{"id":14306,"date":"2019-01-14T09:10:09","date_gmt":"2019-01-14T17:10:09","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/01\/14\/news-8058\/"},"modified":"2019-01-14T09:10:09","modified_gmt":"2019-01-14T17:10:09","slug":"news-8058","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/01\/14\/news-8058\/","title":{"rendered":"Government shutdown impacts .gov websites, puts Americans in danger"},"content":{"rendered":"<p><strong>Credit to Author: Adam Kujawa| Date: Mon, 14 Jan 2019 16:00:00 +0000<\/strong><\/p>\n<p>If you are in the United States, then you should know we are on our 24th day of a government shutdown. While it is considered a &#8220;partial&#8221; shutdown, there are still plenty of government workers who are not being paid or have been sent home, furloughed.<\/p>\n<p>Last week, <a href=\"https:\/\/techcrunch.com\/2019\/01\/11\/shutdown-government-websites-https-certificates-expire\/\" target=\"_blank\" rel=\"noopener\">TechCrunch posted a concerning story<\/a> about the shutdown, which covered the <a href=\"https:\/\/news.netcraft.com\/archives\/2019\/01\/10\/gov-security-falters-during-u-s-shutdown.html\" target=\"_blank\" rel=\"noopener\">findings of NetCraft<\/a>, a UK Internet service company, who discovered that numerous US government websites are now inaccessible due to expired security certificates.<\/p>\n<p>This is a quick post to explain what happened, and more importantly, how cybercriminals will use this situation to their advantage.<\/p>\n<h3>Security certificates<\/h3>\n<p>We aren&#8217;t going to<a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2017\/08\/explained-security-certificates\/\" target=\"_blank\" rel=\"noopener\"> dig deep into how security certificates work<\/a> for websites, but the gist is that every vendor or organization that uses a website requires a security certificate for users to access their site with trust. Today, a few browsers, like Chrome, require these certificates before they even let users access the websites. You can recognize when a website uses a valid security certificate, usually indicated by a <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/05\/https-why-the-green-padlock-is-not-enough\/\" target=\"_blank\" rel=\"noopener\">green lock<\/a> on the URL bar.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26829\" data-permalink=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/attachment\/2019-01-11_12-53-02\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/2019-01-11_12-53-02.png\" data-orig-size=\"256,33\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"2019-01-11_12-53-02\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/2019-01-11_12-53-02.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/2019-01-11_12-53-02.png\" class=\"size-full wp-image-26829 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/2019-01-11_12-53-02.png\" alt=\"\" width=\"256\" height=\"33\" \/><\/p>\n<p>The certificate confirms that the identity of the website that you are communicating with is legitimate. In addition, these certificates make it possible for users to establish a secure connection with the web server hosting the site, which is incredibly important when sending financial or personal information to these sites.<\/p>\n<p>Since some of the most popular browsers won&#8217;t even let users visit a website if it doesn&#8217;t have a valid certificate, we now have a lot of users who can&#8217;t access government websites because the certificates have expired.<\/p>\n<h3>Why did they expire?<\/h3>\n<p>So, if a security certificate lasted forever, what would be the assurance that it hasn&#8217;t been stolen by a criminal who will then be able to use it on their own malicious websites? Because of this reason, and probably some other ones, certificates do expire and it requires the organization that owns the website to purchase and deploy a new certificate that is up to date.\u00a0 Think of it like yearly fees to renew your car tags.<\/p>\n<p>The reason these certificates were allowed to lapse is because there is nobody renewing them.\u00a0 Apparently, most US organization websites maintain their own certificates.\u00a0 This is why not ALL U.S. gov websites are down, just a few of them (at least right now).\u00a0 With the government partial shutdown, the people in charge of making sure citizens can access their websites by keeping these certificates up to date are unable to do their jobs, which eventually leads to users being unable to access these sites at all.<\/p>\n<h4>The Danger<\/h4>\n<p>Okay, so obviously not being able to access some government websites is a pain, but it isn&#8217;t anything that your regular person needs to worry about, as long as they aren&#8217;t frequent visitors to these gov sites. However, with any opportunity, you can bet that cyber criminals are going to take advantage.<\/p>\n<p>That is why we want to make sure that we share some vital warnings about how this shutdown may help cyber-criminals.\u00a0 <em>Please, share this with everyone you know, at least until the shutdown is over<\/em>.<\/p>\n<p>Cyber criminals frequently utilize real world events in order to trick users into clicking on a link, downloading or sharing something.\u00a0 You can look back at a couple of instances where events in <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2012\/06\/blackshades-in-syria\/\" target=\"_blank\" rel=\"noopener\">Syria directly influenced the actions of cyber criminals<\/a>, be it state sponsored or otherwise.\u00a0 In another case, the <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2013\/04\/cyber-criminals-never-waste-a-tragedy\/\" target=\"_blank\" rel=\"noopener\">Boston bombing from a few years back<\/a> was used to try and scam people.