Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

What Is The Marianas Web?

 

The surface is what we think of as “the internet”: the indexed, publicly available portions of the web that you can Google.

The first layer of the “deep web” is those pages on “the internet” that are for a variety of reasons unlisted or restricted-access, rendering them inaccessible to most: members-only, password-protected content, pages that haven’t yet been indexed, new pages, and pages that aren’t indexed because of DMCA complaints (those in particular can be accessed with a little bit of boolean ingenuity that I’ll not go into here).

The second layer consists of the sleazy, clandestine, contraband-type stuff that most people think of when they think of the “deep web”, and it trafficks itself  through anonymizing software (Tor, e.g.), .onion links, and p2p/p2m networks. This is what most people think of when they think of the “Deep web”. It is difficult to access, is creepy, and is therefore notorious. It consists primarily of pirated software and movies, drugs, guns, gambling, offers of contract murder, and illicit pornography. Avoid it. As a wise man once said, “nothing good happens in that part of town after midnight”.

The third and fourth layers are where you see the bulk of the traffic, and is where the truly interesting stuff lives. Most information on these layers of the “deep web” is hidden primarily because it is proprietary or classified. The bulk of deep traffic is on alternate and private networks (that is to say, corporate and government traffic). Layer three consists of classified information trafficked on alternative networks such as JWICS, SIPRNet, and NSANet. The fourth layer is internal corporate traffic hosted on private PANs, WANs and LANs, inaccessible unless you’re already inside or that network is otherwise connected to the “internet” (the indexed, “googleable” surface web that we use every day).

If you consider the way he defines the third and fourth layers then that’s pretty much everything that could be on what one would reasonably term a ‘web’ and so, excludes individual disconnected devices.
There really can’t be anything below Deep Web (though I would happily stand corrected if need be), because it’s just not possible. There’s no seabed to the Deep Web, sure, but I feel like the existing clearly-defined layers are mutually exclusive and comprehensively exhaustive:
  • Layer 1: Internet-facing, Listed, Can be accessed by various non-obvious methods
  • Layer 2: Internet-facing, Unlisted, Can be accessed by obvious and non-obvious methods (primarily through enforced anonymity)
  • Layer 3: Large(/internet)-scale network but not Internet-facing, Unlisted, Can be accessed only through security flaws or direct access (e.g. via a networked device that is also Internet-facing or through physical access to networked devices or infrastructure)
  • Layer 4: Smaller-scale networks and not Internet-facing, Unlisted, Can be accessed only through security flaws (as above)

Can you keep Linux-based ransomware from attacking your servers?

 

According to SophosLabs, Linux/Ransm-C ransomware is one example of the new Linux-based ransomware attacks, which in this case is built into a small command line program and designed to help crooks extort money through Linux servers.

“These Linux ransomware attacks are moving away from targeting end users and gravitating toward targeting Linux servers, web servers specifically, with a piece of software that encrypts data and is similar to what we’ve seen in previous years such as CryptoWall, CryptoLocker, and their variants,” explains Bill Swearingen, director of Cyber Defense, CenturyLink.

As long as attackers can leverage the ease of coding strong encryption and the high availability of anonymous currencies and anonymous hosting, ransomware is here to stay, says Swearingen. With security organizations like SophosLabs seeing and tracking new variants of Linux ransomware, enterprises should make themselves aware of its risks and cures, since as server owners, users, or operators they are prime targets.

Typical target trip ups

With the amount of open-source software in use on Linux web servers, it is very easy for attackers to take advantage of these CMS systems such as WordPress, Drupal, and Joomla with their many unpatched vulnerabilities and exploit them, insinuating these Linux encoders / ransomware and holding enterprise web servers and their data in exchange for some form of booty, says Swearingen. 

Though the first rounds of Linux ransomware have been poorly coded, according to Swearingen, coming rounds will be increasingly more effective. As attackers are writing the next wave of Linux encoders, enterprises need to prepare to withstand their effort.

One obvious answer to Linux malware is to keep those CMS products and the web servers continually patched and updated. But patching produces its own challenges. Even Linux web servers have many layers that the enterprise needs to patch, says Swearingen, including the OS layer, the application layer, and the database layer. "Traditionally companies focus on the operating system layer, running vulnerability scanners. But it’s the applications that the attackers are targeting,” says Swearingen. The enterprise needs to expend effort to uncover and patch holes at all levels. That comes with additional investments in time and money.

Immediate patching is often impractical since patches may be flawed, creating their own issues. Enterprises should thoroughly test new patches before installation to production environments. Proper testing also comes at the sacrifice of time, effort, and additional finances. Enterprises have thresholds where they can begin to afford testing and below that, many cannot justify the expense. 

Even patches that generally function properly may negatively affect certain adjacent applications and software dependencies with conflicts and lack of interoperability so that these CMS and other Linux web server products experience faults or stop working altogether. Ultimately, the enterprise will have to weigh the risks and costs of patching as they approach patching solutions.
Beware: if the same vulnerabilities remain unpatched for years, this is what most attackers are targeting. “Attackers are utilizing well known, well documented vulnerabilities in externally facing applications,” says Swearingen. You must patch eventually, or expect to become a statistic.

Secure development

The best place to secure web applications is at the start, in development. When developers follow coding standards that address the riskiest vulnerabilities that an application can have, they greatly mitigate the potential for successful attacks. “In any custom application, ensure that your developers are referencing the OWASP Top Ten,” says Swearingen.

The OWASP Top Ten application security risks include injection flaws, poorly implemented authentication, cross-site scripting flaws, direct object references, insecure configurations, sensitive data, PII exposure, missing function level access controls, cross-site request forgeries, known-vulnerable components, and unvalidated redirects. In each case, the security hole permits an attacker to insert or access data or components, leading to a broader compromise.

By checking and closing each vulnerability as they create an app, developers can deal the greatest blow to attacks before the app even sees the light of day.

Vulnerability monitoring

As with the OS, there are vulnerability scanners tailored to CMS and web applications. “If you’re running a Word Press site, there is an application called WPScan that can test it,” says Swearingen. HackerTarget makes multiple web and CMS scanners available. OWASP has a WordPress scanner. There are also scanners that can check the source code.

Of course, once you find a vulnerability you will have to either patch it or find some other solution such as a WAF to secure around it.

“You’ll want to implement security best practices including a backup strategy that you can test and confirm works to restore the system in the event that an attacker does encrypt it and hold it for ransom,” says Swearingen. If someone else has provided the server and the enterprise is in charge of the application layer, you should backup the application and perhaps the database, depending on your circumstance, he explains.

To ensure that backups as an approach in general will really counter a Linux ransomware attack, keep the backups on a different system at a different location with different credentials, so that a compromise of the server is not automatically also a compromise of the backups. “Whether you are using server snapshots for backups, make sure the backup system is not mounted from the original server that is subject to compromise,” says Swearingen.

Security practices

Security best practices will lead the enterprise to segment web servers from any externally exposed server and from other networks, and to use highly restrictive access controls, says Swearingen. You should always use all applicable layers of defense that are available to you.

Additional security practices including running certain apps in containers to isolate them from the rest of your systems, says Ben Johnson, chief security strategist, Bit9+Carbon Black. “An app or web server in one container can’t leave it to attack an app in a different container. Even if an attack landed in one container, it wouldn’t get back out to attack something else,” says Johnson.

There are well-known forms of controls that help, too. “Use whitelisting to approve apps that can run on your web server and block everything else,” says Johnson. Hardening systems including closing unused ports goes hand in hand with application blocking.


Experts Warn It Just Takes 10 Seconds To Hack Fitbit Fitness Trackers:

 



Wearables may be a hacker's dream and Fitbit trackers could be the jackpot, according to security researchers who revealed a 10-second hack, but Fitbit disputes such claims.
As wearable devices are increasingly gaining momentum, people store more data on their smartwatches, fitness trackers and other such gadgets. Whenever there's data stored, there are also hackers lurking in the shadows and wearables are a new category capable of carrying malware.

Fortinet security researcher Axelle Apvrille recently detailed how a Fitbit tracker is vulnerable to hacking through its Bluetooth radio, presenting the security breach at the Hack.Lu 2015 conference.
Aprville managed not only to manipulate data stored on the tracker, such as the logged fitness data, but took the hack to the next level and used the Fitbit to distribute code to a computer. If a malicious hacker exploited that vulnerability, that code transmitted to a computer could very well be malware.

Aprville was able to infect the Fitbit Flex tracker in just 10 seconds from as much as 15 feet away, given the gadget's Bluetooth range. Malicious software could pack some code designed to slip a Trojan on a computer, or open a backdoor, when the Fitbit connects to the device for data synchronization.
The security researcher published some slides to show a few hacks, after demonstrating the more severe vulnerability at Hack.Lu.

Nevertheless, this doesn't mean that just anyone could hack a Fitbit tracker to manipulate the data stored on it or to push malicious code to a computer. Vulnerabilities reported by security researchers do not mean such attacks actually occur in the wild, and Apvrille tried to clarify this in a series of tweets following the presentation.

"To complete the scenario you'd need to execute the malicious code on the victim's host. This is yet to do (requires an exploit?)" explains one of the tweets.
In other words, this vulnerability could lead to malicious code being pushed to computers, but this is not the case just yet. For now, it's just a proof-of-concept that it's not that hard to inject code into wearables. It remains unclear for now whether the Flex is the only Fitbit tracker affected by this 10-second hack.
Fitbit, for its part, denied such allegations and argues its devices cannot serve as vehicles for infecting users with malware.

"As the market leader in connected health and fitness, Fitbit is focused on protecting consumer privacy and keeping data safe. We believe that security issues reported today are false, and that Fitbit devices can't be used to infect users with malware. We will continue to monitor this issue," Fitbit said in a statement to Engadget.

Bots and Botnets—A Growing Threat

 


A botnet (also known as a zombie army) is a number of Internet computers that, although their owners are unaware of it, have been set up to forward transmissions (including spam or viruses) to other computers on the Internet. Any such computer is referred to as a zombie - in effect, a computer "robot" or "bot" that serves the wishes of some master spam or virus originator. Most computers compromised in this way are home-based. According to a report from Russian-based Kaspersky Labs, botnets -- not spam, viruses, or worms -- currently pose the biggest threat to the Internet. A report from Symantec came to a similar conclusion.

Computers that are coopted to serve in a zombie army are often those whose owners fail to provide effective firewalls and other safeguards. An increasing number of home users have high speed connections for computers that may be inadequately protected. A zombie or bot is often created through an Internet port that has been left open and through which a small Trojan horse program can be left for future activation. At a certain time, the zombie army "controller" can unleash the effects of the army by sending a single command, possibly from an Internet Relay Channel (IRC) site.

The computers that form a botnet can be programmed to redirect transmissions to a specific computer, such as a Web site that can be closed down by having to handle too much traffic - a distributed denial-of-service (DDoS) attack - or, in the case of spam distribution, to many computers. The motivation for a zombie master who creates a DDoS attack may be to cripple a competitor. The motivation for a zombie master sending spam is in the money to be made. Both of them rely on unprotected computers that can be turned into zombies.

Ways to Combat Botnets, the Invisible Threat.

  1. Install a Windows Firewall. Though sometimes tempting for end users to disable, a properly configured Windows firewall can block many network-based exploits. This measure is especially appropriate for large agencies with many similarly configured machines.


  2. Disable AutoRun. The autorun feature, which automatically installs software, should be disabled to prevent operating systems from blindly launching commands from foreign sources.


  3. Break Password Trusts. Judicious control over local accounts, especially the local administrator account, is critical to isolating and eliminating threats. Disabling computers’ capability to automatically connect to each other closes the path that botnets take to spread to the internal network. This is particularly critical in environments where machines store highly confidential data.


  4. Consider Network Compartmentalization. In most computing environments, workstations do not need to communicate with each other across departments. Shutting down this capability goes a long way toward preventing the spread of botnets. IT managers should establish private virtual local area networks (VLANs), or access control lists (ACLs) between subnetworks to limit exposure. This strategy is not a good fit, however, in environments that mix voice and data communications, as it tends to break the ability to negotiate virtual circuits on the fly.


  5. Provide Least Privilege. When users are not administrators of their own workstations, it is much harder for malware to propagate via drive-by download or for AutoRun methods to take hold on a system. Preventing users from being administrators also makes it more difficult for their user account credentials to spread malware, should the computer become infected.


  6. Install Host-Based Intrusion Prevention To keep botnets from taking root in a system, IT managers should concentrate additional protections on specific network layers based on vulnerability, such as at points of contact between specific hardware and software. This approach does not fix technical flaws or holes in operating systems or application software, but it can reduce the chances that exploits will be successful. These tools are highly effective, but they are expensive and challenging to deploy.


  7. Enhance Monitoring The more that is known about how end users and the network operate in normal activity, the easier it will be to determine in real-time when a botnet infestation causes slight anomalies. Around-the clock monitoring is ideal, using products that collect data on network traffic, train devices to monitor abnormalities, and detect and prevent intrusions. However, even with remote managed security services filling the gap, enhanced monitoring might be beyond the capabilities of many government agencies.


  8. Filter Data Leaving the Network. Botnets typically establish communication with one or more remote servers that hackers use to retrieve private information. To stop these communications, and the threats associated with them, agencies can prohibit unwanted traffic from leaving the network, a tool known as egress filtering. Agencies should force Internet traffic through proxies or content filters (see below), or deploy a data loss prevention (DLP) solution.


  9. Use a Proxy Server. While it is impractical to block all potentially hostile outbound traffic, forcing outbound traffic through a proxy server gives agencies a secondary choke point for monitoring and controlling Web access and for defeating some attempts to tunnel around security measures. Content filtering is appropriate for almost any agency.


  10. Install Reputation-Based Filtering. Tools like IronPort and WebSense can help block e-mail from, and requests to, addresses that have reputations as potential malware sources.


  11. Monitor DNS Queries The way that a workstation responds to domain name system (DNS) queries is often an early warning sign that the workstation may be infected. Specifically, responses from workstations that contain very low time-to-live (TTL) values should be monitored, as low TTL can indicate infection. Monitoring allows system administrators to act before the infection spreads too far
The steps outlined here provide a framework for a cybersecurity strategy tailored to an agency’s specific size, as well as the size of its IT department and budget. CDW-G advises agencies to evaluate each step to devise a strategy that meets their specific needs.

The Secret Web: Where Drugs, Porn and illegal activities take place.

 


Technically the Deep Web refers to the collection of all the websites and databases that search engines like Google don’t or can’t index, which in terms of the sheer volume of information is many times larger than the Web as we know it. But more loosely, the Deep Web is a specific branch of the Internet that’s distinguished by that increasingly rare commodity: complete anonymity. Nothing you do on the Deep Web can be associated with your real-world identity, unless you choose it to be. Most people never see it, though the software you need to access it is free and takes less than three minutes to download and install. If there’s a part of the grid that can be considered off the grid, it’s the Deep Web.

The Deep Web has plenty of valid reasons for existing. It’s a vital tool for intelligence agents, law enforcement, political dissidents and anybody who needs or wants to conduct their online affairs in private–which is, increasingly, everybody. According to a survey published in September by the Pew Internet & American Life Project, 86% of Internet users have attempted to delete or conceal their digital history, and 55% have tried to avoid being observed online by specific parties like their employers or the government.

But the Deep Web is also an ideal venue for doing things that are unlawful, especially when it’s combined, as in the case of Silk Road, with the anonymous, virtually untraceable electronic currency Bitcoin. “It allows all sorts of criminals who, in bygone eras, had to find open-air drug markets or an alley somewhere to engage in bad activity to do it openly,” argues Preet Bharara, U.S. attorney for the Southern District of New York, whose office is bringing a case against Ulbricht and who spoke exclusively to TIME. For 2½ years Silk Road acted as an Amazon-like clearinghouse for illegal goods, providing almost a million customers worldwide with $1.2 billion worth of contraband, according to the 39-page federal complaint against Ulbricht. The Dread Pirate Roberts, the Deep Web’s Jeff Bezos, allegedly collected some $80 million in fees.

Most people who use the Deep Web aren’t criminals. But some prosecutors and government agencies think that Silk Road was just the thin edge of the wedge and that the Deep Web is a potential nightmare, an electronic haven for thieves, child pornographers, human traffickers, forgers, assassins and peddlers of state secrets and loose nukes. The FBI, the DEA, the ATF and the NSA, to name a few, are spending tens of millions of dollars trying to figure out how to crack it. Which is ironic, since it’s the U.S. military that built the Deep Web in the first place.

TOR DE FORCE
The story of the Deep Web is a fable of technology and its unintended consequences. In May 1996, three scientists with the U.S. Naval Research Laboratory presented a paper titled “Hiding Routing Information” at a workshop in Cambridge, England. It laid out the technical features of a system whereby users could access the Internet without divulging their identities to any Web servers or routers they might interact with along the way. They called their idea “onion routing” because of the layers of encryption that surround and obscure the data being passed back and forth. By October 2003, the idea was ready to be released onto the Net as an open-source project called Tor (which originally stood for The Onion Router, though the acronym has since been abandoned). If the Deep Web is a masked ball, Tor provides the costumes. It was a highly elegant and effective creation, so much so that even the people who built it didn’t know how to break it.

In many ways Tor was less a step forward than a return to an earlier era. For much of the Internet’s history, a user’s online persona was linked only loosely, if at all, to his or her real-world identity. The Internet was a place where people could create new, more fluid selves, beginning with a handle or pseudonym. Through much of the 1990s, the Web promised people a second life. But over time–and in particular with the arrival of Facebook–our lives online have been tightly tethered to our off-line selves, including our real names. Now everywhere we go, we radiate information about ourselves–our browsing history, our purchases, our taste in videos, our social connections, often even our physical location. Everywhere but the Deep Web.

Why would the U.S. government fund the creation of such a system? Lots of reasons. The police could use it to solicit anonymous tips online, set up sting operations and explore illegal websites without tipping off their owners. Military and intelligence agencies could use it for covert communications. The State Department could train foreign dissidents to use it. Tor is currently administered by a nonprofit organization based in Cambridge, Mass., and sponsored by a diverse array of organizations including Google and the Knight Foundation. But as recently as 2011, 60% of its funding still came from the U.S. government.

The corruption of the Deep Web began not long after it was built. As early as 2006, a website that came to be known as The Farmer’s Market was selling everything from marijuana to ketamine. It built up a clientele in 50 states and 34 countries before a DEA-led team brought it down in April 2012. The Deep Web isn’t just a source for drugs: there is evidence that jihadists communicate through it and that botnets–massive networks of virus-infected computers employed by spammers–use it to hide from investigators. Even now, it’s the work of a minute or two to find weapons or child pornography on the Deep Web. In August, the FBI took down Freedom Hosting, a company specializing in Deep Web sites, alleging that it was “the largest facilitator of child porn on the planet.” Its owner, a 28-year-old named Eric Marques, is facing extradition from Ireland.
But Silk Road was different. For one thing, it was more discriminating: its terms of service forbade child pornography, stolen goods and counterfeit currency. For another, it didn’t use dollars; it used bitcoins.

When Bitcoin appeared in 2009 it was a radically new kind of currency. It was introduced as a kind of fiscal thought experiment by someone known only as Satoshi Nakamoto, whose true identity is still a mystery. Bitcoin is both a payment system and a currency that is purely digital–it has no physical form. A bitcoin’s worth is determined by supply and demand and is valuable only insofar as individuals and companies have agreed to trade it.

