Home Blog Page 409

China mandates assessment for companies handling big data

Infosec-China

The cyber authority of China has released a draft that mandates every firm that exports to undergo an annual security assessment. The step is undertaken to safeguard data from different types of cyber threats and even cyber terrorism.

According to the new draft from the Cyberspace Administration of China (CAC), any business or organization transferring data of over 1 terabyte or has information affecting more than 500,000 users will be assessed on its security measures. It would also assess information on its potentiality to harm national interest of the country.

The draft which is open for public comment until May 11, also mandates organizations to obtain consent from users before transmitting data beyond borders. This is extension of the legislation passed in November, 2016, which formalized a range of controls on firms that handle data in industries, the government deemed critical to national interests.

The business associations had criticized the law, calling it ‘vague’ and stringent for foreign companies who seek expansion.

This also follows the proposed law which rewards citizens with $1,500 to $73,000 on information on suspected spies.

Under the rules released, sensitive geographic data such as information on marine environments would also be subject to scrutiny. Destination countries and the likelihood of oversees tampering would also be factored in to any assessments.

CIA behind scores of cyberattacks

symantec-cia

Security researcher Symantec has linked scores of cyberattacks around the world to the U.S. Central Intelligence Agency. This comes after web publisher Wikileaks exposing the advanced hacking tools used by the US federal agency.

That means the attacks were likely conducted by the CIA. The files posted by WikiLeaks appear to show internal CIA discussions of various tools for hacking into phones, computers and other electronic gear, along with programming code for some of them, and multiple people familiar with the matter have told Reuters that the documents came from the CIA or its contractors.

Symantec said it had connected at least 40 attacks in 16 countries to the tools obtained by WikiLeaks, though it followed company policy by not formally blaming the CIA.

The CIA has not confirmed the Wikileaks documents are genuine. But agency spokeswoman Heather Fritz Horniak said that any WikiLeaks disclosures aimed at damaging the intelligence community “not only jeopardize U.S. personnel and operations, but also equip our adversaries with tools and information to do us harm.

“It is important to note that CIA is legally prohibited from conducting electronic surveillance targeting individuals here at home, including our fellow Americans, and CIA does not do so,” Horniak said.

She declined to comment on the specifics of Symantec’s research.

The CIA tools described by Wikileaks do not involve mass surveillance, and all of the targets were government entities or had legitimate national security value for other reasons, Symantec researcher Eric Chien said ahead of Monday’s publication.

In part because some of the targets are U.S. allies in Europe, “there are organizations in there that people would be surprised were targets,” Chien said.

Symantec said sectors targeted by operations employing the tools included financial, telecommunications, energy, aerospace, information technology, education, and natural resources.

Besides Europe, countries were hit in the Middle East, Asia, and Africa. One computer was infected in the United States in what was likely an accident – the infection was removed within hours. All the programs were used to open back doors, collect and remove copies of files, rather than to destroy anything.

The eavesdropping tools were created at least as far back as 2011 and possibly as long ago as 2007, Chien said. He said the WikiLeaks documents are so complete that they likely encompass the CIA’s entire hacking toolkit, including many taking advantage of previously unknown flaws.

The CIA is best-known for its human intelligence sources and analysis, not vast electronic operations. For that reason, being forced to build new tools is a setback but not a catastrophe.

It could lead to awkward conversations, however, as more allies realize the Americans were spying and confront them.

Separately, a group calling itself the Shadow Brokers on Saturday released another batch of pilfered National Security Agency hacking tools, along with a blog post criticizing President Donald Trump for attacking Syria and moving away from his conservative political base.

It is unclear who is behind the Shadow Brokers or how the group obtained the files.
(with agency inputs)

Dallas siren club

dallas-siren-club

Cyberattacks are often hush. Off the radar, and often off all possible records. But that wasn’t the case in Dallas. The hack was loud, really loud.
Thanks to a hacker! All 156 emergency sirens screamed for 90 whole minutes, and there was no tornado. The researcher concluded that the hacker has exploited a vulnerable network. But it turns out, the computer networks were spared. Hackers just used the radio.

