Blogging about computer security news since March 2000.
[Iris the Dog] [Harley the Dog] Security::WatchDog
Watching Computer Security

Is "computer security" an oxymoron?
[Ray the Dog] [Rusty the Dog]

GDT::NewsFeeder:: Computer Security News
[Yearly Archives] 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000


Is It FUD?
Is it FUD?

I don't think so; therefore, it probably is.

   @nanofoo tweeted the following on 2010.01.30.

   Obama said nothing in his State of the Union address about 
   the state of the Union w/respect to cyberwarfare preparedness

According to PopSci.com... "we are not prepared."

PopSci.com::U.S. Wargamers Wrap Up Massive Cyberattack Drill: "We Are Not Prepared"

[21 February 2010, top]
Is the U.S. Ready For Cyberwarfare?
TechNews.ACM.org had a posting titled "In Cyber War, Most of U.S. Must Defend Itself" on 2010.02.10 and it started with the following.
   "There are concerns that the United States is extremely 
    vulnerable to a full-scale cyberattack, and the U.S. 
    Cyber Command is not in a position to protect U.S. 
    civilian computer networks [...]"

The TechNews.ACM.org posting included the following.

   "Meanwhile, U.S. military networks are under constant 
    cyberattack because they are such an appealing target, 
    according to Deputy Defense Secretary William Lynn. 
    'And the frequency and sophistication of attacks are 
    increasing exponentially,' he notes.

I believe this is true because we're living in exponential times.

More from the TechNews.ACM.org posting titled "In Cyber War, Most of U.S. Must Defend Itself."

   "McAfee hints at the possibility that countries are 
    competing in a quiet cyber arms race, and communications 
    systems, banks, and power grids are just as likely to be 
    targets as military networks."

Note: McAfee is an "antivirus software and computer security company headquartered in Santa Clara, California."

[Extra] @nanofoo tweeted the following on 2010.02.07.

   China & Russia dominate 2010 ACM Intl. Collegiate 
   Programming Contest http://bit.ly/cVLdpz

@nanofoo tweeted the following on 2010.01.30.

Obama said nothing in his State of the Union address about 
the state of the Union w/respect to cyberwarfare preparedness.
[09 February 2010, top]
Cybersecurity Enhancement Act of 2009
The House voted 422-5 in favor of H.R. 4061 -- The Cybersecurity Enhancement Act of 2009.
   "The bill requires the Obama administration to conduct an 
    agency-by-agency assessment of cybersecurity workforce skills 
    and establishes a scholarship program for undergraduate and 
    graduate students who agree to work as cybersecurity specialists 
    for the government after graduation."  
    [source: NYTimes.com via Slashdot.org]

Yikes! politician Michael Arcuri said, "Nearly every high school hacker has the potential to hamper our unfettered access to the Internet. Just image what a rogue state could do."

FYI to Arcuri: Kids not yet in high school can be crackers.

Science.House.gov::HR4061::Cybersecurity Enhancement Act of 2009

[04 February 2010, top]
Digital Privacy Day 2010
28 January 2010 was Data Privacy Day
   "Data Privacy Day is an international celebration of the dignity 
    of the individual expressed through personal information."

Data Privacy Day... "digital lives in a networked world."

[28 January 2010, top]
DARPA's Cyber Genome Program
DARPA's Cyber Genome Program Proposers' Day is on 29 January 2010.
   "The objective of the Cyber Genome Program is to produce 
    revolutionary cyber defense and investigatory technologies 
    for the collection, identification, characterization, and 
    presentation of properties and relationships from collected 
    digital artifacts of software, data, and/or users to support 
    DoD law enforcement, counter intelligence, and cyber defense 
    teams. Digital artifacts may be collected from live systems 
    (traditional computers, personal digital assistants, and/or 
    distributed information systems such as 'cloud computers'), 
    from wired or wireless networks, or collected storage media. 
    The format may include electronic documents or software (to 
    include malicious software - malware). The Cyber Genome Program 
    will encompass several program phases and technical areas of 
    interest. Each of the technical areas will develop the cyber 
    equivalent of fingerprints or DNA to facilitate developing 
    the digital equivalent of genotype, as well as observed and 
    inferred phenotype in order to determine the identity, lineage, 
    and provenance of digital artifacts and users."
    [source: FBO.gov via Wired.com]

The Wired.com headline should have read: "Pentagon Searches for 'Digital DNA' to Identify Hackers Crackers"

[26 January 2010, top]
Bruce Schneier On China Cracking Gmail
When Bruce Schneier shares information, I try to learn from it.
   "China's hackers subverted the access system Google 
    put in place to comply with U.S. intercept orders."

Dear Mr. Schneier... And I know this is a little thing, but please, please, please write cracking instead of hacking.

CNN.com::U.S. enables Chinese hacking of Google

[24 January 2010, top]
Computer Security Remains an Oxymoron
@nanofoo received the following tweet from @hblodget on 2010.01.18.
   Is Google Going To Address The Fact That So Many Gmail 
   Accounts Are Getting Hacked?  http://bit.ly/76OW0I

And of course the accounts are being cracked (i.e. not hacked).

@nanofoo sent following tweet as a reply to @hblodget on 2010.01.18.

   About Google Gmail being cracked... Oxymoron? computer security

In a nutshell, Google's Gmail is popular; therefore, it is going to be a popular target for crackers and cyber-terrorists. The fact that Gmail gets cracked provides definitive proof that computer security is downright difficult and it is why computer security gurus make lots of money.

[18 January 2010, top]
Baidu Cracked By Crackers
The Slashdot posting makes reference to the "Iranian Cyber Army."
   "Chinese netizens pointed out that the hackers, who call 
    themselves 'Iranian Cyber Army', changed Baidu's DNS 
    records, redirecting traffic to another site."
    --English.People.com.cn

The "hackers" that took down Baidu were "crackers."

YRO.Slashdot.org::Twitter Hackers Take Down Baidu

[13 January 2010, top]
Google Gmail To Default To HTTPS
I agree with Google's assessment.
   "Over the last few months, we've been researching the 
    security/latency tradeoff and decided that turning https 
    on for everyone was the right thing to do."

Gmailblog.Blogspot.com::Default https access for Gmail

[13 January 2010, top]
2010 Starts With a SpamAssassin Bug
Yup... With respect to regular expressions 20[1-9][0-9] matches 2010.

Yet more evidence (like we needed more) that processing dates and times on a computer is non-trivial.

Secure.Grepular.com::SpamAssassin 2010 bug

[02 January 2010, top]
About the Security Watchdog
The Security Watchdog starts 2010 with 497 postings. This blog was started during March of 2000 and the current world of computer security is worse now than it was then. Needless to say, there will always be content for the Security Watchdog for at least the next couple of years.

Security Watchdog Archives: 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000

[01 January 2010, top]


[Yearly Archives] 2005 | 2004 | 2003 | 2002 | 2001 | 2000

Creator: Gerald Thurman [gdt@deru.com]
Last Modified: Sunday, 21-Feb-2010 08:00:39 MST

Thanks for Visiting