Biodun Iginla, BBC News

Biodun Iginla, BBC News
Showing posts with label National Security Agency. Show all posts
Showing posts with label National Security Agency. Show all posts

Tuesday, May 28, 2019

BREAKING: Baltimore says it will not pay ransom after cyberattack


Baltimore city hall was targeted in a cyberattack
Baltimore city hall was targeted in a cyberattack Baltimore city hall was targeted in a cyberattack GETTY IMAGES NORTH AMERICA/AFP/File
ADVERTISING
Washington 
The US city of Baltimore, a victim this month of a cyberattack that paralyzed part of its computer network, will not pay a ransom to undo the damage, Mayor Bernard Young said Tuesday.
Hackers reportedly had demanded $100,000 in bitcoin, but Young told a news conference "I'm not considering" paying it.
ADVERTISING
"As a matter of fact, we are going to work with other cities, encouraging them not to pay either," he said.
Baltimore was the latest big US city, after Atlanta, Georgia and San Antonio, Texas, to be hit with a ransomware attack.
Smaller cities like Greenville, North Carolina and Allentown, Pennsylvania also have been targeted.
The Baltimore attack targeted the Microsoft Windows operating system, blocking city hall's computer system, online sales and real estate sales.
They used a malware known as "EternalBlue," developed by the Maryland-headquartered National Security Agency, The New York Times reported Saturday.
Leaked from the NSA, the hacking tool was posted on the internet in April 2017 by "Shadow Brokers," a hacking group that first surfaced in mid-2016.
- 'Smart virus' -
"This was a smart virus," said Young. "Anytime NSA do something they do it well, I just hope that they had the key so we can all get out of this."
Since the attack was discovered on May 7, the mayor's IT team has worked to restore the network with the help of state, federal and private sector experts, Young said.
"We're making progress on some of the programming piece. We are not there yet," he said, adding he could not say how long it would take.
He said since NSA was the origin of the malware, the city is seeking federal financial assistance to cover the cost of repairs.
But some experts say other malware known as "Robin Hood" was used in the attack, not "EternalBlue."
Robert Graham, of the cyber security firm Errata Security, said Microsoft provided its clients with a patch for "EternalBlue" in 2017.
"Going two years without a patch is gross malfeasance that's hard to lay at the NSA's feet," Graham said in a blog post.

Sunday, August 26, 2018

Reality Winner sentenced for leaking top secret U.S. report

August 27, 2018  03H:43  GMT/UTC/ZULU TIME
A federal judge sentenced former U.S. intelligence contractor Reality Winner on Thursday to more than five years in prison after she admitted leaking to a media outlet a top secret report on Russian interference in U.S. elections, her attorney said.
Winner, 26, who has already spent nearly two years in jail, pleaded guilty in June to passing the National Security Agency report to The Intercept in 2016. She will receive credit for the time she spent in pre-trial confinement, said one of her attorneys, Titus Nichols.
During a hearing in Winner’s hometown of Augusta, Georgia, Judge James Hall approved her lawyers’ request for a 63-month sentence followed by three years of supervised release, Nichols said. It was the longest sentence ever given to someone for illegally disclosing government information, according to Nichols.
“The sentence and accompanying plea agreement both reflect that Reality recognizes that actions have consequences, and that she has learned from her mistake and is prepared to accept the consequences of her actions,” Winner’s attorneys said in a statement.
SPONSORED
Judge Hall also agreed to let Winner be transferred to a federal prison in Fort Worth, Texas, where she could receive medical services and be closer to her family.
Federal prosecutors said her sentence of more than five years was appropriate because Winner betrayed the trust of her colleagues and her country.
“Make no mistake: THIS WAS NOT A VICTIMLESS CRIME,” U.S. Attorney Bobby Christine said in a statement. “Winner’s purposeful violation put our nation’s security at risk... She was the quintessential example of an insider threat.”
Winner had been working with Pluribus International Corp, a company that provides analytical services for U.S. defense and intelligence agencies.
The NSA document she gave the news outlet contained technical details on what it said were Russian attempts to hack election officials in the United States and a voting-machine company before the November 2016 presidential election, two U.S. officials with knowledge of the case have said.
Winner admitted to intentionally printing a copy of the intelligence report in her office and mailing it to the news outlet. She was indicted on a single federal count of willful retention and transmission of national defense information, a felony under the Espionage and Censorship Act that carries a maximum sentence of 10 years in prison, court documents showed.
Betsy Reed, editor in chief of The Intercept, said in a statement that Winner should be honored, and that her sentencing and other prosecutions of whistleblowers were attacks on freedom of speech and of the press.
“Instead of being recognized as a conscience-driven whistleblower whose disclosure helped protect U.S. elections, Winner was prosecuted with vicious resolve by the Justice Department under the Espionage Act,” Reed said.
A federal judge had ordered that Winner be held without bond after prosecutors said she posed a flight risk and public danger, citing what they called “disturbing” comments in her notebook.
In one section Winner wrote: “I want to burn the White House down,” according to prosecutors, who said investigators also found the names of three Islamic extremists known to federal authorities listed in her notebook.
FILE PHOTO: Combination photo showing Reality Winner, the U.S. intelligence contractor charged with leaking classified National Security Agency material, is seen in these undated booking photos in Lincolnton, Georgia, U.S., received June 8, 2017. Lincoln County, Georgia, Sheriff's Office/Handout via 

Monday, May 15, 2017

Global cyber attack: who is to blame?--analysis


by Tamara Kachelmeier and Biodun Iginla, France24 Technology reporters, New York


    NEW YORK - 
    Questions are swirling over who is responsible for the security flaws exploited by hackers in the world's biggest ransomware attack to date, which crippled thousands of businesses and public organizations around the world. Here are some answers:
    - Who bears the blame? -
    Because hackers exploited a security hole in some Windows versions discovered by the National Security Agency, Microsoft says the intelligence agency bears some responsibility.
    "This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem," Microsoft president and general counsel Brad Smith said in a weekend blog post.
    Steven Weber, faculty director at the Center for Long-Term Cybersecurity at the University of California, said "the fault is pretty distributed -- there are plenty of people to blame."
    Weber said the NSA's primary mission is intelligence: "If I were sitting at the NSA I would push that argument right back to Microsoft," he argued. "They would say, 'It's our job to stockpile those weapons and use them against our adversaries.'"
    Other factors were the large number of old, outdated software programs in use and often ineffective security systems.
    Cornell University computer scientist Stephen Wicker blamed "profound ethical lapses" both on the part of the US government and the computing public.
    The flaws "were known to the NSA and CIA, but were kept secret by those organizations to be exploited for their own data collection purposes," Wicker said.
    But he added that a large number of businesses and other users failed to install a patch issued by Microsoft in March.
    "This 'free-rider' problem -- some manufacturers and users choosing to enjoy the benefits of the internet without taking the time and effort to maintain secure computing systems -- is also unethical, and is a problem that will get much worse as the Internet of Things (IoT) continues to grow," Wicker said.
    - How did hackers get this tool? -
    Microsoft effectively confirmed what many analysts have stated, that the ransomware known as "WannaCry" was designed to exploit NSA software that was leaked earlier this year by a group calling itself Shadow Brokers.
    President Vladimir Putin has said Russia -- which has been accused of cyber meddling in several countries -- had nothing to do with the massive cyberattack, and criticized the US intelligence community for creating the original software.
    But Bruce Schneier, chief technology officer for IBM Resilient Systems, has suggested that a state-sponsored actor, most likely Russia, was probably responsible for the initial hack of the NSA.
    "Whoever got this information years before and is leaking it now has to be capable of hacking the NSA and/or the CIA, and willing to publish it all," Schneier said in a recent blog post.
    "The list of countries who fit both criteria is small: Russia, China, and... and... and I'm out of ideas."
    James Lewis, a cybersecurity specialist with the Center for Strategic and International Studies, said he believes the exposure of the flaw likely "leads back to Moscow" -- but that the hackers who designed the malware are probably not Russian.
    "One of the rules in Russia is that Russian criminals are not allowed to hack Russian targets," Lewis said. "This does not fit the pattern of Russian-sponsored activity."
    "The cybercrime market is really innovative," he added, "and they are quick to take advantage of vulnerabilities."
    - What about computer security at large? -
    The attacks came a day after US President Donald Trump signed an executive order calling for improved cybersecurity in the federal government and better cooperation with the private sector.
    But few see this or any single initiative as a silver bullet.
    Weber said the attacks show the risks of an overreliance on computerized systems that are not fully secure.
    "We have built an increasingly digital society on a very insecure foundation and we are starting to see the consequences of that," he said.
    Weber warned there is no single entity capable of fixing this problem in the near future, since security depends on so many factors.
    "If you want to look for an upside, it would be this would be a wakeup call," to improve computer security, he said.
    At the same time, Weber noted that the attack could prompt more people to shun digital technology and turn back to analog systems that can't be hacked.
    Weber said there are already some signs that the public is losing confidence in the digital world as a result of security problems.
    "For Silicon Valley and technology companies, their future depends on these underlying systems working," he said.