How France's TV5 was almost destroyed by hackers
bbc.co.uk
bbc.co.uk
Many institutions have weak cybersecurity including healthcare concerns. In this Fortune article about he Sony hack, the CEO said basically that they did not want to spend the money for Cybersecurity. http://fortune.com/sony-hack-part-1/
Target and Lowe's POS terminals were hacked because they were told to upgrade their software to a newer version of the OS and they didn't do it. The CEO of Target was canned as a result.
Many firms and other institutions love the power of computing without spending the money and hiring the expertise needed to maintain the security. There are private security contractors that these groups can hire to ensure that their environment is fully secure .
In addition to financial audits, shareholders should insist on cyber security audits to ensure that the firm or institution is acting in a responsible manner.
Obviously acting in a responsible manner regarding Cybersecurity is not a guarantee, but many cases of hackers breaking in is because of not even making the attempt to be secure.
it's a tradeoff. you spend time, money and productivity loss (i.e. procedures) on IT security to decrease the risk of a successful attack. every additional dollar spent decreases the probability a bit further (if done right) but your returns are diminishing. at some point it's not worth anymore.
> "The TV5 attack fits into this pattern of highly-targeted attacks, rather than the kind of general criminal activity typically seen on the web."
in my opinion: no matter what kind of business you do, if you fall victim to the "kind of general criminal activity typically seen on the web" you're acting negligent.
then, after a certain point of increased protection attacks drastically decrease for most businesses because you're not worth the time and money it costs to attack you.
but fully secure? i mean, the stuxnet attack is the best counter example.
i compare it to healthy living: by investing time and money and refraining from doing certain pleasurable things you're improving your health and increase the chance to reach an old age. but it's no guarantee - you can still get hit by a car or succumb to cancer at age 20 just due to bad luck.
At issue is that many firms do not implement these security measures at all. The Sony people were repeatedly warned and had earlier breeches but didn't want to spend the money it took to follow measures recommended to them until after the attack. I think their mindset is not so unique and that many firms aren't doing what they can to try to eliminate the breeches. In some cases, the issues are internal, but in others customer lists are breeched, etc. or credit cards hacked as in Target, Lowe's, and others.
Leave the room as fast as you can if anyone ever pitches this to you.
IT security is mostly a risk assessment exercise at most companies. Likelihood of an incident*impact compared to cost. That's reasonable but I think both the likelihood and the impact are really hard to estimate well.
Mandiant was bought out by FireEye.
https://www.fireeye.com/services.html
I believe Sony was using them for forensics as well as establish their new more secure system.
It is important to set up systems so that hackers if (and when) they do breech, are found ASAP, and only get access to compartments and not the entire company.
There are also Israelis that I know of who have a good reputation in cybersecurity.
The most famous TV hack, Max Headroom [1] (NSFW), from what I recall involved overriding the terrestrial signal, presumably with very powerful broadcasting hardware. BBC are digital now, so I am surprised they haven't had a successful incident yet.
[0] https://en.wikipedia.org/wiki/Max_Headroom_broadcast_signal_...
https://en.m.wikipedia.org/wiki/Captain_Midnight_broadcast_s...
Can someone explain that a little more? Are satellite carriage contracts so twitchy that going dark on a channel for more than a few hours forfeits your service?
Terrestrial TV stations can lose your license if they go dark for too long. Obviously satellite is a little different, but I'm sure the people drawing up the contracts would understand that a station going dark is a possibility and would include contingencies for dark stations.
I am pretty sure they would have been able to get something back on air somehow within a day or two even if every single piece of electronics had been physically obliterated.
= cameras with a backdoo^^^^cloud integration/permanently connected to manufacturers server.
In general, crippling hacks aren't terribly useful -- they're embarassing and harmful to the targets, especially in shaking confidence. But they're not particularly useful to a general attacker. Having insider access to a television or broadcast entity would itself be useful.
Other options might be to test (or prove) the capability to take a target down, particularly in preparation for other more advanced capabilities.
The more successful parasites don't disable hosts, but hijack them to their own ends. That is something I'd find more troubling.
Online searches don't show much at Schneier or other security-minded blogs. Am I missing something?
I did find a Friday Squid discussion: https://www.schneier.com/blog/archives/2015/04/friday_squid_...
In general, I think all attacks made against computers have physical world consequences. Time, money, disrupted services...