The Internet - The first Worldwide Tool of Unification ("The End of History")

" ... Now I give you something that few think about: What do you think the Internet is all about, historically? Citizens of all the countries on Earth can talk to one another without electronic borders. The young people of those nations can all see each other, talk to each other, and express opinions. No matter what the country does to suppress it, they're doing it anyway. They are putting together a network of consciousness, of oneness, a multicultural consciousness. It's here to stay. It's part of the new energy. The young people know it and are leading the way.... "

" ... I gave you a prophecy more than 10 years ago. I told you there would come a day when everyone could talk to everyone and, therefore, there could be no conspiracy. For conspiracy depends on separation and secrecy - something hiding in the dark that only a few know about. Seen the news lately? What is happening? Could it be that there is a new paradigm happening that seems to go against history?... " Read More …. "The End of History"- Nov 20, 2010 (Kryon channelled by Lee Carroll)

"Recalibration of Free Choice"– Mar 3, 2012 (Kryon Channelling by Lee Carroll) - (Subjects: (Old) Souls, Midpoint on 21-12-2012, Shift of Human Consciousness, Black & White vs. Color, 1 - Spirituality (Religions) shifting, Loose a Pope “soon”, 2 - Humans will change react to drama, 3 - Civilizations/Population on Earth, 4 - Alternate energy sources (Geothermal, Tidal (Paddle wheels), Wind), 5 – Financials Institutes/concepts will change (Integrity – Ethical) , 6 - News/Media/TV to change, 7 – Big Pharmaceutical company will collapse “soon”, (Keep people sick), (Integrity – Ethical) 8 – Wars will be over on Earth, Global Unity, … etc.) - (Text version)

“…5 - Integrity That May Surprise…

Have you seen innovation and invention in the past decade that required thinking out of the box of an old reality? Indeed, you have. I can't tell you what's coming, because you haven't thought of it yet! But the potentials of it are looming large. Let me give you an example, Let us say that 20 years ago, you predicted that there would be something called the Internet on a device you don't really have yet using technology that you can't imagine. You will have full libraries, buildings filled with books, in your hand - a worldwide encyclopedia of everything knowable, with the ability to look it up instantly! Not only that, but that look-up service isn't going to cost a penny! You can call friends and see them on a video screen, and it won't cost a penny! No matter how long you use this service and to what depth you use it, the service itself will be free.

Now, anyone listening to you back then would perhaps have said, "Even if we can believe the technological part, which we think is impossible, everything costs something. There has to be a charge for it! Otherwise, how would they stay in business?" The answer is this: With new invention comes new paradigms of business. You don't know what you don't know, so don't decide in advance what you think is coming based on an old energy world. ..."
(Subjects: Who/What is Kryon ?, Egypt Uprising, Iran/Persia Uprising, Peace in Middle East without Israel actively involved, Muhammad, "Conceptual" Youth Revolution, "Conceptual" Managed Business, Internet, Social Media, News Media, Google, Bankers, Global Unity,..... etc.)


German anti-hate speech group counters Facebook trolls

German anti-hate speech group counters Facebook trolls
Logo No Hate Speech Movement

Bundestag passes law to fine social media companies for not deleting hate speech

Honouring computing’s 1843 visionary, Lady Ada Lovelace. (Design of doodle by Kevin Laughlin)
Showing posts with label IT Audits. Show all posts
Showing posts with label IT Audits. Show all posts

Thursday, March 7, 2013

Furious NatWest customers pledge to leave bank following latest IT crash

Customers unable to withdraw cash, pay for goods or do telephone or online banking

guardian.co.uk, Lisa Bachelor, Thursday 7 March 2013

Helpful banking? NatWest has declined to elaborate on the cause of its
latest IT woe. Photograph: Bloomberg via Getty Images

NatWest is facing a growing backlash from angry customers who claim they will shut their accounts after another IT problem at the bank left millions without access to their money on Wednesday night.

Customers were unable to withdraw cash, pay for goods and services, or carry out telephone and online banking on Wednesday 6 March and into the early hours of Thursday 7 March after an apparent IT error caused the bank's systems to crash.

NatWest said in a statement it was "disappointed" with the disruption but that the problem, which it declined to elaborate on, had been resolved.

However, some of its customers were still reporting problems this morning. At 9am on Thursday Daniel Adkins tweeted: "Still can't access my online banking. #Natwest statement says everything was fixed at 1am."

Another customer, stigbeater, tweeted Natwest to ask: "When will online banking be back on? Try to login = ssl connection error!"

It is not the first time the bank has been hit by IT problems. In June 2012 a botched software upgrade at the Royal Bank of Scotland group meant millions of NatWest, RBS and Ulster bank customers were left without access to their money for more than a week in some cases.

It now appears the latest technical problem has proved the tipping point for many RBS customers, who took to Twitter on Thursday to say this time they would shut their accounts.

Phil, who tweets as @wheatear9 said: "Why oh why have I stayed with #naffwest I should know better and will depart." Andrew Bissett, meanwhile, tweeted: "Disgraceful service. Am moving my banking to Santander! You cannot be trusted with our money!!!"

Anthony Gray said: "No money on my Oyster card last night. No way of getting money out. Had to walk home. Will now spend today changing banks."

Following the previous NatWest computer meltdown, and other banking problems including Barclays Libor-rigging scandal, millions of people switched their accounts to co-ops, building societies and credit unions.

The Co-op saw applications for its accounts increase by 25% in the week following the last NatWest IT debacle; Charity Bank, which lends its savers' money to charities, saw a 200% increase in depositors; the Ecology Bank had a 266% jump in applications; and Triodos, a Bristol-based "sustainable bank", a 51% increase.

Speaking about NatWest's latest problems, Laura Willoughby of the campaign group Move your Money said: "This is like groundhog day. Could RBS make things any worse for their already battered and bruised customers?

"What is for certain is that RBS customers already seething from news of Libor fines, bonuses and last years meltdown will not be as forgiving a second time around."

A spokeswoman for RBS was unable to say what caused the latest problems and whether or not affected customers would be compensated. However, the bank does not appear to be offering any additional assistance to customers. Those who are tweeting it to complain of fees incurred because of failed direct debits are being told by the bank to "speak to the charges team".

Related Article:


Saturday, June 23, 2012

NatWest 'glitch' leaves victims without pay

Bank says it does not know when systems will be running normally again after IT meltdown

guardian.co.uk, Hilary Osborne and Lisa Bachelor, Friday 22 June 2012

NatWest’s IT meltdown is also having a serious impact on those who do
not bank with it. Photograph: Chris Ratcliffe/Rex Features

Millions of NatWest bank customers have been hit by one of the industry's worst ever computer breakdowns, leaving at least one family forced out of their home and employers unable to make monthly salary payments.

As the crisis moved into its fourth day, the bank, which is owned by the taxpayer-backed Royal Bank of Scotland group, said it did not know when systems would be running normally again, but was confident it had identified the source of the problem, a "technical glitch".

Irate customers told the Guardian they were unable to see how much money was in their accounts and whether bills had been paid. The bank's IT meltdown is also having a serious impact on those who do not bank with it. First-time buyers Mike Johnson and his wife, Laura, were thrown out of the house they thought they had bought on Thursday evening because the mortgage payment did not go through from their solicitor's NatWest account as expected.

"The sales rep turned up that evening and asked us to leave until she could be sure the money was coming. Laura is 20 weeks pregnant and we had to pack our bags then and there, and we are now living with our sister-in-law until this is sorted out," Johnson said.

"NatWest say they are going to compensate people but how are people like us, who do not even bank with them, going to be compensated?"

Another Guardian reader caught up in the chaos said his bank balance was only showing purchases made two days ago and he had no idea what had gone in and out of his account since.

"How can I spend money for food if I have no idea how much money I have left in my account? I have some direct debits due – have they been deducted? Most importantly, have I been paid? When will I know?"

NatWest said the problem emerged as it tried to run payments on Tuesday night. By Friday afternoon it had located the source of the problem, but was still attempting to fix it. A spokesman said: "The problem is one of a technical nature within the bank, not a result of an attack.

"We definitely know what the original problem was and it is being fixed." He could not say when systems would start running normally.

The bank, which has 7.5 million UK personal banking customers and almost 1 million business customers, kept 1,000 branches open until 7pm for a second day running on Friday, and will extend opening hours over the weekend to deal with inquiries. Some branches will stay open longer on Saturday and open on Sunday between 9am and midday. It said customers may be able to withdraw money at branches even if payments into accounts were not showing, but this was being arranged on an individual basis.

However, some have criticised the way that the bank has dealt with the problem.

On the Guardian website one customer wrote: "When I checked with NatWest they said they can't guarantee that even with a high balance that our direct debits will definitely get paid out and it would be up to us to have to claim back any bank charges incurred by direct debits being re-presented. Seems shambolic."

Another said: "It's disgraceful and not the first time for NatWest … feel for the people whose wages not arrived – we can help ours but others not so fortunate. Think we will be looking to move banks!"

Jonathan Hemus, director of Insignia, a specialist in reputation management and crisis communications, said the company should have been prepared to cope with a major IT outage. "NatWest now needs to show that it cares about what happened. While banks can't always be 100% sure about what's going on, they need to demonstrate they're on top of things and acting in an organised way," he said.

"If they don't people can lose confidence in them. It's clearly not helpful that NatWest has taken so long to sort out the problem. The more you can do and the quicker you can do it, the less long-term harm to your reputation."

The bank said it would "ensure no customers will be permanently out of pocket" as a result of missed payments, but it was still not clear what would happen to customers of other banks caught up in the crisis. Some employees expecting their pay day reported being down to their last few pence and said they did not know how they would cope over the weekend if the payments did not go through.

One said: "My employer banks with NatWest. Salaries should have been paid yesterday – still no sign. About a third of my salary due to go out in direct debits in the next few days."

Under Financial Services Association rules NatWest is responsible for any charges customers incur, or interest they need to pay as a result of the bank's error, but there is no liability for consequential losses and consumers who do not bank with NatWest may have trouble gaining compensation.

Lord Oakeshott, the former Liberal Treasury spokesman, said the bank should compensate all customers affected by the problems. "Millions of hard pressed NatWest customers face a bleak weekend without their pay or benefits cheque – with times so hard they have no cushion," he said. "The bank stings them for £30 the moment they go a penny over the line, now it's payback time and they must pay £30 compensation to anyone who's had to wait two days for their cash. When you're really hard up blocked money pipes are as bad as blocked water pipes."


RBS said it "disagrees" with Moody's move

Friday, May 4, 2012

Hackers have breached top secret MoD systems, cyber-security chief admits

Major General Jonathan Shaw says 'it was a surprise to people quite how vulnerable we are'

guardian.co.uk, Nick Hopkins, Thursday 3 May 2012



Shaw said the UK had to develop an array of its own cyber-weapons because it was impossible to create entirely secure computer systems. Photograph: Daniel Law/PA

Computer hackers have managed to breach some of the top secret systems within the Ministry of Defence, the military's head of cyber-security has revealed.

Major General Jonathan Shaw told the Guardian the number of successful attacks was hard to quantify but they had added urgency to efforts to beef up protection around the MoD's networks.

"The number of serious incidents is quite small, but it is there," he said. "And those are the ones we know about. The likelihood is there are problems in there we don't know about."

Government computer systems come under daily attack, but though Shaw would not say how or by whom, this is the first admission that the MoD's own systems have been breached.

The Serious Organised Crime Agency, took its website offline on Wednesday night after becoming the target of a cyber-attack. A spokesman said the attack did not pose a security risk to the organisation.

Shaw, a veteran of the Falklands and Iraq wars, also said the MoD had to be prepared to embrace unconventional and "wacky" ideas if the military wanted to catch up with, and then stay ahead of, rivals in the cybersphere. Getting "kids on the street" to help the military was vital, he said.

"My generation  … we are far too old for this; it is not what we have grown up with. Our natural recourse is to reach for a pen and paper. And although we can set up structures, we really need to be on listening mode for this one."

He added: "If we want to work the response, if we want to know really what is happening, we really have to listen to the young kids out in the street. They are telling us what is happening out there.

"That will pose a real challenge to us. This thing is moving too fast. The only people who spot what is happening are people at the coal face and that is the young kids. We have to listen to them and they have to talk to us."

A former director of UK special forces, Shaw, 54, said he thought the military could learn a trick or two from firms such as Facebook.

The company has a "white hat" programme in which hackers are paid rewards for informing them when they have found a security vulnerability.

Nine people in the UK have been paid a total of $11,000 (£6,785) for working with Facebook. Shaw said this was the kind of "waacky idea we need to bring in".

Shaw has spent the last year reviewing the MoD's approach to cyber-security, and the kind of cyber-capability the military will need in the future.

He says next year's MoD budget is expected to include new money for cyber-defence – an acknowledgment that even during a time of redundancies and squeezed budgets, this is now a priority.

The general said the MoD wasn't "doing badly … but we could do a hell of a lot better. We will get there, but we will have to do it fast. I think it was a surprise to people this year quite how vulnerable we are, which is why the measures have survived so long in the [budget] because people have become aware of the vulnerabilities and are taking them seriously."

China and Russia have been accused of being behind most of the sophisticated cyber-attacks, with state-sponsored hackers targeting military secrets from western governments, or intellectual property from British and American defence firms.

Shaw refused to point the finger at any nation, but admitted the UK was "trying to engage the Chinese on rules of the road in cyberspace", pressing the argument that new international treaties are not necessary to stop this kind of theft and espionage.

Shaw said the number of attacks was "still on an upward curve … and the pace of change is unrelenting".

In his last interview before retiring, Shaw said the UK had to develop an array of its own cyber-weapons because it was impossible to create entirely secure computer systems.

"It is quite right to say that pure defence, building firewalls, will not keep the enemy out. They might be inside already … there is no such thing as total security. You have to learn to live with certain insecurities.

"One needs to engage in internal defence and be quite aggressive about it. And if you are going to manoeuvre in cyberspace, that is something that obviously involves action across the spectrum."

Shaw said he intended to "mainstream" cyber-capabilities across the MoD by 2015. This included ensuring military commanders had a range of cyber-options to use from a "golf bag" of weapons systems.

But he thought cyber-weapons would complement rather than replace more conventional weapons.

"As new capabilities come on the block, you reassess whether you need the old ones, whether they are complimentary or duplicatory.

"People have asked me whether cyber-weapons will make conventional weapons redundant. Absolutely not. A hard bomb is actually quite a good cyber-weapon because it can take out a broadcasting station, take out a server."

The military top brass, he said, had been the "hardest to convince" about the cyber-threat, because high-ranking officers tend to be set in their ways. "We are the wrong guys to deal with this."

Shaw said it still surprised him that the MoD's headquarters in Whitehall "is the only building, main defence security establishment, where you don't leave your mobile phones and Ipad in a box outside your office … people's personal behaviours are not good enough. When we look at cyber-security in the MoD, we are looking at preserving intellectual property and our networks and stopping people spying on us.

"The real challenge is how we secure our supply chains. We are dependent on industry for our technological edge … and preserving that intellectual property is absolutely vital."

He added: "Cyber implies something technical. To the average person in the street, cyber means it is someone else's problem. But it is everyone's problem. We can't just leave it to the techies."

An MoD spokesman said: "The MoD takes all possible precautions to defend our system from attack from both unsolicited, for example 'spam' email, and targeted sources. It would be both misleading and naïve to assume that any system is 100% secure against all possible threats which is why we take additional steps to detect suspicious activity within our own systems.

"We also ensure that our most sensitive networks are not connected to the internet and have additional physical and technical measures in place to defend them."

Friday, March 23, 2012

Most 2011 cyberattacks were avoidable, Verizon says

Despite all the hype about sophisticated attack methods, 97% could have been stopped using fundamental precautions

Computerworld, by Jaikumar Vijayan, March 22, 2012

Computerworld - Despite rising concern that cyberattacks are becoming increasingly sophisticated, hackers used relatively simple methods 97% of data breaches in 2011, according to a report compiled by Verizon.

The annual Verizon report on data breaches, released Thursday, also found that in a vast majority of attacks (80%), hackers hit victims of opportunity rather than companies they sought out.

The findings suggest that while companies are spending increasing sums of money on sophisticated new security controls, they are also continuing to overlook fundamental security precautions.

The conclusions in the Verizon report are based on the investigations into more than 850 data breaches. The report was compiled with the help of the U.S. Secret Service and law enforcement agencies in the United Kingdom, The Netherlands, Ireland and Australia, Verizon said.

Verizon said it found that attacks by so-called "hactivist" groups such as Anonymous for the first time compromised more breached records -- more than 100 million -- than the number of attacks by hackers specifically looking to steal financial or personal data.

Data breach victims and security vendors generally tend to describe attacks as highly sophisticated and involving a great deal of expertise on the part of hackers.

The Verizon report though shows a far more mundane reality.

Most of the breaches didn't require hackers to possess special skills or resources, or to do much customization work. In fact, Verizon said that 96% of the attacks "were not highly difficult" for the hackers.

"Additionally, 97% were avoidable, without the need for organizations to resort to difficult or expensive countermeasures," the report said.

Very often, the companies breached had no firewalls, had ports open to the Internet or used default or easily guessable passwords, said Marc Spitler a Verizon security analyst.

The study found that cybercriminals did not have to work any harder to break into a large organization than into a small one.

Attackers in 2011 generally didn't need new sophisticated tools to break into most organizations, Spitler said.

"We have seen nothing new. Some of the old standbys are continuing to work very well for the people going after information," he said. "Not enough has been done to raise the bar and to force them to spend" significant sums on new tools and exploits.

The most sophistication found by the researchers was in the methods used by attackers to steal data after breaking in to systems, he said.

Attackers typically have installed malware on a victim company's network to escalate privileges, set up backdoors, enable remote control and sniff out sensitive data. Many take steps to remain hidden on the network for a long time and then wipe their tracks when they are done.

Such tasks require moderate to advanced skills and extensive resources on the part of the attackers, according to Spitler. "That is one area where we have raised the bar," he said.

Most of the targeted attacks last year were directed large companies in the finance and insurance industries, according to Verizon.

Hackers, often part of organized groups, used large-scale automated methods to find vulnerable businesses to exploit.

In such cases, more than 85% of victim companies employed less than 1,000 employees and were mostly in the retail, hospitality and food services industries.

The findings once again highlight the need for companies to pay attention to security basics, Spitler said.

"It is about going back to basic security principles. A lot of the same recommendations we have used in past years, we have recommended this year," he said.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

Thursday, February 23, 2012

Netherlands signs cyber crime treaty

RNW, 23 February 2012

The Netherlands and the United States have agreed to intensify their cooperation in the fight against cyber crime.

Justice Minister Ivo Opstelten signed a treaty to that effect on Wednesday evening in Washington DC.

In an interview on Dutch public radio, the minister said that the treaty did not include paragraphs on the protection of privacy. Cooperation will focus on the protection of vital infrastructure, he said. “Coming to mind are the energy supply, banks, water management and airports. Things that affect people’s lives day in, day out.”

The Netherlands and the US agreed to share expertise to safeguard energy supply and other vital utilities that could be threatened by a cyber attack. "We will also carry out better forensic investigations aimed at catching the criminals behind these attacks.”

