Showing posts with label pc security. Show all posts
Showing posts with label pc security. Show all posts
Friday, April 29, 2016
SECURITY - eMail Domains
I just have to comment on paying attention to the domains you receive eMail from.
I got an eMail reminding me 'to confirm your account' on a site I never heard of.
The domain was "@zainiraq.net"
IRAQ.net!
Ya, like that's a safe site, .....NOT.
You need to pay close attention to eMail domains when the eMail looks suspicious or from a site you never heard of.
Suspicious eMail may even claim to be from a site you do deal with. I and an eMail that claimed to be from AARP but the text didn't look right, it was from a domain ending in ".top"
If you get eMail that does look like it's from a site you deal with but has a link to update you account info, DO NOT use the link in the eMail. If you deal with the site, you should have it bookmarked in your browser, use that to access the site. Also, many sites will have a Support contact, you should copy the eMail and Headers, and paste that into their message system so they know someone is trying to spoof them.
All suspicious eMail domains should be added to your SPAM filter. In my case, my eMail provider has a very good system for that. Then your eMail client should also have a way to filter eMail domains.
I got an eMail reminding me 'to confirm your account' on a site I never heard of.
The domain was "@zainiraq.net"
IRAQ.net!
Ya, like that's a safe site, .....NOT.
You need to pay close attention to eMail domains when the eMail looks suspicious or from a site you never heard of.
Suspicious eMail may even claim to be from a site you do deal with. I and an eMail that claimed to be from AARP but the text didn't look right, it was from a domain ending in ".top"
If you get eMail that does look like it's from a site you deal with but has a link to update you account info, DO NOT use the link in the eMail. If you deal with the site, you should have it bookmarked in your browser, use that to access the site. Also, many sites will have a Support contact, you should copy the eMail and Headers, and paste that into their message system so they know someone is trying to spoof them.
All suspicious eMail domains should be added to your SPAM filter. In my case, my eMail provider has a very good system for that. Then your eMail client should also have a way to filter eMail domains.
Labels:
data security,
email security,
pc security
Wednesday, March 23, 2016
SECURITY - ESET Smart Security
Due to the proliferation of ransomware, as a previous article points out, I have decided that I (and everyone else) need better protection. I have been using ESET NOD32 AntiVirus for years and is excellent for what it does do.
Better protection is provided by ESET Smart Security. The following screenshots show some of the features:
Banking & Payment protection:
This is one of the best features. You add the domains for all banking and payment sites (PayPal, banks, credit card, etc) you use and select [Secured browser] and ESET Smart Security provides enhanced protections for those sites in a separate browser window.
CAUTION: My default browser is Firefox and the ESET Secure Browser Window asked me to if I wanted to save the bank's password even though I have Firefox set to NOT remember passwords.
Anti-Theft:
This feature enables Anti-Theft protection for your devices. It is, of course, more applicable for mobile/portable devices (touch-pads, smart phones, etc), it is not necessary for non-portable desktop systems.
I highly recommend ESET products, especially ESET Smart Security.
Better protection is provided by ESET Smart Security. The following screenshots show some of the features:
- This is the ESET home dialog on my system.
- This is the Setup dialog; the top 2 setting categories are like those found in ESET NOD32 AV, the "Network protection" and "Security tools" have the enhanced protection features.
- The "Network protection" settings dialog show the enhancements. "Personal firewall" is just like ESET NOD32 AV, replaces your Windows Firewall. "Network attack protection" and "Botnet protection" are the enhanced features, including ransomware protection. Note the "Recently blocked application or device" under "Troubleshooting wizard."
- "Parental control" is a feature found in ESET NOD32 AV. But note the "Banking & Payment protection" and "Anti-Theft" features (more below).
Banking & Payment protection:
This is one of the best features. You add the domains for all banking and payment sites (PayPal, banks, credit card, etc) you use and select [Secured browser] and ESET Smart Security provides enhanced protections for those sites in a separate browser window.
CAUTION: My default browser is Firefox and the ESET Secure Browser Window asked me to if I wanted to save the bank's password even though I have Firefox set to NOT remember passwords.
Anti-Theft:
This feature enables Anti-Theft protection for your devices. It is, of course, more applicable for mobile/portable devices (touch-pads, smart phones, etc), it is not necessary for non-portable desktop systems.
I highly recommend ESET products, especially ESET Smart Security.
Labels:
ESET,
pc security,
ransomware
Thursday, January 21, 2016
SPAM - More Than Ever
Ever since the expansion, and loosening of controls, of domain-names (especially in Europe) I've notice an vast proliferation of SPAM.
Example domains:
REF: The Spmhaus Project
ALSO: Google's Fighting Spam
Example domains:
- @bborc.top
- @caorc.top
- @eeaorc.top
- @faorc.top
- @paorc.top
REF: The Spmhaus Project
ALSO: Google's Fighting Spam
Labels:
email,
pc security,
SPAM,
web
Monday, September 28, 2015
SPYWARE - Lenovo Machines
"Lenovo in the News Again for Installing Spyware on Its Machines" by Manish Singh, Computer Help Forums 9/24/2015
Despite launching a number of interesting products this year, Lenovo has perhaps got more press time for the things it has done wrong. The Chinese technology conglomerate is back in news, this time for allegedly installing a program on at least some of its refurbished notebook lineup that is programmed to send users' feedback data to Lenovo. Upon further inspection, the program seems to have an association with a third-party marketing and Web analytics firm.
As per many users' report, the company ships its factory refurbished laptops with a program called "Lenovo Customer Feedback Program 64" that is scheduled to run every day. According to its description, Lenovo Customer Feedback Program 64 "uploads Customer Feedback Program data to Lenovo."
Upon further digging, Michael Horowitz of Computerworld found these files in the folder of the aforementioned program: "Lenovo.TVT.CustomerFeedback.Agent.exe.config, Lenovo.TVT.CustomerFeedback.InnovApps.dll, and Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll."
As he further pointed out, Omniture, as mentioned in the suffix of one of the files, is an online marketing and Web analytics firm, which suggests that the laptops are tracking and monitoring users' activities.
On its support website, the largest PC vendor noted that it may include software components that communicate with servers on the Internet. These applications could be on any and every ThinkCentre, ThinkStation, and ThinkPad lineups. One of the applications listed on the website is Lenovo.TVT.CustomerFeedback.Agent.exe.config.
This isn't the first time Lenovo has been caught shipping what appears to be a spyware on its machines. Earlier this year, Lenovo was found bundling a spyware called "Superfish" on its machines. In August, the company was caught covertly downloading and installing software on its Windows PCs. The program modified the BIOS to force the computer to download its programs upon each login.
Labels:
computers,
pc security,
spyware
Tuesday, August 4, 2015
WINDOWS 10 - Violates Privacy
"Windows 10 violates your privacy by default, here's how you can protect yourself" by Conner Forrest, TechRepublic 8/4/2015
Excerpt
NOTE: Full article has screenshots of settings that need change.
Excerpt
Upon installation, Windows 10 defaults to some pretty serious privacy invasions. Here are some steps you can take to keep your personal data private.
Since the July 29 release of Windows 10, the tech world has been talking about the latest OS update from Microsoft. A mere 24 hours after its release, more than 14 million users had downloaded Windows 10.
