CNN's Cyber Shockwave

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Thorn
    Easy Bake Oven Iron Chef
    • Sep 2002
    • 1819

    #16
    Re: CNN's Cyber Shockwave

    Originally posted by AlxRogan
    If you haven't watched this TED talk by Marcus Ranum, you really should take the time and check it out. http://www.youtube.com/watch?v=o59mQhBiUo4 If you want to really understand why some of the things that are done today, take a gander at his one example of how f'ed up HTTP is as a practice.

    I don't have primary responsibility of SCADA systems at my job, but I am responsible for their security interactions with the rest of the company and can fully support Thorn's and Streaker's comments. In just oil and gas companies, there are systems that easily date back 20-30 years and the latest technology just encapsulates serial communcation over Ethernet. There's just some things you can't "protect" in a conventional sense, where proper practice, process, and isolation are your only tools.
    Very nice. That also explains my intense urge to shoot an FTP server, whenever I come across one.


    Originally posted by happypanda
    Australia has a somewhat more established system than we do when it comes to reporting that stuff to local LE. An individual can report a cyber attack to local LE then (as a similar chain to what you stated) that is logged and reported up to a state authority. That state authority then investigates the attack to see if it is associated with other incidents or if it is a single incident. In the case its associated with identity theft or a series of events the AFP (Australian Federal Police) become involved.

    So there still is not much ability to do the actual investigation at the local level. The process is implemented well throughout the country though.
    In some ways, your comparing apples to oranges. While the criminal justice systems are similar in both countries, based on English Common Law, the US police system has some very basic differences. For example, we do not -and cannot- have a Federal Police because of the states' autonomy. (By the way, many people assume the FBI is a US federal police force, but this is incorrect. The FBI cannot investigate most crimes, unless requested to do so by local law enforcement, and even then they cannot help unless there is some federal law that has been broken. The crimes that the FBI has direct responsibility to investigate is rather limited.)

    Another point that can't be over emphasized is that of population, and that causes a further breakdown in comparison. The US has a population of 300 million. Australia's population is less than one tenth of that: 21 million in July 2009, according to the CIA World Factbook. In the US, the Tri-State/New York City metro area alone has that same population within a 100 mile radius of Manhattan.

    So while there may be some comparison as to how things are done in Australia, the differences between there and the US are significant in many ways, and those heavily influence way that authorities will respond to any emergency or investigation, whether "cyber" or not.
    Last edited by Thorn; February 22, 2010, 20:02. Reason: Typo
    Thorn
    "If you can't be a good example, then you'll just have to be a horrible warning." - Catherine Aird

    Comment

    • b0n3z
      Goon
      • Mar 2009
      • 137

      #17
      Re: CNN's Cyber Shockwave

      To go back to what was being talked about in the first couple posts (military going on the offensive) the army is actually starting to work their way into this also. They are suppose to be opening a new MOS (job) somewhere along the lines of "Army Hacker" that, from what I understand, will be offensively as well as defensively capable. Granted I doubt any of ya'll will be directly teaching them, nor will the people who actually teach them most likely be 10% competent or know ANYTHING about hacking other than having a bs Hacker Cert of some sort. (Sorry I vent sometimes because the army really is this dumb)

      As for the military infastructure, I could rip that entire topic a new a$$hole to put it in the NICEST of terms....literally. But I'll leave it up to you to debate it but I know for a fact that it is not secure in the highest levels of our security. Especially since some people like to monitor networks for half a year and THEN the network guys who are suppose to catch it realize after X Months.....

      /cough
      Saving the world one computer at a time...

      or possibly destroying, I haven't figured that out yet.

      Comment

      • AgentDarkApple
        Public Security Section 9
        • Aug 2009
        • 224

        #18
        Re: CNN's Cyber Shockwave

        Originally posted by b0n3z
        TThey are suppose to be opening a new MOS (job) somewhere along the lines of "Army Hacker" that, from what I understand, will be offensively as well as defensively capable.
        Do you know if they are likely to have any civilian counterparts? My husband is in the Army but is doing something else and isn't really a computer guy. However, I would like a job on a base doing something similar to what you described.
        "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

        Comment

        • streaker69
          • Mar 2008
          • 1141

          #19
          Re: CNN's Cyber Shockwave

          Originally posted by AgentDarkApple
          Do you know if they are likely to have any civilian counterparts? My husband is in the Army but is doing something else and isn't really a computer guy. However, I would like a job on a base doing something similar to what you described.
          You could always enlist.
          A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.

          Comment

          • AgentDarkApple
            Public Security Section 9
            • Aug 2009
            • 224

            #20
            Re: CNN's Cyber Shockwave

            Originally posted by streaker69
            You could always enlist.
            Lol they don't want me - I'm anemic and have allergies, ADHD, and solar urticaria. Not to mention my disdain for that level of order and formality. Me and "yes, sir" would not get along. Props to those who do (or did) serve though.
            "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

            Comment

            • streaker69
              • Mar 2008
              • 1141

              #21
              Re: CNN's Cyber Shockwave

              Originally posted by AgentDarkApple
              Lol they don't want me - I'm anemic and have allergies, ADHD, and solar urticaria. Not to mention my disdain for that level of order and formality. Me and "yes, sir" would not get along. Props to those who do (or did) serve though.
              Then you probably wouldn't want to work there as a civilian, since chances are, the area you'd go into you'd have to deal with the authority issues.
              A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.

              Comment

              • happypanda
                Member
                • Nov 2009
                • 18

                #22
                Re: CNN's Cyber Shockwave

                Originally posted by b0n3z
                To go back to what was being talked about in the first couple posts (military going on the offensive) the army is actually starting to work their way into this also. They are suppose to be opening a new MOS (job) somewhere along the lines of "Army Hacker" that, from what I understand, will be offensively as well as defensively capable. Granted I doubt any of ya'll will be directly teaching them, nor will the people who actually teach them most likely be 10% competent or know ANYTHING about hacking other than having a bs Hacker Cert of some sort. (Sorry I vent sometimes because the army really is this dumb)

                As for the military infastructure, I could rip that entire topic a new a$$hole to put it in the NICEST of terms....literally. But I'll leave it up to you to debate it but I know for a fact that it is not secure in the highest levels of our security. Especially since some people like to monitor networks for half a year and THEN the network guys who are suppose to catch it realize after X Months.....

                /cough
                On the topic I thought this article was pretty cool and worth sharing. I like where this change is bringing things. It will absolutely help the domestic progression with being able to respond to large scale cyber challenges.

                http://www.homeland1.com/Critical-In...od-Watch-level

                Small snipet:

                "...the Federated Model for Cyber Security, allows cyber security defense systems to communicate when attacked and transmit attack information instantly and automatically to defense systems at other institutions. The idea is to strengthen the overall cyber security posture of the federated sites."

                Comment

                • AgentDarkApple
                  Public Security Section 9
                  • Aug 2009
                  • 224

                  #23
                  Re: CNN's Cyber Shockwave

                  Originally posted by streaker69
                  Then you probably wouldn't want to work there as a civilian, since chances are, the area you'd go into you'd have to deal with the authority issues.
                  I would expect high security in any of those areas of course. When authority is for security reasons, I do not generally have an issue with it. I was mainly referring to not being compatible with uniforms, "natural" hair coloring, butt-kissery, people pulling rank, being indoctrinated, PT, communal restrooms, standing at attention, being yelled at, etc. Some of the stuff I have seen my husband (and others) put up with is certainly not my cup of tea.
                  "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

                  Comment

                  • erehwon
                    nowhere
                    • Dec 2001
                    • 425

                    #24
                    Re: CNN's Cyber Shockwave

                    Originally posted by AgentDarkApple
                    I did not get to see the CNN special because I do not have cable/satellite. Does anyone know if it will be on their site or if it has made its way to YouTube?
                    You didn't miss much, but the whole CNN's Simulated Cyber Attack War Game "We Were Warned" Cyber.Shockwave - 2/20/10 is on YouTube now.

                    The transcript is here.

                    Interesting take away from Michael Chertoff who was the National Security Adviser for the exercise...

                    "I'm going to have to go up and see the president in about a quarter of an hour, in 20 minutes or so. So I'd like to frame, kind of a summary of where we have been in talking about the issues we have discussed today, both the original cyberattack and the following attack with respect to power.

                    I'd like to once again get everybody's best view on what is the short-term fix, but then I would also like to look at what do we tell the American people about why this is not going to happen again, or are we going to have to tell them, this is going to happen all the time, get used to living in a country where you are constantly unable to communicate and unable to turn your electric lights on.

                    So this is one of those moments before you walk into the Oval Office where you are going to have to be willing to tell the president this is a course of action that is bold but may get you in trouble after the fact is overreaching, or you may want me to go in and say to the president, look, here is what you've got to do to not get overreacting, and it may mean that we are going to have to muddle along for awhile, but in the long run you'll be able to say, look, I didn't touch on anything that civil liberties concern. So I asked you to explicitly address those issues as you talk about the way forward on these problems.
                    "

                    I'm worried anything Chertoff recommends to the President may not have the best interests of the nation in mind, except for Chertoff's bank balance.
                    Nonnumquam cupido magnas partes Interretis vincendi me corripit

                    Comment

                    • happypanda
                      Member
                      • Nov 2009
                      • 18

                      #25
                      Re: CNN's Cyber Shockwave

                      Originally posted by AlxRogan
                      If you haven't watched this TED talk by Marcus Ranum, you really should take the time and check it out. http://www.youtube.com/watch?v=o59mQhBiUo4 If you want to really understand why some of the things that are done today, take a gander at his one example of how f'ed up HTTP is as a practice.

                      I don't have primary responsibility of SCADA systems at my job, but I am responsible for their security interactions with the rest of the company and can fully support Thorn's and Streaker's comments. In just oil and gas companies, there are systems that easily date back 20-30 years and the latest technology just encapsulates serial communcation over Ethernet. There's just some things you can't "protect" in a conventional sense, where proper practice, process, and isolation are your only tools.
                      Thank you very much for posting that video link. I was able to get a lot of good info out of it that I was previously not aware of. I would suggest this video to anyone that wants to know a bit more about the fundamentals behind much of our internet communication techniques.

                      Comment

                      • AgentDarkApple
                        Public Security Section 9
                        • Aug 2009
                        • 224

                        #26
                        Re: CNN's Cyber Shockwave

                        Originally posted by erehwon
                        You didn't miss much, but the whole CNN's Simulated Cyber Attack War Game "We Were Warned" Cyber.Shockwave - 2/20/10 is on YouTube now.

                        The transcript is here.
                        Thanks! Hopefully I can catch up on everything and check it out later this week. I just moved recently and had to use coffee shop wireless for almost two weeks. I should be getting my own connection tomorrow...finally.
                        "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

                        Comment

                        • streaker69
                          • Mar 2008
                          • 1141

                          #27
                          Re: CNN's Cyber Shockwave

                          Originally posted by AgentDarkApple
                          Thanks! Hopefully I can catch up on everything and check it out later this week. I just moved recently and had to use coffee shop wireless for almost two weeks. I should be getting my own connection tomorrow...finally.
                          Did ya have a tough time aligning the cantenna to get best signal from the coffee shop?
                          A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.

                          Comment

                          • AgentDarkApple
                            Public Security Section 9
                            • Aug 2009
                            • 224

                            #28
                            Re: CNN's Cyber Shockwave

                            Originally posted by streaker69
                            Did ya have a tough time aligning the cantenna to get best signal from the coffee shop?
                            Lol no, I live in the basement of a loft building, so that sort of thing does not work well here. At least I live within walking distance and the place has good coffee.
                            "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

                            Comment

                            Working...