Some news, views and musing about things going on in the Information Security World.
Monday, February 27, 2012
FBI turns off 3,000 GPS trackers after Supreme Court ruling
Andrew Weissmann, general counsel for the FBI, has announced that his agency is switching off thousands of Global Positioning System-based tracking devices used for surveillance after a Supreme Court decision last month. Weissmann made the statement during a University of San Francisco School of Law symposium on communications privacy this past Friday.
Sunday, January 8, 2012
Lack of a Backup Could Free a Killer
In a criminal case in Miami in 2009, a man named Randy Chaviano was convicted of second-degree murder committed in 2005 and sentenced to life in prison. As usual, a court stenographer was taking notes at the trial. But then there was a string of coincidences worthy of a Law & Order script.
- The stenographer didn’t have enough paper for her machine — a mistake she’d apparently made before
- Consequently, the notes she took were recorded only in the machine’s internal memory
- She transferred the stenography machine’s records to her own PC
- She deleted the records from the stenography machine
- She didn’t do a backup of the PC
- A virus hit the PC and deleted what was by then the only record of the trial, leaving only a pretrial hearing and closing arguments; it wasn’t clear when this happened
Key Words:
computer viruses,
data destruction,
security controls
Friday, January 6, 2012
Rock Solid: Will Digital Forensics Crack SSD’s?
Journalists always formulate their headlines by stating predictions they know will happen, or asking questions that they know are unlikely to happen. Whenever a headline asks a question, they are really saying 'No'
This article goes into detail about why it is nearly impossible to derive usable forensic data from an SSD drive or memory chip.
Key Words:
data destruction,
forensics,
physical security,
secure erasure,
security controls
Monday, November 21, 2011
Illinois Water Utility Pump Destroyed After Hack
A cyber attack on a Springfield, Ill. public water utility resulted in the destruction of one of its pumps, according to a security expert.
While I would do away with alarmist statements like "This required almost no skill and could be reproduced by a two year old with a basic knowledge of Simatic", and find it hard to give any amount of credibility to people that make such stupid pronouncements, the situation described in this article points out once again how SCADA systems are still not being treated at the level of sensitivity they should be.
While I would do away with alarmist statements like "This required almost no skill and could be reproduced by a two year old with a basic knowledge of Simatic", and find it hard to give any amount of credibility to people that make such stupid pronouncements, the situation described in this article points out once again how SCADA systems are still not being treated at the level of sensitivity they should be.
Key Words:
0-day,
hacking,
password complexity,
passwords,
physical security,
security controls,
spying,
terrorism
Wednesday, November 16, 2011
Europe Bans X-Ray Body Scanners Used at U.S. Airports
The European Union on Monday prohibited the use of X-ray body scanners in European airports, parting ways with the U.S. Transportation Security Administration, which has deployed hundreds of the scanners as a way to screen millions of airline passengers for explosives hidden under clothing.
The European Commission, which enforces common policies of the EU's 27 member countries, adopted the rule “in order not to risk jeopardizing citizens’ health and safety.”
The European Commission, which enforces common policies of the EU's 27 member countries, adopted the rule “in order not to risk jeopardizing citizens’ health and safety.”
Key Words:
law,
physical security,
privacy,
security controls,
terrorism
Police trick 19 criminals into coming forward with free beer
Undercover officers at Derbyshire police sent letters to dozens of people who had evaded arrest asking them to ring a marketing company to collect a free crate of beer.
A total of 19 suspects fell for the hoax and called the number on the letter, which put them through to police officers based at Chesterfield Police Station.
They were told that they needed to arrange a date and time for the free alcohol to be dropped off at an agreed address.
But instead of being handed free ale the wanted men found themselves confronted by police, handcuffed and under arrest.
A total of 19 suspects fell for the hoax and called the number on the letter, which put them through to police officers based at Chesterfield Police Station.
They were told that they needed to arrange a date and time for the free alcohol to be dropped off at an agreed address.
But instead of being handed free ale the wanted men found themselves confronted by police, handcuffed and under arrest.
Tuesday, November 8, 2011
What is Phlashing
Phlashing is a permanent denial of service (DoS) attack that exploits a vulnerability in network-based firmware updates. Such an attack is currently theoretical but if carried out could render the target device inoperable.
Rich Smith, head of HP's Systems Security Lab, discovered the vulnerability and demonstrated the attack at the EUSecWest security conference in June 2008. In a real-world execution, an attacker could use remote update paths in network hardware, which are often left unprotected, to deliver corrupted and flash this to the device. As a result, the device would become unusable.
Rich Smith, head of HP's Systems Security Lab, discovered the vulnerability and demonstrated the attack at the EUSecWest security conference in June 2008. In a real-world execution, an attacker could use remote update paths in network hardware, which are often left unprotected, to deliver corrupted and flash this to the device. As a result, the device would become unusable.
Subscribe to:
Posts (Atom)