Showing posts with label hacking as a service. Show all posts
Showing posts with label hacking as a service. Show all posts

Tuesday, 24 November 2015

Logic Bombs Away !

A logic bomb is a cyber weapon that is some code that triggers an event at a specific time. It is distinct from a virus in that it does not replicate. An example would be some code that destroys the Docs file on a computer on valentines day.

Made famous by Roger Duranio, a disgruntled IT insider, it showed the massive damage that can be done by a malicious insider. All files in the central server were deleted at Paine Webber and then all files on every server in every branch - 2000 servers and 400 branch offices. Duranio had shorted the stock but was perhaps ahead of the analysts who did not seem to notice. Fast forward to today and a less serious breach at Talk Talk took an axe to the share price.

It is a bit of an urban myth that hackers are all high IQ misfits with ADHD or suchlike. This "how to" video on YouTube gives you an idea of what information is freely available and the type of skill level needed.

For anybody wondering how secure public wi-fi is this provides a convincing answer. What is shown in this video may be an offence under the Computer Misuse Act and accessing paid for wifi for free doing this would be illegal but the skill level required is moderate. Do not try this at home !

The Destover trojan which is considered to have been the culprit in the Sony Pictures hack is a very different proposition however according to McDonald and Kharouni experts at Damballa;

“The Destover trojan is a wiper that deletes files off of an infected system, rendering it useless … for ideological and political reasons not for financial gain,”

The penny is dropping that those neutral looking pieces of computer hardware that are so useful to us all need very careful handling.






Wednesday, 18 November 2015

The dark side of digital needs regulation

The utopian idea that the internet would lead to the world uniting for the greater good (Tim Berners-Lee) is starting to look optimistic.

Tremendous benefits have come from improved communications and access to information but the internet economy has started to be a mirror to the human condition with a balance between good and bad.

The core difference is that the internet is unregulated in any effective sense and that behaviours that would not be tolerated elsewhere (such as totally disrespect for property / IP) are considered the norm.

Understandably freedom and privacy are jealously guarded but if the robber barons of history had been unregulated 12 year olds would still be working in factories for minimal wages in the name of progress. Some of the current tech giants, despite lots of cuddly advertising, are looking like wolves in sheeps clothing.

Andrew Keen has identified that the internet has driven income inequality, a crisis in jobs and a surveillance state but there are always 2 sides to any argument and libertarians like Peter Thiel argue effectively the other way. Even so the core argument that is starting to look shaky is that the internet should not be regulated.

The startling rise in cyber crime and hacking generally probably tips the balance towards sensible, democratically mandated regulation. The coming wave of cyber warfare will require that the intermediaries and pipes of the internet introduce more effective controls.

The jurisdictional hurdles need to be crossed or dramatically simplified as a matter of urgency as an unregulated internet that is very powerful can do significant damage. The majority of hacking tools used now are HaaS (or hacking as a service) requiring minimal skill from the operator.

This is a situation similar to having free automatic weapons with unlimited ammunition available on every street corner with minimal regulation. Certainly the Government should stress the need for companies and individuals to take reasonable steps to protect themselves but at the same time a clear regulatory framework needs to be in place to deter criminals and apply proportionate sanction when needed.

Any sane person would recognise that a free cyber weapon to launch DDOS attacks should not be easily available online and that there should be a simple process in place for instant removal. Currently no effective regulation exists in this regard which is great news for the bad guys (and girls).