<\/p>\n<div id=\"attachment_26830\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539.png\" target=\"_blank\" rel=\"noopener\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26830\" data-permalink=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/attachment\/youtubess-1024x539\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539.png\" data-orig-size=\"1024,539\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"YoutubeSS-1024&#215;539\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539-300x158.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539-600x316.png\" class=\"wp-image-26830 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539.png\" alt=\"\" width=\"1024\" height=\"539\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539.png 1024w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539-300x158.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/YoutubeSS-1024x539-600x316.png 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Fake YouTube page setup to infect Syrian rebels.<\/p>\n<\/div>\n<p>With that being said, you can expect that users who are looking for government websites, especially if they offer some kind of service or require some kind of personal information or login to access, is going to be copied by cyber criminals and likely be presented as an alternative way to access the same website.<\/p>\n<div id=\"attachment_26831\" style=\"width: 810px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.gov.sg\/news\/content\/beware-of-fake-ica-phishing-website\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26831\" data-permalink=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/attachment\/fake-ica-website\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website.jpg\" data-orig-size=\"800,500\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Fake ICA website\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website-300x188.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website-600x375.jpg\" class=\"wp-image-26831 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website.jpg\" alt=\"\" width=\"800\" height=\"500\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website.jpg 800w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website-300x188.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/Fake-ICA-website-600x375.jpg 600w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">Fake Singapore Government Website &#8211; From Gov.SG<\/p>\n<\/div>\n<p>While most users are likely not going to be affected by this very much, those that rely on social services and likely older folks will be looking for a way to access these sites, for whatever reason.\u00a0 When they go to search for the site, their first link might take them to a dead end, since the security certificate had expired, however the second or third link might work and take the user to a page that looks exactly where they want to go.\u00a0 Classic phishing attack.<\/p>\n<h4>What to do about it?<\/h4>\n<p>The best thing to do right now is share this information with those close to you so they don&#8217;t make a mistake and give away valuable personal info just because the government has issues keeping itself open.\u00a0 Also, be vigilant moving forward, not just for this case but for others, any bit of sensational news needs to be investigated outside of a link telling you to click.<\/p>\n<p>The bad guys know human behavior and they know that people can&#8217;t help clicking on things that are either convenient or scandalous and sensational. Prove them wrong.<\/p>\n<p>Stay safe and safe surfing!<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/\">Government shutdown impacts .gov websites, puts Americans in danger<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Adam Kujawa| Date: Mon, 14 Jan 2019 16:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/' title='Government shutdown impacts .gov websites, puts Americans in danger'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/01\/shutterstock_402092170.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Today, TechCrunch posted a concerning story about the shutdown and most importantly, they covered the reporting of NetCraft, a U.K. internet service company, about how numerous US government websites are now inaccessible due to expired security certificates. This is going to be a quick post to help explain what happened and more importantly, how cyber criminals will use this situation to their advantage.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/government\/\" rel=\"category tag\">Government<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/\" rel=\"category tag\">Security world<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/access\/\" rel=\"tag\">access<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/government-shutdown\/\" rel=\"tag\">government shutdown<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/security\/\" rel=\"tag\">security<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/security-certificates\/\" rel=\"tag\">security certificates<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/shutdown\/\" rel=\"tag\">shutdown<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trump\/\" rel=\"tag\">trump<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/wall\/\" rel=\"tag\">wall<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/' title='Government shutdown impacts .gov websites, puts Americans in danger'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/01\/government-shutdown-puts-americans-danger\/\">Government shutdown impacts .gov websites, puts Americans in danger<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[12505,1328,20659,714,13447,10497,1343,152,10628],"class_list":["post-14306","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-access","tag-government","tag-government-shutdown","tag-security","tag-security-certificates","tag-security-world","tag-shutdown","tag-trump","tag-wall"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14306"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14306\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14306"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}