Showing posts with label social networks. Show all posts
Showing posts with label social networks. Show all posts

Thursday, December 10, 2009

Chris Brogan Video of Inspirational LeWeb Speech on Value of Social Networks





The New York Times Best Seller with Julien Smith

Click on the book and get connected to Chris Brogan's blog!

CISCO: Beware Koobface - Cyber crooks tarketing banks-social networks

Koobface is malicious code that steals social networking account credentials, logs into profiles and sends "friends" messages along the lines of wanting to share scintillating online videos.

An annual security report being released Tuesday by technology titan Cisco warns that banks and online social networks are prime targets for increasingly sophisticated cyber crooks.

"Criminals have been taking note of the large crowds in social-networking sites," said Cisco security researcher Scott Olechowski. "They steal them with various techniques."

Tactics used to get into social-networking profiles include hacking password databases at vulnerable online services and then exploiting the fact that many people use one password for multiple accounts.

Cisco estimates that a Koobface computer worm, named as a play on social networking hot spot "Facebook," has infected more than three million computers since it first appeared in 2008.
Links enclosed in the messages lead to bobby-trapped Web pages that trick visitors into infecting their machines with copies of the worm.

Crooks sometimes set up fake profiles and then finagle their ways into people's online social circles and entice them to opening computer files tainted with malicious code.

Money-making tricks can be as simple as hackers using social-networking profiles to pretend to be friends in desperate straits that ask to be wired money to get out of trouble in a far-away places.

Social networks are also targeted by hackers out to control or disrupt political discourse.

Business computers can wind up infected because one of every 50 "clicks" in the workplace is to social-networking websites, according to Cisco.

"The blending of social media for business and pleasure increases the potential for network security troubles, and people, not technology, can often be the source," said Cisco fellow Patrick Peterson.

"Without proper cognizance of security threats, our natural inclination to trust our 'friends' can result in exposing ourselves, home computers and corporate networks to malware."

Cyber criminals can mine profiles for names and email addresses of business executives or accounting department members to "spear phish," target strategically placed workers with scams.

The potential for workplace computers to be infected through a social-networking attack is all the more disturbing given the rise of a computer Trojan named Zeus crafted to digitally loot money from banks.

Once in computers, Zeus can swipe information and alter what is seen in Web browsers so that people tending to online banking see correct balances on screen while accounts are actually being emptied by cyber thieves.

"Zeus is sold on a retail basis by criminals to criminals," Olechowski said, putting the price at 700 dollars.

Gangs have used Zeus to steal "400,000 to 1.5 million dollars a shot," he added. Cisco predicts Zeus will be a growing bane in 2010.

Spam remains a tried-and-true method for tricking people into downloading malware or buying specious products, such as fake medicine.

Cisco's report estimates that the amount of spam worldwide next year will rise 30 to 40 percent above 2009 levels.

While US and European countries shut down spam-spewing networks of "zombie" computers infected with malicious code and commandeered by criminals, more are being created in developing countries, according to the California-based firm.

Brazil this year dethroned the United States as the country producing the most spam, according to Cisco. The amount of spam coming from Vietnam and India has also soared.

"In the World Cup of spam, Brazil beat the US for the first time," Olechowski said. "We are starting to see emerging economies represent the bulk of spam globally."

Cyber criminals are taking advantage of improved broadband Internet and computer access in developing countries where people may still have lessons to learn about Internet security.

Increasing spam in developing countries is a symptom of a greater problem, acccording to Cisco senior security researcher Henry Stern.

"This means that there is a greater rate of compromised machines, which means there will be more banking Trojans and other malware," Stern said.

Cisco created a Global Adversary Resource Market Share (ARMS) Race index, which estimates that between five and 10 percent of the world's personal computers are "compromised" by malicious software.

Sunday, August 9, 2009

US Marines Ban Facebook and Twitter: Use of Social Network Sites

The U.S. Marine Corps made it official this week: Social networking sites such as Facebook and Twitter are banned from military networks.

This new administrative directive doesn't change very much but clarifies the use of social networks from a security perspective.

Marines have never been allowed to access non-official sites like Facebook, MySpace or Twitter from military networks because it is classed as improper use of government property.

In this new or revised directive, the Marines have simply put an official stamp on the ban. At the same time, they are also laying out the process to be followed by any Marine who wants to officially access such a site, as part of his or her job.


A Haven and Conduit for Adversaries
"These Internet sites in general are a proven haven for malicious actors and content and are particularly high risk due to information exposure, user generated content and targeting by adversaries," the directive noted.

