Sunday, January 15, 2012

Week 5

You wanna know what makes me really grouchy? When government thinks it can control or fix anything and everything. This seems to further expand on last week's blog.

I listen to Air 1 every morning and Thursday morning I heard it announced that President Obama wants to create Internet ID. Seriously??? So, I looked it up and found it here:

Obama Eyeing Internet ID for Americans


Grrrr.

Inter-agency rivalries to claim authority over cybersecurity have existed ever since many responsibilities were centralized in the Department of Homeland Security as part of its creation nine years ago. Three years ago, proposals were circulating in Washington to transfer authority to the secretive NSA, which is part of the U.S. Defense Department.
So, now we have government agencies bickering about who's going to be in charge of this project, people screaming the private sector should be in charge of the project, and I'm trying to figure out who to thwap with my large trout.

Last week, I talked about Martin Libicki's these that Cyberspace cannot be conquered. This is because ti cannot be owned by anyone. He lists four reasons why Cyberspace cannot be conquered or owned.


  1. Cyberspace is a replicable construct. 
  2. To exist in cyberspace, your interactions must be recognized there.
  3. Some aspects of cyberspace nevertheless tend to be persistent (ie mathematics)
  4. Cyberspace has separate layers, the conquest of each of which has vastly different meaning
Let's face it, what is the point is wasting time with such a silly (and expensive project at the taxpayers dollars) project? 

Also, while Iran has similar applications (why are we even considering such an idea from a country like THAT!?), this is because Iran and even China has limited access to certain areas of the Internet already. Is this one step closer to controlling information???

On a lighter note, Symantec is being sued. Apparently, someone has created a new phrase for certain type of software called "scareware" where a reputable company "scans" your computer and tells you how badly your computer is infected and then you buy their product to fix it. Apparently, some dude didn't like being scared! 


Sometimes you just have to shake your head and laugh and the silliness of people. 

Gross' beef with Symantec involves the free scans conducted by PC Tools Registry Mechanic, PC Tools Performance Toolkit and Norton Utilities.
He was tricked into paying about $30 to correct the issues that the scans revealed, even though the lawsuit alleges the scans didn't really check for anything, and the resulting product he bought served no purpose.
All I have to say to that is, "Dude, get a second opinion!"


 

Sunday, January 8, 2012

Week 4

Well, being a wannabe politician, lots of things interest me. But there are some things that royally honk me off. In a news story Bumper Crop: Cyber Security Legislation, I found out there are more laws to be passed that may infringe on our privacy. In the article it states, 

 “The Cyber Intelligence Sharing and Protection Act would create a cyber security exception to all privacy laws and allow companies to share the private and personal data they hold on their American customers with the government for cyber security purposes,” a statement from the American Civil Liberties Union (ACLU) says. The bill, the group points out, would not limit the companies to sharing only technical, non-personal data."

You know, I'm not a fan of the ACLU, but I have to agree with them here. What bothers me about this whole cyber security legislation though is the fact that, how do you create laws in a part of the world you do not possess or own?? Martin C. Libicki said in his book "Conquest in Cyberspace,"

 "This work is not entitled not "The Conquest of Cyberspace" but "Conquest in Cyberspace for a reason... Emphasizing "in"...reflects that while something akin to conquest can be defined for cyberspace, cyberspace itself cannot be conquered in any conventional sense." Cyberspace can be replicated, be in several places at once, it is built.
Do we need to catch those disgusting perverts that sell child pornography on the Internet? YES! But do not create laws that infringe on my privacy or liberty...Ok...off my soapbox...for now

Finally, I found this article: Japan's Plan for 'Good Computer Virus' Sparks Debate

"The words “good” and “virus” may look funny stuck together in a headline, but the words have become a popular way to describe plans by the Japanese government to use a program designed to attack the attackers."

WHAT!? Wait a second! I know what I'll do! I'll go to a thief's house and steal from him before he steals from me first! HA! *facepalm* It would not be long before a virus like this would be turned around for malicious intent...oh wait! It already has! The article points out, 

"the Morris worm was not written to cause damage, he noted. Yet it ended up causing a massive disruption of the Internet in 1988."
You know, for the most part, most computer users are fully aware of the risks they take when they get online. Not all of them may know how to secure their computers, but they do know risks are out there and are willing to accept those risks when they sign up for service with an ISP. Much like a person getting out and getting behind the wheel of a car to go to work. You can only do so much, but inevitably, you will run into that moron who dropped his taco in his lap or is drunk or texting on their cell phone and no matter how much you try to avoid an accident, there are just some things you can't prevent. I witnessed an accident the other day. Someone wasn't paying attention, ran a red light to turn left and was hit by oncoming traffic with the green light. Does this mean we need cars out there that will prevent car accidents? Or get rid of cars all together?

Just keep the security software updated folks and make sure your customers are up to date on the latest attack. We don't need to complicate things any further. Really, we don't.

Sunday, December 18, 2011

Week 3

This weekend I babysat for some friends of mine. He is about to be sent to Pax River to work on an unmanned airplane. What awesome technology. It was an amusing news story he showed me on his iPhone. Apparently, it was being delivered via truck to Pax River. The reaction of the people as it passed through town was quite amusing. Apparently, this plane is intended to be used for reconnaissance missions and eventually be developed for unmanned air attacks.

However, upon looking at a recommended website from the professor, I found this disturbing story: U.S. Drone Hijacked By GPS Hack?

GPS technology has a long ways to go. Apparently, Iran has been looking for the vulnerability for sometime through various other downed drones. By finding the weakness they were able to take advantage. When a drone's GPS is jammed, the drone goes into autopilot because GPS is "its brain."

Perhaps what bothers me most is the fact that it was publicized that GPS was the drone's weakest point and have known about it for a while! *facepalm*

In this case though, Iran "spoofed" the GPS coordinates to obtain the drone.

Knowing this makes me wonder about what else GPS affects should it be jammed or spoofed. Does this mean a bored geek can try and send different GPS to a person who uses it to get to a destination and either get them lost or worse, lead them to a dangerous destination? If we think about this further, most smartphones also have GPS technology embedded in them. I use mine when I am out of town and in unfamiliar territory.

This was very enlightening to discover! I always knew that with new technology would come new threats. For some reason I had believed that GPS is invulnerable or at the very least never really thought about it being used for malicious intent. But apparently, if it's got circuits and radio waves, it's just a matter of time before someone finds a way to use it for bad intentions.



Sunday, December 11, 2011

Week 2

There are some students who can only take one course at a time because they work. I get the opportunity to take two at the same time. I am lucky enough to be taking Risk Management and Information Security Management at the same time. It has taught me many things.

In Risk Management we learned about the different types of assessments:

Business Impact Assessment (BIA)
Vulnerability Assessment (VA)
Penetration Testing
Risk Assessment (RA)

In these, depending on the organization's size and its needs, an organization can use all of the above to beef up security.

This week, in Information Security Management, though I noted that while there were some project management tools that are similar they each have a purpose as well, but it is not as viable to utilize more than one. It can confuse things, at least from my point of view.

The different types of project management tools we learned about this week were:

Work Breakdown Structure (WBS)
Program Evaluation & Review Technique (PERT)
Gantt Chart

I had found a lot of links that helped me with learning about those different tools. Sometimes the book is not enough. I need it put into little words.

So, now that I have mildly vented my frustration, I found an interesting article about Adobe Flash. You see, I am a webmaster for three sites and all of them have some form of flash on them so this really caught my interest:

New Zero-Day Vulnerabilities Found In Adobe Flash Player

Adobe Acrobat and Reader products are used on both Windows and Mac machines. Macs are known for not being attacked like Windows machines and are so far not being affected, but that does not mean they will be safe. Because the malware is embedded in Adobe files, they can bypass scanners. With more and more websites using Flash Player or Adobe Reader, this makes everyone more susceptible to attacks that cannot be detected.

The malware crashes the programs and obtains control of the system the program is on. The malware can "bypass the antiexploitation features in Windows such as DEP and ASLR, and can get around the Internet Explorer sandbox."

I think this is something I may need to be doing more digging into the Adobe software I am using. For now, maybe I should begin blocking unwanted Flash content from running on my computer. It's a good thing I use Firefox and Chrome!!!!

Sunday, December 4, 2011

Week 1

I am not much of a blogger, in fact, this is my very first blog. I have never kept a diary or anything like that so, this will be an interesting aspect of the course.

The one thing about security is that I apply all that I learn at my home network. It was how I learned to secure my WiFi router and even discover questionable files on my computer with extra extensions.

So, for my future reference, I will post professor's recommended links on here for easy access on a regular basis.

Here's to a new experience! Cheers!