/* ---- Google Analytics Code Below */
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Saturday, April 22, 2023

AI Tools Will Inspire Hacks

Inevitable, especially as they are easier to test and use.

AI Tools like ChatGPT likely to empower hacks, NSA cyber boss warns

By Colin Demarest, Wednesday, Apr 12  in c4isrnet.com 

WASHINGTON — Generative artificial intelligence that fuels products like ChatGPT will embolden hackers and make email inboxes all the more tricky to navigate, according to the U.S. National Security Agency cybersecurity director.

While much-debated AI tools will not automate or elevate every digital assault, phishing scheme or hunt for software exploits, NSA’s Rob Joyce said April 11, what it will do is “optimize” workflows and deception in an already fast-paced environment.

“Is it going to replace hackers and be this super-AI hacking? Certainly not in the near term,” Joyce said at an event hosted by the Center for Strategic and International Studies think tank. “But it will make the hackers that use AI much more effective, and they will operate better than those who don’t.”

U.S. officials consider mastery of AI critical to long-term international competitiveness — whether that’s in defense, finance or another sector. At least 685 AI projects, including several tied to major weapons systems, were underway at the Pentagon as of early 2021.

With enough training, the technology can handle menial tasks, such as answering questions and digging up contact information, or augment military operations by parsing tides of incoming information and facilitating exploration of areas deemed too dangerous for troops.

Something as sophisticated as OpenAI’s ChatGPT, Joyce said Tuesday, can be used to “craft very believable native-language English text” that can then be applied to phishing attacks or foreign influence campaigns. ChatGPT is capable of holding humanlike conversations with enough prompting, and it can provide content like poetry, essays or computer code within seconds.

“That’s going to be a problem,” Joyce said ....'

Tuesday, March 07, 2023

Protecting AI From Hackers or can AI Provide Better Threat Protection?

Big problem.   It has been suggested too that AI methods can be used to provide smart protection,  but early results seem to indicate this is harder than expected.

These Experts are Racing to Protect AI from Hackers. Time is Running Out  By ZDNet, February 24, 2023

Said Bruce Draper, a program manager at the U.S. Defense Department's Defense Advanced Research Projects Agency, "We want to give everyone the opportunity to defend themselves."

Bruce Draper bought a new car recently. The car has all the latest technology, but those bells and whistles bring benefits -- and, more worryingly, some risks. 

"It has all kinds of AI going on in there: lane assist, sign recognition, and all the rest," Draper says, before adding: "You could imagine all that sort of thing being hacked -- the AI being attacked."

It's a growing fear for many -- could the often-mysterious AI algorithms, which are used to manage everything from driverless cars to critical infrastructure, healthcare, and more, be broken, fooled or manipulated? 

What if a driverless car could be fooled into driving through stop signs, or an AI-powered medical scanner tricked into making the wrong diagnosis? What if an automated security system was manipulated to let the wrong person in, or maybe not even recognize there was ever a person there at all? 

As we all rely on automated systems to make decisions with huge potential consequences, we need to be sure that AI systems can't be fooled into making bad or even dangerous decisions. City-wide gridlock or essential services being interrupted could be just some of the most visible problems that could result from the failure of AI-powered systems. Other harder-to-spot AI system failures could create even more problems.

From ZDNet   View Full Article    

Monday, February 13, 2023

A Hackers Mind Pubished

 Just about to read, good direction, about to read     by Bruce Schneier

A Hacker’s Mind         Is Now Published  by Bruce Schneier     

Tuesday was the official publication date of A Hacker’s Mind: How the Powerful Bend Society’s Rules   , and How to Bend them Back.   It broke into the 2000s on the Amazon best-seller list.  ...' 

Reviews in the New York Times  , Cory Doctorow’s blog  , Science , and the Associated Press  ... ' 

 (in Amazon)  ... Legendary cybersecurity expert and New York Times best-selling author Bruce Schneier reveals how using a hacker’s mindset can change how you think about your life and the world.

A hack is any means of subverting a system’s rules in unintended ways. The tax code isn’t computer code, but a series of complex formulas. It has vulnerabilities; we call them “loopholes.” We call exploits “tax avoidance strategies.” And there is an entire industry of “black hat” hackers intent on finding exploitable loopholes in the tax code. We call them accountants and tax attorneys.

In A Hacker’s Mind, Bruce Schneier takes hacking out of the world of computing and uses it to analyze the systems that underpin our society: from tax laws to financial markets to politics. He reveals an array of powerful actors whose hacks bend our economic, political, and legal systems to their advantage, at the expense of everyone else.

Once you learn how to notice hacks, you’ll start seeing them everywhere―and you’ll never look at the world the same way again. Almost all systems have loopholes, and this is by design. Because if you can take advantage of them, the rules no longer apply to you.

Unchecked, these hacks threaten to upend our financial markets, weaken our democracy, and even affect the way we think. And when artificial intelligence starts thinking like a hacker―at inhuman speed and scale―the results could be catastrophic.

But for those who would don the “white hat,” we can understand the hacking mindset and rebuild our economic, political, and legal systems to counter those who would exploit our society. And we can harness artificial intelligence to improve existing systems, predict and defend against hacks, and realize a more equitable world ... 

Sunday, November 13, 2022

New Schneier Book: A Hackers Mind

 I see that Bruce Schneier is coming out with a new book, always interesting, I plan to read and review it, he writes:

New Book: A Hacker’s Mind

I have a new book coming out in February. It’s about hacking.

A Hacker’s Mind: How the Powerful Bend Society’s Rules, and How to Bend them Back isn’t about hacking computer systems; it’s about hacking more general economic, political, and social systems. It generalizes the term hack as a means of subverting a system’s rules in unintended ways.

What sorts of system? Any system of rules, really. Take the tax code, for example. It’s not computer code, but it’s a series of algorithms—supposedly deterministic—that take a bunch of inputs about your income and produce an output that’s the amount of money you owe. This code has vulnerabilities; we call them loopholes. It has exploits; those are tax avoidance strategies. And there is an entire industry of black-hat hackers who exploit vulnerabilities in the tax code: we call them accountants and tax attorneys.

In my conception, a “hack” is something a system permits, but is unanticipated and unwanted by its designers. It’s unplanned: a mistake in the system’s design or coding. It’s subversion, or an exploitation. It’s a cheat—but only sort of. Just as a computer vulnerability can be exploited over the Internet because the code permits it, a tax loophole is “allowed” by the system because it follows the rules, even though it might subvert the intent of those rules.

Once you start thinking of hacking in this way, you’ll start seeing hacks everywhere. You can find hacks in professional sports, in customer reward programs, in financial systems, in politics; in lots of economic, political, and social systems; against our cognitive functions. A curved hockey stick is a hack, and we know the name of the hacker who invented it. Airline frequent-flier mileage runs are a hack. The filibuster was originally a hack, invented by Cato the Younger, A Roman senator in 60 BCE. Hedge funds are full of hacks.

A system is just a set of rules. Or norms, since the “rules” aren’t always formal. And even the best-thought-out sets of rules will be incomplete or inconsistent. It’ll have ambiguities, and things the designers haven’t thought of. As long as there are people who want to subvert the goals of a system, there will be hacks. ... ' 

Thursday, September 08, 2022

Hacking Smartphones

Note this requires device proximity

 Hacking Device Can Secretly Swipe, Tap Smartphone Screen

New Scientist

Jeremy Hsu, August 31, 2022

Separate teams of researchers have developed devices for remotely hacking smartphone touchscreens. Both methods involve placing devices featuring an antenna for transmitting signals and a phone locator under a table. The locator deduces the position and orientation of a touchscreen device placed on the table, then the antenna sends electromagnetic signals imitating electric field disturbances caused by physical touch. The Invisible Finger method created by University of Florida researchers caused both iOS and Android devices to recognize the electromagnetic touches; the GhostTouch technique from scientists at China's Zhejiang University worked with multiple Android devices, but could not crack the iPhone 7 Plus or certain OPPO phone models. The hacks only work with the target device lying face down and positioned close to the antenna.

In NewScientist

Wednesday, August 31, 2022

LastPass Hacked

Reasons still unclear.

LastPass, Password Manager with Millions of Users, Is Hacked

The Wall Street Journal

By Alyssa Lukpat, August 26, 2022

On Aug. 25, online password manager LastPass reported the theft of some of its source code and proprietary information, but said there is no evidence customer information from its more than 33 million users or encrypted password vaults were accessed. LastPass' Karim Toubba said a developer account had been breached, allowing an unauthorized party to access the company's development environment. The unusual activity was detected two weeks ago, prompting an investigation. Toubba said the company is working with a cybersecurity and forensics firm and has rolled out additional security measures. LastPass stores encrypted login information that users can access online with a master password, but they cannot see customers' data. ... '

Wednesday, August 24, 2022

Starlink Hacked

 Another look at this recent development. 

Researcher Hacks Starlink Terminal to Warn SpaceX of Dangerous Flaws

Lennert Wouters has apparently made the details of his hacking tool open source.

By Passant Rabie

A researcher from Belgium created a $25 hacking tool that could glitch Starlink’s internet terminals, and he is reportedly going to make this tool available for others to copy. Lennert Wouters, a security researcher at KU Leuven, demonstrated how he was able to hack into Elon Musk’s satellite dishes at the Black Hat Security Conference being held this week in Las Vegas, Wired reported.

During his presentation at the conference on Wednesday, Wouters went through the hardware vulnerabilities that allowed him to access the Starlink satellite terminal and create his own custom code. “The widespread availability of Starlink User Terminals (UT) exposes them to hardware hackers and opens the door for an attacker to freely explore the network,” Wouters wrote in the description of Wednesday’s briefing.

SpaceX has launched a total of 3,009 satellites to low Earth orbit, building out a megaconstellation designed to beam down connectivity to even the most distant parts of the world. Starlink customers get a 19-inch wide Dishy McFlatface (a clever name bestowed upon the company’s satellite dish) to install on their homes, or even carry with them on the road. 

In order to hack the Starlink dish, Wouters created a modchip, or a custom circuit board that can be attached to the satellite dish, according to Wired. The modchip was put together using off-the-shelf parts that cost about $25 in total, and Wouters has reportedly made the details of the modchip available for download on Github. The small device can be used to access McFlatface’s software, launching an attack that causes a glitch and opens up previously locked parts of the Starlink system. “Our attack results in an unfixable compromise of the Starlink [user terminal] and allows us to execute arbitrary code,” Wouters wrote. “The ability to obtain root access on the Starlink [user terminal] is a prerequisite to freely explore the Starlink network.”  ... ' 

Sunday, May 29, 2022

Smart Office Buildings Are Vulnerable to Hacks

Makes sense considering the context,   

Smart Office Buildings Are Vulnerable to Hacks

The Wall Street Journal, Konrad Putzier, May 3, 2022

Smart office buildings in the U.S. raise concerns about privacy and cybersecurity. Cybersecurity consultants warn that building managers devote little attention to digital security, and the interconnection of smart building systems means accessing a single Internet-connected door can potentially enable hijacking, extortion, or data theft. Lucian Niemeyer at smart-building safety nonprofit Building Cyber Security worries that more criminals will target smart buildings as protections for mobile phones and databases are strengthened. Said Dave Tyson of cybersecurity company Apollo Information Systems Corp., “The bad guys only need to find one way in, and whatever you’ve connected to is now on the table.”  ...

Monday, May 23, 2022

Chinese Hackers Tried to Steal Russian Defense Data

More examples of hacking based warfare.

Chinese Hackers Tried to Steal Russian Defense Data

By The New York Times, May 20, 2022

The emails landed on March 23 in the inboxes of scientists and engineers at several of Russia's military research and development institutes, purportedly sent by Russia's Ministry of Health. They carried a subject line that offered seemingly tantalizing information about a "list of persons under U.S. sanctions for invading Ukraine."

But the emails were actually sent by state-sponsored hackers in China seeking to entice their Russian targets to download and open a document with malware, according to a new report to be released Thursday by the Israeli-American cybersecurity firm Check Point.

The report provides new evidence of Chinese efforts to spy on Russia, pointing to the complexity of the relations between two countries that have drawn closer in solidarity against the United States. It also underscores the sprawling, and increasingly sophisticated, tactics China's cyberspies have used to collect information on an ever-expanding array of targets, including countries it considers friends, like Russia.   ;

The emails landed on March 23 in the inboxes of scientists and engineers at several of Russia's military research and development institutes, purportedly sent by Russia's Ministry of Health. They carried a subject line that offered seemingly tantalizing information about a "list of persons under U.S. sanctions for invading Ukraine."

But the emails were actually sent by state-sponsored hackers in China seeking to entice their Russian targets to download and open a document with malware, according to a new report to be released Thursday by the Israeli-American cybersecurity firm Check Point. ... '

The report provides new evidence of Chinese efforts to spy on Russia, pointing to the complexity of the relations between two countries that have drawn closer in solidarity against the United States. It also underscores the sprawling, and increasingly sophisticated, tactics China's cyberspies have used to collect information on an ever-expanding array of targets, including countries it considers friends, like Russia ...'

In the NYTimes.  

Sunday, May 15, 2022

Russia Is Being Hacked at an Unprecedented Scale

 FROM ACM NEWS

Many cybercriminals and ransomware groups have links to Russia and don't target the nation. Now, it's being opened up.

in Wired  via ACM News | April 28, 2022 

The orders are issued like clockwork. Every day, often at around 5 am local time, the Telegram channel housing Ukraine's unprecedented "IT Army" of hackers buzzes with a new list of targets. The volunteer group has been knocking Russian websites offline using wave after wave of distributed denial-of-service (DDoS) attacks, which flood websites with traffic requests and make them inaccessible, since the war started.

Russian online payment services, government departments, aviation companies, and food delivery firms have all been targeted by the IT Army as it aims to disrupt everyday life in Russia. "Russians have noticed regular hitches in the work of TV streaming services today," the government-backed operators of the Telegram channel posted following one claimed operation in mid-April.

The IT Army's actions were just the start. Since Russia invaded Ukraine at the end of February, the country has faced an unprecedented barrage of hacking activity. Hacktivists, Ukrainian forces, and outsiders from all around the world who are taking part in the IT Army have targeted Russia and its business. DDoS attacks make up the bulk of the action, but researchers have spotted ransomware that's designed to target Russia and have been hunting for bugs in Russian systems, which could lead to more sophisticated attacks.

Full article:  


Tuesday, May 10, 2022

UK Blames Russia For Satellite Hack

In the BBC, more examples of tech warfare and implications.

UK blames Russia for satellite internet hack at start of war   By Chris Vallance,  BBCTechnology Reporter

Russia was behind a cyber-attack targeting American commercial satellite internet company Viasat, UK and US intelligence suggests. The attack began about an hour before Russia invaded Ukraine, on 24 February.

It caused outages for several thousand Ukrainian customers - and affected windfarms and internet users in Central Europe. Officials have long believed Russia was to blame but lacked the evidence to say so publicly. Viasat provides high-speed satellite broadband to commercial and military customers.

The company has previously said "tens of thousands of terminals" were damaged beyond repair, in the cyber-attack, though its core network infrastructure and the satellite itself remained unscathed.  .... ' 

Sunday, March 27, 2022

Serious Cyber Attacks Imminent?

 Given some of the strong language being used lately,  we should be aware of possible attacks on our key infrastructure, including power, water, internet and beyond.     There have seen some indications by Google and other players that they are sending ou emergency security updates and warnings.  Panic not advised, but do secure your key systems.  Imagine your world without an operational internet.     Here from the BBC an outline of key possibilities:  https://www.bbc.com/news/technology-60841924.

US Infrastructure Companies Must Report Hacking

Via Bruce Schneier who writes (and includes considerable comment at the link) 

US Critical Infrastructure Companies Will Have to Report When They Are Hacked ...

Companies critical to U.S. national interests will now have to report when they’re hacked or they pay ransomware, according to new rules approved by Congress .....    The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon. It requires any entity that’s considered part of the nation’s critical infrastructure, which includes the finance, transportation and energy sectors, to report any “substantial cyber incident” to the government within three days and any ransomware payment made within 24 hours.... 

Even better would be if they had to report it to the public.(writes Schneier) ... 

Saturday, March 26, 2022

Cyberwarfare

Cyberwarefare and need for vigilance, prep now and in the Future

Anonymous Claims it Hacked Russia's Central Bank   By Daily Mail (U.K.)  Reuters March 24, 2022

Earlier this week, Anonymous warned Western companies continuing to operate in Russia that they must pull out or risk facing cyberattacks in light of the invasion of Ukraine.

International hacking collective Anonymous claims to have exploited Russia's Central Bank - and is threatening to release 35,000 files which include 'secret agreements' in the next 48 hours.   The bank is responsible for protecting and ensuring the safety of the ruble, the Russian currency which has plummeted in value since the invasion of Ukraine began last month.

In a post on Twitter late last night by one of the group's accounts, Anonymous revealed its latest hack, though details were limited.

From Daily Mail (U.K.)

View Full Article  

Friday, March 25, 2022

Russian Energy Hacking Claimed

Energy being attacked? 

US charges four Russians over hacking campaign on energy sector

By Gordon Corera, Security correspondent, in BBC News

The US has charged four Russians government employees with cyber-attacks on the global energy sector. They are accused of targeting hundreds of companies and organisations in around 135 countries between 2012-2018.Their activities are said to have caused two separate emergency shutdowns at one facility in Saudi Arabia.  The conspiracy then allegedly attempted to hack the computers of a company that managed similar critical infrastructure entities in the US.  Some of the individuals are linked by the US indictment to the FSB, Russia's security service. The UK has also sanctioned a Russian defence organisation said to be linked to the attack.  ... ' 

Wednesday, October 20, 2021

US Commerce Dept Bans Selling Hacking Tools to China, Russia

Not sure this means very much, but the list of tools mentioned within the article is interesting.

 Commerce Department announces new rule aimed at stemming sale of hacking tools to Russia and China   By Ellen Nakashima,    Wash Post

Today at 9:38 a.m. EDT

The Commerce Department on Wednesday announced a long-awaited rule that officials hope will help stem the export or resale of hacking tools to China and Russia while still enabling cybersecurity collaboration across borders.

The rule, which will take effect in 90 days, would cover software such as Pegasus, a potent spyware product sold by the Israeli firm NSO Group to governments that have used it to spy on dissidents and journalists.   ... ' 

Saturday, September 18, 2021

The Hacking of McD's Ice Cream Machine

 A little surreal, but a reminder that anything can be hacked.  I had heard of the problem from McDonalds,  Had been unaware of some of the details involved.  Just the intro below.  Quite a story.  

They Hacked McDonald’s Ice Cream Machines—and Started a Cold War  in Wired

Secret codes. Legal threats. Betrayal. How one couple built a device to fix McDonald’s notoriously broken soft-serve machines—and how the fast-food giant froze them out.OF ALL THE mysteries and injustices of the McDonald’s ice cream machine, the one that Jeremy O’Sullivan insists you understand first is its secret passcode.

Press the cone icon on the screen of the Taylor C602 digital ice cream machine, he explains, then tap the buttons that show a snowflake and a milkshake to set the digits on the screen to 5, then 2, then 3, then 1. After that precise series of no fewer than 16 button presses, a menu magically unlocks. Only with this cheat code can you access the machine’s vital signs: everything from the viscosity setting for its milk and sugar ingredients to the temperature of the glycol flowing through its heating element to the meanings of its many sphinxlike error messages.

“No one at McDonald’s or Taylor will explain why there’s a secret, undisclosed menu," O’Sullivan wrote in one of the first, cryptic text messages I received from him earlier this year.  ... '

Saturday, August 28, 2021

Spies for Hire

More Evidence of Global Hacking

Spies for Hire: China's New Breed of Hackers, By The New York Times, August 27, 2021

A web of front companies controlled by China's secretive state security ministry have hacked computers from the United States to Cambodia to Saudi Arabia seeking sensitive government data as well as less-sensitive information, according to American law enforcement.

The accusations appear to reflect an increasingly aggressive campaign by Chinese government hackers and a pronounced shift in its spy agency's tactics by reaching beyond its own ranks to recruit from a vast pool of private-sector talent.

This new group of hackers has made China's state cyberspying machine stronger, more sophisticated, and more dangerously unpredictable. Sponsored but not necessarily micromanaged by Beijing, this new breed of hacker attacks government targets and private companies alike, mixing traditional espionage with outright fraud and other crimes for profit.....

Cyberhacking tactics have changed since China transferred responsibilities to the Ministry of State Security. ... 

From The New York Times 

View Full Article – May Require Paid Registration

Tuesday, August 03, 2021

Reprogrammable Satellite Launched, is it Hackable?

Had know about this for a while.  'Reprogrammable' Satellite the European Space Agency said.   I also saw a number of the big time security wags were quick to call it 'Hackable'.    Is it?    Have they proven that or is this in the sense that anything is hackable?  The Hubble Space Telescope was just successfully reprogrammed to make it work again.   Was that a 'hack', or just a successful update of the code?  I personally like to say it had the permission of the original designers.  Could have been planned, but not necessarily so.   Can be 'completely repurposed'  they say, but I would guess they are using much of the telecom code. Its not all a hack as they say.  So lets not give the hackers the whole definition, they don't deserve it. 

Reprogrammable satellite launched

ESA / Applications / Telecommunications & Integrated Applications  in ESA

A sophisticated telecommunications satellite that can be completely repurposed while in space has launched.

Developed under an ESA Partnership Project with satellite operator Eutelsat and prime manufacturer Airbus, Eutelsat Quantum has pioneered a new generation of satellites with the European space industry.

The flexible software-defined satellite – which will be used by governments and in mobility and data markets – was launched on board an Ariane 5 on 30 July from Europe’s Spaceport in French Guiana.

It has since reached geostationary orbit some 36 000 km above Earth, where the spacecraft systems checkout was successfully completed.

Because the satellite can be reprogrammed in orbit, it can respond to changing demands during its lifetime.

Its beams can be redirected to move in almost real time to provide information to passengers on board moving ships, planes, trucks, lorries and other land-based transport. The beams also can be easily adjusted to deliver more data when demand surges.

The satellite can detect and characterize any rogue emissions, enabling it to respond dynamically to accidental interference or intentional jamming.

The satellite will remain in geostationary orbit for its 15-year lifespan, after which it will be safely placed in a graveyard orbit away from Earth to avoid becoming a risk to other satellites.

Eutelsat Quantum is a UK flagship project with most of the satellite developed and manufactured by British industry. Airbus is the prime contractor and was responsible for building the satellite’s innovative payload, while Surrey Satellite Technology Ltd manufactured the new platform. The innovative phase array antenna was developed by Airbus in Spain.  ... ' 

Sunday, March 14, 2021

Cameras Hacked

More events and threats to doing business emerging.  Note the links to key infrastructure providers. 

Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals  By Bloomberg   March 10, 2021

A group of hackers say they breached a massive trove of security-camera data collected by Silicon Valley startup Verkada Inc., gaining access to live feeds of 150,000 surveillance cameras inside hospitals, companies, police departments, prisons, and schools.

Hackers say they have compromised data from as many as 150,000 surveillance cameras, including footage from electric vehicle company Tesla.

An international hacking collective executed the breach to demonstrate the ease of exposing video surveillance by targeting camera data provided by enterprise security startup Verkada.

In addition to footage from Tesla factories and warehouses, the hackers exposed footage from the offices of software provider Cloudflare, and from hospitals, schools, jails, and police stations.

Tillie Kottmann, one of the hackers claiming credit for the breach, said the collective obtained root access to cameras, enabling them to execute their own code; they exploited a Super Admin account to access the cameras, and found a username and password for an administrator account online.

A Verkada spokesperson said the company has disabled all internal administrator accounts to block unauthorized access.

From Bloomberg