Showing posts with label Security; Identity Management. Show all posts
Showing posts with label Security; Identity Management. Show all posts

Thursday, July 30, 2015

CyberWatch West Invitation


CyberWatch West would like to invite all MPICT member institutions to join our center. 

CyberWatch West is a regional center for Cybersecurity education covering 14 states in the western US. We are heavily involved in many of the same initiatives as MPICT, including advocating for an ICT transfer model curriculum and continuing support for the ICT winter conference in CA.
Member benefits include travel sponsorships and training and there is no cost to join. For more information, please go to http://cyberwatchwest.org.

To see our member map and to apply for membership, go here: http://cyberwatchwest.org/index.php/about-us/member-map.


For additional information, please contact Corrinne Sande (PI for CyberWatch West) at csande@whatcom.ctc.edu.

Thursday, July 16, 2015

BBC: Darkode hacking forum forced offline

By Leo KelionTechnology desk editor  BBC

15 July 2015
From the sectionTechnology
The Darkode forum, which was created about six years ago, can no longer be accessed
Darkode - a notorious hacking forum used by Lizard Squad and other cybercriminals - has been shut down after an investigation carried out by authorities in 20 countries.
"We have dismantled a cyber-hornets' nest... which was believed by many, including the hackers themselves, to be impenetrable," said one of the US state attorneys involved.

Twenty-eight people have been arrested.

They include a 26-year-old man from Coventry, England.

In addition, the UK's National Crime Agency said an address in Paisley, Scotland, had been searched and material removed for examination. It said that five other suspected members of the site had previously been arrested.

The FBI added that dozens of other people linked to the site had been charged or had their property searched as part of the inquiry.
Restricted access
Darkode's members allegedly used the site to trade and to share hacking tools and information, including details of zero-day attacks - techniques that exploited flaws in products that neither their creators nor the wider security industry were aware of, and thus could not be protected against.

This information was password-protected.

"Only those proposed for membership by an existing user could join, but not until they posted a resume of the skills and achievements that could contribute to the criminal community," explained the NCA.

"There was a hierarchical membership structure, and the status of users determined who they could communicate with, and their access to the commodities and services on offer."

Although the site was not accessible to the general public, it was profiledextensively by the security blogger Brian Krebs, who posted several screenshots on his site.

Botnets - networks of hijacked computers used to mount co-ordinated attacks - were promoted on the site
"Most of the cybercrime forums are in Russian or some other language that's not English, but this was an English-language forum," he told the BBC.

"And it was a sort of meeting ground for cybercriminals from different nationalities and languages.

"A fairly significant number of people were selling botnet services there, and there were also services for deploying malware and phishing."

He added that the forum's visitors included members of Lizard Squad - a group of hackers which has carried out high-profile attacks on Sony, Microsoft and others.

"The guy that was most recently the admin of the forum used the nickname Sp3c," Mr Krebs recalled.

"He was a leading member of the Lizard Squad. What's interesting is that you don't see his name in the lists of those that were apprehended or charged as part of this.

"I don't really know what that means, but there was a definite connection between the Lizard Squad and this forum, at least in the last year or so."

The FBI said that Operation Shrouded Horizon had indicated up to 300 people had used the forum.

"During the investigation, the bureau focused primarily on the Darkode members responsible for developing, distributing, facilitating and supporting the most egregious and complex cybercriminal schemes targeting victims and financial systems," it said.

It added that its counterparts in Australia, Bosnia, Brazil, Israel, Colombia and Nigeria were among those involved in the international crackdown, and that efforts to trace other suspects were "ongoing".

Friday, July 10, 2015

BBC: Huge data breach prompts resignation of top US official

3 hours ago  BBC
From the sectionUS & Canada


The director of the US Office of Personnel Management (OPM) has resigned after a massive data breach involving more than 20 million people.
Katherine Archuleta said she would step down on Friday to help the department "move beyond the current challenges".

Authorities suspect that Chinese-based hackers targeted the computer systems of the OPM, which acts as the personnel office of the federal government.

Initially the OPM said four million workers were affected by the breach.

However, the department disclosed on Thursday that the data of more than 20 million people, including current and former employees, may have been compromised.

Authorities in Beijing have publicly denied any involvement.

Ms Archuleta resignation comes a day after Democrats and Republicans in Congress called for her to step aside as the scope of the data breach expanded significantly.

Among the data targeted were forms used to vet potential employees of federal agencies including as the CIA and branches of the military.

OPM serves as the human resource department for the US government
The stolen data includes health and financial information, criminal records, and the names and addresses of government employees and their relatives.

Experts are concerned that the sensitive information could be used to blackmail US agents.
What was stolen?
social security numbers
residency and educational history
employment history
information about immediate family and other personal and business acquaintances
health, criminal and financial history
findings from interviews conducted by background investigators
fingerprints
usernames and passwords that background investigation applicants used

Source: OPM news release

Last month, US intelligence chief James Clapper said China was the "leading suspect" in the massive data breaches.

His comments came after three days of high-level talks in which China and the US agreed to a "code of conduct" on cyber security issues.

US Democratic presidential hopeful Hillary Clinton said China was "trying to hack into everything that doesn't move in America".

But China has dismissed claims of involvement as "irresponsible and unscientific".

BBC: Hackers 'stole data of millions of US government workers'

10 July 2015 BBC
From the sectionUS & Canada
OPM serves as the human resource department for the US government
Hackers that breached US government databases stole the personal information of at least 21.5 million people, officials said on Thursday.
Those affected include government job applicants, federal contractors, and over a million of their partners, the Office of Personnel Management said.

The figure is more than five times higher than the number of people that were feared to have been affected.

The data breach, which came to light in April, was widely blamed on China.

Authorities in Beijing have publicly denied any involvement.

The breach prompted a series of hearings in Congress and widespread criticism of the state of US cyber defences.

Politicians from both parties demanded OPM boss Katherine Archuleta be fired.

House of Representatives Speaker John Boehner, a Republican, said President Barack Obama "must take a strong stand against incompetence in his administration and instill new leadership at OPM".

Last month, officials said personnel records of 4.2 million current and former federal government employees had been stolen in an incident.
'No misuse yet'
On Thursday, OPM said that while investigating that breach they discovered additional information had also been compromised, including the social security numbers of 21.5 million individuals.

The stolen data also includes health and financial information, criminal records, and the names and addresses of government employees and their relatives.

Those affected include 19.7 million people who underwent background checks and 1.8 million others, mostly the partners of job applicants.


OPM serves as the human resource department for the US government. The agency issues security clearances and compiles records of all federal government employees.
The agency said that it had "no information at this time to suggest any misuse or further dissemination of the information that was stolen from OPM's systems."

But it said that for anyone who underwent a background investigation in 2000 or afterwards "it is highly likely that the individual is impacted by this cyber breach."

Last month, US intelligence chief James Clapper said China was the "leading suspect" in the massive data breaches.

His comments came after three days of high-level talks in which China and the US agreed to a "code of conduct" on cyber security issues.

Earlier this week, US Democratic presidential hopeful Hillary Clinton said China was "trying to hack into everything that doesn't move in America".

China has dismissed claims of involvement as "irresponsible and unscientific".

Monday, June 22, 2015

Supreme Court declares warrantless searches of hotel registries illegal


Data included credit card, home address, driver's license, and vehicle license.


by David Kravets - Jun 22, 2015 11:00am PDT  Ars Technica


Todd Lappin

The Supreme Court gave a big boost to privacy Monday when it ruled that hotels and motels could refuse law enforcement demands to search their registries without a subpoena or warrant. The justices were reviewing a challenge to a Los Angeles ordinance requiring hotels to provide information to law enforcement—including guests' credit card number, home address, driver's license details, and vehicle license number—at a moment's notice. Similar ordinances exist in about a hundred other cities stretching from Atlanta to Seattle.

Los Angeles claimed the ordinance (PDF) was needed to battle gambling, prostitution, and even terrorism, and that guests would be less likely to use hotels and motels for illegal purposes if they knew police could access their information at will.

Justice Sonia Sotomayor, writing for the 5-4 majority, ruled (PDF) that the Los Angeles ordinance violated the Fourth Amendment and is an illegal "pretext to harass hotel operators and their guests."

"Even if a hotel has been searched 10 times a day, every day, for three months, without any violation being found, the operator can only refuse to comply with an officer’s demand to turnover the registry at his or her own peril," Sotomayor wrote.

Enlarge

The hotel operators who brought the challenge faced six months in jail and a $1,000 fine for refusing to comply.

But the decision doesn't mean that hotel operators are forbidden from divulging the information upon demand if they choose to do so, the majority ruled.

"To be clear, we hold only that a hotel owner must be afforded an opportunity to have a neutral decision maker review an officer's demand to search the registry before he or she faces penalties for failing to comply. Actual review need only occur in those rare instances where a hotel operator objects to turning over the registry," Sotomayor wrote.

Justice Antonin Scalia, writing for the dissent, said that "The law is constitutional in most, if not all, of its applications." He scoffed at Sotomayor saying the authorities should get a subpoena or warrant to acquire such information, which Los Angeles requires hotels to keep for at least 90 days. He said Monday's majority decision would hinder sex trafficking and human smuggling investigations, too.

"This proposal is equal parts 1984 and Alice in Wonderland," he wrote.

Sotomayor was joined by Justices Anthony Kennedy, Ruth Bader Ginsburg, Stephen Breyer, and Elena Kagan.

The case is the third high-profile Fourth Amendment decision the court has issued in three years. In 2012, the justices ruled that authorities generally need search warrants when they affix GPS devices to vehicles. And last year, the justices ruled that the authorities need warrants to peek into the mobile phones of suspects they arrest.

In the case decided Monday, Los Angeles hoteliers argued that the law violated their rights, and the San Francisco-based 9th US Circuit Court of Appeals agreed in 2013. The city of Los Angeles appealed, arguing (PDF) that the ordinance helps both local and federal authorities in investigations of all types. The case's briefs can be viewed here.

Monday, June 15, 2015

ITIF: Beyond the USA Freedom Act: How U.S. Surveillance Still Subverts U.S. Competitiveness


Daniel Castro and Alan McQuinn
June 9, 2015  ITIF

A failure to sufficiently reform U.S. surveillance policies is hurting U.S. technology companies, costing American jobs, and weakening the U.S. trade balance.

View Report


Almost two years ago, ITIF described how revelations about pervasive digital surveillance by the U.S. intelligence community could severely harm the competitiveness of the United States if foreign customers turned away from U.S.-made technology and services. Since then, U.S. policymakers have failed to take sufficient action to address these surveillance concerns; in some cases, they have even fanned the flames of discontent by championing weak information security practices. In addition, other countries have used anger over U.S. government surveillance as a cover for implementing a new wave of protectionist policies specifically targeting information technology. The combined result is a set of policies both at home and abroad that sacrifices robust competitiveness of the U.S. tech sector for vague and unconvincing promises of improved national security.

ITIF estimated in 2013 that even a modest drop in the expected foreign market share for cloud computing stemming from concerns about U.S. surveillance could cost the United States between $21.5 billion and $35 billion by 2016. Since then, it has become clear that the U.S. tech industry as a whole, not just the cloud computing sector, has under-performed as a result of the Snowden revelations. Therefore, the economic impact of U.S. surveillance practices will likely far exceed ITIF’s initial $35 billion estimate. This report catalogues a wide range of specific examples of the economic harm that has been done to U.S. businesses. In short, foreign customers are shunning U.S. companies. The policy implication of this is clear: Now that Congress has reformed how the National Security Agency (NSA) collects bulk domestic phone records and allowed private firms—rather than the government—to collect and store approved data, it is time to address other controversial digital surveillance activities by the U.S. intelligence community.

The U.S. government’s failure to reform many of the NSA’s surveillance programs has damaged the competitiveness of the U.S. tech sector and cost it a portion of the global market share. This includes programs such as PRISM—the controversial program authorized by the FISA Amendments Act, which allows for warrantless access to private-user data on popular online services both in the United States and abroad—and Bullrun—the NSA’s program to undermine encryption standards both at home and abroad. Foreign companies have seized on these controversial policies to convince their customers that keeping data at home is safer than sending it abroad, and foreign governments have pointed to U.S. surveillance as justification for protectionist policies that require data to be kept within their national borders. In the most extreme cases, such as in China, foreign governments are using fear of digital surveillance to force companies to surrender valuable intellectual property, such as source code.

In the short term, U.S. companies lose out on contracts, and over the long term, other countries create protectionist policies that lock U.S. businesses out of foreign markets. This not only hurts U.S. technology companies, but costs American jobs and weakens the U.S. trade balance. To reverse this trend, ITIF recommends that policymakers:
  • Increase transparency about U.S. surveillance activities both at home and abroad.
  • Strengthen information security by opposing any government efforts to introduce backdoors in software or weaken encryption.
  • Strengthen U.S. mutual legal assistance treaties (MLATs).
  • Work to establish international legal standards for government access to data.
  • Complete trade agreements like the Trans Pacific Partnership that ban digital protectionism, and pressure nations that seek to erect protectionist barriers to abandon those efforts.

Monday, June 8, 2015

BBC: Millions of US government workers hit by data breach


5 June 2015 BBC

Chinese hackers are suspected of carrying out a "massive breach" of the personal data of nearly four million US government workers, officials said.
The Office of Personnel Management (OPM) confirmed that both current and past employees had been affected.

The breach could potentially affect every federal agency, officials said.

US officials said the hackers were believed to be based in China. Beijing responded by calling such claims "irresponsible".

OPM said it became aware of the breach in April during an "aggressive effort" to update its cyber security systems.

It said it would be contacting all those individuals whose personal data may have been breached in the coming weeks, and offering them 18 months of free credit monitoring and identity theft insurance.

OPM serves as the human resource department for the federal government. The agency issues security clearances and compiles records of all federal government employees.

Information stored on OPM databases includes employee job assignments, performance reviews and training, according to officials.

The breach did not involve background checks and clearance investigations, officials said.

Thursday, May 14, 2015

US House passes Bill to end domestic NSA bulk data collection


Summary:American residents could soon be exempt from the NSA's dragnet, unless surveillance is approved by the secretive FISA court, with the USA Freedom Act passing the US House of Representatives and heading to the Senate.



By Chris Duckett | May 14, 2015 -- 07:04 GMT (00:04 PDT)
ZDNet

The US House of Representatives has voted 338 for and 88 against ending the NSA's dragnet collection of telephone, email, and other online data from millions of Americans, a controversial program that was revealed in 2013 by former security contractor Edward Snowden.

The USA Freedom Act is seen as a big win for privacy and civil rights advocates. The White House backs the reforms, saying the Bill protects privacy while preserving essential national security authorities.

After passing the House, the measure is now heading for a vote in the Senate, where the clash between reformists and supporters of the intelligence community, coming within the context of warnings on the increasing digital reach of the Islamic State terror group, transcends party lines.

Both liberals and staunch conservatives, often at odds on most major legislation, have united in opposition against domestic spying by the National Security Agency.

The Bill, which focuses on people in the US and not overseas, would amend controversial sections of the USA Patriot Act, which was passed in the wake of the September 11, 2001, attacks and will expire on June 1.

The reforms scrap the bulk collection detailed in Section 215 of the Patriot Act, replacing it with a targeted program that allows intelligence agencies to collect data from specific individuals or groups, but only with prior approval of the secret national security FISA court.


Under Section 215, the government stored the acquired data, but the new reforms would compel telcos and other data companies to keep the information to be accessible to intelligence agencies only through court order.The data dragnet was operating in complete secrecy after 2001, and has been under the supervision of the FISA court since 2006. It was consistently renewed by the administrations of George W Bush and Barack Obama.

"Today's vote was a major win for surveillance reform and a major rebuke for those who want to reauthorise the Patriot Act without change," said Center for Democracy & Technology president Nuala O'Connor.

Passage through the House was welcomed by Mozilla, whose head of public policy Chris Riley called for the Senate to swiftly pass the legislation.

"This legislation significantly curtails bulk collection under the Patriot Act and other authorities, and puts us on a path to a more private and secure internet," Riley said.

"We are staunchly opposed to any short- or long-term reauthorisation of these sections of the Patriot Act absent meaningful reforms. Now is not the time to delay on these much-needed reforms."

The Electronic Frontier Foundation (EFF) said US business is being hurt by the NSA's actions, and it hopes the Senate will add amendments to strengthen the Bill.

"The legislation is a good start to shutting backdoors," the EFF said. "The time to fix the backdoor problem is now."

The vote came just a week after a US appeals court ruled that the bulk data collection goes far beyond what congress authorised.

"The text of [section 215] cannot bear the weight the government asks us to assign to it, and that it does not authorize the telephone metadata program," wrote judge Gerard E Lynch last week.

Earlier this month, the French lower house approved legislation allowing authorities to spy on suspected terrorists without prior authorisation from a judge.

The new law, to go before the French Senate later this month, allows authorities to spy on the digital and mobile communications of anyone linked to a "terrorist" inquiry without judicial authorisation, and forces internet service providers and phone companies to give up data upon request.

Intelligence services will have the right to place cameras and recording devices in private dwellings and install keylogging devices.

As the US restricts some of its data surveillance schemes, Australia is in the midst of setting up its own data-retention scheme.

In this week's Australian Budget, AU$131 million was allocated by the government for the creation and maintenance of systems to store all Australians' telecommunications data for two years for warrantless access by law enforcement.

However, the money from the government is expected to cover only between one third and half of the cost to implement the scheme.

The Internet Society of Australia CEO Laurie Patton said the government should guarantee to top up the funding if it is inadequate for all ISPs.

"The government's original cost estimate was not based on widespread industry consultation, and the Internet Society is concerned that the costs have been significantly underestimated, especially in respect of small to medium-sized ISPs that don't have the resources to undertake the work in-house, and therefore will be required to pay for external assistance," he said in a statement.

Tuesday, May 12, 2015

BBC: Staff-tracking app faces legal scrutiny in US

BBC

The woman is alleging that an app which tracks movements 24/7 invaded her privacy
A US sales executive is suing her employer for invasion of privacy, alleging that she was fired after deleting an app which tracked her movements.
The action alleges that Intermex, a firm which arranges money transfers, tracked employees even when off-duty.

Myrna Arias alleges that she was "scolded" for removing the app and fired a few weeks later.

The company has not responded to the allegations.

According to court documents published by website Ars Technica, employees were instructed to download the app, called Xora, to their phones in April 2014.

Xora is described on its website as a workplace management app which allows companies to "remotely manage" their workers by keeping track of their hours and other aspects of their job.

Xora's website says that the app uses GPS to allow bosses "to see the location of every mobile worker on a Google Map".

According to the lawsuit, Ms Arias's manager "admitted that employees would be monitored while off-duty and bragged that he knew how fast she was driving at specific moments ever since she had installed the app on her phone".

"He confirmed that she was required to keep her phone's power on 24/7 to answer phone calls from clients," reads the court document.

It goes on to detail that Ms Arias had "no objection" to being monitored at work but felt that monitoring her location during non-work hours was an invasion of her privacy.

She likened the app to a prisoner's ankle bracelet.
Tracking employees
Her boss "scolded the plaintiff when she de-installed the app in late April in order to protect her privacy", reads the court document.

She was fired on 5 May.

Ms Arias is seeking damages for lost earnings in excess of $500,000.

Mark Weston, a partner at law firm Matthew Arnold & Baldwin, tod the BBC that an employer "would not be allowed to track an employee without the consent of that employee".

Clauses that allow for tracking apps would have to be built into contracts, he said.

As for the legality of firing an employee for refusing to use such an app, Mr Weston said: "In the US, things may be looser because many employees there are employees 'at will'. Accordingly, employers have far greater flexibility than in Europe to dismiss an employee who is not playing ball."

Wednesday, April 22, 2015

See Your Company Through the Eyes of a Hacker

MARCH 24, 2015
Harvard Business review
JP Morgan Chase. Target. Sony. Each has been part of the growing number of cyber-attacks against private companies around the world in recent years. In the latter two cases, CEOs were forced to resign in the wake of the breach. Attacks are growing more sophisticated and more damaging, targeting what companies value the most: their customer data, their intellectual property, and their reputations.
What these attacks – together with breaches to defense, law-enforcement, and military-contractor networks – reveal is that our cyber-security efforts over the last two decades have largely failed, and fixing this will require the attention not only of security officers and IT teams, but also of boards and CEOs.
Companies need to take a new approach. They can do so by looking at themselves through the eyes of their attackers. In the military this is called turning the map around. The point is to get inside the mind of the enemy, and to see the situation as they do, in order to anticipate and prepare for what’s to come.
Unfortunately, this mindset is still too rare. Despite spending billions of dollars every year on the latest security products and hiring the best security engineers and analysts, companies are more vulnerable than they’ve ever been. Two trends account for this: the rapid convergence of enterprise IT architectures, and the proliferation of increasingly sophisticated adversaries.
Changes in enterprise IT over the past decade mean that every company is now a technology company. By the end of the decade, there will be 50 billion devices connected to the Internet, complicating networks and generating petabytes of data. To add to that, the cloud revolution has finally dissolved perimeters – companies enjoying the benefits of infrastructure as a service must depend upon the security of networks and systems beyond their direct control.
As mobility, the Internet of Things, and the cloud change enterprises, adversaries are also becoming more sophisticated. States and state-sponsored entities spy on and attack private companies, often using military-grade tactics and capabilities. They do this within a system where offense enjoys a structural advantage over defense because attribution is difficult, deterrence is uncertain, and attackers need to succeed only once, but defenders must succeed always.
Most companies try to deal with this chaos by parsing signal from noise. They build walled castles around their most precious assets, but perimeters don’t matter when even the average college student owns seven IP-enabled devices. They rely on automated alerts to tell them when something malicious on their networks matches some previous bad event, but this approach overwhelms them with red flags while remaining blind to new and previously unknown threats.
There’s just too much noise to contend with. Security analysts, for example, may see a thousand incidents in a given day, but only have the time and resources to investigate a fraction of them. This is why hackers were able to exfiltrate over 40 million credit-card numbers from Target, despite the fact that a peripheral network device had detected the malware. It’s also the reason why Neiman Marcus was hacked after its system generated over 60-days’ worth of malware alerts. And this is why Sony was hacked after its IT team knew the company had been under attack for two years.
By turning the map around, executive teams can learn a great deal about their own companies, and better prepare for the inevitable attacks. This is how most companies look from an attacker’s perspective:
  • Their security is overwhelmingly focused on generic malware detection and protection against automated threats that aren’t being guided with precision.
  • They don’t have a full picture of what is on their networks, the cloud services they’re using, the applications running on those services, and the security postures of their supply chains and partners. Their IT and security teams are peripheral concerns, costs to be managed rather than centers of excellence that support the core business.
  • Overall, they are reactive, rather than proactive, in their approach to security.
Each bullet-point above is a weakness that attackers can exploit. This is why companies should learn from attackers in deciding how to defend themselves. Here’s how.
1. Understand your major risks and how adversaries aim to exploit them. If security could be calculated, then adversaries would be the numerator. Companies must understand their unique threatscapes to the greatest possible extent, and generic data are insufficient. Effective security must integrate indicators of compromise (have we been attacked?), tactics, techniques and procedures (how are we being targeted?), identity intelligence (who would target us, and why?), vulnerability intelligence (what is being exploited in the wild?), and attack attribution (is this commodity or targeted?). Only with focused threat intelligence can analysts spend their precious and valuable time investigating the most important incidents, prioritizing those associated with your most formidable adversaries and your greatest business risks. You can go crazy (and broke) trying to play Whack-A-Mole in defense against them all. Instead, identify your most essential assets and focus scarce resources only on those threats that actually pose a risk to your company.

2. Take inventory of your assets and monitor them continuously. If security could be calculated, then inventory would be the denominator. At the simplest level, companies must identify and monitor all of their interconnected assets: is a developer spinning up a thousand virtual machines without your knowledge? What applications are running on the database servers holding your most valuable information? Did an employee connect a new device to your corporate network? Does one of your distant subsidiaries have a new partner? Does your HVAC system connect somehow with your Point of Sale? Periodic assessments, reports that take weeks to prepare, and conclusions that require complex interpretation contribute to gaps in security. Companies must maintain a dynamic, real-time inventory of assets, monitor those assets continuously, and render them visually in way that is simple and intuitive for security and operations teams.
3. Make security a part of your mission. The prevailing approach to security is compliance-focused, cost-constrained, peripheral to the core business, and delegatable by C-suite leaders. Working on a team like that isn’t fun inside any enterprise, and it loses against 21st-century adversaries who know that it’s more fun to be a pirate than to join the Navy. Any defense is only as good as the people doing the defending. The new model of security needs to be about mission and leadership, ensuring that we have the best defenders up against the best attackers. Security is no longer delegable, and the mission of security teams must be synonymous with the mission of the company.
4. Be active, not passive, in hunting adversaries on your network and removing them. The term “active defense” has been tarred as a euphemism for “hacking back,” and companies are ill-advised to go on the offensive: first, it’s illegal to access others’ networks without permission, even if you’re acting in supposed self-defense; and second, it’s just not smart to escalate unless you can dominate, and even the biggest companies will ultimately lose against state or state-sponsored adversaries. So while you cannot go attack the other team on their own turf, you can and increasingly must be active against adversaries inside your own networks. This means assuming not merely that you are under attack, but that your attacker is in, and so you must hunt for a stealthy, persistent human adversary in order to contain and remediate the risk before they can cause damage – dramatically cutting the time between breach and detection from its current average of more than 200 days.
It is easy during these days of frequent and devastating attacks to cry out that the sky is falling, and that the very future of the Internet as a trusted domain of commerce and communication is at stake. But it would be wrong to extrapolate the data points of recent years into a line leading to ruin. Too many of us have too much at stake here, and the combined forces of executives, entrepreneurs, software developers, security teams, and investors all turning the map around can equip us to defend against this next generation of adversaries.

Now you can download your entire search history from Google

ZDNet

Summary:Earlier this year, Google quietly rolled out a new feature that lets users download their search history.


By Liam Tung | April 21, 2015 -- 09:02 GMT (02:02 PDT)

With just a few clicks, anyone can now download their entire Google search history - that's every query ever made while the user was signed in.

To download the archive, Google Search users need to sign in and go to their Google Account History page, then click on the gear icon and select Download.

As the file is potentially sensitive, Google urges users to read its warnings, which are "not the usual yada yada". Google advises that the archive shouldn't be downloaded on a public computer and, if it is to be exported to another cloud storage service, that the user reads their export policy in the event they want to take their files elsewhere in future.

Google will send an email to notify a user when the download is complete, with a link to the data, which will be transferred to a Takeout folder in Google Drive. The user will find a .ZIP archive folder containing a series of .JSON files containing searches over quarterly periods.

Takeout is the feature that lets Google users download archives of multiple products, such as Gmail, YouTube, Google Photos, +1s, Hangouts, Calendars, and more. The featurelaunched in 2011 under its Data Liberation Front initiative, but it historically didn't include Search and still doesn't include Google Wallet.

The new capability was first spotted by the Google System blog, which noted that Google started testing the archive download feature for Search last year.

Google's product forums show that people have been using the feature, with mixed success, to download their history since at least February. Google toldVenture Beat that it released the feature in January.

Other companies that allow users to download and store an archive of their activities include Facebook and Twitter.

Two things worth noting are that downloading search history only gives the user a copy of their archive held by Google and doesn't delete the history from the users Web & App Activity page. Google provides instructions how to do that here.



About Liam Tung

Liam Tung is an Australian business technology journalist living a few too many Swedish miles north of Stockholm for his liking. He gained a bachelors degree in economics and arts (cultural studies) at Sydney's Macquarie University, but hacked (without Norse or malicious code for that matter) his way into a career as an enterprise tech, s... Full Bio

Tuesday, April 21, 2015

3CS - Only 80 Seats Remaining

CHECK THIS OUT...

Tours, workshops and more are filling up fast!


3CS is the only national conference for cybersecurity educators in community colleges.

AMAZING Tours being OFFERED:

  • Behind the Scenes Tour of the Bellagio 
  • Switch Corporation’s SUPERNAP Site Tour 
  • National Atomic Testing Museum Tour 
CLICK HERE

To CHECK OUT workshops and sessions!

Space is limited. Don’t delay. Register today.

(only 80 seats remaining)

REGISTER HERE

Monday, April 13, 2015

Mass surveillance case against UK government heads to Europe's highest court


Summary:Three human rights and privacy groups suing the British government against mass surveillance will have their case heard by the European Court of Human Rights.


By Zack Whittaker | April 10, 2015 -- 15:36 GMT (08:36 PDT)
ZDNet

RAF Menwith Hill in Yorkshire, UK, home to a surveillance base (Image: Wikimedia Commons)

A lawsuit aimed at challenging the UK government's mass surveillance programs has been filed with the highest human rights court in Europe.

The case, filed by Amnesty International, Liberty, and Privacy International on Wednesday, is now in the hands of the European Court of Human Rights after the groups said they "exhausted" all legal avenues in the UK.



As the Snowden leaks began, there was "fear and panic" in Congress

Just a few minutes after the first NSA leak was published, the phones of US lawmakers began to buzz, hours before most of America would find out over their morning coffee.
Read More

The suit aims to determine that the UK and US mass surveillance operations were in breach of Europe's human rights laws.

The joint application was submitted just weeks after the UK's Investigatory Powers Tribunal ruled that the UK intelligence agencies it oversees were not at the time breaching the laws. That decision was made because the UK government had by that point declassified how it was tapping the communications of millions of people, but noted that there was a prior lack of transparency.

However, the tribunal also found that the intelligence-sharing relationship between the UK and the US was unlawful prior to December 2014, because rules governing the UK's access to US mass electronic surveillance programs -- including the clandestine PRISM system -- were secret.

"It is ridiculous that the government has been allowed to rely on the existence of secret policies and procedures discussed with the Tribunal behind closed doors -- to demonstrate that it is being legally transparent," said Nick Williams, legal counsel for Amnesty International, in a statement Friday.

Although the case could go either way, the groups note that the Strasbourg court has a long history of pushing back on European member states' intelligence agencies, particularly when non-European countries are involved.



About Zack Whittaker

Zack Whittaker is a writer-editor for ZDNet, and sister sites CNET and CBS News. He is based in the New York newsroom. His PGP key is: EB6CEEA5.

Monday, March 30, 2015

5 Domestic Smart Devices That Are Spying On You Right Now

A couple of weeks ago we experienced a media-wide furore over Samsung’s smart TVs potentially recording all your privately spoken words, with the company’s privacy policy advising owners not to disclose “personal or other sensitive information [because] that information will be among the data captured and transmitted to a third party through your use of Voice Recognition”.
Although Samsung quickly moved to quell fears by telling users that they could deactivate voice recognition or disconnect their TVs from their Wi-Fi network, the very fact that a such clause was inserted into the privacy policy in the first place should be disconcerting, if not downright frightening.

Smart TVs are far from being the only offenders, however. With Facebook recording our every click, Google tracking us around the web, and smartphones saving our locations on a worryingly frequent basis, we are increasingly living in an Orwellian dystopia. The advent of the smart home and the Internet of Things (IoT) is only exacerbating the problem, and there are now so many devices spying on us that they’re becoming ubiquitous.
Here we look at some of those devices, along with what exactly they’re recording, and who’s benefitting:

Sense

What is it?

Manufactured by Hello, the Sense device claims to be “the first system for understanding your sleep and bedroom”. It comes in two parts – a bedside device which monitors external factors such as noise, light, temperature, humidity and particles in the air, and a “Sleep Pill” which attaches to your pillow and monitors your movements and the quality of your sleep by using an accelerometer and gyroscope. It was one of the most-backed Kickstarter projects of last year.

Why should you be concerned?

The bedside device contains an “always-on” microphone, with all audio sent back to Sense’s cloud for easy playback by its owners. While eight hours of snoring might not be very interesting, there are an untold number of reasons why this is a privacy nightmare, with anything from personal details to the sound of two consenting adults being put into a space that the owner has no control over.
Most worrying? A glance at Hello’s privacy policy shows that the company takes no responsibility when it comes to deleting your information, saying:
“You agree that Hello has no responsibility or liability for the deletion of or failure to store any data or other content maintained or uploaded by the service.”
It means that if you accidentally discuss your finances, reveal your personal data, or discuss other sensitive topics, that audio could be stored in the cloud for a long, long time.

LG Smart Thinq Fridge

What is it?

It’s that thing in the corner of your kitchen that you keep food (or beer) in…!
On a serious note, the fridge aims to take over everything to do with cooking and preparing meals. It’ll tell you what’s inside it, help to create shopping lists, inform you when expiration dates are approaching, suggests recipes, sync with your smartphone, and even tell you the weather.

Why should you be concerned?

In order to function effectively, smart fridges need to connect to your Wi-Fi network, and that means that they can be commandeered by hackers and criminals. In fact, Dawn Meyerriecks, the Deputy Director of the CIA’s Directorate of Science and Technology recently told the Aspen Security Centre Forum in Colorado that “Smart refrigerators have been used in distributed denial of service attacks”, and claimed that “At least one smart fridge played a role in a massive spam attack last year, involving more than 100,000 Internet-connected devices and more than 750,000 spam emails”.
This raises wider concerns about security within the Internet of Things. The nature of the sector means access points are going to grow exponentially over the coming years, and while a typical home user might currently have less than ten access points that need to be secured, the IoT could expand that number into the hundreds. Without adequate security, everything from your fridge to your in-car entertainment system could become a potentially exploitable route into your personal data and information.

MyLink

What is it?

MyLink is a product by American car manufacturer Chevrolet that aims to turn a normal vehicle into a smart vehicle. It provides drivers with hands-free control of the hi-fi, an ability to access phone contacts, and access to SiriusXM. That’s all great. What’s less great from a privacy perspective is its built-in data grabber, enticingly called “Valet Mode with Performance Data Recorder.”
My-Link

Why should you be concerned?

“Valet Mode” allows you to monitor you own car remotely, while the “Performance Data Recorder” and tracks data such as GPS location, speed, RPM, gears, and distance driven. The concerning part is that its privacy policy entitles Chevrolet to profile driving activity and sell it in an “anonymous and aggregated form” to third parties – meaning other companies will have access to how and where you drive. Could this information eventually find its way into the hands of the police? Possibly. For example, is it that hard to imagine cloud-based speeding tickets in the not-to-distant future?

iSmart Alarm

What is it?

The iSmart Alarm is a cloud-based, real-time, “intelligent”, home security system. It was founded out of Silicon Valley back in 2012 and has gone on to win multiple awards from publications such as CNet and PC Mag. It offers on-demand video streaming from around your home, control of all your electrical outlets, instant notifications of intruders, control over your lighting, and remote control management of the system.

Why should you be concerned?

The idea of streaming video of your empty house to the Internet should instantly ring alarm bells. Where is the data stored? Who has access to it? Could criminals determine your movements to establish a pattern of whether or not you’re at home? Would the alarm manufacturer also be notified if you got a notification about an intrusion?
Concerns of this nature extend to all “smart systems” in the home. For example, would the manufacturer of a Wi-Fi based entertainment system be able to get information about your choice of audio? Would energy companies ultimately get access to data provided by your smart thermostat, allowing them to hike their rates if they know you’re using the air conditioning?

Xbox Kinect

What is it?

Xbox Kinect is an add-on for Microsoft’s Xbox gaming console. It uses a camera to monitor and record a player’s movements, enabling them to both interact with Windows, games and issue spoken commands. It was originally Microsoft’s response to the popularity of the Nintendo Wii, but has since become an integral part of Microsoft’s entertainment product suite.

Why should you be concerned?

Originally, it was Microsoft’s intention to make it an “always-on” device, but users were not happy. It’s no surprise, and it’s all because of the power of the device’s camera. As the company itself boasts:
“Microsoft’s Xbox One system has a high-definition camera that can monitor players at thirty frames per second. Using a technology called Time of Flight, it can track the movement of individual photons, picking up minute alterations in a viewer’s skin colour to measure blood flow, then calculate changes in heart rate. The software can monitor six people simultaneously, in visible or infra-red light, charting their gaze and their basic emotional states”.
Are you comfortable with Microsoft knowing your emotional state at any given moment? Probably not…

Who is Benefiting?

As with almost everything privacy related, two main groups of people stand to benefit: advertisers and criminals.
While it is true that all the gadgets naturally aim to bring benefits to the user – be those entertainment benefits, practical benefits, or health benefits – all the gadgets we listed also offer clear benefits to manufacturers and advertisers. The manufacturer can collect user data and sell it to third parties, who can then use it to build up a consumer profile of your likes and dislikes – serving you differing adverts depending on your preferences, your mood, or what time of day it is. Ultimately, it means both parties are making a lot of money off your usage of their products.
A further consequence of all this connectivity is that criminals can also benefit. Home networks and company infrastructure can be hacked and exploited, identities can be stolen, and malware and computer viruses can be spread. Why do they do this? The same reason as the companies themselves. Money. Your data is hugely valuable in both the corporate world and criminal underworld. Legal and illegal groups are both willing to go to extreme lengths to get their hands on it.

What do you think?

Is it worth knowing how much milk you’ve got left or how frequently you woke up during the night in order to expose yourself to these risks?
Are some of these smart gadgets really designed with the user in mind, or are they strategies developed by corporate entities to exploit us in every way possible? Do we actually need a car that tells us the average RPM during our last journey?
We’d love to hear your thoughts, you can leave your feedback in the comments below.
Image Credits: Woman tasting smell her meal Via Shutterstock

Wednesday, March 11, 2015

BBC: Wikimedia Foundation sues NSA over surveillance

10 March 2015 Last updated at 07:53 ET BBC

The extent of NSA surveillance has been revealed by whistle-blower Edward Snowden
The NSA's mass surveillance programme violates US laws on freedom of speech, alleges a lawsuit begun by the Wikimedia Foundation.
The legal action has been filed against the spy agency and the US Department of Justice.

The legal action, co-signed by eight other organisations, seeks to end the NSA's large-scale surveillance efforts.

The Foundation is the non-profit group that oversees the running of the Wikipedia online encyclopedia.

The Wikmedia Foundation said it was taking action against the NSA's so-called "upstream" surveillance work which targets communication with people not in the US.

Such spying violates US laws on free speech and those that govern against unreasonable search and seizure, it said.

The scale of the monitoring carried out by the NSA has been revealed in documents made public by whistleblower Edward Snowden over the last two years. Some of those papers show the NSA tapped the net's backbone network to siphon off data. The backbone is made up of high-speed cables that link big ISPs and key transit points on the net.

"By tapping the backbone of the internet, the NSA is straining the backbone of democracy," said Lila Tretikov, executive director of the Wikimedia Foundation, in a blogpost announcing the legal action.

