Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

How Close is the US to Experiencing a Digital Pearl Harbor?

By Carl Weiss
Franklin Delano Roosevelt, 1933. Lietuvių: Fra... 
“December 7, 1941 – A date that will live in infamy.”

Who can ever forget President Roosevelt’s utterance of those fateful words that propelled the United States headlong into World War II?  The fact that the Japanese sneak attack spurred our reluctant country into joining the expanding European and Asian conflict seventy three years ago is not forgotten.  However, what has been lost during the intervening decades is the fact that the US had known through a series of intercepted and decoded diplomatic communiqués that a Japanese attack was imminent.  Yet the administration did little to take defensive action.

The reason that I bring up this fact is to remind us that unless we heed the lessons learned from history we are doomed to repeat them.   While there are a number of people who still view Franklin D. Roosevelt’s inaction in the days leading to the December 7 attack as a conspiracy designed to force the US to become involved in WWII, an argument can be made that this was just another case of bureaucracy in action.  You will recall that prior to the attack the majority of the American public was against entering the war. Several outspoken celebrities including Charles Lindbergh were especially vocal in their opposition.  At the time nobody in the administration wanted to rock the boat and wind up losing the next election.

Seventy three years later, this country is faced with a similar threat.  Not one of imminent attack from the skies on an isolated military installation, but an attack that could affect every man, woman and child in our country.  Moreover, this attack could very well disrupt the infrastructure that we all depend upon to live and work.  I’m not talking about nuclear fire raining down from the sky.  While the Cold War nearly turned hot on several occasions, currently the threat of nuclear conflagration is not high.  What is highly likely is that the next Pearl Harbor will not come in the form of a missile’s contrail.  The biggest threat to national security today comes at the stroke of a computer keyboard. 

The Threat of Cyberwar Rears its Ugly Head

Just like the Japanese in 1940, there are forces at work who have been testing our defenses and with whom we are reluctant to deal with since they are also business partners.  While more than one nation has used computer hackers to steal industrial and military secrets, none has done so more brazenly than China.  For more than ten years that US government has been aware that Chinese hackers have broken into scads of corporate and government computers.

Timeline provided courtesy of USCyberLabs 

2003 – Titan Rain was the US designation given to a coordinated series of attacks on US computers that were labeled as Chinese in origin. Through the use of proxy servers and zombie computers, the identity and locations of the hackers were never identified, so it was not known for certain whether the attacks were perpetrated by state-sponsored hackers or whether they were carried out by corporate entities.  However, theses penetrations occurred in close proximity to other Chinese cyber attacks perpetrated against government and commercial interests in Taiwan.

2004 – The media report attacks against several US military installations.

2005 – In December 2005 the director of the SANS Institute said the 2004 attacks were “most likely the result of Chinese military hackers attempting to gather information on US systems.”

2006July: Media reported that the US State Department was recovering from a damaging cyber attack.
            August: Claims of Congressional computers being hacked are made.
            November: US Naval War College computer infrastructure reportedly attacked.

2007June: The Chinese government hacked a noncritical Defense Department computer system.
            June: Office of the Secretary of Defense computers attacked via malicious email.
            June:  US Pentagon email servers compromised for an extended period.  (Cost to correct $100 million.)
             June: American Military warns that China is gearing up to launch a cyber war on the US targeting computer networks that specialize in trade and defense secrets.
              July: Oak Ridge National Laboratory targeted by Chinese hackers.

2008 May: US Commerce Secretary laptop investigated for data infiltration.
            November: Hacking of White House computers alleged.

2009March: China’s global cyber-espionage network GhostNet penetrates 103 countries and infects at least a dozen new computers every week.

2010January: Operation Aurora attacks against Marathon Oil, ExxonMobil and ConocoPhillips.  Yahoo, Symantec, Northrop Grumman, Morgan Stanley and Dow Chemical were also targeted.
             November – A security report to the US Congress warns that hacking of 15 percent of the world’s Internet traffic by a Chinese telecom firm may have been malicious.

In 2011 and 2012 the Chinese hack attacks had ramped up to epic proportions, targeting everything in this country from information and military technology to satellites and telecom infrastructure to transportation, navigation and energy technology.  By 2013 the attacks had become so widespread that the joke in Washington was that, “If you aren’t being hacked by the Chinese, then you probably don’t matter.”

A February 25 article in the Washington Post stated, “Start asking security experts which powerful Washington institutions have been penetrated by Chinese cyberspies,” report my colleagues Craig Timberg and Ellen Nakashima, “and this is the usual answer: almost all of them.”

Even more shocking was the fact that at the time not only was it known which unit in the Chinese military was responsible for perpetrating many of the electronic break ins (Unit 61398), but it was also known where the unit was located. (The 12-story building at right located on the outskirts of Shanghai is the headquarters of Unit 61398 of the People’s Liberation Army.) 

What’s more troubling still is the lack of response from the federal government to these overt attacks.  Other than toothless rhetoric, little was done to confront China regarding its policies of wanton state-sanctioned hacking.  It wasn’t even until 2012 that anyone from the US Government even presented the Chinese with proof that American companies were being hacked.  During the four-hour meeting attended by two members of the State Department and one from the Pentagon, Chinese diplomats were shown extensive case studies that proved conclusively that Chinese state-sponsored  hackers had penetrated US defense and corporate computer networks. 

The Chinese response as reported by the WashingtonPost: ‘This is outrageous!’ ” a second former official said. “ ‘You’re here and you accuse us of such a thing? We don’t do this.’ ”

And until May 19, 2014 other than saber rattling, that’s all that the US was prepared to do about it.  That’s the date when a US grand jury indicted five Chinese individuals for allegedly targeting six American companies for stealing trade secrets. 

According to Newsweek, “The move "indicates that DOJ has 'smoking keyboards' and (is) willing to bring the evidence to a court of law and be more transparent," said Frank Cilluffo, head of the Homeland Security Policy Institute at the George Washington University.  

What’s interesting about the indictments is the fact that it only concerns corporate espionage.  There is nothing in the charges relating to the Defense Department or US infrastructure breaches that could be far more devastating to this country than the theft of trade secrets.  While several people at the State Department thought that the indictment sent a strong message to the Chinese, others lamented the fact that the charges won’t slow China’s cyber attacks down one bit.

Indicting five Chinese is like bringing charges against a drop of water in the ocean.  Unit 613898 alone employs thousands of hackers and has been implicated in attacks on hundreds of American companies, including cyber security firms and government defense contractors.  They have also purportedly gained access to the networks of a company that helps in the operation of the US utility grid.

Michael Chertoff, the former secretary of Homeland Security summed it up best when he said, “We are in a race against time.” 

Speaking of time, just as in 1941 will the government continue to twiddle its thumbs until it is too late to prevent a disaster that will forevermore be burned into this country’s consciousness? Unlike the Japanese battle cry of  "Tora! Tora! Tora!" that rang out as their attack took place in Oahu on that fateful December day, with the Chinese it is more likely to be one of Data! Data! Data!


Carl Weiss is president of Working the Web to Win, a digital marketing agency based in Jacksonville, Florida.   You can listen to Carl live every Tuesday at 4pm Central on BlogTalkRadio.
Enhanced by Zemanta

In an Age of Cyber Surveillance, Can You Protect Your Privacy?

Listen to internet radio with workingthewebtowin on BlogTalkRadio

By Carl Weiss

Like him or loathe him, Edward Snowden let the cat out of the bag when he revealed that the NSA was using digital surveillance including phone and internet monitoring of millions of Americans.  While some people label him a traitor, others including Rep. Justin Amash (R-Mich.) call him a whistleblower. The Michigan Republican himself admitted that were it not for Snowden’s revelations, Congress as well as the public was in the dark as to the breadth and scope of the NSA’s nefarious activities.

English: Congressman Justin Amash
English: Congressman Justin Amash (Photo credit: Wikipedia)
“Without his doing what he did, members of Congress would not have really known about [those 
programs],” Amash said. “Members of Congress were not really aware on the whole about what these programs were being used for and the extent to which they were being used. Members of the intelligence committee were told, but rank-and-file members really didn’t have the information.” http://rt.com/usa/amash-snowden-whistleblower-congress-068/

While this revelation comes as something of a surprise to the public at large, what is even more shocking is the fact that the NSA isn’t the only government agency known to be digging up dirt on Americans.  A recent newsfeed has revealed that a DEA surveillance unit known as the Special Operations Division has been passing information gleaned from its own wiretaps, informants and metadata to the FBI and Homeland Security, among others.  Like the NSA, the DEA has been cutting corners by illegally sharing information that is has nothing to do with potential terrorist threats.

In a recent article by Reuters entitled, “SecretiveDEA Surveillance Unit Makes NSA Look Like Happy 
Hour,”  investigative Journalists John Shiffman and Kristina Cooke discovered that the DEA blatantly instructed other agencies to cover up where they received their information.

English: The Seal of the United States Federal...
One federal agent from a different agency who worked with the Special Operations Division told Reuters, "You'd be told only, ‘Be at a certain truck stop at a certain time and look for a certain vehicle.' And so we'd alert the state police to find an excuse to stop that vehicle, and then have a drug dog search it." 

The question that every American should be asking is not “What other agencies are busy eroding our freedom?”  What they really should be asking is, “Who is watching the watchers.”  It certainly isn’t Congress or the White House.  Just as important if not more so should be the proviso, “If the government isn’t going to protect my privacy, what can I do about it?”

This is a question that has a number of possible solutions.  In the first place, don’t make it so darned easy for every peeping G-Man to glean your personal information.  Below are several measures that every citizen can employ with ease.

      1.      Open a Private Session in Chrome or Firefox – If you are logged into Google literally every keystroke is 
      monitored and stored by Google.  Want to give Google the shake?  Simply click on the Customize and Control button at the far right on Chrome that looks like three diminutive orange bars stacked one atop the other.  The third option from the top reads, “New incognito window.”  By clicking on this, or by hitting Control+Shift+N, Chrome will pop up a new tab, along with the following:

You've gone incognito. Pages you view in this window won't appear in your browser history or search history, and they won't leave other traces, like cookies, on your computer after you close all open incognito windows. Any files you download or bookmarks you create will be preserved, however.

Going incognito doesn't affect the behavior of other people, servers, or software. Be wary of:
  • Websites that collect or share information about you
  • Internet service providers or employers that track the pages you visit
  • Malicious software that tracks your keystrokes in exchange for free smileys
  • Surveillance by secret agents
  • People standing behind you
Learn more about incognito browsing.
Because Google Chrome does not control how extensions handle your personal data, all extensions have been disabled for incognito windows. You can reenable them individually in the extensions manager.

Google Chrome
Google Chrome (Photo credit: thms.nl)
      2.      On the same Customize and Control button a little further down is an option that is labeled “History.”  Hitting this option brings up all your latest web browsing along with a button that reads, “Clear Browsing Data.”  By hitting this button, you will also clear your download history, delete cookies along with other plug-in data and empty the cache.  You should do this on at least a weekly if not daily basis if you want to erase your online footprints and flush out any cookie-based adware.  Cookies by and of themselves are not malicious by nature.  They are merely text files that can be used to store and share information.

In a search of webopedia.com, a blog entitled, “Do Cookies Compromise Security?,” states that,
 If you have ever returned to a site and have seen your name mysteriously appear on the screen, it is because on a previous visit you gave your name to the site and it was stored in a cookie so that when you returned you would be greeted with a personal message. A good example of this is the way some online shopping sites will make recommendations to you based on previous purchases. The server keeps track of what you purchase and what items you search for and stores that information in cookies. Web sites will often use cookies to keep track of what ads it lets you see and how often you see ads.

Cookies do not act maliciously on computer systems. They are merely text files that can be deleted at any time - they are not plug ins nor are they programs. Cookies cannot be used to spread viruses and they cannot access your hard drive. This does not mean that cookies are not relevant to a user's privacy and anonymity on the Internet. Cookies cannot read your hard drive to find out information about you; however, any personal information that you give to a Web site, including credit card information, will most likely be stored in a cookie unless you have turned off the cookie feature in your browser. In only this way are cookies a threat to privacy. The cookie will only contain information that you freely provide to a Web site.

     3.      Antimalware Programs – No matter the platform or operating system all computers, including Smartphones are vulnerable to viruses and malware.  While malware is designed for a number of purposes, 
ad-aware_07
ad-aware_07 (Photo credit: b1ue5ky)
      including identity theft, corporate espionage, spamming, creating unwanted popup ads or other malicious designs, the best way to stop cyber thieves from robbing you blind is to stop them before they walk through the door.   This is what antimalware programs are all about.  While there are a number of highly touted antimalware creators out there, all of them share one vital trait: They are all designed to block malicious software from entering your system in the first place.  They also need to be updatable since malware continually evolves. If your antimalware package has expired and you have neither renewed nor updated it in more than a month, then you are leaving the door wide open to malware.  Worst of all is the fact that there a number of ways that your system can be breached, including the following:
How Malware Gets On Your Computer
Malware, spyware, and other junk software makes it onto your computer for a number of reasons:
·         You installed something you really shouldn’t have, from an untrustworthy source. Often these include screensavers, toolbars, or torrents that you didn’t scan for viruses.
·         You didn’t pay attention when installing a “reputable” application that bundles “optional” crapware.
·         You’ve already managed to get yourself infected, and the malware installs even more malware.
·         You aren’t using a quality Anti-Virus or Anti-Spyware application.
·         You’ve using Apps on your Smartphone or Tablet that’s are not protected with antivirus/malware software and you’re computer is being back door hacked through shared files.
·         You’re letting your kids run amuck on your computer system by not teaching them proper computer safe usage and what to avoid?


     4.      Encryption – While encryption software that is able to withstand NSA snooping is readily available, hardly anyone uses it.  Moreover, it’s nothing new.  Even as far back as 1995, the government knew that it was possible for the average citizen to add encryption software to any computer system. 

“The ability of just about everybody to encrypt their messages is rapidly outrunning our ability to decode them,” a U.S. intelligence official told U.S. News & World Report in 1995. By the end of the Clinton administration, the government conceded that the Internet had made it impossible to control the spread of strong cryptographic software. But more than a decade later, the cypherpunks seem to have lost the war. 

Better still, the same encryption algorithms that can keep prying government agencies at bay would certainly prove deterrent enough to thwart cyberthieves.  While they might be able to hack into your system, if they didn’t possess the decryption key al they would come away with was a bunch of nonsense.  With everyone clamoring for privacy, why hasn’t encryption come bundled into every computer, tablet and Smartphone on the planet?

One of the reasons that encryption systems have not received widespread use is due to the fact that anyone you wished to email or text would also need the decryption key in order to read your message.  Other wildly popular email and messaging systems would also be affected.

Take Gmail, for example. “If you wanted to prevent government snooping, you’d have to prevent Google’s servers from having a copy of the text of your messages,” Halderman says. “But that would make it much harder for Google to provide features like search over your messages.” Filtering spam also becomes difficult. And end-to-end encryption would also make it difficult for Google to make money on the service, since it couldn’t use the content of messages to target ads.
A similar point applies to Facebook. The company doesn’t just transmit information from one user to
Image representing Facebook as depicted in Cru...
Image via CrunchBase
 another. It automatically resizes users’ photos and allows them to “tag” themselves and their friends. Facebook filters the avalanche of posts generated by your friends to display the ones you are most likely to find the most interesting. And it indexes the information users post to make it searchable. http://www.washingtonpost.com/blogs/wonkblog/wp/2013/06/14/nsa-proof-encryption-exists-why-doesnt-anyone-use-it/

      5.      Use better usernames and passwords. This might seem like a small item but many usernames and passwords are easy to guess. Especially if you have hacking software to help you crack the code. Make your user name longer and unique. Also make sure your passwords are at least 10 characters long and include upper and lower case letters, at least one number and at least one special character. This type of password is many times more difficult to crack than the 8 digit all letter ones that most people use.


The bottom line when it comes to security, the American public needs to decide which is more important, privacy or convenience.  Because in this wired world of ours, you can’t have it both ways.

Carl Weiss is president of W Squared Media Group, a company that specializes in digital marketing.  You can hear Carl every Tuesday at 4 pm on Working the Web to Win.
Enhanced by Zemanta