Biodun Iginla, BBC News

Biodun Iginla, BBC News
Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Monday, August 13, 2018

Analysis: U.S. House candidates vulnerable to hacks: researchers

August 14, 2018  02H23 GMT/UTC/ZULU TIME

by Tamara Kachelmeier and Biodun Iginla, BBC News and Reuters Technology Analysts,  Las Vegas

LAS VEGAS - Three of every 10 candidates running for the U.S. House of Representatives have significant security problems with their websites, according to a new study by independent researchers that underscores the threat hackers pose to the November elections.

The research was due to be unveiled on Sunday at the annual Def Con security conference in Las Vegas, where some attendees have spent three days hacking into voting machines to highlight vulnerabilities in technology running polling operations.
A team of four independent researchers led by former National Institutes for Standards and Technology security expert Joshua Franklin concluded that the websites of nearly one-third of U.S. House candidates, Democrats and Republicans alike, are vulnerable to attacks. NIST is a U.S. Commerce Department laboratory that provides advice on technical issues, including cyber security.
Using automated scans and test programs, the team identified multiple vulnerabilities, including problems with digital certificates used to verify secure connections with users, Franklin told us at Reuters ahead of the presentation.
The warnings about the midterm elections, which are less than three months away, come after Democrats have spent more than a year working to bolster cyber defenses of the party’s national, state and campaign operations.
Democratic National Committee officials told us at Reuters they have completely rebuilt the party’s computer network, including email systems and databases, to avert a repeat of 2016, when Russian intelligence agents hacked into Democratic accounts and then used stolen data to undermine support for Hillary Clinton’s presidential bid.
“No one wants to be the next ‘patient zero,’” said DNC Chief Technology Officer Raffi Krikorian, a former executive with Twitter and Uber.
SPONSORED
The report follows a string of warnings by Trump administration security officials that Russia is actively interfering in the November elections. FBI Director Christopher Wray recently warned that Russian government agents were working around the clock to sow discord ahead of the election.
Democratic Senator Claire McCaskill, who is facing a tough re-election battle in Missouri, last month said that hackers had tried and failed to access her office’s computer network. The Def Con study did not address that incident.
The researchers did not identify any cases where it appeared that politically motivated hackers had exploited those vulnerabilities.
“We’re trying to figure out a way to contact all the candidates” so they can fix the problems, said Franklin, who joined the nonprofit Center for Internet Security last month.
Department of Homeland Security officials said at Def Con that they are offering aid to states and counties for securing election equipment.
Still, some states said they are not getting enough help, and new funding efforts failed in Congress. Individual campaigns are not eligible for federal assistance, so they rely on party officials, an increased number of tech-savvy volunteers and nonprofit groups such as Defending Digital Democracy, a bipartisan project at the Kennedy School of Government at Harvard University.
Franklin also said he found numerous potentially malicious web pages that closely resemble the names of candidates. Hackers use that practice, known as “typo-squatting,” to develop copycat sites for use in phishing campaigns to steal credentials or to criticize candidates.
The candidates at most risk of hacks are ones with small campaigns that have with little expertise in computer technology or security, Franklin said.

STEPS BY THE DNC

The Democratic National Committee agreed to discuss some steps it has taken to bolster security in the hope it can serve as a model for other election offices.
Since Krikorian joined the DNC a year ago, the party has moved email and data storage to Google cloud and replaced most Windows computers with easier-to-defend Apple hardware and Google Chromebooks, he said.
The party also requires staff to fill out monthly surveys pledging that they are following key security practices, including use of two-factor authentication for personal accounts, long and unique passwords, and encryption on computers. They are also asked if they are running operating systems and application software with up-to-date security patches.
The party uses software from San Francisco-based Okta that grants access to DNC systems only after testing devices to confirm the identity of users and verify they are not running malicious software.
The biggest change has been psychological, as staffers and volunteers are trained to assume that the network has been breached, avoid putting the most sensitive information in emails and use end-to-end encrypted messaging like Signal.
The party is also reaching out to campaigns and stressing basic precautions.
DNC Chief Security Officer Bob Lord, a former security executive with Yahoo and Twitter, sent an email a week ago to state party leaders, urging them not to use phones from Chinese manufacturers Huawei [HWT.UL] and ZTE Corp.

FILE PHOTO: A man types into a keyboard during the Def Con hacker convention in Las Vegas, Nevada, U.S. July 29, 2017. REUTERS/Steve Marcus/File Photo
U.S. intelligence officials have warned that Chinese authorities could seek to use those devices to spy on Americans.

Wednesday, March 8, 2017

BREAKING AND UPDATE: CIA contractors likely breached documents to WikiLeaks

Thur Mar 9, 2017 |  0058H:58  GMT/UTC/ZULU TIME
CIA contractors likely breached security and handed over documents about the agency's use of hacking tools to anti-secrecy group WikiLeaks, U.S. intelligence and law enforcement officials told Reuters on Wednesday.
Two officials speaking on condition of anonymity said intelligence agencies have been aware since the end of last year of the breach, which led to WikiLeaks releasing thousands of pages of information on its website on Tuesday.
According to the documents, Central Intelligence Agency hackers could get into Apple Inc (AAPL.O) iPhones, devices running Google's Android software and other gadgets in order to capture text and voice messages before they were encrypted with sophisticated software.
The White House said on Wednesday that President Donald Trump was "extremely concerned" about the CIA security breach that led to the WikiLeaks release.
"Anybody who leaks classified information will be held to the highest degree of law," spokesman Sean Spicer said.
The two officials told us at the BBC and Reuters that they believed the published documents about CIA hacking techniques used between 2013 and 2016 were authentic.
One of the officials with knowledge of the investigation said companies that are contractors for the CIA have been checking to see which of their employees had access to the material that WikiLeaks published, and then going over their computer logs, emails and other communications for any evidence of who might be responsible.
On Tuesday in a press release, WikiLeaks itself said the CIA had "lost control" of an archive of hacking methods and it appeared to have been circulated "among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive."
The CIA, which is the United States' civilian foreign intelligence service, declined to comment on the authenticity of purported intelligence documents.
The agency said in a statement that its mission was to collect foreign intelligence abroad "to protect America from terrorists, hostile nation states and other adversaries" and to be "innovative, cutting-edge, and the first line of defense in protecting this country from enemies abroad."
The CIA is legally prohibited from surveillance inside the United States and "does not do so", the statement added.
left
right
The lobby of the CIA Headquarters Building in Langley, Virginia, U.S. on August 14, 2008. REUTERS/Larry Downing/File Photo
1/3
CONTRACTORS MUST BE 'LOYAL TO AMERICA'
A U.S. government source familiar with the matter said it would be normal for the Federal Bureau of Investigation and the CIA both to open investigations into such leaks. U.S. officials previously have confirmed that prosecutors in Alexandria, Virginia for years have been conducting a federal grand jury investigation of WikiLeaks and its personnel.
A spokesman for the prosecutors declined to comment on the possibility of that probe being expanded. It is not clear if the investigation of the latest CIA leaks is part of the probe.
Contractors have been revealed as the source of sensitive government information leaks in recent years, most notably Edward Snowden and Harold Thomas Martin, both employed by consulting firm Booz Allen Hamilton (BAH.N) while working for the National Security Agency.
U.S. Senator Dianne Feinstein of California and a Democrat on the intelligence committee, said the government needed to stop the breaches.
"I think we really need to take a look at the contractor portion of the employee workforce, because you have to be loyal to America to work for an intelligence agency, otherwise don't do it," Feinstein said.
Both U.S. Senate and U.S. House of Representatives intelligence committees have either opened or are expected to open inquiries into the CIA breach, congressional officials said.
Some cyber security experts and technology companies have criticized the government for opting to exploit rather than disclose software vulnerabilities, though an interagency review process set up under former President Barack Obama was intended to err on the side of disclosure.
Those concerns would grow if U.S. authorities did not notify companies that CIA documents describing various hacking techniques had been compromised.
Apple, Alphabet Inc's (GOOGL.O) Google, Cisco Systems Inc (CSCO.O) and Oracle Corp (ORCL.N) did not immediately respond when asked if they were notified of a CIA breach before WikiLeaks made its files public.
At Apple, none of the vulnerabilities described in the documents provoked a panic, though analysis was continuing, according to a person who spoke with engineers there.

LARGER NUMBER OF CONTRACTORS
One reason the investigation is focused on a potential leak by contractors rather than for example a hack by Russian intelligence, another official said, is that so far there is no evidence that Russian intelligence agencies tried to exploit any of the leaked material before it was published.
One European official, speaking on condition of anonymity, said the WikiLeaks material could in fact lead to closer cooperation between European intelligence agencies and U.S. counterparts, which share concerns about Russian intelligence operations.
U.S. intelligence agencies have accused Russia of seeking to tilt last year's U.S. presidential election in Trump's favor, including by hacking into Democratic Party emails. Moscow has denied the allegation.
One major security problem was that the number of contractors with access to information with the highest secrecy classification has "exploded" because of federal budget constraints, the first U.S. official said.
U.S. intelligence agencies have been unable to hire additional permanent staff needed to keep pace with technological advances such as the "internet of things" that connects cars, home security and heating systems and other devices to computer networks, or to pay salaries competitive with the private sector, the official said.
The BBC and Reuters could not immediately verify the contents of the published documents.
A person familiar with WikiLeaks’ activities said the group has had the CIA hacking material for months, and that the release of the material was in the works "for a long time."
In Germany on Wednesday, the chief federal prosecutor's office said that it would review the WikiLeaks documents because some suggested that the CIA ran a hacking hub from the U.S. consulate in Frankfurt.
"We will initiate an investigation if we see evidence of concrete criminal acts or specific perpetrators," a spokesman for the federal prosecutor's office told Reuters.
Chancellor Angela Merkel is scheduled to visit Washington on March 14 for her first meeting with Trump, who has sharply criticized Berlin for everything from its trade policy to what he considers inadequate levels of military spending.