Sunday, October 8, 2017

A Lesson in Personal and Professional Phone Security Responsibility

10/8/2017 from Wired. {abridged and removed overtly political jabs by DGL}
 
John Kelly's Hacked Phone Could Be a Major National Security Issue | WIRED

Politico reports that former Department of Homeland Security head and current chief of staff John Kelly used a personal smartphone, possibly for months, that was compromised. That is bad. Don't do that. The breach was apparently discovered over the summer, when Kelly gave the smartphone to White House tech support after having problems with it and struggling to successfully run software updates. Several questions remain unanswered, as to what type of phone Kelly was using, and what sort of access hackers may have had. The possibilities run the gamut—and have potentially serious consequences. "Having a phone compromised for several months definitely is not good," says David Kennedy, the CEO of TrustedSec, who formerly worked at the NSA and with the Marine Corps' signal intelligence unit. "To what extent and who compromised it is important. If it was just [run of the mill] malware it's probably not a big deal, but if it was a nation state, monitoring phone communications, emails, and other data is all possible."

How Kelly's phone was compromised matters a lot. There are myriad ways it could have happened, and some are relatively benign. If Kelly had an Android phone he may have gotten tricked into downloading a malicious app. Phishing links and attachments also pose a constant threat no matter what device you're on. From there, a petty criminal might have done something small, like secretly charging Kelly in-app fees or mining some relatively innocuous data. Nothing too alarming there. 'If he's in classified meetings and the phone is in his pocket, hackers could eavesdrop and listen to planning.' David Kennedy, Former NSA Analyst But there's also a whole gray market of security firms, like Zerodium and NSO Group, that sell mobile operating system exploits and espionage tools to governments around the world. Any attacker with awareness about their target—and deep pockets—could have used more sophisticated exploits to burrow deep into the device and start reconnaissance and data-gathering, even potentially masquerading as Kelly on his accounts, or taking them over to mislead his associates.

It's also hard to tell exactly how often and how long Kelly used the phone in question. Reports indicate that Kelly did primarily use his hardened, government-issued smartphone, even while he still had his apparently compromised personal phone around, but it's unclear how often he carried the extra device with him, and what he still relied on it for. A White House spokesman told POLITICO that Kelly "hadn’t used the personal phone often since joining the administration." It would be helpful to know how hard that "often" is working.

The incident was apparently considered serious enough to warrant a memo about the situation in September. A White House spokesman told WIRED, “Last December, General Kelly’s personal phone stopped working and he discontinued its use,” a statement that still leaves the exact timeline open for interpretation. Those details matter, because in a totally owned phone, hackers could have tracked his every move.  Regardless of the method {used}, Kelly's data would have definitely been at risk. Attackers could have used a keylogger to follow his every input. They would also potentially had access to his physical location through GPS and cell ID data. If he stored any sensitive files on the device, needless to say, they would have been exposed. But even assuming that Kelly did no confidential or nationally important work on the personal phone, even if he simply used it to play Candy Crush, it still would have posed a major threat. Attackers can surreptitiously take over a smartphone's microphone and camera, a particular concern given that Kelly takes meetings at the highest levels of national security. "If he's in classified meetings and the phone is in his pocket, hackers could eavesdrop and listen to planning," Kennedy notes.

{DGL:  here is a scenario that is relevant to the "average" citizen.  You give your phone to someone you know because they want to make a call or they want to play a game.  They download a "kid monitor" program without your knowledge.  They enter their phone number as the recipient and turn the program on in the background, and in the settings they set the program to autostart.  Now your phone is set up to do everything talked about above!  Though national security was the topic above, your security, your home's security, the security of your kids and grandkids, etc is relevant to you.}

