Click Here to Kill Everybody Sale

For a limited time, I am selling signed copies of Click Here to Kill Everybody in hardcover for just $6, plus shipping.

Note that I have had occasional problems with international shipping. The book just disappears somewhere in the process. At this price, international orders are at the buyer’s risk. Also, the USPS keeps reminding us that shipping — both US and international — may be delayed during the pandemic.

I have 500 copies of the book available. When they’re gone, the sale is over and the price will revert to normal.

Order here.

EDITED TO ADD: I was able to get another 500 from the publisher, since the first 500 sold out so quickly.

Please be patient on delivery. There are already 550 orders, and that’s a lot of work to sign and mail. I’m going to be doing them a few at a time over the next several weeks. So all of you people reading this paragraph before ordering, understand that there are a lot of people ahead of you in line.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Friday Squid Blogging: China Launches Six New Squid Jigging Vessels

From Pingtan Marine Enterprise:

The 6 large-scale squid jigging vessels are normally operating vessels that returned to China earlier this year from the waters of Southwest Atlantic Ocean for maintenance and repair. These vessels left the port of Mawei on December 17, 2020 and are sailing to the fishing grounds in the international waters of the Southeast Pacific Ocean for operation.

I wonder if the company will include this blog post in its PR roundup.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cell Phone Location Privacy

We all know that our cell phones constantly give our location away to our mobile network operators; that’s how they work. A group of researchers has figured out a way to fix that. “Pretty Good Phone Privacy” (PGPP) protects both user identity and user location using the existing cellular networks. It protects users from fake cell phone towers (IMSI-catchers) and surveillance by cell providers.

It’s a clever system. The players are the user, a traditional mobile network operator (MNO) like AT&T or Verizon, and a new mobile virtual network operator (MVNO). MVNOs aren’t new. They’re intermediaries like Cricket and Boost.

Here’s how it works:

  1. One-time setup: The user’s phone gets a new SIM from the MVNO. All MVNO SIMs are identical.
  2. Monthly: The user pays their bill to the MVNO (credit card or otherwise) and the phone gets anonymous authentication (using Chaum blind signatures) tokens for each time slice (e.g., hour) in the coming month.
  3. Ongoing: When the phone talks to a tower (run by the MNO), it sends a token for the current time slice. This is relayed to a MVNO backend server, which checks the Chaum blind signature of the token. If it’s valid, the MVNO tells the MNO that the user is authenticated, and the user receives a temporary random ID and an IP address. (Again, this is now MVNOs like Boost already work.)
  4. On demand: The user uses the phone normally.

The MNO doesn’t have to modify its system in any way. The PGPP MVNO implementation is in software. The user’s traffic is sent to the MVNO gateway and then out onto the Internet, potentially even using a VPN.

All connectivity is data connectivity in cell networks today. The user can choose to be data-only (e.g., use Signal for voice), or use the MVNO or a third party for VoIP service that will look just like normal telephony.

The group prototyped and tested everything with real phones in the lab. Their approach adds essentially zero latency, and doesn’t introduce any new bottlenecks, so it doesn’t have performance/scalability problems like most anonymity networks. The service could handle tens of millions of users on a single server, because it only has to do infrequent authentication, though for resilience you’d probably run more.

The paper is here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Convicted Hacker Allegedly Commits Fraud While Awaiting Release

Convicted Hacker Allegedly Commits Fraud While Awaiting Release

A Kosovan hacker, granted compassionate release after being convicted of providing personally identifiable information of over 1,000 US government personnel to ISIS, has been charged with committing further crimes while in federal prison.

The US sentenced Ardit Ferizi to 20 years in prison in September 2016 after the hacker admitted accessing a protected computer without authorization and providing material support to a designated foreign terrorist organization.

In December 2020, Federal Judge Leonie Brinkema of the Eastern District of Virginia reduced Ferizi’s sentence to time served, plus 10 years of supervised release to be served in Kosovo after the 25-year-old submitted a handwritten motion stating that his obesity and asthma made him vulnerable to COVID-19. 

According to a federal complaint filed against Ferizi and unsealed on January 12, Ferizi was awaiting deportation back to his native Kosovo when the FBI determined that he had committed multiple new federal offenses. At the time of the alleged offenses, Ferizi was incarcerated at the Federal Correctional Institute in Terre Haute, Indiana.

“We allege Ferizi provided access to personal information of US citizens, even as he was serving his prison sentence for providing similar information to ISIS,” said US Attorney David L. Anderson. 

According to the FBI, in 2017 and 2018 Ferizi became involved in multiple fraudulent schemes while locked up in prison by coordinating with a family member who was operating Ferizi’s email accounts. At least one email account included large databases of stolen personally identifiable information, extensive lists of stolen email accounts, partial credit card numbers, passwords, and other confidential information, accumulated through Ferizi’s criminal hacking activity.

“Based on an IP address resolving to Kosovo, login activity to Ferizi’s other e-mail accounts, and other investigative information, it was determined the family member downloaded the databases of stolen information to liquidate the proceeds of Ferizi’s previous criminal hacking activity,” said the Department of Justice.  

Ferizi and his family member are alleged to have used the electronic services of Google, PayPal, and Coinbase to carry out these new crimes.

Ferizi, known online as Th3Dir3ctorY, is charged with one count of aggravated identity theft and one count of wire fraud in violation. If convicted of both charges, he faces a maximum penalty of 22 years in prison and a fine of $250,000.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

2020 Saw 6% Rise in Number of CVEs Reported

2020 Saw 6% Rise in Number of CVEs Reported

New analysis of the 2020 vulnerability and threat landscape has found that the total number of Common Vulnerabilities and Exposures (CVEs) reported last year was 6% higher than the total reported in 2019.

A year-in-review report from Tenable’s Security Response Team found that 18,358 CVEs were reported in 2020, while only 17,305 were reported the previous year. 

While the increase between 2019 and 2020 may seem slight, the team found that from 2015 to 2020, the number of CVEs reported rose 183%, from 6,487 to 18,358.

“For the last three years, we have seen over 16,000 CVEs reported annually—reflecting a new normal for vulnerability disclosures,” noted researchers. 

Among the 2020 vulnerabilities disclosed were 29 Tenable identified as net-new zero-day vulnerabilities. Of the 29 vulnerabilities, over 35% were browser-related vulnerabilities, while nearly 29% were within operating systems. Font libraries were also popular, accounting for nearly 15% of zero-day vulnerabilities.

Reviewing at which points in the year critical CVEs were reported, researchers uncovered what they termed a “CVE Season” that coincided with summertime.

“Summer 2020—from June to August—was particularly unique for both the sheer volume and number of critical CVE disclosures,” noted researchers. “547 flaws were disclosed in the summer months, including major disclosures in F5, Palo Alto Networks, PulseSecure, vBulletin and more.”

An analysis of the CVE data for breach trends found that from January through October 2020, 730 publicly disclosed events resulted in the exposure of over 22 billion records. Of the industries impacted by breaches, healthcare and education made up the largest share, accounting for 25% and 13% of the breaches. 

Government and the technology industry were also popular targets, accounting for 12.5% and 15.5% of the breaches respectively.

Ransomware was found to be the most popular attack vector in 2020, being cited in 259 incidents. Email compromise was the cause of 105 breaches, while unsecured data led to 83 security incidents. For 179 data breaches, the root cause was unknown. 

The coronavirus pandemic was used time and again by cyber-attackers to lure their victims. By the first two weeks of April, 41% of organizations had experienced at least one business-impacting cyber-attack resulting from COVID-19 malware or phishing schemes.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hy-Vee Data Breach Settlement Proposed

Hy-Vee Data Breach Settlement Proposed

A preliminary settlement agreement regarding a data breach that impacted customers of Iowa-based grocery store chain Hy-Vee has been proposed. 

Hy-Vee launched an investigation after detecting unauthorized activity on some of its payment processing systems on July 29, 2019.

The investigation found that malware designed to access and steal payment card data from cards used on point-of-sale (POS) devices had been installed at certain Hy-Vee fuel pumps and drive-thru coffee shops. 

Restaurants were also impacted, including Hy-Vee Market Grilles, Hy-Vee Market Grille Expresses, and the Wahlburgers locations that Hy-Vee owns and operates, as well as the cafeteria at the chain’s West Des Moines corporate office. 

According to a statement released by Hy-Vee in October 2019, the specific timeframes when data from cards used at these locations may have been accessed varies by location. However, the company said that in general, fuel pumps were impacted from December 14, 2018, to July 29, 2019, whereas restaurants and drive-thru coffee shops were affected beginning January 15, 2019, to July 29, 2019.

“There are six locations where access to card data may have started as early as November 9, 2018, and one location where access to card data may have continued through August 2, 2019,” stated the company.

Hy-Vee concerns in Iowa, Illinois, Kansas, Missouri, Montana, Nebraska, South Dakota, and Wisconsin were impacted by the breach. Data stolen in the prolonged attack included customer names, credit and debit card numbers, card expiration dates, and verification codes.

In October and November 2019, lawsuits were filed over the breach by several customers in Illinois, Missouri, and Wisconsin whose data had been compromised. These customers later teamed up to file a class-action complaint against Hy-Vee at the end of November 2019.  

On January 12, a settlement agreement was proposed that would allow those affected by the breach to submit reimbursement claims for a maximum of $225. The plaintiffs who are named in the suit are earmarked to receive an additional $2,000 “incentive award.”

Under the proposal, customers who faced “extraordinary expenses” because of the data breach, such as hefty, unreimbursed fraudulent charges, may claim up to $5,000.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NTT DATA and Conferma Pay Partner to Deliver Secure, Virtual Payment Comms to Hotels

NTT DATA and Conferma Pay Partner to Deliver Secure, Virtual Payment Comms to Hotels

Global IT innovator NTT DATA and payments technology provider Conferma Pay have announced a partnership to bring secure, digital virtual payment communications to hotels.

The news comes at a time when more and more companies are seeking to implement contact-free payment processes to help reduce the spread of COVID-19 whilst also bolstering payment security and safety.

NTT DATA and Conferma Pay said they have combined to ensure virtual payments reach hotels securely in a digital manner, removing the reliance on traditional paper-based methods such as faxing.

Reception desks will be directed to a digital billing portal when confirming rooms booked with virtual payments, automating the virtual card delivery, removing the need for manual offline chargebacks, eliminating card exposure and tightening payment security.

Furthermore, hotel staff will no longer manually process payments or key card numbers into their merchant terminals. The check-in and check-out process is streamlined with a simplified, touchless experience.

Akihiro Ishizuka, head of global payments and services division at NTT DATA, said: “Payment innovation has accelerated like never before, creating the opportunity for a more efficient and highly secure virtual payment model. Partnering with Conferma Pay is a step forward in our commitment to provide travelers with a frictionless payment experience during check-in. This new integration will streamline the process considerably by reducing manual rekeying of payment data.”

Kelly Cleeton, senior director, global business development at Conferma Pay, added: “The solution we developed with the help of NTT DATA provides another layer of security and enhances the payment experience for our partner travel management companies and their clients.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ring Rolls-Out End-to-End Encryption to Bolster Privacy

Ring Rolls-Out End-to-End Encryption to Bolster Privacy

Controversial connected device company Ring has added video end-to-end encryption (E2EE) to some of its products in a bid to boost user privacy and security.

The Amazon-owned maker of smart doorbells first flagged the move last autumn, but will begin the roll-out this week as part of a “technical preview.

“By default, Ring already encrypts videos when they are uploaded to the cloud (in transit) and stored on Ring’s servers (at rest),” the firm explained in a blog post yesterday.

“With end-to-end encryption, customer videos are further secured with an additional lock, which can only be unlocked by a key that is stored on the customer’s enrolled mobile device, designed so that only the customer can decrypt and view recordings on their enrolled device.”

That will go some way to assuaging customer concerns over who is viewing the videos shot by their doorbell camera.

Around a year ago, four Ring employees were fired after violating company policy when they were caught watching users’ videos.

“Although each of the individuals involved in these incidents was authorized to view video data, the attempted access to that data exceeded what was necessary for their job functions,” Amazon said at the time.

Privacy concerns have also been raised over Ring’s decision to partner with hundreds of police forces across the US — although law enforcers have to request access to users’ videos within a certain time frame and geographic area.

The new E2EE feature will be available on the: Ring Video Doorbell Pro, Ring Video Doorbell Elite, Ring Floodlight Cam, Ring Spotlight Cam Wired, Stick Up Cam Plug In, Stick Up Cam Elite and Indoor Cam.

The move follows a roll-out of two-factor authentication (2FA) to all users in early 2020, to help mitigate the risk of strangers hijacking users’ cameras.

Last month, a new legal case was formed by joining together complaints filed by over 30 users in 15 families who say that their devices were hacked and used to harass them. They’re arguing, among other things, that Ring should have mandated 2FA and the use of strong passwords out-of-the-box.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#CES2021: Microsoft President Calls for Collaboration to Counter Growing Cyber-Threats

#CES2021: Microsoft President Calls for Collaboration to Counter Growing Cyber-Threats

Brad Smith, president of Microsoft, warned of the increasing cyber-threats to society as technology plays a more powerful role in our lives during his keynote address at the Consumer Electronics Show (CES) 2021.

While he outlined the potentially enormous benefits advancements in technologies offer, including in areas like sustainability, the cyber-threats being faced are correspondingly becoming increasingly concerning. “As computers create all this promise, there are new perils arising as well,” he commented.

Smith discussed the time when cybersecurity first really came into consciousness at a governmental level. This was in 1983 when the then US President Ronald Regan watched the movie WarGames, which involved a hacker almost starting World War III after gaining access to a US military supercomputer. Amid concern that a similar scenario could happen in real life, first national security computer directive was created.

Such a proactive approach needs to be taken now, according to Smith: “It’s a powerful reminder that we constantly need to keep learning, we constantly need to keep imagining what comes next.”

The past year has underlined the huge dangers that critical infrastructure and services now face from cyber-attacks. In particular, the SolarWinds attacks towards the end of last year, allegedly conducted by Russian state-backed actors, is something of a game-changer in the view of Smith, and action is required. “This wasn’t a case of one nation simply trying to spy on or hack its way into a computer network of another. It was a mass, indiscriminate assault on the technology supply chain that all of us are responsible for protecting,” he explained.

Therefore, it is critical that a set of international rules and norms are put in place to show what is and isn’t acceptable in the cyber-sphere just as there is for conventional warfare. Smith believes the cybersecurity industry has a key role to play in the development of this. “We need to come together as an industry and use our collective ways to say to every government around the world that this kind of supply chain disruption is not something that any government or any company should be allowed to pursue,” he said.

Smith also said that the SolarWinds incident highlights that everyone needs to work together much more closely going forward to detect threats such as this early, especially in the area of data sharing. He noted that it was a “powerful reminder that threat intelligence and data, about cyber-attacks, really exists in so many silos today,” adding that it is “clear that the only way to protect the future is to understand the threats of the present and that requires us to share data in new ways.”

Smith went on to warn of the dangers of getting too carried away with artificial intelligence (AI) technology, and “surrendering control” of computers, something that was a big theme in WarGames. While AI has the potential to deliver great things, “we have to think about the new guardrails we need to create so that humanity remains in control of our technology.”

Examples include facial recognition technology and machine learning tools, which can offer much more convenience to people, but also threaten fundamental rights such as privacy and even lead to bias and discrimination.

Smith concluded on a positive note, stating that such challenges can be addressed through global collaboration. “If we come together and do work well, it can be a road that leads to a brighter future,” he added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA Warns of Cloud Attacks Exploiting Poor Cyber-Hygiene

CISA Warns of Cloud Attacks Exploiting Poor Cyber-Hygiene

A US cybersecurity agency is urging organizations to improve their cyber-hygiene after warning of multiple successful attacks targeting cloud services used by remote workers.

The Cybersecurity and Infrastructure Security Agency (CISA) revealed in a report yesterday that attackers are increasingly targeting corporate and personal laptops with phishing, brute force login attempts and possibly a “pass-the-cookie” attack to access cloud accounts.

Although these attacks were not tied back to a single threat actor, they shared many of the same tactics.

Some attackers spoofed file hosting services and other legitimate vendors in phishing emails to harvest log-ins, before using these hijacked accounts to phish others in the organization.

In some attacks, account hijackers modified forwarding and keyword search rules. This is often done by BEC attackers looking to monitor email conversations with suppliers, and to hide phishing warnings.

In one example, a VPN server was configured with port 80 open for remote worker access, so cyber-criminals targeted it with brute force log-in attempts.

Although multi-factor authentication (MFA) thwarted some attempts to brute force accounts, in one case threat actors are believed to have used browser cookies to defeat MFA with a “pass-the-cookie” attack.

CISA was at pains to point out that none of this activity is related to the recent SolarWinds supply chain attack believed to have been carried out by sophisticated Russian state actors.

However, these attacks have certainly become widespread enough to warrant intervention by the agency.

It offered a long list of recommendations for organizations to improve their cyber-hygiene and strengthen cloud security practices.

Alongside conditional access (CA) policies, MFA, restrictions on email forwarding, user training, secure privileged access and zero trust, CISA argued that remote employees should not use personal devices for work. At the very least, mobile device management tools should be used to mitigate risk, it said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk