Showing posts with label cyberwar. Show all posts
Showing posts with label cyberwar. Show all posts

Wednesday, March 20, 2013

South Korea Computers Crash, Causing Coffee Cash Crisis

"South Korean banks and media report computer network crash, causing speculation of North Korea cyberattack"
Associated Press, via FoxNews.com (March 20, 2013)

"Computer networks at major South Korean banks and top TV broadcasters crashed simultaneously Wednesday, paralyzing bank machines across the country and prompting speculation of a cyberattack by North Korea.

"Screens went blank at 2 p.m., the state-run Korea Information Security Agency said, and more than six hours later some systems were still down...."
Since the United States and South Korea do joint military drills, which annoys North Kora's government, it's possible that North Korea is behind the attack. Then again, maybe not.

United Nations imposed sanctions on North Korea after last month's nuclear test, which gives the North another motive for scrambling South Korean computers.

The good news is that South Korea's government agencies, power plants, and transportation systems weren't affected.

The bad news is that this outage was a cyberattack, not the result of glitchy software or a squirrel's fiery annihilation in a power line's transformer.

Coffee Cash Crisis at Starbucks

South Korea's economy is one of the world's top 20. I doubt that being plunged into a cash-only world for a few hours will do much damage. On the other hand, I'm glad that I wasn't on coffee break in Seol when the ATMs died.
"...Some customers were unable to use the debit or credit cards that many rely on more than cash. At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and lines formed outside disabled bank machines...."
(Associated Press, via FoxNews.com)

Cyberattack: or Really Bad Luck?

Machines break down sometimes. South Korean might have just been unlucky. Very unlucky.

In this case, so many systems going down at the same time seems - - - improbable.

I'm sincerely glad that I don't have the task of figuring out what happened in South Korea. Sorting through technical data may be much easier than separating accurate eyewitness reports from flights of fancy.
"...'It's got to be a hacking attack,' Lim Jong-in, dean of Korea University's Graduate School of Information Security. 'Such simultaneous shutdowns cannot be caused by technical glitches.'

"The Korea Information Security Agency had reported that an image of skulls and a hacking claim had popped up on some of the computers that shut down, but later said those who reported the skulls did not work for the five companies whose computers suffered massive outages. KISA was investigating the skull images as well...."
(Associated Press, via FoxNews.com)

Speculation and Denial

A Korea Communications Commission official said that destructive code might have been spread from servers sending automatic updates and virus patches for security software. The key word is 'might.' Right now, so soon after the event, I'd be very surprised if investigators had traced the problems to their source.

That said, I think it's reasonable to assume that the outage wasn't an accident. North Korea's leadership apparently denies that they're running an Internet warfare unit. Maybe so, but that outfit is still churning out cold-war-style variations on the old 'capitalistic imperialistic warmonger' rhetoric.

The effect their policies have on North Korea's citizens being what it is, I'm not surprised: distracting folks from bread-and-butter issues might seem expedient, and that's another topic.

Back to the dean of Korea University's Graduate School of Information Security:

"Likely," "Probable," and Motive

"...Lim said he believes hackers in China were likely culprits in the outage in Pyongyang, but that North Korea was probably responsible for Wednesday's attack.

" 'Hackers attack media companies usually because of a political desire to cause confusion in society,' he said. 'Political attacks on South Korea come from North Koreans.'..."
(Associated Press, via FoxNews.com)
I'm inclined to agree with dean Lim: someone probably wanted to mess with South Korean media to "cause confusion in society." Or frustration, anyway.

Consequences of today's attack might be a bit more serious than a few frazzled Starbucks customers. I don't think it's unreasonable to think that losing several hours of productivity, directly from out-of-service machines and indirectly from folks being a bit off their game after a disrupted schedule, might have at least a tiny effect on South Korea's economy.

More seriously, South Korea's servers are part of the Internet - so problems there could spread.

Not a Weekend Project

Whoever arranged for today's outage put a lot of effort into it. And, although it doesn't look like investigators know who the attacks planners were: this does seem to be an attack, the first of several.
"...Orchestrating the mass shutdown of the networks of major companies would have taken at least one to six months of planning and coordination, said Kwon Seok-chul, chief executive officer of Seoul-based cyber security firm Cuvepia Inc.

"Kwon, who analyzed personal computers at one of the three broadcasters shut down Wednesday, said he hasn't yet seen signs that the malware was distributed by North Korea.

" 'But hackers left indications in computer files that mean this could be the first of many attacks,' he said.

"Lim said tracking the source of the outage would take months."
(Associated Press, via FoxNews.com)

Coffee Breaks and Power Grids

I like living in the Information Age, but the benefits of fast global communication and continent-spanning power grids come with new problems.

The The Great Northeast Blackout of 1965 only affected 30,000,000 folks. About 100,000,000 people living in Java and Bali lost power in 2005, and back-to-back power failures in India last year set a new record: the July 30 and 31, 2012, events affected 620,000,000 people.

Since coordinating generators and transmission lines on today's scale involves software, 'throwing a monkey wrench' into the system can be done from the other side of the world.

Most of the serious discussion of 'cyberthreats' has focused on hacking into computers that control power grids, or ones holding secure information.

At least as disquieting, I think, is what could happen if someone managed to get into prescription formula databases, or got control of life support systems in a hospital.

Pleasant dreams.

Related posts:

Wednesday, February 6, 2013

Hack Attack: Good News, Bad news, Security, and Freedom

First, the good news. This could have been a lot worse:
"Sophisticated cyber-attack hits Energy Department, China possible suspect"
FoxNews.com (February 4, 2013)

"The Energy Department has been hit by a major cyber-attack, which resulted in the personal information of several hundred employees being compromised and could have been aimed at obtaining other sensitive information, The Washington Free Beacon reports.

"FBI agents are investigating the attacks, which happened two weeks ago, at the Washington-based headquarters. Fourteen computer servers and 20 workstations reportedly were penetrated during the attack....
It looks like the Energy Department's hack attack is about as serious matter as what happened to Sony Playstation back in 2011. (Apathetic Lemming of the North (April 26, 2011) Individuals were affected, and the organization had a public relations headache: but that's as far as the trouble went.

Apparently hackers got information about Energy Department employees. That could be serious for the individuals involved, if folks who steal identities for fun and profit get it. Identity theft is a real problem, and a bit off-topic for this blog.

Politics, Editorial Views, and Motive

I'm not familiar with the Washington Free Beacon, but understand that it's editorial stance is "conservative." That might explain why the service was interested in posting this article: but doesn't mean that the hack attack didn't happen.

Another Employer's Personnel Files Hacked: So What?

The Energy Department handles information that's a tad more important than usernames and passwords for online games. They're interested in solar energy, wind farms, nuclear weapons, and other energy-related tech. (More at energy.gov)

I don't share the reflexive revulsion toward nuclear weapons, and unquestioning enthusiasm over solar power, expressed by some of my contemporaries. On the other hand, on the whole I'd rather have some technical details of America's nuclear weapons stay where it's supposed to be.

Back to that article:
"...While no classified information was compromised, the Free Beacon reports there are indications the hackers could have been seeking access to such data. Chinese hackers may be suspects, as the department is a known target of Beijing -- according to the Free Beacon, the sophistication of the attack indicates the involvement of a foreign government.

"The department includes the National Nuclear Security Administration, which maintains nuclear weapons.

" 'It's a continuing story of negligence,' former Energy Department security official Ed McCallum told the Free Beacon, explaining that the department continues to have security problems despite controlling some of the most 'sophisticated military and intelligence technology the country owns.'..."
(FoxNews.com)
Mr. McCallum might simply be an irate ex-employee, out to make trouble for his former boss, he may be an irate ex-employee who's legitimately concerned about a clueless former boss, or maybe there's another explanation for what he said.

Old-School Skills, Information Age Issues

I think it's quite possible that whoever's making decisions at the Energy Department is well-meaning Washington bureaucrat: who is very good at managing paperwork; diligent in pursuing greater intradepartmental communication; and clueless about the Internet. Folks in top leadership positions tend to be a bit on the old side, and less than familiar with information technology:
Clueless management is funny - in the comics.

Dilbert.com

In the real world, having a boss who doesn't understand why keeping a network safe from hackers could be a big problem.

Being 'Protected'

I think it would be nice if everybody could share information about anything, and do so without being concerned about anyone's safety. I also think it would be nice if everybody would be nice: but that's not the way the world is.

Reality being what it is, there is a need for secrets: and weapons, and that's almost another topic. Folks who decided to kill several thousand people on September 11, 2001, were not nice. What's happened since strongly indicates that outfits like Al Qaeda and the Taliban are still determined to behave badly.

Sadly, they're not the only ones who threaten the safety of the rest of us.

China isn't the same country it was a half-century back: but its leadership still seems to be unwilling to accept folks whose ideas don't follow the 'party line.' China isn't alone, of course. It's easy to see disagreement as a threat.


I'm concerned about threats from outside America. I'm also concerned about Americans who want to 'protect' us from ideas they don't like. And that is another topic. (March 9, 2008)

Related posts:

Thursday, March 1, 2012

"Chinese Hackers" - - - And Keep Reading

The headline is attention-getting. Which headlines are supposed to be. So was the article's lead paragraph:
"Chinese hackers took over NASA's Jet Propulsion Lab, Inspector General reveals"
FoxNews.com (March 1, 2012)

"Chinese hackers gained control over NASA's Jet Propulsion Laboratory (JPL) in November, which could have allowed them delete sensitive files, add user accounts to mission-critical systems, upload hacking tools, and more -- all at a central repository of U.S. space technology, according to a report released Wednesday afternoon by the Office of the Inspector General...."
I've posted about 'cyberwar' and how important it is to keep the wrong people from getting at anything from my credit card number, to launch codes for nuclear missiles.

Simple? Not

The headline's accurate. So is the lead paragraph.

But there's more going on than "could have allowed...." I put a slightly longer excerpt from the article at the end of this post.1

The article links to a nine-page document:
It's not particularly turgid prose. Certainly not compared with some government documents I've slogged through: If you're interested in what's going on, I suggest you read it yourself.

The report has good news, and it's got bad news.

First, the bad news: NASA, and a whole lot of other government and private outfits, could do a lot better when it comes to keeping their data secure. This is hardly 'news.'

Now, the good news: The Office of Inspector General (OIG) and other agencies around the world have started tracking down and dealing with folks who aren't nice when it comes to other people's data.

Turns out, there are a lot of folks who haven't been nice. And they don't fall into one simple category of 'bad guys.'

Conclusions, Crazy and Otherwise

There's a summary of events and actions at the end of that NASA cybersecurity report.

I might be able to take data from that report; pour in assumptions, biases, and a generous helping of paranoia: and claim that a secret cabal (that's the best kind) of Romanians, Estonians, and Texans, are plotting to take over the world by hacking into the accounting systems of Minnesota companies.

That would be - crazy talk.

I could also claim that the report proves that China's leaders are plotting to take over America's computer networks.

That would be - not so much crazy talk, as arguing ahead of facts. 'Way ahead of facts.

I'm not at all comfortable at how many hack attacks on American - and other - computer networks 'just happen' to come from servers in China. I'd like to believe that China's current leadership has gotten past the 'good old days' of Mao's cultural revolution, and want to make China a better place for the folks who live there. I'd also like to believe that everybody could just get along.

But this is the real world: and national leaders don't always have the best interests of their citizens in mind; or a sensible view of what their citizens need. And that's another topic.

Very Cautious Optimism

I insist on seeing some good news in that Cybersecurity report.

Government agencies in America and elsewhere are apparently treating crimes which are committed primarily online as - crimes.

After what look like serious investigations - not just knee-jerk accusations and assumptions - action has been taken. Correctly, if that catastrophic drop in spam was the result of two rogue Internet Service Providers getting shut down.

China's leadership may have decided to join the rest of the world, where it comes to treating online crimes as 'real' crimes. Okay - that's on the strength of just one arrest: but that's a start.

