Thursday, January 22, 2015

European govts. urge U.S. tech companies to remove terrorist-related postings from sites

Terrorism & social mediaEuropean govts. urge U.S. tech companies to remove terrorist-related postings from sites

Published 22 January 2015

The terror attacks in Paris have led French and German authorities to call on U.S. tech firms to help identify terrorist communications and remove hate speech from social media sites. The United Kingdom has also, for several months now, pressed Internet firms to be proactive in removing extremist content such as videos of sermons by radical Islamic preachers or recruitment material, from their sites. German interior minister Thomas de Maizière has called on Twitter, Facebook, and other sites to work closely with law enforcement authorities. “The less people take responsibility, the more legislators will be forced to take the initiative,” he said at a recent cybersecurity conference.
U.S. tech firms do not see themselves as digital police forces, but they fear potential laws which may limit their operations in Europe.
“Just because the vast majority of this content is found on American services doesn’t reduce their impact on French people,” said French interior minister Bernard Cazeneuve. “We won’t succeed in our fight against terrorism unless Internet actors start taking responsibility.”
The Wall Street Journal notes that these recent requests for more cooperation between U.S. tech firms and European governments contrast with calls from many of the same governments who, following the Edward Snowden leaks, criticized U.S. tech firms for being too close to law enforcement agencies. The Paris attacks certainly have much to do with this shift in rhetoric, one U.S. tech executive points out.
Two week since the attacks, French authorities have flagged and requested the removal of more than 25,000 terrorist-supporting postings on Internet sites. “It’s a major issue,” Cazeneuve said. In response, hackers linked to terror groups, including the Islamic State (ISIS), have launched almost 1,300 cyberattacks aimed to take offline French Web sites or defacing them with pro-jihadi messages. On Tuesday, French newspaper Le Monde, confirmed that hackers linked to ISIS unsuccessfully attempted to take control of its publishing tools.
“This is something we’ve never seen before,” said Vice Adm. Arnaud Coustillière, head of cyberdefense for the French army.
U.S. tech firms object to European governments’ requests for pre-emptive filtering, partly because it is challenging automatically to distinguish hate speech from sarcasm and hyperbole. Facebook’s vice president for messaging products, David Marcus, said this week that the company individually removes content which supports terrorism. “Anything remotely connected to that is generally gone from the platform the minute we see it,” said Marcus. “If there are requests from law enforcement we make sure they are real requests; if not, we fight back.”
U.S. tech firms also note that they already collaborate with foreign law enforcement authorities in matters of emergency. Following the Paris attacks, Microsoft Corp. answered French authorities’ request for e-mail content from two customer accounts within forty-five minutes. The content delivered to the FBI at France’s request is an example of existing relationships with foreign governments, said Brad Smith, Microsoft’s general counsel. “There are times, especially in emergency situations, when existing international legal processes work well.”
The next few weeks will reveal how tech companies decide to respond to European requests. One U.S. tech executive suggested that the United Kingdom, France, and Germany are pushing for faster responses “just to appear tough on terrorism.”

Tuesday, January 20, 2015

If you seek to “switch off” encryption, you may as well switch off the whole Internet

If you seek to “switch off” encryption, you may as well switch off the whole Internet

By Bill Buchanan
Published 19 January 2015

Prime Minister David Cameron has stated that the U.K. government will look at “switching off” some forms of encryption in order to make society safer from terror attacks. This might make a grand statement but it is impossible to implement and extremely technologically naïve.
Encryption is a core part of the Internet; its use is increasing every day — Google’s services, including search and e-mail, use encrypted streams, as do Facebook and Twitter and many other widely used sites. Encryption makes it almost impossible for eavesdroppers to read the contents of the traffic. It is the foundation upon which all e-commerce is based.
It’s just impossible to ban. There is no way to define a law which constrains the use of encryption. Would it be only when used in certain applications (such as email), or by disallowing certain methods (such as the encryption program PGP)? Would using a Caesar code, a cipher nearly 2,000 years old, be illegal?
Such a move would make the United Kingdom — or any country that followed suit — unsafe in which to do business. Free countries wouldn’t consider switching off encryption due to the insecurity it introduces for both consumers and businesses.
Much online content accessed in the United Kingdom is actually stored and processed outside the country. Someone who suspects that they may be monitored can set up a secure connection to a remote site in the cloud — Amazon’s for example — and store and process information there. How would this fall under any new law?
And where would the ban end? Would it include character encoding, such as the Base-64 encoding that allows for e-mail attachments, or the encoding that provides non-Roman character sets for other languages? Encryption is also the basis for cryptographic signing, a digital signature used by all manner of organizations to verify that digital content — software, audio-visual media, financial products — is what it claims to be. It is the basis of trust on the internet.
We have a right to some privacy. Few people would not object to their letters being examined or their phones being tapped — and the rights enjoyed in the days of traditional communications should be no different when applied to their modern digital equivalents.
We also have a right to protect ourselves. With major losses of data occurring regularly, whether from attacks or due to error, we need to protect ourselves and our data. Encryption of data when stored or communicated is one way of doing so. The tools used by the security services to hack systems and break encryption are largely the same used by criminal hackers — reducing encryption levels will increase our vulnerability to both.
The trouble with cryptography
Law enforcement agencies have had an easy ride with computer systems and the internet — it’s relatively easy to pull evidence from the hard drives of suspects, given the lack of security. But the increasing focus on privacy and security has put the pressure on investigators. The battle lines between the right to privacy and the need to investigate crime have been drawn.
The Internet was not designed with security in mind, and most of the protocols in use — HTTP, Telnet, FTP, SMTP — are clear-text and insecure. Encrypted versions such as HTTPS, SSH, FTPS and authenticated mail are replacing them by adding a layer of security through Secure Socket Layers (SSL). While not perfect, this is a vast improvement to a system where anyone can intercept a data packet and read (and change) its contents. The natural step forward is to encrypt the data where it is stored at each end, rather than only as it is transmitted — this avoids what’s called a man-in-the-middle attack(interception of traffic en route by a third party impersonating the recipient), and the encryption key needed to decode the message only resides with those who have rights to access it.
Keeping defense on its toes
Reading enemy communications provides a considerable advantage, so cryptography has become a key target for defense agencies. Conspiracy theories have blossomed around the presence of backdoors in cryptography software. Defeating encryption otherwise requires finding a flaw in the methods used (such as the Heartbleed bug discovered in OpenSSL) or with the encryption keys (such as weak passwords).
There has been a long history of defense agencies trying to block and control high-grade cryptography. The U.S. government took copies of encryption keys through its Clipper chip, attempted to prevent publication of the RSA public key encryption method, and dragged Phil Zimmerman through the courts after claiming his PGP (“pretty good privacy”) encryption software leaving the country was tantamount to illegally exporting weapons.
Hand me your finger
Ultimately username and password combinations alone are too insecure, as computers are now sufficiently powerful to perform brute-force attacks by checking all possible permutations of characters. The introduction of multi-factor authentication improves this by requiring two or more methods such as passwords, access cards, text messages or even fingerprints.
But Virginia Circuit Court judge Steven C. Fucci ruled last year that fingerprints are not protected by the Fifth Amendment (“no person shall be compelled in any criminal case to be a witness against himself”). This means that those using their fingerprints as access keys may have to offer them up to investigators. Unusually, the same does not apply to passwords.
The U.K. equivalent, the right to silence, also comes with encryption key-related exceptions: failing to hand them over is an offense in itself.
Encryption by default
Both Apple’s iOS and Google’s Android operating systems for phones and tablets now offer encryption by default, so that data on their devices are protected straight out of the box. Now that we carry so much data with us on our phones, one might reasonably ask why this took so long.
Of course this ratchets up the tension between privacy and police investigation. With iOS 8 and Android Lollipop, there are no electronic methods to access encryption keys from existing digital forensics tool kits, nor will the users have a password to hand over, so the encryption method technically breaches the law in both the United States and the United Kingdom. The same battle rages over the encrypted Web service Tor which law enforcement sees as a domain where crime can go undetected, but the privacy-minded advocate see as an important bulwark against authoritarianism.
The technical case for switching off encryption is simply a non-starter. In fact we are moving in the opposite direction, replacing the old, open Internet with one that incorporates security by design. If you wish to switch off encryption, it will unpick the stitching that holds the Internet together.

Bill Buchanan is Head, Center for Distributed Computing, Networks and Security at Edinburgh Napier University. This story is published courtesy of The Conversation (under Creative Commons-Attribution/No derivatives).

Concerns grow about attacks on rail systems by domestic terrorists

Concerns grow about attacks on rail systems by domestic terrorists

Published 19 January 2015

The terror attacks in Paris have renewed a sense of insecurity among residents of major U.S. cities. One of the latest Islamic State threats calls on its supporters to target and bomb key U.S. targets, including public transportation hubs, and even police stations. Law enforcement officers in New York have been ordered to remain vigilant. “Pay close attention to people as they approach and look for their hands as they approach you,” reads an internal New York Police Department safety memo which the Daily News obtained.
As DHS officials focus on assuring the American public that security agencies remain on high alert, last week’s incidents on two of the nation’s major metropolitan rail systems raised more concerns about public safety and preparedness.
Last Monday, one person died and eighty-four fell ill after heavy smoke filled the L’Enfant Plaza Metro in Washington, D.C. Officials believe an “electrical arcing event” caused the incident. “The train did not derail. There was no fire on the train. The arcing event was on the wayside, involving the third rail and the supply cables going to the third rail,” National Transportation Safety Board Investigator Mike Flanigon said. “The early indications are this did not involve terrorism but involved a mechanical failure that occurred,” White House press secretary Josh Earnest told reporters.
The following day, roughly 150 New York Fire Department firefighters responded to a three-alarm fire at a construction site in Penn Station that began before 2.30 a.m. The fire, labeled an accident, injured two firefighters. Western Journalism notes that an ISIS supporter published multiple threats on Twitter a few hours before the fire, warning that “tomorrow New York will burn” and predicting a “3:00 a.m. bomb.”
From the 1997 New York City subway-bombing plot to the attacks in Madrid (2004) and London (2005), terrorists have targeted Western rail systems. Between September 2001 and December 2011, at least 838 attacks on passenger rail systems have killed more than 1,370 people. Al-Qaeda militants in Guantanamo told interrogators in 2003 of a plot to target the D.C. metro rail system, and in 2010, Afghan-born jihadist Najibullah Zazi pleaded guilty to terrorism charges after planning to blow up New York subways. Last year, two al-Qaeda-backed terrorists were arrested after plotting to bomb and derail Canada’s rail service between Toronto and Penn Station.
Some commuters involved in the D.C. metro incident reported that the evacuation process was “poorly managed.” “It’s disheartening because there did not appear to be an emergency plan,” said longtime metro rider Lesley Lopez. Chris Geldart, director of the District of Columbia’s Homeland Security and Emergency Management Agency insists that the response was as efficient as possible giving the circumstances. “We had our firefighters go down in a smoke-filled subway tunnel with 200 people on a train and all of the people coming out of the station itself. To … do an event where we go through and do what we call a mass casualty — assess all the folks and get 84 people transferred all in the amount time that they did it — that’s a good response.”

University of Maryland opens new drone test facility

DronesUniversity of Maryland opens new drone test facility

Published 11 December 2014
The University of Maryland has recently opened a new drone test site on the Eastern Shore which will allow researchers and students to help in the safe development of drones for use in U.S. airspace. The university will partner with companies to develop projects in a safe space. Already there are plans to use drones to monitor fish populations in the nearby Chesapeake Bay, examine power lines in the southern part of the state, and perform jobs which are considered “dirty, dull [or] dangerous,” in the words of the head of the facility.
University of Maryland launches drone test facility // Source: umd.edu
The University of Maryland has recently opened a new drone test site on the Eastern Shore which will allow researchers and students to help in the safe development of drones for use in U.S.s airspace.
TheBaltimore Sun reports that after years of planning and coordination, the facility is now open for business. Last Friday, the state Economic Development Secretary Dominick Murray called the potential of the project and the technology “unbelievable.”
“[It] will give industry a place to go,” said Matt Scassero, a former Navy pilot who is in charge of the facility.
Scassero’s statement comes against a backdrop of continuing controversy over the place and role of drones in the United States. Privacy groups are wary of drones being used by law enforcement, while others fear of privacy violations by prying media. The commercial aviation industry is concerned with safety issues in crowded skies.
Many, however, see the benefits of the technology — such as their use to deliver goods, monitor agricultural sites, and measure environmental conditions around the country.
The Maryland facility opens at a time when the Federal Aviation Administration (FAA) is supporting research into how drones may be safely used by private industry. With few exceptions, industry is currently not allowed to operate drones.
The university will partner with companies to develop projects in a safe space. Already there are plans to use drones to monitor fish populations in the nearby Chesapeake Bay, examine power lines in the southern part of the state, and perform jobs which are considered “dirty, dull [or] dangerous,” in Scassero’s words.
The university has already successfully launched its first drone last week, but there is still uncertainty about how much drone use will be allowed in the future. Congress has directed the FAA to develop policies and regulations for drone flight, Currently, each operation at the site require a separate FAA authorization.
The FAA, however, is considering an amendment which would allow for certain small drones to fly at lower altitudes, but the clearances for larger models is likely further away, probably beyond two years.
“With any revolutionary or disruptive technology it always outpaces the regulations,” said Michael Toscano, the head of an unnamed drone industry group, “You don’t write laws for things you don’t know about.”
At the University of Maryland, however, they are focusing on securing a successful flight, and on how these tests can benefit the state. After the successful flight of a radio-controlled propeller craft on Friday, the team loaded it up and returned it to the campus, a symbol of what the future may bring to the site.

Terrorists develop tactics to evade U.S. drones

TerrorismTerrorists develop tactics to evade U.S. drones

Published 9 January 2015
The CIA’s use of Predator drones against Islamic militants in the Middle East began shortly after the 9/11 attacks and has increased dramatically during the Obama administration. As the number of drone strikes in Yemen increased, AQAP militants began to develop tactics to hide themselves from a drone’s sensors.

The CIA’s use of Predator drones against Islamic militants in the Middle East began shortly after the 9/11 attacks and has increased dramatically during the Obama administration. Only a handful of drone strikes were issued through much of the 2000s, but in 2012 alone, forty-one strikes were aimed at Al-Qaeda in the Arabian Peninsula (AQAP), followed by twenty-six in 2013 and twenty-three in 2014, according to the Longwar Journal. Many of these strikes have killed high valued targets including the first major strike in 2002 which killed Ali Qaed Senyan al-Harthi, and five other militants as they rode in a jeep across the desert. Anwar al-Awlaki, the American-born cleric who recruited militants across the world to join al-Qaeda in Yemen, was also killed in a drone strike in 2011.
As president the number of drone strikes in Yemen increased, AQAP militants began to develop tactics to hide themselves from a drone’s sensors.
In a recent AQAP video posted on social media sites, militants describe how fighters can avoid detection by U.S. drones. According to the Washington Times, the video, “Combating Spy Airplanes” shows a step-by-step process for making and using an aluminum-based portable body wrap which it claims will prevent the drone’s infrared cameras from detecting a human’s heat signature. “The aluminum is supposed to act like a heart barrier, keeping the fighter’s body heat from being detected by the drone camera system,” read an analysis by the Middle East Media Research Institute (MEMRI). A camouflage version of the wrap is said to help hide fighters from the drones during the day.
Whether AQAP’s body wrap is actually effective is unclear, but the idea of it shows how militants are studying U.S. military tactics, and then countering them. The homemade AQAP instructional video uses clips from the Pentagon’s official video of the Predator drone. A spokesman for U.S. Central Command, which conducts military operations in Yemen, said “For operational security reasons, we wouldn’t discuss the possible effectiveness or ineffectiveness of specific enemy (tactics, techniques and procedures) nor would we speculate on how they derive their information.”
Some military analysts question the gains made by U.S. efforts in Yemen. They claim AQAP is controlling more territory now than before. “Our long drone war against AQAP has been remarkably ineffective,” said Robert Spencer, who heads Jihad Watch. “Awlaki was killed, but AQAP now controls much of Yemen and acts at will there. They are clearly not cowed, not afraid, not on the defensive.”
Others believe that the need for terrorists to produce videos promoting tactics for countering drones means that the Predator strikes are effective. “One part of their military strategy is to distribute videos and information to followers online, particularly via Twitter and YouTube, showing that they are actively engaged in countering the impact drones have had on their capabilities,” said Steven Stalinsky, executive director of MEMR

Thursday, January 15, 2015

Cybercrime imposing growing costs on global economy

Cybercrime imposing growing costs on global economy

Published 12 January 2015
A new report has found that the cost of cybercrime to the global community and infrastructure is not only incredibly high, but steadily rising as well. The study concluded that up to $575 billion a year — larger than some countries’ economies — is lost due to these incidents. The emergence of the largely unregulated, and unprotected, Internet of Things will make matters only worse.
A new report released by the Center for Strategic and International Studies (CSIS) and the Intel Security Group have found that the cost of cybercrime to the global community and infrastructure is not only incredibly high, but steadily rising as well.
As theTelegraph reports, the study carried out by the two organizations concluded that up to $575 billion a year — larger than some countries’ economies — is lost due to these incidents. Additionally, up to 150,000 jobs could be lost in Europe due to damage from cybercrime and the theft of personal records from 40 million people in the United States, 54 million in Turkey, 20 million in Korea, 16 million in Germany, and over 20 million in China. These thefts have occurred due mostly to the vulnerability of the majority of the world’s data.
Additionally, the report broke down which types of attacks had occurred, including the percentages of “physical” attacks, data leaks, password captures, and stolen accounts. Further, the researchers found a significant rise in these events from the previous year, as well as an increase between 2012 and 2013.
The culprit? The majority of the world does not properly value the precautions needed for actual cyber security.
“One worrying finding is that 260 incidents involved organizations that have reported a data break in the past, and 60 organizations reported multiple incidents in 2013,” said Barry Kouns, president and CEO of Risk Based Security, “I would not want to be the one to explain that to stakeholders.”
Additionally, the Internet of Things (IoT), or the interconnectedness of non-human devices to the Internet, is making the damage much more severe — whether it is through cell phones, utility computers, corporate networks, or even home appliances.
“Once you connect thirty billion devices to the Internet you are opening yourself up to a much bigger attack surface,” said Neil Thacker, an Information Security & Strategy Officer for security firm Websense.
Because of this, many are seeing a greater threat to the actual infrastructure of the global community, since the IoT has been so plugged into that but is still largely unregulated — and unprotected.
These incidents are beginning to be taken more seriously following these ever-alarming numbers. The U.S. State Department has planned a summit to tackle the issue more head-on.
“The inaugural meeting…will formalize and broaden co-operation of cyber issues as envisioned during the US-EU Summit. This cooperation is founded on our shared interest in an open and inter-operable internet, and our commitment to a multi-stakeholder approach to internet governance, internet freedom, and the protection of human rights in cyberspace,” the department stated.

Obama to unveil several cybersecurity initiatives this week

Obama to unveil several cybersecurity initiatives this week
Published 12 January 2015

President Barack Obama, in anticipation of the 20 January State of the Union address, has been sharing details of his address to a generate buzz. “I didn’t want to wait for the State of the Union to talk about all the things that make this country great and how we can make it better, so I thought I’d get started this week,” Obama said last week in Michigan, where he discussed more plans for a rebounding U.S. auto industry. “I figured, why wait? It’s like opening your Christmas presents a little early.”
TheNew York Times reports that this week, Obama will focus on cybersecurity initiatives, including identity theft and electronic privacy laws, aimed at protecting citizens and the private sector.
Later today, speaking at the Federal Trade Commission, Obama will announce plans to tackle identify theft and improve consumer and student privacy. Last October, Obama signed an executive order creating the BuySecure Initiative that equipped government payment cards with chip and PIN technology that makes them more difficult to counterfeit. Today, Obama “will discuss the next steps in his BuySecure Initiative on consumer financial protection and new efforts to bring more innovation to the classroom by bringing peace of mind to educators and parents,” according to an official White House statement.
On Tuesday, at the National Cybersecurity and Communications Integration Center, Obama will discuss plans to improve cyber information sharing between the private sector and federal government. The Cyber Intelligence Sharing and Protection Act (CISPA) would encourage the private sector to share information about cyberattacks with federal agencies specifically DHS and the Justice Department, and should shield them from some privacy protection laws. Previous attempts in Congress to pass an information sharing bill failed. Representative Dutch Ruppersberger (D-Maryland), a former top Democrat on the U.S. House Intelligence Committee, reintroduced the bill last week. The bill is likely to receive more support from a Republican-led Congress.
On Wednesday, Obama will be in Iowa to announce a policy package designed to provide affordable access to broadband Internet nationwide.
On Thursday, Vice President Joe Biden in Norfolk, Virginia, will announce new funding to help train more people to work in the cybersecurity industry. Last September, roughly $450 million dollars in grants were awarded to community colleges working with employers on cyber-related job training.
The move to make cybersecurity a key White House initiative in 2015, comes weeks after the Sony Hack and months after cyberattacks on several U.S. companies including banks, retailers, and other service providers. In February 2013, Obama issued an executive order to improve cybersecurity for critical infrastructure and in February 2014, the National Institute of Standards and Technology released the Cybersecurity Framework, a set of cybersecurity guidelines for businesses and organizations.