Monday, July 13, 2015

I am not a “world class” expert on encryption, but I know of no way to create “3 key” encryption. It may be possible. Ask the NSA. I can't think of any reason why they would employ such a system, but then it's been a while since I worked in that field.
If I thought that the FBI could read my encrypted files, I would no longer encrypt – I would encode. Sending, “Blue baby buggy bumpers” would convey exactly the same message as, “&7GDA PQPQ7 BLX8S GR4OK PWVUC” but would not be decipherable. (Neither would a “one time pad” but that is another story.)
Encryption: if this is the best his opponents can do, maybe Jim Comey has a point
… Behind the opponents’ demand for “concrete technical requirements” is the argument that any method of guaranteeing government access to encrypted communications should be treated as a security flaw that inevitably puts everyone’s data at risk. In principle, of course, adding a mechanism for government access introduces a risk that the mechanism will not work as intended.




“We gotta do something!” True, but shuffling the deck does not eliminate marked cards.
Lawmakers look to strip OPM powers after hack
… Reps. Ted Lieu (D-Calif.) and Steve Russell (R-Okla.), who both likely had their security clearance details taken in the breach, are prepping a bill that would move the security clearance database away from the OPM, perhaps back to the Defense Department (DOD), where it was housed until 2004.
“OPM was never designed to deal with national security,” Lieu told The Hill. [So which idiots moved it there? Bob]
But several senators backing a bill to boost oversight of those holding security clearances, told The Hill that it’s more audits, not necessarily a new agency, that the review process needs. [They ignored the audits that pointed out weak security, why would they stop ignoring them now? Bob]


(Related) Again, shuffling isn't the answer.
Chris Strohm, Michael Riley, and Jordan Robertson report:
The vast cyber-attack in Washington began with, of all things, travel reservations.
More than two years ago, troves of personal data were stolen from U.S. travel companies. Hackers subsequently made off with health records at big insurance companies and infiltrated federal computers where they stole personnel records on 21.5 million people — in what apparently is the largest such theft of U.S. government records in history.
Those individual attacks, once believed to be unconnected, now appear to be part of a coordinated campaign by Chinese hackers to collect sensitive details on key people that went on far longer — and burrowed far deeper — than initially thought.
Read more on Bloomberg.
[From the article:
“China is building the Facebook of human intelligence capabilities,” said Adam Meyers, vice president of intelligence for cybersecurity company CrowdStrike Inc. “This appears to be a real maturity in the way they are using cyber to enable broader intelligence goals.”




“Old data never dies” 2008 breach, 2014 discovery of the breach? Organizations say they have improved (suggesting “Fixed”) their security after every breach.
Herald Scotland reports:
Barclays is paying around half a million pounds in compensation to 2,000 customers, including many in Scotland, after their personal data was found on a USB stick at a flat on the south coast of England.
The electronic device was found by police with a copy of information originally lost last year in the latest problem to hit the banking industry.
The bank has written to around the customers offering them £250 compensation each.
Read more on Herald Scotland.
[From the article:
A source said the information on the USB stick would have been encrypted and almost impossible for it to be read without specialist technology.
The letter stated: "The data taken included information you provided in meetings with a Barclays Financial Planning adviser prior to 2009.
"It includes details taken during the meeting...and the subsequent letter Barclays sent you containing our investment recommendations." It added that it may 'take some time' to establish how the theft happened.
… In February last year it was revealed that thousands of files containing financial and personal data had been stolen from Barclay's internal data bases.
… The files run to 20 pages per person and contain information on customer's investment plans and capabilities and personal information such as health issues and passport number. Barclays say there is no evidence it had been opened
The information taken was provided by customers to Barclay's now closed Financial Planning service prior to 2009.
Since 2014, the company has drastically increased its cyber security capabilities. [Barn doors and missing horses Bob]
… A Barclays spokesman said: "This is not a new theft of data from Barclays. Every indication is that the data here was part of the same theft of data that was reported last year, relating to data stolen in 2008.




For my Ethical Hacking students. Why protecting your identity is important.
Elhanan Miller reports:
Computer hackers likely working for the Syrian regime and Hezbollah have managed to penetrate the computers of Israeli and American activists working with the Syrian opposition, exposing sensitive contacts between the sides.
Al-Akhbar, a newspaper serving as Hezbollah’s mouthpiece in Lebanon, published a series of articles over the weekend purporting to divulge correspondence between Mendi Safadi, a Druze Israeli and former political adviser to Deputy Regional Cooperation Minister Ayoub Kara, with members of the Syrian opposition around the world, taken from taken from Safadi’s computer.
[…]
Though Al-Akhbar’s articles contain dozens of names, nicknames and telephone numbers of Syrians and others who were in touch with Safadi, he maintained they face no real danger of reprisal.
Read more on Times of Israel.




Always surveilling?
EPIC Urges Investigation of “Always On” Consumer Devices
by Sabrina I. Pacifici on Jul 12, 2015
“EPIC has asked the Federal Trade Commission and the Department of Justice to conduct a workshop on ‘Always-On’ Consumer Devices. EPIC described the increasing presence of internet-connected devices in consumer’s homes, such as TVs, toys, and thermostats, that routinely record and store private communications. EPIC urged the agencies to conduct a comprehensive investigation to determine whether “always on” devices violate the Wiretap Act, state privacy laws, or the FTC Act. Earlier this year, EPIC filed a formal complaint with the FTC concerning Samsung TV, arguing that the recording of private communications in the home is an unfair and deceptive trade practice.”




Not a new type of intrusion, but one greatly facilitated by the Internet.
AP reports:
Someone else’s sex tape is proving to be costly for 50 Cent: A jury ordered the rapper-actor Friday to pay $5 million to a woman who said he acquired a video she made with her boyfriend, added himself as a crude commentator and posted it online without her permission.
And the Manhattan jurors are set to continue deliberating next week on possible further, punitive damages in Lastonia Leviston’s invasion-of-privacy lawsuit against the multiplatinum-selling “Get Rich or Die Tryin'” artist.
Read more on Fox News.


(Related) See? This one didn't even need the Internet.
Kathryn Schroeder writes:
A medical reality show used footage of a woman’s husband dying without her knowledge or permission and she only found out because she tuned in to watch the program.
Mark Chanko was struck and killed by a New York City sanitation truck. He is survived by his wife, Anita Chanko, who counts “NY Med” as one of her favorite television shows.
About 16 months after Mark’s death, Anita sat down to watch the program and, to her horror, her husband’s final moments in the hospital were being shown, reports PIX 11.
“I actually watched my husband die in front of my eyes and the worst thing is not only did I hear him moan and groan in pain but I heard him say, ‘Does my wife know I’m here?’” Anita said.
Read more on Opposing Views.
Okay, this definitely has a poor taste aspect to it, but have any privacy laws been broken? How was the airing of this not a HIPAA violation of her husband’s privacy? Public curiosity does not make this man’s care newsworthy, in my opinion. I realize that what happens out in public – on the street – may result in reduced privacy expectations, but filming him in the hospital?
How the heck was this found legal?




Might be a few government agencies in the email address list.
32k email addresses from the Hacking Team breach are now in “Have I Been pwned?”
… What I decided to do was just load the email addresses that appear in the PSTs. This may be a sender or a recipient or even a mention of the email in the body or in an address book, but they’re all just from the PSTs. Of the 32k addresses in there, some of them are completely inconsequential; password reset links, support queues, spam etc. But the vast majority are of consequence and the question of establishing context was solved once Wikileaks published the PSTs. They’re all now searchable which means that given a single email address that appears in HIBP against the Hacking Team breach, a Wikileaks search can establish the context.


(Related) Everyone wants to name a “state sponsor” for their hack. It makes it seems like they are less at fault if their “opponent” is an entire country!
Oh ho. Kelly Fiveash reports that Hacking Team claims it was the victim of a state actor:
The boss of Italian spyware vendor Hacking Team has spoken for the first time about the mass hack on the beleaguered company’s data – which has exposed severe software security holes and gifted terrorists with zero-day exploits.
David Vincenzetti, in an interview with La Stampa newspaper, claimed his firm would recover from the attack and alleged that an unnamed government or organisation with “considerable funds” had infiltrated its data servers and leaked the information.
Read more on The Register.




