Wednesday

,

Sensitive files tied to a US military project were leaked by a multi-billion dollar firm once described as the world’s most profitable spy operation, Gizmodo has confirmed.

A cache of more than 60,000 files were discovered last week on a publicly accessible Amazon server, including passwords to a US government system containing sensitive information, and the security credentials of a lead senior engineer at Booz Allen Hamilton, one of the nation’s top intelligence and defense contractors. What’s more, the roughly 28GB of data contained at least a half dozen unencrypted passwords belonging to government contractors with Top Secret Facility Clearance.

The exposed credentials could potentially grant their holders further access to repositories housing similarly sensitive government data.

Countless references are made in the leaked files to the US National Geospatial-Intelligence Agency (NGA), which in March awarded Booz Allen an $86 million defense contract (around £66.8m). Often referred to as the Pentagon’s “mapmakers,” the combat support agency works alongside the Central Intelligence Agency, the National Reconnaissance Office, and the Defense Intelligence Agency to collect and analyse geospatial data gathered by spy satellites and aerial drones.

The NGA on Tuesday confirmed the leak to Gizmodo while stressing that no classified information had been disclosed. “NGA takes the potential disclosure of sensitive but unclassified information seriously and immediately revoked the affected credentials,” an agency spokesperson said. The Amazon server from which the data was leaked was “not directly connected to classified networks,” the spokesperson noted.

Some of the passwords are encrypted using a hash protocol that’s difficult but not impossible to crack. (UpGuard)

UpGuard cyber risk analyst Chris Vickery discovered the Booz Allen server last week while at his Santa Rosa home running a scan for publicly accessible s3 buckets (what Amazon calls its cloud storage devices). At first there was no reason to suspect it contained sensitive military data. Typically, US government servers hosted by Amazon are segregated into what’s called the GovCloud — a “gated community” protected by advanced cryptography and physical security. Instead, the Booz Allen bucket was found in region “US-East-1,” chiefly comprised of public and commercial data.

Yet the files bore some hallmarks of a government project. First, Vickery spotted the public and private SSH keys of a Booz Allen employee, identified by his LinkedIn page as a lead senior engineer in Virginia — also home to the NGA’s Fort Belvoir campus. “Exposing a private key belonging to a Booz Allen IT engineer is potentially catastrophic for malicious intrusion possibilities,”he said.

SSH keys employ what’s called public-key cryptography and challenge-response authentication. Essentially, Booz Allen stores sensitive data in the cloud, and before the engineer can access it, his private key must pair successfully with a public key on Booz Allen’s server. This protocol only really works, however, so long as the employee’s private key remains a secret.

The public and private SSH keys for a Booz Allen engineer were discovered in the dataset. (UpGuard)

“Booz Allen takes any allegation of a data breach very seriously, and promptly began an investigation into the accessibility of certain security keys in a cloud environment,” a Booz Allen spokesman told Gizmodo on Tuesday. “We secured those keys, and are continuing with a detailed forensic investigation. As of now, we have found no evidence that any classified information has been compromised as a result of this matter.”

Mark Zaid, a Washington lawyer who specialises in national security cases, said the incident is likely to dredge up bad memories of the company. “The first thing that jumps to mind,” he said, is “Oh, no. It’s Booz Allen again.”

Zaid was referring to Edward Snowden, the former NSA contractor who worked for Booz Allen when he fled to Hong Kong in 2013 with a trove of classified material. Another of the firm’s employees, Harold Martin III, was arrested last year and charged under the Espionage Act after federal agents discovered over 50 terabytes of classified data in his residence, the trunk of his car and in an unlocked outdoor shed.

“Obviously, Booz Allen is a large company and a well-respected defense contractor,” Zaid added. “And none of these cases are necessarily related to one another. But it still raises some real serious concerns about what’s going on with Booz Allen’s security protocols.”

In addition to keys, the Booz Allen server contained master credentials to a datacenter operating system — and others used to access the GEOAxIS authentication portal, a protected Pentagon system that usually requires an ID card and special computer to use. Yet another file contained the login credentials of a separate Amazon bucket, the contents of which remain a mystery; there’s no way to verify the contents legally since the bucket is secured by a password, and thus not open to the public.

Moreover, a categorisation script found in one of the Booz Allen files indicates the system under construction is at least designed to handle classified information. And while Vickery didn’t realise its significance at the time, the leaked files also appear connected to a third server he found open last month.

In April, he discovered an Amazon bucket with no password containing a review of what he now believes is the same NGA system. An “application security risk assessment,” carried out using HP software called Fortify, detailed 3039 issues within the program’s source code (only 7 were described as critical). “I’m reading the report,” he says, “and the code snippets line up with code from the second bucket.”

The mission of UpGuard’s Cyber Risk Team is to locate and secure leaked sensitive records, so Vickery’s first email on Wednesday was to Joe Mahaffee, Booz Allen’s chief information security officer. But after received no immediate response, he went directly the agency. “I emailed the NGA at 10:33am on Thursday. Public access to the leak was cut off nine minutes later,” he said.

A reference to classified material from a leaked configuration file. (UpGuard)

“You can have fantastic cybersecurity, but if you’re using IT systems to share information with a partner whose cybersecurity isn’t up to snuff, then your protection measures don’t mean very much,” says Paulo Shakarian, a cybersecurity fellow at the Washington think-tank New America. The big unresolved question, he says, is whether Booz Allen had proper security protocols in place for its contractors working on the NGA project. “And likewise, what has NGA done to ensure that the proper protective measures were in place.”

NGA informed Gizmodo that it was still evaluating the incident and had yet to determine a proper course of action. “It’s important to note that a misconfiguration, properly reported and addressed, does not disqualify industry partners from doing business with NGA,” the agency said, adding that it reserves the right to “address any violations or patterns of non-compliance appropriately.”

On Friday, UpGuard was contacted by a government agency and asked to preserve all of its records related to Vickery’s find. The company said it is abiding by a request not to reveal the agency’s name at this time.

[UpGuard Cyber Risk Team]

Source link

,

The alleged Russian hacker, who was arrested by the Czech police in Prague last October on suspicion of massive 2012 data breach at LinkedIn, can be extradited to either the United States or Russia, a Czech court ruled on Tuesday.

Yevgeniy Aleksandrovich Nikulin, a 29-years-old Russian national, is accused of allegedly hacking not just LinkedIn, but also the online cloud storage platform Dropbox, and now-defunct social-networking company Formspring.

However, he has repeatedly denied all accusations.

Nikulin was arrested in Prague on October 5 by the Czech police after Interpol issued an international arrest warrant against him.

Nikulin appeared at a court hearing held inside a high-security prison in Prague on Tuesday and emaciated after eight months in solitary confinement.

The court ruling, pending appeals, left the final decision in the hands of Czech Justice Minister Robert Pelikan, who can approve extradition to one of the countries and block the other.

The United States has requested Nikulin extradition for carrying out hacking attacks and stealing information from several American social networking companies, including LinkedIn, Dropbox, and Formspring, between March 2012 to July 2012.

However, Russia, where Nikulin is facing a lesser charge, has requested his extradition on a separate cyber theft charge of stealing $3,450 via the Internet in 2009.

“Both [case] documents are very, very sufficient for reasonable suspicion that [the offenses] took place and that there is a reason to press charges,” the judge said.

Hacker Claims FBI Pressured Him to Confess to US Election Hacks

Nikulin’s arrest last October came three days before the United States officially accused Russia of hacking the Democratic National Committee (DNC) and interfering in the 2016 presidential election.

Nikulin’s lawyer says the case is a set-up, indicating that his arrest may have deeper inclinations than over the cyber attacks against American firms.

The Guardian reported Nikulin was interrogated in Prague, where he currently remains imprisoned, by FBI special agent Jeffrey Miller.

Nikulin wrote in a letter from prison that during his interrogation, Miller reportedly brought up the US election hacking and claimed that the FBI agent pressured him to admit to the DNC hack and promised him good treatment if he accepted to cooperate.

Nikulin wrote in the letter that he rejected the offer. His lawyer indicated that Nikulin was not a hacker, but just a victim of an FBI plot.

“Do you really imagine that a high-ranking FBI agent is going to travel all the way from San Francisco just to read this guy his rights?,” Nikulin lawyer said.

Mark Galeotti, a senior security researcher at the Institute of International Relations Prague, also showed his concern about an FBI agent traveling to another country to extradite a hacker.

“An FBI agent traveling from the US to a third country as part of an extradition request is extremely unusual and highlights that the case is seen as significant,” Galeotti said, as quoted by the Guardian.

Nikulin’s Russian lawyer stated that his client’s life revolved around buying and selling luxury cars, adding that Nikulin was “useless with computers” and capable of checking his email and no more and, far from being a super-hacker who can hack big firms.

Tuesday’s court hearing was held in a tiny room inside the prison for security reasons, to which Nikulin’s Czech lawyer said: “In all my 25 years as a lawyer, I don’t remember any cases being tried inside the prison, including serial killers or organized crime cases.

Now, the final decision is in the hands of the Czech Justice Minister Robert Pelikan, who is slated to decide where Nikulin will be extradited: The United States, where he can face a “disproportionately harsh” sentence of 54 years behind bars, or Russia, where he faces a lesser charge of cyber theft.

Source link

,

The joke in the smartphone space in years past was how screens just kept getting bigger — stretching palms and making you look ridiculous when held up to the head to talk.

How times change. Talking into phones? Why, how 2005 of you! Phablets have long been the new normal as the telephone icon lost out in the war to capture our attention via finger-flicking touchscreen fun — losing out to all the other apps offering more visual ways to be entertained and/or communicate, be it by text, selfie lens or silly GIF.

Apple, a laggard at inflating smartphone screen size, has remained something of a reluctant participant in this ‘bigger is better’ logic. Evident in its tortured sloganizing for its very first phablet, the 5.5-inch iPhone 6 Plus — which it launched in 2014 and stuck next to the words: “bigger than bigger”. The less said about which the better.

The iPhone-maker’s reluctance to participate in the pant-stretching smartphone craze has also included an attempt to buck the trend, by reviving — in 2016 — the 4-inch form iPhone factor, and putting a bit more heft under the hood, aka the iPhone SE.

It’s continued to range this ‘littlest iPhone’ alongside its 4.7-inch ‘standard’ flagship and 5.5-inch top of the range phablet. But analyst projections suggest declining demand for SE-sized smartphones in the coming years — as phablets are set to take a greater and greater share of the market.

tl;dr the phablet is now the smartphone fixture.

Analyst IDC put out its latest smartphone market projections yesterday, and looking ahead to 2021 it sees shipments of devices with screens of 4-inches (up to less than 5-inches) losing out to those with larger panes. It’s projecting 314.2M million devices in this iPhone SE size category will ship worldwide this year — shrinking to 223.3M by 2021.

Meanwhile, it’s expecting the vast bulk of the smartphone market to become almost equally divided between devices with screens of between 5-inches and less than 5.5-inches, and those with screens of 5.5-inches and under 6-inches — expecting shipments to grow from 593.3M and 558.7M this year respectively, to 731.4M and 749.3M by 2021.

Which means phablets or phones verging on phablet territory really are the future. Or the ‘phuture’ if you prefer (hattip to my colleague Jon Russell for that quip).

As with most inflationary issues, the line between the smartphone and the phablet has shifted over time as phones have swelled in size — so while a phablet used to start around the 5-inch mark (or even a little less), it’s now more typically 5.5-inches+.

So it’s possible that by 2021 it may have been pushed out a bit further still.

That said, IDC isn’t expecting much market change for the very biggest smartphones (of between 6-inches to under 7-inches). It’s expecting shipments in this whopper category to be 32M this year — and to have grown only slightly to 37.4M by 2021.

So perhaps more likely: a smartphone will simply become synonymous with a device that has a screen size of between 5 and 6 inches. And the word ‘phablet’ will end up being reserved for the minority ‘up to seven inches’ proper whopper category.

Which just goes to show that winning isn’t always what it’s cracked up to be if you’re a weird-sounding word that nobody liked in the first place.

When it comes to smartphone displays, size certainly matters, and the smallest displays (of less than 4 inches look set to disappear entirely). But being the biggest isn’t the best, either — effectively over six inches you have a clumsily large phone and/or a small and therefore not very useful tablet. It’s all about finding the sweet-spot based on device utility: i.e. visual, sensory computing combined with portability.

And that smartphone screen size sweet-spot looks firmly settled at between 5 and 6 inches for the foreseeable future. At least until the computing paradigm shifts again — and some kind of socially acceptable wearable manages to lift everyone’s eyes off attention-sucking glass slabs with an augmented vista of the real world instead. At least that’s one theory.

Until then, we’d like between five and six inches of touchscreen glass please.

Featured Image: Bloomberg/Getty Images

Source link

,

The US military scored an important success in a test of its oft-criticised missile-defence programme, destroying a mock warhead over the Pacific Ocean with an interceptor that is key to protecting US territory from a North Korean attack.

Vice Admiral Jim Syring, director of the Pentagon agency in charge of developing the missile-defence system, called the test result “an incredible accomplishment” and a critical milestone for a programme hampered by setbacks over the years.

“This system is vitally important to the defence of our homeland, and this test demonstrates that we have a capable, credible deterrent against a very real threat,” Syring said in a statement announcing the test result.

Despite the success, the $244m test didn’t confirm that under wartime conditions the US could intercept an intercontinental-range missile fired by North Korea.

OPINION: Is war coming to North Korea?

Pyongyang is understood to be moving closer to the capability of putting a nuclear warhead on such an ICBM and could develop decoys sophisticated enough to trick an interceptor into missing the real warhead.

The most recent intercept test, in June 2014, was successful, but the longer track record is spotty. Since the system was declared ready for potential combat use in 2004, only four of nine intercept attempts have been successful.

Japan threatens to join US in ‘concrete action’ after N Korea missile test

Failure on Tuesday could have deepened concern about a programme that, according to one estimate, has so far cost more than $40bn.

John Tierney, executive director of the Center for Arms Control and Non-Proliferation, told Al Jazeera the missile programme – despite its cost – has a success record of less than 50 percent.

“Unfortunately, we need to be aware of a false sense of security here. This programme is nowhere near ready to be relied upon against North Korea or anybody else. This is a baby step,” Tierney said.  

Pentagon spokesman Navy Captain Jeff Davis had said the test was not timed specifically in response to tensions with Pyongyang but “in a broad sense, North Korea is one of the reasons why we have this capability”.

North Korea says its nuclear and missile programmes are a defence against perceived US military threats.

Its accelerating missile development has complicated Pentagon calculations, most recently by incorporating solid-fuel technology into its rockets. The step would mean even less launch warning time for the United States. Liquid fuel is less stable and rockets using it have to be fueled in the field, a process that takes longer and can be detected by satellites.

Underscoring its uninterrupted efforts, North Korea on Monday fired a short-range ballistic missile that landed in Japan’s maritime economic zone.

In Tuesday’s US test, the Pentagon’s Missile Defense Agency launched an interceptor rocket from an underground silo at Vandenberg Air Force Base in California. The target was an intercontinental-range missile fired from a test range on Kwajalein Atoll in the Pacific.

According to the plan, two-metre-long “kill vehicle” released from atop the interceptor zeroed in on the ICBM-like target’s mock warhead outside Earth’s atmosphere and obliterated it by sheer force of impact, the Pentagon said.

READ MORE: North Korea fires missile in third test in three weeks

The target was a custom-made missile meant to simulate an ICBM, meaning it flew faster than missiles used in previous intercept tests, according to Christopher Johnson, the Missile Defense Agency’s spokesman. It was not a mock-up of an actual North Korean ICBM, and details of its exact capabilities weren’t made public.

Officially known as the Ground-based Midcourse Defense system, the Pentagon likens the defensive tactic to hitting a bullet with a bullet. With congressional support, the Pentagon is increasing by the end of this year the number of deployed interceptors, based in California and Alaska, to 44 from the current total of 36.

Laura Grego, senior scientist at the Union of Concerned Scientists, which has criticised the missile defence programme, called the interceptor an “advanced prototype”, meaning it is not fully matured technologically.

“Overall,” she wrote in an analysis prior to the test, the military “is not even close to demonstrating that the system works in a real-world setting”.

Will the US try to denuclearise North Korea by force?- Inside Story

Source: Al Jazeera and news agencies

Source link

Tuesday

,

UN Secretary-General Antonio Guterres urged the world to raise its ambition in implementing the Paris climate agreement as the United States weighed pulling out of the landmark emissions-cutting deal.    

Making his first address on climate since taking the UN helm five months ago, Guterres said it was “absolutely essential” the world implements the 2015 agreement “with increased ambition”.    

The United States is among the 147 countries and parties that have ratified the agreement, but President Donald Trump has voiced concerns the deal signed by the previous US administration could harm the US economy.    

READ MORE: Trump moves to roll back Obama climate policies

“We believe that it would be important for the US not to leave the Paris agreement,” Guterres said in response to a question following his address at New York University.    

“But even if the government decides to leave the Paris agreement, it’s very important for US society as a whole – the cities, the states, the companies, the businesses – to remain engaged. It is very clear that governments aren’t everything.”

G7 summit ends deadlocked on climate change

At a summit meeting of the G7 group of leading economies over the weekend, Trump refused to join the other six leaders in pledging to implement the Paris accord and said he would announce the US position this week.    

Guterres said the United Nations was engaged with the US administration and Congress to try to convince them to abide by the deal.    

His appeal suggested if the United States – the world’s biggest carbon emitter after China – were to quit the accord, the onus would be on other key players such as China, India, and the European Union to do more to fight global warming.    

The Paris agreement’s commitment to curb carbon emissions and limit temperature rise to well below 2 degrees Celsius and as close as possible to 1.5 degrees “do not nearly go far enough”, Guterres said.

“So we must do our utmost to increase ambition and action until we can bend the emissions curve and slow down global warming,” he said. 

Betting on green economy 

Describing the agreement as a “remarkable moment in the history of humankind”, the UN chief stressed that private corporations – including oil and gas companies – were not awaiting government policy and joining the green economy.    

“Some may seek to portray the response to climate change as a fundamental threat to the economy,” said Guterres. “Yet what we are witnessing in these early years of a systemic response is the opposite.    

“Those who fail to bet on the green economy will be living in a grey future,” he warned. “On the other hand, those who embrace green technologies will set the gold standard for economic leadership in the 21st century.”

READ MORE: The Paris climate agreement and why it matters

Guterres pointed to growth in the clean energy sector, saying solar power grew 50 percent last year and that more new jobs were being created in renewable energy than in oil and gas.    

He argued climate action was a sound security policy, warning of mass displacement from natural disasters or from refugees whose lands become unlivable.    

The UN chief vowed to mobilise governments, the energy industry, investors, and civil society to “raise the bar on climate action”.    

As a first step, Guterres said he would press for ratification of an agreement reached last year on phasing out hydrofluorocarbons (HFCs), a major source of greenhouse gas emissions.    

Guterres announced plans for a summit in 2019 to review progress in implementing the Paris agreement.

Can people power change political anti-science agenda? – Inside Story

Source: AFP news agency

Source link

Follow Us @soratemplates