Bitcoins belong to an era in which trust in banks and government has been compromised. Users can transfer them from one digital wallet to another without banks brokering the transaction or imposing fees. The currency is completely decentralized–its architecture owes a lot to Napster’s successor, BitTorrent–and is based on sophisticated cryptography. Bitcoin is essentially cash for the Internet, virtually anonymous and extremely difficult to counterfeit. The Farmer’s Market was vulnerable because it left financial tracks in the real world. Silk Road didn’t.

Like Tor, Bitcoin has entirely legitimate reasons for existing. As far as anyone can tell, it’s primarily used for legal purposes–scores of businesses accept bitcoins now, including Howard Johnson, the dating website OKCupid and at least one New York City bar. But Bitcoin’s digital slipperiness, when force-multiplied by the anonymity of the Deep Web, creates a potential platform for criminal transactions unlike anything the real or virtual world has ever seen. That potential was realized by the Dread Pirate Roberts.

JOHN GALT 2.0
Ross Ulbricht grew up in Texas, an Eagle Scout who went on to study physics at the University of Texas in Dallas. He was a fan of fellow Texan and libertarian Ron Paul; both studied the Austrian school of economics and the work of its father, Ludwig von Mises, who believed in unrestricted markets. Ulbricht earned a master’s in materials science and engineering at Pennsylvania State University. Acquaintances describe him as bright and straitlaced. “He wasn’t the center of conversation or the center of anything,” says a friend who claims to have briefly dated him last year. “He kind of set himself in the background.”

By the time he graduated, Ulbricht had become interested in the idea of the Internet as a venue for perfecting free markets. His greatest enemy–according to his LinkedIn profile–was the government. “The most widespread and systemic use of force is amongst institutions and governments, so this is my current point of effort,” he wrote. “The best way to change a government is to change the minds of the governed, however. To that end, I am creating an economic simulation to give people a firsthand experience of what it would be like to live in a world without the systemic use of force.”
After graduating from Penn State in 2009, Ulbricht went to Sydney, Australia, to visit his sister. It was there, allegedly, that he began working on what would become Silk Road and transforming himself into the Dread Pirate Roberts. By then, drug dealers were already active on the Deep Web, but their businesses tended to fail for two reasons: the money changing hands was traceable, and it was difficult to build trust with clients. Roberts would solve both of those problems. The double layer of anonymity created by Tor and Bitcoin made the money virtually untraceable. To establish trust, Roberts looked to two temples of legitimate commerce for his ideas: Amazon and eBay.

He was a quick study. Users of Silk Road describe a sophisticated, full-featured experience complete with buyer and seller reviews and customer forums. “When deciding whether or not to go with a vendor, I read the feedback on their page and also ratings from a few months ago,” says one Silk Road client, who declined to be identified. “I also go to the forums and read the seller’s review thread, and depending on the substance, I’ll go to an ‘avenger’s’ thread, where people from the Silk Road community post lab results for individual products.” When transactions did go south, there was a dispute-resolution system. “Honestly it was like a candy store,” says the user.

Products simply arrived by regular mail. “It generally looks like junk mail or information about moving here, or traveling there, or consultation stuff,” the user explains. “Usually, when opening the package, you still won’t know there are drugs in it unless you’re looking for them.” Silk Road’s community had its own subculture, which skewed toward political outliers. “One memorable thread asked whether we were there for the drugs or the ‘revolution,'” recalls the same user. “A lot of people answered ‘came for the drugs, stayed for the revolution.'” Dread Pirate Roberts, or simply DPR, was hailed by Silk Road customers as an antiestablishment hero.

Silk Road launched in January 2011. Its existence was hardly kept a secret–with Tor making it possible to get in and out anonymously, why bother? Hiding would just have been bad for business. “It was basically an open thumbing of noses at law enforcement,” Bharara says.

The FBI got its first glimpse of Ross Ulbricht that October. Someone named “altoid” had been promoting Silk Road in various chat rooms; then, in a Bitcoin forum, altoid posted an ad seeking an “IT pro in the bitcoin community” for “a venture-backed bitcoin-startup company,” according to the complaint against Ulbricht. Ulbricht listed his real e-mail address as the contact for the position.
Ulbricht had left more clues for the feds. His Google+ account linked to some of the same sites and videos–including some from the Ludwig von Mises Institute–that the Dread Pirate Roberts mentioned. The FBI obtained records from Google that showed Ulbricht was accessing his Gmail account from San Francisco; the server through which Roberts accessed Silk Road showed an IP address corresponding to a San Francisco café. Ulbricht also posted a request for help with some computer code on a website for programmers, again under his own name. He hastily changed his user ID (to “frosty”), but the damage was done: that same code later turned up as part of the Silk Road site.

From there the thread becomes darker and more tangled. In January 2013, a Silk Road employee apparently stole bitcoins from users, then managed to get arrested on another charge. Roberts, displaying a side investigators hadn’t seen before, allegedly contracted with a Silk Road customer to have the employee tortured until he or she returned the bitcoins, then killed. This was the work not of a libertarian idealist but of a sociopath. Roberts was unaware that the hit man he was dealing with was an undercover FBI agent who had bought drugs on Silk Road as part of a sting operation. The agent sent Roberts faked photographic proof of the murder. Satisfied, Roberts wired $80,000 from an Australian money-transfer exchange.

According to the testimony of FBI agent Christopher Tarbell, who led the investigation, a Silk Road user in Canada began to blackmail Roberts, threatening to leak information about the site’s clientele. Roberts responded by paying someone known online as “redandwhite” the sum of $150,000 in bitcoins to kill the blackmailer. (Roberts received photos of that killing too, but the Canadian police can’t match it to any murder they’re aware of.) In June 2013, Roberts ordered a set of fake IDs from redandwhite. Later that month, U.S. Customs opened a package from Canada containing nine fake IDs bearing Ulbricht’s photo and birth date. The package also gave them Ulbricht’s address.

The net was closing fast. By July, FBI hackers had tracked down one of Silk Road’s servers, in a foreign country whose name has not yet been revealed, which gave them copies of all Roberts’ e-mail plus transaction records dating to the site’s launch. On July 26, agents from Homeland Security knocked on Ulbricht’s door. He admitted that he’d been living under a false name.
The authorities got another break on July 31, when they raided the condo of a Seattle-area dealer who sold meth, coke and heroin through Silk Road under the handle Nod; they quickly flipped him as an informant. On Oct. 1, two years after they first spotted him, federal agents followed Ulbricht to the Glen Park library and arrested him. The FBI says it caught him red-handed with evidence on his laptop screen.

TRUTH AND CONSEQUENCES
Many in Washington are troubled by the fact that it took so much time and effort just to close one illegal website run by a would-be Walter White.

