Posts

Showing posts with the label Snowden

Why Brexit will be Business as Usual for Cyber Security & Data Protection in the UK

So it actually happened, they have gone and done it, its shocked the world, the UK populous have voted to leave the European Union today. Now what? Well we'll have to just get on with it and starting thinking how Brexit will impact C yber Security and Data Protection in the UK from here on in.  I didn't post a word on Brexit despite being asked numerous times during the "debating" season, or as we in the security industry call it, FUD!.  But now its done and dusted, here are my thoughts, which as always on this blog, are completely  my own. Cyber Security Defence The UK is a significant player in the international cyber threat intelligence community, although a highly secretive business, the “snooping” documents leaked by Edward Snowden demonstrated how closely GCHQ works with their American counterpart agencies. When it comes to the business of protecting the UK’s critical national infrastructure, economy and businesses from cyb...

What is Tor and Should your website block Tor users?

Image
Great infographic by State of the Internet which raises an interesting question, should websites block Tor users?  Certainly one for debate, my view is it depends on your website 'marketplace', function and risk, in other words perform a risk assessment, a lazy answer I know. But i f like me you find yourself often explaining what Tor is to business folk, so they can perform those risk assessments properly, you'll find this infographic comes in quite handy. As it does a simple job of explaining Tor; who uses it, how it provides anonymity  online, and how cyber criminals are embracing the tool for various illicit purposes. I recommend checking out the  State of the Internet website  for further info, statistics and reports on Web and DDoS attacks, which continue to blight the Internet.

Snoopers’ Charter Law Eroding our Digital Privacy is Sneaking In

Image
The UK parliament re-opened for business today with a new UK government, which means a new raft of laws. While the media and the public were pre-occupied with rights eroding laws on unions to take strike action, and the possible replacement of the Human Rights Act, there was another proposed law in the list which seriously erodes another fundamental human right, our right to privacy. In the last coalition government the Liberal Democrats blocked this law on privacy grounds, but with the LibDems blown away in last month's general election, there is nothing to stop a Conservative majority government placing the Snoopers' Charter law. Anti Austerity and Pro Union Protesters in London after the opening of Parliament The Snooper's Charter is actually the nickname for the Communications Data Bill. The intended bill will grant ‘official’ permission for UK government agencies to read our email, listen to our phone calls and access our web browsing history. The law require...

Lenovo's Superfish is Adware at Best and Malware at Worst

Image
Since the middle of 2014, Lenovo have been pre-installing a piece of software commonly known as 'Superfish' onto its new laptops and PCs. In recent days the "Cyber Security" press has questioned the validity of Superfish, saying that it invades personal privacy, and that it exposes Lenovo users to data theft, they do have a point. Although Lenovo aren't the first to covertly push the privacy boundary for commercial gain, and they won't be the last either. Adware at Best Superfish operates fairly covertly in the background of the operating system, as you search online the software returns related advertisements back onto the desktop. These advertisements are chosen by Lenovo, and provide revenue to Lenovo when clicked upon. This is in affect adware, namely a user unwanted and unnecessary piece of software running on the operating system, it appears to be of no benefit or aid to the user, its main purpose is to provide an income for Lenovo. If we needed any a...

Has your Website Account been Hacked?

The relentless stream of data breaches by big business continues, with the likes of Vodafone ,  Tesco , Sony , Adobe and Yahoo , all losing their customer's personal data on mass due to their inadequate security. How do you know if your username, email address and password have fallen into the hands of a cyber criminal due to these breaches? There is one website that seeks to provide some assurance to that question,   https://haveibeenpwned.com  appears to be have acquired the stolen data from the Internet's criminal underworld and allows anyone to freely search it for their own username and email, the website returns a response which states if the account is known to have been compromised or not, namely listed within the stolen database. The website says it has over 161 million stolen accounts that are searched, all this data has been compiled from several of the high profile data thefts. Although the hacked businesses are responsib...

Why isn’t the GCHQ & NSA Privacy Invasion Socially Accepted?

Post Snowden it is easy to jump on the media bandwagon, cry foul that GCHQ and the NSA have gone too far, forsaking our Privacy for Security. Yet if you take a walk through any city or town in the UK, and your image and actions are recorded by hundreds of CCTV cameras, no permission is ever sort, and you have no idea who is watching you without your knowledge, yet this invasion of privacy is socially accepted.   Millions of people in the UK willingly give up their privacy on social networks, sharing almost every aspect of their private lives. This private information is commercially exploited through targeted advertising, this invasion of privacy is socially accepted. The same is true with smart phones where considerable user privacy is given up, just read Apple’s agreement and your mobile phone contract to see the extent, it goes well beyond personal details, phone calls and text messaging. These companies track the applications you use, the websites you browse and where you p...

GCHQ Cracks SmartPhone Codes, Privacy Outrage or Lifesaver?

The Edward Snowden fallout continues with the steady trickle of classified revelations released by the media.   The latest appears to be confirmation of GCHQ ability to crack or bypassed the encryption on Blackberry and Android smartphones. This news isn't really that shocking given cracking encryption is a core part of what GCHQ has done for decades. It is also important to understand that nowhere does the released documentation say GCHQ have been breaking into everyone’s smartphones and harvesting our private data on mass, I doubt they’ll have resource and funding in the UK to do that. My assumption is breaking smartphone encryption is a necessary GCHQ tool for gathering information on specifically targeted bad guys, for example suspected and known terrorists.  Several terrorist plots have been foiled since the 7/7 atrocities, so what if GCHQ's ability to access encrypted smartphone electronic messaging and call information, had played a key par...

Bullrun & Edgehill: US NSA & UK GCHQ have broken Internet Encryption

I have always suspected this and now according to newly leaked documents  by Edward Snowden, the NSA and GCHQ are said to have defeated most of the online encryption used by internet users and the likes of Microsoft, Google, Yahoo and even banks. The usage of supercomputers, court orders and the good old application of pressure to internet service providers, are all said to be tools used to gain access to encrypted data by the government agencies. "In recent years there has been an aggressive effort, lead by NSA, to make major improvements in defeating network security and privacy involving multiple sources and methods, all of which are extremely sensitive and fragile" "NSA has introduced the BULLRUN CoI to protect our abilities to defeat the encryption used in network communication technologies" The US programme name is Bullrun, and is said to have a £150m annual budget, while the UK GCHQ counterpart is called Edgehill. These codewords come from battles in ea...