Tuesday, December 30, 2014

What caused Sony hack: What we now know

By Jose Pagliery
December 29, 2014
NEW YORK (CNNMoney)

What we now know about the Sony Pictures hack shows this cybermystery isn't over yet.

The FBI presented evidence that North Korea was behind the hack. Upon closer examination, security experts, hackers, and people familiar with Sony's computer networks are uniting with this disheartening reality: Anyone could have pulled this off.

It could have been a disgruntled Sony employee, profit-seeking hackers, North Korea--or a combination of the three.

Here's the facts about the hack that we do know:


  • Hackers used computer servers in Bolivia, Cypress, Italy, Poland, Singapore, Thailand and the United States to attack Sony. 
  • The IP addresses associated with those servers have "previously [been] linked to North Korea" by the FBI
  • The malware used against Sony had what the FBI calls "lines of code" and "data deletion" methods similar to malware "North Korean actors previously developed."
  • The computer-wiping software used against Sony was also used in a 2013 attack against South Korean banks and news outlets, which the FBI attributed to North Korea. 
  • The malware was built on computers set to Korean language--unusual in the hacking world. 
  • Hackers demanded Sony Pictures pull "The Interview" to avoid starting a war over a movie.
These facts are why the Obama administration has accused North Korea of hacking Sony Pictures and has vowed to retaliate.

But security experts aren't 100% ready to point their fingers at North Korea--not yet, anyway.

Technical evidence shows anyone can tap servers for hacking and spamming. Hackers routinely borrow and share computer code. Computer wiping software can be bought legally by anyone. A computer's language settings can be changed on a whim. And this hack actually started as an extortion attempt on Nov. 21 when Sony executives got emails saying "The compensation for it, monetary compensation we want."

Robert Graham, a researcher with Errata Security, stresses that anyone can hire hackers on the black market. These cybersoldiers of fortune might work on behalf of a country or an ex-Sony employee--and not even know it. 

He's also wary of how quickly the US government blamed North Korea. Hacking investigations typically take months, including the FBI's takedown of online drug bazaar Silk Road and hunting down members of LulzSec. 

"Even if its true that is was North Korea, I don't think the FBI would do it in three weeks," Graham said. "Maybe six months."

This year's major hacks are a perfect example. Law enforcement still hasn't publicly identified--or arrested--those who broke in to Target, Home Depot, and JPMorgan and stole millions of credit cards and lots of personal data. 

Robert M. Lee, co-founder of consulting and software firm Dragos Security, puts it this way: There might be evidence against North Korea, but what the FBI presented doesn't cut it. 

Lee, until recently a U.S. Air Force intelligence officer specializing in cyber warfare, also worries about how quickly North Korea was blamed. Lee said intelligence agencies and law enforcement don't typically work together at this kind of breakneck speed--and when they do, they often rely on outdated or inaccurate information, because there are so many conflicting intelligence reports. 

For its part, North Korea's government says it was framed. Take that for what you will.

Adding to the fog: Lots of Sony employees with critical access to the computer network were laid off by the company earlier this year, according to ex-employees. And early on, the hackers talked about seeking "equality" at Sony.

A simple explanation points to North Korea. But those who understand hacking worry its just too simple. 




Tuesday, December 9, 2014

Scam of the Week: "Shipping Problem"

Posted by Stu Sjouwerman

We have Black Friday and Cyber Monday behind us. After losing ground to online competitors, brick-and-mortar retailers have struck back with incredible online deals. Wal-Mart said Thanksgiving was its second biggest day ever for online sales and Target's online buying was up 40% over last year.

This is the time of year that people buy new smartphones, TVs, and new game consoles because they are able to get killer deals and they are dying to get their hands on these new goodies.

What you may not know is that similar to a magazine's editorial calendar, hackers have a "scam calendar" which focuses on events exactly like this. They have them planned and ready to roll starting TODAY for the rest of the month.

These malware campaigns do not discriminate between the home and the office, and use social engineering to trick users. A billion of these criminals emails are sent each day. So, I strongly recommend you send this to your users today. Feel free to edit in any way you like:

"Scammers are preying on people that have just made a lot of online purchases on Black Friday and Cyber Monday. There are several scam campaigns being sent right now.

1) Be on the lookout of "Shipping Problem" emails from FedEx, UPS, or the US Mail, where the email claims they tried to deliver a package from (for instance Apple Computer) but could not deliver due to an incomplete address. "Please click on the link to correct your address and you will get your package." If you do, your computer is likely to get infected with malware. Warn everyone in the family, especially teenagers.

2) Watch out of alerts via a TEXT to your smartphone that "confirm delivery" from FedEx, UPS, or the US Mail, and then asks you for some personal information. Do not enter anything. Think before you click!

3) And to reiterate a warning we sent out a few weeks ago, there is a fake refund scam going on that could come from a big retailer. It claims there was a "wrong transaction" and wants you to "click for a refund" but instead, your device may be infected with ransomware.

http://blog.knowbe4.com/scam-of-the-week-shipping-problem

Monday, December 1, 2014

Sony pictures computer system hacked in online attack

25 November 2014

Sony Pictures Entertainment has been targeted by computer hackers in an attack which reports say forced it shut down its systems on Monday.

A skull appeared on computer screens along with a message threatening to release data "secrets" if undisclosed demands were not met, reports said.

The message showed "#GOP" indicating a group called Guardians of Peace was behind the attack.

Sony has issued a statement saying the firm is investigating the "IT matter".

The tech firm has reportedly shut down its computer network as a precaution and advised employees that resolving the situation could take anywhere from one day to three weeks.

Meanwhile, an anonymous user on the Reddit news website posted an image allegedly from a Sony computer screen, which said "Warning: We've already warned you, and this is just the beginning...We have obtained all your internal data including secrets and top secrets".

News of the online attack comes just months after Sony's Playstation network was forced offline by a cyber attack in August.

Wee Teck Loo, head of consumer electronics research at Euromonitor said any negative news for Sony just "piles" pressure on the company that has been struggling financially in both its TV and mobile business.

"Three years ago, the hack on PlayStation network was massive, expensive and absolutely embarrassing. This time round, I don't believe that there will be massive damage, save for Sony's ego, even if the hack is real," Mr. Loo said.

Charles Lim, senior industry analyst at ICT, Frost & Sullivan Asia Pacific, however, said that the attack has put into question what "multi-layers of prevention" Sony has to detect and handle such risks.

"In this breach, GOP claimed to have accessed private keys, source codes, password files and even their production schedule and notes, and that will raise questions," Mr Lim said.

High profile companies like Sony can be targeted and hacked every day, according to Naveen Menon, partner at consulting firm AT Kearney.

In its latest research, the firm said that experts estimate that at least 25% of all companies have already suffered financial loss through some form of cyber attack.

Sony is understandably keen to downplay this latest hacking threat. "We are investigating the matter" is the kind of benign language more commonly used for routine technological issues, not chilling messages threatening to unleash reams of data to the world.

The demands are opaque so it is unclear how much damage could be wrought should Sony fail to resolve the situation before the deadline. Sony Pictures has at least reclaimed its compromised Twitter accounts.

Nevertheless, this internal corporate attack does not yet appear to be of the magnitude of previous public breaches that Sony has suffered.

But the fact that hackers have again apparently infiltrated Sony's systems will do nothing to restore public faith that the Japanese technology giant has its security affairs in order.

And it is somewhat ironic that Sony has only just dismissed the allegation made by hackers that they had succeeded in breaching the Playstation network earlier this year. This latest attack cannot be so easily dismissed.

http://www.bbc.com/news/technology-30189029 

Friday, November 14, 2014

How health history is more valuable to hackers than your credit card information

By Kelly Yee

A recent article stated that medical records could be sold for up to 20 times more than credit card information on the black market. There are various factors as to why consumers' medical information has become so valuable. This article considers those factors as well as some precautions medical providers can take to better protect themselves against malicious threats.

The first thing that needs to be addressed is why hackers prefer to buy and sell medical records versus credit card information.

If we start with credit card information, we need to address the question of how much a thief can profit from stealing a credit card? Sometimes zero, maybe a few thousand dollars if he or she is lucky. The fraud detection software that credit card companies deploy is so sophisticated that any attempt to purchase say a TV, in a state the victim has never been to, is flagged and rejected immediately. There are whole departments dedicated to try to track the thief, so that any loss in revenue by the credit card company is minimized. In other words, when it comes to stolen credit card information, there is a low reward for a moderate risk.

Now, take medical records. Most of us probably don't understand why our medical history is valuable. Why does it matter who knows our medical history?

But, in reality, in a thief's mind the real question is "who would be interested in paying the most for the medical information I have?" The answer lies with medical providers.

The advent of electronic records management has created a landscape where a thief could steal batches (tens of thousands) or patient records in one fell swoop. One of the original goals of electronic records management was to provide seamless access to an individual's medical records to many. This way, multiple departments and specialties could all have access to a singular account of a patient's medical history. This is great for a hospital where different departments need to communicate with one another. From a security standpoint, however, there are now multiple access points too. Electronic records are very useful in one sense as they help with efficiency, document management and overall accountability, but with anything that has multiple points of entry, there is now more vulnerability to malicious use.

HIPPA compliancy is also another area of consideration as it also attributes in some way to the increased value of medical records on the black market. HIPPA is a federal protection act that medical providers must adhere to. HIPPA protects a patient’s information, which also has security safeguards. Any violation by the medical providers or employees could be pursued by a court of law, criminally and civilly. Simply put, under HIPAA, medical providers are federally required to keep patient’s information safe.
Finally, reputation must also be taken into account when considering the value of health records. In the medical community, medical providers get the majority of their business from referral and reputation. A breach in security or any unprofessional act by a medical provider could cost them several patients and therefore business.
Now let’s look at all of the factors together. Electronic records allow thieves the ability to extract thousands of patients’ records in one attack. Medical providers are federally required to keep patient’s information safe through HIPPA. Any violation of HIPPA alone could cost the medical provider millions. Any known breach of patients’ information would negatively affect the provider’s reputation, from both a patient and partner level. This means that millions of dollars and perhaps the medical provider’s existence could be at stake. In other words when taking into consideration factors like the storage of electronic records, HIPAA compliancy and a medical provider’s reputation; when it comes to medical health data there is a high reward for moderate risk for hackers.
Fortunately, security has become a main topic for medical providers and the electronic records management vendors that support them.   Security features like the ones Penango offers where email is encrypted and authenticated is beginning to be the norm. Two-factor authentication is also becoming the norm. This is when the user will need to know a password and have access to the token that generates the time-varying code. While it is easy to figure out or skim passwords for most user accounts, getting access to the token is much harder, and an attacker would have to steal the user’s phone or physical key fob. All these options can help reduce the risk of an attack. 

http://betanews.com/2014/11/03/how-health-history-is-more-valuable-to-hackers-than-your-credit-card-information/

Friday, November 7, 2014

Online ads are attacking you

By Jose Pagliery
October 15, 2014: 3:37 PM ET
NEW YORK (CNNMoney)

An especially sneaky type of hack is on the rise. Hackers can infect your computer by piggybacking on Web ads--even on trusted websites.

