Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

Wednesday, December 20, 2017

North Korea Amassing Bitcoin To Fund Cyberattacks According To Crowdstrike CEO


Content originally published at iBankCoin.com


The CEO of cybersecurity firm Crowdstrike, George Kurtz, says North Korea is "absolutely" accumulating a giant pile of bitcoin to fund cyberattacks.

"They"re building a cache of bitcoin, if you think about it. It"s an anonymous currency, it can easily bypass any sort of sanctions because there are none on bitcoin, and the value has increased dramatically," Kurtz told CNBC"s "Squawk Alley." "It"s the perfect currency for North Korea to be hoarding." -CNBC



Can someone say "prohibited country" regulations?


The opinion comes on the heels of an op-ed in the WSJ by Homeland Security advisor Tom Bossert, who says North Korea was behind the WannaCry ransomware hack earlier this year, which demanded ransom in bitcoin.


The U.S. government has assessed with a "very high level of confidence" that a hacking entity known as Lazarus Group, which works on behalf of the North Korean government, carried out the WannaCry attack, said the official, who spoke on condition of anonymity to discuss details of the government"s investigation. -CNBC



The WannaCry hack is said to have cost billions, crippling hospitals, banks and companies around the world - and "highlights the capabilities that North Korea has in cyber," according to Kurtz.



Crowdstrike CEO on 2018 cyber threat outlook from CNBC.


Crowdstrike is the firm which analyzed the DNC servers and determined that Russia hacked them - however the Irvine, CA company came under fire in late 2016 when they had to retract a botched report on Russian hacking of Ukrainian artillery using the same "fancy bear" malware they also say the Kremlin used on the DNC servers.


The government of Ukraine issued a statement after the artillery report came out, calling it Fake News:


In connection with the emergence in some media reports which stated that the alleged “80% howitzer D-30 Armed Forces of Ukraine removed through scrapping Russian Ukrainian hackers software gunners,” Land Forces Command of the Armed Forces of Ukraine informs that the said information is incorrect.


Ministry of Defence of Ukraine asks journalists to publish only verified information received from the competent official sources. Spreading false information leads to increased social tension in society and undermines public confidence in the Armed Forces of Ukraine. –mil.gov.ua (translated) (1.6.2017)



So DHS"s Tom Bossert drops an op-ed on a North Korean hacking operation which only takes Bitcoin, and the CEO of Crowdstrike follows up with a stark warning on Bitcoin hoarding by Pyongyang. 




Follow on Twitter @ZeroPointNow § Subscribe to our YouTube channel


Wednesday, December 13, 2017

Cyberattacks: The Biggest Threat To OPEC

Authored by Irina Slav via OilPrice.com,


Oil and cybersecurity in one sentence certainly makes for a thrilling read, and there will be an increasing amount of information on the topic as the Internet of Things expands and the global oil industry adopts automation and digital technology.



OPEC is no exception in this digitalization drive, but unlike its non-OPEC counterparts, the cartel has emerged as much more vulnerable to cybersecurity threats.


An analysis of data collected from 134 countries by the International Telecommunication Union has revealed that some of the world’s biggest oil producers, including Iraq, Saudi Arabia, Venezuela, Iran, and the UAE, are lacking in the cybersecurity department. This means that, compared to European producers and the United States, OPEC members are pretty much unprepared for a major cyberthreat.


What is the likelihood of such a threat actually materializing? Well, the general opinion in cybersecurity circles is that everything that can be hacked will be hacked at some point. Saudi Arabia’s oil and gas industry, for example, has been a favorite target for numerous attacks over the last few years, including the Shamoon virus, which in 2012 wiped clean the disks of more than 30,000 computers at Aramco, and according to reports from the cybersecurity industry, reared its ugly head again in 2016.


Overall, about half of all cyberattacks in the Middle East target the oil and gas industry, which suggests the answer to the above question is “Pretty high,” but the worse thing is that this likelihood is only going to get higher in the future. Related: Brent Spikes As This Major Pipeline Breaks Down


Middle Eastern producers are following in the footsteps of their non-OPEC counterparts in adopting digital technology and automation to improve efficiencies in the post-2014 world, where efficiency has come to the fore in oil and gas. The problem, of course, is that the more you digitalize, the more vulnerable you become to attacks through digital channels.


A recent study from Siemens and Ponemon Institute found that as digital tech adoption in the Middle East oil industry rises, so does cyber risk. What’s more, this risk is no longer limited to IT operations: the operational technology area is gaining prominence as a preferred target for cybercriminals.


The reason, according to Siemens and Ponemon Institute, is the convergence between IT and OT in the oil and gas industry. “Attackers have identified this convergence of IT and OT as a key opportunity to penetrate an organisation. As a result, an emerging trend of cyberattacks is designed to disrupt physical devices or processes used in operations. In a digital environment, industrial cyber is the new risk frontier,” says Siemens’ Vice President and Global Head of Industrial Cyber, Leo Simonovich.


The cybersecurity industry is sounding an alarm and it seems those in the Middle East that can afford it are hearing it and heeding the warning to improve their cybersecurity capabilities.


The UAE has a Dubai Cyber Security Strategy. Earlier this year, Saudi Arabia launched a National Cyber Security Center, and last month announced the set-up of a National Authority for Cyber Security, seeking to utilize international expertise and best practices to prop up government and critical infrastructure defenses. Iraq is seriously lagging behind and Iran is seen by cybersecurity insiders as more a source of cyberthreats than as a potential victim.


This sounds all well and good, but the trends in cybercrime point to a desperate need to do more. Cybercriminals do not sit on their hands while potential victims work to improve their defenses. While cybersecurity service providers continue to warn businesses and other organizations that they need to become more pro-active with regard to their cybersecurity measures, the hackers are coming up with new ways to undermine existing defenses. This is true for all industries, but it is especially true for oil and gas in the Middle East—national energy infrastructures are called critical for a reason, after all.









Wednesday, November 15, 2017

"FALLCHILL": DHS, FBI Release Details On North Korean Hacking Tools

As tensions between the U.S. and North Korea mount, the DHS and FBI have just issued a pair of technical alerts about cyber attacks which they say are sponsored by the North Korean government and that have been targeting the aerospace, telecommunications and financial industries since 2016.  According to the alert, North Korean hackers have used a type of malware referred to as “FALLCHILL” to gain entry to computer systems and compromise network systems.








Today, DHS and FBI released a pair of Joint Technical Alerts (TA17-318A and TA17-318B) that provide details on tools and infrastructure used by North Korea to target the media, aerospace, financial, and critical infrastructure sectors in the United States and globally.


 


The North Korean government malicious cyber activity noted in these alerts is part of a long-term campaign of cyber-enabled operations that impact the U.S. Government and its citizens. Working closely with our interagency, industry and international partners, DHS is constantly working to arm network defenders with the tools they need to identify, detect and disrupt state and non-state actors targeting the networks and systems of our country and our allies.



Per the pair of techinical alerts, the FALLCHILL malware provides hackers with wide latitude to monitor and disrupt infected networks. The malware typically gains access to systems as a file sent via other North Korean malware or when users unknowingly downloaded it by visiting sites compromised by the hackers.








FBI has high confidence that HIDDEN COBRA actors are using the IP addresses—listed in this report’s IOC files—to maintain a presence on victims’ networks and to further network exploitation. DHS and FBI are distributing these IP addresses to enable network defense and reduce exposure to any North Korean government malicious cyber activity.


 


This alert includes IOCs related to HIDDEN COBRA, IP addresses linked to systems infected with FALLCHILL malware, malware descriptions, and associated signatures. This alert also includes suggested response actions to the IOCs provided, recommended mitigation techniques, and information on reporting incidents. If users or administrators detect activity associated with the FALLCHILL malware, they should immediately flag it, report it to the DHS National Cybersecurity and Communications Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and give it the highest priority for enhanced mitigation.


 


According to trusted third-party reporting, HIDDEN COBRA actors have likely been using FALLCHILL malware since 2016 to target the aerospace, telecommunications, and finance industries. The malware is a fully functional RAT with multiple commands that the actors can issue from a command and control (C2) server to a victim’s system via dual proxies. FALLCHILL typically infects a system as a file dropped by other HIDDEN COBRA malware or as a file downloaded unknowingly by users when visiting sites compromised by HIDDEN COBRA actors. HIDDEN COBRA actors use an external tool or dropper to install the FALLCHILL malware-as-a-service to establish persistence. Because of this, additional HIDDEN COBRA malware may be present on systems compromised with FALLCHILL.


 


During analysis of the infrastructure used by FALLCHILL malware, the U.S. Government identified 83 network nodes. Additionally, using publicly available registration information, the U.S. Government identified the countries in which the infected IP addresses are registered.



KJU


These latest technical alerts follow similar updates from DHS and the FBI from earlier this summer which highlighted malware they claimed North Korean hackers were utilizing to lauch DDoS attacks in the U.S.  Per The Hill:








The agencies identified IP addresses associated with a malware known as DeltaCharlie, which North Korea uses to launch distributed denial-of-service (DDoS) attacks.


 


The alert called for institutions to come forward with any information they might have about the nation’s cyber activity, which the U.S. government refers to as “Hidden Cobra.”


 


“If users or administrators detect the custom tools indicative of HIDDEN COBRA, these tools should be immediately flagged, reported to the DHS National Cybersecurity Communications and Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and given highest priority for enhanced mitigation,” the alert reads.


 


The DHS and FBI also highlighted some vulnerabilities that North Korea has been known to exploit and recommended organizations upgrade to the latest versions of Adobe Flash Player, Microsoft Silverlight and Hangui Word Processor, or delete them altogether if the programs aren’t needed.



Of course, North Korea has routinely denied involvement in cyber attacks against other countries.









Monday, November 13, 2017

The Crimes Americans Worry About Most

Even though 2017 is already the worst year for mass shootings in modern U.S. history, Americans are more worried about cybercrime than violent crime.


That"s according to a new Gallup poll which found that 67 percent of U.S. adults frequently or occasionally fret about having personal, credit card or financial information stolen by hackers. 66 percent also worry about the threat presented by identity theft.


In comparison with cybercrime, Statista"s Niall McCarthy notes that anxiety about conventional crime forms is less prevalent with a large gap to the third-biggest worry - having a car stolen or broken into. That"s a frequent concern for 38 percent of people while 36 percent tend to worry about burglary when they are away from home.


Infographic: The Crimes Americans Worry About Most | Statista


You will find more statistics at Statista


More serious crimes such as muggings, murders and sexual assault are much further down the list, but why?


The reason cybercrime comes first is more than likely due to far higher levels of victimization, along with substantial coverage in the media. Gallup also found that a quarter of households have experienced hackers stealing their personal information while a mere three percent have experienced a burglary.









Wednesday, November 8, 2017

Former Yahoo CEO Mayer Blames Massive Hacks On - Who Else? - Russia

Looks like this guy’s been up to no good...



In an apology that’s long overdue, considering Yahoo revealed two months ago that a series of cyberattacks that it had previously reported actually impacted all of its 3 billion user accounts, former Yahoo CEO Marissa Mayer apologized on Wednesday for a pair of massive data breaches at the internet company. But rather than take responsibility for the cybersecurity failures at company - which was absorbed by Verizon earlier this year - Mayer blamed the hacks on the most convenient bugbear available.


That’s right: Mayer - who gave the apology during Congressional testimony - is blaming the intrusions on the Ruskies, a charge that we’re sure will find sympathy among certain Senate Democrats.



But lest anybody get it twisted, Mayer - in a deflection of blame that was nothing short of Clinton-esque - managed to apologize without admitting ultimate personal responsibility, Reuters reported.


”As CEO, these thefts occurred during my tenure, and I want to sincerely apologize to each and every one of our users,” she told the Senate Commerce Committee, testifying alongside the interim and former CEOs of Equifax Inc and a senior Verizon Communications Inc executive.


 


“Unfortunately, while all our measures helped Yahoo successfully defend against the barrage of attacks by both private and state-sponsored hackers, Russian agents intruded on our systems and stole our users’ data."



Verizon acquired most of Yahoo Inc’s assets in June after Yahoo was forced to accept a lower bid following several unflattering disclosures related to the hacking incidents. Mayer also stepped down in June. Verizon disclosed last month that a 2013 Yahoo data breach affected all 3 billion of its accounts, compared with an estimate of more than 1 billion disclosed in December.


In March, federal prosecutors charged two Russian intelligence agents and two hackers with masterminding the 2014 cybertheft, the first time the US has charged Russia-linked hackers for alleged cybercrimes. Of the accused, one was arrested. Russia has denied the allegations, and there has been some speculation that the attacks were actually planned by the same North Korea-linked group of hackers that perpetrated the 2014 Sony hacks.


According to Reuters, Special Agent Jack Bennett of the FBI’s San Francisco Division said in March the 2013 breach was unrelated to the one Yahoo disclosed in December and that an investigation of the larger incident was continuing.


“We now know that Russian intelligence officers and state-sponsored hackers were responsible for highly complex and sophisticated attacks on Yahoo’s systems,” Mayer said on Wednesday.


The Senate Commerce Committee took the unusual step of subpoenaing Mayer to testify on Oct. 25 after a representative for Mayer declined multiple requests for her voluntarily testimony. A representative for Mayer told Reuters she was appearing voluntarily.
 









Thursday, October 12, 2017

Equifax Web-Page Goes Offline Amid Reports Of New Breach

Equifax has taken one of its web pages offline as its security team looks into reports of another potential cyber breach, the credit reporting company, which recently disclosed a hack that compromised the sensitive information of 145.5 million people, said on Thursday.






"We are aware of the situation identified on the equifax.com website in the credit report assistance link," Equifax spokesman Wyatt Jefferies said in an email.



"Our IT and security teams are looking into this matter, and out of an abundance of caution have temporarily taken this page offline."



As CBC reports, the move came after an independent security analyst on Wednesday found part of Equifax"s website was under the control of attackers trying to trick visitors into installing fraudulent Adobe Flash updates that could infect computers with malware, the technology news website Ars Technica reported.





When I clicked it (from Gmail on Android) I was redirected to a spam page shortly after seeing the Equifax credit file form.





I thought maybe it was an anomaly because it didn"t happen again. But after reading your article about how sometimes hacks will redirect randomly I tried the link again just now and sure enough I got a spam page again (lucksupply.club saying I won an iPhone X). This is Chrome-in-a-tab from Gmail so i don"t believe there"s any extensions or other malware on my device that could have caused this redirect.



EFX share price is tumbling...


Germany Says It Found "No Evidence" Kaspersky Helped Russia Spy On US

US intelligence agencies are claiming that the Russian government leveraged the popularity of Kaspersky Labs’ cybersecurity software to create what is tantamount to a global spy network with the company’s explicit cooperation. However, Germany’s intelligence agencies say they’ve found “no evidence” to suggest these reports are true.


The Wall Street Journal, which last week reported that the US had identified at least one case of Kaspersky’s software improperly copying classified information, is back with another “exclusive” spoon fed to it by anonymous “senior US officials” alleging that Kaspersky allowed Russian government malware to piggy back on its software. The malware scanned for and copied files labeled “top secret,” not just in the US, but globally. Though WSJ neglects to list other countries that are suspected victims of Russian hacking.



Meanwhile, Germany"s BSI federal cyber agency said on Wednesday it had found no evidence to suggest that Russian hackers had used Kaspersky’s software to spy on US authorities. "There are no plans to warn against the use of Kaspersky products since the BSI has no evidence for misconduct by the company or weaknesses in its software," BSI said in an emailed response to questions about the latest media reports. "The BSI has no indications at this time that the process occurred as described in the media," according to Reuters.


Germany"s BSI, which also uses Kaspersky products for technical analyses, said it was in touch with U.S. officials and other security agencies about the issue so it could take action and issue a warning on short notice if required.





The Russian government used a popular antivirus software to secretly scan computers around the world for classified U.S. government documents and top-secret information, modifying the program to turn it into an espionage tool, according to current and former U.S. officials with knowledge of the matter.



The software, made by the Moscow-based company Kaspersky Lab, routinely scans files of computers on which it is installed looking for viruses and other malicious software. But in an adjustment to its normal operations that the officials say could only have been made with the company’s knowledge, the program searched for terms as broad as “top secret,” which may be written on classified government documents, as well as the classified code names of U.S. government programs, these people said.



After becoming suspicious that the Kaspersky software might be concealing malicious spyware, US intelligence agencies began scrutinizing the software, searching for signs that it was unknowingly copying and transmitting sensitive information.





For many months, U.S. intelligence agencies studied the software and even set up controlled experiments to see if they could trigger Kaspersky’s software into believing it had found classified materials on a computer being monitored by U.S. spies, these people said. Those experiments persuaded officials that Kaspersky was being used to detect classified information.



Later, WSJ notes that, in fact, it was Israeli intelligence that first alerted the US to Kaspersky’s skullduggery, effectively creating a separate, parallel narrative to explain how the deception was exposed.


So, which is it? Did the Israelis tell us? Or did the US discover the breach independently in 2015?


In an ironic twist, Kaspersky exposed Israel for lying about the source of its information on Iran deal talks after WSJ reported two years ago that Israel had spied on negotiations. Israel had said it received its intelligence by other means, but it had in reality infiltrated Kaspersky’s software, a fact the company publicly acknowledged in a research paper published two years ago.





In a twist, Kaspersky appears to have known, or at least suspected, that it had been hacked by Israel. In June 2015, the company published a detailed technical analysis about malicious computer code used to break into its systems, which it dubbed Duqu 2.0. Experts believe that the original Duqu malware, on which the one inside Kaspersky’s system appears to have been based, was used to spy on officials participating in international negotiations over Iran’s nuclear program, a fact that Kaspersky acknowledged in its paper.



The Journal reported in 2015 that Israel had spied on closed-door talks among the U.S. and other world powers about curtailing Iran’s nuclear ambitions. Israeli officials denied spying directly on U.S. negotiators and said they received their information through other means, including close surveillance of Iranian leaders receiving the latest U.S. and European offers.



Which begs the question: Is it possible that Israel was the source of the Kaspersky hack? The country has been exposed for spying on the US before – and not just during the Iran negotiations. And it has also been exposed for infiltrating Kaspersky’s systems.


Keep in mind, suspicions about the infiltration first emerged two years ago at a time of heightened tension between the Obama administration and Israel. In an unprecedented move, the Department of Homeland Security ordered all federal agencies using Kaspersky’s software to uninstall it, effectively ending Kaspersky’s relationship with one of its largest clients.  
 

Friday, September 29, 2017

Airports Systems Just Crashed Globally; Could The Power Grid Be Next?

Authored by Mac Slavo via SHTFplan.com,


Airport computer systems crashed around the globe yesterday. The crash caused passenger delays, angst, and fright among travelers, but a more ominous question has arisen in light of this glitch. Could the next failure be a worldwide power grid outage?



Thousands of travelers were grounded yesterday when a computer glitch took down check-in systems at more than 100 airports worldwide. The crash left passengers waiting in long lines at counters while trying to check-in for their flights. T Amadeus Alta, the company that provides the software, confirmed it is experiencing a “network issue that is causing disruption,” The Telegraph reported.


The glitch affected even massive airports,  such London’s Heathrow International Airport, Charles de Gaulle Airport in Paris, and Ronald Reagan International Airport in Washington, D.C. “Technical teams are working on the problem, services are gradually being restored,” the software company said. After a few hours, officials at Gatwick and Heathrow airports said their systems were “back up and running” after the “momentary IT glitch,” adding there may be a delay due to the outage.





A statement on the glitch read, “A small number of airlines are currently experiencing intermittent issues with their check-in systems at airports around the world — including at Heathrow.”



It continued, “Passengers will still be able to check-in for their flight, although the process may take slightly longer than usual.”



Passengers took to social media to complain about the crash.




According to Fox News, it is still unclear when all the systems will be back up and running, but it begs the question: what if a power grid failure is next?


It isn’t like it’s never happened, but it may only be a matter of time before it occurs on a massive scale.





In December of 2015, 230,000 people in Western Ukraine lost power after 30 substations were mysteriously shut off. Contrary to what most people assumed at the time, this wasn’t an innocuous power outage. The authorities would later admit that the loss of power was caused by a cyber attack, which marked the first time that malware was successfully used to attack a power grid. A similar, albeit more sophisticated cyber attack, occurred one year later just outside of Kiev. Given the current tensions between Russia and Ukraine, it’s widely believed that the Russian government was responsible for these incidents.



However, there’s more to this story than meets the eye. A computer security company has been investigating these attacks, and has discovered the malware that was used to take down the grid. They’ve found that it’s far more dangerous and easier to use than anyone realized before. –Ready Nutrition



It may not necessarily be malicious malware that takes down the grid either.  Even solar flares can cause some incredibly intense issues.





Most policy makers have not taken the threat of an earth-directed solar flare seriously, even though a senior member of the Congressional Homeland Security Committee recently warned that there is a 100% Chance of a Severe Geo-Magnetic Event Capable of Crippling Our Electric Grid.


If such an event were to happen Congressman Roscoe Bartlett, who has advised people to develop individual preparedness plans based on the threat of massive solar flares or electro-magnetic pulse detonations, says that it would take upwards of 18 months to bring the grid back online because of a decaying national infrastructure. –SHTFPlan



With the crash of the airport system affecting people worldwide, imagine how much chaos would ensue should the power grid go down over most of earth.

Wednesday, September 27, 2017

In Stunning Reversal, DHS Says Russians Were Not Behind Attempted Wisconsin Vote Hacking

Just in time for the weekend, the Associated Press reported on Friday that the Department of Homeland Security had notified 21 states earlier that day that their election systems had been targeted by malicious cyber actors. The states and DHS quickly jumped to the conclusion that Russia had ordered the cyberattacks, even though it was reported that the identity or identities of the perpetrators were inconclusive Yet, the news spread like wildfire after readers had been primed as reports of possible infiltartion of state election systems had circulated for nearly a year. Even so, for many states, the call Friday from the Department of Homeland Security was the first official confirmation that their election systems had, in fact, been targeted by hackers.


Federal officials said that in most of the 21 states, the targeting was preparatory activity such as scanning computer systems.



But in a stunning reversal - one which we doubt will put endless rumors of Russian cyberinterference to bed - the AP now reports that DHS has told Wisconsin that the Russian government was not involved in the cyber-targeting.


In an email to the state’s deputy elections administrator that was provided to reporters at the Wisconsin Elections Commission meeting on Tuesday, Homeland Security said that initial notice of Russian involvement was made in error. Also, as we noted at the time, the government did not originally assign blame to the Russians when news of the alleged "scanning" initially broke on Friday although most medias jumped at the opportunity to blame Putin.


Infuriated by the error, some state officials said that DHS should provide an expalanation for the errror, or at least issue an apology to state elections officials, who were understandbly unnerved by the news of Russian involvement.





“Based on our external analysis, the WI IP address affected belongs to the WI Department of Workforce Development, not the Elections Commission,” said the email from Juan Figueroa, with Homeland Security’s Office of Infrastructure Protection.


It wasn’t immediately known if Homeland Security made similar mistakes with any of the other 20 states. Figueroa did not immediately reply to an email seeking an explanation of how the mistake was made.


Homeland Security initially told the Elections Commission that the Russians scanned the state’s internet-connected election infrastructure, likely seeking specific vulnerabilities to access voter registration databases.


“Either they were right on Friday and this is a cover up, or they were wrong on Friday and we deserve an apology,” Mark Thomsen, the commission’s chairman, said in light of the new email.



Wisconsin’s chief elections administrator Michael Haas told AP that Homeland Security had assured the state that it had not been targeted - by Russians, or anybody else, for that matter.





“Wisconsin was not provided any information that indicated before the November election that Russian government actors were targeting election systems,” Haas said. He said one theory is that Homeland Security saw suspicious activity from IP addresses targeting state election systems in other states and assumed that was the intent in Wisconsin as well.



Others were apparently in shock: “It’s been a difficult process trying to piece all of this together,” said Wisconsin Elections Commission spokesman Reid Magney. “We’re trying to understand what happened.”


Furthermore, Wisconsin’s chief information officer, David Cagigal, told the elections commission that Wisconsin had never been told by Homeland Security, prior to the Friday notice, that Russians had targeted Wisconsin’s election system or anything else. Deputy information officer, Herb Thompson, said Homeland Security told the state in October to check on a certain IP address that the state had blocked from accessing its systems in August 2016.





“We have never seen any of those activities result in anything other than someone trying to turn the doorknob to see if a door is open,” Thompson said. “Those IP addresses we talked about, we had blocked, they were related to non-election systems.” Cagigal said, “Our systems were protected and we had no incidences.”



Still, the state"s election commission has promised to improve security before the midterms next year. Reports that Russians may have targeted, or infiltrated, state voting systems have been circulating since late last year, when the Washington Post published a story about alleged Russian infiltration in Vermont, only to retract the story shortly after. 


While we doubt that this will be the last "Russia hacked the elections" fake news, it is reassuring that all this frenzied chaos will at least bring some security to America"s voting systems. Security enhancements being considered include encrypting the entire voter registration database to protect the information and make it unusable to anyone who may be able to steal it and requiring two-factor authentication for the roughly 3,000 local and state officials who have access to the WisVote system.


Perhaps an appropriate question is why this wasn"t done before?

Tuesday, September 26, 2017

Massive Hack At Deloitte: Entire Internal Email System Compromised, Client Emails Exposed

Another day, another major hacking.


The Guardian reports that in the latest corporate cyber breach, one of the world’s “big four” accounting and consultancy firms, Deloitte, was been targeted by a sophisticated hack that "compromised the confidential emails and plans of some of its blue-chip clients." And just like Equifax, New York-headquartered Deloitte was similarly the victim of a cybersecurity attack that went unnoticed for months. The Guardian understands Deloitte discovered the hack in March this year, but it is believed the attackers may have had access to its systems since October or November 2016.


Responding to questions from the Guardian, Deloitte confirmed it had been the victim of a hack but insisted only a small number of its clients had been “impacted”. It would not be drawn on how many of its clients had data made potentially vulnerable by the breach. Alas, the company has yet to provide a full disclosure of just who and which clients were violated: an estimated 5 million emails were in the hacked email cloud and could have been been accessed by the hackers. Deloitte said the number of emails that were at risk was a fraction of this number but declined to elaborate.


While unlike Equifax Deloite is not a public public company and is not accountable to countless shareholders, with $37 billion in revenue last year and over 263,000 worldwide employees, Deloitte is a corporate behemoth which provides auditing, tax consultancy and - like Equifax - high-end cybersecurity advice to some of the world’s biggest banks, multinational companies, media enterprises, pharmaceutical firms and government agencies.  Here the Guardian reports that Deloitte clients "across all of these sectors had material in the company email system that was breached. The companies include household names as well as US government departments."





So far, six of Deloitte’s clients have been told their information was “impacted” by the hack. Deloitte’s internal review into the incident is ongoing.



The hacker compromised the firm’s global email server through an “administrator’s account” that, in theory, gave them privileged, unrestricted “access to all areas”.



Embarrassingly, the administrator level hack required only a single password and did not have “two-step“ verification, much like Deloitte and other companies strongly urge everyone to do.


As the Krebs on Security blog separately notes, "according to a source close to the investigation, the breach dates back to at least the fall of 2016, and involves the compromise of all administrator accounts at the company as well as Deloitte’s entire internal email system"





The source told KrebsOnSecurity they were coming forward with information about the breach because, “I think it’s unfortunate how we have handled this and swept it under the rug. It wasn’t a small amount of emails like reported. They accessed the entire email database and all admin accounts. But we never notified our advisory clients or our cyber intel clients.



This same source said forensic investigators identified several gigabytes of data being exfiltrated to a server in the United Kingdom. The source further said the hackers had free reign in the network for “a long time” and that the company still does not know exactly how much total data was taken.



Penetrating the unknown number of emails involved breaching the Microsoft cloud used the by the company. Emails to and from Deloitte’s 244,000 staff were stored in the Azure cloud service, which was provided by Microsoft. This is Microsoft’s equivalent to Amazon Web Service and Google’s Cloud Platform.


In addition to emails, the Guardian adds the hackers had "potential access to usernames, passwords, IP addresses, architectural diagrams for businesses and health information. Some emails had attachments with sensitive security and design details."


Until today"s report, the hack had been disclosed to the public: the breach, which was US-focused, was regarded as so sensitive that only a handful of Deloitte’s most senior partners and lawyers were informed.





The team investigating the hack is understood to have been working out of the firm’s offices in Rosslyn, Virginia, where analysts have been reviewing potentially compromised documents for six months.



It has yet to establish whether a lone wolf, business rivals or state-sponsored hackers were responsible.



Translation: while Putin wasn"t accused of hacking Equifax, he may yet get the blame this time.


Making this breach even more complicated, it is still unknown what information the hackers acquired: Guardian sources said if the hackers had been unable to cover their tracks, it should be possible to see where they went and what they compromised by regenerating their queries. This kind of reverse-engineering is not foolproof, however.





“In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,” a spokesman said. “As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.



“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers. We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required."



“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”



Deloitte declined to say which government authorities and regulators it had informed, or when, or whether it had contacted law enforcement agencies.


Of course, as noted above, the breach is a deep embarrassment for Deloitte, which offers clients advice on how to manage the risks posed by sophisticated cybersecurity attacks. If only the company had followed its own advice.  Even more awkward, in 2012 Deloitte was ranked the best cybersecurity consultant in the world and has a “CyberIntelligence Centre” to provide clients with “round-the-clock business focussed operational security." It is unclear if that unit was also hacked.


While we await an official statement from Deloitte, what comes next is lots of lawsuits and even more settlements. According to the Guardian, on 27 April Deloitte hired US law firm Hogan Lovells on “special assignment” to review what it called “a possible cybersecurity incident”. The Washington-based firm has been retained to provide “legal advice and assistance to Deloitte LLP, the Deloitte Central Entities and other Deloitte Entities” about the potential fallout from the hack.

Thursday, September 21, 2017

Equifax Accidentally Directs 200,000 Customers To Fake Phishing Website

And the hits just keep coming for Equifax, the once-trusted credit-monitoring firm that has been embroiled in one of the biggest corporate public-relations disasters in recent memory since disclosing that hackers had penetrated its cyber security defenses and absconded with sensitive personal and financial data belonging to 143 million Americans. Because of the types of data that were stolen, including drivers" license, social security and credit-card numbers, experts have described the hack as possibly the most damaging corporate hack yet.


As if this weren’t enough to permanently sully the firm’s reputation (amid cries of “you had one job!”) – the staggering irony of a credit monitoring firm inadvertently divulging the sensitive information that it was supposed to safeguard hasn’t been lost on consumers) a series of subsequent disclosures have portrayed the firm’s executives as bungling, at best, and nefarious, at worst.


In the nearly two weeks since the story broke…





  • It was revealed that three of the firm’s executives, including its CFO, cashed out of stocks and options worth some $2 million in the month between when the company first learned about the hack, and when it was disclosed to the public. A federal prosecutor in Atlanta has opened a criminal investigation into Equifax that will focus both on whether the firm was criminally negligent in failing to patch a hole in its cybersecurity systems, as well as whether the suspect stock sales constitute securities fraud.

  • The company’s head of cyber security was revealed to have no background in computer science or security – a fact the company tried to hastily cover up by scrubbing her social-media profiles. Susan Mauldin, Equifax’s chief information security officer, has a bachelor’s degree in music composition and a master’s in fine arts from the University of Georgia.

  • Several Congressional committees have asked the company to turn over information relating to the hack as multiple investigations appear to be getting under way. The attorneys general of a handful of states, including Massachusetts and Rhode Island, have joined a probe into the company’s handling of the breach.

  • The company has been hit with dozens of lawsuits from consumers alleging fraud, abuse and negligence.

  • Equifax CEO Rick Smith has been called to testify before a special House panel early next month.


When Equifax first set up a website to allow consumers to check whether their information was compromised, it carried a waiver stating that by using the service consumers would forfeit the right to sue Equifax. The internet quickly exploded in outrage, and the company quickly clarified that the waiver didn’t apply to this hacking incident, which…sure. Now, The Verge, The New York Times and a handful of other media outlets are reporting that Equifax accidentally tweeted the link to an imposter website set up by a white-hat hacker hoping to expose gllaring errors that the firm had made in setting up its verification website. This happened not once, but three times. And in at least one instance, the tweet with the phony link was left up for a whole day.



Here’s The Verge:





“Today, Equifax ended up creating that exact situation on Twitter. In a tweet to a potential victim, the credit bureau linked to securityequifax2017.com, instead of equifaxsecurity2017.com. It was an easy mistake to make, but the result sent the user to a site with no connection to Equifax itself. Equifax deleted the tweet shortly after this article was published, but it remained live for nearly 24 hours.”



Luckily for consumers, the fake site wasn’t malicious. Instead, it was set up by developer Nick Sweeting to try and expose the glaring security vulnerabilities that the company had embedded in its recovery website, which it set up as a separate domain, rather than making it a subdomain of Equifax’s main website.





“Luckily, the alternate URL Equifax sent the victim to isn’t malicious. Full-stack developer Nick Sweeting set up the misspelled phishing site in order to expose vulnerabilities that existed in Equifax"s response page. “I made the site because Equifax made a huge mistake by using a domain that doesn"t have any trust attached to it [as opposed to hosting it on equifax.com],” Sweeting tells The Verge. “It makes it ridiculously easy for scammers to come in and build clones — they can buy up dozens of domains, and typo-squat to get people to type in their info.”



Sweeting says no data will leave his page and that he "removed any risk of leaking data via network requests by redirecting them back to the user"s own computer," so hopefully data entered on his site is relatively safe. Still, Equifax"s team linked out to his page. That isn"t reassuring.”



Prior to Equifax customer service sharing the imposter site, Sweeting says he emailed the company’s support team and tweeted to Equifax that he spotted a potential vulnerability. By the time the site was taken down, Sweeting says it had received more than 200,000 hits. In the spirit of transparency, Sweeting included a disclaimer on his site warning consumers that it was a fake – and blasting Equifax for its sloppy security practices.


According to the NYT, phishers cannot create a page on the equifax.com domain, so if the website were hosted there instead, it would be easy for users to tell that the page was legitimate.





“Fortunately for the people who clicked, Mr. Sweeting’s website was upfront about what it was. The layout was the same as the real version, complete with an identical prompt at the top: “To enroll in complimentary identity theft protection and credit file monitoring, click here.” But a headline in large text differed: “Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That’s So Easily Impersonated By Phishing Sites?”



The legitimate Equifax domain was securityequifax2017.com. Sweeting’s was equifaxsecurity2017.com. And as one cybersecurity expert told the NYT, even the legitimate website looks fake because it’s not a subdomain of the larger Equifax site.





“You would think that would be the obvious place to start,” said Rahul Telang, a professor of information systems at Carnegie Mellon University. “Create a subdomain so that if somebody tries to fake it, it becomes immediately obvious.”



The company’s actions, Telang told the NYT, suggest that it had never anticipated or planned for a breach.


This has become clear in the last few weeks. Now, the only thing left to be decided is whether the fact that the company was almost comically unprepared for a hack rises to the level of criminal negligence.

Monday, August 7, 2017

Where Snowden Failed, THIS Won't

By Chris at www.CapitalistExploits.at


When in 2013 Ed Snowden revealed to Joe Sixpack that his data was indeed being hacked and intercepted, not by crazy vodka swilling Ivan in Novgorod but by team America, there was the sort of surprise and outrage that comes with finding your 5-year old just wiped snot across your brand new leather sofa. A lot of yelling and screaming, limbs flailing, and a decent level of embarrassment for Johnny Snotnose, who in this instance was the NSA.


Less than 12 months later, all was forgotten. In the end nobody gave an isht.


In the ghettos of social media the Kardashians were calling and "Hey look, did you know there are pornos on the Internet with woman and farm animals?"


Joe Sixpack doesn"t care about the fact that his photos are accessible, even the naughty ones. Indeed almost every app downloaded today requests permission to breach that gap. Joe doesn"t care about his contacts list being breached. He clicks the "Sure, rape me" "Accept Permissions" button with glee, eager to get the download finished so that he can start sharing photos of what"s on his dinner plate with the whole world because... well, actually I have no idea.


It"s insane to me. Sadly the hoi-polloi spend more time looking at Joe"s dinner choice than reading the fine print on the permissions they"ve just granted to the apps downloaded.


You"d be forgiven for thinking that a goldfish-like memory could be to blame. I certainly thought people would care but obviously I was wrong because ever since then we"ve had more reasons to be outraged over real problems of this nature than you could shake a stick at.


Since Snowden, Wikileaks have provided an absolute deluge of additional fodder in this space. What"s happened?


Nothing! Nobody cares.


