Category: Security

Finance Ruins Everything

Case in point, the hacking of the MTA in New York City, which was caused by lapses at a private equity (PE) owned software firm.

PE is not about building a good company, long term success, or security.  It’s about pump and dump, and security is a cost that you can cut to juice your numbers before they sell out the company.

It’s all pump and dump:

Oh look, a hack of the New York subway system.

A hacking group believed to have links to the Chinese government penetrated the Metropolitan Transportation Authority’s computer systems in April, exposing vulnerabilities in a vast transportation network that carries millions of people every day, according to an M.T.A. document that outlined the breach.

These hacks are becoming commonplace, but it’s not just because everything is connected to the internet. It turns out, hackers got in through commercial software.

To gain access to the M.T.A. and other systems, the hackers took advantage of vulnerabilities in Pulse Connect Secure, a widely used connectivity tool that offers workers remote access to their employers’ networks.

Pulse Connect Secure is owned by Ivanti, a software roll-up owned by private equity firms Clearlake Capital Group, L.P. and TA Associates. I’ve written about the dangers of private equity owning cybersecurity firms – Solar Winds was such a case. (In fact, Thoma Bravo partners – which owns Solar Winds – continues to snap up cybersecurity and compliance firms such as Proofpoint.)

I’ve gone through job reviews on Glassdoor and Indeed, and Ivanti seems to be a typical PE roll-up, ruining the product quality, offshoring jobs and firing people, and just generally destroying enterprise value. Here’s a typical review.

PE takeovers are frequently followed up by the collapse of the firms (usually) after the PE pukes have gotten their vigorish.

We really need to change bankruptcy laws so that these crooks aren’t able to leave someone else holding the bag.

Sauce for the Gander

After decades of merrily hacking into other people’s computers and snooping on people’s emails, it appears that the NSA has been hacked.

A group of hackers are trying to auction off malware that the spy organization has been using to spy on the rest of us:

A mysterious online group calling itself “The Shadow Brokers” is claiming to have penetrated the National Security Agency, stolen some of its malware, and is auctioning off the files to the highest bidder.

The authenticity of the files cannot be confirmed but appear to be legitimate, according to security researchers who have studied their content. Their release comes on the heels of a series of disclosures of emails and documents belonging mostly to Democratic officials, but also to Republicans. Security researchers believe those breaches were perpetrated by agents thought to be acting on behalf of Moscow.

The NSA did not answer Foreign Policy’s questions about the alleged breach on Monday. But if someone has managed to penetrate the American signals intelligence agency and post its code online for the world to see — and purchase — it would constitute a historic black eye for the agency.

………

The files posted over the weekend include two sets of files. The hackers have made one set available for free. The other remains encrypted and is the subject of an online auction, payable in bitcoin, the cryptocurrency. That set includes, according to the so-called Shadow Brokers, “the best files.” If they receive at least 1 million bitcoin — the equivalent of at least $550 million — they will post more documents and make them available for free.

The set of files available for free contains a series of tools for penetrating network gear made by Cisco, Juniper, and other major firms. Targeting such gear, which includes things like routers and firewalls, is a known tactic of Western intelligence agencies like the NSA, and was documented in the Edward Snowden files. Some code words referenced in the material Monday — BANANAGLEE and JETPLOW — match those that have appeared in documents leaked by Snowden. Security researchers analyzing the code posted Monday say it is functional and includes computer codes for carrying out espionage.

If this hack is real, my guess is that they got in through backdoors that the NSA itself insisted on.

It’s Called Paper

The Department of Homeland Security is looking at ways to safeguard electronic voting machines from hackers.

It’s really pretty simple, you eliminate the purely electronic machines, and go with optically scanned machines, which will give you a count in roughly the same time, and then you do a manual recount of a small portion of the precincts.

If you want to retain purely electronic machines, I’d suggest that you require that the software be open source, so that it can be audited.

Instead, they will probably shovel money at Diebold and their ilk:

The Obama administration is weighing new steps to bolster the security of the United States’ voting process against cyberthreats, including whether to designate the electronic ballot-casting system for November’s elections as “critical infrastructure,” Jeh Johnson, the secretary of Homeland Security, said on Wednesday.

In the wake of hacks that infiltrated Democratic campaign computer systems, Mr. Johnson said he was conducting high-level discussions about “election cybersecurity,” a vastly complex effort given that there are 9,000 jurisdictions in the United States that have a hand in carrying out the balloting, many of them with different ways of collecting, tallying and reporting votes.


………

Mr. Johnson said he was considering communicating with state and local election officials across the country to inform them about “best practices” to guard against cyberintrusions, and that longer-term investments would probably have to be made to secure the voting process.

“There are various different points in the process that we have to be concerned about, so this is something that we are very focused on right at the moment,” Mr. Johnson said.

His comments were the latest evidence that recent cyberintrusions have caused alarm in the administration about the potential for hacking to disrupt the election, and how to respond.

Seriously, this sh%$ ain’t rocket science.

Use paper ballots, and make selected public hand recounts of a small randomly selected group of sites.

It’s really that simple.

Obama’s Lawless Behavior in Support of the Security State

You may recall that the NSA bulk data collection of phone records were ruled by an Federal appellate court.

It not turns out that the Obama administration tried to get a ruling from the FISA court saying that they could ignore this ruling.

The interesting bit here is that the FISA court is technically a district court, and so is subordinate to an appellate court.

This shows a complete contempt for the rule of law:

The Obama administration has asked a secret surveillance court to ignore a federal court that found bulk surveillance illegal and to once again grant the National Security Agency the power to collect the phone records of millions of Americans for six months.

The legal request, filed nearly four hours after Barack Obama vowed to sign a new law banning precisely the bulk collection he asks the secret court to approve, also suggests that the administration may not necessarily comply with any potential court order demanding that the collection stop.

US officials confirmed last week that they would ask the Foreign Intelligence Surveillance court – better known as the Fisa court, a panel that meets in secret as a step in the surveillance process and thus far has only ever had the government argue before it – to turn the domestic bulk collection spigot back on.

Justice Department national security chief John A Carlin cited a six-month transition period provided in the USA Freedom Act – passed by the Senate last week to ban the bulk collection – as a reason to permit an “orderly transition” of the NSA’s domestic dragnet. Carlin did not address whether the transition clause of the Freedom Act still applies now that a congressional deadlock meant the program shut down on 31 May.

But Carlin asked the Fisa court to set aside a landmark declaration by the second circuit court of appeals. Decided on 7 May, the appeals court ruled that the government had erroneously interpreted the Patriot Act’s authorization of data collection as “relevant” to an ongoing investigation to permit bulk collection.

Carlin, in his filing, wrote that the Patriot Act provision remained “in effect” during the transition period.

“This court may certainly consider ACLU v Clapper as part of its evaluation of the government’s application, but second circuit rulings do not constitute controlling precedent for this court,” Carlin wrote in the 2 June application. Instead, the government asked the court to rely on its own body of once-secret precedent stretching back to 2006, which Carlin called “the better interpretation of the statute”.

While it is true that  the FISA court is not technically under the 2nd court of appeals, which ruled the program illegal, because they are not in the 2nd district, (technically, they are not in any district) but blithely asking the court to overrule an appeals court shows a complete contempt for due process and the rule of law.

Worst Constitutional Law Professor Ever!

I’m Shocked, Shocked to Find That Gambling Is Going on in Here


Cue Captain Renault

A whistle blower at Tiversa is alleging that the company manufactured false evidence of breaches to gin up business:

A bombshell lawsuit is raising eyebrows in the cybersecurity industry.

A former cybersecurity forensic examiner named Richard Wallace is claiming that his former employer — cybersecurity company Tiversa — “would typically make up fake data breaches to scare potential clients,” CNNMoney reports.

Wallace claims that Tiversa would routinely do this then “pressure firms to pay up” by buying its cybersecurity services, according to a federal courtroom transcript obtained by CNNMoney. This came to a head when Tiversa allegedly approached cancer testing services company LabMD about a supposed hack. LabMD refused to buy into Tiversa’s services, so Tiversa allegedly reported the cancer-testing company to the FTC for having a data breach.

………

This lawsuit raises some potentially worrisome issues about practices in the cybersecurity industry.

Gee you think?

It’s the f%$#ing Wild West out there, with no standards of what constitutes a breach, and no meaningful certification of the security firms.

People have been selling cyber Armageddon, with only one concrete example of their horror stories panning out (Stuxnet which was created by the US and Israeli government), why is it a surprise when we discover that people are selling “breaches” that are either non existent or minor.

I guess being a cybersecurity consultant beats working for a living.

So Not a Surprise

You know those “Cybersecurity” bills that are supposed to protect our data and our privacy?

Not so much:

Cybersecurity legislation advancing in Congress could create the first brand-new exemption to the Freedom of Information Act in nearly half a century—a prospect that alarms transparency advocates and some lawmakers.

A bill approved by the Senate Intelligence Committee last month would add a new tenth exemption to FOIA, covering all “information shared with or provided to the Federal Government” under the new measure.

Another provision in the legislation would require that “cyber threat indicators and defensive measures” which companies or individuals share with the federal government be “withheld, without discretion, from the public.” The Senate bill, which is expected to come to the floor soon, also seeks to shut off any access to that information under state or local freedom of information laws.

Two cybersecurity bills are expected to be taken up on the House floor as soon as this week. Both contain similar language about keeping confidential threat and defensive measure information turned over to the government. However, a new FOIA exemption that was in the House Intelligence Committee cyber bill was taken out, a spokesman confirmed Friday.

In an official Senate Intelligence Committee report made public over the weekend, two Democratic members of that panel objected to the new FOIA exemption, which would be the first brand-new exemption added to the landmark transparency legislation since 1967.

“We are unconvinced that it is necessary to create an entirely new exemption to the Freedom of Information Act, or FOIA,” Sens. Martin Heinrich (D-N.M.) and Mazie Hirono (D-Hawaii) wrote in a statement accompanying the panel’s report on the cyber bill. “Government transparency is critical in order for citizens to hold their elected officials and bureaucrats accountable; however, the bill’s inclusion of a new FOIA exemption is overbroad and unnecessary as the types of information shared with the government through this bill would already be exempt from unnecessary public release under current FOIA exemptions.”

………

Critics say the proposed new FOIA exemption could allow companies to block disclosure of virtually any information by anyone in the government simply by submitting that information to the new cybersecurity portal. McDermott said the narrower provisions were also troubling and have mandatory language that could preclude the government from releasing cyber-related information even when needed to warn about a danger to the general public.

McDermott also said it would set a bad precedent if a bill creating an entirely new FOIA exemption made it into law without passing through the panels which oversee that law in each chamber.

“By authorizing a new exemption to the FOIA through a committee other than the committees of jurisdiction….you’ve undermined FOIA,” she warned.

Not surprised that the Obama administration likes this a lot. His history as President is one of being a cheerleader for the overarching security state, and his jihad on whistle blowers is a national disgrace.

Headline of the Day

President Obama Declares the Threat to Crappy Sony Movies a National Emergency

—Marcy “Emptywheel” Wheeler

A response to Obama’s new executive order, which is vague enough to allow sanctions against pretty much anyone who publishes the data or provides privacy tools..

It is overarching, irresponsible, and fundamentally anti-democratic, which makes it a typical security policy of Obama and His Evil Minions.

But it gets worse. The EO targets not just the hackers themselves, but also those who benefit from or materially support hacks. The targeting of those who are “responsible for or complicit in … the receipt or use for commercial or competitive advantage … by a commercial entity, outside the United States of trade secrets misappropriated through cyber-enabled means, … where the misappropriation of such trade secrets is reasonably likely to result in, or has materially contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States” could be used to target journalism abroad. Does WikiLeaks’ publication of secret Trans-Pacific Partnership negotiations qualify? Does Guardian’s publication of contractors’ involvement in NSA hacking?

And the EO creates a “material support” category similar to the one that, in the terrorism context, has been ripe for abuse. Its targets include those who have “provided … material, or technological support for, or goods or services in support of” such significant hacks. Does that include encryption providers? Does it include other privacy protections?

Finally, I’m generally concerned about this EO because of the way National Emergencies have served as the justification for a lot of secret spying decisions. Just about every application to the FISC for some crazy interpretation of surveillance laws in the name of counterterrorism founds their justification neither in the September 17, 2001 Finding authorizing covert actions against al Qaeda nor the September 18, 2001 AUMF, but instead in President Bush’s declaration of a National Emergency on September 14, 2001. I’m not sure precisely why, but that’s what the Executive has long used to convince FISC that it should rubber stamp expansive interpretations of surveillance law. So I assume this declaration could be too.

In other words, the sanctions regime may well be the least of this EO.

Just lovely.

I Bet Jon Stewart is Having 2nd Thoughts About Retiring Now


This really is TedCruz.com

Ted “Tailgunner” Cruz, has become the first candidate to formally announce that he is running for President:

Senator Ted Cruz of Texas announced on Monday morning that he would run for president in 2016, becoming the first Republican candidate to declare himself officially in the race.

Linking the determination of his immigrant father with the resolve of the founding fathers and his own faith in “the promise of America,” Mr. Cruz spoke at length about his family and his faith as he laid out a case for his candidacy.

“God’s blessing has been on America from the very beginning of this nation, and I believe God isn’t done with America yet,” Mr. Cruz said before thousands of cheering students here at Liberty University. “I believe in you. I believe in the power of millions of courageous conservatives rising up to re-ignite the promise of America.”

“Today, I am announcing that I am running for president of the United States,” Mr. Cruz added. “It is a time for truth, it is a time for liberty, it is a time to reclaim the Constitution of the United States.”

First, there is the internet hilarity, with tedcruz.com being registered by a liberal, and his website, tedcruz.org, is using a Nigerian Prince SSL token on its donation page:

This morning, as Senator Ted Cruz launched his bid to become president of the United States, some people who visited his site thought he might also want to become a Nigerian prince. At least, that’s what his site’s certificate said.

It turns out that Cruz’ campaign had registered to use CloudFlare as the content delivery network for its WordPress-based tedcruz.org site, anticipating a flood of traffic from would be supporters. But because the Cruz campaign hadn’t yet uploaded a certificate to identify the site for secure visits, CloudFlare’s systems automatically assigned the site one of its own certificates, CloudFlare CEO Matthew Prince told Ars. “The Cruz campaign didn’t do anything wrong,” he said. “It was an automated process on CloudFlare’s part.” The certificate that the Cruz campaign’s site got assigned to was also assigned to nigerian-prince.com.

But it gets better:


The certificate, however, is probably the least of the Cruz campaign’s Internet problems. The domain tedcruz.com is currently hosting a site that urges people to support President Obama and immigration reform. And while the tedcruz.org site is intended to take donation information, it doesn’t use SSL by default—so donors’ credit card data could potentially be exposed.

And Donald Trump jumped on the Republican presidential clown car, forming an explaroatory committee for the 2016 campaign, and then “The Donald” went full birther on the Canadian born Cruz:*

Real estate tycoon Donald Trump cast doubt Monday on whether Sen. Ted Cruz (R-Texas) can run for president, because Cruz was born in Canada.

“It’s a hurdle; somebody could certainly look at it very seriously,” Trump said during a phone interview Monday on My Fox New York.“He was born in Canada. If you know and when we all studied our history lessons, you are supposed to be born in this country, so I just don’t know how the courts will rule on this.”

Trump, who says he is exploring a bid for president in 2016, was part of the “birther” movement that questioned President Obama’s birth place, as well as the veracity of his birth certificate. He recently took credit for getting Obama to release his birth certificate while speaking at the Conservative Political Action Conference in February.

After flirting with a 2012 presidential bid, Trump has announced an exploratory committee for 2016 and says he will not renew his contract for his TV show, “The Apprentice” on NBC.

Anyone who writes topical comedy has to be rubbing his hands together in anticipation.

*The consensus amongst Constitutional scholars is that natural born US citizen is one who was a citizen at birth, even if they are born in a foreign nation, so Cruz qualifies.

The Tor Anonymity Network Just Got Hacked by Law Enforcement

Paul Carr at Pando has been writing a lot about potential security issues with TOR, both issues with the ties between the founders and the US state security apparatus, and possible technical issues.

One of the ones that he has mentioned is the compromise of their exit nodes or their directory authorities.

It now appears that a large cluster of exit nodes has been seized by the authorities:

Earlier this week, we reported on an apparent threat by an unnamed agency to disable the Tor anonymity network.

According to founder Roger Dingledine:

The Tor Project has learned that there may be an attempt to incapacitate our network in the next few days through the seizure of specialized servers in the network called directory authorities.

This is not the current problem though,  it appears that some of the exit nodes have been seized by the authorities:

Today, Thomas White who operates “a large exit node cluster for the Tor network and [a] collection of mirrors,” reports that his servers have apparently been compromised.

Tonight there has been some unusual activity taking place and I have now lost control of all servers under the ISP and my account has been suspended. Having reviewed the last available information of the sensors, the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. From experience I know this trend of activity is similar to the protocol of sophisticated law enforcement who carry out a search and seizure of running servers.

White warns “Do NOT use my mirrors/services until I have reviewed the situation,” adding:

At this moment in time I am under no gagging orders or influence from external parties/agencies. If no update is provided within 48 hours you may draw your own conclusions.

Needless to say if you rely on TOR for some sort of crucial secure communications, I would suggest that you find some other method, or go dark, over the short term.

I know a guy with a carrier pigeon.

That’s Mighty White of Them………

A top National Security Agency official will no longer be moonlighting part-time with a private consulting firm run by former NSA chief Keith Alexander. The end of that arrangement comes days after the NSA said this particular work situation was “under internal review” due to potential conflicts of interest.

The private company at issue— IronNet Cybersecurity—was founded by Alexander, who ran the spy agency from August 2005 until March 2014. IronNet Cybersecurity offers protection services to banks for up to $1 million per month. Patrick Dowd, the NSA’s current chief technology officer, had been working with Alexander’s private venture for up to 20 hours per week.

20 hours a week?  For the chief f%$#ing technology officer for the f%$#ing National f%$#ing Security Agency?

Tell me that this isn’t about using his connections to benefit his new firm.

And then there is the fact that while still heading the NSA, Keith Alexander, the NSA white washed his wide ranging, and highly suspicious tech investments:

New financial disclosure documents released this month by the National Security Agency (NSA) show that Keith Alexander, who served as its director from August 2005 until March 2014, had thousands of dollars of investments during his tenure in a handful of technology firms.

Each year disclosed has a checked box next to this statement: “Reported financial interests or affiliations are unrelated to assigned or prospective duties, and no conflicts appear to exist.”

Alexander repeatedly made the public case that the American public is at “greater risk” from a terrorist attack in the wake of the Snowden disclosures. Statements such as those could have a positive impact on the companies he was invested in, which could have eventually helped his personal bottom line.

The NSA did not immediately respond to Ars’ requests for further comment.

The documents were obtained and published Friday by Vice News as the result of a Freedom of Information Act request and subsequent lawsuit against the NSA brought by Vice News reporter Jason Leopold.

BTW, here is the money quote from the Vice article:

That said, Alexander’s interest in surveillance was not limited to his tenure as NSA director. He also invested in firms that are on the cutting edge of surveillance technology.

For example, Alexander invested as much as $15,000 in: Pericom Semiconductor, a company that has designed technology for the closed-circuit television and video surveillance markets; RF Micro Devices designs, which manufactures high-performance radio frequency technology that is also used for surveillance; and as much as $50,000 in Synchronoss Technologies, a cloud storage firm that provides a cloud platform to mobile phone carriers (the NSA has been accused of hacking into cloud storage providers).

Like I said, mighty white of the NSA to give the good General a pass on all of this.

And did I forget to mention this last bit? Since leaving the NSA earlier this year, Alexander has filed at least 9 patents on computer security, that is a something north of 1 patent a month, and the NSA has dutifully signed off of their being unrelated to his work at the NSA:

In an interview Monday with former National Security Agency Director General Keith Alexander, Foreign Policy‘s Shane Harris learned that Alexander plans to file “at least” nine patent applications—“and possibly more”—pertaining to technology for detecting network intruders.

Alexander left his government post in early 2014 and went on to co-found a private company, IronNet Cybersecurity Inc., with unnamed business partners. Alexander said that these business partners helped him create the “unique” method for detecting hackers that he plans to patent. Of course, Alexander himself had unparalleled access to classified security operations from 2005, when he took charge of the NSA, to 2014, when he retired.

Since starting IronNet, Alexander has been peddling his consulting services to major corporations, especially those in the financial industry, and has quoted fees of up to $1 million per month. That astronomical number drew at least one federal representative to suggest that Alexander might be disclosing or misusing classified information.

Presumably, Alexander’s expensive consulting will include access to IronNet’s future patented technology, which will cover “a system to detect so-called advanced persistent threats, or hackers who clandestinely burrow into a computer network in order to steal secrets or damage the network itself,” Foreign Policy reported. Alexander specified to the magazine that IronNet’s technology is unique because it uses “behavioral models” to anticipate a hacker’s next moves.

You know, if I didn’t know better, I would swear that this whole dysfunctional security-industrial complex thing would sound like an awful like like our dysfunctional military-industrial complex, where increasingly large sums of money seem to result in nothing more than massive remuneration for retired generals.

Worst Constitutional Law Professor, Ever

Note that FBI Director James Comey was specifically chosen by Barack Obama, and the President’s behavior to this point has indicated a strong bias toward the position that, “You don’t need to worry about privacy if you have nothing to hide.”

Thus I see Comey’s request for sabotaging the security of computers and mobile devices by requiring back doors to be a position explicitly supported by the whole administration, and as the saying goes, the Cossacks work for the Czar:

FBI Director James Comey has launched a new “crypto war” by asking Congress to update a two-decade-old law to make sure officials can access information from people’s cellphones and other communication devices.

The call is expected to trigger a major Capitol Hill fight about whether or not tech companies need to give the government access to their users’ data.

“It’s going to be a tough fight for sure,” Rep. James Sensenbrenner (R-Wis.), the Patriot Act’s original author, told The Hill in a statement.

He argues Apple and other companies are taking the privacy of consumers into their own hands because Congress has failed to pass legislation in response to public anger over the National Security Agency’s surveillance programs.

“While Director Comey says the pendulum has swung too far toward privacy and away from law enforcement, he fails to acknowledge that Congress has yet to pass any significant privacy reforms,” he added. “Because of this failure, businesses have taken matters into their own hands to protect their consumers and their bottom lines.”

“If this becomes the norm, I suggest to you that homicide cases could be stalled, suspects walked free, child exploitation not discovered and prosecuted,” he said last week.

Comey is asking that Congress update the Communications Assistance for Law Enforcement Act (CALEA), a 1994 law that required telephone companies to make it possible for federal officials to wiretap their users’ phone calls.

It’s a back door, much like the infamous Clipper chip, and the greatest effect of such a change would be to allow cyber-criminals to access your data, your machines, and your identity, because if they cripple security in the interest of law enforcement, criminals will avail themselves to the same technology.

On the Way Out the Door, Eric Holder Goes After Our Privacy ……… Again

For the gazillianth time, he’s seeking the crippling of computer security and privacy system with a back door for law enforcement:

Attorney General Eric Holder, the US top law enforcement official, said it is “worrisome” that tech companies are providing default encryption on consumer electronics. Locking the authorities out of being able to physically access the contents of devices puts children at risk, he said.

“It is fully possible to permit law enforcement to do its job while still adequately protecting personal privacy,” Holder said during a Tuesday speech before the Global Alliance Against Child Sexual Abuse Online conference. “When a child is in danger, law enforcement needs to be able to take every legally available step to quickly find and protect the child and to stop those that abuse children. It is worrisome to see companies thwarting our ability to do so.”

Holder’s remarks, while he did not mention any particular company by name, come two weeks after Apple announced its new iPhone 6 models would be equipped with data encryption that prevents authorities from accessing the contents of the phone. At the same time, Google said its upcoming Android operating system will also have default encryption.

The encryption decision by two of the world’s biggest names in tech is a bid to gain the trust of customers in the wake of the Edward Snowden surveillance revelations.

Holder said he wants a backdoor to defeat encryption. He urged the tech sector “to work with us to ensure that law enforcement retains the ability, with court-authorization, to lawfully obtain information in the course of an investigation, such as catching kidnappers and sexual predators.”

Mr. Holder, I need to explain something to you, and I will talk slowly.

A backdoor is a security hole, and once you create a security hole, it can be used by anyone.

You are asking every American citizen to make their systems less secure for your convenience.

This is a very bad idea.

Law Enforcement Technology Used to Steal Celebrity Pix

This is we should not create technology allow for unlimited access to our private affairs by the state security apparatus. Because whatever technologies they develop will end up in the hands of criminals:

As nude celebrity photos spilled onto the web over the weekend, blame for the scandal has rotated from the scumbag hackers who stole the images to a researcher who released a tool used to crack victims’ iCloud passwords to Apple, whose security flaws may have made that cracking exploit possible in the first place. But one step in the hackers’ sext-stealing playbook has been ignored—a piece of software designed to let cops and spies siphon data from iPhones, but is instead being used by pervy criminals themselves.

On the web forum Anon-IB, one of the most popular anonymous image boards for posting stolen nude selfies, hackers openly discuss using a piece of software called EPPB or Elcomsoft Phone Password Breaker to download their victims’ data from iCloud backups. That software is sold by Moscow-based forensics firm Elcomsoft and intended for government agency customers. In combination with iCloud credentials obtained with iBrute, the password-cracking software for iCloud released on Github over the weekend, EPPB lets anyone impersonate a victim’s iPhone and download its full backup rather than the more limited data accessible on iCloud.com. And as of Tuesday, it was still being used to steal revealing photos and post them on Anon-IB’s forum.

“Use the script to hack her passwd…use eppb to download the backup,” wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. “Post your wins here ;-)”

Apple’s security nightmare began over the weekend, when hackers began leaking nude photos that included shots of Jennifer Lawrence, Kate Upton, and Kirsten Dunst. The security community quickly pointed fingers at the iBrute software, a tool released by security researcher Alexey Troshichev designed to take advantage of a flaw in Apple’s “Find My iPhone” feature to “brute-force” users’ iCloud passwords, cycling through thousands of guesses to crack the account.

If a hacker can obtain a user’s iCloud username and password with iBrute, he or she can log in to the victim’s iCloud.com account to steal photos. But if attackers instead impersonate the user’s device with Elcomsoft’s tool, the desktop application allows them to download the entire iPhone or iPad backup as a single folder, says Jonathan Zdziarski, a forensics consult and security researcher. That gives the intruders access to far more data, he says, including videos, application data, contacts, and text messages.

You can be sure that whatever the NSA is using is light years ahead of this, and that at some point in the next 5 years, it will be available in the criminal underground, along with whatever back doors the NSA has managed to put into our network infrastructure.

This Whole Naked Picture Thing

I’d love to see naked pictures of Jennifer Lawrence and Kate Upton, but only if they voluntarily do some sort of performance in the nude.

Otherwise, it is squicky. I want to see naked women who want to be naked.

Of course, there is an adult naked picture of me that  might still be in existence.

It was the mid-1980s, and my then girl friend wanted a naked picture. (The non digital kind)

I do not know if she still has it, but for the love of God, if you do, do not punish the world with it.

………

I’m over-sharing, aren’t I.

As an aside, I would add one sort of technical thing: I would not trust the crowd in general, and Apple’s cloud in particular, but if you are going to use the cloud to back up your stuff, not only should the stuff be password protected, but it should also be encrypted as well, both to protect yourself from hackers, competitors, and from the NSA.

Who Says That Irony is Dead?

Microsoft filed a lawsuit to seize domains from No-IP.com. Their reason?

In a blog post, Richard Domingues, assistant general counsel for the Microsoft digital crimes unit, said Microsoft pursued the seizure for No-IP’s role “in creating, controlling, and assisting in infecting millions of computers with malicious software—harming Microsoft, its customers and the public at large.” He added: “We’re taking No-IP to task as the owner of infrastructure frequently exploited by cybercriminals to infect innocent victims with the Bladeabindi (NJrat) and Jenxcus (NJw0rm) family of malware.”

(emphasis mine)

To quote the great Anna Russell, “I’m Not Making This Up, You Know.”

Seriously, “Zero Day” Microsoft, the creater of of Windows, is complaining about someone being the “Owner of infrastructure frequently exploited by cybercriminals to infect innocent victims?”

Really?

The irony here is stunning.

Why the NSA Cannot be Trusted with Our Cybersecurity

Many of you may have heard of the “Heartbleed” bug, which may allow people to access passwords of users and the crypto keys of for websites using the most popular SSL program, OpenSSL.

It now appears that the NSA knew about Heartbleedfor 2 years, and kept it a secret so that they could use the exploit:

The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said.

The agency’s reported decision to keep the bug secret in pursuit of national security interests threatens to renew the rancorous debate over the role of the government’s top computer experts. The NSA, after declining to comment on the report, subsequently denied that it was aware of Heartbleed until the vulnerability was made public by a private security report earlier this month.

“Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before 2014 are wrong,” according to an e-mailed statement from the Office of the Director of National Intelligence.

Heartbleed appears to be one of the biggest flaws in the Internet’s history, affecting the basic security of as many as two-thirds of the world’s websites. Its discovery and the creation of a fix by researchers five days ago prompted consumers to change their passwords, the Canadian government to suspend electronic tax filing and computer companies including Cisco Systems Inc. to Juniper Networks Inc. to provide patches for their systems.

Putting the Heartbleed bug in its arsenal, the NSA was able to obtain passwords and other basic data that are the building blocks of the sophisticated hacking operations at the core of its mission, but at a cost. Millions of ordinary users were left vulnerable to attack from other nations’ intelligence arms and criminal hackers.

This bug is, to Bowlderize Joe Biden, “A big f%$#ing deal.”

It basically completely breaks internet security, and the NSA sat on it, because they wanted to use the exploit.

The idea that anyone would allow the NSA in on any discussion of computer security is truly troubling.  It is like like allowing a young Willie Sutton to consult on bank security.*

* Later in life, after he got out of prison, Willie Sutton did actually consult on bank security.

Clinton’s Reinventing Government Initiative Failure in One Corrupt Failure

Remember when President Clinton put forward the idea of “Reinventing Government”?

It was all about how by unleashing “private sector efficiency” on government functions, with the inevitable result being better government for less money.

Leaving aside the historically dismal performance of such efforts ***cough*** Halliburton ***cough***, but one could make the argument that providing logistical service to the military, but when the part of the Office of Personnel Management responsible for security clearance investigations was spun off as a private firm, USIS, that was a core function.

It really doesn’t get any more “core” than preserving state secrets.

And now we see how “private sector efficiency” has allowed the security clearance process to descend into a morass of corruption and incompetence:

The company that conducted a background investigation on the contractor Edward J. Snowden fraudulently signed off on hundreds of thousands of incomplete security checks in recent years, the Justice Department said Wednesday.

The government said the company, U.S. Investigations Services, defrauded the government of millions of dollars by submitting more than 650,000 investigations that had not been completed. The government uses those reports to help make hiring decisions and decide who gets access to national security secrets.

In addition to Mr. Snowden, the company performed the background check for Aaron Alexis, a 34-year-old military contractor who killed 12 people at the Washington Navy Yard last year. Mr. Alexis, who died in a shootout with the police, left behind documents saying the government had been tormenting him with low-frequency radio waves.

The accusations highlight not just how reliant the government is on contractors to perform national security functions, but also how screening those contractors requires even more contractors. U.S. Investigations Service, now known as USIS, is the largest outside investigator for government security clearances. It is one of many companies that has found lucrative government work during the expansion of national security in the last decade.

From 2008 to 2012, about 40 percent of the company’s investigations were fraudulently submitted, the Justice Department said.

(emphasis mine)

It doesn’t save money.  All it does is increase the looting, and gives the looters more money to lobby for more looting.

This is disastrous for both our government and our society.

The Snowden Clause

Have you heard of the new clause in many overseas contracts?

It is a clause requiring that a suppliers are forbidden from storing any related data in the United States:

By now, we’ve heard from tech companies such as Facebook, Google and Cisco Systems that the National Security Agency’s spying poses a threat to their international business and, in Cisco’s case, is already hurting it. So what does that threat look like, exactly, at ground level?

Some companies are apparently so concerned about the NSA snooping on their data that they’re requiring – in writing – that their technology suppliers store their data outside the U.S.

In Canada, a pharmaceutical company and government agency have now both added language to that effect to their contracts with suppliers, as did a grocery chain in the U.K., according to J.J. Thompson, chief executive officer of Rook Consulting, an Indianapolis, Indiana-based security-consulting firm. He declined to name the companies, which are using Rook to manage the segmentation and keep the data out of the U.S.

The US is already choking off its domestic technology industry with insane draconian IP protections, and now we have this.

We are an empire which is sacrificing all on our need for hegemony.

One of the Best Articles on Security Theater I’ve Seen this Far

Read this essay from a former head of security at Ben Gurion airport:

For a bunch of people in snappy uniforms patting down crotches, the TSA is remarkably unpopular. Nobody likes going through security at the airport, but you probably figured most of it had a point. All those hours spent in line with other shoeless travelers are a necessary precursor to safe flying. It’s annoying, but at least it wards off terrorism.

That’s all bullsh%$. The TSA couldn’t protect you from a 6-year-old with a water balloon. What are my qualifications for saying that? My name is Rafi Sela, and I was the head of security for the world’s safest airport. Here’s what your country does wrong.

He is clear, and concisely explains the systemic problems present in the agency.

This is the money quote:

Of course, after a little while it came out that these scanners were useless. I could strap a bomb capable of taking down a 747 to my body and walk right through a body scanner. Nobody would catch me. I’d rather not explain exactly how, but this German man was able to sneak a fake bomb through the same scanners without being caught. And he did it in Germany, a country where “airport security officer” isn’t a synonym for “failed Walmart cashier.”

His basic thesis is that the organization is fatally flawed because it is designed to regulate itself.