Posts

Showing posts from July, 2013

When Hacking can Kill

Luddites say we over egg the seriousness of poor security practises and security breaches, as nobody actually dies, well that's not always the case, sometimes lives are put at stake when information security is poorly managed. A couple of security engineers at Twitter and IOActive said they were able to hack and take control of a Toyota Prius. The engineers described how they could control every aspect of the car, including the steering and were even able to disengage the brakes, so breaking wouldn't work in the car. They even went onto say they could remove their hacking device, eliminating all evidence of their control over the car. This hacking example highlights the concerns with the security of our increasingly smart and connected cars. Cars are rapidly having more sophisticated and complex computer systems, and more external connectivity, which is the age old recipe for security vulnerabilities. Security testing of car computer sys...

Hacking ring responsible stealing over 160 Million credit cards charged

A global credit card hacking ring consisting of four Russians and an Ukrainian, have been indited in the US  with stealing and selling over 160 million credit and debit cards. That's a vast number of card numbers, which led to millions in fraud. Two of four were identified as sophisticated hackers by the US prosecutors, stating they specialised in the hacking of multinational corporations, financial institutions and payment processors, including NASDAQ, Citibank and PNC Bank. According to the indictment, US credit card numbers sold for about $10 each; Canadian numbers were $15 and better-encrypted European ones $50. Interesting that the more secure European cards fetch 5 times the amount of US cards. This will be an interesting court case to watch as it unfolds, especially as more comes out about the hacking techniques used, and perhaps the poor security which these guys took advantage of.

Having a Nice Cyberwar?

Cyberwar makes a great sound bite, so it can be of no great surprise it is a term relentlessly cited by the media at the moment, but is it really the appropriate term to use?   Recently I was invited to hear 'Security Rockstar' Bruce Schneier talk about his thoughts on Cyberwar, he made some intriguing points about the term.  Bruce explained Americans like to band around words like "war" when they aren't actually at war, and avoid using the 'war' word when they are at war. For example "the war on terror", "the war on drugs", and now "cyberwar". I recall that in the first Gulf 'War' the American media focused on titles like 'The Gulf Crisis', 'Crisis in the Gulf', and 'Desert Storm', so certainly some truth there. In the last couple of years US politicians have increasingly been using the term "Cyberwar" in their rhetoric, phrases like 'Cyber Pearl Harbour', 'Cyber 911...