Sunday, June 24, 2012

Energy assets in front line of cyber war

DUBAI (Reuters) - Global energy infrastructure is more vulnerable than ever in an escalating cyber war thanks to "sons of Stuxnet" electronic missiles, which can be created from the virus designed to sabotage Iran's nuclear program.

Cyber espionage is on the rise, with Chinese hackers stealing field data and cutting-edge technology from energy companies around the world since at least 2009, according to leading security firm McAfee (part of Intel Corp).

But the biggest threat to everything from power grids to digital oilfields may come from malware based on the Stuxnet worm, widely thought to have been sponsored by western government agencies, security experts say.

Cyber weapons like Stuxnet that can take control of plants appear to be more of an operational danger than the recently discovered Flame virus, which seems designed to gather data.

"Stuxnet really showed people you could do this, that is the problem. I cannot imagine any major government agency not developing an offensive capability," Eric Byres, a leading authority on critical infrastructure security, told Reuters.

Byres, who advises governments and multinationals on cyber security, said government agencies could seek to infiltrate energy infrastructure in case of political tension. "That is one of the risks, that we are weaponizing our entire energy industry, or leaving weapons inside it, just in case."

Governments are concerned that energy and communications networks would be the first victims of any conflict with a cyber-savvy aggressor.

"It is believed that would be part of any form of warfare - that they would take out private sector infrastructures as part of knocking out a country," said Paul Dorey, who managed BP's digital security until 2008 and is now professor of information security at the University of London.

The stable relationship between the United States, Russia and China, means there seems little chance they will try to disrupt one another's energy networks any time soon.

But Iran has been bombarded with cyber bugs during its intense nuclear standoff with the west, with the virus known as Flame detected in April and a worm called Duqu, designed to gather intelligence on industrial infrastructure for future attacks, found last year.

ESPIONAGE

The United States is by far the biggest source of general malicious activity on the Internet, data from antivirus software maker Symantec Corp indicates, but targeted industrial espionage largely comes from Asia.

"Targeted attacks are increasing dramatically. It could be state sponsored or it could be just hacktivists or it could be a cyber criminal organization. But we know the number one target is government institutions and the second is manufacturing, including oil and gas," Bulent Teksoz, Symantec's chief security strategist for emerging markets said.

According to data from the Repository of Industrial Security Incidents, power and transportation companies see the greatest number of major cyber security problems. Most of those incidents result in some loss of production or equipment control.

Until Stuxnet, breaking into supervisory control and data acquisition (Scada) systems running most of the world's industry was thought to be beyond most hackers.

Thanks to its groundbreaking code now leaked and freely available on the Internet, any competent cyber criminal group could use it to spear Scada security that controls vital infrastructure around the world.

"Stuxnet does provide a delivery vehicle, for non state actors to use, that is a direct threat to critical infrastructure," said Alexander Klimburg, senior cyber security adviser at the Austrian Institute for International Affairs.

"They have to go and develop their own warhead but you have given them a cruise missile... It's perfectly possible that Stuxnet could be adapted for cyber terrorism purposes and that is a real concern."

Byres, who designed the leading industrial firewall system, said that although the original cyber weapon targets Siemens systems that controlled Iran's Natanz centrifuges, its parts could be adapted to take control of any industrial controller.

It has had some impact on at least 22 other installations, including a U.S. metals factory, he said.

CYBER COLD WAR

The mother of all Scada attacks is believed to have occurred 30 years ago, when the U.S. Central Intelligence Agency is said to have used a "logic bomb" to blow up a Siberian gas pipeline.

According to a book by former senior U.S. intelligence officer Thomas Reed, after discovering the KGB was trying to steal pipeline control software, the CIA planted a version that would cause the system to over pressurize and let the Soviets have it.

President Barack Obama warned in 2009 that "cyber intruders" were probing the U.S. power network and that foreign intelligence services were behind some intrusions. In March the U.S. Department of Homeland Security identified a series of attacks on natural gas pipeline operators.

"We believe it is only a matter of time before someone employs capabilities that could cause significant disruption to civilian or government networks and to our critical infrastructure," General Keith Alexander, head of the U.S. Cyber Command, told a senate committee hearing on March 27.

A spokesman for the U.S. Department of Homeland Security declined comment for this article. The agency's Industrial Control Systems Computer Emergency Response Team is charged with responding to cyber attacks on energy plants and other critical infrastructure.