Hackers are slipping malware into legitimate-looking online advertisements. When you visit sites that serve those ads, you're automatically and unknowingly downloading computer viruses. 

"Malvertising" has hit Amazon, Answers.com, Dictionary.com, Examiner.com, The Jerusalem Post, Last.fm, The Pirate Bay, The Times of Israel, Yahoo, and YouTube this year. 

And it's blowing up. The number of malicious ads has nearly doubled every year since 2011, according to data from security firm RiskIQ. Its researchers have discovered 432,374 of them so far this year. 


"The ad tech industry recognizes this is a serious problem," said Geir Magnusson, CTO of online ad platform AppNexus.

Malvertising makes up a microscopic fraction of the 5 trillion online ads displayed each year in the US alone, according to trackers at comScore. But that's still half a million times our computers could get infected. 

Hackers have used malvertising to steal bank account information and lock up files to hold them for ransom.
A major concern now is that hackers are getting smarter at launching attacks that slip past security scanners -- and are customized to specifically attack you.
Online ad networks allow advertisers to know your physical location, Web history, and what kind of browser, device or operating system you use. Hackers are leveraging this to make ads that only deliver malware under specific circumstances.
If the malware exploits a bug in Windows XP, it won't appear if you use Windows 7. It might only target retirees in Florida on weekdays. That's why malvertisements don't always raise alarms. They won't appear for every scanner.
Hackers also take advantage of a vulnerability in the way online ads are bought and sold. When you navigate to a website, a complex negotiation between advertisers occurs in a matter of milliseconds. The highest-bidding advertiser can show you an ad -- or go back to the market and see if there's an even higher bidder somewhere out there -- all in half a second.
The box reserved for advertising on a website might redirect you to a dozen different computer servers before it finally loads the ad. That's how hackers go unnoticed: The first package of data they send seems fine, but they eventually redirect you to a server that spits out malware. They set up deceptive servers to trick ad networks and consumers alike.
"The ecosystem is optimized to get the right ad displayed at the right time at the highest price," said RiskIQ CEO Elias Manousos. "It was never built to stop fraud."
The system's complexity makes it harder to crack down. When Times of Israel was hit with malvertising in September, it took 14 hours to figure out what ad agency was unwittingly passing along the bad ads, according to Jess Dolgin, whose J Media firm serves as the news website's advertising department.
The advertising industry does take steps to protect the public. For example, AppNexuspays dozens of its staff in New York and India to monitor actual ads all day long. And a special software program, dubbed Sherlock, spots those that violate company policy.
Sherlock catches 35 malicious ads a week. But AppNexus serves 30 billion ads a day. Sherlock can't scan them all -- that would delay display time by minutes. Cybersecurity provider Bromium recently concluded the most thorough solution -- rigorous approval of 100% of ads -- is just not possible for the ad industry.
"There are limits to what you can do in milliseconds," said John Clyman, senior director of security at The Rubicon Project (RUBI), an ad exchange.
So how can you avoid malvertising?
The bare minimum: Don't click on ads, especially if they say something like, "Danger! You need to upgrade your antivirus!" And malware-laced ads can look like authentic car or movie commercials.
Minimize exposure: Always update your operating system, apps and Web browser (including plugins, like Java). Up-to-date antivirus programs will catch some malware -- but not all.
Go all the way: Use something like AdBlock, which stops all advertisements from appearing. But pages designed to look good with ads suddenly look horrendous. And worst of all, this chokes off the main revenue stream for publishers, like CNNMoney or your favorite blog.
Ad companies are also clamping down on each other. AppNexus has a three-strike policy before it suspends business with an ad agency. Security researchers suggest an ad industry honor system that universally revokes privileges. You spew malware, you're out. But the problem is so widespread that sounds untenable too.
"It would be interesting to see if anyone would be left standing," Dolgin said.

Wednesday, October 22, 2014

2014 October Shred Event!

Don't forget! Technology Services and New World Recycling will be holding our second annual October Shred Event next Monday, October 27th from 1:00-3:00pm. This is the perfect opportunity to celebrate National Cyber Security Awareness Month by shredding all the sensitive documents that have been taking up space in your home! The Kona Ice truck will be joining us as well!

See you there!

Wednesday, October 15, 2014

Kmart and Dairy Queen Report Data Breach

By Nicole Perlroth
October 10, 2014

In the latest cyberattack on American retailers and restaurants, both Kmart and Dairy queen said their computer systems were compromised in a security instructions involving customers' credit and debit card information.

Kmart, a subsidiary of Sears Holdings, said on Friday that it had been breached and that it was working with law enforcement as well as a forensics team. The company said that it appeared to have been attacked in early September and that malware was present on some of its in-store payment systems. The malware, like the type found at Home Depot recently, was meant to evade antivirus systems.

The company did not indicated how many stores were affected or how many credit cards were potentially compromised but said the malware has been removed.

Dairy Queen also said on Thursday that its in-store payment systems contained malware. The company said it was working with its franchisees to determine if and when each location was breached and posted a full list, with time frames, on its website. That information suggests hackers made their way into Dairy Queen payment systems in August.

Based on early forensics reports, Sears and Dairy Queen said there was no evidence that personal information, debit card PINs, email addresses or Social Security numbers were obtained in the attack. Only account numbers and expiration dates were taken.

Sears and Dairy Queen join nearly a dozen other retailers--including Target, Sally Beauty, Neiman Marcus, the United Parcel Service, Michaels, Albertsons, SuperValu, P.F. Chang's, and Home Depot--that have had their in-store payment systems compromised with malware over the last year.

The Secret Service estimated this summer that 1,000 American merchants were affected by this kind of attack, and that many of them may not even know that they were breached. There have been no arrests to date.

In each case, criminals scanned for tools that typically allow employees and vendors to work remotely, then broke into these tools, using their foothold to install malware on retailer's systems. That malware, in turn, fed customers' payment details back to the hackers' computer servers.

The same group of criminals in Eastern Europe is believed to be behind the earlier attacks, according to several people with knowledge of the results of forensics investigations who spoke on the condition of anonymity because of nondisclosure agreements.

Studies have found that retailers, in particular, are unprepared for such attacks. A joint study by the Ponemon Institute, an independent security research firm, and DB Networks, a database security firm, found that a majority of computer security experts in the United States believed that their organizations lacked the technology and tools to quickly detect database attacks.

Only one-third of those experts said they did the kind of continuous database monitoring needed to identify irregular activity in their databases, and another 22 percent acknowledged that they did no scanning at all.

Sears said it would offer free credit-monitoring services to any customer who had used a credit or debit card at any of its affected store locations. Dairy Queen said it would offer free identity repair services for one year to affected customers.

http://bits.blogs.nytimes.com/2014/10/10/kmart-and-dairy-queen-report-data-breach/?_php=true&_type=blogs&_r=0

Thursday, September 18, 2014

Data Breach at UPS Stores in 24 States

HONG KONG (CNNMoney)

United Parcel Service has discovered a computer breach at 51 stores, making Big Brown the latest retailer to lose customer data.

UPS (UPS) said that the hacking had escaped detection at stores in 24 states, or around 1% of its locations. At most stores, the malware attack occurred after March 26, and was eliminated by August 11.
No fraud has yet been discovered, UPS said, but customer names, postal addresses, email addresses and payment card information were compromised.
Tim Davis, president of The UPS Store, apologized in a statement for any anxiety the theft may have caused customers. He said the company had deployed "extensive resources to quickly address and eliminate this issue."
Each UPS Store is franchised and runs separate computer systems, which may have helped limit the extent of the attack. UPS said the bug was not found at any of its other businesses.
The UPS breach is the latest in a long string of incidents in which hackers have made off with retail consumer data.
Just last week, Albertson's and SuperValu announced that hackers broke into their credit and debit card payment networks. Target (TGT) has been hit, along with Adobe(ADBE), Snapchat, Michaels, Neiman Marcus, AOL (AOL, Tech30) and eBay (EBAY,Tech30).
All in all, a CNNMoney analysis found that half of all American adults were hacked in a recent 12-month period.
http://money.cnn.com/2014/08/21/technology/security/ups-store-data-hack/

Thursday, September 4, 2014

Home Depot is investigating a hack that possibly exposed its customer payment information

NEW YORK (CNNMoney)

The company on Tuesday confirmed it has partnered with banks and law enforcement to look into "some unusual activity" relating to customers.

Independent cybersecurity journalist Brian Krebs was the first to report this, saying "a massive new batch of stolen credit and debit cards" went for sale Tuesday in the black market online.

Krebs said hackers were possibly in Home Depot's computer systems from May until now. If that's true, this might be even larger than the three-week long Target breach that affected 40 million debit and credit cards late last year, he noted.

In a statement, Home Depot spokeswoman Paula Drake said: "Protecting our customers' information is something we take extremely seriously, and we are aggressively gathering facts at this point while working to protect customers."

The company promised to alert customers as soon as it can ascertain a data breach has occurred.

This could turn out to be another giant hack like the ones that hit several brand name U.S. stores. Since late 2013, the list has gotten extensive: Albertson's, Target, Michaels, Neiman Marcus, P.F. Chang's, and SuperValu.

So many companies have been hit, CNNMoney developed it's own tool: What hackers know about you. Check it out.

For perspective, consider that Target (TGT) is still reeling from its brush with hackers. The company's latest figures estimate the damage so far at $148 million--and that number continues to rise. The value of its stock has fallen nearly 5% this year, and the company's CEO resigned.

Meanwhile, Target customers haven't felt any direct impact--that they can attribute to the hack, anyway. But that's partly because banks won't let customers know what big hack forced them to temporarily freeze accounts, nix fraudulent expenses, and reissue debit and credit cards.

http://money.cnn.com/2014/09/02/technology/security/home-depot-hacked/ 

Thursday, August 21, 2014

There's A Sickening Scam On Facebook Which is Exploiting Robin Williams' Suicide

by Alex Heber
August 20, 2014 at 3:10pm

Populating many Facebook feeds this week have been scam posts taking advantage of Robin Williams' tragic suicide.

The posts which are shared unknowingly by your Facebook friends claim to include a "last phone call" video and are designed to sell social media user's information.

Clicking on this post takes you to a website which asks you first to share the post on your own Facebook wall and then take a short survey.

IT security company ESET said scammers earn money for every person they trick in to completing the survey.

"You would have to be pretty ghoulish to proceed any further, but the truth is that the internet has deadened our sensitivities and made many of us all too willing to watch unpleasant thing on our computer screens," ESET security analyst Graham Cluley said.

"By tricking thousands of people into taking a survey, in the misbelief that they will watch the final moments of a comedy legend whose life ended tragically, the scammers aim to make affiliate cash.

"Because every survey that is taken earns them some cents--and the more people they can drive toward the survey (even if they use the bait of a celebrity death video), the more money will end up in their pockets. In other cases, scammers have used such tricks to install malware or sign users up for expensive premium rate mobile phone services."

The Australian government's Stay Safe Online initiative also sent out an alert warning of the threat. This is one of many scams targeting disasters and tragedies as scammers prey on events of global concern. The scams are easily interchanged to suit new events," it said.

The advice is not to share or like anything on Facebook unless you are confident it is safe.

"You should be suspicious of any post that requires you to blindly share posts or provide personal information," Stay Safe Online said in its warning.

http://www.businessinsider.com.au/theres-a-sickening-scam-on-facebook-which-is-exploiting-robin-williams-suicide-2014-8/ 

Tuesday, August 12, 2014

Your personal information just isn't safe

By Jose Pagliery
NEW YORK (CNNMoney)

Companies can't keep your data safe. It's that simple.

When Target lost data on some 110 million customers, it recommended them to credit bureau Experian for "identity theft protection," offering to cover the cost for a year.
Think you're in better hands? Think again.

Sometime before the Target (TGT) hack, Experian had its own data leak--via a subsidiary. That data leak got plugged before Target sent victims to Experian. But it shows that even those entrusted with our most sensitive data don't know how to protect it.

Experian unknowingly sold the personal data of millions of Americans--including Social Security numbers--to a fraudster in Vietnam. That guy then sold the personal information to identity thieves around the globe.

It wasn't until U.S. Secret Service agents alerted Experian that the company stopped.

Hieu Minh Ngo, now 25, was caught and admitted to posing as a private investigator in Singapore to get exclusive access to data via Court Ventures, an Experian subsidiary. Ngo then sold access to fellow criminals.

Federal investigators say that let criminals reach databases with hundreds of millions of Americans' personal data including:

  • names
  • addresses
  • Social Security numbers
  • birthdays
  • work history
  • driver's license numbers
  • email addresses
  • banking information
Criminals tapped that database 3.1 million times, investigators said. Surprised you haven't heard this? It's because Experian is staying quiet about it.

It's been more than a year since Experian was notified of the leak. Yet the company still won't say how many American's were affected. 

CNNMoney asked Experian to detail the scope of the breach. The company refused.

"As we've said consistently, it is an unfortunate and isolated issue--one that did not affect Experian's databases and has no true relevance to the work we did with clients like Target," Experian spokesman Gerry Tschopp said.

Federal court filings show that at least one database actually belonged to another firm--U.S. Info Search. It was Experian's subsidiary that sold database access to Ngo.

Target and Experian insist that the credit monitoring service is unrelated to the incident involving Experian's data-selling business.

But even Experian's credit monitoring service, which collects data on customers, isn't immune.

According to Barry Kouns, a security professional who maintains a Cyber Risk Analytic database of major data breaches, said Experian's databases have been involved in 97 breaches of personal information.

"Based on our research, it appears that data brokers place a high value on collecting and using our information but not so much protecting it," Kouns said.

Wednesday, July 23, 2014

You Should Treat Public Computers Like Public Bathrooms--With a little fear


By Josephine Wolff

When I was in college, the main campus library had several computers set up on the first floor for public use, and invariably, whenever I used one, a previous user had not logged out of her Gmail account. So when I tried to load my account, I would instead find myself staring at the entire contents of someone else's inbox. Of course, I would then log that person out and sign myself in--but those brief moments when I had complete access to another person's email were terrifying nonetheless. How could people be so careless with something as valuable as their email account? And then, inevitably, after my own session, I would make it halfway across campus and suddenly being worrying that I might have forgotten to log myself out--the same way you might worry you forgot to turn off the stove, or lock the door before leaving your house--and so I would trek back up to the library and check.

I still fear public computers, a terror that was only reinforced by the July 10 advisory that the Secret Service and National Cybersecurity and Communications Integration Center issued about keyloggers on hotel business center machines. The advisory, first reported by security researcher Brian Krebs, was directed at the hospitality industry and warned of cases in which people who had registered at hotels with stolen credit cards downloaded keylogging software onto the computers in the hotels’ business centers. 
The software would then capture every keystroke entered on those public machines—including the usernames and passwords entered by unsuspecting hotel guests, as well as the content of any emails or documents they wrote on those machines. The log of these keystrokes would be emailed to the person who had installed the malicious program, providing the hacker with a wealth of data on the business center users. “The suspects were able to obtain large amounts of information including other guests’ personally identifiable information (PII), log in credentials to bank, retirement and personal webmail accounts, as well as other sensitive data flowing through the business center’s computers,” according to the advisory.
This, of course, is a far more serious—and nefarious—threat than college students who forget to log out of their Gmail accounts and thereby give strangers access to their email, but both risks stem from a common problem in computer security: our tendency to treat public computers like personal ones and, more broadly, to ignore the physical dimension of cybersecurity.
Krebs points out that while there are ways that hotels can try to make it more difficult for people to download keyloggers on their computers—by restricting users’ ability to install programs, for instance—there’s a limited amount that can be done to improve the security of public computers, especially if they’re to provide any valuable services to users. Or, as Krebs puts it, “if a skilled attacker has physical access to a system, it’s more or less game over for the security of that computer.”
Basic safeguards are still worth taking, if only to restrict the set of potential perpetrators to “skilled attackers.” The advisory noted:
It doesn’t take much skill to find keylogging software online and install it on a public machine. You don’t need to know how computers work, you don’t need to be an expert coder, you just need to be dishonest—and have access to a computer that other people use. This is data theft at its easiest—and perhaps also at its easiest to overlook.
In cybersecurity research, we think a lot about the variety of threats that can flow over networks and the silent, nonphysical ways that computers can be accessed and penetrated and entered—via email, Web pages, and other means. These sorts of crimes present a whole host of new security problems that are worth studying and addressing in light of the fact that the principles and assumptions of physical security no longer apply. The very notion of “access,” in fact, changes radically in this context—and the language we use to talk about cybersecurity breaches, in which attackers successfully “penetrate” machines, or get “inside” computers, reinforces how thoroughly physical ideas have been co-opted and given virtual meanings in this space.  But sometimes we risk forgetting that the lessons and language of physical security still matter and still apply. Yes, you can steal information from a computer halfway across the world—but it’s often much easier, especially for criminals with limited technical expertise, to steal from a computer you can walk right up to—a computer in a hotel’s business center or college library. Even privately owned computers that are left unlocked present a prime target for the technically unskilled criminal, and while people routinely use lock screens on their cellphones, they often don’t take the same degree of precaution with their laptops.
The good news about the physical security elements of cybersecurity threats is that, just as they are relatively easy for nontechnical people to exploit, they are also fairly straightforward for other nontechnical people to defend against. Essentially, you want to make it as difficult as possible for anyone who is not you to ever use your private computer, and you should only use public ones under the assumption that anything you do on them may be captured or accessible to others. Just as you might take basic hygiene steps to avoid germs and bacteria in public bathrooms (oron public keyboards), some simple cyber hygiene measures can help you ward against the digital diseases carried by the outside world. This means always—always, always—locking your computer whenever you walk away from it, not letting other people use it, and not checking your primary email account or bank account—or doing anything else potentially sensitive—in a hotel business center or on any other public computer.
This certainly won’t protect against all cybersecurity threats—it won’t even protect against all of the problems posed by hotel networks, which can be used to install malware on personal computers, or even public computers—my sophomore year, those same computers in the main campus library that I occasionally (and foolishly) used to check my email were used to send anonymous death threats via email. But at the very least, these sorts of measures will help weed some of the less technically talented from the field of would-be cybercriminals and allow us to continue studying and learning about the novel nature of these digital threats without losing sight of the ways in which they are not entirely new. Cybersecurity and physical security are closely related—increasingly so, as more physical objects are connected to online infrastructure in various ways—and even as computer networks pose some new security challenges, they can still benefit from applying some of the older lessons of physical security.

Monday, June 9, 2014

OUCH! June 2014: Disposing of your Mobile Device

OUCH! June 2014: The Monthly Security Awareness Newsletter for Computer Users

Disposing of Your Mobile Device
Overview: Mobile devices, such as smartphones and tablets, continue to advance and innovate at an astonishing rate. As a result, many of us replace our mobile devices as often as every 18 months. Unfortunately, too many people simply dispose of their older mobile devices with little thought on just how much personal data their devices have accumulated. In this newsletter we will cover what types of personal information may be on your mobile device and how you can securely wipe it before disposing of it or returning it. If your mobile device was issued to you by your employer or has any organizational data stored on it, be sure to check with your supervisor about proper backup and disposal procedures before following the steps below.

For the full newsletter, visit: http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201406_en.pdf 

Friday, April 11, 2014

Heartbleed bug: Check which sites have been patched

by Jason Cipriani
April 9, 2014

We compiled a list of the top 100 sites across the Web, and checked to see if the Heartbleed bug was patched.

The Heartbleed bug was serious. Disclosed less than two days ago, the Heartbleed bug has sent sites and services across the Internet into patch mode.

For an in-depth explanation of what exactly Heartbleed is, and what it does, read this post by our own Stephen Shankland. In essence, the bug potentially exposed your username and password on sites like Facebook, Google, Pinterest, and more.
Using Alexa.com, we've been going through the list of the top 100 sites in the US and asking "Have you patched the Heartbleed bug yet?" Once we have an answer, we will fill in the chart below with the response.
While we wait to hear back, we will be testing the sites against the Qualys SSL Server Test. There may be some instances where the patch isn't detected or a server can not be inspected (the site may be fine, but Qualys can not confirm that), in which case we will mark the site as "be on alert." When a site is marked as such, you should proceed with caution and contact the site or company directly if you have any questions pertaining to your account security.
You may notice some companies will be marked as "was not vulnerable." In that case, the site in question does not use the type of OpenSSL encryption this bug was based on and your data was never at risk.
If you're checking back after seeing earlier versions of this story, you may also notice that some statuses have changed. For instance, the status for Microsoft, MSN, and Live has been updated to "was not vulnerable" once Microsoft confirmed that to be the case.

Monday, April 7, 2014

Happy Earth Day!

Did you know that each person in the United States uses about 749 pounds of paper every year?With tax season coming to a close, do you need to securely dispose of potentially sensitive documents? Please join Technology Services and shred your stuff! Bring your personal documents to Cougar Drive (near the lawn of Banks Hall) to be shredded on-site by New World Recycling and celebrate Earth Day! Thursday, April 24, 2014 from 1:00p-4:00p.

Wednesday, March 19, 2014

DOE Offers "Student Privacy and Confidentiality" Hotline Service

March 18, 2014

1-800-PRI-VACY: Student data privacy has been a hot topic for both concerned educators and vendors. But instead of worrying, why not just call the U.S. Department of Education's private data hotline? PTAC (the DOE's Privacy Technical Assistance Center) has a toll-free phone number where education stakeholders can ask "questions on privacy, confidentiality, and data security"--24 hours a day, seven days a week.

According to the Department of Edtech Head Richard Culatta, the hotline is available for both "schools and developers" to get whatever information they need on security practices--no matter how specific or extreme. The trend tends toward schools, however, according to DOE press rep Dave Thomas:
"The vast majority of the questions on the PTAC hotline come from school/district administrators and state officials in both K-12 and higher education. The questions generally relate to student privacy, and vary widely. Just a few topics we've covered recently include questions about whether data can be shared under FERPA in various contexts, advice on how to store and transmit data securely, advice on protecting privacy in public data tables, and questions about school contracting." 

https://www.edsurge.com/n/2014-03-18-doe-offers-student-privacy-and-confidentiality-hotline-service 

Friday, March 7, 2014

Phishing Scam on Netflix May Trick you with Phony Customer Service Reps

The Huffington Post
by Taylor Casti
Posted 03/07/2014

A new phishing scam targeting Netflix subscribers preys on our blind trust of customer service representatives when it comes to our information.

Users being targeted by the scam will see a phony webpage modeled after the Netflix login page. When a user enters Netflix account info, the scam site claims that the user's Netflix account has been suspended due to "unusual activity" and then provides a fake customer service number. When the user calls that number, a representative on the phone recommends a download of "Netflix support software" which is actually remote login software that gives the scammers complete access to your computer. The scammers may also ask for copies of photo IDs or credit cards.

Jerome Segura of Malwarebytes Unpacked first noticed the scam on Feb. 28 and made a handy video to protect customers from falling for it. He told The Huffington Post that users might stumble across the fake site via a link in phishing email, pop-up window, or ad.

Segura says that while he was on the phone with the "rogue representatives," they were busy searching his computer for things like banking information or lists of passwords.

There are plenty of red flags here to warn customers that something is awry, but for those who are too trusting of the voice on the other end of the customer service line, check out Segura's video for highlights from the call.

A good rule to remember is not to be too trusting when it comes to giving out personal information. Avoid letting someone remotely control your computer, don't send pictures of your ID or credit cards over the Internet and be sure to double check URLs in the address bar of your browser. Also, anyone can look up the real Netflix customer service number and see that it doesn't match the scammers' number.

Happy streaming, and stay safe out there.

Thursday, February 6, 2014

Documentary Screening: Terms and Conditions May Apply

Please join Technology Services for a screening of the critically acclaimed data privacy documentary Terms and Conditions May Apply.

Friday, February 14, 2014
11:30a-1:00p
Atkins-Holman Student Commons

Admit it: you don't really read the endless terms and conditions connected to every website you visit, phone call you make, or app you download. But every day, billion-dollar corporations are learning more about your interests, your friends and family, your finances, and your secrets, and they're not only selling the information to the highest bidder, but also sharing it with the government. And you agreed to all of it. This disquieting expose demonstrates how every one of us is incrementally opting-in to a real time surveillance state, click-by-click--and what, if anything, you can do about it.

Wednesday, January 29, 2014

Data Privacy Day--January 28th

The weakest link in data privacy is, well, you
by Frank Catalano

Happy Data Privacy Day! The first round of credit card numbers is on me!

Yes, this is Tuesday, Jan. 28 really is Data Privacy Day in the U.S. and Canada, commemorating the 1981 signing of Convention 108, an international treaty dealing with privacy and data protection. (In Europe, where it originated, it's known as Data Protection Day.)

Safeguarding one's personal data may seem Sisyphusian in the wake of enterprise-level consumer breaches like those recently at Target and Neiman Marcus. But if you, like me, are concerned, I’ve found it helps to unpack the concept of good personal data hygiene into three elements, each with increasing levels of individual control.
After all, to paraphrase and extend Joseph Heller’s Catch-22 observation, if everyone truly is after your personal information, paranoia is just a good strategy. (No matter how much one might whine about password problems.)
Allow me to over-simplify.
1) Security. This is how well-protected the data is wherever it is stored, largely a technology issue. You, personally (unless you work for the NSA), pretty much are SOL on this, unless you understand data transfer protocols, encryption standards, authentication methods, and can direct which of each is used by an organization that holds your personal information.
Forrester Research recently weighed in on the authentication (that is, proving to the system that you are who you say you are, and that you have the right to get in) part in a dizzying-yet-compact report, “Employee and Customer Authentication Solutions,” that bluntly states, “Current user authentication methods are failing organizations badly.” Rather than concluding that entropy will win, it hopefully points to a “massive third generation of innovation” including the rise of smart mobile device methods, and the concept of “responsive design” for authentication that takes into account how someone is accessing the system, any contextual clues as to legitimacy, and overall risk.
It’s somewhat like how TSA determines a traveler is qualified for an expedited security PreCheck, but without the full-body-massage fallback.
2) Privacy. This is less about technical protection, and more about what can be done with the data and how selectively it’s shared, turning it from a technology to a policy matter. And “policy” means groups of sadly fallible humans making rules, whether they’re expressed as government regulations, vendor contracts or Facebook’s ever-morphing terms of use.
Individuals have – and want – more influence here. Nonprofit Common Sense Media this month released a national survey that shows, for example, 90% of U.S. adults are concerned about how “non-educational interests” might be able to get to and use personal information about students. Whether those “interests” actually could get or use it (or even want to) is a separate but equally important matter. Still, another study done by Fordham University notes that a “sizeable plurality” of school districts using web-based services for student data had contract gaps, such as missing privacy policies. (Interestingly, Microsoft helped underwrite this study.) Not to mention that kids interact with consumer sites and apps outside of a school environment.
Apparently a few parents and school administrators may need to study up on tech, or perhaps contract law. As might anyone who relies on another party to store personal information, to make sure assumptions are backed up by documented assurances.
3) Practice. The third element effectively is a mash-up of the first two: how well they are implemented under real-world conditions. And here is where the individual is in the most control and, if recent reports on self-inflicted injuries are any indication, is the most screwed.
A summary of the 2013 IT Risk/Reward Barometer from ISACA (an association of information security professionals) finds that while nine out of ten of us worry that our information will be stolen, half of us use the same two or three passwords across multiple accounts and websites.
While it’s true that many sites don’t make remembering strong passwords easy due to maddening inconsistencies across sites and even across platforms used for a single account, there is no excuse for using, say, what security firm SplashData called the Worst Password of 2013 (123456) or any of the runners-up (password12345678qwerty). These are actual user passwords revealed as the results of data breaches. You know who you are.
It’s similar to how some website administrators never changed the default webserver login from “admin,” and then wondered why their sites were hacked. That happened, too.
So is there any hope that developments in security can help address practice, the weakest individual human link in personal data safety? Especially since we are, by nature, lazy and easily bump up against what we consider tolerable demands on convenience and memory?
“When technology arises that offers direct privacy and security benefits that individuals value, along with removing user experience friction in achieving it, then we’ll see uptake,” observes Eve Maler, who, as principal analyst for security and risk, co-authored the recent Forrester Research report. Responsive design in authentication is one reason for optimism: “The whole goal is inconveniencing the good guys the least, and the bad guys the most,” she says.
Some of those technologies will include our current BFFs, smartphones (such as approaches like PassQi’s, which uses iPhones, QR codes and bookmarklets to authenticate us with sites we choose – and gently advises us to avoid bad or duplicated site passwords). Just remember to also lock said smartphone’s screen, too, with a thumbprint or PIN.
But personal information is not safeguarded in isolation. Rock-solid technology and vigilant practice fails when confronted with a leaky policy for privacy. If you don’t address all three, you’re not really addressing it at all.
Or, to paraphrase another great literary figure, Pogo: We have met the enemy when it comes to personal data safeguards. And he is us.

Monday, January 27, 2014

Data Privacy Month

Data Privacy Month (DPM) is an annual effort to empower people to protect their privacy and control their digital footprint, as well as escalate the protection of privacy and data as everyone's priority. Data Privacy Month will be celebrated in 2014 starting with Data Privacy day on January 28 and running through February 28. Spend the month helping to ensure your campus community is respecting privacy, safeguarding data, and enabling trust.

Data flows freely in today's online world. Everyone--from home computer users to multinational corporations--needs to be aware of the personal data others have entrusted to them and remain vigilant and proactive about protecting it. Being a good online citizen means practicing conscientious data stewardship. Data Privacy Day (January 28th) is an effort to empower and educate people to protect their privacy, control their digital footprint, and  make the protection of privacy and data a great priority in their lives.

Data Privacy Day is led by the National Cyber Security Alliance, a nonprofit, public-private partnership dedicated to cybersecurity education and awareness, and advised by a distinguished advisory committee of privacy professionals.

http://www.staysafeonline.org/data-privacy-day/about/ 

Friday, January 10, 2014

Securing your Home Network

Home networks were relatively simple years ago, perhaps nothing more than a wireless access point and computer or two used to surf the internet or play games online. However, home networks have become increasingly complex. Not only are we connecting more devices to our home networks, but we are doing more things with them. In the January 2014 edition of SANS monthly security awareness newsletter for computer users, OUCH, SANS offers some basic steps for creating a more secure home network.

To view the full newsletter, click here: http://www.securingthehuman.org/newsletters/ouch/issues/OUCH-201401_en.pdf .