Posts

Attribution: OPM vs Sony

Image
I read  Top U.S. spy skeptical about U.S.-China cyber agreement based on today's Senate Armed Services Committee hearing titled  United States Cybersecurity Policy and Threats . It contained this statement: U.S. officials have linked the OPM breach to China, but have not said whether they believe its government was responsible. [Director of National Intelligence] Clapper said no definite statement had been made about the origin of the OPM hack since officials were not fully confident about the three types of evidence that were needed to link an attack to a given country: the geographic point of origin, the identity of the "actual perpetrator doing the keystrokes," and who was responsible for directing the act. I thought this was interesting for several reasons. First, does DNI Clapper mean that the US government has not made an official statement regarding attribution for China and OPM because all "three types of evidence" are missing, or do we have one...

Good Morning Karen. Cool or Scary?

Image
Last month I spoke at a telecommunications industry event. The briefer before me showed a video by the Hypervoice Consortium , titled  Introducing Human Technology: Communications 2025 . It consists of a voiceover by a 2025-era Siri-like assistant, speaking to her owner, "Karen." The assistant describes what's happening with Karen's household. 15 seconds into the video, the assistant says: The report is due today. I've cleared your schedule so you can focus. Any attempt to override me will be politely rebuffed. I was already feeling uncomfortable with the scenario, but that is the point at which I really started to squirm. I'll leave it to you to watch the rest of the video and report how you feel about it. My general conclusion was that I'm wary of putting so much trust in a platform that is likely to be targeted by intruders, such that they can manipulate so many aspects of a person's life. What do you think? By the way, the briefer before m...

Are Self-Driving Cars Fatally Flawed?

Image
I read the following in the Guardian story  Hackers can trick self-driving cars into taking evasive action . Hackers can easily trick self-driving cars into thinking that another car, a wall or a person is in front of them, potentially paralysing it or forcing it to take evasive action. Automated cars use laser ranging systems, known as lidar, to image the world around them and allow their computer systems to identify and track objects. But a tool similar to a laser pointer and costing less than $60 can be used to confuse lidar... The following appeared in the IEEE Spectrum story Researcher Hacks Self-driving Car Sensors . Using such a system, attackers could trick a self-driving car into thinking something is directly ahead of it, thus forcing it to slow down. Or they could overwhelm it with so many spurious signals that the car would not move at all for fear of hitting phantom obstacles... Petit acknowledges that his attacks are currently limited to one specific unit ...

Top Ten Books Policymakers Should Read on Cyber Security

I've been meeting with policymakers of all ages and levels of responsibility during the last few months. Frequently they ask "what can I read to better understand cyber security?" I decided to answer them collectively in this quick blog post. By posting these, I am not endorsing everything they say (with the exception of the last book). On balance, however, I think they provide a great introduction to current topics in digital security. Cybersecurity and Cyberwar: What Everyone Needs to Know by Peter W. Singer and Allan Friedman Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon by Kim Zetter @War: The Rise of the Military-Internet Complex by Shane Harris China and Cybersecurity: Espionage, Strategy, and Politics in the Digital Domain by  Jon R. Lindsay, Tai Ming Cheung, and Derek S. Reveron Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World by Bruce Schneier Spam Nation: The Inside Story of O...

Effect of Hacking on Stock Price, Or Not?

Image
I read Brian Krebs story  Tech Firm Ubiquiti Suffers $46M Cyberheist just now. He writes: Ubiquiti, a San Jose based maker of networking technology for service providers and enterprises, disclosed the attack in a quarterly financial report filed this week  [6 August; RMB]  with the U.S. Securities and Exchange Commission (SEC). The company said it discovered the fraud on June 5, 2015, and that the incident involved employee impersonation and fraudulent requests from an outside entity targeting the company’s finance department. “This fraud resulted in transfers of funds aggregating $46.7 million held by a Company subsidiary incorporated in Hong Kong to other overseas accounts held by third parties,” Ubiquiti wrote. “As soon as the Company became aware of this fraudulent activity it initiated contact with its Hong Kong subsidiary’s bank and promptly initiated legal proceedings in various foreign jurisdictions. As a result of these efforts, the Company has recovered $...

Going Too Far to Prove a Point

Image
I just read  Hackers Remotely Kill a Jeep on the Highway - With Me in It by Andy Greenberg. It includes the following: "I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold... To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. Instead, they merely assured me that they wouldn’t do anything life-threatening . Then they told me to drive the Jeep onto the highway. “Remember, Andy,” Miller had said through my iPhone’s speaker just before I pulled onto the I-40 on-ramp , “no matter what happens, don’t panic.” As the two hackers remotely toyed with the air-conditioning, radio, and windshield wipers, I mentally congratulated myself on my courage under pressure. That’s when they cut the transmission. Immediately my accelerator stopped w...

My Security Strategy: The "Third Way"

Image
Over the last two weeks I listened to and watched all of the hearings related to the OPM breach. During the exchanges between the witnesses and legislators, I noticed several themes. One presented the situation facing OPM (and other Federal agencies) as confronting the following choice: You can either 1) "secure your network," which is very difficult and going to "take years," due to "years of insufficient investment," or 2) suffer intrusions and breaches, which is what happened to OPM. This struck me as an odd dichotomy. The reasoning appeared to be that because OPM did not make "sufficient investment" in security, a breach was the result. In other words, if OPM had "sufficiently invested" in security, they would not have suffered a breach. I do not see the situation in this way, for two main reasons. First, there is a difference between an "intrusion" and a "breach." An intrusion is unauthorized access ...