Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
A New Paradigm in Data Security: Insider Risk Management
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
State-sponsored Threat Groups Target Telcos, Steal 5G Secrets
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Illegal Content and the Blockchain
Security researchers have recently discovered a botnet with a novel defense against takedowns. Normally, authorities can disable a botnet by taking over its command-and-control server. With nowhere to go for instructions, the botnet is rendered useless. But over the years, botnet designers have come up with ways to make this counterattack harder. Now the content-delivery network Akamai has reported on a new method: a botnet that uses the Bitcoin blockchain ledger. Since the blockchain is globally accessible and hard to take down, the botnet’s operators appear to be safe.
It’s best to avoid explaining the mathematics of Bitcoin’s blockchain, but to understand the colossal implications here, you need to understand one concept. Blockchains are a type of “distributed ledger”: a record of all transactions since the beginning, and everyone using the blockchain needs to have access to — and reference — a copy of it. What if someone puts illegal material in the blockchain? Either everyone has a copy of it, or the blockchain’s security fails.
To be fair, not absolutely everyone who uses a blockchain holds a copy of the entire ledger. Many who buy cryptocurrencies like Bitcoin and Ethereum don’t bother using the ledger to verify their purchase. Many don’t actually hold the currency outright, and instead trust an exchange to do the transactions and hold the coins. But people need to continually verify the blockchain’s history on the ledger for the system to be secure. If they stopped, then it would be trivial to forge coins. That’s how the system works.
Some years ago, people started noticing all sorts of things embedded in the Bitcoin blockchain. There are digital images, including one of Nelson Mandela. There’s the Bitcoin logo, and the original paper describing Bitcoin by its alleged founder, the pseudonymous Satoshi Nakamoto. There are advertisements, and several prayers. There’s even illegal pornography and leaked classified documents. All of these were put in by anonymous Bitcoin users. But none of this, so far, appears to seriously threaten those in power in governments and corporations. Once someone adds something to the Bitcoin ledger, it becomes sacrosanct. Removing something requires a fork of the blockchain, in which Bitcoin fragments into multiple parallel cryptocurrencies (and associated blockchains). Forks happen, rarely, but never yet because of legal coercion. And repeated forking would destroy Bitcoin’s stature as a stable(ish) currency.
The botnet’s designers are using this idea to create an unblockable means of coordination, but the implications are much greater. Imagine someone using this idea to evade government censorship. Most Bitcoin mining happens in China. What if someone added a bunch of Chinese-censored Falun Gong texts to the blockchain?<
What if someone added a type of political speech that Singapore routinely censors? Or cartoons that Disney holds the copyright to?
In Bitcoin’s and most other public blockchains there are no central, trusted authorities. Anyone in the world can perform transactions or become a miner. Everyone is equal to the extent that they have the hardware and electricity to perform cryptographic computations.
This openness is also a vulnerability, one that opens the door to asymmetric threats and small-time malicious actors. Anyone can put information in the one and only Bitcoin blockchain. Again, that’s how the system works.
Over the last three decades, the world has witnessed the power of open networks: blockchains, social media, the very web itself. What makes them so powerful is that their value is related not just to the number of users, but the number of potential links between users. This is Metcalfe’s law — value in a network is quadratic, not linear, in the number of users — and every open network since has followed its prophecy.
As Bitcoin has grown, its monetary value has skyrocketed, even if its uses remain unclear. With no barrier to entry, the blockchain space has been a Wild West of innovation and lawlessness. But today, many prominent advocates suggest Bitcoin should become a global, universal currency. In this context, asymmetric threats like embedded illegal data become a major challenge.
The philosophy behind Bitcoin traces to the earliest days of the open internet. Articulated in John Perry Barlow’s 1996 Declaration of the Independence of Cyberspace, it was and is the ethos of tech startups: Code is more trustworthy than institutions. Information is meant to be free, and nobody has the right — and should not have the ability — to control it.
But information must reside somewhere. Code is written by and for people, stored on computers located within countries, and embedded within the institutions and societies we have created. To trust information is to trust its chain of custody and the social context it comes from. Neither code nor information is value-neutral, nor ever free of human context.
Today, Barlow’s vision is a mere shadow; every society controls the information its people can access. Some of this control is through overt censorship, as China controls information about Taiwan, Tiananmen Square, and the Uyghurs. Some of this is through civil laws designed by the powerful for their benefit, as with Disney and US copyright law, or UK libel law.
Bitcoin and blockchains like it are on a collision course with these laws. What happens when the interests of the powerful, with the law on their side, are pitted against an open blockchain? Let’s imagine how our various scenarios might play out.
China first: In response to Falun Gong texts in the blockchain, the People’s Republic decrees that any miners processing blocks with banned content will be taken offline — their IPs will be blacklisted. This causes a hard fork of the blockchain at the point just before the banned content. China might do this under the guise of a “patriotic” messaging campaign, publicly stating that it’s merely maintaining financial sovereignty from Western banks. Then it uses paid influencers and moderators on social media to pump the China Bitcoin fork, through both partisan comments and transactions. Two distinct forks would soon emerge, one behind China’s Great Firewall and one outside. Other countries with similar governmental and media ecosystems — Russia, Singapore, Myanmar — might consider following suit, creating multiple national Bitcoin forks. These would operate independently, under mandates to censor unacceptable transactions from then on.
Disney’s approach would play out differently. Imagine the company announces it will sue any ISP that hosts copyrighted content, starting with networks hosting the biggest miners. (Disney has sued to enforce its intellectual property rights in China before.) After some legal pressure, the networks cut the miners off. The miners reestablish themselves on another network, but Disney keeps the pressure on. Eventually miners get pushed further and further off of mainstream network providers, and resort to tunneling their traffic through an anonymity service like Tor. That causes a major slowdown in the already slow (because of the mathematics) Bitcoin network. Disney might issue takedown requests for Tor exit nodes, causing the network to slow to a crawl. It could persist like this for a long time without a fork. Or the slowdown could cause people to jump ship, either by forking Bitcoin or switching to another cryptocurrency without the copyrighted content.
And then there’s illegal pornographic content and leaked classified data. These have been on the Bitcoin blockchain for over five years, and nothing has been done about it. Just like the botnet example, it may be that these do not threaten existing power structures enough to warrant takedowns. This could easily change if Bitcoin becomes a popular way to share child sexual abuse material. Simply having these illegal images on your hard drive is a felony, which could have significant repercussions for anyone involved in Bitcoin.
Whichever scenario plays out, this may be the Achilles heel of Bitcoin as a global currency.
If an open network such as a blockchain were threatened by a powerful organization — China’s censors, Disney’s lawyers, or the FBI trying to take down a more dangerous botnet — it could fragment into multiple networks. That’s not just a nuisance, but an existential risk to Bitcoin.
Suppose Bitcoin were fragmented into 10 smaller blockchains, perhaps by geography: one in China, another in the US, and so on. These fragments might retain their original users, and by ordinary logic, nothing would have changed. But Metcalfe’s law implies that the overall value of these blockchain fragments combined would be a mere tenth of the original. That is because the value of an open network relates to how many others you can communicate with — and, in a blockchain, transact with. Since the security of bitcoin currency is achieved through expensive computations, fragmented blockchains are also easier to attack in a conventional manner — through a 51 percent attack — by an organized attacker. This is especially the case if the smaller blockchains all use the same hash function, as they would here.
Traditional currencies are generally not vulnerable to these sorts of asymmetric threats. There are no viable small-scale attacks against the US dollar, or almost any other fiat currency. The institutions and beliefs that give money its value are deep-seated, despite instances of currency hyperinflation.
The only notable attacks against fiat currencies are in the form of counterfeiting. Even in the past, when counterfeit bills were common, attacks could be thwarted. Counterfeiters require specialized equipment and are vulnerable to law enforcement discovery and arrest. Furthermore, most money today — even if it’s nominally in a fiat currency — doesn’t exist in paper form.
Bitcoin attracted a following for its openness and immunity from government control. Its goal is to create a world that replaces cultural power with cryptographic power: verification in code, not trust in people. But there is no such world. And today, that feature is a vulnerability. We really don’t know what will happen when the human systems of trust come into conflict with the trustless verification that make blockchain currencies unique. Just last week we saw this exact attack on smaller blockchains — not Bitcoin yet. We are watching a public socio-technical experiment in the making, and we will witness its success or failure in the not-too-distant future.
This essay was written with Barath Raghavan, and previously appeared on Wired.com.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Fintech Giant Fiserv Used Unclaimed Domain
If you sell Web-based software for a living and ship code that references an unregistered domain name, you are asking for trouble. But when the same mistake is made by a Fortune 500 company, the results can range from costly to disastrous. Here’s the story of one such goof committed by Fiserv [NASDAQ:FISV], a $15 billion firm that provides online banking software and other technology solutions to thousands of financial institutions.

In November 2020, KrebsOnSecurity heard from security researcher Abraham Vegh, who noticed something odd while inspecting an email from his financial institution.
Vegh could see the message from his bank referenced a curious domain: defaultinstitution.com. A quick search of WHOIS registration records showed the domain was unregistered. Wondering whether he might receive email communications to that address if he registered the domain, Vegh snapped it up for a few dollars, set up a catch-all email account for it, and waited.
“It appears that the domain is provided as a default, and customer bank IT departments are either assuming they don’t need to change it, or are not aware that they could/should,” Vegh said, noting that a malicious person who stumbled on his discovery earlier could have had a powerful, trusted domain from which to launch email phishing attacks.
At first, only a few wayward emails arrived. Ironically enough, one was from a “quality assurance” manager at Fiserv. The automatic reply message stated that the employee was out of the office “on R&R” and would be back to work on Dec. 14.
Many other emails poured in, including numerous “bounced” messages delivered in reply to missives from Cashedge.com, a money transfer service that Fiserv acquired in 2011.
Emails get bounced — or returned to the sender — when they are sent to an address that doesn’t exist or that is no longer active. The messages had been sent to an email address for a former client solutions director at Fiserv; the “reply-to:” address in those missives was “donotreply@defaultinstitution.com”.
The messages were informing customers of CashEdge’s main service Popmoney — which lets users send, request and receive money directly from bank accounts — that Popmoney was being replaced with Zelle, a more modern bank-to-bank transfer service.
Each CashEdge missive included information about recurring transfers that were being canceled, such as the plan ID, send date, amount to be transferred, the name and last four digits of the account number the money was coming from, and the email address of the recipient account.
Incredibly, at the bottom of every message to CashEdge/Popmoney customers was a boilerplate text: “This email was sent to [recipient name here]. If you have received this email in error, please send an e-mail to customersupport@defaultinstitution.com.”

Other services that directed customers to reply to the researcher’s domain included Fiserv customer Netspend.com, a leading provider of prepaid debit cards that require no minimum balance or credit check. The messages from Netspend all were to confirm the email address tied to a new account, and concerned “me-to-me transfers” set up through its service.
Each message included a one-time code that recipients were prompted to enter at the company’s website. But from reading the many replies to these missives, it seems Netspend didn’t make it terribly obvious where users were supposed to input this code. Here’s one of the more profane examples of a customer response:

Many others emailed by Netspend expressed mystification as to why they were receiving such messages, stating they’d never signed up for the service. From the gist of those messages, the respondents were victims of identity fraud.
“My accounts were hacked and if any funding is gone your [sic] sued from me and federal trade commission,” one wrote. “I didn’t create the account. Please stop this account and let me know what’s going on,” replied another. “I never signed up for this service. Someone else is using my information,” wrote a third.
Those messages also concerned me-to-me transfers. Other emails came from Detroit-based TCF National Bank.
New York-based Union Bank also sent customer information to the researcher’s domain. Both of those messages were intended to confirm that the recipient had tied their accounts to those at another bank. And in both cases, the recipients replied that they had not authorized the linkage.
In response to questions from KrebsOnSecurity, Fiserv acknowledged that it had inadvertently included references to defaultinstitution.com as a placeholder in software solutions used by some partners.
“We have identified 5 clients for which auto-generated emails to their customers included the domain name “defaultinstitution.com” in the “reply-to” address,” Fiserv said in a written statement. “This placeholder URL was inadvertently left unchanged during implementation of these solutions. Upon being made aware of the situation we immediately conducted an analysis to locate and replace instances of the placeholder domain name. We have also notified the clients whose customers received these emails.”
Indeed, the last email Vegh’s inbox received was on Feb. 26.
This is not the first time an oversight by Fiserv has jeopardized the security and privacy of its customers. In 2018, KrebsOnSecurity revealed how a programming weakness in a software platform sold to hundreds of banks exposed personal and financial data of countless customers. Fiserv was later sued over the matter by a credit union customer; that lawsuit is still proceeding.
Vegh said he found a similar domain goof while working as a contractor at the Federal Reserve Bank of Philadelphia back in 2015. In that instance, he discovered an unregistered domain invoked by AirWatch, a mobile device management product since acquired by VMWare.
“After registering that domain I started getting traffic from all around the world from Fortune 500 company devices pinging the domain,” Vegh said.
Vegh said he plans to give Fiserv control over defaultinstitution.com, and hand over the messages intercepted by his inbox. He’s not asking for much in return.
“I had been promised a t-shirt and a case of beer for my efforts then, but alas, never received one,” he said of his interaction with AirWatch. “This time, I am hoping to actually receive a t-shirt!”
