Security quotes of the week
[Posted September 14, 2016 by jake]
As with past network security changes, a major factor we need to
account for is that no matter how valuable a particular goal is from a
broader industry perspective, people don't tend to react to API breaks
by fixing their code - they react by not upgrading at all.
— Nick Coghlan
Once a proof-of-concept, the pocket-sized USB stick now fits in any
security tester's repertoire of tools and hacks, says
the Hong Kong-based
company [PDF] that developed it. It works like this: when the USB Kill
stick is
plugged in, it rapidly charges its capacitors from the USB power supply,
and then discharges -- all in the matter of seconds.
On unprotected equipment, the device's
makers say it will "instantly and
permanently disable unprotected hardware" .
— Zack
Whittaker
There's more. One company told me about a variety of probing attacks in
addition to the DDoS [distributed denial of service] attacks: testing the ability to manipulate Internet
addresses and routes, seeing how long it takes the defenders to respond,
and so on. Someone is extensively testing the core defensive capabilities
of the companies that provide critical Internet services.
Who would do this? It doesn't seem like something an activist, criminal, or
researcher would do. Profiling core infrastructure is common practice in
espionage and intelligence gathering. It's not normal for companies to do
that. Furthermore, the size and scale of these probes -- and especially
their persistence -- points to state actors. It feels like a nation's
military cybercommand trying to calibrate its weaponry in the case of
cyberwar. It reminds me of the US's Cold War program of flying
high-altitude planes over the Soviet Union to force their air-defense
systems to turn on, to map their capabilities.
— Bruce
Schneier sounds the alarm
In a speech delivered at the Billington Cyber Security Summit in Washington
DC, director general for cyber security at GCHQ, Ciaran Martin, said:
‘We’re exploring a flagship project on scaling up DNS filtering: what
better way of providing automated defences at scale than by the major
private providers effectively blocking their customers from coming into
contact with known malware and bad addresses?’
— Alice
MacGregor (Thanks to Paul Wise.)