Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, December 30, 2016

The Coming Cyber War #23

Cyber Warfare:

A US Air Force EC-130H has been attacking the Islamic State in Syria.

The USMC is looking for hackers, or as it has been put, "a few good nerds" for its cyber warfare section.

The US government is sorting out who is in charge of the cyber domain.

Mirai bot nets are now using TOR to hide its control network.

North Korea has denied launching a cyber attack on South Korea.

 OSCE, the group observing the 'cease fire' (or lack thereof) in Eastern Ukraine has been hit with a major cyber attack.

Russian hackers tracked Ukrainian artillery units through android malware.

Was the Russian hacking of the election system the first 'Russo-American cyberwar?'

How to deter Russian (and others) from attempting the cyber attack again.

A Turkish hacker is giving out prizes for conducting DDoS attacks.

Ukraine had another cyber attack on its power grid.

Ukraine has been hit by 3,500 cyber attacks and considers itself in a cyber war with Russia.

Cyber Security:

Airline entertainment system hacks are back.

This is how cellebrite works.

DARPA has given Raytheon a contract to find ways to protect the power infrastructure.

The US FDIC has released guidelines for medical software and hardware cyber security.

Google has released a tool to look for cyrpto bugs that can be exploited.

KillDisk malware has become ransomware.

McAffee has a security bug that has been unaddressed for months.

Netgear Wifi routers are VERY insecure: stop using!  Netgear has a beta patch.

Nevada accidentally revealed the personal details of all those applying for medical cannabis dispensary licenses.

PwC is threatening to sue security researchers.

North Korea's version of Android takes a screen shot every time an app is opened.

Numerous twitter accounts have been hacked by OurMine, a white hat hacker group.

Ubuntu has found customers are terrible at updating their IoT devices.

The UN has warned the threat of cyber attacks on nuclear power plants is rising.

A US think tank wants security built into all IoT devices, but how may be ... problematic.

The US DOT wants to mandate vehicle to vehicle communication: this is a bad idea, IMO.

Zero Day exploits for two diffferent linux distros' desktops have appeared.

Cyber Espionage:

ADUPS Malware infects new Barnes & Noble tablets, reporting data back to Shanghai.

The NSA's best are supposedly leaving in droves due to Trump's election.

Is the NSA pushing to redefine the interpretation of the 4th amendment?

The British 'Snooper's Charter' may give the government permission to lie in court.

The British Snooper's Charter took a blow in the EU court system, but will it matter with Brexit?

The Chinese have reaffirmed their commitment to cyber surveillance.

The EFF is monitoring the surveillance tech being used at the standing rock protest.

The FBI is probing a hack of the FDIC by the Chinese military.

There is a new search engine just for checking if news is fake.

The Russians made attempts to influence the US Presidential election. Trump denies this. Trump even took swipes at the intel agencies.  The intel agencies are feuding with the Republicans over the hacks. McCain states the facts are there. Obama has ordered a review to be done before he leaves office and is VERY sure Russia is behind the attacks while stating Trump won legitimately.. The review will go beyond the election.  Republicans in Congress disagree with Trump and want a probe. The top management of the intel agencies have not endorsed the report.  The FBI does now agree about the Russians.  Some are saying Putin is trying to 'hack' the confidence in the US system. The Germans are stated the Russians are just getting started. Russia says the claims it attempted to influence the election are just infighting between the two sides in US politics. A piece of legislation moving through congress is going to mandate countermeasures. A report claims Putin personally directed the attacks.

More information on the attack by the Russians on the US Presidential election  The election agency was hacked. Why there is a debate about the hack in the US at all?  The Russians are stating to prove they did the hack or shut up.  Obama is threatening to counterattack Russia.  The CIA head is advising against retaliation.  The Russian fake news bots are the same stuff done in Ukraine, but amped up for the globe.

The American retaliation is to ban several russians from the US, release info on Russian cyber activities and more.  Russia has vowed to attack in return.

A report released by Congress claims Snowden was in contact with Russian intelligence in 2013.

The Russians are trying to unlock the Iphone of the assassin of the Russian ambassador in Turkey.

Twitter is blocking intel agencies' access to its data.

The US Congress has concluded encryption backdoors won't work.

A US Court is demanding information on the collaboration between ATT and the police to spy.

The US House is urging the passage of a bill restricting and regulating the use of Stingray and other cell phone interception devices by the police.

What the US intelligence agencies think of Trump.

The US NIST is seeking help to protect computers from hacking by the up and coming quantum computers.

Did a typo lead to the Podesta email hack?

Cyber Crime:

In a bizarre twist on cyber "crime," Arkansas police are seeking the data from an Amazon Echo to help solve a murder.

Chinese stock traders have been arrested on suspicion of profiting based on hacked insider information.

The FBI has started arresting users of DDoS bot networks.

Here's a guide to hacks in 2016.

Hackers defaced Thai websites over restrictive internet laws.

IBM found most businesses pay when hit by ransomware.

The Leet botnet is bigger than Mirai.

New malicious advertising (malware hiding as advertising) is infecting users' routers rather than their desktop or tablets.

Malware has been found in 26 low cost android devices; resellers are suspected to be adding it.

A Nigerian man has been arrested and charged with hacking the Los Angeles County email system.

A new website found has all the NSA exploits for sale.

The Popcorn Time malware will give you the keys to get rid of it IF you spread it to your friends.  

Quest Diagnostics was hacked and 34,000 customers' data was exposed.

Ransomware infected an LG smart tv.

A Russian cybergang may have scammed millions through the use of fake websites and clicks.

A Swedish hacker posted the specs for a device to hack Mac passwords.

SWIFT was hacked again.

Twitter is cooperating with a journalist who is hunting for someone who sent him a video that induced a seizure.  

Uber is being sued by a former officer in the company allegedly stating employees stalked ex gf/bfs, celebrities and politicians using the data from the app.  Uber claims it has safeguards against that.

Occupied Ukraine has become a hot spot for cybercriminals.

A US citizen surrendered to face charges for a cyber attack.

The US Government is targeting the torrent sites like Pirate's Bay.

Yahoo has reported 1 billion of its accounts have been compromised.  Verizon is considering killing its acquisition of Yahoo.  The database of user information may have sold for as little as $300k.

 META:

The US attempted to and failed to get a change in a treaty to allow for cyber weapons export in a treaty.

Friday, November 18, 2016

Coming Cyber War #21

Cyber Warfare:

The US was mulling a response to any cyber attacks on election day.

The best strategy for the US may not to have a cyber strategy?

US Army wargames have refined the use of cyber warfare teams.

The US Army is rushing to build up its cyber warfare corps.

The US Navy has outlined its cyber defense plans for its warships.  Amongst those plans are the last resort of unplugging the warship from the network in case of compromise.

The US military is looking to tap into its social media forces. 

The US military's attempts to recruit hackers were harmed in a significant way by Snowden.

Massive DDOS attacks are on the rise (*cough*IOT*Cough*)

Russians are accused of conducting massive post election hacks on US based think tanks, NGOs and even some parts of the US government. 

In turn massive DDOS attacks were launched on the top 5 Russian banks on November 10th through 12th.  It seems to be the Mirai software again.

Smaller nations will start employing cyber weapons.

 A DDOS attack took out the heating in two buildings in Lappeenranta, Finland.

Cyber Security:

Adult Friends Finder's websites have been cracked and expose 400 odd million user accounts.

A chess champion reached out to Microsoft to protect him from Russian hackers.

Columbia University has come up with new software to help foil cyber attacks.

China's new tough cyber security law has come into effect.

The cryptsetup bug allows for remote root shell access on linux systems.

The DIRTY COW exploit is still not patched in Android. 

A Google engineer has stated anti virus software is a waste of time and worse than useless.

 Malware detecting CPUs are being developed.

The OATH2.0 bug has left 1 billion mobile apps exposed.

PoisonTap is a new hacking device that can crack a machine in under a minute.

 Researchers successfully hacked a Phillips Smart bulb via a drone.

A security company showed how to hack a US voting machine.

A security company also showed how to create an untraceable rootkit for industrial equipment.

Trump's election to the US Presidency is adding fuel to the fire in the encryption debate.

 US lawmakers are considering a new agency for IoT security.

What would you give up for cyber security?  Apparently, a lot.  

Yahoo is revealing more details of its massive hack.  Some within Yahoo knew of the breach in 2014!

Z-Wave, an IoT device maker, is announcing new security standards for their devices.

Cyber Espionage:

A new, powerful Android malware is targeting executives at companies.

Assange claims Wikileaks never intended to influence the US Election (ha!).

The British have passed a law stating all data, including browsing histories and domains visited, must be kept for up to one year.

China is collecting information off of smart phones in the US.

The FBI has hired a firm with a real time scan & feed from twitter.

linkedin is now blocked in Russia because linkedin refused to house the data for Russian citizens in Russia physically.

The NSA stated a nation-state (see below) attempted to influence the election.

How Russia attempted to influence the US election.

Will Trump's win of the US Presidency greatly increase surveillance?

Cyber Crime:

10% of cloud based repositories have been compromised by malware.

The Chinese passed a very controversial cyber security law.

The FBI seized 23 child porn sites on torrent and then deployed malware from them.

Tesco Bank stopped online transactions after a massive wave of theft.

University of Calgary banned bittorrents and saw a massive drop in the complaints about online IP theft.

Friday, November 04, 2016

The Coming Cyber War #20

Cyber Warfare:

The next American President is predicted to face a cyber crisis within 100 days of taking office.

An American vigilante hacker defaced the Russian Ministry of Foreign Affairs' website and issued a warning if there is further cyber attacks on the US. 

The cyber attack against the DNS company Dyn that took down the internet in the US gets profiled.  A little more info here.

Dyn responded to the attack with a press release.


The attack was supposedly done by 'script kiddies.'

Mirai and Bashlight were the software bots used against the DNS company Dyn.

The Mirai software makes the DDOS attacks much easier. 

What were the lessons learned from the DDOS attack? 

Is there anything that can be done about the DDOS attacks?

How vigilante hackers could stop IoT botnets like the ones in the attack on Dyn.

The Mirai bot attackers are now trying to take down Liberia.

A new more powerful botnet infected 3,500 IoT devices in 7 days.

The British are investing over $2 billion in cyber defense.

Two British hospitals were taken out by a virus.

Here's a look at Russia's attack on the American election system.

Putin has stated cyber attacks are unacceptable and called the interference in the election system by Russia nothing more than hysteria.

The Rocky Mountain Cyberspace Symposium was held.

The Shadow Brokers, those hackers who attacked the NSA and tried (but failed) to sell those secrets, revealed more info.

US military cyber attack teams have reached initial operating capability.

Cyber Security:

The US is said to be boosting cyber defenses for the election.

Drones are now hackable.

Google revealed a Windows security flaw just 10 days after notifying Microsoft.  Hackers have pounced on the reported flaw.  Microsoft has stated Russians have especially.

Yet Google hid a security flaw in Apple's IOS.

A google security engineer claims Android is now as secure as IOS.

A controversial Chinese cyber security law is closer to passing.

Chinese firm Hangzhou Xiongmai Technology had several of its products sold in the US hacked and is recalling them.

How hackable are your IoT devices? 

The Israeli company noted for being able to hack phone has had its firmware leaked online.

All LTE cell phone calls and messages can be intercepted and blocked.

The Rowhammer attack can now root Android devices. 

It might be possible to hack machines via ultrasound.

VeraCrypt has been found to be very flawed.

Cyber Espionage:

Apple has been sharing data with governments.

One of Putin's aides had his email account hacked by a supposed Ukrainian hacker.  It showed just how tight the relationship is between the supposed rebels in eastern Ukraine and Moscow.

The scan order for Yahoo's email is likely to never see the light of day.

Cyber Crime:

A member of Anonymous has been indicted for hacking Boston's Children Hospital.

An American bank regulator was 'hacked' by a former employee.

The Dark Web may not be as dark or as illegal as we think.

The Red Cross was hacked.

The Russian accused of hacking linkedin has been indicted.

A teenager supposedly launched an DDOS attack by accident?!

Weebly has been hacked and 43 million credentials stolen.

Friday, October 21, 2016

The Coming Cyber War #19

Cyber Warfare:

The United States had a cyber attack today with a massive DDOS attack on a key company on the internet causing outages mainly on the East Coast.

Is cyber defense the great space race of our generation?

Destructive cyber attacks are coming.

The IoT Botnet Mirai's software has been released to the public.  DHS is warning about this malware specifically.

Hackers are attacking the US voting systems.

NATO states cyberattacks complicate defense.

Nyotron is bringing a cloud based cyber defense to militaries. 

The US has officially stated Russia is responsible for the hacks on the election system Stateside.  The Russians have responded that's part of the 'anti-Russian hysteria.' sweeping the US.  The hacks, some think, are meant to shake trust in American democracy.  The rhetoric against Russia has been stepped up.  The US government has stated it will doing a proportionate response against Russia.  But how?  Supposedly the CIA (really?  CIA?) is preparing to conduct a cyber attack against Russia.

A warning has been sent out Russian hackers might be attempting to attack the US Presidential election.

The US military needs to get cool to attract cyber experts?  Use a cyber ROTC?  Perhaps.  Or perhaps it needs to pay industry rates...

The British have stated they are actively conducting cyberwarfare operations against Daesh.

Russia, cyber coercion and the classic whodunit.

Cyber Security:

3d printing systems have cyber security issues.

Buzzfeed hacked and had false stories released.

Is cyber security best incentivized by a carrot or a stick?

One election system vendor uses developers in Serbia. 

IAEA has stated at least one nuclear power plant was successfully hacked and had its operations disrupted.

IoT might be really, really bad for the internet.

Johnson & Johnson's insulin pumps are hackable.

MITRE is offering a bounty on rogue IOT devices.

Most businesses do not inspect their cloud services for malware.  And the clouds have lots of it.

Sixgill is moving from defense to detection in software.

Spotify users were hacked through malware carrying ads.

Cyber Espionage: 

Apple watches have been banned from British Cabinet meetings due to hacking fears.

Assange promises more secrets to be revealed about Clinton and Google.  Some more were revealed for the Clinton campaign.  Supposedly, a nation state cut off Assange's internet access.  That nation?  Ecuador!  The host embassy he has asylum with.  Ecuador has stated they did so because Assange was interfering with the US election and not because they were being pressured. 

Gufficer dumped Clinton Foundation data again.

An NSA officer was caught stealing secrets.  He stole apparently tens of terabytes of data.

Trump's email servers are hopelessly hackable.

Yahoo had a regular program of scans of user emails for the NSA and denied it.  (Apple, Google, and Microsoft denied they have a similar programs.)  Yahoo's scans were under a surveillance law that is expiring.  Calls are being made to declassify the program the Yahoo email scans were being done under.  The tool being used apparently was a hacking tool, rather than an email filter.  Verizon wants a $1 billion reduction in the price for purchasing Yahoo due to the lack of disclosure on the email scans.  In fact, Verizon is now saying this is a material breach.  In an odd twist, Yahoo is demanding to know who in the government ordered the monitoring.

A Russian spy ship might have tapped internet cables coming out of Syria.

Cyber Crime:

4Chan hackers are claiming to have wiped a Clinton aide's phone remotely.

A new android malware tries to trick users into taking a picture of themselves holding an ID card.

The Clinton Foundation is warning their donors against phishing.

Apparently, darknet users are strongly against animal trafficking.  

DDOS attacks actually have a changing effect.

Hackers who attacked French TV have still not been found.

Hackers have also hit 6,000 online stores looking for credit card #s over an 18 month period.

Another group of hackers is attacking the SWIFT network.

A huge debit car system breach has affected millions in India and over ten banks.

How hackers got into Podesta and Powell's email accounts.

Malware is not a problem on the Wikileaks site according to Julian Assange.

A Republican Senate Committee website has been hacked.

A Russian hacker has been detained in the Czech Republic for possible extradition to the US.  Russia has strongly criticized the US over the arrest and has named the individual.

The StrongPity malware is infecting users via legitimate software installers.

Friday, September 30, 2016

The Coming Cyberwar #18

Cyber Warfare:

This is the 21st century info warfare and where the 3rd offset strategy intersects with it.

The US Army is getting in on the hacking domain.

The NSA cyber weapons were compromised by the Russians through an operator error.

An hacker who was working for ISIS has been sentenced to 20 years in prison.

After the hacks by the Russians, the US must decide how to react.


Cyber Security:

Cisco is scrambling to patch another vulnerability in its firewalls.

Chinese researchers found a security problem in Tesla S, but Tesla patched it already.

Malware has starting checking to see if it is in a virtual machine.

Another malware masquerades as Street Fighter V updates.

Yahoo was hacked and 500 million users data has been exposed.  Phone companies whose users used Yahoo ought to be concerned.  That Yahoo waited two years to report the attack is being called unacceptable.  The party who hacked Yahoo is in dispute.

Cyber Espionage:

An autistic Briton who hacked the Pentagon and whatnot looking for proof of UFOs has been given clearance, finally, to be extradited to the US for prosecution.

How DID the FBI crack the San Bernardino terrorist's phone?  Some news organizations are suing to find out how.

The FBI is investigating another hack of the DNC.

Putin claims the hacks of the antidoping agency prove the ban of Russian athletes was unwarranted.

Russian hackers have been linked to attacks on German political parties and governments.

Russian hackers are being accused of attempting to disrupt the US elections.

The US is pretty sure Russia is shielding hackers who attacked the US.

Cyber Crime:

A college hacker compromised United Airlines.

An FBI agent busted folks using the Dark Web.

Hackers are spreading malware over the torrents.

A journalist was attacked by a massive DDOS attack and was kicked off the server farm where he was hosted.  Google rehosted the site.  The DDOS attack reached 1 TB per second and had over 150k hosts participating.

Michelle Obama's passport has been leaked online.

Friday, September 16, 2016

The Coming Cyber War #17

Cyber Warfare:

For the last year, someone has been probing the critical infrastructure of the internet.

Obama wishes to avoid a cyber warfare arms race.

What is the US Navy's version of information warfare? 

Should the NSA and US military's cyber command be split?  Senator McCain strongly opposes.

The Pentagon is continuing to reach out to Silicon Valley.

Cyber Security:

Google is offering $200k to hack its Nexus Android phones.

Singapore is pulling its public servants off the net for security reasons. 

A former USAF general has been named the US cyber security chief. 

The US 911 emergency system can be crippled by a mobile bot net.

Cyber Espionage:


The US intelligence agencies are concerned about the threat of Russia throwing doubt on the US election via hackers.

British firms are selling software allowing for anyone to see what's on a smart phone.

GovRAT malware is designed to target US government officials.

Guccifer 2.0, the suspected Russian hacking team, has released more DNC documents.

Watch a leaked video demonstrating how an Italian company's spyware infects computers.

Smartphones can steal 3d printing designs by listening to the printer in action.

New leaked Snowden files show what the NSA could do for satellite eavesdropping.  

Cyber Crime:

18 to 24 year olds are the most likely to use the DARKNET.

Britain is supposedly edging closer to having 10 year prison terms for online pirating.

An FBI agent posed as a journalist to deliver malware to a suspect.

Hackers that broke into the CIA Director's personal email account have been arrested.

An Israeli group,vDOS, claimed to have made $600k doing mercenary DDoS attacks.  The supposed coowners have been since arrested.

PhotoMiner, a cryptocurrency mining malware, has infected Seagate NAS boxes.

Russian hackers are targeting the anti doping agency with hopes of getting US athletes' data.

A teenager figured out how to get free data on his phone.

Friday, September 02, 2016

The Coming Cyber War #16

Cyber Warfare: 

French submarine builder DCNS has been hacked and the plans and capabilities of the new diesel submarines for India have been released. Australia has become very worried about their award to DCNS for their own subs.  The French are calling the attack 'economic warfare.'  Or not.

Japan is setting up a cyber warfare institute.

The leaked NSA cyber weapons' code is mocked for its bugs, problems and bad coding.

The NSA is still sorting out the hacking.

A Polish think tank wants a cyber stance for NATO.

Somalia is a digital battle ground.
Cyber Security:

Cars connected to smart phones are vulnerable.

Cloud based virtual machines can be taken over very easily.

Democrats want an FBI probe of the supposed Russian hacks.  Assange claims more Hillary data is to come.

The Democratic National Committee created a cyber security panel...without any experts on the matter involved.

The FBI has indicated there have been two breaches of voter systems in the US detected.

Guccifer, the 44 yo Romanian who hacked Hillary, has been convicted.

Putin claims to not know who hacked the Democratic Party.

Researchers have developed a chip to look for hardware trojans within other chips.

The Russians are suspected for hacking attempts on the NY Times.  The FBI is investigating.

Wikileaks has become a hub for malware.

The relationship between Wikileaks and Russia is becoming...unsettling.

Cyber Crime:

British companies are selling spyware to authoritarian regimes.

Dropbox's hack was pretty profound.

Insiders seem to be the key for cyber criminals to attack telecoms and others.

The Kimpton hotels have been hacked.

There is malware in the Middle East that can hack any iPhone.

Another malware is infecting Macs via bittorrent.

There is a new ransomware that pretends to be a Windows update.

The Rex Linux Trojan is malware that is a bitcoin miner, DDoS client and ransomware all rolled into one.

The Russian son of a Duma member has been convicted.

SWIFT has disclosed more cyber thefts.

Friday, August 05, 2016

The Coming Cyber War #14

Cyber War:

Five cyber security questions for the US presidential candidates. 

Russia has announced it found malware on computers of at least 20 different agencies.  Word is the NSA is retaliating for Russian hacking of the DNC, Clinton campaign and others..  Not sure how true it is. 

Is Russia a cyber superpower?

The US Navy is using its nuclear submarines are cyber weapon platforms and hacking other nations via those boats.

A DIA cyber officer profiles the global cyber combatants.

Cyber Security:

Wikileaks released an uncurated dump of the DNC information.  Included are audio files.   Even Snowden is questioning wth Wikileaks is doing.

The DNC hack has a lot of misinformation embedded in the real information. 

The FBI is looking into the DNC hack and the White House has stated partisanship has no place in cyber crime investigations. 

The Clinton Campaign was also hacked.  Clinton has stated it was Russia who was responsible.

 Trump called for Russia to hack the US to find Clinton's missing emails.  Then said he was being sarcastic.

Russia says the US is demonizing it because of election scandals, not because it is hacking.

However, Russia has the capability and motive for doing the deed. Cyber Security experts see merit in the idea Russia did the deed.

Microsoft has drafted a rewrite to the Wassenaar Agreement to try to save the cyber security trade.

Someone hacked two screens at a Vietnamese airport to display political messages.

Obama rolled out a color coded cyber threat warning system.

The auto industry also rolled out a cyber security best practices guide.

Cyber Crime:

A cyber security company has admitted in court to hacking its rival.  

A Malvertising campaign ran for an extended period.

Ransomware is now a $34 million per year industry.

The top Nigerian scammer has been reportedly arrested.

Friday, April 29, 2016

Coming Cyberwar #9

Cyberwarfare:

The US military has been conducting cyber attacks on ISIS/Daesh. We reported the attacks earlier, but others are now catching up.

DARPA wants new ways to attribute cyber attacks.

Northrop is looking to develop AI for cyber defense.

Can the US & China back away from their cyber conflict?

Germany just stood up its own cyberwarriors.

Thinking 'slow' on cyber warfare.

Cybercrime:

Some are threatening to DDOS sites and demanding a ransom or else...even when they have never conducted a DDOS. And the businesses pay up!

Toy Maker Maitso's website had ransomware being served to customers.

Cisco has found backdoors installed on 12 million PCs.

Cyber Security:

There is a critical hole in our cell phone networks.

Critical infrastructure is vulnerable to cyberattack.

A nuclear power plant in Germany was found to be infected by computer viruses.

Friday, October 23, 2015

FSB Linked Kaspersky Lab Researcher States Harrassed, Targeted by Malware From Spy Agencies

Researchers tasked with revealing attacks by intelligence agencies are being harassed, locked out of tenders, and in some cases deported, Kaspersky researcher Juan Andrés Guerrero-Saade says.

Retaliation by the unnamed agencies is in direct response to news of prominent advanced-persistent threat campaigns that have coloured information security reporting over recent years.

Those reports are forcing researchers to reveal malware attacks by government spy agencies.

Thursday, October 15, 2015

Program Anomaly Detection Approach Detectiion Software Prototype Developed at Virginia Tech

Imagine millions of lines of instructions. Then try and picture how one extremely tiny anomaly could be found in almost real-time and prevent a cyber security attack.

Called a "program anomaly detection approach," a trio of Virginia Tech computer scientists has tested their innovation against many real-world attacks.

One type of attack is when an adversary is able to remotely access a computer, bypassing authentication such as a login screen. A second example of attack is called heap feng shui where attackers hijack the control of a browser by manipulating its memory layout. Another example of attack is called directory harvesting where spammers interact with vulnerable mail servers to steal valid email addresses.

The prototype developed by the Virginia Tech scientists proved to be effective and reliable at these types of attacks with a false positive rate as low as 0.01 percent.

Sunday, June 01, 2014

Dmitry Gorenbuerg's Notes on the Moscow Conference on International Security 2014

Last week, I attended the Russian MOD’s Moscow Conference on International Security (MCIS). Over the next few days, I plan to share my impressions of the event. First up, the keynote speeches. The lineup of presenters at the plenary session could not have been more prominent. The key Russian speakers included Defense Minister Sergey Shoigu, Foreign Minister Sergey Lavrov, and Chief of the General Staff Valery Gerasimov. The other speakers included Belarusian Defense Minister Yuri Zhadobin, Pakistan Defense Minister Asif Khawaja, Iranian Defense Minister Hossien Dehghan, CSTO Secretary General Nikolay Bordyuzha, the political commissioner of China’s Lanzhou Military District General Li Changcai, Egyptian Deputy Defense Minister Mohamed Said Elassar, and Indian Deputy Defense Minister Anuj Kumar Bishnoi. So quite an all-star cast. The links above go to videos of the speeches (with audio in Russian) whenever they are available. Text summaries of the Shoigu and Gerasimov speeches have been posted online in Russian.

For those who don’t understand Russian, here are some highlights. I didn’t take verbatim notes, so consider these the key points — what seemed to me to be most significant from what was said.

Tuesday, February 04, 2014

Computer Security, Cyberwarfare Firms Being Attracted to Washington DC

Washington D.C. business leaders like venture capitalist Jonathan Aberman want to make the D.C. region a more attractive place for tech start-ups as the U.S. government — specifically the military – increases its spending on tech innovation and cybersecurity.

Defense Department leaders have said cybersecurity poses one of the top threats to the U.S. military and these generals are backing it up with their spending. Cybersecurity is one of the few areas where the U.S. military will spend more this year as their overall budget is cut. The Defense Department will spend $4.7 billion on cyber operations this year – a 21 percent increase over 2013.

Overall, the cybersecurity industry receives about $80 billion in government spending and more than $300 billion in spending within the private sector. Those numbers are expected to expand as it is estimated that cyber theft costs as much as $400 billion in economic losses per year.

This is good news for tech entrepreneurs like Anup Ghosh, who is the type of innovator that D.C. wants to keep in the region rather than see him and his company head to California.

Thursday, January 16, 2014

One Time Use Memory Through Quantum Entanglement

Computer security systems may one day get a boost from quantum physics, as a result of recent research from the National Institute of Standards and Technology (NIST). Computer scientist Yi-Kai Liu has devised away to make a security device that has proved notoriously difficult to build—a "one-shot" memory unit, whose contents can be read only a single time.

The research, which Liu is presenting at this week's Innovations in Theoretical Computer Science conference,* shows in theory how the laws of quantum physics could allow for the construction of such memory devices. One-shot memories would have a wide range of possible applications such as protecting the transfer of large sums of money electronically. A one-shot memory might contain two authorization codes: one that credits the recipient's bank account and one that credits the sender's bank account, in case the transfer is canceled. Crucially, the memory could only be read once, so only one of the codes can be retrieved, and hence, only one of the two actions can be performed—not both.

"When an adversary has physical control of a device—such as a stolen cell phone—software defenses alone aren't enough; we need to use tamper-resistant hardware to provide security," Liu says. "Moreover, to protect critical systems, we don't want to rely too much on complex defenses that might still get hacked. It's better if we can rely on fundamental laws of nature, which are unassailable."

Unfortunately, there is no fundamental solution to the problem of building tamper-resistant chips, at least not using classical physics alone. So scientists have tried involving quantum mechanics as well, because information that is encoded into a quantum system behaves differently from a classical system.

Liu is exploring one approach, which stores data using quantum bits, or "qubits," which use quantum properties such as magnetic spin to represent digital information. Using a technique called "conjugate coding, "two secret messages—such as separate authorization codes—can be encoded into the same string of qubits, so that a user can retrieve either one of the two messages. But as the qubits can only be read once, the user cannot retrieve both.

The risk in this approach stems from a more subtle quantum phenomenon: "entanglement," where two particles can affect each other even when separated by great distances. If an adversary is able to use entanglement, he can retrieve both messages at once, breaking the security of the scheme.

However, Liu has observed that in certain kinds of physical systems, it is very difficult to create and use entanglement, and shows in his paper that this obstacle turns out to be an advantage: Liu presents a mathematical proof that if an adversary is unable to use entanglement in his attack, that adversary will never be able to retrieve both messages from the qubits. Hence, if the right physical systems are used, the conjugate coding method is secure after all.