Mr. Martin's Cybersecurity Summary, Summarized

Here's what I got, after parsing out Mr. Martin's "NASA Cybersecurity..."summary:
  • February 2012
    • JPL systems hacked
    • A Romanian national was indicted in the Central District of California
      • Following convictions in Romania for related criminal activity
    • Result: losses of over $500,000 to the Atmospheric Infrared Sounder (AIRS) Program
  • January 2012
    • Unauthorized accesses into numerous systems belonging
      • NASA
      • The Pentagon
      • The Romanian government
      • Commercial entities
    • Romanian authorities a 20-year-old Romanian national for this intrusion
    • Result: products from a variety of NASA scientific research efforts were inaccessible to the general public for a brief period of time
      • No long-term damage to the underlying programs was reported
  • November 2011
    • JPL IT Security reported suspicious network activity involving Chinese-based IP addresses
    • NASA review disclosed that the intruders had compromised the accounts of the most privileged JPL users
      • Giving the intruders access to most of JPL's networks
    • The Office of Inspector General (OIG) continues to investigate this matter
  • November 2011
    • Following an earlier international fraud scheme
      • That compromised more than 4 million computers worldwide
        • Including 135 NASA systems
      • Over $15,000,000 in assets from the operation have been seized
        • So far
    • Indictments announced
      • By the U.S. Attorney's Office for the Southern District of New York
      • Six Estonians
      • One Russian national
  • February 2011
    • Hacked
      • Two NASA systems
      • A Minnesota-based company's pay and accounting system
    • A Texas man pled guilty to wire fraud in Federal court in Minnesota in connection with the crime
    • Result: more than 3,000 registered users were denied access to oceanographic data supplied by NASA for several days. Direct remediation costs in this case exceeded $66,000
  • February 2011
    • Distribution of malware that caused NASA data to be compromised
    • A British citizen was sentenced in England to 18 months' imprisonment for his role
    • Result: about 2,000 NASA e-mail users were infected with this malware as part of a worldwide computer fraud scheme
  • December 2010
    • Following the hacking of seven NASA systems
      • Many containing export-restricted technical data
    • A Chinese national was detained
      • By Chinese authorities
      • For violations of Chinese Administrative Law
    • This detention
      • Followed
        • An OIG investigation
        • Lengthy international coordination efforts
    • Significance: "This case resulted in the first confirmed detention of a Chinese national for hacking activity targeting U.S. Government agencies. Seven NASA systems, many containing export-restricted technical data, were compromised by the Chinese national."
  • March 2009
    • Following unauthorized intrusions into NASA JPL systems
      • Two computer systems used to support
        • NASA's Deep Space Network
        • Several Goddard Space Flight Center systems
    • Italian authorities
      • Raided the home of an Italian national suspected of taking part in the intrusions
      • Suspect the individual of being a member of a hacker group responsible for an Internet fraud and hacking schemes
    • Result: Good question
      • NASA officials assured us that no critical space operations were ever at risk
  • Other incidents
    • (No date given)
      • 53 NASA systems were affected by the criminal activity sponsored by McColo Inc.
        • None of the systems were mission critical
      • Twenty-one NASA systems compromised as part of criminal activity hosted by rogue ISPs
      • OIG investigations followed
        • Rogue ISPs were identified by NASA OIG and other law enforcement agencies as a major source of
          • Child pornography
          • E-mail spam
          • Stolen credit cards
          • Malicious software
        • Result:
          • Shutdown of rogue Internet Service Providers (ISPs)
            • "McColo Inc."
            • "Triple Fiber Networks,"
          • The U.S. District Court in the Northern District of California ordered McColo Inc. to pay the Federal Government a $1.08 million civil judgment
          • Worldwide reduction in spam of approximately 50 percent shortly after the ISPs were taken offline
    • 2009
      • Following theft of
        • Cisco Systems, Inc., proprietary code
        • Numerous intrusions into NASA systems
          • Including Ames Research Center's Super Computing Center
      • A Swedish citizen indicted in 2009
      • Swedish and U.S. authorities agreed to have the subject tried in Sweden
      • The subject
        • Was found guilty
        • A "formal criminal history" was filed by Swedish authorities
      • Result: several instances when the Ames Research Center's Super Computing Center was temporarily shutdown to clean up after the intrusions
        • Losses to NASA were estimated at over $5,000,000
Relate posts:
In the news:

1Excerpt from the news:
"Chinese hackers took over NASA's Jet Propulsion Lab, Inspector General reveals" Foxnews.com (March 1, 2012) "Chinese hackers gained control over NASA's Jet Propulsion Laboratory (JPL) in November, which could have allowed them delete sensitive files, add user accounts to mission-critical systems, upload hacking tools, and more -- all at a central repository of U.S. space technology, according to a report released Wednesday afternoon by the Office of the Inspector General. "That report revealed scant details of an ongoing investigation into the incident against the Pasadena, Calif., lab, noting only that cyberattacks against the JPL involved Chinese-based Internet Protocol (IP) addresses. "Paul K. Martin, NASA's inspector general, put his conclusions bluntly. " 'The attackers had full functional control over these networks,' he wrote.... "...Beyond a wealth of exploration programs, such as the recent GRAIL mission to study the moon and the upcoming Mars Science Laboratory, JPL manages the Deep Space Network, a network of antenna complex. "Martin released written testimony about the attacks in the report 'NASA Cybersecurity: An Examination of the Agency;s Information Security,' presented to the House Science, Space and Technology Committee investigations panel on Wednesday. It details a host of security lapses and breaches of protocol at the space agency...."

Friday, July 15, 2011

"Digital Sabre-Rattling," "Complex Legal and Cultural Issues," and Heat-Related Deaths

Part of the first paragraph in an op-ed makes my point pretty well:
"...The Pentagon revealed an unclassified version of its 'Strategy for Operating in Cyberspace.' And despite a drumbeat of scare talk and digital sabre-rattling in Washington, the document takes a measured, reasonable approach - focusing on good network hygiene and data-sharing, rather than bombing hackers into submission...."
(Noah Shachtman, Danger Room, Wired (July 14, 2011)
I've put longer excerpts at the end of this post.1

I've also archived a copy of that unclassified document ("DoD Strategy for Operating in Cyberspace (DSOC)" (Department of Defense (July 14, 2011)), along with the text of their news release.2

"Digital Sabre-Rattling?"

I'm not sure if what the vice chairman of the Joint Chiefs of Staff had to say is part of that "drumbeat of scare talk and digital sabre-rattling in Washington" cited by Mr. Shachtman. General Cartwright's attitude certainly isn't a sort of nice, deferential, conciliatory posture toward folks who want to kill Americans.
"...'For the Department of Defense, our networks are really our lifeblood,' Marine Gen. James Cartwright, vice chairman of the Joint Chiefs of Staff, told reporters in an interview prior to Lynn's release of the new strategy....

"...'If it's OK to attack me and I'm not going to do anything other than improve my defenses every time you attack me, it's difficult' to stop that cycle, Cartwright said. 'There is no penalty for attacking (the U.S.) right now.' He added that a number of complex legal and cultural issues need to be sorted out before the Pentagon can devise a comprehensive offensive strategy.

"In response to an audience member's question after his speech, Lynn the White House could be expected to consider using military force in response to a cyberattack 'if there is massive damage, massive human losses, significant economic damage.'..."
(Associated Press, via FoxNews.com).3

Hack Attack: What's the Big Deal?

So far, major hack attacks on American targets have been - rather intellectual. Information has been stolen, folks have found it difficult to use a few online resources, and that's about it.

Even the personal data that's been stolen hasn't been all that serious. Sure, credit card numbers, email addresses, and financial records that were supposed to be personal, private, and not in the hands of whoever some anonymous hacker sold them to, went missing. But we're told that it's okay.

Since there apparently hasn't been a massive wave of identify theft, maybe those reassurances are true.

I certainly hope that's the case.

Sooner or later, though, someone's likely to try taking down the North American power grid. Some folks in China did a serious study of how that could be accomplished. Last year we were told that it's okay, though: the study was purely theoretical. Or maybe a big misunderstanding. Or something. That may be true. (March 20, 2010)

Major Blackout: What to Expect

Let's see what would happen if someone did decide to pull the plug on large parts of North America. Here's a sample of what we could expect:
"Stay safe during West Mich.'s heat wave"
Kyle Underwood, WOOD TV8 (July 15, 2011)

"...More Americans suffer heat-related deaths each year than from any other weather disaster. Many heat-caused fatalities are elderly folks who do not have access to air conditioning or a cooling center. Heat stroke and dehydration are also far more likely during heat waves...."
"Memphis man, 72, becomes third victim of summer heat"
Jody Callahan, The Commercial Appeal (Memphis, Tennessee) (July 14, 2011)

"A 72-year-old man succumbed to the high temperatures Wednesday, becoming the third heat-related death so far this summer in the Memphis area, officials said today...."
"Heat blamed in five Alabama deaths since May"
Associated Press, via The Gadsden Times (July 14, 2011

"At least five deaths are being blamed on the hot weather in Alabama, and health officials said Thursday they fear the number could climb as temperatures soar...."
"Second heat-related death in St. Louis"
STLtoday.com (July 14, 2011)

"An 80-year-old woman whose air conditioner wasn't working properly became the city's second heat-related death this year, officials said Thursday...."
"With many hot days to come, suspected heat deaths hit nine"
Alan Bavley, The Kansas City Star (July 13, 2011 )

"With most of the summer still ahead, and a dangerously hot weekend in the forecast, the Kansas City area on Wednesday added another possible heat-related death, bringing the year's total to nine...."

