Friday, November 25, 2011

Promising step to cybersecurity


The UK government has today released its 2011 Cyber Security Strategy.
With an increased focus on cybercrime, and renewed focus on cyberspace as an engine of economic and social prosperity, the strategy continues to hone Whitehall's understanding of this vibrant, complex and increasingly global domain.
Many of the strategy objectives - in particular those related to securing critical infrastructure - will require close engagement with the private sector.
These public-private partnerships are essential, and, as noted in a recent Chatham House report on critical national infrastructure, they require awareness, engagement and trust among senior decision makers on all sides.
This is not an easy process and requires a keen understanding of the incentives that guide actions in the public and private sectors.
Links to business
The government will also have to balance the tension between building a more secure environment - which requires standards and regulation - and encouraging businesses to set up shop in the UK.
However there are signs that Whitehall is aware of these complexities and the need to experiment with potential solutions.
One new initiative is a three-month pilot scheme among five business sectors: defence, finance, telecommunications, pharmaceuticals, and energy.
It will exchange "actionable information on cyber threats", "analyse new trends" and work to "strengthen and link up our collective cyber security capabilities".
The strategy also supports existing independent initiatives such as Get Safe Online (raising awareness of cyber threats) and Cyber Security Challenge UK (searching for new talent), both of which have taken a good idea and implemented it in a simple and straightforward manner.
Risks
Cybercrime is topic that receives significant focus, in particular for the damage it does to the financial and social fabric of the country.
One primary initiative will create a "national cyber crime capability as part of the new National Crime Agency by 2013".
Another will create, by the end of 2011, a "single reporting system for citizens and small businesses to report cyber crime".
These are all encouraging steps that will require patience and persistence but which are essential.
One idea that looks slightly riskier is a "government-sponsored venture capital model to unlock innovation on cyber security in SMEs" (small and medium enterprises).
The appetite for risk varies widely between Silicon Roundabout and Whitehall, and government experimentation with venture capitalism has often produced mixed results. For example the US government's $535m (�345m) loan to Solyndra - the now-bankrupt solar panel manufacturer.
First steps
The new strategy is more detailed than the 2009 version, and in many ways reads more like a cyber and economic security strategy.
It continues the process set in motion by the recent Foreign Office-led London Conference on Cyberspace, which emphasised the economic and social benefits of a secure cyberspace and called for development of "rules of the road".
The introduction to the strategy notes that the government will report back in 2012 on progress made toward these objectives.
This strategy is a promising step and has ambitiously laid out a task list of dozens of actions.
The real challenge will be to prioritise and deliver in a climate of financial austerity.
David Clemente is a research assistant specialising in international security, at the Chatham House think tank.
He is the co-author off the organisation's recent report "Cyber security and the UK's critical national infrastructure".

Drugs giant challenges Facebook

The German drugmaker Merck KGaA has begun legal action against Facebook after discovering what its lawyer described as the "the apparent takeover of its Facebook page".

The webpage is being used by the German firm's US rival Merck & Co.

Merck KGaA said that the social network "is an important marketing device [and] the page is of great value", adding that since its competitor was benefiting from the move "time is of the essence."

A Facebook spokeswoman said: "We are looking into it."

Merck KGaA said it had entered into an agreement with Facebook for the exclusive rights to www.facebook.com/merck in March 2010.

The German firm said a number of its employees had been subsequently assigned administrative rights to the page.

However, Merck KGaA said that when it had checked the site on 11 October this year it had discovered it had lost control of the page, and that content on the site now belonged to Merck & Co.

Divided

The two drugmakers both stem from the same firm set up by a pharmacy owner in the German city of Darmstadt in 1668.

The business was split in two after World War I as part of the reparations package imposed on Germany.

Merck KGaA's lawyer, Robert Horowitz said he had sent a letter and a series of emails to various Facebook staff asking to discuss what had happened to the webpage.

However, he said the respondents "either did not understand the problem... [or were] intentionally giving unresponsive answers".

Mr Horowitz said that when he had requested a telephone conversation, one of Facebook's staff "incredibly replied that 'no-one is available for a call at this time'".

Legal steps

Merck KGaA has since filed a petition with the- Supreme Court of the State of New York.

"We took legal action versus Facebook to ask for information why a website we thought we owned isn't ours anymore," Dr Gangolf Schrimpf, a spokesman for Merck KGaA, told the BBC.

"We are just trying to learn what happened."

However, the court filing notes that: "Merck is considering causes of action for breach of conduct, tortious interference with contract, tortious interference with prospective business advantage, and/or conversion."

Interaction

Merck KGaA stressed that it had not taken any action against its US counterpart at this stage.

Facebook was unwilling to make a comment beyond saying that it was looking into the case.

Branding experts say the case reflects a growing belief that social networks can offer firms a better way of reaching their customers than through their own websites.

"Company communication departments have realised that many of the people they want to reach and influence are already on Facebook," said Simon Myers, from the consultancy Figtree Network.

"As corporate content becomes more tailored and engaging, social media sites such as Facebook represent a brighter future of greater customer dialogue and interaction than the current corporate website with static content and pictures of people shaking hands."



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Cyber security strategy unveiled

The government will reveal its plan to tackle cyber crime later, including using the intelligence agency GCHQ to help the private sector protect itself.

Police forces will be encouraged to train "cyber specials", while specialist Army reservists could also be used to provide particular skills.

There will also be a big focus on helping the public protect themselves.

It comes as the amount - currently about 6% - of UK GDP generated by the internet continues to grow.

The increasing dependence on the digital world carries risks and the cyber security strategy is aimed at outlining responses to minimise them.

Last year's national security strategy ranked hostile computer attacks on a par with international terrorism as a threat to the UK.

Ministers then announced an extra �650m for cyber security, particularly to bolster protection for key infrastructure and defence assets.

The government says there are more than 20,000 malicious emails sent to its networks each month, 1,000 of which are deliberately targeted.

'Kitemarking'

The strategy is expected to include a new joint initiative between the public and private sector to exchange crucial information on cyber threats and to manage the response to attacks.

It is also expected to set out ways in which GCHQ can help private companies and improve the wider UK cyber security sector.

There will be further details on the Ministry of Defence's new Defence Cyber Operations Group, and a plan to encourage all police forces to follow the lead of the Metropolitan Police and train cyber specialists.

Individuals will also be given more help to protect themselves, amid a warning from GCHQ that 80% of successful attacks could be thwarted by following simple steps like updating anti-virus software regularly.

The strategy is expected to suggest "kitemarking" for cyber security software to help consumers and businesses avoid "scareware" - software which purports to be helpful but is, in fact, malicious.

Earlier this month, the UK hosted an international cyber security conference, drawing together representatives from 60 nations.

The event came soon after GCHQ warned that cyber attacks on the UK were at "disturbing" levels.

Iain Lobban, the head of GCHQ, told the conference that a "significant" attempt was made to target the computer systems of the Foreign Office and other government departments over the summer.

Baroness Neville-Jones, the prime minister's special representative to business on cyber security, said Russia and China - who both attended the conference - were some of the worst culprits involved in cyber-attacks.

Outlining the national security strategy last October, Foreign Secretary William Hague said businesses and individuals must be aware of the risk of cyber attacks, as well as governments.

He said such attacks could become a major threat to the country's economic welfare and its national infrastructure, such as electricity grids.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Thursday, November 24, 2011

Black Friday iTunes malware alert

Criminals are targeting internet users with a new gift certificate scam, according to security experts.

Users receive an email that claims to be from Apple's iTunes store, warns the Eleven security blog.

The ZIP file attached contains malware that may allow hackers to gain access to the recipient's computer.

The blog says the attack appears to have been timed to coincide with Black Friday, one of the US's busiest shopping days.

Black Friday was the name used by Philadelphia's police department in the 1960s to describe the day after Thanksgiving because of all the traffic jams caused by people visiting the city's stores.

It is now viewed by many retailers as the start of the Christmas shopping season. They mark the day with one-off discounts and other special offers.

Eleven says the period has become one of the most popular times for internet scammers to target users.

Infected offer

The security firm says that users are told they have been sent $50 (�32) of iTunes store credit and need to open an attached file to find out their certificate code.

The file contains a program known as Mal/BredoZp-B.

PCthreat.com says the software opens up a backdoor on the users' computers and may also capture passwords and other information.

It says the code may also slow down the infected computer's performance and make files disappear.

The malware can be removed with the use of anti-spyware tools.

Facebook phishing

Security adviser Sophos warns of a separate threat linked to Facebook.

It says users are receiving emails claiming that they have violated the social network's policy regulations by annoying or insulting other members.

An attached link take users to a web page that presents them with a fake "Facebook Account Disabled" form.

The firm says that members are then asked to fill in a series of forms requesting their login details, country of residence and the first six digits of their credit card number.

If the users refuse they are told their account will be blocked automatically.

"New day, new attempt," writes Sophos's security writer Lisa Vaas on the company's blog.

"All these phishing scams boil down to a naked grab for your account details. Remember, neither Facebook nor other reputable social media sites would ask for this information."



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Cyborg insect power breakthrough

Efforts to create an army of cyborg insects are being pursued by a team of US-based engineers.

The group is investigating ways to harvest energy from the creatures to power sensors and other equipment fastened to their bodies.

The team has created an energy scavenging device that is attached close to the insects' wings.

It suggested the creatures might one day be used to aid search-and-rescue operations and surveillance.

The University of Michigan team of engineers published their study in the Journal of Micromechanics and Microengineering.

Power source

The report noted that, despite major advances in micro-air-vehicle technology, no-one had been able to match the aerodynamic performance and manoeuvring capability of insects.

However, it said that if insects were to be equipped with control mechanisms and other add-on kit, the equipment would require a power source.

The team rejected the idea of using miniature solar panels because they would be dependent on available light. So the group decided to develop a vibration energy collector.

The resulting device consists of a tiny three-layered spiral generator.

The outer two layers are made up of PZT-5H - a ceramic substance that produces an electrical charge when mechanical stress is applied. An inner layer of brass provides reinforcement.

Muscle power

The researchers used Green June Beetles to determine the best place to locate the device.

They identified the wings as the most promising power source.

However, the creatures' wing membranes were not rigid or strong enough to support the device, and it also made them less aerodynamic. So the team focussed, instead, on the animals' wing muscle.

The engineers ultimately decided to attach two of the spiral beams to each beetle's thorax. The end of each coil extended out to touch a hardened part of the insect's body close to its wing base where it could pick up energy.

The two devices weighed less than 0.2 grams and generated 45 microwatts of power during flight.

Cyborgs

The researchers suggested that the devices could eventually become the power source for a race of remote controlled cyborg insects with neural electrodes implants, communications equipment, microphones and other sensors.

The team suggested the creatures could wear the equipment in tiny "backpacks".

The animals could then be released into dangerous or hard-to-access locations after an accident has occurred. The information they gathered could be beamed back to the emergency services to help prepare a response.

They said the creatures could usher in "a new era for search-and-rescue operations, surveillance, monitoring of hazardous substances, and detection of explosives".

This is not the first time researchers have tried to work out how to turn animals into remote-controlled automatons.

The report's authors noted experiments to control rats through the parts of their brains related to their whiskers, an attempt to direct sharks by stimulating the part of their brain linked to their sense of smell and research into the locomotion control of cockroaches.

The team also noted that a previous attempt to harvest vibration energy from moths had failed because the 1.28g weight of the device involved proved too heavy for the insects to carry.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Google, Samsung confirm Nexus bug

Google and Samsung have confirmed that there are volume issues with their flagship mobile phone the Galaxy Nexus.

It follows complaints on net forums about unexplained changes in volume.

The handset, the first to feature Google's operating system Android Ice Cream Sandwich, is currently available in the UK and is due to go on sale in the US in December.

Samsung said that it is aware of the problem and will offer a repair but did not say when.

"Regarding the Galaxy Nexus, we are aware of the volume issue and have developed a fix," Samsung said in a statement. "We will update devices as soon as possible."

Google issued an almost identical statement.

Silent alarm

Posting on Google's Android user forum Damian M summed up the problem many seem to be experiencing: "Volume drops to nothing seemingly at random, volume rocker becomes unresponsive for a few seconds," he said.

Some users reported that the issues became worse when using the 2G network. Others complained that they were unable to rely on the device.

"Had this problem since buying the phone on the 17 Nov. Happened so far on 3G, wifi and using the sat nav. It also happened this morning again when my alarm went off," wrote one user nicknamed Stuartea.

"I was already awake and had not touched the phone yet, the alarm sounded for a second and then went silent. Thought that was weird so checked the phone and the volume was down. I can't trust the alarm to wake me up now for work!"

It is unclear at this stage whether the issues are caused by hardware or software faults.

Rivalry

The problem comes as Apple rushes to fix a bug in its new operating system iOS 5.

Users complain that iPhone batteries are running down too quickly.

An initial software patch issued by Apple to solve the problem has not appeared to have helped.

Apple and Samsung are engaged in a fierce rivalry for market share.

Research from Strategy Analytics suggested that Samsung had overtaken Apple to become the world's biggest shipper of smartphones between July and September.

The study said that the South Korean firm had shipped 27.8 million smartphones in the three-month period, compared with 17.1 million from Apple and 16.8 million from Nokia.

Meanwhile, Samsung and Apple remain locked in intellectual property disputes around the world. Both are trying to ban sales of each other's products.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

HTC shares plunge on growth cut

Shares of smartphone maker HTC have fallen by 7%, the maximum allowed in one day, after the company cut its growth forecast.

Taiwan-based HTC said on Wednesday that it expected revenues for the final three months of 2011 to be little changed from a year earlier.

The firm had earlier forecast growth of 20% to 30%.

HTC, the world's fourth-biggest smartphone brand, blamed increased competition and weakening demand.

Analysts and the markets were surprised by the statement filed with the Taiwan Stock Exchange.

"This new guidance takes us by complete surprise and is at odds with recent discussions we have had with distribution channels, especially in Europe," said Sanford Bernstein from Pierre Ferragu in a note to clients.

In October, the company had warned that fourth quarter revenue was slowing, predicting 125bn to 135bn New Taiwan dollars ($4.1bn-$4.4bn; �2.6bn-$2.9bn), compared with T$135.8bn in the previous three months.

Although HTC did not give a specific forecast for Wednesday's further downward revision, it said it predicted no growth compared to the same period last year. HTC's revenue in the last three months of 2010 was T$104bn.

Analysts said the grim outlook could be blamed on lack of new products to compete with an expansion in Apple's distribution channels in the US.

However, the company said it expected a pick up in revenue in the first half of 2012.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Firms 'not ready for IT failure'

Almost three-quarters of firms and public sector organisations across nine European countries may not fully recover their computer systems or data after an IT failure, a survey suggests.

The report by IT group EMC said 74% were "not very confident" they could fully restore their networks.

It also found that 54% admitted they had lost data or suffered systems downtime in the past 12 months.

A total 1,750 IT bosses in countries including the UK were questioned.

The other countries covered in the survey were Germany, France, Italy, Spain, Belgium, Netherlands, Luxembourg and Russia.

EMC said firms needed to put more focus on backup and recovery systems.

Its report found that the most common cause of data loss and downtime was hardware failure, followed by power outage and software malfunction.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Wednesday, November 23, 2011

FBI downplays water supply 'hack'

US officials have cast doubt over reports that a water pump in Illinois was destroyed by foreign hackers.

The FBI and the Department of Homeland Security said they had "found no evidence of a cyber intrusion".

The Illinois Statewide Terrorism and Intelligence Center (STIC) previously claimed a hacker with a Russian IP address caused a pump to burn out.

A security expert, who flagged up the story, said he was concerned about the conflicting claims.

Information about the alleged 8 November breach was revealed on Joe Weiss's Control Global blog last week. His article was based on a formal disclosure announcement by the Illinois STIC.

The report said that the public water district's Supervisory Control and Data Acquisition System (Scada) had been hacked as early as September.

It claimed that a pump used to pipe water to thousands of homes was damaged after being repeatedly powered on and off.

It added that the IP address of the attackers had been traced back to Russia.

The news attracted attention because it could have been the first confirmed case of foreign hackers successfully damaging a US utilities.

'No evidence'

The FBI and the DHS said they had carried out "detailed analysis" and could not confirm the intrusion.

"There is no evidence to support claims made in the initial Fusion Center report - which was based on raw, unconfirmed data and subsequently leaked to the media - that any credentials were stolen, or that the vendor was involved in any malicious activity that led to a pump failure at the water plant," an email sent to the US Industrial Control Systems Joint Working Group said.

"In addition, DHS and FBI have concluded that there was no malicious or unauthorised traffic from Russia or any foreign entities, as previously reported."

The officials added that their analysis of the incident was still ongoing.

Mr Weiss said he was concerned that the email appeared to contradict the initial report.

"This begs the question why two government agencies disagree over whether a cyber event that damaged equipment had occurred at a water utility," he wrote on his blog.

"If the STIC report is correct, then we have wasted precious time and allowed many others in the infrastructure to remain potentially vulnerable while we wait to find out if we should do anything."

Fewer managers

Mr Weiss also notes that a 2010 report by the security company McAfee highlighted the relative vulnerability of the global water system compared with other industries including energy and financial services.

"The water/sewage sector... had the lowest adoption rate for security measures protecting their Scada/ICS systems," it said.

The report noted that the low adoption rate might have been linked to the fact that the water and sewage sector, and said that only 55% of its Scada systems were connected to the internet - a lower percentage than most other industries.

However, it went on to highlight the lower number of managers taking responsibility for the issue.

"When considering this data, the small number of water sector executives amongst those with Scada/ICS systems responsibilities - only 11 out of 143 - needs to be noted," said the McAfee report.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement

Google to kill off more products

Google has announced that it is dropping seven more products in an effort to simplify its range of services.

The out-of-season "spring clean" brings an end to services including Google Wave, Knol and Google Gears.

It is the third time that the US firm has announced a cull of several of its products at the same time after they had failed to take off.

Experts said the strategy might put off users from signing up to new services.

Google announced the move in its official blog.

"We're in the process of shutting a number of products which haven't had the impact we'd hoped for, integrating others as features into our broader product efforts, and ending several which have shown us a different path forward," said Urs Holzle, Google's vice president of operations.

"Overall, our aim is to build a simpler, more intuitive, truly beautiful Google user experience," he added.

Wave goodbye

The seven latest products earmarked for the chop are as follows:

  • Google Wave - an attempt to combine email and instant messaging for real-time collaboration
  • Google Bookmarks List - a service which allowed users to share bookmarks with friends
  • Google Friends Connect - allowed webmasters to add social features to their sites by embedding a snippet of code
  • Google Gears - much-hyped effort to maintain web browser functionality when working offline
  • Google Search Timeline - a graph of historical query results
  • Knol - a Wikipedia-style project, which aimed to improve web content
  • Renewable Energy Cheaper than Coal - a project which aimed to find ways to improve solar power

Google had previously announced its plans to kill off some of the projects on the list.

It has now given details about when the switch-offs will occur. For example Wave will be retired in April, and Knol content will be taken offline in October.

Lessons

The diverse nature of the list illustrated how Google operated as a company, said Richard Edwards, principal analyst at research firm Ovum.

"Any company with the resources and number of brains that Google has will have ideas, only some of which will fly. Hitting the zeitgeist is tricky to plan or predict," he said.

The steady stream of innovations from the search giant and the open way it announced them had been a welcome change in a tech industry that had traditionally kept its cards close, said Mr Edwards.

But he warned that Google needed to be careful about how it announced new products in future.

"It can hype the bejesus out of new announcements and it can be difficult for people to pick out the substance from the hype," he said.

There were, he said, "lessons to be learned" from firms such as Apple which took a more measured approach, announcing just a handful of new products once or twice a year.

Focus

Some experts think that Google is streamlining in order to concentrate on its Facebook rival Google+.

The network gained 10 million users within the first 16 days after its private launch, and 40 million within the first 100 days, making it the fastest-growing social network in the history of the web.

But Mr Edwards was sceptical about how successful the service would be in the long-term.

"There is no likelihood of people flocking away from Facebook at the current time unless it commits some hideous faux pas on privacy," he said.

"Something may displace Facebook but I'm not sure it is likely to be Google+," he added.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement