Showing posts with label Press. Show all posts
Showing posts with label Press. Show all posts

Sunday, August 15, 2010

Entranced!



I am describing my mind and it's fixation with the WikiLeaks/Pfc Manning/Wired Magazine (via Kevin Poulson)/Adrian Lamo/Icelandic Law thing. I am like a person watching a car wreck. I cannot look away. I have not made up my mind on this but I am very intrigued. WikiLeaks may be a criminal enterprise, a heroic counterpoint to secrecy and big brother or we may be watching the evolution of journalism before our very eyes. 

Here is the story so far: Mr. Assange has assisted in the crafting of legislation that was recently passed in Iceland and which subsequently creates a "free press haven" which protects him (and other journalists) from search and seizure and incarceration. He stores his data there and elsewhere where data protection laws exists. He is mirrored by hundreds of other sites and distributes his data globally. Then he leaks 92,000 US military files from Afghanistan (Actually, 77,000 - he keeps some in reserve for Insurance). He shows the horrors of war while continuing to uncover the underhanded practices of individuals, groups, businesses, religions, governments. Private Manning appears to be the leaker and was turned in by Adrian Lamo, the barefoot hacker. The story breaks on the Wired Magazine "Threat Level" blog run by hacker Kevin Poulsen. We learn that Private Manning has a pretty high security clearance and is love with a drag queen from Cambridge, Mass. We have human rights groups joining the military in asking WikiLeaks to edit the documents to protect the people assisting the US Army in Afghanistan. Lastly, we now learn of a potential war within the WikiLeaks "organization" and a potential CyberWar with the US military

He described the original goal of Wikileaks and how it evolved and adapted over time recently at a Berkeley Graduate School of Journalism symposium. This symposium took place just prior to the passage of the law and thus prior to releasing the documents. 

This is a story revolves around hackers. There are hackers at the center, hackers at the news outlets, hackers whistle-blowing on the hacker whistle-blower. This story is crawling with them.

Rather than debate the moral and ethical issues or try and talk about the impact on the newly changing journalistic world or the case details I would like to discuss what the heck happened to those pesky kids inspired by the movie WarGames and Captain Crunch.

In the past 20 years or so hackers have been portrayed by the media consciousness as teenage nerds disillusioned with their place in the world. Kids who get bullied in school and fight back by hacking into NORAD or AT&T or whatever. They have been shown as dweebs and techno punks. I never thought that any of these images were very accurate. Stories about real hackers never seemed to jibe with the images of Hollywood or the mainstream news.

I have been to a few hacker conventions and know a few hackers myself (let us not have a semantic debate about the term - Hacker - that fight was lost awhile back in 1983 if not before. It has many meanings but ask someone on the street in Des Moines or Tulsa and they have a very particular image in mind. In this I omit those folks who steal grandmas credit cards or push child porn and their ilk).  The folks I have met and know are crafty and witty. They spurn convention. They want to know how things work without having someone do the work for them. They love pranks and hate injustice. Some are very vain and cruel. They want information to be free to all. Others are gregarious and kind. All of them have one thing on common, they are all very smart. You have to be smart in a subculture where "what you know" and "what you can do" are the means to establish your status. 

I do not think that the general hacker populace cares one bit how they are portrayed in the media regardless in the past 10 years or so many of them grew up. Those 13 year old kids who in 1983 watched David Lightman hack into WOPR are now 40 and they are doing things.

Originally, they started out in a predictable way. They continued to hack into systems they did not like. They started network sit-ins. They defaced the sites of organizations they didn't like. Then they really evolved.

They started coordinating efforts of anti-WTO protesters in Seattle in 2000 and protesters at the Democratic National convention in Denver in 2008. All groups were open as targets as long as the hackers thought they were making news or changing the public opinion.

Assange and his crew wanted to change the way the media and "just folks" got their information. He wanted to link up all these bloggers with too much time on their hands with original source material and let them get the news unfiltered and then voice their opinions. well, It didn't work out quite how he planned but is doing something. What this something is we will see in the coming months.

The Hacker ethos has finally hit the mainstream. Google (net neutrality issues aside) has sponsored with Yahoo, Microsoft and others some "Random Hacks of Charity" and defied the work of the Chinese government to expose opposition party chinese nationals. Bill Gates wants to make a difference with his charities and has convinced many billionaires to follow his lead. 

J0hnnyhax, otherwise known as Johnny Long, and some friends went to Africa and started Hackers for Charity with the goal of, "proving that hackers have amazing skills that can transform charitable organizations. We’re about stepping into the gap to feed and educate the world’s most vulnerable citizens. We are virtual, geographically diverse and different." He has done amazing work in Uganda setting up labs and user groups, computer education and training. Recently he has been despondent, however. His blog posts the following, 
"HFC has done little relative to our collective capability.
We can throw an 802.11 signal a world-record distance of 275km using junk hardware. We can rootkit Android before it’s released, hack GSM, hijack global DNS, pick every lock on the planet, beat international news agencies to the punch, and weed our way into previously untrodden shadows of the digital world. There is amazing skill in our community. We build robots just because we can, and tweak just about every technology on the planet to unbelievable ends. We are motivated and brilliant. We are self-organizing and ultra-productive when assaulting “impossible” projects. We break, bend, and then re-create the rules. But can we really, honestly do some good in the world? My answer used to be a resounding “YES!” Now, my answer is a much-too-passive “Maybe”.
Yes, with me and my family on the ground here in Uganda, some positive things have happened (http://www.hfc-uganda.org). But is that work reflective of the power of our community? Hardly."

The rent for HFC just doubled in Uganda and Johnny despairs. 

The world is changing. Hackers are growing up. They are attempting to do what previous of generations of folks have tried time after time. They want the world to be fair. They want to contribute. they want to make a difference. It is a hard, long, twisting road and is uphill both ways. Giving up or giving in would be easy and just chugging along in the normal pay-earning life with all our normal problems of home, job, family and personal life seem to be enough to consume all our time. Where will this go?

Will HFC continue? Will Assange get arrested? Will Google divide the Internet into haves and have nots or will it refrain from being evil? I am entranced. I cannot look away. It is magic in the making.

Thursday, September 20, 2007

WLAN IDS and the bizarre world of security exploits

If you make security software (or any software, for that matter) sooner or later you will create what I technically refer to as a booboo. A security vulnerability in your software that raises the ire of your customers and make you feel foolish and sad. Not to worry, mateys, this happens to all software manufacturers. The important thing to remember here is how you handle it. Are you going to be a Pro or a shmuck? Recently, AirDefense (why no dot com?), a WLAN IDS manufacturer had just such and incident. Is this uncommon? Relatively so. Is it dire? Not really. Are you just sniping at your competitor? Kind of, but in the interest of disclosure, we had an incident a long time ago as well so, dear friends, I feel their pain.

Let's talk about what happened first. The vulnerability as explained here happens when you send a specially crafted HTTPS request, which will cause the HTTPS service on the system to crash. It appears from my quick glance as if you need to authenticate first and also be on the segment from which you can administer the system. So what is this? Granted it can bring down the sensor but actually it appears to be a "tempest in a teacup". You need to be the admin or snarf the admin login in order to cause a denial of service to one of probably many tens or hundereds of sensors. Unlikely at best.

So how was this handled? Professionally, in my humble opinion. AirDefense contacted the people who reported the exploit and directed them to a patch for it as reported here, "Solution: Update to the latest firmware version"

AirMagnet had a similar experience Last October. And we handled it the same way. Here is our official response to the problem from back then:


Re: Airmagnet management interfaces multiple vulnerabilities
AirMagnet vendor response below -
(1) The vulnerabilities are tested against an over-a-year old AirMagnet Enterprise product,
(2) Some of these vulnerabilities have been patched and fixed in AirMagnet Enterprise version 7.0.x,
(3) All vulnerabilities are now completely fixed by AirMagnet Enterprise version 7.5 build 6307 and later.
(4) AirMagnet customers can download patches from MyAirMagnet support web site (http://www.airmagnet.com/my_airmagnet/index.php)
So to summarize, there are a lot of security professionals out there who are trying to make a name for themselves and do it in an industry, like the WLAN industry, that is going places. They spend all their time looking for these exploits and I, for one, am glad they do. They keep us honest and ensure that we are doing our very best to protect our customers. Are their motives pure? Debatable but mostly. Do they sit down afterwards and talk amongst themselves about what l@m3rz those software guys are? You bet! Should I take it personally? Nah.

Friday, January 19, 2007

I was in the papers a few times also...

So maybe I am in a, "toot your own horn" kinda mood. (I must not get enough love at work) but I thought I would catalog some props from my past.



I have been printed in a variety of articles in the mainstream press, most of which I am very proud of. For example, I just happened to be a a h@x0r convention in Washington DC called ShmooCon on behalf of AirMagnet when Simple Nomad relased a [kinda] zero day for wifi. I was just hangin out afterwards when a reporter from the Washington Post grabbed a seat at my lonely table to discuss it. Brian Krebs is very well respected and I was happy to talk to him so we chatted about how lame it was that Microsoft kept having stuff blow up on them and this one was such a silly thing. It really blew us away. He asked for a real interview to learn how this had been effecting some of my customers - which it had - and then we went a had a few beers.


You see I was getting calls from a bunch of my customers saying that they were seeing bizarre SSIDs showing up on the Dashboard of our IDS, AirMagnet Enterprise. And to top it all off, they were all in Ad-Hoc, or peer-to-peer mode. SSIDs with names like, linksys, tmobile, hpsetup and wayport-access. My customers were blaming our software, saying we were, "sending false positives". Well, it turns out it was Microsoft's fault the whole time. Go Figure.


Brian is a great guy so I will probably grab a few beers with him this year when I go out in March, but it just goes to show you that 80% of success is just showing up (thanks Woody Allen).


Here are some other links to press on me:



Here is the Washington Post piece. And almost exactly a year later, here is Microsoft's resolution to the vulnerability.



I conducted a walk around with the New York Times (didn't get a mention but my neighborhood did).


And here are a bunch from DefCon 13 where I found a bunch of radio interference:


Wireless Week


The IEEE


EE Times


Information Week




There is also some stuff from waaaaayyyyy back with computer world and a ton of ISSA, ISACA and other speaking engagements. too old to worry about.