09 September 2011

Syria's Cyberthugs | #arabspring #revolution #bashir

The embattled government of Syrian PresidentBashar al-Assad has pulled no punches in holding on to power throughout the country's months-long uprising.

First, street thugs beat back the protesters. Then, tanks. Now, Assad has apparently turned to an army of mostly anonymous propagandists to sway public opinion in his favor on the Facebook pages of Western media organizations.

 We've seen this Syrian Electronic Army, as it's been dubbed, firsthand.

Link: http://bit.ly/mYtUnK

Thursday evening BART protests affect evening commutes | #SFBart #OpBart #protest

CBS News Poll analysis by the CBS News Polling Unit: Sarah Dutton, Jennifer De Pinto, Fred Backus and Anthony Salvanto.
[/i]Ten years the Sept. 11 terrorist attacks, most Americans believe their country will always have to live with the threat of terrorism, a new CBS News/New York Times poll finds. But they don't expect a terrorist attack anytime soon.

Read full article: http://bit.ly/rmX2TZ

Most say US will always face terrorism threat | #WMD #cyberwar #DHS

CBS News Poll analysis by the CBS News Polling Unit: Sarah Dutton, Jennifer De Pinto, Fred Backus and Anthony Salvanto.
[/i]Ten years the Sept. 11 terrorist attacks, most Americans believe their country will always have to live with the threat of terrorism, a new CBS News/New York Times poll finds. But they don't expect a terrorist attack anytime soon.

Read full article: http://bit.ly/nDyZWw

How StartCom Foiled Comodohacker: 4 Lessons | #diginotar #ssl #ca

Strategic Security Survey: Global Threat, Local Pain (click image for larger view and for full slideshow) Based on the boasts of "Comodohacker," he's compromised six certificate authorities (CAs) this year, including Comodo in March and DigiNotar in July. He's also claimed to have exploited at least four more, including GlobalSign.


But the Comodohacker also said that he was unable to hack into StartCom Certification Authority, despite managing to access its network and a hardware security module (HSM). "I already connected to their HSM, got access to their HSM, sent my request, but lucky Eddy . . . was sitting behind HSM and was doing manual verification," according to a Comodohacker post.


Read full article: http://bit.ly/ooAB9I

Google Contacts Iranian Users to Secure Gmail Accounts | #diginotar #ssl #cyberwar

Google is directly contacting users in Iran, who may have been compromised by a rogue SSL certificate, to recommend measures to secure their accounts.

While Google's internal systems were not compromised, it is directly contacting possibly affected users and providing information on securing their accounts because its top priority is to protect the privacy and security of its users, Eric Grosse, vice president of security engineering, said in a blog post late Thursday.

Read full article: http://bit.ly/oGhFih

Apple Delays DigiNotar SSL Update, Partners 'Not Surprised' | #ssl #evssl #verisign


More than a week after a DigiNotar hack that prompted Google (NSDQ:GOOG), Mozilla andMicrosoft (NSDQ:MSFT) to blacklist hundreds of fraudulent secure socket layer certificates, Apple(NSDQ:AAPL) users are still without a security update protecting them from spoofs and man-in-the-middle attacks stemming from the bogus certificates.

But while alarming, Apple's failure to issue an update protecting its customers from hundreds of compromised SSL certificates issued by Dutch certificate authority DigiNotar is not entirely surprising given the company's longstanding history regarding security, security solution providers said Thursday.

Read full article: http://bit.ly/nOcUnE

08 September 2011

Would the United States win a cyberwar? | #apt #hackers #NSA

A while back I taught a week-long class for aspiring hackers, a war room of sorts with attack and defend scenarios, points tallied for successful exploits, and stuff like that. We balanced the war room with plenty of classroom and lecture time. One of the questions raised by the students, directed at a visiting law enforcement head during a lecture, was, "How prepared would the U.S. be for a large-scale cyberattack?" The answer: "Not at all."

This was a couple years back. Since then we're seeing the accelerated ramp-up of U.S. defenses against potential cyberattacks, complete with a raft of new legislation. Conversely, headlines are starting to pop up about attacks with "state-sponsored fingerprints" all over them. We've seen attempts at cooperation across national lines to track agile, cross-border criminals. Companies are ramping up their defenses and wrestling with their security posture and policy to fight things like advanced persistent threats (APT) and other emerging threats. So, let's say we posed the same question again, two years later: How would the United States do in a large-scale cyberattack?"


Read full article: http://bit.ly/nzyGNv

Facebook hacking tool hacks hackers | #bitdefender #hackers #skiddies

A case of criminal irony: Tools built to help hackers break into Facebook accounts have been found hiding malware that infects the computers of the would-be criminals who download them.

The security firm Bitdefender detected three separate tools in the past two days, all of which promise fledgling Facebook fraudsters an easy and free way to steal people's passwords and gain access to their photos.

Link: http://bit.ly/pLPcr7