Perspective. You don't have to sell the most phones...
Apple Inc. Clinches 92% Of Overall Smartphone Industry Profits In Q1 2015
… Apple received 92% of the combined operating income of the top eight smartphone manufacturers in the first quarter of 2015, up from 65% last year. This number is even more surprising when you consider the fact that Apple only sells less than 20% of smartphones globally.




Something for my Intro to IT class!
History of the internet – 40 maps and key resources
by Sabrina I. Pacifici on Jul 12, 2015
For all those who do not recollect or may not know how the internet evolved from ARPANET in 1969 to the web of 2015 with its data analytics, e-commerce profiling and of course, global surveillance, I recommend 40 maps that explain the internet by Timothy B. Lee via Vox, posted on June 2, 2014: “The internet increasingly pervades our lives, delivering information to us no matter where we are. It takes a complex system of cables, servers, towers, and other infrastructure, developed over decades, to allow us to stay in touch with our friends and family so effortlessly. Here are 40 maps that will help you better understand the internet — where it came from, how it works, and how it’s used by people around the world.”




I need to try this. We might use it in our Business classes.
Microsoft's Business Intelligence Service Gets a Power Boost
An updated version of Microsoft’s Power BI service will be released July 24, the company announced Friday. The goal of the updated service is to enable business users to benefit from business intelligence Relevant Products/Services and analytics without requiring sophisticated help from analysts, data Relevant Products/Services scientists, or other tech staff.
… "We believe Power BI is, by a very wide margin, the most powerful business analytics SaaS service," said James Phillips, corporate VP for Microsoft's Business Intelligence Products Group. "And yet, even the most non-technical of business users can sign up in five seconds, and gain insights from their business data in less than five minutes with no assistance, from anyone."
Microsoft offers two levels of the upgraded Power BI service: a free version and another that’s $9.99 per month/per user. The differences between the two tiers have mostly to do with data-refresh rates and collaboration capabilities.


Sunday, July 12, 2015

Another third party vendor. Did they comply with WalMart's required security?
Ahmad Hathout and David Berman report:
Walmart Canada is investigating a potential breach of customer credit card data after one of its websites operated by a third party was compromised.
[…]
A source close to the situation told The Globe and Mail that as many as 60,000 customers could be affected.
According to Walmart’s website, PNI Digital Media operates its online photo centre.
Read more on Globe and Mail.
[From the article:
… the company has disabled the website and its mobile applications and notified the Office of the Privacy Commissioner of Canada.
Walmart said it has “no reason to believe” its Walmart.ca and Walmart.com destinations or its in-store transactions have been affected.




There are techniques that Anthem could have used to confirm that their data was used, but they might view that as counter productive.
On Thursday, I had this exchange with @dapnwmomster on Twitter:
So hackers pull off mammoth hacks like #Anthem and #OPM but none of the data have misused? Is that what we're really supposed to believe?

@PogoWasRight Many Anthem customers had their info used by hackers filing false tax returns - the identity protection they provided FAILED.

@dapnwmomster I'm not sure how plaintiffs can prove the info used in fraudulent filings was from Anthem given numerous other breaches.
Today, J.K. Wall has a report on Indianapolis Business Journal that pretty much reiterates what I had suggested: Anthem continues to claim that there is no evidence of ID theft due to their breach, and it’s going to be challenging for plaintiffs’ attorneys to show that any fraud was due to that breach. Wall starts out by reporting:
Anthem Inc.’s massive data breach reported early this year is now generating real cases of identity theft, according to allegations in a small but growing number of lawsuits filed across the country.
Twenty-six people who have sued the Indianapolis-based health insurer claim they were victims of fraud, with most saying fraudulent tax returns were filed in their names using information obtained from Anthem. It had 78.8 million current and former customers’ records stolen by hackers from Dec. 10 to Jan. 27.
And right there is the first thing that would make me suspicious: why would there be only 26 cases of fraud if 80 million people’s information stolen for criminal purposes? I’d expect a lot more. A lot. Much more than the “hundreds more” one attorney suggests will join the law suit.
But Anthem maintains it’s not the source of its customers’ troubles. That’s based on weekly reports it receives from the FBI, which is checking the black market to see if anyone is selling information from the Anthem hack.
“As part of the ongoing investigation regarding Anthem’s cyber attack, the FBI has been routinely monitoring for fraudulent activity related to this incident,” Anthem spokeswoman Kristin Binns wrote in an email. “Despite allegations to the contrary, there is no evidence that the cyber attackers have shared or sold any individuals’ data; and there is no evidence that fraud has occurred against any individuals who could have been impacted.”
Even if people suspect or believe that the Anthem breach is responsible for any woes they or their minor children have experienced, connecting the dots from the breach to the problems will be a serious hurdle in litigation.




Not sure of the strategic value here, but I'll be interested in following the story.
Daily Pakistan reports:
For the first time, ‘tracking chips’ will be installed in (sic) the feet of 1,600 terror suspects in Punjab province after Eidul Fitr to monitor their movements.
There are some 1,600 terror suspects on the list of the Fourth Schedule in Punjab. The Fourth Schedule defines a terror suspect as a “person who is concerned in terrorism or he belongs to a proscribed organisation”.
“The Punjab government has decided in principle to start electronic surveillance of 1,600 Fourth Schedulers by installing tracking devices on their ankles (commonly known as ankle-band) so that their movements can be monitored,” a spokesman for the provincial Counter-Terrorism Department told the media on Friday.
Read more on Daily Pakistan.




So my new website about Donald Trump's brain (TheBigEmpty.com) would not be anonymous? I'd be sued immediately by “The Donald” – the publicity would be enormous!
New proposal would strike at web’s anonymity
Privacy advocates, public interest groups and even some celebrities are raising alarms about a proposal that could limit the ability of some website owners to disguise themselves.
The issue has caught fire over the past few months as an obscure organization that manages the Internet's domain name system was inundated with comments about a proposal that could bar commercial websites from using proxies to register their web addresses.
… “Whatever the interest in unmasking an anonymous speaker, free speech interests demand the preservation of opportunities for anonymous speech,” Public Knowledge, the Open Technology Institute and the Center for Democracy and Technology argued in joint public comments.
Individuals and businesses are currently allowed to hide their identity, physical location and other personal contact information behind proxies in the public “WHOIS” directory that stores information online about the owners of every registered website domain name.
Proxies can be used by anyone registering a domain, from a lawmaker gearing up for a presidential run who does not want to tip off the press, to a blogger posting unpopular views online. The proxy service comes standard with many of the major domain registrars like GoDaddy.




Innovative or inevitable? I'd say the latter.
Federal agencies test new “release for one, release to all” FOIA policy
by Sabrina I. Pacifici on Jul 11, 2015
Reporters Committee on Freedom of the Press – Adam Marshall, July 9, 2015: “With little public fanfare, seven federal agencies have announced a controversial trial program of publishing documents responsive to most Freedom of Information Act requests online. Under the program, known as a “Release-to-One is Release-to-All” policy, any member of the public will presumably have access to the result of almost any FOIA request. Few other details were released in a brief announcement posted on several agency websites. It remains to be seen whether there will be a delay between sending responsive documents to the requester and posting them for the general public, or whether requesters will simply be sent a link to a public website that already hosts the documents. Agencies participating in the six-month pilot include the
Environmental Protection Agency, the
Office of the Director of National Intelligence, the
Millennium Challenge Corporation, and
certain components of the Department of Defense, the
Department of Homeland Security, the
Department of Justice, and the
National Archives and Records Administration.
In order to mitigate privacy concerns, the announcement states that “participating agencies will not post online responses to requests in which individuals seek access to information about themselves.”




I don't see how the logistics would work unless we shipped the chickens in old oil tankers.
US chicken and seafood processed in China – returned for sale stateside
by Sabrina I. Pacifici on Jul 11, 2015
Food Safety News – “Thanks to our Change.org petition (307,000-plus signatures and rising), millions of Americans have learned that the U.S. Department of Agriculture (USDA) is about to allow U.S chickens to be sent to China for processing and then shipped back to the U.S. for human consumption. This arrangement is particularly alarming given China’s appalling food safety record and the fact that there will be no on-site USDA inspectors in those plants. In addition, American consumers will never know that chicken processed in China is in foods like chicken soup or chicken nuggets because there’s no requirement to label it as such… According to the Seattle Times, domestically caught Pacific salmon and Dungeness crab are currently being processed in China and shipped back to the U.S., all because of significant cost savings…”




I keep trying to make sense of this industry.
Why Taylor Swift will not fight with YouTube
Taylor Swift has become the poster child for defending the rights of all artists from tech giants like Apple and Spotify, who are looking to give away music through their free streaming services.
… Swift's disapproval of Apple's decision is not the first time she openly expressed her feelings about the music-streaming industry. Late last year, Swift also pulled her music from Spotify in an effort to stress the negative ramifications of free streaming on the future of the music business.
But there is one platform in which Swift does not have "Bad Blood": YouTube.
… So why is YouTube receiving seemingly preferential treatment?
The simple answer is, the economics of YouTube make more sense for the 25-year-old and other artists looking to protect their future revenue, because YouTube videos serve a major promotional purpose. On YouTube, Swift is able to monetize her videos in more ways than Spotify and Apple can provide.




For my students, all of whom will use Windows 10.
Lenovo releases a PDF guide to help you get started with Windows 10
… The guide is titled "Starting to use Windows 10" and helps Windows users find out everything new in the operating system.




I want my students to speak the truth, just not to me.


Saturday, July 11, 2015

OPM's version of events.
Information about OPM Cybersecurity Incidents
by Sabrina I. Pacifici on Jul 10, 2015


(Related) If OPM had a Board of Directors, would they fire all the senior managers?
Add Adam Shostack’s post to your must-read list. Here’s a snippet:
The National Journal published A Timeline of Government Data Breaches:
OPM Data Breach
I asked after the root cause, and Rich Bejtlich responded “The root cause is a focus on locking doors and windows while intruders are still in the house” with a pointer to his “Continuous Diagnostic Monitoring Does Not Detect Hackers.”
And while I agree with Richard’s point in that post, I don’t think that’s the root cause. When I think about root cause, I think about approaches like Five Whys or Ishikawa. If we apply this sort of approach then we can ask, “Why were foreigners able to download the OPM database?” There are numerous paths that we might take….
Keep reading on Emergent Chaos.


(Related)
Julie Hirschfield Davis reports:
Katherine Archuleta, the director of the Office of Personnel Management, resigned under pressure on Friday, one day after the government revealed that two sweeping cyberintrusions at the agency had resulted in the theft of the personal information of more than 22 million people, including those who had applied for sensitive security clearances.
Ms. Archuleta went to the White House on Friday morning to inform President Obama that she was stepping down immediately. She said later in a statement that she felt new leadership was needed at the federal personnel agency to enable it to “move beyond the current challenges.”
Read more on The New York Times.




I can see a few holes in this procedure. Probably the FBI will ask for several months to check for records they should already have in their possession.
Background Check Flaw Let Dylann Roof Buy Gun, F.B.I. Says
The man accused of killing nine people in a historically black church in South Carolina last month should not have been able to buy the gun he used in the attack, the F.B.I. said Friday, in what was the latest acknowledgment of flaws in the national background check system.
A loophole in the system and an error by the F.B.I. allowed the man, Dylann Roof, to buy the .45-caliber handgun despite having previously admitted to drug possession, officials said.
Mr. Roof first tried to buy the gun on April 11, from a dealer in South Carolina. The F.B.I., which conducts background checks for gun sales, did not give the dealer approval to proceed with the purchase because the bureau needed to do more investigating about Mr. Roof’s s criminal history.
Under federal law, the F.B.I. has three days to determine whether there is sufficient evidence to deny the purchase. If the bureau cannot come up with an answer, the purchaser can return to the dealer and buy the gun.
In the case of Mr. Roof, the F.B.I. failed to gain access to a police report in which he admitted to having been in possession of a controlled substance, which would have disqualified him from purchasing the weapon. The F.B.I. said that confusion about where the arrest had occurred had prevented it from acquiring the arrest record in a timely fashion.
Mr. Roof’s application was not resolved within the three-day limit because the F.B.I. was still trying to get the arrest record, and he returned to store and was sold the gun.




Just another Thing on the Internet of Things? There's a lot of money flowing alongside the data.
Carmakers want to build a data business. So far they’re screwing it up.
In a move that will surprise no one, automakers want to become a platform and plan to do this by limiting the data they share with Apple and Google.
… The idea is that customers want to use their smart phones as navigation devices and as the link to their music and entertainment accounts–a battle carmakers lost by being slow to adopt new technology and by charging a pretty penny for things like upgraded map CDs—but auto companies still have detailed engine, braking and other highly useful and technical data they can share about the car’s performance and history. And that data is worth something
… The stakes are potentially huge: General Motors Co told investors earlier this year that it expects to realize an additional $350 million in revenue over three years from the high-speed data connections it is building into its cars.
Consultant AlixPartners estimates global revenues from digitally connected cars will grow in value to $40 billion a year worldwide by 2018, from $16 billion in 2013


(Related) So how can my students tap into that money?
Cutting through Internet of Things Hype
The Internet of Things topped Gartner's list of most-hyped technologies last summer. But compelling business cases for IoT are beginning to emerge.
… Dan Vesset, an analyst at International Data Corp., stressed the importance of data monetization for IoT, focusing on how it could be harnessed by media and other content-centric businesses to add value. Citing Clive Humby, who is credited with saying that data is the new oil, Vesset used an oil refinery example.
"Data is valuable like crude oil, but it is unrefined and has to be processed into valuable products," he said. "That means it has to be broken down, analyzed and reassembled."
… a company named Schneider Electric intends to literally build a better mousetrap. Unlike the refrigeration case, an IoT-enabled mousetrap offers significant business potential. By adding sensors to traps, it becomes possible to offer a rodent removal service rather than just selling traps. This switches the business model from a one-time sale to a monthly subscription fee.
… Schneider Electric it takings its realization that services are more important than devices to other aspects of its electronics business. Instead of selling thermostats, it’s now giving them away free to companies that will pay a monthly subscription fee. To make this work, they added sensors to the devices so they can detect sound, motion and temperature.
If the temperature drops or no sound and motion are detected, the system is programmed to conserve energy. The value proposition: The company guarantees a 20 percent energy reduction, which typically yields greater savings than the monthly charge.




Interesting. Backup power to the cellphone towers? Is 8 hours reasonable? After hurricane Katrina, didn't it take a few weeks?
FCC considers safeguards as landlines move to IP
As landline phones move toward operation over the Internet, the Federal Communications Commission wants to make sure those lines are still able to get a signal during a power outage.
FCC Chairman Tom Wheeler on Friday proposed new rules that would force phone providers to offer backup power for customers to buy as they transition away from copper lines.
"IP-based home voice services are more vulnerable to outages during emergencies than their copper predecessors," FCC Chairman Tom Wheeler said in a blog post.
… Phone companies would have to offer customers the chance to purchase eight hours of backup power for an emergency. That number would increase to 24 hours of backup power in three years.




Gee, it must be Saturday...
Hack Education Weekly News
… Via The Chronicle of Higher Education: “The average amount that college students spend on course materials appears to be declining. But not necessarily because textbooks are cheaper. A growing number of students, surveys show, simply skip buying required course materials.”
… A school district in Iowa will put body cameras on principals. “The district spent about $1,100 to purchase 13 cameras at about $85 each. They record with a date and time stamp, can be clipped onto ties or lanyards, and can be turned on and off as needed. For now, they won't be used to record all interactions with adults,” says The Atlantic. Body cameras on cops and body cameras on principals – go ahead and make the connection about what that makes schools…
… Carnegie Mellon University plans to install sensors all over its campus, thanks to $500,000 in funding from Google. According to The Chronicle of Higher Education, “campus could be wired with temperature sensors, cameras, microphones, humidity sensors, vibration sensors, and more in order to provide people with information about the physical world around them. Students could determine whether their professors were in their offices, or see what friends were available for lunch.” Gee, how did universities ever survive without this.