In a recent interview with TechCrunch's Michael Arrington (9 Jan 2010), facebook's founder, Mark Zuckerberg declared the world has changed- that the age of privacy is over.
Okay... when facebook first launched, I had an account. Then I shut it down. I thought to myself, why would I want to put my personal life on the web? Fast-forward a few years and EVERYONE I know not only share their personal lives, but things about me and those I care about on their facebook pages. I restarted my account... if for no other reason than to attempt to keep an eye on what was posted and at least try and protect those I care about from doing something too dangerous from an information security perspective.
But your efforts to protect your privacy won't amount to much if the founder of the site sees the information protected by your privacy settings as lost revenue...
Perhaps, Mr Zuckerberg needs to take a close look at the results of this survey: Cyber Crime Survey: Trust Shaken
Globally, criminals are reviving our concern for our personal information using a powerful motivator- economics (read as: we fear of losing our hard-earned cash)... and unfortunately, Mr Z is missing an opportunity to distinguish himself as a privacy leader.
Why would people continue to use facebook? For now, the perceived benefits of sharing our lives with those we interact with (our tribe) outweigh the risk. However, other tribes want to use our information for another purpose... to scavenge it for tasty morsels of personal information to use to clean out our bank accounts and otherwise disrupt our lives.
Mr Zuckerber's view on the privacy of his customer's data favors the latter group.
I think it may be time to once again, close my facebook account (as though my data is REALLY gone).
Sorry, mom. You'll just have to switch back to email.
Listen to Mr Zuckerberg's comments here: http://www.ustream.tv/recorded/3848950
Showing posts with label cyber-crime. Show all posts
Showing posts with label cyber-crime. Show all posts
1.10.2010
Cybercrime: the Next Driver of Internet Innovation
Those of you that know me have heard me rant about this from my geek soapbox. Well, I finally decided to put it in writing.
Crime is the next driver of Internet innovation: regardless of what color hat you wear.
Sure, crime always been part of the Web (and its ancestors). Remember BBS sites with stolen credit cards back in the 80s? I do. Crime has been with us, just as porn, chatting with our friends and email have been there. Porn begat pay per click... which was adopted by legit advertising... which begat online shopping... which (combined with email) begat social adoption of the web (video games helped for the younger generation... but my mom uses FaceBook because she got used to interacting with the Internet via shopping)... which begat social networking... all of the above begat opportunities for criminals to take money from the unsuspecting- cybercrime.
I'm not implying crime hasn't always been an issue. It has. But it has taken on an entirely new flavor as competition AMONG criminals has sparked heretofore unseen levels of sophistication and innovation. And from a broader perspective, cybercrime is coming to the forefront of our collective consciousness and shaping change in our societies and how we interact on the web. And this is only the beginning.
For the black hatters, this is certainly shaping up to be the golden age of cyber-crime innovation. The monetization of malware has arrived! Supply chains, botnet-for-rent (complete with FAQs), pay-per-X schemes (e.g., iFrame, infection, etc), malware help desks, money-mule recruiting sites, even pay-per-scan sites to test your code against malware scanners! All the while, legal frameworks, jurisdiction issues and white hat technologies struggle to keep pace. These are great times indeed...
And what is the impact of all of this? In the US, municipalities, small businesses and school districts are getting fleeced. National and corporate secrets are being siphoned off like foam from a pint of beer. And perhaps more importantly, the Internet, which began as a place to share ideas freely is becoming a scary place to be... not what we (regardless of what color hat you wear) intended.
For the white hatters our there... this may FINALLY be their wake-up call. Clearly, the old way of doing business, which previously simply hasn't worked is not only becoming embarrassing, it is becoming expensive. It is only a matter of time before the citizenry begins to pressure their governments to shape the future of EULAs... license agreements that hold no one accountable for shoddy work- regardless of the damage it causes. Signature-based tools are so 2000s- stale and woefully not up to the task. The speed of change in the malware world is driving white-hatters to look at new technologies, revisit assumptions and take a new look at risk management. What REALLY needs to be done via the web? What is an acceptable level of risk. Heck, do we as an organization even understand the risk?
Security used to be an afterthought- speed to market, content richness and features were THE issue- regardless of their impact on security or privacy. They still are important... but to the user, privacy and security are quickly becoming an increasing (if not the primary) concern. THAT is change.
Crime is the next driver of Internet Innovation: if I'm wrong... we are all in trouble- regardless of what hat we wear.
~Cpwnk
Crime is the next driver of Internet innovation: regardless of what color hat you wear.
Sure, crime always been part of the Web (and its ancestors). Remember BBS sites with stolen credit cards back in the 80s? I do. Crime has been with us, just as porn, chatting with our friends and email have been there. Porn begat pay per click... which was adopted by legit advertising... which begat online shopping... which (combined with email) begat social adoption of the web (video games helped for the younger generation... but my mom uses FaceBook because she got used to interacting with the Internet via shopping)... which begat social networking... all of the above begat opportunities for criminals to take money from the unsuspecting- cybercrime.
I'm not implying crime hasn't always been an issue. It has. But it has taken on an entirely new flavor as competition AMONG criminals has sparked heretofore unseen levels of sophistication and innovation. And from a broader perspective, cybercrime is coming to the forefront of our collective consciousness and shaping change in our societies and how we interact on the web. And this is only the beginning.
For the black hatters, this is certainly shaping up to be the golden age of cyber-crime innovation. The monetization of malware has arrived! Supply chains, botnet-for-rent (complete with FAQs), pay-per-X schemes (e.g., iFrame, infection, etc), malware help desks, money-mule recruiting sites, even pay-per-scan sites to test your code against malware scanners! All the while, legal frameworks, jurisdiction issues and white hat technologies struggle to keep pace. These are great times indeed...
And what is the impact of all of this? In the US, municipalities, small businesses and school districts are getting fleeced. National and corporate secrets are being siphoned off like foam from a pint of beer. And perhaps more importantly, the Internet, which began as a place to share ideas freely is becoming a scary place to be... not what we (regardless of what color hat you wear) intended.
For the white hatters our there... this may FINALLY be their wake-up call. Clearly, the old way of doing business, which previously simply hasn't worked is not only becoming embarrassing, it is becoming expensive. It is only a matter of time before the citizenry begins to pressure their governments to shape the future of EULAs... license agreements that hold no one accountable for shoddy work- regardless of the damage it causes. Signature-based tools are so 2000s- stale and woefully not up to the task. The speed of change in the malware world is driving white-hatters to look at new technologies, revisit assumptions and take a new look at risk management. What REALLY needs to be done via the web? What is an acceptable level of risk. Heck, do we as an organization even understand the risk?
Security used to be an afterthought- speed to market, content richness and features were THE issue- regardless of their impact on security or privacy. They still are important... but to the user, privacy and security are quickly becoming an increasing (if not the primary) concern. THAT is change.
Crime is the next driver of Internet Innovation: if I'm wrong... we are all in trouble- regardless of what hat we wear.
~Cpwnk
12.14.2009
This is Your Friend... This is Your Friend on FaceBook.
Any questions?
... an egg sizzles as a criminal that has exploited your friend's weak password (or lame security questions), crawls through your personal info and tricks you into downloading and installing a key logger.
The fact is, you aren't really interacting with your friend when you visit a social media site. Each of you interacts with software (most likely, poorly written software) that serves up pages and content to you that are designed to serve as a surrogate for your friend or their interests. It isn't the same thing as having a face to face conversation with them... not by a long shot.
We are social creatures. We like our tribe. We want to belong... We want to trust our friends- our tribe.
Unfortunately, there are some tribes that want what we have.
Incomplete design, flawed privacy and security models and user agreements that hold no one accountable add up to an environment that may be rich in features to lull us into a false sense of security and trust, but is also one which criminals are all too happy to exploit.
Trust your friend. Just don't trust their profile... the click-aholic flash game they are inviting you to play or anything else on your social media site.
... and don't post all of your personal details on your Facebook page. If they are your friends, they already know when your birthday is. Make the bad guys work for it.
Instead, meet your friend for coffee and talk... just pay in cash.
~CPwnk
... an egg sizzles as a criminal that has exploited your friend's weak password (or lame security questions), crawls through your personal info and tricks you into downloading and installing a key logger.
The fact is, you aren't really interacting with your friend when you visit a social media site. Each of you interacts with software (most likely, poorly written software) that serves up pages and content to you that are designed to serve as a surrogate for your friend or their interests. It isn't the same thing as having a face to face conversation with them... not by a long shot.
We are social creatures. We like our tribe. We want to belong... We want to trust our friends- our tribe.
Unfortunately, there are some tribes that want what we have.
Incomplete design, flawed privacy and security models and user agreements that hold no one accountable add up to an environment that may be rich in features to lull us into a false sense of security and trust, but is also one which criminals are all too happy to exploit.
Trust your friend. Just don't trust their profile... the click-aholic flash game they are inviting you to play or anything else on your social media site.
... and don't post all of your personal details on your Facebook page. If they are your friends, they already know when your birthday is. Make the bad guys work for it.
Instead, meet your friend for coffee and talk... just pay in cash.
~CPwnk
2.03.2009
Digital Insurgency
Information assurance, IT (in)security... whatever you want to call it is rife with warlike references. Here's another one for your lexicon.
Digital insurgency.
Why? Traditional IT (in)security begins with an "us-in-here" vs. "them-out-there" approach to protecting the network (and in a few enlightened organizations, the data). We refer to "defense-in-depth"... bastions... firewalls... etc.
The problem is, we are looking at the problem the wrong way.
The reality is, "they" are already among us. Once you start thinking of the adversary among you and your valuable data, your approach changes (or at least should). Sure, don't take down the walls... but you had better learn to operate in an untrustworthy environment. Remove the false sense of security. Assume the enemy knows your technology, your infrastructure layout, your processes, the skill level of your people... everything (except, hopefully your crypto keys).
Get on with counter-insurgency operations within your network. Listen to Sun Tzu- use spies. Engage in insider monitoring. Watch for anomolous behavior. Block "escape routes." Disrupt communications (outbound filtering). Identify and protect what's really important- your data! Encrypt encrypt encrypt (no it doesn't solve the problem... but it does make it harder for script kiddies to pwn you in ways it REALLY counts). Go on the offensive in surgical, well-informed strikes. Improve your interior communication lines' security. Coordinate with the locals... educate and incentivize the populace to cooperate. Associate with those you would never mention among polite company- your competitors... your service providers. Cooperative defense.
Finally, make lasting changes for the long-term good- FIX THE F-ING PROTOCOLS and fatally flawed architecture that allows this to happen!!!
... you get the idea.
~CPwnk
Digital insurgency.
Why? Traditional IT (in)security begins with an "us-in-here" vs. "them-out-there" approach to protecting the network (and in a few enlightened organizations, the data). We refer to "defense-in-depth"... bastions... firewalls... etc.
The problem is, we are looking at the problem the wrong way.
The reality is, "they" are already among us. Once you start thinking of the adversary among you and your valuable data, your approach changes (or at least should). Sure, don't take down the walls... but you had better learn to operate in an untrustworthy environment. Remove the false sense of security. Assume the enemy knows your technology, your infrastructure layout, your processes, the skill level of your people... everything (except, hopefully your crypto keys).
Get on with counter-insurgency operations within your network. Listen to Sun Tzu- use spies. Engage in insider monitoring. Watch for anomolous behavior. Block "escape routes." Disrupt communications (outbound filtering). Identify and protect what's really important- your data! Encrypt encrypt encrypt (no it doesn't solve the problem... but it does make it harder for script kiddies to pwn you in ways it REALLY counts). Go on the offensive in surgical, well-informed strikes. Improve your interior communication lines' security. Coordinate with the locals... educate and incentivize the populace to cooperate. Associate with those you would never mention among polite company- your competitors... your service providers. Cooperative defense.
Finally, make lasting changes for the long-term good- FIX THE F-ING PROTOCOLS and fatally flawed architecture that allows this to happen!!!
... you get the idea.
~CPwnk
Labels:
Cyber security,
cyber-crime,
cybercrime,
cyberwar,
Digital Insurgency,
IT Security
11.08.2008
If he were alive today, Willie Sutton would be a hacker
Willie Sutton is reported (probably falsely) to have said he robbed banks because "that's where the money is." Today, the global IT infrastructure is where the money is. Companies, in an effort to get closer to their customer have entered the "food chain"- and they are not the top predator.
In Willie's day, the only place to buy a Trojan was in a pharmacy. No longer. Want a botnet? No problem, you can rent one. Want a Trojan to use as a payload? No problem. Not only has the bar been lowered for entry to the world of hacking, the potential for damage at the hands of a noob has been raised to that on par of seasoned crackers (as long as the script kiddie can pay for it). And to pay for it, he or she can buy a few stolen credit card numbers.
Willie (when explaining his preference for using a Tommy-gun) observed "you can't rob a bank on charm and personality." You can rob the Web that way. Barriers to entry are low. Attribution remains problematic (whether that is good or bad is perspective-based). Software quality remains shoddy. And it all runs on a fatally flawed architecture (which is unlikely to change for the foreseeable future.) In short, economy and technology favor the attacker.
As for Willie- while he may not have said "Why do I rob banks? Because that's where the money is," he did say:
"Why did I rob banks? Because I enjoyed it. I loved it. I was more alive when I was inside a bank, robbing it, than at any other time in my life. I enjoyed everything about it so much that one or two weeks later I'd be out looking for the next job. But to me the money was the chips, that's all."
Sound like anyone you know?
~CPwnk
Learn more about Willie Sutton
In Willie's day, the only place to buy a Trojan was in a pharmacy. No longer. Want a botnet? No problem, you can rent one. Want a Trojan to use as a payload? No problem. Not only has the bar been lowered for entry to the world of hacking, the potential for damage at the hands of a noob has been raised to that on par of seasoned crackers (as long as the script kiddie can pay for it). And to pay for it, he or she can buy a few stolen credit card numbers.
Willie (when explaining his preference for using a Tommy-gun) observed "you can't rob a bank on charm and personality." You can rob the Web that way. Barriers to entry are low. Attribution remains problematic (whether that is good or bad is perspective-based). Software quality remains shoddy. And it all runs on a fatally flawed architecture (which is unlikely to change for the foreseeable future.) In short, economy and technology favor the attacker.
As for Willie- while he may not have said "Why do I rob banks? Because that's where the money is," he did say:
"Why did I rob banks? Because I enjoyed it. I loved it. I was more alive when I was inside a bank, robbing it, than at any other time in my life. I enjoyed everything about it so much that one or two weeks later I'd be out looking for the next job. But to me the money was the chips, that's all."
Sound like anyone you know?
~CPwnk
Learn more about Willie Sutton
Labels:
cyber crime,
Cyber security,
cyber-crime,
cybercrime,
IT Security
Subscribe to:
Posts (Atom)