I am not sure why but I receive way too many connection requests from fake profiles. Take for instance the following request, seemingly coming from a "Gabriella Kimber" in Germany, who in fact owns a premium account with LinkedIn, and has 414 connections (at the time of writing this post).
A simple Google photo search reveals, this photo has been taken as is from the G+ profile (link) of Lika Roman, who is actually Miss Ukraine 2007 (wikipedia).
I am sure a pretty woman's photograph is put up to attract attention, but still what's their end goal here? What do they aim to gain from such fake accounts?
Showing posts with label Philosophy. Show all posts
Showing posts with label Philosophy. Show all posts
2016-08-09
2015-12-10
Govt Surveillance vs Encryption
There is a battle, a collision, of balance going on, seems like governments are having a hard time in figuring out if they should ban encryption: which goes against all ethics and right to privacy of individuals. BUT on the other hand helps setup surveillance programs to counter terrorism.
- Kazakhstan mandates Internet backdoor
- FBI Director James Comey, called for tech companies currently offering end-to-end encryption to reconsider their business model
2015-08-30
Ashley Madison Hack Study
A bit late in the day now, but here is my study of the (in)famous hack, of the website with the tagline, "Life is short, have an affair".
12-Jul-15:
The website's parent company called ALM (Avid Life Media) had been hacked. Employees first learned of the intrusion when they arrived at work and powered on their computers, to be presented with the initial message from the "Impact Team" - the hacker group that has claimed responsibility for the breach.
The news broke about, and as expected, there was a wide spread fear, among the impacted ~37M users. The original leak:
18-Aug-15:
The company decided not to give in to the demands. And the hackers leaked what was promised (tech links). So, what happens now?
15-Sep-15:
The company used all the right protocols for hashing and salting their passwords. However, poor implementation causes over 11M hashes to be cracked.
15-Dec-16:
Ashley Madison settles the lawsuits for $17.5 M. Interestingly at this point of time, it can only afford to pay up about 10% of this. Plus they will have a whopping 20 yrs of govt oversight to ensure network security.
12-Jul-15:
The website's parent company called ALM (Avid Life Media) had been hacked. Employees first learned of the intrusion when they arrived at work and powered on their computers, to be presented with the initial message from the "Impact Team" - the hacker group that has claimed responsibility for the breach.
The news broke about, and as expected, there was a wide spread fear, among the impacted ~37M users. The original leak:
Besides snippets of account data apparently sampled at random from among some 40 million users across ALM’s trio of properties, the hackers leaked maps of internal company servers, employee network account information, companye c bank account data and salary information.Hackers also claimed that the company had lied, when they sold a service called "Full Delete", which was supposed to purge all user details.
“Full Delete netted ALM $1.7mm in revenue in 2014. It’s also a complete lie. Users almost always pay with credit card; their purchase details are not removed as promised, and include real name and address, which is of course the most important information the users want removed.”The demand from the hackers:
“Avid Life Media has been instructed to take Ashley Madison and Established Men offline permanently in all forms, or we will release all customer records, including profiles with all the customers’ secret sexual fantasies and matching credit card transactions, real names and addresses, and employee documents and emails. The other websites may stay online.”Sounds like a "Robin Hood" of hackers, no? A good for the society, with no personal gains - No BTC demands!
18-Aug-15:
The company decided not to give in to the demands. And the hackers leaked what was promised (tech links). So, what happens now?
- There are numerous websites now offering services to search for your spouse and friends, to see if they were using the website
- We now have bad guys harassing the victims (for a lack of better word), and starting an extortion / blackmail program
- We also have two suicides, which could (not confirmed) be due to this disclosure
- The ALM company has been taken to court, by the users, and face a class action law suit
- The CEO of the company stepped down, over all this controversy
- Some big names got exposed via this hack.
24-Aug-15:
The company announces a $500M bounty, for the person who is able to help find the culprit in this hack. At the same time Kerbs feels a twitter user Thadeus Zu (@deuszu) could be responsible.
The company used all the right protocols for hashing and salting their passwords. However, poor implementation causes over 11M hashes to be cracked.
15-Dec-16:
Ashley Madison settles the lawsuits for $17.5 M. Interestingly at this point of time, it can only afford to pay up about 10% of this. Plus they will have a whopping 20 yrs of govt oversight to ensure network security.
2015-03-23
Anatomy of a hack
A very interesting narrative of how a person's mail.com, gmail, authy, AT&T accounts got compromised, in order to steal his bitcoins. The victim here for sure had taken more precautions than an average user, and hence is really an eye opener.
2014-12-20
Security in Cloud Hosting
As IT Security professionals, we are usually quick to sign-off cloud security providers citing data-privacy and/or confidentiality concerns. However, that may not really be true any more. Things are changing and some service providers may even end up providing an orgnaization better security than their in-house data centers.
An article that seem to agree.
An article that seem to agree.
2014-07-29
Why Open Source isn't neccessarily secure
A good article on why open source isn't necessarily more secure. Personally I think the author doesn't take into account multiple factors, such as turn-around time to patch an identified vulnerability, or how active a product is to engage white-hat hackers.
2014-06-24
"10 Ways to Fix Cybersecurity" What the leaders say?
A must read article that breaks down the answers from industry (so-called) leaders around security. And you realize there is less advise and more sales-pitch in there.
2014-05-17
Diving Underground: Fake ID's & Passports
Continuing with the research of the underground, here is one of the many service providers, promising as-good-as real passports, driving licenses, and ID cards. The payment mode remains BTC
2014-05-16
Antivirus is Dead
Nothing new in here, but a good writeup on why AV is not a reliable security control now. Still a must have investment, but do not expect much from them.
2014-05-08
Technical Experts vs Management
Does not show case IT Security directly, but still as true. A light humor around the disconnect between the technical experts, the stakeholders and the big-bosses in the corporate environment.
2014-05-05
Diving Underground: Counterfeit Currency
Continuing with my research of the underground market, I stumbled upon a website which offers USD and Euro currency, at a discount of up to 75%. The payment is to be made via bitcoins (of course).
A screenshot of the website is pasted below. However, it does make me wonder, how the buyer could be assured of the legitimacy of the seller. Unlike ebay, there is no easy way here to give a negative feedback. Nevertheless, another insight into the thriving underground.
A screenshot of the website is pasted below. However, it does make me wonder, how the buyer could be assured of the legitimacy of the seller. Unlike ebay, there is no easy way here to give a negative feedback. Nevertheless, another insight into the thriving underground.
2014-04-16
Diving Underground: Stolen PayPal Accounts:
2014-03-30
Diving Underground - A Research
I have been researching the underground e-markets, or the dark-corners of the web (as it is popularly called) for a while now.
As I dig deeper, what I keep finding is just jaw-dropping. From drugs, to money laundering services, to pirated softwares, games, books, name it and it is here. Which is nothing new, I am sure web has been famous for that for a while now. The only reason I am surprised is that how easy it is becoming to commit an online fraud.
Update 20-Feb-2016:
Trying to finding tor websites, why not try Quora?
As I dig deeper, what I keep finding is just jaw-dropping. From drugs, to money laundering services, to pirated softwares, games, books, name it and it is here. Which is nothing new, I am sure web has been famous for that for a while now. The only reason I am surprised is that how easy it is becoming to commit an online fraud.
Update 20-Feb-2016:
Trying to finding tor websites, why not try Quora?
2013-09-14
Evolution of Hacking
How hacking techniques have (not) evolved in the last 30 years or so. An interesting article.
- Hackers have changed very little since the 1980s (there have always been moral and immoral hackers)
- Hacking technologies have changed very little
- Motivations have changed very little (it has always been for fun or profit)
- Opportunities have changed dramatically
2013-08-04
SSL Broken in 30 Seconds
2013-07-12
Security for the paranoid!
We all have 100s of accounts, with multiple passwords. So, how can we ensure user friendliness of a password manager, but from a truly [paranoid] security guy's point of view?
We are heading into a world of cloud computing where trust is going to be a huge issue. It is no longer simply a matter of trusting that the software you buy works as advertised.
2013-05-11
India's Cyber Policy
India (finally) works on a cyber security policy/framework. Much needed, but I'm still waiting to see the actual document.
Update 17-Sep-13:
A very good article around India's position for IT Sec and the challenges.
Update 17-Sep-13:
A very good article around India's position for IT Sec and the challenges.
2013-05-02
2013-04-20
Different Types of CISO's
A good sum-up of the three types of CISO's:
- The non-techie, but business-savvy CISO
- The technically competent, but less business-articulate CISO
- The hybrid CISO
2013-03-29
Role of Auditors
Being in a financial organization, makes audits, integrated in the DNA of every IT professional. The audits varies from internal, external, regulatory, statutory, to what not. So, are these of any value?
Personally, I have a lot of respect for the audit function. Especially the IT Security audit. However, I prefer working with auditors who know their jobs, and try and look for real risk, and are not just mechanical bots trained to match documents to their check-lists.
Here is one article that is in-sync to my thoughts.
Personally, I have a lot of respect for the audit function. Especially the IT Security audit. However, I prefer working with auditors who know their jobs, and try and look for real risk, and are not just mechanical bots trained to match documents to their check-lists.
Here is one article that is in-sync to my thoughts.
Subscribe to:
Posts (Atom)

