Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 1st June 2016

PassW0rd – 1st June 2016

Play

Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.

Speaker B: Hello and welcome to the Password Radio Show on Resonance 104.4 FM with me, Peter Warren. In this show, once again, we concentrate on the technology world’s ongoing scandal, the multi-billion pound cybercrime industry, and the efforts that are being taken to combat it and why you should care. Last month, Portsmouth University’s Centre for Counter-Fraud Studies released details of the £193 billion being lost to fraud in the UK on behalf of the credit scoring company Experian. With online buying accounting for most of our purchases, much of the losses are occurring due to cybercrime, and 25% of us are now affected by that cybercrime, and soon we’re going to really start to feel that because the authorities blame us. Up till now, the banks have been prepared to write off the losses because they are saving so much from not having to pay the £3 billion a year call centre and branch costs. But under proposals being discussed by Britain’s big banks, the government, the Bank of England, and GCHQ, Customers could be frozen out of banking services and unable to claim compensation if their account has been hacked, even if they’ve lost their life savings. So why is GCHQ getting involved? Essentially because the big business of cybercrime has ramifications for cyber warfare, but more on that later. At the beginning of this month, the cyber security industry gathers for its annual binge at Earl’s Court known as InfoSec. It attracts the great and the good of the cybersecurity industry and the geeks and the spooks. So Password asked the questions: with losses so high and massive data breaches being announced each week— at the end of May, it was the turn of Tumblr to lose 53 million passwords— what is going wrong? Here’s Lawrence Dine, the managing principal of investigative response for Verizon. A US cyber company that produces the highly respected Internet Breach Report on the problems behind the cybercrime wave.

Speaker C: Well, I think the first thing to look at is that there’s a value in that data, and that’s the reason why it’s being targeted by bad actors. You know, like, so, you know, from our dataset, the motivation behind doing these kind of things, the majority of them, like, over just about 80% of of the motivation that we track can go back to financial motivation. So people will steal anything of value. And in this situation with the databases that we’re seeing online that have been stolen, either stolen recently or stolen years ago and they’re being used again and it’s coming to light, the vast majority of that is around the fact that there’s money to be found. There’s money to be made in that kind of situation. The deep-down security side of things, you know, why is it continuing to happen, and why aren’t we doing better at protecting it, is likely because you do have situations where you have people who are working on trying to find ways to get into your environment, and they do it for a long period of time, and they have forever to get in, and you have to be forever on guard and stop them from getting in.. So I think there is difficulty. I do believe that we should be doing our best to stop people getting in environments, obviously. But it is extremely difficult to be 100% all the time. And all they need is one weakness.

Speaker D: One of the things that some people have been saying though is that from, to use an American expression, from the get-go, that security wasn’t built in. And that means that there is an inherent structural problem with the internet.

Speaker C: To know. Yeah, I absolutely agree that that is a situation that’s been— that we’ve been playing catch-up from day dot. Because when all these things were put together, there was a situation where they didn’t know, or at least they didn’t foresee the situation where everything was going to be connected at one stage. And the security wasn’t a requirement when they were thinking about it.

Speaker D: And one of the interesting things that comes from your report is also that the crime, or the pattern of crime, seems to be quite consistent. The methods of attack that are being used seem to be the same. It’s an attempt to take over computers using spam email and using phishing email.

Speaker C: Yes, absolutely. That appears to be what the— The tip of the spear is we’re seeing that more and more is that phishing is a way into the environment. We are seeing that phishing continuously works. A lot of that is around social engineering though, and it’s about making your people aware of what a phishing email is, and also if they receive something like that, to actually notify somebody within their IT team. To combat that situation. And that’s something that we’re really, really discussing with our clients this year. And it’s one of the main focuses of the DBIR is around getting people involved with protecting your systems. We don’t leave our car keys lying around. We don’t leave our phones on tables. We don’t do stuff like that. But we do give them the keys to our IT environment. By using the same password in every site that you ever go on, that causes issues. And a lot of these databases will have your password in there, and what the bad guys will do is they’ll take your username and password from one site and use it on every site that they can check. And they get a lot of success in that area.

Speaker D: There’s quite an amazing thing here, isn’t there, which is, to use yet another American expression, it’s almost like a perfect storm. You’ve got very, very bad infrastructure, a lack of awareness of the infrastructure itself and the people using it. And also a lack of technical ability for many of the people who are using it. So therefore that makes them utterly vulnerable to anybody who wants to attack them.