The minister said cooperation was important because cyber crimes are often of an international nature. He did not want to go so far as saying that the Netherlands could not do without US expertise. “We must learn from each other."

Saturday, February 18, 2012

Inside fraud job costs ING millions

RNW, 17 February 2012

ING insurance and banking group has lost about 20.5 million euros from a massive fraud committed by one of its own accountants in Australia.

Court documents released last week after Fajina Subramaniam was sentenced to seven years in prison revealed the 42-year-old woman had stolen 37 million euros from the bank over a period of five years.

As a senior accountant, Subramaniam made 200 illegal transfers into her personal accounts or directly to shops and real estate agents. She then used the computer log-ins of former staff to delete the records or change them so the transactions appeared legitimate.

Above market price

The employee started to enjoy a life of luxury with expensive jewelry and various waterfront apartments. While ING has recovered most of the haul of luxury goods and property, the bank has still taken a substantial hit as Subramaniam paid above market rates for the real estate she bought.

She developed a personal relationship with staff from the super luxury Paspaley jeweller's and was reportedly wined and dined on a regular basis.

The court documents also highlighted the poor levels of internal security at the section of ING where Subramaniam worked, ING Australia Holdings.


Related Article:


Monday, December 26, 2011

'Anonymous' hackers hit US security firm Stratfor

BBC News, 26 December 2011

Related Stories 

Stratfor urged its members to notify
authorities about any suspicious
credit card activities
The activist hacker group Anonymous says it has stolen thousands of emails, passwords and credit card details from a US-based security think-tank.

The hackers claim they were able to obtain the information because the company, Stratfor, did not encrypt it.

They say Stratfor's clients include the US defence department, law enforcement agencies and media organisations.

The Austin-based company says it has now suspended the operation on its servers and email.

An alleged member of Anonymous posted an online message, claiming that the group had used Stratfor clients' credit card details to make "over a million dollars" in donations to different charities.

Stratfor later announced that it would keep its email and servers suspended for some time.

It also said the disclosure was "merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor".

Anonymous has previously claimed responsibility for cyber attacks on financial institutions seen as enemies of the whistleblowing website Wikileaks.


Related Article:


Wednesday, September 21, 2011

Hacked Security Firm DigiNotar Files for Bankruptcy

PC Mag, by Sara Yin, September 20, 2011

DigiNotar, a Dutch certificate authority that was hacked in July, has filed for bankruptcy.

"Although we are saddened by this action and the circumstances that necessitated it, we would like to remind our customers and investors that the incident at DigiNotar has no impact on VASCO's core authentication technology," said T. Kendall Hunt, chairman and CEO of VASCO, a U.S. security firm that acquired DigiNotar in January. "The technological infrastructures of VASCO and DigiNotar remain completely separated, meaning that there is no risk for infection of VASCO's strong authentication business."

Hunt added that VASCO was working with the Dutch government to investigate those responsible for the hack. VASCO is also planning to announce the financial damage done.

DigiNotar, established in 1997, was responsible for creating certificates that validate Web sites as legitimate. Although the breach traces back to July, DigiNotar reportedly took weeks to notice and revoked fake certificates without notifying anyone. A subsequent investigation revealed that DigiNotar certificates might have compromised the Google accounts of approximately 300,000 Iranians.

What this means is that when users in Iran and elsewhere navigated to certain Web sites, they might actually be visiting spoofed sites that stole personal information when users logged in. In the wake of the DigiNotar digital certificate hack, Microsoft revoked the trust of five DigiNotar root certificates, followed by Google, Mozilla, and Apple.

A hacker known as Comodo Hacker, who got his name thanks to a March hack of Comodo, has also taken credit for the DigiNotar job. He also claims to have accessed GlobalSign, prompting the company to temporarily stop issuing digital certificates.

Chloe Albanesius contributed to this report.

For more from Sara, follow her on Twitter @sarapyin.


Related Article:


Thursday, September 8, 2011

Dutch Government Struggles to Deal With DigiNotar Hack

PCWorld, by Loek Essers, IDG News, Sep 7, 2011

The Dutch government is trying to minimize the effect of the DigiNotar hack on its IT infrastructure but warned it's a time-consuming process: Not all the SSL certificates can be replaced on the fly.

Piet Hein Donner, minister of the interior, said in a press conference on Tuesday that the government will work as quickly as possible to replace all the DigiNotar SSL certificates in use. However, if the certificates are withdrawn immediately it will be damaging, he warned.

"It particularly concerns the fully automated communication between computers," Donner said. If the certificates are withdrawn right now it would disturb or even block Machine-to-Machine (M2M) communication. That is why the Dutch government chose a "phased and controlled" migration to other certificates. While website certificates should be replaced by Saturday, he said, replacing those involved in M2M communication will take longer.

For the same reason, Microsoft agreed on Tuesday to postpone an automatic software update for the Netherlands that revokes the trust in all DigiNotar certificates for one week. Next week the software update will be rolled out in the Netherlands with an opt-out option. Companies who want to implement the software update this week have to do that themselves. According to Donner this ensures there is no significant disturbance in digital communications in the Netherlands.

On Sept. 2, the Dutch government announced in a night-time press conference, the first in Dutch IT history, that all DigiNotar certificates were to be banned and replaced. According to a report by the security firm Fox-IT published on Monday, 531 fraudulent certificates were issued after DigiNotar was hacked from an Iranian IP address in June. The firm also found proof that the "DigiNotar PKIoverheid CA" certificates the Dutch government uses were compromised. Fox-IT found no evidence that government certificates were misused.

Ronald Prins, CEO of Fox-IT, said on the Dutch television show "Nieuwsuur" on Monday that the real damage for Dutch citizens was limited, but that the implications could have been big. DigiNotar was used for DigiD, an identity management platform used by Dutch government agencies including the Tax and Customs Administration. Hackers could have monitored DigiD traffic and would even be able to manipulate tax filings if they wanted to.

The government replaced the DigiNotar DigiD certificates with PKIoverheid CA certificates from Getronics PinkRoccade, one of the seven (including DigiNotar) SSL certificate providers the government uses. Other problems occurred with the systems of the Rijksdienst voor het Wegverkeer (RDW), which handles vehicle registrations and inspections in the Netherlands. The RDW switched to VeriSign certificates but still has to use DigiNotar for M2M communication, spokesperson Sjoerd Weiland told the Dutch IDG news site Webwereld on Monday.

According to Weiland it is impossible to say when the switch from DigiNotar to another CA can be done. Every business connected to the RDW, including the police and insurance companies, has to switch to new certificates at the same time to prevent the total collapse of all M2M communication. Local governments could have the same problem as the RDW. Minister Donner said there are "some disturbances" in communications between the RDW and local governments.

Dutch financial transactions, Amsterdam's Schiphol airport and the national railways were not affected. "Although several sectors are meanwhile suffering from disruptions, major uncontrollable problems have not appeared to date," Minister Donner and Minister Ivo Opstelten of Public Safety and Justice stated in a letter to the lower house of Parliament. In total DigiNotar issued 57,956 certificates in different sectors in the Netherlands.

Because DigiNotar was hacked in June and the company knew about the hack shortly afterward but did not inform the Dutch government, the attorney general has begun an investigation to determine if DigiNotar can be held formally responsible for the ongoing crisis. Telecom watchdog OPTA is also investigating DigiNotar. That investigation is aimed at the way the certificates were issued.


 (Photo: RNW)

Related Article:


Tuesday, September 6, 2011

Dutch hacking attack grave threat to Iranian dissidents

RNW, 5 September 2011, by Erik Klooster 

 (Photo: RNW)

Iranian dissidents are at grave risk after hackers broke into a Dutch internet company, allowing the Iranian authorities to read messages sent through normally secure sites such as Yahoo and Gmail.

The exact threats the Iranian dissidents are facing as a result of the hacking attack are not yet clear. With elections due in March 2012, however, Iran’s security services are especially vigilant. Ot van Daalen, who heads Bits of Freedom, a Dutch group that defends digital privacy rights, fears the worst:

“It’s horrible to say but it’s entirely possible that the hacking attack has endangered lives in Iran.”

DigiNotar

In July, hackers broke into DigiNotar, a Dutch company that issues certificates of authenticity aimed at protecting websites around the globe. The hackers then issued fake certificates. After that, some internet users who thought they were on a secure site, could have their messages read by anyone, including Iran’s security services. It was only recently that Iranian activists realised something was amiss.

The hacking attack affected dozens of websites of renowned companies, including Microsoft, Wordpress, Facebook, Twitter and Yahoo’s and Google’s email services. Israeli and British secret services were targeted too. Gmail and Yahoo are widely used by Iranian dissidents to communicate with each other. The breach was sealed nine days ago but that does not mean, Van Daalen warns, there no longer are any threats.

“There is a real chance that the Iranian authorities have used these certificates to eavesdrop on users. And it can’t be ruled out they will continue doing so with other certificates.”

Censorship

Iran is one of the countries with the worst censorship in the world, says Frank van Dalen of the Dutch Iran Committee. Internet, he stresses, is one of the last resorts for Iran’s opposition.

“They use internet in all possible ways. Some messages are explicit, others are more implicit but clear to the reader. People also wear green bracelets as a visible sign of protest.”

Serious threat

Van Daalen agrees that the Iranian dissidents are facing a serious threat, with censorship and repression bound to intensify in the run-up to the elections due in March. The Iranian authorities, he cautions, will do all they can to avoid a second Green Revolution. The hacking attack, he ventures, is hardly accidental, since DigiNotar is involved in Dutch projects designed to improve internet access in Iran.

“The Netherlands supports that initiative. This raises the question whether DigiNotar also carries out such work for the Dutch government. If so, that could be a reason why it was targeted. Why was this company attacked and not another certificate-issuing firm? It’s vital to find out.”

It’s not clear if the attack on DigiNotar was carried out by Iran. The Dutch government has launched an investigation. The Iran Committee wants The Hague to summon the Iranian ambassador. DigiNotar itself has refused to comment on the case.


Who issues certificates of authenticity?

  • Before the breach, DigiNotar was authorised to issue certificates of authenticity, which guarantee that a site is secure (with https:// in the navigation bar). Makers of internet browsers such as Microsoft Internet Explorer, Mozilla Firefox and Google Chrome then evaluate if such sites really are secure.

    Currently there are some 600 such companies recognised around the world, according to Bits of Freedom. They in turn, Ot van Daalen adds, are allowed to designate retailers, which number in the thousands. “It is questionable whether all of these companies can be really trusted.”

    A list of “compromised certificates” includes well-known domain names such as Google, Yahoo, Facebook, Skype and Wordpress. So far, however, only internet users in Iran appear to be at risk, according to Van Daalen.

    The Dutch government and Dutch companies are in the process of replacing DigiNotar certificates by certificates issued by other companies. The government has set up a website that gathers all related news and developments.

Friday, April 8, 2011

Dramatic footage of TV newsroom violently shaken by 7.4 quake in Japan

RT.com, April 7, 2011

Dramatic footage as Miyagi TV (MMT) newsroom is violently shaken by the 7.4 magnitude aftershock, shelves fall, staff react - power cuts off for about 20 seconds, comes back on to reveal extensive damage to office. Japan was rattled by a magnitude-7.4 aftershock on Thursday night nearly a month after a devastating earthquake and tsunami flattened the northeastern coast. The strongest aftershock since the day of the magnitude-9.0 megaquake was a fresh blow to victims of that March 11 quake and subsequent tsunami that killed some 25,000 people, tore apart hundreds of thousands of homes and has sparked an ongoing crisis at a nuclear power plant. Damage and injuries from the aftershock were not immediately clear.




Related Articles: