Tampilkan postingan dengan label security. Tampilkan semua postingan
Tampilkan postingan dengan label security. Tampilkan semua postingan

Kamis, 01 September 2011

Expert says UK government is too preoccupied with launching cyber attacks

computing.co.uk

A security expert has claimed that the UK is devoting most of its cyber crime fighting efforts to cyber attack, leaving limited resources for defence.

Speaking exclusively to Computing, Ross Anderson, professor of security engineering at the Cambridge University computer laboratory, stated that 90 per cent of the government's recent funding injection into cyber security was going to the UK's offensive capability.

"The spooks - GCHQ [Government Communications Headquarters, pictured] - are getting 90 per cent of this new £650m for cyber security [they are responsible for cyber attacks]. The rest, about £65m, is going to the police."

Anderson blamed the imbalance on the fact that the UK's cyber defence capabilities are organisationally placed within GCHQ, the body responsible for electronic espionage, or cyber attack.

"Like the US, the UK has unfortunately got the government's offensive and defensive arms linked together.

"CESG [Communications-Electronic Security Group], which is supposedly defending the core functions of government against for example cyber espionage by the Chinese, is a small subsidiary of GCHQ whose job is exploiting those sources abroad.

"This mixed mission is very bad policy, because it means defensive interests are always less important than an offensive approach."

Selasa, 07 Juni 2011

Spear Phishing: More than Spam, it's Espionage

pcworld.com
The most frequent comment I see on stories reporting some new dramatically successful phishing attack is from an overly nearly well-informed technophile who thinks people who fall for phishing schemes are just stupid.

Despite a success rate so high it's become standard operating procedure for Chinese military and government cyber-espionage groups, people who respond to phishing e-mails are treated like they're one walker-assisted step above the elderly shut-ins who send money to help Nigerian princes and ministers of finance mysteriously down on their luck.

If only the stupid fell for phishing scams the successful attacks against companies with sophisticated security -- Google, Lockheed Martin, HB Gary, PayPal, various other U.S. military and intelligence agencies -- would have been able to shut down the breaches quickly. Others with security at least as good -- CitiBank, Bank of America, AOL, Western Union -- wouldn't have to send out alerts every 10 minutes warning people that they weren't sending out alerts, so don't mail in your usernames and passwords.

Phishing works, for the same reason grifting works -- given a set of facts that seem to fit all their expectations and experience, and the opportunity to either help out a co-worker or profit from something that's very little trouble for them, most people will take the risk. (See also "4 Security Tips Spurred by Recent Phishing Attacks on Gmail, Hotmail, and Yahoo").

More...

Kamis, 02 Juni 2011

Google breaks up Gmail spying campaign

scmagazineus.com

Google has identified and disrupted a campaign operating out of eastern China meant to hijack and monitor the Gmail accounts belonging to hundreds of users, the technology giant revealed Wednesday.

Victims included U.S. and Asian government officials -- mostly from South Korea, military members, journalists and Chinese political activists, said Eric Grosse, engineering director of the Google's security team, in a blog post.

The campaign appears to trace back to Jinan, China and involves the theft of user's Gmail passwords, likely through phishing, he said. Google was able to disrupt the campaign, secure the affected accounts and notify the targeted individuals.

"The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Grosse wrote. "Google enables you to forward your emails automatically, as well as grant others access to your account."

More...

Kamis, 14 April 2011

Self-wiping hard drives from Toshiba

net-security.org
Toshiba announces a family of self-encrypting hard disk drives (HDDs) engineered to automatically invalidate protected data when connected to an unknown host. The new Toshiba Self-Encrypting Drive (SED) models enable OEMs to configure different data invalidation options that align with various end-user scenarios.

Designed to address the increasing need for IT departments to comply with privacy laws and regulations governing data security, the drives are ideally suited for PC, copier and multi-function printer, and point-of-sale systems used in government, financial, medical, or similar environments with an acute need to protect sensitive information.

More...

Minggu, 02 Januari 2011

Anti-Eavesdropping iPhone Voice Communications Encryption Security App

prlog.org

In iPhone security news a new voice communications encryption iPhone security app stops eavesdropping, wiretapping and cell phone spys.

PRLog (Press Release)Dec 30, 2010 – A new iPhone personal and business related app has been launched to provide iPhone users with private, secure voice communications. The AES military grade voice communications encryption iPhone security app enables users to talk freely without the fear of their conversation being heard or recorded by any eavesdropping, wiretapping cell phone spys.

Visit http://www.KryptosCom.com for more information, screen shoots, specs and links to the iTunes app store secure purchase area.

The Kryptos voice communications security app utilizes 256 bit AES military grade encryption to encrypt cell phone calls between users. For added security the app uses 1024 bit RSA encryption during the symmetric key exchange. The Secure Voice Over IP (VoIP) application can provide VoIP connectivity for secure calls over several networks including 3G, 4G
and WiFi to protect business, personal and government related information secure, safe
and private.

More...

Selasa, 07 Desember 2010

Lost Laptops Cost Billions

informationweek.com
An Intel-sponsored study finds that organizations fail to grasp the risk of lost laptops.

Businesses are losing billions of dollars annually as a result of lost and stolen laptop computers, a new study shows.

Representatives from Intel, which sponsored "The Billion Dollar Laptop Study," and the Ponemon Institute, which conducted the study, announced their findings at a media event in San Francisco on Thursday.

The 329 organizations surveyed lost more than 86,000 laptops over the course of a year, the study found. Larry Ponemon, chairman and founder of the Ponemon Institute, said that based on these findings and a 2009 survey that put the average cost of lost laptop data at $49,246, the cost to these organizations came to more than $2.1 billion or $6.4 million per organization.

"A lot of organizations are incompetent at protecting information assets," said Ponemon.

More...

Jumat, 05 November 2010

Man in disguise boards international flight

Note: This just in from our friend "Mike" Heads up! Pay attention out there will ya! Grandma was slow, but she was 100! JDL
cnn.com

Atlanta, Georgia (CNN) -- Canadian authorities are investigating an "unbelievable" incident in which a passenger boarded an Air Canada flight disguised as an elderly man, according to a confidential alert obtained by CNN.

The incident occurred on October 29 on Air Canada flight AC018 to Vancouver originating in Hong Kong. An intelligence alert from the Canada Border Services Agency describes the incident as an "unbelievable case of concealment."

"Information was received from Air Canada Corporate Security regarding a possible imposter on a flight originating from Hong Kong," the alert says. "The passenger in question was observed at the beginning of the flight to be an elderly Caucasian male who appeared to have young looking hands. During the flight the subject attended the washroom and emerged an Asian looking male that appeared to be in his early 20s."

More...

Rabu, 29 September 2010

iPhone GPS app helps find man suspected of stealing smart phone

news10.net

ROCKLIN, CA - When Josh Paul's fiancee, Michelle Langford, realized her cell phone was missing Saturday afternoon, Paul wondered about the magazine solicitor who had shown up just a short time before.

"We're looking for the phone and where did the cell phone go?" Paul said. "At that point we put it together."

But Paul did more than just call the police. He thought immediately of the "Mobile Me" GPS application Langford has her phone that allows the phone to be tracked by computer.

"So we grabbed a computer," Paul said, "And saw that her phone was walking approximately 3/4 of a mile from here."

"At first, I thought it was wrong," said Langford. "I was convinced it was a software malfunction, but it wasn't."

It was then the two called police as they traced the phone to a Rocklin residence. When they arrived, however, the thief had already left.

"But the couple at that address said, 'We'd be more than willing to let you log onto our computer and get an update on his status,'" Paul said.

The trail eventually led to a Home Depot store on Fairway Drive in Roseville where Paul identified the alleged thief and police made an arrest.

More...

Senin, 16 Agustus 2010

Internet era espionage pits spy against tech


(AFP)

SAN FRANCISCO — Clashes between the maker of Blackberry smart phones and India, Saudi Arabia and the United Arab Emirates are the latest rounds in a cat-and-mouse game pitting authorities against technologies racing beyond their grasp.

"What is going on is this elegant dance we go through when countries think their sovereignty is being threatened by new technology," said Mark Rasch, who headed the computer crimes division at the US Department of Justice for nine years.

"Governments are very ready to deploy technology that invades privacy, but privacy enhancing technologies make them nervous."

Security experts put the row over Blackberry encryption capabilities in the context of decades of skirmishing around the security implications of new Internet and communications technologies -- a battle that today also touches services like Google's Talk messaging system and the telephone and video services provided by Skype.

More...

Jumat, 13 Agustus 2010

Cars hacked through wireless tire sensors

Note: This hack attack trick just in from our friend "Mike", so pay attention! "From an "Executive Protection" or Family safety stand point, this would be provide a new and interesting vector of attack. No longer would you need to employ a "strong arm" takeover, IED or all out ambush, simply distract or concern the driver enough to get him to pull over".



arstechnica.com

The tire pressure monitors built into modern cars have been shown to be insecure by researchers from Rutgers University and the University of South Carolina. The wireless sensors, compulsory in new automobiles in the US since 2008, can be used to track vehicles or feed bad data to the electronic control units (ECU), causing them to malfunction.

Earlier in the year, researchers from the University of Washington and University of California San Diego showed that the ECUs could be hacked, giving attackers the ability to be both annoying, by enabling wipers or honking the horn, and dangerous, by disabling the brakes or jamming the accelerator.

More...

Rabu, 28 Juli 2010

Cybercriminals having easy time cracking corporate networks


usatoday.com
Verizon today issued its annual Data Breach Investigation Report, timed for the opening day of the giant Black Hat cybersecurity convention in Las Vegas.

It's not widely known that the telecom giant is home to a crack cybersecurity forensics team. Over the past half dozen or so years, Verizon's cybersleuths have been retained by large organizations to probe more than 900 separate cases of data theft in which some 900 million records were compromised. Based on direct evidence from those hands-on probes of real hacks, Verizon's annual breach report stands apart from other cybersecurity studies, many of which are based on subjective, anecdotal opinions of survey respondents.

More...

Selasa, 22 Juni 2010

Android App Aims to Allow Wiretap-Proof Cell Phone Calls

Forbes.com
Worried about the NSA, the FBI, criminals or cyberspies electronically eavedropping on your private phone calls? There may be an untappable app for that.

On Tuesday, an independent hacker and security researcher who goes by the handle Moxie Marlinspike and his Pittsburgh-based startup Whisper Systems launched free public betas for two new privacy-focused programs on Google's Android mobile platform: RedPhone, a voice over Internet protocol (VoIP) program that encrypts phone calls, and TextSecure, an app for sending and receiving encrypted text messages and scrambling the messages stored in their inbox.

Marlinspike says the apps will interface with users' contact lists and other functions on the phone to take the hassle out of making calls and sending texts that can't be eavesdropped by third parties. "Our main aim is to make this as easy as possible," he says. "We want it to be a secure and anonymous drop-in replacement for the normal dialing system on your phone."

More...

Selasa, 08 Juni 2010

Panasonic Spy-Cam is All-Seeing, All-Hearing Nightmare

wired.com

There are plenty of wireless spy-cams around, but this one gets a special mention because it is so cute, and at the same time so very sinister.

The BL-C230A from Panasonic will sit and wait, staring unblinkingly at its assigned slice of the world, watching patiently for some action. Should it hear a sound, see movement or detect body-heat – Predator-style – it will go into action and start filming the unfolding shenanigans, day or night.

The footage can then be emailed to you, or send directly to a VIERA link-compatible TV. If you prefer, you can just dial-in and watch the 30fps, H.264 stream over the 802.11b/g network. You can also pan and zoom remotely and connect up to 16 of these critters together to make a truly UK-style surveillance network.

Jumat, 28 Mei 2010

Protecting the smartphone from malware

connectedplanetonline.com

Despite the increasing sophistication of smartphones and other mobile devices, viruses and malware don’t plague the wireless industry the way they do the personal and business computing worlds. But computer protection software giant Symantec has decided to dive into the smartphone space regardless, in anticipation of future security threats and to stake a claim in the growing applications market.

Symantec (NASDAQ:SYMC) today announced the launch of Norton Everywhere a suite of services and applications targeting Android and Apple iPhone devices as well the growing number of non-PC devices connected to the Internet via Wi-Fi and home networks. The most familiar service in that suite is a mobile version of its Norton Antivirus software, initially for Android phones only, which identifies malicious applications and software before they’re downloaded and installed onto a device. It will also scan applications already installed on a device to see if they are doing anything suspicious, such as accessing phone logs and phone books and relaying that information across the network, and warn users about just what their apps are doing.

Norton Mobile will be available as a Beta application in June, and while Symantec is investigating optimizing the security solution for other platforms, it felt Android was the best place to start. Unlike the iPhone, which uses a closed application distribution model driven by Apple’s App Store, Android software can come from anywhere — the Web, third-party app stores, even embedded in an e-mail, said Dan Nadir, director of product management for Symantec.

More...

Sabtu, 22 Mei 2010

IBM: We distributed malware-ridden USB drives

news.cnet.com

IBM is apologizing for handing out USB drives at a security conference in Australia this week that had malware on them.

The thumb drives were distributed for free to people who walked up to the IBM booth at the AusCERT conference.

"Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected," Glenn Wightwick, chief technologist at IBM Australia, wrote in a letter to AusCERT delegates that was reprinted on the Beast or Buddha blog.

"The malware is detected by the majority of current Anti Virus products [as at 20/05/2010] and been known since 2008," the letter said. "The malware is known by a number of names and is contained in the setup.exe and autorun.ini files. It is spread when the infected USB device is inserted into a Microsoft Windows workstation or server whereby the setup.exe and autorun.ini files run automatically."

More...

Senin, 26 April 2010

Copier Security



Did you know your digital copier or printer has a Hard Drive in it. Did you know all data printed, scanned, emailed, faxed or copied is stored on that Hard Drive and could potentially be accessed by a hacker after it leaves you company at the end of lease?

Sabtu, 20 Februari 2010

Feds file to halt Starwood-Hilton espionage lawsuit


usatoday.com
NEW YORK (AP) — Federal prosecutors have asked a court to halt a corporate espionage lawsuit between Starwood Hotels and Hilton, saying the litigation could compromise a criminal investigation.

The filing Friday by the U.S. Attorney's Office says it is pursuing possible charges of conspiracy, computer fraud, theft of trade secrets and interstate transportation of stolen goods against Hilton and two executives it hired away from Starwood.

Starwood claims the executives took confidential documents and that Hilton used them to develop a competitor to the W Hotels brand.

A judge must approve the government's motion.

More...

Kamis, 04 Februari 2010

Google Asks NSA to Help Secure Its Network


wired.com

Google is teaming up with the National Security Agency to investigate the recent hack attack against its network in a bid to prevent another assault, according to The Washington Post.

The internet search giant is working on an agreement with the controversial agency to determine the attacker’s methods and what Google can do to shore up its network.

Sources assured the Post that the deal does not mean the NSA will have access to users’ searches or e-mail communications and accounts. Nor will Google share proprietary data with the agency.

But the move is raising concerns among privacy and civil rights advocates.

The Electronic Privacy Information Center filed a Freedom of Information Act request on Thursday, shortly after the agreement was made public, seeking more information about the arrangement. (.pdf)

Selasa, 26 Januari 2010

Security specialist: USA made Google hack possible

h-online.com
Backdoors in internet services such email, social networks or the telephone network aren't just a counter-terrorism device for government agencies, they also open doors for cyber espionage and spamming attacks. This is the opinion of security expert Bruce Schneier expressed in a guest comment on the website of American TV broadcaster CNN.

Schneier says that, as an example, Chinese hackers reportedly used a backdoor in Google's Gmail service, created at the US government's request, to spy on political opponents. Such systems are almost an invitation to criminals to snoop on private internet communication and gain knowledge of information such as account or credit card details, said Schneier. The security expert lists further examples such as the intercepting of phone calls after the September 11 attacks and the mobile phone surveillance of members of the Greek government in 2004 and 2005.

More...

Rabu, 13 Januari 2010

New details in Chevy Chase spy case

gazette.net

The Chevy Chase scientist accused of attempted espionage may have impersonated a naval research official and stored classified information at his home, according to documents filed in federal court last week.

Stewart Nozette, 52, of the 100 block of Grafton Street in Chevy Chase Village demanded information on a classified national defense project from a Naval Research Laboratory official, Mark Johnson, claiming that he had "paid for it." The exchange took place when Nozette was working on the classified project at a Defense Department-affiliated laboratory in October 2002, according to an affidavit from an FBI agent seeking a search warrant of Nozette's home and vehicle on Oct. 16, 2009, just three days before Nozette was arrested and charged with attempted espionage.

More...
Related Posts Plugin for WordPress, Blogger...