13.12.17

Cryptocurrency in kilowatt hours: Counting the costs of anonymous transactions



Over the course of last week, bitcoin reached an all-time high value of just under US$17,000, and currently hovers close to that record high. The increase has generated many media articles and much commentary from financial experts. Before we look at the reasons behind the increase, let’s consider the infrastructure.
Society sorts its garbage for recycling and attempts to save energy in many different ways: some speculators in bitcoin may be shocked by the statistics on power consumption of the bitcoin network published by Digiconomist.
To understand the power consumption issue it’s important to have a conceptual overview of how bitcoin works. The system comprises a blockchain, a ledger of records that contain all the transactions and timestamps. A new block is created approximately every 10 minutes by so-called miners. These are a distributed network calculating complex algorithms to create blocks to extend the blockchain. Every miner attempts to calculate the next block, the first to calculate a valid block distributes it to the other miners.
The miners are paid for their services to the network with additionally created bitcoins, diluting the value of existing bitcoins. This is not an issue today, as the increasing value means the dilution has no negative effect. Current revenues paid to Miners are $9.9bn and their estimated mining costs are $1.58bn, making mining a lucrative business and the reason people are keen to create miners.
Bitcoin’s estimated annual power consumption is 31.6 TW⋅h, that’s more power than Ireland uses on an annual basis. The electricity consumed for a single transaction is 251 kW⋅h, which is sufficient to power 8.49 typical households in the US for a day.
If you grab lunch from one of the many restaurants that accept bitcoin, and lunch costs under $15, it will cost more to process the payment than you paid for lunch. Using The average cost of a kW⋅h in California, which according to Electric Choice, is $0.1816, so the cost of a single bitcoin transaction would be approximately $45.
The energy costs are not the only charges in a transaction: the bitcoin network itself levies a charge which, according to a blog from Valve, the gaming provider behind the Steam network, has skyrocketed from $0.20 in 2016 to $20 per transaction today. Based on this and the current volatility in value Valve has decided to discontinue accepting payment using bitcoin.
Logic indicates there is a serious flaw in this business model when you look at the energy costs and the transaction fees. However, as long as the price of bitcoin continues to rise then the flaw may be acceptable to those spending their newly found wealth.
“If you grab lunch from one of the many restaurants that accept bitcoin, and lunch costs under $15, it will cost more to process the payment than you paid for lunch”
With the heightened interest around bitcoin, I have been actively asking people I meet if they hold any of the digital currency. Not surprisingly I have found a few… none of whom use the currency for daily transactions, but are investors or speculators looking for capital gain. And here lies the problem: the currency’s value appears to be inflated by the demand from organizations and individuals looking to make a quick buck.
Sir John Cunliffe, the Deputy Governor of the Bank of England, was quoted in a BBC article as saying “investors should do their homework and think carefully”. He points out that there is no government or central bank behind bitcoin, that it is not an official currency, and that it should be viewed more as a commodity.
Speculation on the recent surge in value is varied: Derek Thompson, a journalist for The Atlantic describes the recent rise as an ‘unsustainable paroxysm’ and compares it to the 17th-century tulip bulb bubble. No one actually knows what is causing the surge, other than demand, and an important factor in this could be that so far 16.5 million bitcoins have been issued, and since in its current format there is a theoretical limit of 21 million, maybe people are just scared of missing out?
One other important element to this is that bitcoin is popular with criminals due to its lack of regulation and pseudo-anonymous character. The UK Treasury recently stated that it believes anti-money-laundering regulations should be updated to include bitcoin and other virtual currencies. Detective Superintendent Nick Stevens from the Serious and Organised Crime Command of the Metropolitan Police stated that “Organised criminal groups have been early adopters of crypto-currencies to evade traditional money laundering checks and statutory regulations”.
I am curious whether the speculators investing in bitcoin have considered that as they push the price up, they are increasing the value for criminals too?
What is apparent is that we are in unchartered territory, a new era of digital currency. While there are problems, for example with currency exchanges being knocked offline by DDoS attacks, and potentially greed playing its part in todays inflated valuation at present, there are likely to be real uses for a digital currency in the future. When the bitcoin bubble inevitably bursts, as all bubbles do, then it will only be a matter of time before another currency appears and those behind, we hope, will have learned from the mistakes of the first.

12.12.17

Happy holidays, scam spotters!

The Identity Theft Resource Center – @ITRCSD – invited researchers from ESET North America to take part in a Twitter chat, a holiday edition of their #IDTheftChat. The conversation related to scams targeting businesses and consumers, which always seem to increase dramatically at this time of year. The chat took place on December 7th 2017, and you can read the whole thing using that hashtag. However, here are the contributions from Lysa Myers, Aryeh Goretsky, and David Harley.
@ITRCSD: Q1: An @AARP survey discovered that 70% of U.S shoppers failed a short quiz on how to stay safe from holiday #scams. What are some tips for safe #shopping this season?
Aryeh: Scams often prey on victims by offering something which sounds “too good to be true.” If it sounds too good to be true, it probably should be avoided.
Lysa: Enable 2-Factor Authentication on your online accounts wherever it’s available. Use credit rather than debit cards if you can, especially online.
Q2: How are #businesses also targeted by Grinches looking to steal valuable data?
Aryeh: Businesses are often sent fake invoices and waybills which install ransomware. Teach staff to avoid these. If questionable, ask your IT dept to look at it. E-cards have been a target in the past and may be used again in holiday-themed attacked.
Lysa: Many breaches are facilitated by stolen credentials. Make sure staff get regular, positive training for recognizing and avoiding phishing and other scams that use social engineering.
Lysa: Thieves often enter networks by exploiting vulnerabilities in software. Updating promptly can help, but for those systems that can’t be quickly updated, utilize layers of protection to help mitigate risk.
Q3: What kind of impact can #DataBreaches have on businesses and their customers?
Aryeh: A data breach can put a company out of business and subject its owners to fines in the 100Ks to millions range.
Lysa: Lost time and productivity are the most obvious impact. Regulatory fines, lawsuits are also a huge potential impact. Don’t discount the loss of reputation – studies show that this can be a significant $$$$ hit.
Q4: If a #breach does occur, it can feel like a real lump of coal. What are some tips for businesses to stay on the nice list with customers?
Aryeh: Create a policy for handling a data breach, and test it 1-2× a year to see how well it works.
Lysa: Businesses’ response in the wake of a breach can make a huge impact on the loss of reputation. Notifications that are quick, orderly and informative are a much easier pill to swallow.
Lysa: Have a breach-response policy in place (and kept updated!) beforehand so that you know who must do what, and when. This will decrease the number & severity of possible errors that could compound loss of trust.
Q5: Mail theft also increases during the holidays. How can you stop a shady snowman?
Aryeh: Get your mail promptly and don’t leave it out all day. Consider a locked mailbox. Place a security camera on your mailbox to record thieves.
Q6: Looking to be Santa’s helper? What kind of employment scams should you look out for?
Aryeh: Be aware of employment scams that offer guaranteed work-from-home, secret shopper or shipping of packages are usually scams.
David: Some job scams are seasonal. Here are some tips that apply to job scams in general, though.
·         Check that the company offering the job exists before you respond to job offers by email. Especially if you haven’t been looking for job offers.
·         If the company exists, check with them directly – and not via the email or contact points linked in the message –that the jobs exist.
·         Be suspicious of poor English and presentation. But don’t assume that good presentation = a genuine offer.
·         If they insist on making your travel and visa arrangements, be deeply suspicious. Run like the wind in the opposite direction if they want you to pay in advance.
·         Many email providers offer free addresses with minimal or no identity checking. Reputable, reliable companies don’t usually use them to make job offers.
·         An organization large enough to have a Human Resources Department yet so tightfisted as to restrict it to a free email account on mail.com (for example)? Unlikely…
·         An old article here, but has lots more points to watch for:
Q7: Ho-ho-hold on. What are some common holiday #phone scams & tips to protect your information & #finances?
Aryeh: Watch out for fake callers pretending to be from banks, Microsoft support, businesses saying you’ve won a prize or surveys offering a free cruise. They are scams.
Lysa: If you haven’t already, now is a good time to consider freezing your credit.
Lysa: Do you make (and test!) regular backups of your data? Do you encrypt sensitive files on your hard drive or on mobile devices? Have you enabled 2 Factor Authentication?
Q8: Don’t follow that scammer under the mistletoe! How can you spot a sweetheart #scam?
Aryeh: Romance scams prey on older single people. Watch out for unexpected friend requests from people across the country or that claim to be serving overseas.
Q9: “But first, let me take an #Elfie.” Best tips for not oversharing on #social media?
Aryeh: Don’t share information that contains your address/location or holiday travel plans. These let crooks know what, where and when to rob you.
Lysa: The Internet is forever: you can’t put the metaphorical toothpaste back in the tube. Before sharing, ask yourself if you would be comfortable with a total stranger, law enforcement, your boss, or your mom/child seeing this?
David: Remember that even if you only share info with people you trust, they may not be as careful as you are. Your friends may be well-intentioned, but they aren’t necessarily security-savvy.
Q10: Please share more resources to having a merry and safe holiday season both online and offline!
Aryeh: Visit welivesecurity.com for the latest on scams, tricks and threats.
@ESET: And don’t forget our #GiveSecurity contest is still running on Instagram! Enter by 12/22 and you could win a MacBook Air, Samsung Tab S3 and more! https://www.eset.com/us/givesecurity/

8.12.17

Virtual keyboard app exposes personal data of 31 million users


Personal data belonging to more than 31 million users of a third-party smartphone keyboard app called ai.type were exposed online due to an unprotected online database.
In total, nearly 580 gigabytes of user records were left visible in a MongoDB database after the app’s Israel-based developer failed to use some form of authentication to secure its database server.
The developer’s keyboard apps boast 40 million users across Android and iOS, but only Android users were affected by the security lapse.
CEO and founder of ai.type, Eitan Fitusi, was later reported as having secured the data with a password after being alerted to the issue several times. Before that happened, however, the treasure trove of information was there waiting to become ‘manna from heaven’ for electronic miscreants.
Perhaps just as worryingly, however, is the sheer scope of information sucked up by the on-screen keyboard app, which offers an alternative to the standard smartphone keyboards.
Reports suggest that the breadth of personal information left visible runs the whole gamut, apparently based also on whether the users had installed the app’s free or paid version. The information collected included users’ full names, email addresses, location data, a device’s IMSI and IMEI number, its make and model, Android version, details from users’ public Google profile, and contents of users’ address books.

Also found was a database table containing over 8.6 million entries of text that had been entered on the keyboard and that reportedly included email addresses and their passwords.
Meanwhile, Fitusi was quoted as saying that the data in jeopardy had not been as extensive as claimed and that the app is not snooping on users.
“It was a secondary database,” he told the BBC of the reports, adding that the geo-location data was not accurate, that no IMEI information had been hoovered up, and that the user behavior collected by the company involved only which ads they clicked.
In response to such data collection practices, ESET security specialist Mark James said that “that in itself is a massive hoard of data to hold on a well secured server away from harm’s reach, but sadly that was just not so”.
“The database was not configured correctly and thus enabled full access from the internet to all the data being held, making it essentially free for all access,” he added.
Another keyboard app, SwiftKey, had its share of security issues last July after it was reported that some users had received predictive text messages intended for other people, including email addresses and phone numbers. Blaming the glitch on a bug in the keyboard’s synchronization program, the app’s maker temporarily suspended cloud syncing.
Users are advised to exercise caution when installing mobile apps. This is, perhaps, doubly the case with keyboard apps which, by their very nature, have access to all data typed by users, including the most sensitive of information, such as passwords and credit card details.


6.12.17

Cryptocurrency exchange Bitfinex plagued by DDoS attacks



Digital currency exchange Bitfinex has been going through a sticky patch of late, having been knocked temporarily offline on Monday due to a distributed denial-of-service (DDoS) attack that was reminiscent of a similar incident from a few days prior.
After first tweeting that “Platform is currently under heavy load and we are working to bring it back online”, the Hong Kong-based cryptocurrency exchange platform confirmed shortly afterwards the true nature of the cyberattack.
Normal operations were back up and running within an hour. This outage was preceded by another DDoS attack, on November 26, which “started during earlier maintenance and has been ongoing since”, according to a tweet posted by Bitfinex that same day.
The cast of characters behind the attacks, or their motives, are unclear. However, the onslaughts come at a time when the bitcoin price hits new highs, possibly triggering efforts on the part of cybercriminals to manipulate and cash in on the price.

Sandwiched between the two attacks was a ‘flash crash’ that reportedly hit Bitfinex last Wednesday and prompted some traders to report severe losses after the prices of cryptocurrencies NEO, OMG, and ETP plummeted by as much as 90%, causing the closing of their positions. Bitfinex argued that it was operating as normal, however.
Another major digital currency exchange, Coinbase, experienced its own flash crash in June, ultimately drawing regulatory scrutiny.
Trading also went berserk a little over two years ago, resulting in a drop of 14% in Bitcoin’s price within a span of some 30 minutes.
Until last week, Bitfinex was the top exchange for U.S. dollar-bitcoin trading in terms of trading volume before it was surpassed by Coinbase.
Much like other cryptocurrency exchanges, Bitfinex is no stranger to being on the receiving end of cyberattacks. On top of experiencing multiple DDoS attacks, Bitfinex landed in hot water in August 2016 following a massive cyberheist. Before the exchange bounced back, the incident may have afforded many traders a sort of déjà vu experience, sparking fears that Bitfinex could go the way of Mt. Gox. That Bitcoin exchange collapsed in 2014 after losing $500 million of customer money to hackers, itself another stark reminder that cryptocurrency trading is not for the faint-hearted.

ISF predicts increasing impact of data breaches next year



The number, magnitude and costs of data breaches are all set to continue on their upward trajectories in the coming year, according to a forecast by the Information Security Forum (ISF).
This prediction is included in their Global Security Threat Outlook for 2018 and comes with a warning that the stakes are now “higher than ever before”.
The increased pervasiveness of data breaches and the higher volume of impacted records are expected to result in far higher costs for organizations of all sizes, notes the ISF, an independent and not-for-profit association of leading organizations from around the world.
The association expects the increased costs incurred in security breaches to come both from traditional areas, such as network cleanup and customer notification, and newer areas such as litigation.
As if in a chain reaction, the data breaches will spur “angry customers” to mount pressure on governments to tighten up data protection laws, which in turn will translate into additional and unforeseen costs. “The resulting mess of international regulations” will trigger new compliance headaches while doing little to deter cybercrime.
“In 2018, we will see increased sophistication in the threat landscape with threats being personalized to their target’s weak spots or metamorphosing to take account of defenses that have already been put in place … These days, the stakes are higher than ever before. High level corporate secrets and critical infrastructure are regularly under attack and organizations of all sizes need to be aware of the significant trends that we forecast in the year to come,” ISF Managing Director Steve Durbin is quoted as saying.
These trends will be underpinned by these five most prevalent threats that the ISF expects to loom large on businesses next year:
·         Crime-as-a-service (CaaS) is set to expand available tools and services, as criminal organizations won’t let up on their efforts to make their malicious wares increasingly more sophisticated. Criminal groups will make forays into new markets and will commoditize their activities globally, which is poised to result in more persistent and damaging cyber incidents than ever before.
·         The Internet of Things (IoT) will add unmanaged risks due to the organizations’ embracing of IoT devices but losing sight of the fact that these devices are often insecure by design, thus affording bad actors ample opportunities for attacks. “In a worst-case scenario, when IoT devices are embedded in industrial control systems, security compromises could result in harm to individuals or even loss of life,” reads the ISF’s prediction.
·         Supply chain remains the weakest link in risk management, according to the ISF, which points to the perils of sharing valuable and sensitive information with suppliers, as it leads to “an increased risk of its confidentiality, integrity or availability being compromised”.
·         Regulation adds to complexity and, as a result of additional resources required to address the obligations enshrined in the EU’s General Data Protection Regulation (GDPR), businesses may – on top of facing extra compliance and data management costs – have their attention and investment drawn away from other important initiatives.
·         Lastly, misalignment between a board’s expectations and the actual ability of information security officers to deliver also constitutes a threat. The ISF notes that many boards don’t realize that it takes time to make substantial improvements to information security, which is why the association anticipates that this mismatch will be most exposed by major incidents. “Not only will the organization face substantial impact, the repercussions will also reflect badly on the individuals and collective reputations of the board members,” according to the ISF.
The ISF was quick to note that the key five threats “are not mutually exclusive and can combine to create even greater threat profiles”.

1.12.17

Cinq conseils pour assurer la sécurité de vos bases de données



Lorsqu’il est question de conseils en matière de sécurité et de prévention du piratage, on parle souvent de l’importance d’avoir un mot de passe fort, d’utiliser des applications de sécurité, de maintenir ses systèmes à jour et d’éviter les paramètres par défaut. En général, ces conseils constituent les protections les plus élémentaires et essentiels que tout gestionnaire de système doit prendre en compte. Cependant, selon le système que vous désirez protéger, vous devriez prendre certains autres points en compte.
Considérant le nombre alarmant de vol et de fuites de données, les cinq conseils clés suivants vous aideront à garder vos bases de données en sûreté, surtout si elles sont hébergées dans le nuage ou par une tierce partie.
1.     Contrôlez l’accès à la base de données
Comme le disait ma grand-mère, quand tous les petits-enfants voulaient l’aider en cuisine : « Trop de cuisiniers gâchent la sauce ».
Il s’avère finalement que ce vieil adage est tout à fait à propos quand on parle de sécurité informatique : quand trop de gens s’ingèrent dans quelque chose, le résultat est rarement positif.
IL VAUT MIEUX QUE VOUS LIMITIEZ LES AUTORISATIONS ET PRIVILÈGES AU MAXIMUM
Le même raisonnement s’applique aux bases de données : l’idéal est que vous limitiez les autorisations et privilèges au maximum.
Contrôler rigoureusement l’accès est la première étape pour tenir les attaquants loin de vos données. En plus des permissions de base du système, vous devriez aussi envisager de :
·         Limiter l’accès aux données confidentielles, à la fois pour les utilisateurs et les procédures – en d’autres mots, n’autoriser que certains utilisateurs et procédures à faire des demandes concernant les informations sensibles;
·         Limiter l’utilisation de procédures clés à quelques utilisateurs spécifiques seulement;
·         Dans la mesure du possible, éviter d’utiliser et d’accéder à ces données simultanément en dehors des heures d’affaires régulières.
La désactivation de tous les services et procédures que vous n’utilisez pas constitue une autre bonne idée, afin d’éviter que ceux-ci puissent être attaqués. De plus, les bases de données devraient dans la mesure du possible se trouver sur un serveur n’étant pas accessible directement via Internet, afin d’éviter que des informations ne puissent être révélées à des attaquants extérieurs.
2.     Identifiez les données sensibles et critiques
D’abord et avant tout, avant d’examiner les techniques et les outils de protection, il convient d’analyser et de déterminer quels renseignements importants doivent être protégés. Pour ce faire, il est important de comprendre la logique et l’architecture de la base de données, afin de pouvoir déterminer plus facilement où et comment les données sensibles seront stockées.
Toutes les données que nous stockons ne sont pas aussi critiques, et toutes n’ont pas toutes besoin d’être protégées, il n’est donc pas logique de consacrer du temps et des ressources à ce type d’information.
Nous vous recommandons également de dresser un inventaire des bases de données de l’entreprise, en tenant compte de l’ensemble de ces services. Bien connaître toutes les instances et bases de données de l’entreprise et tenir un registre de celles-ci constitue la seule façon de les administrer efficacement tout en évitant la perte d’informations.
De plus, un inventaire s’avère particulièrement utile lors d’une sauvegarde d’informations, afin d’éviter de laisser des données critiques en dehors du schéma.
3.     Chiffrez vos informations
Une fois les données sensibles et confidentielles identifiées, nous vous recommandons d’utiliser des algorithmes robustes pour chiffrer celles-ci.
Quand les attaquants exploitent une vulnérabilité et parviennent à accéder à un serveur ou un système, la première chose qu’ils tentent de voler est la base de données. C’est là un trésor précieux pour ces cybercriminels. En effet, les bases de données contiennent généralement plusieurs giga-octets d’informations précieuses. La meilleure façon de protéger une base de données est de la rendre illisible : ainsi, vous pourrez empêcher toute personne d’y accéder sans autorisation.
Vous trouverez davantage d’informations dans notre guide gratuit sur le chiffrement des informations pour l’entreprise.
4.     Rendez vos bases de données anonymes, même hors production
De nombreuses entreprises investissent du temps et des ressources pour protéger leurs bases de données productives, mais se contentent de faire une copie de la base de données originale lorsqu’elles développent un projet ou créent un environnement de test. Ces entreprises commencent alors à utiliser ces données dans des environnements beaucoup moins étroitement contrôlés, les exposant ainsi toutes les informations sensibles.
Le masquage, ou l’anonymisation, désigne un processus par lequel une version similaire est créée, qui conserve la même structure que l’original mais modifie les données sensibles afin que celles-ci demeurent protégées. En utilisant cette technique, les valeurs sont modifiées, tout en conservant leur format initial.
Les données peuvent être modifiées de différentes manières : en les mélangeant ensemble, en les cryptant, en mélangeant les caractères ou en substituant des mots. La méthode spécifiquement utilisée et les règles et formats à respecter seront à déterminer par l’administrateur. Quelle que soit la méthode utilisée, l’administrateur doit s’assurer que le processus est irréversible, c’est-à-dire qu’aucune rétro-ingénierie ne permette à quiconque de retrouver les données originales.
Cette technique est particulièrement utilisée – et recommandée – pour les bases de données faisant partie d’un environnement de test et de développement, puisqu’elle permet de préserver la structure logique des données tout en s’assurant que les informations sensibles des clients ne sont pas disponibles en dehors de l’environnement de production.
5.     Suivez les activités sur vos bases de données
Être conscient de la vérification et l’enregistrement du mouvement des données implique que vous sachiez quelles informations ont été traitées, quand, comment et par qui.
Disposer d’un historique complet des transactions vous permet de comprendre les schémas d’accès et de modification des données vous permet d’éviter les fuites d’informations, de contrôler les changements frauduleux et de détecter les activités suspectes en temps réel.
N’oubliez pas de suivre ces conseils et demeurez très prudent lorsque vous gérez et protégez vos bases de données. L’information qu’elles comprennent est très précieuse pour l’entreprise et très attrayante pour les attaquants; elles méritent donc certainement votre pleine attention.