Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

20190429

As The Privacy Regulators Circle Facebook Is It Already Unstoppable?

This week was both fantastic and terrible for Facebook. Its latest earnings report shows the company has become an unstoppable force whose user growth and profits are immune to its never-ending parade of privacy and security breaches. Even the FCC appears willing to back down from its confrontation with the company and slap it with a fine that amounts to just a tiny fraction of its quarterly profit, making even legal violations nothing more than the cost of doing business. At the same time, Facebook confronts newly emboldened regulators around the world all clamoring for their own chance to bring the world’s most powerful gatekeeper to heel. The only problem is that Facebook may already be unstoppable.

Facebook has much to cheer about.

As has become increasingly clear, the public no longer seems to care about their digital privacy or security.

Despite breach after breach after breach after breach, users aren’t leaving and aren’t demanding any changes to the company’s business practices. In fact, Facebook is only growing bigger as more users clamor to jump onboard the privacy wreck.


Is Facebook simply too large to regulate or change? The answer is that it isn’t just Facebook that seems immune to the death sentence that was historically the outcome of a major breach.

Ashley Madison explicitly credits its massive 2015 security breach in powering its spectacular renaissance, giving it enormous free global media saturation that has driven incredible growth.

It seems the laws of gravity that once applied to security and privacy breaches have been redefined in 2019. Rather than harming a company, having a major breach that garners global headlines can actually be a tremendous boost to a company.

Facebook has learned over the years that while the public is quick to complain about privacy and security issues, they are unwilling to take action to demand change on those fronts. After all, it was just under a decade ago that Facebook fought its first major privacy battle, with the same endless privacy headlines, policymaker threats of regulation and predictions of mass user defections, none of which came true.

Each time there is a public uproar over privacy, Facebook simply waits it out, safe in the knowledge that we no longer care enough about our digital safety to actually give up our membership in its exclusive walled garden.

Similarly, governments are loathe to regulate the very company they depend so heavily upon to win reelection.

Facebook has become a master at calling governmental bluffs. In the aftermath of an almost endless deluge of potential GDPR violations, the company has amassed case after case of egregious deviations from the protections afforded by GDPR, redefining its provisions to its own business needs. To date the European Union has offered only that it is “investigating” the matters but has taken no meaningful action against the company and it is likely that any GDPR-related actions will be litigated in court for years.

Even if the company is fined billions of dollars, the simple fact of the matter is that a few billion dollars against Facebook’s enormous quarterly profit is merely the cost of doing business just like the utility bills and bandwidth costs of its data centers.

If Facebook can get away with doing whatever it wants for a grand total of a few billion dollars of fines a year, it can recoup that cost in a matter of weeks.

In fact, the company predicts the ultimate outcome of the wide-ranging FCC investigation of its consent decree violation will merely be a fine of a few billion dollars and potentially a new consent decree. Given that the Facebook didn’t view the last consent decree as terribly binding on its business practices, it is unclear what good a new agreement would do.

The simple fact of the matter is that Facebook is so massive that even billion-dollar fines can be readily absorbed as the cost of doing business.

In many ways, an apt example is a speeding ticket in the United States. To someone barely making ends meet, a speeding ticket and the attendant fines and insurance rate increases may force them to sell their car or even bankrupt them. To a billionaire supercar owner, they could likely pay the fine out of the cash in their wallet – it simply has no incentivizing impact on their behavior. To address this, many jurisdictions will suspend the driver’s license if they receive too many tickets, ensuring that wealth alone cannot place someone entirely above the law.

Yet, when it comes to social media companies, the maximum penalties they can confront today in most countries are fines that are so small as to amount as nothing more than an annoyance.

In cases where companies face actual legal jeopardy, such as copyright infringement in the United States or hate speech in Germany, the company has invested heavily in addressing the issues, demonstrating that legislation or the threat of it can have a powerful incentivizing impact on their actions.

In the United States anti-monopoly laws have had little practical impact on social media companies because they don’t charge their users a fee, while their impact on the prices charged to advertisers has presented a more complicated picture for regulators.

However, as Facebook's internal correspondence continues to surface through whistleblowers, leaks and disclosures, the company's view of its user data as having very real monetary value could make it more vulnerable to such regulatory intervention.

Yet, as calls for regulation grow, the company’s ability to silence criticism and debate has been on increasing display.

The company did not respond to a request for comment on these issues.

Putting this all together, we really must ask as a society if Facebook is now simply too powerful to regulate. Powerful companies have long given way to new upstarts, been constrained by regulation or even broken up.

Yet, no company in history has ever held the power Facebook does over information itself.

Social media platforms quite literally control who speaks to the President of the United States and what citizens are permitted to talk about with their elected officials. They have even actively intervened in foreign elections to interfere with the information environment in ways that actively harmed one of the parties and today actively ban a number of democratically elected political parties in Europe, including ones holding seats in the European Parliament.

If Facebook was confronted with a legitimate threat to its very existence, it would be within its technical capabilities as a company to intervene in elections across the world to elect anti-regulation candidates, block elected officials from talking about regulation or hearing regulatory concerns from their citizens and even ban all society-wide discussion and debate about regulation.

The capacity is there, Facebook merely has to flip an algorithmic switch to enable it.

In the end, the only question is what it will take to awaken the sleeping giant.


AS SEEN @https://www.forbes.com/sites/kalevleetaru/2019/04/26/as-the-privacy-regulators-circle-facebook-is-it-already-unstoppable/#570f1f4a49ee

20170731

Hackers Are Targeting Nuclear Facilities, Homeland Security Dept. and F.B.I. Say



Since May, hackers have been penetrating the computer networks of companies that operate nuclear power stations and other energy facilities, as well as manufacturing plants in the United States and other countries.

Among the companies targeted was the Wolf Creek Nuclear Operating Corporation, which runs a nuclear power plant near Burlington, Kan., according to security consultants and an urgent joint report issued by the Department of Homeland Security and the Federal Bureau of Investigation last week.

The joint report was obtained by The New York Times and confirmed by security specialists who have been responding to the attacks. It carried an urgent amber warning, the second-highest rating for the sensitivity of the threat.

The report did not indicate whether the cyberattacks were an attempt at espionage — such as stealing industrial secrets — or part of a plan to cause destruction. There is no indication that hackers were able to jump from their victims’ computers into the control systems of the facilities, nor is it clear how many facilities were breached.

Wolf Creek officials said that while they could not comment on cyberattacks or security issues, no “operations systems” had been affected and that their corporate network and the internet were separate from the network that runs the plant.
Continue reading the main story

In a joint statement with the F.B.I., a spokesman for the Department of Homeland Security said, “There is no indication of a threat to public safety, as any potential impact appears to be limited to administrative and business networks.”

The hackers appeared determined to map out computer networks for future attacks, the report concluded. But investigators have not been able to analyze the malicious “payload” of the hackers’ code, which would offer more detail into what they were after.

John Keeley, a spokesman for the Nuclear Energy Institute, which works with all 99 electric utilities that operate nuclear plants in the United States, said nuclear facilities are required to report cyberattacks that relate to their “safety, security and operations.” None have reported that the security of their operations was affected by the latest attacks, Mr. Keeley said.

In most cases, the attacks targeted people — industrial control engineers who have direct access to systems that, if damaged, could lead to an explosion, fire or a spill of dangerous material, according to two people familiar with the attacks who could not be named because of confidentiality agreements.

The origins of the hackers are not known. But the report indicated that an “advanced persistent threat” actor was responsible, which is the language security specialists often use to describe hackers backed by governments.

The two people familiar with the investigation say that, while it is still in its early stages, the hackers’ techniques mimicked those of the organization known to cybersecurity specialists as “Energetic Bear,” the Russian hacking group that researchers have tied to attacks on the energy sector since at least 2012.

Hackers wrote highly targeted email messages containing fake résumés for control engineering jobs and sent them to the senior industrial control engineers who maintain broad access to critical industrial control systems, the government report said.

The fake résumés were Microsoft Word documents that were laced with malicious code. Once the recipients clicked on those documents, attackers could steal their credentials and proceed to other machines on a network.

In some cases, the hackers also compromised legitimate websites that they knew their victims frequented — something security specialists call a watering hole attack. And in others, they deployed what are known as man-in-the-middle attacks in which they redirected their victims’ internet traffic through their own machines.

Energy, nuclear and critical manufacturing organizations have frequently been targets for sophisticated cyberattacks. The Department of Homeland Security has called cyberattacks on critical infrastructure “one of the most serious national security challenges we must confront.”

On May 11, during the attacks, President Trump signed an executive order to strengthen the cybersecurity defenses of federal networks and critical infrastructure. The order required government agencies to work with public companies to mitigate risks and help defend critical infrastructure organizations “at greatest risk of attacks that could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security.”

The order specifically addressed the threats from “electricity disruptions and prolonged power outages resulting from cybersecurity incidents.”

Jon Wellinghoff, the former chairman of the Federal Energy Regulatory Commission, said in an interview last week that while the security of United States’ critical infrastructure systems had improved in recent years, they were still vulnerable to advanced hacking attacks, particularly those that use tools stolen from the National Security Agency.

“We never anticipated that our critical infrastructure control systems would be facing advanced levels of malware,” Mr. Wellinghoff said.

In 2008, an attack called Stuxnet that was designed by the United States and Israel to hit Iran’s main nuclear enrichment facility, demonstrated how computer attacks could disrupt and destroy physical infrastructure.

The government hackers infiltrated the systems that controlled Iran’s nuclear centrifuges and spun them wildly out of control, or stopped them from spinning entirely, destroying a fifth of Iran’s centrifuges.

In retrospect, Mr. Wellinghoff said that attack should have foreshadowed the threats the United States would face on its own infrastructure.

Critical infrastructure is increasingly controlled by Scada, or supervisory control and data acquisition systems. They are used by manufacturers, nuclear plant operators and pipeline operators to monitor variables like pressure and flow rates through pipelines. The software also allows operators to monitor and diagnose unexpected problems.

But like any software, Scada systems are susceptible to hacking and computer viruses. And for years, security specialists have warned that hackers could use remote access to these systems to cause physical destruction.


AS SEEN @

https://www.nytimes.com/2017/07/06/technology/nuclear-plant-hack-report.html?_r=0