This is old news now (anything more than a few hours is old now) but I think it is really pretty cool. A group of security researchers working with an ISP were able to take out another botnet. This time it was the Lethic botnet that mostly focused on distributing unlicensed pharmaceutical, diploma and replica goods spam. M86 Security reported a steep drop in spam after take down. I appreciate them taking this botnet offline because seriously, the less email I get calling out my manhood the better.
Friday, January 22, 2010
Thursday, January 21, 2010
The last few days have had a lot of press about the FBI breaking the law to obtain Americans phone records. They did this thousands of times (2200 of the 4400 requests) by using fake emergency letters. The FBI was even able to obtain the phone records by using a Post-it note. You can read the full DOJ report here. (pdf) I would be more outraged by this if I hadn’t assumed it was happening already. Big brother knows more than you would like to think He does about your communications, even if he gets that information illegally.
Tuesday, January 19, 2010
Stolen from Schneier:
“One of the important things to consider in threat modeling is whether the attacker is looking for any victim, or is specifically targeting you. If the attacker is looking for any victim, then countermeasures that make you a less attractive target than other people are generally good enough. If the attacker is specifically targeting you, then you need to consider a greater level of security.”
More often than not you will not be the specific target of an elite group of hackers determined to infiltrate your network. You will be the victim of a user going to the wrong website and then bringing their infected machine back on to your network without knowing any better. Poor policies around user rights and access control are more likely to bring your network down than ZeroCool.
Monday, January 18, 2010
While a lot of the news around the hacking of Google by China one of the more interesting pieces of this story is that Google hacked back.
Google’s secret counteroffensive managed to gain access to a computer in Taiwan that it suspected of being the source of the attacks. Peering inside that machine, Google engineers actually saw evidence of the aftermath of the attacks, not only at Google, but also at at least 33 other companies, including Adobe Systems, Northrop Grumman and Juniper Networks, according to a government consultant who has spoken with the investigators.
This is what happens when one super power attacks another.
Monday, January 18, 2010
When you are pulling out cash from an ATM it is best to keep your eyes open. Whether it is an ATM Skimmer or an entirely fake ATM, it is probably best to double check before you insert your card. Of course, this is only important if your money hasn’t already been stolen by one of the money mule crews.
What ever happened to ski masks and fake guns?
UPDATE: Even Bruce Schneier admits he would not have noticed this.
Monday, January 18, 2010
Darpa, the research arm of the pentagon, is reporting that there is has been a decline in the number of kids growing up to be geeks and that poses a threat to our ability to compete on the international stage.
My advice, get parents to stop telling their kids to go outside. Nothing says geek like pasty skin.
Monday, January 18, 2010
There is an awful lot of malware and spyware that likes to claim to be something it is not. Like Anti-Virus, or Facebook Apps, or even a program to reset your Steam Password.
Remember, a rose by any other name is still a hack.
Sunday, January 17, 2010
The attacks on Google and 33 other companies that were announced this week have been named Operation Aurora by McAfee. The attack was extremely sophisticated using dozens of pieces of malware, encryption and zero-day vulnerabilities to compromise their victims networks.
This is going on all the time. Most civilians probably don’t realize that there is a cyber war going on all time around them.
Sunday, January 17, 2010
Sometimes it is better late than never. Hopefully this is one of those cases. There have been reports all over the internet about China hacking Google and Google’s response by turning off their censoring services.
One of the things that I am taking away from this is the ability for a company/organization to be on equal footing with a country. The power has been shifting for decades from government to corporation. If a corporation is large enough to force a government to bend to its will then it is pretty obvious who is in control.
In this case China isn’t bending but the story isn’t over yet so it will be interesting to see how it ends.
Friday, January 15, 2010
I have been in a team meeting/training all week and have had no time to read let alone write on all of things going on in the big bad world of security this week. I figured I would start off with some data breach news.
Now, data breaches are going to happen. As long as there is information that criminals want to get then they will find a way to get it. But in this case it is really just people being stupid. Apparently there were groups of users sharing user names and passwords to access their portfolio site. Common sense security.
