Saturday, January 4, 2014

7 InfoSec Predictions For 2014: Good, Bad & Ugly - InformationWeek

7 InfoSec Predictions For 2014: Good, Bad & Ugly - InformationWeek

First, the bad news: Windows XP doomsday, escalating ransomware, botnet-driven attacks, emerging SDN threats. The good news: Threat intelligence goes mainstream.
Predicting the future, of course, is impossible. But based on the dynamic events I've witnessed in information security this past year -- new adversaries, attack techniques, and increased adoption of such emerging technologies as software-defined networking -- here are seven security trends I’ll be watching closely in 2014.
1. Doomsday for Windows XP 
Come April 2014, Microsoft will stop releasing new patches for Windows XP. But from the attackers' standpoint, the real fun will start in May, when Microsoft patches all versions of Windows since Windows XP. When that happens, security experts predict a hack-attack field day, since -- just like Java -- attackers can reverse-engineer the new fixes to find exploitable XP vulnerabilities. Cue difficulties for the millions of consumers and businesses that continue to rely on the unsupported operating system.
"One of the biggest challenges ahead for 2014 is clearly coming with Windows XP, and that obviously has a massive impact not only for the systems that are out there, but the systems that are out there that no one knows about," said Gerhard Eschelbeck, chief technology officer of Sophos, speaking by phone. "Who owns fixing those systems or upgrading those systems or ensuring those systems are still secure, in a world where patches are no longer being provided?"
Given the potential harm facing people who still rely on XP, there still might be an end-of-life reprieve. "Microsoft ought to reevaluate and reassess their decision early next year," Eschelbeck speculated, “if it's the right thing to do to 'end of life' support for an operating system that's been as successful as Windows XP has been."
2. Malware: Follow the Money 
One no-brainer for 2014 is that malware will continue to target an expanded range of institutions that handle money -- and especially virtual currencies. In late November, for example, a new variant of the Gameover malware was spotted that targeted the log-in credentials for users of BTC China Exchange. That China-based exchange handles 40 percent of the world's trades in the cryptographic currency known as Bitcoins.
Going forward, we can also expect improvements that make latest-generation malware tougher to detect or block. For example, increased use of automated generation of domains for call-backs. According to Sophos' Eschelbeck, these techniques are used by malware writers to ensure that infected nodes can connect to command-and-control (C&C) infrastructure and serve as bots in a botnet. For years, security firms have battled botnets by blacklisting these malicious domains. But as attackers have improved their domain-name-generation algorithms, the tedious, largely manual exercise of blocking malicious domains has grown more difficult.
In addition, attackers have begun using "multiple layers of indirection," Eschelbeck said, which makes it more difficult for researchers to pinpoint exactly how C&C communications are flowing. "The first layer that the malware is going to may not be a bad domain at all," he said, but rather an intermediate but otherwise legitimate waypoint compromised by attackers. The more time and effort it takes security researchers to separate good domains from bad domains, the farther ahead attackers can stay from would-be botnet busters.
3. Ransomware shakedown escalates
The above example wasn't the first foray into new attack territory by the authors of the Gameover malware, which is based on the Zeus financial Trojan. "Gameover has also been involved [with] the dropping of CryptoLocker onto victims," said Sean Sullivan, security advisor at F-Secure Labs, referring to the CryptoLocker ransomware, which encrypts an infected PC, then demands users pay a ransom -- sometimes in bitcoins -- to receive a decryption code.
"Ransomware is pretty fascinating stuff. It's showing how cartel-like this problem has become, how it's really been able to extort money, and how it's been really powerful, from a software perspective, simply by locking down a PC until you pay up," said Carl Herberger, VP of security solutions at Radware, speaking by phone. Furthermore, the attacks continue because victims -- reportedly even including one Massachusetts police department -- continue to pay up.
The same must be true for at least some victims of scareware -- which is malware with all bark and no bite -- as well as other extortion schemes, which in 2013 included criminals threatening to launch distributed denial-of-service (DDoS) attacks against business sites, again, unless they paid up.
Expect the scope and combination of these shakedown campaigns to keep expanding in 2014. "If I can take someone down, that's one thing, but if I can extort them for restoring the services when they're down, then they probably have more of a propensity to pay," Herberger said. "I see that being a very big idea that evolves in 2014."
 4. Uptick in bot attacks 
One of the most successful attack campaigns of 2012 and 2013 has been the four waves of Operation Ababil, which have used compromised PCs and servers to launch large-scale DDoS attacks that disrupted the websites of US banks. Even when banks managed to counteract these attacks, their defensive strategies often lead to disruptions for customers.
From an attack standpoint, the campaign has been tough to stop, because it relies on compromised systems to do the dirty work. Botnets have long been attractive to attackers because they offer cheap processing power, and serve as easy spam relays and versatile attack platforms, for launching these types of DDoS campaigns. But bots have gotten even more attractive for attackers as processing power and network pipes have respectively continued to get larger and bigger. Furthermore, even if defenders do manage to clean a few thousand of the bots, hackers only need to begin infecting new ones to regain their attack strength.
"Bots represent the army of the future -- making IT work for you, if you're a bad actor, and against you, if you're the target," said Herberger. "That's the future, that's the fourth generation of warfare: making computers attack."
5. SDN in the crosshairs
One "next big thing," technologically speaking, is software-defined networking(SDN), which -- to simplify the technology at work -- allows software to run independently from the underlying network hardware.
"SDN is starting to get adopted," said Radware's Herberger. "Google is an entire SDN shop, and more and more companies are investigating SDN." But as more businesses turn to SDN, he predicts attackers will seek ways to exploit these environments.
"Google has experienced a very low amount of security problems, and people have suggested that's because they're a full SDN shop -- and the fifth largest shop in the world," said Herberger. "So there's a nice high-value target there, if you could get yourself organized around it." He said that as more financial firms -- including organizations that handle bitcoins -- investigate SDN, related attacks will increase.
6. APT attackers better hide their tracks
In 2013, security firm Mandiant published a report about a hacking group it called APT1. Also known as Comment Crew, this China-based group -- Mandiant alleged -- was in fact an elite band of military hackers who served as part of People's Liberation Army (PLA) Unit 61398.
China denied the allegations, but many information security experts concurred with the findings. Meanwhile, the attackers were put on notice, thus demonstrating the double-edged nature of outing online adversaries: Potential victims may get a heads-up, but attackers can also learn about how they got spotted, then tweak their offensive playbook to make future attacks harder to detect.
"After that [Mandiant report], the community -- by which I mean pretty much everyone in incident response -- saw the tools get updated, which says to me that [the attackers] were watching our blogs, and our security conferences," said Matt Standart, the threat intelligence director at HBGary, speaking by phone. "So they were aware, and they changed." Expect that cycle to continue.
7. Threat intelligence sharing goes mainstream
When it comes to spotting and mitigating APT attacks, could 2014 be the year that threat intelligence sharing becomes the norm? "Threat intelligence is really just information about an adversary that you can use to make a decision about how you respond to that adversary," said Standart at HBGary, which sells related products and services.
Throughout 2013, there have been a number of steps toward better threat-intelligence sharing, including MITRE continuing to refine its Structured Threat Information eXpression (STIX) language format, as well as the Trusted Automated eXchange of Indicator Information (TAXII) message exchange service specifications for sharing threat information. Those standards have already been tapped by many organizations -- including the Financial Services Information Sharing and Analysis Center (FS-ISAC) and the Defense Industrial Base (DIB) sector -- as the preferred approach for sharing cross-platform threat intelligence between different organizations, as well as products.
"If one organization finds that information or understands something about the attacker, then all organizations could benefit... but it's tempered by that fear of disclosing that you've been compromised," said Standart. Accordingly, "we predict that the government will get involved through regulations."
While new regulations may not always be a good thing, "you can still share the threat intelligence data that doesn't give away anything about the incident -- just the attacker details -- so it's kind of a moot thing," he said.
What are your predictions about information security in 2014? Share them in the comments.
Mathew Schwartz is a freelance writer, editor, and photographer, as well the InformationWeek information security reporter.

