Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Thursday, May 18, 2017

Second bigger global cyber attack already underway


 WannaCry XXL? 2nd even bigger global cyber attack already underway

18 May, 2017
As the world reels from the WannaCry ransomware attack, it’s now emerged that a second, potentially larger attack, is already under way. It seems the widespread proliferation of military-grade cyberweapons has ushered in a new era of digital crime.

Cyber bandits have again deployed both the EternalBlue and DoublePulsar exploits developed and used by the NSA which were released by the ShadowBrokers hackers back in April.

“Initial statistics suggest that this attack may be larger in scale than WannaCry, affecting hundreds of thousands of PCs and servers worldwide: because this attack shuts down SMB networking to prevent further infections with other malware (including the WannaCry worm) via that same vulnerability, it may have in fact limited the spread of last week's WannaCry infection,” wrote a security researcher 
who goes by the alias Kafeine at cybersecurity company Proofpoint.

This latest attack uses the two exploits to install the cryptocurrency miner Adylkuzz over corporate Local Area and wireless networks but, rather curiously, may actually have helped slow the spread of WannaCry.

However, in an apparent case of “picking your poison,” the Adylkuzz miner dramatically slows PC and server performance as it extracts cryptocurrency but it does not lock users out of their machines and data, as WannaCry did.      More

Monday, March 21, 2016

FBI says it might be able to unlock San Bernardino terrorist's iPhone without Apple's help

he U.S. government said Monday that it might have a way to unlock  the phone of one of the assailants in December's terror attack in San Bernardino without the help of Apple.
In making the announcement, the government asked for and received a delay in a Tuesday court hearing that was billed as a showdown in the FBI's effort to force Apple to help unlock the phone.
In a filing Monday afternoon, the FBI said it now needs time to investigate another possible way to unlock Syed Rizwan Farook's phone.
"On Sunday, March 20, 2016, an outside party demonstrated to the FBI a possible method for unlocking Farook’s iPhone," the U.S. attorney wrote in court papers. "Testing is required to determine whether it is a viable method that will not compromise data on Farook’s iPhone. If the method is viable, it should eliminate the need for the assistance from Apple Inc. set forth in the All Writs Act Order in this case."
Prosecutors asked that the hearing in Riverside federal court be put on hold "to provide time for testing the method."
The case has become a battleground in a broader dispute between elected officials, law enforcement and technology executives over how far companies must go in aiding criminal investigations.
A Justice Department spokeswoman said in a statement that federal authorities had continued to seek an alternative way to access the phone's contents even during the heated litigation and public back-and-forth with Apple. If the new method works, it would help investigators to continue looking into the Dec. 2 terrorist attack that killed 14 people and wounded 22, said Melanie R. Newman, director of the Justice Department's office of public affairs.
"We must first test this method to ensure it doesn't destroy the data on the phone, but we remain cautiously optimistic," she said.
Although FBI agents have stitched together much about Farook and his wife, Tashfeen Malik, who joined him in the attack, they say the confiscated phone might contain information that would help answer other questions, such as whether the killers had accomplices. Farook and Malik were killed in a shootout with police hours after the attack.
Prosecutors turned to the courts for help after Apple refused FBI requests that its engineers find a way to work around security measures built into the iPhone. Specifically, they wanted the company to write new software that, when uploaded to Farook’s phone, would bypass a security feature that renders the phone useless when more than 10 attempts are made to enter the phone’s four-digit pass code. 
With this done, agents planned to use a computer program to churn through the 10,000 possible pass codes until hitting upon the right one.
Jonathan Zdziarski, a leading expert on iPhone security, put the highest odds on federal authorities now giving a shot to copying a portion of the phone's memory that controls the password-guess counter. By constantly restoring the original copy of that data after every nine guesses, the agency potentially could avoid triggering the feature that makes the phone's contents inaccessible after 10 failed tries.
At the crux of the legal fight has been the All Writs Act, a sweeping, centuries-old law intended to provide judges the authority to issue orders when other avenues are unavailable.
Prosecutors have insisted the act provides a solid legal foundation for the judge to compel Apple to write new software to allow FBI agents to circumvent security features built into the iPhone Farook had used.
In its latest filing, Apple repeated its assertion that applying the act in this case would be wrong because it does not permit judges to make rulings that go beyond the limits of existing law.
Congress, Apple wrote, has considered passing legislation that would force companies to develop software at the government's behest, but rejected the idea.            LATimes

Wednesday, March 9, 2016

Obama Says Google, Facebook, Microsoft, And Visa Will Provide Extra Layer Of Security To Americans

President Barak Obama recently said “With the help of companies like Google GOOGL +0.15%, Facebook FB +0.20%, Microsoft MSFT +1.23%, and Visa V -1.83%, we’re going to empower Americans to be able to help themselves and make sure that they are safe online with an extra layer of security, like a fingerprint or a code sent to your cellphone.”
Sounds intriguing, but Obama failed to explain exactly what these companies are going to provide – and when. Not to mention that he snubbed Apple – which has sold a cumulative lifetime total of 821.8 million iPhones, according to The Motley Fool.
The President remarked on his new cybersecurity initiatives in the Roosevelt Room at the White House last month. ”More and more, keeping America safe is not just a matter of more tanks, more aircraft carriers; not just a matter of bolstering our security on the ground” said Obama. “It also requires us to bolster our security online. As we’ve seen in the past few years and just in the past few days, cyber threats pose a danger not only to our national security but also our financial security and the privacy of millions of Americans.”
Three major points from Obama were:
  1. His budget proposal for the next fiscal year devotes $19 billion to cybersecurity – which is up by more than one-third.
  2. Plans to update antiquated federal IT systems – some of which date back to the 1960′s – which the President says are particularly vulnerable to cyber attacks.
  3. Hiring a first-ever federal chief information security officer (CISO) position who will oversee security and upgrades across all agencies — and interact with the private sector.
  4. Recommended by Forbes
The counter points are:
  1. The U.S. government has spent $100 billion on information and cybersecurity over the past decade, and what do we have to show for it? A $14 billion budget was approved last year – when the OPM hack occurred.
  2. Some legacy mainframe systems are actually more secure than modern cloud based IT infrastructures. Nonetheless – these types of systems take years to upgrade and they must be protected in the interim.
  3. Obama is offering a woefully inadequate salary for the new Federal CISO job which is based in Washington, D.C., D.C. and offers a paltry annual salary range of $123,000+ to $185,000. The current average annual salary for a CISO in D.C. is $225,000, and tops out at $334,000, according to SilverBull, a full-service IT and cybersecurity recruiting and staffing company based in Manchester, Conn.
While Obama is still in office, perhaps he can take the first and best step forward by hiring a deeply experienced federal security chief from the commercial sector. To attract suitable candidates, he’ll have to up the pay to the top end of what more experienced CISOs earn — which means doubling the annual salary.
A new federal CISO should bring clarity to how and when Google, Facebook, Microsoft, and Visa will help protect Americans when they are online. These tech firms employ very large and experienced cybersecurity teams who are on the cutting edge of Internet privacy. If fingerprint sensors and sending codes to our cellphones are part of the online privacy plans that Obama has in mind, then he really needs to invite Apple in — otherwise the new CISO had better.       Forbes

Wednesday, December 23, 2015

The controversial 'surveillance' act Obama just signed


President Barack Obama signs the budget bill in the Oval Office of the White House December 18, 2015 in Washington, DC.
President Barack Obama signed into law a $1.1 trillion spending bill last Friday, staving off a potential government shutdown — and in the process, quietly inaugurated what some have called a second Patriot Act.

As part of the more-than-2,000-page document, the 14th rider to be exact, the appropriations omnibus includes the Cybersecurity Act of 2015. Buried within that section is the text of the Cybersecurity Information Sharing Act (CISA), a bill that seeks to permit private companies to handover information to federal agencies.

In essence, the law allows companies to directly share information with the Department of Defense (including the National Security Agency) without fear of being sued. This info can be used for cybersecurity purposes, but critics have keyed into the law's allowance for using the data to address or investigate a "specific threat" of death, serious bodily harm, serious economic harm, terrorism, harm to a minor and more.

As Wired noted, an earlier bill only allowed information sharing in the case of "imminent threats," but the new "specific" verbiage disregards any timeliness.
The House Committee on Rules described the information sharing measure as "a voluntary cybersecurity information sharing process that will encourage public and private sector entities to share cyberthreat information, without legal barriers and the threat of unfounded litigation — while protecting private information."

As benign as that description may sound, several legislators released comments decrying the implications of the CISA measures.

"I was unable to vote for the omnibus spending bill today because it included an extraneous provision purported to facilitate cybersecurity information sharing that — in effect — will function as a surveillance tool," California Rep. Zoe Lofgren said in a statement.

Oregon Sen. Ron Wyden was even more critical, saying the "unacceptable surveillance provisions" are a "black mark" on the rest of the appropriations bill. He even implied that the information sharing provisions are worse than in previous incarnations.

"Ultimately, I cannot vote for this badly flawed CISA bill. The latest version of CISA is the worst one yet — it contains substantially fewer oversight and reporting provisions than the Senate version did," he said in a statement. "That means that violations of Americans' privacy will be more likely to go unnoticed."

To Wyden's point, 55 civil society groups, security experts and academics, wrote earlier this year that CISA would "seriously threaten privacy and civil liberties, and could undermine cybersecurity, rather than enhance it."

These complaints may be blowing the scope of the bill out of proportion, according to Randy Sabett, vice chair of the privacy and data protection group at the law firm Cooley.

"I try to maintain a relatively open mind toward the arguments that people raise when they start talking about privacy and civil liberties, but I guess where I have difficulty is with some of these sweeping statements that it's a pure surveillance bill," he said.
 
Sabett pointed to CISA's voluntary nature — it doesn't compel any company to share data with the government, only prevents them from being sued for it. On the other hand, the law unequivocally requires both federal authorities and companies to scrub personal information from shared data.

Additionally, the law compels the government to issue regular privacy update reports to monitor any abuses, Sabett said.

And there are many who support the information sharing law, including Obama administration officials and industry groups.

"Cybersecurity is a top priority for DHS and the Obama administration, and this bipartisan effort is a significant step forward in strengthening our nation's cybersecurity," Homeland Security Secretary Jeh Johnson said in a statement after the omnibus spending bill was passed. "I look forward to working with Congress on further strengthening DHS' cybersecurity mission."

The U.S. Chamber of Commerce also put its support behind the new law. Recognizing that cybercrime targets both government and businesses, the Chamber's president and CEO, Thomas Donohue, said in a statement that CISA will allow businesses to voluntarily work with authorities "to better prevent, detect and mitigate threats."

"This legislation, long championed by the Chamber, is our best chance yet to help address this economic and national security priority in a meaningful way and help prevent further attacks," Donohue said.

Financial sector groups, such as the Securities Industry and Financial Markets Association and the American Bankers Association, have applauded CISA. Members of the Cyber Threat Alliance — which is made up of four companies: Palo Alto Networks, Fortinet, Symantec and Intel Security Group — were largely positive on the CISA measures in October.

"I have seen companies benefit from information sharing: To be in a situation where that information is like pulling teeth, and then to see the benefits that come out of it is an eye-opening experience," Sabett told CNBC. "Getting something on the books is going to have a lot more positive effects than the negative effects that the critics are pointing to."   CNBC
 
Everett Rosenfeld Staff Writer