Wednesday, 14 August 2013

Russian pleads not guilty in biggest U.S. hacking case

NEWARK, New Jersey/SAN FRANCISCO (Reuters) - A Russian man accused of being part of the largest cybercrime ring ever prosecuted in the United States pleaded not guilty on Monday to charges that could send him to prison for decades.
Dmitriy Smilianets, 29, of Moscow, entered the plea during an afternoon hearing in federal court in Newark, New Jersey.
His attorney told Reuters that he would fight the charges and that he was looking into possible irregularities with the circumstances of his arrest last year in the Netherlands.
Smilianets wore an orange prison jumpsuit and stood with shackled hands and feet during the appearance with lawyer Bruce Provda before U.S. District Judge Jerome Simandle.
Smilianets is accused of conspiring with a team of hackers from Russia and the Ukraine to steal more than 160 million credit card numbers in a series of breaches that cost victim companies more than $300 million.
The companies infiltrated included financial firms such as NASDAQ and Heartland Payment Systems Inc, along with other well-known names including JetBlue Airways Corp and retailer J.C. Penney Co of Plano, Texas.
Prosecutors allege Smilianets sold the stolen data after it was taken by four other members of his team, including credit card data starting at $10 for an American number and $50 for a European number.
Smilianets was extradited to the United States in September 2012 and has remained in federal custody since. In Russia, he was most widely known as the founder of a championship electronic gaming team called Moscow 5, which traveled the world for competitions. Online, his handles included Dima Brave and Dima Bold.
If convicted, he faces up to 30 years for conspiracy to commit wire fraud, another 30 years for wire fraud and five years each for gaining unauthorized access to computers and conspiracy to gain access.
Also arrested in the Netherlands was Vladimir Drinkman, who remains there fighting extradition. Amid a general worsening of relations with Russia exacerbated by intelligence agency leaker Edward Snowden's flight there, prosecutors last month also unsealed an indictment against another alleged member of the ring still free in that country, Alexandr Kalinin.
YEARS-LONG PURSUIT
Authorities have been pursuing the hackers for years. Many of the breaches were previously reported, though it appeared the one involving Nasdaq OMX Group Inc was disclosed for the first time in July.
Prosecutors said each of the defendants had specialized tasks: Drinkman and Alexandr Kalinin hacked into networks, while Roman Kotov, 32, mined them for data. They allegedly hid their activities using anonymous web-hosting services provided by Mikhail Rytikov, 26, of Ukraine.
Rytikov has not been arrested, but an attorney for him, Arkady Bukh, attended Monday's hearing. Bukh said his client did not know Smilianets.
According to prosecutors, the five men hid their efforts by disabling victims' anti-virus software and storing data on multiple hacking platforms, prosecutors said. They sold payment card numbers to resellers, who then resold them on online forums or to "cashers" who encode the numbers onto blank plastic cards.
The indictment cited Albert Gonzalez as a co-conspirator. Gonzalez is already serving 20 years in prison after pleading guilty to helping mastermind one of the schemes.
Prosecutors say the defendants worked with Gonzalez before his arrest in Miami, then continued on a crime spree after his capture.
Kalinin and Drinkman were previously charged in New Jersey as "Hacker 1" and "Hacker 2" in a 2009 indictment charging Gonzalez in connection with five breaches.
The NASDAQ breach did not include the trading platform that allows NASDAQ customers to buy and sell securities, prosecutors said. Officials with NASDAQ declined to comment.
An official briefed on that incident said the group wasn't able to get any money from their NASDAQ access.
Other victims included Dow Jones, Wet Seal Inc and 7-Eleven Inc, according to prosecutors.
Dow Jones said in a statement that there was "no evidence" that information of Dow Jones or Wall Street Journal customers information was compromised as a result of the breaches.

Comment is free : Observe, Make, Hack: reflections on a hacker camp

The outdoors gathering sparked passionate debate and disagreement – but we all chose to be there to tackle the difficult conversations that will shape our future

festcal
The lights of the Observe, Make, Hack festival. Photograph: @micahflee
Last week marked Observe, Make, Hack – the largest outdoor gathering of hackers, academics, activists and spooks descending upon a campsite in The Netherlands for a week once every four years.
Wandering around the paddocks on the first night of camp, the laser lights and smoke in an empty space known as Rainbow Island at the edge of the camp caught my attention.
“A bit sad isn’t it? That huge space, filled with lights and nobody dancing ...”, I said. Hacktivist Jason Gulledge paused beside me before answering: “Imagine it as a practice run. We all live in our dreams of what could be.”
I fell into crowd-sourcing news back in 2009, sharing thousands of articles about Wikileaks, hackers, the Pirate Bay, Anonymous, Lulzsec and mass surveillance. I eventually took a professional role crowd-sourcing news from online social media on behalf of print media outlets.
I’ve seen some fairly shocking images scrolling down my screen in those years – bloated corpses of Syrian babies, teenagers murdered in Bahrain, Occupy protesters pepper sprayed and beaten: the 24/7 gore of the journalism sausage. And in that time, many of the digital dissidents myself and many others followed and interacted with – Barrett Brown, Jeremy Hammond, Anakata, Jake Davis and more – have one-by-one been prosecuted, persecuted and jailed.
And we’ve been witnessing the never-ending ramp-up of military contractors, constantly clamoiring for billions to take military action over claims of cyber war. That’s not to say there aren’t online threats, but it’d be nice if our governments were as willing to put their dollars into defending critical infrastructure as opposed to launching offensive attacks.
Frankly, news in recent years have been a little depressing, which is how I came to book a spur of the moment, round-ticket from Australia to Europe, desperate to find a thread to hold onto – a belief that the future holds something more than the dystopian reality that has rushed up on us, fermented into a pervasive Big Brother regime of NATO-state condoned totalitarian surveillance. And so in the background of all this gathered perhaps some of the most interesting people alive on the planet.
There was Thomas Drake, NSA whistleblower; Jesselyn Radack, a US department of justice whistleblower; the geeks behind GlobalLeaks, the the first open-source whistleblowing framework; Christopher Schwartz, the young editor in chief behind New Eurasia (one of the only English-speaking news websites featuring activists from Central Asia); the hackers of La Quadrature Du Net such as Jérémie Zimmermann, who led the fight against ACTA and members of hacker collective Telecomix, who slipped across the Turkish border to collect information on the Syrian government surveillance.
In the first mass hacker camp in Europe since the revelations of NSA-whistleblower Edward Snowden, international theory and politics were furiously debated.
Julian Assange, founder of Wikileaks, spoke via video link, discussing the new international body politic being thrashed out in online, hyper-connected networks reaching far beyond beyond the civil society we once knew
Eleanor Saitta also prodded the future of humanity, not only poking at whether democracy really requires rough men doing evil deed into the night to preserve its sanctity, but also questioning the reliance of nation states on surveillance to survive.
Ex-Wikileaks volunteers Herbert Snorasson and Smári McCarthy talked of societal cybernetics; former-CIA agent Ray McGovern took to the stage wearing a "ARREST BUSH & OBAMA" t-shirt; and of course there was Vinjay Gupta, who announced “we’re fighting for free software running on top of hardware that was manufactured by slaves.”
Don’t get me wrong. It was wasn’t some utopian little coffee-house philosophy club gathering. The spooks and the freedom fighters were jammed shoulder against shoulder, and boy was there friction.
FoxIT, a contractor for the Dutch national intelligence agency, attended and quickly found their tent graffitied with red spray-paint. Similarly, the whistle-blowing panel, hosted next to a session on remote SIM-card hacking, made more than a few people squirm.
Yes, it was difficult at times – a strange mix of people. But we chose to be in that space together, because opting out meant more than just opting out of a camp in a sheep paddock in the Netherlands; it would have meant opting out of practicing the difficult conversations that shape our future.
On the last night of the camp, the Italian hackers cracked open 40 liters of brain-scorching grappa, and suddenly there was drunken, twisted dancing amongst the pyrotenics and lighting effects practiced to precision for days before the crowds converged. The Party at the End of the Universe, built on dreams of what the future could hold, was well worth the wait.

The Cisco 2013 Annual Security Report & Security Intelligence Operations


Networks Strain to Keep Pace with Data Explosion

In one minute, Facebook logs 6 million pages views, Google handles 2 million-plus search queries, Twitter adds more than 320 accounts and the data explosion threatens to overwhelm network infrastructure.

Network infrastructure as a topic lacks the sex appeal of slick mobile devices, cool social and location apps, streaming music or viral videos. Yet without the fast-flow of data a robust network infrastructure supports, they all come to a grinding halt. We’ve looked before at the strain our collective appetite for mobile devices and video places on networks. This infographic demonstrates the enormity of the need for network capacity beyond just mobile and video uses and forecasts a future that assures that network providers will be scrambling to keep pace.
Data Explosion - What Happens in Internet Minute
Right now, almost 640 Terabytes of data move across global IP networks in a single minute. Smartphone and social networking application usage comprise much of that data tidal wave.
In one minute…
Today’s data volume challenges network providers to keep pace with an insatiable hunger for bandwidth, yet the future promises to make the demand more acute. The number of networked devices now approximately equals the global population, but by 2015 it’s projected to double. Just 3 years from now, it will take 5 years to view all the video crossing IP networks in one second.

 

Sony Playstation Hack Timeline


Sony Playstation Network Hack