Just yesterday we were alerted to "Dumbo" a CIA project.



Try finding anything on the MSM about it and it"s like searching for a Texan cattle farmer at a vegan food festival.


Sure, we know the MSM are a complete joke but the masses still gather around the MSM drinking fountain for their daily dose of intellectual junk food. What did they have to say on the topic?


Instead of outrage and public humiliation showered on the perpetrators, we"re treated to snowflakes, daffodils, and bubble bath enthusiasts fighting the injustices perpetrated on Joey, who goes by the name Sheila due to his desire to don a frock and spend all his money rearranging his bits at the cosmetic surgeon.



There is, however, one thing that"s going to change it all...


Money.


Data security is like a seatbelt. It only matters when you park the beemer into a gum tree at speed.


People only protect data when that data is attached to economic value.


Ask anyone who"s bought, sold, and transacted in bitcoin what computer they use and not one will say a Windows machine.


The reasons for this are quite simple. That"d be like driving blindfolded at speed without a seatbelt, after chugging back a half a bottle of Glenfiddich.


This is just a first step in data security, and I use bitcoin as an example because typically the folks who have spent any time figuring it out know a thing or two about data security and cryptography.


Back to the masses, though.


Clearly when the wet-lipped psychopaths at some three letter agency are looking at Joe"s Facebook content or the naughty video he made last night with his girlfriend, Joe doesn"t much care. But when Joe begins storing real value and assets on his computer or smartphone and they get stolen, then, and only then, will Joe very quickly attach value to his data security. The learning curve promises to be steep.


That world is coming super fast as I mentioned previously.


Adoption of safety measures will come faster than Brangelina were picking up new ethnic babies from Nambabwia or wherever a few years back. When people realise that their livelihood is directly attached to their data security, then, and only then, will the begin to care.


I posted this chart previously in an article on the rise of cyber security:



Mark Andreessen famously stated that software is eating the world and by George, he was right. With all that software though comes a different set of problems. One of those problems, one even larger than John Prescott, is cyber security.


Now once again, I suspect Joe Sixpack won"t give an isht if someone can see that he"s turning on his heating system from his smartphone while on the way home. But when it gets disrupted and hacked and his phone automatically pays for a weekend at the Marriott in Bali without his knowledge, Joe will search for solutions in a blind panic.


When Joe begins getting paid via smart contracts and in value tokens attached to his workplace and it"s all done on a network, Joe will care a lot.


Economic incentives, both fear and greed, never change. What"s changing is our financial architecture and how we"re going to have to deal with that.


Fortunes will be made on the back of what promises to be an explosion in data security. Watch!


- Chris


"The great fear that I have is that nothing will change." — Edward Snowden


--------------------------------------


Liked this article? Then you"ll probably like my other missives on


this topic as well. Go here to access them (free, of course).


--------------------------------------

Monday, July 24, 2017

David Stockman Has Had Enough: "Brennan, Rice, Power - Lock Them All Up!"

Authored by David Stockman via LewRockwell.com,


We frequently hear people say they have nothing to hide - so surrendering privacy and constitutional rights to the Surveillance State may not be such a big deal if it helps catch a terrorist or two. But with each passing day in the RussiaGate drama we are learning that this superficial exoneration is dangerously beside the point.


We are referring here to the unrelenting witch hunt that has been unleashed by Imperial Washington against the legitimately elected President of the United States, Donald J. Trump. This campaign of lies, leaks and Russophobia is the handiwork of Obama’s top national security advisors, who blatantly misused Washington’s surveillance apparatus to discredit Trump and to effectively nullify America’s democratic process.


That is, constitutional protections and liberties were systematically breached, but not simply to intimidate, hush or lock up citizens one by one as per the standard totalitarian modus operandi. Instead, what has happened is that the entire public debate has been hijacked by the shadowy forces of the Deep State and their partisan and media collaborators.


The enabling culprits are Obama’s last CIA director, John Brennan, his national security advisor Susan Rice and UN Ambassador Samantha Power. There is now mounting evidence that it was they who illegally “unmasked” NSA intercepts from Trump Tower; they who confected the Russian meddling narrative from behind the protective moat of classified intelligence; and they who orchestrated a systematic campaign of leaks and phony intelligence reports during the presidential transition—-all designed to delegitimize Trump before he even took the oath of office.


So all three of them should be locked­up—-that’s for sure. But the more urgent solution would be to unlock and make public all the innuendo, surmises, assessments, half-truths and boilerplate intelligence chatter on which the entire false narrative about Russian meddling and collusion is based.


Stated differently, without the nation’s massive intelligence apparatus and absurd system of secrecy and classified information to hide behind, the RussiaGate witch hunt would have never gotten off the ground.


In truth, as we will essay below, there is no there, there. So what this new chapter in McCarthyite hysteria actually demonstrates is that the Imperial City’s far-flung, 17-agency, $75 billion Intelligence Behemoth is a plenary threat not just to individual liberty, but to the very constitutional democracy on which the latter depends.


To appreciate the severity of the threat, it is necessary to recognize that the post-9/11 Deep State has lowered a double whammy on our system. That is, it unconstitutionally collects the entirety of all internet based communications of America’s 325 million citizen, while at the same time it has effectively disenfranchised 98% of the 535 members of the House and Senate who have been elected to represent them.


Accordingly, behind the Surveillance State’s vast wall of secrecy and so-called “classified” information, there operates a Dark Government that is unaccountable to the public and largely unconstrained by normal constitutional limits, which the Patriot Act and secret FISA courts have more or less suspended.


In the realm of this Dark Government, the heart of American democracy—-the US Congress—has been completely usurped. Almost everything behind the secrecy wall is off limits to the rank and file. Only a handful of intelligence committee members and the House and Senate leadership gets sworn into the classified intelligence.


Yet just consider the hideous asymmetry of this arrangement. The so-called “Gang of Eight,” comprising the heads of the intelligence oversight committees and their respective party leadership, gets orally briefed in a secure “vault”, where they can’t take notes or carry-out any documents.


Moreover, this select handful of legislators consists of the incessantly mobilized and frazzled potentates of Capitol Hill who are always knee-deep in a thousand other distractions—-including a heavy quotient of politicking, fund-raising, and campaign trail excursions.


On the inside of the Surveillance State wall, by contrast, there are 600,000 employees or contractors with “top secret” security clearances alone; and more than 4 million total operatives who spend night and days feasting on the $75 billion Intelligence Community (IC) budget and carrying out projects and missions designed to justify their existence and keep the budgetary gravy train flowing.


For example, in the National Security Agency (NSA) there is a subsidiary entity called TAO (Targeted Access Operations) with a budget of several billions and more than 1,000 employees. The latter predominately consist of high-powered civilian and military hackers, computer geeks, intelligence analysts, targeting specialists, computer hardware and software designers and electrical engineers—-whose job it is to do exactly what Russia is being accused of.


Namely, to hack and electronically infiltrate the communications and operations of nearly every government on the planet, and most especially those of IC designated enemies and adversaries such as Russia and Iran.Indeed, TAOs motto says it all:





“Your data is our data, your equipment is our equipment ­ anytime, any place, by any legal means.”



In any given 24-hour day, the TAO hacks and deposits more disinformation and malware into its targeted foreign networks than all the low level Russian probes that were intercepted by NSA during the entire Presidential campaign.


In other words, Washington is the mother of all hackers and cyber-warfare operations, and what Russia and other nations do is only a small potatoes version of the same. Yet the overwhelming share of these digital cloak and dagger operation by all sides is a huge waste of national resources; and most especially it is of no value at all to the safety of the American people.


That because Russia, China and Iran—-the principal targets of the IC’s massive surveillance and cyber warfare activities—are no threats whatsoever to America’s security.


Iran has zero military capacity to attack the American homeland, and the claim that it is the leading sponsor of terrorism is pure bunkum. That hoary claim has been concocted by the Washington neocons and the Netanyahu political machine—both of which need demonized enemies in order to nurture the public fears on which their power is based.


Likewise, Russia has one 40-year old smoke-belching aircraft carry and a fleet of rowboats—–neither of which are capable of launching an assault on the New Jersey shores. True, it does have about 1,00o nuclear warheads; but where is the evidence that cool-hand Vlad is contemplating national suicide by using them against the US or Europe?


The purported Chinese threat is even more ludicrous. Notwithstanding the fertile imaginations of the Deep State fear-mongers who believe the South China Sea is actually an American Lake, the Red Suzerains of Beijing know fully well that without the continuous custom of Wal-Mart and Amazon warehouses, the Red Ponzi would collapse in a heartbeat. And that they would be hung by angry mobs from the CCTV (China Central Television) Tower shortly thereafter.


In fact, we don’t need the $75 billion Surveillance State to deal with the Taliban, the jihadist warlords of Somalia or any of the warring Sunni vs. Shiite (Houthis) parties of Yemen, either. They do not threaten America’s security in the slightest.


Nor did the government of Khadafy in Libya after he turned in his nukes. Likewise, the Assad regime has never, ever threatened to harm America—-despite the non-stop vilification from Washington.


At most, Washington needs modest local and theatre level capacity to monitor the fading remnants of the Islamic State—-a temporary scourge in the mostly the impoverished Sunni villages of the Upper Euphrates, which would not even exist in the first place had it not been fostered and armed with the weapons the US Army left behind in the fiasco of Iraq.


So consider the contrafactual. In the absence of a vast Warfare State apparatus and associated Surveillance State wall of secrecy what would RussiaGate amount to?


The answer is straight-forward: It was nothing more than a politically motivated plot orchestrated by former CIA director Brennan to undermine the Presidential campaign of a rambunctious outsider. That is, the Donald was unschooled in the groupthink of the Imperial City and had enough common sense to realize that Putin is not our enemy, that NATO is obsolete, that regime change has been a fiasco and that foreign policy should be based on homeland security first, not the perpetuation of an American Empire abroad.


Those inchoate impulses were the Donald’s original sin, and it was unverified and self-serving “intelligence” from the Latvian security service—-of all things—- that provided the pretext for Brennan to launch the Deep State’s own version of jihad against Trump.


What this dubious intelligence did was to finger Vlad Putin himself and that was crucial. It permitted Brennan to puff-up the evidence of run-of-the-mill cyber intrusions by the Russian security services—-or even unconnected Russian hackers and profiteers— into a sweeping but phony narrative about an attack on American democracy with Putin at the very center.


As Scott Ritter—- the weapons expert who blew the whistle on the IC’s trumped up claims about Saddam’s WMDs—-succinctly explained in a recent article, Brennan proceeded to turn a dubious molehill into a vertiable mountain:





According to reporting from the Washington Post, sometime during this period, CIA Director John Brennan gained access to a sensitive intelligence report from a foreign intelligence service. This service claimed to have technically penetrated the inner circle of Russian leadership to the extent that it could give voice to the words of Russian President Vladimir Putin as he articulated Russia’s objectives regarding the 2016 U.S. Presidential election — to defeat Hillary Clinton and help elect Donald Trump, her Republican opponent. This intelligence was briefed to President Barack Obama and a handful of his closest advisors in early August, with strict instructions that it not be further disseminated.



The explosive nature of this intelligence report, both in terms of its sourcing and content, served to drive the investigation of Russian meddling in the American electoral process by the U.S. intelligence community. The problem, however, was that it wasn’t the U.S. intelligence community, per se, undertaking this investigation, but rather (according to the Washington Post) a task force composed of “several dozen analysts from the CIA, NSA and FBI,” hand­picked by the CIA director and set up at the CIA Headquarters who “functioned as a sealed compartment, its work hidden from the rest of the intelligence community.”



The result was a closed­circle of analysts who operated in complete isolation from the rest of the U.S. intelligence community. The premise of their work — that Vladimir Putin personally directed Russian meddling in the U.S. Presidential election to tip the balance in favor of Donald Trump — was never questioned in any meaningful fashion, despite its sourcing to a single intelligence report from a foreign service.



President Obama ordered the U.S. intelligence community to undertake a comprehensive review of Russian electoral meddling. As a result, intelligence analysts began to reexamine old intelligence reports based upon the premise of Putin’s direct involvement, allowing a deeply disturbing picture to be created of a comprehensive Russian campaign to undermine the American electoral process.



Here’s the thing. Vlad didn’t do it. The only interference in the electoral process that he has been associated with is with respect to what Imperial Washington did next door while he was basking in glory at the Sochi Olympics in February 2014.


To wit, the violent coup on the streets of Kiev was organized by agents and organs of the US government; overthrew a constitutionally elected President who had decided to make an economic and security deal with Russia rather than Europe and NATO in keeping with Ukraine’s economic propinquity to the former and its 700- years of history as an integral part of Greater Russia; and which imposed a new government, hand-picked by the Obama State Department, which was dominated by Ukrainian nationalists and neo-Nazis who were demonstrably hostile to the Russian speaking populations of Crimea and the Donbas region of eastern Ukraine.


Stated differently, Imperial Washington is the world champion meddler in other peoples’ politics and elections.


Since the CIA sponsored coup against the Mosaddegh government in Iran in 1953, it has sponsored more than eighty incidents ranging from election bag money to military coups.


By contrast, the putative Russian attack on American democracy consists of three specific accusations—all of which are readily refutable.





In the first place, Podesta’s password was “password” and could have been hacked by any fat guy, or not, on any computer plugged into the worldwide web anywhere.



Moreover, Julian Assange of Wikileaks, who makes a living disclosing the truth, not propagating lies as does the IC, says it did not come from Russian state agents; and that it was in fact leaked, not hacked, by disgruntled Democrat insiders.



In any event, if it had actually been hacked by either Russian agents or the proverbial fat guy, there would be a digital imprint stored in NSA’s vast server farms. The fact that it hasn’t leaked amidst all the rest of the anti-Russian innuendo and intelligence hearsay proves beyond much doubt that no such record exists and no such Russian intrusion ever happened.



As for the DNC emails, the smoking gun there still smolders in plain sight. The FBI apparently never even took custody of the DNC computer—–farming out the job to an outfit named Crowdstrike. Alas, the latter is a DNC contractor and wannabe silicon valley IPO run by some fanatical Russian ex-pats looking for fame and fortune. It’s no wonder they didn’t want the FBI second guessing their conclusions.



Finally, there is the Latvian “intelligence” morsel about Putin’s personal direction of the election meddling campaign. If the Donald had any common sense he would declassify said report forthwith.



But never mind. It surely doesn’t exist anyway—-or it too would have leaked long ago.



And that’s all she wrote. The rest is pure spin leaked by Trump’s enemies in the Deep State and canonized by its collaborators in the main stream media.


Unfortunately, the Donald doesn’t seem to recognize that he is actually President. If he did, he would have the Justice Department launch a prosecution against the faithless officials—-Brennan, Rice and Power—-who concocted the whole RussiaGate defamation in the first place.

Friday, July 21, 2017

Leaked Obama Plan To Fight Election-Day Meddling Included 'Martial Law'

Former US President Barack Obama has been criticized by both Republicans and fellow Democrats for withholding information about Russia’s alleged interference in the US presidential election – criticism that has only intensified since President Donald Trump triumphed over Democrat Hillary Clinton in the November election.


Now, in yet another troubling sign that the Obama administration believed outside hacking groups posed a significant threat to the election, Time magazine reports that his administration had devised a detailed plan to fend off any cyberattaks that sought to falsify vote totals during the election. Obama has been criticized for not informing the American people about hacking attemps allegedly carried out by Russia-linked groups for fear of “rocking the boat” and damaging Clinton’s chances of victory.



Obama and former National Security Adviser Susan Rice


The 15-page plan, a copy of which was obtained by Time, stipulates that “in almost all potential cases of malicious cyber activity impacting election infrastructure, state, local, tribal, and territorial governments,” the governments would have primary jurisdiction to respond.


And if an attack were launched, the White House had several “enhanced procedures” it had prepared to fight back against the attackers.



The document “establishes the federal response plan for a cyber incident that is (or a group of related cyber incidents that together are) likely to result in demonstrable impact to election infrastructure during the 2016 United States presidential election. Furthermore, Obama"s plan appears to include contongencies for martial law...





"Though the plan emphasized the vital role that local authorities would play in combating the hackers, clarifying that they would have primary jurisdiction during an attack, it noted that for the deployment of “armed federal law enforcement agents” who would be deployed to polling places if hackers managed to halt voting.



It also foresaw the deployment of “Active and Reserve" military forces and members of the National Guard “upon a request from a federal agency and the direction of the Secretary of Defense or the President.”



The plan also authorized the creation of the federal “Cyber Response Group,’ which has the authority to form a Cyber Unified Coordination Group to coordinate these activities


The Department of Homeland Security established a committee to coordinate a response to any attempted election hacking. The group includes seven additional agencies on top of the FBI. They are:


  • DHS, National Protection and Programs Directorate.

  • National Association of Secretaries of State

  • State nad Local Election Officials

  • US Election Assistance Commission

  • National Institute of Standards and Technology

  • Department of Justice

  • The FBI

  • Department of Defense Federal Voting Assistance Program

Even though Obama had no intention of sharing this information with the public, the report ironically included a subsection outlining the administration’s policy for disclosing information about cyberattacks to the public. In anticipation of an attack, the group would develop integrated public relations guidance that seeks to maintain election infrastructure. The public relations guidance developed by those agencies will be fully coordinated before Nov. 1 2016, with the NSC to ensure that appropriate spokesperson re identified, remarks are fully consistent and joint messages are used in any potential cyber incident.”


On election day, the group set up a national monitoring center at FBI headquarters. The command center, which operated between 6 am and midnight, served as the launchpad for any counterattacks.


By Election Day, with widespread coverage of Russian hacking and then-candidate Donald Trump’s assertions that the vote would be rigged against him, Gallup found that only 30% of Americans had faith in the honesty of elections, while 69% did not.


Since news first broke that Russian-backed hackers had tried to infiltrate voting systems in 21 states, several notable Democrats – House intelligence Committee ranking member Adam Schiff among them - have criticized Obama’s unwillingness to disclose the information to the public.


First it was Susan Rice illegally ‘unmasking” Trump associates to try and create some illusory heft behind the allegations that the Trump campaign colluded with Russia to tilt the election in Trump’s favor. Then the public was informed about former Attorney General Loretta Lynch’s meeting with former President Bill Clinton and an investigation was launched. Today, Deputy AG Rod Rosenstein suggested that former FBI Director James Comey’s decision to leak his memo about a meeting between himself and President Trump - the one in which the president appeared to lean on his top cop to drop the bureau’s investigation into former National Security Advisor Mike Flynn - was improper.


This, combined with Special Counsel Robert Mueller’s announcement that he’s examining Trump’s finances as the next step in his investigation into allegations of collusion between the Trump campaign and the Russians, begs the question: When will Congress and the FBI switch gears and investigate the DNC?


Read the report in full below:


354227068 Russia Hacking President Obama s Previously Undisclosed Election Day Plan by zerohedge on Scribd



 

Friday, July 14, 2017

Visualizing The Dark Side Of The Web

The term Dark Web is evocative. It conjures up images of hitmen, illegal drugs, and pedophilia. One imagines a place where the dark side of human nature flourishes away from the eyes – and laws – of society at large.


Today’s infographic, from Cartwright King Solicitors, cuts through the mystique and provides an entertaining and practical overview of the Deep Web and the Dark Web.






Courtesy of: Visual Capitalist



LAYERS (PART 1)


Much like the ocean, the internet is divided into defined layers.


The internet most people are familiar with is called the Surface Web. Websites in this layer tend to be indexed by search engines and can be easily accessed using standard browsers. Believe it or not, this familiar part of the web only comprises less than 10% of the total data on the internet.


The next layer down, we encounter the largest portion on the internet – the Deep Web. Basically, this is the layer of the internet that is quasi-accessible and not indexed by search engines. It contains medical records, government documents, and other, mostly innocuous information that is password protected, encrypted, or simply not hyperlinked. To reach beyond this layer of the internet, users need to use Tor or a similar technology.


LAYERS (PART 2)


Tor, which stands for “The Onion Router”, is how the majority of people anonymously access the Dark Web. Tor directs internet traffic through complex layers of relays to conceal a user’s location and identity (hence the onion analogy).



In 2004, Tor was released as an open source software. This allowed the Dark Web to grow as people could anonymously access websites.


Since anonymity is sacrosanct in the deep reaches of the Internet, transactions are typically conducted using cryptocurrencies like Bitcoin or Ethereum. People making purchases in Dark Web markets are (understandably) concerned with privacy, so they often use a series of methods to transfer funds. Below is a common transaction flow on the Dark Web.



Tumblers are used as an extra step to ensure privacy. A conventional equivalent would be moving funds through banks located in countries with strict bank-secrecy laws (e.g. Cayman Islands, Panama).


WHAT’S GOING ON DOWN THERE?


The concept of the Dark Web isn’t vastly different from the Surface Web. There are message boards (e.g. 8chan, nntpchan), places you can buy things (e.g. Alphabay, Hansa), and blogs (e.g. OnionNews, Deep Web Radio). The rules, or rather a lack thereof, is what makes the Dark Web unique.


Anything that is illegal to sell (or discuss) on the Surface Web is available in the Dark Web. Personal information, drugs, weapons, malware, DDoS attackshacking services, fake accounts for social media, and contract killing services are all available for sale.


The Dark Web is full of criminal activity, but it’s also place where dissidents and whistle-blowers can anonymously share information. In countries with restrictive internet surveillance, the Dark Web may be the only place to safely voice criticisms against government and other powerful entities.


MEASURING IN THE DARK


Many .onion sites are only up temporarily, so determining the true size of the Dark Web is nearly impossible. That said, Intelliagg and Darksum recently attempted to map out the Tor-based Dark Web by using a script to crawl reachable sites. They found 29,532 websites; however, 54% of them disappeared during the course of their research. Another recent study found that 87% of Dark Web sites don’t link to any other sites.





It is more accurate to view the darkweb as a set of largely isolated dark silos.


– Graph Theoretic Properties of the Dark-web



Recent changes to Tor, such as 50-character hidden service URLs, have made the Dark Web an even more untraceable place, so we may never fully know what lies beneath the surface of the internet. Based on the parts we have seen, perhaps that’s for the best.