Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

11/11/2021
01:45 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

What Happens If Time Gets Hacked

Renowned hardware security expert raises alarm on the risk and dangers of cyberattackers targeting the current time-synchronization infrastructure.

BLACK HAT EUROPE 2021 - London - Most people take time synchronization for granted, but it operates on what hardware security expert Adam Laurie calls a "fragile ecosystem." Laurie, a renowned hardware hacker, here today demonstrated an unnervingly simple way to alter time on a clock.

"I was curious if I could spoof the time" synchronization signal, he explained in a keynote on his research. So he built his own simulated time-signal system using an open source tool called txtempus, which simulates signals for syncing the time on clocks and watches, and ran it on Raspberry Pi outfitted with a radio-frequency identification (RFID) antenna.

Laurie's contraption overrode the UK region's official low-frequency, radio broadcast-based clock synchronization signal. During his demo, he ultimately reset a red clock's hands to show a mirror-image rendering of the real time on a white clock: The hacked red clock was instructed to display the time as 4:18 while the untouched clock read 9:48, the correct time (see photo).

The white clock was set to operate normally, communicating with the Network Time Protocol (NTP) that transmits local atomic clock broadcasts to timekeeping devices. The red clock, also was set to communicate with National Physical Laboratory, the UK atomic clock feed via NTP, but Laurie commandeered the feed on that link. 

"I overrode the signal" and forced it to display the incorrect time, he said in an interview.

The hack underscored how easily RFID can be abused and how that potentially could wreak havoc by altering time on a wider scale. And unlike other security issues, this risk to time-hacking isn't rooted in software or hardware vulnerabilities: It's more about an aging technology and process.

"It's more of an existential vulnerability because it's the way the technology evolved and the way it was adopted before anyone was worrying that it's not an actual secure method," said Laurie, whose time research is independent of his employer IBM X-Force, where he is the lead hardware hacker.

Time Out
Correct time synchronization affects wide swaths of society: everything from financial transactions that rely on accurate timing of payments, to industrial systems, forensics, and time-stamped network packets on the Internet. Internet of Things (IoT) devices rely on the atomic clock. In his keynote, Laurie cited a 2017 UK report that estimated the cost of time-synchronization failure was a stunning 1 billion British pounds per day.

He also noted government and industry efforts to shore up the security of time synchronization, including that of The Resilient Navigation and Timing Foundation, an international nonprofit advisory council. The foundation has proposed hardening GPS and Global Navigation Satellite System (GNSS) systems to protect spoofing and jamming signals, and adding legal teeth to enforce it.

The Internet's NTP and PTP distribute time updates and currently could be duped into transmitting spoofed information, he pointed out.

"They're not the source of time, but they need the external source that tells them the time," namely the atomic clock, which broadcasts over RF and GPS, Laurie explained.

Ransomware attacks are an obvious threat here, he added.

"If I can take out a financial organization by DOS'ing their atomic clock feed, that would be a very powerful attack," he said.

The security risks of RF long have been illuminated by Laurie and other researchers. The bottom line: RF transmits data in plain text.

"The strongest signal wins, and there's no authentication" in most of these transmissions, he said. There are technologies for validating signals, but most of the existing RF infrastructure remains insecure, he added.

"There's a huge, deployed infrastructure that relies on these insecure technologies. This [time] is one of those hidden nasties waiting to bite us," he said.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises Are Assessing Cybersecurity Risk in Today's Environment
The adoption of cloud services spurred by the COVID-19 pandemic has resulted in pressure on cyber-risk professionals to focus on vulnerabilities and new exposures that stem from pandemic-driven changes. Many cybersecurity pros expect fundamental, long-term changes to their organization's computing and data security due to the shift to more remote work and accelerated cloud adoption. Download this report from Dark Reading to learn more about their challenges and concerns.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-25056
PUBLISHED: 2022-01-26
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.
CVE-2022-0355
PUBLISHED: 2022-01-26
Exposure of Sensitive Information to an Unauthorized Actor in NPM hiep-simple-get prior to 4.0.1.
CVE-2021-46559
PUBLISHED: 2022-01-26
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.
CVE-2021-46560
PUBLISHED: 2022-01-26
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
CVE-2022-23959
PUBLISHED: 2022-01-26
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.