A U.S. Department of Defense report said this month that cyber spying was done by intelligence services, private sector companies, and individuals from dozens of countries, but that it expected China to remain an "aggressive and capable" collector.

"Chinese attempts to collect U.S. technological and economic information will continue at a high level and will represent a growing and persistent threat to U.S. economic security."

U.S. cyber defense chief General Alexander told the committee that Chinese hackers were responsible for a raid in early 2011 on RSA, makers of the SecurID system used by many large companies to access private networks.

The codes and control servers used in the U.S. gas grid attacks match those used to break into RSA, Byres said.

Night Dragon, so called because U.S. security firm McAfee noticed the data raids took place from Beijing-based IP addresses on weekdays from 9.00 am to 5.00 pm Beijing time, was the first known coordinated attacks on global energy companies.

Night Dragon, reported in 2011, focused on stealing information on potential oil and gas reserves and new technologies from western energy companies, valuable information for rivals competing for exploration licenses around the world.

Modern "digital drilling rigs" with their multiple external connections to critical onboard systems, and the roll out of "smart meter" systems linking consumers and power generators via two way communication lines, are new potential weak spots.

"The attackers are getting more skilled and we are increasing the vulnerability," Justin Lowe, an energy security specialist at PA Consulting Group told the conference.

"We are putting more systems out there which are attackable."

(Additional reporting by Jim Finkle in Boston. Editing by Philippa Fletcher and M.D. Golan)


View the original article here

Windows phones to miss out on new software

NEW YORK (AP) — As it struggles to gain a foothold against the iPhone and Android phones, Microsoft Corp. is planning to issue a dramatic update to its phone software, one that won't be available to current Windows Phones.

The new software, Windows Phone 8, will be available on new phones this fall, Microsoft said Wednesday at a presentation in San Francisco. The software will bring Windows phones closer to PCs and tablets running the company's upcoming Windows 8, which is also scheduled to launch later this year.

With its planned software updates —and the Surface tablet computer it introduced earlier this week— Microsoft is taking dramatic steps to ensure that it plays a major role in the increasingly important mobile market.

But the company is playing catch-up in an arena dominated by Apple and Google. Microsoft launched Windows Phone 7 in 2010, making a clean break with its previous phone software, which had become outdated. Nokia Corp., until recently the world's biggest maker of phones, has pledged to use it for all its smartphones, and launched its first Windows Phone in the U.S. earlier this year.

Sales have been anemic, however. IDC estimated that 2.2 percent of the smartphones shipped worldwide in the first quarter of this year ran Microsoft's software, compared to 23 percent for Apple and 59 percent for Android. Still, U.S. wireless carriers support Windows Phone, seeing it as a valuable counterweight to the clout of Apple Inc.'s iPhone and phones running Google Inc.'s Android software.

Windows Phone is making progress in one respect. Hit games "Words With Friends" and "Draw Something" will be among the apps available for Windows 8. There are 100,000 applications available for Windows phones today, Microsoft said. That's far less than the number of apps available for iPhones and Android phones.

Windows Phone 8 will accept expansion memory cards, like Android phones do. It will also work on processors with more than one computing "core," which are common in high-end smartphones. More cores boost computing power and can cut power consumption.

The new software will also work with near-field communications chips, allowing phones to be used in place of credit cards at some payment terminals. At the conference, Microsoft's head of phone software, Joe Belfiore, demonstrated how NFC can be used to link two phones so their owners can play a Scrabble-like game. Tapping the phones together can engage NFC, and prompt the devices to establish a link over Wi-Fi.

Some recent Android phones come with NFC capabilities, but they're missing from the iPhone.

Windows Phone 8 will share the operating system "kernel," or most basic functions, with Windows 8 RT, which will run on tablets and computers. That means manufacturers will have an easier time making hardware that can use either system. Developers will have an easier time moving applications from one platform to the other, Microsoft said.

Changing its phone software at such a basic level means that it will be difficult to install on existing Windows phones.


View the original article here

Saturday, June 23, 2012

Lanai seller to keep rights to build wind farm

HONOLULU (AP) — The billionaire selling 98 percent of the Hawaiian island of Lanai to Oracle CEO Larry Ellison says he plans to keep rights to complete a wind farm project that has caused controversy among the island's 3,200 residents.

Castle & Cooke owner David Murdock said Wednesday afternoon that he'll keep his residence on Lanai and the rights to the farm as part of the deal.

Murdock has clashed with some residents over the project. It would place windmills on as many as 20 square miles of the island and deliver power to Oahu through an undersea cable.