"A Drumbeat of Scare Talk?"

I don't think that some nation, or terrorist group, will hack into the systems that maintain North America's electrical power supply: Almost certainly not today. Or even this weekend. Probably not this month. Or even this year.

Besides, six months from now, we wouldn't have to worry about not having power for air conditioners. Here in Minnesota, at least, it'd be power for heating systems that I'd be concerned about.

Maybe the power would come back on in a little less than 24 hours, like it did in the part of town where I live, after a storm went through recently. If that was the case, not many folks would die. Probably.

On the other hand, no power for days, weeks, maybe a month? During summer? Or winter? I'm pretty sure that quite a few folks would survive. Particularly those of us who are comparatively young, and healthy, and don't live in cities, and have access to basements. Or caves.

The rest of you? Well, maybe you'd survive. Or, maybe not.

Is recognizing that folks die when it gets too hot - or too cold - "a drumbeat of scare talk?" I'd say it depends on how the ideas are presented.

Me? I'm trying to point out that there really is a threat. And that some folks, like the lot that run Al Qaeda and the Taliban, don't seem to respond all that well to polite requests.

Related posts:
News and views:

1Excerpts from yesterday's news and views:
"Pentagon Makes Love, Not Cyber War, in New Strategy"
Noah Shachtman, Danger Room, Wired (July 14, 2011)

"For one day, at least, you can call off the cyberwar. The Pentagon revealed an unclassified version of its 'Strategy for Operating in Cyberspace.' And despite a drumbeat of scare talk and digital sabre-rattling in Washington, the document takes a measured, reasonable approach - focusing on good network hygiene and data-sharing, rather than bombing hackers into submission.

"The question is whether this public summary conveys what's actually in the classified strategy, or reflects the real mood of the Department of Defense.

" 'DoD would like to be much more aggressive in what it says and how it acts,' says a source familiar with the development of the strategy. 'But that tendency to be aggressive has been reined in by the State Department, Treasury, and the White House, and not in an unreasonable way.'

"Listen to the talk inside the Washington Beltway - and especially within the Pentagon — and you'd think hackers were about to reach their hands through our computers, and strangle us all in our sleep....

"Pentagon Discloses Largest-Ever Cyber Theft"
Associated Press, via FoxNews.com (July 14, 2011)

"The Pentagon on Thursday revealed that in the spring it suffered one of its largest losses ever of sensitive data in a cyberattack by a foreign government. It's a dramatic example of why the military is pursuing a new strategy emphasizing deeper defenses of its computer networks, collaboration with private industry and new steps to stop "malicious insiders."

William Lynn, the deputy secretary of defense, said in a speech outlining the strategy that 24,000 files containing Pentagon data were stolen from a defense industry computer network in a single intrusion in March. He offered no details about what was taken but in an interview before the speech he said the Pentagon believes the attacker was a foreign government. He didn't say which nation.

"We have a pretty good idea" who did it, Lynn said the interview. He would not elaborate.

Many cyberattacks in the past have been blamed on China or Russia. One of the Pentagon's fears is that eventually a terrorist group, with less at stake than a foreign government, will acquire the ability to not only penetrate U.S. computer networks to steal data but to attack them in ways that damage U.S. defenses or even cause deaths....
"
2Department of Defense News Release
IMMEDIATE RELEASE
No. 608-11
July 14, 2011

"DOD Announces First Strategy for Operating in Cyberspace

"The Department of Defense released today the DoD Strategy for Operating in Cyberspace (DSOC). It is the first DoD unified strategy for cyberspace and officially encapsulates a new way forward for DoD's military, intelligence and business operations.

"'It is critical to strengthen our cyber capabilities to address the cyber threats we're facing,' said Secretary of Defense Leon E. Panetta. 'I view this as an area in which we're going to confront increasing threats in the future and think we have to be better prepared to deal with the growing cyber challenges that will face the nation.'

"Reliable access to cyberspace is critical to U.S. national security, public safety and economic well-being. Cyber threats continue to grow in scope and severity on a daily basis. More than 60,000 new malicious software programs or variations are identified every day threatening our security, our economy and our citizens.

"“The cyber threats we face are urgent, sometimes uncertain and potentially devastating as adversaries constantly search for vulnerabilities,” said Deputy Secretary of Defense William J. Lynn III. 'Our infrastructure, logistics network and business systems are heavily computerized. With 15,000 networks and more than seven million computing devices, DoD continues to be a target in cyberspace for malicious activity.'

"The DoD and other governmental agencies have taken steps to anticipate, mitigate and deter these threats. Last year, DoD established U.S. Cyber Command to direct the day-to-day activities that operate and defend DoD information networks. DoD also deepened and strengthened coordination with the Department of Homeland Security to secure critical networks as evidenced by the recent DoD-DHS Memorandum of Agreement.

" 'Strong partnerships with other U.S. government departments and agencies, the private sector and foreign nations are crucial,' said Lynn. 'Our success in cyberspace depends on a robust public/private partnership. The defense of the military will matter little unless our civilian critical infrastructure is also able to withstand attacks.' "
3Longer excerpt:
"...'For the Department of Defense, our networks are really our lifeblood,' Marine Gen. James Cartwright, vice chairman of the Joint Chiefs of Staff, told reporters in an interview prior to Lynn's release of the new strategy....

"...Lynn said intrusions in the last few years have compromised some of the Pentagon's most sensitive systems, including surveillance technologies and satellite communications systems. Penetrations of defense industry networks have targeted a wide swath of military hardware, including missile tracking systems and drone aircraft, he said.

"In Cartwright's view, a largely defensive approach to the problem is inadequate. He said the Pentagon currently is focused 90 percent on defensive measures and 10 percent on offense; the balance should be the reverse, he said. For the federal government as a whole, a 50-50 split would be about right, Cartwright argued.

" 'If it's OK to attack me and I'm not going to do anything other than improve my defenses every time you attack me, it's difficult' to stop that cycle, Cartwright said. 'There is no penalty for attacking (the U.S.) right now.' He added that a number of complex legal and cultural issues need to be sorted out before the Pentagon can devise a comprehensive offensive strategy.

"In response to an audience member's question after his speech, Lynn the White House could be expected to consider using military force in response to a cyberattack 'if there is massive damage, massive human losses, significant economic damage.'..."
(Associated Press, via FoxNews.com)

Saturday, June 11, 2011

IMF Hacked, Again - or - 'This isn't Cyberwar: It Just Acts Like Cyberwar'?!

I really hope that the key people who may have clicked the wrong link, or opened the wrong attachment, are a trifle less clueless than Dilbert's manager:



Still, there have been a lot of hack attacks so far this year.

Big ones:
  • Sony
  • Lockheed Martin
  • Oak Ridge
  • L-3 Communications
  • Grumman
    (see June 1, 2011)
Now we hear that the IMF's network has been compromised.

Again.

I hope I don't seem overly-concerned: but it's hard for me to shake the impression that all is not well with corporate and government information networks. Sure: Hacking Sony's Playstation database isn't quite like the International Monitory Fund network leaking. I include Sony's cyber-security woes in that list, because ideally a company as savvy as Sony shouldn't have let that happen.

Something, I think, has gone wrong with too many major commercial and government networks this year.

So, do I think it's time to run in circles and scream like a demented cat? No: That does not appear to be a reasonable approach.

On the other hand, I very sincerely hope that the White House cyber security coordinator has some response in mind. Besides calling cyber war a "turbo metaphor:" one that doesn't quite fit the sort of espionage we've been seeing. I think he's got a point, by the way, about staying calm:Here's what got me started with this post:
"IMF hit by 'very major' cyber security attack"
US & Canada, BBC News (June 11, 2011)

"The International Monetary Fund (IMF) says it has been targeted by a sophisticated cyber attack.

"Officials at the fund gave few details but said the attack earlier this year had been 'a very major breach' of its systems, the New York Times reports.

"Cyber security officials said the hack was designed to install software to create a 'digital insider presence'.

"The IMF, which holds sensitive economic data about many countries, said its operations were fully functional.

"The cyber attack took place over several months, and happened before former IMF chief Dominique Strauss-Kahn was arrested over sexual assault charges...."

"...A cyber security expert told Reuters the infiltration had been a targeted attack, which installed software designed to give a nation state a 'digital insider presence' at the IMF.

" 'The code was developed and released for this purpose,' said Tom Kellerman, who has worked for the Fund...."

'Epidemic' Sounds Dramatic

I think there are a whole lot of hack attacks happening - major ones - this year. I also am a little cautious when someone uses emotive terms like "epidemic."

Still, these anonymous "experts" may be right.
"Targeted cyber attacks an 'epidemic'"
Maggie Shiels, Technology, BBC News (June 2, 2011)

"The targeted attack used by hackers to compromise e-mail accounts of top US officials is reaching 'epidemic' proportions, say security experts.

"The scam, known as spear phishing, was used in a bid to get passwords of Gmail accounts so they could be monitored.

"Via a small number of customised messages it tries to trick people into visiting a web page that looks genuine so users type in login names.

"Such attacks are often aimed at top officials or chief executives.

"Such attacks are not new, say security professionals, but they are becoming more commonplace.

" 'What is happening more and more is the targeting of a couple of high value individuals with the one goal of acquiring valuable information and valuable data,' said Dan Kaminsky, chief scientist at security firm DKH...."

'This isn't War - It Just Acts Like War?!'

Or, famous last words?
"Cyber war threat exaggerated claims security expert"
Maggie Shiels, Technology, BBC News (February 16, 2011)

"The threat of cyber warfare is greatly exaggerated, according to a leading security expert.

"Bruce Schneier claims that emotive rhetoric around the term does not match the reality.

"He warned that using sensational phrases such as 'cyber armageddon' only inflames the situation.

"Mr Schneier, who is chief security officer for BT, is due to address the RSA security conference in San Francisco this week

"Speaking ahead of the event, he told BBC News that there was a power struggle going on, involving a 'battle of metaphors'.

"He suggested that the notion of a cyber war was based on several high-profile incidents from recent years.

"They include blackouts in Brazil in 1998, attacks by China on Google in 2009 and the Stuxnet virus that attacked Iran's nuclear facilities.

"He also pointed to the fallout from Wikileaks and the hacking of Republican vice-presidential candidate Sarah Palin's e-mail.

" 'What we are seeing is not cyber war but an increasing use of war-like tactics and that is what is confusing us...'..."

"...His point of view was backed by Howard Schmidt, cyber security co-ordinator for the White House.

" 'We really need to define this word because words do matter,' said Mr Schmidt.

" 'Cyber war is a turbo metaphor that does not address the issues we are looking at like cyber espionage, cyber crime, identity theft, credit card fraud...."
Okay: no turbo metaphors.

The IMF has been hacked. Again.

American defense contractors have been hacked. Several Times. This year. And the year isn't half-over yet.

Still, it could be worse.

Hey, the North American power grid is still working: right?

So, hey: how bad can it get? (June 1, 2011)

Like I said: Famous last words?

Related posts:
In the news:

Monday, June 6, 2011

China to Google: 'Shut Up Or We'll Hurt You'

Why would anybody want to do business with China?

For the same reason that applies anywhere else: to make a profit. China is a huge country: in terms of geography, population, and now economics.1

Huge Market, Huge Problems

I think a publicly-owned international company might have trouble explaining to its stockholders why it wasn't trying to get a piece of the Chinese market for whatever goods or services it offered.

On the other hand, doing business in China means deciding to put up with the sort of interest the country's leaders take in what their subjects say, do, and think. Or deciding that enough is enough, and pulling out.

If it's so bad, why don't we hear more about the Party's zeal for control and conformity?

I think Google's experience shows why so many international firms stay politely silent:
"Google has become a 'political tool' vilifying the Chinese government, an official Beijing newspaper said on Monday, warning that the U.S. Internet giant's statements about hacking attacks traced to China could hurt its business....

"...Last week, Google said it had broken up an effort to steal the passwords of hundreds of Google email account holders, including U.S. government officials, Chinese human rights advocates and journalists. It said the attacks appeared to come from China....

"...By saying that Chinese human rights activists were among the targets of the hacking, Google was 'deliberately pandering to negative Western perceptions of China, and strongly hinting that the hacking attacks were the work of the Chinese government,' the People's Daily overseas edition, a small offshoot of the main domestic paper, said in a front-page commentary....

"...'Google should not become overly embroiled in international political struggle, playing the role of a tool for political contention," the paper added.

" 'For when the international winds shift direction, it may become sacrificed to politics and will be spurned by the marketplace,' it said, without specifying how Google's business could be hurt....

"...In February, overseas Chinese websites, inspired by anti-authoritarian uprisings across the Arab world, called for protests across China, raising Beijing's alarm about dissent and prompting tightened censorship of the Internet.

"China already blocks major foreign social websites such as Facebook and Twitter."
(Reuters)

Related posts:
In the news:

1 China's gross domestic product, per person, is about $7,600 - not quite on a par with America's $47,200, or Saudi Arabia's $24,200, but well beyond Nicaragua's $3,000 per capita GDP. And China's per capita GDP is growing. 1 It isn't the economic disaster area of the Cold War world.
"Since the late 1970s China has moved from a closed, centrally planned system to a more market-oriented one that plays a major global role - in 2010 China became the world's largest exporter...."
(China, CIA World Factbook)
I think that's all good news. I want China to be wealthy, and for individuals in China to have large disposable incomes. I'll admit to having slightly selfish motives.

International trade existed before there were nations, which lets archaeologists study the economics of ancient cultures - and that's another topic. We're more obviously connected to each other now, I think - and "global economy" is more than a nifty phrase for politicos and journalists.

The way I see it, rich people can buy more stuff than poor people - and are more likely to have money they're willing to lend to entrepreneurs. China is a huge market today. If folks living there were as wealthy as your average Saudi citizen or American, some might decide to come to Minnesota for fishing or winter sports: which would help the economy here.

Sources: CIA World Factbook, China (updated on May 26, 2011), Nicaragua (updated on May 26, 2011), Saudi Arabia (updated on May 26, 2011), United States (updated May 26, 2011).

Saturday, June 4, 2011

Gmail, China, Knee-Jerk Response, and the Information Age

I ran into a news item last night. The focus was on U.S. Defense Secretary Robert Gates, his Chinese counterpart General Liang Guanglie, and what Gates said about China-United States relations. The two men were at an Asia-Pacific annual security conference ("talkfest" is how the article put it): called the Shangri-La Dialogue, of all things.

The latest hack attack coming from servers in China came up, briefly.

Hackers and Imperialist Capitalist Aggressor Warmonger Running Dogs

Times change. I haven't heard diplomatic boilerplate like "capitalist aggressor" for quite a while. Being away from college probably helps, but I think many folks have realized that it's not the 19th century any more, and class struggle just isn't what it used to be. And that's another topic.

Some things haven't changed so much, though.

First, about the latest hack attack:
"There is a lot of talk--and diplomatic tension--this week related to reports that attacks originating from China have breached Google Gmail accounts, including those of senior US government officials. The focus is on e-mail, and whether or not e-mail accounts were hacked, but a breached Gmail account is a much bigger prize than just the e-mail account it is attached to.

"Google claims that the spear phishing attacks that targeted Gmail accounts of White House staff, and successfully exposed accounts of senior US government officials, high-ranking military personnel, and political activists, originated from China. China denies any state-sponsored involvement in the attacks, and the FBI is investigating...."
(PCWorld Business Center)1
I think it's possible that Google and China's leaders are right. I think it's very likely that Google traced the hack attack to servers in China: although I'll admit that Google could, in principle, be faking the attack's source. I don't think that's likely, but is is possible.

As for China's response to news that their servers hosted a hack attack? Again?

According to China's military, it is the work of Yankee imperialists. That's not quite the way they put it, but that's the basic idea:
"...A new irritant was introduced this week, with allegations that computer hackers in China had compromised the personal Gmail accounts of several hundred people, including U.S. government officials, military personnel and political activists.

"The Chinese military tried to direct the spotlight off those allegations Friday, with accusations that the U.S. is launching a global 'Internet war' to bring down Arab and other governments.

"The FBI said it was investigating Google's allegations, but no official government email accounts have been compromised. Google said all the hacking victims have been notified and their accounts have been secured.....
(Associated Press, via Foxnews.com2) [emphasis mine]
Again, China's line seems to be that "the U.S. is launching a global 'Internet war' to bring down Arab and other governments."

That's probably good enough for folks who believe that the CIA blew up New York City's World Trade Center. After all these decades, though, it sounds like the same tired old 'American aggressor warmonger' stuff that cluttered the news in my youth.

A Country's Servers aren't a Country's Government

Since China is one of the world's more tightly-managed countries, in my opinion, I find it a little hard to believe that hackers have just happened to use Chinese servers for hack attacks - for years - and that the country's leadership doesn't know it's happening and can't stop it anyway.

Still, it's possible.

Particularly since I can easily imagine that it's in China's interests to get access to networks in other countries, for either espionage or sabotage, and blame Yankee imperialism.

China's response may simply be knee-jerk xenophobia: the sort of thing that had right-wing loonies blaming whatever they didn't like on the commies, back in 'the good old days.' I remember the real "Happy Days," by the way - and don't, ever, want to go back.

Or, the folks running China may not be the ones who planned and executed all those hack attacks. China's leaders may be aware that the attacks come from servers in their country - and not be able to stop whoever's behind the hacking. If that's the case, they may simply be embarrassed: and desperately want the problem to belong to someone else.

I think it's a good idea to remember that a national government doesn't necessarily control everything that happens within its borders: no matter how much the leaders want to.

Real Threat, Proportional Response

It's entirely possible that no one person or organization is behind attacks on the World Bank, Gmail, Sony, and all the rest. I think it's quite possible that there is no one motive behind the hacking.

My understanding is that there's a hot - if unethical and illegal - market for the sort of data that has quite possibly been stolen. That would make the hacks a new version of burglary. And, most likely, a private-sector effort.

Governments have their own motives.

What's happened in Tunisia, Egypt, Bahrain, Syria, Libya, and elsewhere shows what can happen when old-school leaders lose control of their subjects. My guess is that Iran's rulers are developing a 'just us' intranet to keep the 'Arab spring' from spreading east. The Ayatollahs have nice-sounding motives: they want to 'protect' Iranians from foreign influences.

In my opinion, Iran's leadership isn't the only outfit that's scared of the Information Age. And for good reason. I've gone over that before:I think it's likely that some folks have idealistic reasons for hacking into corporate and government networks. Sometimes I even sympathize - a little - with the ideas they support. Like freedom of information. Which is emphatically not the same as thinking that what they're actually doing is right.

In a way, it's a sort of 'with friends like these, who needs enemies?' situation. A case in point:
"A hacker group has claimed responsibility for defacing the PBS.org website, the Fox.com site, and the Sony network, posting images of defaced websites and stolen databases and emails to its website....

"...Pike linked the hacker group Lulz to Anonymous, the 'hacktivist' collective that -- in the name of the freedom of information -- has hacked numerous websites, wrestled with security firms and made public a decrypted version of the cyberworm that crippled Iran's nuclear power program...."
(Jeremy A. Kaplan, FoxNews.com (June 2, 2011))
According to the article, Pike's considering turning himself in, before law enforcement shows up with a warrant. That's a good idea, in my opinion. Blaming Yankee imperialism may still work as an excuse in diplomacy: but American law enforcement is, in my experience, more interested in facts than finger-pointing.

As I said before, I think it's possible that a server in China could have been used for hack attacks, without the Chinese government being involved.

Determining how likely that is - and whether that's what's actually been happening - is a job I'm profoundly grateful belongs to someone else.

If it turns out that the Beijing bosses are responsible for the hack attacks, I suspect and hope that America's leaders will try to sort the mess out diplomatically. Not because I think the folks who are still occupying Tibet are a bunch of really nice guys who are just misunderstood. It's a matter of proportional response, and how many folks who weren't responsible could get hurt or killed in a military operation.

If the North American power grid goes down this winter? That's something else. (June 1, 2011)

China, Assumptions, and Living in the Information Age

I've been criticized for not having the proper attitude toward China: and not being politely silent.3 It's a familiar reaction. Commie-hunters acted that way in the McCarthy era (January 9, 2010); professors did the same, a few decades later; and I'm don't think trying to impose ideological purity is a good idea - no matter whose ideas are being shoved down my throat.

I also think it's a bad idea to assume that 'foreigners,' 'commies,' 'the military-industrial complex,' 'Big cheese,' or any other standard-issue bad guys are 'really behind' any particular issue. (January 14, 2009)

Finally, I think that these are trying times for old-school autocrats: and anybody who had a privileged position before information technology made it possible for folks to share ideas - without permission from their 'betters.'

I like the comparatively open marketplace of ideas we have today: but then, I don't mind people having access to dangerous technology. Like LP gas, guns, or computers. (June 27, 2008)

Related posts:
News and views:

1 Excerpt from news and views:
"Putting a positive spin on a sometimes stormy relationship, U.S. Defense Secretary Robert Gates said Friday that military ties with China are 'on a more positive trajectory' but need further strengthening....

"...The main elements of friction remain, however. China still claims control of waters the U.S. considers international. Chinese ambition for influence in Southeast Asia and elsewhere still makes smaller nations uneasy, while Beijing dislikes the heavy U.S. naval presence in Asian waters and builds up its military with weaponry only logically intended for use against the U.S.

"A new irritant was introduced this week, with allegations that computer hackers in China had compromised the personal Gmail accounts of several hundred people, including U.S. government officials, military personnel and political activists.

"The Chinese military tried to direct the spotlight off those allegations Friday, with accusations that the U.S. is launching a global 'Internet war' to bring down Arab and other governments.

"The FBI said it was investigating Google's allegations, but no official government email accounts have been compromised. Google said all the hacking victims have been notified and their accounts have been secured.....

"...Gates and Liang met on the sidelines of the Shangri-La Dialogue, an annual security talkfest attended by defense officials from across the Asia-Pacific region. On Saturday Gates was delivering an address to the conference before continuing an around-the-world journey that is his final trip before retiring June 30...."
(Associated Press via FoxNews.com)
1Excerpts from news and views:
"There is a lot of talk--and diplomatic tension--this week related to reports that attacks originating from China have breached Google Gmail accounts, including those of senior US government officials. The focus is on e-mail, and whether or not e-mail accounts were hacked, but a breached Gmail account is a much bigger prize than just the e-mail account it is attached to.

"Google claims that the spear phishing attacks that targeted Gmail accounts of White House staff, and successfully exposed accounts of senior US government officials, high-ranking military personnel, and political activists, originated from China. China denies any state-sponsored involvement in the attacks, and the FBI is investigating.

"The Gmail e-mail accounts are getting all of the attention. Catalin Cosoi, head of the BitDefender Online Threats Lab, notes in a blog post, 'Just as in the previous attack against the Gmail service, we can assume that cyber-criminals went after sensitive documents the users might have inadvertently forwarded from their business inboxes.'

"But, it would be more accurate to say that Google accounts are being targeted or compromised--not just Gmail. Depending on the extent the hacked account relies on Google, there is potentially much more at stake than just the documents that might be forwarded as a file attachments from Gmail. There is no differentiation between hacking a Gmail account, and hacking the rest of the diverse array of Google services....

"...If the victim actually uses Google Docs, the attacker will have access to all documents, spreadsheets, presentations, forms, and drawings stored online by the victim--not just the ones that might have been included as a file attachment in an e-mail.

"Accessing Google Maps could yield valuable information as well. Most users enter a home address as the default location to save time when searching for driving directions....

"...It is up to Google, and China, and the FBI to get to the bottom of whether the compromised accounts are a state-sponsored act of international espionage, or just the work of run-of-the-mill spear phishing cyber-criminals. But, regardless of who is behind the attack, or what the underlying motives are, there is more than just e-mail at stake."
(PCWorld Business Center)
2 Excerpt from news and views:
"Putting a positive spin on a sometimes stormy relationship, U.S. Defense Secretary Robert Gates said Friday that military ties with China are 'on a more positive trajectory' but need further strengthening....

"...The main elements of friction remain, however. China still claims control of waters the U.S. considers international. Chinese ambition for influence in Southeast Asia and elsewhere still makes smaller nations uneasy, while Beijing dislikes the heavy U.S. naval presence in Asian waters and builds up its military with weaponry only logically intended for use against the U.S.

"A new irritant was introduced this week, with allegations that computer hackers in China had compromised the personal Gmail accounts of several hundred people, including U.S. government officials, military personnel and political activists.

"The Chinese military tried to direct the spotlight off those allegations Friday, with accusations that the U.S. is launching a global 'Internet war' to bring down Arab and other governments.

"The FBI said it was investigating Google's allegations, but no official government email accounts have been compromised. Google said all the hacking victims have been notified and their accounts have been secured.....

"...Gates and Liang met on the sidelines of the Shangri-La Dialogue, an annual security talkfest attended by defense officials from across the Asia-Pacific region. On Saturday Gates was delivering an address to the conference before continuing an around-the-world journey that is his final trip before retiring June 30...."
(Associated Press via FoxNews.com)
3 Comments from "Tibet: Fifty Years of Chinese Liberation, and Counting" (March 10, 2009):
"Anonymous said...

"If you are outside of Tibet, just leave Tibet alone, let Tibetan live by themselves, please love your land where you live and shut up. If Dalai was right, a pig could fly.
"March 10, 2009 3:45 PM

"Brian, aka Nanoc, aka Norski said...

"Anonymous,

"If 'Tibetan live by themselves' I might. However, since Tibet was invaded about fifty years ago, and Chinese troops are now stationed to keep the Han shopkeepers safe and Tibetans in line, and quite a number of Tibetans don't like the situation: I will not 'shut up.'

"Kudos, though, at being comparatively civil about it. Particularly in comparison with what may have been another of the throng of Anonymouses out there, responding to 'Today's Main Event: Protesters vs. the Olympic Torch in San Francisco' (April 9, 2008).

"That Anonymous's comment, in full:
"Anonymous said...

"Don't pretend that you know a lot about history. Tibet is still a An English TRANSLATION name as same as Xizang. Now that you don't like China, you can call Xiazang any name you want.
"Suggest you goto a library to read a little more about Tibet then comment on this "Independence", though suggesting going to library is often a mother's duty.
"April 26, 2008 7:54 PM
"March 10, 2009 6:05 PM
"Politics and the Future said...

"China is not my focus in the war on terror only in my economic studies is it a bigger focus for me.

"But I do have to say one thing, with a growing nation could China become a new superpower? could they develop weapons of mass destruction? I know I know I sound like a conspiratist but I'm not. I am only asking.
"I believe they are going to gain more power both militarily and economically.

"March 10, 2009 6:59 PM

"Anonymous said...

"Please pay more attention to your own business. Never lavish your sympathy on Dalai. If you turn blind eyes to the truth and still whitewash a serf owner as your spiritual leader, I would say nothing any more. What do you think if you know those old noble owner picked serfs' eyes and striped their skin for punishment ? They asked serf to take their shit as medicine. How do you feel about it? These only happened several decades ago under Dalai's rule in Tibet. Where is your conscience. How could you depict it as a shangrila? Please look back to the documentary which your western media took before 1990's. If you think you are god and don't need to read, I go.

