Results 1 to 20 of 112

Thread: Malware & other nasty IT / cyber things

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Council Member
    Join Date
    Dec 2009
    Posts
    115

    Default

    Quote Originally Posted by OUTLAW 09 View Post
    The 3 Biggest Lies About the Internet of Things https://safeandsavvy.f-secure.com/20...t-of-things/#…
    Talking to a couple cyber security SMEs recently it would appear one of the biggest threats are high volume, low cost IoT devices like IP security cameras that have very short product development and sales life cycles(measured in months rather than years).

    Lots of persistent vulnerabilities in cheap IoT hardware's firmware that can result in very large and easy to build attack arrays.

    Moore's Law combined with commercial market forces means that this environment of large volume vulnerabilities occurring with each cheap IoT device generation is unlikely to be mitigated without intervention.

    I would suspect that some form of intervention will be required, possibly along the lines of public/private partnership such as certification.

    CE or UL are symbols used to identify compliant appliances for categories like electrical/fire safety.

    I suspect we will need some form of IoT device compliance through certification or litigation.

    Or in emergencies, the ability to remotely identify, locate, and negate them.

    Ralph Nader's "Unsafe at any speed" but instead of targeting the Corvair and greater car industry in terms of safety standards and features, but for the IoT age.

    This is not an original thought as I found it elsewhere first, but there's also the potential for some jurisdictions to "conscript" devices.

    We have moved beyond conscripting humans to work on behalf of sovereign government in most instances, but our devices being conscripted is an entirely different story and not beyond the realm of believability to preempt a crisis and enhance national resilience.

  2. #2
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Cited in part:
    Quote Originally Posted by flagg View Post
    Talking to a couple cyber security SMEs recently it would appear one of the biggest threats are high volume, low cost IoT devices like IP security cameras that have very short product development and sales life cycles(measured in months rather than years).
    This IMHO is one of the most serious points of internet security that urgently needs an answer as it is virtually impossible to constantly update all the various built-in firmware issues for literally thousands of IoTs...down to your for IoT enabled refrigerator.....or TV or baby monitoring device....
    Last edited by davidbfpo; 06-19-2017 at 08:40 AM. Reason: brevity

  3. #3
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    South Korean hosting co. pays $1m ransom to end eight-day outage
    Criminals were talked down from 4.4M USDs...


    https://www.theregister.co.uk/2017/0...a_pays_ransom/
    Last edited by OUTLAW 09; 06-20-2017 at 06:54 AM.

  4. #4
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Honda halts Japan car plant after WannaCry virus hits computer network
    http://reut.rs/2sU6jvK

  5. #5
    Council Member
    Join Date
    Dec 2009
    Posts
    115

    Default

    Nuclear war fears had a public component of "duck and cover".

    Cyber war fears should have a public component of "patch and update".

    Here in NZ, due to our recent and serious seismic activity, we've had a national resilience campaign for personal preparation in case of a future disaster.

    I believe strongly that we are well past the point where we should be conducting national continuous "patch and update" campaigns, to the point of aggressive nudging behaviour in perpetual pursuit of herd device immunity.

    "Loose lips sink ships" for the age of interconnectivity.

  6. #6
    Council Member
    Join Date
    Dec 2009
    Posts
    115

    Default

    Quantum entanglement as a means of potential cyber/coms resilience:

    https://www.scientificamerican.com/a...ntum-internet/

    I knew quantum computing would be an eventual game changer with even recent 1024 bit encryption, but was unaware of quantum entanglement being used as a potential tool to defend against hacking and cracking.

    It's way over my head, but Moore's Law continues on its 52 year relentless journey.

  7. #7
    Council Member
    Join Date
    Dec 2009
    Posts
    115

    Default

    A cyber attack the world isn't ready for

    https://www.nytimes.com/2017/06/22/t...erweapons.html

    Wannacry is the focus, but Doublepulsar backdoor may be a bigger threat

  8. #8
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    BTW...while the US Congress approved 200M USDs to fight Russian info warfare BUT US social media FB, Twitter, Instagram and others seem to be unable to control hate, violence and propaganda being posted minute by minute EVEN though they admit they could....

    BTW...the Trump government has promised a propaganda pushback but not spent a single cent of the 200M USD...

    BTW...the Germans have effectively told the US social media companies to either control what they know they can actually control and if not then 50K Euros per violation.....ACTUALLY not a problem for them to pay the fines as they make billions.....

    At least the Germans are doing something compared to the apparent inaction of Trump who has 200M USDs to spend in this effort....
    Last edited by davidbfpo; 06-25-2017 at 12:33 PM. Reason: brevity

Similar Threads

  1. Russo-Ukraine War 2016 (April-June)
    By davidbfpo in forum Europe
    Replies: 1088
    Last Post: 07-01-2016, 08:44 PM
  2. Leadership of Cyber Warriors: Enduring Principles and New Directions
    By SWJ Blog in forum Media, Information & Cyber Warriors
    Replies: 0
    Last Post: 07-11-2011, 02:41 PM
  3. USAF Cyber Command (catch all)
    By selil in forum Media, Information & Cyber Warriors
    Replies: 150
    Last Post: 03-15-2011, 09:50 PM
  4. Replies: 51
    Last Post: 01-08-2011, 07:42 PM
  5. Question 5: Cyber space (oh you know I had to ask at least one of these)
    By selil in forum TRADOC Senior Leaders Conference
    Replies: 7
    Last Post: 08-14-2009, 03:27 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •