Organic SEO Blog

231-922-9460 • Contact UsFree SEO Site Audit
Showing posts with label Online Security. Show all posts
Showing posts with label Online Security. Show all posts

Monday, April 16, 2012

Boeing Hires Hackers to Secure the Fort

Story first appeared in the Los Angeles Times.

Most weekdays a pair of college buddies ride their bikes to a computer center and try to hack into computer security systems belonging to Boeing Co. Rather than having them arrested, Boeing is paying them to do it — a situation that the car-loving, video-gaming friends have pronounced "awesome."

For two years, the young engineers have worked side by side in a secluded unit where they design and thoroughly test ironclad security systems for the largest aerospace company in the world. Boeing's systems need to be capable of staving off hackers and keeping safe some of the nation's most prized intellectual property.

Like many of their colleagues in surrounding cubicles, the friends spend much of their days devising, revising and analyzing complicated security programs that they then use their well-honed skills to attempt to crack.

The pair from Cal Poly Pomona were hired after they aced a cyber-security competition held by Boeing in which the aerospace giant urged students to consider careers in cyber security and, of course, scouted for fresh talent.

As computer threats become more coordinated and complex, Boeing and other defense contractors are bolstering their cyber-security staffs. Increasingly they are turning to unlikely characters, students who had distinguished themselves more on simulated cyber battlefields than in classrooms. As long as there are computers, there will be somebody trying to attack them.

The damage from hackers to consumers is well known, but the potential for corporate sabotage is far greater, and the need for cyber sleuths like those at Boeing is huge and growing.

Corporate computers serve thousands of employees engaging in different tasks and require layer upon layer of sophisticated security protection.

Those workers need access to the Internet. Although that access enables employees to get the information they need to do their jobs, it also opens a door for hackers to sneak through.

It's not just monolithic corporations at risk. Even small businesses are liable for lost or stolen data. Visa recently stated that 95% of credit card thefts originate at small businesses. Such liability has driven demand for cyber-security expertise.

A generation ago, the brightest engineers in the aerospace industry were typically recruited from Ivy League universities and other prestigious institutions. Now defense contractors are broadening the hiring pool as they hunt for savvy young computer whizzes at local colleges.

Raytheon Co.'s president of intelligence information systems businesses said last year at a conference that her company's most impressive cyber-security hires have come from outside of traditional recruiting outlets.

One recruit was a man who didn't have a college education and didn't graduate from high school. He had a GED and worked at a pharmaceutical plant stuffing pills into bottles.

At night, he participated in online hacker competitions and outperformed others. That person would have not gotten through the normal Raytheon recruiting process.


The Boeing cyber unit is a 3,000-square-foot room with cream-colored walls and floor-to-ceiling windows on a far wall that lets the afternoon sun stream in on row after row of slate-gray cubicles. The work space is a mini-fort of sorts, with 6-foot walls on four sides and small video cameras mounted near the entrance that enable team members to see who is coming their way. It resembles the chaos of a college dorm room. Inside, a tangle of computer wires lies on the floor and papers are strewn about on desks, along with a half-eaten burrito or two.

The techs there enjoy a world full of colorful terms to describe lurking computer threats.

They try to stop "Trojan horses," which enable a hacker to gain access to computers when people click on dangerous links.

They try to squash "worms" that replicate, spread and corrupt computer files.

And they fight "logic bombs" that hide in computers and delete files at a specific time.

Cyber-security professionals have identified tens of thousands of threats aimed at Microsoft Windows programs over the years. If Windows vulnerabilities are found on Boeing's security system, the hackers are responsible for fixing it.


With cyber security risks, if one employee makes a mistake — forgetting to download a security update or clicking a suspicious link — hackers may get all the access they need to cause trouble.

For example, an employee may receive an email with an attachment that appears to be an Excel spreadsheet but in reality is malicious software. Once opened, the file can embed a virus that will record and send back key strokes or other data, such as credit card numbers.

Boeing's cyber-security workers need to know how to counter that attack so even if the virus is launched it will not infect the system. They determine whether the newest, most harmful viruses — which when activated may damage or delete files, cause erratic system behavior, display messages or even erase data — would work on the system.

Boeing's cyber-security team can spend weeks prodding the system on a platform they designed called "cyber range in a box" that simulates the Internet without actually going live on it. They comb through the security system, seeing whether there are new ways to inject harmful code that would change the database content or dump information like credit card numbers or passwords to a hacker.

In this controlled environment, the team can apply what they learn in real-world situations.

Once they find security lapses within the systems, they plug them.


For more organic SEO and web optimization related news, visit the SEO Done Right blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.


Tuesday, October 19, 2010

More Questions for Facebook

The Wall Street Journal




Two House members asked Facebook Inc. for more details about the way applications on the social network handle user information, following revelations of new privacy concerns.

U.S. Reps. Edward Markey (D., Mass.) and Joe Barton (R., Texas) sent Facebook Chief Executive Mark Zuckerberg a letter expressing concerns that "third-party applications gathered and transmitted personally identifiable information about Facebook users and those users' friends." The two representatives are co-chairmen of the House Bipartisan Privacy Caucus.

Their letter follows an article in Monday's Wall Street Journal highlighting a potential privacy loophole in many of the most popular applications on Facebook. The Journal reported apps were transmitting identification numbers for users and their friends to dozens of advertising and Internet tracking companies. The ID numbers can be used to look up a user's real name, and sometimes other information users have made public, and potentially tie it to their activity inside the apps.

Given Facebook's 500 million users and the amount of information they post on the site, "this series of breaches of consumer privacy is a cause for concern," the lawmakers wrote.

The letter asked Mr. Zuckerberg how many users had been affected by the breach, when Facebook became aware of it, and what changes Facebook plans in order to deal with the problem, among other questions. Facebook must respond by Oct. 27.

In August, Reps. Markey and Barton requested information about data-collection practices from 15 websites identified by the Journal as installing the most tracking technology on visitors' computers.

A Facebook spokesman said the company looked forward "to addressing any confusion" and working with the congressmen. "The suggestion that the passing of a user ID to an application, as described in Facebook's privacy policy, constitutes a 'breach' is curious at best," he said.

In a blog post Sunday night, Facebook executive Mike Vernal said that passing along user IDs violated the company's policies. "In most cases, developers did not intend to pass this information, but did so because of the technical details of how browsers work," he wrote.

Still, he said Facebook was "committed to ensuring that even the inadvertent passing of (user IDs) is prevented and all applications are in compliance with our policy."

Mr. Vernal played down the potential risks, writing that knowing a user's ID "does not enable anyone to access private user information without explicit user consent."

Privacy watchdogs called on Facebook to improve privacy controls regarding applications. "Facebook needs to stop addressing this problem with secret 'policy enforcement' and start putting choices and control" in users' hands, wrote Chris Conley, a fellow at the American Civil Liberties Union of Northern California.

At least some of the apps that Facebook shut down after Journal queries into privacy breaches were reinstated by Monday.

"We're back!" wrote Arjun Sethi, the CEO of LOLapps Media Inc., in a blog post. LOLapps makes applications like Gift Creator, which has 3.5 million monthly active users. His company's apps were shut down Friday, after the Journal had found that some LOLapps applications were transmitting users' Facebook ID numbers to a company called RapLeaf Inc., which then sent them with other personal details to a dozen other advertising and data firms. RapLeaf said the transmission was inadvertent.

LOLapps' Mr. Sethi said the company didn't intend to pass along user IDs. He didn't say that the problem was what led to the apps being shut down.

He also wrote that LOLapps had "immediately dissolved" the relationship that had caused it to run afoul of Facebook. He didn't specify whether that relationship was with RapLeaf.

Thursday, September 23, 2010

Twitter Hack opens Pop-ups, Wreaks Havoc

Associated Press

Twitter Security Flaws - Web Clutter Portal becoming favorite target of hackers

A new way to cause mischief quickly spread through short-messaging service Twitter on Tuesday morning before the site could fix the problem, as mysterious "tweets" of blocked-out text propagated themselves and caused popup windows to open.

Shortly before 10 a.m. Eastern time, (1400 GMT), Twitter said on its "safety" feed on the site that the attack had been shut down. It also said it does not believe that any user information was compromised, rather, the "vast majority" of the breaches were pranks or promotions.

The hack had been extra nefarious because the tweets activated without being clicked on - it was enough for Web surfers to move their mouse cursors over them. But it only affected visitors to Twitter.com. Various third-party programs used to send and read tweets, such as Tweetdeck, were unaffected.

The popups could, though didn't necessarily, contain malicious code that could take over poorly protected computers. The White House's official Twitter feed - followed by 1.8 million users - was among those affected, though the offending message was quickly taken down.

Fittingly for Twitter, which limits messages to just 140 characters, the virus may have been among the shortest on record. According to security software maker F-Secure Corp., the shortest virus so far was just 22 characters long.

Twitter said in a blog post it was notified of the security breach at 5:54 a.m. Eastern time. The problem was caused by something called "cross-site scripting." This allowed users to run JavaScript programs on others' computers, turning tweets different colors or causing the pop-up boxes to appear. Some users, Twitter added, took things a step further and included code that got people's accounts to re-tweet the messages without their knowledge.

"It was like a massive snowball fight that got out of control," said Ray Dickenson, chief technology officer at computer security firm SafeCentral.

But while the effects of Tuesday's mischief were very visible - such as the pop-ups - and playful, Dickenson said that he was worried because JavaScript can quietly do more malicious things, like sending people to sites that can infect computers.

Security breaches had been common in Twitter's early days, but the company has since worked to beef up its vigilance and the problems have become less common. Tuesday's hack coincided with Twitter's ongoing rollout of a redesign of its website, which tries to streamline users' Twitter feeds and make it easier to see photos and videos directly on the site, without having to click on a link to YouTube or Flickr.

Twitter said it discovered and fixed this problem last month, and that a recent site update unrelated to the redesign was responsible for its return.

Wednesday, September 08, 2010

Microsoft Obtains Legal Might to Fight Spamming Botnets

USA Today

 
SEATTLE — With a judicial assist, Microsoft has perfected a new superweapon to shoot down botnets, the engines cybergangs use to deliver malicious Internet attacks.

The U.S. District Court of Eastern Virginia last week granted a motion that, in effect, gives Microsoft permanent ownership of 276 Web domains once used by the Waledac cybergang to send instructions to hundreds of thousands of spam-spreading PCs.

Cybersleuths and attorneys at Microsoft's digital crimes unit actually decapitated the Waledac botnet in February by persuading District Court Judge Leonie Brinkema to issue a temporary restraining order to take the 276 domains offline.

Brinkema's order was unusual because the owner of the domains could not be reached and thus did not have a day in court to protest, says Microsoft senior attorney Richard Boscovich Sr.

With permanent ownership of the domains, Microsoft now has a proven legal means to take aim at U.S.-registered domains — including .com, .net, .biz and .org domains — shown to be conducting criminal activity. "It's open season on botnets," says Boscovich. "The hunting licenses have been handed out, and we're coming back for more."

The Waledac botnet was a major source of spam and PC infections, at its peak in 2009 delivering 1.5 billion spam messages daily. Microsoft added detection and filtering for Waledac infections to its free malicious software removal tool. But cleaning infected PCs one by one did not stop the command PCs.

By December, Microsoft Hotmail accounts were getting swamped with more than 650 million e-mail spam messages sent out by Waledac. That helped motivate the company to pursue a court order to shut down the command domains.

Even after the botnet's command center got knocked out, tens of thousands of infected PCs continued trying to phone home for instructions. Internet service provider Cox Communications has contacted several hundred of its subscribers by phone to guide them to Microsoft's free cleanup tool.

Lingering Waledac infections pose a risk, says Jason Zabek, safety manager at Cox. "You never know if something else will pop up to try to use it," he says.

Indeed, Microsoft in one recent seven-day period counted 58,000 PCs attempting 14.6 million connections to the 276 Waledac domains it now owns. The company advises using its free Security Essentials program, which will clean up Waledac and many other infections. Meanwhile, it is back at the hunt. "There are dozens of major botnets and hundreds of smaller ones," says T.J. Campana, Microsoft senior program manager. "Botnets remain the backbone of criminal activity."

Thursday, August 19, 2010

Cameron Diaz Tops List of Riskiest Celeb Searches

Associated Press

If you're looking for Cameron Diaz, Julia Roberts or Jessica Biel online, look out!

The movie stars top the latest list of the most dangerous celebrities to search for online, according to new research by computer-security software maker McAfee Inc.

It's far from an Oscar, but landing atop McAfee's annual list carries a distinction all its own: It means that criminals believe those celebs are the perfect lures to sucker people into visiting malicious websites.

Clicking onto strange sites is sketchy to begin with. But many people do, and their computers get infected. Once a computer is infected, criminals can steal victims' online banking passwords, e-mail passwords, and do other kinds of nasty deeds.

Wednesday, August 04, 2010

Personal Details Exposed Via Biggest U.S. Websites

The Wall Street Journal

The largest U.S. websites are installing new and intrusive consumer-tracking technologies on the computers of people visiting their sites—in some cases, more than 100 tracking tools at a time—a Wall Street Journal investigation has found.

The tracking files represent the leading edge of a lightly regulated, emerging industry of data-gatherers who are in effect establishing a new business model for the Internet: one based on intensive surveillance of people to sell data about, and predictions of, their interests and activities, in real time.

The Journal's study shows the extent to which Web users are in effect exchanging personal data for the broad access to information and services that is a defining feature of the Internet.

In an effort to quantify the reach and sophistication of the tracking industry, the Journal examined the 50 most popular websites in the U.S. to measure the quantity and capabilities of the "cookies," "beacons" and other trackers installed on a visitor's computer by each site. Together, the 50 sites account for roughly 40% of U.S. page-views.

The 50 sites installed a total of 3,180 tracking files on a test computer used to conduct the study. Only one site, the encyclopedia Wikipedia.org, installed none. Twelve sites, including IAC/InterActive Corp.'s Dictionary.com, Comcast Corp.'s Comcast.net and Microsoft Corp.'s MSN.com, installed more than 100 tracking tools apiece in the course of the Journal's test.

The Journal also surveyed its own site, WSJ.com, which doesn't rank among the top 50 by visitors. WSJ.com installed 60 tracking files, slightly below the 64 average for the top 50 sites.

Some two-thirds of the tracking tools installed—2,224—came from 131 companies that, for the most part, are in the business of following Internet users to create rich databases of consumer profiles that can be sold. The companies that placed the most such tools were Google Inc., Microsoft. and Quantcast Corp., all of which are in the business of targeting ads at people online.

Google, Microsoft and Quantcast all said they don't track individuals by name and offer Internet users a way to remove themselves from their tracking networks. Comcast, MSN and Dictionary.com said they disclose tracking practices in their privacy policies, and said their visitors aren't identified by name.

The state of the art is growing increasingly intrusive, the Journal found. Some tracking files can record a person's keystrokes online and then transmit the text to a data-gathering company that analyzes it for content, tone and clues to a person's social connections. Other tracking files can re-spawn trackers that a person may have deleted.

To measure the sensitivity of the data gathered by tracking companies, the Journal created an "exposure index" for the top 50 sites. Dictionary.com ranked highest in exposing users to potentially aggressive surveillance: It installed 168 tracking tools that didn't let users decline to be tracked, and 121 tools that, according to their privacy statements, don't rule out collecting financial or health data. Dictionary.com attributed the number of tools to its use of many different ad networks, each of which puts tools on its site.

Some of the tracking files identified by the Journal were so detailed that they verged on being anonymous in name only. They enabled data-gathering companies to build personal profiles that could include age, gender, race, zip code, income, marital status and health concerns, along with recent purchases and favorite TV shows and movies.

The ad industry says tracking doesn't violate anyone's privacy because the data sold doesn't identify people by name, and the tracking activity is disclosed in privacy policies. And while many companies are involved in collecting, analyzing and selling the data, they provide a useful service by raising the chance Internet users see ads and information relevant to them personally.

"We are delivering free content to consumers," says Mike Zaneis, vice president of public policy for the Interactive Advertising Bureau, a trade group of advertisers and publishers. "Sometimes it means that we get involved in a very complex ecosystem with lots of third parties."

The growing use and power of tracking technology have begun to raise regulatory concerns. Congress is considering laws to limit tracking. The Federal Trade Commission is developing privacy guidelines for the industry.

If "you were in the Gap, and the sales associate said to you, 'OK, from now on, since you shopped here today, we are going to follow you around the mall and view your consumer transactions,' no person would ever agree to that," Sen. George LeMieux, R-Florida, said this week in a Senate hearing on Internet privacy.

Tuesday, August 03, 2010

The Internet Illuminati: Seven Hold Keys to the Digital Universe

CNBC

 
It’s a story straight out of a Dan Brown novel: Seven people from across the globe have been chosen to hold the keys to the Internet.

The key holders are from the U.S., U.K., Burkina Faso, Trinidad and Tobago, Canada, China and the Czech Republic, ensuring that no one person — or nation — will hold all the power.

In the event of a terrorist or other attack on the Internet, the key holders will be flown to an undisclosed location in the U.S. Each key contains a fragment. If at least five are united, they will form a master key that can restore the Internet.

(That’s a smart move: If the law of inviting people to parties holds true, you never know when two of the seven will have prior commitments and can’t make it to save the Internet — and civilization as we know it.)

Of course, the geeks who created this Domain Name Security System tapped into all of their sci-fi skillz to make the announcement dramatic:

“More has happened here today than meets the eye,” said Vinton Cerf, a former program manager with the Department of Defense who’s now with Google and goes by the galactic street name of “Father of the Internet.” “An infrastructure has been created for a hierarchical security system which can be purposed and repurposed in a number of different ways,” he said, practically writing the Hollywood script.

But, like all good secret society plots, there are more questions than answers, such as:

    *      Why Burkina Faso?
    *      Trinidad & Tobago—really?
    *      Would you be able to get a direct flight from either of those countries to the undisclosed US location in the event of global emergency?
    *      Will these people have other jobs, or is their permanent job now Holder of the Key to the Internet?
    *      Where do you keep a key to the Internet—in the ice box? Digitally implanted in your neck?
    *      Do you have to stop skydiving, showering during thunderstorms and other risky behavior after you become a Holder of the Key to the Internet?
    *      What happens if you lose your key to the Internet? Can you give a backup to that nice old lady next door just in case?

Each key is made in a “cryptographic box,” which sounds thrilling, but the illuminat-ous gleam starts to fade when you take a look at what one of the actual keys looks like: It’s like that flimsy cardboard emergency-contact card you get free with a new wallet. My New Jersey driver’s license is more futuristic with its wall of holographic seals that protect mini-me.

And, while you might have been expecting that the Knighting of the Key Holders as Spielberg will write it (or, Trusted Community Representatives, as they’re actually, nerdily called) would be some dramatic secret ceremony involving hooded robes and chanting, they were actually handed their keys in a plastic, tamper-proof evidence bag.

Sci-Fi boys, you disappoint me. After all the secret levers in the ancient stone wall and glitches in the space-time continuum we’ve been through, you give me an emergency-contact card in a Ziploc.

Still, some could not resist the urge to romanticize this intriguing tale of power and codes.

“I'd be honored to have that kind of Internet rock-star status!” said Alyx Kaczuwka, author of the blog LOLFed.com. “ I'd plate the key in gold and wear it around my neck on a big gold chain, and hire people from various Internet memes to be my bodyguards,” she quipped.

Of course, if you were one of the chosen ones, you’d have to give up your Facebook page, in the name of national—sorry, GLOBAL—security, points out Joshua Brown, a VP at Fusion Analytics and the author of the blog TheReformedBroker.com.

We don’t know who all of the seven are, but the BBC reports that Paul Kane of the University of Bath’s SETsquared Innovation Centre is the delegate from western Europe.

"I'm honoured and excited to be recognised," Kane said in a way that only a British businessman can.

Brown suggests that Snooki or The Situation from the show “Jersey Shore” might also be a good choice—no one would ever suspect them. The secret location could be a bar in Seaside Heights, N.J.—and the code could be GTL (gym, tanning, laundry)!

Comedian Harrison Greenbaum agrees: “I would hide my key in something a nerdy cyberterrorist would never be able to find—like a girlfriend!"

Someone get Megan Fox on the horn, we’ve got a movie to make!

The stars are twinkling in the sky as the words start to slowly scroll up the screen and an announcer says in a deep voice:

In a world … where seven people are handed the keys to the Internet … in a Ziploc baggie …

The nation’s very security hangs in the balance ...

Will they be able to save David After Dentist, Keyboard Cat and all of the Internet Universe?

