The Now-Defunct Firms Behind 8chan, QAnon

Some of the world’s largest Internet firms have taken steps to crack down on disinformation spread by QAnon conspiracy theorists and the hate-filled anonymous message board 8chan. But according to a California-based security researcher, those seeking to de-platform these communities may have overlooked a simple legal solution to that end: Both the Nevada-based web hosting company owned by 8chan’s current figurehead and the California firm that provides its sole connection to the Internet are defunct businesses in the eyes of their respective state regulators.

In practical terms, what this means is that the legal contracts which granted these companies temporary control over large swaths of Internet address space are now null and void, and American Internet regulators would be well within their rights to cancel those contracts and reclaim the space.

The IP address ranges in the upper-left portion of this map of QAnon and 8kun-related sites — some 21,000 IP addresses beginning in “206.” and “207.” — are assigned to N.T. Technology Inc. Image source: twitter.com/Redrum_of_Crows

That idea was floated by Ron Guilmette, a longtime anti-spam crusader who recently turned his attention to disrupting the online presence of QAnon and 8chan (recently renamed “8kun”).

On Sunday, 8chan and a host of other sites related to QAnon conspiracy theories were briefly knocked offline after Guilmette called 8chan’s anti-DDoS provider and convinced them to stop protecting the site from crippling online attacks (8Chan is now protected by an anti-DDoS provider in St. Petersburg, Russia).

The public face of 8chan is Jim Watkins, a pig farmer in the Philippines who many experts believe is also the person behind the shadowy persona of “Q” at the center of the conspiracy theory movement.

Watkin owns and operates a Reno, Nev.-based hosting firm called N.T. Technology Inc. That company has a legal contract with the American Registry for Internet Numbers (ARIN), the non-profit which administers IP addresses for entities based in North America.

ARIN’s contract with N.T. Technology gives the latter the right to use more than 21,500 IP addresses. But as Guilmette discovered recently, N.T. Technology is listed in Nevada Secretary of State records as under an “administrative hold,” which according to Nevada statute is a “terminated” status indicator meaning the company no longer has the right to transact business in the state.

N.T. Technology’s listing in the Nevada Secretary of State records. Click to Enlarge.

The same is true for Centauri Communications, a Freemont, Calif.-based Internet Service Provider that serves as N.T. Technology’s colocation provider and sole connection to the larger Internet. Centauri was granted more than 4,000 IPv4 addresses by ARIN more than a decade ago.

According to the California Secretary of State, Centauri’s status as a business in the state is “suspended.” It appears that Centauri hasn’t filed any business records with the state since 2009, and the state subsequently suspended the company’s license to do business in Aug. 2012. Separately, the California State Franchise Tax Board (FTB) suspended this company as of April 1, 2014.

Centauri Communications’ listing with the California Secretary of State’s office.

Neither Centauri Communications nor N.T. Technology responded to repeated requests for comment.

KrebsOnSecurity shared Guilmette’s findings with ARIN, which said it would investigate the matter.

“ARIN has received a fraud report from you and is evaluating it,” a spokesperson for ARIN said. “We do not comment on such reports publicly.”

Guilmette said apart from reclaiming the Internet address space from Centauri and NT Technology, ARIN could simply remove each company’s listings from the global WHOIS routing records. Such a move, he said, would likely result in most ISPs blocking access to those IP addresses.

“If ARIN were to remove these records from the WHOIS database, it would serve to de-legitimize the use of these IP blocks by the parties involved,” he said. “And globally, it would make it more difficult for the parties to find people willing to route packets to and from those blocks of addresses.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Deep Instinct Appoints Goldman Sachs Partner as CFO

Deep Instinct Appoints Goldman Sachs Partner as CFO

Deep Instinct has appointed former managing director and partner at Goldman Sachs Heather Bellini as its new chief financial officer. 

The deep learning cybersecurity company, which was founded in 2015 and is headquartered in New York, announced the appointment today. 

While at Goldman Sachs, Bellini led the research diligence and investor education initial public offering (IPO) process for over 20 companies, including Atlassian, Crowdstrike, Dropbox, Facebook, MongoDB, Slack Technologies, VMware, and Zoom Video Communications. 

In addition to carrying out equity research analysis of the software sector and select internet-related companies, Bellini also headed the company’s Technology Research Group that covered Alphabet and Microsoft among others. 

Bellini is a founding member of the Women’s Circle at Columbia Business School and a member of the steering committee for the Jacobs Technion-Cornell Institute at Cornell Tech. In 2020, she was named to the inaugural Barron’s 100 Most Influential Women in Finance list.

“Heather established a phenomenal track record at Goldman Sachs, is highly regarded and well known and joins us as we’re on a strong path to becoming the most comprehensive, integrated and innovative deep neural network cybersecurity company in the world,” said Guy Caspi, CEO and co-founder of Deep Instinct.

Bellini, who has been a partner at Goldman Sachs since 2012, told Bloomberg that her first priorities at Deep Instinct will be to put the financial and operational infrastructure in place to scale the business globally and set the company on the path to the public markets.

“As the world increasingly migrates to all things cloud and digital transformation takes center stage, the need for best in class cybersecurity prediction, prevention, and protection has never been more important,” said Bellini. “I am excited to be joining the team and look forward to building out the financial and operational infrastructures that will be critical in our ongoing global expansion and success.”

Prior to working for Goldman, technology analyst Bellini held roles at Oppenheimer, Lehman Brothers, and International Strategy & Investment Group. She will assume her new role on January 1.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Files Antitrust Lawsuit Against Google

US Files Antitrust Lawsuit Against Google

A civil antitrust lawsuit has been filed against American multinational technology company Google by the United States Department of Justice and eleven state attorneys general.

The complaint alleges that Google unlawfully maintained monopolies in search and search advertising through anticompetitive and exclusionary practices that harmed competitors and consumers and suppressed competition in advertising.

The tactics allegedly used by Google to maintain its monopoly include establishing long-term agreements with Apple that require Google to be the default—and de facto exclusive—general search engine on Apple’s popular Safari browser and other Apple search tools.

Google is further accused of entering into arrangements that force pre-installation of its search applications in prime locations on mobile devices and make them undeletable, regardless of consumer preference.

Another accusation leveled at the tech giant is that it used monopoly profits to buy preferential treatment for its search engine on devices, web browsers, and other search access points, “creating a continuous and self-reinforcing cycle of monopolization.” 

“Google has entered into a series of exclusionary agreements that collectively lock up the primary avenues through which users access search engines, and thus the internet, by requiring that Google be set as the preset default general search engine on billions of mobile devices and computers worldwide and, in many cases, prohibiting preinstallation of a competitor,” wrote the DoJ in a statement released yesterday.

Google’s alleged anticompetitive practices have harmed competitors by preventing them from gaining vital distribution and scale. The company is further accused of suppressing competition in advertising so it can charge advertisers more than it could in a competitive market without having to increase the quality of the services it provides to them.

“Google’s conduct has harmed consumers by reducing the quality of search (including on dimensions such as privacy, data protection, and use of consumer data), lessening choice in search, and impeding innovation,” stated the DoJ. 

“As with its historic antitrust actions against AT&T in 1974 and Microsoft in 1998, the Department is again enforcing the Sherman Act to restore the role of competition and open the door to the next wave of innovation—this time in vital digital markets,” said Deputy Attorney General Jeffrey Rosen.

Rosen said that the Antitrust Division has been looking at Google and its competitive practices for more than a year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

M&S Boss Spoofed in Gift Voucher Scam

M&S Boss Spoofed in Gift Voucher Scam

Criminals are impersonating the boss of a major British multinational retailer to trick victims into sharing their bank account details.

Posing as Marks & Spencer CEO Steve Rowe, the scammers have posted fraudulent adverts online that promise victims the chance to win a gift voucher as part of a fictitious prize draw promotion. 

When victims click on the link in the ad, they are taken to an M&S-branded portal and asked to provide their name, address, mobile phone number, and bank details including SORT code and account number.

The fraudulent adverts, uncovered by the Parliament Street think tank’s cyber-research team, have been uploaded to social networking site Facebook from an unverified page entitled “Marks and Spencer Store.”

The adverts depict a man who bears no resemblance to the real Steve Rowe clutching M&S-branded shopping bags accompanied by the message, “Hello everyone, my name is Steve Rowe and I am the CEO of Marks and Spencer! I’ve an announcement to make – To celebrate our 135th Anniversary, We are giving EVERYONE who shares & then comments by 11.59pm tonight one of these mystery bags containing a £35 M&S voucher plus goodies! Make sure you enter here [URL].”

Those who know their retail history will easily be able to spot that the advert is fake as Marks and Spencer was in fact formed in 1884 when Michael Marks, a Polish refugee, opened a market stall in Leeds, with the slogan “Don’t ask the price, it’s a penny.” In 1894, Marks went into partnership with Thomas Spencer, a former cashier from the wholesale company Dewhirst.

“As we head into the busy shopping season, we can only expect to see more of these types of ‘sale’ scams emerge online,” commented Tessian CEO Tim Sadler. “Treat these posts just like you would any phishing email; ask yourself if this deal seems legitimate and verify the identity of the person requesting you to take an action, before clicking on any links. 

“And if you’re still unsure, visit the retailer’s website and official social media channels to cross-check that the deal has been mentioned elsewhere.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#GlobalEthicsDay2020: New Security Incident Response Ethics Guidelines Released

#GlobalEthicsDay2020: New Security Incident Response Ethics Guidelines Released

New ethics guidelines for incident response and security teams have been released by the Forum of Incident Response and Security Teams (FIRST) to coincide with Global Ethics Day today. The document offers advice and recommendations for cybersecurity professionals on how they should conduct themselves in a professional and ethical manner when dealing with incidents.

Created by ethicsFirst, a special interest group within FIRST, the framework outlines a number of principles with an accompanying explanation of how they can be applied. Each serve as a reminder that the primary focus of security personnel during an incident should be the public interest. FIRST added that each principle has been reviewed by senior practitioners and that they are based on real-life scenarios.  

It is hoped the guidance will reinforce the importance of principles such as trustworthiness, coordinated vulnerability disclosure, authorization, team health and recognition of jurisdictional boundaries when cybersecurity teams handle these difficult situations.

Jeroen van der Ham and Shawn Richardson, Ethics SIG co-chairs of FIRST, commented: “Integrity and professionalism are paramount in our industry. The new ethicsFirst principles were developed and examined by some of the world’s most senior cybersecurity experts with the aim of providing a universal language of how to deal with incidents and make the internet safe for everyone.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#InfosecurityOnline: Utilizing Automation in New Security Architecture

#InfosecurityOnline: Utilizing Automation in New Security Architecture

The shift to cloud networks and a wider attack surface brought about by new working practices during the COVID-19 pandemic have made traditional security strategies unfit for purpose, according to Steven Tee, principal solutions architect at Infoblox, speaking during a session at the Infosecurity Online event.

He made the case that there needs to be much greater use of automated tools such as machine learning to effectively detect and combat cyber-attacks in the current age.

Tee began by outlining the alarming increase and impact of cybercrime over recent years. “Cybercrime is a problem that either directly or indirectly affects everyone,” he said. He noted that the average cost of a data breach in 2019 was almost $4m.

This is linked to substantial changes in network architectures, which have been heavily exacerbated by the shift to remote working during COVID-19. These include the growing implementation of cloud systems and use of IoT devices, which are expanding the attack surface area and largely rendering the traditional perimeter security model redundant.

Tee said: “With the adoption of cloud, SD-WAN, work from home and the massively increased attack surface, we’re ever more reliant on next-generation technologies such as analytics and machine learning that can study behavior over time and make decisions in real time.”

In Tee’s view, the main barrier to implementing such measures on a widescale basis is not a lack of tools and technologies, but rather a shortage of skilled personnel and resources to use them effectively. “In conjunction with a global skills shortage, it’s not uncommon for enterprises to own tools without the in-house knowledge required to effectively use them,” he added.

Another issue is that personnel involved in an organization’s cybersecurity often work in silos, such as between tech and network teams and vendors. Tee commented: “All of this makes security and incident response efforts harder due to manual, inefficient and untimely data sharing, wasting time and resources.”

In order to address these kinds of issues, especially at a time where budgets are being reduced, Tee firstly recommended the use of security frameworks. “Frameworks allow teams to follow a tried and trusted process of securing their networks and dealing with threats using a common language,” he explained.

Ensuring visibility across all security frameworks through automated technology is also critical across teams. Tee said: “Quite simply, if you don’t know what’s on a network, then you can’t effectively decide policy and tools to adequately protect them.” In addition, security alerts and threat intelligence are insufficient without this visibility being in place.

Tee then went on to discuss the importance of organizations adequately protecting DNS protocols. He noted that most malware relies on DNS to launch attacks “using it at every stage, from penetration to infection to exfiltration. He added that “it’s one of the only protocols in widespread use today that has not been secured.”

Organizations should therefore focus on technology that mitigates the DNS layer to prevent these bad connections, before automatically sharing this information with other security tools such as next generation firewalls.

Protecting against data exfiltration over DNS is also critical, according to Tee, as they “can be used as a covert communication channel to bypass firewalls.” To do so, again machine learning and analytics must be utilized in order to discover whether lookups are legitimate or not.

Tee concluded by saying how effective use of machine learning and data analytics “leads to the ability to detect, contain and remediate threats faster.”   

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trust in Remote Working Tools Declines as Need for Security Increases

Trust in Remote Working Tools Declines as Need for Security Increases

The longer spell of remote working has led to more concerns about the capability of tools along with an acceptance of the importance of cybersecurity to the business.

According to the research of 2600 businesses by Cisco, two-thirds (62%) of respondents said more than half of their workforce were working remotely, with 85% saying that cybersecurity is now extremely important or more important than it was before the pandemic.

Secure access was determined as the top cybersecurity challenge faced by the largest proportion of organizations (62%) when supporting remote workers. Other concerns raised by organizations globally included data privacy (55%) and maintaining control and enforcing policies (50%).

Oliver Tavakoli, CTO at Vectra, said the initial flurry of adding security in to cover remote working use cases in March/April when employees were first sent home was when “many of those changes were held together with duct tape and bailing wire and were not intended for the long haul.”

He added: “As it becomes evident that the WFH model is going to be with us well into 2021 and there is a sense that many companies will not return to a pre-pandemic models of almost everyone working from an office all the time, longer-term and more sustainable investments into how employees connect to applications are being undertaken. Zero-trust and a bias toward cloud-native delivery of applications have become central to that direction.”

Daniel Norman, senior solutions analyst at the Information Security Forum, said the COVID-19 pandemic has highlighted particular shortcomings across the technical responses for many organizations. “Many multi-nationals’ technical crisis management and business continuity plans were inadequately positioned to enable a secure remote working environment for a global workforce, and those that have made the adaptations have been rushed and ad hoc,” he said.

“Many organizations prioritized productivity and operational success over security and privacy. At the start of the pandemic “keeping the lights on” was a frequently used strategy – however, over time, overdependency on untested technologies, new vulnerabilities in systems, poorly constructed policies and a lack of training for a remote workforce has meant that organizations are facing a deluge of cyber-threats, alongside an emergence of cyber-risks from their own workforce.”

The Cisco research also found that 61% of respondents stated their organizations experienced a jump of 25% or more in cyber-threats and alerts since the start of COVID-19. Norman said: “Training a remote workforce to manage emerging cyber-risks is also a challenge to do well. Remote working will likely never go away now, with many individuals preferring remote work to office work, so organizations face a choice – invest now and secure the crumbling infrastructure and fatigued workforce, or risk compromise.”

Commenting on why he felt cybersecurity is “more important” to businesses now than before the pandemic, Hank Schless, senior manager, security solutions at Lookout, said: “Everyone’s approach to cybersecurity architecture has changed forever. When every employee started working from home, organizations had to quickly scale their security to protect each home as a remote office. When this change first happened, many IT and security teams relied heavily on VPN to ensure secure access to corporate resources. However, what they soon realized was that creating a secure connection wasn’t enough in case the device itself was compromised.”

Tavakoli said it was important before, it is important now and will be important in the future. “The main thing to keep in mind is that when the way in which you utilize IT undergoes a dramatic shift, your cybersecurity strategy needs to follow.”

The Cisco survey found 60% of respondents are moderately or very concerned about the privacy protections associated with the tools they are using to support remote interactions, while half of the respondents do not feel that businesses can effectively protect their data today.

Schless said: “Without the visibility and conditional access capabilities of a modern endpoint protection tool, this could lead to a threat actor mistakenly being introduced into the corporate infrastructure. As a result, the security perimeter needs to be extended to every endpoint including iOS, Android and Chrome OS devices.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#InfosecurityOnline: Consider Flexible Training for Different Skill Sets

#InfosecurityOnline: Consider Flexible Training for Different Skill Sets

An employee improvement strategy should include scalable and practical training, an understanding of the employee’s skill set and certifications to validate that practical training.

Speaking as part of the Infosecurity Online event, Hack the Box technical account manager Sam Nye, and business development manager Katerina Tasiopoulou, said there are “major shifts rippling through the cybersecurity training sector,” especially as training has forced a move to online learning. Nye said some businesses and users are “suited to handle this” and while online training is not new, the way in which content is presented and interacted with has changed.

“Also the way we deliver training is important,” added Tasiopoulou. “In our industry, experience is useful in hardening skill set and learning skills like coding.”

Both speakers agreed that the pace of change of cybersecurity, especially in how exploits and vulnerabilities are introduced, demonstrates the need for adaptability, and that comes from ongoing training and for practical skills “throughout the year, and not just on a short course,” said Nye.

Tasiopoulou said there can be no such thing as “one size fits all” training, as all businesses have diverse skill sets and experience among their employees. “How can training be the same? It cannot, so understand that you need to give appropriate training to get the most out of your employees,” she stated.

“Although security can be consistent as a topic and some organizations have hundreds of employees and some have a handful, some are defensive, some offensive and some more consultative “so there is no training that can be beneficial to all of these use cases simultaneously.”

Tasiopoulou said training needs to be tailored, and also that certifications are important as a baseline for validating skills and for employees. However, the speakers acknowledged that certifications can become outdated. Therefore, the ideal scenario is to implement training that combines hands-on experience, acknowledges the varied skill set of your workforce and recognizes their certifications “to validate practical training.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DarkSide Ransomware Group Donates $10,000 to Charities

DarkSide Ransomware Group Donates $10,000 to Charities

A ransomware group has reportedly donated thousands of dollars stolen from corporate victims to charities.

The DarkSide group claimed to have made a $10,000 donation in Bitcoins to two charities: The Water Project and Children International. The latter has already said it will not be keeping the money, which by law it has to do as the funds are technically the proceeds of crime.

Ironically, if the ransomware group had kept quiet about the donation then the organizations would likely have been none the wiser. Instead, it wrote a press release on its dark web site crowing that “no matter how bad you think our work is, we are pleased to know that we helped change someone’s life,” according to The Guardian.

The group, which is said also to steal victims’ data in order to force them to pay up, apparently used legitimate US-based digital donation platform The Giving Block to channel the funds to the charities.

Brian Higgins, a Comparitech security specialist, argued that the group may be trying to test out a new method of laundering funds.

“However, it’s more probable that DarkSide clearly has too much time on its hands and too much stolen money knocking about in its Bitcoin wallets,” he added. “If they were really serious about ‘making the world a better place’ they’d all sell their laptops and stay off the internet.”

DarkSide claims not to attack schools, hospitals, governments or charities and to “carefully analyze” target organizations’ accounts to ensure they have enough cash to pay.

However, Javvad Malik, security awareness advocate at KnowBe4, questioned its assertion that this is a victimless crime.

“Whenever an organization is extorted via ransomware or other means, that money impacts actual individuals. Many people have lost their jobs over the years and there have been organizations that have ceased to exist,” he argued. “Criminals need to understand that there is a very real impact of their actions, and simply giving an amount to charity cannot make up for that.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk