Home Blog Page 314

Cybersecurity insurers in the cloud space creating a new paradox

Cyber insurance

For starters, cyber insurance is not a hot topic and has been around for over a decade and a half. While, it is also at a nascent stage when compared to the major insurance market, cyber insurance has been designed to alleviate losses incurred from attacks on different aspects on the business, such as endpoint protection, cloud security, etc. Timetric’s in an ‘Insight Report: Developments in Cyber insurance’ pointed that the growing attacks have placed cyber insurance as a key mitigation tool. “Although cyber insurance does not replace the need for cybersecurity technology, it has the ability to complement cybersecurity standards through mitigating cyber risk.” It is no longer a debate of cloud computing any more. Out of 10 carriers, seven use cloud in their businesses today. It has become an integral part of the technology environment.

The adoption is so rampant that now insurers are the ones who are jumping on the cloud bandwagon. The Deloitte’s 2019 Insurance Outlook notes that, with insurers increasing cloud usage for seamless digital transformation, now regulators are raising flags on the cybersecurity.  This is majorly because several core systems and even critical data are moved to third parties in offsite. “The traditional drivers of cloud computing—cost savings and pay-as-you-consume contracts—will likely continue to push usage. Yet the next round of adoption will likely be driven by other key benefits that cloud offers—namely speed, flexibility, and scalability. Insurance CIOs, who are under pressure to deliver digital capabilities, are looking at developing applications on the cloud as a faster alternative to on-premises deployments,” the study points out.

A survey from Ovum, pointed out that a major share of Software as a Service (SaaS) are residing in the cloud. The data stresses that insurers are leveraging cloud more than ever before with a major chunk even for operational activities.

The Deloitte study also stresses on the fact that, “As insurers plan their IT investments, they should give cloud a higher priority when deploying new applications. At the same time, they should utilize the advanced capabilities of cloud to gain access to better analytics for business decisions.”

It is now imperative for insurers to make sure that cloud providers must be accountable for the security of their cloud’s hardware and software while regulations and implications understanding cyber threats must be the insurer’s prerogative.

The need for cloud and insurance are more than ever before. Companies are attributing greater value to their digital infrastructure. According to Allianz SE, organizations are paying roughly $3.25 billion each year in annual premiums for cyber insurance. But that is just a drop in the ocean, considering the cyber insurance market will sextuple by 2025 touching close to $20 million.

We at CISO MAG are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Swimlane secures $23 million to accelerate growth

cybersecurity regulations

Swimlane, an independent security orchestration, automation and response (SOAR) provider, recently secured $23 million in a Series B financing round led by utility-backed energy investment and innovation firm Energy Impact Partners (EIP). The Denver-based company stated the new funding will be used to accelerate its product development and expand the company’s partnerships.

Swimlane delivers scalable and flexible security operations management software to help organizations address all security operations (SecOps) needs, including prioritizing alerts, orchestrating tools and automating the remediation of evolving threats. Swimlane claims that its suite of security orchestration, automation, and response (SOAR) tools were designed to help security teams tackle the ever-growing number and increasing complexity of cyber-attacks.

Commenting on the new investment Cody Cornell, the co-founder and CEO of Swimlane, said, “The sheer volume of threats, shortage of available security talent and lack of integration between existing security and IT products creates an almost impossible situation for the modern security ops team. Swimlane is built for organizations looking to alleviate the pain of being understaffed and overworked, improving staff retention by moving away from reactive mundane tasks, and ultimately, creating a more proactive, effective and secure organization.”

“We look for companies with the proven ability to execute globally across vertical markets and ultimately transform how businesses operate—and Swimlane fits firmly in this category,” said Sameer Reddy, EIP partner. “Security teams across the world face the same two foundational challenges—a lack of qualified staff and too many point solutions to manage and operate well. As the leading independent SOAR provider on the market, we have heard directly how Swimlane helps resolve these organizational inefficiencies and streamlines the way industries respond to incidents, adhere to regulatory compliance mandates and mitigate the risk of cyberattacks for their customers.”

Malware laden laptop sells at 1.3 million in art auction

WannaCry-wakeup-call

Art and its aficionados have a special place in the human psyche. For some, it is the ultimate panacea, and for the others, it doesn’t make any sense. True in both the senses, you may find it unfathomable to learn that a laptop laden with literally all the famous malware sold for $1.3 million at an art auction.

The 11-year-old 10.2 inch Samsung Netbook also called as “The Persistence of Chaos” by artist Guo O Dong is infected with six different strains of malware namely ILOVEYOU, MyDoom, SoBig, BlackEnergy, WannaCry and DarkTequila. It is believed to have caused damages totalling to $95 billion to IT systems across the world.

It is not that the malware is rare or of high value, “These pieces of software seem so abstract, almost fake with their funny, spooky names, but I think they emphasize that the web and IRL are not different spaces,” Guo said while speaking to Motherboard. “Malware is one of the most tangible ways that the internet can jump out of your monitor and bite you.”

To prevent the malware from spreading from the new owner, the laptop’s internet connectivity and ports are disabled.

“By submitting a bid you agree and acknowledge that you’re purchasing this work as a piece of art or for academic reasons, and have no intention of disseminating any malware,” Guo said in the terms of the auction to ABC.

The laptop began its bid at $1.9 million and was eventually sold to an unknown person for $1.3 million and will be shipped from a gallery in New York.

The laptop was created in collaboration between the artist and cybersecurity company Deep Instinct. “We have this fantasy that things that happen in computers can’t actually affect us, but this is absurd,” Guo told The Verge. “Weaponised viruses that affect power grids or public infrastructure can cause direct harm. [WannaCry caused] the equivalent of $US100 million in damages and led to the cancellation of tens of thousands of doctors’ appointments. It is not a leap to say this caused significant human harm.”

ZTE launches first-of-its-kind cybersecurity laboratory in Europe

Penetration Testing, continuous testing, security testing

In a first, Chinese telecom conglomerate ZTE has launched a first-of-its-kind cybersecurity laboratory in Rome, Europe. The facility is launched in a bid to promote transparency and mutual trust with all the concerned third parties, as well as a grand avowal of the company’s commitment toward providing its customers with end-to-end security solutions and services. The company attains to do it by integrating security considerations and controls into every aspect of the product’s life cycle.

The laboratory will provide its global customers security assessment and audit services including source code review of 4G and 5G services by ZTE, procedural document review, black box testing and penetration testing. The laboratory will also extend as industry cooperation and research platform which will enable other global ICT companies to conduct research in several vectors of cybersecurity.

“The security lab is an open and cooperative platform for the industry,” said Zhong Hong, ZTE Chief Security Officer at the launch. “ZTE plans to gradually achieve the cybersecurity goals through three steps: first, meeting the requirements of cybersecurity laws, regulations and industry standards as well as certification schemes; second, conducting an open dialogue to enhance transparency and establishing cooperation with customers as well as regulatory agencies; and third, sustaining the open cooperation mechanism to contribute to cybersecurity standardization.”

Angelo Tofalo, Undersecretary of Defence; Flavia Marzano, Assessora for Roma Semplice; Zhong Hong, Chief Security Officer of ZTE and Li Bin, Minister Counsellor of the Chinese Embassy were all part of the opening ceremony.

Should Data Go on Your Balance Sheet?

Data Balance Sheet

Contributed by Jason Bloomberg, President, Intellyx

With all the buzz today about just how valuable data are, I wondered whether we should treat data as a corporate asset – and if so, whether they should go on the balance sheet. Today, data aren’t even treated as an intangible asset for accounting purposes.

I had no idea the can of worms I was opening. It turns out many people have asked this question before, both about the value of data as well as of information (more about the difference in a bit). Gartner analyst Doug Laney even wrote a book last year on the subject he named Infonomics, after the field of inquiry he spearheaded on the topic.

His basic idea: shoehorn information into the intangible asset class in standard accounting, thus representing information alongside other intangible assets like copyrights and licenses.

Sounds promising to be sure – but the devil is in the details. It seems that either representing information as an asset class is simply too hard, or perhaps the advantages of the status quo outweigh any particular reason to change how we account for information.

And yet, there is widespread agreement that data and information have value – and for digital organizations, may even represent the preponderance of value in their companies.

Take Facebook, for example. Facebook’s market cap is $444 billion, but its book value (value of its tangible assets) is only $66 billion. For a conventional company, the $378 billion difference between these numbers represents the market’s expectation of future earnings potential.

However, since Facebook doesn’t put data on its balance sheet, just how much of this $378 billion represents the value of its data and how much is the expectation of future earnings is anyone’s guess.

If we can’t answer this question, therefore, then our ability to judge the value of companies like Facebook is in jeopardy, making it impossible to either invest in or manage them rationally.

It’s time to take a closer look at this question – if not to solve the problem itself, at least to understand what’s at stake.

Why Infonomics is so Difficult

First, a note on the question of data vs. information. For the purposes of valuation, you can think of data as raw material that we can process into information. As with any other raw material, data only have value in terms of their utility after we’ve converted them into their finished form.

A ton of gold ore is worthless unless we refine it into gold, and then the value of the ore is the value of the resulting gold minus the cost of refining it. So too with data and information. The most important question we must answer, therefore, is how to recognize the value of information as an asset, while the cost of processing it is an important, but secondary question.

The first option, of course, is the status quo: simply ignore the value of information as intangible asset. As the Facebook example above illustrates, this approach obfuscates the standard balance sheet, and limits our ability to compare balance sheets between companies with different information valuations.

This unsatisfactory result could very well lead to shenanigans, both on the part of companies mischaracterizing their balance sheets as well as investors leveraging hidden information about the value of information as a sort of insider trading. But given that no one really wants additional regulation, and the annoying fact that we wouldn’t know how to regulate information valuation anyway, we’re probably stuck with the status quo.

The alternative that Infonomics touts is to reflect information as an asset on balance sheets as though it were an intangible asset like other intangible assets. However, putting this approach into practice soon runs into a number of knotty issues that result from fundamental differences between information and other asset types.

For example, if you share your information, does it go up or down in value? The answer: it depends. The value of a trade secret in large part depends upon keeping it secret, so sharing it would cause its value to plummet.

But in other cases, the value of information depends upon the network effect. An image on Instagram that 50 people see may have little to no value. But what about an image that goes viral, where 50 million people see it? Now we’re talking serious green.

Beyond Infonomics for the Digital Era

Neither Infonomics nor the status quo gives us a workable solution for valuing information – and as companies become increasingly digital, this problem will only get worse.

A third option might be to come up with an entirely separate ‘information balance sheet’ that deals solely with information-based assets. Companies would thus have two balance sheets – the one they have now and the new information-based one.

The advantages are clear: we now have the luxury to write new rules of accounting to suit the unique properties of information as an asset class.

How do we deal with depreciation or amortization? How would an insurance company value information for insurance purposes? We’d have the luxury of starting with a blank sheet of paper instead of having to bring all the baggage of standard accounting with us.

The downsides, however, are equally clear: twice the paperwork, and thus twice the hassle. Years of arguing over the details. And even if we managed to agree on the new set of rules, valuing companies would still be a difficult task.

Sure, we may have two separate sets of numbers, one for traditional assets and one for information, but now what? Do we simply add the two numbers together? What’s that company really worth, anyway?

The Digital Era Requires Radical Thinking

The fourth option is perhaps the most radical – but has an inherent simplicity that is quite appealing. In this case, we rethink the entire notion of a balance sheet where information becomes the core asset.

Other assets don’t go on the balance sheet at all. Instead, we reevaluate them in terms of their informational value.

Here’s an example. Today we may have a car, which is a physical asset. We know how to value it, how to depreciate it, how to insure it, etc.

Now, let’s think about replacing the car with your shared ride service of choice. Now instead of a physical asset, we have the utility of the shared ride service, which isn’t really an asset at all.

Let’s go one step further. Instead of the utility of the shared ride service, which is difficult to assign a value to, let’s treat the information associated with the shared ride service as the asset.

How to summon a car. How to pay for the car. The information the app provides to the user. All of these are examples of information that give us a way of assigning an asset value to the utility of the shared car service.

In other words, instead of trying to value the utility of information, instead we focus on the value of the information of utility.

The Intellyx Take

It’s difficult to get your head around the information of utility, and even harder to explain it in under 1,500 words. But that never stopped me before!

Here’s another example. In his 1974 book Marketing for Business Growth, Harvard Business School Professor Theodore Levitt made a profound, and now familiar point. He said, “people don’t want to buy a quarter-inch drill, they want a quarter-inch hole.”

A famous quote to be sure – only its wrong. People don’t want the hole. They want to hang up the picture. Only they don’t want to hang up the picture, either, not really; they really want the utility of hanging up the picture (for example, to get warm fuzzies when looking at a picture of their kids).

However, there’s no good way to measure the value of such utility. Instead, lets measure the value of the information about the picture’s utility – for example, information about people’s buying habits or other behaviors around hanging up that picture.

In this way we convert all considerations of value into considerations of the value of information – and thus we only understand the value of tangible assets in terms of the information they provide, process, or consume.

For traditional enterprises that think of assets in traditional ways, this approach doesn’t even make sense.

As we complete our move to the digital era, however, information (or data, if you prefer) will be the currency of global commerce. All assets will thus become information assets, and how we value companies will depend solely on how we value their information.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Australian teen hacks Apple thinking it would land him a job

Patchwork BADNEWS, APT31 threat group

How far would you go to land a dream job? In the teens, people tend to be too impulsive and naïve to see the bigger picture and that’s what went wrong with a teen in Australia who tried to hack Apple thinking the deed with land him a job at the global technology conglomerate.

In all fairness to the 17-year-old teen from Adelaide, he was under the impression that Apple would do the same to him what Apple did to the European hacker who had broken into its system and offered him a job. As per details, the boy along with a friend confessed that they broke into the mainframe of Apple in December 2015 and again in 2017 by creating false credentials. The servers in Apple gave him access thinking it was an employee.

The incident was found by the Federal Bureau of Investigation which contacted the Australian Federal Police (AFP) and reported him. According to his lawyer, Mark Twiggs, the boy wasn’t aware of the seriousness of his actions and really thought the company would have given him a job. “This started when my client was 13 years of age, a very young age. He had no idea about the seriousness of the offence and hoped that when it was discovered he might gain employment at this company,” he said. Fortunately, Apple did not incur any financial loss in the incident.

The Magistrate David White did not convict the youngster, instead, handed him a $500 (around $346 US) 9-month good behavior bond. He also told the teen to use his gifts for good. “He is clearly someone who is a gifted individual when it comes to information technology, that being said, those who have this advantage of being gifted doesn’t give them the right to abuse that gift,” he said. “The manner in which the world functions is one that is heavily reliant on computer technology and those who unlawfully interfere with those systems can do enormous amounts of damage.”

“Identity-based protection is the future of cybersecurity strategy”

Peter Smith

Peter Smith is the CEO and founder of Edgewise. Prior to founding Edgewise, he was on the founding team at Infinio Systems where he led cross-functional strategy for Infinio’s products and technology as VP of Product Management. Peter brings a security practitioner’s perspective to data center products with more than ten years of expertise as an infrastructure and security architect of full-service data centers and customer-hosting environments for Harvard University, Endeca Technologies, American Express, Fidelity UK, Bank of America, and Nike. In an elaborate interview with Augustin Kurian from CISO MAG, Peter discusses his journey, the scope of microsegmentation, and benefits of a Zero Trust environment.

Your journey with IT Infrastructure began in your college days while you handled infrastructure and security for Harvard Business School. From there on, you have consistently been a person who handled IT architecture. Tell us a bit about your journey that led you to Edgewise.

That’s right. When I was managing Harvard’s network very early in my career, I built an early version of a network access controller (NAC) before it was even an established category. My NAC determined who could access which resources from where. For example, a student would have a different level of access in their dorm than they would in a classroom.

Later, I joined Endeca to run infrastructure and security, and it was there that I first experienced the problem that Edgewise is now addressing. I was trying to control user and application behavior based on address-based firewall controls, but it was a nightmare. That was when I realized that I needed to control the app itself, and not the underlying address.

Coincidentally, during this time, I met Bob Gleichauf, chief scientist of In-Q-Tel and the creator of the Cisco NAC that I used to replace my original NAC at Harvard. He encouraged me to run with my idea and develop it into a product which led me to found Edgewise.

What were your initial challenges in properly implementing network security? What according to you was essentially wrong with network packets?  

To date, most of the focus for cybersecurity has been on early detection and rapid remediation of anomalous behavior or attacks-in-progress, but the sheer volume of new threats and vulnerabilities that are constantly appearing is simply too overwhelming. There are literally hundreds of thousands of new malware samples and at least a dozen new vulnerabilities discovered daily. It’s inevitable that, eventually, an attack will succeed in evading traditional network security tooling.

Access, however, is not unlimited. There are a finite number of communication pathways between applications. If these pathways can be secured, then even if an attack bypasses perimeter controls, it will not be able to continue to communicate and gain unauthorized  access to data or applications.

Microsegmentation can secure applications, hosts, and even individual databases on the network and restrict communication into and out of these “secure zones.” But most means of doing so rely on IP addresses, ports, and VLANs. Today’s networks—especially cloud and containers— are dynamic. Therefore, using only ephemeral, network-based information to make secure access decisions is highly risky and unreliable as instances spin up and down and as new applications are continuously deployed. Plus, traditional methods of microsegmenting a network can take months, even years, cost millions of dollars, and is a policy management nightmare throughout deployment. We thought there had to be a better way.

Edgewise was recently approved with two new patents on key elements for automating microsegmentation to enable zero trust security for enterprises. Tell us briefly about these new patents.

The two new patents, plus the one we were awarded in December, cover the basic pillars for extreme automation of microsegmentation within a network, which are:

Right data: Before microsegmentation can take place, the security team needs a comprehensive, accurate map of application communications pathways. One of our patents describes Edgewise’s ability to map communications through load balancers, layer-7 proxies, and NAT without deploying an agent to those devices or modifying their configurations. This patent is an important piece of collecting high-quality, high-fidelity data about network communications, which is the essential ingredient for automating microsegmentation.

Right analysis: Our third patent covers our ability to use machine learning to build the minimum number of policies necessary to secure access pathways between applications. We don’t rely on IP addresses for microsegmentation, but instead create immutable, cryptographic software identities using attributes of communicating applications, so even if the application is moved, policies don’t need to be changed.

Right control: The patent we were awarded in December describes how Edgewise verifies software identity at both ends of a network communication to ensure that only approved software communicates–denying access to malicious software and misused administrative tools.

We have eight more patents pending, but these three patents form the core of our intellectual property.

How do you propose microsegmentation for zero trust security in a cloud platform?

Microsegmentation tools that rely on IP addresses, ports, and protocols can’t protect cloud architectures. Due to the dynamic nature of the cloud, static security controls are unreliable because network constructs can change multiple times throughout any given day, or even a single session.

To overcome this problem, Edgewise builds cryptographic fingerprints for workloads, as described above. Using software identity rather than network information to build policies gives us the ability to take a uniform approach to policy creation and application identification so the security team can know with certainty that only software verified by its fingerprint is allowed to communicate, independent of network location.

Combine this software identity approach with zero trust principles — specifically, require access verification for every communication request, allow only identified applications to connect, implement least-privilege access, and update policies dynamically using machine learning—and now you have a method of microsegmentation that actually works and isn’t an operational mess.

Tell us relevance of creating a zero trust environment. How does zero trust environment fare against several vectors of cyber threats, including insiders?

The concept of zero trust is pretty simple: all communications inside the network are assumed to be potentially hostile and must be identified before they are allowed access. With zero trust, least-privilege access is applied not only to who is accessing the data, but also what, meaning the services, devices, or connections touching the data. It’s the best way to ensure network security is hardened all the way to the interior.

Concerning insider threats, there are five steps to combating them through zero trust.

First, remove overly permissive access controls that allow employees to interact with data and systems without resistance. Second, implement continuous authentication and authorization. Often, credentials are only checked one time at each juncture. Zero trust abandons the idea of a trusted user or process and requires a check on authorization and authentication every time access is requested. Previous access doesn’t determine future access.

Next, enable multi-factor authentication, which is not at all cumbersome in a modern zero trust network. Multi-factor authentication can happen automatically and seamlessly because identities are collections of multiple factors which cannot be changed by an attacker, whether it’s an unwitting insider or an external threat.

Fourth, segment the network. A modern, zero trust segmentation strategy shifts focus away from the network to what is communicating on the network, using identity as the basis for perimeterization. It continuously authorizes and authenticates communicating assets, enforcing control based on communicating assets.

Finally, take a data-centric approach. The vast majority of insider attacks happen because an employee wants to steal or destroy company-proprietary data. So, put security control as close as possible to the thing attackers want: the data. A zero trust network places the strongest protection around the most sought-after assets instead of the environment in which the assets are communicating.

Edgewise’s product portfolio claims to detect load balancers without relying on IP addresses or ports, without installing an agent on the load balancer. What are the benefits of such a system? How reliable are they?  

Like many network tools, the presence of load balancers is generally detected based on network constructs such as IP addresses, ports, and protocols. But in modern networking environments that include cloud, serverless, or containers, the network architectural information changes constantly, which makes it hard to detect load balancers. And if they’re not detected, both they and the traffic that flows through them will be unprotected.

We use machine learning and statistical methods to find load balancers that otherwise would go undetected, and we can do so without installing an agent on the load balancer itself, which is important because in some environments such as the cloud, installing an agent isn’t possible.

The system takes as little as one second to map the load balancer, NAT, and proxy entry/exit points. Once those points are mapped, the ongoing connection tracking is 100% accurate. This mapping process occurs during the initial ML learning period and provides the highest quality data to the ML policy automation process.

What are future plans of Edgewise? What is the future of cybersecurity?

Edgewise will continue to advance security’s and operations’ ability to rapidly and automatically discover and microsegment their networks to achieve zero trust. We strongly believe that zero trust is going to be the foundation of all security control in the future, and that companies must adapt how they protect their networked assets. A layered security strategy is the best strategy, but it’s time for companies move the most hardened control directly to applications and services instead of the network. Networking is going to continue to change — 15 years ago we couldn’t have conceived of containers — but what isn’t going to change is the data organizations need to protect. Protecting the data first is key to preventing full-scale data breaches, and I think identity-based protection is the future of cybersecurity strategy.

‘Wellbeing’ budget in jeopardy after New Zealand Treasury office got hacked

The New Zealand Treasury office is the latest government organization to be hit with a cybersecurity scandal. It is reported that hackers tried to infiltrate the documents of the upcoming budget, which has also been called the “wellbeing budget”.

The budget has been the limelight for being a bill that has been one of the first in the world where the wellbeing of citizens of New Zealand has been kept at the top-most priority. Two days before the document was scheduled to be released, the Treasury office found out that the systems were hacked with over 2,000 attempts recorded in a 48-hour period.

The New Zealand police have been alerted over the incident that has occurred in the parliament, and investigations have begun into the incident.

“The Treasury takes the security of all the information it holds extremely seriously,” said Treasury secretary Gabriel Makhlouf to RNZ. “It has taken immediate steps today to increase the security of all budget-related information and will be undertaking a full review of information security processes. There is no evidence that any personal information held by the Treasury has been subject to this hacking.”

Explaining the incident in metaphorical fashion, he said, “Imagine you’ve got a room in which you have placed important documents that you feel are secure, are bolted down with a lock and key, but unknown to you one of those bolts has a weakness, and someone who attacks that bolt deliberately, persistently and repeatedly finds that it breaks and they can enter and access those papers. That’s what’s happened here. It wasn’t an instance of someone stumbling into the room accidentally, it wasn’t an instance of someone attacking the bolt and finding it broke immediately.”

With the hack, the entire budget is in jeopardy with several commentators calling it a political embarrassment.

Flipboard exposed sensitive user data for nine months, data of 145 mn users at risk

DEO data breach

For nearly nine months, popular news aggregator, Flipboard, exposed sensitive user data to hackers in what has been called as a glaring security breach. It is still not estimated over the number of users that have been affected by the breach but the company has disclosed that only a subset of the 145 million monthly active users has been affected, which may still project an alarmingly huge number touted to be among millions.

According to a statement from the company, the hack occurred between June 2, 2018, and March 23, 2019, and again between April 21 and April 22, 2019. The breached database contains information like data like usernames, email addresses, and passwords.  On the plus side, the stolen passwords have been encrypted.

“Flipboard has always cryptographically protected passwords using a technique known by security experts as “salted hashing”. The benefit of hashing passwords is that we never need to store the passwords in plain text. Moreover, using a unique salt for each password in combination with the hashing algorithms makes it very difficult and requires significant computer resources to crack these passwords. If users created or changed their password after March 14, 2012, it is hashed with a function called bcrypt. If users have not changed their password since then, it is uniquely salted and hashed with SHA-1,” it said in the statement.

Flipboard also stated any user who used third-party accounts to log in to the website may not have been affected. But as a precaution, “we have replaced or deleted all digital tokens,” the release added.

Flipboard has reset passwords of all users “even though the passwords were cryptographically protected and not all users’ account information was involved. You can continue to use Flipboard on devices from which you are already logged in. When you access your Flipboard account from a new device, or the next time you log into Flipboard after logging out of your account, you will be asked to create a new password,” the statement said.

 

5 Data Breaches to Understand the Importance of Data Security

Data Security, Unprotected Database Exposes 14 Million Key Ring App Users Info

Do you know about data breaches? If you think no, then think again — have you heard about the data scandal of Cambridge Analytica and Facebook?

Contributed by: Asim Rahal

If yes, you very well know about data breaches. It’s a loss or theft of data — corporate or users’ personal data — from an organization using malicious methods.

The ever-growing list of companies that faced data breaches in the past includes big names like eBay, Macy’s, Reddit, Twitter, etc. What’s the aftermath? These institutions lose people’s trust and their market value and face legal penalties as well. For example, a monetary sanction is usually levied under GDPR.

So, the question arises: how to prevent data breaches? There is no hard and fast rule for protecting data from malicious people, but there is a practice called Data Security. It helps organizations protect their and their users’ data from various types of attacks. However, it’s still very common to hear about a breach.

If companies are aware of data security, why do data breaches still happen? First of all, it’s almost impossible to fully protect a computer. Then, sometimes, companies don’t understand the importance of data security. So, they don’t put their best efforts at data security, and a data breach is usually the result.

That’s why this post discusses the worst data breaches of this century to help you — as a company owner or a security professional — understand the effects of a data breach. Thus, the importance of data security. Let’s get started.

5 Worst Data Breaches of 21st Century

Yahoo [2013-2014]

Yahoo — the once popular giant — announced in September 2016 that 3+ billion user accounts were stolen during 2013-2014, making it the biggest known data breach in history. The data included names, email addresses, phone numbers, security questions, dates of birth, and encrypted passwords of its users.

As a result, its share price tanked by 5% in a day. Also, it caused a loss of $350 million during its acquisition by Verizon. Yahoo was criticized for its late disclosure of the breaches and faced several lawsuits and an investigation by the United States Congress. Last but not least, users lost their trust in Yahoo.

Marriott International [2014-2018]

Marriott International — the popular hospitality group — faced a massive data breach affecting up to 500 million guests. Hackers extracted people’s personal data as well as loyalty program, payment, and reservation information. That’s not all, encrypted credit card data of 100 million customers was also stolen.

The first data breach originated in 2014 at Starwood, which was acquired by Marriott International in 2016. It was uncovered after four years in September 2018, when a security tool alerted about an unauthorized data access. Consequently, the company faced a class-action suit, and its shares also fell around 5.6%.

Adult Friend Finder [2016]

The FriendFinder Network that includes Adult Friend Finder and adult content websites like Penthouse.com and Stripshow.com was hacked in October 2016. The hack exposed data of 412 million accounts including names and email addresses, comprising 20 years of data stored on six different systems.

What was their worst mistake? The passwords were stored in SHA-1 — a weak hashing function, allowing hackers to crack most of the passwords. Then, they kept the data of 15 million deleted accounts for no reason. The network faced a class action lawsuit and was questioned for its security practices too.

eBay [2014]

At eBay, intruders accessed data using three corporate employees’ credentials for several months until May 2014. They accessed personal data including names, addresses, and encrypted passwords of 145 million users. The method used for compromising keys was unannounced but could be malware or phishing.

The company took the breach seriously and advised all its customers to change their credentials. However, eBay was condemned for poor communication and bad implementation of the password-renewal form. The breach resulted in a decline in user activity, and eBay faced a class-action lawsuit as well.

Equifax [2017]

The data breach at Equifax — one of the largest credit bureaus — in July 2017 affected more than 147 million consumers. The hackers gained access to crucial data including Social Security Numbers, driver’s license numbers, addresses, etc. Also, it exposed the credit card data of 200+ thousand people as well.

How did it happen? The attackers managed to enter the company’s systems through a web application’s vulnerability in mid-May. Fortunately, it didn’t find any evidence of unauthorized activity on its core credit reporting databases. As a devastating result, its share price tanked by 18% in the span of a few days.

So, Why is Data Security Important?

Data Security is crucial for any organization as it can make or break a company’s business as well as its reputation. However, Data Security has become a tedious task since cybercriminals come up with numerous methods to break into the corporate systems, resulting in the loss or theft of sensitive information.

So, what kind of sensitive information gets lost or stolen? A data breach can expose a lot of information, of which, the most sensitive information includes a company’s financial or payment information, its Intellectual Property (IP), and its users’ financial, medical, or personal information. Of course, it’s not all.

Then, what are the common methods or reasons which lead to a data breach? The most common reasons leading to a cyber attack are weak passwords, human errors, malware and trojans, outdated software, etc. Also, there are application vulnerabilities, unsecured endpoints, and poor security systems as well.

That said, the question arises: how a data breach can be prevented? The best method for securing data is by using a combination of hardware and software technologies. For example, antivirus, anti-malware, encryption tools, firewalls, software patches, two-factor authentication tools, system updates, etc.

However, it’s not easy to configure and monitor all these security methods and tools. That’s why you must look for a data security solution on that identifies data breaches and security threats monitors data leakage and unauthorized access, employs limited access, and prohibits unsecured devices and endpoints.

Another method commonly used to prevent data breaches, is penetration testing. A process in which “ethical hackers” (in service of cybersecurity companies) probe the client’s web assets in attempt to locate “points of failure” which could be used in an attack. Once pinpointed, these breaches can be sealed, preventing an attack and “proofing” client digital assets.

Imperva’s data security solution is one example of a “360” product, which packs the best protective features for securing the data in your organization. It identifies sensitive data, searches for database vulnerabilities, monitors data activities, checks for risky or malicious users, masks sensitive data, and neutralizes ransomware as well.

It also offers FlexProtect Plans that feature various security systems in flexible packages for protecting your applications, data, or applications and data. They include many tools like Data Security Gateways, IP Reputation Intelligence, User Rights Management, Web Application Firewall, etc.

What is your opinion on data security? Do you think your organization is doing enough to protect its crucial data? Write a comment below to share feedback.

Asim Rahal is a Detroit-based independent service provider specializing in IT and cybersecurity. You can reach him on Twitter at https://twitter.com/AsimRahal

CISO MAG does not evaluate the advertised product, service, or company, nor any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.