<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; hacking</title>
	<atom:link href="http://allthingsd.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Sat, 26 May 2012 19:52:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>Despite Bumpy Launch, Activision Sells 3.5 Million Copies of Diablo III in 24 Hours</title>
		<link>http://allthingsd.com/20120523/despite-bumpy-launch-activision-sells-3-5-million-copies-of-diablo-iii-in-24-hours/</link>
		<comments>http://allthingsd.com/20120523/despite-bumpy-launch-activision-sells-3-5-million-copies-of-diablo-iii-in-24-hours/#comments</comments>
		<pubDate>Wed, 23 May 2012 17:29:01 +0000</pubDate>
		<dc:creator>Tricia Duryee</dc:creator>
				<category><![CDATA[Commerce]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Activision]]></category>
		<category><![CDATA[Blizzard Entertainment]]></category>
		<category><![CDATA[Diablo III]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Mike Morhaime]]></category>
		<category><![CDATA[PC gaming]]></category>
		<category><![CDATA[virtual world]]></category>
		<category><![CDATA[World of Warcraft]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=211528</guid>
		<description><![CDATA[Activision is claiming to have sold 3.5 million copies of Diablo III in its first 24 hours, setting a record for the fastest-selling PC game ever.]]></description>
			<content:encoded><![CDATA[<p>Despite reports of hacking and several operational issues after launch, Activision is claiming to have <a href="http://investor.activision.com/releasedetail.cfm?ReleaseID=676112">sold 3.5 million copies of Diablo III</a> in the first 24 hours of sales, setting a record for the fastest-selling PC game ever.</p>
<p><img class="alignright size-medium wp-image-211538" title="diablo_town-portal" src="http://allthingsd.com/files/2012/05/diablo_town-portal-380x241.jpg" alt="" width="380" height="241" />After Activision&#8217;s Blizzard studios launched the highly anticipated PC game on May 15, players had problems logging on and said their accounts were being hacked.</p>
<p>&#8220;Despite very aggressive projections, our preparations for the launch of the game did not go far enough,&#8221; the company said in an apology <a href="http://www.cinemablend.com/games/Blizzard-Apologizes-Diablo-3-Server-Problems-Delays-Real-Money-Auction-House-42607.html">issued last week</a>. Yesterday, <a href="http://www.forbes.com/sites/erikkain/2012/05/22/blizzard-responds-to-diablo-iii-security-issues/">the company issued another statement</a>, confirming that some accounts &#8220;may have been compromised.&#8221;</p>
<p>In addition to selling 3.5 million copies on day one, Activision said more than 1.2 million players received Diablo III as part of signing up for the World of Warcraft Annual Pass promotion. Based on that total, internal calculations and reports from distribution partners, Activision believes this makes Diablo III the biggest PC game launch in history. </p>
<p>By the end of the first week, Diablo sales reached 6.3 million. The game costs $60 for either the physical copy or the digital version.</p>
<p><img class="alignleft size-medium wp-image-211559" title="diablo_map sanctuary" src="http://allthingsd.com/files/2012/05/diablo_map-sanctuary-380x282.jpg" alt="" width="380" height="282" />&#8220;We&#8217;re definitely thrilled that so many people around the world were excited to pick up their copy of Diablo III and jump in the moment it went live,&#8221; said Blizzard&#8217;s CEO and co-founder Mike Morhaime. &#8220;We also regret that our preparations were not enough to ensure everyone had a seamless experience when they did so. I want to reaffirm our commitment to make sure the millions of Diablo III players out there have a great experience with the game moving forward, and I also want to thank them for their ongoing support.&#8221;</p>
<p>In the game, players take on one of five heroic characters &#8212; barbarian, witch doctor, wizard, monk or demon hunter. As that character, they must save the world of Sanctuary from the forces of the Burning Hells. As they engage in the virtual world, players gain new abilities and acquire artifacts.</p>
<p>For the first time ever, those artifacts can be traded for real-world currency through an auction house.</p>
<p>During the company&#8217;s first-quarter conference call two weeks ago, it confirmed that consumer feedback from the beta test had gone well, especially when it came to the new trading method.</p>
<p>Blizzard does not intend to sell any items in the auction house, in contrast to other game models where companies profit from selling in-game virtual goods. But interestingly, Blizzard will charge players a transaction fee on sales, or roughly 15 percent on most items.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120523/despite-bumpy-launch-activision-sells-3-5-million-copies-of-diablo-iii-in-24-hours/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.K. Report Condemns News Corp.</title>
		<link>http://allthingsd.com/20120501/u-k-report-condemns-news-corp/</link>
		<comments>http://allthingsd.com/20120501/u-k-report-condemns-news-corp/#comments</comments>
		<pubDate>Tue, 01 May 2012 11:37:02 +0000</pubDate>
		<dc:creator>Paul Sonne and Jeanne Whalen</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[James Murdoch]]></category>
		<category><![CDATA[Jeanne Whalen]]></category>
		<category><![CDATA[News Corp.]]></category>
		<category><![CDATA[News International]]></category>
		<category><![CDATA[News of the World]]></category>
		<category><![CDATA[Paul Sonne]]></category>
		<category><![CDATA[Rupert Murdoch]]></category>
		<category><![CDATA[scandal]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>
		<category><![CDATA[voicemail]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=201797</guid>
		<description><![CDATA[The U.K. parliamentary committee probing illicit voicemail interception by News Corp.'s shuttered News of the World tabloid released a final report Tuesday concluding that News Corp. Chief Executive Rupert Murdoch is "not a fit person to exercise the stewardship of a major international company" and accusing several former company executives of misleading parliament.]]></description>
			<content:encoded><![CDATA[<p>The U.K. parliamentary committee probing illicit voicemail interception by News Corp.&#8217;s shuttered News of the World tabloid released a final report Tuesday concluding that News Corp. Chief Executive Rupert Murdoch is &#8220;not a fit person to exercise the stewardship of a major international company&#8221; and accusing several former company executives of misleading parliament.</p>
<p>The report says Mr. Murdoch and his son, News Corp. Deputy Chief Operating Officer James Murdoch, presided over a culture of &#8220;willful blindness&#8221; at News Corp. It also singles out James Murdoch for displaying a &#8220;lack of curiosity,&#8221; even &#8220;willful ignorance,&#8221; when handling fallout from the phone-hacking scandal as the manager overseeing News Corp.&#8217;s British newspaper unit, News International, from late 2007 to 2012.</p>
<p><a href="http://online.wsj.com/article/SB10001424052702304050304577377570029613042.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120501/u-k-report-condemns-news-corp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stealthy Shape Security Lands $6 Million From Kleiner Perkins and Eric Schmidt</title>
		<link>http://allthingsd.com/20120426/stealthy-shape-security-lands-6-million-from-kleiner-perkins-and-eric-schmidt/</link>
		<comments>http://allthingsd.com/20120426/stealthy-shape-security-lands-6-million-from-kleiner-perkins-and-eric-schmidt/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 12:04:56 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Accel Partners]]></category>
		<category><![CDATA[computer crime]]></category>
		<category><![CDATA[Crowdstrike]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Derek W. Smith]]></category>
		<category><![CDATA[Eric Schmidt]]></category>
		<category><![CDATA[Gaurav Garg]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Kleiner Perkins Caufield & Byers]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Peter Wagner]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sequoia Capital]]></category>
		<category><![CDATA[Shape Security]]></category>
		<category><![CDATA[Solera Networks]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Sumit Agarwal]]></category>
		<category><![CDATA[Ted Schlein]]></category>
		<category><![CDATA[TomorrowVentures]]></category>
		<category><![CDATA[Troy Tribe]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Zero-Day]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=200189</guid>
		<description><![CDATA[A security start-up aims to change the economics of launching hacking attacks.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/files/2011/05/hackers_ver1.jpg"><img src="http://allthingsd.com/files/2011/05/hackers_ver1-184x285.jpg" alt="" title="hackers_ver1" width="184" height="285" class="alignleft size-medium wp-image-79611" /></a></p>
<p>There&#8217;s an interesting new fundamental thought emerging among computer security companies. The logic goes like this: First, your digital assets are going to be attacked. Second, no matter what preparations you make to defend those assets, a determined attacker is going to find a hole or a method of penetrating your defenses that you didn&#8217;t think of.</p>
<p>Most attacks are relatively cheap to carry out, because they&#8217;re not that sophisticated. More often than not, attackers copy the methods they use from each other. Attacks are inexpensive, and most attackers have the luxury of limitless time.</p>
<p>The exception is attacks using so-called &#8220;zero day&#8221; vulnerabilities, where a previously unknown vulnerability, usually in the operating system, is used to gain access to a system. Most &#8212; but not all &#8212; of the time, once a zero-day vulnerability is seen and documented, the weaknesses it reveals are patched, making it the type of weapon that can be used only once.</p>
<p>As such, zero-day vulnerabilities are often traded on the black market and sold at a high price. For example, when the <a href="http://allthingsd.com/20120406/researchers-show-how-easy-a-new-stuxnet-like-attack-can-be/">Stuxnet worm</a> &#8212; the malware that was used to attack and sabotage the Iranian nuclear program &#8212; was first discovered, security researchers were impressed that it used no fewer than four distinct zero-day vulnerabilities in Microsoft Windows. So many used at once indicated that the cost to carry out the attack was high, leading to the conclusion that only a state-sponsored attacker would have the funds to carry it out. This led to the logical conclusion that either the U.S. or Israel had been behind Stuxnet.</p>
<p>I bring it up because Stuxnet is an example of the conclusion of this new fundamental thought I mentioned at the start. Why not make attacks expensive for the attackers? The early estimates on Stuxnet put its cost at $3 million, and it is believed that it required a team of 10 skilled programmers and as long as six months to develop. It was not a cheap attack. It was expensive.</p>
<p>That&#8217;s the idea behind Shape Security, which today announced that it has landed a $6 million Series A round of venture capital funding led by Kleiner Perkins Caufield &#038; Byers and TomorrowVentures, the fund led by Google Chairman Eric Schmidt.</p>
<p>Peter Wagner, a former partner at Accel Partners, as well as executives from LinkedIn, Twitter, and Facebook, will also join the round. Ted Schlein, managing partner at Kleiner Perkins, has joined the board of directors, along with Gaurav Garg, a limited partner at Sequoia Capital and personal investor in the round.</p>
<p>We don&#8217;t as yet know a great deal about Shape Security or its intentions. But we do know who&#8217;s running it: According to <a href="http://www.sec.gov/Archives/edgar/data/1548097/000154809712000001/xslFormDX01/primary_doc.xml">this filing with the U.S. Securities and Exchange Commission</a>, its CEO is Derek W. Smith. Another key exec and director is <a href="http://www.linkedin.com/in/sumitagarwalusaf">Sumit Agarwal</a>, the former head of Google’s mobile product management, <a href="http://allthingsd.com/20100203/another-googler-to-obama-administration-now-weve-got-a-foursome/">who in 2010 took a post in the Department of Defense</a> as senior adviser for Cyber Innovation.</p>
<p>Another key exec is Troy Tribe, who appears to be the same person who used to be <a href="http://www.linkedin.com/in/troytribe">VP for business development</a> at Solera Networks, which specializes in network-security analytics and forensics.</p>
<p>This is the second time in as many weeks that I&#8217;ve noticed a security company talking about changing the economics for attackers. The <a href="http://allthingsd.com/20120418/security-start-up-crowdstrike-hires-former-fbi-cyber-cop/">first was Crowdstrike</a>, which announced that it had hired Shawn Henry from the FBI and landed a $26 million investment from Warburg Pincus. Neither has said yet exactly what you do to make launching a computer attack more expensive. I&#8217;m certainly eager to know more.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120426/stealthy-shape-security-lands-6-million-from-kleiner-perkins-and-eric-schmidt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What's This? A Mac Virus? No, Actually It's a Weakness in Java.</title>
		<link>http://allthingsd.com/20120406/whats-this-a-mac-virus-no-actually-its-a-weakness-in-java/</link>
		<comments>http://allthingsd.com/20120406/whats-this-a-mac-virus-no-actually-its-a-weakness-in-java/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 20:57:02 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[computer crime]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Little Snitch]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Office for Mac]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security Mac OS X]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[software update]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=194020</guid>
		<description><![CDATA[Chatter about a new Trojan affecting Macs fails to acknowledge where the real vulnerability lies: With Oracle's Java and not Apple's OS X itself.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120406/whats-this-a-mac-virus-no-actually-its-a-weakness-in-java/keep_calm/" rel="attachment wp-att-194045"><img src="http://allthingsd.com/files/2012/04/keep_calm-380x285.jpg" alt="" title="keep_calm" width="380" height="285" class="alignright size-Featured wp-image-194045" /></a>When a computer incident happens on Apple&#8217;s Mac OS X, it&#8217;s a headline-making event. When it happens on Windows, it&#8217;s just another day.</p>
<p>That remains the reality, even after a bunch of media reports on how a vulnerability in Java has led to the creation of a Mac <a href="https://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed">botnet about 600,000</a> strong.</p>
<p>Today I&#8217;ve been getting calls from people who say something roughly in line with the following: &#8220;I thought you said Macs didn&#8217;t get viruses? What about this?&#8221;</p>
<p>No, I explain, I never said Macs will <em>never</em> get viruses or other Malware. But historically its record versus other platforms compares favorably. As is the case with investment instruments, past results are no guarantee of future performance, and let&#8217;s face it, there&#8217;s no such thing as a perfectly secured computing platform.</p>
<p>But let&#8217;s look closely at the facts around the Flashback Trojan causing all this consternation, and clear up what it is versus what it is not, and put the results of the incident in perspective.</p>
<p>Yes it&#8217;s true that some 600,000 Macs are confirmed to have been infected. The claim, first made by <a href="http://news.drweb.com/show/?i=2341&#038;lng=en&#038;c=14">Dr. Web</a>, an outfit I had never heard of, has since been <a href="https://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed">corroborated by Kaspersky Labs</a>, whose research and analysis capabilities are well-respected. More than half of the compromised machines are in the U.S., 95,000 in Canada, 47,000 in the U.K., and 41,000 in Australia.</p>
<p>The trojan targets a vulnerability in software that is not even an Apple product: Java. You&#8217;ll recall that Java is add-on software created by Sun Microsystems and now the property of the software giant Oracle. Rather common, it is no longer shipped as a default add-on to Apple&#8217;s Mac OS X beginning in 2011, when Apple first shipped Lion.</p>
<p>Through this hole in Java, certain Web sites are serving up malicious Java applets. Once inserted on the machine, the software then prompts the user to enter the password they use to run the machine. It attempts to trick the user by appearing as an update to Adobe&#8217;s Flash video and animation software.</p>
<p>If the user doesn&#8217;t fall for the trick, it tries something else. Here again it checks to see if there are any Microsoft Office applications on the machine, or Skype. If there are, it deletes itself. </p>
<p>Then it does something interesting. It scans the contents of the Mac&#8217;s hard drive to determine if certain applications are present, and if they are, it deletes itself. Among those applications are security tools such as <a href="http://www.obdev.at/products/littlesnitch/index.html">Little Snitch</a>, a networking security tool, or Packet Peeper, another security tool. It also deletes itself if it sees the user has installed XCode Mac developers tools, and any kind of anti-virus software.</p>
<p>Presuming it finds none of them, it proceeds to contact a command-and-control server for the purpose of downloading and installing more malware. That malware is being used to commandeer the Macs and generate Web traffic to boost revenue for some pay-per-click ads on Web sites, making money for someone who&#8217;s behind the scheme. Nothing surprising there.</p>
<p>Apple has issued a fix to Mac OS X that closes the hole in Java, and you can protect yourself by running Software Update from within your machine&#8217;s System Preferences. Today would be a good day to do that if you haven&#8217;t already. Once you&#8217;ve done this you&#8217;re no longer vulnerable to the attack.</p>
<p>If you&#8217;re among the 600,000 already compromised you can turn to third parties to help you remove it. F-Secure has some <a href="http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml">instructions here</a> for determining if your machine is affected. If you&#8217;re comfortable running some commands in the Mac&#8217;s terminal program, there are also some good instructions <a href="http://arstechnica.com/apple/news/2012/04/how-to-check-forand-get-rid-ofa-mac-flashback-infection.ars">here at ArsTechnica</a>.</p>
<p>So what does all this say about the state of security on the Mac? Nothing that wasn&#8217;t true already. No system is perfectly secure, and this, along with MacDefender, amounts to exactly the second security incident worth mentioning to hit the Mac in about a year. The number of machines affected is less than 1 percent of the 63 million Macs currently in use around the world.</p>
<p>The conventional wisdom has often held that Macs are targeted by malware less often than Windows machines because of their relatively small market share. This still has some merit, but the fact is that Windows is also where the vulnerabilities are. Historically, Mac OS X has been substantially less vulnerable to this sort of thing than Windows.</p>
<p>Does that let Apple off the hook entirely? No, though to its credit, Apple had a fix ready within a week of learning of this vulnerability. That&#8217;s not exactly a pokey response, especially when the problem lies not directly within Apple&#8217;s software, but in Oracle&#8217;s.</p>
<p>Here&#8217;s a thought: Turn off Java in your Web browsers. You probably won&#8217;t miss it. <a href="http://reviews.cnet.com/8301-13727_7-57408841-263/how-to-check-for-and-disable-java-in-os-x/">Here&#8217;s some instructions for that</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120406/whats-this-a-mac-virus-no-actually-its-a-weakness-in-java/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Researchers Show How Easy a New Stuxnet-Like Attack Can Be</title>
		<link>http://allthingsd.com/20120406/researchers-show-how-easy-a-new-stuxnet-like-attack-can-be/</link>
		<comments>http://allthingsd.com/20120406/researchers-show-how-easy-a-new-stuxnet-like-attack-can-be/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 14:07:28 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Dale Peterson]]></category>
		<category><![CDATA[Digital Bond]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[industrial computers]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Natanz]]></category>
		<category><![CDATA[nuclear research]]></category>
		<category><![CDATA[nuclear weapons]]></category>
		<category><![CDATA[PLC]]></category>
		<category><![CDATA[programmable logic controller]]></category>
		<category><![CDATA[Rapidy]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Schneider Electric]]></category>
		<category><![CDATA[Siemens]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=193852</guid>
		<description><![CDATA[While the Stuxnet worm was seen as difficult to make, inherent weaknesses found in widely used industrial control computers make attacks like that surprisingly easy to carry out, new research says.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20110716/cyberwar-its-not-fiction-anymore/warroom/" rel="attachment wp-att-98887"><img src="http://allthingsd.com/files/2011/07/Warroom-380x285.png" alt="" title="Warroom" width="380" height="285" class="alignright size-Featured wp-image-98887" /></a>One of the great residual concerns about the Stuxnet computer worm that attacked the Iranian nuclear program has been that study of its methods would lead to other attacks like it.</p>
<p>Those fears were theoretical for a while. If you could attack the industrial computers controlling nuclear centrifuges and make them explode, as happened in the case of Stuxnet, you could, in theory, use the same approach to attack industrial computers controlling critical infrastructure in the U.S. The only thing needed is knowledge about vulnerabilities lurking in those systems. </p>
<p>The bad news is that, as of yesterday, those vulnerabilities are no longer a theory. The good news is that the good guys found them first.</p>
<p>Yesterday, researchers for a volunteer program called <a href="http://threatpost.com/en_us/blogs/looking-firesheep-moment-researchers-lay-bare-woeful-scada-security-012012">Project Basecamp</a> have discovered three vulnerabilities inside a common model of industrial computer known as a programmable logic controller (PLC). These PLCs basically sit between a regular computer running Windows and a big piece of industrial equipment &#8212; say, a pump or a generator or a nuclear centrifuge.</p>
<p>PLCs are part of a larger set of industrial computers known as Supervisory Control And Data Acquisition (SCADA) systems. Security research into SCADA systems has increased dramatically since the <a href="http://www.bloomberg.com/news/2010-09-24/stuxnet-computer-worm-may-be-aimed-at-iran-nuclear-sites-researcher-says.html">revelation of the Stuxnet worm in 2010</a>.</p>
<p>The work was done by researchers at <a href="http://www.digitalbond.com/2012/04/05/news-from-camp-4/">Digital Bond</a>, a security research firm specializing in work on SCADA systems. What they built was a software module called &#8220;modiconstux,&#8221; which carries out a Stuxnet-like attack on a PLC device called a Modicon Quantum, made by <a href="http://www2.schneider-electric.com/sites/corporate/en/products-services/automation-control/products-offer/range-presentation.page?p_range_id=538">Schneider Electric</a>.</p>
<p>Borrowing techniques learned from the Stuxnet worm, modiconstux does two things: It downloads the current set of instructions the PLC is using &#8212; a set of programming commands known as &#8220;ladder logic&#8221; &#8212; giving the attacker the ability to understand what the PLC is doing day in and day out. This is key: If you&#8217;re going to hijack a PLC to make the machine it&#8217;s controlling explode, you have to first understand the process you&#8217;re going to sabotage.</p>
<p>The second thing that modiconstux does is upload new ladder logic. The classic example I think of in explaining this comes from the first public demonstrations of Stuxnet carried out by researchers at Symantec. In that case, a Siemens PLC had been programmed to blow up a balloon by instructing a pump to send a certain amount of air to the balloon and then stop. After being hijacked by Stuxnet, the logic was changed in such a way that the pump didn&#8217;t stop, and the balloon popped. Not very menacing, but if you use your imagination, you can see that popping balloon as a metaphor for a lot of very dangerous outcomes.</p>
<p>What&#8217;s even scarier than the outcome is the fact that the exploit works without any actual computer hacking having to take place beforehand. Dale Peterson, Digital Bond&#8217;s CEO, said the attack works because the PLC is insecure in the first place. There isn&#8217;t so much as a password required to download the existing ladder logic, nor to upload the altered ladder logic. And if that PLC is connected to the Internet in any way, it is wide open to attack.</p>
<p>The team also released two other vulnerabilities. One tells the same Scheider Electric PLC to stop, essentially freezing it in place until it can be reset. The third is a vulnerability for a type of PLC device made by General Electric.</p>
<p>The vulnerabilities have been released to the wider world through <a href="http://www.metasploit.com/">Metasploit</a>, an open source vulnerability monitoring service that&#8217;s owned by Rapid7, a Cambridge, Mass-based company that specializes in helping companies stay ahead of new computer security vulnerabilities. Metasploit subscribers can download the exploit code and test it on their own systems, and demonstrate simulated attacks that in all likelihood will scare the heck out of their bosses.</p>
<p>It should also scare the heck out of legislators and policymakers who have talked incessantly about the <a href="http://allthingsd.com/20110716/cyberwar-its-not-fiction-anymore/">need to prepare for a &#8220;cyberattack.&#8221;</a> Chances are, the next time there&#8217;s a serious conflict, attacks carried out by way of a computer will be used to sabotage infrastructure, sow confusion, interfere with logistics and so on. Stuxnet proved what could be done, and what to that point had generally been considered only a theory.</p>
<p>Created by parties unknown &#8212; though the smart money <a href="http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html?pagewanted=all">says it was Israel, with some help from the U.S.</a> &#8212; the Stuxnet worm burrowed its way into PLCs at an Iranian nuclear installation, made the centrifuges spin too fast, and caused some of them to explode. The Iranian nuclear enrichment program was thought to be set back by anywhere from one to two years.</p>
<p>Since then, researchers have been on the lookout for the next Stuxnet, assuming that a second worm would be easier to construct. They&#8217;ve also been studying the inherent weaknesses in SCADA systems like PLCs. What they&#8217;re finding should give us all pause.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120406/researchers-show-how-easy-a-new-stuxnet-like-attack-can-be/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government Security Gurus: All Our Networks Are Belong to Them</title>
		<link>http://allthingsd.com/20120323/government-security-gurus-all-our-networks-are-belong-to-them/</link>
		<comments>http://allthingsd.com/20120323/government-security-gurus-all-our-networks-are-belong-to-them/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 11:45:26 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Kasperky Labs]]></category>
		<category><![CDATA[Pentagon]]></category>
		<category><![CDATA[Sandia National Lab]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spies]]></category>
		<category><![CDATA[terrorists]]></category>
		<category><![CDATA[Threatpost]]></category>
		<category><![CDATA[U.S. Department of Defense]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=189445</guid>
		<description><![CDATA[And by "them," they mean the bad guys: Spies, terrorists and troublemakers.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120323/government-security-gurus-all-our-networks-are-belong-to-them/dod_swiss_cheese/" rel="attachment wp-att-189447"><img src="http://allthingsd.com/files/2012/03/dod_swiss_cheese-380x285.jpg" alt="" title="dod_swiss_cheese" width="380" height="285" class="alignright size-Featured wp-image-189447" /></a>Think U.S. military computer networks are secure? Think again. A panel of computer security experts from across the U.S. government told a U.S. Senate committee yesterday that computer networks operated by the U.S. Department of Defense are so thoroughly compromised by spies from other nations that there&#8217;s almost no point in trying to keep them out.</p>
<p>At a meeting in Washington, the Senate Armed Services Subcommittee on Emerging Threats and Capabilities heard testimony from experts that, essentially summarized, goes like this: The attackers already have access to the systems, so rather than try to lock them out, it&#8217;s now a matter of managing them, now that they&#8217;re in. Just as in the real world, spies are going to get into the country whether you want them to or not. So, knowing that they&#8217;re there, it makes more sense to make their day-to-day spying activities as difficult and costly as you can. DOD security practices currently focus on trying to keep intruders out.</p>
<p>&#8220;I think we have to go to a model where we assume that the adversary is in our networks,&#8221; James Peery, director of the Information Systems Analysis Center at the Sandia National Lab, <a href="http://threatpost.com/en_us/blogs/experts-tell-senate-government-networks-owned-resistance-futile-032112">told legislators</a>, as reported by Threatpost, a blog produced by security firm Kaspersky Labs. &#8220;They&#8217;re on our machines, and we’ve got to operate anyway. We have to protect the data anyway.&#8221;</p>
<p>The hearing echoed some things we&#8217;ve been hearing on the security front from the likes of <a href="http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/">Art Coviello, the EMC vice president and former CEO of RSA Security</a>, who spoke to <strong>AllThingsD</strong> recently.</p>
<p>Current practice calls for perimeter-based defenses that aim to put a defensive ring around a network to keep intruders out. That thinking is out of date and in need of a significant rethink, the panelists said. It should be noted that most of the agencies represented at the hearing were doing what government executives usually do when they go before the U.S. Senate: Jockeying for more funding.</p>
<p>That is, except for one agency: Michael Wertheimer, director of research and development at the super-secret National Security Agency (NSA), an agency whose budget is classified to begin with, said that current levels are sufficient, but that money needs to be spent more wisely. Then again, the NSA just built a <a href="http://allthingsd.com/voices/the-nsa-is-building-the-countrys-biggest-spy-center-watch-what-you-say/?refcat=voices">massive data center in the Utah desert</a>, which didn&#8217;t exactly come cheap.</p>
<p>You can watch a <a href="http://www.senate.gov/fplayers/jw57/urlMP4Player.cfm?fn=armed032012p&#038;st=725&#038;dur=4890">video of the 81-minute hearing here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120323/government-security-gurus-all-our-networks-are-belong-to-them/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not Lulzing Anymore: Five Hackers Charged in U.S., U.K. and Ireland</title>
		<link>http://allthingsd.com/20120306/not-lulzing-anymore-five-hackers-charged-in-us-uk-and-ireland/</link>
		<comments>http://allthingsd.com/20120306/not-lulzing-anymore-five-hackers-charged-in-us-uk-and-ireland/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 14:21:25 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[computer crime]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[PlayStation]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=180859</guid>
		<description><![CDATA[Five people on two continents are charged as being members of the LulzSec hacking troupe that caused so much mayhem last summer. They are alleged to have been turned in by one of their own.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2012/03/lulz.jpg" alt="" title="lulz" width="380" height="285" class="align right size-full wp-image-181028" />Well, it finally happened: The hacking troupe variously known as LulzSec and Anonymous appears to have been beheaded. <a href="http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/">Fox News is reporting</a> that five people who function as the group&#8217;s leaders have been arrested in the U.S., the U.K. and Ireland.</p>
<p>I&#8217;m working on getting copies of the criminal complaints, and will add them here when I do, but here&#8217;s the rundown: It looks like one of the group&#8217;s insiders got caught and probably made some kind of misstep in covering his tracks, and then worked secretly with the government to inform on other members. This is <a href="http://allthingsd.com/20110606/no-lulzsec-hackers-have-been-arrested-at-least-not-yet/">exactly what I said</a> was likely to happen in this case, way back in June.</p>
<p>According to Fox, the one who turned is a New Yorker named Hector Xavier Monsegur, who worked under the handle Sabu. He&#8217;s 28 years old and the father of two, and lives on the Lower East Side of Manhattan. This is his <a href="https://twitter.com/#!/anonymousabu">Twitter feed</a>. He&#8217;s been a cooperating witness since June, which coincides nicely with the moment when the first rumors started to emerge that the FBI had penetrated the group.</p>
<p>Fox says that according to documents that will be unsealed in a New York federal court today, Monsegur pleaded guilty in August to several hacking-related crimes. His cooperation led to charges against five more people in Chicago, the U.K. and Ireland. Among them is Jake Davis, the 18-year-old resident of the Shetland Islands, who went by the handle Topiary, and whom police in the U.K. <a href="http://allthingsd.com/20110801/uk-police-say-this-is-the-face-of-lulzsec-hacker-known-as-topiary/">collared on Aug. 1</a>.</p>
<p>The other four are Ryan Ackroyd, who went under the handle &#8220;Kayla.&#8221; He&#8217;s a Londoner. Two people from Ireland were also charged: Darren Martyn, whose handle was &#8220;pwnsauce,&#8221; and Donncha O’Cearrbhail, who called himself &#8220;palladium.&#8221; Jeremy Hammond of Chicago went by the handle &#8220;Anarchaos.&#8221;</p>
<p>The news makes the following tweet by Monsegur, a.k.a. Sabu, seem sort of ironic. Among his final tweets, before word emerged that he had helped turn in his comrades, were several railing against informants and other &#8220;cowards.&#8221; Clearly, he was keeping up a brave public face:</p>
<p><!-- tweet id : 176683332988452865 --><br />
<style type="text/css">#bbpBox_176683332988452865 a { text-decoration:none; color:#0084B4; }#bbpBox_176683332988452865 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_176683332988452865" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#C0DEED; background-image:url(http://a0.twimg.com/profile_background_images/290810645/tTxe9h.jpg);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">Without informants or companies bending over+giving up their customer data the feds would be further behind than they are now. Ride up.</span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on March 5, 2012 7:59 am" href="http://twitter.com/#!/anonymouSabu/status/176683332988452865" target="_blank">March 5, 2012 7:59 am</a> via <a href="http://blackberry.com/twitter" rel="nofollow" target="blank">Twitter for BlackBerry®</a><a href="https://twitter.com/intent/tweet?in_reply_to=176683332988452865" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=176683332988452865" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=176683332988452865" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=anonymouSabu"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a0.twimg.com/profile_images/1728484932/shirt01_normal.gif" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=anonymouSabu">@anonymouSabu</a>
<div style="margin:0; padding-top:2px">The Real Sabu</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
<p>Anonymous, the wider hacker group with which LulzSec teamed up last year, was quick to urge its followers to block Sabu&#8217;s Twitter account.</p>
<p><!-- tweet id : 177085815682379777 --><br />
<style type="text/css">#bbpBox_177085815682379777 a { text-decoration:none; color:#009999; }#bbpBox_177085815682379777 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_177085815682379777" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#131516; background-image:url(http://a0.twimg.com/images/themes/theme14/bg.gif);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">@<a href="http://twitter.com/intent/user?screen_name=anonymouSabu" class="twitter-action">anonymouSabu</a> is now controlled by feds. We have blocked the account and we suggest you do as well. <a href="http://twitter.com/search?q=%23BlockAnonymouSabu" title="#BlockAnonymouSabu">#BlockAnonymouSabu</a></span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on March 6, 2012 10:38 am" href="http://twitter.com/#!/anonops/status/177085815682379777" target="_blank">March 6, 2012 10:38 am</a> via <a href="http://www.tweetdeck.com" rel="nofollow" target="blank">TweetDeck</a><a href="https://twitter.com/intent/tweet?in_reply_to=177085815682379777" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=177085815682379777" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=177085815682379777" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=anonops"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a0.twimg.com/profile_images/1852746447/anonops_normal.png" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=anonops">@anonops</a>
<div style="margin:0; padding-top:2px">AnonOps</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
<p>Hammond, the one in Chicago, was said to be the one who led the <a href="http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/">hack against the private intelligence company Stratfor</a>. He was profiled by Chicago Magazine in 2007 and portrayed as something of a <a href="http://www.chicagomag.com/Chicago-Magazine/July-2007/The-Hacktivist/">digital Robin Hood</a>.</p>
<p>Ackroyd is said to be the one who found the weaknesses in the servers of the U.S. Senate that led to its <a href="http://allthingsd.com/20110613/lulzsec-strikes-again-hits-bethesda-softworks-and-u-s-senate/">being attacked in June</a>. Hacking federal computer systems is considered a serious crime in the U.S., but is something that LulzSec said, in the posting to Pastebin at the time, that they carried out &#8220;just for kicks.&#8221;</p>
<p><strong>Update:</strong> So the US Attorney&#8217;s Office in New York has issued its press release confirming most of what Fox reported. Here it is.</p>
<blockquote class="memo"><p>Six Hackers in the United States and Abroad Charged for Crimes Affecting Over One Million Victims</p>
<p>Four Principal Members of “Anonymous” and “LulzSec” Charged with Computer Hacking and Fifth Member Pleads Guilty; “AntiSec” Member also Charged with Stealing Confidential Information from Approximately 860,000 Clients and Subscribers of Stratfor</p>
<p>U.S. Attorney’s Office March 06, 2012 	</p>
<p>Five computer hackers in the United States and abroad were charged today, and a sixth pled guilty, for computer hacking and other crimes. The six hackers identified themselves as aligned with the group Anonymous, which is a loose confederation of computer hackers and others, and/or offshoot groups related to Anonymous, including “Internet Feds,” “LulzSec,” and “AntiSec.”</p>
<p>RYAN ACKROYD, a/k/a “kayla,” a/k/a “lol,” a/k/a “lolspoon”; JAKE DAVIS, a/k/a “topiary,” a/k/a “atopiary”; DARREN MARTYN, a/k/a “pwnsauce,” a/k/a “raepsauce,” a/k/a “networkkitten”; and DONNCHA O’CEARRBHAIL, a/k/a “palladium,” who identified themselves as members of Anonymous, Internet Feds, and/or LulzSec, were charged in an indictment unsealed today in Manhattan federal court with computer hacking conspiracy involving the hacks of Fox Broadcasting Company, Sony Pictures Entertainment, and the Public Broadcasting Service (“PBS”). O’CEARRBHAIL is also charged in a separate criminal complaint with intentionally disclosing an unlawfully intercepted wire communication.</p>
<p>HECTOR XAVIER MONSEGUR, a/k/a “Sabu,” a/k/a “Xavier DeLeon,” a/k/a “Leon,” who also identified himself as a member of Anonymous, Internet Feds, and LulzSec, pled guilty on August 15, 2011 in U.S. District Court to a 12-count information charging him with computer hacking conspiracies and other crimes. MONSEGUR’S information and guilty plea were unsealed today. The crimes to which MONSEGUR pled guilty include computer hacking conspiracy charges initially filed in the Southern District of New York. He also pled guilty to the following charges: a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of California related to the hacks of HBGary, Inc. and HBGary Federal LLC; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Central District of California related to the hack of Sony Pictures Entertainment and Fox Broadcasting Company; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Northern District of Georgia related to the hack of Infragard Members Alliance; and a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of Virginia related to the hack of PBS, all of which were transferred to the Southern District of New York, pursuant to Rule 20 of the Federal Rules of Criminal Procedure, in coordination with the Computer Crime and Intellectual Property Section (“CCIPS”) in the Justice Department’s Criminal Division.</p>
<p>Late yesterday, JEREMY HAMMOND, a/k/a “Anarchaos,” a/k/a “sup_g,” a/k/a “burn,” a/k/a “yohoho,” a/k/a “POW,” a/k/a “tylerknowsthis,” a/k/a “crediblethreat,” who identified himself as a member of AntiSec, was arrested in Chicago, Illinois and charged in a criminal complaint with crimes relating to the December 2011 hack of Strategic Forecasting, Inc. (“Stratfor”), a global intelligence firm in Austin, Texas, which may have affected approximately 860,000 victims. In publicizing the Stratfor hack, members of AntiSec reaffirmed their connection to Anonymous and other related groups, including LulzSec. For example, AntiSec members published a document with links to the stolen Stratfor data titled, “Anonymous Lulzxmas rooting you proud” on a file sharing website.</p>
<p>The following allegations are based on the indictment, the information, the complaints, and statements made at MONSEGUR’s guilty plea:</p>
<p>Hacks by Anonymous, Internet Feds, and LulzSec</p>
<p>Since at least 2008, Anonymous has been a loose confederation of computer hackers and others. MONSEGUR and other members of Anonymous took responsibility for a number of cyber attacks between December 2010 and June 2011, including denial of service (“DoS”) attacks against the websites of Visa, MasterCard, and PayPal, as retaliation for the refusal of these companies to process donations to Wikileaks, as well as hacks or DoS attacks on foreign government computer systems.</p>
<p>Between December 2010 and May 2011, members of Internet Feds similarly waged a deliberate campaign of online destruction, intimidation, and criminality. Members of Internet Feds engaged in a series of cyber attacks that included breaking into computer systems, stealing confidential information, publicly disclosing stolen confidential information, hijacking victims’ e-mail and Twitter accounts, and defacing victims’ Internet websites. Specifically, ACKROYD, DAVIS, MARTYN, O’CEARRBHAIL, and MONSEGUR, as members of InternetFeds, conspired to commit computer hacks including: the hack of the website of Fine Gael, a political party in Ireland; the hack of computer systems used by security firms HBGary, Inc. and its affiliate HBGary Federal, LLC, from which Internet Feds stole confidential data pertaining to 80,000 user accounts; and the hack of computer systems used by Fox Broadcasting Company, from which Internet Feds stole confidential data relating to more than 70,000 potential contestants on “X-Factor,” a Fox television show.</p>
<p>In May 2011, following the publicity that they had generated as a result of their hacks, including those of Fine Gael and HBGary, ACKROYD, DAVIS, MARTYN, and MONSEGUR formed and became the principal members of a new hacking group called “Lulz Security” or “LulzSec.” Like Internet Feds, LulzSec undertook a campaign of malicious cyber assaults on the websites and computer systems of various business and governmental entities in the United States and throughout the world. Specifically, ACKROYD, DAVIS, MARTYN, and MONSEGUR, as members of LulzSec, conspired to commit computer hacks including the hacks of computer systems used by the PBS, in retaliation for what LulzSec perceived to be unfavorable news coverage in an episode of the news program “Frontline”; Sony Pictures Entertainment, in which LulzSec stole confidential data concerning approximately 100,000 users of Sony’s website; and Bethesda Softworks, a video game company based in Maryland, in which LulzSec stole confidential information for approximately 200,000 users of Bethesda’s website.</p>
<p>The Stratfor Hack</p>
<p>In December 2011, HAMMOND conspired to hack into computer systems used by Stratfor, a private firm that provides governments and others with independent geopolitical analysis. HAMMOND and his co-conspirators, as members of AntiSec, stole confidential information from those computer systems, including Stratfor employees’ e-mails as well as account information for approximately 860,000 Stratfor subscribers or clients. HAMMOND and his co-conspirators stole credit card information for approximately 60,000 credit card users and used some of the stolen data to make unauthorized charges exceeding $700,000. HAMMOND and his co-conspirators also publicly disclosed some of the confidential information they had stolen.</p>
<p>The Hack of International Law Enforcement</p>
<p>In January 2012, O’CEARRBHAIL hacked into the personal e-mail account of an officer with Ireland’s national police service, the An Garda Siochana (the “Garda”). Because the Garda officer had forwarded work e-mails to a personal account, O’CEARRBHAIL learned information about how to access a conference call that the Garda, the FBI, and other law enforcement agencies were planning to hold on January 17, 2012 regarding international investigations of Anonymous and other hacking groups. O’CEARRBHAIL then accessed and secretly recorded the January 17 international law enforcement conference call, and then disseminated the illegally-obtained recording to others.</p>
<p>***</p>
<p>MONSEGUR, 28, of New York, New York, pled guilty to three counts of computer hacking conspiracy, five counts of computer hacking, one count of computer hacking in furtherance of fraud, one count of conspiracy to commit access device fraud, one count of conspiracy to commit bank fraud, and one count of aggravated identity theft. He faces a maximum sentence of 124 years and six months in prison.</p>
<p>ACKROYD, 23, of Doncaster, United Kingdom; DAVIS, 29, of Lerwick, Shetland Islands, United Kingdom; and MARTYN, 25, of Galway, Ireland, each are charged with two counts of computer hacking conspiracy. Each conspiracy count carries a maximum sentence of 10 years in prison.</p>
<p>O’CEARRBHAIL, 19, of Birr, Ireland, is charged in the indictment with one count of computer hacking conspiracy, for which he faces 10 years in prison. He is also charged in the complaint with one count of intentionally disclosing an unlawfully intercepted wire communication, for which he faces a maximum sentence of five years in prison.</p>
<p>HAMMOND, 27, of Chicago, Illinois, is charged with one count of computer hacking conspiracy, one count of computer hacking, and one count of conspiracy to commit access device fraud. Each count carries a maximum sentence of 10 years in prison.</p>
<p>DAVIS is separately facing criminal charges in the United Kingdom, which remain pending, and ACKROYD is being interviewed today by the Police Central e-crime Unit in the United Kingdom. O’CEARRBHAIL was arrested today by the Garda.</p>
<p>The case is being prosecuted by the U.S. Attorney’s Office for the Southern District of New York. The investigation was initiated and led by the FBI, and its New York Cyber Crime Task Force, which is a federal, state, and local law enforcement task force combating cybercrime, with assistance from the PCeU; a unit of New Scotland Yard’s Specialist Crime Directorate, SCD6; the Garda; the Criminal Division’s CCIPS; and the U.S. Attorneys’ Offices for the Eastern District of California, the Central District of California, the Northern District of Georgia, and the Eastern District of Virginia; as well as the Criminal Division’s Office of International Affairs.</p>
<p>The charges contained in the indictment and complaints are merely accusations, and the defendants are presumed innocent unless and until proven guilty.</p></blockquote>
<p>And here&#8217;s the initial indictment on Hector Monsegur, initially filed in the US District Court for the Southern District of New York in August of last year. I&#8217;m gathering up documents on the other people charged in this and will share it as I get it.</p>
<p><a title="View Monsegur on Scribd" href="http://www.scribd.com/doc/84148479/Monsegur" style="margin: 12px auto 6px auto; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;">Monsegur</a><iframe class="scribd_iframe_embed" src="http://www.scribd.com/embeds/84148479/content?start_page=1&#038;view_mode=list&#038;access_key=key-1p9z0laafqzn0jrz0gg" data-auto-height="true" data-aspect-ratio="0.772727272727273" scrolling="no" id="doc_3469" width="100%" height="600" frameborder="0"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120306/not-lulzing-anymore-five-hackers-charged-in-us-uk-and-ireland/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>James Murdoch Leaves News Corp. Publishing Unit</title>
		<link>http://allthingsd.com/20120229/james-murdoch-leaves-news-corp-publishing-unit/</link>
		<comments>http://allthingsd.com/20120229/james-murdoch-leaves-news-corp-publishing-unit/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 14:16:03 +0000</pubDate>
		<dc:creator>Peter Kafka</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Chase Carey]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[James]]></category>
		<category><![CDATA[James Murdoch]]></category>
		<category><![CDATA[News Corp.]]></category>
		<category><![CDATA[phonegate]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[Rupert Murdoch]]></category>
		<category><![CDATA[Tom Mockridge]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=179228</guid>
		<description><![CDATA[More fallout from PhoneGate: News Corp. executive James Murdoch has "relinquished his position" as executive chairman head of News International, the conglomerate's British newspaper unit. News Corp., which also owns this Web site, says News International chief executive Tom Mockridge will stay on and report to News Corp. chief operating officer Chase Carey. James Murdoch "will continue to assume a variety of essential corporate leadership mandates, with particular focus on important pay-TV businesses and broader international operations," according to his father, News Corp. CEO Rupert Murdoch.]]></description>
			<content:encoded><![CDATA[<p>More fallout from PhoneGate: News Corp. executive James Murdoch has &#8220;relinquished his position&#8221; as executive chairman head of News International, the conglomerate&#8217;s British newspaper unit. News Corp., which also owns this Web site, says News International chief executive Tom Mockridge will stay on and report to News Corp. chief operating officer Chase Carey. James Murdoch &#8220;will continue to assume a variety of essential corporate leadership mandates, with particular focus on important pay-TV businesses and broader international operations,&#8221; according to his father, News Corp. CEO Rupert Murdoch.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120229/james-murdoch-leaves-news-corp-publishing-unit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Anonymous</title>
		<link>http://allthingsd.com/20120227/hackers-anonymous/</link>
		<comments>http://allthingsd.com/20120227/hackers-anonymous/#comments</comments>
		<pubDate>Tue, 28 Feb 2012 07:59:12 +0000</pubDate>
		<dc:creator>Eric Johnson</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[cole stryker]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacktivism]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=178627</guid>
		<description><![CDATA[Anonymous is a handful of geniuses surrounded by a legion of idiots. &#8211; Cole Stryker, an author who has researched the hacker group]]></description>
			<content:encoded><![CDATA[<blockquote><p>Anonymous is a handful of geniuses surrounded by a legion of idiots.</p></blockquote>
<p class="attribution">&#8211; <a href="http://www.nytimes.com/2012/02/27/technology/attack-on-vatican-web-site-offers-view-of-hacker-groups-tactics.html?_r=1&#038;pagewanted=all">Cole Stryker</a>, an author who has researched the hacker group</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120227/hackers-anonymous/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Seven Questions for RSA Security Head Art Coviello</title>
		<link>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/</link>
		<comments>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 14:50:39 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[analytics]]></category>
		<category><![CDATA[Art Coviello]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[intelligence]]></category>
		<category><![CDATA[Lockheed Martin]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=178287</guid>
		<description><![CDATA[A year after an attack on its widely used security system, the head of RSA Security talks about lessons learned and what the computer security industry needs to do next.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/coviello-rsa/" rel="attachment wp-att-178294"><img src="http://allthingsd.com/files/2012/02/coviello-rsa-380x285.png" alt="" title="coviello-rsa" width="380" height="285" class="alignright size-Featured wp-image-178294" /></a>It&#8217;s been almost a year since the security company RSA disclosed that it had come under what it described as an &#8220;<a href="http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/">extremely sophisticated</a>&#8221; cyberattack.</p>
<p>It went on to explain <a href="http://allthingsd.com/20110404/rsa-explains-how-it-was-hacked/">some of the circumstances </a> of the attack, a little bit about what data was taken, and then later conceded that at least some of that  information was used to launch an ultimately unsuccessful attack <a href="http://allthingsd.com/20110527/lockheed-martin-network-disrupted-rsa-tokens-reportedly-involved/">against the defense contractor Lockheed Martin</a>.</p>
<p>Last year was a tough one for RSA. Its security tokens, which generate six-digit numbers that act as a second constantly-changing password to help keep intruders out of sensitive computer systems, are the backbone of the security systems of many companies and government agencies.</p>
<p>Art Coviello, the onetime CEO of RSA and now executive vice president of its parent EMC, will be giving a keynote address tomorrow at the annual RSA Security Conference in San Francisco. I thought it might be a good chance to talk with him about the legacy of the attack on RSA, see if there was anything new he could share about what was learned about the attack, and how what happened is shaping RSA&#8217;s thinking about the computer security landscape.</p>
<p><strong>AllThingsD: Art, You&#8217;ll be speaking at RSA about a year after the infamous attack on your company. How are you approaching the speech, and what are you going to say?</strong></p>
<p><strong>Coviello</strong>: Part of what I&#8217;ll be talking about is the renewed sense of dedication we have to our mission, our responsibility to customers to regaining and maintaining their confidence. And also applying the lessons learned and sharing them vigorously, not only with our attack, but some of the other attacks that we have privileged insight into. And the bottom line is that we do hope, in the final analysis, that people have more of a sense of urgency in protecting themselves, because the truth of the matter is that we weren&#8217;t alone. The theme will be how security has to change from the kind of perimeter defenses that seemed to be dissolving even before our attack, to the requirement for more resilient security based on intelligence that you can get on a more real-time basis. So I&#8217;ll be outlining RSA&#8217;s vision for intelligence-driven security.</p>
<p>It will be a fairly strong call to action for the industry. We&#8217;ve had a great run in creating a trusted digital world, for all its weaknesses and idiosyncrasies. But as you see with trends like the consumerization of IT, we&#8217;ve never had a generation of employees and consumers that has been as technology-savvy as we have today, and in many instances they&#8217;re getting ahead of the enterprise IT organization&#8217;s ability to absorb the technologies they use day in and day out. And that puts an even bigger burden, from a security perspective, on IT organizations. And so they need to manage what they can&#8217;t directly control, and secure what they can&#8217;t directly control, and that means perimeters are nonexistent. So how do you get the intelligent controls you do have deployed more intelligently, so that even if things are out of reach, they&#8217;re not out of your ability to secure them? Our attack did not only raise awareness, but also the action level of people. </p>
<p><strong>The attack that RSA suffered last year caught a lot of people by surprise. For those who haven&#8217;t kept track, have there been any new disclosures or information disclosed since, or is there anything new that you&#8217;ve learned?</strong></p>
<p>No. And the funny part about it, as with all things in the press, if nothing bad happens, nothing gets written about. To date, there has been only one instance where it has been suggested that the information stolen from us has been used in another attack. And that was Lockheed Martin. And that attack was unsuccessful. There have been no other attacks, and believe me, we have stayed close with law enforcement and other sources, and have run down every one of these that has been reported, and there&#8217;s no substantiation of even another attempted attack, let alone a successful one. So we stand by the original decision we made in March, which was to announce that information had been stolen, to announce that you couldn&#8217;t launch a direct attack with the information stolen, and that if you took the remediation steps that we advised our clients to take, you&#8217;d be fine.</p>
<p>I think &#8212; and this is my theory &#8212; the attacker thought that they would be able to get in, steal the information they got from us without being caught, and then steal information from others, and combine them. And, quite frankly, because of our quick action in detecting that we were breached and some information stolen, we blew their cover. I can&#8217;t think of a reason to explain why they would go to all that trouble and you would only see one instance of a follow-up attack, and that one instance was stopped. And that got lost in all the coverage. </p>
<p><strong>The impression I got was that the attacker seemed to get that this was an attack that was only partially successful, and that whoever it was &#8212; the speculation was that it was China &#8212; they only got a little of what they had hoped to get, and once detected, the jig was up. Is that more or less how you see it?</strong></p>
<p>I couldn&#8217;t put it better than that. And we said that everything we saw pointed to a nation-state, but we never had the smoking gun to point to a particular country as the source of the attack.</p>
<p><strong>So then what happened after the attack was that, since a lot of people and companies and government agencies had put a lot of faith in the RSA dongles and your system to keep people out, there was a bit of a crisis with that faith.</strong></p>
<p>Totally true, let me step in here. That was one of the issues we had to wrestle with when the Lockheed incident happened. Because of the Lockheed thing, people thought we had to issue new tokens to everyone. That was not the case. We continued to stand by the remediation. But we had to recognize the angst and the perception among customers. And that is why we had to offer to replace the tokens. And sure, there were a number of customers who did, but the vast majority did not. No one likes the fact that it happened, but our concern right from day one was for the customers. The proof of the pudding is that our customers are still taking tokens. We&#8217;ve lost a negligible number of customers. And, in fact, we&#8217;ll be talking this week about some surveys showing that people are still buying tokens.</p>
<p><strong>So you say in your remarks you plan to talk about real-time security intelligence, which is something I&#8217;ve talked about <a href="http://allthingsd.com/20120221/big-blue-goes-big-on-it-security/">with IBM recently</a>. Is real-time intelligence the direction where the entire security industry has to go?</strong></p>
<p>First of all, the NetWitness &#8212; and this is another irony in all this &#8212; I signed the purchase and sale agreement to purchase NetWitness just a few days before the attack on RSA. And one of the reasons we bought it is that we had it deployed all across EMC. And we viewed it as being very effective in spotting anomalies in network traffic. So the issue today, especially with the porous perimeters that we have, is not whether or not you can or will be breached, because you can be breached. The issue is how fast can you spot it. </p>
<p>The Verizon data-breach report (<a href=http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2011_en_xg.pdf>PDF here</a>) says that more than 90 percent of exfiltrations occur within hours or days of the initial breach. But about 79 percent of breaches aren&#8217;t spotted until weeks after they occur. We were able to see the attack in progress, which is why we were able to minimize the information that did get out, and we were within a blink of an eye of stopping the attack altogether. And it was based on this NetWitness technology. But since we acquired it, we have been leveraging it to see not just movements of packets, but to combine with our (Security Event Management) product to not just log information, but ingest all kinds of contextual information. This is unprecedented in security technology and, frankly, IBM doesn&#8217;t have it. </p>
<p>And one of the things that I&#8217;ll be saying in the keynote is that the age of Big Data has arrived for security, and it has. It is a Big Data problem. If you&#8217;re going to be able to spot these attacks in real time and have a resilient security system, as opposed to one that breaks and doesn&#8217;t bend, which is what the perimeter defenses do today, then you have to have real-time analytical capability. Only today do we have the storage and analytical capability, and the ability to deploy it at scale. One disadvantage of the attackers is that they are not legitimate. There will always be something in how they get access, or what they do, that will allows us to find them out.</p>
<p><strong>The observation I made in talking with IBM last week is that there are so many new problems and threats emerging that it&#8217;s not only difficult to keep track of them, but it&#8217;s also hard to filter security vendors who offer conflicting visions and products they all say are a panacea. CIOs are getting confused, and are having a hard time calibrating their priorities. How do they find any clarity these days?</strong></p>
<p>Let me read a line from my keynote: We have to stop being linear thinkers, blindly adding controls on top of failed models. It&#8217;s the model itself that is broken. If a vendor is coming to you, saying, &#8220;I&#8217;ve got this new control, just add it to this uncoordinated silo of controls that already exist,&#8221; then they are not doing you much of a service. What we&#8217;re advocating is that people double down on some of the qualitative things that have nothing do with technology. So the first element of having what we call an intelligence-driven security system is doing a better job of assessing and managing risk. And I&#8217;m going to put a challenge out to the audience, and I&#8217;m going to say that no one does this meaningfully, and no one does it well.</p>
<p><strong>So what needs to change?</strong></p>
<p>When I talk about understanding the threats outside-in, as well as inside-out, what I mean is not only understanding what your material assets are, but marrying that knowledge to an understanding of who might attack you, how they might come at you. The next step is getting leverage from the controls that you have. You have to disinvest in some. Let&#8217;s face it, 10 or 12 years ago, antivirus signatures numbered in the tens of thousands. Now they number in the tens of millions. How can that make any sense? As soon as you have a signature, someone has a new virus to overcome it. It&#8217;s these static models that don&#8217;t bend, but break, that have to change. The controls that we have have to be more intelligent.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120227/seven-questions-for-rsa-security-head-art-coviello/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous Fails, Once Again, to Make Its Point</title>
		<link>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/</link>
		<comments>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 21:58:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Ann Coulter]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[Bill O'Reilly]]></category>
		<category><![CDATA[chat rooms]]></category>
		<category><![CDATA[Church of Scientology]]></category>
		<category><![CDATA[computer crime]]></category>
		<category><![CDATA[distributed denial of service attacks]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[jail]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[Megaupload]]></category>
		<category><![CDATA[Megaupload.com]]></category>
		<category><![CDATA[MPAA]]></category>
		<category><![CDATA[New Jersey]]></category>
		<category><![CDATA[Ohio]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[prison]]></category>
		<category><![CDATA[PROTECT IP Act]]></category>
		<category><![CDATA[RIAA]]></category>
		<category><![CDATA[Rudolph Giuliani]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SOPA]]></category>
		<category><![CDATA[Stop Online Piracy Act]]></category>
		<category><![CDATA[Sweden]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[U. S. House of Representatives]]></category>
		<category><![CDATA[U.S. Department of Justice]]></category>
		<category><![CDATA[U.S. Senate]]></category>
		<category><![CDATA[United Kingdom]]></category>
		<category><![CDATA[Universal Music Group]]></category>
		<category><![CDATA[US Federal LAw]]></category>
		<category><![CDATA[Washington D.C.]]></category>
		<category><![CDATA[Wikileaks]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=165909</guid>
		<description><![CDATA[Big as they were, the attacks carried out in revenge for the Megaupload arrests accomplished nothing significant.]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_166097" class="wp-caption alignright" style="width: 390px"><img src="http://allthingsd.com/files/2012/01/anonymous_cleanup.png" alt="" title="anonymous_cleanup" width="380" height="284" class="size-full wp-image-166097" /><span class="media-attribution">AllThingsD.com</span><p class="wp-caption-text"> </p></div>The world seemed awfully impressed yesterday with the size and oomph of the revenge attacks carried out online in reaction to the arrests of four people associated with the file-sharing site Megaupload.com. </p>
<p>Yet now that the attacks have subsided, it&#8217;s time to see them for what they are: Nothing more than a blunt instrument that accomplishes nothing constructive.</p>
<p>As of today, only one of the Web sites attacked by the hacker troupe Anonymous is still apparently affected, and that belongs to the <a href="http://www.universalmusic.com/">Universal Music Group</a> recording label. It currently displays only a message saying &#8220;The Site is under maintenance. Please expect it to be back shortly.&#8221; Others that had been attacked yesterday, including the sites of the <a href="http://www.justice.gov/">U.S. Department of Justice</a>, the <a href="http://riaa.org/">Recording Industry Association of America</a> and the <a href="http://mpaa.org/">Motion Picture Association of America</a> all seemed to be operating normally.</p>
<p>Thursday&#8217;s attacks, which have been described as the biggest action yet organized by Anonymous, were launched in apparent revenge for the FBI&#8217;s arrest of several people associated with the file-sharing site <a href="http://allthingsd.com/20120119/fbi-charges-seven-with-online-piracy/">Megaupload.com</a> over suspicions of online piracy. Taking place against the backdrop of <a href="http://allthingsd.com/20120118/sound-bites-from-the-sopa-strike/">a wider, more civil protest</a> against anti-piracy legislation currently before the U.S. Congress, the atmosphere around the attacks has been politically charged.</p>
<p>As <a href="http://news.cnet.com/8301-31322_3-57362437-256/anonymous-goes-nuclear-everybody-loses/">Molly Wood of CNET put it</a>, the #OpMegaUpload attacks &#8212; coming as they did on the heels of Wednesday&#8217;s peaceful anti-SOPA protest &#8212; seem like an &#8220;unsettling wave of car-burning hooligans that sweep in and incite the riot portion of the play,&#8221; spurring equally unsettling reactions from the powers that be.</p>
<p>Many outlets have portrayed the attacks as &#8220;hacks,&#8221; implying that someone had picked a lock in order to commit some kind of sabotage. But the tactic used &#8212; a distributed denial-of-service (DDoS) attack &#8212; is more aptly compared to a blunt instrument, requiring neither skill nor knowledge, only large numbers of willing participants who team up to swarm a site with more requests than it can accommodate and thus overwhelm its ability to function normally.</p>
<p>The adjective &#8220;willing&#8221; is debatable, and perhaps inaccurate. Anonymous was able to generate such impressive numbers with the operation &#8212; it claimed more than 5,000 participants &#8212; by spamming a link in chat rooms and via Twitter that, when clicked, triggered a tool used to launch the attack. People tricked into following the link are given no context or information, and so may or may not have any idea that they&#8217;re participating in the execution of a crime.</p>
<p>For the record, it is illegal in the U.S., the U.K., Sweden and other countries to launch and participate in a DDoS attack like the one Anonymous organized. As anyone who has observed the evolution of Anonymous (and its various affiliates using the names LulzSec and AntiSec) should know, the <a href="http://allthingsd.com/20110719/16-arrested-in-nationwide-hacker-crackdown/">FBI arrested 16 people last July</a>, many of them charged with participating in a DDoS attack against PayPal in protest of its <a href="http://allthingsd.com/20101204/paypal-to-wikileaks-youre-cut-off/">shutting down an account used by WikiLeaks</a>. </p>
<p>In 2009, a New Jersey man was sentenced to a <a href="http://nakedsecurity.sophos.com/2009/11/20/scientology-website-attacker-jail/">year and a day in prison</a> for launching a DDoS attack against the Church of Scientology. And in 2010, a 23-year-old Ohio man was sentenced to 30 months in prison for launching DDoS attacks against several prominent U.S. conservatives, including the author Ann Coulter, former New York City mayor Rudolph Giuliani and Fox News commentator Bill O&#8217;Reilly.</p>
<p>Records like that suggest to me that DDoS attacks never accomplish anything that the people who organize and carry them out attempt to do. At most, they inconvenience the people who visit and operate the targeted sites for a few hours, until the attention spans of the attackers shift elsewhere. They also generate headlines that are forgotten by nearly everyone except the targets, and sometimes law enforcement. </p>
<p>And so it will be this time. Mark your calendars, because the Megaupload revenge attacks will spur a series of arrests later this year. Some of those arrested will be people who didn&#8217;t know they were committing a crime. And that certainly won&#8217;t help Anonymous&#8217; image. Nor will it further a single bit of what passes for the Anonymous agenda.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Scary Was the Internet in 2011?</title>
		<link>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/</link>
		<comments>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 23:22:39 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[Duqu]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Kaspersky Labs]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[PLC]]></category>
		<category><![CDATA[sabotage]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sony]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=158718</guid>
		<description><![CDATA[How scary was the Internet in 2011? It depends on what you consider scary. News of attacks, some silly, some downright chilling, created uneasiness all year.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/hackingexposed-242x300-2/" rel="attachment wp-att-158729"><img src="http://allthingsd.com/files/2012/01/hackingexposed-242x3001-242x285.png" alt="" title="hackingexposed-242x300" width="242" height="285" class="alignright size-Featured wp-image-158729" /></a>With 2011 in the books, I thought it would be interesting to revisit some predictions I made last year on the subject of computer security. In &#8220;<a href="http://allthingsd.com/20101230/2010-was-the-year-the-internet-got-scary-get-used-to-it/">2010 Was the Year the Internet Got Scary. Get Used to It.</a>&#8221; I looked at a string of events on the computer security landscape during the prior year and thought about what they meant for the year ahead.</p>
<p>I wrote then: </p>
<blockquote class="memo"><p>
&#8220;The unvarnished fact is that the networked society to which we’ve become accustomed in the last several years has a soft, vulnerable underbelly. </p>
<p>And the more we rely upon it, the more people with a combination of advanced technical skills and repugnant motivations are going to look for ways to turn it against us.</p>
<p>Some will do so as a means of making a personal profit. Others may see it as a way of advancing a political or ideological agenda.</p>
<p>But others will want to use theirs skills to do serious harm to innocent people on a large scale.&#8221;</p></blockquote>
<p>Part of these predictions or ruminations or whatever you care to call them makes me think of the hijinks of the group that started out in the spring variously known as LulzSec, Anonymous and later adopted the moniker AntiSec. This loosely affiliated group emerged from the wake of the various attacks against Sony, and seemed to have nothing to prove but that it could make mincemeat out of whatever security measures had been put in place <a href="http://allthingsd.com/20110604/sony-hacked-for-what-seems-to-be-the-umpteenth-time/">by Sony </a>or whatever <a href="http://allthingsd.com/20110605/lulzsec-strikes-again-claims-attack-on-nintendo-server/">video game outfit</a> it had targeted on a given day.</p>
<p>Sony&#8217;s Playstation Network was a favorite target, and its service was <a href="http://allthingsd.com/20110705/sony-to-finally-complete-restoration-of-playstation-services-after-attacks/">at least partially offline</a> during two months ended in July. </p>
<p>Then, as summer dawned, the group&#8217;s members became aware of global politics and <a href="http://allthingsd.com/20110620/lulzsec-and-anonymous-team-up-to-hack-governments-and-banks/">teamed up with Anonymous</a>, the Wikileaks-allied band of hackers known for their campaigns of digital civil disobedience. Together they declared &#8220;immediate and unremitting war&#8221; on governments and corporations, and said their top priority would be to steal and leak any classified government information, including but not limited to email and documentation. They <a href="http://allthingsd.com/20110623/lulzsec-goes-all-wikileaks-on-arizona-state-cops/">attacked an Arizona police agency</a> as a way of making a statement against anti-immigrant laws in that state, and <a href="http://allthingsd.com/20110624/arizona-confirms-lulzsec-docs-are-authentic-worries-about-officer-safety/">published the names and home addresses</a> of several officers.</p>
<p>Later they sought to earn some street cred by stealing &#8220;secret&#8221; documents from NATO, only to learn after the fact that the documents they released had not only been released before, but <a href="http://allthingsd.com/20110721/anonymous-hacks-nato-steals-lame-documents/">weren&#8217;t even really all that secret</a> to begin with. It wasn&#8217;t long before alleged members of the group started showing up <a href="http://allthingsd.com/20110801/uk-police-say-this-is-the-face-of-lulzsec-hacker-known-as-topiary/">in handcuffs</a>, which seemed not to faze them. The prospect of body bags and real-world violence during a <a href="http://allthingsd.com/20111102/facing-real-world-violence-anonymous-backs-down-against-drug-cartel/">confrontation with Mexican drug cartels</a>, however, did.</p>
<p>Yet for all the headlines they garnered and the headaches they caused, the LulzSec/Anonymous/AntiSec gang wasn&#8217;t anywhere near the scariest thing to appear on the computer security landscape in 2011. To my mind, one of the top three scariest things was the disclosure of Operation Shady RAT, which Intel-unit McAfee said appeared to be the <a href="http://allthingsd.com/20110803/operation-shady-rat-the-biggest-hacking-attack-ever/">biggest large-scale compromise ever</a>, affecting 72 organizations and governments around the world, including the U.S., Taiwan, Vietnam, South Korea, Canada and India — some of them dating back as far as 2006. McAfee said the attacker was a &#8220;state actor,&#8221; though it declined to name it. The candidate highest on the short list was, naturally, China.</p>
<p>The second truly scary incident was the attack carried out <a href="http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/">against RSA Security</a>, a unit of the IT company EMC, the maker of the popular SecurID tokens that so many people have on their keychains and use to create an added layer of security that goes beyond the password. Months later, the U.S. defense contractor Lockheed Martin was <a href="http://allthingsd.com/20110528/lockheed-martin-confirms-it-came-under-attack/">attacked with duplicate SecurID</a> tokens.</p>
<p>Finally, the Stuxnet Trojan (used by parties officially unknown, but probably Israel with a little help from the U.S.) continued to fascinate and confound security researchers in 2011. Having caused nuclear centrifuges in Iran to explode in an attempt to set back that country&#8217;s nuclear weapons research program, Stuxnet was found to have a sibling called Duqu. Unlike Stuxnet, which messed with industrial control computers and made them do things they wouldn&#8217;t normally do, Duqu&#8217;s mission was much simpler: <a href="http://www.kaspersky.com/about/press/duqu.aspx">Steal everything in sight</a>.</p>
<p>And after that, it was discovered by researchers at Kaspersky labs that Stuxnet and Duqu are part of an even bigger family, with at least three more siblings still undetected by researchers, and that all five were created by the <a href="http://www.reuters.com/article/2011/12/28/us-cybersecurity-stuxnet-idUSTRE7BR1EV20111228">same people and with the same tools</a>.  Chances are we&#8217;ll see at least a few of those final three in 2012, particularly as <a href="http://online.wsj.com/article/SB10001424052970204720204577132923798499772.html">tension with Iran heats up</a>.</p>
<p>So while there was much to consider scary happening on the Internet in 2011, I&#8217;m grateful for being wrong on one key prediction: That we didn&#8217;t see a significant computer attack used to physically harm innocent people on a large scale. That&#8217;s one prediction I hope to miss for years to come.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stratfor Hack Damage Report: 50,000 Credit Cards, 44,000 Passwords</title>
		<link>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/</link>
		<comments>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 22:10:00 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Stratfor]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=157427</guid>
		<description><![CDATA[Number of Lulz: Incalculable.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2011/07/anonymous_at_scientology_in_los_angeles-380x285.png" alt="" title="anonymous_at_scientology_in_los_angeles" width="380" height="285" class="alignright size-Featured wp-image-99962" />A few days after the private security think tank Stratfor disclosed that it had been the <a href="http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/">victim of a hacking attack</a>, apparently carried out by the loosely affiliated group Anonymous, the extent of the damage is becoming clear.</p>
<p>Identity Finder, a New York-based identity theft protection firm, has analyzed the information breached and summarized what the attackers appear to have made off with.</p>
<blockquote class="memo">
<ul>
<li>50,277 unique credit card numbers, of which 9,651 are <em>not</em> expired<br />
<LI>86,594 email addresses, of which 47,680 are unique<br />
<LI>27,537 phone numbers, of which 25,680 are unique</p>
<li>44,188 encrypted passwords, of which roughly 50 percent could be easily cracked
<li>73.7 percent of decrypted passwords were weak
<li>21.7 percent of decrypted passwords were medium strength
<li>4.6 percent of decrypted passwords were strong
<li>Average decrypted password length: 7.1 characters
<li>10 percent of decrypted passwords were less than 5 characters long
<li>Only 4.8 percent of decrypted passwords were 10+ characters long
<li>Presumably the remaining non-decrypted passwords were stronger than the decrypted subset
<li>13,973 of the addresses belonged to United States victims; the remainder belonged to individuals from around the world</ul>
</blockquote>
<p>There are also an additional 2.7 million email messages that the attackers claim to have taken, but that have not yet been released.</p>
<p>Stratfor has promised to inform the customers whose information was taken no later than Dec. 28, which is tomorrow. Anonymous, ever seeking to justify its actions in the name of some higher moral purpose, said in a tweet that Stratfor, which sells subscriptions to its intelligence analysis reports to government, law enforcement agencies and businesses, isn&#8217;t &#8220;the harmless company it tries to paint itself as,&#8221; and that the emails will show that.</p>
<p><!-- tweet id : 151731063918563329 --><br />
<style type="text/css">#bbpBox_151731063918563329 a { text-decoration:none; color:#99001a; }#bbpBox_151731063918563329 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_151731063918563329" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#131516; background-image:url(http://a1.twimg.com/images/themes/theme14/bg.gif);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">@<a href="http://twitter.com/intent/user?screen_name=techwriterjim" class="twitter-action">techwriterjim</a> It was conducted by <a href="http://twitter.com/search?q=%23Antisec" title="#Antisec">#Antisec</a>. Stratfor is not the &#8220;harmless company&#8221; it tries to paint itself as. You&#8217;ll see in those emails.</span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on December 27, 2011 11:27 am" href="http://twitter.com/#!/AnonymousIRC/status/151731063918563329" target="_blank">December 27, 2011 11:27 am</a> via <a href="http://code.google.com/p/qwit/" rel="nofollow" target="blank">Qwit</a><a href="https://twitter.com/intent/tweet?in_reply_to=151731063918563329" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=151731063918563329" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=151731063918563329" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=AnonymousIRC"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a1.twimg.com/profile_images/1554234337/anontopenyan_normal.png" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=AnonymousIRC">@AnonymousIRC</a>
<div style="margin:0; padding-top:2px">AnonymousIRC</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
<p>Whatever. Wired reported that someone who participated in the attack said that a total of four servers were breached, <a href="http://www.wired.com/threatlevel/2011/12/antisec-hits-private-intel-firm-million-of-docs-allegedly-lifted/">and the data on them wiped</a>. The question that then logically arises is this: What was a firm that&#8217;s ostensibly in the business of advising business and government clients on security doing about its own?</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intelligence Firm Gets Hacked, Maybe by Anonymous</title>
		<link>http://allthingsd.com/20111225/intelligence-firm-gets-hacked-maybe-by-anonymous/</link>
		<comments>http://allthingsd.com/20111225/intelligence-firm-gets-hacked-maybe-by-anonymous/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 06:41:09 +0000</pubDate>
		<dc:creator>Liz Gannes</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[Strator]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=156854</guid>
		<description><![CDATA[Influential international security research firm Stratfor Global Intelligence Service was hacked this weekend, with confidential client information posted online. While the attack itself has been confirmed, competing anonymous press releases argue over whether or not it was the work of civil disobedience collective Anonymous.]]></description>
			<content:encoded><![CDATA[<p>Influential international security research firm <a href="http://www.stratfor.com/">Stratfor Global Intelligence Service</a> was hacked this weekend, with confidential client information <a href="http://pastebin.com/bQ2YHDdw">posted online</a>. While the attack itself <a href="https://www.facebook.com/stratfor/posts/10150456077898429">has been confirmed</a>, competing anonymous <a href="http://pastebin.com/8yrwyNkt">press releases</a> argue over whether or not it was the work of civil disobedience collective Anonymous.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111225/intelligence-firm-gets-hacked-maybe-by-anonymous/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Today Is a Very Good Day to Update Java on Your Computer</title>
		<link>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/</link>
		<comments>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 13:45:03 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Bain Capital Ventures]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[HD Moore]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[Technology Crossover Ventures]]></category>
		<category><![CDATA[Tim McAdam]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=149758</guid>
		<description><![CDATA[A nasty security vulnerability in Java is likely to cause headaches at large companies with lots of PCs, because installing a fix takes a lot of time.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/javacrosshairs/" rel="attachment wp-att-149768"><img src="http://allthingsd.com/files/2011/12/javacrosshairs-348x285.png" alt="" title="javacrosshairs" width="348" height="285" class="alignright size-Featured wp-image-149768" /></a>Consider yourself warned: Today is a very good day to update the version of Java running on your computer. This applies to you whether you run Windows, Mac OS X or Linux. If you&#8217;ve noticed your machine suggesting that you update Java, do it right away.</p>
<p>The reason? A scary vulnerability in Java that was detected over the summer, and which Oracle has subsequently fixed, is being exploited by people who create the malware and crimeware that causes so many headaches for home users and corporate IT departments.</p>
<p>The risk is especially acute at large companies with big fleets of desktops and notebooks to manage. If you&#8217;re a home user, the patch is easy to install. But most employees don&#8217;t have administrative privileges on their work desktops or notebooks, so someone from the IT department has to come and install the patch for them. </p>
<p>That&#8217;s a big, time-consuming process, says HD Moore, chief security officer at Rapid7, a Cambridge, Mass-based company that specializes in helping companies stay ahead of new computer security vulnerabilities. He&#8217;s also the chief architect of <a href="http://metasploit.com/">Metasploit</a>, which Rapid7 owns. </p>
<p>One of the reasons this particular vulnerability is so bad is that even after it was detected and fixed, it wasn&#8217;t fully understood how dangerous it is, Moore says. Crimeware creators somehow figured it out ahead of most security researchers, and started adding code to Web sites designed to take advantage of it. And that&#8217;s especially dangerous at this time of the year, when people are shopping online both at home and the office. &#8220;It&#8217;s kind of like a perfect storm,&#8221; Moore told me yesterday. Add to that the fact that many companies have IT staff taking vacation during the holiday season, and the timing couldn&#8217;t be worse.</p>
<p>Enterprise is historically bad at patching Java vulnerabilities anyway, because it doesn&#8217;t have the same automatic update tools that Windows or Adobe Flash does. &#8220;The tools for patching Java aren&#8217;t that great,&#8221; Moore told me. &#8220;A Java update just isn&#8217;t treated with the same fervor as a Windows update.&#8221;</p>
<p>So how bad is this one? The National Vulnerability Database <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544">rates it a 10</a> out of 10 on the severity scale, and also rates it as &#8220;low&#8221; on the access complexity scale &#8212; meaning it&#8217;s really easy for the bad guys to carry out an attack using it.</p>
<p>Security blogger Brian Krebs discovered the vulnerability <a href="http://krebsonsecurity.com/2011/11/new-java-attack-rolled-into-exploit-kits/">being &#8220;weaponized,&#8221;</a> that is, built into the software that computer criminals buy on the black market. For instance, those who have bought something called the Blackhole Exploit Kit, a $4,000 software toolkit used to target Windows machines, are getting automatic updates that include tools to take advantage of the Java vulnerability.</p>
<p>What to do until you can get all your machines updated with the latest version of Java? Simple, really: Disable it and block it at the firewall, until all the machines on the network that need the update have it, Moore says. </p>
<p>Rapid7, incidentally, is a security company on the rise. Just last month it raised a <a href="http://www.rapid7.com/news-events/press-releases/2011/2011-tcv-funding.jsp">$50 million series C round</a> of funding, led by Technology Crossover Ventures and joined by previous investors Bain Capital Ventures; Tim McAdam, a TCV partner, joined Rapid7&#8242;s board.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP Memo Spanks Columbia Researchers Over Flaming Printers Flap</title>
		<link>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/</link>
		<comments>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 19:45:26 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Columbia University]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hewlett-Packard]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[imaging and printing]]></category>
		<category><![CDATA[printers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[VJ Joshi]]></category>
		<category><![CDATA[Vyomesh (VJ) Joshi]]></category>
		<category><![CDATA[Vyomesh Joshi]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=148698</guid>
		<description><![CDATA[No, a hacked HP printer can't burn down your house or office, but HP has a fix in the works anyway.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2011/11/springsteen-fire-feature-380x285.png" alt="" title="springsteen-fire-feature" width="380" height="285" class="alignright size-Featured wp-image-148769" />Hewlett-Packard is still doing a little damage control from an <a href="http://redtape.msnbc.msn.com/_news/2011/11/29/9076395-exclusive-millions-of-printers-open-to-devastating-hack-attack-researchers-say">MSNBC story</a> that emerged yesterday citing researchers at Columbia University saying essentially that HP printers could be hacked in such a way as to make them burst into flames. HP has denied most of the claims.</p>
<p>Printers are Internet-connected devices just like computers. They have their own operating systems and software, and so, in theory, are vulnerable to attacks by hackers just as computers are. There was an old urban myth that in the run-up to the first Iraq War in 1991, hacked HP printers shipped to Iraq were instrumental in shutting down Iraqi radar systems. It wasn&#8217;t true &#8212; it was published on April 1 of that year by the trade magazine InfoWorld &#8212; but the idea stuck, and at least one group of security researchers <a href="http://www.infoworld.com/t/intrusion-detection-and-prevention/attack-the-trojan-printers-331">has been studying the use</a> of Trojans installed into printers.</p>
<p>The Columbia researchers had claimed that a part inside a printer called a fuser, used to dry the ink, could be remotely instructed to overheat, eventually causing paper inside the printer to turn brown and start to smoke. </p>
<p>Conceptually it&#8217;s not that different from the Stuxnet attack against the Iranian nuclear research program. The attackers in that case, thought to be Israel with a little help from the U.S., attacked industrial control computers known as SCADA systems that serve as the bridge between typical Windows-based machines and industrial equipment that the SCADA systems control. In the case of Stuxnet, the SCADA systems were controlled &#8212; often they have only default passwords or no passwords at all &#8212; and the machines they were connected to could be instructed to literally destroy themselves. </p>
<p>Some researchers at the U.S. Department of Energy&#8217;s Idaho National Lab did just that in the video below, showing in a controlled environment that a generator could be hijacked over the Internet and <a href="http://www.youtube.com/watch?v=fJyWngDco3g">made to destroy itself.</a></p>
<p>But could you do the same thing with a printer? Theoretically, I&#8217;d say it&#8217;s possible. But in this case, HP says not where its printers are concerned.  </p>
<p>Below is an internal HP memo from Vyomesh &#8220;VJ&#8221; Joshi, the head of HP&#8217;s Imaging and Printing Group, that was circulated to employees today.</p>
<p>First off, he says, the fire issue is not true. As noted in the public statement, HP&#8217;s printers have a component called a thermal breaker that prevents the fuser from overheating, and it can&#8217;t be overcome by a firmware upgrade.</p>
<p>But Joshi also spanks the Columbia researchers for turning to the media and not calling HP first, which is the way security researchers usually operate when they identify a serious vulnerability. There is, he concedes, a vulnerability to malicious firmware modifications, especially on printers that are left unprotected on a network without a firewall running. HP aims to fix that. But usually in these situations, the media doesn&#8217;t get called until a fix is ready. &#8220;Unfortunately in this situation, a Columbia representative took it upon himself to contact the media and reports were published prior to a solution being available,&#8221; he writes.</p>
<p>Joshi&#8217;s full memo is below.</p>
<blockquote class="memo"><p><strong>From: IPG, Vyomesh Joshi<br />
Sent: Tuesday, November 29, 2011 4:40 PM<br />
Subject: Inaccurate Printer Security Press Coverage</strong></p>
<p>Dear IPG Employees,</p>
<p>As many of you have read today there has been sensational and inaccurate press coverage regarding potential security risks with some HP LaserJet printers.  I wanted to make sure you had the most current information and context for this situation.  No customer has reported unauthorized access. We have also seen speculation in the media regarding the potential for devices to catch fire due to a firmware change.  This claim is inaccurate.  We have issued a <a href="http://www.hp.com/hpinfo/newsroom/press/2011/111129b.html">public statement</a> communicating to customers and partners and refuting inaccurate information.</p>
<p>This information first came to us late last week from a research lab based at Columbia University.  As a result, we have identified a specific vulnerability exists for some HP LaserJet devices if placed on a public internet without a firewall or if a malicious effort is made to modify the firmware of the device by a trusted party on the network. Our security team is taking immediate measures to build a firmware upgrade to resolve any potential risk and will be communicating this proactively to customers and partners who may be impacted.</p>
<p>Typically when a security issue is identified, responsible disclosure is followed so that vulnerabilities are not made public until a solution is available.  Unfortunately in this situation, a Columbia representative took it upon himself to contact the media and reports were published prior to a solution being available.</p>
<p>We have always taken security very seriously. In fact, HP’s reputation for security continues to be among the highest in the industry. I want to assure you that our security experts are working around the clock to mitigate any potential risk.</p>
<p>We will make every effort to communicate new information as it becomes available.</p>
<p>Regards,</p>
<p>VJ</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Surveillance Catalog</title>
		<link>http://allthingsd.com/20111119/the-surveillance-catalog/</link>
		<comments>http://allthingsd.com/20111119/the-surveillance-catalog/#comments</comments>
		<pubDate>Sat, 19 Nov 2011 12:00:30 +0000</pubDate>
		<dc:creator>Jennifer Valentino-DeVries, Jeremy Singer-Vine, Zachary M. Seward, Julia Angwin, Courtney Banks, Scott Thurm and Ashkan Soltani</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Ashkan Soltani]]></category>
		<category><![CDATA[Courtney Banks]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Jennifer Valentino-DeVries]]></category>
		<category><![CDATA[Jeremy Singer-Vine]]></category>
		<category><![CDATA[Julia Angwin]]></category>
		<category><![CDATA[Scott Thurm]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[Wall Street Journal]]></category>
		<category><![CDATA[Zachary M. Seward]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=145950</guid>
		<description><![CDATA[Documents obtained by The Wall Street Journal open a rare window into a new global market for the off-the-shelf surveillance technology that has arisen in the decade since the terrorist attacks of Sept. 11, 2001.]]></description>
			<content:encoded><![CDATA[<p>Documents obtained by The Wall Street Journal open a rare window into a new global market for the off-the-shelf surveillance technology that has arisen in the decade since the terrorist attacks of Sept. 11, 2001.</p>
<p>The techniques described in the trove of 200-plus marketing documents include hacking tools that enable governments to break into people’s computers and cellphones, and &#8220;massive intercept&#8221; gear that can gather all Internet communications in a country.</p>
<p><a href="http://projects.wsj.com/surveillance-catalog/">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111119/the-surveillance-catalog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>News Corp. Lawyer Noted Hacking "Culture" in 2008</title>
		<link>http://allthingsd.com/20111102/news-corp-lawyer-noted-hacking-culture-in-2008/</link>
		<comments>http://allthingsd.com/20111102/news-corp-lawyer-noted-hacking-culture-in-2008/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 13:30:25 +0000</pubDate>
		<dc:creator>Cassell Bryan-Low</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Cassell Bryan-Low]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[James Murdoch]]></category>
		<category><![CDATA[News Corp.]]></category>
		<category><![CDATA[News of the World]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=139315</guid>
		<description><![CDATA[Newly released documents show that an outside lawyer for News Corp. in 2008 warned of a "culture of illegal information access" at the company's News of the World newspaper, raising new questions about News Corp.'s longtime assertion that it was unaware of how widespread phone hacking was at the now-closed tabloid.]]></description>
			<content:encoded><![CDATA[<p>Newly released documents show that an outside lawyer for News Corp. in 2008 warned of a &#8220;culture of illegal information access&#8221; at the company&#8217;s News of the World newspaper, raising new questions about News Corp.&#8217;s longtime assertion that it was unaware of how widespread phone hacking was at the now-closed tabloid.</p>
<p>The lawyer&#8217;s opinion, and other documents released Tuesday by Parliament&#8217;s Culture, Sport and Media Committee, add to already mounting pressure on top News Corp. executives, including Deputy Chief Operating Officer James Murdoch, who has insisted he was in the dark about the extent of illegal reporting tactics at the time.</p>
<p><a href="http://online.wsj.com/article/SB10001424052970204528204577012153254681664.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111102/news-corp-lawyer-noted-hacking-culture-in-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Talking Science Fiction and Fact With Intel Futurist Brian David Johnson (Video)</title>
		<link>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/</link>
		<comments>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 22:51:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Brian David Johnson]]></category>
		<category><![CDATA[communicator]]></category>
		<category><![CDATA[computing]]></category>
		<category><![CDATA[Cory Doctorow]]></category>
		<category><![CDATA[futurist]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[mobile computing]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[science-fiction]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Star Trek]]></category>
		<category><![CDATA[the future.]]></category>
		<category><![CDATA[tricorder]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=132599</guid>
		<description><![CDATA[Science fiction makes it possible to have a conversation about the future, Johnson says, by giving us the metaphors we need to figure out what we want and don't want to happen.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/future-is-now/" rel="attachment wp-att-132616"><img src="http://allthingsd.com/files/2011/10/future-is-now-380x285.png" alt="" title="future-is-now" width="380" height="285" class="alignright size-Featured wp-image-132616" /></a><em>We are living in the future<br />
I&#8217;ll tell you how I know<br />
I read it in the paper<br />
Fifteen years ago*<br />
</em><br />
<object width="235" height="40"><param name="movie" value="http://grooveshark.com/songWidget.swf" /><param name="wmode" value="window" /><param name="allowScriptAccess" value="always" /><param name="flashvars" value="hostname=cowbell.grooveshark.com&#038;songIDs=25858106&#038;style=metal&#038;p=0" /><embed src="http://grooveshark.com/songWidget.swf" type="application/x-shockwave-flash" width="235" height="40" flashvars="hostname=cowbell.grooveshark.com&#038;songIDs=25858106&#038;style=metal&#038;p=0" allowScriptAccess="always" wmode="window" /></object></p>
<p>It&#8217;s been more than 30 years since my favorite American bard, John Prine, sang that lyric, and it came to mind as I sat down today to meet with Brian David Johnson, who is, to my recollection, the first person I&#8217;ve ever known to carry the job title &#8220;futurist.&#8221; And yes, it sounds a little specious, until you find out he works as a futurist for the chipmaker Intel, which certainly has a long-term strategic interest in anticipating the demands of the future well before they happen.</p>
<p>Johnson was a guest today on The Wall Street Journal&#8217;s &#8220;Digits&#8221; program, which I co-hosted with the Journal&#8217;s affable <a href="http://twitter.com/#!/simonconstable">Simon Constable</a>. Johnson is in New York to speak at Comic Con about Intel&#8217;s <a href="http://techresearch.intel.com/tomorrowproject.aspx">Tomorrow Project</a>, which aims to ask honestly what computing may be like 15 or 20 years from now &#8212; and the implications for our daily lives.</p>
<p>Think back to 1996 and you probably had some idea of what 2011 would be like. But did you really? You may have had a cellphone, but would you have imagined how much of your daily life would be punctuated by its use, beyond making phone calls? If you were to zap back in time and have a conversation with the 1996 you about life in 2011, you&#8217;d probably have to rely on science fiction to get the point across. &#8220;You know the <a href="http://en.wikipedia.org/wiki/Communicator_%28Star_Trek%29">communicator</a> and <a href="http://f4.aaa.livedoor.jp/~data/tng-MedicalTricorder.htm">tricorder</a> from &#8216;Star Trek&#8217;? Yeah, we basically have those. We call them smartphones, and they&#8217;re <a href="http://allthingsd.com/20111014/sprint-launch-of-iphone-4s-led-to-best-retail-day-ever/">kind of a big deal</a>,&#8221; the 2011 you might say. &#8220;And they&#8217;re also the <a href="http://allthingsd.com/20111011/the-iphone-finds-its-voice/">talking computers</a> from &#8216;Star Trek.&#8217; And you won&#8217;t believe <a href="http://allthingsd.com/20111005/smartphone-snapshot-still-a-two-horse-race/">who makes them</a>.&#8221;</p>
<p>Science fiction makes it possible, Johnson says, to have a conversation about the future, by giving us the metaphors we need to figure out what we want and don&#8217;t want to happen. Hence &#8220;The Tomorrow Project Anthology,&#8221; a collection of short stories set in the future, imagining plausible situations emerging from science fact of today. One volume of the anthology was published <a href="http://techresearch.intel.com/newsdetail.aspx?Id=30">earlier this year</a>, and a new one is out now. </p>
<p>What happens, on some hypothetical day in the future, when passwords are easily and readily hackable and all our personal information is more or less available for all the world to see and take and use? That&#8217;s what the writer Cory Doctorow asks in his story, &#8220;The Knights of the Rainbow Table,&#8221; which appears in the new volume.</p>
<p>So these are some of the things that Simon and I talked about with Johnson in today&#8217;s closing segment on &#8220;Digits,&#8221; which you can  see below. Enjoy.</p>
<p><object id="wsj_fp" width="512" height="363"><param name="movie" value="http://s.wsj.net/media/swf/VideoPlayerMain.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><param name="flashvars" value="videoGUID={D53A19FC-3901-4CB6-971C-868BA813C284}&#038;playerid=1000&#038;plyMediaEnabled=1&#038;configURL=http://wsj.vo.llnwd.net/o28/players/&#038;autoStart=false" base="http://s.wsj.net/media/swf/"name="flashPlayer"></param><embed src="http://s.wsj.net/media/swf/VideoPlayerMain.swf" bgcolor="#FFFFFF"flashVars="videoGUID={D53A19FC-3901-4CB6-971C-868BA813C284}&#038;playerid=1000&#038;plyMediaEnabled=1&#038;configURL=http://wsj.vo.llnwd.net/o28/players/&#038;autoStart=false" base="http://s.wsj.net/media/swf/" name="flashPlayer" width="512" height="363" seamlesstabbing="false" type="application/x-shockwave-flash" swLiveConnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object></p>
<p>*Lyrics from &#8220;Living in the Future,&#8221; by John Prine, from the 1980 album &#8220;Storm Windows.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stop Me Before I Hack Again</title>
		<link>http://allthingsd.com/20111013/stop-me-before-i-hack-again/</link>
		<comments>http://allthingsd.com/20111013/stop-me-before-i-hack-again/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 06:59:39 +0000</pubDate>
		<dc:creator>Voices</dc:creator>
				<category><![CDATA[Voices]]></category>
		<category><![CDATA[celebrity]]></category>
		<category><![CDATA[Christopher Chaney]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Scarlett Johansson]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=132305</guid>
		<description><![CDATA[It started as curiosity and it turned into just being addicted to what was going on behind the scenes … I was almost relieved when they came and took the computer. Christopher Chaney, the alleged &#8220;celeb hacker&#8221; who was arrested on charges of hacking the email accounts of Scarlett Johansson and other celebrities, said he [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>It started as curiosity and it turned into just being addicted to what was going on behind the scenes … I was almost relieved when they came and took the computer.</p></blockquote>
<p class="attribution"><a href="http://www.wired.com/threatlevel/2011/10/hacker-glad-he-got-caught/">Christopher Chaney, the alleged &#8220;celeb hacker&#8221;</a> who was arrested on charges of hacking the email accounts of Scarlett Johansson and other celebrities, said he was glad he got caught because he didn&#8217;t know how to stop.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111013/stop-me-before-i-hack-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony Finds Unauthorized Sign-In Attempts on PlayStation Network</title>
		<link>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/</link>
		<comments>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 14:44:10 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[PlayStation Network]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=131493</guid>
		<description><![CDATA[In a setback to its efforts to reestablish a reputation for online security, Sony said Wednesday it has found a "large amount" of unauthorized sign-in attempts on its PlayStation Network and other online entertainment services, forcing the temporary suspension of about 93,000 user accounts. The Japanese electronics and entertainment giant said in a statement that credit card details for those user accounts are "not at risk."]]></description>
			<content:encoded><![CDATA[<p>In a setback to its efforts to reestablish a reputation for online security, Sony said Wednesday it has found a &#8220;large amount&#8221; of unauthorized <a href="http://online.wsj.com/article/SB10001424052970203633104576625971976475508.html">sign-in attempts</a> on its PlayStation Network and other online entertainment services, forcing the temporary suspension of about 93,000 user accounts. The Japanese electronics and entertainment giant said in a statement that credit card details for those user accounts are &#8220;not at risk.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>News Corp. Unit to Pay $4.7 Million Tied to Dowler Hack</title>
		<link>http://allthingsd.com/20110919/news-corp-unit-to-pay-4-7-million-tied-to-dowler-hack/</link>
		<comments>http://allthingsd.com/20110919/news-corp-unit-to-pay-4-7-million-tied-to-dowler-hack/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 18:25:00 +0000</pubDate>
		<dc:creator>Cassell Bryan-Low</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Dowler]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[News Corp.]]></category>
		<category><![CDATA[News International]]></category>
		<category><![CDATA[News of the World]]></category>
		<category><![CDATA[phone hacking]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=122110</guid>
		<description><![CDATA[News Corp.'s U.K. newspaper unit has agreed to pay about £3 million ($4.7 million) tied to recent allegations that its News of the World tabloid hacked the phone of a murdered teenage girl in 2002, according to a person familiar with the matter.]]></description>
			<content:encoded><![CDATA[<p>News Corp.&#8217;s U.K. newspaper unit has agreed to pay about £3 million ($4.7 million) tied to recent allegations that its News of the World tabloid hacked the phone of a murdered teenage girl in 2002, according to a person familiar with the matter.</p>
<p>The media giant&#8217;s News International unit has agreed to pay roughly £2 million to the Dowler family and about £1 million to a charity, the person added. Unlike dozens of other alleged phone-hacking victims, the Dowler family hasn&#8217;t filed a lawsuit against the company.</p>
<p><a href="http://online.wsj.com/article/SB10001424053111904194604576580813144073454.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110919/news-corp-unit-to-pay-4-7-million-tied-to-dowler-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP Makes Enterprise Security Push</title>
		<link>http://allthingsd.com/20110912/hp-makes-enterprise-security-push/</link>
		<comments>http://allthingsd.com/20110912/hp-makes-enterprise-security-push/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 07:01:54 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Fortify]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hewlett-Packard]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Léo Apotheker]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tom Reilly]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=119380</guid>
		<description><![CDATA[Hewlett-Packard announced a broad IT security strategy that seems a harbinger of the new enterprise-y HP that CEO Léo Apotheker has in mind.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2011/09/leo_d9.png" alt="" title="leo_d9" width="380" height="285" class="alignleft size-full wp-image-119483" />When he laid out his plans to transform the company at a <a href="http://allthingsd.com/20110315/apotheker-sets-hewlett-packard-on-a-cloud-centric-path/">speech in San Francisco in March</a>, Hewlett-Packard CEO Léo Apotheker said IT security would play a big role going forward.</p>
<p>Today, HP presented a new strategy intended to boost its role in the business of supplying IT security to large businesses. With two big shifts hitting the corporate computing environment &#8212; cloud computing and scores of worker-selected mobile devices entering the workplace &#8212; there are a lot of new security challenges giving CIOs headaches.</p>
<p>&#8220;If you look at those trends, they challenge the traditional notions of enterprise security,&#8221; says Tom Reilly, HP&#8217;s VP and general manager for Enterprise Security Products. &#8220;So we want to address those challenges.&#8221;</p>
<p>The traditional approach in IT security was to establish strong perimeters around the network and around a company&#8217;s computers that could keep bad guys out and let good guys in, and then setting strict rules about what people allowed access can do.</p>
<p>Cloud computing obviates the need for a perimeter, because all the computing resources are, well, in the cloud. They live on some virtualized server in someone else&#8217;s data center. And someone who brings their iPhone to the office expects to have the same level of access to the resources they need to do the job. The old models don&#8217;t really apply anymore.</p>
<p>Meanwhile, attacks are surging. A study by the Ponemon Institute &#8212; which, in fairness, was sponsored by HP&#8217;s subsidiary ArcSight &#8212; found that cyberattacks against a group of 50 large companies grew by 44 percent last year versus the prior year. The companies in the sample group &#8212; all of which had 700 or more users &#8212; were hit with a combined 72 successful attacks per week, averaging more than one per company per week. The study also found that the costs to mitigate these attacks went up by 56 percent year over year.</p>
<p>&#8220;The bad guys are getting better, but as we change our IT environment we&#8217;re giving them more surface area from which to launch these attacks,&#8221; Reilly says.</p>
<p>So HP is coming into the picture with what it says is a new approach. It turns out HP has been quietly building up its security bona fides through acquisitions. Last year it paid $1.5 billion to acquire security intelligence firm ArcSight, of which Reilly was CEO. In 2009, it acquired TippingPoint, a network security outfit that came with the $2.7 billion acquisition of 3Com. Another pair of acquisitions, Fortify and SPI Dynamics, both specialize in application security.</p>
<p>HP&#8217;s plan is to mix these security capabilities into its Enterprise services offerings, Reilly says. Rather than try to sell each company new firewalls or other stuff, HP can come in and augment whatever security the company is already using with better information about threats and a new set of tools that can see how the company&#8217;s infrastructure is being used, not just on-premise, but within cloud-based environments, as well. </p>
<p>The point, Reilly says, is not so much to sell specific new security products to companies, but to take a service-based approach that helps a company get a better handle on the new security troubles it may be facing.</p>
<p>The trouble is that HP hasn&#8217;t generally been viewed as a player in the IT security market, and risk-averse CIOs are usually slow to embrace new vendors, because they tend to have long-term relationships with suppliers. But with the nature of the threats changing, HP is apparently hoping to use its status as an established supplier of servers, PCs and other IT products and services, to start a conversation around security with its customers.</p>
<p>There has been a lot of activity around security in the last few years. Intel spent more than $7 billion to acquire the security software firm McAfee earlier this year, and IBM already offers a muscular set of security products and services. It will quickly run into competitors, for sure.</p>
<p>If nothing else, following as it does in the wake of HP&#8217;s plans to <a href="http://allthingsd.com/20110819/hewlett-packards-pc-business-what-happens-next/">divest itself</a> of PCs and its mobile device business, a robust security offering is something that enterprise customers are going to expect. If there&#8217;s really going to be a new enterprise-centric HP, expect to see more moves like this. Whether or not they&#8217;ll work is another matter.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110912/hp-makes-enterprise-security-push/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Targets Multiply</title>
		<link>http://allthingsd.com/20110909/hacking-targets-multiply/</link>
		<comments>http://allthingsd.com/20110909/hacking-targets-multiply/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 07:00:21 +0000</pubDate>
		<dc:creator>Jennifer Valentino-DeVries</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[iSec Partners]]></category>
		<category><![CDATA[Jennifer Valentino-DeVries]]></category>
		<category><![CDATA[Mathew Solnik]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=118975</guid>
		<description><![CDATA[As everything from cars to electricity meters gets hooked up to the Internet or cellphone networks, it isn't just PCs that are vulnerable to cyberattacks, security researchers and government officials warn.]]></description>
			<content:encoded><![CDATA[<p>As everything from cars to electricity meters gets hooked up to the Internet or cellphone networks, it isn&#8217;t just PCs that are vulnerable to cyberattacks, security researchers and government officials warn.</p>
<p>&#8220;The number of these networked devices has skyrocketed in the past two years,&#8221; said Don Bailey, of cyber-security firm iSec Partners, who has been studying the vulnerability problem along with colleague Mathew Solnik. &#8220;They aren&#8217;t just in automotive systems but in security systems, industrial control systems, medical devices.&#8221;</p>
<p>At a conference in August the two iSec researchers demonstrated how they could unlock and start a car by sending certain text messages to the car&#8217;s alarm system. The researchers said the real problem isn&#8217;t the possibility that hackers will start stealing cars. The ramifications are much broader. The same basic approach could be used by hackers to disrupt businesses or vital services.</p>
<p><a href="http://online.wsj.com/article/SB10001424053111904836104576558713969743864.html?mod=WSJ_Tech_LEFTTopNews">Read the rest of this post on the original site &#187;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110909/hacking-targets-multiply/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Letter Suggests Hacking "Widely Discussed" at News of the World</title>
		<link>http://allthingsd.com/20110816/letter-suggests-hacking-widely-discussed-at-news-of-the-world/</link>
		<comments>http://allthingsd.com/20110816/letter-suggests-hacking-widely-discussed-at-news-of-the-world/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 16:48:31 +0000</pubDate>
		<dc:creator>Paul Sonne, Jeanne Whalen and Bruce Orwall</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[bribes]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[James Murdoch]]></category>
		<category><![CDATA[News Corp.]]></category>
		<category><![CDATA[News of the World]]></category>
		<category><![CDATA[voicemail]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=110631</guid>
		<description><![CDATA[News Corp. came under fresh attack Tuesday as new, written evidence submitted to a U.K. parliament committee suggested that voice-mail interception was "widely discussed" at its News of the World tabloid and showed several former executives bluntly contradicting recent testimony by Deputy Chief Operating Officer James Murdoch.]]></description>
			<content:encoded><![CDATA[<p>News Corp. came under fresh attack Tuesday as new, written evidence submitted to a U.K. parliament committee suggested that voice-mail interception was &#8220;widely discussed&#8221; at its News of the World tabloid and showed several former executives bluntly contradicting recent testimony by Deputy Chief Operating Officer James Murdoch.</p>
<p>The U.K. Parliament&#8217;s Culture, Media and Sport Select Committee released written statements from Mr. Murdoch, several former top executives and a law firm that was retained by the media company as it dealt with fallout from the scandal over allegations that the now-closed News of the World illegally intercepted voice-mail messages and bribed police to obtain information.</p>
<p><a href="http://online.wsj.com/article/SB10001424053111903480904576511963847040354.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20110816/letter-suggests-hacking-widely-discussed-at-news-of-the-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
