The Washington Post reports that—as part of a security test—a team of students from The University of Michigan hacked D.C.'s new Internet-based voting system. The "White Hat" hackers from Michigan compromised the system so that after a vote was cast the Web site played The University of Michigan fight song, "The Victors."
According to the Post, Jeremy Epstein, a computer scientist working with the Common Cause good-government nonprofit on online voting issues said "the fight song is a symptom of deeper vulnerabilities. ... In order to do that, they had to be able to change anything they wanted on the Web site."
Because of the hack, Paul Stenbjorn, the Board of Elections' chief technology officer said a portion of the Internet voting pilot—which was expected to be rolled out this month—is being temporarily scrapped.
The good news, of course, is that to ensure election integrity, D.C. took the opportunity to open its election web-site to community testing. That the vulnerability was found and exploited by a team of students from my Alma Mater is icing on the cake. That they rigged the system to play The Victors is the maraschino cherry on top. Go Blue!
The bad news—and one that every organization having a web site has to pay attention to—is that web-sites, like software everywhere, is buggy. That's why this story is a good reminder to all organizations of the importance of effectively managing cybersecurity risk.
Showing posts with label Miscellany. Show all posts
Showing posts with label Miscellany. Show all posts
Monday, October 4, 2010
Friday, August 20, 2010
Was Malware Responsible for Crash of Spanair Flight 5022?
The Registry reports that malware may have been a contributory cause of the crash of Spanair flight JK 5022 crashed in August 2008. The flight crashed moments after taking off from Madrid's Barajas Airport on a scheduled flight to Las Palmas with 172 on board.
According to the Registry, the airline's central computer which registered technical problems on planes was infected by Trojans at the time of the fatal crash and this may have resulted in a failure to raise an alarm over multiple problems with the plane.
According to the Registry, the airline's central computer which registered technical problems on planes was infected by Trojans at the time of the fatal crash and this may have resulted in a failure to raise an alarm over multiple problems with the plane.
Thursday, May 13, 2010
Are Cars Next for Cybercriminals?
The New York Times reports that in a "paper, which will be presented at a computer security conference next week in Oakland, Calif., computer security specialists at the University of Washington and the University of California, San Diego, report that while modern cars have extensive safety engineering in the design of their computer control systems, little thought has been given to the potential threat of hackers who may want to take over the networks that increasingly control modern cars. ...The researchers asked what could happen if a hacker could gain access to the network of a car, said Tadayoshi Kohno, a University of Washington computer scientist. He said the research teams were able to demonstrate their ability to circumvent a wide variety of systems critical to the safety of drivers and passengers. ...They also demonstrated what they described as “composite attacks” that showed their ability to insert malicious software and then erase any evidence of tampering after a crash. ... The researchers were able to activate dozens of functions and almost all of them while the car was in motion."
Read the NY Times story.
Read the NY Times story.
Wednesday, April 7, 2010
ISP Privacy Proposal Draws Fire
Brian Krebs reports that the American Registry for Internet Numbers (ARIN) — one of five regional registries worldwide that is responsible for allocating blocks of Internet addresses – is considering a proposal to ease rules that require ISPs to publish address and phone number information for their business customers. The proposal is drawing strong criticism from information systems security professionals as it will make it harder to fight spam, malware and other forms of cybercriminal activity.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Tuesday, December 8, 2009
Brian Krebs, Washington Post Journalist, Named Cybercrime Hero by Cisco
What's happening: Cisco's 2009 Annual Security Report names Brian Krebs, Washington Post journalist, as winner of its Cybercrime Hero.
The report writes: Kudos to Brian Krebs, who reports on computer security issues in his Security Fix blog on the website of The Washington Post. Krebs has spent a significant amount of time researching and reporting on banking Trojans like Zeus and Clampi and exposing how they operate.
In the fall of 2009, Krebs published a series of articles about the online “bank jobs” conducted by the sophisticated malware that Zeus and Clampi distribute. Through his extensive research and reporting, Krebs managed to discover a great deal about these Trojans. The tactics and routines associated with the malware—and the significant number of businesses and individual users who have been affected by it—would likely impress even some of the most successful bank thieves in history.
Krebs has taken time not only to report on these dangerous threats, but also to provide readers with practical and easy-to-understand advice about how not to fall victim to such scams.
What it means: Congratulations to Krebs for his award. The information security community has a friend in Krebs. One can only hope that a Pulitzer follows.
**********************************
Cisco names Security Fix author 'cybercrime hero'
The report writes: Kudos to Brian Krebs, who reports on computer security issues in his Security Fix blog on the website of The Washington Post. Krebs has spent a significant amount of time researching and reporting on banking Trojans like Zeus and Clampi and exposing how they operate.
In the fall of 2009, Krebs published a series of articles about the online “bank jobs” conducted by the sophisticated malware that Zeus and Clampi distribute. Through his extensive research and reporting, Krebs managed to discover a great deal about these Trojans. The tactics and routines associated with the malware—and the significant number of businesses and individual users who have been affected by it—would likely impress even some of the most successful bank thieves in history.
Krebs has taken time not only to report on these dangerous threats, but also to provide readers with practical and easy-to-understand advice about how not to fall victim to such scams.
What it means: Congratulations to Krebs for his award. The information security community has a friend in Krebs. One can only hope that a Pulitzer follows.
**********************************
Cisco names Security Fix author 'cybercrime hero'
Thursday, October 29, 2009
Information Security Breach Surfaces at House Ethics Committee
What's happening: The House Ethics Committee announced that a document containing the names of more than two dozen members of Congress being investigated by the Committee—together with the status of the investigations—had surfaced on a part of the web known as "peer-to-peer."
What it means: The embarrassment to the Ethics Committee caused by the breach and the risk to the reputation of lawmakers resulting from it serve to illustrate the danger of peer-to-peer networks—used primarily for the illegal sharing of copyrighted material. Sensitive information can be all-too-easily sucked up into a peer-to-peer network becoming accessible to anyone on the same peer-to-peer. Cyber-criminals regularly troll peer-to-peer networks looking for sensitive information (like credit card numbers) that they can monetize. Peer-to-peer networks are very dangerous and serve no useful purpose in the business environment.
What to do: Management must outlaw peer-to-peer networks in the corporate environment and must make sure the network (including all remote computers) is regularly scanned for the presence of peer-to-peers. Users also need to be trained about the dangers of peer-to-peer networks and should be strongly discouraged from using them at home.
**********************************
New York Times: Ethics Inquiries Into Lawmakers Surface via Security Breach
WASHINGTON — The House ethics committee announced Thursday that it would begin full investigations into two House members ... but a security breach threatened to make public the names of many other members facing ethics inquiries.
http://www.nytimes.com/2009/10/30/us/politics/30ethics.html?_r=1&scp=5&sq=ethics%20committee&st=cse
What it means: The embarrassment to the Ethics Committee caused by the breach and the risk to the reputation of lawmakers resulting from it serve to illustrate the danger of peer-to-peer networks—used primarily for the illegal sharing of copyrighted material. Sensitive information can be all-too-easily sucked up into a peer-to-peer network becoming accessible to anyone on the same peer-to-peer. Cyber-criminals regularly troll peer-to-peer networks looking for sensitive information (like credit card numbers) that they can monetize. Peer-to-peer networks are very dangerous and serve no useful purpose in the business environment.
What to do: Management must outlaw peer-to-peer networks in the corporate environment and must make sure the network (including all remote computers) is regularly scanned for the presence of peer-to-peers. Users also need to be trained about the dangers of peer-to-peer networks and should be strongly discouraged from using them at home.
**********************************
New York Times: Ethics Inquiries Into Lawmakers Surface via Security Breach
WASHINGTON — The House ethics committee announced Thursday that it would begin full investigations into two House members ... but a security breach threatened to make public the names of many other members facing ethics inquiries.
http://www.nytimes.com/2009/10/30/us/politics/30ethics.html?_r=1&scp=5&sq=ethics%20committee&st=cse
Subscribe to:
Posts (Atom)