{"id":26907,"date":"2011-08-29T03:11:07","date_gmt":"2011-08-29T02:11:07","guid":{"rendered":"http:\/\/alienbabeltech.com\/main\/?p=26907"},"modified":"2011-08-29T03:32:22","modified_gmt":"2011-08-29T02:32:22","slug":"cyber-security-%e2%80%a6-a-work-in-progress-starts-with-users","status":"publish","type":"post","link":"http:\/\/alienbabeltech.com\/main\/cyber-security-%e2%80%a6-a-work-in-progress-starts-with-users\/","title":{"rendered":"Cyber Security \u2026 a Work in Progress, Starts with Users"},"content":{"rendered":"<blockquote>\n<h6><span style=\"color: #00ccff;\">The following is by G. A . &#8220;Andy&#8221; Marken, President of <a href=\"http:\/\/www.markencom.com\/index.htm\" onclick=\"_gaq.push(['_trackEvent', 'outbound-article', 'http:\/\/www.markencom.com\/index.htm', 'Marken Communications']);\" ><span style=\"color: #00ccff;\">Marken Communications<\/span><\/a><span style=\"color: #00ccff;\"> Inc. He has kindly given us permission to republish his thought-provoking article. As with everything that we publish at AlienBabelTech, the opinions expressed are solely those of the individual writer and do not necessarily reflect the views and the <strong>opinions of the rest of the ABT staff.<\/strong><\/span><\/span><strong><span style=\"color: #00ccff;\"><span style=\"color: #00ccff;\"> \u2013Mark Poppin,<\/span> <span style=\"color: #00ccff;\">ABT Senior Editor<\/span><\/span><\/strong><\/h6>\n<\/blockquote>\n<p><strong>Black Hats, DefCon<\/strong><\/p>\n<blockquote><p><a href=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-13.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-26909\" title=\"Untitled-1\" src=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-13.jpg?resize=300%2C161\" alt=\"\" srcset=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-13.jpg?resize=300%2C161 300w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-13.jpg 367w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><strong><em>\u201c<\/em><\/strong><em>Of course, the whole point of a Doomsday Machine is lost, if you *keep* it a *secret*!\u201d<\/em> <strong>\u2013 Dr. Strangelove in \u201cDr. Strangelove or How I Learned to Stop Worrying and Love the Bomb,\u201d Columbia Pictures (1964)\u00a0 <\/strong><\/p><\/blockquote>\n<p>The annual Black Hat, DefCon events\u2026you can almost smell the cyber napalm in the morning<\/p>\n<p>While there are a lot of good things about Las Vegas (business-friendly policies), it\u2019s a logical location for a hacking, malware, cyber penetration convention.\u00a0 After all, it was founded on a fundamental human frailty \u2026 personal greed, beating the odds.<\/p>\n<p><strong>HINT:<\/strong>\u00a0 It\u2019s impossible to beat the odds!<\/p>\n<p>Unfortunately, you also can\u2019t beat the odds when it comes to protecting personal, corporate and government secrets.<\/p>\n<p>Malicious and pain-in-the-behind bad guy hacking, hacktivism wins more often than the good guys.<\/p>\n<p>It\u2019s why no one with half a brain uses any of the ATM machines when the nearly 9,000 \u201cattendees\u201d are in town. They\u2019re hacked just for the heckovit!<\/p>\n<p>It was here that Aruba wanted to demonstrate the strength of their cryptographic technology and wireless technology by provisioning the two events.<\/p>\n<p>Now that takes \u2026 well, you know!<\/p>\n<p><strong>Conference Fun<\/strong><\/p>\n<p>Seems like everyone took a whack at them, generating:<\/p>\n<p style=\"padding-left: 60px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 670 rogue attacks<\/p>\n<p style=\"padding-left: 60px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 191 AP flood attacks<\/p>\n<p style=\"padding-left: 60px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 489 AP spoofing<\/p>\n<p style=\"padding-left: 60px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 1,659 hotspot attacks<\/p>\n<p style=\"padding-left: 60px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 1,700 Block ACK attacks<\/p>\n<p>\u00a0As Major Kong said, <em>\u201cShoot, a fella&#8217; could have a pretty good weekend in Vegas with all that stuff.\u201d<\/em><\/p>\n<p>Yeah, there was a lot of fun \u2018n games; but a lot of serious business was discussed and I gotta\u2019 tell you, the future isn\u2019t all that bright.<\/p>\n<p>The \u201cnoise\u201d highlight of the two conferences was McAfee\u2019s report of a five-year global study.<\/p>\n<p>Their report (Operation Shady Rat) is available on their website but they focused on the cyber-espionage activities against 70 targets \u2013 sensitive government, business and private organizations.<\/p>\n<p>The bottom line was they had all been penetrated\/ripped off; but the real news was how long they had gone unnoticed \u2013 some for months, but many for a year or more.<\/p>\n<p>Dmitri Alperovitch, of MacAfee Labs, noted that pretty much anyone with data worth stealing had been compromised and that was just the tip of the iceberg.<\/p>\n<p>General Turgidson looked at the amount of damage being done and said, <em>\u201c<\/em><em>Gee, I wish we had one of them doomsday machines.<\/em><\/p>\n<blockquote><p><a href=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-23.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-26910\" title=\"Untitled-2\" src=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-23.jpg?resize=516%2C293\" alt=\"\" srcset=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-23.jpg?resize=516%2C293 516w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-23-300x170.jpg 300w\" sizes=\"auto, (max-width: 516px) 100vw, 516px\" data-recalc-dims=\"1\" \/><\/a><strong>Global Issue \u2013 <\/strong>McAfee\u2019s five-year study uncovered cyber penetrations everywhere, even in the most aggressively protected organizations.\u00a0 The countries, areas not shown?\u00a0 Those folks haven\u2019t uncovered the malicious, vicious work or they swept the attacks under the rug.\u00a0 Complex programming produces a lot of the openings for hackers, hactivists, cybercriminals but users who bypass organization program\/network security pose the best opportunities for getting inside.\u00a0 <strong>Source &#8211; McAfee<\/strong><\/p><\/blockquote>\n<p>The conclusion was, companies (and folks) could be divided into two categories:\u00a0 Those Global organizations that <em>know they\u2019ve been compromised <\/em>and those that <em>don\u2019t yet know<\/em>.<\/p>\n<p>Us?\u00a0 Ignorance is bliss.<\/p>\n<p>The security folks weren\u2019t ignorant of the problem though and didn\u2019t mince words in the sessions about management\u2019s poor response to all the bad things that can happen when security sucks.<\/p>\n<p>Instead of beefing up security staffs (the shows were hunting grounds for new employees), organizations were buying hack insurance.<\/p>\n<p>Why protect company information and secrets when you can pass the buck?<\/p>\n<p>As General Ripper said, <em>\u201c<\/em><em>Today, war is too important to be left to politicians.\u201d<\/em><\/p>\n<p>While Anonymous has scored some impressive penetrations in company, government and law enforcement organizations, one of the panels didn\u2019t give them much credit except for showing folks how their network security sucked.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-32.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-26911\" title=\"Untitled-3\" src=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-32.jpg?resize=520%2C271\" alt=\"\" srcset=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-32.jpg?resize=520%2C271 520w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-32-300x156.jpg 300w\" sizes=\"auto, (max-width: 520px) 100vw, 520px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<blockquote><p><strong>Packed Sessions \u2013 <\/strong>The DefCon and Black Hat sessions brought forward industry leaders and lots of discussions including concern over Net neutrality, privacy, and cyberwar activities\/concerns.\u00a0 Mudge noted that added layers of security not only add to the complexity but increase the attack surface.\u00a0 Robert Clark of the U.S. Army Cyber Command, who packed his session, said governments need to monitor\/seize data and user rights.\u00a0 <strong>Source &#8211; TechRepublic<\/strong><\/p><\/blockquote>\n<p><strong>Bad Kids at Play<\/strong><\/p>\n<p>People who hack\/secure for a living didn\u2019t think much of Anonymous or LulzSec equating their self-righteous activities to a bunch of kids sneaking into a school to smash and steal stuff.<\/p>\n<p>Releasing private, personal, secret documents may be cool; but increasingly, personal information about people is being outed ruining reputations and putting folks in danger.<\/p>\n<p>The professional hackers\/hacktivists didn\u2019t condone that type of reckless activity, since the whole objective of the two shows was to point out weaknesses in the systems and get people to correct them.<\/p>\n<p>When that doesn\u2019t happen, they let everyone know how they can get inside the organization.<\/p>\n<p>Or, if the organization is doing really bad stuff, dig it up and expose it to the world.<\/p>\n<p>Sounds reasonable to us.<\/p>\n<p>A lot of the speakers like Pieter Zatko or \u201cMudge\u201d were seasoned hackers who went legit working for businesses and organizations to improve programming\/network quality and beef-up security.<\/p>\n<p>Zatko noted that because today\u2019s systems are so complex, they\u2019re breeding grounds for malicious coders.<\/p>\n<p>A recent IBM report showed that for every 1,000 lines of code, one to five bugs were introduced, providing open doors for kids who are really good at hacking and crooks who are really \u201cinspired.\u201d<\/p>\n<p>General Ripper knew the source of the problem and explained, <em>\u201c<\/em><em>That&#8217;s the way your hard-core Commie works.\u201d<\/em><em><\/em><\/p>\n<p>Back in the good old days of the two events, it was only natural that most of the discussions centered on the big target in the room &#8212; Microsoft Windows.<\/p>\n<p>With \u201ceveryone\u201d using the OS, it was fun\/easy for hackers, crackers and attackers to beat the living c__p out of MS without even trying.<\/p>\n<p>But that has slowly changed because MS:<\/p>\n<p style=\"padding-left: 30px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u00a0is investing a lot in security technology<\/p>\n<p style=\"padding-left: 30px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 improved the quality of their programming\/development<\/p>\n<p style=\"padding-left: 30px;\">&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 has been more responsive when problems have been uncovered<\/p>\n<p>\u00a0Or\u2026it\u2019s just no fun kicking the old dog anymore.<\/p>\n<p>Then too, some folks see Windows as irrelevant in the brave new \u201cpost PC World.\u201d<\/p>\n<p>The rogues have turned their attention on Jobs\u2019 Apple.\u00a0 \u00a0The disorganized Anonymous said Mac OS X and other OSes were their big focus for the coming year.<\/p>\n<p>It wasn\u2019t a big issue when IT departments kept Macs at a safe distance.<\/p>\n<p><strong>Office Apples<\/strong><\/p>\n<p style=\"text-align: left;\">But now that companies have \u201cbent\u201d their policies, and are allowing people to BYOD (bring your own device), \u00a0security holes are becoming a major problem.<\/p>\n<p style=\"text-align: left;\" align=\"center\">We knew that Apple increasing their marketshare wasn\u2019t something that would lead to any good.<\/p>\n<blockquote><p><a href=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-42.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-26912\" title=\"Untitled-4\" src=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-42.jpg?resize=244%2C330\" alt=\"\" srcset=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-42.jpg?resize=244%2C330 244w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-42-221x300.jpg 221w\" sizes=\"auto, (max-width: 244px) 100vw, 244px\" data-recalc-dims=\"1\" \/><\/a><strong>Generation Wired \u2013 <\/strong>We will always have hackers \u2013 good and bad \u2013 who are better, smarter, faster than the generations that try to protect the Net\/users.\u00a0\u00a0 Like this 10-year-old who attended the two events, every new generation is wired differently and digging around stuff just to uncover problems, issues, opportunities is natural to them.\u00a0 Little things like security are minor inconveniences, not locks on the doors.\u00a0 <strong>Source \u2013 CNN Money<\/strong><\/p><\/blockquote>\n<p>The issue seems to be that the more secure the OS and your device, the less convenient it is to use; and you\u2019ve gotta\u2019 admit Apple\u2019s devices are easy to use.<\/p>\n<p>DefConers and BlackHatters like to point out that one of the reasons hackers, hactivists and cybercriminals succeed so well is that folks just turn off the security features to make their stuff easier to use.<\/p>\n<p>Crud\u2026we wanted it both ways!<\/p>\n<p>One of the highlights of the two events \u2013 beside hacking ATMs and rubbing shoulders with the CIA, FBI, DEA, etc.. &#8212; \u00a0is the annual Pwnie awards.<\/p>\n<blockquote><p><a href=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-52.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-26913\" title=\"Untitled-5\" src=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-52.jpg?resize=231%2C231\" alt=\"\" srcset=\"http:\/\/i0.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-52.jpg?resize=231%2C231 231w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-52-150x150.jpg 150w\" sizes=\"auto, (max-width: 231px) 100vw, 231px\" data-recalc-dims=\"1\" \/><\/a><strong>Pwnie Awards \u2013 <\/strong>Every year, companies, hackers, discoveries are \u201chonored\u201d for their inability to protect their content, for the bugs\/holes they uncovered, their deeds (good and bad).\u00a0 The conclusion from this year\u2019s DefCon, Black Hat Conference was that there will be even more awards presented next year and the malicious, vicious attacks will be bigger and more profuse.<\/p><\/blockquote>\n<p>Individuals, companies as well as malware discoverers and breakers are honored with a garish gold My Little Pony prize each year.<\/p>\n<p><strong>Prize Winners<\/strong><\/p>\n<p>Gates had a matching collection of them and he passed them on to Ballmer who also has an unbroken record.<\/p>\n<p>Sony got theirs, so did a lot of individuals who weren\u2019t able to attend because they were doing hard time.<\/p>\n<p>Then there are the folks who wanted to bask in the spotlight, but outing themselves to the crowd just didn\u2019t seem really \u201cprudent.\u201d<\/p>\n<p>Jobs won\u2019t send anyone next year&#8211;period.<\/p>\n<p>Other than a few people getting job offers, others getting ticked because they were one-upped by a **** little 10-year-old no less; Black Hat and DefCon are two conferences you can bet will be around for years.<\/p>\n<p>While attention is being focused on the bad guys\/gals and the havoc they cause, the security industry still isn\u2019t doing a good job of protecting computer users from themselves and the hostile world around them.<\/p>\n<p>Yes, law-enforcement agencies around the globe are tracking down and arresting more malicious folks and cybercriminals.<\/p>\n<p>While some of the hacking community has a strong sense of social responsibility, there are more who think nothing of hacking, defacing, exposing an organization and individuals because they feel they\u2019ve been wronged.<\/p>\n<p>Many get carried away with their own \u201cpower\u201d and hurting people because the Net gives them invisibility; and bragging about their exploits is a big ego booster.\u00a0 But there are a lot of ethical hackers out there who get a real rush out of finding a firewall hole or software bug that gives them entrance into an organization\u2019s database so the weaknesses can be corrected.<\/p>\n<p>For the rest of us who are system\/net challenged, all we can do is be cautious, skeptical, alert.<\/p>\n<p>Just remember what Major Kong said<em>, \u201c<\/em><em>I got a pretty fair idea that something doggone important is goin&#8217; on back there.\u201d <\/em><\/p>\n<p><a href=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-62.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-26914\" title=\"Untitled-6\" src=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-62.jpg?resize=390%2C252\" alt=\"\" srcset=\"http:\/\/i2.wp.com\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-62.jpg?resize=390%2C252 390w, http:\/\/alienbabeltech.com\/main\/wp-content\/uploads\/2011\/08\/Untitled-62-300x193.jpg 300w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>The hackers can be a pain in the behind, but the really bad guys?\u00a0 If it looks\/sounds too good to be true\u2026it probably is!!!<\/p>\n<p style=\"text-align: center;\"># # #<\/p>\n<p><strong>by: G.A. &#8220;Andy&#8221; Marken<\/strong><\/p>\n<p><strong> President<\/strong><\/p>\n<p><strong> Marken Communications Inc.<\/strong><\/p>\n<p><strong> <a href=\"mailto:Andy@markencom.com\">Andy@markencom.com<\/a><\/strong><\/p>\n<blockquote><p>Please join us in our <a href=\"http:\/\/alienbabeltech.com\/abt\/index.php\" target=\"_blank\">Forums<\/a><\/p>\n<p>Become a Fan on <a href=\"http:\/\/www.facebook.com\/pages\/AlienBabelTech\/123268467142\" onclick=\"_gaq.push(['_trackEvent', 'outbound-article', 'http:\/\/www.facebook.com\/pages\/AlienBabelTech\/123268467142', 'Facebook']);\" target=\"_blank\">Facebook<\/a><\/p>\n<p>Follow us on <a href=\"http:\/\/twitter.com\/alienbabeltech\" onclick=\"_gaq.push(['_trackEvent', 'outbound-article', 'http:\/\/twitter.com\/alienbabeltech', 'Twitter']);\" target=\"_blank\">Twitter<\/a><\/p>\n<p>For the latest updates from ABT, please <a href=\"http:\/\/alienbabeltech.com\/main\/?feed=rss2\" target=\"_blank\">join our RSS News Feed<\/a><\/p>\n<p>Join our Distributed Computing teams<\/p>\n<ul>\n<li>Folding@Home &#8211; Team AlienBabelTech &#8211; 164304<\/li>\n<li>SETI@Home &#8211; Team AlienBabelTech &#8211; 138705<\/li>\n<li><a href=\"http:\/\/www.worldcommunitygrid.org\/reg\/viewRegister.do?teamID=3P39R3SRV1\" onclick=\"_gaq.push(['_trackEvent', 'outbound-article', 'http:\/\/www.worldcommunitygrid.org\/reg\/viewRegister.do?teamID=3P39R3SRV1', 'World Community Grid &#8211; Team AlienBabelTech']);\" target=\"_blank\">World Community Grid &#8211; Team AlienBabelTech<\/a><\/li>\n<\/ul>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>The following is by G. A . &#8220;Andy&#8221; Marken, President of Marken Communications Inc. He has kindly given us permission to republish his thought-provoking article. As with everything that we publish at AlienBabelTech, the&#46;&#46;&#46;<\/p>\n","protected":false},"author":396,"featured_media":26915,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2533,7],"tags":[4815,4813,4814,3921,4818],"class_list":["post-26907","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-abt-news","category-technology","tag-apple-security","tag-black-hats","tag-defcon-hacking","tag-internet-security","tag-pwnie-awards"],"_links":{"self":[{"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/posts\/26907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/users\/396"}],"replies":[{"embeddable":true,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/comments?post=26907"}],"version-history":[{"count":0,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/posts\/26907\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/media\/26915"}],"wp:attachment":[{"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/media?parent=26907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/categories?post=26907"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/alienbabeltech.com\/main\/wp-json\/wp\/v2\/tags?post=26907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}