Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Monday, February 03, 2014

U.S. intelligence agencies warn Obama administration about new security threat to Obamacare website

U.S. intelligence agencies last week urged the Obama administration to check its new healthcare network for malicious software after learning that developers linked to the Belarus government helped produce the website, raising fresh concerns that private data posted by millions of Americans will be compromised.
READ MORE

Friday, December 20, 2013

"This is the first time a government insider has gone on record challenging the administration's insistence that there were no worrisome security concerns."

"Teresa Fryer, the chief information security officer for the Centers for Medicare and Medicaid Services (CMS), revealed the findings when she was interviewed Tuesday behind closed doors by House Oversight Committee officials..."

Security bombshell #1:
Details are not being made public for security reasons but Fryer testified that one vulnerability in the system was discovered during testing last week related to an incident reported in November. She says that as a result, the government has shut down functionality in the vulnerable part of the system. Fryer said the other high-risk finding was discovered Monday.
Security bombshell #2:
In another security bombshell, Fryer told congressional interviewers that she explicitly recommended denial of the website’s Authority to Operate (ATO), but was overruled by her superiors. The website was rolled out amid warnings Fryer said she gave both verbally and in a briefing that disclosed “high risks” and possible exposure to “attacks”.

Fryer also said that she refused to put her name on a letter recommending a temporary ATO be granted for six months while the issues were sorted out.
READ MORE

Tuesday, November 19, 2013

4 cyber security experts concur: Obamacare website dangerous for Americans to use!

Healthcare.gov ‘may already have been compromised,’ security expert says
Rubin called for a security review of the site, but stopped short of calling for a complete tear down and rebuild of the healthcare.gov site. Others were less cautious.

“You can bolt a metal door on to make a house better, but if the foundation is bad. . .” Kennedy said.
READ MORE

Hearing: Security Flaws in Obamacare Website Endanger Americans
Kennedy demonstrated an attack in the hearing room, showing how on Finder.Healthcare.gov a hacker could breach into a computer, monitor its webcam, and steal passwords.

Hackers from Russia or China could “absolutely” breach the online marketplace, he said.

The problems could only get worse since the president’s team is trying to fix the website while it is still up and running.

Morgan Wright, a cyber terrorism expert and CEO of Crowd Sourced Investigations, LLC., said attempting to fix one line of code could open up a “Pandora’s box.”

“You create an unintended series of cascading events you have no control over because you don’t have a grasp of what the code is actually doing,” he said. “You think you’ve changed one thing, by doing that you’ve opened up a Pandora’s box of vulnerabilities on the other side.”

Kennedy said he has never seen anything like it.
READ MORE

Monday, September 17, 2012

Mortal combat in the White House

Computer World: Questions loom about Obama's cybersecurity plans

As opposition mounts to an executive order, question is whether White House will plow ahead or drop idea...
Those familiar with what's going on in Washington behind the scenes say the recent opposition is giving the White House pause. There are two forces in the White House on the matter, said one source who requested not to be named. One group is rethinking whether the executive [order] is such a good idea, he said. The other faction wants to act much more affirmatively than anybody expects, he said.

"They are in mortal combat," the source said.

Friday, June 01, 2012

Codename: 'Olympic Games'

...as a story in Technology Review points out, Stuxnet’s traits have already shown up several other malware samples that have hit American targets, implying that the Obama administration has been more focused on using its new weapons than in considering the consequences once that destructive code proliferated in the wild.
What Stuxnet's Exposure As An American Weapon Means For Cyberwar


Monday, May 28, 2012

The most sophisticated cyber weapon yet unleashed: The ‘Flame’

SECURELIST: THE FLAME: QUESTIONS & ANSWERS

Thanks to Legal Insurrection: Stuxnet-on-steroids Flame virus hits Iran

Thursday, September 30, 2010

Iran caper: who is behind the cyber attack?

While the boors and bores of the mainstream media continue to focus on the “crucial matters” of our time such as Stephen Colbert’s tedious appearance before Congress and whether a Delaware senatorial candidate spent two days as a witch in high school, news of real importance is breaking all around us.

I am not just referring to the cataclysmic testimony by Chris Coates in front of the Civil Rights Commission on Friday, but to a yet bigger story with a potentially huge implications for geo-politics — the recent (and possibly ongoing) cyber attack on Iranian computers that may have temporarily crippled the nuclear capability (and who knows what else) of the totalitarian Islamic state.
Cyber War on Iran: the Siemens Connection

Tuesday, September 28, 2010

Business owners: here's what will happen to you if you piss HIM off

(And you now know just HOW pissy he can get): New Cybersecurity Bill Gives Obama ‘Power To Shut Down Companies’
Businesses who don’t follow government orders would be suspended for at least 90 days with no congressional oversight.

Wednesday, July 07, 2010

The federal government is launching an expansive program dubbed "Perfect Citizen" to detect cyber assaults on private companies and government agencies...

Some industry and government officials familiar with the program see Perfect Citizen as an intrusion by the NSA into domestic affairs, while others say it is an important program to combat an emerging security threat that only the NSA is equipped to provide.
U.S. Program to Detect Cyber Attacks on Infrastructure

Friday, September 04, 2009

Dr. Strangelove meets Olympia Snowe

This Republican-In-Name-Only keeps turning up in all the wrong places. I cannot tell you how much she disgusts me.
"The cybersecurity threat is real," said Leslie Harris, president of the Center for Democracy and Technology, which obtained the draft of S. 773, "but such a drastic federal intervention in private communications technology and networks could harm both security and privacy."

Jennifer Granick, civil liberties director at the Electronic Frontier Foundation, told Mother Jones the bill was "contrary to what the Constitution promises us." According to Granick, granting the Commerce Department oversight of "critical" networks such as banking systems would grant the government access to potentially incriminating information without cause or warrant, a violation of the Constitution's prohibition against unlawful search and seizure.

Like the health care bill, there are several versions of S. 773; what people have seen is vaguely written. The bill does not clearly define what a cyberemergency or critical network is. Nor does it explicitly define the powers of the president in such an emergency or what he is prevented from doing. That is left up to the administration in power.
Read the whole thing

Friday, August 28, 2009

Bill would give president emergency control of Internet

Internet companies and civil liberties groups were alarmed this spring when a U.S. Senate bill proposed handing the White House the power to disconnect private-sector computers from the Internet.

They're not much happier about a revised version that aides to Sen. Jay Rockefeller, a West Virginia Democrat, have spent months drafting behind closed doors. CNET News has obtained a copy of the 55-page draft of S.773 (excerpt), which still appears to permit the president to seize temporary control of private-sector networks during a so-called cybersecurity emergency.

The new version would allow the president to "declare a cybersecurity emergency" relating to "non-governmental" computer networks and do what's necessary to respond to the threat. Other sections of the proposal include a federal certification program for "cybersecurity professionals," and a requirement that certain computer systems and networks in the private sector be managed by people who have been awarded that license.
Read more