A year ago I wrote that with the then epidemic of "ransomware" attacks the Hackers had learned how to monetise remote attacks on Healthcare practices. That piece included detailed suggestions on minimum necessary practices and questions for suppliers and vendors.
Thirty Years in I.T. Theories, Ideas, Opinions.... Leveraging knowledge of the past to understand now. @SteveJCbr & stevej.cbr@gmail.com
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
2014/01/27
2014/01/07
Now Read This: Why the Munich Open Source Conversion won't be replicated in Australia.
Whichever side of the Open Source vs Proprietary Software debate you lie on, this article is a "must read". The headline take-away is: "Our goal was 'Freedom', to become independent."
How Munich rejected Steve Ballmer and kicked Microsoft out of the city, Steve Heath, 18th Nov, 2013.
2013/01/27
National Security: Prevention and Strengthening Defences missing from Gillard Strategy
The Gillard government has released a new National Security strategy specifically including Cyber-Security. It updates a 2009 strategy released by the Rudd government:
Because what is outlined is incomplete:
Strong and Secure: A Strategy for Australia's National SecurityThe strategy is strong, competent and wrong...
Because what is outlined is incomplete:
They have failed to address the root cause of cyber-attacks: vulnerable and error-filled Operating Systems and poor Application Software. Fix the weakness, stop the compromises before they happen, spend the money on where it can do good, not support "Business As Usual".Cleaning up the mess and containing damage after the fact is exactly wrong: it's attempting to catch the horse after its has bolted.
2013/01/26
Security: Computer Security for Business Continuity in Healthcare
If you run a Healthcare-realted Business, things changed in the last 6 months...
Ransomware is set to boom [0] and cyber-security is now part of our National Security Plan.
Businesses now have to secure their computers and data just as they secure their premises and goods.
It's not optional, fail to do so and you will go out of business, just when is the question.
Ask yourself this: "If my computers were destroyed, how long could I continue the business? At reduced capacity or at all?", then act accordingly.
i.e. Does anyone around the world see you as a high-value, exploitable target?
Especially those in low-income countries with employment problems: poverty corrupts, not just power or the love of money.
The Internet is defined by its explosive growth: A few For-Profit hackers have noticed Business Ransomware is an ideal way to monetise remote computer attacks & exploits.
The numbers of these attacks will now double every few months as word gets around, new "toolkits" are sold to them and they ramp up their activities.
Every business that can raise $5,000 and relies on its systems and data for daily operations is now in their sights. These people have no morals, ethics or compassion in their work: they want your money and don't care about the damage they cause or the impact of their actions. Appeals to them will fall on deaf ears. Neither believe that a single ransom payment will be the last you'll hear of them. Why would you trust the word of criminals who've already broken in and callously damaged your systems?
Ransomware is set to boom [0] and cyber-security is now part of our National Security Plan.
Businesses now have to secure their computers and data just as they secure their premises and goods.
It's not optional, fail to do so and you will go out of business, just when is the question.
Ask yourself this: "If my computers were destroyed, how long could I continue the business? At reduced capacity or at all?", then act accordingly.
i.e. Does anyone around the world see you as a high-value, exploitable target?
Especially those in low-income countries with employment problems: poverty corrupts, not just power or the love of money.
The Internet is defined by its explosive growth: A few For-Profit hackers have noticed Business Ransomware is an ideal way to monetise remote computer attacks & exploits.
The numbers of these attacks will now double every few months as word gets around, new "toolkits" are sold to them and they ramp up their activities.
Every business that can raise $5,000 and relies on its systems and data for daily operations is now in their sights. These people have no morals, ethics or compassion in their work: they want your money and don't care about the damage they cause or the impact of their actions. Appeals to them will fall on deaf ears. Neither believe that a single ransom payment will be the last you'll hear of them. Why would you trust the word of criminals who've already broken in and callously damaged your systems?
2013/01/11
Security: Healthcare systems are "soft-targets": the Next Big Exploit
Previous pieces on Security:
There are two ways to monetise e-Health Records:
- NBN: the business case for 100-1000Mbps symmetric for SOHO & SME
- Security: The Massive hole in the PCEHR system
- Cyberwar: paper-tiger or real threat?
- NBN, stuxnet and Security: It's worse than you can believe
- Cyberwar: Bush/O'Bama authorised Stuxnet
- The NBN and defending against Cyber warfare attacks.
- The NBN as an Essential Strategic Defence for Cyber-warfare.
- CyberWars, Governments and Internet Security
- Why new Secure Internet solutions are technically Hard
There are two ways to monetise e-Health Records:
- Identity Theft. Huge amount of high-quality info. Medicare Cards are worth 'points' as Govt. ID's.
- Ransomware: healthcare can't operate without its data and they print money by the truckload.
2012/12/13
Security: The Massive hole in the PCEHR system
In the last few days, three computer security stories have hit the news:
- At ADFA, hacking of 10,000 staff and student identity details.
- Credit-Card hacking of small Australian retailers by a Romanian ring [Radio National B'fast with AusCERT]
- A Gold Coast Medical Centre had its data encrypted and held to ransom by 'Russians' [Radio National B'fast]
These may seem small, incidental stories, but they are signs of something much darker. At the end of 2004 the Hackers Turned Pro [and a 2007 piece]: now they're after the money, not publicity nor headlines. In fact, rather the reverse, like special tactical units, military or police, they now want to go completely undetected - to avoid detection, to be completely stealthy.
2012/10/15
Security: The Desktop Wars are over
Comments back from a friend on an idea I was toying with for security on PC's.
It seems the Desktop Wars are over and I need to embrace the New World Order:
Smartphones, Tablets, Mobile-Devices have changed the problems and our thinking.
It seems the Desktop Wars are over and I need to embrace the New World Order:
Smartphones, Tablets, Mobile-Devices have changed the problems and our thinking.
2012/06/20
Cyberwar: paper-tiger or real threat?
Marcus Ranum, renowned IT Security expert, has interesting views on Cyberwar.
It's a lot more nuanced and subtle than "One Big Attack".
Where I diverge: a Big Event is a great distraction for really 'interesting', subtle actions - and can be just as simple as the First Worm by Morris. Oooops, it wasn't meant to do that...
Things you should read or view:
It's a lot more nuanced and subtle than "One Big Attack".
Where I diverge: a Big Event is a great distraction for really 'interesting', subtle actions - and can be just as simple as the First Worm by Morris. Oooops, it wasn't meant to do that...
Things you should read or view:
- RSA Conference, 2012, On Cyberwarfare
- Fabius Maximus posts on cyberwar
- You must Be >this< Tall To Play Cyberwar (has DoD grown enough yet?)
- Cyberwar: The Pentagon Cyberstrategy
- Cyberwar: About Stuxnet, the next generation of warfare?
- Congress Authorizes Pentagon to Wage Internet War [Wired. Ryan Singel]
- M.R. on rearguard-security: Cyberwar
NBN, stuxnet and Security: It's worse than you can believe
What did US Intelligence tell the Australian Government about Real Network Security when a chinese vendor was vetoed as supplier of NBN (central?) switches?
Now that we have O'bama admitting "we did Stuxnet, with a little help", we know that they aren't just capable and active, but aware of higher level attacks and defences: you never admit to your highest-level capability.
Yesterday I read two pieces that gave me pause: the first, the US Navy replacing Windows with Linux for an armed drone was hopeful, the other should frighten anyone who understands Security: there's now a market in Zero-Day vulnerabilities.
The things the new-world of the NBN has to protect us against just got a lot worse than you can imagine.
Now that we have O'bama admitting "we did Stuxnet, with a little help", we know that they aren't just capable and active, but aware of higher level attacks and defences: you never admit to your highest-level capability.
Yesterday I read two pieces that gave me pause: the first, the US Navy replacing Windows with Linux for an armed drone was hopeful, the other should frighten anyone who understands Security: there's now a market in Zero-Day vulnerabilities.
The things the new-world of the NBN has to protect us against just got a lot worse than you can imagine.
2012/06/05
Cyberwar: Bush/O'Bama authorised Stuxnet
We've crossed a Internet Security Rubicon: the USA admits to combined cyber-attack operations with Israel against Iran's nuclear enrichment program.[NY Times]
The Washington Post's "Zero Day" series says a lot more.
It's a very important event when a government goes public with its most-secret security or intelligence programs: it took over 4-decades after WWII (and the 'Spycatcher' court case) for news of just part of the Allied SIGINT activities to become public.
The work of Bletchley Park, the home of Alan Turning's biggest contribution, was kept secret to the point of allowing mass casualties rather than give it away.
The only reason I can think of for O'Bama to publicise the USA's active, and successful, practice of cyber-attack is they think they've developed protections against it.
The Washington Post's "Zero Day" series says a lot more.
It's a very important event when a government goes public with its most-secret security or intelligence programs: it took over 4-decades after WWII (and the 'Spycatcher' court case) for news of just part of the Allied SIGINT activities to become public.
The work of Bletchley Park, the home of Alan Turning's biggest contribution, was kept secret to the point of allowing mass casualties rather than give it away.
The only reason I can think of for O'Bama to publicise the USA's active, and successful, practice of cyber-attack is they think they've developed protections against it.
2012/04/27
The NBN and defending against Cyber warfare attacks.
CYBER-WARFARE and the Australian NBN.
We know from "Stuxnet" that Nation States are actively building and deploying Cyber warfare tools, applying them to National Security concerns and running them as Military, not technical, operations. This includes accurate reconnaissance and network topology and vulnerability mapping. The worst case is that attackers will gain access to the network control tools and infrastructure.
Recent coverage suggests that Obama denied a US Military request to launch a cyber attack on Syria's infrastructure during the recent 'troubles'.
From the "slammer" worm, we know that any Cyber warfare attack will be fully developed within 3 minutes, and any attack will be launched at the worst possible time for defenders, possibly accompanied by physical distractions.
Recovery from "munitions grade" worm/malware compromise will be long and expensive. Experience is that malware infections is as damaging to businesses as a fire: Within 12 months of a fire, 80-90% of small businesses fail.
We know from "Stuxnet" that Nation States are actively building and deploying Cyber warfare tools, applying them to National Security concerns and running them as Military, not technical, operations. This includes accurate reconnaissance and network topology and vulnerability mapping. The worst case is that attackers will gain access to the network control tools and infrastructure.
Recent coverage suggests that Obama denied a US Military request to launch a cyber attack on Syria's infrastructure during the recent 'troubles'.
From the "slammer" worm, we know that any Cyber warfare attack will be fully developed within 3 minutes, and any attack will be launched at the worst possible time for defenders, possibly accompanied by physical distractions.
Recovery from "munitions grade" worm/malware compromise will be long and expensive. Experience is that malware infections is as damaging to businesses as a fire: Within 12 months of a fire, 80-90% of small businesses fail.
2012/04/18
The NBN as an Essential Strategic Defence for Cyber-warfare.
Whilst reading this piece today I 'had a thought'.
The National Security kind that interest the Intelligence agencies and Military, a.k.a. "Cyber-warfare".
This is as far removed from normal Cyber-security as guarding bank vaults is from fighting a war. Attack, and hence Defence, is taken to a whole new level: because the resources employed and what is at stake is taken to a whole new level.
One argument in support of the NBN I've not heard is about Security, but not the "how to keep your bank account and credit card safe" kind - the usual direct theft or Identity Fraud talked about at Cyber-Security conferences.online", Nick Hopkins, guardian.co.uk, Monday 16 April 2012 15.00 BST
The National Security kind that interest the Intelligence agencies and Military, a.k.a. "Cyber-warfare".
This is as far removed from normal Cyber-security as guarding bank vaults is from fighting a war. Attack, and hence Defence, is taken to a whole new level: because the resources employed and what is at stake is taken to a whole new level.
2012/02/18
CyberWars, Governments and Internet Security
There's an 800-lb Gorilla in Internet Security that nobody discusses or acknowledges:
If Governments decide to apply their Technical and Military Intelligence skills to the Internet, not only won't we know, we won't be able to do anything about it.Talking to a friend recently, off the top of my head I outlined 4 levels of Internet attackers/exploits (highest level/most competent at the top):
- [4] National Military and Commercial Intelligence: surveillance, espionage, counter-espionage, targeted cyber-attack.
- [3] Commercial Espionage and "Exploit as a business": Exploits and SPAM as a Service, botnets, Credit Card and Identity trading.
- [2] small-scale, "hobbyist" and semi-professional technical creators. Some sales to level [3].
- [1] script-kiddies, Internet "graffiti"/vanity attackers, customers of level [3].
2012/02/13
Security threats "in the network": detection and countering
A new Internet Security report for July-Dec 2011 from M86 is out: "New M86 Security Labs Report Reveals Spread of Malware Growing via Social Media, Targeted Attacks and Exploit Kits" [PDF]
It triggered a thought that first occurred to me during the "No Internet Censorship" campaign:
It triggered a thought that first occurred to me during the "No Internet Censorship" campaign:
The perfect place for those wanting to hide illegal activities is "within the network", to work as Admins for Internet Providers. They can monitor, avoid and intercept Law Enforcement etc. requests and respond in many subtle ways.This thought arose after two rather disconcerting incidents for me:
- A TV documentary on Internet Porn mentioned the officers have to view these images and that it can lead to desensitisation over time, and
- an unprovoked personal attack within an Admin's forum by a "security professional" upon an individual. Sexually explicit language was used and that the language went unremarked by the entire forum was gob-smacking for me.