The quick ramp up was due, in part, to Microsoft releasing the update as a free download for existing Windows users. Windows 10 also came with a new service model as Windows will be releasing service packs every few months to users.
The model itself got some backlash, especially from organizations that don't want to upgrade their system that frequently. More recently, though, some criticism has arisen over privacy concerns brought on by the new OS.
The first issue is that Windows 10 automatically assigns an advertising ID to each user on a device tied to the email address that's on file. Using that ID, the company can tailor ads for web-browsing and using certain applications.
The next concern is that much of users' personal data is synced with Microsoft's servers. Some of this information, like your WiFi password, can then be encrypted and shared with your contacts, using a feature called WiFi sense. Although, some have argued that this isn't a security risk, because the user must choose to share the network.
Additionally, Microsoft's personal assistant, Cortana, must collect data as well to provide the kind of service it does, but it is likely not better or worse than its Apple and Google contemporaries.
One of the biggest worries, though, is Microsoft's policy on disclosing or sharing your personal information. The following is an excerpt from the privacy policy:
"We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good faith belief that doing so is necessary to protect our customers or enforce the terms governing the use of the services."
The problem is that many users want personalized services, but it's difficult to draw the line at what data should be collected. Forrester's Tyler Shields said that instead of making these features default, Microsoft could have allowed users to opt-in later if they wanted to enable them.
"This is more of a privacy-friendly stance that may have been palatable to the general public," Shields said. "However, Microsoft would have had less adoption to its value added services had it made them opt-in, thus lessening the potential success of the Windows 10 launch."
So, how do you protect yourself from these issues? Here are some steps you can take to opt-on or disable some of the problematic features.
The first thing to note is that, if you haven't yet installed Windows 10 but you plan on doing so, make sure you that you do a custom install so you'll be able to pick and choose what is enabled at the onset. But, if you installed Windows 10 using Express settings, you can still disable some of the default privacy settings.
From the start button, click "Settings" and then click "Privacy" and click the "General" tab on the left sidebar. Under that tab you'll see a few sliders where you can toggle certain features on or off.
The top toggle button is the most important as it disables the advertising ID for each user. But, if you want to cover your bases, you should go ahead disable the rest of the options as well.
NOTE: Full article has screenshots of settings that need change.
Labels:
pc security,
privacy,
TechRepublic,
win10,
windows
Thursday, April 10, 2014
SECURITY - Heartbleed Hacks SSL Security Servers
Heartbleed hacks into the SSL protocol that protects HTTPS sites.
"Security bug Heartbleed could have provided key that unlocks personal online data" PBS NewsHour 4/9/2014
Excerpt
"Security bug Heartbleed could have provided key that unlocks personal online data" PBS NewsHour 4/9/2014
Excerpt
GWEN IFILL (NewsHour): You may have heard headlines today about a major lapse in Internet security and the possibility that millions of passwords, credit card numbers, bank information, and commonly used Web sites could have been exposed.
It involves a bug or security leak called Heartbleed, which can be used to read encrypted information.
Hari Sreenivasan gets a breakdown on what you need to know.
HARI SREENIVASAN (NewsHour): Essentially, Heartbleed can be used to read the memory of computer servers, the places behind a Web site that store your information, including the lock and key system which protects your usernames and passwords.
You probably see this encryption in the form of a green lock when you conduct a transaction and exchange information. The breach was revealed this week, but apparently has existed for a long time.
Russell Brandom of The Verge, an online site covering tech news, is here to help explain.
Labels:
cybersecurity,
data security,
hacking,
PBS-Newshour,
pc security,
SSL
Wednesday, April 9, 2014
WINDOWS XP - The Enhanced Mitigation Experience Toolkit (EMET)
Now that SECURITY support for ordinary users of Windows XP is ended, here's an alternative way to protect WinXP.
Note that Microsoft Updates (which you should be using instead of Windows Updates) will still update some Microsoft software, like the "Malicious Software Removal Tool." What stops is security updates to WinXP itself.
The alternative protection is Microsoft's The Enhanced Mitigation Experience Toolkit (EMET)
WARNING: The EMET is NOT for amateurs. If used incorrectly it can cause problems with WinXP. But if you use Recommended Settings on installation, and the Quick Profile Name [Recommended Security settings] it should be safe.
Note that EMET is for all versions of Windows and some features are not available in WinXP.
Here's a screenshot of my EMET GUI:
With WinXP SEHOP & ASLR are not available.
There Software Profiles you can [Import]. I imported Popular Software.
From the support page in above link:
The Microsoft Download page for EMET. You should download both the Setup and Guide.
Note that EMET is just a GUI that makes setting various Windows options easier.
Also, I did try with DEP [Always On] (Maximum protection settings) but that prevented 2 of my boot-time apps from running, like MiniMinder. So I changed back to the settings you see in my GUI screenshot.
Note that Microsoft Updates (which you should be using instead of Windows Updates) will still update some Microsoft software, like the "Malicious Software Removal Tool." What stops is security updates to WinXP itself.
The alternative protection is Microsoft's The Enhanced Mitigation Experience Toolkit (EMET)
WARNING: The EMET is NOT for amateurs. If used incorrectly it can cause problems with WinXP. But if you use Recommended Settings on installation, and the Quick Profile Name [Recommended Security settings] it should be safe.
Note that EMET is for all versions of Windows and some features are not available in WinXP.
Here's a screenshot of my EMET GUI:
With WinXP SEHOP & ASLR are not available.
There Software Profiles you can [Import]. I imported Popular Software.
From the support page in above link:
What is the Enhanced Mitigation Experience Toolkit?
The Enhanced Mitigation Experience Toolkit (EMET) is a utility that helps prevent vulnerabilities in software from being successfully exploited. EMET achieves this goal by using security mitigation technologies. These technologies function as special protections and obstacles that an exploit author must defeat to exploit software vulnerabilities. These security mitigation technologies do not guarantee that vulnerabilities cannot be exploited. However, they work to make exploitation as difficult as possible to perform.
EMET 4.0 and newer versions also provide a configurable SSL/TLS certificate pinning feature that is called Certificate Trust. This feature is intended to detect man-in-the-middle attacks that are leveraging the public key infrastructure (PKI).
Are there restrictions as to the software that EMET can protect?
EMET can work together with any software, regardless of when it was written or by whom it was written. This includes software that is developed by Microsoft and software that is developed by other vendors. However, you should be aware that some software may not be compatible with EMET. For more information about compatibility, see the "Are there any risks in using EMET?" section.
What are the requirements for using EMET?
EMET 3.0 requires the Microsoft .NET Framework 2.0.
EMET 4.0 and 4.1 require the Microsoft .NET Framework 4.0. Additionally, for EMET to work with Internet Explorer 10 on Windows 8, KB2790907 must be installed.
The Microsoft Download page for EMET. You should download both the Setup and Guide.
Note that EMET is just a GUI that makes setting various Windows options easier.
Also, I did try with DEP [Always On] (Maximum protection settings) but that prevented 2 of my boot-time apps from running, like MiniMinder. So I changed back to the settings you see in my GUI screenshot.
Labels:
Microsoft Updates,
pc security,
win xp
Wednesday, March 19, 2014
WINXP - Updates to Continue for Big Business For a Fee
More proof that Microdunce does not care about peon customers. They are just another greedy company who cares only about profits and not serving customers who bought their product. I would be willing to pay $50/year for continued WinXP Updates.
This strategy is recently confirmed by several banks making the Updates For Fee deal with Microdunce to protect their ATMs running WinXP.
"Microsoft will still patch Windows XP for a select group" by Gregg Keizer, PCWorld 9/1/2013
Excerpt
This strategy is recently confirmed by several banks making the Updates For Fee deal with Microdunce to protect their ATMs running WinXP.
"Microsoft will still patch Windows XP for a select group" by Gregg Keizer, PCWorld 9/1/2013
Excerpt
Just because Microsoft doesn't plan on giving Windows XP patches to the public after April 8, 2014, doesn't mean it's going to stop making those patches.
In fact, Microsoft will be creating security updates for Windows XP for months—years, even—after it halts their delivery to the general public.
Some will pay big for support
Those patches will come from a program called "Custom Support," an after-retirement contract designed for very large customers who have not, for whatever reason, moved on from an older OS.
As part of Custom Support—which according to analysts, costs about $200 per PC for the first year and more each succeeding year—participants receive patches for vulnerabilities rated "critical" by Microsoft. Bugs ranked as "important," the next step down in Microsoft's four-level threat scoring system, are not automatically patched. Instead, Custom Support contract holders must pay extra for those. Flaws pegged as "moderate" or "low" are not patched at all.
"Legacy products or out-of-support service packs covered under Custom Support will continue to receive security hotfixes for vulnerabilities labeled as 'Critical' by the MSRC [Microsoft Security Response Center]," Microsoft said in a Custom Support data sheet. "Customers with Custom Support that need security patches defined as 'Important' by MSRC can purchase these for an additional fee.
"These security hotfixes will be issued through a secure process that makes the information available only to customers with Custom Support," the data sheet promised.
Because Microsoft sells Custom Support agreements, it's obligated to come up with patches for critical and important vulnerabilities. And it may be required to do so for years: The company sells Custom Support for up to three years after it retires an operating system.
Custom Support and the XP security updates that result have been one reason why some experts have held out hope that Microsoft will backtrack from retiring XP next April. Their reasoning is straightforward: Microsoft will have patches available—its engineers won't have to do any more work than they already committed to doing—so handing them out to all would be a simple matter.
Or not. Most experts have said that the chance Microsoft will prolong Windows XP's life run between slim and none. And giving away patches to everyone risks a revolt by those big customers who have paid millions for Custom Support.
But Microsoft does have options. Here are our suggestions:
Continue patching for free
If Windows XP remains a major presence, as it appears likely, with projections as high as 33.5 percent of all personal computers at the end of April 2014, Microsoft could decide to continue patching the aged OS with free fixes for critical vulnerabilities, maybe even those rated important.
Such a move would be unpalatable to Custom Support customers, but Microsoft could renegotiate the fees—unlikely—or remind those companies of the program's other benefits, which include access to support representatives, as well as to prior patches and hotfixes.
Patch critical vulnerabilities under attack
Microsoft could selectively patch only the critical bugs that are being exploited by hackers. Presumably, that would be a subset of the complete XP patch collection assembled each month.
Some analysts have picked this option as a possibility. Last December, Michael Cherry of Directions on Microsoft posed just such a situation.
"Suppose ... a security problem with XP suddenly causes massive problems on the Internet, such as a massive [denial-of-service] problem?" asked Cherry at the time. "It is not just harming Windows XP users, it is bringing the entire Internet to its knees. At this time there are still significant numbers of Windows XP in use, and the problem is definitely due to a problem in Windows XP. In this scenario, I believe Microsoft would have to do the right thing and issue a fix ... without regard to where it is in the support lifecycle."
Charge users for XP patches
Although Microsoft would much rather book revenue from the sale of a newer OS, it may realize that some will refuse to upgrade, and try to make money rather than give away fixes.
It's unlikely that Microsoft would be able to charge $200 annually for post-retirement patches, as it does with Custom Support customers, but it may be able to get away with $50 a year for individuals and small businesses, perhaps with a maximum machine cap at, say, five PCs per customer.
Traditionally, Microsoft's not charged for support, but it could cast this as a special situation caused by the longevity of XP, which was due to the delay of Vista and secondarily, that OS's subsequent flop. In late 2007, when Microsoft extended XP availability to OEMs by several months, it cited Vista's delayed launch for the unusual move. (It added another extension in 2008 that kept XP alive on new "netbook" PCs, the then-popular class of cheap laptops, until mid-2010.)
And Microsoft has talked up a transformation to a "devices-and-services" company; a pay-for-support plan would mesh nicely with the latter half of that strategy.
Labels:
computers,
Microsoft Updates,
pc security,
win xp
Monday, January 20, 2014
CYBERCRIME - Who Orchestrated the Target Breach
"Were criminal gangs involved in the Target security breach?" PBS Newshour 1/18/2014
Excerpt
Excerpt
HARI SREENIVASAN (Newshour): Another story that we wanted to follow up on tonight is the state of credit card security, or lack of it. This following discourse is about major security breaches at big retailers, including Target and Neiman Marcus. Now new details are emerging about who was behind it, and how it was accomplished. For more we are joined now, from Washington, by Mike Riley with Bloomberg News. So, there was a big report out - it started to layout the details. How do these hackers get all the credit card numbers?
MIKE RILEY, Bloomberg News: So, they have a pretty sophisticated piece of malware that goes on the point of sales system itself, so that is the terminal that sits in front the the cash register that we all swipe our cards on. So, the malware goes there and it takes advantage of a quirk, where within that machine, all that information that is taken off that card is sent from one memory chip to another. It is not encrypted in that process, and they grab it right there.
HARI SREENIVASAN: And so, who is writing this malware?
MIKE RILEY: It looks like it is Eastern European or Russian criminal gangs. Some of the most sophisticated hackers in the world are Russian or Eastern European. What they have done is they have gotten really good systems. It is like a supply chain that you can buy pieces of malware. If you are good enough, as in this case - they have bought a specific piece of malware, called Black POS. It is a pretty good piece of malware to begin with, but then they customized it. They made it better. They made it harder to find, and then they figured out a scheme to get into Target's computers, and stuck it on the point of sales system. It is also pretty clear that the same gang, or a group of different hackers using the same malware, are targeting other retailers. We have not seen the end of this.
Labels:
Cybercrime,
data security,
PBS-Newshour,
pc security
Friday, September 6, 2013
SECURITY - From Dilbert
9/6/2013
Labels:
cybersecurity,
data security,
humor,
pc security
SECURITY - The NSA's Internet Hacking
"Revealed: The NSA’s Secret Campaign to Crack, Undermine Internet Security" by Jeff Larson (ProPublica), Nicole Perlrothand and Scott Shane (The New York Times), ProPublica 9/5/2013
The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents.
The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.
Many users assume — or have been assured by Internet companies — that their data is safe from prying eyes, including those of the government, and the N.S.A. wants to keep it that way. The agency treats its recent successes in deciphering protected information as among its most closely guarded secrets, restricted to those cleared for a highly classified program code-named Bullrun, according to the documents, provided by Edward J. Snowden, the former N.S.A. contractor.
Beginning in 2000, as encryption tools were gradually blanketing the Web, the N.S.A. invested billions of dollars in a clandestine campaign to preserve its ability to eavesdrop. Having lost a public battle in the 1990s to insert its own “back door” in all encryption, it set out to accomplish the same goal by stealth.
The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated.
The N.S.A. hacked into target computers to snare messages before they were encrypted. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world.
“For the past decade, N.S.A. has led an aggressive, multipronged effort to break widely used Internet encryption technologies,” said a 2010 memo describing a briefing about N.S.A. accomplishments for employees of its British counterpart, Government Communications Headquarters, or GCHQ. “Cryptanalytic capabilities are now coming online. Vast amounts of encrypted Internet data which have up till now been discarded are now exploitable.”
When the British analysts, who often work side by side with N.S.A. officers, were first told about the program, another memo said, “those not already briefed were gobsmacked!”
An intelligence budget document makes clear that the effort is still going strong. “We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic,” the director of national intelligence, James R. Clapper Jr., wrote in his budget request for the current year.
In recent months, the documents disclosed by Mr. Snowden have described the N.S.A.’s broad reach in scooping up vast amounts of communications around the world. The encryption documents now show, in striking detail, how the agency works to ensure that it is actually able to read the information it collects.
The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant. But it shows that the agency, which was sharply rebuked by a federal judge in 2011 for violating the rules and misleading the Foreign Intelligence Surveillance Court, cannot necessarily be restrained by privacy technology. N.S.A. rules permit the agency to store any encrypted communication, domestic or foreign, for as long as the agency is trying to decrypt it or analyze its technical features.
The N.S.A., which has specialized in code-breaking since its creation in 1952, sees that task as essential to its mission. If it cannot decipher the messages of terrorists, foreign spies and other adversaries, the United States will be at serious risk, agency officials say.
Just in recent weeks, the Obama administration has called on the intelligence agencies for details of communications by Qaeda leaders about a terrorist plot and of Syrian officials’ messages about the chemical weapons attack outside Damascus. If such communications can be hidden by unbreakable encryption, N.S.A. officials say, the agency cannot do its work.
But some experts say the N.S.A.’s campaign to bypass and weaken communications security may have serious unintended consequences. They say the agency is working at cross-purposes with its other major mission, apart from eavesdropping: ensuring the security of American communications.
Some of the agency’s most intensive efforts have focused on the encryption in universal use in the United States, including Secure Sockets Layer, or SSL, virtual private networks, or VPNs, and the protection used on fourth generation, or 4G, smartphones. Many Americans, often without realizing it, rely on such protection every time they send an e-mail, buy something online, consult with colleagues via their company’s computer network, or use a phone or a tablet on a 4G network.
For at least three years, one document says, GCHQ, almost certainly in close collaboration with the N.S.A., has been looking for ways into protected traffic of the most popular Internet companies: Google, Yahoo, Facebook and Microsoft’s Hotmail. By 2012, GCHQ had developed “new access opportunities” into Google’s systems, according to the document.
“The risk is that when you build a back door into systems, you’re not the only one to exploit it,” said Matthew D. Green, a cryptography researcher at Johns Hopkins University. “Those back doors could work against U.S. communications, too.”
Paul Kocher, a leading cryptographer who helped design the SSL protocol, recalled how the N.S.A. lost the heated national debate in the 1990s about inserting into all encryption a government back door called the Clipper Chip.
“And they went and did it anyway, without telling anyone,” Mr. Kocher said. He said he understood the agency’s mission but was concerned about the danger of allowing it unbridled access to private information.
“The intelligence community has worried about ‘going dark’ forever, but today they are conducting instant, total invasion of privacy with limited effort,” he said. “This is the golden age of spying.”
A Vital Capability
The documents are among more than 50,000 shared by The Guardian with The New York Times and ProPublica, the nonprofit news organization. They focus primarily on GCHQ but include thousands either from or about the N.S.A.
Intelligence officials asked The Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of Americans and others.
The files show that the agency is still stymied by some encryption, as Mr. Snowden suggested in a question-and-answer session on The Guardian’s Web site in June.
“Properly implemented strong crypto systems are one of the few things that you can rely on,” he said, though cautioning that the N.S.A. often bypasses the encryption altogether by targeting the computers at one end or the other and grabbing text before it is encrypted or after it is decrypted.
The documents make clear that the N.S.A. considers its ability to decrypt information a vital capability, one in which it competes with China, Russia and other intelligence powers.
“In the future, superpowers will be made or broken based on the strength of their cryptanalytic programs,” a 2007 document said. “It is the price of admission for the U.S. to maintain unrestricted access to and use of cyberspace.”
The full extent of the N.S.A.’s decoding capabilities is known only to a limited group of top analysts from the so-called Five Eyes: the N.S.A. and its counterparts in Britain, Canada, Australia and New Zealand. Only they are cleared for the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century.
Unlike some classified information that can be parceled out on a strict “need to know” basis, one document makes clear that with Bullrun, “there will be NO ‘need to know.’ ”
Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources.
Ties to Internet Companies
When the N.S.A. was founded, encryption was an obscure technology used mainly by diplomats and military officers. Over the last 20 years, with the rise of the Internet, it has become ubiquitous. Even novices can tell that their exchanges are being automatically encrypted when a tiny padlock appears next to the Web address on their computer screen.
Because strong encryption can be so effective, classified N.S.A. documents make clear, the agency’s success depends on working with Internet companies — by getting their voluntary collaboration, forcing their cooperation with court orders or surreptitiously stealing their encryption keys or altering their software or hardware.
According to an intelligence budget document leaked by Mr. Snowden, the N.S.A. spends more than $250 million a year on its Sigint Enabling Project, which “actively engages the U.S. and foreign IT industries to covertly influence and/or overtly leverage their commercial products’ designs” to make them “exploitable.” Sigint is the abbreviation for signals intelligence, the technical term for electronic eavesdropping.
By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors or by surreptitiously exploiting existing security flaws, according to the documents. The agency also expected to gain full unencrypted access to an unnamed major Internet phone call and text service; to a Middle Eastern Internet service; and to the communications of three foreign governments.
In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, someone familiar with the request told The Times.
The 2013 N.S.A. budget request highlights “partnerships with major telecommunications carriers to shape the global network to benefit other collection accesses” — that is, to allow more eavesdropping.
At Microsoft, as The Guardian has reported, the N.S.A. worked with company officials to get pre-encryption access to Microsoft’s most popular services, including Outlook e-mail, Skype Internet phone calls and chats, and SkyDrive, the company’s cloud storage service.
Microsoft asserted that it had merely complied with “lawful demands” of the government, and in some cases, the collaboration was clearly coerced. Executives who refuse to comply with secret court orders can face fines or jail time.
N.S.A. documents show that the agency maintains an internal database of encryption keys for specific commercial products, called a Key Provisioning Service, which can automatically decode many messages. If the necessary key is not in the collection, a request goes to the separate Key Recovery Service, which tries to obtain it.
How keys are acquired is shrouded in secrecy, but independent cryptographers say many are probably collected by hacking into companies’ computer servers, where they are stored. To keep such methods secret, the N.S.A. shares decrypted messages with other agencies only if the keys could have been acquired through legal means. “Approval to release to non-Sigint agencies,” a GCHQ document says, “will depend on there being a proven non-Sigint method of acquiring keys.”
Simultaneously, the N.S.A. has been deliberately weakening the international encryption standards adopted by developers. One goal in the agency’s 2013 budget request was to “influence policies, standards and specifications for commercial public key technologies,” the most common encryption method.
Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology, the United States’ encryption standards body, and later by the International Organization for Standardization, which has 163 countries as members.
Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.”
“Eventually, N.S.A. became the sole editor,” the memo says.
Even agency programs ostensibly intended to guard American communications are sometimes used to weaken protections. The N.S.A.’s Commercial Solutions Center, for instance, invites the makers of encryption technologies to present their products and services to the agency with the goal of improving American cybersecurity. But a top-secret N.S.A. document suggests that the agency’s hacking division uses that same program to develop and “leverage sensitive, cooperative relationships with specific industry partners” to insert vulnerabilities into Internet security products.
A Way Around
By introducing such back doors, the N.S.A. has surreptitiously accomplished what it had failed to do in the open. Two decades ago, officials grew concerned about the spread of strong encryption software like Pretty Good Privacy, or P.G.P., designed by a programmer named Phil Zimmermann. The Clinton administration fought back by proposing the Clipper Chip, which would have effectively neutered digital encryption by ensuring that the N.S.A. always had the key.
That proposal met a broad backlash from an unlikely coalition that included political opposites like Senator John Ashcroft, the Missouri Republican, and Senator John Kerry, the Massachusetts Democrat, as well as the televangelist Pat Robertson, Silicon Valley executives and the American Civil Liberties Union. All argued that the Clipper would kill not only the Fourth Amendment, but also America’s global edge in technology.
By 1996, the White House backed down. But soon the N.S.A. began trying to anticipate and thwart encryption tools before they became mainstream.
“Every new technology required new expertise in exploiting it, as soon as possible,” one classified document says.
Each novel encryption effort generated anxiety. When Mr. Zimmermann introduced the Zfone, an encrypted phone technology, N.S.A. analysts circulated the announcement in an e-mail titled “This can’t be good.”
But by 2006, an N.S.A. document notes, the agency had broken into communications for three foreign airlines, one travel reservation system, one foreign government’s nuclear department and another’s Internet service by cracking the virtual private networks that protected them.
By 2010, the Edgehill program, the British counterencryption effort, was unscrambling VPN traffic for 30 targets and had set a goal of an additional 300.
But the agencies’ goal was to move away from decrypting targets’ tools one by one and instead decode, in real time, all of the information flying over the world’s fiber optic cables and through its Internet hubs, only afterward searching the decrypted material for valuable intelligence.
A 2010 document calls for “a new approach for opportunistic decryption, rather than targeted.” By that year, a Bullrun briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum.
But the agency was concerned that it could lose the advantage it had worked so long to gain, if the mere “fact of” decryption became widely known. “These capabilities are among the Sigint community’s most fragile, and the inadvertent disclosure of the simple ‘fact of’ could alert the adversary and result in immediate loss of the capability,” a GCHQ document outlining the Bullrun program warned.
Corporate Pushback
Since Mr. Snowden’s disclosures ignited criticism of overreach and privacy infringements by the N.S.A., American technology companies have faced scrutiny from customers and the public over what some see as too cozy a relationship with the government. In response, some companies have begun to push back against what they describe as government bullying.
Google, Yahoo and Facebook have pressed for permission to reveal more about the government’s secret requests for cooperation. One small e-mail encryption company, Lavabit, shut down rather than comply with the agency’s demands for what it considered confidential customer information; another, Silent Circle, ended its e-mail service rather than face similar demands.
In effect, facing the N.S.A.’s relentless advance, the companies surrendered.
Ladar Levison, the founder of Lavabit, wrote a public letter to his disappointed customers, offering an ominous warning. “Without Congressional action or a strong judicial precedent,” he wrote, “I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States.”
Statement from the Office of the Director of National Intelligence:
It should hardly be surprising that our intelligence agencies seek ways to counteract our adversaries’ use of encryption. Throughout history, nations have used encryption to protect their secrets, and today, terrorists, cybercriminals, human traffickers and others also use code to hide their activities. Our intelligence community would not be doing its job if we did not try to counter that.
While the specifics of how our intelligence agencies carry out this cryptanalytic mission have been kept secret, the fact that NSA’s mission includes deciphering enciphered communications is not a secret, and is not news. Indeed, NSA’s public website states that its mission includes leading “the U.S. Government in cryptology … in order to gain a decision advantage for the Nation and our allies.”
The stories published yesterday, however, reveal specific and classified details about how we conduct this critical intelligence activity. Anything that yesterday’s disclosures add to the ongoing public debate is outweighed by the road map they give to our adversaries about the specific techniques we are using to try to intercept their communications in our attempts to keep America and our allies safe and to provide our leaders with the information they need to make difficult and critical national security decisions.
Labels:
data security,
NSA,
pc security,
privacy
Friday, April 12, 2013
SECURITY - Online Gaming Firms Targeted by Malware
"'Winnti' Malware Targeting Online Gaming Firms" by Chloe Albanesius, PC Magazine 4/12/2013
News of game-related hacks are nothing new; they have dominated headlines in recent years, from the massive Sony PlayStation Network takedown to the more recent hack of The War Z.
Attacks on gaming firms might not be isolated incidents, however. Researchers at Kaspersky Lab this week said they uncovered a series of targeted attacks originating in China that are taking aim at Web-based gaming companies.
"According to our estimations, this group has been active for several years and specializes in cyber attacks against the online video game industry," Kaspersky said in a blog post. "The group's main objective is to steal source codes for online game projects as well as the digital certificates of legitimate software vendors. In addition, they are very interested in how network infrastructure (including the production of gaming servers) is set up, and new developments such as conceptual ideas, design and more."
Kaspersky started investigating the group - known as Winnti - in the fall of 2011 at a behest of a computer game publisher that detected malware on its network. The malware was pushed out to users via a standard update, prompting concern that the company was spying on its users.
"However, it later became clear that the malicious program ended up on the users' computers by mistake; the cybercriminals were in fact targeting the companies that develop and release computer games," Kaspersky said.
Once installed on someone's computer, the hackers could control that machine without the user's knowledge. The malware was "the first time we saw Trojan applications for the 64-bit version of Microsoft Windows with a valid digital signature," Kaspersky said. Previous incidents of digital signature abuse had only hit 32-bit systems.
The digital certificate in question belonged to South Korea-based KOG, which also produced MMPRG, like Kaspersky's client. Ultimately, the certificate was revoked, but "over the next 18 months we discovered more than a dozen similar compromised digital certificates."
Kaspersky said that its research suggests that at least 35 companies from around the world have been infected by Winnti malware at some point in time, with a "strong focus" on Southeast Asia.
Labels:
cybersecurity,
malware,
networking,
pc security,
trojan
Thursday, November 15, 2012
SECURITY - NASA Security Breach
"Stolen NASA Laptop Had Unencrypted Employee Data" by Mathew J. Schwartz, Information Week 11/15/2012
NASA is warning all employees and contractors that their personal information may have been compromised after a thief stole a NASA laptop and documents from an agency employee's locked car.
"On October 31, 2012, a NASA laptop and official NASA documents issued to a headquarters employee were stolen from the employee's locked vehicle. The laptop contained records of sensitive personally identifiable information (PII) for a large number of NASA employees, contractors and others," said Richard J. Keegan Jr., associate deputy administrator of NASA, in a notice sent to all employees.
The data on the laptop wasn't encrypted. "Although the laptop was password protected, it did not have whole disk encryption software, which means the information on the laptop could be accessible to unauthorized individuals," he said.
NASA doesn't yet know the full extent of the breach, presumably because the agency is still attempting to reconstruct and study everything that was on the stolen laptop. "Because of the amount of information that must be reviewed and validated electronically and manually, it may take up to 60 days for all individuals impacted by this breach to be identified and contacted," said Keegan.
In addition to now implementing full-disk encryption software for NASA laptops, Keegan said NASA will pay ID Experts to notify people who've been affected by the breach, and to provide identity theft and credit monitoring services. Anyone affected will be notified about the breach via a written, mailed letter -- but not by email or phone, he said.
Given the continuing increase in the number of data breaches affecting organizations, and the accompanying costs of notifying affected people and cleaning up the mess, surely technology-savvy NASA would have already required that all agency laptops be secured using full-disk encryption software?
In fact, that hasn't been the case, apparently owing to user resistance. An IT executive at Goddard Space Flight Center, for example, said that the facility recently implemented data-at-rest encryption on PCs. But some users aren't fans of the software, which they said interfered with some of the tools on their PCs.
In the wake of this breach, however, NASA administrator Charles F. Bolden Jr. and CIO Linda Cureton have ordered that "no NASA-issued laptops containing sensitive information can be removed from a NASA facility unless whole disk encryption software is enabled or the sensitive files are individually encrypted," said Keegan. "This applies to laptops containing PII, international traffic in arms regulations (ITAR) and export administration regulations (EAR) data, procurement and human resources information, and other sensitive but unclassified (SBU) data."
NASA facility CIOs have been ordered to add or enable encryption capabilities for the maximum number of laptops by November 21, 2012. By December 21, 2012, all laptops that leave NASA facilities must have encryption capabilities. In the meantime, employees who are telecommunicating or traveling "should use loaner laptops if their NASA-issued laptop contains unencrypted sensitive information," according to Keegan's communication.
Cureton's office will also review whether any further agency security policies need to be revised to help prevent future data breaches stemming from lost or stolen laptops.
A NASA spokeswoman didn't immediately respond to an emailed request for comment about what type of full-disk or file encryption technology the agency would be using, whether it planned to train all employees to determine what qualifies as "sensitive information" that must be encrypted -- or whether employees' compliance with the new policies would be monitored and enforced.
Labels:
computers,
data security,
pc security
Wednesday, August 15, 2012
INTERNET - Guarding Personal Information
"A Perilous Cyber World: Guarding Personal Information from Hackers and Thieves" PBS Newshour 8/14/2012
Excerpt
As a long-time computer & IT professional, my advice for Laptop and Desktop PCs:
Excerpt
JEFFREY BROWN (Newshour): And we begin an occasional series about the way we live ever more of our lives online in the digital age, and some of the risks and rewards connected with this evolution.
In coming segments, we will discuss the connections and disconnections of online life, the differences between engaging online and in the physical world, and what does it mean exactly when a video go viral.
We begin with a look at just how much of us, our identities, are online, and how vulnerable that can make us.
Mat Honan learned this firsthand recently when he was hacked and lost control of his phone, email and personal computer. He told the tale in "Wired" magazine, where he's a technology writer.
Also joining us is Peter Pachal, who watches this world closely as the technology editor for the Web site Mashable.
As a long-time computer & IT professional, my advice for Laptop and Desktop PCs:
- The HIGHEST security is NOT to be online unless you need to be, this includes turning off your system when you are not using it
- Passwords - The old advice about NOT using any part of your name or your wife's or children's, even your pets', applies
- Passwords - Do NOT use any part of an address where you have lived, worked, or gone to school
- Passwords - Do NOT use your nickname(s)
- Passwords - Do NOT use birthday dates; yours nor your family's (not even if you reverse or scramble, more later)
- Passwords - DO have one Master Password that is for very limited use, examples: system Administrator Account (NEVER have a blank password for Administrator), access to a password management tool you use, access to your ISP or eMail providers
- ALWAYS, always run a good Antivirus Utility (and "free" antivirus utilities are NOT good), one that includes protection against Root-Tool-Kit, Trojans, etc, and KEEP THE DEFINITIONS UP-TO-DATE
Labels:
Cybercrime,
cybersecurity,
data security,
internet,
pc security
Thursday, June 7, 2012
INTERNET - Google Warning for GMail Users
"Google to warn users targeted by state-sponsored attacks" by Josh Rogin, Foreign Policy 6/5/2012
UPDATE: A senior Senate aide confirmed that this evening he received a warning on his Gmail account that Google suspected he had been the target of a state-sponsored cyber attack.
Web giant Google is about to announce a new warning informing Gmail users when a specific type of attacker is trying to hijack their accounts -- governments and their proxies.
Later today, the company will announce a new warning system that will alert Gmail users when Google believes their accounts are being targeted by state-sponsored attacks. The new system isn't a response to a specific event or directed at any one country, but is part and parcel of Google's recent set of policy changes meant to allow users to protect themselves from malicious activity brought on by state actors. It also has the effect of making it more difficult for authoritarian regimes to target political and social activists by hacking their private communications.
"We are constantly on the lookout for malicious activity on our systems, in particular attempts by third parties to log into users' accounts unauthorized. When we have specific intelligence-either directly from users or from our own monitoring efforts-we show clear warning signs and put in place extra roadblocks to thwart these bad actors," reads a note to users by Eric Grosse, Google's vice president for security engineering, to be posted later today on Google's Online Security blog, obtained in advance by The Cable. "Today, we're taking that a step further for a subset of our users, who we believe may be the target of state-sponsored attacks."
When Google's internal systems monitoring suspicious internet activity, such as suspicious log-in attempts, conclude that such activities include the involvement of states or state-backed initiatives, the user will now receive the specialized, more prominent warning pictured above. The warning doesn't necessarily mean that a user's account has been hijacked, but is meant to alert users that Google believes a state sponsored attack has been attempted so they can increase their security vigilance.
Google wants to be clear they are not singling out any one government for criticism and that the effort is about giving users transparency about what is going on with their accounts, not about highlighting the malicious actions of foreign states.
"If you see this warning it does not necessarily mean that your account has been hijacked. It just means that we believe you may be a target, of phishing or malware for example, and that you should take immediate steps to secure your account," Grosse writes. "You might ask how we know this activity is state-sponsored. We can't go into the details without giving away information that would be helpful to these bad actors, but our detailed analysis-as well as victim reports-strongly suggest the involvement of states or groups that are state-sponsored."
Google insiders told The Cable that Google will not be giving out information on which governments it sees as the most egregious violators of web privacy. For Google, the new initiative is not an effort against governments but a way to help its users help defend and protect themselves.
Users who click through the new warning message will be directed to a page that outlines commonly seen security threats and suggests ways users can immediately raise their level of security on Gmail.
"We're constantly working to prevent harmful activity on our services, especially attempts to compromise our users' information," the insider said. "The primary message is: we believe that you're a target so you should take immediate steps to protect your account."
