Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, August 10, 2011

Cybersecurity is not on top of PH priorities

“In light of the recent spate of hacking directed toward its websites, the government reiterated its support for the passage of the cybercrime and data privacy bills, saying they are not taking these attacks lightly.”

--- Read full story here c/o GMA News
Image from the movie "The Matrix" 
(Photo Credit: http://www.moviespictures.tk/the-matrix.html)

This only shows how backward PH is in terms of ICT development. First, the coding practices used by the Government and perhaps other institutions in the country are below standards, if not obsolete. Most of these did not undergo rigorous security testing, for the simple reason that the establishment of safeguards require a lot of technical and monetary resources -which is very limited in this part of the world. Not everyone can afford to hire a professional systems analyst, more so the government. Second, cybersecurity is not a priority in the government's budget.  This is understandable considering that there are more pressing matters at hand such as education, social welfare and servicing foreign debts. For a developing country, the development of it's websites is the least of its concerns.

At present, the cybercrime bill and the data privacy bill are already pending in Congress on different levels. While everyone is hoping that the enactment of these bills would solidify government policy regarding online security, they are not an assurance that internet crimes will stop. At most, they will provide a sense of security for the users and a deterrent for hackers and the goons of the internet. Furthermore, an effective enforcement mechanism is necessary in order to fully implement the laws.

Passing a law is not the solution, but only a part of it.  Website developers, system analysts, programmers, and all internet users in general have to do their share to ensure the integrity and safety of their data and transactions across the web.


Entry No. 8
Soleil Flores

Wednesday, August 3, 2011

Operation Shady RAT (Remote Access Control)

The internet is perhaps the most dangerous place on the planet. No one is safe. Not even the United Nations.
Photo Source: http://www.presstv.ir/detail/163926.html
Security company McAfee, discovered the biggest series of cyber attacks in the last 5 years which involved the the infiltration of the networks of 72 organizations including the United Nations, governments (US, Taiwan, India, South Korea, Vietnam and Canada) and companies around the world. It believed there was one "state actor" behind the attacks but declined to name it, though the evidence "allegedly" points to China. (Source: Reuters)

Cyber attacks are perhaps as old as the internet. However, what is alarming about this report is that a "state actor" is involved in the attacks against various governments of different countries. Should the "state actor" be proven, could such cyber attacks escalate to a dispute under the principles of international law?

In international law, the state is responsible for all actions of its officials and organs, even if the organ/actor/official is acting ultra vires. However, before a state can be held responsible for any action, it is necessary to prove a causal connection between the injury and an official act or omission attributable to the state alleged to be in breach of its obligations.

In the case at bar, it is not clear whether the "hacker-state-actor" owed an international obligation to the injured governments under either a treaty or customary law. So far, the only relevant document regarding the matter is the 2007 resolution passed by the UN Disarmament and International Security Committee related to IT security concerns related to organized crime, terrorism and politically motivated cyber attacks. Take note that this is not even the General Assembly or the Security Council, but a Committee. Hence, no "force" so to speak.

While the use of all the illegally obtained data is still largely an open question, the need for an international legal framework to combat malicious or illegal use of information technology is called for by many sectors around the world. After all, we live in the age where information is power ---political or economic.


Entry No. 7
Soleil Flores

Wednesday, June 22, 2011

The Attack of Philker Hackers

Hacking is old news. So old, that it is believed that hacking has been around pretty much since the development of the first electronic computers(1). Anyone with security vulnerabilities can be a target. No one is safe. Not even government websites. Last year isolated attacks were experienced in different government agencies particularly: Department of Social Welfare and Development (DSWD); TESDA; GSIS; National Disaster Coordinating Council (NDCC); and Philippine Information Agency (PIA) .

And you think they have learned their lesson? Well, not really.

Just recently, the latest Government web sites to join the ranks are:


What is alarming about the recent attacks is that there is one group who call themselves Philker Hackers, responsible for the attacks on the PNRI, FDA and OVP websites.