Targeting the backbone means the NSA casts a "vast net" and inevitably scoops up data unrelated to any target and will also include domestic communications, violating the rules governing what the NSA can spy on, said Ms Tretikov.

Information in the Snowden papers revealed that Wikipedia has been explicitly targeted, said the blogpost.

"By violating our users' privacy, the NSA is threatening the intellectual freedom that is central to people's ability to create and understand knowledge," said Ms Tretikov.

In an accompanying editorial published in the New York Times, Wikipedia founder Jimmy Wales said he hoped the lawsuit would bring an "end to the NSA's dragnet surveillance of Internet traffic".

Other organisations joining the lawsuit include Human Rights Watch, Amnesty International USA, the National Association of Criminal Defence Lawyers and the Global Fund for Women.

The NSA and DoJ have yet to comment on the legal action.

New smoking gun further ties NSA to omnipotent “Equation Group” hackers

What are the chances unrelated state-sponsored projects were both named "BACKSNARF"?
by Dan Goodin - Mar 11, 2015 6:01am PDT  Ars Technica


Niels Noordhoek

Researchers from Moscow-based Kaspersky Lab have uncovered more evidence tying the US National Security Agency to a nearly omnipotent group of hackers who operated undetected for at least 14 years.

FURTHER READING
HOW “OMNIPOTENT” HACKERS TIED TO NSA HID FOR 14 YEARS—AND WERE FOUND AT LAST

"Equation Group" ran the most advanced hacking operation ever uncovered.The Kaspersky researchers once again stopped short of saying the hacking collective they dubbed Equation Group was the handiwork of the NSA, saying only that the operation had to have been sponsored by a nation-state with nearly unlimited resources to dedicate to the project. Still, they heaped new findings on top of a mountain of existing evidence that already strongly implicated the spy agency. The strongest new tie to the NSA was the string "BACKSNARF_AB25" discovered only a few days ago embedded in a newly found sample of the Equation Group espionage platform dubbed "EquationDrug." "BACKSNARF," according to page 19 of this undated NSA presentation, was the name of a project tied to the NSA's Tailored Access Operations.



"BACKSNARF" joins a host of other programming "artifacts" that tied Equation Group malware to the NSA. They include "Grok," "STRAITACID," and "STRAITSHOOTER." Just as jewel thieves take pains to prevent their fingerprints from being found at their crime scenes, malware developers endeavor to scrub usernames, computer IDs, and other text clues from the code they produce. While the presence of the "BACKSNARF" artifact isn't conclusive proof it was part of the NSA project by that name, the chances that there were two unrelated projects with nation-state funding seems infinitesimally small.


Kaspersky Lab
The code word is included in a report Kaspersky published Wednesday detailing new technical details uncovered about Equation Group. Among other new data included in the report, the timestamps stored inside the Equation Group malware showed that members overwhelmingly worked Monday through Friday and almost never on Saturdays or Sundays. The hours in the timestamps appeared to show members working regular work days, an indication they were part of an organized software development team. Assuming they worked a regular 8 to 5 workday, the timestamps show the employees were likely in the UTC-3 or UTC-4 time zone, a finding that would be consistent with people working in the Eastern part of the US. The Kaspersky report discounted the possibility the timestamps were intentionally manipulated, since the years listed in various executable files appeared to match the availability of computer platforms the files ran on.

Previously found evidence suggesting a possible connection to the NSA included the Equation Group's aptitude for conducting interdictions that in 2009 placed highly advanced malware on a CD-ROM sent to a prestigious researcher who attended a scientific conference. That interdiction was similar to an NSA-sponsored one detailed in documents leaked by former NSA subcontractor Edward Snowden thatinstalled covert implant firmware on a Cisco Systems router as it was being shipped to its unwitting customer. Still other ties included zero-day vulnerabilities shared between Equation Group malware and the NSA-led Stuxnet worm that sabotaged Iranian uranium enrichment efforts in 2009 or so. The countries that were and were not targeted are also consistent with Equation Group being a US-sponsored project.

Most of the new details included in Tuesday's report will be of interest only to hard-core researchers. Still, they only bolster previous findings that Equation Group was hands down the world's most advanced hacking operation ever to come to light. Whereas before the sprawling Equation Drug platform was known to support 35 different modules, Kaspersky has recently unearthed evidence there are 115 separate plugins. The architecture resembles a mini operating system with kernel- and user-mode components alike. Readers can expect more revelations to come as researchers continue to analyze new samples and further examine the malware that has already come to light.

Facebook Infosec Virtual Meet and Greet, March 20th

Image result for facebook
Hey there,

Julian Nagler from Facebook's Information Security team here. Over the past year we've made a dedicated effort to support existing organizations making an impact in educating students on the skill sets needed to succeed in information security careers. 

We see first hand how the shortage of qualified talent in the infosec field is negatively impacting the industry, and the safety of the internet at large. We're committed to doing whatever is within our power to change this reality. 

In addition to the other work we do, we've found great value in speaking face to face with students across the country as we've supported and participated in various events. We'd like to broaden the scope of this engagement to reach as many students as possible. 

As a result, we're pleased to announce our first virtual meet and greet scheduled for next Friday, March 20th, 2015. We'd be honored to have your infosec club, or any other interested students join and participate. 

This will be a fantastic opportunity for students to ask any questions they may have about careers in information security, the ins and outs of various jobs within the field, or any other pressing questions they may have. 

This is by no means meant to be a recruiting event, rather we're focused on doing what we can to present the attractiveness of a career in information security.

Please have students RSVP to the event here, and submit any questions they’d like addressed to meetsecurity@fb.com

The event will be hosted via livestream here

Thank you so much for your assistance in distributing. 

-- 
Julian Nagler|facebook

1 Hacker Way| Menlo Park, 94025