Speaker C: Yes, we can certainly say that, you know, there’s lots of vulnerabilities available out there. There’s lots of layers in place of bad layers where it makes it very, very difficult to to protect a lot of this stuff. But there is success. I mean, if it was as bad as what that sounds, then you would have data breaches, massive data breaches continuously going on, and we would be battling wars all the time. So there are people out there that have good layered security and protection in place that are stopping these things from happening. But at the same time, on the flip side of that, you are seeing a lot of data breaches. And I think based on the fact that phishing still works, based on the ransomware infection that we are seeing constantly within the environment right now, that’s around instant access to data.

Speaker D: I mean, but to go back to your point, Lawrence, and you know, we would be seeing this sort of thing all of the time. In a sense, we are. LinkedIn had a breach within what it was— there were announcements of details of a lot of passwords going from LinkedIn. Yahoo had a breach. There were announcements that Gmail had lost data within the last 2 weeks or so. Tumblr yesterday. And I think another company. These are happening on a very regular weekly basis. So that does seem to indicate that there is a significant issue.

Speaker C: Well, there certainly is a significant issue. The one thing I will point out with all those different data losses is I don’t have intimate details into when they actually were breached, and some of them may have been breached years ago, and now they’re just getting the information that that data was lost. So, it’s probably over a longer period of time than what it appears. And a lot of times what will happen is, you know, a bad actor will get access to data, but they will hold onto it because, you know, the newer the data is, the higher value it is, so they will try to sell it to other bad actors first. A lot of times what happens is they sell what they can, and then after a period of time they just release it into the wild. And they have different motivations. So it goes from being a monetary motivation to an ideology motivation. So they just go, right, I’ve sold what I can, but now I’m going to show these people that I’m actually a good hacker and I can do that. So I’ll just release it into the wild.

Speaker B: Lawrence Dine on the reasons for cybercrime: It’s a picture that there is widespread agreement on. The problems that we now face have been with us since the late ’80s, and we’ve chosen to do nothing about them. Rod Rasmussen of Infoblox, a company that specializes in countering the latest internet threat, ransomware, which has seen a 3,500% increase over the the past few years agrees with Vine. Ransomware happens because people click on links or attachments in unsolicited email that then runs a program which encrypts your computer. Who does it hit? Individuals, small and large companies, hospitals, and even police forces, all of whom have paid thousands of pounds to the criminals to free up their computers. But it’s not new. As Rasmussen points out, it has been around for nearly 30 years.

Speaker E: Yeah, absolutely. It’s not just hype in the press. We’re seeing just an amazing quantity of this going on out there, and a couple of reasons for that. One thought is that this isn’t anything new. We actually saw this back in the ’80s and ’90s, but on a much smaller scale, and it was harder to get away with because you had to get that ransom paid in some way, and that was a lot easier to trace back in the day. Today you have things like cryptocurrency, Bitcoin and things like that, where it’s anonymous and fairly easy for people to set up and make it untraceable. So cashing out is a lot easier. You have encryption, which is a lot more readily available and a lot easier to do at a level where it’s almost impossible to break unless you’re a state actor. So it makes it a very effective crime. The other thing is criminals have a tendency to kind of follow the herd and go after what works. There are a lot of underground forums and things like that where they share their success stories, and by the way, it’s also where they sell the kits to set these things up. So there’s really an economy, an underground economy that thrives on selling bits and pieces of this. So I can separate myself from the actual crime and still make money off of it by selling a kit for exploiting drive-by exploits as somebody’s browsing something, or phishing kits, or whatever, to get my lures out there, and then also the technology to do the encryption and then get the payoff. So it’s a lot of reasons for this, but it’s extremely effective, and as Been circulating around the big payoffs, so more and more people have been interested in doing it.

Speaker D: I mean, that’s the interesting point, isn’t it? Because, yeah, the top cybercriminals, a lot of people think that they’re actually actively going out and breaking into banks. They’re not. They’re far cleverer than that. What they’re doing is they’re putting together the tools to do criminal actions, and they’re selling them in volume to lots and lots of people who are using them.

Speaker E: Yeah, absolutely. And it’s depending on where you are and what jurisdiction, it may not even be illegal, right? So, and it’s very hard to prove a case that you’re facilitating crime, even if you do get caught at it.

Speaker B: So billions of pounds go to crime, a massive increase in the amount of computers being locked with ransomware, and at least 25% of us being affected. Surely it can’t get any worse. Well, unfortunately it can, because in pre-internet days, a vulnerability in your security would mean that only your house was at risk if criminals knew that a French window door lock was faulty. Now, because of poor code, the poor locks are in a huge number of homes. As a result of that, the criminals have found that they can make money in this information age from compiling databases of the vulnerable and selling that data to all comers. And because of that, intelligence agencies have found the criminals particularly useful because they compile lists of the data ages weak. Rich Barger, the chief intelligence officer of ThreatConnect, spent months creating the Project Camera Shy report which investigated Chinese hacking groups and attributed cyber espionage activity to a specific unit, 78020, of the Chinese Liberation Army. One of the things that he found was that they were targeting individuals who they knew would be weak.

