Showing posts with label sans. Show all posts
Showing posts with label sans. Show all posts

Wednesday, April 02, 2008

NATO Summit and EU Conference address the global reaches of illict cyber activity

On the Internet -- crime, espionage and some say, terrorism can cross a border with the click of a mouse. Because of this, it probably shouldn't be surprising that this is a hot topic at the NATO summit, as well as, a seperate conference conducted by the EU.

The AP is reporting:

At a two-day conference starting Tuesday in Strasbourg, France, the Council of Europe will to review implementation of the international Convention on Cybercrime and discuss ways to improve international cooperation.

Cyber defense also will be on the agenda when heads of state from NATO's 26 member nations gather in Bucharest Wednesday for three days. The leaders are expected to debate new guidelines for coordinating cyber defense.
Cyber defense is increasingly becoming a concern. For instance, there is increasing evidence that the Chinese have been hacking into other government's systems and have a cyber war doctrine being developed.

Last year, there was the much written about attack on the government of Estonia, also.

The EU conference will also address more financially motivated criminal activity on the Internet, also.

The AP article quotes a German University Professor, Marco Gercke, who specializes in computer law as saying:

Compared to regular terror attacks, it is much easier for the offenders to hide their identity. There are at least 10 unique challenges that make it very difficult to fight computer-related crime," said Gercke, one of the conference participants. "The success rate of cybercrime is very high."
While it is unknown, whether or not, these meetings of the minds will yield any results -- the fact is that unless there is greater cooperation and collusion between the good guys -- the problems of undesirable activity being spread with the click of a mouse is likely to continue growing at an alarming rate.

A little more teamwork and forward thinking might go a long way towards solving the problem. Of course, taking some of the players out from the opposition (bad guys) would go a long way, also!

To close this brief post, I would like to point to matters a little closer at home. An American computer law expert recently wrote a forward thinking article on the Hannaford data breach, where hackers stole 4.2 million payment (credit/debit) card numbers and the recent settlement between TJX and the FTC.

In his well thought out article, Ben Wright of SANS writes:

The FTC is well-meaning here, but it is misdirected. By singling out TJX and chastising it with the “unfairness” “bad guy” rhetoric, the FTC distracts the necessary public conversation. It implies that if we can just punish these lazy merchants enough (and force them to comply with the PCI and similar controls), then credit cards will be safe. That’s wrong.

The criminal warfare directed at the credit card system is more powerful than the theory behind PCI. The whole credit card system needs to change. As a society we need to focus on beating the criminals, and stop flogging victims like TJX as unfair privacy infringers.

To me, this means that instead of spending all our resources on inadequate security and filing litigation against the "unlucky targets" of organized cyber crime, we need to start addressing the root of the problem. I'll give anyone reading this one guess, who that might be?

Saturday, February 16, 2008

The $54 million lost laptop law suit

Found this story on SANS Newsbites. Apparently, a former Best Buy customer is suing Best Buy after they lost her laptop and allegedly tried to cover up the matter.

After going to a link on Information Week, I discovered that the plaintiff in question, Raelyn Campbell started a blog to chronicle her battle with the retailer.

The blog states Raelyn's intention in her own words:

I have filed a lawsuit against Best Buy and launched this blog in an effort to bring attention to the reprehensible state of consumer property and privacy protection practices at America's largest consumer electronics retailer, with the hope that it might motivate Best Buy to effect changes and spare future consumers the experience I have been subjected to -- or worse.

Whether due to what seems to be a plague of bad customer service, inept employees or a combination of both, Raelyn charges that:

Her laptop went missing and the Geek Squad initially couldn't find it in their computer.

That later on, a computer entry mysteriously appeared which leads to speculation that the Geeks were covering their tracks.

She tried to settle for $5,000.00, but was continuously low-balled by Best Buy.

After she filed a law suit, Best Buy tried to offer $2500.00.

Raelyn declined this offer because (in her own words):
I advised Best Buy's lawyer that I would drop the suit if Best Buy would provide compensation for my expenses and time and address the shortcomings in its property and privacy protection practices.
Additionally Raelyn is charging that Best Buy broke D.C. law by not notifying her immediately that she could become an identity theft victim.

Her blog has a lot of links to other allegations of employee abuse at Best Buy, which can be seen, here.

Of note, this episode -- no matter whether you think a $54 million law suit is called for or not --brings up the very real problem of all the portable data we carry being exposed when we drop it off somewhere for repairs.

It's a far shot that a responsible business would knowingly employ personnel that steal, but dishonest employees are a reality in today's world. Since information isn't inventoried and can be copied, protecting it is a little more difficult than other assets such as money or merchandise. In fact, most of the time when information is stolen, no one ever probably notices it is missing (my opinion).

Since information is worth a lot of money, this poses a problem.

This leaves a lot of things to consider and my guess is that protecting information is going to be a hot subject for a long time to come.

There are a slew of comments on the blog, both bashing and praising Raelyn for this action. Please note on blogspot, Raelyn can control the comments and therefore is being transparent by publishing them all.

To end this post, I will refer to (what I consider) some sage advice and commentary from three SANS newsbite editors:

[Editor's Note (Pescatore): I was thinking of suing my employer for about that much for forcing to me to carry a laptop all the time. This does point out an issue where some companies have allowed employees to do business on personal laptops that get repaired at places that don't protect them very well, and then the business information ends up on eBay and thousands of customers have to get notified, etc. etc.

(Cole): This will continue to happen; so two key take aways. One, use folder level encryption with a strong passphrase so repair people will not have access to your data. Full disk encryption will not work, since the techs need to log into the system. Second, backup of all of your critical data on a removable drive.

(Schultz): It is easy to predict that lawsuits of this kind are going to proliferate in the future. Many organizations have been downright irresponsible in handling personal and financial information, let alone others' computers. The threat of a lawsuit is likely to force such organizations to radically tighten their procedures for handling such information and computing equipment.

If you are interested in reading more from the SANS people, I've provided a link to their SANS Newsbites page, here.

Saturday, January 19, 2008

A rumor of electrical power grids being hacked via the Internet

Here is a scary report -- electrical power grids shut off by hackers demanding money using the Internet.

Ted Bridis of the AP is reporting:

Hackers literally turned out the lights in multiple cities after breaking into electrical utilities and demanding extortion payments before disrupting the power, a senior CIA analyst told utility engineers at a trade conference.

All the break-ins occurred outside the United States, said senior CIA analyst Tom Donahue. The U.S. government believes some of the hackers had inside knowledge to cause the outages. Donahue did not specify what countries were affected, when the outages occurred or how long the outages lasted. He said they happened in "several regions outside the United States."

"In at least one case, the disruption caused a power outage affecting multiple cities," Donahue said in a statement. "We do not know who executed these attacks or why, but all involved intrusions through the Internet."
Unfortunately, the CIA doesn't seem to want to verify where this happened at.

I did a Google news search and there are power outages being reported all over, but most notably in Africa and Pakistan.

If anyone else cares to speculate, a link to Google and power outages can be seen, here.

Problem is power outages happen all the time and I'm not sure if the search reveals any unusual activity.

Of course, the CIA will not confirm or deny exactly which outages were caused by hackers.

Apparently, the CIA official announced this at a SANS conference in New Orleans on Thursday. Information Week has more information on this, here.

Nonetheless, if power grids can be shut down using the Internet, it makes me wonder how secure we really are sometimes?

Last summer shutting down power grids was part of the plot in the movie, "Live Free or Die Hard" starring Bruce Willis.

AP article (courtesy of SF Gate), here.

Monday, June 12, 2006

Are Terrorists Probing Our Computer Systems?

I read a pretty alarming article by Barton Gellman of the Washington Post, stating that terrorists might already be planning cyber-attacks:

"Late last fall, Detective Chris Hsiung of the Mountain View, Calif., police department began investigating a suspicious pattern of surveillance against Silicon Valley computers. From the Middle East and South Asia, unknown browsers were exploring the digital systems used to manage Bay Area utilities and government offices. Hsiung, a specialist in high-technology crime, alerted the FBI's San Francisco computer intrusion squad."

"Working with experts at the Lawrence Livermore National Laboratory, the FBI traced trails of a broader reconnaissance. A forensic summary of the investigation, prepared in the Defense Department, said the bureau found "multiple casings of sites" nationwide. Routed through telecommunications switches in Saudi Arabia, Indonesia and Pakistan, the visitors studied emergency telephone systems, electrical generation and transmission, water storage and distribution, nuclear power plants and gas facilities."

The article also reports another issue, which is a big problem:

"New public-private partnerships are helping, but the government case remains a tough sell. Alan Paller, director of research at the SANS Institute in Bethesda, said not even banks and brokerages, considered the most security-conscious businesses, tell the government when their systems are attacked. Sources said the government did not learn crucial details about September's Nimda worm, which caused an estimated $ 530 million in damage, until the stricken companies began firing their security executives."

"Experts said public companies worry about the loss of customer confidence and the legal liability to shareholders or security vendors when they report flaws."

For the full story, link here.

If the observations in this article are accurate, we can no longer afford to "keep the lid" on cyber-attacks in the interest of protecting bottom lines. Being worried about consumer confidence and legal liability should take second place to the safety and welfare of all concerned.

Here are some previous posts, I written on this subject:

Mounties Lack Resources to Fight Organized Crime and Cite Ties to Terrorism

Do Financial Crimes and Internet Fraud Fund Terrorism