"March 10, 2009 8:04 PM

"Brian, aka Nanoc, aka Norski said...

"Anonymous #2, or maybe the same Anonymous,

I know that Tibet isn't Shangri-La (Lost Horizon is a pretty good movie, though - so is Star Wars). Live
[!] isn't the movies.

"I do, though, seem to have hit a nerve.

"Apparently, one is not supposed to discuss, or mention, the liberation of Tibet - except in glowing terms.

"Anybody interested in the Chinese side of this issue could do a lot worse than reading that op-ed I linked to.

"This isn't just about the Dalai Lama, by the way: the new overlords of Tibet may not be that big an improvement over the monks they displaced.
"March 10, 2009 8:11 PM

"Brian, aka Nanoc, aka Norski said...

"Politics and the Future,

"I think I followed that comment.

"China's nuclear weapons program began, as far as can be determined, in the mid-1950s. At this time, they almost certainly have hundreds, but not thousands, of nuclear bombs in their stockpile. Chinese leaders have repeatedly pledged to not use nuclear weapons first in a confrontation. ("Weapons of Mass Destruction (WMD) - Nuclear Weapons" GlobalSecurity.org)

"I'm inclined to believe Chinese leaders on this point. After the debacle we call the Cultural Revolution, Chinese leadership has shown few to no suicidal tendencies.

"(North Korea with nukes is a whole different ball of wax.)

"Not that I have unwavering confidence in the good will of the Chinese government.

"For those looking for something to be concerned about, there's China's secret submarine base (no kidding): "Forget the Olympics For Now: China's Secret Submarine Base is Serious" (May 2, 2008)
"March 12, 2009 12:48 PM"
(Comments from "Tibet: Fifty Years of Chinese Liberation, and Counting" (March 10, 2009))

Wednesday, June 1, 2011

L-3 Communications, Grumman: Hack Attack

I'd like to think that most folks running major technology companies in America are a trifle less clueless than Dilbert's manager:



Unhappily, it doesn't take a pointy-haired manager, or executives who think "password1" is a strong password, to have security troubles.

A system like this sounds fairly safe, I think:
"...SecurID adds an extra layer of protection to a login process by requiring users to enter a secret code number displayed on a keyfob, or in software, in addition to their password. The number is cryptographically generated and changes every 30 seconds...."
(Wired)
The SecurID service probably worked pretty well. Until someone hacked into their system. We still don't know exactly what data was stolen, and how it's been used, but whats been happening to American defense contractors suggests that the encryption seeds for SecurID tokens is available to someone with Internet access.

And an interest in classified data about United States weapons systems.

This is not, in my considered opinion, good news. At all.

I've put excerpts from the last two days' news at the end of this post.1

There's probably going to be quite a bit of finger-pointing, as word of this these hack attacks spreads. One of the more sensible points to look into, I think, is why more clients of SecurID didn't change their systems after the original hack?!

Oh, Come On: How Bad Could It Be?

Someone speculated that the control system for Predator drones might be hacked with data that's quite possibly been taken from someone's network. About the best outcome of that might be that the drones wouldn't work at all. Someone with a little piloting skill and the right software might decide to hijack a Predator drone and send it on a new mission.

That, I think, would be bad news. But then, I'm one of those people who don't think that the military-industrial complex and Yankee imperialism is the greatest threat to world peace and spotted owls.

Looking beyond strictly military data, America - and a fair number of other countries - depends on a complex power grid and a telecommunications system for most of what we do every day. Which, for quite a few months each year here in Minnesota, includes keeping the temperature inside above freezing.

Back when the Y2K bug was being dealt with, I evaluated my household's resources. Happily, we didn't get a chance to test this: but I'm pretty sure we would have been okay for at least a few weeks, if the power had failed at midnight, December 31, 1999.2

Then there are nightmare scenarios, like someone getting clever with a pharmacy chain's prescription software. Think Colossus: The Forbin Project meets Dr. Giggles.

Maybe the power grid and phone system crashing in mid-winter wouldn't be so bad, after all.

Related posts:
In the news:

1 Excerpts from the news:
"Top military contractor Northrop Grumman Corp. may have been hit by a cyber assault, the latest in a string of alarming attacks against military suppliers...."

"...Lockheed Martin said its network had been compromised last week, and defense contractor L-3 Communications was targeted recently, as well. Both intrusions involved the use of remote-access security tokens, experts say.

"On May 26, Northrop Grumman shut down remote access to its network without warning -- catching even senior managers by surprise and leading to speculation that a similar breach had occurred...."

"...Charles Dodd, an information warfare consultant with Nisrad Cyber Research Institute, raised a scary possibility: Unmanned aerial vehicles such as the Predator can be controlled by computers. If hackers access those computers, can they operate those deadly drones?

" 'If adversaries get that technology, we may not be the one that controls those weapons,' he told Fox News.

"The network attacks spiral from a security breach in March, when hackers stole information related to RSA's SecurID access keys...."
(FoxNews.com)
"An executive at defense giant L-3 Communications warned employees last month that hackers were targeting the company using inside information on the SecurID keyfob system freshly stolen from an acknowledged breach at RSA Security.

"The L-3 attack makes the company the second hacker target linked to the RSA breach - both defense contractors. Reuters reported Friday that Lockheed Martin had suffered an intrusion.

" 'L-3 Communications has been actively targeted with penetration attacks leveraging the compromised information,' read an April 6 e-mail from an executive at L-3's Stratus Group to the group's 5,000 workers, one of whom shared the contents with Wired.com on condition of anonymity...."

"...Together, the attacks suggest the RSA intruders obtained crucial information - possibly the encryption seeds for SecurID tokens - that they're using in targeted intelligence-gathering missions against sensitive U.S. targets....

"...SecurID adds an extra layer of protection to a login process by requiring users to enter a secret code number displayed on a keyfob, or in software, in addition to their password. The number is cryptographically generated and changes every 30 seconds...."
(Wired)
2 No 'survivalist' stuff: the water heater holds a pretty good supply of water, and the basement could be sealed off. It would have been cold and dark, though.

Unique, innovative candles


Visit us online:
Spiral Light CandleFind a Retailer
Spiral Light Candle Store

Blogroll

Note! Although I believe that these websites and blogs are useful resources for understanding the War on Terror, I do not necessarily agree with their opinions. 1 1 Given a recent misunderstanding of the phrase "useful resources," a clarification: I do not limit my reading to resources which support my views, or even to those which appear to be accurate. Reading opinions contrary to what I believed has been very useful at times: sometimes verifying my previous assumptions, sometimes encouraging me to change them.

Even resources which, in my opinion, are simply inaccurate are sometimes useful: these can give valuable insights into why some people or groups believe what they do.

In short, It is my opinion that some of the resources in this blogroll are neither accurate, nor unbiased. I do, however, believe that they are useful in understanding the War on Terror, the many versions of Islam, terrorism, and related topics.