Category Archives: Internet Security

Dozens of pro-Trump rallies retreat to internet, insist it’s not due to poor attendance – Mashable

A man wearing a T-shirt bearing the name of President Donald Trump, right, argues with a counterprotester after being hit by a flying plastic bottle of water near a "Free Speech" rally staged by conservative activists, in Boston.

Image: AP/REX/Shutterstock

For an organization with an estimated 280,000 members, ACT for America's website feels a bit desperate.

"We are the NRA of national security," the site declares, a comparison that, of course, would not be necessary for an organization that felt it could stand on its own reputation.

The group had been trying to organize 67 pro-Trump (and anti-Muslim) rallies across the United States on Sept. 9, but they've exchanged that plan for a day of internet raging, claiming that they are too concerned for the safety of their attendees to carry out the plan.

"ACT [American Congress for Truth] for America is deeply saddened that in todays divisive climate, citizens cannot peacefully express their opinion without risk of physical harm from terror groups domestic and international," the group wrote in a statement to Breitbart. "In recent weeks, extremist and radical organizations in the United States and abroad have overrun peaceful events in order to advance their own agendas, and in many cases, violence has been the result. Given the security issues of organizing public events, the responsible decision is to deny this opportunity to Neo-Nazis, Antifa, the KKK, and ISIS inspired individuals and groups."

ACT for America, according to the Southern Poverty Law Center, is "far and away the largest grassroots anti-Muslim group in America." It's a group in which "national security" is a euphemism for "anti-Islam." The group pushes unnecessary anti-Sharia legislation, has tried to block Syrian refugees from resettling in the United States, and its founder has said that any practicing Muslim cannot be a "loyal citizen of the United States." As you can tell from statement given to Breitbart, the group isn't above equating anti-fascist activists with ISIS and the KKK. The statement is reminiscent President Donald Trump, who condemned "violence on many sides" of an Aug. 12 neo-Nazi riot in Charlottesville, Virginia, during which a neo-Nazi allegedly killed a woman named Heather Heyer.

ACT says it's canceling for safety reasons, following the well-worn hate group tradition of proclaiming to be the Real Victims. But, as Gizmodo pointed out, it's unclear whether anyone was really going to attend to begin with

"The left organizes a march to D.C. and they show up in the tens of thousands," ACT founder Brigitte Gabriel says in the opening video on the site. "We need to act with the same passion and the same commitment."

Rousing, but evidently not that effective. A quick glance at Facebook pages for the planned rallies shows a range of 2-11 people who said they planned on going. The rally in Washington, D.C., had only three planned attendees and 10 "interested," which, if you know anything about how Facebook numbers translate to physical numbers, should tell you that the organizers would have been lucky if one guy shows up with his kid halfway through their mission to find a hot dog stand.

ACT says it will release more details about their planned internet activities at some point in the near future. When asked whether ACT called off the rallies because attendance was expected to be poor, David White, the group's communications director, wrote in an email that "attendance was not a factor in the decision."

Read the original here:
Dozens of pro-Trump rallies retreat to internet, insist it's not due to poor attendance - Mashable

Ransomware Victims Pay Much More Than Just the Ransom – eWeek

Todays topics include an analysis on the true cost of ransomware; Facebook awarding $100,000 for spear phishing security research; Google partnering with UC Berkeley to create an eclipse movie; and Microsoft giving Skype for desktops a mobile look makeover.

Ransomware has been a growing internet security attack tactic over the course of the past yearand the costs to businesses are far more than the ransom they pay to their attackers.

In a ransomware attack, an attacker installs malware that encrypts data on a victim's system and then demands a ransom in order to decrypt the data. In June, the FBI's Internet Crime Complaint Center released its 2016 Internet Crime Report, providing statistics on $1.33 billion in victim losses from a total of 298,728 complaints about various internet-related crimes that were reported during the year. Looking specifically at ransomware, the FBI received 2,673 complaints, with a total of $2.4 million in losses.

The true cost of ransomware is much more than just the ransom payments made by victims, however, as businesses must also take into account the disruption to their operations, which is a non-trivial financial concern.

Facebook awarded the fourth Internet Defense Prize at the USENIX Security Conference in Vancouver on Aug. 17, giving the winning research team a $100,000 award.

The Internet Defense Prize was started in 2014 as an effort to encourage security researchers to investigate and develop new methods for improving internet security.

A team of security researchers from the University of California, Berkeley won the 2017 prize for a new approach to detecting credential spear phishing attacks. Spear phishing attacks, also sometimes referred to as "whaling," involve a targeted fraudulent email that is sent to a specific individual with the goal of tricking the user into clicking on a link or opening an attachment.

Members of Google's Making and Science initiative nd the Multiverse team at the University of California, Berkeley's Space Science Laboratory have teamed up on a project to produce a high-definition, time expanded video of the Aug. 21 total solar eclipse using images from more than 1,000 amateur photographers and astronomers.

The group of volunteer photographers were stationed along the entire path of totality of the eclipse stretching from Corvallis, Ore., to Charleston, S.C.

The teams from Google and Berkeley will stitch together the crowd-sourced photos to create a continuous view of the solar eclipse as it traversed the United States. The dataset from the so-called Eclipse Megamovie Project will be made available to the general public and to the scientific community for further research. The goal of the Megamovie initiative is to study how the sun's corona changes over time.

Microsoft has released a preview version of its Skype software for desktop PCs that owes much of its look and feel to the iOS and Android versions of the app.

"For Mac, Windows 10 November Update and lower, Windows 8, and Windows 7 users, Skype Preview delivers most of the great features of our next generation mobile experience, but is specifically designed with desktop in mind to take full advantage of the larger screen," blogged Microsoft representatives on Aug. 17.

In fact, the new Skype for desktop computers borrows a lot from its mobile incarnations. It inherits many of the streamlined, chat-centric interface elements that previously set apart the Skype mobile apps from their desktop counterparts.

See the rest here:
Ransomware Victims Pay Much More Than Just the Ransom - eWeek

A Very Dumb Mistake Costs Cryptocurrency Investors Big Time – WIRED

The digital financial services developer Enigma prides itself on ultra-secure products. The company's Catalyst platform protects financial info with a cutting-edge combination of blockchain-inspired privacy technology and cryptography. So it comes as no small surprise that on Monday, scammers took over the company's website, mailing lists, and Slack accounts by exploiting some extremely basic security mistakes Enigma had made. The blunders also facilitated a scam that ultimately cost Enigma supporters almost $500,000.

Enigma has planned an Initial Coin Offering for September 11an unregulated cryptocurrency fund-raising campaign that startups use when they want to raise capital for their company without going through the process of working with an established financial institution or venture capital fund. (The SEC has promised to clamp down on these ICOs, but so far is in the exploratory phase.)

With the ICO in mind, scammers compromised official Enigma channels to create a sense of legitimacy and urgency. The plot proved easy to pull off. At least one of the passwords protecting the Enigma accounts, which included a Slack account with administrative privileges, had previously leaked, and reports indicate that the accounts weren't protected by two-factor authentication.

The hackers began defacing the company's main site and Slack accounts, and pushed a special "pre-sale" ahead of the ICO, directing money toward their own cryptocurrency wallet. They also went rogue on the company's mailing lists. Many users realized that the push was a scam, but the hustle did tempt some interested backers into sending 1,492 coins in the cryptocurrency Ethereum, which converts to almost $495,000.

Enigma said in a statement on Monday that its community fund-raiser, also called a crowd sale, was always set definitively for September 11, and emphasized that its secure servers had not been hacked. But a spokesperson confirmed that the scammers compromised account passwords using various methods. And in response to the incident, the company says it is adding strong, random passwords and two-factor authentication for each account, plus implementing robust password changing and better system compartmentalization. "Weve moved up a number of critical security steps and taken additional measures to protect the community going forward," says Tor Bair, Enigma's head of marketing and growth. "Were now very well aware of the potential threats and are taking no chances."

Though honest mistakes can happen at any growing organization, the Enigma community grappled with the implications of the incident on Monday, wondering how a specialized cryptography company could only now be realizing the need for stringent account hygiene. "This will go down in crypto history as one of the stupidest moments ever. We need a meme," one Reddit user wrote. Some Redditors even claimed that they used the breached credential repository Have I Been Pwned to determine that the Enigma accounts scammers accessed reused a previously exposed account password from CEO Guy Zyskind. But Zyskind told WIRED that none of the breached Enigma accounts relied on reused passwords.

While the Enigma team worked to restore secure Slack service, the community's discussion moved to secure messaging app Telegram. "No word on honoring those who were scammed b/c of y'all negligence and poor security? Speaks volumes," a user called Jay wrote in the open chatroom. Many users indicated support for Enigma, though, and seemed satisfied with the company's remediation efforts.

"Hacking accounts that do not have dual-factor authentication enabled and other best in class security measures is a trivial hack for most dedicated attackers," says Chris Pierson, the general counsel and chief security officer of the payment platform Viewpost. "To the public it looks as if the company has been hacked, and provides a significant amount of negative press about the companys security and privacy responsibilities."

Enigma said on Monday evening that it is working to mitigate the damage. We're actively investigating the scam attempt and the parties involved with multiple partners, including vigilant members of our community, other companies in our space, and exchanges, Bair says.

Since they are unregulated by the governmentfor now, anywayICOs have perks that make them appealing to cryptocurrency companies, but by their nature they are also less predictable than standard fund-raising avenues. In mid July, scammers stole roughly $7 million from supporters during the ICO of the cryptocurrency management platform CoinDash. A few days later, hackers stole $32 million in Ethereum (though much of it was later recovered) by exploiting a vulnerability in a crypto product called Parity Wallet.

"The news of the attack is certainly not surprising," says Eric Klonowski, a senior advanced threat research analyst at the internet security firm Webroot. "Investors were ready to part with their money at a moments notice, and the attacker was prepared to capitalize.... That said, recent core cryptocurrency heists are all a result of third-party vulnerabilities and their handling of investments, and not in the cryptography or implementation itself."

With the September 11 ICO still rapidly approaching, at least Enigma has some time to get its first-line security right.

Visit link:
A Very Dumb Mistake Costs Cryptocurrency Investors Big Time - WIRED

WomensLaw.org | Internet Security

http://www.womenslaw.org//laws_state_type.php?id=13404&state_code=PG&lang=en

Add Link to Email

Please note that computer use can be monitored by an abuser, and there are ways for an abuser to access your email and to find out what sites you have visited on the Internet. It is impossible to completely clear all data related to your computer activity.

If you are in danger, please use a computer that the abuser cannot access (such as a public terminal at a library, community center, or domestic violence organization), and call your local domestic violence organization and/or the National Domestic Violence Hotline at 1-800-799-SAFE for help. For a list of local and national resources see our State and Local Programs page and enter your state in the drop-down menu.

Please note that computer use can be monitored by an abuser, and there are ways for an abuser to access your email and to find out what sites you have visited on the Internet. It is impossible to completely clear all data related to your computer activity. If you are in danger, please use a computer that the abuser cannot access (such as a public terminal at a library, community center, or domestic violence organization), and call your local domestic violence organization and/or the National Domestic Violence Hotline at 1-800-799-SAFE for help. For a list of local and national resources see our State and Local Programs [/gethelp_type.php?type_name=StateandLocalPrograms] page and enter your state in the drop-down menu.

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en

Maybe. There are a number of ways the abuser could have access to your email account:

If you're not sure whether the abuser has access to your email account, for your safety it's best to act like s/he does, and avoid sending emails you wouldn't want him/her to see.

Maybe. There are a number of ways the abuser could have access to your email account: * If you share an email account with the abuser, s/he will be able to read any of the emails in your account. * If you use a Web-based email program like Gmail or Yahoo, your email account may be visible to someone who visits those websites on your computer unless you properly log out. Just closing your browser is not enough - you must first log out of your account to make sure that when the abuser goes to the email programs website, your personal account information wont be on the screen. * If you use of one these Web-based email programs, the abuser may be able to access your email account if s/he knows your email address and password. Note: Some people's computers save their email address and password for them. If your computer has your email address and password saved, anyone with access to your computer can read your email. * If you use a computer-based email program like Outlook, Outlook Express, Eudora or Apple Mail, anybody who has access to your computer can read your email. * If the abuser knows your email address, remember to not open any email attachments sent from the abuser and to not reply to an email sent by the abuser using your new email account, as these actions may let the abuser install spyware on your computer and track your email messages. * Most computers have a function called "AutoComplete," which stores information you've typed on your computer in the past. For example, if AutoComplete is turned on, when you go to type something into a search engine such as Google, a pop-up box will appear and list the things you've searched for in the past. (You may also see this pop-up box when entering your credit card information or your address into an online form.) If you have AutoComplete turned on, the abuser may be able to access your email account even if you haven't told him/her your email address or password.If you're not sure whether the abuser has access to your email account, for your safety it's best to act like s/he does, and avoid sending emails you wouldn't want him/her to see.

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en#content-13407

Add Link to EmailAdd Text to Email

If you believe that the abuse does NOT have access to your email account, here are a few steps that you may want to take anyway, to try to keep your email account secure:

You may also want to follow the steps in What should I do if I think the abuser can access my email account? in case the abuser has access to your email account without your knowledge.

If you believe that the abuse does NOT have access to your email account, here are a few steps that you may want to take anyway, to try to keep your email account secure: * Make sure you have a password the abuser will not be able to guess. Pick a password that does not contain obvious information (such as your name, birthday, Social Security number, pet's name, etc.), which the abuser could guess. It may also be a good idea to change your password regularly. If you are not sure how to change the password on your email account, you can likely find that information by going to help or ?. * Do not write your password down. Make sure you change your computer settings so that it does not save your username (email address) and password. Your computer may ask you if you want to save your username and password after you enter it. Make sure to click on "no." * When you are finished using your email, always log out or sign out. If you do not hit "log out" or "sign out," your email account may still be open due to a feature called AutoComplete, even if you close the window. See Can the abuser access my email account? [/laws_state_type.php?id=13404&state_code=PG&open_id=all#content-13407] for more information on AutoComplete. * If you do decide to give the abuser your email address, remember to not open any email attachments sent from the abuser or to reply to an email sent by the abuser using your new email account, as these actions may let the abuser install spyware on your computer and track your email messages.You may also want to follow the steps in What should I do if I think the abuser can access my email account? [/laws_state_type.php?id=13404&state_code=PG&open_id=all#content-13410] in case the abuser has access to your email account without your knowledge.

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en#content-13408

Add Link to EmailAdd Text to Email

If the abuser has access to your email account or computer, s/he may be able to read the emails you send and receive, even if you delete them.

Therefore, to send and receive emails that you do not want others to see, you may want to set up an alternate email account that the abuser doesn't know about. There are a number of free, Web-based e-mail services that you can use. When signing up for a new email account, do not use any of your real identifying information if you wish to remain private and anonymous. Here is a list of a few free, web-based email programs:

Keep in mind that the abuser may still be able to read your email if you create a new account if you do not log out properly or if you choose a password that s/he can guess or find. The safest way to use a new email address is from a computer that the abuser does not have any access to.