Those opposed to the project think it'll ruin pristine views of the Pacific Ocean and other Hawaiian islands.


View the original article here

LinkedIn sued for $5 million over data breach

 An Illinois woman has filed a $5 million lawsuit against LinkedIn Corp, saying the social network violated promises to consumers by not having better security in place when more than 6 million customer passwords were stolen.


The lawsuit, which was brought in federal court in San Jose, California, on June 15 and seeks class-action status, was filed less than two weeks after the stolen passwords turned up on websites frequented by computer hackers.


The attack on Mountain View, California-based LinkedIn, an employment and professional networking site with more than 160 million members, was the latest massive corporate data breach to have attracted the attention of class-action lawyers.


A federal judicial panel last week consolidated nine proposed class-action lawsuits in Nevada federal court against online shoe retailer Zappos, a unit of Amazon.com, over its January disclosure that hackers had siphoned information affecting 24 million customers.


The LinkedIn lawsuit was filed by Katie Szpyrka, a user of the website from Illinois. In court papers, her Chicago-based law firm, Edelson McGuire, said LinkedIn had "deceived customers" by having a security policy "in clear contradiction of accepted industry standards for database security."


LinkedIn spokeswoman Erin O'Harra said the lawsuit was without merit and was driven "by lawyers looking to take advantage of the situation."


"No member account has been breached as a result of the incident, and we have no reason to believe that any LinkedIn member has been injured," O'Harra said on Wednesday.


Legal experts say that meaty settlements in online customer data theft cases will likely be difficult to obtain because plaintiffs will have to show that they were actually harmed by a breach.


"In consumer security class actions, the demonstration of harm is very challenging," said Ira Rothken, a San Francisco-based lawyer at the Rothken Law Firm, which handles similar cases for plaintiffs.


If it turns out that the LinkedIn breach was limited to customer passwords and not corresponding email addresses, it will be that much harder for plaintiffs to prove they were harmed by the hack, Rothken said.


Edelson, a boutique firm that has long litigated data breach and Internet privacy lawsuits, scored a success in March when it obtained a settlement against social gaming company RockYou over a 2009 data breach.


In that case, a federal judge in Oakland, California, allowed a suit handled by Edelson against RockYou to proceed on breach of contract grounds - allegations Edelson has repeated against LinkedIn. Under the March 28 settlement, RockYou denied wrongdoing, but agreed to pay Edelson $290,000 in legal fees.


The case is Katie Szpyrka v. LinkedIn Corporation, U.S. District Court for the Northern District of California, No. 12-3088.


(Reporting By Basil Katz; Editing by Martha Graybow and Leslie Adler)


View the original article here

IDATE launches latest DigitalWorld Yearbook

Rating: It’s an industry Bible and Goldmine of useful stats rolled into one


GoMobile News had the pleasure of attending the launch of the DigiWorld Yearbook 2012 in London. This publication is now in its 12th year and has rapidly established itself as something of a Bible for the mobile industry – although in effect its remit covers the entire digital economy. What we took away from this launch was the publication’s conclusion that there are three big game changers at work within the cellular industry: – mobile everywhere; content in the cloud; and big data. The launch was accompanies by a keynote speech from Olaf Swantee, CEO, Everything Everywhere. He used the opportunity to make an impassioned plea for his company to be able to roll out 4G in the 1800 MHz spectrum.The Yearbook is actually the product of a body originally called IDATE but now rapidly re-branding itself as the DigiWorld Institute.


DigiWorld is thus best thought of as a kind of NGO (non-governmental organisation). However, it carries out research and provides consulting – especially to governmental organisations.


In a nutshell this publication is absolutely packed jam full of useful statistics about the current state of the mobile/cellular industry.


One industry luminary with whom GoMobile News exchanges views at the Yearbook launch revealed that he find the country section at the back of the publication particularity useful.


The presentations highlighted exactly the kind of trends and directions which GoMobile News itself feels are currently shaping the way the mobile industry transforms itself.


The launch was also an unashamed plug for IDATE’s own yearly event which it is calling the DigiWorld Summit which takes place this year between 14th-15th November [2012].


And a very civilised venue it has too in the shape of Le Corum, Montpelier France. A great chance to network with the good and great in the mobile industry.


Rather than try to describe what’s in the 2012 Yearbook, the best thing for readers to do is download the 2011 version in .pdf format because it’s free and is a clear guide as to what to expect from the current version.


If your searching for the reality rather than the fiction in true revenues from participation in the mobile industry try this Yearbook.


View the original article here

Brit firm Ensygnia gets QR code Patent for log-in process

Rating: New service will consign forgotten IDs and passwords to a thing of the past


We’re not quite sure what the major 2D barcode players like NeoMedia and ScanLife will make of this but a UK start-up company Ensygnia has confirmed  that – it had been granted its first technology patent by the UK Patent Office. This win had taken a mere 18 months to achieve. What the company is effectively providing is a secure log-in and check-out services using QR Codes – OneScan. The company claims that thanks to its encrypted QR (eQR) codes, OneScan service marks the beginning of the end for multiple passwords and log-in credentials for anyone accessing Internet services or private networks.“Using OneScan we can deliver a level of identification and authentication security greater than that used by consumer Banks today – without the need for specialist devices. We will be able to offer OneScan to register, to log-in, to pay at the online check-out, or to simply buy goods as they are advertised in magazines, on TV and even in shop windows when the stores are closed,” argues Richard Harris, CEO and co-founder of Ensygnia.


He continued, “At a stroke Ensygnia is making simple password protection a thing of the past and revolutionising Internet security and safety for all the providers and all the users of company networks, online stores, and social media services.”


In fact, that the two-communication channel approach of OneScan is only one element of the strengthened security process of the service Ensygnia’s CTO and co-founder, Matt Deacon, argues.


“With OneScan, users will no longer need to enter their ID or user name into a browser,” he said.


“Accessing a web service or network that uses OneScan will generate a unique Ensygnia encrypted QR code (eQR) which users simply scan to deliver their log-in credentials to the service over the separate mobile connection.”


Deacon continued, “Other security checks – including personal questions or password phrases – can be added to the process on the mobile to further strengthen security if required.”


“However, once these are completed you are automatically logged on to the service you are trying to access,” Deacon explained.


“In this way, your ID and your authentication information are kept completely invisible and out of band during the log-in and only come together in the background within the service.”


For online retail stores Harris added that OneScan could mean an end to ever entering credit or debit card information into a web site again.


“After registering once with Ensygnia on a secure channel, users could shop online safely and securely using OneScan to confirm purchases,” Deacon said.


“At the check-out stage of the online process,” he explained, “Instead of entering financial and personal information into the website, users would simply scan an eQR Code and confirm the transaction on our separate channel.


All the required banking and delivery information would be provided to the site in the background on the separate channel.”


Harris also reckons that stores and advertisers could include eQR codes alongside products in magazines, shop windows, or on television as well as the web allowing OneScan customers to quickly and securely buy goods with a single scan with no requirement to register, log-on or provide any financial information.


The company also revealed that it is now opening Beta stage testing of OneScan to a selection of partners.


To register for Beta trials or more information on One San visit the company web site here.

 

View the original article here

Swype keyboard updated by Nuance

The software studies which words the owner commonly uses to reduce mistakes The "next generation" of Swype - software that makes it easier to use a keyboard on a touchscreen device - has been unveiled by its owner Nuance.


The update builds in the firm's XT9 predictive text technology, allowing devices to complete words or phrases based on owners' previous usage.


It also adds the US firm's Dragon speech recognition functions, letting users dictate text rather than type it.


Nuance bought Swype from its inventors in October for $102.5m (£65m).


Its ability to let users drag their fingers from one letter to another, rather than typing them, had already helped it emerge as a popular alternative to standard built-in smartphone keyboards on Android phones.


Nuance said that manufacturers had already shipped more than 200 million devices with Swype preinstalled.

Asian appeal

The ability to dictate, rather than type, words may help the product gain more traction in parts of Asia where some languages with non-Roman alphabets have thousands of characters


The revamp also introduces the ability to interpret "handwriting", allowing users to write messages by drawing characters in Chinese and Korean alphabets


Alternative products include Swiftkey, Slideit, Thumb Keyboard and Smart Keyboard, but one analyst said combining the original feature set with Nuance's other technologies might give it an edge.


"It's an opportunity for Nuance to capitalise on the massive growth we're seeing in the handheld market - and of course Swype also works on Android tablets which also have great potential," said Chris Green, principal technology analyst at the consultants Davies Murphy Group Europe.


"As Swype moves out of beta they will look to licence technology to more handset makers, generating considerable royalties.


"A lot of vendors think that voice recognition will be the next big battleground among both software and handset makers - so by integrating the function into Swype at this stage, the firm gives itself an advantage."


View the original article here