2010/10/13
Why new Secure Internet solutions are technically Hard
Information Security is both very hard and very easy at the same time.
Not only are Internet Nasties a nuisance, or worse, they prevent the new, useful Applications and Networks like e-Commerce, i-EDI, e-Health, e-Banking, e-Government and other business/commercial transactions systems.
Perfect Security isn't possible: ask any bank.
Defenders need to be 100.00% correct, every minute of every day.
Attackers need just one weakness for a moment to get in.
Not all compromises/breaches are equal: from nothing of consequence, up to being in full control with system owners not being aware of it.
All 'Security Systems' can only be "good enough" for their role, which depends on many factors.
How long do you need to keep your secrets? Minutes or Decades?
Not only are Internet Nasties a nuisance, or worse, they prevent the new, useful Applications and Networks like e-Commerce, i-EDI, e-Health, e-Banking, e-Government and other business/commercial transactions systems.
Perfect Security isn't possible: ask any bank.
Defenders need to be 100.00% correct, every minute of every day.
Attackers need just one weakness for a moment to get in.
Not all compromises/breaches are equal: from nothing of consequence, up to being in full control with system owners not being aware of it.
All 'Security Systems' can only be "good enough" for their role, which depends on many factors.
How long do you need to keep your secrets? Minutes or Decades?
2008/12/09
Climbing out of the Ooze, or is that GNUze?
I've written on Microsoft heading for financial trouble and mounting internet security problems - but they have an underlying cause.
Both ignore the hard-won Unix principle: Less is More.
[the joke behind the pager, 'less']
Both ignore the hard-won Unix principle: Less is More.
[the joke behind the pager, 'less']
2008/01/01
Solving 'Spam'
It never ceases to amaze me, the Politician attitude to Porn and 'Spam' & it's friend, malware.
Porn is "bad, bad, bad" and Pollies show very high interest - including policy & legislation.
Lots of angst & trashing around about eradicating something that 2,000+ years of writing/publishing shows can't be controlled/legislated away. The physical publishing world & (cable) TV show that the only effective is means of control is to allow-but-license.
Same as tobacco. Never going to eradicate it, only control it.
'Restricted Content' access can only be controlled iff:
Porn is "bad, bad, bad" and Pollies show very high interest - including policy & legislation.
Lots of angst & trashing around about eradicating something that 2,000+ years of writing/publishing shows can't be controlled/legislated away. The physical publishing world & (cable) TV show that the only effective is means of control is to allow-but-license.
Same as tobacco. Never going to eradicate it, only control it.
'Restricted Content' access can only be controlled iff:
- every page is 'classified' at source (meta-tags),
- an unforgeable Internet 'proof-of-age' card/system is created,
- there are criminal penalties for subverting the system, forging identities or misclassifying pages,
- there are no legal jurisdictions outside 'the system' [e.g. on the high-seas],
- all browsers enforce 'the rules',
- and browsers can't be built/written to ignore 'the rules'.
2007/04/20
The End of the Internet, or the Microsoft Users Net-Meltdown?
The 2005 Australian Computer Crime and Security Survey(PDF) reports that at the end of 2004 "the hackers turned pro". The 2006 ACCSS indexACCSS index may be easier for downloads. [In 2016, the ACCSS was replaced by "the BDO and Australian Cybercrime Survey".]
For 2-3 years now, most malware has satisfied the definition of Organised Crime:
In an August 2006 post, I reported the ACCSS comments and new comments from SANS .
ZDNet now report that Rootkits becoming increasingly complex and operate by stealth. They say:
For 2-3 years now, most malware has satisfied the definition of Organised Crime:
it's theft, it's purposeful, it's co-ordinated.
In an August 2006 post, I reported the ACCSS comments and new comments from SANS .
ZDNet now report that Rootkits becoming increasingly complex and operate by stealth. They say:
If you use a Microsoft system and connect to the Internet without extensive protection, you should be afraid, very afraid. And even large organisations who do everything right, are still open to targetted "zero day" attacks. The first Windows Vista security problems are being reported. It's better than their previous efforts, but still contains significant security flaws. The Whitehouse mandated a minimum security configuration for all US Federal Government Vista destops.
Rootkits -- malicious software that operates in a stealth fashion by hiding its files, processes and registry keys--have grown over the past five years from 27 components to 2,400, according to McAfee's Rootkits Part 2: A Technical Primer (PDF).
Subscribe to:
Posts (Atom)