Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

U.S. VA explores protecting your hacking cough from hacking



Though cybercriminals haven’t yet started hacking pacemakers for kicks, the U.S. Veteran Affairs Department (VA) has launched a new project to ensure connected medical devices are protected.
As reported by NextGov.com, VA has begun fact-finding information on methods to safeguard wirelessly connected medical equipment from malicious cyber attacks.
As the Internet of Things (IoT) is increasingly used in health applications, more and more connected devices are being employed by health centers and hospitals for patient monitoring and diagnosis.
VA is concerned that the wireless nature of the connectivity allows these devices to bevulnerable to nefarious actors. And so the department is undertaking a “comprehensive, defense-in-depth” initiative that seeks to secure IoT equipment on hospital networks from any malicious attacks.
VA’s interest in bolstering IoT security follows a recent attack on the MedStar Health network in Washington, D.C. which saw its patient records blocked by ransomware.
As more devices become integrated into healthcare facilities, concerns for hospital network security are increasing in tandem. This concern was behind VA’s new cybersecurity strategy launched last fall that focused on securing medical devices and general medical cybersecurity.


VA has set guidelines for the IoT security needs

According to the NextGov report, VA’s requirement for medical IoT security include: automation; scalability to millions of devices; consideration for device time lags; and the capacity to generate reports on protocols, threat indicators and device traffic volume.
And this data integrity issue is one that will grow ever thornier as medical wearables and implantables become more commonplace.
ReadWrite recently wrote that RFID chips, for example, could replace medical alerts bracelets and avoid drug interactions caused by mis-prescribing drugs but “a number of people have told me that the ease of removing an RFID chip (with a scalpel presumably) could result in identity or financial theft. Others raise the issues of hacking and long-term medical complications caused by implants. But regardless of resistance, this technology is here, it is being used successfully for a range of purposes and it will be an integral part of wearables of the future.”

New Node.js v6 boosts security, reliability for IoT jobs



Amidst the fast-changing landscape of the Internet of Things (IoT), the world’s fastest growing open source platform Node.js launched a major update that will enhance its security, reliability and performance for IoT-related solutions.
News of the update came from the Node.js Foundation, an industry-backed, community-led consortium that developed the open source platform. It announced the release of version 6 of Node.js, a universal platform that is used for IoT, microservice architectures, mobile, web applications and enterprise application development.
Currently Node.js has 3.5 million users and is posting an annual growth rate of 100% – the fasted growing open source platform in the world. The consortium says Node.js is the only unified platform that can be used by full stack JavaScript developers for IoT, mobile, back end and front end projects.
“The Node.js Project has done an incredible job of bringing this version to life in the timeline that we initially proposed in September 2015. It’s important for us to continue to deliver new versions of Node.js equipped with all the cutting-edge JavaScript features to serve the needs of developers and to continue to improve the performance and stability enterprises rely on,” said Node.js Foundation community manager Mikeal Rogers. “This release is committed to Long Term Support, which allows predictable long-term stability, reliability, performance and security to the growing number of enterprise users that are adopting Node.js as a key technology in their infrastructure.”
The Foundation’s diverse member base includes such companies as: Google, SAP, GoDaddy, Fidelity, Groupon, Yahoo! and NodeSource.


Node.js v6 key upgrade is 4x performance

A key upgrade with the latest Node.js version (Node.js v6) is its enhanced performance — four times faster than version 4 — which will significantly cut startup time for large applications.  As well, the latest Node.js version will come equipped with v8 JavaScript engine 5.0, which features improved support for ECMAScript 2015.
Meanwhile, security received upgrading as well, with several new features that make it easier to write secure code for Node.js V6. Its new Buffer API helps cut the risk of vulnerabilities and bugs filtering into applications through a new constructor method for creating Buffer instances. And other enhancements allow developers to use older modules safely that have not been updated for use with the new constructor.
Lastly, reliability has been boosted by a focus on increased testing and documentation for Node.js v6, which assists companies that are currently using the platform or are exploring the possibility in the future.

Gartner: Global IoT security spending to hit $348m in 2016



The rapid growth of the Internet of Things (IoT) and the tandem acceleration in malicious attacks on connected devices will drive worldwide expenditures on IoT security by 24% this year to $348 million. And that’s the good news; according to a new report that momentum isexpected to accelerate significantly after 2020.
An Information Week article reported Gartner’s latest predictions on the IoT security market in a new market report released this week entitled “Forecast: IoT Security, Worldwide, 2016”.
“Gartner forecasts that 6.4 billion connected things will be in use worldwide in 2016, up 30 percent from 2015, and will reach 11.4 billion by 2018,” said Gartner research director Ruggero Contu. “However, considerable variation exists among different industry sectors as a result of different levels of prioritization and security awareness.”
The Gartner report sees moderate IoT security spending in the next few years as the technology continues to establish itself. It predicts respectable spending growth that will increase to $547 million in 2018 and to $841 million in 2020.
However, after 2020 the report expects IoT security spending to take on much greater momentum, “as improved skills, organizational change and more scalable service options improve execution.”
The adoption of IoT technology in both consumer and industrial sectors will also be a major growth accelerant in connected devices.  And as the proliferation of connected devices accelerates, IoT vendors will be forced to prioritize a radically evolving set of security challenges.


Gartner sees IoT the root of 25% of attacks by 2020

Gartner’s report anticipates that over 25% of identified security attacks on enterprises will be IoT-related by 2020. Yet with less than 10% of IT security budgets expected to be allocated to IoT by then, a dangerous security mismatch is looming.
In light of budget restrictions, vendors will struggle to create immediate security fixes and so will likely focus excessively on exploits and vulnerabilities. But Gartner predicts that the industry’s preoccupation with putting out IoT security fires will distract them from finding long-term security solutions.
In order to properly secure IoT, enterprises will “focus more and more on the management, analytics and provisioning of devices and their data,” said Contu. “IoT business scenarios will require a delivery mechanism that can also grow and keep pace with requirements in monitoring, detection, access control and other security needs.”
He adds that cloud-based security services are vital to the ensuring that IoT technology reach its full potential in strength and scale. Gartner predicts that by 2020 half of all IoT implementations will employ some type of cloud-based security to satisfy regulatory and reliability demands.

Will security vulnerabilities dent smart city efforts?



As the Internet of Things (IoT) drives ever more smart city initiatives, security experts fear IT departments will soon be overwhelmed by hackers attracted by huge new troves of data.
recent article by ITWeb discussed increasing IoT and smart city security issues with Paul Williams, major account manager for network security firm Fortinet.
Williams sees a new IoT-driven era emerging where cloud services and connected workplace devices proliferate rapidly. While IoT technology growth is undeniably benefiting productivity, he warns that it is also creating chaos for Chief Information Officers (CIOs) whose tightly held control over their IT systems is being shattered.
“CIOs now have to grapple with the idea of employees using unsanctioned cloud services via unsecured phones to hook up to corporate servers and accessing sensitive business data,” said Williams. “CIOs should look at IoT devices that offer device-to-device encryption, and bolster comprehensive encryption schemes to protect data in networks, cloud services and endpoint devices.”
He sees the quickly expanding smart city services technology and services available as adding to this chaos with new targeted security vulnerabilities.
“Connected devices will generate huge data repositories and businesses that adopt big data systems will see an even larger data deluge,” he said.
“To protect huge amounts of data with large inflows and outflows, the bandwidth capabilities of security appliances will come to the fore.”


Smart cities weakened by devices’ authentication issues

He says smart cities bristling with connected devices face a major vulnerability in that most of IoT technology only requires a one-time authentication process across multiple sessions. This differs from laptops and cell phones which usually require authentication every time.
“This will make them attractive to hackers looking to infiltrate into company networks, as it allows easy control and sniffing of traffic,” said Williams.
“CIOs should map out where these gateways are and where they are linked to − they can reside internally or externally and even be connected to IoT device manufacturers.”
The dangers posed by the growing global footprint of smart cities are very real, and he says new viruses are emerging to specifically target IoT technology. Williams gives the example of the new Conficker worm which was designed to attach itself to IoT devices and spread via PCs.
“Such worms and viruses are persistent and can propagate from device to device particularly with mobile and the Android operating system,” he warns. “They can easily infect up to 50 million PCs if the spread of IoT worms is not properly mitigated.”

Fashion deal signals a new era in connected clothes



For those deafened by the silence of their wardrobe, a new technology partnership will enableconnected clothes to keep you regularly updated with news from your t-shirt drawer.
As reported by Quartz, London-based Internet of Things (IoT) startup Evrythng forged a deal with clothes-maker Avery Dennison to connect 10 billion pieces of clothing to the internet. The value of the deal was not released.

Smart labels will be attached by Avery Dennison to clothing during its manufacturing process, with the first web-enabled products hitting stores by the summer. Data produced by each unique article of clothing will feed into Evrythng’s platform for analysis.
Unique clothing identifiers could allow consumers to verify the ethical origin of materials in clothes, determine product availability or let aging shoes advise the customer how to recycle that type of footwear. The data could also enable brands to use the platform to enhance loyalty programs.
“The internet of things is still at the margins in the way it hits consumers’ lives; now you have billions of everyday objects with identities in the cloud,” said Evrythng co-founder Andy Hobsbawm.

Avery Dennison makes products for such brands as Hugo Boss, Nike and Under Armor, though the companies would not say which particular brands have signed up for the initiative. However, Avery Dennison suggests that sportswear companies will likely be early adopters of IoT enabled clothes, especially considering firms like Nike are already making smart sneakers.
“We’re noticing sports brands engaging consumers with technology more and more,” says Avery Dennison vice president Deon Stander.


Now clothes provide data, too

Clothing labels have been providing digital information for years through such means as bar codes and QR codes, but that information is on broader classes of products. Meanwhile Evrythng says its technology allows a new IoT approach where each unique piece of clothing produces granular data that can be better mined for actionable information.
Privacy and security issues remain a key concern as more objects and articles of clothing become connected to the internet and produce streams of data. Evrythng says they will incorporate privacy safeguards into its clothing label project that will allow customers to set the level of information they are sharing.

“The more information accessed on the web the better, but like everything else on the internet, there also has to be individual judgement calls about what’s appropriate. Not everyone wants to share everything, and that’s fine,” Hobsbawm says.

Credit Card Robbery in Starbucks: Who Is Guilty and What to Do

Credit Card Robbery in Starbucks: Who Is Guilty and What to Do

Credit Card Robbery in Starbucks: Who Is Guilty and What to Do

Starbucks is probably the most affordable place to enjoy a cup of coffee and friendly service in the whole world. These “fast-drink” cafes are located in many big cities and even tiny towns of the world. Starbucks cafes have a nice peculiarity: every guest gets a paper cup of coffee with his name on it. This simple trick makes every customer feel welcome and surrounded by attention. But in Victorville, California, a Starbucks worker invented another horrible knavish trick to get something more than tips. In one of the Californianstarbucks with a drive thru a customer was robbed—without stealing anything.
Elizabeth Becerra visited a local drive thru Starbucks with her brother. They were served and asked to wait for a few seconds for the worker to check thecredit card data and print a receipt. After everything had been done, Elizabeth drove home. A few days later, it turned out that somebody used the woman’s credit card without her knowledge. This mysterious somebody made an expensive purchase at the grocery shop (212 dollars disappeared from the card) right on New Year’s day! The plastic card was not stolen or borrowed by somebody, and the last payment was made in Starbucks. That is whenElizabeth decided to settle the issue and talk to the Starbucks employee whohad served them. The process of “getting even” was recorded on camera and then posted on YouTube.
Becerra decided to attack the alleged thief suddenly to see her very first reaction. The woman accused the Starbucks employee of making an illegal copy of her plastic card. Elizabeths strategy was very wise and efficientthe worker owned up to the crime without any denial or lying. The 19-year old Starbucks worker apologized sincerely and told her “victim” that she was just a high-school student who was keen on soccer.
But that attempt to mollify Becerra’s anger was unsuccessful. Elizabeth promised to file charges against that young scammer. Moreover, she uploaded the video of disclosure to the Internet to attract public’s attention to the credit card security issue. In the comments below the video, YouTube users separated into two groups: defenders of the 19-year-old Starbucks thief and her haters. Many people claimed that the worker was very confused by Elizabeth’s aggressive behavior, and she could not have performed such a trick herself. The girl took the blame upon herself, just to calm Becerra down. And the haters are sure that the former Starbucks worker (she was fired) was a part of the crime syndicate!
Official representatives of the local Starbucks claimed that it was the first and the last incident of credit card fraud in their cafe.

Sony Pictures' security chief once thought data breaches weren't a big deal

Ap346373206136

Sony stands to lose a lot from the massive hack that continues to leak tons of documents and data — passwords, full-length films and the social security numbers of 47,000 people, including celebrities — to the public, experts say.
The company has remained mostly mum about the hack, but as Fusion points out, some of the Sony Pictures' history could possibly shed some light on the fact that data security wasn't always a major concern up top.
In 2007, Sony's executive director of information security said in an interview with CIO that he wasn't willing to put up a lot of money to defend the company's sensitive information. He also talked about how he convinced a security auditor, a year before in 2006, that the company's use of very weak passwords wasn't such a big deal.
"It’s a valid business decision to accept the risk” said Jason Spaltro, who is now Sony Pictures' senior vice president of information security, in the interview. “I will not invest $10 million to avoid a possible $1 million loss."
The loss of what Sony has endured following the mysterious "Guardians of the Peace" hack is probably much, much more substantial than $1 million, however.
"I have no idea how to value the dollar cost of losing control of employee Social Security Numbers, highly confidential company documents, and of course the reputation damage from being victimized like this," Tod Beardsley, engineering manager at security firm Rapid7, toldMashable in an email. 
Beardsley said he didn't want to victim-blame Sony, and that the security landscape has changed a lot since 2007. But Adrian Sanabria, a security expert with 451 Research, said companies typically have to endure a breach before they begin taking information security seriously. Even though some companies get put out of business by hacks, "there will still be that head of InfoSec bragging that he convinced auditors that terrible passwords are okay.""If it were possible to spend 10 million 2007 dollars to prevent this incident, that would have been a serious bargain.”

Sanabria told Mashable it will be the lawsuits that will be the big deal. Top-billed film stars, movie theaters, retail chains and streaming services all stand to lose out on something if people download Annie and Fury, he said.
"So many files have been leaked that this is really just the tip of the tip of the iceberg," he said.
Sony's Spaltro has a salary that tops $300,000 this year, Fusion notes. It will break $400,000 if he gets his bonus.

Students Sue Google for Monitoring Their Emails

Google.jpg

In a challenge to one of Google's more controversial practices, a group of students in California are suing Google, claiming that the company's monitoring of Gmail violates federal and state privacy laws.
The U.S. District Court for the Northern District of California is currently hearing the complaint from nine students whose emails were subject to Google surveillance because Gmail is a component of Apps for Education. Apps for Education is a suite of free, web-based education tools that has some 30 million users worldwide, most of whom are students under 18 exposed to the software via their schools.
A Google rep told Education Week that the company scans and indexes emails from all Apps for Education users. The company uses the data for potential advertising, among other purposes.
Education Week speculates that the case could have "major implications" for how the Family Educational Rights and Privacy Act [FERPA] is interpreted. FERPA, which was issued in 1974, ensures the privacy of records of students under the age of 18. The Department of Education'srecent guidance on the issue also appears to indirectly state that Google's Gmail practices run afoul of FERPA.
The students are seeking class-action certification for the case.  
If successful, that could lead to a payment to millions of Gmail users. However, in a victory for Google, U.S. District Judge Lucy Koh in San Jose, Calif., on Tuesday declined to combine other related suits against Google's Gmail on similar grounds into one class-action suit.Google's surveillance of Gmail for advertising purposes has raised hackles among privacy advocates. In particular, the ElectronicPrivacy Information Center (EPIC) points out that even if Gmail users agree to Google's terms, that doesn't mean that non-subscribers who email with them do. "Non-subscribers have not consented and indeed may not even be aware that their communications are being analyzed or that a profile may be compiled of him or her," states anFAQ on EPIC on the subject. EPIC also takes issue with Google's ability to compile a detailed profile of a Gmail user by linking their Gmail data with cookies used by Google's search engine. Google has said that it doesn't cross-reference such data.

Microsoft has also criticized Google's Gmail practices in its Scroogled campaign, contrasting Google's data mining with Microsoft's Outlook, which doesn't use email data to serve users ads.

Credit Cards Stolen from Target Are Flooding the Black Market

Target1

Credit-card data stolen during a massive data breach at Target last month is hitting the black market, according to multiple reports.
Cybersecurity firm Easy Solutions "noticed a 10- to 20-fold increase in the number of high-value stolen cards on black market websites, from nearly every bank and credit union," The New York Times reported. Easy Solutions did not immediately respond to Mashable's request for comment.
Security blogger Brian Krebs, who broke the original story about the Target hack, also reported on Friday that thieves have been selling batches of 1 million cards at "$20 to more than $100 per card."
Krebs reported that a fraud analyst at a major bank told him that "his team had independently confirmed that Target had been breached after buying a huge chunk of the bank’s card accounts from a well-known 'card shop' — an online store advertised in cybercrime forums as a place where thieves can reliably buy stolen credit and debit cards."
Once in possession of the credit cards, thieves can clone the cards and use them in stores. If they get access to a customer's PIN, they could also withdraw money from their account. Target CEO Gregg Steinhafel said in a message to customers that "There is no indication that PIN numbers have been compromised on affected bank issued PIN debit cards or Target debit cards."
Target did not immediately respond to a request for comment on the latest reports.
The company said it would notify all 40 million of its affected customers this weekend. These customers made purchases at Target stores between Nov. 27 and Dec. 15.

The Simplest Way to Secure Your Webcam Without Any Software

The Simplest Way to Secure Your Webcam Without Any SoftwareWebcam

Let’s start with the bad news: Your webcam is vulnerable. It can be remotely activated and you won’t even know it’s on. A report this month in the Washington Post revealed that the FBI figured out how to do this years ago.
Now for the good news: You can protect your webcam privacy with a bit of MacGyver-esque ingenuity. All you need is a Post-it note.
Start with your standard 2x2-inch Post-it Note in the color of your choice (we don't recommend the super-sticky variety). A piece of notepaper will work just as well. A piece of black tape would be a more permanent solution, but you will probably want to use that webcam someday. Tape, black or otherwise, could leave glue residue on the webcam lens or tiny illumination light, rendering it useless.
No writing on the Post-it is required. Simply fold the paper into approximate thirds; the placement of the folds will depend on where the webcam rests on your laptop. The goal is to fold the note so the sticky portion adheres to the back of your laptop screen (the computer’s cover), a third sits on top of the upper edge and the remaining third covers your webcam. The last third shouldn't be so large that it reaches and obscures a portion of your screen.
You can press the Post-it Note’s sticky portion onto the back of your screen, but we recommend leaving it free so you can slide away the DIY cover when you want to use your webcam.
Our Vine video takes you through each step
Now, even if someone can access your webcam, he will only see your Post-it Note, not your unknowing face.
It’s also worth noting that before any hacker can gain access to your computer, he still needs your help. Most of the software used to activate webcams is malware, born on the back of phishing emails. If you never open or act on these messages, your likelihood of protection from hackers is much higher.
Of course, this is just one solution. You can add privacy to your webcam in other crafty ways — even with some 3D-printed options for less than $15. Share your preferred method in the comments below.