Showing posts with label Expert. Show all posts
Showing posts with label Expert. Show all posts

Saturday, 7 September 2013

Trust no one, advises security expert after NSA revelations

IDG News Service - The U.S. National Security Agency's efforts to defeat encrypted Internet communications, detailed in news stories this week, are an attack on the security of the Internet and on users' trust in the network, some security experts said.

The NSA and intelligence agencies in allied countries have found ways to circumvent much of the encryption used on the Internet, according to stories published by The New York Times, ProPublica and the Guardian. The NSA, the British GCHQ and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies, according to the news reports.

The reports, relying on documents provided by former NSA contractor Edward Snowden, show that many tech companies are collaborating with the spy agencies to "destroy privacy," said cryptographer and security specialist Bruce Schneier. "The fundamental fabric of the Internet has been destroyed."

The new revelations should raise major concerns from Internet users over who they can trust, Schneier added. "I assume that all big companies are now in cahoots with the NSA, cannot be trusted, are lying to us constantly," he said. "You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer."

It doesn't appear that the NSA is defeating encryption by brute force but by "cheating" by attempting to build backdoors into systems and strong-arm companies into giving it information, Schneier said.

Digital rights group the Center for Democracy and Technology echoed some of Schneier's concerns, with CDT senior staff technologist Joseph Lorenzo Hall calling the NSA's encryption circumvention efforts "a fundamental attack on the way the Internet works."

The NSA has been working for years to build backdoor vulnerabilities into encryption standards and technology products, the stories said. A representative of the NSA didn't respond to a request for comment on the stories.

Hall criticized those efforts. "In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it's incredibly destructive for the NSA to add flaws to such critical infrastructure," he said in an email. "The NSA seems to be operating on the fantastically naA-ve assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners."

The New York Times story this week, citing a Guardian report from July, said Microsoft has worked with the NSA to provide the agency with pre-encryption access to Outlook, Skype and other products.

Microsoft has repeatedly denied helping the NSA break encryption on its products. The company complies with legal court orders for information on its customers and will provide agencies with unencrypted customer information residing on its servers if ordered by a court to do so, a spokeswoman said.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Wednesday, 21 August 2013

Security expert kick-starts fund to pay Facebook bug finder a $10K bounty

Computerworld - After a Palestinian researcher was denied a bug bounty by Facebook, Marc Maiffret, CTO of BeyondTrust, kicked off a crowd-sourced fund yesterday to come up with a reward.

The researcher, Khalil Shreateh, expressed his gratitude today to Maiffret and others who have contributed to the fund. "Thank you so much. I never imagined what they will do for me," Shreateh said in a telephone interview.

Seventy-nine people have contributed nearly $9,000 in the last 24 hours to an account that will be handed over to Shreateh once it reaches the goal of $10,000.

Maiffret seeded the fund with $3,000 of his own money after appearing on CNN to talk about the Facebook vulnerability that Shreateh found.

Earlier this month Shreateh reported a vulnerability to Facebook's bug bounty program, saying that he had found a way to post content to any user's timeline, even when not on a victim's friends list. Facebook rebuffed him in return emails and ultimately claimed his discovery wasn't a bug.

Frustrated, Shreateh took matters into his own hands and planted a message on CEO Mark Zuckerberg's Facebook timeline.

That got the attention of Facebook's security engineers, who quickly locked Shreateh out of his account. After restoring his access, Facebook said it would not pay him a bounty.

"The more important issue here is with how the bug was demonstrated using the accounts of real people without their permission," said Facebook software engineer Matt Jones in a Sunday entry on Hacker News. "Exploiting bugs to impact real users is not acceptable behavior for a white hat."

Jones did acknowledge that Facebook should have asked Shreateh for more information before dismissing his report, but he also ticked off a list of reasons, including the fact that Facebook receives "hundreds of reports each day" and the lack of detailed proof in Shreateh's original report. He also intimated that Shreateh's poor English skills had been a problem.

In an interview on CNN Monday, Maiffret took exception to Facebook's decision not to reward Shreateh.

"Ultimately, he helped kill a bug that could have been used by pretty bad guys out there to do things against Facebook users," said Maiffret. "Ultimately, he did a great thing and I don't think that should be lost in all this."

The vulnerability was certainly worth money to criminals, Maiffret asserted. "It would have been something that was very useful to folks in the underground to be able to post different content on celebrity sites or whatever it might have been, to be able to lure people to websites that would then attack them," he said. "With the nature of the severity, it would be good for Facebook to pay the guy."

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Wednesday, 7 August 2013

Media Alert: July 31, 2013 - Facebook Stock Rebound: UMD-Smith Expert Comments

MEDIA ALERT: July 31, 2013
Attention: Finance Reporters

Facebook Stock Rebound: UMD-Smith Expert Comments

COLLEGE PARK, Md. - David Kass, Tyser Teaching Fellow in finance at the University of Maryland’s Robert H. Smith School of Business, comments on Facebook’s price per share rebounding to near its $38 IPO level (from May 2012) after trading as low as $17.55 last September.

The Smith School has an in-house facility for live or taped interviews via fiber-optic line for television or multimedia content.

"The reason for this increase is a much better-than-expected earnings report. Revenues and profits were higher than analyst forecasts, especially for mobile users. Revenue increased 53 percent versus second quarter 2012, while operating profit increased 54 percent. Revenue from advertising ($1.6 billion) represented 88 percent of total revenue and a 61 percent increase from the same quarter last year. Mobile advertising revenue represented 41 percent of advertising revenue for second quarter 2013.

"If Facebook can continue to grow its advertising revenues rapidly, especially in the high growth mobile area, the outlook for its stock performance is very good. However, Facebook's price-earnings ratio, which exceeds 50:1, leaves little room for disappointment.”

Kass has held senior positions with the Federal Trade Commission, General Accounting Office, Department of Defense, and the Bureau of Economic Analysis. His teaching includes advanced financial management and business finance, and he has launched a Smith School “Warren Buffett” blog. He has appeared on Bloomberg TV, CNBC, PBS Nightly Business Report and others.

Phone/Email: 301-405-9683, dkass@rhsmith.umd.edu
Bio: www.rhsmith.umd.edu/finance/faculty/kass.aspx
Twitter: twitter.com/DrDavidKass

About the University of Maryland's Robert H. Smith School of Business
The Robert H. Smith School of Business is an internationally recognized leader in management education and research. One of 12 colleges and schools at the University of Maryland, College Park, the Smith School offers undergraduate, full-time and part-time MBA, executive MBA, online MBA, MS in business, PhD and executive education programs, as well as outreach services to the corporate community. The school offers its degree, custom and certification programs in learning locations in North America and Asia.


View the original article here