Showing posts with label CyberWar. Show all posts
Showing posts with label CyberWar. Show all posts

Friday, August 2, 2013

Cyberwarfare

 

Cyberwarfare

Hypothetical "Information Warfare" (IW) Exercises

 

Could a Cyberwar Cripple the U.S.?
by Deborah Radcliff

Source: CNN
http://www.cnn.com/2001/TECH/computing/01/24/information.warfare.idg/i ndex.html

January 24, 2001

(IDG) -- It’s April Fool’s Day, 2002. Glitches in air traffic controller screens nearly cause a collision above New York’s LaGuardia Airport. Two weeks later, California Independent System Operator Corp., which controls California’s power grid, somehow misplaces an electrical energy order to Southern California Edison, leaving two-thirds of San Diego in the dark. Then in May, a high-power microwave burst fries the electronics at an abortion clinic in Virginia.

Hypothetical "information warfare" (IW) exercises like these are being played out around the country in preparation for what politicians, the military and law enforcement officials fear will be an orchestrated cyberattack on critical U.S. infrastructure companies. The theory goes that if a well-funded, organized series of cyberattacks were to strike at a target’s economic and structural nerve centers, it would send the target society into chaos and make it difficult for the military to communicate and move troops.

This particular information war game was played out among 75 IT executives attending an IW workshop at the SANS Institute’s Joint Computer Security Conference in Monterey, Calif.

"In the worst-case scenario, every major industry sector would be affected," says Stephen Northcutt, a SANS fellow and a former military IW expert who led the animated workshop at the conference. Note that most of the targets in Northcutt’s IW games are private-sector companies.

"When you’re talking about information warfare, you’re talking about information systems used to cripple the government and economy," says John Tritak, director of the Critical Infrastructure Assurance Office (CIAO) in Washington. "Close to 90 percent of those critical infrastructure companies are privately owned and operated."

The CIAO, formed in 1998 under presidential directive PDD-63, outlines a national infrastructure protection plan to bring better security and reporting to the telecommunications, transportation, emergency services, energy and financial industries. The directive deems those industries as critical to the nation’s operational infrastructure. Although President Bush isn’t bound to support the directive, Tritak and others say they hope PDD-63 will remain in effect.

In two years, IW preparedness has moved forward the fastest in the highly regulated and well-organized financial, energy and telecommunications sectors, say Tritak and others. But IT leaders in the private sector say they’re hesitant to report incidents to agencies like the CIAO and the FBI. Still, Tritak says the agencies need this information for intelligence and predictive analysis.

While the impact of IW bears the same uncertainty as Y2K, many IW experts say cyberterrorism and cyberwarfare are inevitable. In the past year, hacking hobbyists have shown how easy it is to propagate viruses throughout Internet-connected mail systems. They’ve also shown they can hack armies of unwitting computers and make those computers do their bidding. Now, the U.S. government is thinking about what terrorists with more resources could accomplish. And so are countries like China and Russia, which are developing their own IW capabilities, according to Richard Power in the book Tangled Web.

The directive that created the CIAO is a national defense document that, ironically, relies on the private sector to accomplish its mission. Telling that to executives hasn’t been easy.

"The concept of information warfare doesn’t present a compelling case to the CEO and the board, whose responsibility is to their shareholders and customers," Tritak explains. "But as they begin to see that operating in a reliable and secure business environment is part of taking full advantage of the Information Age, they get it."

To make this business connection, the CIAO recruited a private-sector security expert, Nancy Wong, from San Francisco-based Pacific Gas and Electric Co., to help develop a business-friendly framework and get the message out. Wong soon learned she had a third challenge: keeping government, in its zeal to protect, from crossing constitutional lines between public and private sectors.

"We put in place a road map to identify who are the people who have the most influence in business risk management -- financial security analysts, bond raters, corporate executives, even auditors," Wong says. "We’re using existing networks by cascading information through their members to the people who communicate it even further."

The networks Wong refers to include industry associations like the Institute of Internal Auditors, the North American Energy Reliability Council and the National Security Telecommunications Advisory Committee.

The CIAO’s strategy of taking advantage of existing networks -- and their built-in emergency preparedness -- helped speed along the formation of the first of two Information Sharing and Analysis Centers (ISAC) for the financial and telecommunications industries. ISACs are privately owned, industry-specific cooperatives through which the government plans to channel warnings out to the private sector. The government also plans to use ISACs to gather intelligence it needs to better predict an orchestrated attack.

Energy and technology centers are expected to be completed by the end of March. The long-standing emergency management methodologies and collaborative networks provide the framework for these infrastructure analysis and reporting structures.

Bruce Moulton, vice president of infrastructure risk management at Boston-based Fidelity Investments, explains, "If a failure occurs in the Northwest power grid, for example, the energy sector has processes to keep that power failure from rippling across the United States."

And because its core business is consumer trust, the financial services industry has particular impetus for security and disaster planning, says Moulton, who chairs the financial services ISAC. "We’ve already got a good framework of controls to protect against disruption and customer privacy violations," he adds.

A Matter of Trust

But the biggest problem with this infrastructure plan is that businesses have a hard time visualizing the return on investment in risking corporate privacy by reporting breaches.

"The risks in reporting are clear: the fear of negative publicity, proprietary information shared in court, loss of public confidence or reduced trust in the economy itself," Harris Miller, president of the Information Technology Association of America, told an infrastructure panel last month at SafeNet 2000.

The question of reporting was one of the most nettlesome issues tossed around at SafeNet, where leading privacy and security professionals, educators, vendors and infrastructure companies met with government infrastructure protection heavyweights at Microsoft Corp.’s conference center in Redmond, Wash.

Meanwhile, industry leaders are awaiting the passage of a House bill, the Cybersecurity Information Act, that would reduce liability and antitrust action, along with actions brought under the Freedom of Information Act that are related to cyberinformation sharing.

Who Responds?

Such complexities spotlight the precarious relationships being forged among defense agencies, law enforcement bodies and the private sector, which all have stakes in the national infrastructure. On top of that, there’s the sticky issue of jurisdiction.

Who responds to an orchestrated attack, particularly one that affects military operations and crosses state lines? The answer differs from region to region. But, absent a declaration of martial law, it wouldn’t be the military.

"When we’re at war, we just go blow up the bad guys. But domestically, our mission is different. We can’t trespass [into private systems] when we chase the bad guys. And we can’t blow up the bad guys, because the bad guys are an unknown," explained Jim Christy, a supervisory special agent at the Defense Department’s Information Assurance Office, to a group of 400 officials at a state summit on cybercrime in Mesa, Ariz., in October.

So the burden of responding to private-sector calls for help will most likely fall to the FBI’s InfraGard program, which itself is fishing for intelligence from corporations and private citizens. Many IT leaders say they don’t trust the agency, especially given its poor sensitivity to business issues, including efforts to limit encryption exports, and most recently, its controversial Carnivore e-mail wiretapping system.

Meanwhile, Arizona has unveiled perhaps the most unusual plan on the drawing board today: Make the Air Force National Guard the nerve center for private-sector reporting and response, an idea that comes from Christy and Republican State Rep. Wes Marsh, who’s also a member of the Air Force Reserve. Marsh says that because members of the National Guard work full time in the private sector, they’d make excellent liaisons between the government and private sector.

Better Today

No matter how you look at these issues, the net result of the presidential directive is that security awareness is rising, ISACs are forming and executives are more clued in. In spite of raised awareness, internal and external cyberthreats continue to rise, according to a joint survey by the FBI and the San Francisco-based Computer Security Institute. And, in a nonscientific online poll by Computerworld last month, only 17 percent of 150 respondents said their companies were prepared to respond to an orchestrated, warlike cyberattack.

But is this work moving fast enough? "This is a race. If the industry doesn’t learn to manage its risk in a prudent way and something like an Exxon Valdez happens, then you’ll see a chilling effect as laws get passed during the crisis," says Tritak. "At the same time, if you try to overplay the risks and threats, you could lose your audience."

Already, international IW efforts are moving forward.

The U.S. military has publicly announced the formation of IW units. Cyberclashes between Israeli and Palestinian factions that shut down Israeli and Palestinian government Web sites prompted the FBI to issue a warning to American businesses in October. In December, the FBI issued another warning of an "increase in hacker activity specifically targeting U.S. systems associated with e-commerce."

Yet in spite of these indicators, IW thinkers say a cyberwar is years away.

"Clearly, the eventuality of such an attack is present. That’s what motivated [the Clinton] administration to move forward with a national plan," says Tritak. "But I don’t think anyone has the cybercapability today to launch an attack that would cripple the nation’s infrastructure.

[The presidential directive] predicts such a scenario is still years away."

Back To Contents

Saturday, June 1, 2013

Cyber-Scare

Cyber-Scare

bostonreview.net

The age of cyber-warfare has arrived. That, at any rate, is the message we are now hearing from a broad range of journalists, policy analysts, and government officials. Introducing a comprehensive White House report on cyber-security released at the end of May, President Obama called cyber-security “one of the most serious economic and national security challenges we face as a nation.” His words echo a flurry of gloomy think-tank reports. The Defense Science Board, a federal advisory group, recently warned that “cyber-warfare is here to stay,” and that it will “encompass not only military attacks but also civilian commercial systems.” And “Securing Cyberspace for the 44th President,” prepared by the Center for Strategic and International Studies, suggests that cyber-security is as great a concern as “weapons of mass destruction or global jihad.”

Unfortunately, these reports are usually richer in vivid metaphor—with fears of “digital Pearl Harbors” and “cyber-Katrinas”—than in factual foundation.

Consider a frequently quoted CIA claim about using the Internet to cause widespread power outages. It derives from a public presentation by a senior CIA cyber-security analyst in early 2008. Here is what he said:

We have information, from multiple regions outside the United States, of cyber-intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyber-attacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet.

So “there is information” that cyber-attacks “ have been used.” When? Why? By whom? And have the attacks caused any power outages? The CIA may have some classified information, but very little that is unclassified suggests that such cyber-intrusions have occurred.

Or consider an April 2009 Wall Street Journal article entitled “Electricity Grid in U.S. Penetrated By Spies.” The article quotes no attributable sources for its starkest claims about cyber-spying, names no utility companies as victims of intrusions, and mentions just one real cyber-attack, which occurred in Australia in 2000 and was conducted by a disgruntled employee rather than an external hacker.

It is alarming that so many people have accepted the White House’s assertions about cyber-security as a key national security problem without demanding further evidence. Have we learned nothing from the WMD debacle? The administration’s claims could lead to policies with serious, long-term, troubling consequences for network openness and personal privacy.

Cyber-security fears have had, it should be said, one unambiguous effect: they have fueled a growing cyber-security market, which, according to some projections, will grow twice as fast as the rest of the IT industry. Boeing, Raytheon, and Lockheed Martin, among others, have formed new business units to tap increased spending to protect U.S. government computers from cyber-attacks. Moreover, many former government officials have made smooth transitions from national cyber-security policy to the lucrative worlds of consulting and punditry. Speaking at a recent conference in Washington, D.C., Amit Yoran—a former cyber-security czar in the Bush administration and currently the C.E.O. of NetWitness, a cyber-security start-up—has called hacking a national security threat, adding that “cyber-9/11 has happened over the last ten years, but it’s happened slowly, so we don’t see it.” One way for the government to protect itself from this cyber-9/11 may be to purchase NetWitness’s numerous software applications, aimed at addressing both “state and non-state sponsored cyber threats.”

From a national security perspective, cyber-attacks matter in two ways. First, because the back-end infrastructure underlying our economy (national and global) is now digitized, it is subject to new risks. Fifty years ago it would have been hard—perhaps impossible, short of nuclear attack—to destroy a significant chunk of the U.S. economy in a matter of seconds; today all it takes is figuring out a way to briefly disable the computer systems that run Visa, MasterCard, and American Express. Fortunately, such massive disruption is unlikely to happen anytime soon. Of course there is already plenty of petty cyber-crime, some of it involving stolen credit card numbers. Much of it, however, is due to low cyber-security awareness by end-users (you and me), rather than banks or credit card companies.

Second, a great deal of internal government communication flows across computer networks, and hostile and not-so-hostile parties are understandably interested in what is being said. Moreover, data that are just sitting on one’s computer are fair game, too, as long as the computer has a network connection or a USB port. Despite the “cyber” prefix, however, the basic risks are strikingly similar to those of the analog age. Espionage has been around for centuries, and there is very little we can do to protect ourselves beyond using stronger encryption techniques and exercising more caution in our choices of passwords and Wi-Fi connections.

To be sure, there is a war-related caveat here: if the military relies on its own email system or other internal electronic communications, it is essential to preserve this capability in wartime. Once more, however, the concern is not entirely novel; when radio was the primary means of communication, radio-jamming was also a serious military concern; worries about radio go back as far as the Russo-Japanese War of 1904-1905.

The ultimate doomsday scenario—think Live Free or Die Hard—could involve a simultaneous attack on economic e-infrastructure and e-communications: imagine al Qaeda disabling banks, destroying financial data, disrupting networks, and driving the American economy back to the nineteenth century. This certainly sounds scary—almost as scary as raptors in Central Park or a giant asteroid heading toward the White House. The latter two are not, however, being presented as “national security risks” yet.

There are certainly genuine security concerns associated with the Internet. But before accepting the demands of government agencies for new and increased powers to fight threats in cyberspace and prepare for cyber-warfare, we should look more closely at well-defined dangers and ask just where existing technological means and legal norms fall short. Because the technologies are changing so quickly, we cannot expect definitive answers. But cyber-skeptics—who argue that cyber-warfare is still more of an urban legend than a credible hazard—appear to be onto something important.

One kind of cyber-security problem grows out of resource scarcity. A network has only so much bandwidth; a server can serve only so much data at one time. So if you want to disable (or simply slow down) the computer backbone of a national economy, for example, you need to figure out how to reach its upper limit.

It would be relatively easy to protect against this problem if you could cut your computer or network off from the rest of the world. But as the majority of governmental and commercial services have moved online, we expect them to be offered anywhere; Americans still want to access their online banking accounts at Chase even if they are travelling in Africa or Asia. What this means in practice is that institutions typically cannot shut off access to their online services based on nationality of the user or the origin of the computer (and in the case of news or entertainment sites, they do not want to: greater access means more advertising income).

Together, these limitations create an opportunity for attackers. Since no one, not even the U.S. government, has infinite computer resources, any network is potentially at risk.

Taking advantage of this resource scarcity could be an effective way of causing trouble for sites one does not like. The simplest—and also the least effective—way of doing this is to visit the URL and hit the “reload” button on your browser as often (and for as long) as you can. Congratulations: you have just participated in the most basic kind of “denial-of-service” (DoS) attack, which aims to deny or delay the delivery of online services to legitimate users. These days, however, it would be very hard to find a site that would suffer any noticeable damage from such a nuisance; what is missing from your cyber-guerilla campaign is scale.

Now multiply your efforts by a million—distribute your attacks among millions of other computers—and this could be enough to cause headaches to the administrators of many Web sites. These types of attacks are known as “distributed denial-of-service” or DDoS attacks. Administrators may be able to increase their traffic and bandwidth estimates and allocate more resources. Otherwise they have to live with this harassment, which may disable their Web site for long periods.

DDoS attacks work, then, by making heavier-than-normal demands on the underlying infrastructure, and they usually cause inconvenience rather than serious harm. Not sure how to do it yourself? No problem: you can buy a DDoS attack on the black market. Try eBay.

In fact, your own computer may well be participating in a DDoS attack right now. You may, for example, have inadvertently downloaded a trojan—a hard-to-detect, tiny piece of software—that has allowed someone else to take control of your machine, without obvious effect on your computer’s speed or operations. Some computer experts put the upper limit of infected computers as high as a quarter of all computers connected to the Internet.

Because a single computer is inconsequential, the infected computers form “botnets”—nets of robots—that can receive directions from a command-and-control center—usually just another computer on the network with the power to give commands. What makes the latest generation of botnets hard to defeat is that every infected computer can assume the role of the command-and-control center: old-fashioned methods of decapitation do not work against such dispersed command-and-control. Moreover, botnets are strategic: when network administrators try to block the attacks, botnets can shift to unprotected prey. Commercial cyber-security firms are trying to keep up with the changing threats; thus far, however, the botnets are staying at least one step ahead.

DDoS threats have been far more commercial than political. The driving force has been cyber-gangs (many of them based in the former Soviet Union and Southeast Asia) which are in the extortion business. They find a profitable Internet business that cannot afford downtime and threaten to take down its Web site(s) with DDoS attacks. The online gambling industry—by some estimates, a $15-billion-a-year business—is a particularly appealing target because it is illegal in the United States: it cannot seek protection and take advantage of robust U.S. communications infrastructure. Thus, administrators of popular gambling sites commonly receive threats of DDoS attacks and demands for $40,000-$60,000 to “protect” the sites from attacks during peak betting periods (say, before big sporting events such as the Super Bowl). Many legitimate businesses fall victim to cyber-extortion, too. Since it is better to dole out a little cash to stop future attacks than to deal with the PR fallout—and possible drop in stock prices—that usually follows cyber-attacks, cyber-crime is underreported and underprosecuted.

Another commercial opportunity for cyber-gangs is the creation of a large army of for-hire botnets, with extremely powerful attack capabilities. It is currently quite straightforward to rent the destructive services of a botnet ($1000/day is a going rate). The point was made forcefully by a controversial recent experiment: a group of BBC reporters purchased the services of a botnet 22,000 infected-computers strong from a vendor of cyber-crime services and used it to attack the site of a cyber-security company.

The commercial availability of DDoS-attack capability has generated excitement about political applications. The risks to online freedom of expression may be considerable: saying anything controversial may trigger a wave of cyber-attacks that your adversaries can purchase easily. These attacks are financially burdensome and politically disabling for the victim. Getting your server back online is usually the least of your problems. Your Web hosting company may kick you off its servers because the cost of dealing with the damage caused by cyber-attacks usually outweighs the monetary gains of hosting controversial groups, from political bloggers to LGBT groups to exiled media from countries such as Burma (just to mention some recent victims of DDoS attacks). Protection from DDoS is available, but usually too expensive for nonprofits.

An alternative to expensive DDoS protection is a kind of distributed defense network. Imagine an idealized world in which every computer has the latest anti-virus update and where users do not open suspicious attachments or visit dubious Web sites. Cyber-gangs would then be left to their own devices—to attacking with computers they own—and the security issues would be considerably diminished. This perfect world is impossible to achieve, but the right policies could get us pretty close. One option is to go “macro”—to ensure that all critical national infrastructure is prioritized and protected, with extremely flexible resource allocation for the key assets (part of the job of a cyber-czar). This, however, would do little to curb the DDoS market. Indeed, it might embolden the attackers to ratchet up their capabilities. An alternative is to go “micro”—ensure that people who are responsible for the creation of this market in DDoS attacks in the first place (i.e., you and me) are knowledgeable (or at least literate) in cyber-security matters and do not surf with their antivirus protection turned off. This latter solution could eliminate the problem at root: if all computers were secure and computer users careful, botnets would significantly shrink in size. This, however, is a big “if,” and most skepticism over whether the federal government is well-placed to educate about these threats is justified.

The security threats from DDoS attacks pale in comparison with the potentialconsequences of another kind of online insecurity, one more likely to be associated with terrorists than criminals and potentially more consequential politically: data breaches or network security compromises (I say “potential” because very few analysts with access to intelligence information agree to speak on the record). After all, with DDoS, attackers simply slow down everyone’saccess to data that are, in most cases, already public (some data are occasionally destroyed). With data breaches, in contrast, attackers can gain access to private and classified data, and with network security compromises, they might also obtain full control of high-value services like civil-aviation communication systems or nuclear reactors.

Data breaches and network security compromises also create far more exciting popular narratives: the media frenzy that followed the detection of China-based GhostNet—a large cyber-spying operation that spanned more than 1250 computers in 103 countries, many of them belonging to governments, militaries, and international organizations—is illustrative. Much like botnets, cyber-spying operations such as GhostNet rely on inadvertently downloaded trojans to obtain full control over the infected computer. In GhostNet’s case, hackers even gained the ability to turn on computers’ camera and audio-recording functions for the purposes of remote surveillance, though we have no evidence that attackers used this function.

In fact, what may be most remarkable about GhostNet is what did not happen. No computers belonging to the U.S. or U.K. governments—both deeply concerned about cyber-security—were affected; one NATO computer was affected, but had no classified information on it. It might be unnerving that the computers in the foreign ministries of Brunei, Barbados, and Bhutan were compromised, but the cyber-security standards and procedures of those countries probably are not at the global cutting edge. With some assistance on upgrades, they could be made much more secure.

In part, then, the solution to cyber-insecurity is simple: if you have a lot of classified information on a computer and do not want to become part of another GhostNet-like operation, do not connect it to the Internet. This is by far the safest way to preserve the integrity of your data. Of course, it may be impossible to keep your computer disconnected from all networks. And by connecting to virtually any network—no matter how secure—you relinquish sole control over your computer. In most cases, however, this is a tolerable risk: on average, you are better off connected, and you can guard certain portions of a network, while leaving others exposed. This is Network Security 101, and high-value networks are built by very smart IT experts. Moreover, most really sensitive networks are designed in ways that prevent third-party visitors—even if they manage somehow to penetrate the system—from doing much damage. For example, hackers who invade the email system of a nuclear reactor will not be able to blow up nuclear facilities with a mouse click. Data and security breaches vary in degree, but such subtlety is usually lost on decision-makers and journalists alike.

Hype aside, what we do know is that there are countless attacks on the government computers in virtually every major Western country, many of them for the purpose of espionage and intelligence gathering; data have been lost, compromised, and altered. The United States may have been affected the most: the State Department estimates that it has lost “terabytes” of data to cyber-attacks, while Pentagon press releases suggest that it is under virtually constant cyber-siege. Dangerous as they are, these are still disturbing incidents of data loss rather than seriously breached data or compromised networks. Breakthroughs in encryption techniques have also made data more secure than ever. As for the data loss, the best strategy is to follow some obvious rules: be careful, and avoid trafficking data in open spaces. (Don’t put important data anywhere on the Internet, and don’t leave laptops with classified information in hotel rooms.)

Although there is a continuous spectrum of attacks, running from classified memos to nuclear buttons, we have seen no evidence that access to the latter is very likely or even possible. Vigilance is vital, but exaggeration and blind acceptance of speculative assertions are not.

So why is there so much concern about “cyber-terrorism”? Answering a question with a question: who frames the debate? Much of the data are gathered by ultra-secretive government agencies—which need to justify their own existence—and cyber-security companies—which derive commercial benefits from popular anxiety. Journalists do not help. Gloomy scenarios and speculations about cyber-Armaggedon draw attention, even if they are relatively short on facts.

Politicians, too, deserve some blame, as they are usually quick to draw parallels between cyber-terrorism and conventional terrorism—often for geopolitical convenience—while glossing over the vast differences that make military metaphors inappropriate. In particular, cyber-terrorism is anonymous, decentralized, and even more detached than ordinary terrorism from physical locations. Cyber-terrorists do not need to hide in caves or failed states; “cyber-squads” typically reside in multiple geographic locations, which tend to be urban and well-connected to the global communications grid. Some might still argue that state sponsorship (or mere toleration) of cyber-terrorism could be treated as casus belli, but we are yet to see a significant instance of cyber-terrorists colluding with governments. All of this makes talk of large-scale retaliation impractical, if not irresponsible, but also understandable if one is trying to attract attention.

Much of the cyber-security problem, then, seems to be exaggerated: the economy is not about to be brought down, data and networks can be secured, and terrorists do not have the upper hand. But what about genuine cyber-warfare? The cyber-attacks on Estonia in April-May 2007 (triggered by squabbling between Tallinn and Moscow over the relocation of a Soviet-era monument) and the cyber-dimension of the August 2008 war between Russia and Georgia have reignited older debates about how cyber-attacks could be used by and against governments.

The Estonian case is notable for the duration of the attacks—the country was under “DDoS-terror” for almost a month, with much of its crucial national infrastructure (including online banking) temporarily unavailable. The local media and some Estonian politicians were quick to blame the attacks on Russia, but no conclusive evidence emerged to prove this. The Georgian case—widely discussed as the first major instance of cyber-attacks (primarily DDoS) accompanying conventional warfare—has barely lived up to its hype. Many Georgian government Web sites were, in fact, targets of severe DDoS attacks. So was at least one bank. Yet, the broader strategic importance of such attacks within the Russian military operation is not clear at all, nor did Russia acknowledge responsibility for the attacks.

Although the attacks on Estonia and Georgia are often grouped together—perhaps because of the tentative Russian involvement in both—they are also very different. One important difference is in the degree of technological sophistication of the two countries. Attacking the Internet in Estonia, which made Internet access a basic human right in 2000, is like attacking the banks in Lichtenstein: the country’s economy, politics, and even some emergency services are pegged to it so tightly that being offline is a national calamity.

Georgia, on the other hand, is a technological laggard. When Georgia’s major government Web sites became inaccessible during the war, the Foreign Ministry was slow in finding a temporary home on a blog. The lapse may have gone largely unnoticed: 2006 Internet statistics gathered by the United Nations show that Georgia had about seven Internet users per one hundred population compared to 55 in Estonia and 70 in the United States. The Georgian case also highlights the danger of drawing too many strategic lessons from cyber-attacks. After all, one common result of the loss of Internet access is power outages, common during wartime regardless of cyber-attacks.

Moreover, both Georgia and Estonia are in a sense “cyber-locked,” with limited points of connection (even in Estonia) to the external Internet. This limited connectivity and the two countries dependence on physical infrastructure heighten their vulnerability. Less cyber-locked nations do not face the same risk. As Scott Pinzon, former Information Security Analyst with WatchGuard Technologies, told me, “If Georgia or Estonia were enmeshed into the Internet as thoroughly as, say, the State of California, the cyber-attacks against them would have been reduced to the level of nuisance.” The smartest way to guard against future attacks may, then, be to build robust infrastructure—laying extra cables, creating more Internet exchange points (where Internet service providers share data), providing incentives for new Internet service providers, and attracting more players to sell connectivity in places that now have limited infrastructure. The United States has actually done quite a bit of this already, so the Estonian experience may have little to teach Americans. While it might benefit Estonia and some other countries to invest heavily in upgrades, the United States may be able to forego dramatic and costly changes in favor of regular maintenance and incremental improvements.

Quite apart from the technological issues of cyber-warfare, there is the question of what even constitutes cyber-war. How do existing legal categories apply in this new setting?

For largely geopolitical reasons, Estonia initially called the cyber-attacks a cyber-war, a move that now seems ill-considered (on a recent trip to Estonia, I noticed that Estonian officials had replaced the term “cyber-war” with the more neutral “cyber-attacks”). The militarization of cyberspace that inevitably comes with any talk of war is disturbing, for there is no evidence yet to link the current generation of cyber-attacks to warfare, at least not in the legal sense of the term. However, the attacks on Estonia and Georgia did each pose an intriguing legal question, and neither has yet been answered definitively. First, do cyber-attacks constitute a “use of armed force” as understood by international law (the Estonian case)? Second, what kind of cyber-attacks are allowed under the laws of war once the conflict has already begun (the Georgian case)?

The first question is the trickiest. Commenting on the attacks, the Estonian defense minister said “such sabotage cannot be treated as hooliganism, but has to be treated as an attack against the state.” But did the cyber-attacks constitute the beginning of an armed conflict, as understood by the Geneva Conventions or Article 51 of the United Nations Charter? If the cyber-attacks constituted an armed attack, Estonia’s NATO allies should have followed Article 5 of the North Atlantic Treaty, which treats an attack against one member state as an attack against all and calls for collective defense. NATO only sent a team of experts to assess the damage. Using the metrics of conventional conflicts to assess the severity of these attacks is not easy. How intense and severe must the damage be in order for the cyber-attacks to qualify as armed attacks? Does damage in cyberspace qualify, even in the absence of offline damage? Is inconvenience to Internet users enough? What about the duration of the attacks?

However such questions are answered, the aggrieved party would still have to prove that a cyber-attack was state-sponsored, and it is unclear how one makes this argument in a legally convincing fashion. Are states only responsible for actions they directly control? Are they also responsible for all cyber-activity in their territory? And how far does that responsibility extend? At least one computer with an IP address belonging to the Russian government was identified as part of a botnet used in the Estonian attacks, but it is hard to build a case for Russian government responsibility on that IP address alone, since there were thousands of other participating computers.

If state involvement cannot be proven beyond doubt, cyber-attacks should be treated as crimes and dealt with under national and, in some cases, international criminal law. But there are difficulties on this front as well. For example, unlike Estonia and many countries, Russia has never signed the Council of Europe Convention on Cybercrime, which is the first international treaty seeking to harmonize national laws and facilitate cross-border cooperation among states on issues of cyber-crime. This makes it impossible to hold Russia to the standards envisioned in the Convention, and international law also provides few mechanisms for punishment.

The second question—what kinds of attacks would be allowed under the law of armed conflict?—presents another theoretical challenge, though for now at least, existing legal standards may suffice to address the issues.

Common sense dictates that the severity and targets of such attacks should be guided by international law, particularly the Geneva Conventions and associated protocols. Broadly speaking, current norms state that the conduct of war must meet three fundamental standards: belligerents must distinguish military from civilian objects when selecting targets; balance military necessity with humanitarian concern (the choice of weapons is not unlimited and must be made with the avoidance of unnecessary suffering in mind); and shun the use of force that is disproportionate, in the sense that it shows insufficient attention to the unnecessary suffering that might result. These principles have proved very hard, but not impossible, to interpret in conventional conflict; applying them to cyberspace is not an insurmountable challenge.

The careful application of these three principles to the conduct of war could explain why militaries might shy away from cyber-attacks. First, it is hard to predict the consequences of such attacks; cyber-attacks typically lack surgical precision and are notorious for side effects—a virus planted in a military network could easily spread to civilian computers, causing much unanticipated collateral damage.

Second, precisely targeted cyber-attacks could be a more humane way of conducting warfare. Instead of bombing a military train depot, with collateral civilian deaths, one can temporarily disable it by hacking into its dispatch system. However, the rules of war also stipulate that once a belligerent has used a more humane weapon, it ought to use that weapon in similar situations—and who would voluntarily abandon tanks in favor of computers only?

Third, most cyber-attacks are hard to justify in strategic terms and therefore would open associated personnel to prosecution for war crimes. For example, if there is little to be gained from attacking a poorly maintained Web site of the Georgian parliament, Russia could not justify an attack on it in military terms. If it went ahead with such an attack, its commanders woul risk prosecution for a disproportionate use of force.

The Internet does create one complexity worth considering in the context of applying existing laws of war: civilians on both sides can now participate in hostilities remotely. At the height of the war with Georgia, Russian blogs were full of detailed instructions on how to enlist in the cyber-war effort. Currently, humans are of little value in this process: a conventional botnet attack is more damaging. Yet, it is possible that human-powered botnets—or “meatbots”—could soon play a more serious role. Would participants then be liable for war crimes for their actions as civilians, who, unlike combatants, do not enjoy immunity under the law of war for their participation in hostilities? Would such civilian actions fall under the category of “direct participation in hostilities,” outlined in Commentary to Additional Protocol I to the Geneva Conventions (“Direct participation in hostilities implies a direct causal relationship between the activity engaged in and the harm done to the enemy at the time and the place where the activity takes place”)? We may need a special clarification of this concept for cyberspace, but other metrics—the damage caused, the targets chosen, and so forth—could still apply.

The legal options are also complicated in the case of classical rather than meatbot-powered DDoS attacks because there are often at least five parties to it: attackers, computer users whose machines are enlisted by the attackers, target Internet sites, software vendors responsible for the exploited security vulnerabilities, and various Internet service providers who deliver the attack traffic. These parties have different degrees of responsibility, and some of them are liable for negligence, itself a murky legal area.

Putting these complexities aside and focusing just on states, it is important to bear in mind that the cyber-attacks on Estonia and especially Georgia did little damage, particularly when compared to the physical destruction caused by angry mobs in the former and troops in the latter. One argument about the Georgian case is that cyber-attacks played a strategic role by thwarting Georgia’s ability to communicate with the rest of the world and present its case to the international community. This argument both overestimates the Georgian government’s reliance on the Internet and underestimates how much international PR—particularly during wartime—is done by lobbyists and publicity firms based in Washington, Brussels, and London. There is, probably, an argument to be made about the vast psychological effects of cyber-attacks—particularly those that disrupt ordinary economic life. But there is a line between causing inconvenience and causing human suffering, and cyber-attacks have not crossed it yet.

The usefulness of cyber-attacks as a military tool is also contested. Some experts are justifiably skeptical about the arrival of a new age of cyber-war. Marcus J. Ranum, Chief Security Officer of Tenable Network Security, argues that it is pointless for superpowers to develop cyber-war capabilities to attack non-superpowers, as they can crush them in more conventional ways. As for non-superpowers, their use of cyber-capabilities would almost certainly result in what Ranum calls “the Blind Mike Tyson” effect: the superpower would retaliate with offline weaponry (“blind me, I nuke you”). If Ranum is right, we should forget about the prospect of all-out cyber-war until we have technologically advanced superpowers that are hostile to each other. Focusing on cyber-crime, cyber-terrorism, and cyber-espionage may help us address the more pertinent threats in a more rational manner.

In the meantime, those truly concerned about the future of the Internet, global security, and e-Katrinas would be advised to watch a recent South Park episode, in which the Internet suddenly disappears and hordes of obsessed families head to the Internet Refugee Camp in California, where they are allowed to browse their favorite Web sites for 40 seconds a day, while the military fights the no-longer-blinking giant Internet router. Finally, a nine-year-old boy plugs the router back in, and its magic green light returns. This would make a sensible strategy for many governments, which are all-too eager to adopt militaristic postures instead of focusing on making their own Internet infrastructures more robust.


Sunday, April 21, 2013

@th3j35ter is more than a Newt Gingrich, he also violates Wounded Warriors | The Internet Chronicle

My dear j35t3r, you are a bottomless source of lulz.

When I helped ruin your Westboro Baptist Psy-Op, Topiary took all the glory and I stole all your troll food. You were a failure then, and you are a failure now. You may be pretty good at throwing packets around, but that doesn’t mean you have any valuable skills. I have all the insanely advanced Computer Science 101 it takes to do what you do, but I can get attention for my cause without the parlor tricks you pass for hacktivism. This site gets nearly as much traffic as yours without the need for that kind of childish behavior.

failtroll th3j35ter is more than a Newt Gingrich, he also violates Wounded Warriors

In June, th3j35t3r received a huge spike in traffic because Tyler Bass mentioned him in an interview with LulzSec.

Lately, no one’s been paying attention to you. That makes you a sad little troll, eh? Your recent confrontation with John Tiessen not only proves you are desperately in need of attention, but it also shows how fearful you are of engaging truly skilled trolls. Remember that hilarious, substantive troll about Hugo Carvalho I published on pastebin in your name? You denied it before I could even refresh the page to see the view count. I guess you were saving all your attention for this obstreperous John Tiessen nutjob. I guess it’s just natural that you’d pick the low hanging fruit. It’s okay, you know I’m a pro, and you know not to fuck with me.

John Tiessen is right though, you are a Newt Gingrich. The fact that Tiessen is a sex offender only strengthens his point. It takes one to know one, as they say. You’re an adult who believes that the childish DDoS of Jihadist web sites justifies the illegal possession of a bot-net. You rape the computers of children, old women, wounded soldiers, and the general public just so you can get the kind of attention that other writers at this site and I command with pure creativity. And then, most insulting of all, you use what you do as a platform to collect donations for Wounded Warriors and yourself. You sick Newt Gingrich.

I hope you enjoy your empty bitcoin purse and your dwindling traffic. Your 15 minutes of fame are up, loser. Tick-tock, tango down, stay frosty. Get the fuck off the internet forever, please.

Yours truly,

Someone much better than you

P.S. As a joke, I advertised my bitcoin address (18zJouAQAMzX5sJygZ4M2QV7yb8FzxSbdq) and begged for money to spend on Silk Road. Since then, I have received more donations than you ever will.

We tested this page and blocked content that comes from potentially dangerous or suspicious sites. Allow this content only if you’re sure it comes from safe sites.

Posted from DailyDDoSe

Joseph K Black plagiarizes Gregory D Evans | The Internet Chronicle

Joseph K Black plagiarizes Gregory D Evans

Famous for books that are 99.3% plagiarized, security charlatan Gregory D Evans has, for once, had his work stolen out from under him. Joseph K Black has adopted Gregory D Evans’ methods. Black has cited his doubtful “expertise” as a reason for people to pay attention to him. Joseph K Black is unapologetic about his obvious intellectual theft from Gregory D Evans, just as Evans embraces his place as a plagiarist.

twittershot Joseph K Black plagiarizes Gregory D Evans

Twitterrific is a Mac-only Twitter client, final proof of Gregory D Evans' fraudulent computer expertise.

Gregory D Evans obviously doesn’t care that he’s a plagiarist, as long as he gets his attention. He’s made many contradictory and uninformed comments for reporters who think he’s an expert on Anonymous or computer security.

This is a challenge to Joseph K Black: Step up your game if you want to outdo Gregory D Evans.

We tested this page and blocked content that comes from potentially dangerous or suspicious sites. Allow this content only if you’re sure it comes from safe sites.

Posted from DailyDDoSe

Project World Awareness: This psychopaths kettle is boiling... she did warn us....

Photo

Foresight Through Hindsight | Project World Awareness
http://www.projectworldawareness.com/forums/


Comments

  • osmankadrikoca on April 28th, 2009

    ‘When an artist looks at the world,he sees color..

    When a musician looks at the world,she hears music..

    When an economist looks at the world,she sees a symphony of costs and benefits..

    The economist’s world might not be as colorful or as melodic as the others’ worlds,but it’s more practical..

    If you want to understand what’s going on in the world that’s really out there,you need to know economics..„

  • Lisa on September 8th, 2010

    Hey Jude, this Rocks!! Thank you so much for taking the time to provide a place where we can gather and start the conversation. Luv ya!

  • admin on September 9th, 2010

    I’m in lala land so going to take a rest…Thanks for the comment Lisa…can always count on you xoxoxo

    ~hugs

  • Elyssa Durant on September 9th, 2010

    “The paradox of education is precisely this– that as one begins to
    become educated, one begins to examine the society in which he [or
    she] is being educated.” – Baldwin

  • vaxen_var on September 9th, 2010

    Hope all your lala’s are us… ;) Happy 9 of 7 jude san.

  • admin on September 9th, 2010

    I think this article, published in 1993, gives an excellent perspective on why 9/11 and the war on terrorism were ‘needed’ for US For. Pol. Leon Hadar: The Green Peril, Creating the Islamic Fundamentalist Threat (Cato Institute) http://bit.ly/c3w2m1

    Here are some more articles posted on this in 2006 (ignore the Dutch comments) http://bit.ly/bV11Sk

    Nye/Woolsey – Defend Against the Shadow Enemy (US Senate, 5 Sep. 2001) http://bit.ly/bxYrX5

    Donald Rumsfeld: From Bureaucracy to Battlefield (Sep. 10, 2001) http://bit.ly/9IjyNu Ever read this speech ?

  • admin on September 9th, 2010

    OHHH and BTW…my lala’s were fine lolll
    ~hugs

  • Elyssa Durant on September 10th, 2010

    Hey Jude~ I just came across this comment iin the Examiner http://tinyurl.com/2fbvprv

    “WE NEED NULLIFICATION NOW TO REGAIN OUR COUNTRY FROM THESE TYRANNICAL FREAKS WHO HAVE TAKEN OVER AMERICA AND WANT TO USHER IN THEIR ILLUMINATI NWO INSANITY. I NEED HELP IF ANYBODY GIVES A DAMN IN THIS WORLD.”

    http://disc.yourwebapps.com/discussion.cgi?disc=149495;article=131896;ti

    KEVIN CANADA
    631 778-5024

    The eror is real and although I can’t call perssonallly, I’m wondering if there is some way we can le that there ARE people who give a damn. Aritcle link

    http://www.examiner.com/human-rights-in-national/extremist-stalking-cells-america

    http://tinyurl.com/2fbvprv

  • Lessat on September 10th, 2010

    Your gift of Words & Wisdom is a blessing to us all ….thank you for always reaching out to help your fellow man. Hugs

  • opphoto on September 10th, 2010

    Just popped by to check on you and your your lala’s ;-) Thanks for the meeting spot, it’s a great start!

  • admin on September 11th, 2010

    Exclusive: Google, CIA Invest in ‘Future’ of Web Monitoring | Danger Room | Wired… http://bit.ly/cribNL <> hold 4 HiStory…

    Thanks for all checking in hope to hear *more* from you ;)
    ~love, me

  • admin on September 12th, 2010

    per your post Ellysa… http://www.nwbotanicals.org/oak/newphysics/synthtele/synthtele.html

  • Krystin Piel on September 21st, 2010

    nice blog!! Learning something new everyday and benefiting from the posts of other people is one reason why I love to read blogs. Thanks for sharing this.

  • admin on September 22nd, 2010

    You’re very welcome…enjoy!!!
    ~hugs,~jude

  • Just1Marine on April 5th, 2011

    Great site my friend. Stay Free, Semper Fi

  • rockingjude on April 5th, 2011

    Semper Fi~

    XOXO

  • Al Holtje on March 24th, 2012

    Hey Jude, I’ve been around for a long time. Worked as a cryptographer at NATO Headquarters in Paris for 3 years during the Cold War and came away at the early age of 22 with the ability to look at any problem figure it out and then put the pieces back together. I did exactly that on Wall Street for 35 years. Designing and implementing systems. In 1987 I was asked to look at the new computerized trading system and said: “NO” it had too many loop holes and needed to be strengthened. System was making big money so nothing got done. Later that year i realized that the system could experience a sell off and invested in puts on the S&P500. The market crashed and well let’s just say, I have the confirmations to prove it.

    That being said. Here we go again except this time, it’s out of control. Thank you very much for publishing my article “Bursting the Bubble” and, if there’s anyway I can help let me know. Again, great site and … Thank You
    Al Holtje

  • rockingjude on March 24th, 2012

    Would love to talk with you…I wasn’t on the inside but a group of us that were trading released what was happening with the housing market etc way before anyone even realized it was a problem…ergo I decided our private boards weren’t enough and built this site…got on twitter and started talking… ;)

    ~jude

Leave a Reply

© 2009-2013 Project World Awareness 


 

image.png

image.jpeg

RockingJude in all her glory... 

I let it rest. When she disappeared from the blogosphere and her precious twitter, I secretly hoped that she had either followed through with her frequent threats of suicide or was finally receiving the long term psychiatric hospitalization that she so desperately needs. 

No such luck. Jude reappeared to solicit sympathy and assistance from some of my biggest fans (DefCon 4 types) begging them to protect her from me and my hacking skills. 

Jude Vosika, "allegedly from Wyoming" accused me once again of hacking her site and begged for assistance from AntiSec and LulzSec. 

Little Miss V claims she had to hire security professionals (again) to secure her pathetic, unoriginal site, ProjectWorldAwareness.com (which, incidentally is not registered in her name or place of residence) as a result of being hacked since 2010 by me and my "cronies."

I have two things to say:

1. What is so damn special about her pathetic website worthy of hacking? She BEGGED me to post these generic comments just so my name would be on her page. She also took my original writings (protected by copyright) and posted them as her own on her stupid little site. 

Since she can't spell, write and has no education or real "creds" you can find other comments and people complaining that she merely steals materials from others (like myself) and when she wants to troll or harass people she uses fake names since hers carries no weight. 

This is clearly evident in the screen cap above where she pretends to be a well respected and independent thinker using his name to threaten me on my blog. 

"You don't need to be a rocket scientist" to realize that Jude Vosika was posing as someone she claims also hacked her when I met her a few years ago under VERY bizarre circumstances.. 

2. If you're so damn sure I am hacking you, call the fucking Feds. God knows you have enough an interest in them judging by how you stalked and fixated on my father; posting his bio and credentials on YOUR pathetic little website. 

Glad that shit got suspended. Couldn't have happened to a nicer person. 

To be continued if need be. 

Quit while your ahead, stupid cunt. 

PS  Also noticed Jude posts under multiple admin accounts, Gravatars and multiple aliases and personalities; but she sure loves using her self-proclaimed "celebrity" and the name ROCKINGJUDE ( @rockingjude on Twitter and FaceBook) and her less than interesting timeline to create, drama, terror, fear and to enlist help from 200,000 or so [probably] paid followers to stalk, bully, threaten, harrass and terrorize her victims.

I wonder how many of these people have ever met this deranged woman.  I sure wish I never did.

Word of advice, if you ever see "Hello, it's me" in her tineline-- she has slipped into an altar ego where she "hunts" her victims with the help of few friends for days, weeks, months, or in my case, years on end. 

I have an advanced degree in Psychology and worked as a therapist for the state, the CDC, SAMHSA, and several other agencies and organizations.

I could you her diagnosis, but that would be sinking to her level and she would claim I am victimizing her.

Do yourselves a favor. STAY AWAY!

[originally posted June 19, 2011 updated in light of recent events April 20, 2013]

 

Just me,

e 📧
@ELyssaD™

Forgive typos! iBLAME iPhone

Posted from DailyDDoSe

Tuesday, April 2, 2013

SE Ops » DaveN || WORLDWIDE! Firetown busted again!

FlameWars

Tuesday, February 7th, 2006

DarthN
In a galaxy far far away ….. dum dum dum dee dee dum well something like that anyway lol

People have said a lot of things in the past few weeks about a certain competition V7N , So I jumped in with both feet, why people will ask, to be honest because I was bored. Remember I had a go at Jason Calcanis, and Blog Herald jumped all over me .. lol not Jason hmm

Well I had a go at John Scott recently mainly because I felt that he was having a pop at Mike Grehan, well I think those two have kissed and made up now so I’m not going into the details..

So why am I posting this .. dead easy, FlameWars can and do get you links. Ok the Flamewars rules :

a) Pick your fighting ground
Example Threadwatch, Notice Seobook is just pointing out a writeup on SeoBuzzBox, Ok Threadwatch is one of playing grounds like V7N, so if you’re going to pick a fight pick a ground you feel comfortable with.

b) Get in quick and straight to the point !
OK I knew that telling John to suck my dick would make him rise to the bait … well it had to really, lol. Also notice the “officially NOT on the fence so you better pick a side” to seobook .. chances are Aaron wall won’t bite back at me ..(phew He didn’t) but someone would have to back him up, hopefully John Scott’s Troll ;)

c) The response
John Scott returns his volley, it’s a very good return, and I would have been done and walked away. I knew that people would post the calm down or stop being childish etc threads, but John made a schoolboy error he posted a controversial image of a disabled child ! ( now in his playing ground that might have been acceptable but not here .. oops )

d) Sit back
The community should now attack or walk away, top tip… you do the same lol (notice half way down John Scott post

e) Wait and wait some more ..
BINGO the target .. yes a Flamewar should always target someone who is defending someone else. Mike Dammann steps up .. thank you lord a fool

Mike Dammann’s Post :
looking at people like DaveN and Mike Grehan and their lack of class and manners. So should everyone in this industry be.

Class and manners… ok, Mike Grehan has these, so he may feel offended but not me

I find it surprising that anyone would want to associate himself with such individuals. That speaks very poorly of our industry as a whole that anyone that low could be accepted as equals within our community.

LOL I’m a Blackhat Seo. I work in Casinos, Pills, Loans, and the Affiliate marketplace, Notice the Naked Bull Riding !! (added for my whitehat corp clients, I still love you guys too)

Those 2 are yes men and what DaveN has suggested for John Scott to do to him … wouldn’t be a surprise to me if that is how Mike and Dave have gotten your foot into the door somehow.

YES men HAHAHAHA, that’s too funny I nearly pissed myself , you see Mr Damman, you have the good and you have the evil, we are not the same by a long shot, I mud wrestle in the serps , while Mike swims in champagne, both top of our Game, just different games lol

Aaron doesn’t have to pick any side, Dave. You don’t get it. He is not on your level, he’s intelligent enough to understand seo without sucking up to anyone, and he is mature enough to choose his battles well and not fall into the herd mentality.

Yep, I agree I threw the Aaron bit in to find my Troll :)

But then again, if it wasn’t for following someone, you and Mike Grehan would be working at McDonalds or cleaning trainstation bathrooms together

Lol that’s too funny as well, I have worked at a Happy Eater (they are like McDonald’s but on our motorways), while I was saving up to go to college to learn how to programme which was kind of a big step because none of my friends or family were into computers, so that kind of rules out the bit about having to follow someone.

I have no problems of you bad mouthing me and you linking to my site, after all you’re a fucking nobody, but isn’t that part of the game, but please get some facts right .

I have been married twice, but never walk out on my family
I do live in a half a million pound house and have never lived in my car
I always pay my way and never free load or sneak into places
I have rode a bull naked (well with my boxers still on!)
And the ONLY competition I will be entering is the Greg and DaveN Vodka challenge, But again thanks for the Links

DaveN

who has WHO by the balls now?

Firetown0

Posted from DailyDDoSe

SE Ops » DaveN || WORLDWIDE! Go Team #BLACK

FlameWars

Tuesday, February 7th, 2006

DarthN
In a galaxy far far away ….. dum dum dum dee dee dum well something like that anyway lol

People have said a lot of things in the past few weeks about a certain competition V7N , So I jumped in with both feet, why people will ask, to be honest because I was bored. Remember I had a go at Jason Calcanis, and Blog Herald jumped all over me .. lol not Jason hmm

Well I had a go at John Scott recently mainly because I felt that he was having a pop at Mike Grehan, well I think those two have kissed and made up now so I’m not going into the details..

So why am I posting this .. dead easy, FlameWars can and do get you links. Ok the Flamewars rules :

a) Pick your fighting ground
Example Threadwatch, Notice Seobook is just pointing out a writeup on SeoBuzzBox, Ok Threadwatch is one of playing grounds like V7N, so if you’re going to pick a fight pick a ground you feel comfortable with.

b) Get in quick and straight to the point !
OK I knew that telling John to suck my dick would make him rise to the bait … well it had to really, lol. Also notice the “officially NOT on the fence so you better pick a side” to seobook .. chances are Aaron wall won’t bite back at me ..(phew He didn’t) but someone would have to back him up, hopefully John Scott’s Troll ;)

c) The response
John Scott returns his volley, it’s a very good return, and I would have been done and walked away. I knew that people would post the calm down or stop being childish etc threads, but John made a schoolboy error he posted a controversial image of a disabled child ! ( now in his playing ground that might have been acceptable but not here .. oops )

d) Sit back
The community should now attack or walk away, top tip… you do the same lol (notice half way down John Scott post

e) Wait and wait some more ..
BINGO the target .. yes a Flamewar should always target someone who is defending someone else. Mike Dammann steps up .. thank you lord a fool

Mike Dammann’s Post :
looking at people like DaveN and Mike Grehan and their lack of class and manners. So should everyone in this industry be.

Class and manners… ok, Mike Grehan has these, so he may feel offended but not me

I find it surprising that anyone would want to associate himself with such individuals. That speaks very poorly of our industry as a whole that anyone that low could be accepted as equals within our community.

LOL I’m a Blackhat Seo. I work in Casinos, Pills, Loans, and the Affiliate marketplace, Notice the Naked Bull Riding !! (added for my whitehat corp clients, I still love you guys too)

Those 2 are yes men and what DaveN has suggested for John Scott to do to him … wouldn’t be a surprise to me if that is how Mike and Dave have gotten your foot into the door somehow.

YES men HAHAHAHA, that’s too funny I nearly pissed myself , you see Mr Damman, you have the good and you have the evil, we are not the same by a long shot, I mud wrestle in the serps , while Mike swims in champagne, both top of our Game, just different games lol

Aaron doesn’t have to pick any side, Dave. You don’t get it. He is not on your level, he’s intelligent enough to understand seo without sucking up to anyone, and he is mature enough to choose his battles well and not fall into the herd mentality.

Yep, I agree I threw the Aaron bit in to find my Troll :)

But then again, if it wasn’t for following someone, you and Mike Grehan would be working at McDonalds or cleaning trainstation bathrooms together

Lol that’s too funny as well, I have worked at a Happy Eater (they are like McDonald’s but on our motorways), while I was saving up to go to college to learn how to programme which was kind of a big step because none of my friends or family were into computers, so that kind of rules out the bit about having to follow someone.

I have no problems of you bad mouthing me and you linking to my site, after all you’re a fucking nobody, but isn’t that part of the game, but please get some facts right .

I have been married twice, but never walk out on my family
I do live in a half a million pound house and have never lived in my car
I always pay my way and never free load or sneak into places
I have rode a bull naked (well with my boxers still on!)
And the ONLY competition I will be entering is the Greg and DaveN Vodka challenge, But again thanks for the Links

DaveN

who has WHO by the balls now?

Firetown0

Posted from DailyDDoSe

FBI — The Cyber Threat: Planning for the Way Ahead

The Cyber Threat
Planning for the Way Ahead

02/28/13

Denial of service attacks, network intrusions, state-sponsored hackers bent on compromising our national security: The cyber threat is growing, and in response, said FBI Director Robert S. Mueller, the Bureau must continue to strengthen its partnerships with other government agencies and private industry—and take the fight to the criminals.

“Network intrusions pose urgent threats to our national security and to our economy,” Mueller told a group of cyber security professionals in San Francisco today. “If we are to confront these threats successfully,” he explained, “we must adopt a unified approach” that promotes partnerships and intelligence sharing—in the same way we responded to terrorism after the 9/11 attacks.


Padlocks graphic

 Focus on Hackers and Intrusions

The FBI over the past year has put in place an initiative to uncover and investigate web-based intrusion attacks and develop a cadre of specially trained computer scientists able to extract hackers’ digital signatures from mountains of malicious code. Learn more 


The FBI learned after 9/11 that “our mission was to use our skills and resources to identify terrorist threats and to find ways of disrupting those threats,” Mueller said. “This has been the mindset at the heart of every terrorism investigation since then, and it must be true of every case in the cyber arena as well.”

Partnerships that ensure the seamless flow of intelligence are critical in the fight against cyber crime, he explained. Within government, the National Cyber Investigative Joint Task Force, which comprises 19 separate agencies, serves as a focal point for cyber threat information. But private industry—a major victim of cyber intrusions—must also be “an essential partner,” Mueller said, pointing to several successful initiatives.

The National Cyber Forensics and Training Alliance, for example, is a model for collaboration between private industry and law enforcement. The Pittsburgh-based organization includes more than 80 industry partners—from financial services, telecommunications, retail, and manufacturing, among other fields—who work with federal and international partners to provide real-time threat intelligence.

Another example is the Enduring Security Framework, a group that includes leaders from the private sector and the federal government who analyze current—and potential—threats related to denial of service attacks, malware, and emerging software and hardware vulnerabilities.

Mueller also noted the Bureau’s cyber outreach efforts to private industry. The Domestic Security Alliance Council, for instance, includes chief security officers from more than 200 companies, representing every critical infrastructure and business sector. InfraGard, an alliance between the FBI and industry, has grown from a single chapter in 1996 to 88 chapters today with nearly 55,000 members nationwide. And just last week, the FBI held the first session of the National Cyber Executive Institute, a three-day seminar to train leading industry executives on cyber threat awareness and information sharing.

“As noteworthy as these outreach programs may be, we must do more,” Mueller said. “We must build on these initiatives to expand the channels of information sharing and collaboration.”

He added, “For two decades, corporate cyber security has focused principally on reducing vulnerabilities. These are worthwhile efforts, but they cannot fully eliminate our vulnerabilities. We must identify and deter the persons behind those computer keyboards. And once we identify them—be they state actors, organized criminal groups, or 18-year-old hackers—we must devise a response that is effective, not just against that specific attack, but for all similar illegal activity.”

“We need to abandon the belief that better defenses alone will be sufficient,” Mueller said. “Instead of just building better defenses, we must build better relationships. If we do these things, and if we bring to these tasks the sense of urgency that this threat demands,” he added, “I am confident that we can and will defeat cyber threats, now and in the years to come.”

Resources:
- Read Director Mueller’s remarks
- Cyber Crime page
- National Cyber Investigative Joint Task Force

- National Cyber Forensics and Training Alliance
- Infragard

Posted from DailyDDoSe