Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Friday Squid Blogging: Flying Squid
How squid fly.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Medieval Security Techniques
Sonja Drummer describes (with photographs) two medieval security techniques. The first is a for authentication: a document has been cut in half with an irregular pattern, so that the two halves can be brought together to prove authenticity. The second is for integrity: hashed lines written above and below a block of text ensure that no one can add additional text at a later date.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Attack against Florida Water Treatment Facility
A water treatment plant in Oldsmar, Florida, was attacked last Friday. The attacker took control of one of the systems, and increased the amount of sodium hydroxide — that’s lye — by a factor of 100. This could have been fatal to people living downstream, if an alert operator hadn’t noticed the change and reversed it.
We don’t know who is behind this attack. Despite its similarities to a Russian attack of a Ukrainian power plant in 2015, my bet is that it’s a disgruntled insider: either a current or former employee. It just doesn’t make sense for Russia to be behind this.
ArsTechnica is reporting on the poor cybersecurity at the plant:
The Florida water treatment facility whose computer system experienced a potentially hazardous computer breach last week used an unsupported version of Windows with no firewall and shared the same TeamViewer password among its employees, government officials have reported.
Brian Krebs points out that the fact that we know about this attack is what’s rare:
Spend a few minutes searching Twitter, Reddit or any number of other social media sites and you’ll find countless examples of researchers posting proof of being able to access so-called “human-machine interfaces” — basically web pages designed to interact remotely with various complex systems, such as those that monitor and/or control things like power, water, sewage and manufacturing plants.
And yet, there have been precious few known incidents of malicious hackers abusing this access to disrupt these complex systems. That is, until this past Monday, when Florida county sheriff Bob Gualtieri held a remarkably clear-headed and fact-filled news conference about an attempt to poison the water supply of Oldsmar, a town of around 15,000 not far from Tampa.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
India Calls Out Twitter for Differential Treatment
India Calls Out Twitter for Differential Treatment

Twitter has been issued a non-compliance notice by the Indian government for failing to block accounts used to spread misinformation and provoke violence.
Prime Minister Narendra Modi ordered Twitter to block over 1,000 Twitter accounts after political protestors stormed Delhi’s Red Fort and clashed with police on January 26, India’s Republic Day.
Twitter only partially complied with the request, temporarily blocking some of the accounts that the Indian government said were used to trend hashtags designed to incite violence. One hashtag determined by the government to be inflammatory was #ModiPlanningFarmerGenocide.
Under Section 69A of India’s Information Technology Act, failure to meet the government’s account-blocking requests could see Twitter employees in India hit with fines and sentenced to up to seven years in prison.
India’s minister for electronics and information technology, Ravi Shankar Prasad, said yesterday in Parliament that action would be taken against social media companies whose services are exploited to spread fake news and incite violence.
“We have now flagged Twitter,” Prasad told Parliament. “Our department has engaged with Twitter. That’s why I didn’t want to comment on this issue outside and chose the House to raise these questions.
“What is the matter that when there is violence in US Capitol Hill, social media platforms stand by police investigation but when Red Fort is breached, the same platforms go against the Indian government? Red Fort is the symbol of our pride. We won’t allow these double standards.”
Following the violent breach of the US Capitol building on January 6, Twitter took swift action to suspend more than 70,000 user accounts
A statement issued by India’s Ministry of Electronics and Information Technology said that while Twitter was free to formulate its own rules and guidelines, Indian laws, which are enacted by the Parliament of India, must be followed irrespective of Twitter’s own rules.
In a statement issued yesterday, Twitter said: “Because we do not believe that the actions we have been directed to take are consistent with Indian law, and, in keeping with our principles of defending protected speech and freedom of expression, we have not taken any action on accounts that consist of news media entities, journalists, activists, and politicians.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Apax to Acquire Herjavec Group
Apax to Acquire Herjavec Group

Funds advised by Apax Partners today announced the signing of a definitive agreement to acquire a majority stake of global managed security services provider Herjavec Group (HG).
Under the deal, Robert Herjavec, who founded the award-winning company in 2003, will stay on as chief executive officer and remain a significant stakeholder.
Herjavec said he “couldn’t be more thrilled” to welcome the Apax Partners team to his award-winning company.
Describing what the business has achieved so far, Herjavec said: “Over the past seventeen years, HG has remained steadfast in our mission to make enterprises around the world more secure. We have succeeded in that effort by developing an industry-leading 24/7 Managed Security Services practice, by advancing our proprietary IP, by diversifying our offerings to include Advisory, Managed Detection & Response, Identity and Incident Response services, and by hiring what I fundamentally believe is the very best team in the world.”
For Herjavec, the planned acquisition is recognition of the work that he and his colleagues have put in over the years.
“This acquisition and the growth funding that results is a testament to our entire team, and to our loyal customer base who has entrusted us with their mission critical assets,” said Herjavec.
“I am excited for this next phase in our growth trajectory as we continue to earn their trust by expanding our localized support models, deepening our Managed Security Services offerings and furthering our platform development to drive incremental automation, efficiency and security ROI.”
Apax plans to partner with HG’s management team to accelerate international expansion efforts and advance the “HG Identity” and “HG SOAR” proprietary platforms.
“We are excited to partner with Robert and [his] team as we look to drive the business forward, investing in continued product innovation and growth acceleration while maintaining the company’s number one priority: customer centricity,” said Apax partner Rohan Haldea.
No financial terms of the deal have been disclosed. Dentons US LLP is serving as legal counsel to Herjavec Group, and Kirkland & Ellis LLP is serving as legal counsel to Apax.
The proposed acquisition follows Apax Funds’ prior investments in Sophos and in Coalfire, a cybersecurity advisory business acquired by the Apax Funds in 2019.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Illinois Is State Hit Hardest by Cybercrime
Illinois Is State Hit Hardest by Cybercrime

The highest concentration of cybercrime victims in the United States can be found in Illinois, according to a recent study by Clario.
The London-based cybersecurity company analyzed cybercrime data in the UK and the US to determine which geographical areas were hardest hit by attackers.
In the US, Illinois topped the table with 14.6 victims per 1,000 people. The Prairie State was followed closely by Virginia, which had 13.2 victims per 1,000 people, and New York, which had 11.
Total losses due to cybercrime were $107,152,415 in Illinois, $92,467,791 in Virginia, but just $19,876,576 in New York.
California was where the most money had been stolen collectively, with $573,624,151 lost to digital thieves. Cybercrime victims in Ohio lost more per person on average ($28,734) than anywhere else in the United States.
In the UK, Somerset had the highest victim count with 13.6 victims per 1,000 people, followed by Northumbria, with 13.5, and Dorset, with 9.1.
In the UK, the Channel Island of Jersey saw the highest per person loss to cybercrime, with threat actors taking $11,244 on average from each victim.
The study found victims residing in capital (or financial capital) cities lost far less money to cybercrime on average. In New York City, the average amount swiped from each victim was $516, while in London it was $1,049.
Many victims in both countries felt that their local government and legal system could be doing more to respond to cybercrime.
“When asked, 57% of Brits told us that reporting issues to their local government had seen no response, while 37% of Americans said the same,” said Clario researchers.
“Meanwhile, only 21% of people in the UK felt the legal system would help them in cases of cybercrime, while a staggering 55% of Americans felt their law enforcement was letting them down online.”
Clario produced the study using a combination of government, ONS, and census data mixed with open crime data from local constabularies and police forces on the number of victims of cybersecurity-related crimes. The financial-loss data came from the FBI’s “2019 Internet Crime Report” and UK police data.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
UK Govt Reveals Plans to Build Trust in Use of Digital Identities
UK Govt Reveals Plans to Build Trust in Use of Digital Identities

The UK government has unveiled draft rules for governing the future use of digital identities.
The move is part of the government’s commitment to developing the digital identity market, making it quicker and easier for people to verify themselves using modern technology and create a process as trusted as using passports or bank statements.
The new Trust Framework lays out the draft rules organizations should follow, including the principles, policies, procedures and standards governing the use of digital identity. It outlines areas such as:
- How organizations should handle and protect people’s data
- What security and encryption standards should be followed
- How user accounts should be managed
- How to protect against fraud and misuse
The framework, once finalized, is expected to be brought into law, with specific standards and requirements for organizations which provide or use digital identity services. For example, businesses will be required to have a data management policy which explains how they create, obtain, disclose, protect and delete data, a detailed account recovery process and a procedure for notifying users if they suspect someone has fraudulently accessed their account or used their digital identity.
The Department for Digital, Culture, Media and Sport – which is working alongside the digital identity community to develop the framework – has also invited the public to contribute.
Digital infrastructure minister, Matt Warman, said: “Establishing trust online is absolutely essential if we are to unleash the future potential of our digital economy.
“Today we are publishing draft rules of the road to guide organizations using new digital identity technology and we want industry, civil society groups and the public to make their voices heard. Our aim is to help people confidently verify themselves while safeguarding their privacy so we can build back better and fairer from the pandemic.”
Emma Lindley, co-founder of Women in Identity, added: “We believe that digital identity systems should be inclusive and accessible for anyone that chooses to use them.
“This collaborative approach by the government in designing the trust framework is a step in the right direction towards accountability across all stakeholders who are involved, and ensures no one is left behind.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#WomenInScience: High Number of Girls Sign Up for Codebreaking Contest
#WomenInScience: High Number of Girls Sign Up for Codebreaking Contest

Over 6500 girls across the UK have signed up to a codebreaking competition aimed at encouraging more girls to consider a career in the cybersecurity industry, the National Cyber Security Center (NCSC) has revealed.
These figures have been published on this year’s International Day of Women and Girls in Science, a global campaign that aims to achieve full and equal access to and participation in science for women and girls. The NCSC said that the high numbers participating in the 2021 CyberFirst Girls Competition demonstrates significant interest among girls in learning about cybersecurity, an industry in which women remain heavily under-represented.
The competition first launched in 2017, with over 37,000 girls participating since then. It is designed to inspire girls to consider pursuing a career in cybersecurity, thereby improving gender diversity in the sector in the coming years.
More than 600 schools in the UK put forward teams of girls aged 12 to 13 for the first round of this year’s contest, which is being held virtually due to ongoing COVID-19 social distancing restrictions. The teams will tackle puzzles covering cryptography, logic and networking that are set by the NCSC with input from CyberFirst industry partners.
The highest scoring teams in the first round will qualify for the semi-finals, where they will face local rivals in the Northern Ireland, Scotland, Wales and five English regions on March 19. The winners of these events will earn a place at the Grand Final in April, where they will have the chance to be crowned codebreaking champions.
Chris Ensor, NCSC deputy director for cyber-growth, commented: “On International Day of Women and Girls in Science, we’re pleased to say that thousands of girls came forward to compete in this year’s CyberFirst Girls Competition and we congratulate the top teams which now go forward into the semi-finals.
“These girls have opened the door to what could one day be an exciting and rewarding career, where more female representation is undoubtedly needed. We owe a special thanks to teachers who encouraged pupils to take up this fun opportunity to engage with – and hopefully be inspired by – cybersecurity.”
Digital infrastructure minister Matt Warman, added: “It is marvelous to see so many girls showing an interest in cybersecurity and well done to those who made it to the next round.
“The cybersecurity industry needs talented people and I hope everyone who took part had fun and felt inspired to consider an exciting career cracking codes, disrupting cyber-attacks and protecting our online spaces.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Political Bias and Impulsive Behavior Open Door to Misinformation
Political Bias and Impulsive Behavior Open Door to Misinformation

Americans are three-times as likely to follow strangers on Twitter if they share the same political views, according to new research which sheds more light on the spread of online misinformation and social media “echo chambers.”
The peer-reviewed study from researchers at MIT and the UK’s Exeter University began by identifying 842 random Twitter users who displayed partisan bias towards the Republican or Democratic Party.
Eight bot accounts were then created with varying degrees of partisanship to follow the group.
The report concluded that, no matter what the strength of partisanship displayed by the bots and no matter whether Democrat or Republican, Twitter users were almost three-times more likely to follow back someone with the same political affiliation as their own.
More partisan users were also more likely to follow the bots with stronger political affiliation, it noted.
The authors claimed that previous research had shown conservatives to be more likely to create social ties with those of their own political persuasion than liberals, a finding seemingly contradicted by this study.
“Partisans are much more likely to connect to complete strangers simply because they share the same political views,” explained report co-author Mohsen Mosleh of Exeter University Business School.
“This suggests that if one seeks to reduce partisan assortment on social media networks, it may be necessary for algorithms to actively counteract pre-existing psychological biases – biases that are part of the political sectarianism in which America is currently embroiled.”
The findings may help to explain why deliberate misinformation campaigns, like the ones sponsored by the Kremlin before the 2016 US Presidential election, represent such a danger to Western democracies. Bots spouting fake news designed to appeal to one side or another would seem to have a captive audience, especially in the highly partisan climate of the US.
“What we mainly show here is that being mostly connected to like-minded others may make people more prone to false beliefs by insulating them from corrective information,” Mosleh told Infosecurity by email.
A link was also made between misinformation and the social media echo chamber in a 2018 University of Amsterdam study, which likened the latter to dry kindling in a forest and the former to a wildfire.
“There are certain signs that point to a link between these two phenomena – echo chambers and the spread of misinformation – since homogeneous clusters of users with a preference for self-confirmation seem to provide capable green-houses for the seedling of rumors and misinformation,” it warned.
A separate study by MIT, University of Regina and Exeter University researchers released today claimed, perhaps unsurprisingly, that more intuitive and less reflective thinkers were more likely to tweet about hyper-partisan content and fake news.
The same type of users were more likely to fall for “get rich quick” schemes and sales promotions, it said.
This would lend weight to calls for more critical thinking and media literacy classes to be taught in schools.
“These results reinforce the claim that the human capacity to reason is hugely consequential and something that should be cultivated and improved rather than ignored,” argued Mosleh.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk