Tiny Khloe: 2026 Exxxotica Interview| Author | Post |
|---|---|
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | Hackers Lurking in Vents and Soda Machines By NICOLE PERLROTH APRIL 7, 2014 SAN FRANCISCO — They came in through the Chinese takeout menu. Unable to breach the computer network at a big oil company, hackers infected with malware the online menu of a Chinese restaurant that was popular with employees. When the workers browsed the menu, they inadvertently downloaded code that gave the attackers a foothold in the business’s vast computer network. Security experts summoned to fix the problem were not allowed to disclose the details of the breach, but the lesson from the incident was clear: Companies scrambling to seal up their systems from hackers and government snoops are having to look in the unlikeliest of places for vulnerabilities. Hackers in the recent Target payment card breach gained access to the retailer’s records through its heating and cooling system. In other cases, hackers have used printers, thermostats and videoconferencing equipment. Companies have always needed to be diligent in keeping ahead of hackers — email and leaky employee devices are an old problem — but the situation has grown increasingly complex and urgent as countless third parties are granted remote access to corporate systems. This access comes through software controlling all kinds of services a company needs: heating, ventilation and air-conditioning; billing, expense and human-resources management systems; graphics and data analytics functions; health insurance providers; and even vending machines. Break into one system, and you have a chance to break into them all. “We constantly run into situations where outside service providers connected remotely have the keys to the castle,” said Vincent Berk, chief executive of FlowTraq, a network security firm. Data on the percentage of cyberattacks that can be tied to a leaky third party is difficult to come by, in large part because victims’ lawyers will find any reason not to disclose a breach. But a survey of more than 3,500 global I.T. and cybersecurity practitioners conducted by a security research firm, the Ponemon Institute, last year found that roughly a quarter — 23 percent — of breaches were attributable to third-party negligence. Security experts say that figure is low. Arabella Hallawell, vice president of strategy at Arbor Networks, a network security firm in Burlington, Mass., estimated that third-party suppliers were involved in some 70 percent of breaches her company reviewed. “It’s generally suppliers you would never suspect,” Ms. Hallawell said. The breach through the Chinese menu — known as a watering hole attack, the online equivalent of a predator lurking by a watering hole and pouncing on its thirsty prey — was extreme. But security researchers say that in most cases, attackers hardly need to go to such lengths when the management software of all sorts of devices connects directly to corporate networks. Heating and cooling providers can now monitor and adjust office temperatures remotely, and vending machine suppliers can see when their clients are out of Diet Cokes and Cheetos. Those vendors often don’t have the same security standards as their clients, but for business reasons they are allowed behind the firewall that protects a network. Security experts say vendors are tempting targets for hackers because they tend to run older systems, like Microsoft’s Windows XP software. Also, security experts say these seemingly innocuous devices — videoconference equipment, thermostats, vending machines and printers — often are delivered with the security settings switched off by default. Once hackers have found a way in, the devices offer them a place to hide in plain sight. “The beauty is no one is looking there,” said George Kurtz, the chief executive of Crowdstrike, a security firm. “So it’s very easy for the adversary to hide in these places.” Last year, security researchers found a way into Google’s headquarters in Sydney, Australia, and Sydney’s North Shore Private hospital — and its ventilation, lighting, elevators and even video cameras — through their building management vendor. More recently, the same researchers found they could breach the circuit breakers of one Sochi Olympic arena through its heating and cooling supplier. Fortunately, the researchers were merely testing for flaws that could have been exploited by real hackers. Billy Rios, director of threat intelligence at Qualys, a security firm, was one of those researchers. He said it was increasingly common for corporations to set up their networks sloppily, with their air-conditioning systems connected to the same network that leads to databases containing sensitive material like proprietary source code or customer credit cards. “Your air-conditioning system should never talk to your H.R. database, but nobody ever talks about that for some reason,” Mr. Rios said. The Ponemon survey last year found that in 28 percent of malicious attacks, respondents could not find the source of the breach. Ms. Hallawell compared the process of finding the source of a breach to “finding a needle in a haystack.” Ideally, security experts say, corporations should set up their networks so that access to sensitive data is sealed off from third-party systems and remotely monitored with advanced passwords and technology that can identify anomalous traffic — like someone with access to an air-conditioning monitoring system trying to get into an employee database. But even then, companies require security personnel with experience in detecting such attacks. Even though Target used security technology supplied by FireEye, a company that sounds alerts when it identifies such anomalous activity, its I.T. personnel ignored the red flags, according to several people who confirmed the findings of a Bloomberg Businessweek investigation last month but could not speak publicly about Target’s continuing internal investigation. Like all else, security experts say, it’s simply a matter of priorities. One Arbor Networks study found that unlike banks, which spend up to 12 percent of their information technology budgets on security, retailers spend, on average, less than 5 percent of their budget on security. The bulk of that I.T. spending goes to customer marketing and data analytics. “When you know you’re the target and you don’t know when, where or how an attack will take place, it’s wartime all the time,” Ms. Hallawell said. “And most organizations aren’t prepared for wartime.” [Link] |
| Hardware All-Star Member Your other left 14595 Posts 3/02 | |
| BYOB_Kenobi Senior Member “Life can only be understood backwards; but it must be lived forwards.” - Kierkegaard 2684 Posts 8/09 | The scariest for me is the front-end fake vending machines. Our whole country doesn't give a shit about digital security, legally, federal enforcement, and making public/private companies accountable for stolen sensitive data (which is a function of no legal consequences). So many federal agencies using outdated computers, bad network, old software, outdated antivirus (U.S. Marshals Run Outdated Antivirus, Get Infected), lost-stolen laptops, etc. etc. Sure NSA gets endless money and any agency/mil-contractor labels something as anti-terrorism on a funding request. they get it, but anything else is considered crap. What about those credit/debit cards Europe uses that are more secure (Outdated Magnetic Strips: How U.S. Credit Card Security Lags), but we the superpower, richest country in world, our banks lag behind adopting/using them? We get hacked endlessly, not low level Joe Blow, but Senators, Pentagon, NASA, DoD, large tech companies, etc. etc. routinely. Prior and during military conflicts (Iraq) and other threats (Iran), we and other allies have knowingly used viruses to help shut down or interrupt communications prior to invasion. If this is a successful real world tactic, why do we still not care and take action. Start by playing defense and hardening and updating our systems. Pen test and stress test routinely. Have companies and governments become more accountable for breaches, stolen information and lost hardware/files. Per normal the US only cares about offense - latest Tomahawk cruise missile performance, rail guns, attack drones.... Long overdue to shore up our defenses and stay on top of it. |
| jayo All-Star Member 2117 Posts 7/04 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | |
| killbillvol69 All-Star Member ^Lucy Pinder 18635 Posts 4/08 | From that same article: "On Tuesday, a 19-year-old man was arrested in Canada on charges that he had used the Heartbleed flaw to steal taxpayer data from the Canada Revenue Agency. The agency reported on Monday that some 900 Canadian Social Security numbers had been compromised." This was big news up here. They had to shut down the Canada Revenue Agency website for 5 days, right when everyone is trying to pay their taxes in advance of the April 30 deadline. As a result, they've extended the income tax deadline to May 5 this year. For the whole country. That's a shit ton of money the government is missing out on when you consider how much money they take in, and losing the investment money they could have made on it for those 5 days. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | By NICOLE PERLROTH June 5, 2014 Security experts are still trying to plug the hole left by Heartbleed, the bug found in the widely used OpenSSL encryption protocol, with some 12,000 popular domains still vulnerable, according to AVG Virus Labs. Now they have something else to worry about. On Thursday, the OpenSSL Foundation issued a warning to users that a decade-old bug that makes it possible for an attacker to conduct a so-called man-in-the-middle attack on traffic encrypted with OpenSSL. The advisory warns users that someone could use the bug to intercept an encrypted connection, decrypt it, and read the traffic. Users of OpenSSL are advised to deploy a new patch and upgrade to the latest version of OpenSSL software. The bug was initially discovered by Masashi Kikuchi, a Japanese researcher at Lepidum, a software firm. “Attackers can eavesdrop and make falsifications on your communication when both of a server and a client are vulnerable,” reads an FAQ on Lepidum‘s website. Unlike Heartbleed, which could be used to directly exploit any server using OpenSSL, this new bug requires that the attacker be located between two computers communicating. A likely target, for example, would be someone using an airport’s public Wi-Fi. The new bug was introduced into OpenSSL when it was first released in 1998, more than 10 years before Heartbleed, which was first introduced in a code update on New Year’s Eve in 2011. The fact that the new bug went undetected for so long is another black mark on the management of OpenSSL. The encryption method is open source, meaning it can be reviewed and updated by anyone. Because of that, it is considered more secure and more trustworthy than proprietary code vetted by just one company’s engineers. But, in reality, OpenSSL had only one full-time developer and three “core” volunteer programmers in Europe, and operated on a budget of $2,000 in annual donations. This, despite the fact that OpenSSL is used to encrypt the majority of the world’s web servers and widely used by technology companies such as Amazon and Cisco. Following the Heartbleed discovery, major companies, including Amazon, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Rackspace, Qualcomm and VMWare, each pledged $100,000 a year over the next three years to the Core Infrastructure Initiative, a new open source initiative organized by the Linux Foundation to support crucial open-source infrastructure, like OpenSSL. |
| Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 | AUG. 10, 2015 By Zeynep Tufekci A FRIDGE that puts milk on your shopping list when you run low. A safe that tallies the cash that is placed in it. A sniper rifle equipped with advanced computer technology for improved accuracy. A car that lets you stream music from the Internet. All of these innovations sound great, until you learn the risks that this type of connectivity carries. Recently, two security researchers, sitting on a couch and armed only with laptops, remotely took over a Chrysler Jeep Cherokee speeding along the highway, shutting down its engine as an 18-wheeler truck rushed toward it. They did this all while a Wired reporter was driving the car. Their expertise would allow them to hack any Jeep as long as they knew the car’s I.P. address, its network address on the Internet. They turned the Jeep’s entertainment dashboard into a gateway to the car’s steering, brakes and transmission. A hacked car is a high-profile example of what can go wrong with the coming Internet of Things — objects equipped with software and connected to digital networks. The selling point for these well-connected objects is added convenience and better safety. In reality, it is a fast-motion train wreck in privacy and security. The early Internet was intended to connect people who already trusted one another, like academic researchers or military networks. It never had the robust security that today’s global network needs. As the Internet went from a few thousand users to more than three billion, attempts to strengthen security were stymied because of cost, shortsightedness and competing interests. Connecting everyday objects to this shaky, insecure base will create the Internet of Hacked Things. This is irresponsible and potentially catastrophic. That smart safe? Hackers can empty it with a single USB stick while erasing all logs of its activity — the evidence of deposits and withdrawals — and of their crime. That high-tech rifle? Researchers managed to remotely manipulate its target selection without the shooter’s knowing. Home builders and car manufacturers have shifted to a new business: the risky world of information technology. Most seem utterly out of their depth. Although Chrysler quickly recalled 1.4 million Jeeps to patch this particular vulnerability, it took the company more than a year after the issue was first noted, and the recall occurred only after that spectacular publicity stunt on the highway and after it was requested by the National Highway Traffic Safety Administration. In announcing the software fix, the company said that no defect had been found. If two guys sitting on their couch turning off a speeding car’s engine from miles away doesn’t qualify, I’m not sure what counts as a defect in Chrysler’s world. And Chrysler is far from the only company compromised: from BMW to Tesla to General Motors, many automotive brands have been hacked, with surely more to come. Dramatic hacks attract the most attention, but the software errors that allow them to occur are ubiquitous. While complex breaches can take real effort — the Jeep hacker duo spent two years researching — simple errors in the code can also cause significant failure. Adding software with millions of lines of code to objects greatly increases their potential for harm. The Internet of Things is also a privacy nightmare. Databases that already have too much information about us will now be bursting with data on the places we’ve driven, the food we’ve purchased and more. Last week, at Def Con, the annual information security conference, researchers set up an Internet of Things village to show how they could hack everyday objects like baby monitors, thermostats and security cameras. Connecting everyday objects introduces new risks if done at mass scale. Take that smart refrigerator. If a single fridge malfunctions, it’s a hassle. However, if the fridge’s computer is connected to its motor, a software bug or hack could “brick” millions of them all at once — turning them into plastic pantries with heavy doors. Cars — two-ton metal objects designed to hurtle down highways — are already bracingly dangerous. The modern automobile is run by dozens of computers that most manufacturers connect using a system that is old and known to be insecure. Yet automakers often use that flimsy system to connect all of the car’s parts. That means once a hacker is in, she’s in everywhere — engine, steering, transmission and brakes, not just the entertainment system. For years, security researchers have been warning about the dangers of coupling so many systems in cars. Alarmed researchers have published academic papers, hacked cars as demonstrations, and begged the industry to step up. So far, the industry response has been to nod politely and fix exposed flaws without fundamentally changing the way they operate. In 1965, Ralph Nader published “Unsafe at Any Speed,” documenting car manufacturers’ resistance to spending money on safety features like seatbelts. After public debate and finally some legislation, manufacturers were forced to incorporate safety technologies. No company wants to be the first to bear the costs of updating the insecure computer systems that run most cars. We need federal safety regulations to push automakers to move, as a whole industry. Last month, a bill with privacy and cybersecurity standards for cars was introduced in the Senate. That’s good, but it’s only a start. We need a new understanding of car safety, and of the safety of any object running software or connecting to the Internet. It may be hard to fix security on the digital Internet, but the Internet of Things should not be built on this faulty foundation. Responding to digital threats by patching only exposed vulnerabilities is giving just aspirin to a very ill patient. It isn’t hopeless. We can make programs more reliable and databases more secure. Critical functions on Internet-connected objects should be isolated and external audits mandated to catch problems early. But this will require an initial investment to forestall future problems — the exact opposite of the current corporate impulse. It also may be that not everything needs to be networked, and that the trade-off in vulnerability isn’t worth it. Maybe cars are unsafe at any I.P. |
| Use the code below to link to this topic or a specific post. |
| URL of this thread |
| Link to this post with HTML |
| Link to this post with Forum Code |