Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

18 July 2012

One in ten UK businesses have suffered from cybercrime


Research by Hiscox reveals that one in ten small businesses in the UK have experienced a data hack.

The study also revealed that 90% of small businesses don't have a cyber crime insurance policy. While four in ten SME's are worried about their computer systems being hacked only one in four are confident about their security measures against attacks.

Cyber crime is costing the UK economy around £11bn a year and while the media is reporting a growing number of high profile data breaches, some small businesses may also be a popular target for hackers because the systems are usually easier to get into and the breach may not be found out for a good few weeks..............


Click here to read more .... 
Solutions : www.xcyss.in

09 September 2011

Certificate hacks: PKI didn't fail us, humans did

By  | InfoWorld


With the high likelihood that GlobalSign has been hacked, this brings to at least three the number of popular public PKI certification authorities (CAs) attacked in recent months by a single hacker. The other CAs are Comodo and DigiNotar.
The computer security world is aflutter because hundreds of bogus digital certificates have been issued. "It's a massive failure of PKI," they say. "It proves that there's too much trust spread around," say others.
But it's hard for me to get worked up about any public CA or PKI compromise. Here's why: Almost nobody pays serious attention to digital certificate warning messages in the first place.
I've yet to see the person who, when presented with a certificate error, didn't continue on and visit the website they were trying to access. Most users are simply annoyed by digital certificate warning messages. How dare they get in the way of a quick-loading Web page!
It's not just mom and granddad who are ignoring digital certificate warnings. A few years ago, a survey revealed that the more users knew about digital certificates and PKI, the more likely they were to ignore the warnings.
Part of the problem is that for as long as public PKI has been in existence -- nearly two decades -- it has tended to be implemented poorly. Websites with SSL certificates are notorious for having mistakes in their certificates. Mostly they have incorrect host names, where the subject name does not match the host name being contacted -- but certificates are often expired or have other x.509 mistakes. I attended a Black Hat Las Vegas 2010 conference on the subject where Ivan Ristic, directory of engineering at Qualys, revealed that the majority of websites using SSL certificates had errors.
Qualys found 22.65 million SSL-enabled websites and hosts on the Internet (out of hundreds of millions of websites). Only 720,000 had SSL certificates with a valid name match. Only 28 percent of the most popular SSL websites had a proper name, although 70 percent had digital certificates that were linked to a trusted CA. That's good. But 28 percent were untrusted, and 4 percent had trust chains that could not be verified.
Moreover, Qualys said more than 2 percent of the 22.65 million sites were suspicious. More than 137,000 certs were expired, 96,000 were self-signed, and more than 1,000 were revoked (but still being used). Twenty-one thousand had invalid digital signatures, and more than 57,000 had unknown CAs. Ninety-nine digital certificates had known bad keys left over from the Debian random number generator vulnerability, which was found and fixed more than a year before.
I'm sure that these statistics have improved over the last year, but if only 3 percent of SSL-enabled sites (720,000 divided by 22.65 million) had a correct and valid SSL certificate (including only 28 percent of popular websites), can we really ask end-users to rely on public PKI?
Don't get me wrong: I'm sad anytime I hear that a CA is hacked. CAs have heavy, tight security around the digital certificates that can issue other certificates. Most are protected by hardware security modules (HSMs), which usually require smart cards, USB tokens, or some other physical security device. In fact, it usually takes multiple physical tokens (each attached to different people) in order to access the important digital certificates. HSMs should be used by any company with a PKI, but especially by CAs.
The Comodo hacker referenced above talks about being thwarted by an HSM. My guess is that the other compromised CAs were either not using HSMs or were not using them appropriately.
The bottom line is that PKI didn't fail us. Its mathematical beauty and potential assurance is something rare in the computer security world. If run correctly, it would greatly benefit our online world. But as with most ongoing security risks, human nature ruins the promise.


Source: http://www.infoworld.com/t/cyber-crime/certificate-hacks-pki-didnt-fail-us-humans-did-172173

Solutions : http://www.xcyss.in/      

Hackers Are the New Mob: White House Gets Serious on Cybercrime



Potential teenage Matthew Brodericks, beware: In this era of LulzSec, DDoS attacks on BART and hacktivst group Anonymous telling NATO that the world doesn't belong to them anymore, the White House has decided that it's time to take hacking seriously, asking for tougher sentencing for those found guilty of cybercrime.
Speaking before the Senate Judiciary Committee, Associate Deputy Attorney General James Baker and Secret Service Deputy Special Agent in Charge Pablo Martinez explained that sentencing has failed to keep up with the growing seriousness of hacking, and that the administration is calling for the Computer Fraud and Abuse Act to be folded into the Racketeering Influenced and Corrupt Organizations Act.

The key to understanding the proposed changes is the new presumption that modern hackers are not acting alone. Martinez told the Committee that "Secret Service investigations have shown that complex and sophisticated electronic crimes are rarely perpetrated by a lone individual," adding that online criminals "organize in networks, often with defined roles for participants, in order to manage and perpetuate ongoing criminal enterprises dedicated to stealing commercial data and selling it for profit" (or, you know, just to cause chaos and show that they can hack into that place someone said they couldn't, but whatever). It's a narrative picked up by Baker, who went even further, saying that "[a]s computer technology has evolved, it has become a key tool of organized crime. Many of these criminal organizations are similarly tied to traditional Asian and Eastern European organized crime organizations."
In addition to reclassifying hacking as an organized crime activity, the White House's proposal seeks the creation of a national data breach standard, replacing whatever various state laws may be in place.


Source : http://techland.time.com/2011/09/08/hackers-are-the-new-mob-white-house-gets-serious-on-cybercrime/#ixzz1XSH09UWF





Solutions:  http://www.xcyss.in/   

07 September 2011

19 Million victims of cybercrime a minute in the UK


Over 19 million people are falling victim to cybercrime per minute reveals the Norton Cybercrime report released today (7 September 2011).
The report claims that 51% of people in the UK have experienced some form of cybercrime during their lifetime. In addition, three times as many people have experienced crime online in the past year than have experienced offline crime.
'It's important for people to think about how they are protected online, otherwise they risk losing their hard-earned cash,' said Adam Palmer, lead security advisor at Norton.
The report claims that on average £474 million a year is lost to cybercrime in the UK with an additional £619 million lost in terms of the value victims place on their lost time. Globally, Norton estimates cybercrime costs around £71 billion last year.

Cybercrime can be prevented

Computer viruses and other malware are the most common form of preventable cybercrime, according to the Norton Cybercrime report, with 38% saying they'd encountered a virus.
Of those who have suffered viruses, 10% with then hit with by credit card fraud, while 6% had their social network hacked.
Sarah Kidner, editor of Which? Computing said: 'The figures in Norton's report are alarming. However, we wouldn't want them to stop people enjoying a rich online experience. Security software, notably our Best Buys, provide an excellent defence.
'However, it is essential that people keep their software up-to-date and ensure that they download updates for their operating system,' Kidner continued.

Source: http://www.which.co.uk/news/2011/09/19-million-victims-of-cybercrime-a-minute-in-the-uk-264954/

 For solutions related to cyber security visit us at http://www.xcyss.in/