There are some protections against that sort of snooping, like device lockers in the West Wing where staffers are encouraged to leave their phones, and Sensitive Compartmented Information Facilities, where officials shed all their devices before discussing truly secret issues of national security. But human error is a problem. People don't always comply with SCIF protocols. "Most people, even though data breaches and surveillance are in the news every day, they still don’t really understand that they could be targeted—they always think that it will never happen to them," says Larry Johnson, the CEO of security firm CyberSponse who was a special agent in the Secret Service for 24 years and worked on cybersecurity in the White House. "It’s like everything in security, it’s not convenient to be secure, but once you walk into the White House you have to be cognizant of all of the things around you and anything that isn't quite right." Experts say that it's surprising that Kelly in particular used a potentially compromised phone, given his past military and command service. Still, it's possible that Kelly was lucky, and whatever malware was on his phone just served him malicious ads and tried to trick him out of some money. If it really was the worst case scenario, though, one or a handful of nation states may have gained valuable intelligence that could haunt the United States for years. Without more information—and none seems forthcoming—we'll never know just how worried we should be.

Tuesday, September 19, 2017

Equifax Breach

I have been making mental notes about the Equifax security breach, intending to write a post on the issues involved; however, AskLeo! beat me to it.  You know that I like AskLeo! because he is accurate and his writing is understandable but accurate- well, most of the time it is accurate.  In the Equifax case, I will never be able to write about the issue better than Leo.  So, here's the link, and Leo is where I am at on this:  https://askleo.com/equifax-breach-means/?awt_l=8ysdX&awt_m=JgW.cUt4a3dfbL&utm_source=newsletter&utm_campaign=20170919&utm_medium=email&utm_content=featured

Wednesday, August 9, 2017

Problem with Spectrum Cable knocking out or damaging your home network

A number of household in our region are experiencing one or more of the following, especially when it is raining or going to rain in the area:

  • The entire house network goes down.
  • Network components are damaged:  routers, TVs, receivers (requiring total replacement or servicing)  The damage seems almost random, with some devices on the network, such as the cable modem, unaffected.  With routers, maybe only one port is damaged, along with the ports of devices attached to that port via ethernet.
  • Surge protectors "flip," but the surge is not detected as "incoming" from the power outlets.
  • TV reception is erratic.
  • Phone performance is erratic.
Here is what is happening:  The cable to your house is serving power to your house network components (via cable and then out through the ethernet cables) that is at the very high end of what is acceptable.  When it is going to rain or is raining in the area, the temperature naturally drops by, say, 8 degrees F.  This affects the cable power into your house, raising the effective power over what your house components can handle. The result is the list above.

Solution:  If you have the above symptoms, Spectrum service needs to be called.  The service person needs to measure the cable power.  If it is too high at your house, ie at the high end of normal then s/he will have to insert a device at the connector to your house that will lower the power further down into the safe range.

Note that, as of today, Spectrum is aware of the problem and they may change the power at a central level.  I'm not sure that will work because everyone has a different distance to the house and different cables to the house.  Lowering the power at a central point might impact those with long distances or small cable sizes.  Also, those who have had the power lowered at their house may find the signal power lowered too much.  We'll see.

Please communicate this to your friends and neighbors.    

Saturday, June 17, 2017

Would you believe it-a built-in never being able to update Windows 10 to new Versions

There was a Windows 10 version, 1511 hat was one of the initial versions of Windows 10, during the time when the offer was available to go from Windows 7 or 8 to Windows 10.  In fact, the general release schedule is:

  • Version 1507, released 5/29/2015, retired 5/9/2017
  • Version 1511, called "the November Update" released 11/10/2015
  • Version 1607, called "the Anniversary Update" released 8/2/2016
  • Version 1703, called "the Creators Update" released 4/5/2017
The problem is, if you  want to update from Version 1511- yes update, not upgrade- to Version 1607, you can't!  For some reason an update route is not provided!  If you want to update to Version 1703 from version 1511, you can, but you have to wipe away all your installed programs; data is saved, but not programs.

So, even if you had automatic update on the entire time from the installation of Version 1511, as I did, Version 1607 may not have installed.  Why?  There is no rational reason that Microsoft can give.  If you don't have Version 1607 installed, you can't ever get to any future version of Windows  without doing a "clean install," where you have to reinstall all of your applications.

