Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Sunday, January 10, 2021

Seditionists Had Unfettered Access to Congressional IT Systems

After Wednesday's invasion by protesters, America's Capitol building is now grappling with "the process of securing the offices and digital systems after hundreds of people had unprecedented access to them," 

Rioters could have bugged congressional offices, exfiltrated data from unlocked computers, or installed malware on exposed devices. In the rush to evacuate the Capitol, some computers were left unlocked and remained accessible by the time rioters arrived. And at least some equipment was stolen; Senator Jeff Merkley of Oregon said in a video late Wednesday that intruders took one of his office's laptops off a conference table...

Former Senate sergeant at arms Frank Larkin, who retired as Senate sergeant at arms in 2018, adds that cybersecurity is the next priority after physical security. In spite of this, the mob Wednesday had ample opportunities to steal information or gain device access if they wanted to. And while the Senate and House each build off of their own shared IT framework, ultimately each of the 435 representatives and 100 senators runs their own office with their own systems. This is a boon to security in the sense that it creates segmentation and decentralization; getting access to Nancy Pelosi's emails doesn't help you access the communications of other representatives. But this also means that there aren't necessarily standardized authentication and monitoring schemes in place. Larkin emphasizes that there is a baseline of monitoring that IT staffers will be able to use to audit and assess whether there was suspicious activity on congressional devices. But he concedes that representatives and senators have varying levels of cybersecurity competence and hygiene.
It's also true that potentially exposed data at the Capitol on Wednesday would not have been classified, given that the mob had access only to unclassified networks. But congressional staffers are not subject to Freedom of Information Act obligations and are often much more candid in their communications than other government officials. Security and intelligence experts also emphasize that troves of unclassified information can still reveal sensitive or even classified information when combined... Kelvin Coleman, executive director of the National Cyber Security Alliance, who formerly worked in the Department of Homeland Security and National Security Council... adds, though, that for now the most important thing congressional IT staffers can do is account for which devices were stolen and begin a mass effort to reset passwords, add multifactor authentication to any accounts that don't already have it, wipe and reimage hard drives when practical, and comb monitoring logs for signs of access or exfiltration.

There is more information at Wired.

Friday, August 7, 2020

Russia is Expert at Online Disinformation

At her Thursday keynote, Stanford Internet Observatory's research manager Renee DiResta explained how Russian military intelligence – the GRU – and the private Internet Research Agency (IRA) were putting the likes of China to shame. Security companies and government agencies have good reason to move their focus from Beijing to Moscow, she warned.

The basic methods of hacking public opinion are fairly simple, DiResta explained. Fake accounts generate content and spam it out on social media to amplify the message. If enough real people pick up and the posts go viral the mainstream media kicks in and amplifies the desired message still further.

In Russia's case, it spreads divisive material, stolen information, and fake news in an attempt to turn Americans against each other, sour civil society, sow doubt, and create distractions, leaving people unsure of what's really going on. This worked. In China's case, it tried to make people like China. This didn't work.

https://www.blackhat.com/us-20/briefings/schedule/#hacking-public-opinion-21289


Friday, December 6, 2019

What Are the Biggest Cyber Risks in the Upcoming Year?

What are the expected trends in cyber security in the upcoming year? According to a report from Trend Micro--

  • Third-party libraries, container components and even remote workers represent a major supply chain risk to organizations as they head into a new decade.
  • Continued user misconfigurations will exacerbate cloud security challenges, while developers’ reliance on third-party code could expose countless organizations, it continued.
  • Shared container components containing vulnerabilities as exposing organizations to attacks across the IT stack.
  • Supply chain risk will extend to managed service providers (MSPs), especially those with multiple SMB customers.
  • Home and remote working environments are potential hotspots for supply chain attacks -- everything from weak Wi-Fi security in public workspaces to smart home challenges posed by unsecured smart TVs, speakers and digital assistants.

The security firm's 2020 predictions report, The New Norm, emphasizes the cloud as a likely attack objective, as near-do-wells  focus efforts on code injection attacks to obtain sensitive information — either directly or via third-party incursions.

Monday, August 19, 2019

New Certification Rules from the EU Cybersecurity Act


In June 2019, the European Cybersecurity Act was instituted, introducing the first-ever EU-wide rules on the cybersecurity certification of products, processes, and services. This serves to strengthen the role of the EU Agency for Cybersecurity (ENISA).

The European cybersecurity certification framework establishes tailored and risk-based EU certification schemes, aiming to increase the cybersecurity of online services and consumer devices. Such European cybersecurity certification scheme comprises a comprehensive set of EU-wide rules, technical requirements, standards and procedures serving to evaluate a specific product, service or process on the basis of its cybersecurity properties. Each certificate will carry one of three assurance levels, and will be recognized EU-wide.
The harmonized rules are expected to facilitate cross-border trade of relevant products and services, reduce market-entry barriers, and simplify the process of cybersecurity certification.
ENISA has received a permanent mandate with additional responsibilities and resources to better help Member States in addressing cybersecurity threats and incidents. This includes support to policy implementation, standardization, certification, crisis management and coordinated vulnerability disclosure. ENISA's mandate has been applicable since 27 June 2019. The Commission is currently preparing the requests for ENISA to design certification schemes and to establish two expert groups:
the European Cybersecurity Certification Group, consisting of Member States representatives; and
the Stakeholder Cybersecurity Certification Group, mandated to advise ENISA and the Commission.
I.a. on the basis of a public consultation, the Commission will identify strategic priorities for certification and a list of ICT products, services and processes to be included in the scheme.”

See further information here...

Friday, August 16, 2019

Abuse of Online Privacy Rules Means Personal Info Can Be Compromised - So Require Credentials

With the introduction of Europe's General Data Protection Regulation, firms in Europe and around the globe should be aware that social engineering tactics can be used to acquire an individual’s sensitive data.

“…For social engineering purposes, GDPR has a number of real benefits, Pavur said. Firstly, companies only have a month to reply to requests and face fines of up to 4 percent of revenues if they don't comply, so [the] fear of failure and time are strong motivating factors.

In addition, the type of people who handle GDPR requests [is] usually admin or legal staff, not security people used to social engineering tactics. This makes information gathering much easier….” See this article.

Direct email marketing, for example, is already regulated under the EU's e-Privacy Directive. Such rules require consent before someone can be sent direct marketing. A so-called "soft opt-in" makes this slightly easier. If a firm has an existing relationship, for instance, if a customer has bought a product from them before, they may still contact that recipient.

The European Union is updating the rules on electronic communications just as the UK is hustling to engage its own Data Protection Act in place, considering how Brexit will affect tech firms. The continued flow of data between the UK and the rest of Europe (and the world) depends on governments’ ability to interact.

Tuesday, August 6, 2019

Known Apple Vulnerability Remains Unpatched

Apple Wireless Direct Link (AWDL) is at the core of Apple services like AirPlay and AirDrop, and Apple has been including AWDL by default on all devices the company has been selling, such as Macs, iPhones, iPads, Apple watches, Apple TVs, and HomePods.

It seems that the AWDL protocol, installed on over 1.2 billion Apple devices, contains vulnerabilities that enable attackers to track users, crash devices, or intercept files transferred between devices via man-in-the-middle (MitM) attacks.
These are the findings of a research project that started last year at the Technical University of Darmstadt, in Germany, and has recently concluded, and whose findings researchers will be presenting later this month at a security conference in the US. The project sought to analyze the Apple Wireless Direct Link (AWDL), a protocol that Apple rolled out in 2014 and which also plays a key role in enabling device-to-device communications in the Apple ecosystem. While most Apple end users might not be aware of the protocol's existence, AWDL is at the core of Apple services like AirPlay and AirDrop, and Apple has been including AWDL by default on all devices the company has been selling, such as Macs, iPhones, iPads, Apple watches, Apple TVs, and HomePods. But in the past five years, Apple has never published any in-depth technical details about how AWDL works. This, in turn, has resulted in very few security researchers looking at AWDL for bugs or implementation errors.

Monday, June 10, 2019

GDPR will impact more than privacy

Similar to how GDPR hugely impacted how millions of organizations handle personal data when it was enforced last year, Strong Customer Authentication (or SCA) will have profound implications for how businesses handle online transactions and how we pay for things in our everyday lives when it is enforced on September 14.

SCA will require an extra layer of authentication for online payments. Where a card number and address once sufficed, customers will now be required to include at least two of the following three factors to do anything as simple as ordering a taxi or pay for a music streaming service. Something they know (like a password or PIN), something they own (like a token or smartphone), and something they are (like a fingerprint or biometric facial features).

Without careful preparation, failed transactions and additional friction may have a significant negative impact on conversion rates.



Tuesday, April 23, 2019

Knowledge Worker Productivity Improvements with Machine Learning


Leveraging machine learning to enhance capabilities that can recognize context, concepts, and meaning means there are interesting new opportunities for collaboration between knowledge workers and computational power. For example, Bluedog’s experts can now provide more of their own input for training, quality control, and fine-tuning of algorithm-based outcomes. We use the computational power of our servers to augment the expertise of human collaborators — this helps to create new areas for our experts to leverage.

For example, at Bluedog, we utilize several algorithm-based tools to help us quickly assess opportunities for our clients. We extract information from Word Documents locally for multiple uses. With one tool, we take advantage of each Word document’s XML metadata. From there, we use a regex library to find each targeted word or phrase in the document, then adding them to a list. Our toll then performs for-loops to scan for relevant patterns in the XML to extract data.

Knowledge workers — the staff or consultants who reason, create, decide, and apply insight into non-routine cognitive processes — can contribute to redesigning work process roles and team member roles. Consider financial auditing, where AI is likely to become pervasive. Often, when AI offers a finding, the algorithm’s reasoning isn’t obvious to the accountant, who ultimately must offer an explanation to a client — characteristic of the “black box” problem. To improve this outcome, Bluedog recommends providing an interface so experts to enter concepts they deem important into the system and be provided with a means to test their own hypotheses. In this way, we recommend making models accessible to common sense. 

As cybersecurity concerns mount, organizations have increased the use of instruments to collect data at various points in their network to analyze threats — and to address “Internet-of-Things” (IoT) devices. However, many of these data-driven systems do not integrate data from multiple sources. Nor do they incorporate the common-sense knowledge of cybersecurity experts, who know the range and diverse motives of attackers, understand typical internal and external threats, and appreciate the degree of risk to an organization. 


Bluedog’s experts specify the use of Bayesian models — which employ probabilistic analysis to capture complex interdependence among risk factors —  combined with expert systems judgment. In cybersecurity for enterprise networks, complex factors may include large numbers and types of devices on the network. It is crucial to access the knowledge of the organization’s security experts about attackers and risk profile to better intercept cybercriminals.

Wednesday, March 6, 2019

Ireland's First Report on GDPR

Last month marks the release of the first annual GDPR report from Ireland’s data protection supervisory authority, the Data Protection Commission (DPC). This is a follow-on from the DPC’s final pre-GDPR annual report and covers May through December of 2018.

The report confirms the DPC’s role as the clearinghouse for cross-border privacy complaints: A new category, termed ‘multinational complaints – others’, makes up 22% of all GDPR complaints in the report. These complaints are second to access rights as the largest category of complaint. 

This document also sets out the DPC’s views on the new complaint-handling mechanism under the Data Protection Act of 2018. When a negotiated resolution is not possible, the DPC is no longer legally obliged to make a formal, statutory decision. Instead, the DPC has a range of options: providing advice to the complainant; issuing statutory notices to controllers or processors; and, opening statutory enquires.

If a non-EU company is offering services over the internet to consumers in the EU, these companies are required to have a  data protection representative due to increased territorial scope. Article 3 of the GDPR applies to any ‘data subject’ in the EU, i.e. a person living in the EU. Notably, Article 3(2) applies to the processing of personal data of any individual “in the EU.” The individual’s nationality or residence is irrelevant. The GDPR protects the personal data of citizens, residents, tourists, and other persons visiting the EU. So as long as an individual is in the EU, any personal information of that person collected by any controller or processor who meets the requirements of Article 3(2) is subject to the GDPR. Learn more about having a data representative here.



Wednesday, January 2, 2019

A New Year, Time to Take the Temperature of... DevOps

Sometimes adoption of DevOps results in chaos -- perhaps because of the evolving relationship between development and operations? When taking a shared approach to accountability for application life cycle, many still lack processes, tools, and monitoring needed to know who is ultimately responsible for addressing and fixing issues.

As the lines between development and operations continue to blur, perhaps one should focus on adopting tools that deepen visibility into applications?  It seems that clarifying ownership of applications and services avoids the "since everyone owns this, nobody does" model.

Read more about the state of DevOps

Friday, December 28, 2018

Huawei - Security Threat For Many Reasons


The Chinese firm Huawei is the world’s largest manufacturer of networking gear such as base stations and antennas that mobile operators use to run wireless networks. Those networks carry data that are used to help control power grids, financial markets, transport systems, and other parts of countries’ vital infrastructure. The fear is that China’s military and intelligence services could insert software or hardware “back doors” into Huawei’s gear.