Category Archives: Internet Security
Security This Week: The Very Best Hacks From Black Hat and Defcon – WIRED
As they do every year, hackers descended on Las Vegas this week to show off the many ways they can decimate the internet's security systems. Here's a collection of some of our favorite talks from this week's Black Hat conference, including some we didn't get the chance to cover in depth.
Before the week even began, we took a look at how $15 worth of magnets could overcome a "smart" gun's protections, turning it into just a regular ol' gun. Similarly, a popular safe turned out to be anything but against a homemade robot safecracker. Also not so secure? Some of the popular tools hackers use to control other people's systems, which turn out to be riddled with vulnerabilities themselves. Radioactivity sensors are easy to hack and not likely to get fixed. Entire wind farms can be shut down or hijacked with some lock picking tools and a proof-of-concept worm. And a bug in a Broadcom chip that lives inside every iPhone and lots of Android devices ended up exposing a billion or so smartphones to Wi-Fi attacks. Yes, billion.
At least some people are doing it right. Netflix managed to DDoS itself, but on purpose, and to help other services defend against the same obscure (for now) attack. After months of trying, Google finally patched the tricky Cloak & Dagger attack that threatened Android users, and still does if you're not on Android O, which, uh, no one is yet. They also stopped some highly sophisticated malware, likely from a cyberarms dearly, that impacted a handful of high-value targets. Some researchers are open-sourcing a tool that might help fix the SS7 vulnerability that has plagued cell networks for years. But others demonstrated a cheap and easy way to ferret out zero-days from IoT devices, so it evens out. Also? Evil bubbles! Just trust us.
Otherwise, we watched shotguns shoot down some poor unfortunate drones. Which seems like an appropriate way to go out. Here are the rest of the talks we found interesting but didn't get to cover in depth.
Leave it to hackers to turn the wholesome American institution of the carwash into a horrifying death trap. Security researchers Billy Rios and Jonathan Butts have offered a vivid new demonstration the consequences of connecting industrial equipment to the internet, hacking an automatic carwash to close its doors around a victim vehicle and repeatedly strike it with the system's robotic arm. They found that they could locate 150 of the carwashes publicly on the internet, guess their default usernames and passwords, and even disable a safety feature meant to prevent the carwash's equipment from touching a vehicle. They convinced one family carwash to let them test their attacks, but didn't actually try them on a vehicle to avoid causing damage to the arm. But they did create a kind of proof-of-concept video (below) showing the carwash door repeatedly slamming on the hood of their pickup truck.
In September of last year, security researchers at the Keen Labs group of the Chinese tech giant Tencent pulled off an impressive feat of automotive hacking, completely undermining the security of a Tesla S to disable its brakes after it automatically connected to their rogue Wi-Fi hotspot. Tesla responded with a batch of security fixes, and even added a new security measure to its vehicles known as codesigning, which requires that any code installed on the car's head unit be signed with an unforgeable key held only by Tesla. Now, less than a year later, the same hackers have struck again, this time finding a path into the Tesla X's innards that works via not just a Wifi connection, but via a cellular signal, vastly increasing its range. And after defeating Tesla's codesigning protection and installing their own firmware on the vehicle to take control of its brakes, they added a wonderfully unnecessary flourish, captured in the video below.
One group of hackers has modernized the old party trick of the woman singing a high pitched note at the perfect frequency to break a wine glass. With nothing but soundwaves emitted from a small "gun" device they created, they were able to vibrate the MEMS sensors that function as accelerometers and gyroscopes that stabilize everything from quadcopter drones to hoverboards to the image inside an Oculus Rift headset. By merely firing resonant sound waves at exactly the right frequency at those devices, the hackers say they could cause the hoverboard to tip, making the image inside the Oculus shake nauseatingly, and potentially knock a drone out of the sky. But the hackers, who work for Chinese e-commerce firm Alibaba, didn't exactly carry out all those dramatic attacks; They tested their drone hacking technique on a non-moving drone with its rotors removed for safety, and had to install the sonic emitter inside the hoverboard's case to make that attack work. But they argue those demos nonetheless prove their attack works, and could be made more powerful with larger, more expensive sonic equipment.
On Wednesday, FBI Cyber Division Unit Chief Tom Grasso gave a Black Hat audience details of the December Avalanche takedown orchestrated by a group of international law enforcement agencies. It took four years of work to eliminate the sophisticated online criminal infrastructure known as "Avalanche." The platform could act as a botnet, and was also used to power malware distribution, launch phishing attacks, and move stolen money. The initiative involved sinkholing more than 800,000 malicious domains, Grasso said, and in January 2016 when Avalanche administrators moved one of their private domain registration servers from Moldova to the US, officials got a search warrant and ultimately accessed administrator email addresses and a list of more than 200 clients.
Grasso particularly emphasized the crucial role of international cooperation in the operation. In addition to the necessity of law enforcement collaboration, the private sector also contributes to the FBIs cyber crime work, offering everything from threat intelligence to technical help. In the case of Avalanche, numerous third parties including the Shadowserver Foundation and the German application research firm Fraunhofer contributed to the investigation. And Grasso made a plea for further assistance. If you think you want to go out and take down a threat yourself but youre like, I dont know if that would be legal, we can make it legal for you to do that. We can take your good ideas and formulate them into a sound legal plan.
Read more:
Security This Week: The Very Best Hacks From Black Hat and Defcon - WIRED
‘Internet of things’ hackers raise cloud of fear – E&E News
Attendees at the DEF CON security conference in Las Vegas last week hacked into voting machines, including this model last used in the mid-2000s. Blake Sobczak/E&E News
What do a car wash, a smart meter and a voting machine have in common?
They can all be hacked.
While most devices built on computer code can be broken, researchers at last weekend's DEF CON security conference in Las Vegas said fixing a hacked device has separate challenges. That creates big headaches for operators of critical U.S. infrastructure, including the electric grid, as connected devices fill every corner of modern life.
Jeff Debrosse, founder and CEO of NXT Robotics Corp., which provides robots for data centers and energy companies, said the threat of rogue devices is growing. "The internet is going to be swamped."
Debrosse told E&E News his robotic brainchild, modeled after a Mars rover, is designed to be a "series of connected devices," including cameras, motion sensors and a microphone.
"Unfortunately, the smallest devices just can't be updated, so [security] is going to have to happen in the network," he said, noting that he has added encryption to the communications protocol used by his own product, among other measures. "As a community, we have to figure out how to get that done, because it's coming our way."
The U.S. East Coast caught a glimpse of that dire future last fall, when attackers drew on raw computing power from thousands of hacked electronics to briefly knock down a core pillar of the internet. That "distributed denial-of-service" attack hobbled Dyn, a company that routes traffic to popular sites like Twitter and Grubhub (Energywire, Oct. 25, 2016).
With Dyn offline, casual web users were effectively blocked from reaching swaths of the internet.
"The internet of things terrifies me," said Craig Williams, senior technical leader and outreach manager for Cisco Talos, part of Cisco Systems Inc. "There is no quick solution. We've got devices out there now that are going to be vulnerable, that will have no company around to patch them."
The potential for thousands or even millions of hacked devices to be bundled together in a "botnet" for cyberattacks has set off alarm bells at government agencies and private companies.
When the powerful Mirai botnet of hacked cameras hit cybersecurity journalist Brian Krebs' website last September, power grid operators took note. The North American Electric Reliability Corp. published a rare warning about growing risks posed by the "internet of things."
The subsequent attack on Dyn drove home the danger to utility executives eager to avoid seeing their own "smart" electronics drafted into some hacker's army.
This outdoor security robot from NXT Robotics is an "internet of things" amalgam stitched together with cameras, microphones and digital sensors. Blake Sobczak/E&E News
Energy companies have separately turned to the "industrial internet of things" for efficiency gains in operational networks, though so-called IIoT technologies can carry many of the same security flaws as their consumer-grade counterparts.
"If you are going toward the new concepts for example, 'industry 4.0' or 'IIoT' or whatever well, you have to do it right," said Vladimir Dashchenko, senior security researcher on the critical infrastructure defense team at Russia-based cybersecurity firm Kaspersky Lab.
In a presentation at DEF CON's "IoT Village," Dashchenko laid out bugs he found in several IIoT software products used in multiple sectors and potentially "thousands" of control system environments. As he spoke, hackers at the back of the conference room competed to find faults in everything from smart refrigerators to drones.
Rep. Will Hurd (R-Texas), who visited DEF CON with his colleague Rep. Jim Langevin (D-R.I.) on the House Homeland Security Committee, stopped by the IoT Village and the neighboring "Industrial Control Systems" Village, the latter replete with a home-hacking contest and a realistic mockup of a chemical plant.
"One of the things that I learned is the length of time that these critical components within critical infrastructure are in place," Hurd said on the sidelines of the conference. "These things are designed to last for 20, 30 years. It's just one more thing that you have to take into account."
Eventually, cyberthreats will outpace even well-crafted, internet-of-things devices, according to Katie Moussouris, founder and CEO of Luta Security.
"Old hardware can't keep up with newer security technologies," Moussouris said.
That raises a thorny question for policymakers and IoT companies: Where do they go to die, when it's appropriate for them to die from a security standpoint?
For many IoT systems, there is no simple "off" switch to prevent them from being exploited for eventual use in wide-scale cyberattacks like the ones on Dyn and Brian Krebs. The devices may continue to beacon out to the internet long after their useful life, waiting to be hijacked.
Joseph Mlodzianowski, vice president of training firm Aries Security, deliberately connected IoT devices to the hostile WiFi networks at DEF CON as an invitation for hackers to try their hand. His "sheep city" in the conference's Packet Hacking village included a connected train system, garage door opener and a smart meter that, when hacked, shut off lights to half of the model town.
"All IoT devices lack security," Mlodzianowski said, adding that his mantra is, "you can't spell 'idiot' without 'IoT.'"
Policymakers have tried to address some of the security problems plaguing the IoT space. At least nine federal agencies, from the Federal Trade Commission to Department of Homeland Security, have offered some level of IoT-related guidance, "often on data security and privacy," according to a recent report from the Government Accountability Office.
Congress has also taken note. Hurd told a crowd of DEF CON attendees Sunday that he would push for a hearing on IoT, particularly as "smart" and autonomous vehicles start to become a reality.
"Connected cars is the subsection of IoT that most members [of Congress] can wrap their heads around," Hurd told a crowd of DEF CON attendees Sunday. "We all know we have to bake in security."
Hurd alluded to the early development of the internet, when technologists spared little thought to how their small, trusted network could be abused by hackers. "Let's not make those same mistakes when it comes to IoT," he said.
Moussouris, of Luta Security, suggested Congress could consider offering tax credits to organizations that lay out concrete steps to address IoT cybersecurity.
"Every single manufacturer or writer of open-source software that goes into a device be it car, medical device, or [other] IoT has to have an ability to find and fix vulnerabilities and has to have a process to handle the discovery of new vulnerabilities," she said.
Moussouris acknowledged that small manufacturers may be tempted to cut corners on security, given tight budgets and tough competition.
"They are, unfortunately, relearning old history lessons in security architecture and response," she said. "But on the other hand, if we bog [IoT firms] down with overly heavy regulations, we stifle innovation, so we have an economic responsibility to balance that out."
Visit link:
'Internet of things' hackers raise cloud of fear - E&E News
Facebook Donates $1M in New Funds for Internet Security at Black Hat – eWeek
LAS VEGASFacebook Chief Security Officer Alex Stamos outlined his views in an hour-long keynote at the Black Hat USA conference here on how the security industry should improve and also announced new investments to boost security.
Stamos is no stranger to Black Hat, which is celebrating its 20th anniversary this year. He said that in the early days there was a much more adversarial atmosphere at the event. He noted that in the early years, the true impact of internet security wasn't well understood, but today that's no longer the case with security breaches making headlines on a regular basis.
"We're no longer the hacker kids fighting against corporate conformity," Stamos said. "We don't fight the man anymore, we are the man, but we haven't changed how we view our responsibilities."
In Stamos' view the security industry as represented at Black Hat has a responsibility to help improve security in ways that it still hasn't achieved to actually help make people live's safer. He noted that often security research is focused on complexity and not the actual harm of cyber-attacks.
As a community, he said that there is an over-weighted focus on incredible security exploits and zero-days, though that's not what the bulk of actual security issues are. The vast majority of things that end up harming internet users are items that he labels as abuse, which includes be things as simple as spam, password re-use or harassing someone online.
"As a community overall we not yet living up to our potential," Stamos said. "We have perfected the art of finding problems without fixing the root issues."
Security nihilism is a condition that Stamos said is prevalent in the industry, with many people holding that view that most threats are from advanced hacker and nation-state adversaries.Stamos emphasized that while zero-day issues are important there needs to be more conversations about standard security issues. He also wanted the audience to remember that users aren't the problem.
"The modern world of technology is built on tightropes and we haven't put nets underneath," Stamos said. "Every single day we ask people to walk the tightrope and if they fall off, we say sorry can't help you."
Facebook's CSO didn't just take the stage just to deliver a sermon to his Black Hat audience on what they should do. He also used his time to explain what his company is doing to make the internet safer for everyone. Facebook recently renewed its' support of the Internet Bug Bounty which pays security researchers for finding vulnerabilities in open-source software.
Stamos also announced $1 million in new funding for the Internet Defense Fund to help encourage original research into practical defensive technologies. Topics that Stamos is interested in include research on how to improve security patching. Stamos added that Facebook is already working on making sure that its users can stay safe while working on unpatched operating systems.
"This room is full of $800 fully patched smartphones, but that's not how it is in the rest of the world," Stamos said. "There are lots of unpatched devices and we can't say they aren't worth protecting."
Stamos also recognized the role that Facebook played in the recent U.S. election and in elections around the world. To that end, Facebook is now also a founding sponsor of the Defending Digital Democracy Project, which is an initiative at the Harvard University's Belfer Center to help secure elections.
"We're working with Harvard to help protect democracy," Stamos said. "We are thinking about how to help election campaigns help themselves and setup good IT infrastructure."
Stamos also advocated for more diversity in the security industry, both in terms of gender and background to better reflect the broader internet community that the security industry is supposed to be protecting.
"It's a critical moment for our industry. We have been asking people to pay attention to us and now they are," Stamos said.
With that focus he wants security professionals to have empathy for the people that use the technology that the security industry builds. He also wants to shift the focus from the spectacular hacks to actually fixing real problems.
"I want as much thought a possible put into out how we eliminate entire classes of vulnerabilities and not just how to do spectacular demos on stage," he said.
Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.
See the original post:
Facebook Donates $1M in New Funds for Internet Security at Black Hat - eWeek
ARRIS Launches First Gateway with ARRIS Secure Home Internet by McAfee; Exclusively at Best Buy – PR Newswire (press release)
Cyberattacks in the connected home are a growing consumer concern. A recent McAfee study** revealed that 81 percent of consumers think it's important that their online identity and internet-connected devices are secure. As consumers install increasing numbers of connected devices into their home, savvy cybercriminals have morphed their focus to those new devices, knowing that many consumers fail to take the proper security precautions to protect themselves. Today, any device that connects to the internet is a potential target if not properly secured. This is why ARRIS partnered with McAfee, a leading independent cybersecurity company, to enable best-in-class security at the point where data flows in and out of the home.
Product Highlights
"The ARRIS SBG7580-AC is the first gateway to incorporate device security into the gateway, the entry point for internet into the home. In doing so, we've created a single product that delivers cybersecurity protection to devices in the home, including unsecured IoT devices," said Sandy Howe, SVP and GM, Consumer Products Group at ARRIS. "Instead of installing and updating security software on every single connected device, now people can simply connect to protect. ARRIS pioneered gateway technology, and the SBG7580-AC with ARRIS Secure Home Internet by McAfee showcases our 20+ years of technology communications expertise."
"We pioneered the digital life protection space where we made it our mission to protect all the devices that our customers use," said John Giamatteo, Executive Vice President, Consumer Business Group at McAfee. "With the integration of Secure Home Internet into the ARRIS gateway, we are delivering on this mission with an industry leader. The best security software is the kind that people actually use, and together with ARRIS, McAfee is making it easier than ever for consumers to protect every connected device in the home."