According to a statement issued Dallas City Manager T.C. Broadnax clarified the cause of the chaos, saying the “hack” used a radio signal that spoofed the system used to control the siren network centrally.

“I don’t want someone to understand how it was done so that they could try to do it again,” Broadnax said without going much into details. “It was not a system software issue; it was a radio issue.”

First installed in 2007, the Dallas outdoor emergency warning system powers sirens made by a company called Federal Signal.

According to The Hacker News, “It was noted that “it’s a tonal-type system” that’s usually controlled by tone combinations used by the EAS broadcast over the National Weather Service’s weather radio, and by Dual-Tone Multi-Frequency (DTMF) or Audio Frequency Shift Keying (AFSK) encoded commands from a command center terminal sent over an emergency radio frequency.” The commission has a 7000MHz range of radio frequency for public safety.

The reports suggest that the emergency system could be compromised by an outside radio equipment. Similar to the ones used on the age-old phreaking.

New sibling of doomsday vault stores data

norway-emergency-vault

What would you do to if you have something that’s precious and important, and want to make sure it remains safe? If you were a squirrel, you’d think of digging a hole and hiding it. Ironically, that’s what even the rest of the world is doing— reaching out to the farthest corner and hiding important things from not just people but even protecting it from potential nuclear holocaust, bio warfare, and even alien invasion.

This is what the Doomsday Vault is meant to do. The first doomsday vault was built in 2008, to backup seeds. Also known as the Global Seed Vault, the facility duplicates seed samples from across the globe. Even if every single grain of wheat is wiped out of the planet, the vault will have a backup.

The vault has a new sibling now, and this one is meant to store data. Dubbed as the Artic World Archive, the facility can store information crucial to companies and individuals for 1000 years.

The data is stored in analog format on film reel. Film is an optical medium, “so what we do is, we take files of any kind of data — documents, PDFs, JPGs, TIFFs — and we convert that into big, high-density QR codes. Our QR codes are massive, and very high resolution; we use greyscale to get more data into every code,” said Rune Bjerkestrand, Piql, the company behind the idea, told The Verge.

The data is kept offline and access is provided on demand when needed. The Arctic World Archive is connected to the world wide web using high speed optical fiber connection.

There haven’t been any talks of a third vault. But these can be an inspiration to one of those episodes of Black Mirror. As far as now, the nations of the world have agreed to keep it free from military installations and occupation, making it close to a demilitarized zone.

Cherry-picking, a new trend among hackers

Patchwork BADNEWS, APT31 threat group

This is the second time this year, where a security measure for safety has given an access card for cybercriminals. The first one was with WhatsApp and Telegram, where encryption, designed to spruce security potentially enabled hackers to slip-through a malware-ridden photographs. With no mechanism for intercepting messages in transit, and being far more difficult to scan for viruses or other malicious attacks sent using the service, the hackers could access the account, check photographs and even hijack the account.

The next one is rather more dangerous, as it involves your money as well as your personal details. This security measure has been deployed by almost all the companies from across the world including many high-profile websites like Google, Facebook, Amazon, among others. We are talking about the two-step verification. According to a Daily Mail report, hackers have used a common vulnerability in telecom networks to rip access codes off to online bank accounts.

The users will be oblivious to the fact that their accounts have been compromised until they see a random transaction made on the account or a malicious message have been sent on social media. The reports state that criminals were able to exploit Signal System 7 (SS7). SS7 helps networks to route calls and texts, by switching signal towers. Hackers are here redirecting data and intercepting the two-step authentication using the SS7 service.
One of the first attacks was reported in Germany. According to German newspaper Süddeutsche Zeitung, telecoms company Q2 Telefonica has confirmed the attacks. Although, the number of affected customers remain unknown. Daily Mail states that the attacks have been brought to the attention of legislators in the U.S. way back in 2014, who have initiated a crackdown on the fault.

Congressman Ted W Lieu said in a statement: “Everyone’s accounts protected by text-based two-factor authentication, such as bank accounts, are potentially at risk until the FCC and telecom industry fix the devastating SS7 security flaw. Both the FCC and telecom industry have been aware that hackers can acquire our text messages and phone conversations just knowing our cell phone number. It is unacceptable the FCC and telecom industry have not acted sooner to protect our privacy and financial security.”

Even after this being a problem that legislators know about since 2014, there hasn’t been much noise around it. In fact, world’s largest internet companies across the world still continue to restrict themselves to this method, only at the mercy of hackers.

The silver lining is that hackers must pass the first stage of verification which includes your username and password to initiate the attack. But again, the numerous amounts of hacks that are reported everyday puts you back right at the center of the table. Thankfully, you can find out if your account has been compromised in one of those thousands of mass data breaches. Visit the site ‘Have I Been Pwned?’ A key factor is having multiple passwords for different sites. Second method can be updating your password every now and then. You can also deploy a reputable password manager that can help you generate complex passwords, and will save it in an encrypted format.

SDutch Parliament attacked by ransomware

City of Liège, dutch-parliament, norwegian paliament cyberattack

According to Dutch news agency ANP, the Dutch parliament’s website was briefly hit by a so-called ‘ransomware’ attack.

The form of attack in which hackers scramble a computer system and seek a ransom to unscramble it came amid concerns that Turkish hackers are targeting the Netherlands.

Turkey’s relations with several European Union countries, including the Netherlands and Germany, have been badly strained after Turkish ministers were banned from campaigning in their cities ahead of an April 16 referendum that would give Turkish President Tayyip Erdogan sweeping powers.

The Dutch parliament said it had taken “appropriate measures” in response to the breach but declined to give details, ANP reported.

Two publicly-funded websites used by Dutch voters to help them decide which party to vote for in the national election on March 15 also came under attack on election day.

Fox-IT, a Dutch internet security firm, reviewed those attacks and said it believed they were conducted by Turkish hacking groups.

Earlier, NL Times was the victim of at least two DDoS attacks, in an attempt to take the site offline, according to a Turkish-language Facebook group linked to cyber-attackers. In a DDoS attack, a large amount of traffic is sent to specific servers, causing them to crash.

Website Rumag was hacked on Monday, according to NU.nl. Pro-Turkish and anti-European texts with a photo of Turkish president Recep Tayyip Erdogan were posted on the site. After the Turkish text a message was displayed in English. It read: “Hey Europe, you often talk about democracy, human rights and freedom. But your fear of ‘Great Turkey’ shows your colonialist, racist and fascist crusade mentality and shows your true face.” The message is signed by hacking group Cyber-Warrior Akincilar.

Cybersecurity finds place in product reviews

cybersecurity

The U.S. non-profit group that conducts extensive reviews of cars, kitchen appliances and other goods, Consumer Reports, is gearing up to start considering cybersecurity and privacy safeguards when scoring products.

The group, which issues scores that rank products it reviews, said it had collaborated with several outside organizations to develop methodologies for studying how easily a product can be hacked and how well customer data is secured.

The first draft of the standards are available online at thedigitalstandard.org.

Issues covered in the draft include reviewing whether software is built using best security practices, studying how much information is collected about a consumer and checking whether companies delete all user data when an account is terminated.

Consumer Reports will gradually implement the new methodologies, starting with test projects that evaluate small numbers of products, Maria Rerecich, the organization’s director of electronics testing, said in a phone interview.

“This is a complicated area. There is going to be a lot of refinement to get this right,” Rerecich said.

The effort follows a surge in cyberattacks leveraging easy-to-exploit vulnerabilities in webcams, routers, digital video recorders and other connected devices, which are sometimes collectively referred to as the internet of things.

“Personal cyber security and privacy is a big deal for everyone. This is urgently needed,” said Craig Newmark, the founder of Craigslist who is a director at Consumer Reports.

Security researchers have said the attacks are likely to continue because there is little incentive for manufacturers to spend on securing connected devices. “We need to shed light that this industry really hasn’t been caring about the build quality and software safety,” said Peiter Zatko, a well-known hacker who is director of Cyber Independent Testing Lab, one of the groups that helped Consumer Reports establish the standards.