Photo Credit: http://www.techalang.com/

Philker Hackers, who are "proudly Filipino" claim that they are "white hats":

“WE ARE NOT TRYING TO DAMAGE YOU. WE ONLY WANT TO HELP PROTECT OUR COUNTRY’S CYBERSPACE BY DOING WHAT SEEMS TO BE THE MOST EFFICIENT WAY TO GET EVERYONE’S ATTENTION. MAY THIS DEFACE SERVE AS A REMINDER THAT YOU ALWAYS HAVE TO LOOK OUT FOR INTRUDERS. NO MATTER HOW INTELLIGENT AND COMPETENT YOUR COMPUTER PERSONNEL ARE, THERE WILL BE UNETHICAL HACKERS THAT ARE CONSTANTLY WORKING ON BREAKING IN YOUR SECURITY, WHETHER IT’S YOUR MONEY OR INFORMATION THEY ARE AFTER; IN THIS CASE, YOU ARE FORTUNATE THAT IT WAS US WHO HAS SUCCESSFULLY BROKEN IN. YOU ALSO HAVE TO UNDERSTAND THAT BOTH THE PRIVATE AND PUBLIC SECTORS ARE AT RISK HERE, THIEVES AND TERRORIST ARE ALL LURKING ONLINE POSSESSING THE SKILLS TO TAKE DOWN MULTIPLE NETWORKS AND ASSUME ACCESSIBILITY OVER ACCOUNTS, WATCHING OUT FOR THE MOST VULNERABLE TARGETS; TRUST US, WE’RE CUT FROM THE SAME CLOTH, THE DIFFERENCE IS THAT WE HAVE GOOD INTENTIONS. THEY DERIVE THEIR ENERGY FROM GREED. WE DERIVE OURS FROM OUR THIRST TO KEEP OUR COUNTRY’S CYBERSPACE SAFE. EXPECT MORE FROM US. WE ARE PHILKER.”

Philker Hackers allege that they are merely "protecting our country's cyberspace" yet under the Computer Misuse Act of 1990 in the United Kingdom, "unauthorized access even to expose vulnerabilities for the benefit of many is not legal." As Struan Robertson puts it, "There’s no defense in our hacking laws that your behavior is for the greater good. Even if it’s what you believe." (2)

Unfortunately, the current state of Philippine legislation does not offer the same protection.

Although hacking is nothing but universal occurrence nowadays, the recent events only demonstrates the quality of internet security we have in this country. It only shows how weak the Government's defenses are in terms of protecting themselves from online threats. The hacking incidents call not only for a major upgrade in the government measures regarding online data security but also a reflection on the country's current internet or cyber policies and ethics.

Entry #1

----------
Sources:
(1) Timeline: A 40-year history of hacking 
http://articles.cnn.com/2001-11-19/tech/hack.history.idg_1_phone-phreaks-chaos-computer-club-emmanuel-goldstein?_s=PM:TECH

(2) License to hack? - Ethical hacking
http://www.infosecurity-magazine.com/view/4611/license-to-hack-ethical-hacking/

(3) Photo Credit:  http://www.techalang.com/

(4) On the various articles related to the different attacks:
(a) http://www.gmanews.tv
(b) http://www.abs-cbnnews.com
(c) http://www.techie.com.ph
(d) http://newsinfo.inquirer.net
(e) http://www.techalang.com/

Collateral Damage

For the past two months, it seems a new major website or web service has gotten hacked on a weekly basis. May saw the PlayStation Network fall prey to a hacker attack that compromised the credit card information, email addresses and passwords of a sizable portion of its customers. What followed was a storm of hacker attacks, which included targets such as the CIA, the US Senate, Bethesda Softworks, Nintendo, Sega, and PBS, among others.

What interests this blogger is not the hacking itself, but the recent news that the accounts of XBOX Live members have also apparently been compromised, notwithstanding the fact that Microsoft claims it was never hacked. Apparently, some of the email and password combinations compromised in the earlier attacks on Sony’s PSN, Sega, et al, also worked on XBOX Live accounts. Reports have also surfaced of similar incidents happening with Facebook accounts.

It’s pretty amazing how much collateral damage a single hacking incident could have. A perfectly secure web service can find its customers inconvenienced by the delinquency of a completely unrelated web service that happens to have the same customers, using the same passwords and email addresses. It’s easy to pin the blame on the end user for being sloppy in reusing the same email and password combinations. But in actual practice, human memory is fickle and can barely remember a single password. Let’s face it, multiple passwords by end users will be the exception, not the rule, for the foreseeable future.

This all serves to dampen the spirits of those who push for greater integration of web services. It’s bad enough that two totally rival services with absolutely no hope of integration (PSN and XBOX Live) have ably demonstrated that a security breach on one service can have dire consequences on the customers of the other. What more for services that go out of their way to integrate, like Google, Youtube, and Blogger? What of Facebook and Digg, which have been integrated into practically every website?

Perhaps it’s time to propose legislation that would mandate the major web services and websites provide adequate security measures against hacking, not just for their own benefit but for the whole internet in general. Hacking isn’t going away any time soon, and as this debacle shows, a single hack is a stone thrown into a calm, serene pond—it ripples, and shatters the serenity for all.