Google Search

Showing posts with label tells. Show all posts
Showing posts with label tells. Show all posts

Saturday, November 2, 2013

Former VA official tells lawmakers of state-sponsored computer hacking at VA

WASHINGTON - At least eight foreign-sponsored organizations have hacked into computer networks at the Veterans Affairs Department in recent years or were actively trying to do so, a former VA computer security chief told Congress on Tuesday.

Jerry Davis, who served as the VA's chief information security officer until February 2013, said in written testimony to a House subcommittee that the VA became aware of the computer hacking in March 2010 and that attacks continue "to this very day."

Davis said the hacking "successfully compromised VA networks and data," but he did not indicate how the information may have been used. The intrusions raise the potential for identity theft and could complicate efforts to share data with the Pentagon, long viewed as key to quicker processing of disability claims.

"The entire veteran database in VA, containing personally identifiable information on roughly 20 million veterans, is not encrypted, and evidence suggests that it has repeatedly been compromised since 2010 by foreign actors, including in China and possibly in Russia," said Rep. Mike Coffman, R-Colo., chairman of the House Veterans' Affairs oversight and investigations subcommittee.

Officials with the VA's inspector general's office said the main threat to veterans would appear to be credit card theft. They also could not point to any specific instances in which such fraud has occurred. Investigators also said hackers had obtained access to the emails of senior VA managers, but did not know what had been done with the emails.

Linda Halliday, an assistant inspector general, said investigators were seeing fewer weaknesses with the VA's computer security, but she told lawmakers that 4,000 weaknesses and vulnerabilities have not been addressed. She cited weak passwords and user accounts with inappropriate access as among the most common problems.

Stephen Warren, acting assistant secretary for information and technology at the VA, said the state of computer security at the VA was something he wrestled with continually, but the inspector general's citation of security threats dealt with what could go wrong. He said that's not the same as the removal of information from the VA's computers.

"We're talking about potential. We're not talking about actuals," Warren said in describing the computer security problem at the VA.

Warren told the hearing he disagreed with Coffman's assessment that the VA's computer systems had been compromised repeatedly by foreign entities. He said he knew of only one such instance. He declined to cite which country that involved, saying he would prefer to discuss it in a closed session.

At another point in the hearing, Warren said he was aware of more than one foreign entity that had attempted to hack into the VA's systems. He said such attacks go beyond foreign governments, but through crime syndicates seeking financial gain.


View the original article here

Tuesday, October 22, 2013

“Nej till Google!” – Sweden tells a local council that Google’s cloud is a no-go area

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Swedish bureaucrats have instructed a town in the Scandinavian country to say "No" to Google.

Salem, a municipality approximately 30km south-west of Stockholm, wanted to ink a deal to use Google Apps, but the Information Commission thought otherwise.

When I first spotted this story, my immediate thought was that it would have something to do with PRISM.

If you haven't been following computer security news lately, that's the USA's controversial programme to conduct widespread network surveillance of foreigners.

You can see why overseas jurisdictions might want to discourage their residents from using cloud services offered by companies which are themselves regulated by US law.

But Sweden's broadside against Google has nothing to do with whether the US government does or doesn't have its digital eyes on the cloud storage of non-US residents.

This is an argument directly with Google over its own privacy provisions.

The Swedish data protection mandarins already disagreed with the Municipality of Salem back in 2011, arguing that Google's contractual land-grab over its customers' data "for the purposes of providing, maintaining and improving the services" was a step too far.

The municipality apparently felt that this was reasonable because it would help to improve Google's IT-related services to everyone - in other words, that the people of Salem could tolerate this clause for the greater good of all.

But the Swedish Datainspektionen ordered Salem to renegotiate with Google, on the grounds that the clause was too open-ended to be safe.

The decision noted, amongst other things, that the contract was too loose about how the data might be handled by subcontractors, or by Google after the contract ended.

Salem did go back to the negotiating table, and came up with a revised deal last month, but it still wasn't enough for the regulators, whose decision is that the earlier shortcomings have not been addressed.

So Salem must negotiate again with Google, or find another way to deliver its IT services.

On the surface, this may sound like Nordic bureaucratic pettiness, but I think we should applaud the Swedish privacy experts here.

It's one thing to outsource your own IT services - personal email, blogging, web site, and so forth - to save time and money. That's your own choice to make.

And it's fair enough if you're a company whose customers can vote with their chequebooks (yes, they still exist, at least in Australia!) if they don't like the service provider you've chosen.

But as a "customer" of a local government, you don't have that liberty, so you are stuck with the privacy-related decisions made by your council.

I suppose, as Google's own Eric Schmidt once famously joked, "you can just move, right?"

But that's the same Eric Schmidt who's on the record as having said that "Google policy is to get right up to the creepy line and not cross it."

Let's see if Salem can win the battle to get Google to back off a bit in the next round of negotiations...

Follow @duckblog


View the original article here

Sunday, June 30, 2013

Microsoft tells all Windows 7 users to uninstall security patch, after some PCs fail to restart

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft has advised all users of Windows 7 (and the server version, Windows Server 2008) who installed a security update on Tuesday to uninstall it, after some customers found their computers would not restart or applications would not load.

Users who experienced problems described how they saw fatal system errors like the following:

Windows fatal system error

STOP: c000021a {Fatal System Error}
The Session Manager Initialization system process terminated unexpectedly with a status of 0xC000003a (0x00000000 0x00000000).
The system has shutdown.

The problem appears to be connected with Update 2823324 in Microsoft Security Bulletin MS13-036, a security update for the Windows file system kernel-mode driver (ntfs.sys).

In a blog post on the Microsoft Security Response Center, the company blamed the problem on conflicts with third-party software:

We are aware that some of our customers may be experiencing difficulties after applying security update 2823324, which we provided in security bulletin MS13-036 on Tuesday, April 9. We’ve determined that the update, when paired with certain third-party software, can cause system errors. As a precaution, we stopped pushing 2823324 as an update when we began investigating the error reports, and have since removed it from the download center.

Contrary to some reports, the system errors do not result in any data loss nor affect all Windows customers. However, all customers should follow the guidance that we have provided in KB2839011 to uninstall security update 2823324 if it is already installed.

According to media reports, computers in Brazil have been particularly badly hit - with machines continually rebooting.

Windows 7 patchMicrosoft's knowledgebase article on this issue, explains that one symptom of the bug can be that Kaspersky Anti-Virus for Windows may display a message claiming its license is invalid, and that as a consquence it may no longer provide anti-malware protection.

Microsoft has already acknowledged the issue and said that it’s working on a fix. Yes, that's right. Some people had problems with the Patch Tuesday update, so there will be an update. But in the meantime, don't update the bit that's broken.

Users are recommended to block the 2823324 security update or uninstall it if its already present. More information on how to do this is detailed in this Microsoft knowledgebase article.

Follow @gcluley

View the original article here

Sunday, April 21, 2013

Boy meets girl. Girl strips on webcam. Tells boy to do the same. Girl blackmails boy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

# And when two lovers woo
They still say, "I love you."
On that you can rely
No matter what the future brings
As time goes by. #

The famous song Dooley Wilson sang in Casablanca may have got it wrong. For the age-old romantic story of "Boy meets girl" has surely become an awful lot more complicated now the internet has come along.

At least, that's what male computer users in Singapore are discovering.

We've warned readers before about some of the dangers involved in finding love online. Such as the true story of the Facebook blind date that turned into a supermarket robbery.

Now, people are being warned about another risk of finding love in the online world - webcam extortion.

Webcam extortion. Image from ShutterstockBut it's not the familiar headline of perverted hackers blackmailing young women into stripping in front of the camera.

This time the tables have turned, and it's *men* who are being victimised by *women*, in a peculiar twist on traditional webcam extortion.

Singapore's Police Force has warned of femme fatales befriending potential victims on sites such as Facebook and Tagged.com.

The women enter steamy webcam conversations with their prey, where they strip and encourage their male victim to do the same.

What the man doesn't realise, as he feverishly rips his clothes off and agrees to engage in various sexual acts in front of the camera, is that his female love interest is secretly recording everything that's going on.

The male victim is then blackmailed for money by the woman who threatens to circulate the compromising photographs and videos.

Ouch! That must put a dampener on the evening.

Here is a video of a Singapore TV programme which reconstructed just this kind of crime. (Warning: The acting is a bit cringeworthy)

The Singapore Police Force says it has seen a five-fold increase in the number of reported cases of such web extortion - over 50 in 2012, compared to 11 the previous year.

Here is a summary of their tips to avoid you becoming the next man to be duped in such a fashion:

Always be wary of strangers befriending you on social networks. If they're suddenly showing a romantic interest in you, ask yourself honestly if it's likely that they've selected you for online love out of the billions of other internet users.Never put yourself into a compromising position on your webcam. In short, keep your clothes on.. as you can't be sure if the person at the other end isn't making a video recording. At the same time, you shouldn't give away too much personal information to someone you don't really know.If anyone does ever attempt to extort money from you online, don't pay them. Contact the police instead. You may be embarrassed about the mess you have got yourself into, but the authorities are the right ones to investigate and (hopefully) bring the culprit to justice.

The threat doesn't just lie with webcam blackmail either. You can imagine how a man, believing he is being seduced online by a sexy woman, might be all too eager to click on a link she suggests or run a malicious program on his computer. Before he knows it, his computer could be under the control of a hacker.

Be careful out there, and keep your trousers on chaps.

Follow @gcluley

Webcam and female silhouette image from Shutterstock.


View the original article here

Wednesday, November 21, 2012

Nude photos of Justin Bieber a ruse: bellybutton tells the tale! Think before you click

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Justin BieberDon't click on that photo of Justin Bieber!

It's not him, fans say.

Sure, there's the trademark bird tattoo on the left hip, but the nipples are all wrong.

A photo distributed on the internet shows a headless naked male body engaged in what might perhaps be a sexual act with himself.

It was allegedly leaked when a thief made off with the singer's laptop and camera after a show in Washington.

The gadgets contain "a lot of personal footage," the star tweeted within hours of the theft:

There's just so much wrong with this picture, and I'm not talking about Justin Bieber's pink parts.

The first bit of wrongness has to do with anybody who'd actually risk their cyber security by clicking on an alleged celebrity photo.

The land of Twitter has plenty of skeptical Twitizens, but so too does it have far too many drooling fans eager to click on JB's charms.

Take Breanna, for example:

Hopefully, young fans like Breanna have wise friends who can educate them regarding malware, which loves to hitch a ride onto PCs using come-ons like nude celebrity pictures.

Earlier this week, Microsoft released its most recent Security Intelligence Report, which showed that photos, movies, software and other media are increasingly infested with Trojans and other attack vectors.

Anybody who goes out searching for nude photos of celebrities is just asking to be taken advantage of.

There's a long history of malware authors making the most of splashy celebrity-related headlines, whether it's the death of Michael Jackson or Amy Winehouse, Rihanna sex videos or a purported video of the killing of Osama Bin Laden.

Beyond the danger of clicking on what could be malware-laced photos, what in the world is Bieber doing storing personal footage on a laptop that hasn't been properly encrypted and secured with a strong password?

Sophos's Graham Cluley made this YouTube video a while back to explain how to choose a hard-to-crack but easy-to-remember password, but if you're tackling the task of security education for Beliebers, you might want to cut right to the part where he addresses password management software programs like 1Password, KeePass and LastPass, any of which will lift the task of remembering all their different passwords.

And with that accomplished, we will leave Bieber's fans to the task of bellybutton analysis.

But do point out to them that, as the Huffington Post shows, the star's belly button is clearly an outie.

Follow @LisaVaas

View the original article here