Pricing and Availability The ARRIS SURFboard SBG7580-AC with ARRIS Secure Home Internet by McAfee is available exclusively at BestBuy.com for $199.99.
About ARRIS ARRIS International plc. (NASDAQ: ARRS) is a world leader in entertainment and communications technology. Our innovations combine hardware, software, and services across the cloud, network, and home to power TV and internet for millions of people around the globe. The people of ARRIS collaborate with the world's top service providers, content providers, and retailers to advance the state of our industry and pioneer tomorrow's connected world. For more information, visitwww.arris.com.
For the latestARRISnews:
ARRIS, theARRISLogo, and SURFboard are trademarks or registered trademarks ofARRIS Enterprises, LLC. McAfee and the McAfee logo are trademarks of McAfee, LLC or its subsidiaries in the US and/or other countries. All other trademarks are the property of their respective owners. ARRIS Enterprises, LLC.2017. All rights reserved.
* Exclusively at Best Buy until Sept 30, 2017.
** In September 2016, McAfee commissioned OnePoll to conduct a survey of 9,800 consumers (aged 18-55+). Respondents were individuals who use an internet-enabled device on a daily basis in the following countries: Australia, Canada, France, Germany, Italy, Mexico, Netherlands, Spain, the U.K., and the U.S.
***ARRIS Secure Home Internet by McAfee blocks connected devices from reaching a known malicious site. As new and unknown sites are identified by McAfee, ARRIS Secure Home Internet by McAfee will automatically detect, block and secure connected devices from them.
****Actual rates may vary depending on a number of factors including, but not limited to: the services offered by cable service providers, network traffic, computer equipment, type of server, number of connections to server, and availability of internet router(s).An approximate value of $240 when compared to comparable offerings.
View original content with multimedia:http://www.prnewswire.com/news-releases/arris-launches-first-gateway-with-arris-secure-home-internet-by-mcafee-exclusively-at-best-buy-300486799.html
SOURCE ARRIS International plc
See original here:
ARRIS Launches First Gateway with ARRIS Secure Home Internet by McAfee; Exclusively at Best Buy - PR Newswire (press release)
Bitdefender unveils 2018 edition of Total Security, Internet Security … – Windows Report
For various PC problems, we recommend to use this tool.
This tool will repair common computer errors, protect you from file loss, malware, hardware failure and optimize your PC for maximum performance. Quickly fix PC issues and prevent others from happening with this software:
Bitdefender, the leading security firm has announced new consumer solutions that are designed to withstand attacks by advanced ransomware like the Wannacry and Petya. The new Bitdefender will make it increasingly difficult for the attackers to break into your systems. Bitdefender is powered by the machine learning and artificial-based technologies, something that the company has been developing since 2008.
Bitdefender Total Security 2018 will extend its protection to home users and will ensure that they are protected by an advanced layer of privacy. As one might have already deduced the number of malware and ransomware attacks are on a constant rise and its high time even the home users opt for a comprehensive security solution. True to its tradition the Bitdefender 2018 is light and will not slow down your computer.
The latest suite from Bitdefender Total Security 2018 offers a multi-layer defence mechanism capable of detecting ransomware attacks that usually evade detection filters. The Advanced Threat Detection keeps an eye on patterns of behaviour and is capable of blocking even the latest threats. On the other hand, the Real Time Protection will work in tandem with the Advanced Threat Defence and blocks all the known threats.
Bitdefender has also baked in a new feature called as File Safe. The File Safe is a special super secret compartment that prevents unauthorised alterations to the sensitive files. Other innovative features include Webcam Protection, a service that prevents webcam spying and blackmailers from unauthorised access of your webcam. Furthermore the Account Privacy for iOS and Android will ensure that none of your emails have been leaked.
The daily risks to users are more serious now that at any point in history, and Bitdefender is rising to the occasion with its 2018 consumer security product line, said Bitdefenders Vice President Consumer Solutions,Ciprian Istrate. Bitdefender 2018 advances the companys philosophy of protecting its customers with a layered approach against all major threats, from privacy loss to ransom demands
Lets take a look at the entire Bitdefender 2018 Lineup
The Bitdefender Total Security 2018 is the most comprehensive offering of the lot. It offers complete protection across multiple platforms including Windows, Mac OS, iOS (coming soon) and also Android. The Total Security offers advanced malware detection, multi-layer ransomware protection and webcam protection for better privacy.
The Antivirus Plus aims at providing the best protection against threats on Windows. The security suite is also optimised to preserve speed and battery life. The Antivirus Plus 2018 also offers a multi-layer ransomware protection.
Bitdefender Antivirus Plus offers performance optimisation tools like Autopilot, Photon and Battery mode. Privacy Protection features include complete data protection, advanced threat defence, Anti-Fraud and Secure Browsing.
The Bitdefender Family Pack 2018 is extremely useful as it will protect your entire family. The Family Pack comes witha monitoring tool to keep track of kids on Windows, Mac, iOS and Android. Parents can use this tool and safeguard their kids from inappropriate content, block disturbing phone calls and SMS.
The best part is that parents can track their kids whenever they are using smartphones and the children, on the other hand, can mark themselves safe using the Parental Advisor mobile app. Also, the parents can create a geofence and will get notifications whenever the children enter a restricted area.
Looking for complete protection against online threats? The Internet Security 2018 offers webcam protection, ransomware protection and file safe. It will work against all type of threats including viruses, Trojans, ransomware, zero-day, spyware and rootkits. Furthermore, the product also offers Social Network Protection, Password Manager and also file shredder.