Speaker H: They would target specific individuals, you know, in organizations of interest. And again, you know, an attacker like this is going to target the vulnerable user, not necessarily the vulnerable asset. So at work, at home, if you think about how nomadic we are with our computer systems, the laptop that I might check my Facebook and do personal business might be the very one that I bring into work. Log into my VPN or log into my work-related material. And so there’s this transitive nature with how I leverage some of these assets and the information within there. And so if I can target you specifically with a spear-phishing message, I might be able to target and get access to not only the content that you have at work, but maybe some of your personal relationships. And we also have personal relationships with the people we work for. So maybe if I wanted to target you, I would target a colleague. And from targeting that colleague, I get your email, or I get some content that we’ve shared and exchanged on. If I can repurpose that content because you trust that individual and you trust that content, and I just happen to slip my malicious implant in with that content and force you to interact with it. Now I’ve effectively social engineered you and potentially hooked you with a very crafted, very specific thing that is intended to support my intelligence collection operation.

Speaker B: Rich Barger telling us how Chinese spies home in on the weak to promote Chinese military and economic interests. Something that is not a one-off. Peter Singer is a respected academic. He is also the author of Ghost Fleet, a science fiction book that he has successfully used to raise awareness among the military of the changing threat that the information age presents.

Speaker G: Yes, so it’s both reflecting that but also an important shift that’s happening in the 21st century. So it’s reflecting that, the idea that The very technologies that we use and depend on, whether it’s us as civilians to military units, are inherently global. It redefines what the home front is. It redefines the domains of battle. So cyber conflict is something that takes place in a realm that, you know, you can’t touch or feel, but it’s real. It matters. And yet it— is mostly run by civilians. So for example, 98% of U.S. military communications go over the civilian-owned and operated internet. You take that away and you could hamstring— has alliance relationships with the Philippines and with Taiwan of different kinds, and again, there’s It’s a— I guess for me the framing is this. In the 20th century, great power conflict was thinkable because we had two world wars that actually happened and killed tens of millions of lives. And we had the fear of a third world war that shaped everything from geopolitics to sports, how we looked at the Olympics and medal counts, who we compared ourselves to. And then with the turn of the 21st century, we felt like we’d put this behind us. And yet it’s becoming thinkable once more, whether you look at the military planning being done in both Washington, D.C., but also in Moscow, Beijing, London. These are the things that worry the politicians and the generals and admirals.

Speaker B: It’s a world that Singer thinks has some uneasy resonances to the former Cold War. That was Peter Singer, an academic and author of Ghost Fleet. During the Second World War, posters appeared stating that careless talk costs lives. Many in the UK Ministry of Defence have been wary about equating the current situation to one of conflict like that, but there do appear to be some alarming developments. Should we not be worried about a world where 25% of us have been victims If it occurred on the high street, there would be howls of outrage and demands for resignation. So what’s the solution to this world where our carelessness is having such enormous unintended consequences? Well, according to Todd Beardsley, the senior security manager of Rapid7, which recently surveyed the communication protocols which underpin the fragile web we all depend on, We all, but particularly the politicians, have got to come up to speed with the world that we live in to impose the changes that need to be made. Because surprise, surprise, Beardsley and Rapid7 found that the bedrock of the internet has not really changed in over 20 years and that little of it is protected.

Speaker F: So what we found was that the internet of 2016 looks and operates an awful lot like what we thought the internet looked like in 1996. There is a preponderance of nominally insecure services running out there, and there’s actually millions and millions of them. The biggest difference between the internet of ’96 and the internet of today is that it’s bigger. The other big difference is that we all rely on it. We rely on the internet to be safe and secure and available for allowing us to live our lives. And yet a lot has not changed when it comes to the services that are offered on the internet. And so what we wanted to do was take a look at the global internet and slice it up by country to see if there are countries that are better or worse at deploying encrypted services, which while they may not be inherently secure, they’re at least more secure than a clear text unencrypted service.

Speaker D: And let’s just be clear about this. When you’re talking about the internet, you’re talking about bits of programming that make bits of it work. So you’re talking about protocols like the one that used to be used to transfer large amounts of data up onto a website, which was FTP. FTP, you know, File Transfer Protocol. So the things that basically let you do things on the internet.

