Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts
Friday, December 26, 2014
2014, the year of the Cyberbreach
![]() |
| This interactive chart from www.informationisbeautiful.net/ shows some of this year's biggest hacks. |
And I’m not talking about North Korea’s much ballyhooed hacking of Sony Studios to prevent the release of its film, “The Interview,” which features the assassination of dictator Kim Jong-un by two bumbling journalists, played by James Franco and Seth Rogen.
![]() |
The Lizard Squad:
Cyber Grinches
|
No, what I’m talking about is a group of Grinches calling themselves the “Lizard Squad” who tried to steal Christmas from thousands of kids this year by launching a distributed denial of service attack on new Sony PlayStation and Microsoft Xbox game consoles.
The attack, which succeeded in overwhelming Sony and Microsoft’s servers with so much fake internet traffic that they crashed, prevented owners of these new gaming systems from connecting to the Internet. The attack, however, did not affect games that did not require an Internet connection to play.
While the motives behind North Korea’s alleged hack seems akin to an unruly child throwing a temper-tantrum because someone was planning to make fun of it, the aims behind the Lizard Squad’s latest action are somewhat unclear.
In an article on the Winbeta blog, the group claims its motives were more pure. They claim they did it to show consumers just how bad Microsoft and Sony were at protecting their data and to force both companies to upgrade their security. Doing it on Christmas day, they said, would “would anger and reach the largest amount of people – more people [more] angry calls for a greater response from the companies.”
Whether or not you believe their goals were as altruistic as they claim – and it’s hard to, when in that same article, the group also claims to have launched the attack “for laughs” – they are correct. This past year seems to have been the year where Cybersecurity has failed the consumer in some very big ways.
It all started in November of 2013 with the hacking of Target, where 40 million credit cards numbers were stolen. Then in January came news that millions of SnapChat accounts were hacked and info on users, including their phone numbers had been posted online for anyone to download. Then in the Spring, Home Depot fell victim of a cyberattack where approximately 53 million email addresses and 56 million credit card accounts were compromised.
In the summer, while most of us were relaxing at the beach, beside the pool, or with friends and family at barbecues, hackers were hard at work. In May came word that the world’s largest online auction site, E-Bay, had its user database breached, which gave cybercriminals access its customers’ names, account passwords, email addresses, physical addresses, phone numbers and birth dates. Then in June the U.S. Secret Service tipped off the popular Asian-themed restaurant chain, P.F. Chang’s, that 33 of its locations had their credit-card-processing terminals compromised and that the hack had been going on for eight months.
Not even big banks, who you’d assume have some of the most secure computer systems on the J.P. Morgan Chase & Co. as well as four other banks, had their systems breached. In this attempted cyber bank heist, J.P Morgan reported that as many as 76 million households were affected and that the names, addresses, phone numbers and e-mail addresses of its clients had been exposed. It was also recently revealed by the New York Times, that the hack was made possible because the company “failed to upgrade one of its network servers” and “switch on two-factor authentication” meaning that access was possible without knowing a combination of a password and the value of a one-time code.
planet, were immune from this summertime hack-attack. In late August the Wall Street Journal reported that
Attacks continued into the Fall with breaches at Google, where in September almost 5 million Gmail usernames and passwords were hacked and posted to a Russian web site, and most infamously at Apple, where hackers broke into the company’s iCloud storage site and stole nude photos of celebrities such as Jennifer Lawrence and Kate Upton and released them on the Internet. That was followed by an attack in October, targeting software giant Adobe, in which 38 million of its users had their account and credit card information exposed.
I could go on and list more – and if you are really interested there is a pretty cool graphic showing the relative size of all the major databreaches in the past few years here – but I think we all get the point. Cybersecurity is nowhere near as “secure” as it needs to be in a world where we conduct and store much of our lives online.
Being in the IT industry myself, I’m not going to point any fingers here, because I know how hard it is keeping computer networks safe with the crop of tools currently at our disposal. That said, I think it’s well past time that the IT industry came up with better methods of keeping our data safe. Chief among these new strategies should be the ditching of any method based on password authentication.
Let’s face it, typing in a password to a computer was OK back in the ’90s when dialup was still the norm and e-commerce was just a dream. But in today’s world, we need a more sophisticated method of identification. Next year I might take a stab at suggesting a few alternatives, but in the meantime, I think the IT industry needs to concentrate on making 2015 the year of REAL cybersecurity.
Friday, May 30, 2014
Privacy in the modern world is really an illusion
“Yeah,” I replied, closing the lid of my laptop. “About that….”
Undeterred, he went about his rant how we live in an oversharing world, where people seem to believe “that every single errant thought, routine errand and bowel movement is worth a chirp!”
“Tweet,” I corrected.
“Whatever!” he said disgustedly. “My point is what the hell happened to the idea that other people should keep their noses out of my business? In my day, people used to get upset when they found out other people were eavesdropping into their private affairs. Today it seems like people get upset if the world doesn’t know what they are doing!”
I smiled sadly at the Elder Geek. “Welcome to ‘The Brave New World’ of Edward Snowden and the NSA, WikiLeaks, Google and Big Data.”
“I think you mean ‘Big Brother’,” he corrected.“Whatever,” I said.
The Elder Geek frowned. “How can people be so casual about this? Doesn’t anybody care that there is all this private information floating around about them for everyone to see!”
“Why should they care, when no one else does?” I asked. “With red-light and security cameras popping up on virtually every corner and their own personal devices spying on them, people just seem to take it for granted that privacy in the modern world is really an illusion. Like the citizens of Oz, we’ve all been fooled into ignoring the man behind the curtain.”
“Why that’s outrageous!” the Elder Geek stammered.
I nodded. “You’re right, but people have become so enamored by the magical powers of their smart phones, TVs and thermostats; tablet computers and customer loyalty cards and the convenience of Internet shopping, that they don’t seem to care that both their every physical and online move is being tracked. Like junkies, we’ve become addicted to our high-tech devices and now we can’t live without them.”
“Well they should learn!” the Elder Geek grumbled.
“Easier said than done. Unlike the good old 1980s, it’s nearly impossible to keep all your data private. Julia Angwin, an investigative reporter for the Wall Street Journal , tried it and wrote about it in her book, “Dragnet Nation: A Quest for Privacy, Security and Freedom in a World of Relentless Surveillance.” Among the things she tried was not using Google nor any of its related services and she even resorted to carrying a “burner” cell phone, but she still found that for the average person, it was nearly impossible to keep her anonymity online. You can hear her talk about her experiences in this interview on NPR’s “Fresh Air” program.
“So what you’re saying is that there is no hope and we’d better get used to Big Brother…or Big Data or whomever watching our every move?” he asked resignedly.
“No. Not exactly. Earlier this month, the European Union Court of Justice came out with a ruling stating that people have ‘the right to be forgotten,’ and part of that right includes letting people erase traces of their digital past from the Internet.”
“Well that’s encouraging!” he said brightly.
“Yeah well don’t get your hopes up yet,” I said trying to put a damper on his expectations. “As much as I agree with that sentiment, the courts over there are going about it the wrong way. They are putting the onus on Google to delete that information from their search results.”
“So what’s a matter with that?” he asked.
“Well it’s like asking a carpenter to put a self-closing hinge on the barn door after the horse has escaped, instead of putting a lock on the door BEFORE the horse got out,” I explained. “Just making Google exclude the information from their search results won’t get rid of the data. I know it’s hard to believe, but there are other search engines out there besides Google. (Anyone remember AltaVista? Yahoo? Dogpile? Bing?) And it won’t stop the company that originally collected that data on you from using that outdated information in the future. What the courts should have really mandated is that the companies who collect your data be legally obligated to purge their information on you every few years. Then we will be getting somewhere.”
The Elder Geek pondered this for a moment. “So how do you propose doing this?” he asked.
I gave him a mischievous smile. “Why sharing it with everyone on Facebook and Tweeting about it with #DeleteMe of course!”
Saturday, January 18, 2014
Beware! Big Data is watching!
In his novel, “1984” he predicted a dystopian future in which the government sought to control the populace by spying on them.
But 30 years after that story was supposed to have taken place, it’s not “Big Brother” we have to fear, but rather “Big Data.”
Since computers began integrating themselves into our lives back in the early ’80s, we have become so used to our near constant connection to the Internet that those of us who are actually old enough to remember life back in 1984 can’t imaging having to live again in that pre-interconnected world.
But our modern ability to have all of humanity’s collective knowledge (or depending on your point of view, cute cat videos) at our fingertips has come with a dark side that even Darth Vader would have feared. The rise of “Big Data.”
Big Data, for those of you not familiar with the term, refers to companies who track our every online click and use that information to compile a virtual personality profile of us. These dossiers are then used to either target us with ads or are sold to other companies anxious to get their hands into our wallets.
Now businesses collecting data about their customers is nothing new. It has gone on since at least the ’90s – if not earlier – with supermarkets using customer loyalty cards to track purchases and print coupons targeted to the buyer on the backs of register receipts.
![]() |
| The Nest Smart Thermostat |
I generally don’t have a problem with this type of thing, but what set the alarm bells off in my head was the recent announcement that Google – perhaps the biggest of all the “Big Data” companies in the world – recently bought a small company called Nest, which makes a line of smart thermostats.
Through the magic of the Internet, I can already see you staring at your computer/tablet/phone screens making that “so what?” face. But let me tell you why you should be concerned.
Nest’s line of smart thermostats are designed to learn your schedule, program themselves and enable you to remotely control them via an app on you install on your cell phone.
Again I can see you making that “so what?” face. Right now you are probably thinking, “I hate having to get out my 150 page manual every time I need to change the temperature or reprogram my current set-back thermostat!”
Well so do I, and I do like the idea of a thermostat automatically adjusting itself to fit my schedule. The problem I have with it, is with the Internet connectivity Google is likely to enhance in future models.
Remember Google is perhaps the world’s biggest and best-know search engine, whose name has already become a verb. It is in the business of collecting data on you. It does this every time you search for something on the Web, send a message from G-mail, watch a Youtube video and to some extent when you use an Android-based phone. So what makes you think Google is not going to be collecting data on you from its newly acquired line of smart thermostats and smoke/carbon monoxide detectors?
But what, you may ask, can Google really learn about you from just your thermostat settings? Off the top of my head I can think of at least a half-dozen things: where you live right down to the street address, what kind of heating (or cooling) system you have, how warm/cool you like your home and most importantly when you are home and away and when you’re likely to be awake and asleep.
Now I’m no conspiracy theorist and I do generally believe that Google does try to live by its “Don’t Be Evil” corporate motto. But let’s face it, Google is now a multi-billion dollar public company, that, like any business with lots of investors, is in business to make money. And the thing Google uses to make money with is our data. So to expect them NOT to use the data they’ll collect from the thermostats and other home automation products they’ll create is unreasonable.
How might they use this information? Image this scenario. Just as you are getting back from vacation, you get a call or text from some person or company you’ve never heard of or done business with before.
“Hello Mr. Smith,” it will say. “Welcome home! I hope your trip was a good one! We’re calling/texting because we see that your furnace filter is due to be replaced in the next three days. Well right now we’re offering a sale on filters especially made for your Acme Furnace, Model ABC123. And oh by the way, we see that your unit hasn’t been serviced in the last six months. For an extra $69.99 we could send a tech out to your home at 1313 Mockingbird Lane, Mockingbird Heights, New Jersey. From your schedule it looks like Fridays you get home from work early and we do have a 4 p.m. slot open. If that’s not good, we have Saturday appointments also. Since you like to sleep until noon on the weekends, we could schedule it at 1 p.m. if that works better for you.”
If you don’t find the fact that your house just told a complete stranger that you weren’t home and what your normal schedule is down right creepy, I don’t know what will. I try very hard to discourage even my own neighbors from knowing when I’m home or not, so my house won’t be a target of burglars. But with my house blabbing about my schedule to the entire Internet, I just might as well get rid of all timers for my lights and keep my doors unlocked.
Okay, so I’m exaggerating a bit, but the fact that my private schedule will suddenly be public knowledge is no exaggeration.
And I do mean public knowledge.
Because if the recent Target credit card hacking case and Edward Snowden have taught us anything, it’s that no data is completely safe. Make no mistake, the data coming from Internet-enabled home automation devices like these smart thermostats would be a gold mine to some hacker; low paid, ethically-challenged systems operator or even a government spy agency.
You think the Cryptolocker virus that struck at the end of last year was bad? Now imagine instead of locking up all the data on your computer hard drive and ransoming it back to you, some Internet miscreant hacks into your heating system on the coldest day of the year.
Want your heat back? Then send $25,000 to this PayPal account or freeze!
Attacks probably won’t be as blatant or obvious as that. Smarter operators or even our own government could just tap into the data your thermostat sends back to Google and use it to determine when you come and go. Then they could sell that data on some black market to burglary rings looking to target specific zip codes or use it themselves to break into your home when they know you will be out.
I realize all these things are pretty unlikely and there will no doubt be some safeguards on the devices to prevent exactly the sort of abuses I talk about here. But the idea that there will be some gadget or gadgets inside my house, watching me and learning all about my habits and reporting them back to some anonymous, faceless entity – even if it’s for totally “legitimate” purposes – is still creepy. It smacks of the exactly the kind of surveillance state George Orwell warned us about all those years ago.
It’s almost enough to make me want to go back to those carefree, pre-connected days of 1984.
Labels:
1984,
Big Brother,
Big Data,
George Orwell,
Google,
Nest
Subscribe to:
Posts (Atom)