Snapchat To Update App In Wake Of Breach -- Dark Reading

Snapchat To Update App In Wake Of Breach -- Dark Reading

Kelly Jackson Higgins January 02, 2014

Snapchat, a mobile photo-messaging app created for wiping out traces of the messages for privacy reasons, this week was hit with a major breach of its users' privacy that exposed names and phone numbers of some 4.6 million of its customers. The data dump came after security researchers published a proof-of-concept for a weakness associated with the "Find Friends" feature.
The app provider late today announced that it would update Snapchat to better protect its users. "We will be releasing an updated version of the Snapchat application that will allow Snapchatters to opt out of appearing in Find Friends after they have verified their phone number. We’re also improving rate limiting and other restrictions to address future attempts to abuse our service," Snapchat said in a blog post.
Snapchat also said researchers could email the firm at security@snapchat.com for any vulnerability discoveries. "We want to make sure that security experts can get a hold of us when they discover new ways to abuse our service so that we can respond quickly to address those concerns. The best way to let us know about security vulnerabilities is by emailing us: security@snapchat.com," Snapchat said.
The blog post came in response to criticism by the researchers who first reported and then published details on the flaw in Snapchat's app after saying they had not gotten a response from Snapchat. A hacker group yesterday exploited the flaw and posted online to a site called SnapchatDB the names and phone numbers, with the final two digits obscured, on some 2.6 million Snapchat users.
"As much as we were hoping it wouldn't be exploited, we did expect at least something to come of it. We don't condone the Snapchat DB leak, and feel that it's a pretty reckless way to get across the point to Snapchat," researchers at Gibson Security told Dark Reading in an email interview.
The researchers say they tried to contact Snapchat in August electronically before their original post about the flaw. On Dec. 27, Snapchat posted a blog basically dismissing the vulnerabilities. "This week, on Christmas Eve, a security group posted documentation for our private API. This documentation included an allegation regarding a possible attack by which one could compile a database of Snapchat usernames and phone numbers," Snapchat said in that post. "Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way. Over the past year we’ve implemented various safeguards to make it more difficult to do. We recently added additional counter-measures and continue to make improvements to combat spam and abuse."
Find Friends basically lets users upload their contacts list to Snapchat so that Snapchat can display the accounts of users that match those phone numbers.
Gibson Security said Snapchat's director of operations contacted them via email, but that they hadn't heard anything since then as of this morning.
The breach of user information is another example of the risks associated with many mobile apps today, security experts say. "In a rush for growth, companies often put security on the back burner. Snapchat here is no exception. What we see here is a classic example of how the intersection of social media, mobile platforms, and cloud create new entry doors for the hackers to exploit. Today’s rapid moving parts and the plethora of connections make it all too easy for the attackers," says Bala Venkat, CMO at Cenzic.
Kevin O’Brien, director of product marketing at CloudLock, says this low bar of entry into the mobile app space basically complicates security. The Snapchat customer data dump has damage potential to the users, he says.
"Spoofed phone calls" are one potential abuse, he says, as well as criminals using the phone numbers, geographic information, and usernames for identity theft or to escalate victims' user privileges elsewhere. "PII [personally identifiable information] is valuable. It allows you to get closer to the target," O'Brien says.
Gibson Security, meanwhile, suggests users delete their Snapchat accounts or contact their mobile phone network providers to change their phone numbers if they are especially concerned those numbers could be fully discerned by prospective attackers. "They should definitely ensure their security and privacy settings are up to date and well adjusted in all their social media accounts. Users should perform due diligence when registering for new social media accounts -- if a site doesn't deserve [or shouldn't have] your phone number, don't give it to them," the researchers say.
Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contactDark Reading's editors directly, send us a message.

Friday, January 3, 2014

Tech Support Scams: Part 2 | OnGuard Online

Tech Support Scams: Part 2 | OnGuard Online

Computer Screen WarningThey’re baaaack!
No, not poltergeists. Scammers. And they want your last penny.
We’ve written before about tech support scams — where a caller claims that your computer has a terrible virus and needs immediate attention. The scammer asks for remote access and then charges you for “fixing” a problem that wasn’t there.
Now, they’re working the phones again, and they claim that if you paid for tech support services, they can get you a refund. We’ve heard about several variations of this scam:
  • They might ask if you were happy with the service. If you say no (and you probably will), they claim they can get you a refund.
  • Or they might say that the company is going out of business and providing refunds to people who already paid.
Once they’ve got you hooked, they claim that they need your bank or credit card account number to process the refund.
They might say that you need to create a Western Union account to receive the money. They may even offer to help you fill out the necessary forms — if you give them remote access to your computer. But instead of transferring money to your account, the scammer withdraws money fromyour account.
So, what can you do if you paid for bogus tech support services?
  • File a complaint at ftc.gov/complaint.
  • If you paid with a credit card, call your credit card company and ask them to reverse the charges.
  • Hang up on callers who offer a refund in exchange for your bank or credit card account number or a Western Union account.
Blog Topic: Avoid Scams

Wednesday, January 1, 2014

The economy: The 2014 outlook - Dec. 9, 2013

The economy: The 2014 outlook - Dec. 9, 2013

NEW YORK (Money Magazine)

After five frustrating years, the economy is ready to bust out. Stocks already had a banner run in anticipation of the rebound, housing is scorching, and jobs won't be far behind.

There are plenty of moves you can make with your money to play to these strengths, even if the economy pulls some punches.

Bonds: Tweak your mix in 2014 - Dec. 9, 2013

Bonds: Tweak your mix in 2014 - Dec. 9, 2013

Blackrock 2014 Outlook The List What to Know, What to Do: via PDF

Blackrock 2014 Outlook The List What to Know, What to Do: via PDF 



Making sense of year-end investing ‘advice’ - Chuck Jaffe - MarketWatch

Making sense of year-end investing ‘advice’ - Chuck Jaffe - MarketWatch

Dec. 26, 2013, 8:30 a.m. EST

Making sense of year-end investing ‘advice’

It’s foolish to invest solely on financial predictions


The problem with listening to year-end roundups and year-ahead financial forecasts is that someone will be right, most will be wrong and all will be forgotten by everyone but you long before the year is out.
It’s not that making predictions is a fool’s game; it’s fun, and it distills an expert’s thinking down to something easy to digest. The foolish part is acting — investing — based solely on those forecasts.
That has never been more clear to me than this month, when my show “ MoneyLife ” has had a run of tremendous guests, all of them talking about the year ahead and none of them in real agreement over what happens next.
Grace, a 40-something listener from Tacoma, Wash., who has been taking greater charge of her finances since going through a divorce two years ago, wrote that each guest has been smart and sounded great, but that the abundance of advice had left her confused about what to do next.
“If I only listened to one show, I could have come out thinking, ‘Yup, that’s a good expectation for what’s going to happen and how I should act,’” she wrote, “But since I listen every day, it all sounds good, but I can’t decide who to believe is right.”
It started with Jim O’Shaughnessy of O’Shaughnessy Asset Management — author of “What Works on Wall Street” — suggesting that anyone who needs yield and income will want to look at global high-dividend stocks, because they won’t find that income in 10-year Treasurys, and domestic dividend plays have been bid up.
Next, it was David Lafferty, chief investment strategist at Natixis Global Asset Management, suggesting that volatility would be up for the first quarter of 2014 — and possibly the first half — but noting that investors with reasonable expectations should ride it out to reasonable single-digit gains for the year.
Brian Sullivan, chief investment officer at Regions Investment Management, said he expected that the Federal Reserve’s actions had already been priced into the market, so that investors should not expect the after-effects of tapering to bite into the uptrend, while Steve Scruggs, manager of the Queens Road Funds contradicted that by suggesting that there will be adverse effects to the market and the economy as the central bank decreases its financial support.

Five innovations in medical care to watch in 2014

"Laura Landro lists five innovations in medical care to keep an eye on in the coming year.
Scott Wren, senior equity strategist forWells Fargo Advisors, is nervous that the market’s recent rally is eating into returns investors might have expected from 2014, which should make the 12 months ahead feel worse than he might have expected at the end of the third quarter.
John Herrmann, the rates strategist for Mistubishi UFJ Securities, was far more bullish about the economy than most, suggesting that the broad economic numbers have been misleading and the economy’s underpinnings are much stronger than most people believe.
On the other hand, Peter Schiff, chief global strategist for Euro Pacific Capital, is one of the loudest bears around, and he was growling about how investors need to overhaul their investment strategy or risk getting mauled by what lies ahead.

How To Play Goldman Sach’s Top Trades For 2014 (GS,GXC,JJC,EUFN,KBE,FXC,CEO,CHL,SAN,LYG,FXCM)

How To Play Goldman Sach’s Top Trades For 2014 (GS,GXC,JJC,EUFN,KBE,FXC,CEO,CHL,SAN,LYG,FXCM)

Tickers in this Article: GSGXCJJCEUFNKBEFXCCEOCHLSANLYGFXCM
With 2013 winding down, a variety of investment banks, strategists and market pundits are beginning to make their forward looking predictions on just what will happen in the new year. For retail investors, following predictions can provide valuable insight to how the macroeconomic picture is evolving and ultimately lead to portfolio gains. Venerable investment bank Goldman Sachs (NYSE:GS) recently unveiled its top trades for 2014.

While Goldman is no stranger to controversy, it is pretty good at calling the shots when it comes to the market. While there are no guarantees that its predictions will come true, the odds are pretty good based on historical evidence. For investors, taking on some of Goldman’s ideas could do their portfolio a world of good.

Driven By The Taper

Through a series of research notes given out to top clients, investment bank Goldman Sachs unveiled its latest list of the six best trades for 2014. The bulk of Goldman’s latest list of recommendations plays off the idea that the Federal Reserve will begin winding its quantitative easing programs this year. The Fed has been buying bonds at an impressive clip over the past few years in an effort to drive down interest rates.

Using that fact as a framework, Goldman developed a series of pairs trades- going long and short- various asset classes in order to profit from various market situations caused by the resulting taper and the continuation of low real interest rates. While some of the recommendations are pretty technical at first blush, the recent boom in exchange traded funds gives investors the ability to tackle some of these ideas with relative ease. While they aren’t for everyone, the potential profits on these trades could be some of the biggest gains investors see throughout 2014. Here’s how to play some of the top ideas.

Long China & Short Copper

According to Goldman, Chinese equities are dirt cheap and are trading for pre-crisis prices. That makes them a value as growth returns to Asia’s Dragon economy. Meanwhile, shorting copper provides investors with a hedge if Chinese growth doesn’t pan out as planned. Copper prices are generally tied to China’s output as the metal is used in a variety of infrastructure and manufacturing uses. The added bonus is that Goldman predicts copper prices will face their own headwinds in 2014 as supplies will remain robust. That could boost this trade idea throughout the year.

The easiest way for investors to bet on this plan via ETFs is go long the SPDR S&P China(NYSE:GXC), while shorting the iPath DJ-UBS Copper ETN (NYSE: JJC). The GXC tracks a basket of 490 of China’s largest companies- including CNOOC (NYSE:CEO) and China Mobile (NYSE:CHL). The iPath Copper ETN follows a basket of copper futures and should fall as the surplus of supply takes hold. Overall, Goldman estimates that this trade should next investors around 25% in 2014.
Go Long European & U.S. Banks

U.S. and European banks could be a great trade throughout the year as Goldman predicts that several of the same forces that propelled the stocks higher this year will persist into the next. That includes stronger overall economic growth- which is good for loan volumes and deal making- as well as accommodative policies by the world’s central banks. Overall, GS predicts that European and U.S. banks could net investors 20% in 2014.

Playing that trade is possible via the iShares MSCI Europe Financials (NASDAQ:EUFN). The ETF follows 100 of Europe’s largest banking and financial institutions. Top holdings for EUFN include Banco Santander (NYSE:SAN) and British bank Lloyd’s (NYSE:LYG). Shares of the ETF yield nearly 2% and expenses are dirt cheap at 0.48%. For U.S. bank exposure, the SPDR S&P Bank ETF (NYSE:KBE) makes adding a swath of banking stocks easy.

Go Long The Greenback Against The Loonie

Goldman estimates that strong economic growth in the U.S. should have it beating our neighbors to the North in the returns department. Additionally, with the taper finally getting underway, the U.S. dollar should be a source of strength in 2014. Canada’s government still has room to ease more to stimulate growth- adding to its weakness. That means the Canadian currency- the Loonie- should continue to fall relative to the U.S. dollar.

Aside from opening up a forex account at a broker like FXCM (NASDAQ:FXCM), shorting the CurrencyShares Canadian Dollar Trust (NYSE:FXC) can provide the easiest way to play this trade idea. The CurrencyShares ETF is backed by physical Canadian currency and has already sunk close to a 52-week long as the “taper talk” begun. Goldman estimates that the short Loonie trade will net you about 8% in 2014.

The Bottom Line

With 2014 quickly approaching, Goldman Sach’s has unveiled its latest list of profitable trades for the new year. While they seem complex at first, the boom in exchange traded funds has made them available to every investor. Betting on them could mean big gains in the year ahead.

Disclosure - At the time of writing, the author did not own shares of any company mentioned in this article.

Many Key Changes to Goldman Sachs Conviction Buy List for 2014 - Dollar General (NYSE:DG) - 24/7 Wall St.

Many Key Changes to Goldman Sachs Conviction Buy List for 2014 - Dollar General (NYSE:DG) - 24/7 Wall St.

Many Key Changes to Goldman Sachs Conviction Buy List for 2014

ABBV
ATW
DG
ENB
EXR
HCA
MKTO
MTG
PCLN
TIF
USB
VSI

Technostalgia: Remembering our first computers | Ars Technica

Technostalgia: Remembering our first computers | Ars Technica


Ars editors remember the computers that began their digital lives.

Being a bunch of technology journalists who make our living on the Web, we at Ars all have a fairly intimate relationship with computers dating back to our childhood—even if for some of us, that childhood is a bit more distant than others. And our technological careers and interests are at least partially shaped by the devices we started with.
So when Cyborgology's David Banks recently offered up an autobiography of himself based on the computing devices he grew up with, it started a conversation among us about our first computing experiences. And being the most (chronologically) senior of Ars' senior editors, the lot fell to me to pull these recollections together—since, in theory, I have the longest view of the bunch.
Considering the first computer I used was a Digital Equipment Corp. PDP-10, that theory is probably correct.

BookMark