Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
lite.cnn.io
lite.cnn.io
This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it isn't part of your predetermined threat vector analysis then it gets through and you lose everything.
The guy took steps to hide his identity then reported it to the CIA. They emailed back with a job offer. Back then we assumed it was trap to get him to travel to the USA from Canada, but these days, based on what I've seen, I think it was legitimate.
Sometimes I like to let thoughts simmer:
In 2001 a shitty high school hacker had a reasonably credible offer from the CIA.
It isn't just cyber security but surveillance infrastructure in general. If you cultivate a large group of surveillance assets (even people) with a method of collection that can be effectively attacked, you are creating something worth the effort to attack.
By creating a position that can be attacked, you will get attacked. And given enough attacks you will get attacked successfully sooner or later.
It is safer to not build the surveillance apparatus in the first place because you _always_ lose control of it sooner or later.
But the truth is that all the infrastructure for surveillance is going to be built anyway, if not by us then by our enemies or private industry. It's better to accept that it is going to be built and use our resources as best we can to protect the world.
Of course. And then you attack _their_ surveillance infrastructure and take the fruit of their investments periodically.
Attacking surveillance infrastructure (tbh) seems more productive than building it.
I totally believe that in the Swordfish era of the early 2000's they would have legitimately hit up a high schooler with some demonstrated ability.
This is why I think cryptocurrency is a terrible idea. Even if nobody ever finds a problem with the system itself (unlikely on an infinite timescale), every bank will get hacked at some point, and with no rollbacks it will eventually end in disaster.
Cryptocurrency is similar. Its 'real', unlike USD/EUR/etc, which are insured. At best its a record in a centralized db.
Please rethink your position on disaster :-) If 2017 is anything to go by, the world is more resilient to disaster than believed.
this is why anything sensitive is air gapped and inside a SCIF... but good luck getting everyone to adhere to that all of the time. it's a hard problem to solve when people want things to "just work".
Also, many places people think are air gapped aren't any more. Think smart lightbulbs and bluetooth worms. A hacked android device that gets too close to the perimeter can infect the lightbulb which infects the next one on and down the chain. If someone networks the control computer for the lights to the same network with the classified files it's lights out.
I think of the internet less of a binary thing these days and more of a spectrum. Things can be "pretty dark" like in the basement of NORAD or "white hot" like the twitter feed of Donald Trump. But twitter still goes down sometimes and data can be exfiltrated in so many ways. What's the baud on opening and closing vents and reading it from space satellites?
Here's an example where researchers used a scanner in an office building to exfiltrate data from the network. Malware on the network activates the scanner in a certain pattern, which lights up the room. The difference in lighting is recorded using a drone outside across the parking lot:
https://www.bankinfosecurity.com/black-hat-europe-beware-air...
I think it is a trap of sorts --- "join us and help build the future dystopian surveillance state, or we'll find out who you are and arrest you".
Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.
"Let's set up a whole fake parking lot, hire people to come and go in it, get a bunch of fake license plates, buy a bunch of cars, setup a camera surveillance system and feed it out onto the internet and see if anybody finds it!"
"APPROVED! I don't care how much it costs!"
Live or recorded video footage from somewhere else can be spotted as fake (car license plates, distant shop signs, different weather conditions, etc) and recorded footage will also eventually wrap around revealing it's recorded. It all depends on what they need to accomplish.
Typically they're cheap devices from China using the same tech just with slightly different branding.
They usually have default passwords like admin:admin that users aren't required to change and often have vulnerabilities that grant access to the rest of the network. And people expose the ports for these things to the entire internet. Maybe people just assume nobody will happen upon their IP address?
The irony, of course, is that people install these for security.
Remember when wifi devices rarely had passwords and you could use your neighbors internet? What caused the change to the modern practice of unique strong passwords by default? Was it consumer driven or was there some other factors? Whatever happened, we need that for IoT devices too.
For IoT devices it is harder to push through, there are no real incentives to spend on security except the potential for bad marketing once systems are compromised. In my company we usually have unique device and server generated public/private keys so compromising one device will not make the whole fleet vulnerable. This is just one of the methods. In most cases security is really hard to sell to the project managers at early stage of R&D unless they have had prior unpleasant experience or market mandated stringent requirements themselves. After all, making systems more secure is usually going to make projects longer and more costly on the paper. "Security is not part of the MVP and we will worry about it later" is way too common reaction.
Now there's almost none of those left, and what places do advertise "free WiFi" are captive/login portals. It was more free and open back then, I actually quite miss those days...
Anyway, this is just yet another example of computing getting worse the more money there is to be made in it from mainstream use.
ISPs are unfortunately the problem, not the solution.
Need a OSS system for the cameras, just like OSS firmware such as Openwrt to replace vendor firmwares.
Camera itself does not have enough resource to deal with DDOS or brutal-force attach or updating-with-CVE-quickly if they'are exposed to the public internet _directly_, they should sit behind some firewall. I hope those important cameras, or privacy-concerned cameras, are at least not installed with a public IP, not sure if that is true though, otherwise more exploits will keep coming.
i have not hearded wide spread problem with openwrt yet.
true OSS openwrt has the fastest updates and security fixes, and it's solid.
That would have been impressive, Person of Interest style.
Cameras are notoriously easy to break into. I would venture to say those 123 cameras has the same manufacturer and share the same reset instruction.
The first sentence of the article has more detail but is still false. Then the second sentence of the article contradicts the first sentence, adding the phrase "of the DC city police". Shall we believe that version?
https://twitter.com/internetofshit
Welcome to the IoT age. It's not going to get better, only get worse.
Some manufacturers have hard-coded backdoors/authentication bypasses, any vulnerable devices spread across the US, and the rest of the world.
Here is an example of one vulnerability from one larger manufacturer (Hikvision): https://ipvm.com/reports/hik-hack-map
I wonder if it's a reference to Dead Souls (https://en.wikipedia.org/wiki/Dead_Souls).
Here's a recent article about it:
http://www.bbc.com/news/business-39579321
In the west, the woman is traditionally the housewife.
Hence, a smart woman wanting high social status kind of had two options: become an engineer or a doctor. First option was easier and also less painful (doctors were also subjected to nasty shit like having to relocate to unpleasant places without choice because there was a demand for their services there, some areas like surgery were also much less women friendly etc.).
Also, dunno about Rusia, but in Eastern Europe, even now, there is a good "girls in math" story. Maybe less in physics or computer-science, but in pure and applied math there's lots of girls. Probably most of the smart ones jump ship more towards finance than tech though, when they realize they can't really get a nice paying job with a math degree alone.
The thing is - positive discrimination doesn't solve the problem, because it comes from school. You need to encourage girls to take science classes - it has to be expected of them that they do so (rather than go towards, e.g., humanities). That, I don't think is actively happening in the US or even some parts of western europe.... by the time you're dealing with graduates, it's already too late to fix the gender-imbalance problem.
[1] My little daughter's godfathers are German (she grew up in Romania, but he didn't). She told me that among german women, it's a thing of pride to be bad at math. And that her daughter was praised in school that "you're pretty good, for a girl". With that sort of attitudes during childhood... it's bound to be hard to get gender balance later (that "praise" would be perceived as insult here)
When I was going to school girls were usually better at math. I remember getting help from them with some calculus problems.
My CS teacher in high school was a woman as well and before teaching she worked as a programmer. She was a great role model for girls I'd imagine. Well she was a great role model for me too because she was a great teacher.
Not being familiar enough with history of this in US/Silicon Valley, want to ask: were things always "unequal", or did things go wrong somewhere along the way?
So yes, it makes sense to have a movement for diversity here, because something is pushing women out of these fields, so we have to push back.
I'm not sure for the increased participation of women in tech though. Maybe better education? Maybe less of a "computer lovers are all nerds" culture? I honestly don't know.