Trusted by 500 million users. Stay always safe from viruses and malware
Your computer is vulnerable to malware, therefore its important to protect it properly. Malware comes in various forms, and it can cause performance loss and many other security-related issues.
If youre looking for a professional tool that can protect your PC from malware, spyware and ransomware, we strongly recommend you try Bitdefender. Considered by experts to be the best antivirus in the world, Bitdefender has more than 500 million active users worldwide. Become the member of Bitdefender family today and secure your PC from all online threats.
Download Bitdefender (50% WindowsReport discount)
Tags: bitdefender
Read the original post:
Bitdefender unveils 2018 edition of Total Security, Internet Security ... - Windows Report
Women in IT Security: Eight Women to Watch – SC Magazine
Women in IT Security: Eight Women to Watch
Diana L. Burley is a full professor of human and organizational learning at The George Washington University, and executive director and chair of the Institute for Information Infrastructure Protection (I3P), a consortium of universities, national laboratories and nonprofit institutions dedicated to strengthening the cyber infrastructure of the U.S.
Prior, she managed a computer science education and research portfolio and led the Cyber Corps program for the U.S. National Science Foundation. She co-chairs the ACM/IEEE-Computer Society Joint Task Force on Cybersecurity Education and, in 2013, served as co-chair of the U.S. National Research Council Committee on Professionalizing the Nation's Cybersecurity Workforce.
Widely cited in the media, Dr. Burley is also an in-demand speaker at industry gatherings, most recentlyat tech panelshosted by the U.S. Department of Homeland Security's Cyber Security Division, and(ISC)2.
She has been the recipient of a number of awards and honors and has authored 75 publications on cybersecurity, information sharing and IT-enabled change.
Jennifer Stisa Granick is an attorney, educator and the director of civil liberties for the Center for Internet and Society(CIS) atStanford Law School. A prominent advocate for intellectual propertylaw,free speech andprivacy, she has represented a number of high-profilehackers, including internet activistAaron Swartz.
Beginning her legal work at the statepublic defender's office, she then became a trial attorney before shifting to a private practice where she specialized in defending cases involvingcomputer crime. In 2001, she also began teaching cyber law at Stanford University. Granick was the civil liberties director at theElectronic Frontier Foundationfrom 2007 to 2010 and then an attorney at ZwillGen, where she specialized in internet security issues.
Most recently, Granick was in the news for her work on a case seeking to reveal how the government proceeds in matters of domestic snooping and how it strong arms companies into cooperating with federal efforts to thwart cryptography.
Dawn-Marie Hutchinson, executive director for the office of the CISO at Optiv, recognizes the potential security crisis that complements the growth of the Internet of Things (IoT). As our devices increasingly become tethered to the internet, she says, not enough people are concerned about the security implications and the risks presented.
"I was blown away to hear most people don't think [the IoT is] really a thing yet," she said in May at Interop during a presentation on securing enterprise infrastructure.
The former head of information security at Urban Outfitter has more than 15 years of achievement in healthcare, retail, technology, and professional services sectors. Her extensive experience in cybersecurity and risk management transfers to the board room where she is fluent in speaking with board members about the risks the company faces so the approporiate decisions can be made to enhance business strategy, improve supply chain operations and manage enterprise risk.
Jeannette Jarvis, director of product management at Intel Security, is a huge proponent of threat intelligence sharing, and she predicts it will rise this year as a primary strategy for mitigating cyberattacks.
"Sharing threat intelligence shifts the balance of power away from the adversaries and back to us, the defenders, Jarvis said.
Adversaries have more information about our defenses than we have about their attacks, and this asymmetry significantly influences threatdefenseeffectiveness," she told the World Economic Forum. "Attacks can be tested againstsecuritydefenses with impunity, whether in laboratories or deployedsystems. Preventing attackers fromtestingagainst us is very difficult and possibly unsolvable."
Jarvis told the forum that in order to improve our cyber defenses, the industry must cooperate. "Crowdsourced threat intelligence and collaborative analytics help connect the dots and form better pictures of what is happening in the attack landscape. 2017 will be the year in which threat intelligence sharing makes its most significant strides."
Armed with a master's degree in global affairs, transnational security from NYU, Alex Kassirer lent her expertise on the Anderson Cooper 360 show before becoming a terrorism analyst at NBC News as well as a senior analyst, lead on counterterrorism at Flashpoint.
Her ability to dig deep into areas of the Dark Web where most computer users never venture, along with her fluency in Arabic, enables her to keeps tabs on the online presence of jihadists who engage in hacking and cybercrime. This includes AlQaeda, ISIS and other terrorist movements, as well as nation-state actors. This reconnaissance includes getting vetted to be granted entree into underground forums and then communicating with the actors so as to interpret how they think and might act.
Frequently cited on cyber terrorism issues in the media, she was recently profiled in the The New York Times and was included among "54 Amazing Women" in Glamour magazine.
Law firms are always scanning the horizon, and cybersecurity is not only a goliath, but it is a goliath that is never going away, Nelson told an industry publication. We are here to stay in the digital world, and data is black gold. Data is the new oil, and having seen that, law firms are very responsive.
She maintains a cybersecurity and electronic evidence blog, Ride the Lightning, and is a co-host of two Legal Talk Network podcast series:The Digital Edge: Lawyers and Technologyand Digital Detectives.
With more than 15 years in the security field, Wendi Whitmore, global partner & lead at IBM X-Force Incident Response & Intelligence Services (IRIS), has diverse experience to arm her in efforts in the global incident response, proactive services and intelligence teams within IBM Services.
Prior, Wendi was a VP at CrowdStrike Services, where she was responsible for professional service offerings and engagements. That included critical security breach response for Fortune 500 companies and the federal government. She spent six years at Mandiant and prior was a special agent conducting computer crime investigations with the Air Force Office of Special Investigations.
A frequent speaker at industry gatherings, including the fourth annual Women in Cybersecurity Conference (WiCyS), held in May in Tucson, as well as SANS, BlackHat, DoD Cybercrime and the FBI National Infragard Conference, she also has been widely cited in the media on the topics of online privacy and consumer awareness.
After a dozen years as a senior researcher at the National Security Agency, Ellison Anne Williams left to found and take the CEO title at Enveil, a data protection company that uses homomorphic crypto to protect data interactions including search and analytic.Or, as she puts it, "does cool stuff with massive amounts of data."
The company certainly reached an early milestone when it was named a runner-upin theRSAConferenceInnovation Sandbox Contest 2017 for its "pioneering work in data security." It was the youngest company to compete in the competition and was selected from a roster of more than 300 startups. This is the first time in over 20 years of work into homomorphic encryption that this kind of scale has been achieved, Williams said at the event.
Fortified with masters degrees in mathematics and computer science, and a Ph.D. in mathematics, Ellison Anne Williams in 2009 authored The Use of Neural Networks in Intrusion Detection.
More:
Women in IT Security: Eight Women to Watch - SC Magazine
The Internet of Identities (IoI) – CSO Online
Jon Oltsik is a principal analyst at Enterprise Strategy Group ESG and has been quoted in the Wall Street Journal, Business Week, and the New York Times.
Everyone is talking about IoT these days and for good reasonthere are already billions of devices connected to the global internet, and some researchers are predicting 50 billion by 2020. This alone will make the CISO's job more difficult, but security executives face many other associated challenges as well:
As they say down south, That dog dont hunt. In other words, traditional security processes, controls and technologies cant scale to meet the security challenges of an IoT mobile world.
This is exactly where identity (i.e. device identity, user identity, asset identity, etc.) comes into play. Connecting sources and destinations must move beyond Layer 2/3 protocols and user name and passwords. Moving forward, everything on the internet must have a trustworthy identity. These trustworthy identities can then be used to guide and monitor secure connections.
[ Related: 4 places to find cybersecurity talent in your own organization ]
My colleague Mark Bowker has dubbed this trend the "Internet of Identities" (IoI), and it fits with many security trends we are tracking. For example, trustworthy identities are at the center of networking trends such as micro-segmentation and software-defined perimeters (SDPs). Once I know the identity of a device or person and the identity of the application or service they want to connect to, I can authenticate each entity, check a policy engine to ensure that this is an authorized connection, segment and encrypt the traffic between source and destination, and maintain an audit log of connections and even all packets exchanged between the two nodes.
In essence, the big global internet gets carved up into billions of fixed-function and personal virtual network segmentsall drive by identities at either end of the pipe.
In my humble opinion, Marks theory is spot on because we need to use identity, software-defined networking technologies, and big data analytics to decrease the network attack surface and monitor whats going on across billions of nodes. On the business side, IoI will also help organizations provide high-performance services to critical network traffic and high-value customers.
While IoI seems logical, its success over the next few years depends on many factors, including:
1.Strong authentication of IoT devices. Every IoT device must have a strong and unique identity based upon biometric technologies, fingerprinting techniques or tried-and-true X.509 digital certificates.
2.Broad use of standards and baked-in technologies.Im thinking of some type of rationalization around standards like FIDO, OAuth, OpenID, SAML, etc., while increasing the use of common biometrics like fingerprint readers on phones.
3.Cloud oversight of identities.Facebook, Google and Microsoft have identity scale in the cloud and are already fighting for identity control, but IoI must evolve into a cooperative ecosystem. Industry bigwigs have to work together and agree on an identity ecosystem similar to the model provided by the Trusted Identity Group and NSTIC from the National Institute of Standards and Technology (NIST).
4.Greater use of software-defined networking technologies.As I mentioned above, Im thinking about greater use of micro-segmentation and a migration from VPN technology to software-defined perimeters that provide any-to-any network access based upon user, identity, location, risk and strict business-driven policies.
5.Mature User and Entity Behavior Analysis (UEBA) tools.There will be far too much happening for security analysts to keep track of connections or spot anomalous behavior. Mature behavior-based security analytics tools based upon machine learning and artificial intelligence (AI) must continue to evolve to bridge this gap.
Large organizations must plan for IoI in several ways:
Continue reading here:
The Internet of Identities (IoI) - CSO Online
Trump Says He Pressed Putin, While Casting More Doubt On Election Meddling – NPR
President Donald Trump says he and Russian President Vladimir Putin agreed to form a joint cyber security unit during their talks at the G-20 Summit in Hamburg, Germany. Saul Loeb/AFP/Getty Images hide caption
President Donald Trump says he and Russian President Vladimir Putin agreed to form a joint cyber security unit during their talks at the G-20 Summit in Hamburg, Germany.
President Trump says he "strongly pressed" Russian President Vladimir Putin twice about Russia's meddling in the U.S. election and that it's now time "to move forward in working constructively with Russia."
That work, Trump said, will include a joint cyber security operation, as well as a new ceasefire in Syria.
In a series of tweets Sunday about his meetings with Putin at the G-20 Summit, Trump said Putin "vehemently denied" interfering in the U.S. election.
"I've already given my opinion," Trump added, apparently referring to his remarks in Poland shortly before attending the G-20 Summit in Germany. When he was asked about election hacking, Trump replied, "Well, I think it was Russia, and I think it could have been other people in other countries. Could have been a lot of people interfered."
He added, "Nobody really knows for sure."
At that news conference in Warsaw, Trump also noted that "three or four" U.S. intelligence agencies, rather than all of them, say that Russia sought to interfere in the election. And he compared their findings about Russia's involvement to the hunt for weapons of mass destruction in Iraq making it clear that he remains a skeptic.
Trump's posts on Sunday morning also included digs at the CIA, FBI and the Democratic National Committee, as well as a plan to work with Russia to form a "Cyber Security unit," raising questions about whether America's president agrees with U.S. intelligence agencies' conclusion that Russia carried out hacking to help Trump win the White House.
After Trump touted the plan to collaborate with Russia on Internet security issues, he was criticized by fellow Republicans, including his former rivals for the presidency.
"It's not the dumbest idea I've ever heard, but it's pretty close," Sen. Lindsey Graham, R-S.C., said on NBC's Meet the Press.
Graham called the meeting with Putin "disastrous," and said that while he sees Trump having success in other foreign policy areas, "when it comes to Russia, he's got a blind spot."
Sen. Marco Rubio, R-Fla., had a similar take, saying that "Partnering with Putin on a 'Cyber Security Unit' is akin to partnering with [Syrian President Bashar] Assad on a 'Chemical Weapons Unit.'"
Treasury Secretary Steve Mnuchin, defended the president, asking on ABC's This Week, "Why would President Trump broadcast exactly what he said" to Putin and adding, "Strategically that makes no sense."
It's the second time in recent days Trump has tweeted about the Russian hacking. On Friday, he wrote from the international talks in Hamburg to say, "Everyone here is talking about why John Podesta refused to give the DNC server to the FBI and the CIA. Disgraceful!"
Responding to that post, Podesta clarified that he had worked for Hillary Clinton's presidential campaign and not the DNC. He also reminded the president of his duties at the G-20 conference and told Trump, "Get a grip, man."
At the Hamburg meetings, Trump and Putin spoke for more than two hours. Afterwards, Putin said he thought Trump had "agreed" with his denials of Russia's involvement in the U.S. presidential campaign.
Secretary of State Rex Tillerson has offered a nuanced take on the two leaders' meeting, saying that while Trump raised the "concerns of the American people regarding Russian interference in the 2016 election" at the very start of his time with Putin, Trump also decided to focus on advancing talks on other issues. Tillerson added that in the meeting, "there was not a lot of re-litigating of the past."
When reporters asked Tillerson about how direct the American president had been in confronting Putin over Russia's interference in the U.S. democratic process and whether Trump had presented any evidence to try to convince Putin Tillerson replied:
"The Russians have asked for proof and evidence. I'll leave that to the intelligence community to address the answer to that question. And again, I think the President, at this point, he pressed him and then felt like at this point let's talk about how do we go forward. And I think that was the right place to spend our time, rather than spending a lot of time having a disagreement that everybody knows we have a disagreement."
After Friday's more than two-hour meeting between the two leaders, Tillerson's Russian counterpart, Foreign Minister Sergey Lavrov, implied that the U.S. president might not agree with his agencies' assessment, stating, "Of course, President Trump also mentioned that certain circles in the United States keep on spinning the issue of Russia's interference in the U.S. elections even though they are unable to prove that."
Trump didn't dispel that notion today, using the term "fake news" to refer to U.S. media outlets such as the Associated Press and New York Times that have clarified that four U.S. intelligence agencies (including the FBI and CIA) have concurred on Russia's attempt to meddle in America's national vote, rather than all 17 U.S. agencies that were mentioned in early reports.
There are no plans as of yet for another meeting between Trump and Putin, Tillerson said on Friday. He added that the State Department will explore "the cyber issue and this issue of non-interference."
On Sunday, Trump said the cyber collaboration unit would work to prevent election hacking. But that concern wasn't at the top of Lavrov's list earlier in the weekend, when he said the effort would focus on terrorism, organized crime, and problems such as child pornography and "so-called suicide networks," in addition to "hacking in all its forms."
Go here to read the rest:
Trump Says He Pressed Putin, While Casting More Doubt On Election Meddling - NPR
Internet freedom must be protected but also respected – Independent Online
Cyber security, now theres an unusual juxtaposition. Trying to control the free flow of information on the internet is like trying to pull the plug on gravity.
Netizens are panicked, and rightly so, over the latest financial computer worm WannaCry which hit 150 countries. The good old mattress seems to be an appealing option to stash hard earned moolah.
A dark cloud hangs over the USs formidable security as there is a good possibility that Russian tinkering helped deliver motor-mouth Donald Trump to the countrys presidential seat. If true, the security breach is far-reaching and could turn geopolitics on its head.
There are a myriad viruses that challenge coders on a daily basis.
According to Chinas IT giant Tencents annual report on internet security, last year alone its anti-virus lab identified 148 million new internet viruses.
The US insurance industry estimates the cost of cybercrime to the global economy at more than $450 billion.
Governments all over the world are seeking to manage and rein in cyber criminals bustling trade. A mammoth task, but one must admire their temerity for trying. Even if its just to placate ordinary citizens and help them sleep at night.
In recent weeks, the US and China passed tough cyber security laws.
Chinas cyber security law came into effect on June 1. The country has 730 million netizens. The government has clarified that it was not intended to manage foreign websites nor restrict the free flow of information.
The Cyberspace Administration of China released a statement saying that the law was to prevent any infringement of its cyber sovereignty. It would stop illegal information entering China under the pretext of providing free flow of information.
The administration believed this did not contradict its support for the free flow of information.
In the real world, all enterprises or individuals are required to observe laws of the countries they enter, and there should be no exception in cyberspace, it said. While the merits of this statement may be heavily contested by freedom of information activists, there is a positive part of the law which deals with the protection of personal information.
Professor of law at the Communication University of China told monthly magazine Beijing Review that the law would protect the publics personal information.
The trading of customers personal information is a pesky business which internet and cellphone users have to endure. The law clarifies the responsibilities of internet service providers and operators and promises heavy penaltiesfor trading personal information.
A survey by the Internet Society of China showed 84% of internet users were affected by personal information leaks.
In South Africa, Parliament has tabled the controversial Cybercrimes and Cybersecurity Bill for public comment this month. The bill has been doing the rounds since 2015 and is inching closer to being signed into law.
Activists have cautioned that parts of the bill are so broadly defined that they are open to abuse. For example, whistleblowers and journalists have little or no protection. If information is obtained unlawfully, even if it is in the public interest, both the whistleblower who leaked it and the journalist who published it can face criminal charges. Parts of the bill regrettably also gag freedom of speech. If it succeeds, it would be a blight on our hard-fought democracy.
Drafting law to combat cyber crime is a worthy pursuit but turning ordinary citizens and journalists into criminals is a crime in itself.
Melanie Peters is the Live Editor of Weekend Argus. She is on a 10-month scholarship with the China Africa Press Centre. Instagram: mels_chinese_takeout
See the original post:
Internet freedom must be protected but also respected - Independent Online
The internet, security and privacy – TechTarget (blog)
Security and privacy are always hot topics when it comes to discussions about the internet. And with the emerging internet of things, security and privacy questions are becoming even more prevalent.
The Internet of Things (IoT) world may be exciting, but there are serious technical challenges that need to be addressed, especially by developers. In this handbook, learn how to meet the security, analytics, and testing requirements for IoT applications.
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.
Its one thing to safeguard your passwords or to carefully designate who can view your online photos. But connecting your home to the internet? That could be dangerous or just plain unnerving. Imagine someone hacks your house and can turn lights on and off, or open the front door at will. So its no surprise that many companies are spending a lot of money and engineering hours on making smart home systems safe and secure.
At the same time, a new generation of products is getting popular. Take Alexa (and her cousins): a microphone in the middle of the room where you call and she answers whatever your question may be. The weather in Rome. The news in Atlanta. The business hours of a nearby store. Its essentially a browser you can talk to that understands what you are asking and, most of the time, provides solid answers.
This technology is a big step forward, both in technology and as a new way of connecting and interacting with the internet. The screen and keyboard are now a microphone and speaker. Technology prognosticators are already predicting that this method of computer interaction will soon become dominant.
So, back to security and privacy. Product manufacturers let us install passwords, and they implement encryption along with a host of other security features so that our secrets stay secret. But we suddenly fall in love with Alexa, believing that Alexa only listens if we say, Hi Alexa, before asking a question. Right? Just like we believe that our smartphone only listens if we say, Hey Siri. Right? Or that our voice-enabled remote control only listens if we push the voice button (Right?)
Recently I met someone who had placed a sticker over the camera on his laptop. I asked him why, and the answer was not terribly surprising: I want to make sure that I am not being watched. But what about being listened to? Which is potentially more damaging someone looking at your face while you are at your computer or someone able to listen to what you are saying anytime you are near the computer?
In addition to a sticker over the camera, should there be earbuds on the microphone? And what about cell phones? Is your cell phone listening to your conversations when youre not using it? Well, probably not, at least not so far. But with this promising new user interface, replacing the keyboard and screen with a microphone and speaker is becoming mainstream.
Now, think about introducing this concept in every piece of equipment in our homes. We could talk to the washing machine, dishwasher, refrigerator, television and so forth, but all these appliances and electronics would be permanently listening. What we say could be sent over the internet to an interpreter that translates words into code that can be executed, as if we had typed it into a browser. The result is either sent back over the internet as an action to do something (for example, turn on off the lights, start the dishwasher), or it is sent back as a voice stream that comes out of the speaker.
So, yes, we care about security and we heed the warnings to pay attention to privacy. But on the other hand, we all now walk around with cameras and microphones that 007 (the Sean Connery version, at least) could only dream of. How do we balance installing microphones in every room in our house with paranoia?
Product developers and manufacturers should put security and privacy first in building technology for voice-enabled wireless equipment like remote controls. Do not develop technology that listens to anything not intentionally shared and, by the way, the remote batteries would die quickly without the option to turn the microphone on and off. But we cannot control who uses our technology, in what kinds of products and with what intent.
Put security and privacy first, not because there may be a little man in your TV listening to conversations in your living room, but because this next generation of technology is rolling out quickly and skyrocketing in popularity. Without putting security first, will there ever be a legal framework protecting the consumer and defining responsibilities? Who will be responsible if a third party hacks or otherwise abuses the technology capabilities?
Headline-making cyberattacks on big companies and their customers passwords, credit card numbers and email addresses are just the beginning. With the arrival of IoT and technology advancements in our homes and in our lives, security and privacy are becoming more important than ever.
All IoT Agenda network contributors are responsible for the content and accuracy of their posts. Opinions are of the writers and do not necessarily convey the thoughts of IoT Agenda.
Originally posted here:
The internet, security and privacy - TechTarget (blog)