Showing posts with label Cyberattack threat. Show all posts
Showing posts with label Cyberattack threat. Show all posts

Friday, March 22, 2013

The Ugly Truth Behind Obama’s Cyber-War

Net Intrusion
by ALFREDO LOPEZ


Last week, a top U.S. government intelligence official named James Clapper warned Congress that the threat of somebody using the Internet to attack the United States is “even more pressing than an attack by global terrorist networks”. At about the same time, Keith Alexander, the head of the National Security Agency, announced that the government is forming 13 teams to conduct an international “cyber offensive” to pre-empt or answer “Internet attacks” on this country.

This, as they say, means war.

Clapper issued his melodramatic assessment during an appearance before the Senate Intelligence Committee. As Director of National Intelligence, he testified jointly with the heads of the CIA and FBI as part of their annual “Threat To the Nation” assessment report.

While undoubtedly important, these “threat assessment” appearances are usually a substitute for sleeping pills. The panel of Intelligence honchos parades out a list of “threats” ranked by a combination of potential harm and probability of attack. Since they began giving this report (shortly after 9/11), “Islamic fundamentalist terrorist networks” have consistently ranked number one. Hence the sleep-provoking predictability of it all.

But Clapper’s ranking of “cyber terrorism” as the number one threat would wake up Rip Van Winkle.

“Attacks, which might involve cyber and financial weapons, can be deniable and unattributable,” he intoned. “Destruction can be invisible, latent and progressive.” After probably provoking a skipped heartbeat in a Senator or two, he added that he didn’t think any major attack of this type was imminent or even feasible at this point.

So why use such “end of the world” rhetoric to make a unfeasible threat number one?

The answer perhaps was to be found in the House of Representatives where, on that same day, Gen. Alexander was testifying before the Armed Services Committee about, you got it, “cyber-war”.

Besides being head of the NSA, Alexander directs the United States Cyber Command. I’m not joking. Since 2010, the United States military has had a “Cyber Command”, comprised of a large network of “teams” some of whose purpose is to plan and implement what he called “an offensive strategy”.

Up to now, the Obama Adminstration’s stated policy has been to prioritize protection and defense of its own Internet and data systems and, unsurprisingly, those of U.S. corporations. Now we realize that the President has been cooking another dish on the back burner. When these military leaders talk about “offensive strategy”, they mean war and in warfare, the rules change and warriors see democracy as a stumbling block at least and a potential threat at worst.
Is there a “cyber threat”? Sure, just like there’s a “personal security threat” at your front door. You live among other humans and a few of them sometimes rob people. The Internet is a neighborhood of two billion people in constant communication. To do what it was developed to do, it has to be an open, world-wide communications system and so people can exploit that by harming your website or stealing your data if you don’t protect these things adequately. Developing protections is part of what technologists in every setting, including government services, do every day and they do it well, minimizing the incidence of an on-line hack.

That’s contemporary society. You lock the door to your house, turn on your car alarm on and protect your computer’s data. Most of the time it’s unnecessary but you do it for those rare occasions that it might be called for.

You do not, however, break into a thief’s home, kill him or her and wipe out everyone in the house. That’s what President Obama is proposing. No longer is this Administration interested in just “protection of data”; it now plans to pre-emptively attack data operations and Internet systems in other countries. The non-euphemistic term for this kind of “offensive strategy” is hacking and hacking takes two forms: data theft and disruption of service. In other words, the government plans to do what it throws people in jail for doing.

Clearly, this isn’t only about data theft or service disruption. It’s entwined with the political conflicts Washington has with other countries like China and Iran. The Internet is now another battlefield and this offensive strategy gives our government another weapon in its ceaseless war on the world.

While this weapon might sound benign, almost game-like, compared to other military adventures, it is actually a vicious and punishing strategy promising a festival of unavoidable collateral damage.

A “cyber offensive” can target just about anything in a country (like the computers running an Iranian power plant) and, depending on how the Internet systems are inter-connected, almost automatically cut service to people, schools, hospitals, security services and governments themselves. This is the digital version of nuclear warfare, horrific for its impact and its fundamental immorality.

When the announcements were made, the mainstream media flew into a frenzy of evaluation and analysis. Is this cyber threat real, commentators asked? Most of them found that, at this point, it isn’t. But that’s not the point and it isn’t the real threat.

The carefully planned and coordinated Clapper/Alexander testimony provides a pretext for the array of repressive Internet-governing laws, strategies and programs the Administration already has in place. Their purpose is a ratcheting control of the Internet by the government, a redefinition of our constitutional rights and the eviscerating of our, and the world’s, freedoms. Now, with this “cyber war” scenario, these measures can be more easily defended and made permanent.

We can group those laws and programs into three categories.

1 - ”Extreme Data Collection”

The Obama Administration is building a huge data center in Bluffdale, Utah whose role is to capture and store all data everyone in this country (and most of the world) transmits. You read that right.

“Flowing through its servers and routers and stored in near-bottomless databases will be all forms of communication,” wrote James Bamford in Wired Magazine, “including the complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails — parking receipts, travel itineraries, bookstore purchases, and other digital ‘pocket litter.’”

While having your entire on-line life tracked and stored in Utah is pretty creepy, the more pressing issue is how government officials plan to use this data and how they are collecting it. To mine its value, they need to order it to make searches, filtering and lists possible. You need a strategy and while Obama officials have been pretty open about what they’re building, they are closed-mouth about what they intend to do with it.

We know they are working hard on developing code-breaking technology which would allow them to read data which is super-encrypted, the last wall of privacy and protection we have. We also know that, to get this data, they have a remarkable system of surveillance that includes direct capture (capturing data from your on-line sessions), satellite surveillance and the tapping (through easily available data captures) of major information gatherers like Google and Yahoo. The fact that they plan to open this center in September, 2013 means that the intense surveillance and data gathering is in place. You are now never alone.

This is the kind of information on “the enemy” they need in a cyber-war but this information is about us and so the question pertains: who is the enemy here?

2 - “Internet Usage Restriction”

If you’re conducting a war, you can’t have people running around the battlefield trading information and distributing it because, after all, you need secrecy. But collecting and distributing information is entirely what the Internet is about.

No reasonable person expects the entire shut-down of the Internet but the curtailment of on-line expression is now happening and getting worse, re-defining the meaning of free speech and making it an embattled concept.

Under the law, for instance, any corporation or individual can claim you are violating their copyright and demand you remove offending material from a website. You can challenge and litigate that but it doesn’t really matter because, under the Digital Millenium Copyright Act your web hosting service faces huge penalties if they keep the site on-line and the copyright violation is proven. So, to avoid the legal fees and the risk, they’ll just wipe your website. This happens all the time.

If the hosting service stands strong — as some progressive providers do — the people claiming the violation will just go “upstream” to the company that provides your web hosting service’s connection to the Internet and, to avoid legal problems, that “upstream provider” will just unplug the server. Servers host many websites, sometimes in the hundreds, and other services and so not only do you lose your site but everyone else on the server has theirs taken off-line. And this happens without even going in front of a judge.

Sure, there is still robustly exercised “freedom of speech” on the Internet. But the laws are in place to curtail it and, if the government wants, it can (and will) curtail. It’s a modern-day version of benevolent dictatorship which can, as history demonstrates, become pretty darn malevolent pretty fast.

3 — “Selective Repression”

There are hundreds of criminal cases against Internet activists world-wide right now and scores in the United States. The ones most of us are most familiar with, those involving Aaron Swartz and Bradley Manning, are only the tip of the frightening iceberg.

A day after the testimony before Congress, for example, federal authorities announced the case of a techie named Matthew Keys . Keys, who worked for a tv station in Los Angeles owned by the Tribune Company, is accused of leaking a username and password to an activist from the well-known hacker organization Anonymous. Authorities say the Anonymous activist used that user/password combo to satirically alter a headline on the website of the Tribune-owned Los Angeles Times.

Keys is now charged with conspiracy to transmit information to damage a protected computer; transmitting information to damage a protected computer and attempted transmission of information to damage a protected computer. Each count carries a 10 year jail sentence, three years of supervised release and a fine of $250,000. For giving someone who changed a headline a username and password!

Last year, we at May First/People Link were raided by the FBI which literally stole a server from one of our server installations in New York City. They were investigating terroristic emails from some lunatic to people at the University of Pittsburgh and the dozens of servers this bozo used included one of ours. We have some anonymous servers which means there are no records of who used them, no traces…no information about the person sending the email; it’s to protect whistle-blowers and others needing total anonymity.

The FBI knew this but they stole the server anyway and then, about a week later, put it back. They never informed us of any of this. We found out because one of our techies went into the server installation and found one of the servers gone and installed a hidden camera which caught the agents when they returned the machine.

If all these developments seem disturbing to you, that’s justified. These repressive and intrustive measures target the very essence and purpose of the Internet. Created as a way for people to communicate with each other world-wide, this marvel of human interaction is now being turned into a field across which countries shoot programming bombs at each other while repressing and even punishing ordinary people’s communication: dividing us, perpetuating the feeling of loneliness that’s a constant in today’s societies and crippling the struggles for change that combat the division and loneliness and depend on the Internet to do it.

The Internet’s true purpose is to bring the world’s people closer to each other. The Obama Administration is doing just the opposite. It would advisable for those of us who have consistently opposed and fought against wars of all kinds to view this “cyber war” as an equally dangerous and destructive threat.

Tuesday, September 27, 2011

The 'Worm' That Could Bring Down The Internet

(Thanks to Jason On for the share--jef)

Terry Gross - Fresh Air from WHYY
NPR - September 27, 2011


For the past three years, a highly encrypted computer worm called Conficker has been spreading rapidly around the world. As many as 12 million computers have been infected with the self-updating worm, a type of malware that can get inside computers and operate without their permission.

"What Conficker does is penetrate the core of the [operating system] of the computer and essentially turn over control of your computer to a remote controller," writer Mark Bowden tells Fresh Air's Terry Gross. "[That person] could then utilize all of these computers, including yours, that are connected. ... And you have effectively the largest, most powerful computer in the world."

The gigantic networked system created by the Conficker worm is what's known as a "botnet." The Conficker botnet is powerful enough to take over computer networks that control banking, telephones, security systems, air traffic control and even the Internet itself, says Bowden. His new book, Worm: The First Digital World War, details how Conficker was discovered, how it works, and the ongoing programming battle to bring down the Conficker worm, which he says could have widespread consequences if used nefariously.

See If You're Infected
 
Learn more about the symptoms of the Conficker worm and test to see whether your computer is infected at the Conficker Working Group website.

"If you were to launch with a botnet that has 10 million computers in it — launch a denial of service attack — you could launch a large enough attack that it would not just overwhelm the target of the attack, but the root servers of the Internet itself, and could crash the entire Internet," he says. "What frightens security folks, and increasingly government and Pentagon officials, is that a botnet of that size could also be used as a weapon."

When Russia launched its attack on Georgia in 2008, Russian officials also took down communication lines and the Internet within Georgia. Egypt also took down its own country's Internet service during the uprisings last spring.

"It's the equivalent of shutting down the train system during the Civil War, where the Union troops and the Confederate troops used trains to shuttle arms and ammunition and supplies all over their area of control," says Bowden. "And if you could shut their trains down, you cripple their ability to function. Similarly, you could do that today by taking down the Internet."
The Conficker worm can also be used to steal things like your passwords and codes for any accounts you use online. Officials in Ukraine recently arrested a group of people who were leasing a portion of the Conficker worm's computers to drain millions of dollars from bank accounts in the United States.

"It raises the question of whether creating or maintaining a botnet is a criminal activity, because if I break into a safe at the bank using a Black & Decker drill, is Black & Decker culpable for the way I use the tool?" he says. "That's one of the tools you could use the botnet for. With a botnet of 25,000 computers, you could break the security codes for Amazon.com, you could raid people's accounts, you could get Social Security numbers and data — there's almost no commercial security system in place that couldn't be breached by a supercomputer of tens of thousands."

After Conficker was discovered in 2008 at Stanford, it prompted computer security experts from around the world to get together to try to stop the bot. The volunteer group of experts, which called itself the Conficker Working Group, also tried to get the government involved with their efforts. But they soon discovered that the government didn't have a very good understanding of what the worm could do.

"[They] began reaching out to the NSA [National Security Agency] and [the Pentagon] to see if they would be willing to loan their computers [to help them], and what [they] discovered was that no one in the government understood what was happening," says Bowden. "There was a very low level of cyberintelligence, even at agencies that ought to have been very seriously involved, who were responsible for protecting the country, its electrical grid, its telecommunications. These agencies lacked the sophistication not only to deal with Conficker, but even to understand what Conficker was."

At some point in early 2009, the Conficker Working Group learned that the Conficker worm could wreak havoc on April 1, 2009 — a date when the computers infected by Conficker would receive instructions from their remote-controlled operator.

"The assumption was that if Conficker was to do anything, that would be the day that it would be destructive to the Internet," says Bowden. "But on April 1, nothing happened."


The Conficker Working Group realized that the creator of Conficker had little interest in taking down the Internet or using its bot to create mass destruction.

"The people behind it apparently want to use it for criminal reasons — to make money," says Bowden.

But that doesn't mean that Conficker is controlled, says Bowden. No one knows yet who controls the worm or what its intentions might be.

"At any moment, Conficker could do something really threatening," he says. "[People fighting the bot] are trying to figure it out still. And every new day, as the worm makes its contacts, they generate long lists of computers that are infected — which still include big networks within the FBI, within the Pentagon, within large corporations. So they monitor it and keep track of where it's spread, and they're still working with the government to secure vital computer networks from botnets like Conficker."

Saturday, July 16, 2011

Pentagon Declares the Internet a Domain of War

Thursday, July 14, 2011 by The Hill (Washington, DC)
by John T. Bennett

The Pentagon released a long-promised cybersecurity plan Thursday that declares the Internet a domain of war.

The plan notably does not spell out how the U.S. military would use the Web for offensive strikes.

The Defense Department’s first-ever plan for cyberspace calls on the DoD to expand its ability to thwart attacks from other nations and groups, beef up its cyber workforce and expand collaboration with the private sector.

Like major corporations and the rest of the federal government, the military “depends on cyberspace to function,” the DoD plan says. The U.S. military uses cyberspace for everything from carrying out military operations to sharing intelligence data internally to managing personnel.

“The department and the nation have vulnerabilities in cyberspace,” the document states. “Our reliance on cyberspace stands in stark contrast to the inadequacy of our cybersecurity.”

Other nations “are working to exploit DoD unclassified and classified networks, and some foreign intelligence organizations have already acquired the capacity to disrupt elements of DoD’s information infrastructure,” the plan states. “Moreover, non-state actors increasingly threaten to penetrate and disrupt DoD networks and systems.”

Groups are capable of this largely because “small-scale technologies” that have “an impact disproportionate to their size” are relatively inexpensive and readily available.

The Pentagon plans to focus heavily on three areas under the new strategy: the theft or exploitation of data; attempts to deny or disrupt access to U.S. military networks; and any attempts to “destroy or degrade networks or connected systems.”

One problem highlighted in the strategy is a baked-in threat: “The majority of information technology products used in the United States are manufactured and assembled overseas.”

DoD laid out a multi-pronged approach to address those issues.

As foreshadowed by Pentagon officials’ comments in recent years, the plan etches in stone that cyberspace is now an “operational domain” for the military, just as land, air, sea and space have been for decades.

“This allows DOD to organize, train and equip for cyberspace” as in those other areas, the plan states. It also noting the 2010 establishment of U.S. Cyber Command to oversee all DOD work in the cyber realm.

The second leg of the plan is to employ new defensive ways of operating in cyberspace, first by enhancing the DoD’s “cyber hygiene.” That term covers ensuring data on military networks remains secure, using the Internet wisely, and designing systems and networks to guard against cyber strikes.

The military will continue its “active cyber defense” approach of “using sensors, software, and intelligence to detect and stop malicious activity before it can affect DOD networks and systems.” It also will look for new “approaches and paradigms” that will include “development and integration … of mobile media and secure cloud computing.”

The plan underscores efforts long underway at the Pentagon to work with other government agencies and the private sector. It also says the Pentagon will continue strong cyber R&D spending, even in a time of declining national security budgets.

Notably, it calls the Department of Homeland Security the lead for “interagency efforts to identify and mitigate cyber vulnerabilities in the nation’s critical infrastructure.” Some experts have warned against DOD overstepping on domestic cyber matters.

The Pentagon also announced a new pilot program with industry designed to encourage companies to “voluntarily [opt] into increased sharing of information about malicious or unauthorized cyber activity.”

The strategy calls for a larger DoD cyber workforce.

One challenge, Pentagon experts say, will be attracting top IT talent because the private sector can pay much larger salaries — especially in times of shrinking Defense budgets. To that end, “DOD will focus on the establishment of dynamic programs to attract talent early,” the plan states.

On IT acquisition, the plan lays out several changes, including: faster delivery of systems; moving to incremental development and upgrading instead of waiting to buy “large, complex systems”; and improved security measures.

Finally, the strategy states an intention to work more closely with “small- and medium-sized business” and “entrepreneurs in Silicon Valley and other U.S. technology innovation hubs.”

Thursday, July 8, 2010

Threat of 'cyberwar' has been hugely hyped

(Like every other threat in recent history, it's the methodology of our govt to over-hype a threat so they can then spend trillions of dollars fighting it, whether the failed war on drugs, the endless war on terror, this new threat of cyberwar, or Obama's declared war on the BP oil disaster. Experience says we should know what's coming next.--jef)


~x0x~

By Bruce Schneier | July 7, 2010

(CNN) -- There's a power struggle going on in the U.S. government right now.

It's about who is in charge of cyber security, and how much control the government will exert over civilian networks. And by beating the drums of war, the military is coming out on top.

"The United States is fighting a cyberwar today, and we are losing," said former NSA director -- and current cyberwar contractor -- Mike McConnell. "Cyber 9/11 has happened over the last ten years, but it happened slowly so we don't see it," said former National Cyber Security Division director Amit Yoran. Richard Clarke, whom Yoran replaced, wrote an entire book hyping the threat of cyberwar.

General Keith Alexander, the current commander of the U.S. Cyber Command, hypes it every chance he gets. This isn't just rhetoric of a few over-eager government officials and headline writers; the entire national debate on cyberwar is plagued with exaggerations and hyperbole.

Googling those names and terms -- as well as "cyber Pearl Harbor," "cyber Katrina," and even "cyber Armageddon" -- gives some idea how pervasive these memes are. Prefix "cyber" to something scary, and you end up with something really scary.

Cyberspace has all sorts of threats, day in and day out. Cybercrime is by far the largest: fraud, through identity theft and other means, extortion, and so on. Cyber-espionage is another, both government- and corporate-sponsored. Traditional hacking, without a profit motive, is still a threat. So is cyber-activism: people, most often kids, playing politics by attacking government and corporate websites and networks.

These threats cover a wide variety of perpetrators, motivations, tactics, and goals. You can see this variety in what the media has mislabeled as "cyberwar." The attacks against Estonian websites in 2007 were simple hacking attacks by ethnic Russians angry at anti-Russian policies; these were denial-of-service attacks, a normal risk in cyberspace and hardly unprecedented.
A real-world comparison might be if an army invaded a country, then all got in line in front of people at the DMV so they couldn't renew their licenses. If that's what war looks like in the 21st century, we have little to fear.

Similar attacks against Georgia, which accompanied an actual Russian invasion, were also probably the responsibility of citizen activists or organized crime. A series of power blackouts in Brazil was caused by criminal extortionists -- or was it sooty insulators? China is engaging in espionage, not war, in cyberspace. And so on.

One problem is that there's no clear definition of "cyberwar." What does it look like? How does it start? When is it over? Even cybersecurity experts don't know the answers to these questions, and it's dangerous to broadly apply the term "war" unless we know a war is going on.

Yet recent news articles have claimed that China declared cyberwar on Google, that Germany attacked China, and that a group of young hackers declared cyberwar on Australia. (Yes, cyberwar is so easy that even kids can do it.) Clearly we're not talking about real war here, but a rhetorical war: like the war on terror.

We have a variety of institutions that can defend us when attacked: the police, the military, the Department of Homeland Security, various commercial products and services, and our own personal or corporate lawyers. The legal framework for any particular attack depends on two things: the attacker and the motive. Those are precisely the two things you don't know when you're being attacked on the Internet. We saw this on July 4 last year, when U.S. and South Korean websites were attacked by unknown perpetrators from North Korea -- or perhaps England. Or was it Florida?

We surely need to improve our cybersecurity. But words have meaning, and metaphors matter. There's a power struggle going on for control of our nation's cybersecurity strategy, and the NSA and DoD are winning. If we frame the debate in terms of war, if we accept the military's expansive cyberspace definition of "war," we feed our fears.

We reinforce the notion that we're helpless -- what person or organization can defend itself in a war? -- and others need to protect us. We invite the military to take over security, and to ignore the limits on power that often get jettisoned during wartime.

If, on the other hand, we use the more measured language of cybercrime, we change the debate. Crime fighting requires both resolve and resources, but it's done within the context of normal life. We willingly give our police extraordinary powers of investigation and arrest, but we temper these powers with a judicial system and legal protections for citizens.

We need to be prepared for war, and a Cyber Command is just as vital as an Army or a Strategic Air Command. And because kid hackers and cyber-warriors use the same tactics, the defenses we build against crime and espionage will also protect us from more concerted attacks. But we're not fighting a cyberwar now, and the risks of a cyberwar are no greater than the risks of a ground invasion. We need peacetime cyber-security, administered within the myriad structure of public and private security institutions we already have.

Tuesday, May 4, 2010

Washington hypes Cyberattack threat to justify regulating Web

Networks have been under attack -- and successfully handled by operators -- as long as they’ve been around. Be wary of calls for more government supervision of the Internet.

By Jerry Brito and Tate Watkins
posted April 29, 2010 at 1:31 pm EDT

Arlington, Va. —
We marched into Baghdad on flimsy evidence and we might be about to make the same mistake in cyberspace.

Over the past few weeks, there has been a steady drumbeat of alarmist rhetoric about potential threats online. At a Senate Armed Services Committee hearing this month, chairman Carl Levin said that “cyberweapons and cyberattacks potentially can be devastating, approaching weapons of mass destruction in their effects.”

The increased consternation began with the suspected Chinese breach of Google’s servers earlier this year. Since then, press accounts, congressional pronouncements, and security industry talk have increasingly sown panic about an amorphous cyberthreat.

Bush administration cybersecurity chief Michael McConnell recently warned that the United States “is fighting a cyber-war today, and we are losing.”

According to McConnell, now a vice president at Booz Allen Hamilton, “our power grids, air and ground transportation, telecommunications, and water-filtration systems are in jeopardy.” More recently, Sens. Jay Rockefeller (D) and Olympia Snowe (R) wrote about “sophisticated cyber adversaries” with the potential “to disrupt or disable vital information networks, which could cause catastrophic economic loss and social havoc.”

Yet none of the prognosticators of disaster presents any evidence to sustain their claims. They mention the Google breach, but that was an act of espionage that, while serious, did not lead to catastrophe.

There have been and continue to be many “cyberattacks” on government and private networks, from the Korea attacks to the denial-of-service attacks during the Georgia-Russia war. To be sure, these attacks are a serious concern and we should continue to study them.

But so far, these types of events tend to be more of a nuisance than a catastrophe. The biggest result is that websites are down for a few hours or days.

This shows that security should be a serious concern for any network operator. It does not show, however, that these attacks can lead – much less have ever led – to the types of doomsday scenarios that politicians imagine. There is no evidence that these attacks have ever cost any lives or that any type of critical infrastructure has ever been compromised: No blackouts, no dams bursting, no panic in the streets.

The cyberalarmist rhetoric conflates the various threats we might face into one big ball of fear, uncertainty, and doubt. This week for example, the director of the Central Intelligence Agency announced that a cyberattack could be the next Pearl Harbor.

Cyberwar, cyberespionage, cyberterrorism, cybercrime – these are all disparate threats. Some are more real than others, and they each have different causes, motivations, manifestations, and implications. As a result, there will probably be different appropriate responses for each.

Unfortunately, the popular discussion largely clumps them into the vague and essentially meaningless “cyberthreat” category.

Let’s take a deep breath.

Before we can effectively address any of these amorphous “cyberthreats,” we must first identify what, specifically, these threats are and to what extent the federal government plays a role in defending against them.

The war metaphor may be useful rhetoric, but it is a poor analogy to the dispersed and different threats that both public and private information technology systems face.

The fact is, as long as we have had networks, they have been under attack. But over the past 20 years network operators have developed effective detection, prevention, and mitigation strategies.

This is why we should be wary of calls for more government supervision of the Internet. Last week, as part of its National Broadband Plan, the Federal Communications Commission began an inquiry into whether to establish a “voluntary cybersecurity certification program.” Through the program the FCC would certify communication service providers based on a set of cybersecurity standards developed directly by the FCC, or indirectly through a third party.

More ominously, Senators Rockefeller and Snowe have introduced the Cybersecurity Act of 2010 that aims to change how the Internet works in the name of security. It would also create a national system of licensing for security professionals, and would dole out millions of dollars in cyberpork to “regional cybersecurity centers” and other programs.

At the heart of calls for federal involvement in cybersecurity is the proposition that we reengineer the Internet to facilitate better tracking of users in order to pinpoint the origin of attacks. The Rockefeller-Snowe bill looks to develop such a “secure domain name addressing system.”

That’s a slippery slope.

And there’s the fact that we have seen a wasteful military-industrial complex develop before, and in this rush to “protect” we might be seeing a new one blossoming now. The greater the threat is perceived to be – and the less clearly it is defined – the better it is for defense contractors like Booz Allen Hamilton, which last week landed $34 million in Defense Department cybersecurity contracts.

That money could certainly be put to better use right now.

Anyone concerned about net neutrality or civil liberties – in particular online privacy and anonymity – should take notice. Before the country is swept by fear and we react too quickly to the “gathering threat” of cyberattacks, we should pause to calmly consider the risks involved and the alternatives available to us.

Rather than pass a sweeping “cyberdefense” bill right away, Congress should take the time to untangle the different threats that confront us and make sure they are addressing each appropriately. If not, we will be saddled with an overreaching one-size-fits-all result.

Giving the military and federal agencies the tools to protect their online assets might be an appropriate first response. But reengineering the Internet and imposing standards and licensing on the most innovative sector of our economy should give us pause. There is no reason to rush to action.

~~//o)X(o\\~~


Hacked US Treasury websites serve visitors malware
05-04-2010

Updated Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday.

The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.

To cover their tracks, the miscreants behind the compromise tailored it so it attacks only IP addresses that haven't already visited the Treasury websites. That makes it harder for white hat-hackers and law enforcement agents to track the exploit. Indeed, Thompson initially reported that the problem had been fixed until he discovered the sites were merely skipping over laboratory PCs that had already encountered the attack.

The attack is most likely related to mass infections that two weeks ago hit hundreds of sites hosted by Network Solutions (http://www.theregister.co.uk/2010/04/19/network_solutions_mass_hack/) and GoDaddy, said Dean De Beer, founder and CTO of security consultancy zero(day)solutions.

He made that assessment based on the observation that the compromised Treasury websites are hosted at Network Solutions and the owner of grepad.com is also the owner of record for most of the websites used in the earlier attacks.

"There's a very high probability that it's the same person," De Beer said. "The only things that are changing are the domains."

Earlier, Thompson speculated the attack might be the result of someone exploiting a SQL injection vulnerability on the Treasury websites. After investigating that possibility, De Beer said it was unlikely because the hacked Treasury sites contained static HTML pages that aren't susceptible to such exploits.

Media representatives at the Treasury Department didn't return a phone call seeking comment. 

This posting was updated to include details linking the attacks to similar mass compromises that hit sites hosted by Network Solutions and GoDaddy.