021
Multi-factor authentication: Use it for all the people that access your network, all the time
Internet Security

Multi-factor authentication: Use it for all the people that access your network, all the time

April 21, 2021
Next Post
The Magic of Generative Adversarial Network (GANs)

The Magic of Generative Adversarial Network (GANs)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Machine Learning Tacks Evolution of COVID-19 Misinformation
Machine Learning

Machine Learning Tacks Evolution of COVID-19 Misinformation

April 22, 2021
How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021
Neural Networks

How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021

April 22, 2021
Instagram debuts new tool to stop abusive message salvos made through new accounts
Internet Security

Instagram debuts new tool to stop abusive message salvos made through new accounts

April 21, 2021
Improve Your Cyber Security Posture by Combining State of the Art Security Tools
Internet Privacy

Improve Your Cyber Security Posture by Combining State of the Art Security Tools

April 21, 2021
6 Ways AI is Changing The Learning And Development Landscape
Data Science

6 Ways AI is Changing The Learning And Development Landscape

April 21, 2021
Weekly NFT roundup April 14-20: Real-world applications grow through postage and insurance
Blockchain

Weekly NFT roundup April 14-20: Real-world applications grow through postage and insurance

April 21, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Machine Learning Tacks Evolution of COVID-19 Misinformation April 22, 2021
  • How AI Is Disruptive Innovation For OCR | by Infrrd | Apr, 2021 April 22, 2021
  • Instagram debuts new tool to stop abusive message salvos made through new accounts April 21, 2021
  • Improve Your Cyber Security Posture by Combining State of the Art Security Tools April 21, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates