Archive for 2011/11/08

The Pentagon’s far-out research agency and its brand new military command for cyberspace have a confession to make. They don’t really know how to keep U.S. military networks secure. And they want to know: Could you help them out?

Darpa convened a “cyber colloquium” at a swank northern Virginia hotel on Monday for what it called a “frank discussion” about the persistent vulnerabilities within the Defense Department’s data networks. The Pentagon can’t defend those networks on its own, the agency admitted.

Because it’s the blue-sky research agency that helped create the internet, Darpa framed the problem as a deep, existential one, not a pedestrian question of insecure code. “It is the makings of novels and poetry from Dickens to Gibran that the best and the worst occupy the same time, that wisdom and foolishness appear in the same age, light and darkness in the same season,” mused Regina Dugan, Darpa’s director. She’s talking about the internet. “These are the timeless words of our existence. We know it is true of everything.”

Put in a blunter way, U.S. networks are “as porous as a colander,” Richard Clarke, the former White House counterterrorism chief turned cybersecurity Cassandra, told a packed ballroom.

More:
http://www.wired.com/dangerroom/2011/11/darpa-hackers-cybersecurity/

http://www.wired.com/threatlevel/2011/11/senate-net-neutrality-rebuff/

http://www.24oranges.nl/2011/11/06/internet-thugs-realnetworks-lose-case-against-hilbrand-edskes/

See also:

Dutch language news article:
http://webwereld.nl/nieuws/108474/realnetworks-gaat-door-met-rechtszaak-om-hyperlink.html

 

http://s1.securityweek.com/hacked-mit-server-used-stage-attacks-scan-vulnerabilities

http://www.securelist.com/en/blog/208193211/Duqu_First_Spotted_as_Stars_Malware_in_Iran

http://www.telegraph.co.uk/news/politics/william-hague/8873387/British-firm-with-links-to-William-Hague-sells-protester-tracking-product-to-Iran.html

http://www.belgacom.com/be-en/newsdetail/ND_20111107_bgc_deezer.page

http://torrentfreak.com/injured-movie-pirate-drops-lawuit-against-mpaa-111107/

http://torrentfreak.com/internet-doomsday-wrongs-and-rights-of-copyright-fortune-telling-111107/

Speaking to El Reg in her first interview in her new role at the IWF, Susie Hargreaves also revealed the need for greater openness, independence and transparency at the anti-child sex abuse organisation. The IWF’s fundamentals, she believes, are just about right, but the public don’t always get what it does.

http://www.theregister.co.uk/2011/11/06/iwf_ceo_interview/

http://www.reghardware.com/2011/11/07/armed_robbers_steal_thousands_of_call_of_duty_games/

The websites of Israel’s Mossad and Shin Bet intelligence services as well as the Israel Defence Force were reportedly offline for a brief period over the weekend following a 4 November threat by Anonymous to take down the sites.

http://www.theregister.co.uk/2011/11/07/anonymous_shenanigans/

http://www.theregister.co.uk/2011/11/07/adidas_hack_attack/

Dutch language news article:
http://www.security.nl/artikel/39091/1/Recherche_elimineerde_Bredolab-botnet_dankzij_cookie.html

Previously:
http://vrritti.com/?s=bredolab

Spokesperson of the Dutch Team High Tech Crime states that his team will continue business as usual “even if the judge may feel differently.” That such an approach may jeopardize the successful outcome of any criminal prosecution is a risk he’s willing to take.

Dutch language news article:
http://www.security.nl/artikel/39093/1/Terughacken_door_politie_in_strijd_met_mensenrechten.html

Previously:

Dutch Public Prosecutor’s Office: Bredolab admin was making 100,000 euros per month
The Dutch Public Prosecutor’s Office argues that “entering” the PCs does not constitute a breach of law as this action was meant to limit the damage already caused by Bredolab. The Office refuses to talk about “hacking them back” and says the PCs had already been compromised: “We use another metaphor: the police see that a home has been broken into, enters the building through the door that had already been forced open and leaves a note on the table stating ‘there has been a breaking and entering’ “.

More:
http://vrritti.com/2010/11/01/dutch-public-prosecutors-office-bredolab-admin-was-making-100k-euros-per-month/

These attacks see users being redirected to install malware before connecting to popular sites. Some incidents have also featured attacks on network devices, where routers or modems are compromised remotely.

Brazil has some big ISPs. Official statistics suggest the country has 73 million computers connected to the Internet, and the major ISPs average 3 or 4 million customers each. If a cybercriminal can change the DNS cache in just one server, the number of potential victims is huge.

http://www.securelist.com/en/blog/208193214/Massive_DNS_poisoning_attacks_in_Brazil

The Dutch banks payment terminals were being manipulated, card data copied. Money withdrawn by criminals from locations in Italy, Malaysia and Canada

Dutch language news article:
http://www.security.nl/artikel/39100/1/Skimmers_manipuleerden_kaartlezers_in_ABN-Amro_filialen.html

http://www.zdnet.com/blog/btl/abcnewscom-traffic-surges-thanks-to-yahoo-partnership/62815

http://www.zdnet.com/blog/london/englands-rioters-threatened-with-facebook-twitter-ban/704

http://www.ispreview.co.uk/story/2011/11/07/ericsson-predicts-10-fold-growth-in-mobile-broadband-data-traffic-by-2016.html

http://gizmodo.com/5856886/we-are-legion-the-story-of-the-hacktivists-or-101-guy-fawkeses

http://gizmodo.com/5857010/massive-time-warner-outage-hits-the-us

http://gizmodo.com/5857051/spotify-for-windows-phone-7-hits-today-and-is-gorgeous

http://gizmodo.com/5857101/have-you-ever-noticed-that-all-movie-posters-look-the-same

http://gizmodo.com/5857129/an-innocent-guy-got-shot-with-a-rubber-bullet-by-the-oakland-police-for-no-reason

http://news.cnet.com/8301-1023_3-57319369-93/schmidt-sees-siri-as-a-threat-to-googles-search-business/

http://news.cnet.com/8301-31001_3-57319344-261/riaa-lawyer-says-dmca-may-need-overhaul/

http://arstechnica.com/business/news/2011/11/20-banking-hacks-turn-n00bs-into-financial-fraudsters.ars

http://arstechnica.com/business/news/2011/11/can-dram-replace-hard-drives-and-ssds-ramcloud-creators-say-yes.ars

http://arstechnica.com/business/news/2011/11/vulnerabilities-give-hackers-ability-to-open-prison-cells-from-afar.ars

The group, which coordinates its efforts through the Reddit social networking site, calls its endeavor The Darknet Project (TDP).

The goal behind the project is to create a global darknet, a decentralized web of interconnected wireless mesh networks that operate independently of each other and the conventional internet. In a wireless mesh network, individual nodes can relay data for other nodes, ensuring that the routing of data remains robust as nodes on the network are added and removed. The idea behind TDP is that such a network would be resistant to censorship and shutdown because there would be no central point of control over the infrastructure.

More:
http://arstechnica.com/open-source/news/2011/11/the-darknet-plan-netroots-activists-dream-of-global-mesh-network.ars

http://arstechnica.com/tech-policy/news/2011/11/google-microsoft-uses-patents-when-products-stop-succeeding.ars