Wednesday, December 21, 2011

Lady Gaga social media Hack is a warning to celebrities to ensure their PR firms invest in information security

Phew. The hacking is over! And just in time, I'm on my way to Japan! So excited to spend Xmastime with my TokyoMonsters! I also want to thank Little Monsters for making tomorrow the 20th Marry The Night Download Day. You are so sweet + generous, I love u. Xx Ready for redwine and 12 hrs of napping. Is it weird I like flying because I can sleep and my t-t-telephone has no service? #stopcallin wee!
Was one of the latest posts on Lady Gaga’s facebook page after her Twitter and Facebook account had been hacked and several posts/tweets went out promising her fans iPad’s.
On FaceBook
"Lady Gaga's new iPad comes out in 3 days!
"So for the next 72 hours we will be hosting a massive giveaway to all the Mother Monster fans. Sign up and receive your special Lady Gaga edition iPad in time for the Holidays! For contest rules and registration visit the link below."
And Twitter
"Monsters, I'm giving away FREE ipad2's to each one of you in the spirit of the holidays :)"
Fans normally follow celebrities and fake links on celebrity events, news and rumours are popularly used to lure fans to click on spam or malicious links sending such messages viral.
Compromise of a legitimate site with millions of users is the holy grail of celebrity hacks as there is instant access to a wide population of trusting fans. In this case 100000 fans clicked on the links. The usual recommendation of think before you click holds no good when the attack comes from a site of high credibility. No wonder it caused Lady Gaga Stress. I am happy that her team has been able to quell the hack and remove the links.
I advised in my post “Celebrities at High Risk from Hackers” those big celebrities who use social media like Twitter and Facebook to interact with fans and hire media firms to manage these accounts, should ensure that their teams with access to the celebrity’s account and personal data protect its confidentiality through the use of security best practices.
I believe that the current Lady Gaga hack is an apt example of the risks celebrities’ face.

Monday, December 19, 2011

Spies set honey traps on social networks to obtain strategic information

Online temptation the art of using search engines to honey trap businessmen, politicians, bureaucrats and military officials “was an article I wrote seven months ago on the use of Social Networks to honey trap for corporate and military espionage. The Indian government today requested senior paramilitary and armed force personnel to stop flaunting their career information on such sites or stay away altogether. Many of these personnel posed in official uniform to impress people including girls. They became easy target for “across the border honey’s” who enticed them further with video chats and other types of conversation designed to extract strategic information or blackmail. This channel was also used to introduce malware onto sensitive government computers which is a high security threat. The government has decided to monitor social network pages of officials in sensitive positions, particularly those in border positions.
Honey traps have been effectively used by petty thieves. Do read a previous post on “Entrapment for Theft”

Reported Examples

Times of India 20 Dec 12 Indian Army Colonel honey-trapped by ISI, probe ordered
Excerpt: A Colonel was cultivated by a woman when he was posted in Bangladesh for a military course in one of the institutes of the neighbouring country. The relationship developed into a love affair sometime in the middle of this year.The Colonel was approached by ISI operatives based in Bangladesh, asking him to work for them. Sources said the Colonel also received letters threatening to put up on the Internet photographs of him in compromising position with the woman, as well as to send them to Delhi, if he failed to work for the ISI

Sunday, December 18, 2011

Six Actions Governments must take to build a Secure Cyberspace

The rate of growth of cyberspace fuelled by individuals and businesses has been rapid.  The advent of smartphones has ensured a network of over 5 billion internet devices. Cloud computing and smart phone apps are major drivers of online commerce. Internet has entered utilities, businesses, homes, and even cars. Governments use cyberspace to provide egovernance to their citizens.
As interconnectivity and online transactions grew so did three major cyber risks – corporate espionage, cyber warfare and cyber crime. The rate of growth of these three risk vectors have left most governments underprepared and underinvested in building strong national and international cyber ecosystems. The rapid growth rate of a free Internet coupled with the not so technology savvy bureaucrats left governments without any relevant policy on building a strong ecosystem for the development and protection of national cyberspace. Bridging the gap requires a multibillion US dollar investment in building cyber institutions, cyber policy and domestic cyber development capability in products, services and training.
The six focus areas and related laundry list below should ideally  be enacted/executed in partnership with Industry and academia.
1.    Create an ecosystem for development of domestic cyber protection capabilities
a.    Capability to build secure products for the national cyber ecosystems
b.    Incentives for tech entrepreneurs to invest in security product development
c.    Labs and standards for evaluating and certifying products as security compliant
d.    Policies or regulation to ensure critical national infrastructure players invest in security defenses
e.    Set-up standard bodies for development and promulgation of security standards
f.     Enhance existing bodies like CERT for better incident response and vulnerabilility reporting
g.    Develop better online monitoring mechanism to detect hostile activities on the Internet

2.    Create an ecosystem for safe business transactions
a.    Capability to build tools for fraud detection and control
b.    Bodies that will establish trust in online identities such as identity service providers who can provide authentication services
c.    Capability to build tools for prescreening Internet content
d.    Capability to report online cybercrime
e.    Capability to trust online transactions
f.     Capability to trust and rate online business entities
g.    Capability to monitor the activities of online businesses in real time to certify businesses as safe to transact with
h.    Promulgate ethical standards for use of the Internet by business  in partnership with industry bodies

3.    Create an ecosystem for lawful use of the Internet
a.    Develop cyber police and cyber courts
b.    Training of police and judiciary
c.    Effective laws and regulation
d.    Cyber Bills and Acts

4.    Create an infrastructure to train new cyber security professionals
a.    Security courses in schools and college
b.    Funded research

5.    Develop effective international policies to deal with cross border issues
a.    Sign transactional treaties for fighting cybercrime internationally
b.    Establish international policy on privacy and law for use of cyberspace
c.    Establish norms for Internet service provider hosting content from or related to, India or Indians

6.    Promotion of cyber security awareness
a.    Encourage mcommerce players to promote citizen cyber security awareness
b.    Encourage the media to highlight cyber security issues and create awareness
c.    Institutionalize cybersecurity awareness training for children in schools
d.    National cybersecurity day

Tuesday, December 13, 2011

Midsized service firms face business continuity issues if senior executives leave with operational data

Three senior executives of a midsized private firm, where arrested under the Indian IT Act on charges of stealing data and software. The executives started their own company and took several employees from their previous firms with them. This incident highlights the need for effective data protection for mid sized firms in the service industry which stand the risk of their business models being replicated if the senior team moves out along with the data and other key employees. Beside loss of data there is a possibility of business interruption or business continuity as key client relationship and operations are hampered.
While, this may not apply in this case, I have heard of certain companies filing cases for data theft under the IT Act to harass key employees who have left the company with the intent of working with competitors or setting up their own firms.