Thursday, April 13, 2017

FBI obtained FISA warrant to monitor Trump adviser Carter Page

FBI obtained FISA warrant to monitor Trump adviser Carter Page - The Washington Post

FBI obtained FISA warrant to monitor Trump adviser Carter Page

The FBI obtained a secret court order last summer to monitor the communications of an adviser to presidential candidate Donald Trump, part of an investigation into possible links between Russia and the campaign, law enforcement and other U.S. officials said.

The FBI and the Justice Department obtained the warrant targeting Carter Page's communications after convincing a Foreign Intelligence Surveillance Court judge that there was probable cause to believe Page was acting as an agent of a foreign power, in this case Russia, according to the officials.

This is the clearest evidence so far that the FBI had reason to believe during the 2016 presidential campaign that a Trump campaign adviser was in touch with Russian agents. Such contacts are now at the center of an investigation into whether the campaign coordinated with the Russian government to swing the election in Trump's favor.

Page has not been accused of any crimes, and it is unclear whether the Justice Department might later seek charges against him or others in connection with Russia's meddling in the 2016 presidential election. The counterintelligence investigation into Russian efforts to influence U.S. elections began in July, officials have said. Most such investigations don't result in criminal charges.

The officials spoke about the court order on the condition of anonymity because they were not authorized to discuss details of a counterintelligence probe.

Team Trump's ties to Russian interests

During an interview with the Washington Post editorial page staff in March 2016, Trump identified Page, who had previously been an investment banker in Moscow, as a foreign policy adviser to his campaign. Campaign spokeswoman Hope Hicks later described Page's role as "informal."

Page has repeatedly denied any wrongdoing in his dealings with the Trump campaign or Russia.

"This confirms all of my suspicions about unjustified, politically motivated government surveillance," Page said in an interview Tuesday. "I have nothing to hide." He compared surveillance of him to the eavesdropping that the FBI and Justice Department conducted against civil rights leader Martin Luther King Jr.

[Despite early denials, growing list of Trump camp contacts with Russians haunts White House]

The White House, FBI and Justice Department declined to comment.

FBI Director James B. Comey disclosed in public testimony to the House Intelligence Committee last month that the bureau is investigating efforts by the Russian government to interfere in the 2016 presidential election.

Comey said this includes investigating the "nature of any links between individuals associated with the Trump campaign and the Russian government and whether there was any coordination between the campaign and Russia's efforts."

Trump lists Carter Page among his foreign policy team in 2016

Play Video1:12

During an interview with The Washington Post's editorial board on March 21, 2016, then-presidential candidate Donald Trump named Carter Page as one of his forei (The Washington Post)

Comey declined to comment during the hearing about any individuals, including Page, who worked in Moscow for Merrill Lynch a decade ago and who has said he invested in Russian energy giant Gazprom. In a letter to Comey in September, Page had said he had sold his Gazprom investment.

During the hearing last month, Democratic lawmakers repeatedly singled out Page's contacts in Russia as a cause for concern.

The judges who rule on Foreign Intelligence Surveillance Act (FISA) requests oversee the nation's most sensitive national security cases, and their warrants are some of the most closely guarded secrets in the world of U.S. law enforcement and intelligence gathering. Any FISA application has to be approved at the highest levels of the Justice Department and the FBI.

Applications for FISA warrants, Comey said, are often thicker than his wrists, and that thickness represents all the work Justice Department attorneys and FBI agents have to do to convince a judge that such surveillance is appropriate in an investigation.

The government's application for the surveillance order targeting Page included a lengthy declaration that laid out investigators' basis for believing that Page was an agent of the Russian government and knowingly engaged in clandestine intelligence activities on behalf of Moscow, officials said.

Among other things, the application cited contacts that he had with a Russian intelligence operative in New York City in 2013, officials said. Those contacts had earlier surfaced in a federal espionage case brought by the Justice Department against the intelligence operative and two other Russian agents. In addition, the application said Page had other contacts with Russian operatives that have not been publicly disclosed, officials said.

[Former Trump adviser admits to 2013 communication with Russian spy]

An application for electronic surveillance under the Foreign Intelligence Surveillance Act need not show evidence of a crime. But the information obtained through the intercepts can be used to open a criminal investigation and may be used in a prosecution.

The application also showed that the FBI and the Justice Department's national security division have been seeking since July to determine how broad a network of accomplices Russia enlisted in attempting to influence the 2016 presidential election, the officials said.

Since the 90-day warrant was first issued, it has been renewed more than once by the FISA court, the officials said.

In February, Page told "PBS NewsHour" that he was a "junior member of the [Trump] campaign's foreign policy advisory group."

A former Trump campaign adviser said Page submitted policy memos to the campaign and several times asked to be given a meeting with Trump, though his request was never granted. "He was one of the more active ones, in terms of being in touch," the adviser said.

The campaign adviser said Page participated in three dinners held for the campaign's volunteer foreign policy advisers in the spring and summer of 2016, coming from New York to Washington to meet with the group. Although Trump did not attend, Sen. Jeff Sessions (R-Ala.), a top Trump confidant who became his attorney general, attended one meeting of the group with Page in late summer, the campaign adviser said.

Page's role as an adviser to the Trump campaign drew alarm last year from more-established foreign policy experts in part because of Page's effusive praise for Russian President Vladimir Putin and his criticism of U.S. sanctions over Moscow's military intervention in Ukraine.

In July, Page traveled to Moscow, where he delivered a speech harshly critical of the United States' policy toward Russia.

While there, Page allegedly met with Igor Sechin, a Putin confidant and chief executive of the energy company Rosneft, according to a dossier compiled by a former British intelligence officer and cited at a congressional hearing by Rep. Adam B. Schiff (Calif.), the ranking Democrat on the House Intelligence Committee. Officials said some of the information in the dossier has been verified by U.S. intelligence agencies, and some of it hasn't, while other parts are unlikely to ever be proved or disproved.

On Tuesday, Page dismissed what he called "the dodgy dossier" of false allegations.

Page has denied such a meeting occurred, saying he has never met Sechin in his life and that he wants to testify before Congress to clear his name. A spokesman for Rosneft told Politico in September that the notion that Page met with Sechin was "absurd." Page said in September that he briefly met Russian Deputy Prime Minister Arkady Dvorkovich during that trip.

Comey has declined to discuss the details of the Russia probe, but in an appearance last month, he cited the process for getting FISA warrants as proof that the government's surveillance powers are very carefully used, with significant oversight.

"It is a pain in the neck to get permission to conduct electronic surveillance in the United States. And that's good,'' he told an audience at the University of Texas in Austin.

Officials have said the FBI and the Justice Department were particularly reluctant to seek FISA warrants of campaign figures during the 2016 presidential race because of concerns that agents would inadvertently eavesdrop on political talk. To obtain a FISA warrant, prosecutors must show that a significant purpose of the warrant is to obtain foreign intelligence information.

[How hard is it to get an intelligence wiretap? Pretty hard.]

Page is the only American to have had his communications directly targeted with a FISA warrant in 2016 as part of the Russia probe, officials said.

The FBI routinely obtains FISA warrants to monitor the communications of foreign diplomats in the United States, including the Russian ambassador, Sergey Kislyak. The conversations between Kislyak and Michael Flynn, who became Trump's first national security adviser, were recorded in December. In February, The Washington Post reported that Flynn misled Vice President-elect Mike Pence and others about his discussions with Kislyak, prompting Trump's decision to fire him.

In March, Trump made unsubstantiated claims about U.S. surveillance of Trump Tower in New York. Later that month, Rep. Devin Nunes (R-Calif.), chairman of the House Intelligence Committee and a Trump transition official, charged that details about people "associated with the incoming administration, details with little apparent foreign intelligence value" were "widely disseminated" in intelligence community reporting. He said none of the surveillance was related to Russia. The FISA order on Page is unrelated to either charge.

Last month, the former director of national intelligence, James R. Clapper Jr., told NBC's "Meet the Press" that U.S. law enforcement agencies did not have any FISA orders to monitor the communications of Trump, either as a candidate or as a president-elect, or his campaign. But Clapper did not address whether there were any FISA warrants targeting Trump associates.

Three years before Page became an adviser to the Trump campaign, he came to the attention of FBI counterintelligence agents, who learned that Russian spy suspects had sought to use Page as a source for information.

In that case, one of the Russian suspects, Victor Podobnyy — who was posing as a diplomat and was later charged by federal prosecutors with acting as an unregistered agent of a foreign government — was captured on tape in 2013 discussing an effort to get information and documents from Page. That discussion was detailed in a federal complaint filed against Podobnyy and two others. The court documents in that spy case only identify Page as "Male 1.'' Officials familiar with the case said that "Male 1'' is Page.

In one secretly recorded conversation, detailed in the complaint, Podobnyy said Page "wrote that he is sorry, he went to Moscow and forgot to check his inbox, but he wants to meet when he gets back. I think he is an idiot and forgot who I am. Plus he writes to me in Russian [to] practice the language. He flies to Moscow more often than I do. He got hooked on Gazprom thinking that if they have a project, he could rise up. Maybe he can. I don't know, but it's obvious that he wants to earn lots of money.''

Checkpoint newsletter

Military, defense and security at home and abroad.

The same court document says that in June 2013, Page told FBI agents that he met Podobnyy at an energy symposium in New York, where they exchanged contact information. In subsequent meetings, Page shared with the Russian his outlook on the state of the energy industry, as well as documents about the energy business, according to the court papers.

In the secret tape, Podobnyy said he liked the man's "enthusiasm" but planned to use him to get information and give him little in return. "You promise a favor for a favor. You get the documents from him and tell him to go f--- himself,'' Podobnyy said on the tape, according to court papers.

Page has said the information he provided to the Russians in 2013 was innocuous, describing it as "basic immaterial information and publicly available research documents." He said he had assisted the prosecutors in their case against Evgeny Buryakov, who pleaded guilty to conspiring to act in the United States as an unregistered agent of Russian intelligence.

Rosalind S. Helderman contributed to this report.

Read more:

Trump adviser's public comments, ties to Moscow stir unease in both parties

Blackwater founder held secret Seychelles meeting to establish Trump-Putin back channel

Trump administration sought to enlist intelligence officials, key lawmakers to counter Russia stories



^ed 

Data breaches through wearables put target squarely on IoT in 2017

Data breaches through wearables put target squarely on IoT in 2017 | JavaWorld

Data breaches through wearables put target squarely on IoT in 2017

Security needs to be baked into IoT devices for there to be any chance of halting a DDoS attack, according to security experts.

wearable smart watch
Credit: Pexels

Forrester predicts that more than 500,000 internet of things (IoT) devices will suffer a compromise in 2017, dwarfing Heartbleed. Drop the mic — enough said.

With the sheer velocity of how the distributed denial-of-service (DDoS) attacks spread through common household items such as DVR players, makes this sector scary from a security standpoint.

"Today, firms are developing IoT firmware with open source components in a rush to market. Unfortunately, many are delivering these IoT solutions without good plans for updates, leaving them open to not only vulnerabilities but vulnerabilities security teams cannot remediate quickly," write Forrester analysts.

The analyst firm adds that when smart thermostats alone exceed over 1 million devices, it's not hard to imagine a vulnerability that easily exceeds the scale of Heartbleed. Security as an afterthought for IoT devices is not an option, especially when you can't patch IoT firmware because the vendor didn't plan for over-the-air patching.

Alex Vaystikh, co-founder/CTO of advanced threat detection software provider SecBI, says small-to-midsize businesses and enterprises alike will suffer breaches originating from an insecure IoT device connected to the network. The access point will be a security camera, climate control, an old network printer, or even a remote-controlled lightbulb. This was demonstrated in September in a major DDoS attack on the web site of security expert Brian Krebs. A hacker found a vulnerability in a brand of IoT camera and caused millions of them to simultaneously make HTTP requests from Krebs' site. 

"It successfully crashed the site, but DDoS attacks are not a great way to make money. However, imagine an IoT camera within a corporate network being hacked. If that network also contains the company's database center, there's no way to stop the hacker from making a lateral move from the compromised camera to the database," Vaystikh said. "This should scare organizations into questioning the popular BYOD mentality. We are already seeing a lot of CCTVs being hacked within organizations." 

Florin Lazurca, senior technical manager at Citrix, believes that consumers will be a target of opportunity in 2017. Innovative criminal enterprises will devise ways to monetize on potentially billions of internet-facing devices that many times do not meet stringent security controls. "Want to browse the internet? Pay the ransom. Want to use your baby monitor? Pay the ransom. Want to watch your smart TV? Pay the ransom," Lazurca says.

Florin Lazurca, senior technical manager at Citrix

Mike Kelly, CTO of Blue Medora, agrees, stating that, "the inability to quickly update something, such as your home thermostat, is where we will see the risk. It's not about malware getting on the devices, the focus will need to be on the ability to remediate the issue. Like we saw with Windows, there will be a slew of vulnerabilities, but unlike with a computer, patching won't be as easy with IoT devices," he says.

More connected devices will create more data, which has to be securely shared, stored, managed and analyzed. As a result, databases will become more complex and the management burden will increase. Those organizations that can most effectively monitor their database layer to optimize peak performance and resolve bottlenecks will be in a better position to exploit the opportunities the IoT will bring, he says.

Lucas Moody, CISO at Palo Alto Networks, says security has to be baked into the IoT devices – not be an afterthought. The bloom of IoT devices has security practitioners in the hot seat, with industry analysts suggesting a possible surge up to 20 billion devices by 2020.

"Given the recent upward trend in both frequency and intensity of DDoS attacks of late, 2017 will introduce an entirely new challenge that security teams will need to contend with; how do we secure devices, many of which are by design dumb and, for that matter, cheap?," he says. 

Large corporations are still challenged with finding security talent to manage security in the "traditional" sense, leaving IoT startups to fend for themselves in a digital economy. 

Moody asks, can they keep up? For the interconnected future of cars, televisions and refrigerators, maybe, but maintaining the security of smaller – and seemingly less critical items – such as toasters, thermostats, and pet feeders, it seems unlikely.

"Security has to be baked into these technologies from the conception and design stages all throughout development and roll-out. Security practitioners will need to do more than just scramble to develop strategies to address this pivotal trend," he says.

Corey Nachreiner, CTO at WatchGuard Technologies, predicts that IoT devices will become the de facto target for botnet zombies. With the shear volume of internet-connected devices growing every year, IoT represents a huge attack surface for hackers. More disturbingly, many IoT manufacturers do not create devices with security in mind, and therefore release devices full of potential vulnerabilities. Many of their products have vulnerabilities that were common a decade ago, providing easy pickings for cyber criminals.

Many IoT devices coming on the market have proprietary operating systems, and offer very little compute and storage resources. Hackers would have to learn new skills to reverse engineer these devices, and they don't provide much in terms of resources or data for the attacker to steal or monetize. On the other hand, another class of IoT products are devices running embedded Linux. These devices look very familiar to hackers. They already have tools and malware designed to target them, so "pwning" them is as familiar as hacking any Linux computer.

"On top of that, the manufacturers releasing these devices seem to follow circa 2000 software development and security practices. Many IoT devices expose network services with default passwords that are simple for attackers to abuse," Nachreiner says.

He cited the leaking of the source code for the Mirai IoT botnet. This botnet included a scanner that automatically searched the internet to find unsecured, Linux-based IoT devices, and take them over using default credentials. With this leaked code, criminals were able to build huge botnets consisting of hundreds of thousands of IoT devices. They used these IoT botnets to launch gigantic DDoS attacks that generated up to 1Tbps of traffic; the largest ever recorded.

In 2017, criminals will expand beyond DDoS attacks and leverage these botnets for click-jacking and spam campaigns to monetize IoT attacks in the same way they monetized traditional computer botnets. Expect to see IoT botnets explode next year, he says.

Mike Davis, CTO at CounterTack, believes IoT will continue to be a part of the threat conversation in the coming year, but fundamentally there will be a massive change in the risks associated with the devices — it won't be about security, it will be about patching. 

Hold your IoT security hypberbole

Stan Black, CSO at Citrix, says we need to dispel security myths around emerging technology like IoT, machine learning and artificial intelligence.

"Many people are afraid to adopt these emerging technologies for fear that they may be their security downfall, but as with any technology, the same security 1-2-3s apply. Change the admin username and password, allow and enable devices on separate networks (separate from the networks used to pass sensitive data), create management and access policies, and above all, make sure that employees are educated about how, when and where to use these kinds of technologies," he says. 

Adoption of emerging tech like IoT can actually have more security benefits than challenges, if implemented correctly, Black says. The same goes for machine learning. The security wave of the future includes these technologies, so it's best for businesses to learn about them early, learn about the benefits and reap the rewards of clouds, devices and networks that can learn from, and adapt to, changing behaviors to make for a stronger security posture.

The wave of the future will be computers that can grant or deny access based on fingerprinted keyboards that can sense the normal amount of pressure your fingers normally apply. Taking advantages of benefits like these will help companies move to a new security infrastructure and mindset, he predicts. 

"The mobile devices we depend on every day are loaded with sensors, heat, touch, water, impact, light, motion, location, acceleration, proximity, etc. These technologies have numerous applications including sensing motion and location to ensure people are safe when they travel," Black adds.

These devices are rarely protected or maintained with the same vigor as corporate IT systems, making them generally more vulnerable to being compromised and drafted into a zombie army. This situation is nothing new, but in the next year we can expect to see "personal networks of things" reside in homes with gigabit internet connections — like those offered by Google and AT&T — and so make home networks far more interesting, especially if vulnerabilities in popular home devices can be exploited mechanically (e.g., how the Mirai botnet was built).

Consumers will need to protect their personal networks from this new version of Mirai botnets, creating demand for services that safeguard them. More importantly, vendors will need to adopt better standards for protection of devices. If the Mirai botnet is any indication, the lack of security in device design is still quite profound, Black says.

Speaking of standards

Steven Sarnecki, vice president of federal and public sector at OSIsoft, pointed to the National Institutes of Standards and Technology's (NIST) National Cyber Center of Excellence for a glimpse of what is to come. NIST is currently piloting a project to assess how energy companies can better utilize connected devices to integrate and increase security with hopes of sharing those best practices and insights across the energy sector.  

"As more companies wake up to the reality of IoT security threats, these solutions will become more commonplace, enabling enterprises to markedly increase their security footprint with only minimal incremental cost," he says.

Sarnecki adds that in 2017 he would expect a large portion of IoT users, especially within the enterprise and industrial spaces, to begin to seriously consider the "internet of threats" aspect posed by IoT to their networks. Energy companies, water utilities, and many other critical infrastructure sectors rely on connected devices to support their missions.

Jeannie Warner, security manager at WhiteHat Security, agrees that new guidelines will emerge from organizations such as NIST requiring that application security vendors partner with device manufacturers and testing labs to deliver secure IoT systems. 

"The internet of things is growing daily, with smart devices and controlling applications at the core of every business from healthcare to smart cars and smart buildings. It's essential to protect smart anything from attackers attempting to exploit their vulnerabilities," she says.

In the same way manufacturing safety testing via the American National Standards Institute controls new releases in devices, she believes NIST SP 800 or a similar body will form guidelines for a comprehensive security assurance through the integration of dynamic application scanning technology and rigorous device controls testing.

Commonalities in all IoT systems include controls for tracking and sensing interfaces, combined with web- or mobile-enabled control applications that combine to expand the borders of the security ecosystem, she says. New guidelines will (ideally) force more application security vendors to partner with device control testing labs to support manufacturing earlier in the development process, helping the innovative organizations to manage risk by identifying vulnerabilities early in development, continue to monitor challenges during testing, and help release more secure products.

Big data

The enterprise has paid attention to IoT for some time, though 2017 will be the year we move past the "wow" phase and into the "how do we do we securely and effectively bring IoT to the enterprise, how do we handle the high speed data ingest, and how do we optimize analytics and decisions based on IOT data," says Redis Labs Vice President of Product Marketing Leena Joshi.

Mark Bregman, Chief Technology Officer at NetApp, believes 2017 will be about capitalizing on the value of data. The explosion of data in today's digital economy has introduced new data types, privacy and security concerns, the need for scale and a shift from using data to run the business to recognizing that data is the business.

Off-line data analytics and threat hunting become endless money pits, says Gunter Ollmann of Vectra Networks. "We're told, and we observe, that each year our corporate data doubles. That power-of-two exponential growth, after merely four years of storing, mining, and analyzing logs for threats, means a 16-fold increase in overall costs — with an accompanying scaled delay in uncovering past threats."

Recommended

  • JavaWorld Java IDEs review, September 2016
  • diamond light source synchrotron main chamber
  • android beginners2
  • CI/CD with Jenkins and Docker, Part 1



^ed 

Sex robots with terrifyingly realistic genitalia to hit the market NEXT YEAR and cost £12,000

Sex robots with terrifyingly realistic genitalia to hit the market NEXT YEAR and cost £12,000

Sex robots with terrifyingly realistic genitalia to hit the market NEXT YEAR and cost £12,000

These next generation of sex dolls are due to be "hyper realistic" with never before seen features installed for customers pleasure

SEX robots with terrifyingly realistic genitals are set to hit the market next year for around £12,000.

That means one of the bonking bots could be yours for less than the price of a new Ford Fiesta.

Inside the store that makes terrifyingly realistic sex dolls
Hyper real sex dolls with life like genitals could be on the market next year
4
Hyper real sex dolls with life like genitals could be on the market next year

These next generation of sex dolls are due to be "hyper realistic" with never before seen features installed for customers pleasure.

Built in heaters for that body-heat feel and sensors to respond to touch will be installed to give customers looking for robo romps a more human experience.

The life-like love androids are called "RealDolls" and are made by California based Abyss Creations.

RealDolls founder Matt McMullen said:

Reddit

4
RealDolls founder Matt McMullen said: "I want to have people actually develop an emotional attachment to not only the robot but the actual character behind it – to develop some kind of love for this being."

Company founder Matt McMullen said: "I want to have people actually develop an emotional attachment to not only the robot but the actual character behind it – to develop some kind of love for this being."

Related stories

Love machine

Humans could be becoming addicted to mind-blowing romps with SEX ROBOTS, according to expert

love machine

Teenagers will soon end up losing their virginity to SEX ROBOTS, Brit academic claims

Cyborg psychos

Sex with robots could make you a 'psychopath' warns a leading expert

ROBOT ROMPS

What is a robot sex doll, how much do they cost and who makes them?

BOOB RAIDER

Lara Croft SEX robot to offer lusty men an 'out of this world' experience

Robot romance

REVEALED: Women will be having more sex with ROBOTS than men by 2025

A top researcher in the area has revealed he believes the arrival of sex robots that are not simply passive partners will have a profound effect on human sexual behaviour.

David Levy, author of Love and Sex with Robots said: "I've no doubt some will find it creepy, but the arrival of sexually responsive robots will have enormous consequences.

"We have already seen rapid changes in human relationships thanks to the internet, mobile devices and social media.

"The next major advance will enable us to use our technology to have intimate encounters with the technology itself – to fall in love with the technology,to have sex with robots and to marry them."

Earlier this year it was revealed teens could soon be losing their virginity to sex bots.

Professor Noel Sharkey, who is considered the UK's leading authority on the morality and ethics of the robotic revolution.

The life-like love androids are called "RealDolls" and are made by California based Abyss Creations.
4
The life-like love androids are called "RealDolls" and are made by California based Abyss Creations.
The idea of human/robot relationships has been at the forefront of science fiction for years with it acknowledged in genre classics like Blade Runner
4
The idea of human/robot relationships has been at the forefront of science fiction for years with it acknowledged in genre classics like Blade Runner

He predicted that youngsters could soon end up having their first erotic experience with a mechanical love machine – with grim implications for the relations between real men and women.

He said: "It's not a problem having sex with a machine. But what if it's your first time, your first relationship? What do you think of the opposite sex then? What do you think a man or a woman is?

"It will get in the way of real life, stopping people forming relationships with normal people."

The idea of human/robot relationships has been at the forefront of science fiction for years with it acknowledged in genre classics like Blade Runner.

The topic is also a central part of the Channel 4 series Humans which returned to screens this month.


We pay for your stories! Do you have a story for The Sun Online news team? Email us at tips@the-sun.co.uk or call 0207 782 4368




^ed 

Rash of in-the-wild attacks permanently destroys poorly secured IoT devices | Ars Technica

Rash of in-the-wild attacks permanently destroys poorly secured IoT devices | Ars Technica


Rash of in-the-wild attacks permanently destroys poorly secured IoT devices

Ongoing "BrickerBot" attacks might be trying to kill devices before they can join a botnet.

Researchers have uncovered a rash of ongoing attacks designed to damage routers and other Internet-connected appliances so badly that they become effectively inoperable.

PDoS attack bots (short for "permanent denial-of-service") scan the Internet for Linux-based routers, bridges, or similar Internet-connected devices that require only factory-default passwords to grant remote administrator access. Once the bots find a vulnerable target, they run a series of highly debilitating commands that wipe all the files stored on the device, corrupt the device's storage, and sever its Internet connection. Given the cost and time required to repair the damage, the device is effectively destroyed, or bricked, from the perspective of the typical consumer.

Over a four-day span last month, researchers from security firm Radware detected roughly 2,250 PDoS attempts on devices they made available in a specially constructed honeypot. The attacks came from two separate botnets—dubbed BrickerBot.1 and BrickerBot.2—with nodes for the first located all around the world. BrickerBot.1 eventually went silent, but even now the more destructive BrickerBot.2 attempts a log-on to one of the Radware-operated honeypot devices roughly once every two hours. The bots brick real-world devices that have the telnet protocol enabled and are protected by default passwords, with no clear sign to the owner of what happened or why.

Move over, Mirai

The attacks are a variation on those mounted by Mirai, a botnet made up of network cameras, digital video recorders, and other so-called Internet-of-things devices. The point of Mirai is to build an army of devices that cripple prominent websites with record-setting distributed DoS attacks. The motivation for the PDoS attacks remains unclear, in part because BrickerBot.2 attacked a much wider variety of storage devices—including those used by servers—rather than storage used only by more limited IoT devices.

"When I discovered the first BrickerBot, I thought it was a drastic attempt to stop the IoT Botnet DDoS threat," Radware researcher Pascal Geenens told Ars. "I thought this was a competitor hacker who wanted to take out his competition and get access to the list of IP [addresses] of bots that were in the competitor's botnet. But upon discovery of the second BrickerBot this theory changed, as the second one is targeting any Linux-based system—not only embedded, BusyBox-based Linux with flash storage. What motivates people to randomly destroy things? Anger, maybe? A troll, maybe?"

All of the devices targeted by BrickerBot.1 ran the BusyBox collection of Unix tools, exposed a secure shell command window to the open Internet, and ran an older version of the Dropbear SSH server. Most of the destructive effects of BrickerBot.1 resulted from targeting two specific types of flash storage—Memory Technology Device and MultiMediaCard devices—which are widely used by IoT devices and also found in Raspberry Pi mini computers. During a four-day period starting on March 20, BrickerBot.1 used nodes scattered all over the world to attack devices inside the Radware honeypot 1,895 times. The devices performing the attack were access points and wireless bridges made by Ubiquiti Networks, with operating environments that were similar to the devices on the receiving end of the attack.

Meaner, stealthier BrickerBot.2 emerges

Less than an hour after BrickerBot.1 began attacking the Radware honeypot devices, BickerBot.2 made its first appearance. BrickerBot.2 targets a much wider variety of storage disks, and many of the Linux-based devices they're found on don't run BusyBox or use the Dropbear SSH server. BrickerBot.2 also uses the Tor anonymity service to conceal the IP addresses of its member nodes. Still, BrickerBot.2 can only access machines that expose a telnet service protected by default passwords—a requirement that greatly limits its destructive effects.

Enlarge / Command sequence of BrickerBot.2

Radware

The updated botnet also carries out a longer list of malicious commands once it successfully gains administrative control of a targeted device. As the image above shows, in addition to corrupting the storage device, BrickerBot.2 wipes all stored files, removes the default Internet gateway, disables TCP timestamps, and limits the maximum number of kernel threads to just one. That all but ensures that most damaged devices won't be restored without a major undertaking. Radware has more details about the attacks here.

The common thread linking all the devices—whether targeted by BrickerBot.1 or BrickerBot.2—is that they are so poorly secured that they are easy prey for Mirai and other highly destructive botnets. That leaves open the possibility that the rash of PDoS attacks is being carried out by one or more vigilantes who want to take out these devices before they can be conscripted into a powerful DoS army that poses a serious threat to the Internet as we know it. IoT users who don't want to change default passwords and close or limit access to telnet and SSH out of concern they'll be used in crippling attacks against others now have a much more self-interested reason for locking down their devices—preventing them from being bricked.

Dan Goodin / Dan is the Security Editor at Ars Technica, which he joined in 2012 after working for The Register, the Associated Press, Bloomberg News, and other publications.

You May Also Like



^ed 

Malware BrickerBot Is Bricking Vulnerable IoT Devices, Rendering Them Completely Useless

Malware Called BrickerBot Is Bricking Vulnerable IoT Devices, Rendering Them Completely Useless : TECH : Tech Times


Malware Called BrickerBot Is Bricking Vulnerable IoT Devices, Rendering Them Completely Useless

BrickerBot Malware
A new kind of malware called BrickerBot is attacking Internet of Things devices again, this time rendering them completely useless and inoperable. Here's what it does. (Photo : Chung Sung-Jun | Getty Images)

Last year, the Mirai botnet hit Internet of Things, rendering numerous unsecure and vulnerable devices into a self-made electronic army able to launch damning DDoS attacks.

A New Malware On The Loose

There's a new malware attack on the way, unfortunately, and it's targeting the same type of devices. This time, however, it's blocking them completely, meaning they're being rendered useless and inoperable, intentionally collapsing their services for good.

It's no secret that Internet of Things devices have always been ripe target for malware, and this is because the method with which they are designed and managed is impaired at its core. Manufacturers, for instance, create these internet-connected products and sell them off commercially, frustratingly often without firm security measures or maintenance set in place first. Needless to say that the the vulnerabilities of these devices are easy to expose because of which.

What You Need To Know About BrickerBot

Case in point: BrickerBot, the new malware in question. It scours the internet, combing for unsecure databases of default usernames and passwords. Suppose it finds one and successfully logs in, then the device goes kaput: completely rendered useless. The device's connectivity will be disrupted, its processing power will be limited, and its storage will be wiped, leaving it nothing more than a useless hunk of plastic or metal. Researchers coin this attack as a PDoS, which means "permanent denial of service."

Experts still can't explain why the malware performs what it does, although theories and speculation suggest that a vigilante is carrying out the chore. There are two known variants of BrickerBot, suffixed by "1" or "2." According to reports, the BrickerBot 2 variant uses TOR in order to obfuscate the hosts in control of it.

The response to BrickerBot has so far been of bafflement and perplexity. No one has managed to determine the purpose of the malware. It remains to be seen whether there's an underlying message to the attacks, or if it's simply a case of a crafty hacker wanting to wreak wanton havoc.

Is BrickerBot The Work Of An Activist?

It's being suggested, however, that BrickerBot might actually be a form of activism, which sees a small pool of bricked IoT devices a small price to pay, if to limit the potential impact of a future IoT botnet. Simply put, this theory suggests that the person behind the BrickerBot shuts down these vulnerable devices so as to prevent anything more dangerous from potentially occurring.

Radware, a cybersecurity company, recently observed almost 2,000 PDoS in a span of four days. Most of the devices attacked were in North and South America, though some were also recorded in Europe, Asia, and Africa. Moreover, because BrickerBot is using the TOR network, it could prove difficult to disrupt.

In the meantime, for those who want to prevent BrickerBot from potentially affecting their IoT devices, they can perform these easy measures: change the default password and shut down external access to telnet.

Thoughts about BrickerBot? Have you experienced the malware attacking your IoT device firsthand? Feel free to sound off in the comments section below!



^ed 

Shadow Brokers' malware release includes Oracle Solaris administrator-access security flaw

Shadow Brokers' malware release includes Oracle Solaris administrator-access security flaw | Computing

Shadow Brokers' malware release includes Oracle Solaris administrator-access security flaw

US National Security Agency had 'skeleton keys' to any Oracle/Sun Solaris system for decades

Crumbling padlock

Sun/Oracle Solaris operating systems a completely open book to the NSA

An analysis of some of the new files dumped by Shadow Brokers, a hacking group of unknown provenance that claims to have cracked a server holding a cache of US National Security Agency (NSA) developed...



^ed 

Wednesday, April 12, 2017

EXPERTS: WHERE THERE’S A TAX, THERE’S A WAY TO CHEAT

Powers That Beat: EXPERTS: WHERE THERE'S A TAX, THERE'S A WAY TO CHEAT
EXPERTS: WHERE THERE'S A TAX, THERE'S A WAY TO CHEAT
Philadelphia Inquirer, The (PA)

April 17, 1995
Section: PHILADELPHIA BUSINESS
Edition: FINAL
Page: F01




IRS TRIES TO IMPROVE ITS RATE OF COLLECTION ACCORDING TO EXPERTS, WHERE THERE'S A TAX, THERE'S A WAY TO CHEAT.


Julie Stoiber, INQUIRER STAFF WRITER


Today is tax day. Listen to how easy it was for one man to rip off the Internal Revenue Service:

My Company filed a total of 9,000 returns in 1992, for tax year I 991, which netted my customers approximately $8 million in total refunds. Of that total, I would guess that roughly half of the returns contained false information about dependents, wages, or filing status. That year . . . I recognized how easy it was."

Richard M. Hersch, a tax preparer from Ardmore, kept his scheme going for two years.

Testifying this month before a U.S. Senate committee, Hersch gave a glimpse of the opportunities for fraud just in the IRS's electronic filing system: "In all modesty, it would take several hours for me to share with you the virtually endless possibilities."

Hersch is a big fish in the murky pond of tax deception. He has plenty of company, and they come in all sizes.

Tax cheats inhabit every neighborhood and economic stratum, and they have endless ways of paying less than they owe. They are your doctor, your neighbor, your lawyer, your favorite waitress at the corner tap. Even your Aunt Betty is ripping off Uncle Sam.

"The number of criminal prosecutions is rising. The number of cases we are working is rising," said Steven J. PeterseII, a Criminal Investigation Division chief in the IRS's Philadelphia office. "One could assume there is pIenty of it."

The tax gap - the difference between what the government collects and what it is owed - runs about $127 a year, according to IRS estimates. A 100 percent collection rate for just one year could make a big

The federal budget deficit, which stands at $200 billion.

Not to mention what it could do for the legions of honest taxpayers: If everyone woke up tomorrow and deckiec~ to play it straight with the IRS, Congress could cut tax rates across the board.

Peter R. Merrill, an economist in Price Waterhouse's Washington office, concluded that rates could go down by as much as 10 percentage points. He came up with that number by dividing the tax gap by the amount the government would collect if everyone suddenly started paying his or her fair share. human nature being what it is, though, that is not likely to happen.

"I think most people are honest - and most people practice tax avoidance," said Jeffrey M. Miller, the Center City lawyer who represents Hersch. "Most people try to pay as little tax as they can."

Miller declined to discuss Hersch, who pleaded guilty and is to be sentenced later this month. But he was willing to share observations gleaned during seven years in the U.S. Attorney's Office and 17 as a criminal defense lawyer. Tax avoidance takes all forms, Miller said. "Some are legal, some are illegal, and some are questionable."

* A man buys a house at the Shore with four bedrooms. In one of them, he puts a desk - and writes off one-quarter of the cost of the house as a business expense.

* A video shop owner makes a deal with her workers to pay half their salary in cash; nobody declares the full amount, and both employer and employees get a break on their taxes.

* A waitress, on her feet till 2 in the morning, earns $150 in tips. She has three kids at home with their noses pointed toward college. For income tax purposes, those tips become $15.

*A contractor withholds taxes from his workers' pay, but puts the money back into his business instead of in the mail to the IRS. At tax time, his workers file for refunds - and get them - even though their boss never actually paid taxes on their behalf.

Mom and Pop at the deli down the block take in $7,000 cash a week, and tell the IRS it is $4,000.

"Next time you go into a store and buy something, see if it gets rung up," said Martin Enterlin, another criminal investigation chief at the IRS. "If not, that's a pretty good indication it's not going to get reported."

Penalties for those who get caught range from fines to jail time.

And the IRS, some say, is not bad at catching them.

Marc Durant, a Center City lawyer who represents white-collar criminals, said the IRS's criminal investigators are competent and well-trained, with strong accounting backgrounds.

John B. Stine 2d, a tax partner at Price Waterhouse, said that the IRS's computer programs are increasingly sophisticated, and that, as a result, the reporting of stock sales, real estate sales, on-the-side income and dividends and interest has improved.

But the tax gap suggests that there are plenty of evaders out there, particularly those in cash businesses.

Durant, like Miller, worked as a prosecutor in the U.S. Attorney's Office before switching to criminal defense.


"Economic sociopaths" is what he calls the big tax cheats, the schemers. "They will steal from anybody at any time. The rest, he said, "are really basically just regular people."


 And many of them don't think of themselves as criminals.

In a country jaded by tales of government waste, fat-cat favoritism, and crooked congressmen, taxation based on the honor system is a tough sell.

"The system depends on taxpayers' willingness to comply," Durant said. "The whole sense of the public . . . That the government does not deserve their faithful compliance.

"I'm near certain that the incidence of tax evasion in World War II was a . . . fraction of what it is today," he said. "I'm certain, intuitively, that there is more tax evasion today. During World War II, people felt the country needed the money."

Today, they are more likely to feel that the government will throw it away on $600 toilet seats or some congressional perk, like the publicly subsidized hair salon for legislators that only recently was eliminated.

"People are struggling," Durant said. "I think they feel that the money goes to better use to them than to the government."

He remembers one case in which a business owner kept two sets of books - one with actual revenues, the other with what he reported to the government - for the sheer joy of knowing how much he was getting over on the IRS.


When he got caught, the evidence was overwhelming.

"I don't want to sound like an apologist for these people," Durant said. "I'm not an apologist. I'm just telling you the kinds of things I hear."

Miller hears the same thing.

"Everybody who pays taxes thinks about the guy who is not paying taxes."

And they come up with ways to keep more for themselves.

The IRS, in its efforts to stop them, devises new measures to detect cheaters. And just as quickly, the tax cheats come up with ways to circumvent them. "Fraud perpetrators . . . adapt continuously to new fraud controls," IRS Commissioner Margaret Milner Richardson recently told Congress.

Hersch, the Ardmore tax preparer, rode to riches on electronic filing and the Earned Income Tax Credit, a refund for the working poor, which he dubbed "Easy Income for Tax Cheats."

Big-time schemers like Hersch are often brought down when a relationship goes awry. Someone with an ax to grind - disgruntled employee, ex-spouse - goes to the IRS.

"Despite how straightforward my schemes were, I was caught only because several employees of my company became informants and went to the authorities," Hersch told his Senate audience. "I am confident that if the employees had not turned me in, the IRS would never have caught on and that I would still be in business today."

Illustration: PHOTO

PHOTO (2)

1. Martin Enterlin (left) and Steven J. Petersell, employees of the IRS Criminal Investigation Division, at the Philadelphia office.

2. Marc Durant, a Center City lawyer, says IRS investigators are well-trained and have strong accounting backgrounds. He said big tax cheats are "economic sociopaths" who "will steal from anybody at any time." The rest "are really basically just regular people," he said.

(The Philadelphia Inquirer VICKI VALERIO)






Copyright (c) 1995 The Philadelphia Inquirer


^ed 

‘NSA-Proof’ Email Service ‘ProtonMail’ by Harvard and MIT Students becomes massive success

Necessity is the mother of invention, the old adage has proved its worth again when a group of Harvard and MIT students came together to create an NSA-proof email service.

ProtonMail, the new email platform launched at European Organization for Nuclear Research (CERN) by five security experts ‘who were drawn together by a shared vision of a more secure and private Internet,’ is probably safer and secure than Lavabit, Snowden’s defunct email service.

The service has many benefits over conventional email service providers. As the founders explain:

They are incorporated in Switzerland, which is well known for offering the strongest privacy protection to both individuals as well as countries.

The site uses end-to-end encryption and intense user authentication measures, implying that the data transmitted through their services is inaccessible to the ProtonMail team itself, let alone other people.

“ProtonMail’s segregated authentication and decryption system means logging into a ProtonMail account that requires two passwords. The first password is used to authenticate the user and retrieve the correct account. The second password is a decryption password which is never sent to us. It is used to decrypt the user’s data in the browser so we never have access to the decrypted data, or the decryption password,” reads the website.

It is free forever and does not allow tracking or logging of personally identifiable information.

“We do not save any metadata such as the IPs used to connect to accounts, or  the times certain accounts are accessed,” the website says.

Even data with non-ProtonMail users is secure and emails are provided with an optional expiration time so that there are no trails of sent messages.

They use only trusted secure implementations AES, RSA, along with OpenPGP with open source cryptographic libraries.

Besides, the service providers have invested heavily in hardware security, with fully encrypted hard disks and multiple password layers, thus preserving data security even in an event of hardware seize.

Additionally, they conduct routine server side integrity checks and uses Swiss SSL secured connections.

With a few weeks in private beta, ProtonMail launched its beta phase recently and is an easy to use ‘comprehensive security for everyone,’ according to the website claims.

Worth giving a try!!!!

/ed70