|
Internet Security News
Breaking news and updates in Internet security
Last Updated: March 10th, 2010 20:18:23 CST -0600
Jail Sentences Not Certain For Mariposa Botnet Authors
Although the three men believed to be behind the Mariposa botnet were recently identified and arrested by Spanish authorities, it looks like they may avoid serving any jail time for their online trespasses. Spain's cybercrime laws are quite weak at the moment.
 | | Jail Sentences Not Certain For Mariposa Botnet Authors |  |
According to Brian Krebs, Captain Cesar Lorenzana, who works for the Spanish Civil Guard, explained that prison sentences typically aren't associated with deeds committed from behind a keyboard. Plus, some things simply aren't against the law.
"In Spain, it is not a crime to own and operate a botnet or distribute malware," he said. "So even if we manage to prove they are using a botnet, we will need to prove they also were stealing identities and other things, and that is where our lines of investigation are focusing right now."
Furthermore, Krebs wrote, "[T]he men are all free on their own recognizance. . . . [T]hey are free to hoover up as much stolen data as they please, as the Mariposa working group has not yet been able to shutter the Web sites that served as the repository for personal and financial data stolen from people whose systems were ensnared by the bot."
The good news is that Spain is trying to modernize its laws, so even if the Mariposa's authors get off this time, they (and/or other cybercriminals) shouldn't be in the clear forever.
McAfee: Intellectual Property Poorly Guarded In Aurora Attacks
Google and the other companies that were affected by Operation Aurora had some commendable security measures in place, according to a new report from McAfee; you might consider them the virtual equivalents of steel doors with reinforced hinges. However, it turned out that the companies might have left their internal safe doors unlocked.
 | | McAfee: Intellectual Property Poorly Guarded In Aurora Attacks |  |
George Kurtz, McAfee's CTO, explained late yesterday on the McAfee Security Insights Blog that he discovered some problems with respect to the companies' source code configuration management systems (SCMs). Enough problems to call them "inherently insecure," in fact, as he found that attackers were able to "siphon out source code or, worse, modify and add code."
Kurtz then continued, "SCMs are used by software engineers to manage their projects and are used to store source code, the crown jewels of any tech company."
And as you might suppose, leaving one's intellectual property exposed isn't the best way to run a business.
In response, McAfee is taking a closer look at how SCMs should be secured, and Perforce, which is a popular management system, has been scrutinized in what's supposed to be the first in a series of white papers.
These lessons should benefit a wide range of individuals and companies, considering that many organizations have probably modeled their security systems after what Google, Adobe, Rackspace, and other corporations hit by Operation Aurora have in place. Hopefully an Operation Aurora 2 will become impossible as a result. Or at the least, perhaps some less organized and skilled hackers will be repelled.
Meanwhile, efforts to identify the people behind Operation Aurora haven't progressed much since the last time we discussed them. A security company called Damballa did issue a statement earlier this week alleging that the hackers used a "garden variety botnet" and were "more amateur than average," but Google has disputed this claim.
Open Identity Exchange Launches
Online identity theft might become less of a problem in the future thanks to the efforts of Google, PayPal, Equifax, VeriSign, Verizon, CA, and Booz Allen Hamilton. Today, these organizations announced the formation of the Open Identity Exchange (OIX).
OIX is a nonprofit entity meant to make exchanging online identity credentials a more secure process. It's gotten off to a good start, too, having already been approved as a trust framework provider by the U.S. government.
This means that OIX solutions should at some point allow American citizens to access all sorts of vital information on the Web. Drummond Reed, Acting Executive Director of OIX, explained in a statement, "As we roll out progressively stronger levels of certification, this will empower U.S. citizens to access and manage their tax records, Social Security records, veteran's benefits, and many other government services online."
Also, "OIX is currently working on development of trust frameworks for public media, telecommunications, library services . . . and professional associations."
You may not have to wait long to see these possibilities brought to (figurative) life. In addition to being backed by so many important partners, OIX has received grants from the OpenID Foundation and Information Card Foundation, meaning it's probably in good financial shape.
M86 Security Finds URL Filters, Anti-Virus Scanners Ineffective
New data from M86 Security corroborates the widely held idea that anti-virus scanners and URL filters won't save careless Web users. Indeed, the security company estimates that more than half of all threats can evade these two means of detection, leaving people at risk from lots of nasty stuff.
 | | M86 Security Finds URL Filters, Anti-Virus Scanners Ineffective |  |
M86 Security's new report, "Closing the Vulnerability Window in Today's Web Environment," indicates that anti-virus scanning correctly identifies just 39 percent of Web threats, which isn't exactly impressive. But the practice of URL filtering fares even worse, detecting just 3 percent of threats.
Assuming these figures are accurate, something obviously needs to be done, and it seems that adding a third layer of security may be the trick.
Bradley Anstis, the vice president technical strategy at M86 Security, explained in a statement, "To counter the specific cases that we analyzed in this report, and to ensure maximum efficiency, we believe a three-pronged approach of combining URL filtering, anti-virus scanning and real-time code analysis should be best practice."
This practice achieved a 100 percent success rate in M86 Security's testing. Although people should of course exhibit caution online no matter how well-protected their computers seem to be.
Qualys Introduces Malware Scanner For Sites
The beta version of a free service has become available to help website owners keep their properties safer. QualysGuard Malware Detection is designed to scan sites for malware infections and other threats, regardless of sites' size or the site owners' physical location.
 | | Qualys Introduces Malware Scanner For Sites |  |
This service is supposed to do everything shy of solve a problem. The process starts with it conducting daily scans. Then, it'll alert sites' owners to any issues it uncovers. Finally, it should point out vulnerable snippets of code, making the removal of malware easier. All without delivering false positives.
Philippe Courtot, the chairman and CEO of Qualys, explained his company's motivation for introducing this service by stating, "We created QualysGuard Malware Detection as a way to fight against cybercrime and to make the Web a safer place for everyone."
He then continued, "This is a comprehensive free solution that arms businesses of all sizes to monitor malware threats on their web sites and take steps to remediate vulnerabilities."
Hopefully QualysGuard Malware Detection will live up to its billing. A free way of keeping sites and their visitors safe certainly sounds good, and is bound to become quite popular if it works well.
NY Mans Pleads Guilty To Selling Pirated Software Online
A New York man has pleaded guilty in U.S. District Court in Alexandria, Virginia, to criminal copyright infringement for selling more than $250,000 worth of pirated copies of popular business, engineering and graphic design software programs.
According to court documents, Robert Cimino, 59, of Syracuse, N.Y., advertised the sale of discounted popular software programs on a number of Internet advertising forums, operating under the business name "SoftwareSuite."
Customers would contact Cimino by email and would usually buy the products using PayPal. Cimino would mail them pirated copies of Adobe, Autodesk, Intuit and Quark programs he had burned to CD or DVD to the customers. Cimino admitted that from February 2006 to September 2009, he received at least $270,035 from his sales of infringing software products.
Cimino is scheduled to be sentenced by U.S. District Judge Anthony J. Trenga on May 28, 2010. Cimino faces a maximum sentence of five years in prison, three years of supervised release, a $250,000 fine, restitution and forfeiture.
U.S. Schools Fall Short On Cybersecurity Education
Young U.S. Internet users are not receiving enough education about being safe online, according to a new poll by the National Cyber Security Alliance (NCSA) and supported by Microsoft.
 | | U.S. Schools Fall Short On Cybersecurity Education |  |
More than three quarters of teachers have spent fewer than six hours on education related to cyberethics, cybersafety, and cybersecurity in the last 12 months; more than 50% of teachers reported their school districts do not require these subjects as curriculum; and only 35% taught proper online conduct.
Key highlights of the survey include:
*More than 90% of technology coordinators school administrators and teachers support teaching cyberethics, cybersafety and cybersecurity in schools. However, only 35% of teachers and just over half of school administrators report that their school districts require cyberethics, cybersafety, and cybersecurity in their curriculum.
*Low levels of integration of key cyberethics, cybersecurity, and cybersafety topics into everyday instructional activities. For example, only 27% of teachers taught about the safe use of social networks, only 18% taught about scams, fraud and social engineering, and only 19% taught about safe passwords in the past 12 months. Additionally, 32% of teachers indicated they had not taught cyberethics, and 44% of teachers had not taught cybersafety or cybersecurity.
*Differing opinions between teachers and administrators as to who is or should be responsible (parents vs. teachers) for educating students about cyberethics, cybersafety, and cybersecurity. For example, while 72% of teachers indicated that parents bear the primary responsibility for teaching these topics, 51% of school administrators indicate that teachers are responsible.
"The study illuminates that there is no cohesive effort to provide young people the education they need to safely and securely navigate the digital age and prepare them as digital citizens and employees," said Michael Kaiser, Executive Director of the National Cyber Security Alliance. "Unfortunately, we are not meeting the needs of schools, teachers, or students.
The survey also found schools rely on shielding students instead of teaching behaviors for safe and secure Internet use. More than 90 percent of schools have built up digital defenses, such as filtering and blocking social networking sites, to protect children on school networks. Those measures may help reduce the online risks children face at school, they do not prepare students to act more safely when accessing the Internet at home or on mobile devices.
Avsim Hacker (Maybe) Brought Before Cops
Perhaps people who like to spend their spare time in the cockpits of imaginary F-16s should be left alone. The man in charge of a flight simulator site that was attacked claims to have identified the hacker and forwarded information to the authorities.
 | | Avsim Hacker (Maybe) Brought Before Cops |  | Avsim is one of the best-known flight sim communities in existence. It's been around for a long time, too. Unfortunately, a hacker managed to wipe about a decade's worth of modification info and forum posts from the site's servers back in May.
Now, though, Tom Allensworth, the publisher and CEO of Avsim, has told the BBC, "We . . . have incontrovertible evidence of the individual that performed the hack. We have protected the forensic evidence and provided that evidence to the London police. We are committed to bringing justice to bear on this case."
Allensworth is confident in the outcome, too, adding, "We fully expect that the criminal complaint . . . will result in the perpetrator spending some time behind bars - under UK law." (Since Avsim's located in the US, this means he's not pushing for extradition or anything of that sort.)
Neither London's Metropolitan Police Service nor the accused individual (who hasn't been publicly named) has made any comment yet.
Email Password Hackers Present Real Threat
The next time you have something really important to tell someone, consider whether a drive over to his or her house wouldn't be a nice way of spending a few minutes. One reporter has found that it's quite easy (and perhaps all too common) for people to buy email accounts' passwords from hackers.
 | | Email Password Hackers Present Real Threat |  | Tom Jackman wrote in an article for the Washington Post, "[S]ervices as YourHackerz.com are still active and plentiful, with clever names like 'piratecrackers.com' and 'hackmail.net.' They boast of having little trouble hacking into such Web-based e-mail systems as AOL, Yahoo, Gmail, Facebook and Hotmail, and they advertise openly."
Jackman found that prices for passwords range from around $30 to $100, which means that even the average ten-year-old can probably afford these hackers' services.
Plus, unless someone important is involved or things get rather serious, law enforcement isn't terribly likely to look into (or at least resolve) the matter, because accessing a computer without authorization is just a misdemeanor in most areas and tracking down a perpetrator can be difficult.
And it doesn't help, of course, that all of these facts have now been publicized in a widely-read newspaper.
So if you've got some nasty business rivals or psycho exes, at least try to play it safe by changing your password often for as long as you're in the person's sights. Then there's always the option of putting a few more miles on the odometer, too.
Laptops, CDs Alarm Governors, Credit Unions
Today's lesson - that stuff in the physical world can pose a security threat - is a simple one. It seems to be an important one, too, as governors and credit unions are receiving unsolicited and suspicious laptops and CDs.
 | | Laptops, CDs Alarm Governors, Credit Unions |  |
The laptops may represent the more interesting development. Robert McMillan reports, "The U.S. Federal Bureau of Investigation is trying to figure out who is sending laptop computers to state governors across the U.S., including West Virginia Governor Joe Mahchin and Wyoming Governor Dave Freudenthal. . . . According to sources familiar with the investigation, other states have been targeted too . . ."
New HP laptops are apparently just showing up, unsought but ready for use, at government offices. That's fine if some Bill Gates-like figure has decided to give small gifts to our country's political leaders, of course. It's less fine if someone's trying to steal all of their passwords and whatever sort of public and private info they'd use the laptops to view.
As for the CDs, the problem appears to be smaller. Indeed, the discs probably just exposed some lapses in judgment. Malware infected CDs that were sent to credit unions were "part of an authorized pen[etration] test," according to Johannes Ulrich, who spoke with a Microsolved representative.
It doesn't look like any damage has been done, then. Just try to keep in mind the old warnings about knowing where stuff's been and gifts being too good to be true.
|