Showing posts with label Steve Kroft. Show all posts
Showing posts with label Steve Kroft. Show all posts

Wednesday, June 28, 2017

NSA Partly Responsible For Latest Cyber Attack? OF Course!

"The N.S.A. Needs to take a leadership role....to address the plague that they've unleashed." - NY Times, today

Simpletons often see a temporary divergence from endorsing an agency, Bureau or person as a "contradiction" which probably harkens back to the old saw "a foolish consistency is the hobgoblin of little minds". So because I may have endorsed the NSA as part of the intel community that has exposed Russian hacking in the 2016 election, some may wonder why I'd now want to "attack" the NSA. But this is more in the way of a citizen's "pull yourself up!" mandate than attack.

I am referring, of course, to how the agency enabled and allowed a nasty worm to get loose some five years ago which has since been repurposed by "bad guys"  to attack our nation and others.  The guise is under a "ransomware" mode when the net user's computer turns into a 'brick'  unless he or she coughs up 300 Bitcoin bucks. So yeah, the NSA now bears responsibility - at least partial - for yesterday's global "Petya" attack, as it did last month's "Wannacry" attack. The most recent has one-upped the Wannacry attack in that no "kill switch" has yet been found."


Most would probably not recall the 60 Minutes episode from March 4, 2012, which sheds light on the current attacks.

In that episode, Gen. Michael Hayden (formerly of the NSA) was heard to say:

"We have entered into a new phase of conflict in which we use a cyberweapon to create physical destruction, and in this case, physical destruction in someone else's critical infrastructure. This was a good idea, alright? But I also admit this was a really big idea too. The rest of the world is looking at this and saying, 'Clearly someone has legitimated this kind of activity as acceptable international conduct.' The whole world is watching."

Following on, there appeared Sean McGurk - former head of cyber defense at The Department of Homeland Security, in charge of protecting critical infrastructure in the U.S. - who addressed Hayden's more or less glib patter:

"You can download the actual source code of Stuxnet now and you can repurpose it and repackage it and then, you know, point it back towards wherever it came from."

CBS' Steve Kroft then remarked: "Sounds a little bit like Pandora's box." To which McGurk responded, "Yes!"

McGurk added:

"They opened up the box. They demonstrated the capability. They showed the ability and the desire to do so. And it's not something that can be put back."

Kroft then pressed the issue, asking:

"If somebody in the government had come to you and said, "Look, we're thinking about doing this. What do you think?" What would you have told them?"

To which McGurk didn't hesitate in responding:

"I would have strongly cautioned them against it because of the unintended consequences of releasing such a code."

Kroft then surmised that one such "unintended consequence" is that this same code might be "re-purposed" and used against us. Perhaps against nuclear power plants or the power grid. Again, McGurk responded:"Yes", labeling the possible retributive cyber attack worm, "Son of Stuxnet".

But this was no laughing matter, certainly not five years ago and not now after obvious repurposed cyber attacks using NSA "exploits" have transpired.  As I noted in a post from 5 years ago:

"Because of the hubristic, belligerent and arrogant actions of an enclave of pointy-headed computer geeks at the Puzzle Palace, we're likely all in jeopardy (as we were with the Wall St. quants with the financial meltdown). These sort of reckless actions do not bode well, and although their creators and the guilty agency might argue they were done with the "best intentions" , i.e. to slow down Iranian processing of nuclear fuel, we know the road to Hell is paved with them."

In the case of Stuxnet, its malicious trail commenced in June of 2010, when it was first detected and isolated by a tiny company in Belarus after one of its clients in Iran complained about a software glitch. Subsequently, reports filtered in that Iran's centrifuges were somehow compromised, though they didn't let on that they were aware of the real culprits which I suspected at the time was the NSA, whose cryptological-computer-savvy 'fingerprints' were all over it.

Barely a month later, the FLAME virus was unleashed wreaking some havoc but not as much as Petya did yesterday with its ransomware attack.

An AP Report ('Digital Virus has Nations on Alert') noted at the time:

"Unlike a bullet or a missile fired at an enemy, a cyberweapon that spreads across the internet might circle back to infect computers it was never supposed to target. It's one of the unusual challenges facing the programmers who build such weapons."

According to the same AP report, Russian digital security provider Kaspersky Lab - which first identified the virus - stated that Flame's complexity and functionality 'exceeded those of all other cyber menaces know to date'"

Those words were enough to convince me that, like the Stuxnet worm, FLAME is a creature of the geeks at NSA.  Thus the AP report's ending "Yet FLAME's author remains unknown because there is no information in the code of the virus that would link it to a particular country" merely confirmed its place and source of origin.

In yesterday's manifestation of the latest virus reincarnation (as the 'Petya' ransomware), the origin appeared to be in the Ukraine, where officials reported the country's power grid as well as banks and government offices were affected.    Subsequently, Russia's Rosneft oil company also reported falling victim - but avoided major damage owing to a quick response - as did Danish shipping giant A.P. Moller-Maersk.  According to Anders Rosendahl, a spokesman for the shipping group:

"We're talking about a cyber attack. It has affected all branches of our business, at home and abroad."

The cyber attack rapidly snowballed into a world wide crisis, which also affected U.S. companies, as well as a hospital in Pennsylvania where surgeries had to be cancelled because the computers were down.

The worst aspect of this latest attack? It was "self spreading". That is, it possessed the capability to spread across networks without any human interactions. Such self-propagating software is called by the name "worms" because of the similarity to the way worm infestation diseases spread.  This is exactly the character of the original Stuxnet.

Let's bear in mind in the wake of the recent attacks that both Wannacry and Petya have managed to spread rapidly using break in tools originally created by the National Security Agency. Also, these tools were recently released to the Web. So yes, the NSA bears more than a little responsibility to try to get the cyber plague "evil genie" back into the "bottle."

Some bottle. Any bottle.  And then, think - really hard  and long - before unleashing the next cyber weapon that could boomerang back on the rest of us.



Tuesday, August 26, 2014

Are The Data Brokers Profiling You As A Perv or Psycho?

"Corey MacDuff"  has a full list displayed concerning his sex entertainment choices at ExactData - a Chicago data broker.  These include:

- His purchase of two sex toys in  June of 2013:  one dildo and one artificial vagina

- His purchase of three DVDs, one involving spanking by women, and two others - one of women dildoing each other, the other dildoing males.

- His online (pornhub) movie selections all to do with females lactating on each other.

- His purchase of two thongs, one pair of ankle and wrist restraints and one whip from a "Discipline" Emporium


"Corey" might not be overly shocked that the universe of his sexual predilections has been captured by purchase data, but would he be as blasé if he knew this list was being SOLD to any would be purchaser in the constellation of corporations? Would he be at all upset if he knew a prospective employer wanted to buy it?  Does that put a different light on the privacy issue - or is he also likely to blink and yawn and spout 'Whatever...' ? What if one of the buyers is the FBI or the NSA? Does that put a new light on it?

This sordid national underbelly of personal data collection, storage and selling was brought to light in the disturbing '60 Minutes' first segment about Data Brokers on Sunday night. Steve Kroft, host for the segment, went inside the sordid universe of the miscreants who - because of lax government laws (there are no comparable loose laws in Europe)- allows the vast collection and storage of terabytes of raw, personal data each year.

The companies number in the thousands and do all their collecting in the name of "commerce".  As Kroft observed: "They're collecting, analyzing and packaging some of our most personal information and selling it as a commodity - to each other, to advertisers and even to the government- often without our direct knowledge. And most of it operates in the shadows with virtually no oversight".

Did you buy 12 guns - three Glock 9mms, 4 Bushmaster .223s and 5 AR-15s last year? The government likely knows all about them thanks to data brokers who even have their eyes scanning buyers at gun shows.

Kroft noted that companies have been tracking customers for years, collecting names and addresses, tracking credit card purchases and asking people to fill out "questionnaires" so that can send discount offerings and catalogs."

The problem is today, people are giving out more and more personal information online via Twitter, Facebook and blogs: our likes and dislikes, our closest friends, our bad habits, even our daily movements both on and off line.

According to Federal Trade Commissioner,  Julie Brill, we've "lost control of our most personal information.".

What has happened is that data brokers are now scooping up all this personal data online and compiling dossiers on each person - each with his or her name on file. Spooky? Damned right! As Brill told Kroft:

"All the information is about individuals. It is information that is identified to an individual or linked to an individual,"

She added that:

"I don't think people have any idea that this information is being collected and sold and that it is personally about them. And that the information is basically a profile of them."

Kroft explained that no one even knows how many companies are trafficking our data but  would include research firms, internet companies, advertisers and trade associations.  He put the spot light on several of them, including: epsilon, datalogix, Lotame, Transunion, and acxiom - which is the largest data broker.

Acxiom is a veritable marketing giant that brags it has, on average, 1500 pages of information on each of 200 million Americans. That is a total of 300 billion pages of information over all, and all for sale. But as Kroft points out, "it's much harder for Americans to get information on acxiom and, of course, the company declined a request for an interview. Clearly, they don't want to be highlighted on a top investigatory program that would broadcast their existence and activities to Americans.

Kroft went on:

"Acxiom is fairly vague on the methods it uses to collect information and who its customers are."

As one former ACLU rep noted, "It's not about what we know we're sharing. It's about what we don't know that's being collected and sold about us."

He added that he believed people would be astounded to learn the kind of information that's being gathered about them and that could end up in their profiles. This includes: religion, ethnicity, political affiliation, user names, income and family medical history - and that's just for openers.

The former ACLU rep (Tim Sparapani)  also reminded Kroft that right now one can buy a full list of medications - by malady - taken by any given individual.  The range of info also includes alcoholism,, depression, psychiatric problems,  history of genetic problems, cancer, heart disease....down to the most rare and unexpected maladies. Not to mention sexual orientation (obtained via what clubs the person is frequenting,  what bars or restaurants purchases are being made at, and what products are being purchased online).

Sparapani added that not only can the information be sold to a prospective employer, it actually is. Didn't get that cherished job you wanted? Could be that the employer knows you have a genetic condition that's untreatable and for which he doesn't wish to shell out benefits, pay medical costs, or he knows you're part of the LGBT community and doesn't want you part of his community.

No wonder data brokers have been flying under the radar for years,  preferring people know as little as possible about the industry and the information being collected and sold. (One big reason I've done this blog post.)

But the evidence is there, if you know where to look, which Kroft then demonstrated.  In the middle of the segment he was at his computer, going online, and brought up all sorts of companies peddling sensitive, personalized information..

For example, he displayed the web page of a Connecticut data broker called STATLISTICS which provides advertisers with lists of Gay and Lesbian adults.  The rates for the lists start at $125.

Then there was Response Solutions, which provides lists of all those suffering from bipolar disorder, with the rates starting at $205.00 per list.

Then there was Paramount Media which operates out of a building in Erie, PA. It offers lists of people with alcohol, sexual and gambling addictions and also people desperate to get out of debt. (A promising set of info for loan sharks?)

Meanwhile, a Chicago company, ExactData, brokers the names of all those who've had a sexually transmitted disease as well as lists of all those who have purchased adult material - which is compiled under 'PML Eroticia Masterfile'. The constellation of goodies offered up includes: adult toys purchased and type, books and magazines by title, DVDs and videotapes by title, as well as lesbian or gay offerings. In addition, the purchase of all "potency/virility/libido enhancing" substances, materials- and by date..

Tim Sparapani observed that "no one has ever looked into these lists. It's completely opaque."

Perhaps worse than the totally opaque data brokers are the ones that disguise themselves as 'family friendly' outfits who pose as offering help but are actually in the business of data brokerage. One of those Kroft showed was Take5 Solutions in Boca Raton, Fla. - which runs 17 websites including 'Good Parenting Today' and T5 HealthyLiving.com. People can share stories about their families and health but - according to Kroft: "What visitors don't realize is that Take5's real business is collecting and selling the data assembled from their assorted front websites.


Maybe it's time now someone looked into what these brokers are up to and started developing regulations (whoa what an idea!). In the meantime, people need to be mindful of the fact that every time they make a purchase or even passively enter the online world - they are constantly being tracked and monitored (as Kroft showed in the next segment - using a special software tool known as 'Disconnect' created by a former Google engineer.)

In the end segment, Kroft et al had gone online at the NY Times and observed the screen as more than a dozen third parties that the website had allowed in to observe all movements. They were all companies that place ads and also "measure people's behavior on the website."

Can these parasites be prevented from following you around and snooping on your every move?  NO, because as Kroft's techie observed: "They're inside your browser or your mobile device. Most computers and browsers all them in by default."

Is there an ultimate solution to all this snooping right now?  Yeah! Don't go online! In the meantime, one can hope our government wakes up to the need to protect citizens' privacy - but given how it allows NSA to run roughshod over it, don't hold your breath!