10/8/2017 from Wired. {abridged and removed overtly political jabs by DGL}
John Kelly's Hacked Phone Could Be a Major National Security Issue | WIRED
Politico reports that former Department of Homeland Security head and current chief of staff John Kelly used a personal
smartphone, possibly for months, that was compromised. That is bad. Don't do that.
The breach was apparently discovered over the summer, when Kelly gave the smartphone to White House tech support
after having problems with it and struggling to successfully run software updates. Several questions remain
unanswered, as to what type of phone Kelly was using, and what sort of access hackers may have had. The
possibilities run the gamut—and have potentially serious consequences.
"Having a phone compromised for several months definitely is not good," says David Kennedy, the CEO of TrustedSec,
who formerly worked at the NSA and with the Marine Corps' signal intelligence unit. "To what extent and who
compromised it is important. If it was just [run of the mill] malware it's probably not a big deal, but if it was a nation state,
monitoring phone communications, emails, and other data is all possible."
How Kelly's phone was compromised matters a lot. There are myriad ways it could have happened, and some are
relatively benign. If Kelly had an Android phone he may have gotten tricked into downloading a malicious app. Phishing
links and attachments also pose a constant threat no matter what device you're on. From there, a petty criminal might
have done something small, like secretly charging Kelly in-app fees or mining some relatively innocuous data. Nothing
too alarming there.
'If he's in classified meetings and the phone is in his pocket, hackers could eavesdrop and listen to
planning.'
David Kennedy, Former NSA Analyst
But there's also a whole gray market of security firms, like Zerodium and NSO Group, that sell mobile operating system
exploits and espionage tools to governments around the world. Any attacker with awareness about their target—and
deep pockets—could have used more sophisticated exploits to burrow deep into the device and start reconnaissance
and data-gathering, even potentially masquerading as Kelly on his accounts, or taking them over to mislead his
associates.
It's also hard to tell exactly how often and how long Kelly used the phone in question. Reports indicate that Kelly did
primarily use his hardened, government-issued smartphone, even while he still had his apparently compromised
personal phone around, but it's unclear how often he carried the extra device with him, and what he still relied on it for. A
White House spokesman told POLITICO that Kelly "hadn’t used the personal phone often since joining the
administration." It would be helpful to know how hard that "often" is working.
The incident was apparently considered
serious enough to warrant a memo about the situation in September.
A White House spokesman told WIRED, “Last December, General Kelly’s personal phone stopped working and he
discontinued its use,” a statement that still leaves the exact timeline open for interpretation.
Those details matter, because in a totally owned phone, hackers could have tracked his every move. Regardless of the method {used}, Kelly's data would have definitely been at risk. Attackers could
have used a keylogger to follow his every input. They would also potentially had access to his physical location through
GPS and cell ID data. If he stored any sensitive files on the device, needless to say, they would have been exposed.
But even assuming that Kelly did no confidential or nationally important work on the personal phone, even if he simply
used it to play Candy Crush, it still would have posed a major threat. Attackers can surreptitiously take over a
smartphone's microphone and camera, a particular concern given that Kelly takes meetings at the highest levels of
national security.
"If he's in classified meetings and the phone is in his pocket, hackers could eavesdrop and listen to planning," Kennedy
notes.
{DGL: here is a scenario that is relevant to the "average" citizen. You give your phone to someone you know because they want to make a call or they want to play a game. They download a "kid monitor" program without your knowledge. They enter their phone number as the recipient and turn the program on in the background, and in the settings they set the program to autostart. Now your phone is set up to do everything talked about above! Though national security was the topic above, your security, your home's security, the security of your kids and grandkids, etc is relevant to you.}
There are some protections against that sort of snooping, like device lockers in the West Wing where staffers are
encouraged to leave their phones, and Sensitive Compartmented Information Facilities, where officials shed all their
devices before discussing truly secret issues of national security. But human error is a problem. People don't always
comply with SCIF protocols.
"Most people, even though data breaches and surveillance are in the news every day, they still don’t really understand
that they could be targeted—they always think that it will never happen to them," says Larry Johnson, the CEO of
security firm CyberSponse who was a special agent in the Secret Service for 24 years and worked on cybersecurity in
the White House. "It’s like everything in security, it’s not convenient to be secure, but once you walk into the White
House you have to be cognizant of all of the things around you and anything that isn't quite right."
Experts say that it's surprising that Kelly in particular used a potentially compromised phone, given his past military and
command service.
Still, it's possible that Kelly was lucky, and whatever malware was on his phone just served him malicious ads and tried
to trick him out of some money. If it really was the worst case scenario, though, one or a handful of nation states may
have gained valuable intelligence that could haunt the United States for years. Without more information—and none
seems forthcoming—we'll never know just how worried we should be.
A source of computer tips and secrets for friends, neighbors, and family of Duane Leet. Noone reading this blog is tracked and no information is associated with anyone.
Sunday, October 8, 2017
Tuesday, September 19, 2017
Equifax Breach
I have been making mental notes about the Equifax security breach, intending to write a post on the issues involved; however, AskLeo! beat me to it. You know that I like AskLeo! because he is accurate and his writing is understandable but accurate- well, most of the time it is accurate. In the Equifax case, I will never be able to write about the issue better than Leo. So, here's the link, and Leo is where I am at on this: https://askleo.com/equifax-breach-means/?awt_l=8ysdX&awt_m=JgW.cUt4a3dfbL&utm_source=newsletter&utm_campaign=20170919&utm_medium=email&utm_content=featured
Wednesday, August 9, 2017
Problem with Spectrum Cable knocking out or damaging your home network
A number of household in our region are experiencing one or more of the following, especially when it is raining or going to rain in the area:
Solution: If you have the above symptoms, Spectrum service needs to be called. The service person needs to measure the cable power. If it is too high at your house, ie at the high end of normal then s/he will have to insert a device at the connector to your house that will lower the power further down into the safe range.
Note that, as of today, Spectrum is aware of the problem and they may change the power at a central level. I'm not sure that will work because everyone has a different distance to the house and different cables to the house. Lowering the power at a central point might impact those with long distances or small cable sizes. Also, those who have had the power lowered at their house may find the signal power lowered too much. We'll see.
Please communicate this to your friends and neighbors.
- The entire house network goes down.
- Network components are damaged: routers, TVs, receivers (requiring total replacement or servicing) The damage seems almost random, with some devices on the network, such as the cable modem, unaffected. With routers, maybe only one port is damaged, along with the ports of devices attached to that port via ethernet.
- Surge protectors "flip," but the surge is not detected as "incoming" from the power outlets.
- TV reception is erratic.
- Phone performance is erratic.
Solution: If you have the above symptoms, Spectrum service needs to be called. The service person needs to measure the cable power. If it is too high at your house, ie at the high end of normal then s/he will have to insert a device at the connector to your house that will lower the power further down into the safe range.
Note that, as of today, Spectrum is aware of the problem and they may change the power at a central level. I'm not sure that will work because everyone has a different distance to the house and different cables to the house. Lowering the power at a central point might impact those with long distances or small cable sizes. Also, those who have had the power lowered at their house may find the signal power lowered too much. We'll see.
Please communicate this to your friends and neighbors.
Saturday, June 17, 2017
Would you believe it-a built-in never being able to update Windows 10 to new Versions
There was a Windows 10 version, 1511 hat was one of the initial versions of Windows 10, during the time when the offer was available to go from Windows 7 or 8 to Windows 10. In fact, the general release schedule is:
So, even if you had automatic update on the entire time from the installation of Version 1511, as I did, Version 1607 may not have installed. Why? There is no rational reason that Microsoft can give. If you don't have Version 1607 installed, you can't ever get to any future version of Windows without doing a "clean install," where you have to reinstall all of your applications.
To find this out, I spent 2 weeks with Microsoft support, first at level 1 for a week, then at level 2, then doing phone tag for a week to get a level 3 person to talk to (that is about as high as you can go). The total number of hours spent by Microsoft support was probably 3 hours. However, the total time for level 3 was about 30 seconds, not counting having to listen to my consternation that the situation I described above actually exists. At the beginning of the conversation I told the level 3 person what my version was, so the conversation would have been 10 seconds, but that person still logged on to my computer and checked the version for himself. Then he just said that I couldn't update to any level without deleting all my programs. That was all! When I asked if I could see a knowledgebase article describing this situation, he said there was an internal article, but not an external article. When I asked why it wasn't publicized, there was no answer. (Ha!) When I asked why level 1 didn't know about this, he said he didn't know.
That's two rants this week. I must not be in a good mood.
By the way, no native English speaker in the chain of support, which I bet is part of the problem.Level 1, 2, and 3 could be continents away. Is that right, Microsoft?
- Version 1507, released 5/29/2015, retired 5/9/2017
- Version 1511, called "the November Update" released 11/10/2015
- Version 1607, called "the Anniversary Update" released 8/2/2016
- Version 1703, called "the Creators Update" released 4/5/2017
So, even if you had automatic update on the entire time from the installation of Version 1511, as I did, Version 1607 may not have installed. Why? There is no rational reason that Microsoft can give. If you don't have Version 1607 installed, you can't ever get to any future version of Windows without doing a "clean install," where you have to reinstall all of your applications.
To find this out, I spent 2 weeks with Microsoft support, first at level 1 for a week, then at level 2, then doing phone tag for a week to get a level 3 person to talk to (that is about as high as you can go). The total number of hours spent by Microsoft support was probably 3 hours. However, the total time for level 3 was about 30 seconds, not counting having to listen to my consternation that the situation I described above actually exists. At the beginning of the conversation I told the level 3 person what my version was, so the conversation would have been 10 seconds, but that person still logged on to my computer and checked the version for himself. Then he just said that I couldn't update to any level without deleting all my programs. That was all! When I asked if I could see a knowledgebase article describing this situation, he said there was an internal article, but not an external article. When I asked why it wasn't publicized, there was no answer. (Ha!) When I asked why level 1 didn't know about this, he said he didn't know.
That's two rants this week. I must not be in a good mood.
By the way, no native English speaker in the chain of support, which I bet is part of the problem.Level 1, 2, and 3 could be continents away. Is that right, Microsoft?
Thursday, June 15, 2017
The fault is yours, not the Russians!
Yes, I'm frustrated. All the stuff in the news about Russian hacking. The root causes of all the security breaches, whether email accounts, databases, or documents, are two:
- Someone clicked on something they shouldn't (phishing)
- Someone leaked information the shouldn't have, either because it was ethically wrong or it was legally wrong.
The lesson you need to take away from all this is that your clicking, your use of simple or the same password across multiple sites, your lax administration of your own IT environment, which allows any flash drive to insert bad stuff into your computer or take information out of your computing devices, is going to be the source of your security problems.
This whole episode in this country's history, and the whole assessment of your own security posture, is built on a lie if you don't follow the reasonable, responsible rules for internet security. You are at fault; stop shifting the blame!
Monday, June 12, 2017
An Internet of Things (IoT) Router for the Home
Over the years I've discussed routers in several posts. Most recently I talked about the need for a total house router that will protect your Internet of Things (IoT) Technically, I'm not really discussing the Internet of Things, but the Intranet of Things, ie, the stuff connected to your internal network, or Intranet.)
This kind of router is the Next Generation Firewall (NGFW). I've said that I could not find a router or firewall that was in the "home" price range; they were all $1000 or more and always stand-alone firewalls.
Norton has come out with a home solution. It is called the Norton Core Router (Amazon link) . I do not have this router. However, the literature reads like this device has the functions required to protect your IoT. You should take a look at it, especially if you are in a "greenfield" environment, such as a new home or small business, or you are replacing your router because you are changing providers. Again, a disclaimer... I haven't used this device.
This kind of router is the Next Generation Firewall (NGFW). I've said that I could not find a router or firewall that was in the "home" price range; they were all $1000 or more and always stand-alone firewalls.
Norton has come out with a home solution. It is called the Norton Core Router (Amazon link) . I do not have this router. However, the literature reads like this device has the functions required to protect your IoT. You should take a look at it, especially if you are in a "greenfield" environment, such as a new home or small business, or you are replacing your router because you are changing providers. Again, a disclaimer... I haven't used this device.
Monday, June 5, 2017
Important Reference Page for Windows 10 update errors
I've experienced a spat of Windows 10 upgrade errors in the past month. In addition, people are reporting that their Windows 10 machines are "freezing" during operation or startup. Their computer is useless. The problem seems associated with either the incremental upgrades or with the big upgrade, "Creators Version." (version 1703, Builds 10.0.15063 and up)
In other blog entries I have been and will be reporting on specific situations, but here I want to document an important reference page for Windows upgrade errors. This entry is not for the casual user; it's for the IT pro. But I need to refer to it on a regular basis, so I am putting it in my blog. For those of you that are IT proficient, this page will be useful.
I'm working pretty much full time on computers with upgrade problems. Some are diagnosed with hardware issues, some are related to the fast start option, coupled with partial upgrades in progress, and some are undiagnosed.
Subscribe to:
Posts (Atom)