Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

2012/10/15

Security: The Desktop Wars are over

Comments back from a friend on an idea I was toying with for security on PC's.

It seems the Desktop Wars are over and I need to embrace the New World Order:
 Smartphones, Tablets, Mobile-Devices have changed the problems and our thinking.

2012/06/20

NBN, stuxnet and Security: It's worse than you can believe

What  did US Intelligence tell the Australian Government about Real Network Security when a chinese vendor was vetoed  as supplier of NBN (central?) switches?
Now that we have O'bama admitting "we did Stuxnet, with a little help", we know that they aren't just capable and active, but aware of higher level attacks and defences: you never admit to your highest-level capability.

Yesterday I read two pieces that gave me pause: the first, the US Navy replacing Windows with Linux for an armed drone was hopeful, the other should frighten anyone who understands Security: there's now a market in Zero-Day vulnerabilities.

The things the new-world of the NBN has to protect us against just got a lot worse than you can imagine.

2012/06/05

Cyberwar: Bush/O'Bama authorised Stuxnet

We've crossed a Internet Security Rubicon: the USA admits to combined cyber-attack operations with Israel against Iran's nuclear enrichment program.[NY Times]

The Washington Post's "Zero Day" series says a lot more.

It's a very important event when a government goes public with its most-secret security or intelligence programs: it took over 4-decades after WWII (and the 'Spycatcher' court case) for news of just part of the Allied SIGINT activities to become public.

The work of Bletchley Park, the home of Alan Turning's biggest contribution, was kept secret to the point of allowing mass casualties rather than give it away.

The only reason I can think of for O'Bama to publicise the USA's active, and successful, practice of cyber-attack is they think they've developed protections against it.


2012/02/18

CyberWars, Governments and Internet Security

There's an 800-lb Gorilla in Internet Security that nobody discusses or acknowledges:
If Governments decide to apply their Technical and Military Intelligence skills to the Internet, not only won't we know, we won't be able to do anything about it.
Talking to a friend recently, off the top of my head I outlined 4 levels of Internet attackers/exploits (highest level/most competent at the top):
  • [4] National Military and Commercial Intelligence: surveillance, espionage, counter-espionage, targeted cyber-attack.
  • [3] Commercial Espionage and "Exploit as a business": Exploits and SPAM as a Service, botnets, Credit Card and Identity trading.
  • [2] small-scale, "hobbyist" and semi-professional technical creators. Some sales to level [3].
  • [1] script-kiddies, Internet "graffiti"/vanity attackers, customers of level [3].
These levels may or may not be "official" and may not be complete. But they are roughly right.