Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 11th May 2016

PassW0rd – 11th May 2016

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to Password on Resonance FM, the program that takes the pulse of the technology industry. In today’s show, cybersecurity is once again dominating the news with a headline in City AM proclaiming the UK is sleepwalking into a cyber crisis. And the release of new research from the government that shows that two-thirds of UK businesses have fallen victim of cybercrime. We’ve been looking at why. So what is the issue? Paradoxically, it’s the internet itself. Since it took off 20 years ago, our lives have been turned upside down, with businesses across the world rushing to get online to cut costs and take advantage of the commercial opportunities it presents. Everyone has rushed to get online— businesses, the public, and the criminals. It’s a crowd surge that has challenged conventional notions of morality, which has shown that many people don’t see right and wrong in the same way when they are online and remote. They would do things online that they wouldn’t do in the real world. While there are also a lot of people who use the internet who have no conception about the risks that they face. According to some experts, that has led to the biggest problem: the sheer amount of cybercriminals and a crippling skill shortage of defenders, with some figures putting the shortfall of skilled cybersecurity professionals at between half a million and a million people. This is contrasted against a very sophisticated operation by the cybercriminals to take advantage of the huge number of people who are online and technologically naive. And the businesses that lock the doors to their offices but see cybersecurity as an inconvenience. At the end of April, the cybersecurity company Verizon published its breach report, considered by the industry as the bellwether of cybercrime trends, and it made grim reading because there was very little that was new. The criminals are after money. They use email, known as phishing attacks, where they con you into opening an attachment And 30% of them are getting opened. And more and more, that will lead to your machine being hit by ransomware—code that locks your machine unless you pay a ransom. Here’s Lawrence Dine of Verizon to tell us more.

Speaker D: One of the things that we’ve specifically pointed out again this year is that the majority of breaches, or the majority of actors in these situations, What they’re after is money. What they’re trying to do is get money. And any information that can be monetized, they will steal. But I agree, based on the stats that we’ve got on utilities, so 69% is cyber espionage or DDoS or crimeware. So yes, crimeware would would include things like ransomware and stuff like that, which a lot of industries are going to be susceptible to. So that’s the three different patterns for, you know, through incidents and probably the same three for breaches as well.

Speaker F: Okay, I mean this rise in ransomware, I can remember writing some of the first stories about ransomware. It struck me at the time that what the criminals were aiming for was small and medium-sized businesses that weren’t very aware of the threat. Would that be fair? Yeah.

Speaker D: Small and medium businesses are more susceptible to it, but not as a target. We’re seeing all levels of industry get targeted with ransomware. And we get calls from various organizations that have us on retainer, but I think you’re probably more likely to find small and medium businesses aren’t going to have their data backed up in a way that can be easily restored. So I think if I was— the bad guys would probably more target them for that reason because they’re more likely to get a payout, whereas a big business will probably have good backups in place and will simply wipe the computer and restore it.

Speaker F: Lawrence, could we just look at that thing of targeting? Because that’s interesting, isn’t it? Because you and I are talking about targeting, we’re probably just as guilty as anybody else, because in reality it’s not targeting, is it? Well, what’s happening is you send out these spam emails or the method that you wish to try to use to infect the computers, and you send out as many as you possibly can. It’s a blanket approach, and what you’re doing is looking for those organizations that may not have people who are aware enough or may not have the relevant security in place, and that’s how the targeting occurs. The targeting is through weakness and vulnerability rather than design. Absolutely.

Speaker D: Now, there may well be phishing that are targeted at a specific company because they they’ve been hired to get information out of there, or they want— there’s something in there that they’re very interested in, and you know, cyber espionage, that kind of thing. So that may be more of a target where it can be either industry or even client-specific or individual-specific. But I think with ransomware and the main phishing stuff, they do just blanket send and hope for the best.

Speaker F: And so in a sense, what your report has found out then is this is where the blanket approach is exposing the vulnerabilities. The report is exposing the weaknesses in awareness and perhaps also weaknesses in particular systems? Yes, absolutely.

Speaker D: And more on the awareness side of it. That’s something that, you know, I think I said at the beginning of the call, that’s something that we’re targeting and we’re trying to assist our clients with.

Speaker B: Verizon’s Laurence Dine. Now, one of the other trends that researchers have woken up to this year is the sheer number of attacks. The number of cybercriminals now outstrips the defenders, and they are using automated software. According to the police, such sophistication is not limited to the attacks. They also use sophisticated grooming techniques to find talent. Here’s Ian Glover, president of the industry accreditation group Crest, which worked with the National Crime Agency on a report into cybercrime grooming.

Speaker G: Crime, then you’ll see, you’ll see that they go from, from gaming into, into cheats. And then they go from cheats into modifications. And to facilitate the modification, they start to use extraction tools. And they obtain those extraction tools from the internet, obviously. But also, they then start to join some of the gaming and hacking forums. Right.

Speaker B: When you say extraction tools, what do you mean?

Speaker G: So you need to break down the code. So in other words, you need to— if you’re going to do a modification on the game, then you need to extract the code. Yeah.

Speaker B: So basically what they do is they get the kids interested in, or they go on talking about cheats and things like that, and then they start saying, do you know you can do some other— sorry?

Speaker G: Yeah, yeah, the children become interested. I think that’s what happens., and then they gradually migrate towards some of the forums where those tools and things are discussed. Right. And what then happens is that you’re marginally on the legal side. So at that point, if you are doing modifications to the game, in theory you’re breaking IPR law. In reality, the gaming companies aren’t doing very much about that. And so you’re already starting to move into into, well, it’s okay to break code and it’s okay to extract stuff. And that starts to socialize the idea that that’s an acceptable thing to do.

Speaker F: Right.

Speaker B: And so then what they’re doing is they’re looking for particular people, or in a sense, it becomes a self-fulfilling system because those people who become the most interested in doing this start to gravitate quite naturally to other forums. Yes.

Speaker G: And if you look at what happens with the social interaction, it moves from a face-to-face physical element into a gaming element where they have a lot of international friends and friends from other places, into the hacking forum where again that extension to their social network and their social standing starts to increase. So what tends to happen is their social standing within their normal community starts to diminish, and their social standing in their online presence starts to increase.

Speaker B: Ian Glover of Crest. Such sophistication doesn’t just end there. Just like the technology industry, the cybercriminals cannot get enough skilled people even with their efforts at grooming. So the criminals have turned to headhunting and are offering hundreds of bitcoins for each project, a trend that has been noticed by Narayan Neelakantan, the chief security officer for the Indian Stock Exchange.

Speaker H: There is a clear requirement of sharing of skills. So it’s very clearly, if you look at the darknet, very clearly there are requirements, like you have requirements for enterprises and organizations that we need people of this skill set, and this is typically the task that we need to carry out. And then they group together, they form a team like how we form project teams for enterprises, and they execute the whatever hack or whatever crime or theft that they want to do. And then, then it’s like these resources are available again, they are free, and then that’s how it works.

Speaker B: So where would you typically find the websites where they’re asking for people to put together these teams and these requirements?

Speaker H: So you have to connect to the Tor network. So there is an underground Tor network where you have all these underground sites, and typically you can’t directly enter them. You need an introduction first. Somebody has to introduce you, and that has to be a trusted person. So there is an inner circle, and then those guys introduce these guys, and then that’s where all this works, and it is pretty organized.

Speaker B: So what do they say then? Do they say this is the project, this is what we want to do, and you know, this is what we need? How specific is the information that is being—

Speaker H: It’s not at all specific. It’s very sketchy and it’s all linked to your Bitcoins. So they will say that these many— typically it talks about effort estimate and type of skill. That’s all. There is no target, nothing is mentioned. And then we don’t have visibility beyond that how it works. So the visibility that we have sitting outside is to this extent that, okay, it’s all about money being given as bitcoins and these are the skill sets that are sought and the typical effort that it would take, estimated effort. That’s it. We don’t have access beyond that.

Speaker B: So how are you picking up this information? Are you monitoring those sites?

Speaker H: So we typically, what we do is we have couple of agencies whom we have sort of hired who pose as hackers and they get into this underground web and that is the information that they pass on back to us. So obviously they pass on very filtered information because they don’t want to get exposed themselves because they are posing as trolls there and they pass on credit intel which is more relevant to our organization or our sector or our area of, what do you say, let us say typically financial sector types. So that’s the information that we are privy to. Beyond that, for us also it’s a black box.

Speaker B: I mean, do you see some sort of credibility coming from the skills that are being requested?

Speaker H: Yeah, so it’s very different. So I think those people that way are very selective in what they post. Because they do not want to leave any kind of trail to even try to have some kind of remote connection to what target they are targeting. It will look like a general request, so it might also sometimes it looks like a bounty hunter request. So it looks the request is so simple that okay, we have these kind of vulnerabilities in certain type of operating system, do you have the skills to exploit them? So they are that generic. So it will be a long shot to really try to come up with some kind of connection in the real world to what exactly, or what kind of organization or sector that they might be targeting, because there are just— those many systems are like typically used by almost all enterprises worldwide.

Speaker B: Narayan Nilankantan on the cyber skill shortage that is forcing the criminals to headhunt. It’s a skills shortage that is creating real problems. As Bradley Moore-Finch, the Director of Strategy for the Manchester technology exhibition IP Expo, outlines, they conducted a survey of IT skills in the North and found that there just weren’t enough.

Speaker E: I think for us there’s a real lack of both support and skill sets coming through the education and sort of youth experiences. System so that it’s actually impacting businesses staying competitive on the international landscape and domestically. And I think there’s also a north-south divide so that I think, you know, if you have got these sets of skills, you’ll find yourself in the Southeast rather than the Northwest.

Speaker F: Why do you think that?

Speaker E: It’s just more jobs, more companies are based down south, and there’s a lot more opportunities. There’s also the I guess the London weighting on wages and with the sort of lots of investment in the infrastructure and the transport links in and around the Southeast, it’s probably the place to be. I know there’s great investment going on HS2 and into the Northwest. There’s no evidence, certainly from our research at the moment, there doesn’t seem to be much evidence of a real sort of migration of skilled, limited number of skilled people moving to the Northwest. I think what we find is that it’s just getting the people, the candidates, to the Northwest. And because there’s a limited number, the wages are increasing. It’s definitely an employer-employees market. And I think with that in mind, I think the head offices down south are the ones that are seeing the applicants. It’s interesting also, when you look at unified communications as a subject, the ability to provide flexible working and remote working is seen as an incredibly important perk for the younger professionals today, and they will certainly choose companies based on this sort of ability to provide these services and ways to work, which is another reason why it’s interesting that only 3% of the Northwest was interested in providing these services. So maybe there’s a— there’s a cultural shift that needs to happen before they start taking advantage of the technology.

Speaker F: In terms of this skill shortage, what do you think should be done? I mean, surely, you know, the North East could say, hang on a minute, we should have an education initiative, we should be pushing for people to fulfil these needs, and we should be doing this locally. What are you wanting?

Speaker E: Yeah, well, what we want to see is a lot more investment and support This will probably be a long-term investment. This is not something that is a silver bullet. I think there’s 100 things which need to be done better from central and local government, but we need to drive businesses to the North West. You know, the BBC going there is an interesting example, and certainly one which could be replicated by anything that the government can control. And then, you know, perhaps enhance rents and rates and taxes, perhaps, if dare I say, for businesses moving their HQs views to the Northwest. And if the jobs are there, then the people will have to go there, and then eventually the standard of living will change, and everything will follow from the jobs, we think.

Speaker F: Now, one of the things about all of these pushes to try to educate people is they’re always focused on the young. Yet there are a lot of people who have been thrown out of work. Now they’re wondering what on earth they can do. Do you think that they could possibly be trained up or retrained or encouraged to go into this area? Because To be perfectly honest, it is the future, isn’t it?

Speaker E: I think that’s an excellent idea and one which should definitely happen. Yes, I couldn’t agree more. I think anybody, no matter what age you are, will have to be retrained at some stage in their career with the way technology and working practices are changing. So that kind of infrastructure to be able to do that would be an excellent idea.

Speaker B: The skills shortage that is leaving us all exposed in a world that we don’t know enough about. It’s a situation that is desperate and needs some urgent action from the government. This week, two separate conferences in London discussed the issue and stressed how bad the situation is. And according to one of the speakers, Paco Hope of the software testing and penetration company Sigetal, with the rollout of the Internet of Things, it’s only going to get worse.

Speaker C: One of the biggest issues that people may not be aware of is that many of these products come out, it’s the first generation. It’s the first version of something. It probably has bugs. It may have vulnerabilities. And you have a laptop on your Wi-Fi network, and you know that regular patches come out to update your laptop and make it more secure. What about that light bulb that just joined your Wi-Fi network, or the toaster, or the refrigerator, or the television? Is there a new version to fix the bugs or to fix the vulnerabilities? How would you get that? There’s a lot of devices that ship with bugs, ship with vulnerabilities, and the average person will struggle to get the latest version and keep their things secure. The other problem in IoT today is so many companies are startups. They’re new. They may release the first generation and then never release another version, so you could have buggy, vulnerable things for which there is no update because the company moved on, discontinued the product, went out of business, whatever.

Speaker F: So what are the ramifications of that for somebody then? What are the ramifications of having some Internet of Things connected device in their house that has got, as you say, buggy software in it?

Speaker C: The implications could be numerous. One of the problems with say the Jeep that made the big demo, you know, they could actually get into this Jeep over the internet. I mean you have devices on your Wi-Fi network that could very well be allowing access into your private Wi-Fi or into your home network. And you don’t really know and you don’t have a good way to figure it out.

Speaker F: Now, and of course we did have the example connected house that belonged to Samsung was hacked by some university students as part of a project.

Speaker C: That’s right. And there’s any number of devices, alarm systems, car door locks, house door locks, CCTV, and baby monitors. Many of these systems join your home Wi-Fi, and then they broadcast on some channel, and you may or may not know how secure they are. And you, the end consumer, aren’t really in a good position to figure that out.

Speaker F: It’s a very good point, isn’t it? Because at one point when they first rolled out the first baby alarms, you could actually tune to your next-door neighbor’s frequency but by accident and start listening to what was going on in their house. What you’re saying is that not only is that possibility and potential there, but also you could get somebody not only coming onto your own networks, but interfering with them and maybe even making your life uncomfortable. They could lock your door, for example, and lock you in.

Speaker C: And in the example you gave of the baby monitor, you had to be within within 20 meters or 50 meters of the house realistically to pick up that signal. But with the Internet of Things, most of these devices are available over the internet. So someone can go to the baby monitor connecting website, which you would use to look at your own baby monitor, but someone anywhere on the globe could attempt to guess your website ID or access codes or whatever it takes, and then they can pretend to be you and see into your house. They could pretend to be you and send a firmware update that changes the code on that baby monitor to do something it was never designed to do in the first place. But now that’s malicious. And you, the person with the baby and a camera pointed at the baby, have no idea that any of this is happening.

Speaker F: Now, one, one of the things that you’ve been saying though is that it— obviously you can have these things rolled out. Uh, well, in that case then, But don’t we need to say there’s got to be security on these things? You’ve got to have security on them before you put them on the market.

Speaker C: [Speaker:CHRIS] That’s right. And people should look for security in the devices that they think about buying. Though even then, it’s hard to evaluate the claims on the box because they’ll say things like, “We require a password and only someone with your password can get in.” And what we’ve discovered in many instances is yeah, the password is required, but there’s also ways to bypass that access control entirely. And so it’s hard for you, the nontechnical consumer, to evaluate the truth of the claims. You need to look for the security of the product, but it’s hard to do much more than take it at face value.

Speaker F: So do you think then people should also be saying, Because one of the points that you were making is that sometimes these devices are so small it’s almost impossible to actually put any security on them. Do you think that people should be looking for some almost— in the UK we’d call it a kite mark, but a mark that says there is security on this system, it is as secure as we can possibly make it?

Speaker C: Right, and I think we’re going to see that in industry. We’re seeing both at, say, the ISO, the International Standards Organization, as well as various national organizations in the US and the UK. Many organizations are trying to produce some sort of standard that’s meaningful where you can say, yeah, this software and this device is trustworthy. That’s a really hard problem, and at the end of the day, it ends up getting you something. It’s a bit like saying you have an MOT done on your car. I mean, yeah, you’d be negligent to drive a car that couldn’t pass the MOT.. But does that mean that car is perfectly safe and secure and there’s absolutely nothing wrong with it? No, it’s more of a baseline expectation than some sort of gold star, perfect car.

Speaker B: Paco Hope of Sigital. One of the main findings from the Data Risk Management in Financial Services summit at the London Stock Exchange, which was attended by former government ministers, top experts from GCHQ, and the Password radio show, though because of Chatham rules we can’t quote anyone, was that lack of awareness is a crucial issue. Ignorance among businesses and the public is the problem that we face. As the Verizon report points out, the criminals are doing the same thing that they have been doing for years, and they will continue to do so as long as they can make money. One of their techniques is to exploit the fact fact that people often misspell the websites that they want to go on and don’t check. It’s a weakness that Ilya Kolochenko, the head of Hitech Bridge, who was also at the London Stock Exchange, is trying to do something about.

Speaker I: The problem is very simple and very complicated on the other side. Today, current domain name system allows, practically speaking, anybody to become an owner of any domain that is not yet owned by somebody else. For example, if you’d like to become an owner of hsbc-e-banking.com and the domain is not owned yet by the bank or by some other companies, you can become the owner of this domain. Afterwards, you can obviously do whatever you want, from classical things like stealing potential clients of the bank who think that they are clicking on the domain of the bank up to infecting them with various malware when they’re opening the link thinking that they’re going to— they’re banking of their bank. Today, the problem is significantly growing. First of all, because we have introduced different top-level domains like we have.pizza,.xxx,.banking, and others. A lot of cybercriminals are using these top-level domains to create various domains that pretend to belong to various known brands, fashion brands, banks, and governments even. And after, they use it to compromise internet users.

Speaker F: It’s odd, this, isn’t it? Because I thought this problem had gone away. I mean, people were talking about this some 16 years ago, even longer, when I can remember that BT had one of its domain names taken by somebody who was trying to force them to pay a lot of money for it. And all that he did was go in for some reputational damage. And he started putting porn on a website that to all intents and purposes looked as though it was British Telecom’s research laboratories in Martlesham.

Speaker I: Unfortunately, the problem is still here. Moreover, the problem is continuously growing because legislation is pretty blurred.. And a lot of people are just using the domains, at least until the time they’re not being sued. Because in the past, we saw some successful cases of famous brands or celebrities who, after several years in court, they got their domains back. But it cost them a lot of time, a lot of efforts, a lot of money they have paid to their lawyers. And during all this time, during the processes, is gone. They continue abusing the domain name, and practically speaking, to this day there is no silver bullet solution to stop somebody from using your brand or a part of your brand name in his or her domain. And this creates a lot of inconveniences, especially when I speak about typos in domains. You know, when people are typing, especially from their cell phones, and they make a typo in the domain name, it’s very difficult afterwards to prove that the domain with the typo belongs to you because the original domain is yours.

Speaker F: It creates an entire process in the court. I mean, that’s an interesting point, isn’t it? Because one of the things that people deliberately do is go and get domains that have got typographical errors in them because then somebody goes on to that domain name, maybe they put in information about their banking or whatever, and as a result of that, they lose their financial information. So how else then could that affect the average person on the street?

Speaker I: I would say that unfortunately, the potential impact, the potential consequences and damage are only limited by creativity of cyber criminals. Unfortunately, today there are a lot of cybercriminal groups who use typesquatting, cybersquatting, and phishing to perform a lot of very harmful activities.

Speaker B: That was Ilya Kolyuchenko of Hitech Bridge. You are listening to Password with Peter Warren on Resonance FM. If you have just joined us, I am afraid you have missed it and you will have to wait until next week. Password is a joint production between the Cybersecurity Research Institute and Future Intelligence.

Speaker A: Thanks for listening and goodbye. This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00