Speaker F: [Speaker:JASON] Right, and so like I think when most people today when they talk about the internet, they’re talking mainly about the World Wide Web, that thing that gives us web pages. Much of that, we’ve seen some good progress there on moving that to a more encrypted footing, but we have other services out there like FTP, the File Transfer Protocol, offer at all. This is worrying to me. If you were to ask me before we started this, what are the top 5 protocols offered on the internet, I would be able to tell you HTTP, which is what gives us the web pages, and HTTPS, which is the secure version of HTTP, are probably number 1 and 2, but I wouldn’t be able to fill in the rest for you. Today I know that FTP is number 4, which is really concerning to me.

Speaker D: Right, okay, now you mentioned the word encryption. Encryption’s bandied around all of the time now. Why do we want to encrypt these things? Why, what is the point? Why does that make us safer?

Speaker F: Well, we use encryption as kind of a stand-in for security when we want to measure like the security of a thing, of a service. So what encryption gets you is not so much like the ability to like tell secrets to your friends, but it does let you do things like positively identify a service out on the internet through the use of cryptographic certificates. If a service does not offer encryption, I can’t tell you with any kind of guarantee that I’m talking to who I think I’m talking to. Really, it’s kind of like the opposite of anonymity is this aspect of encryption. It gives you pretty solid identity. People can identify themselves. Also, with encryption, encryption lets you do things like send usernames and passwords over the internet without them being spied on. So, like, no one else can pretend to be me. So, encryption gets you to a place where you can identify the service you’re trying to use, like maybe, like, an online store or something like that, and it lets the online store identify you. So, it gives you, like, this mutual identification. And so this is kind of a core concept of encryption that the cleartext services that we found don’t offer. We see things like FTP, we see, like, direct access to databases that don’t offer encryption. We see just lots of servers, most servers are not fully encrypted. They use a kind of opportunistic encryption, which has its own sort of problems.

Speaker D: [Speaker:DAVID HEATHFIELD] Okay, so what are the ramifications of this to people? What does it mean if we have got everything in clear text, if it’s not encrypted, and even if these protocols aren’t encrypted in the way that you’re talking about?

Speaker F: Well, what it means is that if you’re relying on the internet to conduct your life, to do business, and to run the internet, what it means to people is that you really don’t have any guarantee that you’re talking to the— services are not talking to each other in a secure way, in that they can’t identify each other, and people can’t identify services, services can’t identify people, and it means that an actor in between you and the service can eavesdrop on communications, can alter your communications in either direction. If I, you know, I’m trying to buy something off a website that’s not encrypted, for example, and I might want to say like, “I will send you $10,” an attacker could could change that to $1 or $100 or what have you there. So you lose a ton of security when you don’t have encryption. Clear text, though, is the history of the internet. The internet was basically a science experiment and everybody used to know each other on the internet, but clearly that’s not the case today.

Speaker D: Okay. Now, just as a final question, politicians have often said that they don’t think that they should intercede in the development of the internet. Many people have uncharitably said that that is because the politicians don’t really understand very much about the technology or the internet. Do you think that the politicians need to become a little more involved in this process, given the dependence that we will have on it?

Speaker F: So here at Rapid7, the company I work with, we have a pretty robust policy and legislation mission. So we work with politicians here in the US. On crafting legislation that is pro-security more than, you know, more than I think many security companies do. And we are also very pro-research and pro-tinkering. So the things that I think politicians would do well by is paying attention to experts who do, like, kind of live and breathe internet architecture and internet infrastructure. And make sure that when we talk about encryption, we know what we’re actually talking about. Encryption is not just like secretly plotting on dark corners of the internet. Encryption is like a fundamental feature of security. You don’t get to have security without encryption. I mean, I can look at a cleartext protocol versus an encrypted protocol, right? And I can’t tell that either one of them is secure or insecure. Well, what I can tell you is that the clear text protocol can’t possibly be secure. The encrypted one certainly is farther along. And so I think politicians would do well to kind of understand that distinction. And it’s not super hard to explain either. It’s just a matter of getting, you know, people who are good at teaching these sorts of things to the people who are governing.

Speaker B: Todd Beardsley with some food for thought for the gathering at next week’s InfoSec, where the former Foreign Secretary William Hague, who organized an emergency world summit into cybersecurity in 2011, will be making the address. You’re listening to Password with Peter Warren on the issues that are challenging our new world, and I’m afraid if you’ve just tuned in, you’ve missed it. Password is brought to you by Future Intelligence and the Cyber Security Research Institute. And if you’d like to know more about these issues, please log on to our websites, www.futureintelligence.co.uk and www.csri.info. Thanks for listening and goodbye.

Speaker A: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00