Monday, July 8, 2013

Ex-FBI chief speaks about risk of cyber terror

By SHAWN POGATCHNIK
The Associated Press

                                                               


DUBLIN -- United States intelligence officials must do a better job analyzing the mountains of global internet, telephone and financial data they already collect to thwart the cyber terrorists of tomorrow, according to former FBI director Louis Freeh.
Speaking to The Associated Press ahead of the Global Intelligence Forum starting Monday in Ireland, Freeh said hackers seeking to take control of, or take down, key pieces of U.S. infrastructure could do more damage than the attackers of 9/11. He said computer systems controlling power plants, the navigation of aircraft and ships, and even the switching of street lights could be hijacked to gridlock societies and kill large groups of people.
"People traditionally think of this threat as somebody stealing their identity or their credit card number, or making it inconvenient to go to the ATM (cash machine). That's a very benign view of the potential for what cyber terrorism really is," Freeh said.
"You could manipulate transportation systems, aviation guidance systems, highway safety systems, maritime operations systems. You could shut down an energy system in the northeast U.S. in the middle of winter. The potential for mass destruction in terms of life and property is really only limited by (the attackers') access and success in penetrating and hijacking these networks," he said.
Freeh said people shouldn't be lulled into complacency just because hackers' attacks on government and business targets to date hadn't directly killed anybody.
"There's a lot of technology and a lot of ability out there, particularly with state actors," he said, referring to other governments' cyber-spying operations including in China, which U.S. authorities previously have blamed for stealing American corporate trade secrets. "We went through the Cold War without anybody using a nuclear bomb, but that didn't mean the capability and threat weren't there."
Freeh, 63, directed the Federal Bureau of Investigation from 1993 to 2001, leaving just before the al-Qaida attacks on the World Trade Center and Pentagon. In the years since he's become a top private investigator, most recently publishing the report into the cover-up of child abuse in the Penn State University football program. Last week he was appointed to oversee a probe into alleged corruption and malpractice in the payouts of billions in compensation from BP's 2010 oil spill in the Gulf of Mexico.
He said his keynote speech Monday to an annual seminar organized by Mercyhurst University's Institute for Intelligence Studies would focus on how intelligence and law-enforcement agencies need to use the internet to identify threats - and keep their own secrets secure. The four-day conference brings together intelligence officials worldwide, with a focus this year on combating internet-based crime.
It takes place against the backdrop of continuing revelations from former U.S. National Security Agency analyst Edward Snowden, who is believed still to be holed up in Moscow's airport three weeks after the U.S. Justice Department charged him with espionage and theft of government property.
Freeh questioned Snowden's description as a whistleblower - and why the NSA ever gave Snowden such access to its secrets without effective supervision.
He said Snowden should "come to a forum or an arena where he can raise his whistleblower defense." He said the NSA, like other U.S. government agencies, has an internal reporting process for whistleblowers alleging wrongdoing but Snowden appears not to have used this.
"He's said publicly that he was witnessing and participating at least indirectly in what he thought was a mass violation of U.S. rights, constitutional rights, human rights, and so was forced to publicly disclose this. It's just not accurate. It's Hollywood-esque and may be romantic for somebody to think: My God, this guy had no choice. But the reality is he had plenty of options and choices," Freeh said.
He said the NSA gave Snowden system-wide access with "the ability to extract and copy top-secret documents detailing secured and elaborate programs." He noted that a recent PricewaterhouseCoopers survey found that employee insiders committed around a third of all breaches of sensitive data.
And that, he said, was the biggest issue for government agencies and corporations: What should be accessible on its own internal intranet connections, and who should be cleared to see it?
As things stand now, he said, "too many people have too much access" to sensitive documents in companies and government agencies. He suggested that a group's most confidential information might have to be left without an electronic fingerprint at all and be kept, old school, like the Coca-Cola company's recipe for its soft drinks once was under lock and key in a safe.
But he said, conversely, everyone in the 21st century should assume that every time we click our keyboard, or thumb our smart phone, it's being put blindly into multiple databases ranging from internet aggregators to NSA hard drives.
For law enforcement officials, he said, the challenge was whether this tsunami of information could be mined effectively before an attack. While he described U.S. collection of data as "very robust," its analysis and use in detecting crimes was not.
"In the internet world we live in, all of our data is collected. I'm going to walk around with my cell phone today and my carrier is going to know my location on a minute-by-minute basis," he said. "So it's not really the data. It's how you protect it, how you manage it, and what people's expectations are for its utilization."

Uproar in the mobile fingerprint market

 
Mergers, tech giants and massive opportunity defines space
01 July, 2013

Mobile payments saw a major push in 2012 thanks largely to increasing NFC adoption, growing interest in contactless payments and mobile wallet initiatives like Isis. With the addition of  high-value functionalities, however, comes the need for secure and reliable mobile authentication.
Mobile contactless functionality is certainly in our future – in many ways it’s already here – but the technology has been met with skepticism in some circles due to weaknesses in authentication and identity verification. PINs and passwords simply are not enough as mobile becomes the next target for hackers.
Enter biometrics.
Many believe the answer will be found in the marriage of biometrics and mobile devices. But which biometric modality should be used? Walter Hamilton, executive director at the International Biometrics & Identification Association, says there are several frontrunners.
Fingerprints have been a staple of biometrics from the beginning and though flashier modalities have surfaced, the fingerprint continues to hit above its weight class.
“Fingerprint, iris, and facial recognition are the ‘Big 3’, with fingerprint being the most common and popular modality,” says Hamilton. “They are quick, reliable, easy to use, highly accurate and are not adversely affected by environmental conditions.”

Giving mobile the finger

Most mobile devices already contain the audio and camera components required to authenticate voiceprint and facial recognition. Still many experts feel fingerprint is the best way tool for mobile security because it can offer an added level of verification and consent.
The challenge is that today few devices possess fingerprint scanner hardware.
“Durability against shock, vibration and impacts that may affect the sensor surface are serious concerns,” explains Hamilton. “Implementations need to be small because real estate and power consumption in the mobile platform are at a premium.”
Sebastien Taveau, chief technology officer with California-based fingerprint sensor manufacturer Validity, echoes this sentiment. “It must be small enough that it doesn’t take up too much space, doesn’t use too many processing cycles and doesn’t add friction to consumer interaction with the device.”
“Technology is like a diet,” says Taveau. “It is always easier to gain weight than drop it – the same holds true for technology, it’s hard to shrink it down to something that’s consumer-acceptable.”

AuthenTec: The Apple of the market’s eye

Prior to 2012, the market resembled something of a two horse race between the Melbourne, Fla.-based AuthenTec and San Francisco’s UPEK. The competition saw the market split between two solutions: AuthenTec’s area sensor and UPEK’s swipe sensor.
An area sensor is a silicon-based scanner that did not use optical characteristics; rather it required the use of a light source, which proved to be heavy on power consumption – a concern for mobile implementation. With this method, because the silicon is the sensor, a finger has to be physically applied to its surface to conduct the authentication.
Swipe sensors like that provided by UPEK use a silicon scanner shaped like a thin bar of sensor pixels. This method sees the user swipe their finger over the bar while the sensor takes successive images of the finger and reconstructs them using a complex algorithm.
This competition between UPEK and AuthenTec continued until 2010 when the companies merged under the AuthenTec name, bringing the two most viable fingerprint scanner solutions under one roof.
The merger and the subsequent ripples it sent changed the fingerprint sensor landscape and captured the attention of mobile device giant Samsung, followed shortly by Apple.
Apple bought AuthenTec in July of 2012, a move that at $356 million ranks it among the most expensive acquisitions Apple has made to date.
While Apple’s purchase of AuthenTec was certainly driven by the desire to possess the fingerprint scanner technology, insiders suggest it was just as much about keeping the technology out of Samsung’s hands.
Prohibiting Samsung from incorporating AuthenTec sensors in its devices was certainly a blow to mobile fingerprint implementation, but as one door closes another often opens.