It will be the challenge of their lives for they are ... THE CHOSEN SEVEN.


Illuminati Treats:

Google Predicts the Future. You knew that Google Earth in all of its invasive glory was only a peek through the portal of what was to come. And now, Google is teaming up with the CIA to predict the future.

Thomas’s English Secrets. Apparently only seven people (there they go again with that number seven!) know the secret recipe for making all the nooks and crannies in Thomas’s English Muffins. A judge ruled one of the seven can’t go work for a rival.

Sunday, June 27, 2010

U.S. Unveils Plan to Make Online Transactions Safer
Associated Press

 
In the murky world of the Internet, how do you ever really know who you're talking to, who you're buying from or if your bank can actually tell it's you when you log in to pay a bill?

Amid growing instances of identity theft, bank account breaches and sophisticated Internet scams, the government is looking for ways to make those transactions in cyberspace more secure.

But officials must tread carefully, as efforts to create identity cards, personal certificates or other systems of identifiers raise privacy worries and fears of Big Brother tracking its citizens online.

In a draft plan released Friday, the White House laid out an argument for a yet-undeveloped, voluntary identification system and set up a website to gather input from experts and everyday Internet users on how it should be structured.

The website was already getting votes, snipes and suggestions Friday afternoon - underscoring the incendiary nature of any discussion of Internet regulation or formal structure.

"The technology that has brought many benefits to our society and has empowered us to do so much has also empowered those who are driven to cause harm," said White House cyber coordinator Howard Schmidt in a blog posting Friday outlining the need for better security online.

The plan, he said, envisions a future in which people would be able to get a secure identifier - such as a smart identity card or a digital certificate - from a variety of service providers. Customers could then use the card or identifier to prove who they are as they make their online transactions.

"Digital authentication has been the holy grail of Internet security policy since the early '90s," said James Lewis, cyber security expert and senior fellow at the Washington-based Center for Strategic and International Studies. This latest effort, he said, has a better chance of succeeding than previous tries, "but we need to see how much opposition it runs into and whether people will actually use it even if it gets deployed."

Ari Schwartz, vice president at the Center for Democracy and Technology, said the unfettered openness of the Internet is what allowed it to grow and prosper but also created security gaps that need to be addressed. But any move to improve identity systems raises many concerns.

"The whole thing is very difficult to do and privacy is one of the more difficult pieces of it," said Schwartz, adding that the system has to balance efforts to maintain privacy while still finding out enough about someone to ensure his identity.

The government, he said, is correct to try to plan ways to move toward better security, rather than letting it just happen with no coordination.

But cyber security experts also argued that the technologies for creating such identifiers already exist and are already used in different ways by businesses, particularly banks.

"The vision they put forth is already realized and commercially available," said Roger Thornton, a cyber security expert and chief technology officer for California-based Fortify Software.

He noted that banks already use sophisticated fingerprinting processes to identify a customer who signs in. The system knows if a customer is using a different computer and will often require additional identification if that computer has not been used for the banking website before.

But many companies don't bother with the more expensive or complex identification systems.

So, said Thornton, "the opportunity is there to make things more interoperable and more uniform."

The draft plan is part of an administration effort to promote cyber security both within the government and among society as a whole. Lawmakers have introduced a number of bills aimed at furthering those goals, and the White House plan was met with initial support from one of the authors of Senate computer security legislation.

Monday, June 07, 2010

Google Dropping Windows Over Security? Good Luck With That
PC World

 
Sources from within Google are claiming that the online search and advertising giant is implementing an official transition away from the Microsoft Windows operating system. According to the reports, the culture shift is intended to reduce security concerns. That makes a compelling headline--especially for a Microsoft rival developing its own operating system--but it doesn't make a very good security strategy.

On one level, it makes perfect sense for Google to abandon Windows. Google has always been a bitter rival of Microsoft, and Google's Android mobile operating system and upcoming Chrome operating system are built on Linux. Of course Google should avoid generating additional revenue for Microsoft and rely on the platform that forms the foundation of what Google expects its customers to use.

Another area where Google should eat its own proverbial dog food is with Web browsers. The Chrome Web browser has been gaining market share since its launch, but it was a zero-day flaw in Microsoft's Internet Explorer Web browser that was exploited to compromise systems and steal data from Google earlier this year. With the exception of key developers that might need to see how things render in IE, users at Google should ostensibly not be using the competing browser.

That brings us to the claim that security concerns are behind the move to abandon Windows. The reports suggest that Google has banned the use of Windows in response to the Operation Aurora attacks which Google alleged were state-sponsored attacks from the Chinese government.

The flaw in that logic is that it assumes the attacker would be unable to compromise alternative platforms like Linux or Mac OS X. Microsoft Windows--by virtue of its dominant market share--is the target of the vast majority of general malware attacks, so switching from Windows may reduce the daily operational risks. But, when it comes to precision, targeted attacks, alternative OS platforms don't provide any better defense so dropping Windows would not have prevented the Operation Aurora attacks.

In fact, alternative platforms may arguably make a precision attack that much easier. The Mac OS X platform has an illusion of superior security because malware developers don't care to invest time and resources developing exploits that only work on five percent of the possible targets. However, year after year Mac OS X is compromised in a matter of minutes--or even seconds--in the annual Pwn2Own contest.

Before Google decides to base its security strategy on which operating system platform it relies on, the Google management and IT administrators should read the venerable information security classic Hacking Exposed--currently in its sixth edition. The first step to an attack is gathering details of the intended target--or footprinting.

Hacking Exposed explains that "The systematic and methodical footprinting of an organization enables attackers to create a near complete profile of an organization's security posture." The bottom line is that Google can use whatever operating system, Web browser, or other applications it chooses, but a professional attack will learn what those are during reconnaissance and design the attack accordingly to exploit whatever software Google is using.

I asked George Kurtz, Worldwide CTO for McAfee, his thoughts. Kurtz explains "Just moving operating systems doesn't always mean an organization will realize greater protection against TARGETED attacks. It certainly could make a difference in reducing the amount of day to day malware that impacts a windows environment. One point that might be worth mentioning is that while targeted attacks can be launched against any OS, there is a tremendous amount of expertise gained over the past five to seven years against the Windows environment. It will take a similar maturation period to develop tools that are just as sophisticated as the Windows environment for say OS X. Things like rootkits and their associated functionality are incredibly sophisticated and relatively mature in the Windows world."

Randy Abrams, Director of Technical Education for ESET, says "The Google response is a marketing / public relations response to attempt to show Google is doing something about security by blaming Microsoft for Google's own patch management and security problems. What were they thinking by running an outdated version of IE 6?"

Abrams agrees "In a targeted attack, the OS is no longer a significant issue. Not only is the OS an attack vector, but installed third-party apps are another attack vector. If an attacker knows your OS and goes after an Adobe flaw, the game still ends up with you on the losing end."

Kurtz added "Layer 8 is generally the biggest security challenge we have. The same people who fall victim to social engineering will do so via e-mail or IM, no matter what browser or OS they are using."

ESET's Abrams sums up with "Google would do much more to improve its security by using current versions of browsers and ensuring greater patch management practices."

Every organization should abandon IE6 and be seriously exploring a transition from Windows XP. Each has inherent security concerns, and the combination of the two almost begs to be hacked. And, Google in particular has valid reasons to abandon Windows and Internet Explorer that go well beyond security.

But, Google needs to remember that it's Google. It is a jackpot of sensitive data and information for a successful attacker. Google needs to understand the nature of targeted attacks and have a better security policy than simply a knee-jerk reaction to ban Microsoft software.
Microsoft to Google: You're not Exactly Safe Yourself
PC World

 
It looks like Microsoft isn't too pleased with Tuesday's rumors that Google will stop using Windows internally due to security vulnerabilities in the OS. Google reportedly will switch to more secure operating systems, including the Mac OS, Linux, and Google's upcoming Chrome OS, according to the Financial Times.

Microsoft's response: Our security is better than you think, and yours really isn't so great if you look closely enough.

A Tuesday post on The Windows Blog by Microsoft's Brandon LeBlanc defends Redmond's honor in the ongoing security debate. He asserts that when it comes to thwarting malware, Microsoft has stepped up its once sorry game.

"When it comes to security, even hackers admit we're doing a better job making our products more secure than anyone else. And it's not just the hackers; third party influentials and industry leaders like Cisco tell us regularly that our focus and investment continues to surpass others," LeBlanc writes.

Microsoft's more recent security improvements include frequent software updates via Windows Update and Microsoft Update, many of which are pushed to users automatically; BitLocker disc encryption improvements in Windows 7; and various security enhancements in Internet Explorer 8, including the SmartScreen filter to thwart malware and phishing attempts online.

Google, Apple Diss


LeBlanc also accuses Google of being a tad hypocritical about security. He links to a Mashable story from March that states that Yale University had delayed switching to Google's Gmail due to security concerns. "There is some irony here that is hard to overlook," he writes.

Apple gets the treatment too. LeBlanc points to an InfoWorld article that discusses how the Mac's growing popularity may make it (and other Apple devices) more appealing targets for hackers.

LeBlanc's points are valid, and certainly no operating system is 100-percent secure. And it's also possible that Google's alleged plan to dump Windows internally--a report that didn't originate from an official company source--may be a sneaky PR stunt to trumpet the security strengths of Google's Windows competitors, Android and Chrome.

That said, Microsoft has no one to blame but itself for its bad security rap. Indeed, past versions of Windows and Internet Explorer were a hacker's dream. And even if Redmond has changed its security-deficient ways, its competitors are bound to exploit its malware-friendly image.

Thursday, May 20, 2010

Symantec to Purchase VeriSign's Web-Security Arm
Associated Press

 
Symantec Corp.'s decision to pay $1.28 billion to buy a division of VeriSign Inc. that sells security technology to websites highlights how quickly the companies are moving in opposite directions.

Symantec, best known for its antivirus software for personal computers, wants to secure more things.

With the VeriSign deal, announced Wednesday, Symantec will have spent nearly $3 billion in two years acquiring technologies that make it a bigger player in other parts of the security market, such as protecting data on mobile phones and delivering software over the Internet.

Meanwhile, VeriSign, whose brand is ubiquitous on the Web for protecting online transactions, wants to secure fewer things.

It wants to focus instead on a lesser-known but more robust part of its business: managing traffic to websites with addresses ending in ".com" and ".net," and collecting fees for registering those domain names.

VeriSign has been purging divisions for the past three years, after realizing it was spread too thin following a buying binge designed to insulate it from the kinds of problems it had after the dot-com collapse a decade ago.

Prior to Wednesday's deal with Symantec, VeriSign had sold more than a dozen businesses since 2007 for a total of nearly $1 billion. Some were curious choices for VeriSign to have in the first place, such as a division that did billing services for telecommunications companies and another that sold ring tones and insurance for mobile phones.

What Symantec gets out of the VeriSign deal is one of the Web's best-known brand names for security.

VeriSign's logo - a check mark and the tag "VeriSign Secured" - is ubiquitous on websites that have bought its security technology. The VeriSign division that Symantec is buying sells "certificates" to websites that want protection for their customers' data. The Secure Sockets Layer, or SSL, certificates allow data to be encrypted between a user's browser and a website's servers. A padlock icon appears on a user's browser when that technology is being used.

The certificate business has long been a cornerstone for VeriSign, but has come under pressure in recent years.

In part, that's because cheap SSL certificates sold by other companies are easy to come by. The competition has forced VeriSign to sell more of its cheaper SSL certificates, too, even though their security measures are weaker.

Revenue in that division rose just 3 percent last year to $410 million, while revenue in VeriSign's domain-name division jumped 12 percent to $616 million.

Still, at the end of last year, more than 1 million sites were using VeriSign's SSL certificates, making the business an attractive target for a company such as Symantec looking to extend its brand.

The deal is expected to close in the September quarter. Symantec said it expects the transaction to reduce its adjusted earnings by 9 cents per share for the current fiscal year. It won't add to adjusted profit until the September quarter of next year.

The business VeriSign is left with is a lucrative one, but whose weakness following the dot-com collapse was a key reason VeriSign went on a tear with its acquisitions.

VeriSign is critical in steering Internet traffic to ".com" and ".net" Web sites. Its directories help Internet computers locate websites and know where to send e-mail.

The company makes its money by collecting a fee every time someone registers or renews a domain name ending in ".com" or ".net." Although Web site owners buy names through third parties, VeriSign gets fees as operator of the ".com" and ".net" registries.

Those fees generally go up each year, and as of July 1 will be $7.34 per ".com" name and $4.65 per ".net" name. Those fees add up with some 85 million ".com" names and 13 million ".net" names registered - and they account for the bulk of revenue in the domain-name division.

Symantec shares were up 2 cents in extended trading. They had fallen 32 cents, or 2 percent, to close the regular trading session at $15.63. VeriSign shares rose 83 cents, or 3 percent, to $28.82 in extended trading, after falling 24 cents to close at $27.99.

Both companies are based in Mountain View, Calif.

Sunday, May 09, 2010

Recent Examples of Internet 'Hijackings'
Associated Press

Some instances of Internet outages caused by hijacked traffic, as listed by the Department of Homeland Security and other sources:

April 1997: MAI Network Services, an Internet service provider in Virginia, passes bad routing information to Sprint, which relays it, causing widespread outages.

April 1998: An Israeli ISP causes widespread outages.

December 1999: AT&T's server network is hijacked by another ISP.

May 2000: Sprint addresses hijacked by another ISP.

April 2001: Global Internet carrier Flag Telecom hijacks routes.

December 2004: Turk Telekom, a Turkish ISP, hijacks much of the Internet on Christmas Eve.

September 2005: AT&T, XO and BellSouth traffic is misdirected to Bolivia. The next day, it's sent to Germany instead.

January 2006: Traffic from several U.S. ISPs hijacked by a telecommunications unit of Con Edison in New York.

February 2008: Pakistan Telecom hijacks YouTube, affecting much of the world.

April 2010: China Telecom, the country's largest ISP, hijacks the Internet, causing outages spreading to Europe and the U.S.

Monday, April 26, 2010

Blippy Debit Card Numbers Still Appearing in Google
San Francisco Chronicle

Blippy, the social network for people who want to publicize their purchases, got in big trouble yesterday for publishing some of its users credit card numbers. But by mid-afternoon, Blippy had announced the problem was taken care of and that the situation was "a lot less bad than it looks."

Well, it still looks really bad.

With the help of an SAI reader, we found Blippy was still making at least one debit card number available to scamsters Google searching for the terms "site:blippy.com +outstanding." We've pasted a screenshot below.

A Blippy spokesperson agreed with us yesterday that these kinds of privacy mistakes are a "nightmare scenario" for Blippy.

Rationale people would assume that two days of publishing user's credit card and debit card numbers would be death blow for a social network designed for people who want to publish the purchasing history.

We're not so certain. The very fact that anybody uses Blippy, even before this week's cluster, suggests to us that there are lots of people with very little concern for their privacy. Some people would even suggest those types are just being realists, that any sense of privacy on the Internet is an illusion anyway.

The reader who spotted this info asked us not to use his name. We asked him if he was associated with Blippy or any of its competitors. He told us, "no connections whatsoever beside being a user."

"I just don't want problems with authorities because of the credit card numbers or anything. I don't think its a felony since it's google publishing this information but I wouldn't want to worry like the guy who sold the iphone 4g you know!"

Monday, February 22, 2010

Hack Attacks and Technical Snafus at Facebook and Twitter


NEW YORK (AP) - Facebook users have been complaining about problems at the social media site.

Users in the U.S. and other countries reported problems beginning Saturday morning. Some could not log in, and the site was unusually slow and glitchy for others. Users in London, Bangkok and Mexico City reported problems. Many used Twitter to complain.

Facebook spokesman Matt Hicks said it was a "small percentage of users" who had problems accessing Facebook, their friends' profiles or specific site features because of an isolated server problem.

At 6 p.m. Saturday, Facebook said it had restored access to the users who were having access problems.

Facebook, which has more than 100 million users, has occasionally experienced such hiccups. Twitter has had bigger problems. Last August, hackers shut down the short messaging service for several hours. Facebook also experienced problems, though it was never shut down completely.

Friday, February 19, 2010

Corporations, Agencies Infiltrated by Botnet
AP

SAN FRANCISCO (AP) - Security experts have found a network of 74,000 virus-infected computers that stole information from inside corporations and government agencies. The unusual thing about the incident is not that it happened but that it was discovered, and it is a reminder of the dangers of having computers with sensitive data connected to the open Internet.

More than 2,400 organizations, including financial institutions and energy companies and federal agencies, were infiltrated by the "botnet," according to the NetWitness Corp. security firm, which discovered it.

NetWitness didn't name the companies or agencies whose computers were compromised. The Wall Street Journal said the affected companies included Merck & Co., Cardinal Health Inc., Paramount Pictures and Juniper Networks Inc. Merck and Cardinal Health said in statements Thursday that one computer in each company was among those in the botnet but no sensitive information was taken. The other two companies didn't return messages from The Associated Press seeking comment Thursday.

The victims don't appear to have been specifically targeted, unlike the recent computer attacks on Google Inc. that prompted the Internet search leader to threaten to pull its business out of China. That's an important distinction, because it shows how online secrets can fall into the wrong hands even when criminals aren't necessarily looking for them.

"This kind of stuff is out there and it's pervasive," said Amit Yoran, CEO of NetWitness and former cybersecurity chief at the U.S. Department of Homeland Security. Parts of the botnet discovered by his firm likely are still active. He said the network appears to be run from computers in Eastern Europe and China, but it's not certain the perpetrators are there.

Botnets are networks of poisoned PCs that are remotely controlled by hackers and behave like their criminal robots. The PCs are often infected when their owners visit bad Web sites or open malicious e-mail attachments.

Botnets are a major tool for cybercrime. They help criminals amass troves of stolen data that they can sell on the black market or use for their own schemes, such as yanking money from victims' bank accounts.

The biggest on record is the one created by the Conficker worm. That infected anywhere from 3 million to 12 million PCs running Microsoft Corp.'s Windows operating system and is still active.

The botnet NetWitness discovered used malicious software called "ZeuS" that steals passwords and other online credentials. It's primarily focused on poaching Internet banking credentials and is well known in the security community.

The fact that so many companies and government agencies were hit generally appears to have been incidental. Yoran said the attackers were targeting specific information rather than specific organizations.

Still, they were very successful, snatching more than 68,000 credentials over four weeks. Most of those credentials were login details for Facebook and Yahoo and other personal e-mail services. On the face of it those aren't the most sensitive pieces of information, but they can hold the keys to unlocking other types of online accounts and private data.

Security experts who weren't part of the NetWitness report said the findings illustrate the growing risk from the ZeuS software, whose authors are constantly updating it to evade detection by antivirus software and other security measures.

Don Jackson, researcher with the Counter Threat Unit of SecureWorks, said millions of computers are infected with ZeuS. Perhaps half a million of those are being milked by professional operators running the latest versions of the software.

He said the botnet NetWitness found was a "major threat" but added that the criminals behind it appeared to be using an older version of the software that is easier to detect.

"There are dozens of these types of operations ongoing every day that just aren't named," he said.

A bigger concern, Jackson said, is a new version of ZeuS that has appeared in the last few months and is more powerful and even harder to detect.

One of its features is that it gives a hacker the ability to conduct financial transactions directly from a compromised computer. Otherwise the criminal would have to steal the login credentials and use them on another computer. Some banks have put up extra security measures to detect and stop that.

Thursday, January 28, 2010

Social Media Security Flaws Haunting The Internet
Scandals, Probes, Hacks
Social Sites Creating Huge Headaches Worldwide
Canada Privacy Office Launches New Facebook Probe

AP


Canada's privacy commissioner is once again probing Facebook over the online social network's privacy policies.

The Privacy Commissioner of Canada said Wednesday it is investigating a complaint from a Facebook user over changes the company introduced in December.

The announcement came just five months after Facebook agreed to give users more control over the information they share with outside applications such as games and quizzes in response to concerns raised by Canadian privacy officials.

The latest complaints stem from changes Facebook made to give users more granular controls over what information is shared with others, while pushing users to be more open.

The complaint alleges that Facebook's new, "default" settings made more information exposed than the user had previously intended. Facebook insists those settings were merely recommendations.

Elizabeth Denham, the assistant privacy commissioner, said some Facebook users have been disappointed at changes that were supposed to improve protection of their personal information.

Facebook, which is based in Palo Alto, Calif., said it has not seen the complaint but it is confident that its process last month was "consistent with user expectations, and within the law."

In the U.S., the Electronic Privacy Information Center and nine other organizations have also filed a complaint with the Federal Trade Commission over last month's changes.