Note: If you do decide to give the abuser your email address, remember to not open any email attachments sent from the abuser or to reply to an email sent by the abuser using your new email account, as these actions may let the abuser install spyware on your computer and track your email messages.

If the abuser has access to your email account or computer, s/he may be able to read the emails you send and receive, even if you delete them. Therefore, to send and receive emails that you do not want others to see, you may want to set up an alternate email account that the abuser doesn't know about. There are a number of free, Web-based e-mail services that you can use. When signing up for a new email account, do not use any of your real identifying information if you wish to remain private and anonymous. Here is a list of a few free, web-based email programs: * Gmail: http://www.gmail.com [http://www.gmail.com] * Hotmail: http://www.hotmail.com [http://www.hotmail.com] * AOL Mail: http://mail.aol.com * Yahoo!Mail: http://mail.yahoo.com * Mail.com: http://www.mail.com [http://www.mail.com] * Hushmail: http://www.hushmail.com [http://www.hushmail.com] * Mail City: http://mail.lycos.com [http://mail.lycos.com/] * Fastmail: http://www.fastmail.fm [http://www.fastmail.fm/]Keep in mind that the abuser may still be able to read your email if you create a new account if you do not log out properly or if you choose a password that s/he can guess or find. The safest way to use a new email address is from a computer that the abuser does not have any access to. Note: If you do decide to give the abuser your email address, remember to not open any email attachments sent from the abuser or to reply to an email sent by the abuser using your new email account, as these actions may let the abuser install spyware on your computer and track your email messages.

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en#content-13410

Add Link to EmailAdd Text to Email

As you are browsing the Internet, you may come across an email address that you can click on in order to send an email to that address -- something that looks like this: info@domain123.com.

If you share a computer with the abuser and click on an email link, you may be sending the email from the abuser's email address without even knowing it. This could put you in danger since whoever you wrote to might try to write you back, but will be writing to the abuser's email address instead.

It is safer to copy the email address and paste it directly into a new message from your own email account.

As you are browsing the Internet, you may come across an email address that you can click on in order to send an email to that address -- something that looks like this: info@domain123.com [http://info@domain123.com]. If you share a computer with the abuser and click on an email link, you may be sending the email from the abuser's email address without even knowing it. This could put you in danger since whoever you wrote to might try to write you back, but will be writing to the abuser's email address instead. It is safer to copy the email address and paste it directly into a new message from your own email account.

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en#content-13411

Add Link to EmailAdd Text to Email

You should print and save any threatening or harassing email messages the abuser sends you, as they may be used as evidence of his/her abuse in court or with the police. To be able to prove that the abuser sent these messages, you may have to print out the messages with the header, which shows the account information of the sender of the email.

Additionally, depending on the content of the messages and how many s/he sends, s/he may be committing a crime, such as stalking or harassment. You can report any threatening or harassing emails to the police. For more information on online harassment, please see our Stalking/Cyberstalking page. To read the definitions of any harassment or cyberstalking crimes in your state, you can go to our Crimes page and enter your state in the drop-down menu.

Threatening or harassing emails may also be a basis for a restraining order against the abuser. To read about the types of restraining orders available in your state, select your state from the drop-down menu on our Restraining Orders page

You should print and save any threatening or harassing email messages the abuser sends you, as they may be used as evidence of his/her abuse in court or with the police. To be able to prove that the abuser sent these messages, you may have to print out the messages with the header, which shows the account information of the sender of the email. Additionally, depending on the content of the messages and how many s/he sends, s/he may be committing a crime, such as stalking or harassment. You can report any threatening or harassing emails to the police. For more information on online harassment, please see our Stalking/Cyberstalking [/simple.php?sitemap_id=90] page. To read the definitions of any harassment or cyberstalking crimes in your state, you can go to our Crimes [/laws_state_type.php?statelaw_name=Crimes&state_code=GE] page and enter your state in the drop-down menu. Threatening or harassing emails may also be a basis for a restraining order against the abuser. To read about the types of restraining orders available in your state, select your state from the drop-down menu on our Restraining Orders [/laws_state_type.php?statelaw_name=RestrainingOrders&state_code=GE] page

http://www.womenslaw.org/laws_state_type.php?id=13404&state_code=PG&lang=en#content-13412

Add Link to EmailAdd Text to Email

back to top

Original post:
WomensLaw.org | Internet Security

Facebook Awards $100K for Spear Phishing Security Research – eWeek

Facebook awarded the fourth Internet Defense Prize at the USENIX Security Conference in Vancouver, Canada on Aug. 17, providing the winning research team with a $100,000 award.

The Internet Defense Prize got started in 2014 as an effort to help encourage and reward security researchers for investigating and developing new methods that can help improve internet security. For the 2017 prize, a team of security researchers from The University of California, Berkeley detailed a new approach to detecting credential spear phishing attacks.Spear phishing attacks, also sometimes referred to as 'whaling' involve a targeted fraudulent email that is sent to a specific individual with the goal of tricking the user into clicking on a link or opening an attachment.

"Our method uses features derived from an analysis of fundamental characteristics of spear phishing attacks, combined with a new non-parametric anomaly scoring technique for ranking alerts," the research abstract states. "We evaluate our technique on a multi-year dataset of over 370 million emails from a large enterprise with thousands of employees."

The method described by the researchers was able to detect two spear phishing attacks in the dataset that had been previously unknown, as well as six spear phishing attacks that were previously known. In a blog post, Facebook security researcher, Nektarios Leontiadis stated that the winning research is important because spear phishing attacks have led to many information leaks in recent years. He noted that the winning research holds the potential to help reduce the volume of spear phishing compromises in the future.

"Secondly, the authors acknowledge and account for the cost of false positives in their detection methodology," Leontiadis wrote. "This is significant because it factors into the overhead cost and response time for incident response teams."

Though Facebook has funded the Internet Defense Prize, it's not entirely clear how or when the social networking giant will integrate the method from the winning 2017 spear phishing research into its operations.

"Facebook is always examining new security measures and practices, assessing how to best protect people," a Facebook spokesperson told eWEEK in an email.

Facebook has however successfully benefitted from past Internet Defense Prize research, which is one of the many reasons why the social networking site continues to fund the effort. During a keynote at the Black Hat USA security conference on July 26, Alex Stamos, Chief Security Officer (CSO) at Facebook announced $1 million in new funding to help encourage original research with the Internet Defense Prize. Stamos also provided insight into how past winning research has helped to positively influence Facebook's security.

The 2014 Internet Defense Prize winning research was for a paper on the detection of second order vulnerabilities of web apps using stack analysis that has had an impact on Facebook's security operations.

"This influenced how we built our internal static analysis tools that run on our code before it is pushed to production," Stamos said during his Black Hat USA keynote. Another paper proposed a post-quantum cryptosystem, which is the type of research that needs to be done now, so when quantum computers become practical, people's information can still be kept secure, Stamos said.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Read the original post:
Facebook Awards $100K for Spear Phishing Security Research - eWeek

Resilience, Emergencies and the Internet: Security In-Formation – Peace Research Institute Oslo (PRIO) (press release)

This book traces how resilience is conceptually grounded in an understanding of the world as interconnected, complex and emergent. In an interconnected world, we are exposed to radical uncertainties, which require new modes of handling them. Security no longer means the promise of protection, but it is redefined as resilience - as security in-formation. Information and the Internet not only play a key role for our understanding of security in highly connected societies, but also for resilience as a new program of tackling emergencies. Social media, cyber-exercises, the collection of digital data and new developments in Internet policy shape resilience as a new form of security governance. Through case studies in these four areas this book documents and critically discusses the relationship between resilience, the Internet and security governance. It takes the reader on a journey from the rise of complexity narratives in the context of security policy to a discussion of the Internet's influence on resilience practices, and ends with a theory of resilience and the relational. The book shows how the Internet nourishes narratives of connectivity, complexity and emergency in political discourses, and how it brings about new resilience practices. This book will be of much interest to students of resilience studies, Critical Security Studies, Internet-politics, and International Relations in general.

View post:
Resilience, Emergencies and the Internet: Security In-Formation - Peace Research Institute Oslo (PRIO) (press release)

LIBTELCO Hosts First Cyber Security Confab – Liberian Daily Observer

The Liberian government has become cognizant of the threat of cyber crime that is affecting countries and companies globally.

Against this back ground the Liberia Telecommunications Corporation, (LIBTELCO), yesterday convened the nations first annual National Cyber Security Forum at a resort in Monrovia to deliberate on the establishment of a national cyber-security strategy against external invaders.

The forum is focused on creating awareness for cyber security and its implications for the government, business, and society. The event was graced by some of the sub-regions leading cyber security experts from business, government, and academia.

We are proud to be hosting this event and appreciate the important role that cyber security plays to ensure our economy operates securely, said Dr. Darren Wilkins, Managing Director of LIBTELCO. We look forward to working with our colleagues toward the development of a national cyber security strategy in the near future.

The future of every entity in Liberia that uses computers and the internet hinges on its approach to cyber security.

By bringing thoughtful people of like minds together from across disciplines, we can transform our country from a start-up nation to a cyber-nation, cognizant of cyber security and cyber threats, Dr. Wilkins explained.

Several institutions from various sectors of Liberia are participating in the event. The program also brings together cyber security experts from the Ivory Coast, Liberia, United States, and China.

Making a presentation at the conference, an Ivoirian Business Development Manager, Koffi Adjoumani, said the issue of cyber security should not be overlooked by any government or entity.

On the topic, Cyber Security Awareness, Mr. Adjoumani noted that it is hard to time that Africans began to prepare themselves against the threat of hackers, who are causing a substantial amount of damage across the globe. This is a threat that is invading the globe and we have to prepare ourselves for it. There is no better way to go about that than to convene such a gathering where we can put our ideas together, he said.

Some of the major contributors to the event include Liberia Telecommunications Authority (LTA), the Central Bank of Liberia (CBL) and several other institutions from both the public and private sectors.

LIBTELCO Head of Cyber Security, Al-hassan Sheriff noted that the conference would not have come at no better time as the nation is about to go to a very important election.

He indicated that the need for a vibrant cyber security program in the country cannot be overemphasized. We need a very strong strategy that will help protect our country. The sooner we do this, the better it is for us, Mr. Sheriff said.

It is my hope that this event will address and increase our awareness on cyber-security and bring us together for a closer collaboration on this very important subject.

The advent and use of the internet and its accompanying technologies has made it imperative for all of us to understand the basic understanding of the cyber threat, cybercrime, and cyber security, he said.

The internet is a communication tool that now affects almost every aspect of our lives, from education to entertainment to banking, health, sports among others.

What the entire internet has brought to us for comfort has altered our daily routine. The internet is also the world marketplace, where trillions in financial deals occur yearly. Moreover, as technology advances, especially Wi-Fi technology, the internet has become widely accessible by smaller and smaller mobile users, he said.

See the article here:
LIBTELCO Hosts First Cyber Security Confab - Liberian Daily Observer

Free or hate speech? Silicon Valley searches for proper line – CBS News

The internet was built on the premise of allowing people to engage in free speech and exchange ideas, even dangerous ones.

That ethos now faces a stern test following the violence and terror attack in Charlottesville, creating a host of ethical questions for businesses including Facebook, PayPal and Spotify. Many are deciding to ban white supremacist and neo-Nazi users from sending money, posting comments and listening to "white power" music.

While those decisions are applauded by many, others are questioning whether tech companies are going too far by deciding what music their customers can listen to or what comments are acceptable. The dilemma was spelled out by Cloudflare CEO Matthew Prince, who wrote in a blog post about how he decided to cancel the account of the Daily Stormer. The issue came to a head for Cloudflare, an internet security company, when the neo-Nazi publication claimed "we were secretly supporters of their ideology," he noted.

That was a "tipping point" for his company, Prince noted.

"Someone on our team asked after I announced we were going to terminate the Daily Stormer: 'Is this the day the Internet dies?'" he wrote. "He was half joking, but only half. He's no fan of the Daily Stormer or sites like it. But he does realize the risks of a company like Cloudflare getting into content policing."

During the past decade, American businesses have increasingly espoused ideals such as diversity and inclusivity. The Charlottesville attack is pushing employees and customers to ask those corporations whether they are going to live up to their slogans and corporate policies, said Brian Kropp, HR practice leader at consulting firm Gartner.

"You don't know what the values of your company are until they are tested, and now they are being tested," he said. "Whatever you say you stand for in an organization, you have to stand up for it when the moment comes. If you do that, odds are things will work out."

PayPal (PYPL) cut off business with more than three dozen hate groups and other extremist organizations following the white nationalist rally in Charlottesville. Among those are Altright.com, a white nationalist group led by Richard Spencer.

"Regardless of the individual or organization in question, we work to ensure that our services are not used to accept payments or donations for activities that promote hate, violence or racial intolerance," PayPal said in a statement.

Facebook (FB) banned the Facebook and Instagram accounts of a white nationalist who attended the Charlottesville rally. Facebook CEO Mark Zuckerberg wrote in a post, "Debate is part of a healthy society. But when someone tries to silence others or attacks them based on who they are or what they believe, that hurts us all and is unacceptable."

At the same time, some customers are pushing back, asking in social media posts whether the organizations will hold other groups to the same standards. Others are expressing concern that it might backfire.

"I think this leads to more Nazis," one user wrote in response to Cloudflare's decision. "Instead of laughing at them, they feel persecuted and silenced. Which reinforces their beliefs."

While some users claim their free speech is being violated, private companies have the right to set their terms of service, just as they have the right to discipline employees for code of conduct violations. The latter was an issue that arose when Google fired engineer James Damore after he published a manifesto that argued the gender gap in technology is due to biological factors, such as women's higher "neuroticism" than men.

"People confuse the fact that the government is not allowed to restrict free speech, but private companies are," said Michael Niborski, a partner at law firm Pryor Cashman who specializes in free speech issues. "It's a cost-benefit analysis by the company: Are we going to lose customers? Are we going to get bad publicity because we are giving them a platform or a website and allowing them to display their music?"

He added, "One thing that makes this particularly unique is you are talking about one of the most vilified, negative groups in history, and so companies feel protected in taking their music down."

In essence, Silicon Valley is confronting the "paradox of tolerance," the idea outlined by philosopher Karl Popper that a tolerant society must be intolerant of intolerance. Otherwise, the intolerant will have the freedom to destroy tolerance.

Employees increasingly are important constituents in businesses' decisions to stand up against bigotry and white supremacy, Gartner's Kropp said. A generation ago, workers didn't identity as much with their employers' values, but employees now see their workplaces as extensions of their own core beliefs.

"If you are banning some of these things, it's a fairly small minority of people who are fairly outraged about it," he said. But without speaking out against intolerance, "especially in the tech space where it's super competitive, you run a huge risk of losing a chunk of your employee base to the competition."

But banning white supremacists can be good for business, even if some customers question corporate control over free speech.

For instance, dating site OKCupid banned white supremacist Chris Cantwell for life, 10 minutes after they received the alert he had a profile on their site. Customers praised the decision, with one women writing, "Single women all over the world thank you!!!"

"There is no room for hate in a place where you're looking for love," OKCupid said on Twitter.

Link:
Free or hate speech? Silicon Valley searches for proper line - CBS News

The Yin-Yang of Cybersecurity Legislation The Internet of Things Cybersecurity Act – CSO Online

The dynamic of opposites permeates human culture: light and dark, push and pull, happy and sad, supply and demand, yin and yang. While we tend to prefer one over the other, the reality is that the tension between opposites is what makes them complementary. The same can be said of technology. We all know that quick and free access to information, regardless of economic status, is changing the world. But none of that would be possible without security safeguards like accountability and authentication. Without those, economics, capitalism, and even democracy itself are severely strained. Which is why security is a multi-billion dollar industry.

The recent growth of the Internet of Things (IoT) is a case study of what happens when access and availability are not counterbalanced by security. The vast majority of IoT devices available today have been built with little to no thought for security, and yet they are being integrated into the fabric of our daily lives at an unprecedented rate. As a result, massive botnets like Mirai and Hajime composed of millions of compromised IoT devices managed to take down a significant segment of the Internet and affect hundreds of thousands of businesses around the world. Most security experts agree that these attacks are just the tip of the IoT-based cyberthreat iceberg, and that they represent an extraordinarily large attack vector built into our emerging digital economy.

TheInternet of Things Cybersecurity Act of 2017 Actis a noteworthy attempt to address these challenges before they escalate further. The proposed IoTCA bill gives the problem of security and control a good deal of attention, since solving the problem of authentication (people-to-machines, software-to-hardware, data-to-processes, etc.) would be almost analogous, in the Internet security world, to solving world peace.

Over the next few years, billions more IoT devices will become part of our digital lives. If implemented properly, they could utterly transform business and society. However, their value will be limited by the degree to which we can trust their Authenticity that they are what or who they claim to be. Though the IoTCA is not a silver bullet, it attempts to help reduce the level of obvious risks in a ballooning population of Internet-connected devices.

Of course, like everything, even legislation is a two-edged sword. Im concerned about any attempt to legislate vulnerabilities, in part because technology evolves so quickly. Trying to strike a balance between progress and protection can be a tricky business, much like trying to shoe a horse at full gallop. While the government should use its power of the purse its contracting and procurement processes to move the ball forward, its probably not practical, for example, to demand written verification or certification that an IoT product is vulnerability or defect free. Security is a moving target. Frankly, the best that such a certification could mean is that at the moment a device was analyzed it was free from any known defects or vulnerabilities and was not vulnerable to any attacks that the manufacturer knew about. Knowing how fast things change in cyberspace, however, such verifications are the digital equivalent of mayflies.

Similarly, the IoTCAs proposal to require industry standard protocols, however well intentioned, may have unintended consequences because of its potential impact to innovation. These sorts of things need to be developed with care. Standards take time for a good reason. Imposing them with the force of law may unintentionally stifle breakthrough solutions that might leapfrog current technologies. And in that case, everyone would lose.

On the other hand, the proposed IoTCA legislations liability protection for those who are forthcoming about vulnerabilities is a breath of fresh air, especially compared to some of the critical infrastructure sectors that, for fear of regulatory fines, limit vulnerability disclosures.

Likewise, the bills notation about the important role of segmentationreflected a sophisticated understanding of security strategy: When it comes to cybersecurity strategy, Segmentation is still king.

Segmentation (limiting access based on need-to-know to those with authenticated credentials):

The bill rightly encourages the adoption of segmentation strategies and architectures. This approach would intelligently allow IoT devices to be incorporated into the network while limiting their potential negative impact. Visibility into devices actively connected to the network also continues to be a challenge for most organizations. Which is why the bills inventory of devices requirement would help create an excellent starting point for companies or businesses to reference when selecting and operating IoT devices. Proper segmentation and monitoring would not only separate classes of devices and data, but would also allow administrators to pinpoint and isolate misbehaving devices, check them against an inventory, and then extend remediation to all related devices, and not just the one that had been identified.

Intentional design is a strategy whereby vulnerabilities and potential attack vectors are identified and architected out of the network during the network architecture design phase, rather than relying exclusively on security technology. Segmentation is a fundamental part of such a design strategy. At Fortinet, were experimenting with a strategy called Earned Trust, where IoT devices would be allowed access based on their stated trust levels, but whose network behaviors would be automatically and actively monitored to ensure they are performing as advertised. If their behavior, or level of earned trust changes, the network could automatically adjust their access policies. At the same time, the level of monitoring or access for similar devices could be elevated while we determine if the observed behavior was an anomaly or endemic to an entire class of devices.

Of course, the boom of IoT across its many classes (consumer, commercial, industrial) means that the majority of data is no longer contained inside traditional networks. Which means that securing only a few points within the network will no longer be good enough. Security strategies like segmentation need to be woven deep into the core of the network and at the same time expand out to the cloud, remote locations, and even end users. These security technologies need to be able to work as an integrated system to automatically identify, understand, and protect infrastructures from the massive attack surfaces and new attack vectors created by IoT across todays and tomorrows increasingly distributed and elastic network environment.

While the adoption and integration of IoT is going to require taking a fresh look at existing security solutions and strategies, the questions we need to ask about business goals, related risks, and risk mitigation havent changed. Network security not only needs to continue to actively prevent intrusions, it also needs to minimize the risk of serious breaches by reducing the time taken to detect and respond to new threats. Security solutions need to become better at collecting and sharing intelligence. They will need to be able to correlate indications of compromise and automatically coordinate a response to a threat or breach regardless of where it occurs or what attack vector was used. Given the scope and scale at which networks are evolving, achieving this will require a broad, powerful, and automated approach to security that many agencies and organizations do not yet have in place.

Id like to see a little more consultation with industry as this bill progresses. Businesses and even nations are staking their financial futures on the new digital economy.

Back to the topic of synergistic opposites:

Which is the truth? Right now, they both are, in part. But the good news is that, going forward, we can ensure that we maintain a healthy balance between the yin of ubiquitous IoT (and the convenient and instant access to information/services it represents), and the yang of holding it accountable to doing what we expect it to do, and nothing more, through authentication and the adoption of the principles of Earned Trust.

Read more here:
The Yin-Yang of Cybersecurity Legislation The Internet of Things Cybersecurity Act - CSO Online

Can US lawmakers fix IoT security for good? – Network World

While the Internet of Things (IoT) has carved out a comfortable place for itself in todays society and markets, many still fear that the interconnectivity-driven phenomenon is extraordinarily vulnerable to outside attacks. A number of U.S. Senators believe they may have a solution to the problem, and have put forward the Internet of Things Cybersecurity Improvement Act of 2017.

What are the exact details of the text of the bill, and how does it intend to secure one of the most diverse and unregulated assets of the economy? What potential pitfalls stand in the bills way, and how much of a chance does it have of becoming law? An analysis of the IoT Act reveals that its a healthy step in the right direction, but it may not be enough.

As the strength and value of the IoT is driven by the proliferation of networked devices, it stands to reason that more and more digitally-connected gadgets could only be a good thing for it. Shoddy, non-patchable hardware has proven to be an incredible vulnerability for the IoT, however, and could cripple it in the future. One massive 2016 cyberattack exploited connected IoT devices for nefarious purposes, for instance.

The IoT Cybersecurity Improvement Act hopes to remedy this problem by reevaluating government procurement standards. Currently, many of the devices bought by government agencies come equipped with pre-installed passwords which cant be changed easily, and sometimes cant be changed at all. This serious security threat will be mitigated by the bill, which aims to enforce regulations which ensure all devices sold to the federal government are patchable.

The bill also prohibits vendors from selling devices which possess known vulnerabilities, and orders the Department of Homeland Security to work with industry officials to formulate clearer guidelines. These are all steps in the right direction, but may prove tricky to enforce, as the bills language regarding what constitutes an internet-connected device can be interpreted as being overly broad.

Uncertainty like that in a bill can be costly in the long run, driving up cost as courts must litigate over the tiny details in the bills language. Nonetheless, the frightening levels of vulnerability in the IoT, which is largely made up of un-patchable, relatively poorly-defended gadgets, necessitates a stricter approach to cybersecurity, which this bill attempts to provide.

The success of the IoT Cybersecurity Improvement Act will largely hinge upon whether the federal governments spending power is enough to solve the IoTs security dilemma. While the bill possesses some language that fosters increased government cooperation with private industry leaders, it may not be enough to persuade the broader market to take the IoTs cybersecurity more seriously.

IoT spending is already set to surpass $800 billion in 2017 alone, and could even rocket up to an astonishing $1.4 trillion by 2021. As the market for devices continues to grow, and global incomes rise, the IoT could be endangered if companies attempt to meet the staggering demand for IoT gadgets by lowering their security standards to optimize production.

A factsheet of the bill produced by one of its sponsoring senators even recognizes how challenging it may be for companies to meet some of its requirements, and notes that government employees could still buy non-compliant devices if they first receive permission from the Office of Management and Budget.

Regardless of what shortcomings the bill may possess, its incentivizing of manufacturers to produce better-secured devices will be invaluable in the years to come as the IoT continues to grow at a remarkable pace. Some parts of the bills language will be incredibly challenging to follow through on, such as its requirement that agencies inventory any and all IoT devices they use. To expect the government to accurately keep track of all internet-connected gadgets it uses could prove to be a pipe dream, but at very least such measures grant IoT security some of the respect and attention it desperately needs.

Some of the details of the bill could be misinterpreted and end up mitigating private researchers abilities to solve IoT security issues, but this too is unlikely, and could be solved with reasonable amendments and wise enforcement policies. Uncle Sams late arrival to the IoT cybersecurity scene could end up haunting the market for some time as hackers probe for opportunities, but should ultimately be welcomed as a new, more secure chapter in the IoTs story.

While it would be a serious stretch to say that U.S. lawmakers have permanently secured the internet, the IoT Cybersecurity Act of 2017 takes aim at the most egregious vulnerabilities that plague the market today. The only question that remains is whether the bill can gather enough support to pass, and whether it will inspire the private sector to crackdown on future breaches of internet security.

This article is published as part of the IDG Contributor Network. Want to Join?

Read the original here:
Can US lawmakers fix IoT security for good? - Network World