Showing posts with label New York Times. Show all posts
Showing posts with label New York Times. Show all posts

Friday, 30 August 2013

Data breach interactive chart shows major increase in security flaws




Data breach interactive chart shows major increase in security flaws
If you didn’t believe us that hackers have been keeping themselves really busy in the last few years, this interactive graphic might just be the visual proof you need.
David McCandless of Information is Beautiful created the graphic with coder Tom Evans. It shows all the different “data breaches” that have occurred since 2004 affecting more than 30,000 people. Each attack is displayed as a bubble, based on that victim-count. You can also filter by year, method of leak, what was stolen, and the type of organization.
Pretty much any article about a hack you might read includes some mention of how “cyberattacks are growing,” and “the amount of hacks have increased in the last X amount of years.” This graphic gives those call-outs merit, but also highlights some of the internal mistakes companies have made that let regular folks accidentally leak out data .
As you scroll up from 2004, the size of the breaches actually seem to diminish slightly, but the frequency definitely increases and varies from hundreds of thousands to tens of millions of victims. You can click on each bubble to get a little more information about the breach and click through to a report.
Check it out and let us know what you think of the interactive graphic.

Wednesday, 28 August 2013

How Twitter Dodged Website Attack That Took Down New York Times

https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQGg7gOxaozaj-5-pT14xcPdzzCAwF9FCUYXoCwc9gbGGnc_VB9MA 
Chalk one up for Twitter Inc.
While the New York Times and Google Inc. (GOOG:US) had visitors to their sites redirected this week by hackers, the microblogging service was better able to deflect attacks because of a simple tool called a registry lock. Like alerts sent to credit-card users when something bad happens, the feature notifies website managers of attempts by intruders to tamper with critical information, such as Web-address data.
The cost? As little as $50 a year.
Large banks, e-commerce companies, gambling sites and pornographers have used registry locks from VeriSign Inc. (VRSN:US) and NeuStar Inc. (NSR:US) to prevent unauthorized changes. Attacks by the Syrian Electronic Army routed New York Times readers to a site that displayed the group’s initials and altered some registration data. They underscore how vulnerable many companies are to relatively unsophisticated attacks, which can take down sites and harm their businesses.
“This is certainly an ah-ha moment,” said Rodney Joffe, a senior technologist at NeuStar. The Sterling, Virginia-based company began offering registry locks in 2010 and requires that website domain information be accompanied by two layers of verification, such as additional codes from security tokens.
“It is a niche business but there’s no reason for it to be,” he said. “It’s the kind of thing you have to do today.”
While Twitter’s site operated normally, twitter.co.uk was inaccessible for some users. The Syrian Electronic Army, which backs the country’s president, Bashar al-Assad, claimed responsibility for the New York Times and Twitter intrusions, as well as the Washington Post this month and the Financial Times in early May. Unknown hackers altered Google’s website in the Palestinian territories, displaying a map without Israel.

Raising Bar

The attacks exploited weaknesses in a registration network called the Domain Name System, exposing risks that site operators face because they’re relying on third parties to handle their online addresses. Weaknesses in DNS, which was created in the 1980s to help computers find websites using names instead of numbers, haven’t been seen as a significant threat outside of the financial-services and retail sectors up to now, according to John Pescatore, director of emerging-security trends at the SANS Institute in Stamford, Connecticut.
“There are still a lot of sloppy practices,” Pescatore said. “There’s a lot of room to raise the bar.”
Because Twitter, based in San Francisco, monitors its DNS information in real time and had implemented a registry lock, it was better prepared than the New York Times, according to HD Moore, chief research officer at Rapid7, a Boston-based security firm. Since the attacks, many other companies have moved to institute similar safeguards, he said.

DNS Flaw

Twitter has had its DNS records hacked before. The company acknowledged in 2009 that its DNS records were compromised by hackers who defaced the site with a message about Iran. Jim Prosser, a spokesman for Twitter, declined to comment on the company’s security measures.
A vast system that underpins how computers locate each other, DNS is often called the phone book of the Internet. In 2008, Dan Kaminsky, a security researcher, uncovered a flaw in the system that would let hackers easily impersonate legitimate sites. He worked with technology companies to fix it. The finding prompted several companies that process financial transactions online to adopt additional security measures to ensure their domain information is secure, while others stayed on the sidelines, according to SANS’s Pescatore.