A new market structure

With AuthenTec within Apple, the fingerprint scanner market has entered something of a Renaissance. Companies like Validity and Sweden-based Fingerprint Cards AB are gaining a foothold and are bringing with them new solutions.
“Following the acquisition, suddenly everyone wanted to move at the same time,” explains Taveau. It has allowed Validity to reach the rest of market, he explains, beginning with PCs and expanding to other consumer electronics.
Apple’s involvement not only created an opportunity for newcomers to grab market share, its high profile presence is also elevating consumer awareness of fingerprint technology.
“Apple’s acquisition of Authentec has certainly put focus on biometrics and opened up new opportunities in the biometric market,” says Alexander Blomquist, regional sales director with Fingerprint Cards AB.
- See more at: http://secureidnews.com/news-item/uproar-in-the-mobile-fingerprint-market/?sthash.OoRqDki9.mjjo#sthash.OoRqDki9.iePGOElg.dpuf

Saturday, July 6, 2013

Things CEOs Hate To Pay For and How They Can Help You Make Your Case for Security

http://www.securityweek.com/things-ceos-hate-pay-and-how-they-can-help-you-make-your-case-security

By Mark Hatton on July 02, 2013

When Making the Case for a Security Budget, Don’t Just Provide Numbers and Statistics...
As a CEO, I hate spending money on things that don’t help grow my business or improve the products and services we bring to market. While I know there are necessary evils in business that require funding, the thought of spending money on things that are only used in a worst-case scenario are not attractive options to me when it comes to the allocation of limited and important resources. Having spent the majority of my career in the cyber security business, I am well aware that many of my CEO brethren lump security spending into the same bucket as other less desirable expenditures and believe me, I get it.
When the case is being made for budget, my management team expects that I’m going to ask some tough questions. What is the payoff? Where does the risk exist? How likely are we to be affected? What is the potential impact to our business? These are questions that need to be answered. Bottom line, I’m looking for them to prove their case as to why the risk or reward to the business warrants the expenditure.
IT Security BudgetsExecutives make purchasing decisions everyday based upon need over want, because they recognize that the failure to do so puts the company in an unacceptable position of risk. We don’t like it, but we understand it.
Here are five other things that we hate spending money on but are willing to do so in order to protect the business. Looking at the rationale for spending money in these areas can help you make the case to your own executive team why cyber security needs to be a priority in your company.
1. Insurance – in business and in your personal life, insurance is a check nobody ever wants to write. But we understand that protecting our critical assets against a catastrophic event is a necessity. Failure do so would be putting the company at risk of serious harm or even “going under” from a single event.
2. Legal Services – while I personally love our attorneys, life would be much simpler without the legal wrangling over contracts, leases and other complicated legal documents. But to try to do it alone would be crazy. Being protected under the law is a must for corporations, both private and public, and it’s well worth the expenditure to have these experts on your team.
3. Compliance – government regulations and compliance initiatives have been on the rise in recent years and show no signs of slowing down. Failure to comply can lead to fines and penalties that could be devastating to large corporations and catastrophic for small to mid-size businesses. Ensuring compliance is a top concern of all management teams, no matter how costly.
4. Data Storage – billions are spent each and every year on data storage solutions and yet I seem to get an alert on a weekly basis telling me that my email is over the size limit. The reason we hate spending money in this area is because we know that a large percentage of what is being stored does not contain critical data tied to the success of the business. However, we can’t take the chance that important data is not accessible so we make the additional investment.
5. Disaster Recovery – again, worst-case scenario expenditure, but one that is absolutely necessary. With many businesses existing solely upon their information and intellectual property (IP), the the sudden catastrophic loss of its data center due to weather, or other form of disaster, could spell the end for many businesses. In today’s market full of information-based companies, the potential for systems and data to be unavailable is a non-starter.
Hopefully you noticed a common theme throughout these examples of things we don’t like to spend money on, but do anyway. In each case, the potential cost to the business of not making the investment far exceeds the actual spend. In other words, these are all critical services that are necessities and not choices. Cyber security is simialr and touches all of the examples above. Failure to protect your company’s critical data is not an option and can have wide-reaching implications beyond the walls of your own business. Depending upon the industry you are in, the compliance and legal issues that would result from a cyber-attack would put you at much more than further financial risk. A complete loss of data or IP could also put you quickly out of business.
When making the case for a security budget, this is the type of argument that will resonate with the CEO. Don’t throw numbers and statistics at them; lay out the business case and the importance cyber security plays in the protection of the brand. They probably still won’t like it, but they’ll be far more willing to buy into this rationale. For an executive not intimately involved with IT and security, it’s kind of like airbags in their car. They don’t want to ever think about them, but they’ll be glad they had them if they ever needed them.

Thursday, July 4, 2013

EU Parliament approves stricter penalties for cyber attacks

Botnet attacks will carry a five year jail term under the new rules, which EU member states are expected to adopt shortly




Cyber criminals could face tougher penalties across the European Union under new rules adopted by the European Parliament, which include the creation of a specific offence of using botnets.
The draft directive adopted by the parliament on Thursday defines specific criminal offences for cybercrime and sets specific sanctions for each. It also requires E.U. countries to assist fellow member states and respond to urgent requests for help within eight hours in the event of a cyber attack.
The text has already been informally agreed with member states, and that agreement is expected to be formalized shortly. The member states will the have two years to implement it in national law.
Under the draft law, using botnets to establishing remote control over a significant number of computers by infecting them with malicious software carries a penalty of at least three years' imprisonment.
Meanwhile criminals responsible for cyber attacks against "critical infrastructure", such as power plants, transport networks and government network would face at least five years in jail. The same would apply  if an attack is committed by a criminal organisation or if it causes serious damage.
"Attacks against information systems pose a growing challenge to businesses, governments and citizens alike. Such attacks can cause serious damage and undermine users' confidence in the safety and reliability of the Internet," said Home Affairs Commissioner, Cecilia Malmström, welcoming the news.
Companies or organizations would also be liable for offences committed for their benefit, for example hiring a hacker to get access to a competitor's database.
The directive, which updates rules that have been in place since 2005, also requires member states to allow judges the possibility to sentence criminals to two years in jail for the crimes of illegally accessing or interfering with information systems, illegally interfering with data, illegally intercepting communications or intentionally producing and selling tools used to commit these offences.
Minor cases are excluded, but it is up to each country to determine what constitutes a "minor" case.
However technology blogger Glynn Moody expressed concern about possible mission-creep. "I predict laws will be abused by E.U. governments to attack coders and geeks," he said on Twitter.
The directive will apply across all E.U. member states with the exception of Denmark, which decided to opt out.
Follow Jennifer on Twitter at @BrusselsGeek or email tips and comments to jennifer_baker@idg.com.

http://news.techworld.com/security/3456263/eu-parliament-approves-stricter-penalties-for-cyber-attacks/?olo=rss&utm_source=twitterfeed&utm_medium=twitter

Wednesday, July 3, 2013

Ignoring Compliance Is A Real Option

http://www.darkreading.com/compliance/ignoring-compliance-is-a-real-option/240157262?cid=nl_DR_weekly_2013-06-27_html&elq=6505e97b7c084990ab86405e605fa5e3
          
 
Life is full of choices. Lots of choices. We even have choices we don't recognize as available. Business is the same way. For instance, did you know that both compliance and security are optional for your business? They are choices. Every day your business makes choices about how much effort, if any, it will make toward meeting compliance requirements or securing its assets, for both the physical facilities and its information assets.                                                                           "But wait, Glenn! Compliance is REQUIRED of businesses in my industry." OK, but let's be honest and clear: Compliance to laws and regulation may be legally required, but that does not mean your organization and others in your industry have actually chosen to fully embrace every legal requirement.  I bet you could tell me right now three ways your organization falls short of compliance. And you can probably also tell me how others in your industry, working under the same compliance requirements, fall short in even more ways. If compliance were an actual requirement, like oxygen is to our bodies, then your organization would quickly fail or be closed for noncompliance. Compliance failure sometimes results in business failure, but more often businesses are noncompliant to some extent and continue to operate. They survive, perhaps even thrive, without meeting all legal requirements. The multitude of ambiguities in many laws and regulations only complicate the matter, and many companies consider themselves compliant only by embracing loose interpretations. Your organization is probably like most. Compliance as a whole is considered a requirement, but the details of compliance are broken down into many smaller elements that are considered optional. Your company's employees choose some areas to bring into strict compliance and others to skimp on. Most organizations want to follow the rules of law and regulations of their industries, and most make a reasonable effort to do so. While the letter of the law may be subject to interpretation, and penalties have different weights, most businesses generally make choices to keep them within at least the spirit of the rules. Unfortunately, too many businesses, however good their stated intentions, choose to treat compliance as a series of costly add-on projects, rather than the routine behaviors and processes that create true compliance. This misguided attitude often leads them to attempt to cut corners that are usually more costly in the long run, sometimes even costing them their businesses. The best companies are those that recognize the choices, evaluate them in advance, and then choose how to most efficiently incorporate actions into their processes that make them as compliant as possible. Glenn S. Phillips hopes you choose wisely. He is the president of Forte' Incorporated where he works with business leaders who want to leverage technology and understand the often hidden risks awaiting them. Glenn is the author of the book Nerd-to-English and you can find him on twitter at @NerdToEnglish.

Monday, July 1, 2013

Encryption has thwarted US government wiretaps for first time

            http://www.wired.co.uk/news/archive/2013-07/01/encryption-wiretaps?utm_medium=referral&utm_source=t.co

For the first time, encryption is thwarting US government surveillance efforts through court-approved wiretaps, US officials said on Friday 28 June.
The disclosure, buried in a report by the US agency that oversees federal courts, also showed that authorities armed with wiretap orders are encountering more encryption than before.
The revelation comes as encryption has come front and centre in the wake of the  NSA Spygate scandal, and as Americans consider looking for  effective ways to scramble their communications from the government's prying eyes.
According to today's  report from the US Administrative Office of the Courts:
Encryption was reported for 15 wiretaps in 2012 and for 7 wiretaps conducted during previous years. In four of these wiretaps, officials were unable to decipher the plain text of the messages. This is the first time that jurisdictions have reported that encryption prevented officials from obtaining the plain text of the communications since the AO began collecting encryption data in 2001.
Those figures are just a blip on the screen in the office's 2012 Wiretap Report, which said there were 3,395 authorised wiretaps from federal or state judges. (The figures, a significant increase  from 2011′s reported 2,732, do not account for those secretly authorised by the Foreign Intelligence Surveillance Court, which is at the centre of the  Spygage firestorm.)
To be sure, the encryption numbers begin to highlight the government's stated fear, and its propaganda railing against encryption -- which is a standard feature on today's Apple computers.
Consider that, when federal law enforcement officials were clamouring for legislation authorizing a backdoor into most all electronic communication methods during the President Bill Clinton administration, FBI Director Louis Freeh told Congress in 1997, "all of law enforcement is also in total agreement on one aspect of encryption. The widespread use of uncrackable encryption  will devastate our ability to fight crime and prevent terrorism."
Sixteen years later, and judging by the government's own accounting, we're not even close to Freeh's fears becoming reality, despite the government's continued  push for a backdoor into virtually everything.
The report, meanwhile, said that 97 percent of the wiretaps issued last year were for "portable devices" such as mobile phones and pagers. About 87 percent of the wiretaps were issued in drug-related cases, the report said. Other equipment tapped included computers, phone land lines, fax machines and, among other things, microphones.
This article first appeared on Wired.com

Friday, June 28, 2013

The Top Five IT Security Cyber Threats Are...

The Top Five IT Security Cyber Threats Are...


26 June 2013

As cybercrime expands and evolves, a new study categorizes and describes the top five threats: data breaches, malware, DDoS, mobile threats and the industrialization of fraud – and they're all interrelated.


  1. Data Breach
  2. Malware
  3. DDoS
  4. Mobile Threats
  5. Industrialisation of Fraud 
Security firm 41st Parameter describes each threat in turn. The data breach threat is illustrated by the LivingSocial breach earlier this year. 50 million records were compromised in April. Although no financial records were stolen, they probably weren’t the direct target: “consumers don’t realize that the real concern behind the theft of personal data (such as email addresses, birthdates and encrypted passwords) is potential exposure to various forms of identity theft.”
The real problem with large data heists comes in the following months when the attackers use the data they have stolen to engineer compelling phishing attacks “to dupe unsuspecting victims into revealing sensitive data that can be used to open new accounts or take over existing ones.” In this instance there were two difficulties – firstly consumers still tend to reuse passwords over multiple accounts, and secondly LivingSocial’s business model sends out ‘daily deals’ emails to its subscribers. A forged email could look like a genuine LivingSocial mail but actually contain a disguised link to a malicious site.
That malicious site would contain the second of the major threats: malware. Malware delivery from a malicious URL, otherwise known as drive-by downloading, is one of the three top delivery mechanisms of 2012. The others are app repackaging for mobile devices, and smishing. The first takes a genuine app, alters it for bad intent, and then redistributes it via a different channel. Smishing is the use of “unsolicited text messages that prompt users to provide credentials.”
There is no single solution to malware, but the threat can be mitigated by the use of up-to-date anti-malware software, and improved visibility into the devices – especially mobile devices – that connect to the corporate network.
The third threat is DDoS. DDoS attacks are disruptive, driving costs up and reputations down; and there are more than 7000 DDoS attacks every day. But there is a growing issue “more prevalent now than it’s ever been,” when the target site is a bank. Possibly using account credentials stolen by the malware distributed after a data breach, it’s now “common for fraudsters to access a group of accounts, perform reconnaissance and money movement activities and then immediately launch a DDoS attack in order to create a diversion.”
The fourth threat is that posed by and to the mobile market – 700 million smartphones were sold in 2012 alone. “Since fraudsters typically attack the weakest point of ingress,” warns 41st Parameter, “and without the proper device recognition and detection systems in place, the mobile channel may soon emerge as their channel of choice.” Overall, 2012 saw a 163% increase in mobile threats, with 95% of mobile threats attacking the Android platform. In all, 32.8 million mobile devices were infected with malware.
Finally, the report discusses the industrialization of fraud. Since online transactions are by their nature ‘machine-to-machine’ they lend themselves to automation. But just as the banks automate their own processes, so too are criminals automating fraud. “Recently, 41st Parameter has seen the standardization of fraud software building blocks and data formats, which make it easier to collaborate and exchange information between fraud rings.” And there are more than 10,000 of these fraud rings in the US alone.
One of the problems that comes from this automation is that criminals can just as easily perpetrate hundreds or thousands of small frauds to gain the same financial return as a few large ones – but staying small they are more likely to slip under the banks’ fraud detection systems.
All of these threats could stem from that initial data breach: stolen personal data leading to phishing and the installation of malware that steals account data (although the mobile arena is increasingly used to do the same), in turn leading to financial fraud which is increasingly industrialized and disguised by DDoS attacks. In fact, “The increase in large-scale data breaches and high-volume, coordinated fraud attacks are byproducts of the industrialization of fraud driven by the movement of services online,” says Eli Katz, vice president of financial industry solutions at 41st Parameter. “Financial institutions and consumers must each take steps to adjust to this evolving threat landscape.”