The FBI is policing an ever evolving Internet using static, often outdated laws. The Communications Assistance for Law Enforcement Act, which governs law enforcement’s warrant process and is known as CALEA, was passed in 1994. “We’re coming up next year on its 20th anniversary,” says Marcus Thomas, former assistant director of the FBI’s technology division, who now advises Subsentio, a firm that helps companies comply with CALEA. “It’s in serious need of being updated to keep pace with the current environment.”

Even leaving aside specialized tools like Tor, there are plenty of mainstream technologies that criminals can use to hide their activities: satellite phones, PIN messaging on BlackBerrys and even Apple iMessage, the instant-messaging service on iPhones and iPads. “The DEA got burned in April when it came out that we weren’t able to capture iMessage on a wiretap,” says Diana Summers Dolliver, a professor at the University of Alabama’s department of criminal justice who previously worked at the Drug Enforcement Administration. “So of course all the bad guys went out and got iPhones and encrypted iMessage.”

The FBI isn’t trying to listen in on everything the way the NSA allegedly does; it’s just looking to obtain legal search warrants under CALEA. But even that isn’t as simple as it sounds. “First of all, even if you have an idea that they’re using their computer to ill ends, you can’t seize the computer for evidence,” Dolliver says. “You have to have probable cause. So that’s roadblock No. 1. Then, once you get ahold of their computer, it takes a lot of forensic work to figure out who the perps are.” There are also many companies that have built their businesses specifically on providing their users with privacy and anonymity. Interest groups like the Center for Democracy and Technology argue that making new technologies CALEA-compliant stifles innovation and that building in back doors for law enforcement can make otherwise secure systems vulnerable to hackers.

For years the FBI has been working with other agencies on a proposal to update CALEA, which they finally submitted to the White House in April. The FBI won’t comment on details, but generally speaking, the idea is not to force companies to divulge information, potentially compromising them technologically, but to increase fines on those that choose not to comply. If the arguments are reasonable, the timing is terrible: the Edward Snowden leaks began on June 5 and, almost at once, the idea of making electronic surveillance by the government easier became politically radioactive.
In 2012 the FBI established–jointly with the DEA, the ATF and the U.S. Marshals Service–the National Domestic Communications Assistance Center (NDCAC) in Quantico, Va. The center exists because–to quote from the appropriations bill that funds it–“changes in the volume and complexity of today’s communications services and technologies present new and emerging challenges to law enforcement’s ability to access, intercept, collect, and process wire or electronic communications to which they are lawfully authorized.” In essence, the NDCAC is a tech startup with at least $54 million in funding for the 2013 fiscal year that’s focused on helping law enforcement penetrate areas of the Web that are currently unsearchable.

The FBI isn’t the only agency that’s worried about the Deep Web. The Senate Finance Committee is looking at beefing up the IRS’ funding for dealing with virtual currencies and investigating potential tax shelters, Senate sources say. Bitcoin presents Washington with a whole set of regulatory challenges all on its own. Is Bitcoin a currency? (Under certain definitions, no, because it isn’t legal tender issued by a country.) Is it a commodity? Should bitcoin traders be regulated as banks or wire services?

CRACKDOWN
The incarceration of ross Ulbricht started a spreading wave of arrests of suspected Deep Web dealers. On Oct. 8, police in Sweden arrested two men on charges of selling pot through Silk Road, and four more men were picked up in the U.K. the same day on drug charges. “These arrests send a clear message to criminals,” said Keith Bristow, head of Britain’s National Crime Agency. “The hidden Internet isn’t hidden, and your anonymous activity isn’t anonymous. We know where you are, what you are doing, and we will catch you.”

It’s not completely clear that that’s true. One of the documents leaked by Snowden was an NSA presentation dated June 2012 titled “Tor Stinks.” It described the difficulties the NSA has been having cracking Tor, and it said definitively, “we will never be able to de-anonymize all Tor users all the time.” The Deep Web template that Ulbricht created remains technically sound. As one former Silk Road user puts it, “The dust has settled and everyone is kind of like ‘Oh, well, time to order some more drugs.’ We all knew it was coming.” There are forum posts discussing the possibility of a reconstituted Silk Road, based on a backed-up version of the old site but with added security, that could launch on Nov. 5. “This will be where the action is once it’s up and running,” says the user.
Tor itself is left in the curious position of being funded by some parts of the federal government (including the State Department and the Department of Defense) while others (the FBI and the NSA) are trying to crack it. But even law-enforcement officials directly involved with the case hasten to clarify that they don’t blame the technology itself for Silk Road. “There’s nothing inherently wrong with anonymity on the Internet,” U.S. Attorney Bharara says. “There’s nothing inherently wrong with certain kinds of currency, like bitcoins. Just like there’s nothing inherently wrong with cash. But it happens to be the case that … it’s also the thing that allows the drug trade to flourish. It allows money laundering to happen. It allows murder for hire to happen.”

What’s certain is that the need for Tor–or something like it–isn’t going away. The Internet is becoming an increasingly unprivate place, where multibillion-dollar business plans are being built on companies’ ability to observe and rapaciously harvest every last iota and fillip of consumer behavior. More and more, it falls to consumers themselves to say where the line is and to take control of their personal information.

What makes the Internet, and particularly the Deep Web, so hard to pin down is that it cuts across so many spheres that used to be strictly separate. It’s private and public, personal and professional and political, all at the same time; it has a peculiar way of compressing all the formerly disparate threads of our lives into one single pipeline leading directly into our studies and bedrooms. It’s virtually impossible for the law to tease those strands apart again. Right now we’re trapped unpleasantly between two ideals, the blissful anonymity of the Net as it was first conceived and the well-regulated panopticon it is becoming. It’s the worst of both worlds: the Deep Web provides too much privacy and the rest of the Web not enough.

Ulbricht himself currently has plenty of privacy. He’s spending 20 hours a day alone in a cell in an Alameda County jail near Oakland, Calif. On Oct. 16 he hired a New York lawyer named Joshua Dratel, who has some experience with controversial cases. His past clients include several alleged terrorists. “He’ll be pleading not guilty whenever he’s arraigned on charges,” Dratel told TIME. “He denies the charges right now, and he’ll continue to deny [them],” he said. Perhaps inevitably, 20th Century Fox has already optioned the story of Silk Road from Wired magazine for a feature film.
Meanwhile, Ulbricht fills his days writing letters to friends and family and reading Patrick O’Brian’s Master and Commander. He has no Internet access. He may, however, still have some of his pirate’s treasure. On Oct. 25, Bharara announced that, after a prolonged hacking campaign, investigators had gained access to a cache of 122,000 of the Dread Pirate Roberts’ bitcoins, worth over $24.9 million. But there may be many more millions out there. People may always be fallible and venal, but technology, at least for the time being, can still keep some of our secrets.

Hackers steal personal data of 15 million T-Mobile wireless customers

 



Hackers have stolen personal information belonging to about 15 million T-Mobile wireless customers, including Social Security numbers, home addresses, birthdates and other personal information.

The hackers got the information from credit reporting agency Experian, which T-Mobile uses to check the credit of its customers. Experian said T-Mobile customers who applied for wireless service between Sept. 1, 2013 and Sept. 16, 2015 may have had their information stolen.

Experian said it immediately notified law enforcement authorities after discovering the hack and that "there is no evidence to-date that the data has been used inappropriately."

The companies said that payment card and banking information was not affected.

T-Mobile customers can sign up for two free years of credit monitoring services at www.protectmyID.com/securityincident, a service owned by Experian. The company said that affected customers should "remain vigilant" against identity theft and watch for phishing email scams that ask for sensitive information such as bank account and Social Security numbers.

There have been a string of high-profile hacks of businesses and other organizations in recent years affecting millions of people, including adultery website Ashley Madison, Sony Pictures, the insurer Anthem, retailers such as Home Depot and Target, eBay and the U.S. Office of Personnel Management.

Nearly 800 data breaches were reported last year by U.S. organizations, according to the Identity Theft Resource Center.

"I am incredibly angry about this data breach and we will institute a thorough review of our relationship with Experian," said T-Mobile US Inc. CEO John Legere in a statement.

Gigabytes of user data from hack of Patreon donations site dumped online

 



Hackers have published almost 15 gigabytes' worth of password data, donation records, and source code taken during the recent hack of the Patreon funding website.
The data has been circulating in various online locations and was reposted here by someone who said it wasn't immediately possible to confirm the authenticity of the data. Security researcher Troy Hunt has since downloaded the archive file, inspected its contents, and concluded that they almost certainly came from Patreon servers. He said the amount and type of data posted by the hackers suggest the breach was more extensive and potentially damaging to users than he previously assumed.

"The fact that source code exists ... is interesting [and] suggests much more than just a typical SQL injection attack and points to a broader compromise," he told Ars. Referring to the inclusion of a 13.7-gigabyte database, he added: "At the very least, it means mapping individuals with the Patreon campaigns they supported. There's more data. I'll look closer once the restore is complete."
He said unpacking such a large archive file, sorting through its contents, and loading various MySQL database files takes time. Hunt, who maintains the widely visited have i been pwned? website, said he expected to index affected e-mail addresses on the service as soon as possible.  

Update 1: Hunt has now been able to sift through the data and has found 2.3 million unique e-mail addresses, including his own.
According to Patreon officials, user passwords were cryptographically protected using bcrypt, a hashing function that's extremely slow and computationally demanding to use. Its use was one of the saving graces of the breach, since it meant crackers would have to devote vast amounts of time and resources to crack the hashes. With the inclusion of source code, however, it's possible crackers may find programming mistakes that could significantly accelerate the process. That's precisely what crackers did last month to bcrypt-hashed password data taken during the hack of the cheaters dating website Ashley Madison. Access to the source code may also expose the encryption key said to protect social security numbers and tax IDs.

Hunt isn't the only one to view the contents. Several people have posted screenshots of the purported Patreon data on social media sites, including the image included at the top of this post. If authentic, some of the contents were generated on Patreon servers as recently as September 24. As this Ars post was being prepared, a variety of Patreon subscribers, including this one, took to Twitter to say they found their e-mail addresses in the dump.
Patreon subscribers should make sure they have changed their compromised password, both on Patreon and on any other websites it may have been used. Patreon users should also be prepared for the very real possibility that anything they did on the donations site is now a permanent part of the Internet record.

Update 2: Hunt said the release appears to include the entire database taken in the hack, including a fair number of private messages sent and received by users. "Obviously all the campaigns, supporters and pledges are there too," he wrote in one tweet. "You can determine how much those using Patreon are making." In a separate tweet, he wrote: "The dollar figure for the Patreon campaigns isn't the issue, it's supporters identities, messages, etc. Everything private now public."

'Digital India' making India a 'strategic' cyber attack victim

 




A FireEye report found that 38 percent of organisations in India were exposed to targeted advanced persistent attacks in the first half of 2015, a 23 percent increase from the previous report.
"Geopolitical tensions and digitization in the region have steadily ratcheted up in recent months, and cyber activity reflects this," the security firm said.

FireEye found organisations in every geography in Asia Pacific, including India, experienced a higher or equal rate to advanced persistent threat (APT) groups than the global average of 20 percent in the report.

In the first half of 2015, FireEye revealed two attacks likely conducted by China-based threat actors on Indian organisations. APT30 conducted a decade-long cyber-espionage campaign that compromised, among others, an Indian aerospace and defense company. The WATERMAIN campaign targeted India and its neighboring countries and appeared to target information about ongoing border disputes and other diplomatic matters.

"India is fast becoming a strategic target, in part because of the potentially sensitive information that is expected to be digitized through ambitious and high-profile projects such as Digital India," the report said.

"The focus on India is reflected in the finding in today’s report that India ranked fourth in Asia Pacific countries exhibiting the most command-and-control (CnC) infection callbacks, which indicates the presence of compromised systems that are actively communicating with the APT groups’ command and control infrastructure."

Across Asia Pacific, the FireEye report revealed that over 50 percent of telecommunications firms and government organisations have faced advanced persistent attacks, with education and the high-tech industry not far behind. The WATERMAIN threat is an example of attacks on higher educational institutions on India and bordering countries.

Bryce Boland, chief technology officer for Asia Pacific at FireEye said, “As India embarks on ambitious technology projects, attackers are exploiting gaps to compromise critical networks. Indian organisations are more likely to be exposed to attacks than the global average. In the future, India’s growing economic clout and rising regional influence are likely make it a more attractive target to threat groups. These threat groups seek access to intellectual property, intelligence and critical infrastructure.”

New Botnet hunts for Linux capable of launching 20 DDOS attacks per day at 150 GPS

 

A network of compromised Linux servers has grown so powerful that it can blow large websites off the Internet by launching crippling Distributed Denial-of-service (DDoS) attacks of over 150 gigabits per second (Gbps).
The distributed denial-of-service network, dubbed XOR DDoS Botnet, targets over 20 websites per day, according to an advisory published by content delivery firm Akamai Technologies.
Over 90 percent of the XOR DDoS targets are located in Asia, and the most frequent targets are the gaming sector and educational institutions.
 

Thousands of medical systems exposed online that are vulnerable to web attacks.

 



Two security researchers uncovered thousands of medical systems exposed online that are vulnerable to web attacks.

On Saturday, September 26, researchers Scott Erven and Mark Collao presented their findings at Derby Con 5.0 in a presentation entitled “Medical Devices: Pwnage and Honeypots.”
“We know medical devices are exposed to the Internet both directly and indirectly, so just how hard is it to take it to the next step in an attack and gain remote administrative access to these critical life saving devices? We will discuss over 20 CVE’s Scott has reported over the last year that will demonstrate how an attacker can gain remote administrative access to medical devices and supporting systems,” reads a description for the researchers’ talk. “Over 100 remote service and support credentials for medical devices will be presented. So is an attack against medical devices a reality or just a myth? Now that we know these devices have Internet facing exposure and are vulnerable to exploit, are they being targeted? We will release and present six months of medical device honeypot research showing the implications of these patient care devices increasing their connectivity.”
As reported by The Register, the researchers spotted 68,000 vulnerable medical systems online belonging to an unnamed U.S. health organization via the use of Shodan. The exposed devices included 488 cardiology machines, 323 picture archiving and communication gear, 133 infusion systems, and 97 MRI scanners.
Using their “real life” MRI and defibrillator honeypots, Erven and Collao were able to observe the types of attacks that are typically launched against those devices if exposed. Over a period of six months, they spotted 55,416 successful SH and web logins and 299 malware payloads.
In the case of the malware-based attacks, many of the attackers apparently never realized the value of what they had compromised.
“They come in, do some enumeration, drop a payload for persistence and connect to a command and control server,” Collao said. “We can deduce that there is owned medical devices calling back to a C2 (command and control server) and that there is an attacker out there who does not know what they sitting on. These devices are getting owned repeatedly now that more hospitals are WiFi-enabled and no longer support arcane protocols.”

Apple’s biggest ever hack – how to avoid being hacked

 


More than 225,000 Apple accounts have been hacked into – but only those of people who have ‘jailbroken’ their Devices
It’s been revealed that more than 225,000 valid Apple accounts have been stolen from people without their knowledge – but only if they had ‘jailbroken’ their phones.

The research from Weiptech and Palo Alto networks discovered that the details were obtained via malware that was distributed by using the popular jailbreak tool Cydia.
‘Jailbreaking’ your phone is when you remove the hardware restrictions on iOS and allows you to access banned apps and customise your phone, among other Things.

However, as it is not approved by Apple and it is done using unauthorised tools, it’s also an easy way for malicious people to instal malware on your phone, iPad or Apple TV.
The Malware, KeyRaider, uploaded all of the stolen information to a separate server.
Because this server wasn’t secure, the researchers who discovered the hack managed to hack into it, and download some of the stolen data before they were cut off.

As reported by The Next Web, login details were stolen, and so were purchasing receipts and device IDs, among other data.
It’s worrying news for anyone who has ‘jailbroken’ their device – but those who haven’t are safe.

How to avoid being hacked

  • Don’t download any third party apps that haven’t been sanctioned by Apple
  • Change your passwords regularly
  • Keep your sensitive emails secure, use different passwords for different email accounts
  • If you have jailbroken your phone, change your passwords

Lenovo Caught (3rd Time) Pre-Installing Spyware on its Laptops

 

Lenovo has once again been caught installing spyware on its laptops and workstations without the user's permission or knowledge.
One of the most popular computer manufacturers is being criticized for selling some refurbished laptop models pre-installed with invasive marketing software that sends users data directly to the company.
This is not first time Lenovo has allegedly installed spyware onto consumers PCs.
  • Earlier this year, Lenovo was caught red-handed for selling laptops pre-installed with Superfish malware that opened up doors for hackers.
  • In August, Lenovo again got caught installing unwanted and non-removable crapware into part of the BIOS reserved for custom drivers

Lenovo Laptops comes Pre-installed with 'Spyware'

Now, the Chinese computer manufacturer is making news once again for embedding tracking software into its laptops and workstations from Lenovo ThinkPad, ThinkCentre, and ThinkStation series.
Michael Horowitz from Computerworld has discovered a software program, called "Lenovo Customer Feedback Program 64," that operates daily on these systems and can be categorized as Spyware.
The purpose of this program is to send customers' feedback data to Lenovo servers. According to Horowitz, the company has mentioned this in its EULA, but he "can not recall ever being asked [for] a Customer Feedback program" while ever setting up his Lenovo PC.
Horowitz also found that this program includes some other files, which is as follows:
  1. Lenovo.TVT.CustomerFeedback.Agent.exe.config
  2. Lenovo.TVT.CustomerFeedback.InnovApps.dll
  3. Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll
One of these files belongs to Omniture, which is an online marketing and Web analytics company, which is included to track and monitor users' activities and send that data to this online marketing agency.
Lenovo does mention on its website that there may be software program installed on its systems that connect to its online servers, but it does not mention anything about sending your data for financial profit.

How to Remove Lenovo Spyware?

In order to remove 'Lenovo Customer Feedback Program 64' from your affected machines, you have to do it manually. Follow these simple steps:
  • Know your System Type (whether it's a 32-bit or 64-bit version of Windows)
  • Download TaskSchedulerView
  • Now, search your Lenovo PCs for Lenovo Customer Feedback Program 64
  • Disable Lenovo Customer Feedback Program 64 daily task from running
  • Additionally, you can also rename the "C:\Program Files (x86)\Lenovo"


 

 

Should we hack the hackers?

 


Should we hack the hackers?
Western companies are being fleeced for hundreds of millions by cybercriminals. Is it time to give them a dose of their own medicine?



If we’re losing the war against cybercrime, then should we take off the gloves and strike back electronically against hackers?

As banks reel from another major hacking revelation, a former US director of intelligence has joined some of them in advocating for online counterstrikes against cybercriminals.
In February, security firm Kaspersky detailed a direct hack against 100 banks, in a co-ordinated heist worth up to $1bn. This follows growing sentiment among banks, expressed privately, that they should be allowed to hack back against the cybercriminals penetrating their networks.

At February’s Davos forum, senior banking officials reportedly lobbied for permission to track down hackers’ computers and disable them. They are frustrated by sustained hacking campaigns from attackers in other countries, intent on disrupting their web sites and stealing their data.
Dennis Blair, former director of national intelligence in the Obama administration, has now spoken out in favour of electronic countermeasures, known in cybersecurity circles as hacking back, or strikeback.
Blair co-authored a 2013 report from the US Commission on the Theft of American Intellectual Property. It considered explicitly authorising strikeback operations but stopped short of endorsing this measure at the time. 

Instead, the report suggested exploring non-destructive alternatives, such as electronically tagging stolen data for later detection. It also called for a rethinking of the laws that forbid hacking, even in self-defence.
Western law enforcers don’t have jurisdiction in the countries where cybercriminals operate. Ideally, they would pass information about hackers onto their counterparts there, said Blair, but in many cases local police are un-cooperative. It’s time to up the ante, he suggested.
“I am more leaning towards some controlled experiments in officially conducting aggressive cyber-tracking of where attacks come from, discovering their origin, and then taking electronic action against them,”.

There’s just one problem with strikeback operations, said Mark Rasch, a former federal cybercrime prosecutor and the head of Maryland-based Rasch Technology and Cyber-law: it’s against the law. “You have to start with the general assumption that hacking back is most likely illegal,” he said.
Long-standing laws on both sides of the Atlantic clearly forbid unauthorised tampering with a computer, even if someone is using that computer to attack you. In the UK, the Computer Misuse Act sets those rules. In the US, the Computer Fraud and Abuse Act does the same.
Even without this legislation, the law generally frowns upon what Rasch calls “self help”. Judges dislike vigilante justice.

The stakes are getting higher, though. Since the report’s release, corporate America has seen several devastating cyber-attacks. JP Morgan suffered a breach affecting 76 million households. Home Depot and Target were also hacked, and most recently, Sony Entertainment was embarrassed by the theft of internal documents.
“I’ve been seeing the way that technology is developing. I think it’s worth some limited legislation to post penalties back to hackers,” Mr Blair said, adding that companies should work with law enforcement rather than taking matters into their own hands.
“Law enforcement authorities can go back down the same route that [the hackers] use to attack, and cause physical damage to their equipment,” he added.

A Gentler Poke
Advertisement
Is frying someone’s laptop remotely with a killer poke even possible? Even if it is, it may not achieve the desired effect, says Dave Dittrich, a computer specialist at the University of Washington’s Applied Physics Laboratory, who is a specialist in the topic. “How expensive is it to buy a new one? $500? Cyber is not the same as physical when it comes to disabling ‘weapons’ to remove a threat.”
Frying is not the only form of counter-hack, points out Dittrich. “I prefer the term ‘active response continuum’ to make it clear and explicit that there is a wide range of actions, from benign to very aggressive and intrusive,” he said.
These actions include simply probing an attacker’s computer to see what kinds of attack tool they are using.

“That falls on the lower end of the active response continuum, and has less chance of causing any harm to anyone (beyond trespassing, which may still be a crime, but a lesser offense),” Dittrich said.
Could laws be tweaked to allow gentler forms of active defence? Even if they were, technical problems remain, warned Jon Ramsey, chief technology officer at Dell SecureWorks, Dell’s security unit. One of the biggest challenges is attribution, he pointed out. It is difficult to trace an attack to a specific individual in cyberspace.

“Without accurate traceback there is a significant and substantial risk that organisations start attacking legitimate organizations,” he said. “Where would this end? It would cascade out of control. Threat actors often use compromised devices of companies and individuals that become unwilling and unknowing participants in attacks and are attacked themselves.”
For example, cybercriminals frequently launch compromised computers that are part of a botnet to launch their attacks, said Bill Nelson. He is the executive director of FS-ISAC, a US industry forum for financial services firms to privately share information about cyber threats.
A botnet is a large collection of computers owned by innocent users, which have been infected by malware. The malware enables cybercriminals to remotely control the computers.

“We do not endorse hacking back because there can be significant unintended consequences,” said Nelson.
These issues apparently haven’t stopped financial institutions from considering the idea in private before. In December, Bloomberg reported that banks had considered using offshore contractors to carry out a counter-attack, after a widespread attack on the US banking community that US officials believed was mounted from within Iran.
According to Bloomberg, the FBI discovered that computers used in a cyber-attack on the banking community had been disabled by a third party, and the agency had investigated banks to see if they had already engaged in strikeback activity across national boundaries. It apparently absolved banks under investigation, though.

Banks would have been particularly sensitive to the idea of hacking back across international borders, said John Pescatore, who worked in the Secret Service and the NSA before becoming director of security research and training company the SANS Institute.
“They need to cross country boundaries to do it. That’s what was really coming out of Davos,” he said, adding that these companies are well aware of the legal dangers when crossing international lines. “It’s that boundary crossing issue where I think the larger financial institutions are saying: ‘we need some help’.”
Instead of engaging in such legally risky behaviour, banks that are attacked should simply share information about it with the government to help prepare an industry-wide response, argued John Carson. He is the executive vice president of BITS, the technology policy division of the US Financial Services Round Table, an industry association for financial firms.
Information sharing, while good for cybersecurity, may carry its own legal risks, Carson warned: “Today if there is an attack, there’s a reluctance to share that information because it could be used against that institution in a civil suit.”
Legislators are trying to plug that gap. In January, the Cyber Intelligence Sharing and Protection Act (CISPA) was reintroduced in the House. The Bill would allow companies to share information about cyber-threats and hacks with law enforcement without fear of legal reprisal.
In February, Senator Tom Carper (D-Del) also introduced the Cyber Threat Sharing Act of 2015, which would accomplish similar goals. President Obama also signed an executive order advocating cybersecurity information sharing.

Armed with this information, the government might be the ideal partner to hack back against cybercriminals .
Blair affirms that banks shouldn’t handle it themselves: “I still think it should be handled through law enforcement authorities, and I would not give some immunity to companies who try it on their own. Because then you just make it wild west, vigilante stuff.”
Law enforcement is equally constrained by the law, though, said Rasch. “You can get a warrant to search and seize stuff, but since when did law enforcement have the authorisation to impose punishments on their own? If that’s what you’re talking about with hacking back, I don’t think they can do it,” he said.

The real question, he added, is whether a government would consider refusing to prosecute law enforcement in the event of a cyber strikeback. But at that point, it stops being a legal discussion. “You’re getting out of the realm of law. You’re getting into the realm of politics,” he warned.
At this level, the problem is that one government may simply have different rules or priorities to another. If a government refuses to prosecute its own cybercriminals when they’re attacking companies in your country, then should your government support strikebacks by law enforcement that believes it has identified a hacking group?

“It’s a dangerous game you play, when you decide that because they’re not following the rules, you’re not going to either. Because then you don’t have rules,” he said.
The problem seems simple: do you take the high road, or stoop to their level? At stake are not only millions of dollars in intellectual property, but also elements of critical national infrastructure, and even free speech.
As we face such threats, Blair remains convinced that strikebacks are a useful deterrent. He is less concerned with the legal debate than he is with the fact that western firms are being fleeced by shadowy cyber-crooks half a world away.
“Sitting around sucking our thumbs debating legal points is getting us nowhere,” he concluded. “We’re being robbed blind.”