Wednesday, November 6, 2013

NSA is Protecting National Security



            The National Security Agency (NSA) is protecting our national security by intercepting and analyzing data within the country in order to determine potential threats.  This practice has many Americans questioning the legitimacy and necessity of this practice.  This information gathering process and scrutiny is necessary to prevent another 9/11 terrorist attack. 
            The NSA analyzes metadata from legally obtained electronic and telephonic communications.  According to Foreign Intelligence Surveillance (FISA) Court Judge Clair Eagan, the purpose of the surveillance of the NSA is to make “connections between known and unknown international terrorist operatives as part of authorized investigations” (Crovitz, 2013).  The process ws designed to protect citizens.
            It is important to understand what data the NSA is gathering.  Many citizens are under the impression that the NSA is recording and listening to every conversation made on the telephone and looking at every email message being sent.  This is not accurate.  The Fourth Amendment prohibits the NSA from listening to the content of calls without a court order.  The NSA collects metadata which includes the phone numbers of the caller and receiver, the date of the call and length of telephone call.  The NSA uses mathematical processes to determine potential threats.  If the data represents a threat, evidence must be presented to the FISA Court to obtain a separate order to investigate these threats (Saletan, 2013). The data gathered during the surveillance makes it possible to determine where threats exist.  It is impossible to quickly determine where threats exist without the use of electronic means due to the high volume of communications.  If this information is not known quickly the potential for terror rises exponentially. 
            The United States is not alone in gathering intelligence.  Many countries employ surveillance programs to evaluate their people as well as other governments, regardless of whether the country is considered an ally or an adversary.  In 2008 a German broadcaster reported that Germany had been monitoring email between industry leaders from Afghanistan, Germany and a journalist (Gewirtz, 2013). Furthermore, it is well known that cameras, known as “cctv” are deployed on every residence throughout London.  Residents of many countries accepted the fact that their activities are being monitored.  Many of these people believe that this monitoring protects them from physical dangers presented by thieves and other non-law abiding citizens.  Foreign countries are watching and listening to our communications within the United States too.  They use this intelligence to gain the competitive edge by stealing proprietary information from US companies.  They learn our military secrets in hopes of beating us at our own game and use the information they learn to influence future policies.  They will likely try to use the recent data about the alleged interception of German Chancellor Angela Maerkel’s cell phone calls as leverage in the future.
              Many citizens are speaking out in favor of preventing the NSA from gathering intelligence.  Changes that prevent the collection of data by the NSA will threaten the security of each person living in the United States and the very security we enjoy today.     Our enemies and our allies are already gathering and using this information. 
            It is important to understand how the NSA has authority to collect metadata.  Two sources allow the collection of data.  First, section 215 of the Patriot Act “gives the government the power to obtain any “tangible thing” from third parties relevant to a terrorist investigation” (Lee, 2013).  This section allows the collection of metadata.  Second, section 702 of the Foreign Intelligence Surveillance Act is “designed to facilitate the acquisition of foreign intelligence information concerning non-U.S. persons located outside the United States” (Logiurato, 2013).  These acts have are evaluated regularly and have been assessed and approved as recently as December of 2012.  These lawful acts allow the US Government to gather information that will help protect the people of this country from a variety of threats.  Some peole will argue that the Fourth Amendment protects them from the watchful eye of the government.  A 1979 Supreme Court decision, known as the third party doctrine, specifies that “users don't have Fourth Amendment rights protecting information they voluntarily turn over to someone else. Courts have said that when you dial a phone number, you are voluntarily providing information to your phone company, which is then free to share it with the government” (Lee, In AP surveillance case, the real scandal is what’s legal, 2013).  Finally, the NSA may not act on threats without a court order by FISA.  These checks and balances that restrict access to protected information without a court order by FISA. 
            We must protect our country against the enemy that is within us and the enemy from afar.  It is important that sophisticated means are used to determine threats so problems can be prevented from happening.  It is time to accept the fact that the NSA is gathering information to protect us.


References
Crovitz, G. L. (2013, September 22). Making the Case for NSA Surveillance—At Last. Retrieved from Wall Street Journal: http://online.wsj.com/news/articles/SB10001424127887323808204579089153571584472
Gewirtz, D. (2013, October 28). Why do allies spy on each other? Retrieved from ZDNet: http://www.zdnet.com/why-do-allies-spy-on-each-other-7000022476/
Lee, T. B. (2013, June 25). Here’s everything we’ve learned about how the NSA’s secret programs work. Retrieved from The Washington Post: http://www.washingtonpost.com/blogs/wonkblog/wp/2013/06/25/heres-everything-weve-learned-about-how-the-nsas-secret-programs-work/
Lee, T. B. (2013, May 14). In AP surveillance case, the real scandal is what’s legal. Retrieved from The Washington Post: http://www.washingtonpost.com/blogs/wonkblog/wp/2013/05/14/in-ap-surveillance-case-the-real-scandal-is-whats-legal/
Logiurato, B. (2013, June 7). Here's The Law The Obama Administration Is Using As Legal Justification For Broad Surveillance. Retrieved from Business Insider: http://www.businessinsider.com/fisa-amendments-act-how-prism-nsa-phone-collection-is-it-legal-2013-6
Saletan, W. (2013, June 6). Stop Freaking Out About the NSA. Retrieved from Slate: http://www.slate.com/articles/news_and_politics/frame_game/2013/06/stop_the_nsa_surveillance_hysteria_the_government_s_scrutiny_of_verizon.html

A new threat

Over the past several days three friends have described a similar scam that impacted someone in their family.  I am providing this information to you in hopes of preventing future occurrences.

The scam:  A social engineer/scam artist calls and says that he is calling from Microsoft Solutions (or similar) related to an issue with your computer.  He says that your computer has been hacked or has an issue.  Next, the caller will ask you to go to a website or he may ask if he can access your computer remotely to gather evidence to prove that your machine was hacked or to "fix" the problem.  This probably isn't his first rodeo .. he will provide you "proof".  The website will show you "proof" that your machine was hacked OR if he accesses your computer remotely, he will demonstrate the problem he identified.  He might even offer to  'clean up' some files on your computer.  The caller will then demand compensation ($100 - $700) for his services or to prevent future problems.  If you hang up or refuse he will be persistent by calling you back.  You might even discover that your computer doesn't boot up.

What happened during the scam?:  The social engineer used information he may have found posted on one of many websites that provides your name, phone number and address or used some other means to identify and find you.  He created an urgent situation to manipulate you into allowing him to access your computer.  The website you accessed loaded malware (malicious software) on your computer or the caller installed malware on your computer when you allowed him to access your computer remotely.  The caller may have also gathered information from your computer (tax records, data or other information from your computer).  You may not be able to use your computer without paying the fee.  

What is a social engineer?   A social engineer/scam artist is someone who influences you to take an action that may or may not be in your best interest.  Social engineering is a tactic used to get information from individuals and businesses regularly.  This person will make a situation appear urgent and will manipulate you by exploiting your fears.  These people are 'professionals' with an arsenal of people, tools and resources to get you to do what they want.  Social engineers use freely available tools to make their call appear to come from Microsoft (or another well known entity), they use computer tools to access unprotected computers and will even take on a persona to trick you.   

How to prevent:  Stay on your A-game!  Just like any reputable institution, Microsoft's technical support does not make random calls to customers or users.  Be suspicious of unsolicited callers!  The situation described above cannot be prevented with virus protection - the situation involves human interaction.  The victim is manipulated unwittingly into allowing someone onto their home computer.  Don't be the next victim.  
Looking for a good site to find out about computer issues?  A good source is Kim Kommando.  She does a nice job of providing news about threats in a way that everyone can understand.

Friday, June 28, 2013

Government Officials using secret email accounts


Earlier this month the Associated Press reported that several high-level political appointees in the Obama administration are using secret email addresses for official business.  One can assume that if this is a fact, it's being done to deny less energetic people from tying the person to an issue.  

Federal computer week alleges that the former administrator of the Environmental Protection Agency, Lisa Jackson, was discovered using an email account under the name of Richard Windsor in 2012.  In addition, they allege that Kathleen Sebelius (Health and Suman Services Secretary) used a secret government account for correspondence.  According to a Fox News report Sebelius admitted she has two accounts, one for private email and one for public email.  She explains that "27-28,000 come into the public email, about 400 come into the private email.  It's just a management issue.  I can't possibly answer or screen all of them, and I want people to get timely answers".

What is the media doing to us?  Secretary Sebelius' explanation is reasonable.  Why does the media feel that it's their obligation to run people through the mud without giving them a chance to explain?!!   The Fox News reports that the practice of having multiple email accounts has been standard operating practice for years.  That seems  reasonable to me.

The Fox News report stated, "The Interior Department gave the AP a list of about 100 government email addresses for political appointees who work there but none for the interior secretary at the time, Ken Salazar, who has since resigned. Spokeswoman Jessica Kershaw said Salazar maintained only one email address while serving as secretary, but she would not disclose it. She said the AP should ask for it under the Freedom of Information Act, which would take months longer."  

I am tired of the lack of unity in this country.  The problem is that one bad fish gives the impression that the entire load is contaminated.  Maybe they are.  Society has changed since I was a kid.  My memories are of a time when the President was revered by all and politicians weren't looking out for their best interests.  Our freedom of speech is a wonderful right, however, some people use that freedom to openly exercise their right to be hateful (Westboro Baptist Church,  Ku Klux Klan and even groups that demonstrate against in our country against her citizens).  The news media spin the news and even ridicule people to move people from one side to another.  We're living in angry times.  It's time for everyone to stop thinking so hard about themselves and think about how their actions impact the good of the country.  It's time to re-introduce a campaign to strengthen the country and our personal principles. 




 

Thursday, May 30, 2013

Password Security


Most people know the importance of creating a unique password for each website the user logs into.  Following that "rule" is important.  Many people also understand that the password should be complex.  The article in ARS Technica this week demonstrates that a hacker who gets access to hashed passcodes can decipher the passwords, even the hardest ones, in a short time.

Many sources prescribe that a "good password" contains several ingredients:
  •    The password should be no shorter than 8 numbers or letters long.
  •    The password should have UPPER CASE, lower case, numbers and special characters.
  •    The password should NOT contain a word from the dictionary (any language)
  •    The password should be comprised of a passcode.

This article suggests that a good password cracker can defeat even a very complicated password hash, sometimes, in a matter of a few hours.  According to the article, password expert Jeremi Gosney (Stricture Consulting Group) used a single computer with a AMD Radeon 7970 graphics card to successfully crack 90 percent of the 14,734 password hashes provided to him in a matter of 20 hours.  The least successful expert cracked 62 percent of the hashes -- in one hour. 



What are users to do?  Creating a good password simply isn't enough.  It is the only thing a user has power over, however.  A website owner has a great responsibility to securely store account information.  This includes on the server as well as on backup tapes, on paper, etc.  I mentioned that users have no control over how securely this information is stored.  It's important to recognize that users have limits to what can be controlled.  Given the lack of complete control I have a few suggestions:
  1. NEVER store credit card information on a merchant website.  Many merchant sites allow the user to save credit card information.  Just say "no".
  2. Maintain the practice of using a complex password.
  3. NEVER re-use a password on two merchant websites.
  4. If the merchant website requires you to save your credit card data on their website use a re-loadable credit card.
  5. Use a Password Manager to create a password for you.  Store the password securely.
It's a cruel world out there.  Protect yourself!


Wednesday, December 26, 2012

NIST glossary

NIST Updates their IT Security Glossary


The National Institute for Standards and Technology recently updated their glossary in Interagency Report 7298.  The report is great, not only does the document provide a definition of the term, it also provides the source of the term.

A few terms I hadn't seen previously include "No-Lone Zone (NLZ)" which is a term that defines an "area, room or space that, when staffed, must be occupied by two or more appropriately cleared individuals who remain within sight of each other."  The term has to do with information assurance and protection of data.  In a NLZ, two authorized individuals who act as a check and balance system to protect the integrity of data by verifying that tasks are completed appropriately and all safety requirements are completed.  The two people verify that the other person completed the tasks as ordered.

This document may be a great way for people new to the IT Security area to find out what a term means then the individual can refer to the source document to get additional details.  The source document is CNSSI-4009.  I googled CNSSI-4009 and found references to CNSS.gov.  CNSS is the Committee on National Security Systems.  CNSSI-4009 is the National Information Assurance Glossary that was last revised in April of 2010.  The information in this glossary was exactly what was posted in the NIST glossary.  I did a little more research and found this image (source:  http://commons.wikimedia.org/wiki/File:No_lone_zone.jpg)
A little more research provided me with a wikipedia site that told me that the Two-Man rule was used for the protection of nuclear weapons, (as in the Minuteman Missile sites where two people were required to launch a nuclear weapon) and to protect COMSEC materials and manuals.

I bookmarked this website.  This is a nice reference when looking for information or even to learn about something new.

Monday, October 29, 2012

The time has come...

SC Magazine is leading with the story

Monster breach hits South Carolina taxpayers.

Unfortunately this shouldn't come as a surprise to anyone anymore.  According to the report in early September "unknown hackers "probed" agency systems, and sometime in the middle of the month, they were able to access the data that was stolen".   Details related to the breach were limited to the comment that it was tied to a "server issue" by South Caroliana Department of Revenue spokesperson Samantha Cheek.

Folks, the breaches aren't stopping.  We have insecure wireless networks, servers, code and sloppy employees out there.  We've got journalists and CEOs pushing BYOD (bring your own device) and cloud technologies.  The "cool kids" are all over implementing these new ideas.  It's likely we still have folks with unencrypted tapes and computers sitting in their vehicles.  Wake up folks!  We are not ready to bring our own devices!  It's clear that the criminals are more persistent than the industry. 

Something has got to change.

Can we MAKE programmers write more secure code?  Secure the networks?  Quit buying equipment from foreign companies who insert backdoors and insecure code?  How about that cloud?  Is your information hosted in a country where privacy laws allow them to access the data you think is secure?

Social security data is the basis for critical functions for Americans.  Our social security number is the identifying number that is used to store our credit score, social security eligibility, health records (in many cases), tax records, as well as a host of other important data. 

What can we do to protect ourselves?!!  Clearly consumers cannot secure the data center or the programming running systems.  We can freeze our consumer credit (Equifax, TransUnion and Experian), stop using credit or isolate ourselves from society by living in a cave.  It's a lot of trouble to freeze your credit if you want to buy anything.  Most people couldn't live without some type of credit and living in a cave is not going to work for most folks.

Obviously the solution is to ensure equipment, software and people do the right thing for existing and future equipment.  The other solution is to increase the scrutiny used when approving loans, credit cards or anything else used to modify or use information tied to social security numbers and associated personal information. 

Do you hear me Dell?  Don't send a TV out when some yayhoo opens up a credit card and buys a $5,000 TV without scrutinizing the request.  Put additional checks and balances into the equation.  Weeks later you find out that the television went to someone other than the person it was billed to.  The system ain't workin'.

I'm still a paranoid consumer and I hope you are too.  I want to see more scrutiny out there folks! 

Friday, October 26, 2012

Tampering with PIN pads

It was reported this week that the PIN pads at Barnes & Noble were replaced with skimming devices in 63 stores.  These external skimming devices were unwittingly used by customers whose credit card numbers were compromised and in some cases used. 

Many consumers are aware of security breaches such as the T. J. Maxx/Marshalls incident in 2005 when customer data was intercepted by poorly secured wireless access points.  The breach where social security numbers and other sensitive information was lost when a Veteran's Affairs database on a laptop was stolen from an analyst's home in 2006.  In 2011 77 million Sony Playstation accounts were hacked.  The list certainly doesn't stop there.

How do we protect ourselves?  Consumers often have no role in the security of their information.  Consumers are often the victims of the reckless or careless actions of others.  I have a few suggestions:

Protect your computer.  Install and maintain a virus protection suite that includes malware protection.  Ensure your computer has up-to-date patches for software on the computer including the operating system (Windows, Mac os, etc.) as well as updated software patches.  Backup important files to a separate thumb or hard drive.  Provide physical protection for that drive.

Minimize the amount of information you provide online retailers.  Do not set up accounts where your credit card data is saved on the retailers server. 

Protect your passwords.  It's important that you create a unique password for each account you use.  Consider using a password safe where you can store your passwords electronically in an encrypted file on  your computer.

Consider using a separate credit card  for online purchases.  Many people have a credit card with a nice credit limit that they use for most purchases.  If that card is compromised the credit limit might allow a thief to rack up lots of charges.  Transferring funds to a separate card to cover expenses will lower the potential amount of hassle.  Several retailers offer reloadable cards that can be used for online purchases to limit your exposure.

Ask the cashier to swipe your card.  The Barnes & Noble breach was limited to the customer PIN pad.  Hand your card to the cashier and ask him or her to swipe your card. 

Know where to go if the worst happens.  Visit OnGuardOnline.gov to learn how best to respond if you become a victim.

Stay safe out there!