Update, 12:44 p.m. ET: The lead paragraph has been updated to reflect Fiserv’s 2020 revenues, which were nearly $15 billion.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Fastway Couriers Confirms Security Breach
Fastway Couriers Confirms Security Breach

A globally franchised courier company has issued a notice confirming that it was the subject of a cyber-attack.
The assault on Fastway Couriers was discovered by one of the company’s third-party IT development contractors on February 25.
In a security notice issued March 11, Fastway Couriers confirmed that a cyber-attack had occurred and that it had resulted in a data breach.
“Fastway Couriers confirms that one of its IT systems has been subject of a cyber-attack, the consequence of which has been that parcel receivers’ data has been compromised,” stated the company.
Data affected by the incident includes names, addresses, email addresses, and phone numbers belonging to nearly 450,000 parcel recipients. Fastway Couriers said that the exposed information “is used only for the purposes of parcel delivery.”
The company said that no financial data or any other personal data was compromised in the attack as such information is not stored on any Fastway Couriers IT systems.
“The data that was compromised relates to the customers of Fastway clients,” stated Fastway Couriers. “Names, addresses and contact details of 446,143 parcel receivers were compromised.
“The data compromised relates to Fastway deliveries, in-flight or undelivered parcels over a period of approximately 30 days from mid-January onwards.”
Fastway Couriers said that the attack was “mitigated by 9am on February 26th” and that the third-party contractor who discovered it advised Fastway of the breach on March 2.
“On learning of the cyber breach, Fastway advised the Data Protection Commission and the Gardai,” said Fastway in its security notice. “Fastway has made the requisite data breach submission to the Data Protection Commission.”
Fastway Couriers said that it had hired an IT consultancy firm to carry out an incident response and independent review of the cyber-attack.
“It is distressing that our IT system was compromised by a malicious hack as we are exceptionally careful in every aspect of our data protection obligations,” said Danny Hughes, CEO of Fastway Couriers. “I deeply regret that people’s personal data has been compromised and I apologize to our clients and their customers.”
Fastway Couriers was established in 1983 in Napier in New Zealand. Today it has a presence in Australia, Ireland, Northern Ireland, and South Africa.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Spanish Data Protection Agency Issues Highest Ever Fine
Spanish Data Protection Agency Issues Highest Ever Fine

Vodafone Spain has been hit with the highest ever fine to be issued by the Spanish Data Protection Agency (AEPD).
The telecommunications company was financially penalized in four separate fines totaling $9.72m over its use of aggressive telemarketing tactics and its failure to protect data.
Two of the fines, which together total $7.16m, relate to the EU’s General Data Protection Regulation (GDPR) violations. A third, for $2.39m, cited Spanish laws on digital rights and telecommunications as well as the GDPR. The final fine, for $179k, concerns violations of a Spanish law regarding cookies.
A total of 191 complaints about the telecommunications company’s consent and data-processing practices were factored into the AEPD’s decision.
In a decision notice published March 11, the AEPD stated that Vodafone had targeted customers with unsolicited calls, emails, and SMS messages without first obtaining their consent. The communications were received even by customers who had specifically requested that their details be added to a directory listing people who do not want to receive marketing communications.
Vodafone Spain was found to have approved an international data transfer that didn’t meet the requirements of the GDPR. The company was further found to be operating without any means or methods to verify the origin or legality of the data being processed.
The AEPD found that after outsourcing a large proportion of its operations, Vodafone Spain was no longer able to identify which of its customers had opted out of receiving third-party communications or marketing messages.
Describing the company’s grasp of its customers’ information, the data authority said that Vodafone Spain lacks any “real, continuous, permanent and audited control” over how customer data is used and is unable to “provide detailed documentation on data protection guarantees.”
Before the Vodafone Spain fine, the largest penalty handed out by the AEPD was a $7.14m fine imposed on CaixaBank in January 2021. The AEPD said that Vodafone’s previous behavior had contributed to the fine’s heftiness.
From January 2018 to February 2020, Vodafone Spain has been warned or fined on more than 50 separate occasions.
Vodafone is reportedly going to appeal the decision of the AEPD.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
UK Nurseries Get First Official Cyber-Attack Warning
UK Nurseries Get First Official Cyber-Attack Warning

The UK’s National Cyber Security Centre (NCSC) has issued its first ever cybersecurity warning to nurseries and childminders.
The agency, which is part of the nation’s GCHQ intelligence service, said that the education sector’s increasing reliance on technology has made it an “appealing target” for cyber-criminals.
In a new set of guidelines published online, the NCSC warns early years practitioners that part of safeguarding the children in their care is making sure that sensitive data belonging to those children and their families doesn’t fall into the wrong hands.
