Showing posts with label cyberwar. Show all posts
Showing posts with label cyberwar. Show all posts

Monday, August 13, 2018

CYBERWARS - Can America Fend Off Cyber Attacks

"How prepared is the U.S. to fend off cyber warfare?  Better at offense than defense, author says" PBS NewsHour 8/6/2018

Excerpt

SUMMARY:  “We spent years worrying about the giant cyber-Pearl Harbor,” says David Sanger, author of “The Perfect Weapon: War, Sabotage and Fear in the Cyber Age.”  But, he argues, that has blinded us to more subtle uses, in which we are all collateral damage.  Sanger joins Judy Woodruff to discuss the threats and realities, how the U.S. wages cyber warfare, and how prepared the U.S. is to stop attacks.

Monday, March 05, 2018

RUSSIA'S WAR ON AMERICA - Target, State Voting Systems

"Russia’s sights are set on U.S. elections.  Can states secure their voting systems in time?" PBS NewsHour 2/28/2018

Excerpt

SUMMARY:  The scope of Russian meddling in the last U.S. election has been outlined in special counsel Robert Mueller’s indictments and the threat confirmed by heads of U.S. intelligence agencies.  What can states do to protect American voters and democracy?  Judy Woodruff talks with David Becker of the Center for Election Innovation & Research, and Denise Merrill Connecticut's Secretary of State.

Monday, May 15, 2017

CYBER WARS - Impact of Worldwide Attack

"Analyzing the impact of the worldwide cyber attack" PBS NewsHour 5/13/2017

Excerpt

SUMMARY:  Nearly 100 countries around the world worked to restore services after a massive cyber attack on Friday.  The ransomware attack appeared to exploit a vulnerability in Microsoft Windows, which was identified by the U.S. National Security Agency and later leaked to the internet.  Former Assistant Attorney General for National Security John Carlin joins Hari Sreenivasan for more on the attack.

Monday, October 31, 2016

CYBER WARS - Protecting Consumer Data

Also a Greed File

"FCC chief outlines new plans to protect consumer data online" PBS NewsHour 10/27/2016

Excerpt

SUMMARY:  There are new rules for broadband providers when it comes to collecting and sharing consumer data.  On Thursday, the Federal Communications Commission voted for the first time to create protections on the transmission of personal information for broadband providers.  Hari Sreenivasan speaks with Tom Wheeler, chairman of the FCC.

HARI SREENIVASAN (NewsHour):  New rules for broadband providers when it comes to collecting and sharing customer data.

The Federal Communications Commission voted for the first time today to create protections on the transmission of personal information from broadband providers.

Tom Wheeler is the chairman of the FCC.  And he joins me now.

What is a provider going to have to do under these new rules?

TOM WHEELER, Chairman, Federal Communications Commission:  Well, the key thing is that it is the consumers' information.  It's not the network's information.

And the consumer now has the choice to say how they want that information to be used and if they want it to be used.  So, there are really three key things.  One, there has to be transparency, that the consumers have to be told, here's what we're doing with your information.  Two, they have to have choice.  So, do you want to opt in or opt out of this kind of service?

And, three, that data, when it's stored someplace, has to be stored securely and consumers have to know if there is some kind of data breach.

HARI SREENIVASAN:  So, you have also expanded the definition of what is sensitive data.  And some businesses have pushed back, saying, the browsing history, the app usage, Internet companies like Facebook and Google, they already have all that, and you're placing undue burdens on companies like Verizon, AT&T, et cetera.

TOM WHEELER:  But what we're talking about is not the fact that you may go to a dozen sites that each will get a little bit of information.

We're talking about the network that takes you to every site and knows everything you're doing.  And that's the big difference.  You hire the network to deliver you to those sites.  You don't hire the network to take your information without your permission and turn around and resell it.

Monday, October 17, 2016

POLITICAL HACKING - U.S. vs Russia

"Blaming Russia, how will the U.S. respond to pre-election hacks?" PBS NewsHour 10/11/2016

IMHO:  Wikileaks has morphed into a partisan Trump supporter and is no longer a friend nor protector of the people.  They definitely do NOT understand you cannot conduct international diplomacy nor anti-terrorist functions from within a glass-house.  A degree of secrecy is necessary.

Excerpt

SUMMARY:  WikiLeaks has been releasing emails it claims come from Clinton campaign chairman John Podesta, detailing behind-the-scenes strategy.  Meanwhile, the White House is blaming Russia for hacking Democratic party websites and attempting to influence the presidential election.  What's going on?  Hari Sreenivasan learns more from Lisa Desjardins and chief foreign affairs correspondent Margaret Warner.

HARI SREENIVASAN (NewsHour):  Since Friday, the anti-secrecy group WikiLeaks has been releasing e-mails that were hacked from the account of Hillary Clinton campaign chairman John Podesta.  The stolen messages detail how the campaign responded to important issues through the race for the White House.

It is unclear who was behind this latest digital theft, but, on Friday, the Obama administration did blame Russia for the hacking of Democratic Party Web sites earlier this year and attempts to breach state election systems, in order to influence the vote for president.

Today, White House spokesman Josh Earnest said there will be a U.S. response to the alleged Russian hacking.  He told reporters aboard Air Force One:  “The President has talked before about the significant capabilities that the U.S. government has to both defend our systems in the United States, but also carry out offensive operations in other countries.  So, there are a range of responses that are available to the President, and he will consider a response that's proportional.”

With me now to sift through what all this means in both political and diplomatic terms are the NewsHour's Margaret Warner and Lisa Desjardins.

Lisa, tell me — let's start with what is in the e-mails.

LISA DESJARDINS (NewsHour):  Right.

So, this latest dump, so people can keep track, began on Friday.  These are about 2,000 e-mails, a little bit more, coming from Clinton campaign chairman John Podesta, obviously a very big player in the Clinton world now and for years.

Now, in these, we see one of the standout notes that we have gotten — there haven't been all that many — is from a Clinton 2013 speech to an Italian bank.  You may have seen that quote.  In the speech that was referenced in these e-mails, it was purported to say — quote — “My dream is a hemispheric common market with open trade and open borders.”

Obviously, that's raised a lot of questions in this year of very heated talk about trade and especially after Clinton herself came out against one of the largest-in-history trade deals, the Trans-Pacific Partnership.

And that's probably the biggest kind of headline that's come out of these e-mails, but also they include a great deal of campaign tactics, including a 71-page briefing, sort of oppo research to some extent on Bernie Sanders.  All of this was happening during that very heated primary campaign.

Now, the Clinton campaign themselves is not confirming the authenticity of any of these e-mails.  It's very important to say that WikiLeaks has posted these.  We know they were hacked, so the authenticity is fair to question.

And the Clinton campaign is pushing back strongly, saying this is from a state actor, and this is obviously an illegal act in politics.

Monday, August 22, 2016

CYBER WAR - NSA Code Breach

"Analyzing the NSA code breach in the context of recent cybersecurity events" PBS NewsHour 8/17/2016

Excerpt

SUMMARY:  On Saturday, programming code for National Security Agency hacking tools was shared online.  The content appears to be legitimate, but it is not clear if it was intentionally hacked or accidentally leaked.  Hari Sreenivasan speaks with The Washington Post's Ellen Nakashima and Paul Vixie of Farsight Security about where this development fits in the context of other recent cybersecurity breaches.

HARI SREENIVASAN (NewsHour):  The National Security Agency's primary mission is to spy on the electronic communications of countries and people overseas.

Over the weekend, though, sophisticated code the NSA developed to penetrate computer security systems was posted online.  This serious breach comes amid the ongoing revelations of the hacking of the Democratic National Committee and other organizations, allegedly by groups linked to Russian intelligence.

For more on this, we turn to The Washington Post national security correspondent Ellen Nakashima, and Paul Vixie.  He designed and built some of the software that is the backbone of the Internet today.  He is now chairman and CEO of Farsight Security, a computer security firm.

Ellen Nakashima, what happened this weekend?  What got released?

ELLEN NAKASHIMA, The Washington Post:  Over the weekend, apparently on Saturday, mysteriously, a cache of NSA hacking tools was released online through file-sharing sites such as BitTorrent and Dropbox.

It really wasn't noticed until about Monday, when the computer security community started commenting on it and questions arose as to whether or not the NSA had been hacked.

HARI SREENIVASAN:  So, Paul Vixie, if these lock picks, these digital tools to try break into different systems out are out in the open now, these are the tools that the American government was using, what is the consequence, if it is in the public sphere?

PAUL VIXIE, Farsight Security:  Well, I think, every day, everybody is trying to hack everybody.  So, this is not huge news.

What's big news about it is that these tools were built by the U.S. government.  Some of the lock picks, as you call them, are now obsolete.  They are relying on vulnerabilities that have since been closed, because the files are about 3 years old.

But at least one of them is active against a very current piece of equipment from CiscoAnd it is going to lead to a lot of break-ins while the patches are prepared and shipped and then applied.

Monday, July 11, 2016

DOCUMENTARY - "Zero Days"

"‘Zero Days,’ a detective story about the cyber warfare arms race" PBS NewsHour 7/7/2016

Excerpt

SUMMARY:  “Zero Days,” a new documentary by Alex Gibney, lays out a sobering view of the rise of cyber warfare and its acceleration since intelligence agencies sabotaged Iran’s nuclear program.  Gibney sits down with Jeffrey Brown.

HARI SREENIVASAN (NewsHour):  A new documentary lays out a sobering view about the use of cyber-warfare, a future that’s accelerated since intelligence agencies sabotaged Iran’s nuclear program.

The film, called “Zero Days,” opens in more than a dozen cities tomorrow and will be available online.

Its director stopped by as part of the recent AFI Docs festival.

Jeffrey Brown has our conversation.

JEFFREY BROWN (NewsHour):  The 2010 cyber-attack on an Iranian nuclear facility dubbed Stuxnet, the first question was, what exactly was this sophisticated weapon, the second, who created and carried it out, and in the years since, many new questions have arisen about cyber-warfare and the new world we live in.

The documentary “Zero Days” pulls together what happened with Stuxnet and since.

Alex Gibney, Academy Award-winning documentary maker of numerous films, joins me now.

Welcome to you.

ALEX GIBNEY, Director, “Zero Days”:  Thank you.

JEFFREY BROWN:  Why was this a subject you wanted to tackle?

ALEX GIBNEY:  It seemed like it was a story that was about the Internet and the militarization of the Internet, but wasn’t properly understood.  And I certainly didn’t understand it, so it made me want to dig in.



Trailer Quotes:

  • "Get Ready to Get Very, Very Paranoid"
  • "Welcome to the Next Global War"

Monday, January 04, 2016

CYBER WARS - Cybersecurity Act of 2015

"Will a new cybersecurity law make us safer?" PBS NewsHour 12/29/2015

Excerpt

SUMMARY:  Folded into the massive spending and tax cut bill was a significant and controversial new law on cybersecurity.  The act encourages private companies to share data about hacks with the government, but it's raising questions among security advocates and privacy groups alike.  Jeffrey Brown talks to James Lewis of the Center for Strategic and International Studies and Elissa Shevinsky of JeKuDo.

GWEN IFILL (NewsHour):  Before the president and Congress left town for the holidays, they managed to enact a massive 2,000-page package of spending and tax cuts.  Typically, these laws draw attention only for the chaos they create, like shutting down the government.

But there’s a lot more deep inside, in this case, a significant and controversial new law governing cyber-security and Internet data.  The new law encourages private companies to share data about cyber-hacks with the government.  It protects companies from liability, and it also allows data to shared with other companies and with the Department of Homeland Security.

Lawmakers from both parties said it was a good deal.

SEN. DIANNE FEINSTEIN, D-Calif.:  If someone sees a particular virus or harmful cyber-signature, they should tell others, so they can protect themselves.  That’s what this bill does.

REP. DEVIN NUNES, R-Calif.:  We believe that sharing is an area where you really can’t do any harm.  It doesn’t hurt anybody to have a way to talk.  But, right now, they can’t even talk.

SEN. SUSAN COLLINS, R-Maine:  Does it make sense that we require one case of measles to be reported to a federal government agency, but not a cyber-attack?

GWEN IFILL:  But there are some security advocates and privacy groups who say the law manages to go too far, and not quite far enough.

Jeffrey Brown has that debate.

JEFFREY BROWN (NewsHour):  To understand more, we’re joined by James Lewis, senior fellow for the Center for Strategic and International Studies, and Elissa Shevinsky, founder of JeKuDo, a tech start-up designed to provide private communications to customers.

Attention Elissa Shevinsky:  Encrypting user data on sights is EXACTLY what ISIS is using today to communicate.  NOT giving government access is the real danger here, not your concern over privacy.

Wednesday, February 26, 2014

CYBERWAR - Use, or Not to Use, Against Syria

Here's my take:  The issue comes down to does the U.S. start a Cyber Arms Race (similar to the Nuclear Arms Race), or does that race already exist?  IMHO the Cyber Arms Race already exists, although it is in its infancy.

"Syria War Stirs New U.S. Debate on Cyberattacks" by DAVID E. SANGER, New York Times 2/24/2014

Excerpt

Not long after the uprising in Syria turned bloody, late in the spring of 2011, the Pentagon and the National Security Agency developed a battle plan that featured a sophisticated cyberattack on the Syrian military and President Bashar al-Assad’s command structure.

The Syrian military’s ability to launch airstrikes was a particular target, along with missile production facilities.  “It would essentially turn the lights out for Assad,” said one former official familiar with the planning.

For President Obama, who has been adamantly opposed to direct American intervention in a worsening crisis in Syria, such methods would seem to be an obvious, low-cost, low-casualty alternative.  But after briefings on variants of the plans, most of which are part of traditional strikes as well, he has so far turned them down, according to officials familiar with the administration’s long-running internal debate.

Syria was not a place where he saw strategic value in American intervention, and even covert attacks — of the kind he ordered against Iran during the first two years of his presidency — involved a variety of risks.

The considerations that led Mr. Obama to hesitate about using the offensive cyberweapons his administration has spent billions helping develop, in large part with hopes that they can reduce the need for more-traditional military attacks, reflect larger concerns about a new and untested tactic with the potential to transform the nature of warfare.  It is a transformation analogous to what happened when the airplane was first used in combat in World War I, a century ago.

The Obama administration has been engaged in a largely secret debate about whether cyberarms should be used like ordinary weapons, whether they should be rarely used covert tools or whether they ought to be reserved for extraordinarily rare use against the most sophisticated, hard-to-reach targets.  And looming over the issue is the question of retaliation: whether such an attack on Syria’s air power, its electric grid or its leadership would prompt Syrian, Iranian or Russian retaliation in the United States.

It is a question Mr. Obama has never spoken about publicly.  Because he has put the use of such weapons largely into the hands of the N.S.A., which operates under the laws guiding covert action, there is little of the public discussion that accompanied the arguments over nuclear weapons in the 1950s and ’60s or the kind of roiling argument over the use of drones, another classified program that Mr. Obama has begun to discuss publicly only in the past 18 months.

But to many inside the administration, who insisted on anonymity when speaking about discussions over one of America’s most highly classified abilities, Syria puts the issue back on the table.  Mr. Obama’s National Security Council met Thursday to explore what one official called “old and new options.”

Caitlin Hayden, the spokeswoman for the National Security Council, declined to discuss “the details of our interagency deliberations” about Syria.  “But we have been clear that there are a range of tools we have at our disposal to protect our national security, including cyber,” she said, noting that in 2012 “the president signed a classified presidential directive relating to cyberoperations that establishes principles and processes so that cybertools are integrated with the full array of national security tools.”

The directive, she said, “enables us to be flexible, while also exercising restraint in dealing with the threats we face.  It continues to be our policy that we shall undertake the least action necessary to mitigate threats.”

One of the central issues is whether such a strike on Syria would be seen as a justified humanitarian intervention, less likely to cause civilian casualties than airstrikes, or whether it would only embolden American adversaries who have themselves been debating how to use the new weapons.

Wednesday, January 15, 2014

NSA - Hacking by Radio

Public release of this information is a direct threat to U.S. national security.  We have just let our new enemies know what to look for.

"N.S.A. Devises Radio Pathway Into Computers" by DAVID E. SANGER and THOM SHANKER, New York Times 1/14/2014

Excerpt

The National Security Agency has implanted software in nearly 100,000 computers around the world that allows the United States to conduct surveillance on those machines and can also create a digital highway for launching cyberattacks.

While most of the software is inserted by gaining access to computer networks, the N.S.A. has increasingly made use of a secret technology that enables it to enter and alter data in computers even if they are not connected to the Internet, according to N.S.A. documents, computer experts and American officials.

The technology, which the agency has used since at least 2008, relies on a covert channel of radio waves that can be transmitted from tiny circuit boards and USB cards inserted surreptitiously into the computers.  In some cases, they are sent to a briefcase-size relay station that intelligence agencies can set up miles away from the target.

The radio frequency technology has helped solve one of the biggest problems facing American intelligence agencies for years: getting into computers that adversaries, and some American partners, have tried to make impervious to spying or cyberattack.  In most cases, the radio frequency hardware must be physically inserted by a spy, a manufacturer or an unwitting user.

The N.S.A. calls its efforts more an act of “active defense” against foreign cyberattacks than a tool to go on the offensive.  But when Chinese attackers place similar software on the computer systems of American companies or government agencies, American officials have protested, often at the presidential level.

Among the most frequent targets of the N.S.A. and its Pentagon partner, United States Cyber Command, have been units of the Chinese Army, which the United States has accused of launching regular digital probes and attacks on American industrial and military targets, usually to steal secrets or intellectual property.  But the program, code-named Quantum, has also been successful in inserting software into Russian military networks and systems used by the Mexican police and drug cartels, trade institutions inside the European Union, and sometime partners against terrorism like Saudi Arabia, India and Pakistan, according to officials and an N.S.A. map that indicates sites of what the agency calls “computer network exploitation.”

“What’s new here is the scale and the sophistication of the intelligence agency’s ability to get into computers and networks to which no one has ever had access before,” said James Andrew Lewis, the cybersecurity expert at the Center for Strategic and International Studies in Washington.  “Some of these capabilities have been around for a while, but the combination of learning how to penetrate systems to insert software and learning how to do that using radio frequencies has given the U.S. a window it’s never had before.”

No Domestic Use Seen

There is no evidence that the N.S.A. has implanted its software or used its radio frequency technology inside the United States.  While refusing to comment on the scope of the Quantum program, the N.S.A. said its actions were not comparable to China’s.

“N.S.A.'s activities are focused and specifically deployed against — and only against — valid foreign intelligence targets in response to intelligence requirements,” Vanee Vines, an agency spokeswoman, said in a statement.  “We do not use foreign intelligence capabilities to steal the trade secrets of foreign companies on behalf of — or give intelligence we collect to — U.S. companies to enhance their international competitiveness or increase their bottom line.”

Tuesday, July 09, 2013

CYBERWAR - What to Do About Chinese Cyber Theft

"US Government, Industry Fed up with Chinese Cyber Theft; What’s Being Done?" PBS Newshour 7/8/2013

Excerpt

SUMMARY:  As U.S. and Chinese officials meet this week in Washington to discuss cyber issues -- as well as broader strategic and economic issues -- a number of Congress members and computer security experts say they are fed up with China stealing proprietary data from American companies.  Ray Suarez reports.

Wednesday, May 29, 2013

CYBERWAR - Chinese Hack U.S. Weapon Designs?

COMMENT:  The digital-world makes things much easier for everyone, BUT that includes for criminals and espionage.  This means EVERYONE has to be more vigilant about protecting their online data.  Unfortunately our government is playing catchup in technology (hardware and software).

"Is U.S. Less Secure After Chinese Hack Weapons Designs?" PBS Newshour 5/28/2013

Excerpt

JEFFREY BROWN:  There was a new report today of cyber-spying by the Chinese, this time aimed at U.S. military and defence systems.

According to The Washington Post, designs for more than two dozen U.S. weapon systems have been hacked and compromised.  The Post cited a confidential report by a Pentagon advisory panel called the Defense Science Board -- among the designs said to have been breached:  An advanced Patriot missile system; the FA-18 fighter jet; and the F-35 Joint Strike Fighter, considered the most expensive weapons system ever built.

In a written statement today, a Pentagon spokesman said the Defense Department "takes cyber-espionage very seriously," but "suggestions that cyber-intrusions have somehow led to the erosion of our capabilities or technological edge are incorrect."

Warnings about the cyber-threat from China to both the military and private businesses have grown in recent months.  In March, National Security Adviser Thomas Donilon told an audience that the attacks had to stop.

NATIONAL SECURITY ADVISOR TOM DONILON, United States:  Increasingly, U.S. businesses are speaking out about their serious concerns about sophisticated, targeted theft of confidential business information and proprietary technologies through cyber-intrusions emanating from China at a very large scale.  The international community cannot afford to tolerate such activity from any country.

Thursday, March 28, 2013

INTERNET - Spam or Not to Spam Cyber War

"Cyber War Over Spam Slows Access for Internet Users" PBS Newshour 3/27/2013

Excerpt

SUMMARY:  A dispute between an online company that sends spam emails and a company trying to mitigate spam has led to the one of the largest reporter cyber attacks in history, creating slow access to common sites like Netflix for millions of web users.  Hari Sreenivasan talks over the case with Nicole Perlroth of the New York Times.

HARI SREENIVASAN (Newshour):  One company fights spam; the other is said to be behind sending those pesky e-mails.  A dispute between the two has led to one of the largest reported cyber-attacks in Internet history, the result, widespread congestion that's slowing access for millions of users to sites like Netflix.

Nicole Perlroth has been covering the story for The New York Times, joins me now.


NOTE:  For users, this is what eMail client filters are for.  Delete spam eMails, or move spam to a [Spam] folder.

Tuesday, March 12, 2013

CYBERWAR - Demand That China Stop Hacking U.S. Cyberspace

"U.S. Demands China Block Cyberattacks and Agree to Rules" by MARK LANDLER and DAVID E. SANGER, New York Times 3/11/2013

Excerpt

The White House demanded Monday that the Chinese government stop the widespread theft of data from American computer networks and agree to “acceptable norms of behavior in cyberspace.”

The demand, made in a speech by President Obama’s national security adviser, Tom Donilon, was the first public confrontation with China over cyberespionage and came two days after its foreign minister, Yang Jiechi, rejected a growing body of evidence that his country’s military was involved in cyberattacks on American corporations and some government agencies.

The White House, Mr. Donilon said, is seeking three things from Beijing:  public recognition of the urgency of the problem; a commitment to crack down on hackers in China; and an agreement to take part in a dialogue to establish global standards.

“Increasingly, U.S. businesses are speaking out about their serious concerns about sophisticated, targeted theft of confidential business information and proprietary technologies through cyberintrusions emanating from China on an unprecedented scale,” Mr. Donilon said in a wide-ranging address to the Asia Society in New York.

“The international community,” he added, “cannot tolerate such activity from any country.”

In Beijing, a spokeswoman for the Chinese Foreign Ministry, Hua Chunying, did not directly say whether the government is willing to negotiate over the proposals spelled out by Mr. Donilon.  But at a daily news briefing Tuesday she repeated the government’s position that it opposes Internet attacks and wants “constructive dialogue” with the United States and other countries about cybersecurity issues.

Until now, the White House has steered clear of mentioning China by name when discussing cybercrime, though Mr. Obama and other officials have raised it privately with Chinese counterparts.  In his State of the Union address, he said, “We know foreign countries and companies swipe our corporate secrets.”

But as evidence has emerged suggesting the People’s Liberation Army is linked to hacking, the China connection has become harder for the administration not to confront head-on.  The New York Times three weeks ago published evidence tying one of the most active of the Chinese groups to a neighborhood in Shanghai that is headquarters to a major cyberunit of the People’s Liberation Army.  That account, based in large part on unclassified work done by Mandiant, a security firm, echoed the findings of intelligence agencies that have been tracking the Chinese attackers.

American officials say raising the issue with the Chinese is a delicate balancing act at a time when the United States is seeking China’s cooperation in containing North Korea’s nuclear and missile programs, and joining in sanctions on Iran.  Yet they have been expressing their concerns about cyberattacks with Chinese officials for years.  Starting in 2010, they invited P.L.A. officials to discuss the issue — a process that has only just started — and last November, Mr. Obama broached the subject at a summit meeting with Prime Minister Wen Jiabao, a senior administration official said.

Monday, March 04, 2013

CYBERWAR - Pinning Down Motive For Hacking Against U.S.

"As Hacking Against U.S. Rises, Experts Try to Pin Down Motive" by NICOLE PERLROTH, DAVID E. SANGER, and MICHAEL S. SCHMIDT; New York Times 3/3/2013

Excerpt

When Telvent, a company that monitors more than half the oil and gas pipelines in North America, discovered last September that the Chinese had hacked into its computer systems, it immediately shut down remote access to its clients’ systems.

Company officials and American intelligence agencies then grappled with a fundamental question: Why had the Chinese done it?

Was the People’s Liberation Army, which is suspected of being behind the hacking group, trying to plant bugs into the system so they could cut off energy supplies and shut down the power grid if the United States and China ever confronted each other in the Pacific?  Or were the Chinese hackers just trolling for industrial secrets, trying to rip off the technology and pass it along to China’s own energy companies?

“We are still trying to figure it out,” a senior American intelligence official said last week.  “They could have been doing both.”

Telvent, which also watches utilities and water treatment plants, ultimately managed to keep the hackers from breaking into its clients’ computers.

At a moment when corporate America is caught between what it sees as two different nightmares — preventing a crippling attack that brings down America’s most critical systems, and preventing Congress from mandating that the private sector spend billions of dollars protecting against that risk — the Telvent experience resonates as a study in ambiguity.

To some it is prime evidence of the threat that President Obama highlighted in his State of the Union address, when he warned that “our enemies are also seeking the ability to sabotage our power grid, our financial institutions, our air traffic control systems,” perhaps causing mass casualties.  Mr. Obama called anew for legislation to protect critical infrastructure, which was killed last year by a Republican filibuster after intensive lobbying by the Chamber of Commerce and other business groups.

But the security breach of Telvent, which the Chinese government has denied, also raises questions of whether those fears — the subject of weekly research group reports, testimony and Congressional studies — may be somewhat overblown, or whether the precise nature of the threat has been misunderstood.

American intelligence officials believe that the greater danger to the nation’s infrastructure may not even be China, but Iran, because of its avowal to retaliate for the Stuxnet virus created by the United States and Israel and unleashed on one of its nuclear sites.  But for now, these officials say, that threat is limited by gaps in Iranian technical skills.

There is no doubt that attacks of all kinds are on the rise.  The Department of Homeland Security has been responding to intrusions on oil pipelines and electric power organizations at “an alarming rate,” according to an agency report last December.  Some 198 attacks on the nation’s critical infrastructure systems were reported to the agency last year, a 52 percent increase from the number of attacks in 2011.

Researchers at McAfee, a security firm, discovered in 2011 that five multinational oil and gas companies had been attacked by Chinese hackers.  The researchers suspected that the Chinese hacking campaign, which they called Night Dragon, had affected more than a dozen companies in the energy industry.  More recently, the Department of Energy confirmed in January that its network had been infiltrated, though it has said little about what damage, if any, was done.

But security researchers say that the majority of those attacks were as ambiguous as the Telvent case.  They appeared to be more about cyberespionage, intended to bolster the Chinese economy.  If the goal was to blow up a pipeline or take down the United States power grid, the attacks would likely have been of a different nature.

In a recent report, Critical Intelligence, an Idaho Falls security company, said that several cyberattacks by “Chinese adversaries” against North American energy firms seemed intended to steal fracking technologies, reflecting fears by the Chinese government that the shale energy revolution will tip the global energy balance back in America’s favor.  “These facts are likely a significant motivation behind the wave of sophisticated attacks affecting firms that operate in natural gas, as well as industries that rely on natural gas as an input, including petrochemicals and steel-making,” the Critical Intelligence report said, adding that the attack on Telvent, and “numerous” North American pipeline operators may be related.

American intelligence experts believe that the primary reason China is deterred from conducting an attack on infrastructure in the United States is the simple economic fact that anything that hurts America’s financial markets or transportation systems would also have consequences for its own economy.

COMMENT:  The REASON for hacking U.S. systems is in reality irrelevant.  The ABILITY to hack our systems is, or should be, the point.  Hacking methods used for economic reasons can be use for more destructive reasons.

Monday, February 25, 2013

CYBERWAR - Cyberspace Cold War

"A New Cold War, in Cyberspace, Tests U.S. Ties to China" by DAVID E. SANGER, New York Times 2/24/2013

Excerpt

When the Obama administration circulated to the nation’s Internet providers last week a lengthy confidential list of computer addresses linked to a hacking group that has stolen terabytes of data from American corporations, it left out one crucial fact:  that nearly every one of the digital addresses could be traced to the neighborhood in Shanghai that is headquarters to the Chinese military’s cybercommand.

That deliberate omission underscored the heightened sensitivities inside the Obama administration over just how directly to confront China’s untested new leadership over the hacking issue, as the administration escalates demands that China halt the state-sponsored attacks that Beijing insists it is not mounting.

The issue illustrates how different the worsening cyber-cold war between the world’s two largest economies is from the more familiar superpower conflicts of past decades — in some ways less dangerous, in others more complex and pernicious.

Administration officials say they are now more willing than before to call out the Chinese directly — as Attorney General Eric H. Holder Jr. did last week in announcing a new strategy to combat theft of intellectual property.  But President Obama avoided mentioning China by name — or Russia or Iran, the other two countries the president worries most about — when he declared in his State of the Union address that “we know foreign countries and companies swipe our corporate secrets.”  He added:  “Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions and our air traffic control systems.”

Defining “enemies” in this case is not always an easy task.  China is not an outright foe of the United States, the way the Soviet Union once was; rather, China is both an economic competitor and a crucial supplier and customer.  The two countries traded $425 billion in goods last year, and China remains, despite many diplomatic tensions, a critical financier of American debt.  As Hillary Rodham Clinton put it to Australia’s prime minister in 2009 on her way to visit China for the first time as secretary of state, “How do you deal toughly with your banker?”

In the case of the evidence that the People’s Liberation Army is probably the force behind “Comment Crew,” the biggest of roughly 20 hacking groups that American intelligence agencies follow, the answer is that the United States is being highly circumspect.  Administration officials were perfectly happy to have Mandiant, a private security firm, issue the report tracing the cyberattacks to the door of China’s cybercommand; American officials said privately that they had no problems with Mandiant’s conclusions, but they did not want to say so on the record.

That explains why China went unmentioned as the location of the suspect servers in the warning to Internet providers.  “We were told that directly embarrassing the Chinese would backfire,” one intelligence official said.  “It would only make them more defensive, and more nationalistic.”

That view is beginning to change, though.  On the ABC News program “This Week” on Sunday, Representative Mike Rogers, Republican of Michigan and chairman of the House Intelligence Committee, was asked whether he believed that the Chinese military and civilian government were behind the economic espionage.  “Beyond a shadow of a doubt,” he replied.

In the next few months, American officials say, there will be many private warnings delivered by Washington to Chinese leaders, including Xi Jinping, who will soon assume China’s presidency.  Both Tom Donilon, the national security adviser, and Mrs. Clinton’s successor, John Kerry, have trips to China in the offing.  Those private conversations are expected to make a case that the sheer size and sophistication of the attacks over the past few years threaten to erode support for China among the country’s biggest allies in Washington, the American business community.

Wednesday, February 20, 2013

CYBERWAR - Chinese Military Hacking Unit

"More Evidence Chinese Military Unit Hacked Hundreds of U.S. Computer Systems" (Part-1) PBS Newshour 2/19/2013

JUDY WOODRUFF (Newshour):  A U.S. security firm charged today that there's an all-out effort to break into computer systems in the U.S. and elsewhere.  The report laid out an extensive case against China and its military.

The newest allegations of cyber-attacks by the Chinese government came up at the White House today.  Reporters asked spokesman Jay Carney about a study that blames China's military for a large-scale years-long hacking campaign.

JAY CARNEY, White House Press Secretary:  We have repeatedly raised our concerns at the highest levels about cyber-theft with senior Chinese officials, including in the military, and we will continue to do so.

JUDY WOODRUFF:  The report alleges this nondescript 12-story office building is the locus of the hacking.  It's situated in Shanghai and is run by Unit 61398, a bureau within the general staff of the People's Liberation Army.

A Virginia-based security firm, Mandiant Corporation, traced the hacking there and concluded it is one of the most prolific cyber-espionage groups in terms of the sheer quantity of information stolen.  Mandiant said the Chinese stole reams of information from U.S. military contractors, energy companies, the aerospace and telecommunications industry and others.

In Beijing, a Chinese government spokesman called the report groundless, without addressing the specific findings.

HONG LEI, Chinese Foreign Ministry Spokesman:  China firmly opposes hacking, has implemented relevant laws and regulations and adopted strict enforcement measures to prevent hacking activities.  China is also a victim of Internet hacking attacks.

We have stressed many times that hacking attacks are transnational and anonymous.  Determining their origins is extremely difficult.  We don't know how the evidence in this so-called report can be tenable.

JUDY WOODRUFF:  Still, the Mandiant findings are some of the most detailed accusations yet against China over hacking.

More generally, a U.S. national intelligence estimate said this month that China is carrying out a major cyber-espionage campaign against American targets.  And Apple said today it was hacked by the same group that attacked Facebook last week.  Both companies said no data was compromised and both traced the attacks back to China.

The report noted that there have been more than 140 different victims since 2006, and that the Chinese unit maintained access to those networks for nearly a year on average.


"U.S. Security Firm Report Says Chinese Hackers Targeted Over 140 Victims" (Part-2) PBS Newshour 2/19/2013

Excerpt

SUMMARY:  Though China denies the allegations, security firm Mandiant has issued a report detailing years of prolific cyber-espionage against the U.S. by a Chinese military unit.  Mandiant's Richard Bejtlich and Christopher Johnson from the Center for Strategic and International Studies join Judy Woodruff to discuss what was stolen.



"Chinese Army Unit Is Seen as Tied to Hacking Against U.S." by DAVID E. SANGER, DAVID BARBOZA, and NICOLE PERLROTH; New York Times 2/18/2013

Monday, February 18, 2013

CYBERWAR - Examining Cyber Security

"Examining Cyber Security With Homeland Security Secretary Janet Napolitano" PBS Newshour 2/15/2013

Excerpt

SUMMARY:  Among the initiatives launched by President Obama in his State of the Union address was a comprehensive cyber security plan.  Homeland Security Secretary Janet Napolitano talks with Ray Suarez about combating the growing threat of cyber attacks and the top three countries poised to launch cyber attacks against the U.S.

Wednesday, February 13, 2013

AMERICA - Cybersecurity, Executive Orders vs CISPA

"Obama's Cybersecurity Executive Order vs. CISPA: Which Approach Is Best?" by Chloe Albanesius, PCMag.com 2/13/2013

As part of his State of the Union speech last night, President Obama tipped an executive order that is intended to improve the security of Internet-based critical infrastructure.  But what does that order include?

Obama's plan would allow federal agencies to notify private companies if they detect any sort of cyber intrusion that would harm operations or the security of company data.

Specifically, the plan expands the Defense Industrial Base (DIB) information-sharing program to other federal agencies.  The DIB was put in place in 2011 and allows the Defense and Homeland Security Departments to share non-classified information about cybersecurity-related threats with DIB partner companies, like contractors.

But as we've seen with hacks of the Federal Reserve and the Department of Energy, defense-related agencies are not the only ones being targeted by hackers.  So the executive order "requires Federal agencies to produce unclassified reports of threats to U.S. companies and requires the reports to be shared in a timely manner," the White House said.  It also allows for "near real-time sharing of cyber threat information to assist participating critical infrastructure companies in their cyber protection efforts."

Obama has also ordered the National Institute of Standards and Technology (NIST) to develop a framework for handling cyber-security threats.  "NIST will work collaboratively with industry to develop the framework, relying on existing international standards, practices, and procedures that have proven to be effective," the White House said.

Given the rapid pace of technology, the recommendations will be technology neutral, the administration said.  Once they've been developed, DHS will work with other agencies to reach out to companies for voluntary implementation of the framework.

While sharing details about cyber attacks might seem like a no brainer, a major concern is how the data is handled.  If these threats deal with a credit card company or major social network, will your personal information be protected?

The White House insisted that the executive order includes "strong privacy and civil liberties protections."  Any type of information sharing will be based on the Fair Information Practice Principles (FIPP), a set of information-sharing principles developed by the FTC, as well as other applicable privacy and civil liberties policies, principles, and frameworks.

"Agencies will conduct regular assessments of privacy and civil liberties impacts of their activities and such assessments will be made public," the White House said.

Executive Order vs. CISPA

Last night, Obama called on Congress to do even more on cyber security.  Two members of the House, in fact, plan to re-introduce the controversial CISPA information-sharing bill today, but it has not secured the support of the White House.  A bill backed by the administration was introduced in the Senate last year, but did not make any major headway.

The main difference between the White House executive order and CISPA is that CISPA would allow private companies (like Facebook or Google) to share details about cyber attacks with the government, whereas the executive order is a one-way street, with the feds sharing information with the private sector.  CISPA opponents were concerned about immunity clauses that they said would incentivize companies to hand over customer information without hesitation.

As a result, the White House threatened to veto CISPA if it made it to President Obama's desk.  The White House Office of Management and Budget (OMB) released a statement that said the bill "departs from longstanding efforts to treat the Internet and cyberspace as civilian spheres."

In a statement last night, the ACLU issued its support for the executive order and warned against CISPA.  "The president's executive order rightly focuses on cybersecurity solutions that don't negatively impact civil liberties," said ACLU Legislative Counsel Michelle Richardson.  "For example, greasing the wheels of information sharing from the government to the private sector is a privacy-neutral way to distribute critical cyber information."

Broadband trade association USTelecom said the executive order "takes some important steps toward achieving policy goals that will help protect our nation from harmful threats," but said the issue should ultimately be handled by Congress - via bills like CISPA.

Friday, February 01, 2013

CYBERWAR - New York Times Hacked by China

"New York Times Computer System Target of Lengthy Chinese Hacking Attack" PBS Newshour 1/31/2013

Excerpt

SUMMARY:  The New York Times fell victim to a four-month cyber attack by Chinese hackers who cracked passwords to more than 50 email accounts, including those of top reporters.  Ray Suarez talks with Times reporter Nicole Perlroth and Grady Summers, vice president of the cyber security company hired to investigate the attacks.