BrokeBerry

Attack Computer Wiz

A Security & Technology Weblog
Showing posts with label Government. Show all posts

David Kernell, son of Democratic Representative from Tennessee Mike Kernell, was convicted by jury of “Hacking” Sarah Palin’s Yahoo account. The 22 year old Kernell was convicted of unauthorized access to a computer and obstruction of justice.

Kernell used information that Palin herself made available to the public to guess her challenge questions that ultimately lead to his ability to gain access to her Yahoo account. Once he gained access to her account he changed her password and posted screen shots of emails on the internet.

On her Facebook page, Sarah Palin released the following statement (in part):

    “My family and I are thankful that the jury thoroughly and carefully weighed the evidence and issued a just verdict. Besides the obvious invasion of privacy and security concerns surrounding this issue, many of us are concerned about the integrity of our country’s political elections. America’s elections depend upon fair competition. Violating the law, or simply invading someone’s privacy for political gain, has long been repugnant to Americans’ sense of fair play. As Watergate taught us, we rightfully reject illegally breaking into candidates’ private communications for political intrigue in an attempt to derail an election.”

Source: eWeek
Source: Facebook

user Posted by Mike Wright

| More


Juror #4 comes forward and speaks out about the conviction. I found it very interesting that Juror #4 is a CCIE (Cisco Certified Internetwork Expert).

You can read the entire article from Network World here.

user Posted by Jason

| More


Terry Childs was found guilty on the single charge of denying computer access on Tuesday. This conviction could hold a maximum five year prison sentence.

user Posted by Mike Wright

| More


Below is a CBS News video that shows the extreme security risk of data stored on copy machines. I am simply amazed that organizations and enterprise would allow data to simply walk out their doors as shown in the video below.

We don't need hackers and crackers to break into networks and steal data. For a few hundred dollars anyone can purchase it legitimately.

It is very simple and only takes a small amount of effort to remove a hard disk and wipe it making data unrecoverable.



Watch CBS News Videos Online

user Posted by Mike Wright

| More


The trial of the city of San Francisco’s ‘rogue administrator’ is over and Terry Childs' fate is now in the hands of a jury. We first wrote about Childs back in 2008. Childs was the network administrator for the city of San Francisco that held the cities network hostage after locking out everyone and refusing to hand over the network password.

Childs was charged in July of 2008 and has been in custody ever since. If convicted, Childs faces five years in prison for his alleged crimes.

I wonder if San Francisco practices separation of duties now.

Source: Network World

user Posted by Mike Wright

| More


Just weeks after the US Department of Defense announced that it would be relaxing its policy on the use of portable media devices it has relaxed its policy concerning social networking. Employees using non classified computer systems will be able to access social networking websites such as FaceBook and Twitter. Personal use of these sites must be accompanied by authorization and all official postings are closely monitored.

There is no mention in the source whether or not the DoD has installed any filtering, monitoring or auditing software or systems to ensure that usage is within policy and to protect against release of unauthorized data.

Information Week Government

user Posted by Mike Wright

| More


The Federal Trade Commission (FTC) made breach notifications on Monday to almost 100 organizations. The notifications advised these organizations that they (the organizations not the FTC) had sensitive data compromised. Data that the organizations lost include employee data, customer data, information about computer networks and other sensitive information.

The breach was accomplished with Peer to Peer or P2P technology. This can be accomplished when users within the organizations use applications for playing online games, software for making telephone calls online, chatting, sharing music, videos, and/or files. When these applications are malicious in nature or misconfigured people are able to use them to access files on the users system.

You can find more information and a copy of the sample letter that was sent out by the FTC using the link below.

FTC Press Release

user Posted by Mike Wright

| More


The US military has lifted its outright ban on portable media devices. The ban was put into place after it was found that users had used devices to install Malware on government computer systems. There is a great video about this from 60 minutes that can be viewed using the link below.

The new policy for using portable media devices are quite strict, as they should be. The devices can only be used for mission critical situations and they all must go through inspection and be sanitized before they can be used. They must also be government purchased and government owned with a strict ban on personally owned devices. There is no mention of the technical controls being implemented but without some technical means to enforce these policies it will be hard to prevent abuse.

Similar requirements were written into my organizations policy; organization purchased, organization owned, authorized users, authorized work, and absolutely no personally owned devices. But as I stated above, without a technical mechanism to scan, audit, report, and enforce the policy people are basically on their word.

CBS News “Sabotaging The System”

Information Week

user Posted by Mike Wright

| More


It was recently reported that during the 2010 Winter Olympics the US Department of Homeland Security will be monitoring Twitter and other social networking websites. Allegedly they are looking for terrorist related posts and comments. It seems logical that the Olympics or any gathering of that size would be a significant target for terrorist activity. It also seems logical that these types of sites could hold vital information that could be used to detect, deter, and defend against such activity. What does not seem logical is the fact that people assume that postings are not already being monitored by government organizations. But thank you for the reminder ABC.

ABC News

user Posted by Mike Wright

| More


Researchers are Carnegie Mellon University have discovered that your Social Security Number is not just some random number as many assume. In fact, many of us already knew that the first three numbers identified the State of issue. The second two numbers are a “group number”. But as it turns out the last four numbers may be guessed with a relative high degree of accuracy. The scary part of this is that all of the information needed to build their algorithm is freely available on the internet, thank you Federal Government!

Gives a new spin on “we are from the Government and are here to help you.”

Read more here (Source link broken as of 3/18/2010, sorry)

Update 7/10/2009

Nice story on this topic here. Network World

user Posted by Mike Wright

| More


Terry Childs, whose most notable claim to fame was bringing down the City/County of San Francisco’s network, will be standing trial for his stunts. In a nutshell, he locked down the cities FiberWAN network by changing, and then not disclosing, the password on one of their main routers. It is reported that about 60% of the cities network traffic passes through this router causing untold losses.

Source: The Register

user Posted by Mike Wright

| More


I love the Onion... Of course this is a joke but it's fun :)

Link to Pic

user Posted by Mike Wright

| More


I don’t even need to spend the effort writing about this because Martin McKeay hit the nail square on the head (link below). I do want to add though; Where are the fact checkers? Has this information been validated or is the media and the web users just letting it run like wildfire? And, is this just a fabricated story meant to cause damage to the McCain/Palin ticket?

My thoughts… and of course, I could be wrong… I think this will turn out to be a fraud and the screen shots that everyone is seeing and ranting so much about will be discovered to be fabricated and completely false. Can we say "Photoshop"?

Martin’s Blog

Updates:

9/18/2008: I still stand by my thought that this is going to turn out to be a fraud... Let’s assume, granted lets agree that YES in fact her email accounts were hacked, that part I am not disagreeing with. Let’s also agree that some (a single so far) emails are valid and verifiable. This much I believe to be fact. (Passwords suck) There is no way that anyone with half a brain cell would assume that using a personal (Yahoo) email account would believe that they could do so for government business and keep if off the radar. IF this was the case, her emails to "The Govenator" would have been sent to T-1000@yahoo.com.... NOT his state of California email account. It is basic Government employee training (right down to the guy who changes the mints in the bottom of the urinals) that you do not do anything on the systems that you don’t want to read about in tomorrow’s news paper. Non-repudiation Look it up. In addition to that: The email accounts have been deleted from Yahoo… If that is also fact it would be destruction of evidence, a serious crime, which I also doubt her or Yahoo would be willing to so publically commit. My thoughts are still, Photoshop between the lines. Here is another great link with credit to Martin McKeay

9/23/2008: Busted

user Posted by Mike Wright

| More