#ISC2Congress: Modern Security Pros Are Much More than Technologists, Says Bruce Schneier

#ISC2Congress: Modern Security Pros Are Much More than Technologists, Says Bruce Schneier

Speaking in the opening keynote of the virtual (ISC)2 Security Congress, renowned security technologist and best-selling author Bruce Schneier discussed the public-interest aspects of technology.

In particular, he explored the ethics of data privacy and security, whilst also outlining how today’s cybersecurity professionals are more than technologists; the work they do affects society as a whole.

“In cybersecurity, government access to encrypted communications has been the subject of a 25-year long debate. On the one side, there are police claiming they are going dark and need access to encrypted data in order to solve crimes. On the other side, security experts say it is impossible to provide that access without making systems insecure.”

Schneier explained that both sides of the argument are relevant, with various ongoing discussions held globally as to which angle of the issue is more important.

“However, here’s the problem,” he added. “Almost no policy-makers are discussing this issue from a technologically-informed perspective.

“Technology is deeply intertwined with society [today] – it is literally creating our world. It is no longer sustainable for technology and policy to be in different worlds.”

Therefore, modern information security professionals must become “public-interest technologists,” Schneier argued, adding that they must align technologically focused thought processes with issues of societal policy.

“Today, technology has become de facto policy. Companies have effective control over free speech, censorship and freedoms, regardless of what national laws are.”

This has led to the creation of terms such as algorithmic discrimination, digital divide and surveillance capitalism, Schneier added, and “this means that internet policy is no longer a separate thing.

“Technology is remaking the world, and we will never get the policy right if policy-makers get the tech wrong.”

Addressing the issue requires two key things, he explained. Firstly, policy-makers must understand technology. “What we want is for policy-making discussions to be informed by the relevant technologists.”

Secondly, more technologists (security pros) need to get involved with policy. “The world needs more public-interest technologists,” Schneier said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Over 80,000 ID Cards and Fingerprint Scans Exposed in Cloud Leak

Over 80,000 ID Cards and Fingerprint Scans Exposed in Cloud Leak

A US-based used electronics retailer has exposed over 2.6 million files, including ID cards and biometric images, after a misconfigured AWS S3 bucket was discovered.

Researchers at Website Planet traced the instance back to California-based TronicsXchange, previously trading as GreenElectronicsExchange (GEEx).

A random scan for server vulnerabilities led to the discovery of the wide open S3 bucket on October 12 2020. The company itself appeared to be shuttered, with an invalid contact email and its website offline, but Website Planet contacted AWS two days later and the issue was eventually remediated.

Of the millions of files found in the database, perhaps the most damaging for customers was the 80,000 or so images of personal identification cards such as driver’s licenses, and 10,000 fingerprint scans.

Each driver’s license photo exposes multiple pieces of information about that individual, including license number, full name, birthdate, home address, gender, hair and eye color, height and weight, and a photo of the individual, among other things.

According to the report, seen exclusively by Infosecurity, the leaked data mostly relates to Californians who visited TronicsXchange stores in 2012-15.

It’s unclear if any malicious actors found the exposed data store before Website Planet, but doing so is increasingly easy thanks to automated tools. The researchers warned that the personal data could have been used to apply for credit cards or open bank accounts.

“TronicsXchange’s misconfigured bucket contained an extensive set of personal information including personal identifiable information that can be harnessed by nefarious hackers to cause severe financial, social and reputational damage to those affected by the leak,” they argued.

“Furthermore, given the fact that government-issue documents were exposed, nefarious users could potentially conduct identity fraud across different platforms and institutions. Users’ true likenesses, copies of official documentation and contact details could be harnessed to conduct identity theft.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Firms Least Likely to Pay Ransom Globally

UK Firms Least Likely to Pay Ransom Globally

Two-fifths of UK firms have been hit by ransomware over the past year, and although they were the least likely to pay a ransom globally, those that did paid out some of the highest sums, according to CrowdStrike.

The security vendor polled 2200 senior IT decision makers and IT security professionals globally, including 200 in the UK, to compile its 2020 Global Security Attitude Survey.

The large numbers infected by ransomware over the past year could be a result of the pandemic, which has created security gaps as organizations focused on digital transformation to support remote workers.

In fact, 63% of UK respondents agreed that they’re at greater risk of attack due to the crisis. The average amount of time it takes UK organizations to detect a security incident increased by 56% from 2019 to 61 hours, giving attackers a bigger head start.

It’s also notable that nearly half (48%) of UK respondents said COVID-19 has accelerated their digital plans by six months, the third highest in Europe. These efforts can also expand the corporate attack surface, especially when only a fifth (21%) said they had modernized their security tools accordingly.

The good news is that just 13% of attacked firms in the UK pay a ransom, the lowest of any country and less than half the global average (27%).

CrowdStrike’s EMEA CTO, Zeki Turedi, claimed this may be a reflection of the improved incident response capabilities of British firms.

“In the UK, we have a very mature process when it comes to handling cyber-incidents,” he told Infosecurity.

“Companies are more likely to contact their insurance provider or legal team who will work with a pre-approved incident response company to help them investigate and remediate the threat.”

However, the average penalty paid by British firms was £940,000, significantly more than in France (£560,000), Germany (£800,000) and Italy (£300,000).

This could be a reflection of the relative wealth of these victim companies, or the growing trend for attackers to steal sensitive corporate data whilst encrypting files.

“E-crime actors have started using data extortion as part of their tactics. One example is PINCHY SPIDER, which will extort confidential and sensitive information before deploying REvil. Recently we have also seen the same actor auction off stolen information in cases when they could not retrieve payment,” continued Turedi.

“The thinking and approach to ransomware has to change. It is no longer just about being able to recover from an attack, but making sure it does not happen in the first place.”

The full report can be found here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Capcom Ransomware Breach May Have Hit 350,000

Capcom Ransomware Breach May Have Hit 350,000

A leading gaming company has revealed that a security breach announced earlier this month is much worse than first thought, with data on potentially hundreds of thousands of customers, employees and others compromised.

Nearly two weeks ago, Resident Evil developer Capcom revealed the breach, believed to be a ransomware attack, happened on November 2. At the time it said: “there is no indication that any customer information was breached.”

However, in an update post yesterday, the Osaka-headquartered firm admitted that some personal and corporate information had been taken.

Although at present Capcom could only confirm the compromise of data on five former employees, four employees and some sales and financial info, much more may have been taken.

Some 350,000 individuals may be at risk of data compromise. This includes: 134,000 customers who used the video game support help desk in Japan, 14,000 Capcom Store members in North America, 4000 Esports website members in North America, 40,000 shareholders, 153,000 former employees, their families and applicants and 14,000 employees “and related parties” taken from HR.

The potentially compromised information varies slightly by category, but includes names, home and email addresses, birthdates, shareholder numbers, phone numbers and photos.

Also at risk is an unspecified quantity of corporate information including sales data, business partner information, and sales and development documents.

“None of the at-risk data contains credit card information. All online transactions etc. are handled by a third-party service provider, and as such Capcom does not maintain any such information internally,” the notice continued.

“As the overall number of potentially compromised data cannot specifically be ascertained due to issues including some logs having been lost as a result of the attack, Capcom has listed the maximum number of items it has determined to potentially have been affected at the present time.”

Jon Niccolls, EMEA and APAC incident response lead at Check Point Software, claimed that so far this year over 500 organizations per week have been hit by ransomware which also attempts to steal sensitive data.

“To protect against these attacks, companies need to combine technology and processes: solutions that can prevent stealthy attacks and prevent data leaks, and educate employees about the risks of phishing emails, as this is how many ransomware attacks are launched,” he added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk