PSA: If you’ve ever used a Sennheiser headset with your Mac, it is wide open to attack

If you’ve ever used a Sennheiser headset or speakerphone device with your Mac (or Windows PC), the accompanying HeadSetup app has left your machine wide open to attack.

In what has been described as a ‘monumental security blunder,’ the app allows a bad actor to successfully impersonate any secure website on the Internet …

ArsTechnica explains.

To allow Sennheiser headphones and speaker phones to work seamlessly with computers, HeadSetup establishes an encrypted Websocket with a browser. It does this by installing a self-signed TLS certificate in the central place an operating system reserves for storing browser-trusted certificate authority roots. In Windows, this location is called the Trusted Root CA certificate store. On Macs, it’s known as the macOS Trust Store.

The critical HeadSetup vulnerability stems from a self-signed root certificate installed by version 7.3 of the app that kept the private cryptographic key in a format that could be easily extracted. Because the key was identical for all installations of the software, hackers could use the root certificate to generate forged TLS certificates that impersonated any HTTPS website on the Internet. Although the self-signed certificates were blatant forgeries, they will be accepted as authentic on computers that store the poorly secured certificate root. Even worse, a forgery defense known as certificate pinning would do nothing to detect the hack.

Although the app encrypted the key with a passphrase, the passphrase itself (SennheiserCC) was stored in plaintext in a configuration file.

“It took us a few minutes to extract the passphrase from the binary,” Secorvo researcher André Domnick told Ars. From then on, he effectively had control of a certificate authority that any computer that had installed the vulnerable Sennheiser app would trust until 2027, when the root certificate was set to expire. Dominick created a proof-of-concept attack that created a single certificate […] that spoofed Google, Sennheiser, and three of Sennheiser’s competitors.

Even if you later uninstalled the app, the certificate would still be trusted. All Mac users who have ever used the HeadSetup app should manually uninstall the certificate by following Sennheiser’s instructions. (The instructions leave out the first step, which is to ensure you’re in the Finder.)

If you still use the app, you can download the latest version of HeadSet, which should also delete the vulnerable certificate, but the safest option would be to do it manually as above first

[“source=forbes]

Entry period open for Fashion Fallies show

Fashion Fallies is returning for fall of 2018. Organizers of the wearable art and performance event that wooed crowds last fall are busy planning this year’s event, which will take place once again at Haliburton School of Art + Design on Friday, Nov. 9. The Arts Council ~ Haliburton Highlands event has recently rleased their call for entry.

Fashion design experience is not required. Any and all mediums are welcome, including paper, wire, plastic, recycled materials, yarn, leaves, etc. Accessories, jewelry, single pieces or complete ensembles are all welcome.

“We have already heard that some people have already begun creating pieces,” says Amy Brohm, Fashion Fallies planning committee member. “People are really excited about this event and we have a number of new things planned for 2018.”

An information session and slideshow will be taking place on Wednesday, June 6 between 5:30 to 6:30 p.m. in the Common Room of the Haliburton County Public Library for anyone who is interested in finding out more about the event and how they can submit a piece.

In addition, The Fashion Fallies committee in conjunction with Visible Voices studio is hosting a workshop called Head Over Heels for Fashion Fallies. This $10 workshop or pay-what-you-can is happening on Saturday, June 16 between 1 and 4 p.m. at Visible Voices Open Arts Studio on Industrial Drive. Head Over Heels will provide an opportunity to make fun and whimsical headpieces and get people inspired about creating for Fashion Fallies. All materials will be provided.

Source:-haliburtonecho