“You may not think it, but regardless of the size and nature of your setting, the information that you hold is of value to a criminal,” said the NCSC.
Nurseries are advised to keep a backup copy of essential information like staff records, family contact details in an emergency, and business-critical data such as email, fee payments, banking information, and invoices.
The guidelines also recommend controlling access privileges to devices used on site by implementing strong passwords and two-factor authentication. Access to communications and images should also be restricted.
“If you send out newsletters, social media posts, or any other communications that include photos or details of children in your care, make sure you control who can access these,” said the NCSC.
“For example, you should password protect newsletters so only families who have been given the password can open them. You should also check the privacy settings across any social media accounts you use, so that only the child’s carers have access.”
To protect devices from viruses and malware, nurseries are advised to use antivirus software on the laptops and other computers in their facility and, when installing apps and software onto smartphones, to go through official app stores only.
Phishing was singled out as a cyber-attack that pre-schools should be particularly wary of.
“Many phishing emails are currently preying on fears of COVID-19, but criminals can also use other methods to trick you, such as sending text (SMS) messages, or by phone,” warned the NCSC.
The guidelines advise nursery managers to “think about how you can encourage and support your staff to question suspicious or just unusual requests, even if they appear to be from important individuals.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
UK Cyber Security Council Unveils Inaugural Leadership Team
UK Cyber Security Council Unveils Inaugural Leadership Team

The UK Cyber Security Council has introduced its first four trustees as part of preparations to become a fully independent body later this month.
The council’s inaugural leadership has been confirmed as the following: Dr Claudia Natanson (chair), Jessica Figueras (vice-chair), Mike Watson (treasurer) and Carla Baker (trustee).
The appointments come as the independent body for the UK cybersecurity profession prepares to transition from the Cyber Security Alliance led formation project to becoming an entity in its own right at the end of March. The establishment of the Cyber Security Council was first commissioned by the Department for Digital, Culture, Media and Sport (DCMS) in 2019 by a consortium of existing cybersecurity professional groups known as the Cyber Security Alliance.
As a self-regulatory body, the council is tasked with addressing key education and skills challenges faced by the industry. Its remit includes promoting the highest possible standards of cybersecurity expertise, professional conduct and practice for the benefit of the public and attracting and developing the next generation of cybersecurity professionals. It will work closely with the National Cyber Security Centre (NCSC) on these areas.
Dr Natanson, chair of the Council trustees, commented: “Cybersecurity is the new frontline for national security: for individuals, for private companies, for public companies, for critical national infrastructure and for government. While the technical aspects of cybersecurity are the absolute responsibility of the UK’s NCSC, the UK needs a body responsible for increasing the number, variety and diversity of cybersecurity specialists that the country produces, for raising the overall standard of skills of everyone in the profession, for ‘standardizing the standards’ and for raising awareness of the importance of the critical importance and value of the profession to organizations and wider society.”
Dr Budgie Dhanda, co-chair of the Council’s Formation Project Board, added: “We’re very aware of a vast amount of pent-up demand within both the cyber-related and wider industry from organizations, both large and small, keen on developing standards and practices, intent on building international relationships and links, and willing and able to positively influence the overall direction of the profession. With the trustees in place, we can start to move forwards with membership, which will bring new opportunities for them to do so under the auspices of the council.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Twitter Updates 2FA to Enable Use of Multiple Security Keys
Twitter Updates 2FA to Enable Use of Multiple Security Keys

Yesterday (March 15) Twitter announced that it has updated its two-factor authentication (2FA) to allow users to enroll and login with more than one physical key on both mobile and web. Until yesterday, it only allowed the use of one key per account.
Furthermore, users will also soon have the option to add and use security keys as their only authentication method, without any other methods turned on, the social media giant explained via its Twitter account.
The news comes after Twitter giant first updated its 2FA in December 2020 to support the use of physical security keys on Android and iOS.
The company outlined in a blog post in 2020 that the update added an extra layer of security to accounts. “Instead of only entering a password to log in, you’ll also enter a code or use a security key. This additional step helps make sure that you, and only you, can access your account,” the post read.
Commenting on yesterday’s multiple-key announcement, ESET cybersecurity specialist Jake Moore, said: “Twitter is usually a forerunner in protecting its users’ accounts with multi-factor authentication (MFA), and physical security keys are a step forward in the process. Adding different options gives choice and confidence to the user.
“Social media platforms are often slow on forcing their userbase to take up extra layers of security through fear of them finding it too difficult or getting locked out. However, with the proper support, this quickly makes all accounts far better protected,” he added.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk