As far as the criminal mind goes this level of information is yet another commodity to be traded within the criminal marketplace. After my last post detailing which criminal classes are concerned with which privacy bits people often post on Facebook, I believe that there are so many things wrong with this scenario as far as privacy is concerned, it should be simply assigned the title of Soup Sandwich.

The new service, called Places, allows Facebook users to tap the location-sensing capabilities of their mobile phones to "check in" to a business or address and then instantly share it with their Facebook connections. The optional service will also allow users to find other people who have also recently logged their presence physically nearby.

In this case it may interest domestic criminals rather than offshore cybercriminals, truly crossing from the cyber threat to the physical threat. As former US Attorney Karen Hewitt is quoted – “Everyone on the Internet may not be a bad guy, but all bad guys are on the Internet.”

As far as the Soup Sandwich metaphor:

The term expresses a state of extreme uselessness, which can be understood by considering the functionality and worth of soup between two slices of bread.

My assessment is that this is going to begin to bring violence aspects to a whole new level. Globally. The traditional black market for business account access will probably lead to cybercriminals being ripped off by window shopping gang bangers who simply use the who/what account data to plan their home invasions.

Five Steps to Home Invasion

[click to continue…]

{ 0 comments }

With a grand total of 900 million records lost over the past six years, there is plenty of reason to be concerned about personal and financial information. But where does this concern fit in regards to other everyday issues? And what can public private partnerships really do about it?

Objective: Clarity

Securing Our eCity has been working closely with APWG and NCSA throughout 2009 and 2010 as part of the Messaging Convention to create the Advanced Strategy Online (ASO).

After two collaborative ASO meetings held this May in San Diego and this June in New York City the recommendations are now being compared with the poll data gathered from the APWG / NCSA sponsored poll.

The Messaging Convention driven by NCSA and APWG includes:

…ADP; AVG; Costco; ESET; Facebook; Google; Intel; Intuit; McAfee; Microsoft; PayPal; RSA, The Security Division of EMC; Science Applications International Corporation (SAIC); Symantec; Trend Micro; Verizon Communications; VeriSign; Visa; Walmart; Yahoo!; the U.S. Department of Commerce; the U.S. Department of Homeland Security (DHS); Office of Justice Programs, U.S. Department of Justice; the U.S. Federal Bureau of Investigation (FBI); the U.S. Federal Trade Commission (FTC); and the U.S. Internal Revenue Service (IRS).

Michael Kaiser of the National Cyber Security Alliance provides further details:

[click to continue…]

{ 0 comments }

Until mid-July, malware attacks on SCADA control systems such as power grids use was considered one of many HILFs. Not anymore. Now it’s better to have a plan and as the Boy Scout motto says, “Be Prepared” in a defense in depth stance.

For CIOs this couldn’t come at a worse time – unstable economic situations  for business combined and the Stuxnet worm has erupted into a proof of concept nightmare of what malware can do to the power grid – and worse, what grid failure can do to an unprepared business.

HILF – is the catchy new term for a show-stopping event and no, it doesn’t start with an “M”. HILF stands for High Impact Low Frequency. These types of events include malware targeting SCADA controls as well as “Acts of God” and even EMP – electromagnetic pulses – which result from solar flares or nuclear detonation.

Businesses take note: the NERC strategy suggests that businesses plan for HILFs such as EMP or malware such as Stuxnet. Particularly it stresses to plan for effects in which one emergency may bleed over into another.

The report examines three high-impact, low-frequency risks in detail: coordinated cyber, physical, or blended attacks; pandemic illness; and Geomagnetic Disturbances (GMD) and Electromagnetic Pulse (EMP) events. These risks are rare, and in some cases have never occurred.

Article: Learn Seven Ways To Keep HILFS From Crashing Your Party

Stuxnet’s Sophisticated Attack

Stuxnet has been evaluated as a weaponized exploit packaged neatly into a sophisticated social engineering nightmare. Why is this little critter causing so much discussion?