Increased Threat
"The very nature of social networking sites, creates a larger threat, attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage."

Improper use of US equipment
The ban, however, is only for people using Marines' equipment and networks while they are working. Marines may still Twitter or post to Facebook on their own time and on their own computers but they should do so with a raised level of awareness.

The military isn't against using sites like Facebook and Twitter, said 1st Lt. Craig Thomas, a Pentagon-based spokesman for the Marine Corps.

Facebook, YouTube and Twitter
The U.S. Central Command has a Facebook page, a channel on YouTube and a Twitter account to get out information regarding operations news. The Army is using MySpace to recruit new soldiers and the U.S. Forces Afghanistan page on Facebook has more than 24,000 fans.
A Balanced Approach
"The Marine Corps has got to find a balance between security and letting Marines capitalise on the technology," Thomas said in a recent interview. "We don't want information leaks. We want to keep Marines focused on their mission at work and we also wanted to save critical bandwidth. We're trying to find the fine line."
Measured Progress
Thomas noted that 30 years ago, soldiers were warned about revealing too much information in letters home. Then 10 years ago, they were warned about how they used e-mail. Today, the focus is on social networks.

Tight Lips
"You can't have someone posting, 'Hey, we're leaving on this date and at this time,'" he added. "Believe me, the enemy is checking out what you guys are reporting and what service men and women are saying online.

The Marine Corps instills tight operational security. They need to be cognizant of what they're saying, whether verbally or what they're saying on social networking sites."

Thursday, July 30, 2009

Social Engineering - The biggest Threat to Security is still You and your People

Social Engineering - Are you Tempted?
Whether they are going through the eTrash, dumpster diving, pod slurping, or impersonating other people, our constant companions, the hackers know that social engineering is still the best way to by-pass security.

People Skills
Social engineering finds and hits directly at our weak spot, you're a nice gal /guy, a people person and people are still the weakest link in security. Yes, it is difficult to change this because it means changing people's attitude and behaviour. Plus you have just spent 10's of thousands of Dollars, Pounds and Euros, to give them better customer facing skills.

Why? It Works!
Why are hackers still using social engineering to gain access to organisations? Because it still works better than anything else and it provides quicker results. It's easier to infiltrate an organisation via the people because the security is focused elsewhere, on the building and on Technology. Plus your guard is down, your complacent because you 'think' you are secure.

Who? People!
Front-of-House contact people are the most succeptible to intrusions. Partly because they form the first barrier but also because they are often bored, busy, isolated. Almost certainly, the least aware, uninformed or not adequately trained, concerning social engineering techniques and their risk to security. After all, who doesn't like to help a nicely dressed, sexy gal /guy and be rewarded by a smile, a compliment or just some friendly attention? What 'bait' would work on you?

What are the most likely vulnerabilities versus bad behaviours:

1. People want to be, and are trained to be helpful and co-operative. Sometimes this help can go too far and they give away too much information. - Make it clear to them what they can and cannot reveal, in writing.

2. People want to avoid confrontation and are trained towards compromise. It's difficult for some people to ask others to prove who they are. They don't like or want confrontation, especially with a possible 'authority' figure. Support your staff's doubts and back them up, review and clarify their decisions.

3. People like convenience and easy options. No one wants to take the complex additional security check route because they are busy or distracted, even if it may protect or benefit the organisation. Make the secure route the easy option for your staff.

4. People are messy, unorganised and easily distracted. They leave paper around, leave screens open to view, copy multiple people on e-mails, gossip and leak data. Provide them with pleasant incentives to change their behaviour and give them other, more positive things to talk about.

5. People are curious, inquisitive creatures. A great example is an employee who finds a USB drive in the parking lot. The first thing they do when they get to their desk is plug it in to see what's on it. You have to tell them why this is a threat to security and also a violation of someone else's privacy.

Is there light?
Social engineering attacks are some of the most difficult to defend against, but not all is darkness. Your greatest weapon is training and education. Maintaining awareness of current threat profiles and passing those on as a simple and easy to implement 'cheat sheet' or guidelines. Address all of peoples' senses, sight, sound and listenning. Use the technology Podcasts, MP3s, YouTube Videos, Twit and Facebook them. Whatever it takes.

Technical Barriers
There are very few technical solutions to people problems but here are some technical controls that are sensible to put in place:

* Lock down or limit capability of all peripheral devices, especially USB ports. There are now many commercial products that allow security administrators to completely lock down USB ports. This might be difficult but not impossible, because many devices are connected via USB ports.
* Use Data Loss Prevention techniques and products. Know who has access to your data, when they access it, and what they are accessing. Not very effective if someone's profile has been duplicated, stolen or access has been incorrectly allowed.
* Use encryption on every device and wherever systems talk to systems.

Remember 'If your employees don't know what social engineering is and how it operates, why should they change their behaviour?" You are the Agent of Change! Make it so!

Sunday, July 26, 2009

Is Innovation a Healthcare Solution?

While we don't yet have holographic physicians to consult, healthcare is moving online, encouraged by an international coalition of medical and technology companies.

Medical devices from weighing scales to asthma inhalers could soon carry the technology to connect directly to the web, shuttling data between doctors and their patients.

For practical reasons, health workers are often unable to talk to home-based patients with chronic conditions on a daily basis but they could keep in contact online. Medical records automatically updated whenever the patient measures their own blood pressure, checks their weight, or takes their medication. Such technology could help medical workers ensure remote patients are healthy, and detect any problems at an early stage before they become serious.

The move beyond traditional telehealth, remote contact with a patient through phone calls or video conferencing, is being encouraged by the Continua Health Alliance, a non-profit open industry group. The alliance boasts some powerful players in both the technology and medical arenas, including IBM, Intel, Google, Kaiser Permanente and the UK's National Health Service.

We're moving into a 'Web 2.0'-style healthcare model. The medical provider doesn't have to be logged in at the same time as the patient to see the data.

Remote control

The technology for a "Health 2.0" model already exists, but the standards needed to guarantee its smooth running have been lacking, until now. In February, Continua announced guidelines aimed to ensure the interoperability of new medical gadgets. Continua-certified devices will use USB or Bluetooth, and data transmitted between devices will use an IEEE standard in the same way that Wi-Fi networks do.

At the beginning of the year US firm Nonin unveiled the world's first Continua-certified product, a USB handheld pulse oximeter for blood oxygen monitoring.

More devices have followed: in May, international technology development firm Cambridge Consultants announced a wireless inhaler built around the company's Continua-compatible Vena platform.

The device receives a wireless signal and alerts the user when a dose should be inhaled. Once it has sensed the medication being issued, the gadget transmits a confirmation signal back to a central server, and the patient's health record is automatically updated.

'Ecosystem approach'

"To be honest the technology is the easy bit," says Paul Jones, chief technology officer for the National Health Service. "It's all very well having a clever weighing device in your room that notices your weight has increased and you're at risk of diabetes but if that alert doesn't reach the right people the whole system falls apart."

The UK Department of Health has begun trials involving thousands of patients to test whether patients and medics could benefit from the Health 2.0 system, although it's too early yet to draw any conclusions.

Parker is confident that tests of this nature will show the power of the Continua model, because the Continua Alliance already links professional healthcare workers with technology providers. "It's a whole ecosystem approach," he says, which provides technology companies with feedback from healthcare experts to improve their products.

FaceBook for health?

Health 2.0 might involve more than patient-medic interactions. The social networking sites that have emerged in recent years could have their healthcare counterparts, says Paul Williamson of Cambridge Consultants, which is based in the UK.

"We made some concept websites that go with our inhaler to show how you could use the data to benefit the patient," he says. The sites receive signals from medical devices and award points for every compliant dose of medicine. Friends with similar conditions could then informally compete against each other to improve compliance.

Watch a video of Cambridge Consultants' inhaler and concept social network site in action (YouTube)

In research, it's been found that the biggest motivation to take care of your health is co-workers and family. If we can tie compliance to social situations we can create the right environment for people to help themselves.

Sharing society

Parker acknowledges that some may find talk of merging health records and social networks unsettling given the privacy concerns dogging existing services like Facebook. Indeed, any talk of moving medical records online is met with unease, when Continua Alliance member Google launched the Google Health service last year, privacy and security issues were raised. Data security will always remain a high priority.

Thankfully attitudes are changing. With online services like Twitter, people are sharing more personal information than ever before, and some web users may have few qualms about sharing personal data. There's been a sociological shift from not sharing any information to sharing everything, your location and what you're doing every hour of the day.

Jones stresses that patients won't be forced to use the new technology, even in the publicly funded NHS. Those in the UK that do opt for an online service can expect their data to be stored in NHS-run systems rather than Google Health or similar private-sector databases.

"It's about understanding that there's a trade-off," says Parker. A patient might decide that the benefits from using the latest technology to interact with medics, and their peers, outweigh the potential privacy cost – or they might not. "I think a lot of people are now looking at this and deciding it's worth it."