Sunday, May 08, 2016
An observation. Today’s
Election section of the Google News page is all Donald Trump. There are no articles on Hillary Clinton until
you page down. No matter what else you
may think, the Donald does know how to lead the media by the nose.
One of the “benefits” of Office365?
How can these devices remain undetected for months? Do watch the video!
Large Credit Card Breach at Walmart in Fredericksburg
Fredericksburg City Police says a "large number"
of debit/credit card users at the Central Park Walmart had their card
information stolen, with dozens of reports of fraudulent cash withdrawls.
Walmart Global has confirmed an unspecified number of
cards have been compromised.
It's
believed the suspects obtained the card information by placing overlay devices
on credit card readers at checkout counters in March and April.
… In a statement to Patch, Walmart spokesperson Deisha Barnett
said the company took steps to protect customers as soon as
they were alerted to the fraudulent activity.
… Fredericksburg City Police also released a video to show how
quickly a skimmer device is placed on a credit/debit card readers. [Not at
Walmart, but still interesting. Bob]
We don’t track smartphones as closely as we track airbags.
Lucian Constantin reports:
A vulnerability in an Android
component shipped with phones that use Qualcomm chips puts users’ text messages
and call history at risk of theft.
The flaw was found by security
researchers from FireEye and was patched by Qualcomm in March. However, because the vulnerability was introduced five years ago, many affected
devices are unlikely to ever receive the fix because they’re no longer supported by their manufacturers.
Read more on Computerworld.
We have become a nation of terrified, gullible, ignorant sheep.
Dark, Curly Haired Man With Olive Skin Suspected of Terrorism
After Intensely Scribbling Strange Script Aboard Plane. But There’s Just One
Problem.
… An airline agent
told the man he was suspected of terrorism, the Post said — mostly because of
whatever it was his former seatmate had seen him intensely scribbling (but his
look and accent apparently gave her pause, too).
The man under investigation laughed, the paper said.
He wasn’t scribbling in Arabic or penning code for a
terrorist plot — he was in the middle of a math equation.
Guido Menzio hails from Italy and is a well-regarded
economist who’s an associate
professor at the University of Pennsylvania.
… Menzio told the paper
he was “treated respectfully throughout” but is unimpressed by a “broken system
that does not collect information efficiently.” He added to the Post that airline security
protocol “is too rigid — in the sense that once the whistle is blown everything stops without
checks – and relies on the input of people who may be completely clueless.”
Saturday, May 07, 2016
There goes that Guinness World Record.
Garbage in, garbage out: Why Ars ignored this week’s massive
password breach
Earlier this week, mass panic ensued when a security firm
reported the recovery
of a whopping 272 million account credentials belonging to users of Gmail,
Microsoft, Yahoo, and a variety of overseas services. "Big
data breaches found at major email services" warned Reuters, the news
service that broke the news. Within
hours, other news services were running stories based on the report with
headlines like "Tech
experts: Change your email password now."
Since then, both Google and a Russia-based e-mail service
unveiled analyses that call into question the validity of the security firm's
entire report.
"More than 98% of the Google account credentials in
this research turned out to be bogus," a Google representative wrote in an
e-mail. "As we always do in this
type of situation, we increased the level of login protection for users that
may have been affected." According
to the report, the compromised credential list included logins to almost 23
million Gmail accounts.
(Related)
Here's how I verify data breaches
A continuous process.
Nothing new there. Perhaps if we
combine IBM’s Watson with their Quantum Computer…
Mohit Kumar writes:
Defense Advanced Projects Agency
(DARPA) is offering funding for security researchers who can help the agency to
develop algorithms that can identify hackers under its new game-changing
initiative called ‘Enhanced
Attribution Program’.
Although organizations and
countries give their best to identify cyber campaigns who infiltrated their
critical infrastructure, tracking down the culprits has always been a difficult
task — thanks to TOR, Virtual Private Networks (VPNs), and other methods
used to hide the attack source.
However, through this new
initiative, the United States military research agency DARPA hopes that
agencies would quickly track and identify sophisticated hackers
or criminal groups by monitoring their exact behavior and physical
biometrics.
The aim of Enhanced Attribution
program is to track personas continuously and create “algorithms for
developing predictive behavioral profiles.”
“The goal of the Enhanced
Attribution (EA) program is to develop technologies for generating
operationally and tactically relevant information about multiple concurrent
independent malicious cyber campaigns, each involving several operators; and
the means to share such information with any of a number of interested parties
without putting at risk the sources and methods used for collection,” reads the
project’s official site.
In other words, the Enhanced
Attribution Program will not only help the government characterize the cyber
criminal but also share the criminal’s modus operandi with potential victims
and predict the attacker’s next target.
Read more on The Hacker News.
Wait… “without putting at risk the sources and methods
used for collection?” That sounds to me
like a response to recent court cases where the government has dismissed cases
rather than reveal their surveillance methods
Does Congress know about this? Do computers have a “Right to Privacy?” Perhaps a “Right to be left alone?”
Lindsay Tonsager writes:
In a blog
post published on the Federal Trade Commission (FTC) website, Jessica
Rich, Director of the FTC’s Bureau of Consumer Protection,
recently stated that:
“we regard data as ‘personally
identifiable,’ and thus warranting privacy protections, when it can be reasonably
linked to a particular person, computer,
or device. In many cases,
persistent identifiers such as device identifiers, MAC addresses, static IP
addresses, or cookies meet this test.”
The post (which
reiterates Ms. Rich’s remarks at the Network Advertising Initiative’s
April meeting) suggests a shift in the FTC’s treatment of IP addresses and
other numbers that identify a browser or device. The FTC
previously has taken the position that browser and device
identifiers are deserving of privacy protections, but the FTC generally
has avoided classifying these identifiers as equivalent to
personally identifiable information (such as name, email, and
address) except in the narrow context of children’s privacy.
Read more on Covington & Burling Inside
Privacy.
I don’t post much from Kellogg. I’m not sure why that is.
Is Reading Someone’s Emails Like Entering Their Home?
… In the late
nineteenth century, when considering laws about intercepting confidential
messages, Congress debated whether the telegraph was comparable to the postal
service. Protecting the privacy of a telegram,
after all, only made sense if everyone agreed that telegrams were analogous to
personal letters—a view that, though it never became an official act of
Congress, was eventually supported by state laws.
But the rise of electronic communications has made this
analogical reasoning even more of a headache. By 1995, courts were debating whether
encryption software belonged on a list of regulated munitions (alongside bombs
and flamethrowers) or whether encryption was in fact a “language act” protected
by the first amendment.
Wouldn’t this fall under the same exemption as your
fingerprints? It’s pretty hard NOT
seeing your face, does a photograph make that much of a difference?
Defeat for Facebook in Court Is Bad News for Firms That Scan
Faces
Who owns your
face?
A California judge on Thursday ruled against Facebook in a lawsuit that says the company violated user privacy by
scanning their faces without permission and inviting others to “tag” them in
photographs.
The case is significant because it’s one of the first to
test the boundaries of how companies use facial recognition software, a
rapidly-advancing technology that treats faces as the modern-day equivalent of
a fingerprint. (At Facebook, the company
has internally referred to the tool as a “faceprint.”)
… In the ruling,
which you can read
here, U.S. District Judge James Donato agreed that Facebook’s scanning and
tagging feature qualified as a use of biometric identifier covered by the
statute. On a key procedural issue, he
refused Facebook’s request to decide the case under California law, where
companies don’t face restrictions on the use of biometrics.
Statistically backed assertions.
… How large is this
secret ECPA docket? Extrapolating from a
Federal Judicial Center study
of 2006 federal case filings, I have estimated
that more than 30,000 secret ECPA orders were issued that year alone. Given recent DOJ disclosures,
the current annual volume is probably twice that number. And those figures do not include surveillance
orders obtained by state
and local authorities, who handle more than 15 times the number of felony
investigations that the feds
do. Based on that ratio, the annual
rate of secret surveillance orders by federal and state courts combined could
easily exceed half a million. Admittedly
this is a guess; no one truly knows, least of all our lawmakers in Congress. That is precisely the problem.
Some interesting (or at least amusing) speculation.
Panama
Papers Source Offers to Aid Inquiries if Exempt From Punishment
The anonymous source behind the huge leak of documents
known as the Panama Papers has
offered to aid law enforcement officials in prosecutions related to offshore
money laundering and tax evasion, but only if assured of protection from
punishment.
“Legitimate
whistle-blowers who expose unquestionable wrongdoing, whether insiders or
outsiders, deserve immunity from government retribution,” the source, who has
still not revealed a name or nationality, said in a statement
issued Thursday night.
This should amuse my researching students.
OSoMe: The IUNI observatory on social media
by Sabrina I. Pacifici on May 6, 2016
OSoMe: The IUNI
observatory on social media. PeerJ
Preprints 4:e2008v1 https://doi.org/10.7287/peerj.preprints.2008v1
“The study of social phenomena is becoming increasingly
reliant on big data from online social networks. Broad access to social media data, however,
requires software development skills that not all researchers possess. Here we present the IUNI Observatory on
Social Media, an open analytics platform designed to facilitate
computational social science. The system
leverages a historical, ongoing collection of over 70 billion public messages
from Twitter. We illustrate a number of
interactive open-source tools to retrieve, visualize, and analyze derived data
from this collection. The Observatory,
now available at osome.iuni.iu.edu,
is the result of a large, six-year collaborative effort coordinated by the
Indiana University Network Science Institute.”
Wisdom from my favorite statistical website. (I think #4 will become critical)
The Four Things I Learned From The Donald Trump Primary
1. Don’t rule out the ahistorical
when there’s little history.
2. Take a nuanced view of the
polls.
3. Maybe favorability ratings
aren’t as hard to change as we thought.
4. Don’t assume the party knows
what it’s doing.
Let’s give some credit to Trump himself! No, I don’t think that Trump is a strategic
and tactical mastermind who planned every move he made, or even that every move
was successful. On the whole, though,
more of what he did worked than didn’t work. Trump generated
a ton of free media coverage; that helped him. He was willing
to challenge Republican orthodoxy; that, at the very least, didn’t hurt
him. I don’t know whether he’s built a
new political coalition or the Trump phenomenon is sui generis, but whatever
the guy did, it worked.
Local. Fluffy. Looks like it was written by DU’s Marketing
team. http://www.csoonline.com/article/3065841/leadership-management/universities-developing-cybersecurity-degrees-to-fill-jobs-gap.html?google_editors_picks=true
Universities developing cybersecurity degrees to fill jobs
gap
If they want to continue to protect our nation’s most
valuable data from cyber-attacks, leading security practitioners need to look
to the future of the security industry and develop ways to grow the talent
needed to fill the looming jobs gap.
My Saturday sillies.
Hack Education Weekly News
… The Justice
Department has warned
North
Carolina that its new anti-trans bathroom law violates the Civil Rights Act.
According
to the AP, “North Carolina’s prized public universities could be the
biggest losers as state leaders defend a new law limiting the rights of LGBT
people. The 17-university system, which
includes the University of North Carolina at Chapel Hill and North Carolina
State University as well several historically black colleges, risks losing more
than $1.4 billion in federal funds if the Republicans who run the Legislature
don’t reverse the law. The U.S. Justice
Department wants an answer by the end of business on Monday.” The new head of the UNC system, “Margaret Spellings
Is Caught Between Her State and the Federal Government. Now What?” asks
The Chronicle of Higher Education.
… Via
Inside Higher Ed: “The Federal Trade Commission announced Thursday that the
operators of Gigats.com
agreed to settle deception charges. Gigats.com
is an education lead-generation company based in Orlando, Fla., that
claims to prescreen job applicants for employers. However, the company was
instead gathering information for for-profit colleges and career
training programs, according to the FTC.”
For my Computer Security and Ethical Hacking students.
Pay What You Want for the Ethical Hacker and Pentester Pro
Learning Bundle
… Anyone can start
learning them with the Ethical Hacker and Pentester Pro Bundle at MakeUseOf Deals.
It combines nine high-quality video courses,
and you can pay what you want for the tuition. Read on to find out more.
… All of these courses come with lifetime access, and you can
stream the lessons on desktop and mobile devices. Best of all, you can claim a certificate of
completion to put on your CV when you master each subject.
… You can name your price on the last two courses in this deal, but to unlock the full bundle, you simply need to beat the
average price paid. These
nine courses are normally worth $1,431 put together, so grab the bundle now to
enjoy a huge markdown!
Friday, May 06, 2016
Surely no bank is still using Windows XP?
New Trojan Targets Banks in US, Mexico
… The Trojan,
written in .NET apparently by Spanish-speaking developers, caught the attention
of researchers because it relies on popular tools such as Fiddler, an HTTP
debugging proxy server application, and Json.NET, a high-performance JSON
framework for .NET.
The malware is delivered using an installer named
“curp.pdf.exe” that is served on several compromised websites. Once executed, the installer downloads three
files to the Windows system directory: the main payload (syswow.exe), a Fiddler
DLL file (FiddlerCore3dot5.dll), and a Json.Net DLL file (Newtonsoft.Json.dll).
The main payload is then executed and
the installer terminates itself.
.. If the infected
machine is running Windows XP or Windows Server 2003, the malware creates a
registry entry for persistence, downloads a configuration file, and launches
the Fiddler proxy engine. For other
Windows versions, the threat doesn’t create a registry entry, and it starts the
proxy engine only after installing a Fiddler-generated root certificate.
Once it’s installed on a device, the malware collects
system information and sends it back to its command and control (C&C)
server, which responds with a configuration file containing different C&C
locations and other instructions. Json.NET
is used to parse the server’s response and save it in an XML file. This file contains the list of domains
targeted by the malware — when users visit these domains, they are redirected
to phishing websites designed to trick them into handing over their
information.
A small local problem?
Kieran Nicholson reports:
State investigators are looking
into a database breach at the Colorado Department of
Transportation which could lead to identity thefts.
The breach of the Disadvantaged Business
Enterprise program with CDOT was discovered recently and has
been reported to the Colorado Bureau of Investigation, said Amy Ford, a CDOT
spokeswoman.
[…]
“A probationary employee, who
worked at CDOT from January 2016 to April 2016 and had access to confidential tax
returns of DBE…firms, had been using personal information for improper
purposes,” the notification letter, sent Wednesday, said.
Read more on Denver
Post.
One way to control your music library?
Apple Stole My Music. No, Seriously
“The software is functioning as intended,” said Amber.
“Wait,” I asked, “so it’s supposed to delete my personal files from my internal hard drive without asking my permission?”
“Yes,” she replied
“Wait,” I asked, “so it’s supposed to delete my personal files from my internal hard drive without asking my permission?”
“Yes,” she replied
… What Amber
explained was exactly what I’d feared: through the Apple Music subscription,
which I had, Apple now deletes files from its users’ computers. When I signed up for Apple Music, iTunes
evaluated my massive collection of Mp3s and WAV files, scanned Apple’s database
for what it considered matches, then removed the original files from my
internal hard drive. REMOVED them. Deleted. If Apple Music saw a file it didn’t
recognize—which came up often, since I’m a freelance composer and have many
music files that I created myself—it would then download it to Apple’s
database, delete it from my hard drive, and serve it back to me when I wanted
to listen, just like it would with my other music files it had deleted.
(Related) I will have to warn my students.
Apple Music’s new student membership option discounts the
service by 50%
Amid news that Apple
Music is getting a makeover come this summer, Apple today launched a
new plan to boost subscribers to its streaming music service and competitor to
Spotify, SoundCloud, Tidal and others. It’s
introducing an Apple Music student plan which will discount the service by 50
percent for those who are enrolled in an eligible college or university.
… The student
membership is rolling out now in the available markets.
Think about those little secondary issues?
Cheryl Clark reports:
When Sharp Grossmont Hospital
officials realized anesthesia drugs were disappearing from surgery carts, they
turned to video surveillance to catch those responsible. In the process, they also captured many images
of women undergoing surgery.
The video surveillance has raised
questions about patient privacy and how well the hospital managed its storage
of dangerous drugs.
Read more on KPBS.
Useful backgrounder? Something our App students could build?
How Shops Track You Using Your Smartphone
Coming soon to a law firm near you?
Gabe Friedman reports:
The privacy focused class-action
law firm Edelson P.C. announced it has filed a federal class-action
under seal that targets a Chicago-based regional law firm for data security
holes.
On Thursday morning, name partner
Jay Edelson tweeted that
he had filed a motion to unseal the complaint against the unnamed firm.
[…]
In an interview with Big Law
Business in March, Edelson explained that his firm had conducted a year-long investigation and identified 15 major
law firms with inadequate cybersecurity. He said his firm planned to file a series
of lawsuits that target data security vulnerabilities at law firms on
behalf of firm clients who have concerns about how their data is being
protected.
Read more on Bloomberg
BNA.
I’m hard-pressed to see how any such civil suit could
prevail if there’s been no actual hack or data compromise of the defendants’
systems, but the FTC could sure as hell investigate or take action if
infosecurity is that bad.
Either way, this will be one to watch. If nothing else, if the lawsuit is unsealed,
this could become a name and shame situation to get law firms off the dime to
bring their A game on security.
Will this impact our student portal? Possibly.
Joey Bunch reports:
A bill to protect students’
online privacy while they are doing their school work is on its way to the
governor’s desk to be signed into law.
The Colorado House gave it final
passage Thursday with a 65-0 vote. House Bill 1423 would
prevent educational software and app makers from collecting any data that can
be linked directly back to an individual student.
Read more on Denver
Post.
(Related) Same
question. Different state.
Rep. Cristin McCarthy Vahey (D-Fairfield) praised passage
of legislation that would protect student privacy by imposing certain
restrictions on the use and sharing of student data. HB 5469, AN
ACT CONCERNING STUDENT DATA PRIVACY, was passed by the Senate Wednesday
evening. The bill now goes to the
Governor’s desk.
The legislation would restrict how student information may
be used by contractors, consultants, and operators of websites, online
services, and mobile applications for schools. Companies would be required to specify how
they will secure student data and would be prohibited from using student data
for advertising unless authorized by the contract.
Read more on Fairfield
Sun.
Lacking demonstrable intelligence themselves (real or artificial)
it amazes me that politicians are addressing these issues. Were they frightened by the Terminator
movie?
White House worries about bad A.I. coding
… President Barack
Obama's administration released a report this week that examines the problem associated with
poorly designed systems that, increasingly, are being used in automated
decision making.
… A second effort
looks at our algorithmic future through a series of four workshops held across
the U.S. to examine A.I.'s impact on society.
… The U.S. will
produce an A.I. report after it holds workshops beginning May 24 in Seattle. That will be followed by meetings in
Washington, Pittsburgh and New York City in July.
For some old school types.
How to Get RSS Feed Updates Straight to Your Email Inbox
Maybe it’d be better to receive those RSS updates as emails.
Fortunately, this is possible! You’ll need to know how to use IFTTT, which is a lovely web
service that can perform all kinds of actions based on certain triggers. In our case, whenever our RSS feed updates, we
want IFTTT to send it to us as email.
Good news for the employability of my Computer Security
students?
After ISIS, Americans Fear Cyberattacks Most
Perfect timing.
Today’s Computer Security lecture is on Networks.
Interop: 12 killer (and free) tools for network engineers
Visibility is key to troubleshooting network woes, but
getting such access can be expensive. To
help out, a veteran networking pro shared with attendees of the Interop
conference in Las Vegas his list of a dozen mostly free “killer” tools.
A real concern.
Likely to have a serious negative impact no matter who wins.
Americans’ Distaste For Both Trump And Clinton Is
Record-Breaking
I can predict which if my students will become this
employee!
Subscribe to:
Posts (Atom)