Tuesday, February 24, 2015

VA Secretary Robert McDonald apologizes for misstating military record - The Washington Post


You can be outraged if you can state, without looking it up, the difference between Special Forces and Rangers. How many of us can do that?  Some Special Forces don't think this is that big of a deal either. 

From the article:

Wood quoted retired Army Col. Gary Bloomberg, a former Special Forces commander, calling McDonald's claim "a boneheaded statement." But Bloomberg said he and other former special ops officers did not consider it as egregious as some other misrepresentations.

"No one got really crazy about the whole thing, compared to some of what we've seen," he told the Huffington Post. "It's a lot different from guys running around faking their special forces credentials. … I can see [other former special forces soldiers] going, 'Hey, check out this boneheaded remark,' but I don't see the gravitas that I would with a guy wearing medals he didn't earn.'"

Monday, February 23, 2015

What Good is Tor in 2014?

 Tor is not a privacy slam dunk. #NewAmCyber

It's probable, especially in the wake of the recent NSA revelations, that government agencies such as the NSA and CSIS sniff traffic on many exit nodes.


More:
http://resources.infosecinstitute.com/good-tor-2014/

Friday, February 20, 2015

Replacements - The Ledge Lyrics

 I have heard this song at least a thousand times, but I've never looked at the lyrics.

Wow. Strong and sad. I think I knew that kid.

I'm glad I was able to get tickets today.

See you guys in DC in May.

http://www.metrolyrics.com/the-ledge-lyrics-replacements.html

Thursday, February 12, 2015

Jeb Bush just revealed the social security numbers of a bunch of former constituents


Dear "eGovernor" Bush,
Privacy protection is an important part of the job. Who is your security officer? You have a security officer, right?

In a ham-handed effort at transparency, the likely 2016 Republican presidential candidate Jeb Bush just released a trove of emailsfrom his time as Florida's governor—but the emails included confidential messages, personal information and even social security numbers from thousands of people. What was he thinking?

The un-redacted email dump was first identified by the Verge, which found emails that, among other things, discussed the firings of public employees. In some emails, petitioners sent their social security numbers to Bush, who was famously responsive to email inquiries from his constituents.


Friday, January 30, 2015

I was quoted in an FCW article on mobile device security.



Striking a balance with mobile device security


Agencies face a delicate balancing act when it comes to providing mobile security.

On the one hand, IT departments seek to extend endpoint security to a growing population of mobile devices. It's easy to see why: Smartphones can go missing along with agency data, and mobile devices in general can introduce malware to enterprise networks. On the other hand, employees want the ease of use of consumer technology, and agency managers covet the potential productivity boost.

More:
http://fcw.com/articles/2014/12/08/striking-a-balance-with-mobile-device-security.aspx


Saturday, January 24, 2015

Best Alternatives to Tor: 12 Programs to Use Since NSA, Hackers Compromised Tor Project

 Here are a list of programs you can use now that Tor has been breached (Note that some of them like Disconnect and Peerblock are not full-scale replacements for Tor and Tails uses Tor):

More:
http://www.idigitaltimes.com/best-alternatives-tor-12-programs-use-nsa-hackers-compromised-tor-project-376976

Thursday, January 15, 2015

New CISSP Domains



CISSP Domains, Effective April 15, 2015

  • Security and Risk Management (Security, Risk, Compliance, Law, Regulations, Business Continuity)
  • Asset Security (Protecting Security of Assets)
  • Security Engineering (Engineering and Management of Security)
  • Communications and Network Security (Designing and Protecting Network Security)
  • Identity and Access Management (Controlling Access and Managing Identity)
  • Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
  • Security Operations (Foundational Concepts, Investigations, Incident Management, Disaster Recovery)
  • Software Development Security (Understanding, Applying, and Enforcing Software Security) 

Saturday, December 6, 2014

Crews maintaining 450 ICBMs had just one wrench with which to attach nuclear warheads



Staff at bases in North Dakota, Wyoming and Montana had to send the toolkit to each other via FedEx, the review found. Mr Hagel said that problem had now been rectified.

Inspectors reportedly ignored the fact that ageing blast doors at nuclear silos would no longer seal shut.

On staffing, the reviews found that a culture of micromanagement and extreme exam-testing distracted from major problems with equipment and nuclear readiness.


Thursday, December 4, 2014

Sony Kept Thousands of Passwords in a Folder Named "Password"


I especially like ALL_SSL_Certs_2012.xlsx!

The second trove of data snuck out sometime yesterday, and it didn't take long for Buzzfeed to stumble upon the Facebook, MySpace (an ancient form of Facebook), YouTube, and Twitter "usernames and passwords for major motion picture social accounts." Likely due to the fact that they were saved in a huge file called "Password." Which contained even more passwords called things like "Facebook login password." So they would know that that was the password. Because who needs encryption or security or common sense or even the vaguest attempt at grade-school level online safety.

Friday, November 28, 2014

Cheap Black Friday Android tablets: Security threats found

 "Bluebox Labs purchased over a dozen of these Black Friday 'bargain' Android tablets from big name retailers like Best Buy, Walmart, Target, Kmart, Kohl's and Staples, and reviewed each of them for security," the company wrote on its blog. "What we found was shocking: most of the devices ship with vulnerabilities and security misconfigurations; a few even include security backdoors. What seemed like great bargains turned out to be big security concerns. Unfortunately, unsuspecting consumers who purchase and use these devices will be putting their mobile data and passwords at risk."

More:
http://bgr.com/2014/11/26/cheap-black-friday-android-tablets/

Tuesday, November 11, 2014

New Attack Method Can Hit 95% Of iOS Devices

 FireEye recommends that organizations warn users to protect themselves three ways. One, users shouldn't install apps from third-party sources other than Apple's official store or an enterprise app store. Two, users shouldn't click on install buttons on a pop-up from third-party web pages. Three, if iOS shows an alert with an "Untrusted App Developer" warning, users should click "Don't Trust" and uninstall the app immediately.

More:
http://www.darkreading.com/new-attack-method-can-hit-95--of-ios-devices/d/d-id/1317359

Saturday, October 25, 2014

IAF asks personnel not to use Xiaomi phones

 IAF personnel and their families have been asked to desist from Chinese 'using Xiaomi Redmi 1s' phones as these are believed to be transferring data to their servers in China and could be a security risk.

"F-secure, a leading security solution company, recently carried out a test of Xiaomi Redmi 1s, the company's budget smartphone, and found that the phone was forwarding carrier name, phone number, IMEI (the device identifier) plus numbers from address book and text messages back to Beijing," says an advisory issued by the IAF to its personnel.

The IAF note, issued some weeks back, has been prepared by the intelligence unit based on the inputs from Indian Computer Emergency Response Team (CERT-In), according to IAF sources.

More:
http://m.timesofindia.com/india/IAF-asks-personnel-not-to-use-Xiaomi-phones/articleshow/44926994.cms

Thursday, October 23, 2014

New Fitbit activity tracker release, price, specs, new features



Here we look at what to expect from the next Fitbit tracker, when it will be available, and what it will cost. We're basing our report on the latest rumours and leaks, historical data, rival trackers, and recent Fitbit trademark applications for a Fitbit Surge, Fitbit Charge and PurePulse. In what may be no coincidence, just weeks after the razzmatazz unveiling of the Apple Watch, first Gizmodo then The Verge suddenly get leaked information each on one of the new trackers.

Fitbit Charge activity tracker leak

New Fitbit Charge and Charge HR trackers: new features – Force replacement and heart-rate monitor


More:
http://mobile.pcadvisor.co.uk/features/gadget/3531709/new-2014-fitbit-surge-charge-activity-tracker-release-date-price-specs-features/

Thursday, October 16, 2014

This POODLE bites: exploiting the SSL 3.0 fallback


SSL 3.0 is nearly 18 years old, but support for it remains widespread. Most importantly, nearly all browsers support it and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.

Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.

Tuesday, October 14, 2014

Truly scary SSL 3.0 vuln to be revealed soon: sources



Gird your loins, sysadmins: The Register has learned that news of yet another major security vulnerability - this time in SSL 3.0 - is probably imminent.

 

Maintainers have kept quiet about the vulnerability in the lead-up to a patch release expected in in the late European evening, or not far from high noon Pacific Time.

 

Details of the problem are under wraps due to the severity of the vulnerability.

 

To that end it is unknown what platforms were impacted, but as SSL is very widely used any flaw will require plenty of urgent attention ... and probably be unwelcome news to a tech community already reeling from the recent Shellshock vulnerability in Bash and the Heartbleed flaw.

 

The SSL flaw won't be the only thing keeping security bods and system administrators busy. A dangerous worm has been discovered exploiting a zero-day flaw (CVE 2014-4114) in all versions of Microsoft Windows and Server 2008 and 2012.

 

From:

http://www.theregister.co.uk/2014/10/14/nasty_ssl_30_vulnerability_to_drop_tomorrow/?mt=1413288787389

Saturday, October 11, 2014

DEFCON Router Hacking Contest Reveals 15 Major Vulnerabilities



According to the rules of the contest, an entry wasn't considered valid unless the contestant also showed proof of disclosure to the manufacturer. Here's a full list of routers in which 0-days were reported in Track 0, along with our current understanding of the fix in progress:

  • ASUS AC66U; reported, but no response from the manufacturer.
  • Netgear WNDR4700; reported, but no response from the manufacturer.
  • D-LINK 865L; reported, and manufacturer confirms it is working on a fix, currently in beta.
  • Belkin N900; reported, and manufacturer acknowledgedbut was unclear on providing a fix.
  • TRENDnet TEW-812DRU; reported, and manufacturer claims all reported 0-days are fixed.
  • Actiontec Q1000; reported, and manufacturer acknowledged the report.

For details please see the full contest results.

Tuesday, October 7, 2014

OMB gives DHS new powers to scan some civilian agency networks for cyber threats



OMB added this new requirement for DHS to scan civilian agency networks in the aftermath of the Heartbleed vulnerability. During that time, DHS had to get permission from agencies to scan their networks, which delayed its mitigation strategy by a few days.

DHS made it clear in May during a House hearing that it needed Congress to give it more authorities to scan agency networks.

Andy Ozment, the assistant secretary of the Office of Cybersecurity and Communications in DHS, told Federal News Radio in an interview before OMB issued the FISMA guidance that when DHS doesn't have the explicit authorities that it needs and Congress wants them to have, it makes everything harder.

More:

Friday, October 3, 2014

Hackers’ Attack on JPMorgan Chase Affects Millions -



Until just a few weeks ago, executives at JPMorgan said they believed that only one million accounts were affected, according to several people with knowledge of the attacks.

As the severity of the intrusion — which began in June but was not discovered until July — became more clear in recent days, bank executives scrambled for the second time in three months to contain the fallout and to reassure skittish customers that no money had been taken and that their financial information remained secure.

The hackers appeared to have obtained a list of the applications and programs that run on JPMorgan's computers — a road map of sorts — which they could crosscheck with known vulnerabilities in each program and web application, in search of an entry point back into the bank's systems, according to several people with knowledge of the results of the bank's forensics investigation, all of whom spoke on the condition of anonymity.


Saturday, September 27, 2014

43% of companies had a data breach in the past year

 Even in companies that have breach plans in place, employees aren't convinced they will work. Only 30% of those responding to the survey said their organization was "effective or very effective" at creating such plans.

One reason might be that few companies seem to take the need seriously. Of the companies surveyed, just 3% looked at their plan of action each quarter. Thirty-seven percent hadn't reviewed or updated their plan since it was first put in place.

More:
http://www.11alive.com/story/news/2014/09/24/43-of-companies-had-a-data-breach-in-the-past-year/16144167/