Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, August 27, 2018

CYBERSECURITY - Offense & Defense

What do you expect?  The hacking got Trump in the White House and Republicans in the driver seat.  'They' are not really going to stop that.

"Playing offense and defense in the face of cybersecurity threats" PBS NewsHour 8/22/2018

Excerpt

SUMMARY:  In the past 48 hours, findings have been released regarding attempts by hackers to influence the midterm elections.  Now, the Democratic National Committee has reportedly asked the FBI to investigate an attempt to infiltrate its voter database.  Nick Schifrin joins Amna Nawaz to discuss what groups might be responsible for hacking and what preventive measures are being deployed.

Monday, January 08, 2018

SECURITY - Your Computer

As a retired Computer System Specialist and IT Technician, I had to deal with this issue on a regular bases and have over 40yrs experience.  There are simple steps that can protect your computer:
  • You cannot be hacked if your computer is OFF (not just logged out).
  • Your computer cannot be hacked if you are NOT online.  Disable your internet connection if you have no need to use the internet.  AND never go online without an anti-virus.
  • BUY a very high quality anti-virus utility.  'Free' anti-virus utilities (including Windows Defender) do NOT have all the features you need, most are only demo versions of a full utility you can purchase.
  • ALWAYS keep your Operator System up-to-date!

"Is your computer safe from hackers?" PBS NewsHour 1/4/2018

This particular issue applies to shared users.

Excerpt

SUMMARY:  This week, Google announced the discovery of three design flaws in processors of computers, tablets and smartphones that could let hackers access data.  Dmitri Alperovitch, co-founder of CrowdStrike, tells Hari Sreenivasan about the vulnerabilities and what’s being done to address them.

Monday, October 09, 2017

THE RUSSIA FILE - Hacked NSA Documents

"Report: Russia hacked NSA documents with aid from antivirus software" PBS NewsHour 10/5/2017

Excerpt

SUMMARY:  The Wall Street Journal reported that Russia obtained classified information about how the U.S. military protects its computer networks and conducts electronic spying.  The breach occurred when data was stolen by an NSA contractor, then hacked by Russia.  Hari Sreenivasan speaks with The Wall Street Journal's Shane Harris.

Monday, September 11, 2017

DATA SECURITY - The Equifax Hack


"Hackers accessed personal data from 143 million Equifax customers.  Here's what we know." by Erica R. Hendry, PBS NewsHour 9/7/2017
Equifax, a major credit reporting agency, announced Thursday that hackers had gained access to personal data from approximately 143 million of its customers.

Here's what we know.

What happened?

Sometime between mid-May and July, hackers breached an Equifax web application, gaining access to the names, birth dates, addresses, Social Security numbers and, in some cases, driver's license numbers of some 143 million customers, the company said in a blog post Thursday.

Equifax discovered the breach July 29.  The company says it has “no evidence of unauthorized activity on Equifax's core consumer or commercial credit reporting databases.”

Who's affected?

Equifax is one of the three major credit tracking companies in the country.

The number of customers affected in this breach amounts to nearly half of the entire U.S. population, which was 324 million in a U.S. census count in January, CNBC points out.

Along with the sensitive personal data, hackers also gained access to credit card numbers of 209,000 U.S. customers and documents related to credit report disputes from another 182,000 American consumers.

TechCrunch says citizens of Canada and the UK were also affected by the breach.

How bad is this?

As TechCrunch put it:  “pretty bad.”

Reporter Ron Miller writes:

This is not the worst breach of all time by a long shot in terms of pure numbers.  That distinction goes to Yahoo, now part of Oath (which was acquired by our parent company, Verizon).  They had a leak involving more than a billion users.

But this leak is particularly worrisome because Equifax is a credit reporting service and tracks a history of your consumer life, credit cards, credit scores and more — and it gives the black market a potential gold mine of information about people's financial lives.

“In addition to the number [of victims] being really large, the type of information that has been exposed is really sensitive,” said Beth Givens, executive director of the Privacy Rights Clearinghouse, told the Washington Post.  “All in all, this has the potential to be a very harmful breach to those who are affected by it.”

What's next?

Equifax's stock fell 9 percent after the news broke, USA Today noted.

The company has set up a website — www.equifaxsecurity2017.com — for consumers to see whether, and how much of, their data was breached.  It's offering free credit monitoring to all those affected by the hack.

Meanwhile, law enforcement and an independent cybersecurity firm are investigating the scope of the hack and how it occurred.  They're expecting to release their findings in the coming weeks.



"Did the Equifax hack put your personal data at risk?  Here's what to do now." PBS NewsHour 9/8/2017

Excerpt

SUMMARY:  Half of all Americans could have had their sensitive data compromised by a security breach at the credit reporting agency Equifax.  William Brangham joins John Yang to discuss what happened and what consumers should do to safeguard their credit.

Monday, July 24, 2017

POLITICS - Hack the Vote Trauma?

"How Russia hacked American faith in the democratic process" PBS NewsHour 7/20/2017

Excerpt

SUMMARY:  What did the Russian government really do to the American voting process and confidence in its efforts to meddle with the 2016 election?  A new cover story for TIME magazine takes a deep dive into the lengths at which the Obama administration and cybersecurity officials tried to protect the U.S. election system.  Judy Woodruff takes a closer look with its author, Massimo Calabresi of TIME.

Monday, May 22, 2017

CYBER SECURITY - The Global Cyber Attack, Update

"Microsoft’s president says global cyberattack is a ‘wakeup call’" PBS NewsHour 5/15/2017

Excerpt

SUMMARY:  A global ransomware attack has hit more than 200,000 victims, such as hospitals and schools, in more than 150 countries since Friday.  The virus takes advantage of a security flaw in Microsoft's Windows operating system, which the company patched in March, though many users ignored the fix or refused to pay for it.  William Brangham reports and Judy Woodruff talks to Microsoft President Brad Smith.




"When should the government reveal cyber flaws to tech companies?" PBS NewsHour 5/15/2017

Excerpt

SUMMARY:  If the government can detect that there is a hole in a company's software that makes it vulnerable to attack, do they have an obligation to tell that company, even if it gives away the government's tool for conducting surveillance?  William Brangham speaks with Eric Geller of POLITICO about that tension and what consumers need to know when it comes to cybersecurity and how to protect themselves.

Thursday, May 18, 2017

NATIONAL SECURITY - Trump Properties Vulnerable

QUESTION:  Where is Homeland Security and the Secret Service in all this?  Are they not protecting a President against this?!

"Any Half-Decent Hacker Could Break Into Mar-a-Lago" by Jeff Larson and Julia Angwin (ProPublica) and Surya Mattu, (Gizmodo), ProPublica 5/18/2017

We tested internet security at four Trump properties.  It's not good.

This story was co-published with Gizmodo.

Two weeks ago, on a sparkling spring morning, we went trawling along Florida's coastal waterway.  But not for fish.

We parked a 17-foot motor boat in a lagoon about 800 feet from the back lawn of The Mar-a-Lago Club in Palm Beach and pointed a 2-foot wireless antenna that resembled a potato gun toward the club.  Within a minute, we spotted three weakly encrypted WiFi networks.  We could have hacked them in less than five minutes, but we refrained.

A few days later, we drove through the grounds of the Trump National Golf Club in Bedminster, New Jersey, with the same antenna and aimed it at the clubhouse.  We identified two open WiFi networks that anyone could join without a password.  We resisted the temptation.

We have also visited two of President Donald Trump's other family-run retreats, the Trump International Hotel in Washington, D.C., and a golf club in Sterling, Virginia.  Our inspections found weak and open WiFi networks, wireless printers without passwords, servers with outdated and vulnerable software, and unencrypted login pages to back-end databases containing sensitive information.

The risks posed by the lax security, experts say, go well beyond simple digital snooping.  Sophisticated attackers could take advantage of vulnerabilities in the WiFi networks to take over devices like computers or smart phones and use them to record conversations involving anyone on the premises.

“Those networks all have to be crawling with foreign intruders, not just ProPublica,” said Dave Aitel, chief executive officer of Immunity, Inc., a digital security company, when we told him what we found.

Security lapses are not uncommon in the hospitality industry, which — like most industries and government agencies — is under increasing attack from hackers.  But they are more worrisome in places where the President of the United States, heads of state and public officials regularly visit.

U.S. leaders can ill afford such vulnerabilities.  As both the U.S. and French presidential campaigns showed, hackers increasingly exploit weaknesses in internet security systems in an effort to influence elections and policy.  Last week, cyberattacks using software stolen from the National Security Agency paralyzed operations in at least a dozen countries, from Britain's National Health Service to Russia's Interior Ministry.

Since the election, Trump has hosted Chinese President Xi Jinping, Japanese Prime Minister Shinzo Abe and British politician Nigel Farage at his properties.  The cybersecurity issues we discovered could have allowed those diplomatic discussions — and other sensitive conversations at the properties — to be monitored by hackers.

The Trump Organization follows “cybersecurity best practices,” said spokeswoman Amanda Miller.  “Like virtually every other company these days, we are routinely targeted by cyberterrorists whose only focus is to inflict harm on great American businesses.  While we will not comment on specific security measures, we are confident in the steps we have taken to protect our business and safeguard our information.  Our teams work diligently to deploy best-in-class firewall and anti-vulnerability platforms with constant 24/7 monitoring.”

The White House did not respond to repeated requests for comment.

Trump properties have been hacked before.  Last year, the Trump hotel chain paid $50,000 to settle charges brought by the New York attorney general that it had not properly disclosed the loss of more than 70,000 credit card numbers and 302 Social Security numbers.  Prosecutors alleged that hotel credit card systems were “the target of a cyber-attack” due to poor security.  The company agreed to beef up its security; it's not clear if the vulnerabilities we found violate that agreement.  A spokesman for the New York attorney general declined comment.

Our experience also indicates that it's easy to gain physical access to Trump properties, at least when the President is not there.  As Politico has previously reported, Trump hotels and clubs are poorly guarded.  We drove a car past the front of Mar-a-Lago and parked a boat near its lawn.  We drove through the grounds of the Bedminster golf course and into the parking lot of the golf course in Sterling, Virginia.  No one questioned us.

Both President Obama and President Bush often vacationed at the more traditional presidential retreat, the military-run Camp David.  The computers and networks there and at the White House are run by the Defense Information Systems Agency.

In 2016, the military spent $64 million on maintaining the networks at the White House and Camp David, and more than $2 million on “defense solutions, personnel, techniques, and best practices to defend, detect, and mitigate cyber-based threats” from hacking those networks.

Even after spending millions of dollars on security, the White House admitted in 2015 that it was hacked by Russians.  After the hack, the White House replaced all its computer systems, according to a person familiar with the matter.  All staffers who work at the White House are told that “there are people who are actively watching what you are doing,” said Mikey Dickerson, who ran the U.S. Digital Service in the Obama administration.

By comparison, Mar-a-Lago budgeted $442,931 for security in 2016 — slightly more than double the $200,000 initiation fee for one new member.  The Trump Organization declined to say how much Mar-a-Lago spends specifically on digital security.  The club, last reported to have almost 500 members paying annual dues of $14,000 apiece, allotted $1,703,163 for all administration last year, according to documents filed in a lawsuit Trump brought against Palm Beach County in an effort to halt commercial flights from flying over Mar-a-Lago.  The lawsuit was dropped, but the FAA now restricts flights over the club when the President is there.

It is not clear whether Trump connects to the insecure networks while at his family's properties.  When he travels, the President is provided with portable secure communications equipment.  Trump tracked the military strike on a Syrian air base last month from a closed-door situation room at Mar-a-Lago with secure video equipment.

However, Trump has held sensitive meetings in public spaces at his properties.  Most famously, in February, he and the Japanese prime minister discussed a North Korean missile test on the Mar-a-Lago patio.  Over the course of that weekend in February, the President's Twitter account posted 21 tweets from an Android phone.  An analysis by an Android-focused website showed that Trump had used the same make of phone since 2015.  That phone is an older model that isn't approved by the NSA for classified use.

Photos of Trump and Abe taken by diners on that occasion prompted four Democratic senators to ask the Government Accountability Office to investigate whether electronic communications were secure at Mar-a-Lago.

In March, the GAO agreed to open an investigation.  Chuck Young, a spokesman for the office, said in an interview that the work was in “the early stages,” and did not offer an estimate for when the report would be completed.

So, we decided to test the cybersecurity of Trump's favorite hangouts ourselves.

Our first stop was Mar-a-Lago, a Trump country club in Palm Beach, Florida, where the President has spent most weekends since taking office.  Driving past the club, we picked up the signal for a WiFi-enabled combination printer and scanner that has been accessible since at least February 2016, according to a public WiFi database.

An open printer may sound innocuous, but it can be used by hackers for everything from capturing all the documents sent to the device to trying to infiltrate the entire network.

To prevent such attacks, the Defense Information Systems Agency, which secures the White House and other military networks, forbids installing printers that anyone can connect to from outside networks.  It also warns against using printers that do more than printing, such as faxing.  “If an attacker gains network access to one of these devices, a wide range of exploits may be possible,” the agency warns in its security guide.

We also were able to detect a misconfigured and unencrypted router, which could potentially provide a gateway for hackers.

To get a better line of sight, we rented a boat and piloted it to within sight of the club.  There, we picked up signals from the club's wireless networks, three of which were protected with a weak and outmoded form of encryption known as WEP.  In 2005, an FBI agent publicly broke this type of encryption in minutes.

By comparison, the military limits the signal strength of networks at places such as Camp David and the White House so that they are not reachable from a car driving by.  It also requires wireless networks to use the strongest available form of encryption.

From our desks in New York, we were also able to determine that the club's website hosts a database with an insecure login page that is not protected by standard internet encryption.  Login forms like this are considered a severe security risk, according to the Defense Information Systems Agency.

Without encryption, spies could eavesdrop on the network until a club employee logs in, and then steal his or her username and password.  They then could download a database that appears to include sensitive information on the club's members and their families, according to videos posted by the club's software provider.

This is “bad, very bad,” said Jeremiah Grossman, chief of Security Strategy for cybersecurity firm SentinelOne, when we described Mar-a-Lago's systems.  “I'd assume the data is already stolen and systems compromised.”

A few days later, we took our equipment to another Trump club in Bedminster, New Jersey.  During the transition, Trump had interviewed candidates for top administration positions there, including James Mattis, now secretary of defense.

We drove on a dirt access road through the middle of the golf course and spotted two open WiFi networks, TrumpMembers and WelcomeToTrumpNationalGolfClub, that did not require a password to join.

Such open networks allow anyone within range to scoop up all unencrypted internet activity taking place there, which could, on insecure sites, include usernames, passwords and emails.

Robert Graham, an Atlanta, Georgia, cybersecurity expert, said that hackers could use the open WiFi to remotely turn on the microphones and cameras of devices connected to the network.  “What you're describing is typical hotel security,” he said, but “it's pretty concerning” that an attacker could listen to sensitive national security conversations.

Two days after we visited the Bedminster club, Trump arrived for a weekend stay.

Then we visited the Trump International Hotel in Washington, D.C., where Trump often dines with his son-in-law and senior adviser Jared Kushner, whose responsibilities range from Middle East diplomacy to revamping the federal bureaucracy.  We surveyed the networks from a Starbucks in the hotel basement.

From there, we could tell there were two WiFi networks at the hotel protected with what's known as a captive portal.  These login screens are often used at airports and hotels to ensure that only paying customers can access the network.

However, we gained access to both networks just by typing “457” into the room number field.  Because we provided a room number, the system assumed we were guests.  We looked up the hotel's public IP address before logging off.

From our desks in New York, we could also tell that the hotel is using a server that is accessible from the public internet.  This server is running software that was released almost 13 years ago.

Finally, we visited the Trump National Golf Club in Sterling, Virginia, where the President sometimes plays golf.  From the parking lot, we recognized three encrypted wireless networks, an encrypted wireless phone and two printers with open WiFi access.

The Trump club websites are hosted by an Ohio-based company called Clubessential.  It offers everything from back-office management and member communications to tee time and room reservations.

In a 2014 presentation, a company sales director warned that the club industry as a whole is “too lax” in managing and protecting passwords.  There has been a “rising number of attacks on club websites over the last two years,” according to the presentation.  Clubessential “performed [an] audit of security in the club industry” and “found thousands of sensitive documents from clubs exposed on [the] Internet,” such as “lists of members and staff, and their contact info; board minutes, financial statements, etc.”

Still, the club software company has set up a backend server accessible on the internet, and configured its encryption incorrectly.  Anyone who reaches the login page is greeted with a warning that the encryption is broken.  In its documentation, the company advises club administrators to ignore these warnings and log in regardless.  That means that anybody snooping on the unprotected connection could intercept the administrators' passwords and gain access to the entire system.

The company also publishes online, without a password, many of the default settings and usernames for its software — essentially providing a roadmap for intruders.

Clubessential declined comment.

Aitel, the CEO of Immunity, said the problems at Trump properties would be difficult to fix: “Once you are at a low level of security it is hard to develop a secure network system.  You basically have to start over.”

Monday, October 17, 2016

POLITICAL HACKING - U.S. vs Russia

"Blaming Russia, how will the U.S. respond to pre-election hacks?" PBS NewsHour 10/11/2016

IMHO:  Wikileaks has morphed into a partisan Trump supporter and is no longer a friend nor protector of the people.  They definitely do NOT understand you cannot conduct international diplomacy nor anti-terrorist functions from within a glass-house.  A degree of secrecy is necessary.

Excerpt

SUMMARY:  WikiLeaks has been releasing emails it claims come from Clinton campaign chairman John Podesta, detailing behind-the-scenes strategy.  Meanwhile, the White House is blaming Russia for hacking Democratic party websites and attempting to influence the presidential election.  What's going on?  Hari Sreenivasan learns more from Lisa Desjardins and chief foreign affairs correspondent Margaret Warner.

HARI SREENIVASAN (NewsHour):  Since Friday, the anti-secrecy group WikiLeaks has been releasing e-mails that were hacked from the account of Hillary Clinton campaign chairman John Podesta.  The stolen messages detail how the campaign responded to important issues through the race for the White House.

It is unclear who was behind this latest digital theft, but, on Friday, the Obama administration did blame Russia for the hacking of Democratic Party Web sites earlier this year and attempts to breach state election systems, in order to influence the vote for president.

Today, White House spokesman Josh Earnest said there will be a U.S. response to the alleged Russian hacking.  He told reporters aboard Air Force One:  “The President has talked before about the significant capabilities that the U.S. government has to both defend our systems in the United States, but also carry out offensive operations in other countries.  So, there are a range of responses that are available to the President, and he will consider a response that's proportional.”

With me now to sift through what all this means in both political and diplomatic terms are the NewsHour's Margaret Warner and Lisa Desjardins.

Lisa, tell me — let's start with what is in the e-mails.

LISA DESJARDINS (NewsHour):  Right.

So, this latest dump, so people can keep track, began on Friday.  These are about 2,000 e-mails, a little bit more, coming from Clinton campaign chairman John Podesta, obviously a very big player in the Clinton world now and for years.

Now, in these, we see one of the standout notes that we have gotten — there haven't been all that many — is from a Clinton 2013 speech to an Italian bank.  You may have seen that quote.  In the speech that was referenced in these e-mails, it was purported to say — quote — “My dream is a hemispheric common market with open trade and open borders.”

Obviously, that's raised a lot of questions in this year of very heated talk about trade and especially after Clinton herself came out against one of the largest-in-history trade deals, the Trans-Pacific Partnership.

And that's probably the biggest kind of headline that's come out of these e-mails, but also they include a great deal of campaign tactics, including a 71-page briefing, sort of oppo research to some extent on Bernie Sanders.  All of this was happening during that very heated primary campaign.

Now, the Clinton campaign themselves is not confirming the authenticity of any of these e-mails.  It's very important to say that WikiLeaks has posted these.  We know they were hacked, so the authenticity is fair to question.

And the Clinton campaign is pushing back strongly, saying this is from a state actor, and this is obviously an illegal act in politics.

Monday, October 10, 2016

OPINION - Shields and Gerson 10/7/2016

"Shields and Gerson on the 2005 Trump tape, Russian hacking and the upcoming debate" PBS NewsHour 10/7/2016

Excerpt

SUMMARY:  With the only vice-presidential debate over and the second presidential one just ahead, it's the home stretch of the election -- and it's full of surprises.  Judy Woodruff talks to syndicated columnist Mark Shields and The Washington Post's Michael Gerson about the 'enthusiasm gap,' whether the new video of Trump threatens his support among evangelicals, Russian hacking, Sunday's debate and more.

JUDY WOODRUFF (NewsHour):  It's also the moment we turn to the analysis of Shields and Gerson.  That's syndicated columnist Mark Shields and Washington Post columnist Michael Gerson.  David Brooks is away.

Gentlemen, welcome.

So, there was a lot of news that we learned about late this afternoon that has to do with this campaign.

But, Mark, I do want to start quickly with a question about Georgia.  The very fact — and you heard to some of the voters we talked to — the very fact that a state that Mitt Romney won by eight points four years ago, where it's close — I mean, it's still uphill for Hillary Clinton, but it's close because of what we talked about.

MARK SHIELDS, syndicated columnist:  Yes.

No, it is.  Defined — the interviews defined the enthusiasm gap.  It isn't just on one side.  It's on both sides.  There's minimal excitement.  And, for Hillary Clinton, I think what came through in your piece is, it's not a question of the percentage of the African-American vote, in addition trying to get 30 percent of the white vote, but it's numbers.

She could get high percentages, but if you don't get numbers in the turnout — but the hope, obviously, is that Georgia can move eventually, if not this time, into the category of Virginia, North Carolina, states that have changed; Colorado, and Nevada.

JUDY WOODRUFF:  Michael.

MICHAEL GERSON, The Washington Post:  Yes.

I think that the Republican fear is exactly the Virginia example.  When Barack Obama won it in his first term, it was the first time Virginia had gone Democratic since 1964.

MARK SHIELDS:  That's right.

MICHAEL GERSON:  And now it's not even close.  It's because — Hillary Clinton is ahead by about eight points in Virginia.

The state has gotten more diverse; more Hispanics and Asians, more college-educated people.  It's gone in a certain direction that I think Republicans fear for a couple of these states that region.

JUDY WOODRUFF:  So, as we said at the outset, there’s been a blizzard of news late this afternoon, Mark, starting with the Obama administration naming Russia, saying high officials in Russia were behind these hacks against the Democratic Party and other Democratic figures.

Then you had WikiLeaks coming out soon after with information about John Podesta, who is Hillary Clinton’s campaign chairman, and some e-mailed exchanges over nuclear energy, and then the Washington Post story, which I think I want to start with that, essentially releasing the audiotape — and you heard it in John Yang’s report — showing — videotape showing Donald Trump’s lewd remarks about women about 10 years ago.

MARK SHIELDS:  Judy, let’s get one thing straight. This is not locker room talk. This is not a preteen, adolescent finding dirty words.

This is a 60-year-old man being obscene, obscene toward — in discussing women, boasting, bragging in the worst and most offensive way.

And I just think the political implications are profound.  Senator Kelly Ayotte, Republican in New Hampshire, has said she would vote for Donald Trump, but will not endorse him.  In a debate this past week, she was asked, do you consider Donald Trump to be an appropriate role model for the children of New Hampshire?  “Absolutely” was the end of her answer, was immediately pounced on.  She apologized.  Cut a spot.

Every Republican candidate in the country who is in a competitive race is going to be asked in the next week, whether in a debate or where else, by opponents or by the press, do you consider Donald Trump to be an appropriate role model for the children of our state?

And it just — as far as the women’s vote you just reported on in Georgia, it makes it so, not simply difficult.  It makes it almost impossible for somebody with self-respect, who has a mother or sister or a daughter, you know, somebody like this in Abraham Lincoln’s chair.

JUDY WOODRUFF:  Michael, how do you assess this?

MICHAEL GERSON: Well, I think the problem here is not just bad language, but predatory language, abusive language

MARK SHIELDS:  It is.

MICHAEL GERSON:demeaning language.

That indicates something about someone’s character that is disturbing, frankly, disturbing in a case like this.  And I think evangelicals have a particular problem right now.  I mean, they are the people who argued, many of whom, leaders, argued that character counts during the Bill Clinton years.

And now character apparently doesn’t count at all.  So, I think there’s a deep tension here.

Monday, October 03, 2016

HACKING THE VOTE - Manipulation of Election 2016 Results?

A gift from Donald's Russian friend.

"Could hackers compromise November election results?" PBS NewsHour 9/30/2016

Excerpt

SUMMARY:  Since the hacking of the Democratic National Committee, there has been growing concern about cyber-manipulation of election results this November.  Voter registration databases in Illinois and Arizona were penetrated in June, and the FBI reported this week on attempts against several other states.  Hari Sreenivasan talks to chief foreign affairs correspondent Margaret Warner for more on the threat.

HARI SREENIVASAN (NewsHour):  Concern has been growing about possible cyber-manipulation of the U.S. election since revelations in June that the Democratic National Committee and Democratic Congressional Committee's data had been stolen.

U.S. intelligence official pointed the finger at Russian-government-linked hackers, though wouldn't say so publicly.  Separately, Illinois and Arizona's voter registration databases were penetrated in June, forcing them to temporarily shut down.

This week, FBI Director James Comey told Congress there had been new attempts to penetrate many more state voter databases.

Margaret Warner has been looking into this and joins me now.

So, what's the real danger to the elections if voter registration databases are being hacked?

MARGARET WARNER (NewsHour):  Hari, on one hand, it could be strictly criminal.  People want to get addresses, home phone numbers, e-mails, and use it for criminal purposes.

And many states have had to deal with that in the past.  But the other danger is that information can be used to selectively used to manipulate the vote on Election Day.

For example, send out e-mails to voters in certain districts, perhaps minority districts, and, oh, your registration place has been changed, your voting place has been changed.  And this has been done often by phone.  It's an old, old trick.  Or to simply to delete them from the database, so when they get there, there is incredible confusion.

So, as a senior homeland security official told me this afternoon, the other danger that really worries us is that just the news of these hacks undermined American voters' view of the credibility of the U.S.  election system.  And there are certainly foreign powers who would like to do that.

HARI SREENIVASAN:  So, let's talk about those foreign powers.

Do the U.S. officials believe that the Russians are behind this or any of the other hacks that have been related so far?

MARGARET WARNER:  Yes.

First of all, they established that they were behind the hacks you mentioned earlier, the DNC and the DCCC, and that there are two sort of outfits, what is called Fancy Bear — it's a nickname — and one is Cozy Bear.

One is linked to the old KGB called the GRU and one is linked to military intelligence.  And I was told by cyber-experts who have been involved in these investigations that these voter database hacks are the work of so-called Fancy Bear, which is the one side to Russian military intelligence.

This is the same outfit that, in Ukraine, in Ukrainian elections two years ago, penetrated the database of the Ukrainian election authorities and tried to switch the actual plate that showed who was winning where.  They didn't succeed, but the fake plate that showed someone else won did end up on Russian TV in Russia.

Monday, September 19, 2016

HACKING THE CAMPAIGN - Election System Vulnerabilities

"How hackers could prey on election vulnerabilities" PBS NewsHour 9/15/2016

Excerpt

SUMMARY:  This week, emails written by former Secretary of State Colin Powell, which were critical of Donald Trump and Hillary Clinton, appeared on a website that's reportedly an outlet for hackers tied to Russia.  Judy Woodruff speaks with Dmitri Alperovitch of Crowdstrike and David Sanger of The New York Times about the recent wave of hacks tied to the presidential campaign and the impact on the election.

JUDY WOODRUFF (NewsHour):  This year's political campaign has a new and different wrinkle.  Cyber-hacking has led to regular public releases of documents and private e-mails involving the political parties and key players.

The Democrats are the most frequent targets.  But it's not only them.

The list of election season cyber-attacks is growing.  The latest target, former Secretary of State Colin Powell.  A trove of his e-mails appeared online this week after his personal account was hacked.  In one referring to GOP nominee Donald Trump and black voters, Powell wrote, “He takes us for idiots.”

Another referred to Democrat Hillary Clinton as greedy, not transformational.  The messages were posted on a site that's reportedly an outlet for hackers tied to Russia.

Clinton today did blame the Russians.  The White House wasn't saying.

JOSH EARNEST, White House Press Secretary:  We don't necessarily want to reveal sources and methods that the FBI uses to conduct these kinds of investigations.

JUDY WOODRUFF:  All of this follows the July release of thousands of Democratic National Committee e-mails.  They were published on WikiLeaks just before the Democratic Convention.  And on Tuesday, WikiLeaks tweeted a link to more DNC files.  The Web site's founder, Julian Assange, claimed in an interview with the NewsHour last month that it's done in the public interest.

JULIAN ASSANGE, Founder, WikiLeaks:  And that performs an ongoing role leading to great works in investigative journalism, successful court cases, civil litigation, criminal process, and, of course, also contributes to public understanding.

JUDY WOODRUFF:  Meanwhile, Politico reports hackers are also targeting state Democratic officials.  And congressman Michael McCaul, chair of the House Homeland Security Committee, says Republican operatives have been hacked as well.

Still, in Washington yesterday, the president's homeland security adviser, Lisa Monaco, played down any threat to the integrity of the election, but added:

LISA MONACO, Assistant to the President for Homeland Security:  The efforts of malicious actors to intrude upon voter registration databases and other elements of our critical infrastructure, as well as our voting infrastructure, is of concern.

JUDY WOODRUFF:  The White House says if there is a response to the hacking, it may not be announced in advance, or ever.

For a deeper look at the actors and the politics behind the hacks, we turn to Dmitri Alperovitch.  He's co-founder and chief technology officer at CrowdStrike.  That's the cyber-security firm that investigated online breaches of the Democratic Party over the summer.  And David Sanger, chief Washington correspondent for The New York Times.

Tuesday, August 30, 2016

ELECTION THREAT - Russian Hack of Voting System

"FBI WARNS OF ELECTION HACK" by Ellen Nakashima, San Diego Union-Tribune 8/30/2016

NOTE: This is from the online edition of the newspaper, therefore no article link.

Agency alerted Arizona officials that Russians were behind assault on state’s voting system

The FBI is investigating a series of suspected foreign hacks of state election computer systems and websites, and has warned states to be on the alert for potential intrusions.

Hackers have targeted voter registration systems in Illinois and Arizona, and the FBI alerted Arizona officials in June that Russians were behind the assault on the system in that state.

The bureau described the threat as “credible” and significant, “an eight on a scale of one to 10,” Matt Roberts, a spokesman for Arizona Secretary of State Michele Reagan, said Monday.  As a result, Reagan shut down the state’s voter registration system for nearly a week.

It turned out that the hackers had not compromised the state system or even any county system.  They had, however, stolen the user name and password of a single elections official in Gila County.

Roberts said FBI investigators did not specify whether the hackers were criminals or employed by the Russian government.  Bureau officials on Monday declined to comment.

The Arizona incident is the latest indication of Russian interest in U.S. elections and party operations, and follows the discovery of a high profile penetration into Democratic National Committee computers.  That hack produced embarrassing emails that led to the resignation of DNC Chairwoman Debbie Wasserman Schultz and sowed dissension on the eve of Hillary Clinton’s nomination as the party’s presidential candidate.

The Russian campaign is also sparking intense anxiety about the security of this year’s elections.  Earlier this month, the FBI warned state officials to be on the lookout for intrusions into their elections systems.  The “flash” alert, which was first reported by Yahoo News, said investigators had detected attempts to penetrate election systems in several states and listed internet protocol addresses and other technical fingerprints associated with the hacks.  In addition to Arizona, Illinois officials discovered an intrusion into their elections system in July.  Although the hackers did not alter any data, the intrusion marks the first successful compromise of a state voter registration database, federal officials said.

“This was a highly sophisticated attack most likely from a foreign (international) entity,” said Kyle Thomas, director of voting and registration systems for the Illinois State Board of Elections, in a message that was sent to all election authorities in the state.

The Illinois hackers were able to retrieve voter records, but the number accessed was “a fairly small percentage of the total,” said Ken Menzel, general counsel for the Illinois elections board.

State officials alerted the FBI, he said, and the Department of Homeland Security also was involved.  The intrusion in Illinois led to a week-long shutdown of the voter registration system.

The FBI has told Illinois officials that it is looking at foreign government agencies and criminal hackers as potential culprits, Menzel said.

At least two other states are looking into possible breaches, officials said.  Meanwhile, states across the nation are scrambling to ensure that their systems are secure.

Until now, countries such as Russia and China have shown little interest in voting systems in the United States.  But experts said that if a foreign government gained the ability to tamper with voter data — for instance by deleting registration records — such a hack could cast doubt on the legitimacy of U.S. elections.

“I’m less concerned about the attackers getting access to and downloading the information.  I’m more concerned about the information being altered, modified or deleted.  That’s where the real potential is for any sort of meddling in the election,” said Brian Kalkin, vice president of operations for the Center for Internet Security, which operates the MS-ISAC, a multistate information-sharing center that helps government agencies combat cyberthreats and works closely with federal law enforcement.

Nonetheless, the Senate minority leader, Harry Reid of Nevada, asked the FBI Monday to investigate evidence suggesting that Russia may try to manipulate voting results.  In a letter to FBI Director James Comey, Reid wrote that the threat of Russian interference “is more extensive than is widely known and may include the intent to falsify official election results.” Recent classified briefings from senior intelligence officials, Reid said, have left him fearful that President Vladimir Putin’s “goal is tampering with this election.”

Reid argued that the connections between some of Donald Trump’s former and current advisers and the Russian leadership should, by itself, prompt an investigation.  He referred indirectly in his letter to a speech given in Russia by one Trump adviser, Carter Page, a consultant and investor in the energy giant Gazprom, who criticized U.S.  sanctions policy toward Russia.

“Trump and his people keep saying the election is rigged,” Reid said.  “Why is he saying that?  Because people are telling him the election can be messed with.”  Trump’s advisers say they are concerned that unnamed elites could rig the election for Clinton.  Reid argued that if Russia concentrated on “less than six” swing states, it could alter results and undermine confidence in the electoral system.  That would pose challenges, given that most states have paper backups, but he noted that hackers could keep people from voting by tampering with the rolls of eligible voters.

James Clapper, the director of national intelligence, has told Congress that manipulation or deletion of data is the next big cyberthreat — “the next push on the envelope.”  Tom Hicks, chairman of the federal Election Assistance Commission, an agency set up by Congress after the 2000 Florida recount to maintain election integrity, said he is confident that states have sufficient safeguards in place to ward off attempts to manipulate data.  For example, if a voter’s name were deleted and did not show up on the precinct list, the individual could still cast a provisional ballot, Hicks said.  Once the voter’s status was confirmed, the ballot would be counted.

Hicks also said the actual systems used to cast votes “are not hooked up to the internet” and so “there’s not going to be any manipulation of data.”  However, more than 30 states have some provisions for online voting, primarily for voters living overseas or serving in the military.

This spring, a DHS official cautioned that online voting is not yet secure.

“We believe that online voting, especially online voting in large scale, introduces great risk into the election system by threatening voters’ expectations of confidentiality, accountability and security of their votes and provides an avenue for malicious actors to manipulate the voting results,” said Neil Jenkins, an official in the department’s Office of Cybersecurity and Communications.

Private-sector researchers are also concerned about potential meddling by Russians in the U.S. elections system.  Rich Barger, chief information officer at ThreatConnect, said that several of the IP addresses listed in the FBI alert trace back to a website-hosting service called King Servers that offers Russia-based technical support.  Barger also said that one of the methods used was similar to a tactic employed in other intrusions suspected of being carried out by the Russian government, including one this month on the World Anti-Doping Agency.

“The very fact that (someone) has rattled the doorknobs, the very fact that the state election commissions are in the cross hairs, gives grounds to the average American voter to wonder: Can they really trust the results?” Barger said.

Nakashima writes for The Washington Post.  The New York Times contributed to this report.

Monday, August 22, 2016

CYBER WAR - NSA Code Breach

"Analyzing the NSA code breach in the context of recent cybersecurity events" PBS NewsHour 8/17/2016

Excerpt

SUMMARY:  On Saturday, programming code for National Security Agency hacking tools was shared online.  The content appears to be legitimate, but it is not clear if it was intentionally hacked or accidentally leaked.  Hari Sreenivasan speaks with The Washington Post's Ellen Nakashima and Paul Vixie of Farsight Security about where this development fits in the context of other recent cybersecurity breaches.

HARI SREENIVASAN (NewsHour):  The National Security Agency's primary mission is to spy on the electronic communications of countries and people overseas.

Over the weekend, though, sophisticated code the NSA developed to penetrate computer security systems was posted online.  This serious breach comes amid the ongoing revelations of the hacking of the Democratic National Committee and other organizations, allegedly by groups linked to Russian intelligence.

For more on this, we turn to The Washington Post national security correspondent Ellen Nakashima, and Paul Vixie.  He designed and built some of the software that is the backbone of the Internet today.  He is now chairman and CEO of Farsight Security, a computer security firm.

Ellen Nakashima, what happened this weekend?  What got released?

ELLEN NAKASHIMA, The Washington Post:  Over the weekend, apparently on Saturday, mysteriously, a cache of NSA hacking tools was released online through file-sharing sites such as BitTorrent and Dropbox.

It really wasn't noticed until about Monday, when the computer security community started commenting on it and questions arose as to whether or not the NSA had been hacked.

HARI SREENIVASAN:  So, Paul Vixie, if these lock picks, these digital tools to try break into different systems out are out in the open now, these are the tools that the American government was using, what is the consequence, if it is in the public sphere?

PAUL VIXIE, Farsight Security:  Well, I think, every day, everybody is trying to hack everybody.  So, this is not huge news.

What's big news about it is that these tools were built by the U.S. government.  Some of the lock picks, as you call them, are now obsolete.  They are relying on vulnerabilities that have since been closed, because the files are about 3 years old.

But at least one of them is active against a very current piece of equipment from CiscoAnd it is going to lead to a lot of break-ins while the patches are prepared and shipped and then applied.

Monday, August 01, 2016

RUSSIA - Hacking DCCC and Clinton?

"Clinton's campaign and the DCCC are cyber hacked — was it the Russians?" PBS NewsHour 7/29/2016

Excerpt

SUMMARY:  Clinton's campaign and the Democratic Congressional Campaign Committee have been cyber hacked.  Sources told the NewsHour the DCCC hacker is the same as one that hit the Democratic National Committee.  U.S. intel officials believe they're Russian.  Judy Woodruff talks with Susan Hennessey of the Brookings Institution and Andrew Weiss, of the Carnegie Endowment for International Peace for insight.

JUDY WOODRUFF (NewsHour):  We return to the hacking of the Democratic National Committee.

According to reports, U.S. intelligence has high confidence the Russian government was behind it.  Sources close to the investigation told the “NewsHour” one of the hackers was also involved in the breach of the Democratic Congressional Campaign Committee, and then today's revelations that Hillary Clinton's campaign was also hacked.

We explore how the U.S. government should respond now with Susan Hennessey.  She was an attorney in the Office of the General Counsel of the National Security Agency.  She is now a fellow at the Brookings Institution.  And Andrew Weiss; he has worked for both Republican and Democratic administrations, as a staffer on the National Security Council [and] in the State and Defense Departments.  He is now at the Carnegie Endowment for International Peace.

And we welcome both of you to the “NewsHour.”

Susan Hennessey, let me start with you.

Before I even ask you about the hacking of the Clinton campaign itself, which we just learned about this afternoon, how confident are you that it was the Russian government that was behind the hacking into the DNC and the Congressional Campaign Committee?

SUSAN HENNESSEY, Brookings Institution:  All right, so when attributing cyber-attacks, it's almost impossible to ever be 100 percent certain.

In this case, you are about as certain as you could reasonably expect to be.  There were strong technical indicators that emerged as early as June.

Now I'm hearing that the intelligence community has reported to the president high confidence.  That's a likely indicator that they have found corroborating evidence through other intelligence mechanisms, signals intelligence, financial intelligence, human intelligence

So, at this point, it's a fair operating assumption.  There might be some room for plausible deniability, but it's really quite certain.

JUDY WOODRUFF:  All right, I just want to say, we're having a little difficulty with your microphone.  We're going to trying to get that fixed.

I'm going to turn right now to Andrew Weiss.

What about you?  How much confidence do you have that it's clearly the Russian government behind what we know so far?

ANDREW WEISS, Carnegie Endowment for International Peace:  Well, so far, this is a very fast-moving story.  And I think we all need to be cautious, because the facts are not clearly out there.

Yesterday, General Clapper, who is the president's director of national intelligence, was talking in Aspen, and he said he wasn't prepared at this stage to make a call.  But so far, everything that has dribbled out seems to point in the direction of some form of Russian government involvement.

There's been forensic data that has been trumped out — dribbled into the press that points to comparable attacks that have been attributed to Russia over the past several months.  And the attacks on the DNC and the DCCC seem to be fitting within the same group of Russian actors.

Monday, July 11, 2016

DOCUMENTARY - "Zero Days"

"‘Zero Days,’ a detective story about the cyber warfare arms race" PBS NewsHour 7/7/2016

Excerpt

SUMMARY:  “Zero Days,” a new documentary by Alex Gibney, lays out a sobering view of the rise of cyber warfare and its acceleration since intelligence agencies sabotaged Iran’s nuclear program.  Gibney sits down with Jeffrey Brown.

HARI SREENIVASAN (NewsHour):  A new documentary lays out a sobering view about the use of cyber-warfare, a future that’s accelerated since intelligence agencies sabotaged Iran’s nuclear program.

The film, called “Zero Days,” opens in more than a dozen cities tomorrow and will be available online.

Its director stopped by as part of the recent AFI Docs festival.

Jeffrey Brown has our conversation.

JEFFREY BROWN (NewsHour):  The 2010 cyber-attack on an Iranian nuclear facility dubbed Stuxnet, the first question was, what exactly was this sophisticated weapon, the second, who created and carried it out, and in the years since, many new questions have arisen about cyber-warfare and the new world we live in.

The documentary “Zero Days” pulls together what happened with Stuxnet and since.

Alex Gibney, Academy Award-winning documentary maker of numerous films, joins me now.

Welcome to you.

ALEX GIBNEY, Director, “Zero Days”:  Thank you.

JEFFREY BROWN:  Why was this a subject you wanted to tackle?

ALEX GIBNEY:  It seemed like it was a story that was about the Internet and the militarization of the Internet, but wasn’t properly understood.  And I certainly didn’t understand it, so it made me want to dig in.



Trailer Quotes:

  • "Get Ready to Get Very, Very Paranoid"
  • "Welcome to the Next Global War"

Monday, June 20, 2016

RUSSIA - Political Hacking

"Inside Russian hacking of Democrats' opposition research on Trump" PBS NewsHour 6/14/2016

Excerpt

SUMMARY:  For nearly a year, Russian hackers have been penetrating Democratic National Committee computers and stealing, among other things, research compiled on presumptive Republican nominee Donald Trump.  Gwen Ifill talks to Dmitri Alperovitch of CrowdStrike and Sasha Issenberg of Bloomberg Politics for more on the stunning sophistication of these breaches and the reasons behind them.

GWEN IFILL (NewsHour):  The Democratic National Committee said today Russian government hackers have penetrated its computer network.  Breaches by two separate groups allowed hackers to access e-mails, internal chats, and opposition research Democrats have compiled on presumptive Republican nominee Donald Trump.

Hackers may have had access for a year.  The Washington Post reported that computer networks for Hillary Clinton and Trump were also targeted.

We get some insight on how this happened and why from Dmitri Alperovitch.  He is the co- founder of CrowdStrike, the intelligence company that investigated the breach for the DNC.  And Sasha Issenberg, a contributor for Bloomberg Politics and author of the book “The Victory Lab: The Secret Science of Winning Campaigns.

Dmitri Alperovitch, how significant an intrusion was this into the Democratic Party's file?

DMITRI ALPEROVITCH, Crowdstrike:  This was a pretty scary intrusion.

And, in fact, there were two intrusions in place here.  Two separate Russian government-affiliated actors, we believe, that are part of the intelligence services of Russia infiltrated the network first in the summer of last year and were able to get access of the communications service at the DNC, essentially giving them the ability to monitor the e-mail traffic that was going through their servers, and a completely separate actor that penetrated that network in April of this year and went straight for the research department of the Democratic National Committee, specifically looking for the opposition files on the Republican presidential candidate, Donald Trump.

GWEN IFILL:  How did the DNC find out?  How were they alerted to this intrusion, and how were you?

DMITRI ALPEROVITCH:  Well, in early May, they discovered that there was something off on the network that was highly suspicious.  And they called us in.

GWEN IFILL:  Their internal IT people?

DMITRI ALPEROVITCH:  Their internal IT people determined that something may be off.  They didn't yet know if it was a breach. They asked us (Crowdstrike) to come in and evaluate.

And, within 24 hours, we were able to ascertain with our software deployed on all their machines there was in fact two breaches from two separate Russian intelligence services that were inside that network.

GWEN IFILL:  Sasha Issenberg, you wrote a book about how dependent campaigns have become on data and the things needed to support that amount of data, specifically about the 2008 Obama campaign.  So, in this case, what kinds of things exist in this — in these records?

SASHA ISSENBERG, Contributor, Bloomberg Politics:  Yes, you know, parties at this point are largely hubs of information.

They gather intelligence on the electorate, on — data on individual voters that they use the make tactical decisions, and then they're kind of a permanent research operation, especially at times like this, where there are open primaries within a party, and you don't know who the nominee is going to be.

And the DNC basically says to the Clinton campaign or Sanders or O'Malley campaigns, we will spend the year building resources for you that we can hand to you when you're the nominee.  In this case, a dossier on Donald Trump, probably the DNC has more information in its files on its servers than any other organization that has been researching Donald Trump for an hour — for a year — pardon me — and not just Trump, but his circle, his advisers, his staffers.

And so a foreign intelligence organization that wants to understand who those people are, the relationships they have, potential points of leverage or influence would probably find that the DNC has more of it sitting around than anyone else.

Monday, April 04, 2016

CRACKED - iPhone vs FBI

aka 'The Right to Hide Criminals Case'

"FBI cracks the locked iPhone, but legal questions remain unanswered" PBS NewsHour 3/29/2016

Excerpt

SUMMARY:  A conflict between tech giant Apple and the FBI over the encrypted iPhone of one of the San Bernardino shooters came to a moot point when Justice Department officials announced they had cracked the phone's security without Apple's help.  Gwen Ifill talks to Devlin Barrett of The Wall Street Journal and Fred Kaplan of Slate for more on how the FBI got what it wanted and what happens now.

GWEN IFILL (NewsHour):  A pitched battle between the Obama Justice Department and one of the world's biggest tech companies appeared to end abruptly this week, when the government decided to drop its insistence that Apple crack the code for an iPhone used in the San Bernardino shootings.

Apple had refused, insisting such cooperation would constitute a major breach of privacy.  The impending standoff ended yesterday when the government announced it had been able to crack the phone after all, without Apple's help.

But questions remain.

For that, we turn to Devlin Barrett, who covers the Justice Department for The Wall Street Journal, and Fred Kaplan, a columnist with Slate.  He's the author of “The Dark Territory: The Secret History of Cyber War.”

Devlin, starting with you, did one or the other of the parties in this case back away, just back up?

DEVLIN BARRETT, The Wall Street Journal:  The government backed away.  The government said — but it also got what it wanted, in a sense, because it got into the phone it had been trying to get into for months.

I think what you saw happen was that the government spent two months saying it can't get into this phone without Apple, and then at the last minute, essentially, it said, actually, someone has just come to us and told us that we can get into it without Apple, and that's what happened.

GWEN IFILL:  So, Fred Kaplan, the obvious question for so many of us is, who broke into the phone for them, and how did they find them, and had they — would they have been able to find them before without all of this legal mishmash?

FRED KAPLAN, Slate:  Well, it seems to be an Israeli cyber-security firm called Cellebrite, which consists mainly of retired professionals from the — an outfit called Unit 822, which is a — the cyber-warfare branch of the Israeli intelligence agency, sort of the Israeli NSA.

You can imagine.  Here's the FBI saying, we can't break into this phone.  Here's Apple saying, we don't want anybody to break into this phone.  This is the most secure phone out there.  You have got hundreds, maybe thousands of hackers around the world who look at this and say, hmm, let me give this a try.

And, you know, the law that the FBI was invoking to get Apple to open it themselves, which is a 1789 law called the 'All Writs Act,' states that if somebody else can do it, if you can find some way to do it without demanding that a company like Apple do it, then you have to drop your suit.

And that's why the FBI withdrew.  They had to.  They really didn't want to.  They thought that they had a good case here and were ultimately trying to test a new legal principle to accommodate for this new stronger era of encryption.

IMO:  This is a case where the actual effects privacy-rights fanatics is to allow criminals to hide.  That is just WRONG!  There is no Constitutional right to have criminals hide.



RELATED:  Breaking into iPhone may help find Louisiana killer

Sunday, March 27, 2016

FILM - At the Movies, "Sneakers"

Got the DVD "Sneakers."

It's really, really good, and note the cast..... WOW!

Cast

  • Robert Redford as Martin Bishop/Martin Brice
  • Ben Kingsley as Cosmo
  • Sidney Poitier as Donald Crease
  • David Strathairn as Irwin "Whistler" Emery
  • Dan Aykroyd as Darren "Mother" Roskow
  • River Phoenix as Carl Arbogast
  • Mary McDonnell as Liz
  • Stephen Tobolowsky as Werner Brandes
  • Timothy Busfield as Dick Gordon
  • Eddie Jones as Buddy Wallace
  • George Hearn as Gregor
  • Donal Logue as Dr. Gunter Janek
  • Lee Garlington as Dr. Elena Rhyzkov
  • James Earl Jones as NSA Agent Bernard Abbott


Monday, September 07, 2015

HACKING - China and Russia Link-Up

"How China and Russia are mining major U.S. data hacks" PBS NewsHour 8/31/2015

Excerpt

SUMMARY:  Intelligence services in Russia and China are cross-referencing hacked U.S. databases to reveal the identities of U.S. intelligence workers, according to a report in the Los Angeles Times.  Jeffrey Brown learns more from reporter Brian Bennett.

GWEN IFILL (NewsHour):  Next, a closer look at how major hacks of U.S. data are being used by China and Russia to target U.S. spies.

Today’s Los Angeles Times reports that intelligence services in those two nations are aggressively cross-referencing leaked information, including security clearances, airline records and medical insurance forms, to reveal the identities of intelligence officers and agents.

Jeffrey Brown has more.

JEFFREY BROWN (NewsHour):  We hear about these high-level data breaches all the time.  Today’s story connects some of the dots in a chilling way, claiming, for example, that at least one clandestine network of American engineers and scientists who work with U.S. undercover agents overseas has already been compromised.

One of the article’s authors, L.A. Times reporter Brian Bennett, joins me now.

And welcome to you.

So, we hear about these acts.  This is about what happens afterwards, right, cross-indexing and putting together the information.  What kind of clues are they looking for?

BRIAN BENNETT, The Los Angeles Times:  So, right now, countries like China and Russia are collecting massive amounts of data on the lives of Americans and the lives of government workers.

And this is going to allow them to get a dossier on people and know about their medical history, their banking information, if they have financial difficulties and might be vulnerable to blackmail or something else, their — any marital indiscretions that may have come out, their connections overseas.  And all this information is put together in massive databases and powerful computers can crunch them and give a very detailed view of people traveling.

Monday, July 13, 2015

NATIONAL SECURITY - OPM Hack

"OPM hack affecting more than 21 million includes sensitive data" PBS NewsHour 7/9/2015

Excerpt

SUMMARY:  More than 21 million Americans had personal data stolen from files held by the Office of Personnel Management.  Anyone who went through background checks to apply for a government position since 2000 has been affected, according to the OPM.  That makes the data breach six times larger than was originally disclosed.  Gwen Ifill learns more from Josh Lederman of the Associated Press.

GWEN IFILL (NewsHour):  More than 21 million Americans had personal information stolen from government files in a data breach that was six times as large as originally disclosed.  The information was hacked from the Office of Personnel Management, or OPM, which said today it is highly likely that anyone who went through background checks to apply for a government position since 2000 was affected.

Joining us to fill in the blanks is Josh Lederman of the Associated Press, who has been covering the story.

In terms of scope, we know this is huge, but how is it different from the earlier hacks we have heard about, Josh?

JOSH LEDERMAN, Associated Press:  Well, what we’re finding out now, Gwen, is not only were many more Americans affected than we previously knew, but just what kinds of data.

We’re talking about very personal data that most people would be very uncomfortable knowing is out there.  We’re talking about health histories, their criminal histories, their educational and residency backgrounds, as well as interviews that they conducted with members of OPM, Office of Personnel Management, or other people conducting background checks in the process of applications to get a security clearance.