Friday, December 19, 2014

Movie Magic USB hacking tool really exists

usbTech Crunch brings us a cool USB hacking tool here

As they describe it, the star hax0r of the movie is left alone with a computer, they pull out a necklace, plug it into the computer, it takes it over and sets up a reverse shell.

Unfortunately it only works on a Mac, ( how is this possible!  just kidding ) but other versions are coming soon

Friday, December 12, 2014

Washington Post Article on Sony hack - also the "Don't spend $10 Million to protect $1 Million" quote IS Director


Why it’s so hard to calculate the cost of the Sony Pictures hack
The cyberattack on Sony Pictures went far beyond the typical corporate hack -- with attackers allegedly leaking huge amounts of data, including personal information about employees and internal company strategy information. The malware reportedly used in the attack also damaged the underlying systems at the company, making recovery much more difficult than other types of corporate cyberespionage.

"These attacks are pretty devastating," said Kurt Baumgartner, principal for security research at Kaspersky Lab. The investigation into the situation could run on for months, and the cleanup will likely cost millions "if not tens of millions," he said.
...
Jason Spaltro, then executive director of information security at Sony Pictures, called it a "valid business decision to accept the risk of a security breach"  in a 2007 interview with CIO Magazine, adding he would not invest "$10 million to avoid a possible $1 million loss."

http://www.washingtonpost.com/blogs/the-switch/wp/2014/12/05/why-its-so-hard-to-calculate-the-cost-of-the-sony-pictures-hack/

OK, look at it this way:
  • 2007:  Sony would not invest "$10 million to avoid a possible $1 million loss." 
    • Also 2007 TJ Maxx,  reported over $250 million
  •  2011, Sony's PlayStation Network an estimated $170 million
  • 2011: RSA $66 Million
  • 2013: Target  $400 million
  • 2014: Sony ???
Also 2014:
 Fusion [ when did Kash Hill leave Forbes? Halloween - Oh I was London]  reports that documents leaked after the recent attack show the company had just 11 people assigned to its information security team: "Three information security analysts are overseen by three managers, three directors, one executive director and one senior-vice president." (Sony Pictures did not respond to requests for comment for this story.)
 BTW - According to Wikipedia, Sony Pictures Entertainment revenue for as of March 2014 was $8.0B

Thursday, December 11, 2014

*Updated* Google News in Spain goes Dark

Update: Gizmodo agrees -  http://gizmodo.com/a-big-round-of-applause-to-google-for-shaming-spain-wor-1669840971

In a new take on "planned outage", Google has turned off Google News in Spain over a ridiculous tax for the snippets their search engine displays.

Techdirt calls it the "Nuclear Option", I call it "Well, Duh".

I was kinda hoping they'd do it in Germany or the EU (OMG what a crock!)

I say Go Go Google!

EFF has an important writeup in their blog too - can't resist this quote:
 Online intermediaries may be a convenient scapegoat for the fading fortunes of European newspaper publishers, but banning the use of text snippets alongside website links is a misguided and—now self-evidently
—counter-productive approach. Once it becomes illegal for aggregators to freely link news summaries to publicly-available websites, it becomes that much easier for those who want to prohibit other sorts of links, such as links to political YouTube videos, to make their case.
This will be fun to watch when the news websites in Spain Lose All Their Traffic

It won't shut down until Dec 16, think there will be furious backpedaling at the Spanish news sites?

Hint to Spanish sites:  Look for referer tag in your logs to see how much money you'll lose.


Tuesday, December 9, 2014

Viewing or using Sony stolen documents? Wrong Wrong Wrong

And I'm not gonna do it.  Period.

And there's always a BUT.

Remember:

1. The rootkit on the audio CD?
2. The promise to run Linux on the PS3?
3. All the Harrassment for Geohot?

the list goes on

Sony is not a friend of their community.  Is this karma?

The idiots that are threatening the families are going to get caught, and they're going to do time. BTW. duh?


Friday, December 5, 2014

Australia News (ABC) reports 77 Chinese arrested in Kenya accused of Cybercrime network attacking Banking and telecom system.

http://www.abc.net.au/news/2014-12-05/dozens-of-chinese-held-in-kenya-in-cyber-bust/5945610

Other interesting tidbits
  1. Running mysterious "command centre" from upmarket houses in the capital Nairobi
  2. "preparing to raid the country's communication systems".
  3. equipment capable of infiltrating bank accounts, Kenya's M-Pesa mobile banking system and ATMs.
  4. "being in the country illegally and operating radio equipment" without the necessary permits.
  5. "military-style dormitories".
  6. "China promised to send investigators to work with ours on this matter," 
  7. the group were making microchips for ATM cards 
Maybe most interesting of all:
China, a major investor in Kenya's infrastructure and communications networks and hailed earlier this year by president Uhuru Kenyatta as "an honourable partner" for east Africa's largest economy