The new announcement comes only days after the company said they would alert users in mainland China when they use search terms that are likely to be censored by the Chinese government. According to another of Google's official blogs, that move was meant to improve the search experience for Chinese users by allowing them to avoid terms that would result in stalls or breaks in their search experience due to government filters.
For example, Google said that Chinese users searching the character for "river," which is "jiang" in Chinese, causes technical problems. The same character is also used in the search for former Chinese President Jiang Zemin.
Google didn't specifically mention Chinese censorship in its notice about Chinese search terms, apparently in an effort not to antagonize the Chinese government any more than necessary. Google and Beijing have been at odds since 2010, when the company announced it would no longer censor search terms on the Google.cn and moved the bulk of its Chinese operations to Hong Kong.
That move followed a series of Gmail attacks in 2010, directed at Chinese human rights activists, which were widely suspected to be linked to the Chinese government. Following those attacks, the government-controlled People's Daily publicly accused Google of being an agent for U.S. intelligence agencies.
While last week's announcement and this week's announcement are both being presented by Google as user based initiatives not directed at foreign governments, Google CEO Eric Schmidt has been speaking out publicly and forcefully in recent months about the potential negative role governments can play in circumventing internet freedom.
"While threats come from individuals and even groups of people, the biggest problem will be activities stemming from nations that seek to do harm," he said in London last month.
Labels:
cybersecurity,
email,
internet,
pc security
Monday, May 28, 2012
WINDOWS - Backups Revisited
I am re-posting this subject because of several queries via Usenet.
Having a good backup utility is the absolutely best way for restoring your system. And by "good" I mean an image backup utility, NOT a file backup.
An image backup utility takes a "snap shot" of sectors on your hard drive (not just files) which means you have your boot sector and everything else. The most efficient will image only used sectors, not the entire drive (used and blank).
I use "O&O DiskImage Pro" (compatible with all versions of Windows)
It has saved my WinXP SP3 desktop 2 times in the years I've use it.
I also use it to load a new hard drive (I needed a bigger one), connected the new drive (IDE HD0) jumpered just like the old one, booted to the DiskImage CD, recovered my backup to the new blank drive (DiskImage asked if I wanted it bootable, yes of course) booted to the drive with absolutely no problems. Already had a partition tool (link follows, Windows Disk Management cannot do this without loosing data) installed and use it to expand the used space to include the entire (now bigger) drive.
EaseUS Partition Master Professional Edition
Purchase of "O&O DiskImage Pro" includes a Boot ISO image you can write to a CD/DVD. Boot to the CD and it runs the ENTIRE DiskImage utility (Backup AND Recovery). I use this method to create backups to an external USB hard drive.
The Windows installed DiskImage (and you must install in on your system) allows you to mount your image backups as another drive, thereby you can recover individual files.
"O&O DiskImage Pro" is worth every dime ($30 for 1 copy, $50 for 3), from a very satisfied user not affiliated with O&O.
CAUTION: You should NEVER create backups WITHOUT running a virus scan FIRST!
Having a good backup utility is the absolutely best way for restoring your system. And by "good" I mean an image backup utility, NOT a file backup.
An image backup utility takes a "snap shot" of sectors on your hard drive (not just files) which means you have your boot sector and everything else. The most efficient will image only used sectors, not the entire drive (used and blank).
I use "O&O DiskImage Pro" (compatible with all versions of Windows)
It has saved my WinXP SP3 desktop 2 times in the years I've use it.
I also use it to load a new hard drive (I needed a bigger one), connected the new drive (IDE HD0) jumpered just like the old one, booted to the DiskImage CD, recovered my backup to the new blank drive (DiskImage asked if I wanted it bootable, yes of course) booted to the drive with absolutely no problems. Already had a partition tool (link follows, Windows Disk Management cannot do this without loosing data) installed and use it to expand the used space to include the entire (now bigger) drive.
EaseUS Partition Master Professional Edition
Purchase of "O&O DiskImage Pro" includes a Boot ISO image you can write to a CD/DVD. Boot to the CD and it runs the ENTIRE DiskImage utility (Backup AND Recovery). I use this method to create backups to an external USB hard drive.
The Windows installed DiskImage (and you must install in on your system) allows you to mount your image backups as another drive, thereby you can recover individual files.
"O&O DiskImage Pro" is worth every dime ($30 for 1 copy, $50 for 3), from a very satisfied user not affiliated with O&O.
CAUTION: You should NEVER create backups WITHOUT running a virus scan FIRST!
Labels:
pc backup,
pc security,
windows
Tuesday, April 17, 2012
COMPUTERS - Data Privacy and Cyber Security
"How Will FCC's Google Street View Fine Shape Data Privacy Rules?" (1 of 2) PBS Newshour 4/16/2012
Excerpt
"Preventing a 'Cyber-Pearl Harbor'" (2 of 2) PBS Newshour 4/16/2012
Excerpt
Excerpt
RAY SUAREZ (Newshour): And to two stories about Internet privacy.
First: the latest on a government investigation of Google's collection of personal data that started with taking pictures and ended up gathering a lot more.
Google's Street View, launched in 2007, was part of the company's ambitious plan to photograph and map the entire world right down to street level. But it turned out that Street View vehicles were collecting more than just visual images. Their antennas also picked up personal information from local Wi-Fi networks, including Internet usage history and passwords.
In May 2010, Google publicly acknowledged it had done so, but insisted that any such data collection was accidental. The Federal Communications Commission began investigating. And, on Friday, it fined the company $25,000, the maximum penalty available, for obstructing the investigation.
In its report, the FCC said, "Although a world leader in digital search capability, Google took the position that searching its employees' e-mail would be a time-consuming and burdensome task." The FCC found Google did indeed collect personal data, but it cleared the company of charges that it had acted illegally.
The search engine giant challenged the finding that it failed to cooperate. Instead, it issued a statement that said, "We provided all the materials the regulators felt they needed." European regulators have also investigated the company for similar reasons. Last year, the French government fined Google about $140,000.
MAN: You're now exploring a neighborhood in our full-screen mode.
RAY SUAREZ: In the meantime, those who would rather not see their homes on Street View do have an alternative. The company provides users the option of graying out images to meet privacy concerns.
The FCC report generated plenty of questions over the past 48 hours about what Google did.
We ask some of those now with two people watching this case, Jeffrey Rosen, a professor of law at the George Washington University and legal affairs editor for The New Republic, and David Bennahum, the chief executive of Punch Media, a news and entertainment network for iPads.
"Preventing a 'Cyber-Pearl Harbor'" (2 of 2) PBS Newshour 4/16/2012
Excerpt
JEFFREY BROWN (Newshour): And now to our second look at privacy online and a story about protecting computers from cyber-attacks.
NewsHour correspondent Tom Bearden reports.
MAN: Utahans' Social Security numbers, names, addresses, birth dates.
TOM BEARDEN: Nine hundred thousand people had their names, addresses, and Social Security numbers stolen when the Utah Health Department's server was hacked. This kind of thing happens more often than most people realize: Web sites taken down, high-tech secrets stolen, intellectual property rights violated, and individuals swindled.
But Douglas Maughan says there's much more at stake than just crime. He heads the Department of Homeland Security's Cyber Security Division.
Labels:
computers,
cybersecurity,
data security,
pc security
Friday, March 2, 2012
INTERNET - Google's New Privacy Policy
"Google's New Privacy Policy: Invasive, Innovative or Both?" PBS Newshour 3/1/2012
Excerpt
COMMENT: As an IT Technician and internet user this is what I see.
First, the personal data IS collected by Google servers, so consolidating the data from all the servers makes no difference.
Second, I run Firefox browser with an Add-Blocker add-on, I can CHOOSE block any add, including Google adds. There are 3rd-party add-block utilities for your system and IE.
Then there are utilities like SUPERAntiSpyware that includes the option to remove Adware.Tracking Cookies.
You cannot protect people who leave the back door unlocked from getting robbed, the same applies to people who use the internet WITHOUT paying close attention to privacy issues involved.
Excerpt
JEFFREY BROWN (Newshour): And we turn to a big change for one of the tech industry's giants in the debate over online privacy.
In recent weeks, Google has been alerting its more than one billion users around the world that, beginning today, the company is consolidating some 60 privacy policies of its different services into one and more closely coordinating those services into one large database.
Here's part of how the company explains it.
WOMAN: So, instead of over 60 policies for different Google products and features, we're introducing just one, with fewer words, simpler explanations and less legal goop to wade through. That means that when you use Google, from Gmail and search, to YouTube and calendar, you can count on one simplified policy that explains our privacy commitment to you.
JEFFREY BROWN: Google says the move will also allow it to better serve customers by pulling together personalized information across a variety of different sites.
COMMENT: As an IT Technician and internet user this is what I see.
First, the personal data IS collected by Google servers, so consolidating the data from all the servers makes no difference.
Second, I run Firefox browser with an Add-Blocker add-on, I can CHOOSE block any add, including Google adds. There are 3rd-party add-block utilities for your system and IE.
Then there are utilities like SUPERAntiSpyware that includes the option to remove Adware.Tracking Cookies.
You cannot protect people who leave the back door unlocked from getting robbed, the same applies to people who use the internet WITHOUT paying close attention to privacy issues involved.
Labels:
browsers,
internet,
pc security,
privacy,
web
Thursday, January 5, 2012
SECURITY - Protecting Against Phishing
"How to Boost Your Phishing Scam Detection Skills" LifeHacker 1/5/2012
Phishing scams—the ones that try to get you to provide private information by masquerading as a legitimate company—can be easy to uncover with a skeptical eye, but some can easily get you when you let your guard down for just a second. Here's how you can boost your phishing detection skills and protect yourself during those times when you're not at full attention.
Want to test your phishing IQ and find out what kind of scams you're most likely to miss? Take this test.
What You Can Do
The way most phishing scams find victims is through email, but sometimes you'll come across a phishing site in the wild as well. Either way, here are the basic principles you want to follow to keep a cautious eye out for these malicious traps.
Check the URL
Phishing scams are designed to look like official emails and web sites from actual companies, but they aren't actually those things—they're just imitations. Because the emails and web sites are imitations they'll probably look a little different from what you'd expect in general, but more importantly those sites can't have the same URL as the web site they're pretending to because they are different sites. To check the URL, just hover of the link you're thinking of clicking. At the bottom of your window you should see the URL displayed. Once you do that, you have to figure out if it is a good URL or a bad URL.
Using PayPal as an example, you'll generally see http://www.paypal.com as part of the URL. Sometimes you'll see something like http://subdomain.paypal.com as well. Both of these URLs are okay, because they end in paypal.com. A phishing URL, however, might look something like this: http://paypal.someotherdomain.com. In this case, "paypal" is attached to another domain name (someotherdomain.com). URLs like this are the ones you want to avoid.
Always Go Direct
The best thing you can do to avoid phishing scams is always go directly to the web site you want to visit rather than clicking a link. This way you don't have to figure out if the URL is safe or not because you'll be using a URL in your bookmarks (or your brain) that you already know is safe. Doing this can also help protect you from phishing scams when you let your guard down because you'll be in the habit of visiting sites directly rather than clicking links.
I fell for a phishing scam once when I read the email right after I woke up in the morning. It was from my bank and they'd sent me a lot of verification notices lately since I'd been traveling and using my debit card all over the place. When I got another one, I didn't even think about it because I'd just woken up. I went to the site, filled in my info, and then immediately realized I'd just provided that information to a phishing scam site. I called the bank to let them know right away and got a new card, but had I changed my default behavior to calling the bank of visiting the bank's web site this probably wouldn't have happened. Of course, that's what I do now and it hasn't been a problem since.
What Your Browser Can Do For You
Detecting phishing scams on your own mainly require the mild paranoia and the behavioral adjustment described above, but there are a few other things you can do to make your everyday browsing safer.
Turn Off Form Autofill
One great feature of many web browsers is the autofill feature. It makes it really easy to fill out forms using information already stored in the browser. It also makes it easy for you to ignore the form you're filling out and just submit it, causing you to potentially miss a phishing scam when you're rushing through the process. While this precaution isn't necessary, and you might prefer the convenience of autofill to the safety benefits that deactivating it can provide, turning it off will provide a little added protection.
Utilize Your Browser's Built-In Tools
Most browsers come with some phishing protection built-in to help protect you, but it isn't always enable by default. Google Chrome keeps track of common phishing sites and can alert you when you visit one, but you may need to go through the short setup process to make it work. Firefox also offers phishing and malware protection in a similar way, and you can enable it in the Security section of Firefox's preferences.
Bump Up Your Phishing Protection with Web of Trust
Web of Trust is one of our favorite browser extensions because it automatically lets you know if a web site is trustworthy or not. While it can't possible verify every single site on the internet, it can make you aware of potentially harmful sites and phishing scams. All you have to do is install the extension for your browser and it will display a trust rating in your browser's toolbar. (You can read more about this here.) Web of Trust is available to download for Google Chrome, Firefox, Internet Explorer, Opera, Safari, and as a bookmarklet for other browsers.
Labels:
internet,
pc security,
windows
Friday, December 9, 2011
SECURITY - Pentagon Seeks Hacker Help
"Pentagon asks hackers for help with cyber security" by Joseph Straw, Daily News 11/8/2011
The Pentagon agency that invented the Internet is asking the hacker community for help in eliminating Defense Department computer vulnerabilities.
The Defense Advanced Research Projects Agency, or DARPA, hosted a meeting this week for defense stakeholders and civilian computer experts, acknowledging that it has to start thinking differently about cyber security, Wired.com reported.
And the computer networks that run U.S. infrastructure are so vulnerable to cyber attack that the White House should think twice before even attacking emerging adversaries, a national security expert said.
Richard Clarke, who advised ex-Presidents Bill Clinton and George W. Bush, added that U.S. defense networks are "as porous as a colander."
Their Goliath scale leaves them especially vulnerable to tiny attacks, the Associated Press and Wired reported.
Clarke, who claims his early 2001 warnings to the Bush administration about the emerging threat of Al Qaeda went unheeded, issued the new warnings as tensions escalate between the U.S., Israel and their shared adversary Iran.
Last month Wired reported that a mundane virus called a key logger - one that surreptitiously records keyboard typing - was found on the computers used to remotely pilot Air Force drones targeting terrorists overseas.
In 2009 national security officials disclosed that Russian and Chinese agents had penetrated the U.S. electric grid and left behind software to help map the systems.
Labels:
cybersecurity,
malware,
pc security,
web
Subscribe to:
Posts (Atom)









