Ramblings of an old Doc
“The more complex things become, the more vulnerable”
Published on January 24, 2011 By DrJBHL In Personal Computing

 

This isn’t Murphy's Law. It’s mine:  “The more complex things become, the more vulnerable”.

 

This is dedicated to tazgecko for reminding me to get off my duff and do this article. Thanks, mate, and an early, Happy Oz Day to you!

 

So, Cisco has put out it's 2010 Security Report analyzing events and projecting trends for 2011.

Link: http://www.cisco.com/en/US/prod/collateral/vpndevc/security_annual_report_2010.pdf

 

 

The Good:

There have been several large botnets “taken down” as a result of heightened Law Enforcement activity and prosecution. This has resulted in much less spam (90% less, in fact), and fewer attacks, but the number and rate are still alarming.

Also, large software vendors like Microsoft and Apple have been improving updates and notifications to customers about potential/actual flaws and patches or other “mitigators”.

The Bad:

Apple has been forced to deploy more than sixty patches to it's iOS 4 mobile platform and the Zeus-Trojan targeting Symbian OS phones are proof that miscreants are trying to exploit “Zero Day” vulnerabilities. I've reported on that in prior articles with respect to iE and all Windows OS's except W7.

Simply put, we're seeing evolution at work: Our “antibiotics” are creating more and more cybercriminals seeking easier “targets of opportunity”. The cybercriminals are moving from the desktop to the mobile devices.

Worse, efforts at “jail breaking” phones and other devices removes them from the security umbrella that was built into limiting their “point of access”.

The Stuxnet trojan/virus is another example, although it's purported use against Iran's nuclear effort was “good”, it will be modified by hackers for “bad” ends: Identity theft and other nefarious purposes.

So, while brief, and these are just some of the high points (or low points) from the forty five page Cisco Report, this summary should “encourage” you to “be careful out there”.


Comments (Page 1)
2 Pages1 2 
on Jan 24, 2011
Good job on this Doc. About time too....  
on Jan 24, 2011

You look like Bones McCoy and sound like Phil Esterhaus!

Basically, every "tool" can be used for good or bad depending upon in whose hands the tool resides.  Computers are seen as good - yet they are the primary tool of hackers.  I guess as Apple innovates more (and grabs a large share of new markets), they find out what Microsoft has known all along - nothing is impregnable.

And the DrJBHL Law?  Somethings are truisms that need no proof.  Yours being one of them (and Murphy's another ).

on Jan 24, 2011

Rats. And here I was thinking I was being brilliant and insightful.

on Jan 24, 2011

Rats. And here I was thinking I was being brilliant and insightful.

"I'm a Doctor Jim ... not a genius"

on Jan 24, 2011

There have been several large botnets “taken down” as a result of heightened Law Enforcement activity and prosecution. This has resulted in much less spam (90% less, in fact)

I wondered why my spam had dropped off so much, not that I'm complaining. A year or so ago I was getting at least 10x's as much as I am now.  Yay, go team go!!!

on Jan 24, 2011

Yep..that's good news, but the criminals go to where the pickins' are easier... these aren't hard workers.

A pity they don't turn their skills toward a constructive project, isn't it?

on Jan 25, 2011


Rats. And here I was thinking I was being brilliant and insightful.
"I'm a Doctor Jim ... not a genius"

Zing!

on Jun 08, 2011

BUMP!!!

Watched this on HungryBeast , thought it was worth posting ...

"In June last year, a computer virus called Stuxnet was discovered lurking in the data banks of power plants, traffic control systems and factories around the world.

Pandora’s box has been opened; on the new battlefield the aggressors are anonymous, the shots are fired without starting wars and the foot soldiers can pull their triggers without leaving their desks.

Last week the United States government announced they would retaliate to a cyber-attack with conventional force. The threat is real, and the age in which a computer bug could cost lives has begun."

 

on Jun 08, 2011

tazgecko
"In June last year, a computer virus called Stuxnet was discovered lurking in the data banks of power plants, traffic control systems and factories around the world.

As a corollary - in the old days, bugs were small, compact, and not as versatile.  They had to be,   Memory was expensive (and at least on the PC side, limited).  Now bugs - like Stuxnet - are malware bloatware.  But they do the job. Unfortunately.

on Jun 08, 2011

That video is some scary shit.

on Jun 08, 2011

Dr Guy
But they do the job.

Depends who's doing what to whom (and why): Case in point - Israel and Iran... I don't believe Israel built the trojan/virus, but I believe they used it effectively against a sworn enemy and knowing a little about the technology capabilities of Israel, if they wanted to build one, it'd make Stuxnet look like a common cold compared to the plague.


 

 

 

on Jun 08, 2011

Guys seriously, these concerns about Stuxnet are minimal.  Stuxnet was specifically designed for a type of centrifuge that nobody uses except Iran and it was in a big desperation attempt to reset the nuclear timetables.  The following investigations led to the US, Isreal, UK and to a very small degree France alongside Germany.  You don't have to worry about big doomsday scenarios with Stuxnet because it is not compatible with anything else out there.

Stuxnet is also the US's way of showing off to the rest of the world its new toy's capabilities like Desert Storm was.  A world infomercial so to speak.

on Jun 09, 2011

RogueCaptain
You don't have to worry about big doomsday scenarios with Stuxnet because it is not compatible with anything else out there.

Stuxnet ... no we don't have to worry about it. But like the video said, the code (and the know-how) is now out there. Programmers can change, develop and 'improve', for their own device.

on Jun 09, 2011

RogueCaptain
You don't have to worry about big doomsday scenarios with Stuxnet

Nope....only Skynet....

on Jun 09, 2011

"There have been several large botnets “taken down” as a result of heightened Law Enforcement activity and prosecution. This has resulted in much less spam (90% less, in fact), and fewer attacks, but the number and rate are still alarming."

 

Eh? 90%? Sources, sir? It's true that Rustnock botnet has been taked down, but 90%? Any law enforcement activity cannot solve the problem long-term, because the poorly administered end-user machines are just as vulnerable - it's only matter of time someone else starts zombifying them. 

2 Pages1 2