  1. Stuxnet has automated espionage against a critical infrastructure component. What used to take Cold War spies years to penetrate and diagram was automated within seconds. It was designed to gain access to the visual information part of the control system – the user interface or human machine interface (HMI).
  2. This blended threat masks whodunit. The true intent behind Stuxnet may never be known and theoretically, the rootkit nature of this malware could have allowed future attacks to propogate, endangering the entire control system. All of this could occur on a global scale not unlike a scenario out of Richard Clarke’s Cyberwar book.
  3. Blended Threat = there were boots on the ground and a well organized global effort. The organization who created Stuxnet also made a masterful social engineering move by heisting the VeriSign digital certificates from software firms JMicron and Realtek:

VeriSign JMicron Technology Certificate used to sign device drivers

Here’s where criminology comes in – Randy Abrams points out that JMicron and Realtek have offices in the same Taiwanese industrial park. These two companies had their digital signatures stolen, that these signatures may have been stolen. I think that both companies could have been criminally penetrated either through physical means or through the compromise of their shared telco / fiber connection.

Right now there are two schools of thought: one is that industrial control system attacks/hacks are nothing new and may not result in the end of the world. The other line of thinking is that this is an evolution of a threat which, by becoming automated in nature, should be treated with the same respect as a power plant gate guard seeing a gentleman armed with a 12 gauge shotgun approaching his guard booth: the gentleman may be hunting quail, or the gentleman may have ill intent. Either way, it’s up to security to assess the threat potential.

{ 1 comment }

Credit Card Fraud: Even New Cards are at Risk

August 3, 2010

Today I became involved in a conversation between my dad and his coworker. When it reached the topic of cyber-crime, i started listening in. His wife had used a card on a fake website and it was stolen. A story we’ve all heard many times.
However, my dad brought up his own personal account that was [...]

Read the full article →

One Billion Blocked – Malware and IE 8

August 3, 2010

Every layer of protection you add will harden the target against cybercrime. By way of Terry Zink’s blog comes this data about the SmartScreen technology found in Internet Explorer 8:
1 billion malware blocks is an amazing milestone and an example of two things. First socially engineered attacks like malware continue to be a [...]

Read the full article →

Perfect Citizen Walks a Fine Line

July 28, 2010

Perfect Citizen is an NSA program to monitor the cyber-security of all critical infrastructures. Raytheon is believed to have been contracted to create the hardware and software which will be installed in key networks across the nation. Perfect Citizen will gather data about those networks to detect their weaknesses and identify attacks against them. Referred to as Big Brother by its opponents, Perfect Citizen may constitute an invasion of privacy by gathering too much information, but it is at greater risk of gathering too little.

Read the full article →

San Diego Chamber Advocates for Cybersecurity in Washington, D.C.

July 27, 2010

By guest blogger – Ruben Barrales, President and CEO, San Diego Regional Chamber of Commerce
At the San Diego Regional Chamber of Commerce, we advocate on behalf of San Diego businesses on a local, regional, state, national or international level to help make San Diego a better place to do business. As San Diego [...]

Read the full article →

Comic-Con and SOeC: Grassroots to Mainstream in San Diego

July 21, 2010

It occurred to me that the scope of SOeC now resembled the origins of the now world famous Comic-Con forty years ago.
SOeC and Comic-Con: From Grassroots to Mainstream
This week San Diego is inundated with the cultural phenomenon which is Comic-Con. In a similar grassroots fashion to Securing Our eCity (SOeC), Comic-Con started nearly forty [...]

Read the full article →

SOeC goes to the White House!

July 14, 2010

Today was a monumental day in the history of Cybersecurity – Last year President Obama brought cybersecurity to the forefront of national security issues.
In March of this year, Secretary Napolitano laid out a challenge for individuals, business and organizations to pick up and share ideas on how we can work together to raise awareness [...]

Read the full article →

Psyb0t: The Botnet Attacking and Owning Internet Routers

July 6, 2010

 This article details why I recently bought my parents a newer model non-Linksys router.
The first known botnet worm to target routers and DSL modems is circulating in the wild, according to research revealed this week.
Unlike your home computer it’s easy to remedy any lost router password.
If you lose the password for your home router you [...]

Read the full article →