Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

End of Bibblio RCM includes -->
11/11/2021
01:45 PM
Connect Directly
Twitter
RSS
E-Mail

What Happens If Time Gets Hacked

Renowned hardware security expert raises alarm on the risk and dangers of cyberattackers targeting the current time-synchronization infrastructure.



BLACK HAT EUROPE 2021 - London - Most people take time synchronization for granted, but it operates on what hardware security expert Adam Laurie calls a "fragile ecosystem." Laurie, a renowned hardware hacker, here today demonstrated an unnervingly simple way to alter time on a clock.

"I was curious if I could spoof the time" synchronization signal, he explained in a keynote on his research. So he built his own simulated time-signal system using an open source tool called txtempus, which simulates signals for syncing the time on clocks and watches, and ran it on Raspberry Pi outfitted with a radio-frequency identification (RFID) antenna.

Laurie's contraption overrode the UK region's official low-frequency, radio broadcast-based clock synchronization signal. During his demo, he ultimately reset a red clock's hands to show a mirror-image rendering of the real time on a white clock: The hacked red clock was instructed to display the time as 4:18 while the untouched clock read 9:48, the correct time (see photo).

The white clock was set to operate normally, communicating with the Network Time Protocol (NTP) that transmits local atomic clock broadcasts to timekeeping devices. The red clock, also was set to communicate with National Physical Laboratory, the UK atomic clock feed via NTP, but Laurie commandeered the feed on that link. 

"I overrode the signal" and forced it to display the incorrect time, he said in an interview.

The hack underscored how easily RFID can be abused and how that potentially could wreak havoc by altering time on a wider scale. And unlike other security issues, this risk to time-hacking isn't rooted in software or hardware vulnerabilities: It's more about an aging technology and process.

"It's more of an existential vulnerability because it's the way the technology evolved and the way it was adopted before anyone was worrying that it's not an actual secure method," said Laurie, whose time research is independent of his employer IBM X-Force, where he is the lead hardware hacker.

Time Out
Correct time synchronization affects wide swaths of society: everything from financial transactions that rely on accurate timing of payments, to industrial systems, forensics, and time-stamped network packets on the Internet. Internet of Things (IoT) devices rely on the atomic clock. In his keynote, Laurie cited a 2017 UK report that estimated the cost of time-synchronization failure was a stunning 1 billion British pounds per day.

He also noted government and industry efforts to shore up the security of time synchronization, including that of The Resilient Navigation and Timing Foundation, an international nonprofit advisory council. The foundation has proposed hardening GPS and Global Navigation Satellite System (GNSS) systems to protect spoofing and jamming signals, and adding legal teeth to enforce it.

The Internet's NTP and PTP distribute time updates and currently could be duped into transmitting spoofed information, he pointed out.

"They're not the source of time, but they need the external source that tells them the time," namely the atomic clock, which broadcasts over RF and GPS, Laurie explained.

Ransomware attacks are an obvious threat here, he added.

"If I can take out a financial organization by DOS'ing their atomic clock feed, that would be a very powerful attack," he said.

The security risks of RF long have been illuminated by Laurie and other researchers. The bottom line: RF transmits data in plain text.

"The strongest signal wins, and there's no authentication" in most of these transmissions, he said. There are technologies for validating signals, but most of the existing RF infrastructure remains insecure, he added.

"There's a huge, deployed infrastructure that relies on these insecure technologies. This [time] is one of those hidden nasties waiting to bite us," he said.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
//Comments
Threaded  |  Newest First  |  Oldest First
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Creating an Effective Incident Response Plan
Security teams are realizing their organizations will experience a cyber incident at some point. An effective incident response plan that takes into account their specific requirements and has been tested is critical. This issue of Tech Insights also includes: -a look at the newly signed cyber-incident law, -how organizations can apply behavioral psychology to incident response, -and an overview of the Open Cybersecurity Schema Framework.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-45343
PUBLISHED: 2022-11-29
GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.
CVE-2022-44635
PUBLISHED: 2022-11-29
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgr...
CVE-2022-46146
PUBLISHED: 2022-11-29
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, i someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for...
CVE-2022-36433
PUBLISHED: 2022-11-29
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.
CVE-2022-4202
PUBLISHED: 2022-11-29
A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclose...