Wednesday, June 22, 2011

American Companies Will Be Forced To Disclose Hacks

Following the well-known recent Sony affair, American companies will be demanded to disclose if they’ve been hacked. That’s the essence of the new legislation currently drafted in Congress.

The idea for new legislation has been suggested by Mary Bono Mack, a Republican from California. All Mary Bono Mack wants is to see companies demanded to provide a basic level of protection for their customers' personal data, and if they fail it, they have to notify the government of the problem.

After Mack had held hearings on data leaks at Sony and Epsilon, a bill was promised to be brought in, specifically designed to protect user personal data. Now, if the proposed legislation gets the votes, it will force US businesses to protect their own consumers by at least requiring reasonable security policies and procedures able to protect information containing personal data. But the most interesting part is that the new law will provide for nationwide notice in case of a hack.

The bill is already circulating through the government. For example, the National Journal has revealed that the Commerce, Manufacturing, and Trade Subcommittee of the House Energy and Commerce Committee has scheduled a hearing for tomorrow to discuss the proposal.

Mary Bono Mack is reported to have had an aggressive timetable for pushing the draft through subcommittee and full committee. The reason for the rush is that punters can’t wait and want something done right now.

According to the new legislation, all companies in the United States would be demanded to erase old or unnecessary information. They would also be required to notify the government no later than 2 days after discovering a data loss. This part of the legislation is supposed to prevent wide-spread situations where outdated databases without protection were still kept on the company network, becoming a soft target for intruders.

However, the bill specifies that the companies wouldn’t have to tell about the breach if it’s "an accident". That promises to be quite interesting to see if the companies try and use this clause as a reason for not publicizing their failures. Finally, the law would provide the FTC with the authority over information protection at non-commercial organizations like universities and charities.

Saturday, June 11, 2011

Sony Criticized For Lack Of Cybersecurity

The recent hack at Sony has left customers angry and security experts wondering why the company didn’t make basic fixes to its stricken cybersecurity program.

Late last week the hackers managed to compromise a massive amount of users’ personal data from Sony Pictures’ site using a simple technique. Security experts pointed out that the leak indicated how poorly Sony protected its users’ information: its security was bypassed by a simple attack method. The experts say that any website worth its salt should be able to withstand attacks of this kind. Considering that Lulz Security effortlessly managed to steal a massive amount of personal data of over 1,000,000 Sony users, the hackers must be lining up to give Sony a kicking.

Meanwhile, Sony CEO acknowledged the latest intrusion last Friday, claiming that the company had taken steps to protect against further security breaches. In addition, Sony was reported to retain a team of experts tasked to conduct the forensic analysis of the attack. However, Sony didn’t detail what specific action was taken to prevent future intrusion.

Lulz Security uploaded the stolen data to The Pirate Bay to prove that Sony stored its users’ passwords in a simple text file, which can only be called “disgraceful and insecure”.

Affected users blame Sony for allowing the intruders compromise their personal data, saying that such attitude showed little respect to the customers. Moreover, the company even failed to notify the users about the breach, which occurred several days ago.

Experts of the Cyber Consequences Unit of the United States, a research group engaged in monitoring online threats, were emphatic when asked whether people’s passwords could be stored unencrypted: they simply replied: “Never”. Passwords should always be hashed, so the companies should use some kind of encryption. U.S. Cyber Consequences Unit’s experts, who have been critical of the company’s security earlier, claimed that it needed to revise the methods used to safeguard the users’ personal information. Both Sony customers and security experts recommend the company to press the reset button on their cybersecurity program before another breach happens.

Tuesday, May 31, 2011

The Pirate Bay Sued By Finnish Record Labels

The largest BitTorrent tracker site in the world The Pirate Bay has been sued again. Now the plaintiffs are more than twenty record labels from Finland, desperately attempting to halt piracy in their country. The petition to block The Pirate Bay was sent by the country's Copyright Information and Anti-Piracy Center on behalf of the IFPI.

Finnish pro-copyright outfit, which claims its goal is to ensure favorable operational conditions for the recording industry in the country, represents 23 record labels that launched a lawsuit at the Helsinki District Court. Like other similar outfits, the International Federation of the Phonographic Industry (IFPI) in Finland required the court to order telecommunications company called Elisa to deny access to a popular Swedish site providing Internet users with access to copyrighted content like music, films, and other material. The representative of the IFPI claimed that a legitimate online market can’t develop in country if infringing services like The Pirate Bay are allowed to go on with their operations.

In response, the Internet service provider argued that it doesn't condone piracy in the Internet, and refused to block access to The Pirate Bay unless the court orders it to do so.

Founded 8 years ago, the BitTorrent tracker allows millions of people to share copyrighted content through BitTorrent technology, or P2P links offered on the website. Two years ago, the website founders were fined and sentenced to prison for copyright infringement, but The Pirate Bay is still operational. However, the members of the service are still being pursued.

For example, recently the Denmark judge ruled that the website member nicknamed Icenfire should pay over $35,000 in damages for movie upload. The movie in question was Anders Matthesen’s comedy of 2009, “Black balls”, which was released on Blu-ray in the country, but the United States and Canada never saw the movie in the stores. The fine included the cost of the violation itself ($28,000) and associated court costs ($7,500). The individual was singled out by a Danish pro-copyright group, which claimed he was the original uploader. The outfit had raided his home in Denmark back in February, right after the routine analysis revealed the unauthorized upload


Monday, May 23, 2011

Sony PSN Hacked Again; 100-M Users' Info Stolen

NEW YORK — Sony Corp has been hacked again, exposing more security issues for the company less than a month after intruders stole personal information from more than 100 million online user accounts.

A hacked page on a Sony website in Thailand directed users to a fake site posing as an Italian credit card company. The site was designed to steal information from customers, Internet security firm F-Secure disclosed on Friday.

It is the latest in a series of security headaches for Sony, which discovered in April hackers had broken into its PlayStation Network and stole data from more than 77 million accounts. On May 2, Sony disclosed hackers had also stolen data from about 25 million user accounts of the Sony Online Entertainment website, a PC-based games service.

The PlayStation attack, considered the biggest in Internet history, prompted the Japanese electronics giant to shut down its PlayStation Network and other services for close to a month.

"It's a Sony security issue," said Jennifer Kutz, a representative for F-Secure, referring to the fraudulent website.

The latest hacking, which the security company said occurred separately from the April attack, was reported just hours after Sony told customers of another breach on one of its units.

So-Net, the Internet service provider unit of Sony, alerted customers on Thursday that an intruder had broken into its system and stolen virtual points worth $1,225 from account holders.

Critics have slammed the company for not protecting its networks securely and then waiting up to a week before telling its customers of the attack and the possible theft of credit card information, prompting lawmakers and state attorneys general to launch investigations.

Security experts said they were not surprised that the electronics company has not yet fixed weaknesses in its massive global network. Earlier this week, Sony shut down one of its websites set up to help millions of users change their passwords after finding a security flaw.

"Sony is going through a pretty rigorous process and finding the holes to fill," said Josh Shaul, chief technology officer for computer security firm Application Security Inc.

"The hackers are going through the same process and they're putting their fingers in the holes faster than Sony can fill them."

"What we've done is stopped the So-Net points exchanges and told customers to change their passwords," So-Net said in a statement in Japanese to consumers.

About 100,000 yen ($1,225) was stolen from accounts that were attacked. The company said there was no evidence other accounts in the online system had been compromised.

"At this point in our investigations, we have not confirmed any data leakage. We have not found any sign of a possibility that a third party has obtained members' names, address, birth dates and phone numbers."

Security experts have told Reuters Sony's networks around the world remain vulnerable to attack.

Sony's string of security problems could be attracting more hackers to attack its networks.

"I think it's now 'I'm a hacker and I'm bored, let's go after Sony,'" Shaul said.

A Sony representative in the United States could not immediately be reached for comment.