Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Monday, May 9, 2011
Claim AC Comment
I recently wrote this and posted it anonymously to Slashdot. The links in that comment lead back to this blog, to posts about my startup environment, dm-live.
Wednesday, April 27, 2011
More bad karma for Sony
Perhaps, Sony could've spent a little more time on their own security, instead of wasting time locking out Linux users.
Update: 2011-05-01
A lot of news outlets covered this story, and named it the worst data breach in history. It was a featured story this week On the Media. Here is a link to the (mp3).
Monday, April 4, 2011
Epsilon data breach
Over the weekend, Slashdot reported that a company, epsilon, notified users it had been attacked and suffered a web intrusion into their databases. The intrusion resulted in a data breach. The data that was stolen constituted several million valid email addresses tied to the users' known vendors. This could lead to immediate "phishing" attempts- i.e. the bad guys impersonating the known vendor to trick the user into revealing more account details, etc. Here is Slashdot's
headline.
I received a notice from Abe Books informing me that their customer list was stolen. It's still to be determined how many different vendors accounts are affected.
I received a notice from Abe Books informing me that their customer list was stolen. It's still to be determined how many different vendors accounts are affected.
Thursday, January 20, 2011
On Point : Stuxnet
Yesterday's On Point discussed the Stuxnet worm. The guests were very much in favor of deploying the worm, and weren't shying away from calling it a weapon of war. They thought that it was a good alternative to a physical attack (airstrike). A few callers questioned the attack on the grounds that we have no declaration of war against Iran and that the attack was a covert operation. The host pointed out that the recipient of the attack can reverse engineer the "bomb," and potentially point it back at us. At least one caller amplified that theme. The guests responded that we are already under attack daily, and that we better be prepared for threats that can emerge very quickly. This kind of cyber attack may not be confined to computer networks. For example, one of the guests mentioned that enemies have surveyed our electrical grid for vulnerabilities. If I remember correctly, the Y2k disaster scenarios included failure of certain types of programmable controllers, perhaps similar to the ones targeted by Stuxnet, that are widely deployed in all kinds of industrial settings.
The stuxnet worm included four different attack scenarios using four different Windows zero day bugs. To me it seems that is a real grey area. The white-hat security researchers look for bugs in order to fix the OS; black hats find holes that they can exploit for profit. The "gray hats" are apparently at work finding holes that they can exploit to harm enemies.
Here is a link to the discussion.
Update: 2011-01-26
Slashdot reported recently that cybercriminals are finding that Windows is "tapped out" and are gearing up to attack other platforms. Whether that is really true, or not is debatable. (My WAG is that the Windows field is still ripe and there are easy pickins' for the taking.) However, others have already noted that a successful attack against unix (and its variants) would definitely be worth something to bad guys because the core of online sites are hosted on a unix-variant platform.
I thought this AC comment was on the mark.
Update: 2011-03-15
On the Media picked up the discussion. The point is made that it is "Hiroshima moment" in warfare. Stuxnet is a new type of weapon that was developed to target a specific enemy. It is the first salvo in the age of cyber-warfare.
The stuxnet worm included four different attack scenarios using four different Windows zero day bugs. To me it seems that is a real grey area. The white-hat security researchers look for bugs in order to fix the OS; black hats find holes that they can exploit for profit. The "gray hats" are apparently at work finding holes that they can exploit to harm enemies.
Here is a link to the discussion.
Update: 2011-01-26
Slashdot reported recently that cybercriminals are finding that Windows is "tapped out" and are gearing up to attack other platforms. Whether that is really true, or not is debatable. (My WAG is that the Windows field is still ripe and there are easy pickins' for the taking.) However, others have already noted that a successful attack against unix (and its variants) would definitely be worth something to bad guys because the core of online sites are hosted on a unix-variant platform.
I thought this AC comment was on the mark.
Update: 2011-03-15
On the Media picked up the discussion. The point is made that it is "Hiroshima moment" in warfare. Stuxnet is a new type of weapon that was developed to target a specific enemy. It is the first salvo in the age of cyber-warfare.
Monday, December 20, 2010
Interesting Computer Security Story
Here is an interesting headline with serious security implications for computer networks.
.
Wednesday, December 15, 2010
Stand up for the Bill of Rights? Anyone? Beuller?
This story is one that slips under the radar, but it has the potential to be as big of story as the warrantless wiretapping cases. This is another case with widespread implications for computer network security. IPSEC is a separate TCP/IP protocol designed for creating encrypted tunnels suitable for VPN traffic. For example, it is widely used to create encrypted tunnels between "home office" and "branch office" networks. The general idea is to create a wide area network with connections via the internet over secure and encrypted tunnels. The potential compromise of OpenBSD's IPSEC implementation raises serious security concerns because OpenBSD's permissive license allowed it to be used on a lot of hardware, especially "dedicated" VPN boxes.
This is a story to watch. A bunch of people are going to be taking a second look at the code. If it turns out there is a backdoor, it will be especially ironic because Theo de Raadt forked OpenBSD from FreeBSD mostly because he insisted on better security code auditing.
Here is Slashdot's
headline.
Also,
The Fourth Amendment doesn't really count for much any more. The disposition of the Mark Klein case is discouraging. I heard part of this interview.
Here it is broken into 10 minute segments:
1.
2.
3.
4.
5.
This is a story to watch. A bunch of people are going to be taking a second look at the code. If it turns out there is a backdoor, it will be especially ironic because Theo de Raadt forked OpenBSD from FreeBSD mostly because he insisted on better security code auditing.
Here is Slashdot's
Also,
The Fourth Amendment doesn't really count for much any more. The disposition of the Mark Klein case is discouraging. I heard part of this interview.
Here it is broken into 10 minute segments:
1.
2.
3.
4.
5.
Subscribe to:
Posts (Atom)