To find this out, I spent 2 weeks with Microsoft support, first at level 1 for a week, then at level 2, then doing phone tag for a week to get a level 3 person to talk to (that is about as high as you can go).  The total number of hours spent by Microsoft support was probably 3 hours.   However, the total time for level 3 was about 30 seconds, not counting having to listen to my consternation that the situation I described above actually exists.  At the beginning of the conversation I told the level 3 person what my version was, so the conversation would have been 10 seconds, but that person still logged on to my computer and checked the version for himself.  Then he just said that I couldn't update to any level without deleting all my programs.  That was all!  When I asked if I could see a knowledgebase article describing this situation, he said there was an internal article, but not an external article.  When I asked why it wasn't publicized, there was no answer.  (Ha!)  When I asked why level 1 didn't know about this, he said he didn't know.

That's two rants this week.  I must not be in a good mood.

By the way, no native English speaker in the chain of support, which I bet is part of the problem.Level 1, 2, and 3 could be continents away. Is that right, Microsoft?

Thursday, June 15, 2017

The fault is yours, not the Russians!


Yes, I'm frustrated.  All the stuff in the news about Russian hacking.  The root causes of all the security breaches, whether email accounts, databases, or documents, are two:

  1. Someone clicked on something they shouldn't (phishing)
  2. Someone leaked information the shouldn't have, either because it was ethically wrong or it was legally wrong. 
Folks, this is a human problem, not a technology problem. And it is not 'their' fault.  Whether it is Hillary's server, the Democrat server, any of Hillary's comrade's emails, or documents released from undisclosed resources, the fault lies with the Democrats, Hillary, Hillary's comrades, or the deep state; it is not the fault of the Russians.  The "Russians" is just a euphemism for those out there that are trying to get information.  The Russians may in fact be Russians, but from a technological certainty, any one with a little technological black hat experience can fake the origin as Russians.

The lesson you need to take away from all this is that your clicking, your use of simple or the same password across multiple sites, your lax administration of your own IT environment, which allows any flash drive to insert bad stuff into your computer or take information out of your computing devices, is going to be the source of your security problems.

This whole episode in this country's history, and the whole assessment of your own security posture, is built on a lie if you don't follow the reasonable, responsible rules for internet security.  You are at fault; stop shifting the blame!


Monday, June 12, 2017

An Internet of Things (IoT) Router for the Home

Over the years I've discussed routers in several posts. Most recently I talked about the need for a total house router that will protect your Internet of Things (IoT) Technically, I'm not really discussing the Internet of Things, but the Intranet of Things, ie, the stuff connected to your internal network, or Intranet.)

This kind of router is the Next Generation Firewall (NGFW).  I've said that I could not find a router or firewall that was in the "home" price range; they were all $1000 or more and always stand-alone firewalls.

Norton has come out with a home solution.  It is called the Norton Core Router (Amazon link) .  I do not have this router.  However, the literature reads like this device has the functions required to protect your IoT.  You should take a look at it, especially if you are in a "greenfield" environment, such as a new home or small business, or you are replacing your router because you are changing providers.  Again, a disclaimer... I haven't used this device.


Monday, June 5, 2017

Important Reference Page for Windows 10 update errors

I've experienced a spat of Windows 10 upgrade errors in the past month.  In addition, people are reporting that their Windows 10 machines are "freezing" during operation or startup.  Their computer is useless.  The problem seems associated with either the incremental upgrades or with the big upgrade, "Creators Version." (version 1703, Builds 10.0.15063 and up)  

In other blog entries I have been and will be reporting on specific situations, but here I want to document an important reference page for Windows upgrade errors.  This entry is not for the casual user; it's for the IT pro.  But I need to refer to it on a regular basis, so I am putting it in my blog.  For those of you that are IT proficient, this page will be useful.  


I'm working pretty much full time on computers with upgrade problems.  Some are diagnosed with hardware issues, some are related to the fast start option, coupled with partial upgrades in progress, and some are undiagnosed.  

Printfriendly

Print Friendly and PDF