Security Steps

NeuStar and VeriSign, another provider of registry lock services, declined to identify the companies using its registry lock services. Danny McPherson, chief security officer of VeriSign, said in a statement that the technology gives customers more control over who can change information.
Eileen Murphy, a spokeswoman for the New York Times (NYT:US) Co., said the newspaper is looking at additional measures.
“In light of this attack and the apparent vulnerability even at what had been highly secure registrars, we are tightening all of our security,” she said.
Jay Nancarrow a spokesman for Google, declined to comment on the company’s security. The company’s Palestine site itself wasn’t hacked and Google is talking with the domain manager to resolve the issue, he said.
One complication of hosting sites with addresses of specific countries or regions is that many of the registration providers don’t use registry locks and other protective steps, said Paco Hope, a principal consultant with Cigital Inc.
“When you’re a company like the New York Times or Twitter or Google, your stock in trade is the Internet, it’s the service you offer, and that’s why it makes sense to put in a lot more security,” Hope said.
The rise in sophisticated hacking attacks is helping fuel a market for computer-security technology that is expected to exceed $65.7 billion this year, according to Gartner Inc.
Many companies that didn’t prioritize a threat involving their DNS records are now rethinking that approach, SANS’s Pescatore said.
“It’s one of several Achilles’ heels of using the Internet,

Times site affected by hacking attack




New York: The New York Times website was unavailable to readers on Tuesday afternoon after an online attack on the company's domain name registrar, Melbourne IT. The attack also forced employees of The Times to take care in sending emails.

Marc Frons, chief information officer for The New York Times Co., issued a statement at 4:20 p.m. warning employees that the disruption - which appeared to still be affecting the website well into the evening - was "the result of a malicious external attack." He advised employees to "be careful when sending email communications until this situation is resolved."

In an interview, Frons said the attack was carried out by a group known as "the Syrian Electronic Army, or someone trying very hard to be them."

The website first went down after 3 p.m.; once service was restored, the hackers quickly disrupted the site again. Shortly after 6 p.m., Frons said that "we believe that we are on the road to fixing the problem."

The Syrian Electronic Army is made up of hackers who support President Bashar Assad of Syria. Matt Johansen, head of the Threat Research Center at White Hat Security, posted on Twitter that he was directed to a Syrian Web domain when he tried to access The Times' website.

The SEA first emerged in May 2011, during the first Syrian uprisings, when they started attacking a wide array of media outlets and nonprofits and spamming popular Facebook pages like President Barack Obama's and Oprah Winfrey's with pro-Assad comments. Their goal, they said, was to offer a pro-government counter narrative to media coverage of Syria.

The group has consistently denied ties to the Assad government and has said it does not target Syrian dissidents, but security researchers and Syrian rebels are not convinced. They say the group is the outward-facing campaign of a much quieter surveillance campaign targeting Syrian dissidents and are quick to point out that Assad once referred to the SEA as "a real army in a virtual reality."

Until now, The Times has been spared from being hacked by the SEA, which has successfully disrupted the Web operations of news organizations including The Financial Times.

On Aug. 15, the group attacked The Washington Post's website through a third-party service provided by a company called Outbrain. At the time, the SEA also tried to hack CNN. Some information security experts said the group also appeared to be ready to attack The New York Times website that day. (Just a day earlier, on Aug. 14, The Times' website was down for several hours. The Times cited technical problems and said there was no indication the site was hacked.)

In a post on Twitter on Tuesday afternoon, the SEA also said it had hacked the administrative contact information for Twitter's domain name registry records. According to the Whois.com lookup service, the Syrian Electronic Army was listed on the entries for Twitter's administrative name, technical name and email address.

Jim Prosser, a Twitter spokesman, said the social network was "looking into" the Syrian Electronic Army's claim that it had taken control of a Twitter domain.

Frons said the attacks Tuesday on Twitter and The New York Times required significantly more skill than the string of SEA attacks on media outlets earlier this year, when the group attacked Twitter accounts for dozens of outlets ranging from The Guardian to The Associated Press. Those attacks caused the stock market to plunge after the group planted false tales of explosions at the White House.

"In terms of the sophistication of the attack, this is a big deal," said Frons. "It's sort of like breaking into the local savings and loan versus breaking into Fort Knox. A domain registrar should have extremely tight security because they are holding the security to hundreds if not thousands of websites."
© 2013, The New York Times News Service