Thursday, July 28, 2011

Madoff trustee in $1 billion settlement with Tremont

July 28, 2011

Madoff trustee in $1 billion settlement with Tremont

NEW YORK, The trustee seeking money for victims of Bernard Madoff's fraud announced a more than $1 billion settlement with Tremont Group Holdings Inc, which he had accused of missing warning signs of the Ponzi scheme.

Thursday's settlement raises the amount of money trustee Irving Picard said he has recovered for Madoff's victims to $8.6 billion, or roughly half the $17.3 billion lost by customers who filed claims. It requires court approval.

Picard has said Rye, New York-based Tremont, which is part of Massachusetts Mutual Life Insurance Co, was the second-largest "feeder fund" group that funneled money to Madoff from its own investors.

He had sued Tremont for $2.1 billion on February 28, accusing it of missing "red flags" and "blindly relying on Madoff to drive their funds' returns" for nearly 15 years.

Tremont and its now-defunct Rye Investment Management unit lost more than $3 billion of client money funneled to Madoff and his firm Bernard L. Madoff Investment Securities LLC, whose liquidation is overseen by Picard.

The Tremont accord covers more than one dozen U.S. and foreign investment funds and their affiliates.

Once the more than $1 billion of settlement payments are released from escrow, Picard will allow more than $3 billion of customer claims related to the Rye Select and Tremont funds against the Madoff firm's bankruptcy estate.

The settlement "gives investors in our funds the potential to recover a substantial portion of their losses" from Madoff's fraud, Tremont spokesman Montieth Illingworth said in a statement. "Bringing this matter to a close, with proofs of claim preserved, was the best outcome."

http://www.newsmeat.com/news/meat.php?articleId=104872686&channelId=2951&buyerId=newsmeatcom&buid=3281

Tuesday, July 19, 2011

U.S. Arrests 14 for Roles in PayPal Cyber Attack ...

July 19, 2011

U.S. arrests 14 for roles in PayPal cyber attack

Washington, U.S. authorities on Tuesday arrested 16 people on charges they participated in major cyber attacks, including the crippling of eBay's PayPal website as retribution for dropping WikiLeaks as a client.

FBI agents arrested 14 people in nine states and Washington, D.C., for the PayPal attack, which occurred last December and was allegedly coordinated by the hacking group Anonymous. It was the biggest take down so far tied to the high-profile cyber attack.

Financial institutions like PayPal, Visa and MasterCard withdrew services from WikiLeaks last year after the website published thousands of sometimes embarrassing secret U.S. diplomatic reports that have caused strains between Washington and numerous allies.

Hackers responded with so-called distributed denial-of-service attacks that flooded the companies' websites and rendered them unavailable to legitimate users, according to the indictment filed in California.

PayPal suffered attacks for several days last December.

The 14 individuals were charged with conspiracy, which carries a maximum penalty of five years in prison if convicted, and intentional damage to a protected computer, which carries a maximum sentence of 10 years in prison.

Law enforcement authorities believe Anonymous is mostly made up of hackers believed to be in their teens and early 20s.

"The fact that they have been tracked back and that some of them have been arrested is a significant development," said Mark Rasch, a former chief of the Justice Department's cyber crimes unit and now director of Cybersecurity and Privacy Consulting for the government technology services firm CSC.

In addition, U.S. authorities executed more than 35 search warrants around the country as part of its investigation into coordinated cyber attacks against major companies and organizations, the Justice Department said.

The Justice Department and FBI have been under pressure to crack down on hackers who have stepped up their attacks on corporate and government websites over the last several months in a bid to thwart their activities.

Stewart Baker, a former top official of the Homeland Security department, said the FBI probably gave the case extra attention because of the public taunting the bureau received from Anonymous and related groups.

"It does look like some of these guys (hackers) were just fools. The PayPal attack in particular," said Baker, now at the law firm Steptoe and Johnson LLP. "It looks like these bozos must have just said 'Cool, an attack on PayPal. You can use my machine.'

"I think it makes it a lot less likely that that people will join the next digital lynch mob," he said.

Another related arrest came in New Mexico where an employee for a contractor for AT&T's wireless service faced charges of accessing a computer without authorization by allegedly downloading thousands of documents related to its 4G data network and LTE mobile broadband network.

The data was subsequently downloaded to a file-sharing web site in April and another one of the loosely organized groups of hackers, Lulz Security, subsequently publicized the data breach, the complaint said.

AT&T had no comment on the arrest.

http://www.newsmeat.com/news/meat.php?articleId=102964380&channelId=2951&buyerId=newsmeatcom&buid=3281

Thursday, June 16, 2011

Copyright aspects of hyperlinking and framing ...

See ...

Copyright aspects of hyperlinking and framing

While hyperlinking among webpages is an intrinsic feature of the web, some websites object to being linked to from other websites; some have claimed that linking to them is not allowed without permission.

Contentious in particular are deep links, which do not point to a site's home page or other entry point designated by the site owner, but to content elsewhere, allowing the user to bypass the site's own designated flow, and inline links, which incorporate the content in question into the pages of the linking site, making it seem part of the linking site's own content unless an explicit attribution is added.

Methods of website linking

This article pertains to methods of hyperlinking to/of different websites, often used in regard to search engine optimization (SEO). Many techniques and special terminology about linking are described below.

A reciprocal link is a mutual link between two objects, commonly between two websites to ensure mutual traffic.

For example, Trish and Roger have websites. If Roger's website links to Trish's website, and Trish's website links to Roger's website, the websites are reciprocally linked.

Website owners often submit their sites to reciprocal link exchange directories, in order to achieve higher rankings in the search engines. Reciprocal linking between websites is an important part of the search engine optimization process because Google uses link popularity algorithms (defined as the number of links that lead to a particular page and the anchor text of the link) to rank websites for relevancy.[citation needed]
Resource Linking

Resource Links are a category of links, which can be either one-way or two-way, usually referenced as "Resources" or "Information" in navbars, but sometimes, especially in the early, less compartmentalized years of the Web, simply called "links". Basically, they are hyperlinks to a website or a specific webpage containing content believed to be beneficial, useful and relevant to visitors of the site establishing the link.

In recent years, resource links have grown in importance because most major search engines have made it plain that—in Google's words-- "quantity, quality, and relevance of links count towards your rating."[1]

The engines' insistence on resource links being relevant and beneficial developed because many artificial link building methods were employed solely to "spam" search-engines, i.e. to "fool" the engines' algorithms into awarding the sites employing these unethical devices undeservedly high page ranks and/or return positions.

Despite cautioning site developers (again quoting from Google) to avoid "'free-for-all' links, link popularity schemes, or submitting your site to thousands of search engines (because) these are typically useless exercises that don't affect your ranking in the results of the major search engines[2] -- at least, not in a way you would likely consider to be positive,"[3] most major engines have deployed technology designed to "red flag" and potentially penalize sites employing such practices.

Forum signature linking

Forum signature linking is a technique used to build backlinks to a website. This is the process of using forum communities that allow outbound hyperlinks in a member's signature.

This can be a fast method to build up inbound links to a website; it can also produce some targeted traffic if the website is relevant to the forum topic. It should be stated that forums using the nofollow attribute will have no actual Search Engine Optimization value.

See also:

Backlink: incoming links
Deep linking: linking directly to a page within another website.
Inline linking: linking directly to content within another website.
Page Rank

http://www.justice.gov/criminal/cybercrime/reporting.htm#ip

Thursday, June 9, 2011

China and the US: Sizing up for cyber war? Critics think the tough talk is a smokescreen for censorship ...

June 9, 2011

China and the US: Sizing up for cyber war?

Senior US officials call cyber attacks 'acts of war', but critics think the tough talk is a smokescreen for censorship.

As senior US officials warn that cyber attacks on vital systems would be considered "acts of war" eliciting a real world military response, one professor at the National Defence University surmises that battles of the future might be fought by guys hunched over keyboards in dark basements, rather than strapping lads toting M-16s.

In light of recent cyber attacks on Google apparently launched from China, online tensions - the possible precursors to outright conflict - have been spreading from chat rooms, to Gmail accounts and into the meeting rooms of military decision makers in recent weeks.

"We operate in five domains: air, land, sea, outer space and cyberspace," says Dan Kuehl, a professor of information operations at the National Defence University in Washington. "An ever increasing amount of what we do has dependencies on cyberspace; a guy typing on a computer is one of the new faces of war," Kuehl told Al Jazeera, stressing that he is not speaking for the US government or his elite military university.

"A response to a cyber-incident or attack on the US would not necessarily be a cyber-response. All appropriate options would be on the table," Pentagon spokesman Colonel Dave Lapan said recently.

Tough talk and phishing trips

One US defence official told The Wall Street Journal newspaper: "If you shut down our power grid, maybe we will put a missile down one of your smokestacks," in rhetoric likely aimed at China. For its part, the Chinese government categorically denied any involvement in the cyber attacks, which Google reported to the US state department and media outlets last week.

The reason for this sort of digital tough-talk is related to basic military strategy. "There is value in ambiguity," Kuehl said. "You don't want your adversary to think 'I can go up to that red line but I can't cross it'. You want them to think 'I won't do anything in the first place'," for fear of old fashioned physical reprisal.

Phishing attacks recently launched against Google's mail service targeted the personal e-mail accounts of some senior US officials, along with Chinese journalists, human rights activists and South Korea's government.

These attacks are similar in form to the scam e-mails most people receive from, say, the widow of a Nigerian millionaire who asks the user to open a message so they can claim their $14m reward for being a nice person. Once the message is opened, the victim's computer is compromised.

"This was a pretty straight forward phishing attack, other than the more sophisticated social engineering where the e-mail seems to come from someone who you know,” says Richard Stiennon, the chief research analyst at IT-Harvest and author of Surviving Cyberwar, referring to recent actions against Gmail.

"The Chinese have the early advantage in executing cyber warfare. If you have a large information gathering operation, knowing even the personal data of officials can be valuable," he told Al Jazeera. If data is stolen from personal accounts it is likely dumped into massive data banks for processing, crossing referencing and analysis.

WikiLeaks documents indicate that US diplomats are concerned about China's government recruiting top hackers to launch cyber war campaigns.

"There is a strong possibility the PRC [People's Republic of China] is harvesting the talents of its private sector in order to bolster offensive and defensive computer network operations capabilities," said a secret state department cable from June 2009.

Tampering with logistics

Since 2002, cyber intruders, apparently from China, have exploited vulnerabilities in the Window's operating system to steal login credentials in order to gain access to hundreds of US government and defence contractor systems, according to a 2008 cable.

China, for its part, says it is ready for online conflict should it arise. "Of late, an internet tornado has swept across the world... massively impacting and shocking the globe. Behind all this lies the shadow of America," said a recent article published in the Communist-Party controlled China Youth Daily newspaper, signed by Ye Zheng and Zhao Baoxian, who are scholars with the Academy of Military Sciences, a government linked think-tank.

"Faced with this warm-up for an internet war, every nation and military can't be passive but is making preparations to fight the internet war," the article said.

That attacks apparently came from China does not, onto itself, implicate the Chinese government. Internet or IP addresses which delineate where a computer is physically located can be compromised, allowing users in one country to take over a computer somewhere else to launch attacks.

"How do you know where to strike back? You don't," says Bruce Schneier, a technology expert and author of several books who The Economist magazine describes as a "security guru".

"You don't have nationality for cyber attacks, making retaliation hard," he told Al Jazeera.

But the nature of the Chinese state, where information is closely controlled, most corporations are linked to the Communist Party apparatus and dissidents are crushed, means the government likely had some knowledge of what was happening, Stiennon says.

And, even if the Google attack was carried out by rogue hackers, American defence planners haven't been taking any chances. One possible scenario involves a Chinese move to re-take Taiwan - an island which China views as a renegade - despite the US and UN considering it a sovereign country.

"The Chinese have looked at their biggest potential military adversary, the US, and decided that their biggest weaknesses are that they are far away and dependent on computers," says Kuehl from the defence university. He thinks likely Chinese strategies are twofold: The obvious "degrading enemy military apparatuses in the theatre of war" and "preventing the enemy from getting there". Cyber attacks, targeting battle ship deployments and logistics, would play decisively in the latter.

"The threat, from a military perspective, isn't data denial, it is data manipulation," Kuehl says. "What do you do when the data on your screen is wrong and air traffic controls, money, deployment orders and personnel have all been tampered with?"

Misdirection and censorship

Regardless of China's broader aims or involvement from the Chinese government in recent cyber mischief against Google, there is nothing new or impressive about recent cyber attacks, even though the international media has focused on them, Schneier says. "Millions of these kinds of attacks happen all the time," he says. To him, recent phishing operations against Google are not even worthy of a blog post, as such events happen so frequently.

Chris Palmer, the technology director with the Electronic Frontier Foundation advocacy group, thinks recent rhetoric about cyber war is a "smokescreen to limit freedom of speech on the internet".

"If I was being cynical, this campaign [about cyber security] is being launched by defence contractors to drum up a threat and get money from it," Palmer told Al Jazeera.

The US state department's tough talk about physical reprisals is not the way to defend American infrastructure from attacks, he says. The solution is much simpler: Taking sensitive data off the internet entirely.

Gaining access to military documents or networks controlling physical infrastructure like water treatment plants and nuclear facilities "should be like Mission Impossible, requiring a physical presence". In the film, Tom Cruise has to sneak into a heavily guarded room to physically access a computer with secret information.

In the 1980s and early 1990s, power plants, for example, ran on private networks where the censors would talk to the controllers, Palmer says. "Now things that are supposed to be private have become virtually private, going over the same lines as internet traffic." As getting online became cheaper, and operating private networks became more costly and cumbersome compared to using the standard internet, companies began using the regular net.

"Not being on the internet costs more for dollars and opportunity cost," he says. "The design and the reality don't match anymore, but the design was supposed to be private." And this semi-public link to the broader net leaves vital systems potentially open to attack.

While military contractors propose new products to defend against online threats, commercial cyber crime - where companies seek data on competitors and rivals try to steal industrial secrets - may be a bigger issue than fears of nation to nation conflicts spilling onto the internet.

"The [US] defence department, just like everyone else, is struggling with the rapid rise of cyber threats," says Richard Stiennon, the security analyst. "It is all new. They don't have a basis in international law or jurisdictional avenues from which to build a cyber response."

And, the need for better international norms for governing cyber conflict is one of the few points of agreement between analysts. "The big thing here is that there is nothing magic about cyberspace," Schneider says."Everything that is true is still true when you put the word 'cyber' in front of it."

Some may say that international laws are often worth little more than the paper on which they are printed. And, sadly, the ability to exert force still determines the international pecking order. But, it may still be better to have an unenforceable framework for online conflict than none at all.

As Bruce Schneier puts it, "I think a UN conference on cyber war would be a great thing to do".

http://english.aljazeera.net/indepth/features/2011/06/201168204035985818.html

Friday, June 3, 2011

London Cyberwar ~ MI6 hits al-Qaida in 'Operation Cupcake' ...

June 3, 2011

MI6 hits al-Qaida in 'Operation Cupcake'

LONDON, Britain's cyberwar against al-Qaida took a sweet turn when intelligence officials hacked into a Web site, subbing bomb-making plans with a cupcake recipe.

The cyber operation was undertaken by MI6 and and Britain's Government Communications Headquarters to disrupt efforts by al-Qaida in the Arabian Peninsula to recruit so-called lone wolf terrorists with the English-language Inspire magazine, The Daily Telegraph said.

The British publication did not indicate when the cyberattack on Inspire occurred. British and U.S intelligence had planned separate operations after learning the magazine was about to launch in June 2010, developing a number of cyber countermeasures, including computer viruses.

When visitors tried to download the Webazine, instead of getting instruction about how to "Make a Bomb in the Kitchen of Your Mom" by "The AQ Chef," they got garbled computer code that was a Web page of recipes for "The Best Cupcakes in America."

Among other things, the substituted text produced by Main Street Cupcakes in Hudson, Ohio, included recipes for a mojito cupcake and a rocky road cupcake, the Telegraph said.

The text was supposed to be a recipe for making a lethal pipe bomb with household items, intelligence officers said.

The cyberattack also deleted an article called, "What to Expect in Jihad," by now-deceased al-Qaida leader Osama bin Laden, and his deputy, Ayman al-Zawahiri, the Telegraph said.

Inspire is produced by the radical preacher Anwar al-Awlaki, a leader of al-Qaida in the Arabian Peninsula who lived in Britain and the United States, and an associate.

Read more: http://www.upi.com/Top_News/World-News/2011/06/03/MI6-hits-al-Qaida-in-Operation-Cupcake/UPI-86971307102683/#ixzz1OECeCoUA

Saturday, May 14, 2011

Beware ~ Cyber Scams Rife at Social Networks

May 14, 2011

Cyber scams rife at social networks: Microsoft

Social networks are "lucrative hot beds" for cyber scams as crooks endeavor to dupe members of online communities, according to a Microsoft security report released on Thursday.

"Phishing" attacks that use seemingly legitimate messages to trick people into clicking on booby-trapped links, buying bogus software, or revealing information rocketed 1,200 percent at social networks last year, it said.

"We continue to see cyber criminals evolve attack methods such as a significant rise in social network phishing," Microsoft malware protection center manager Vinny Gullotto said in the Security Intelligence Report.

Phishing using social networking as a "lure" represented 84.5 percent of all such trickery in December as compared with 8.3 percent at the start of 2010, according to the report.

Microsoft analyzed data gathered from more than 600 million computer systems worldwide from July through December of last year for the semi-annual study.

"The popularity of social networking sites has created new opportunities for cyber criminals to not only directly impact users, but also friends, colleagues and family through impersonation," the report said.

"These techniques add to an existing list of social engineering techniques, such as financial and product promotions, to extort money or trick users into downloading malicious content."

Social engineering is a reference to fooling people to access machines or data instead of trying to hack into networks using software skills.

Microsoft noticed a "polarization" of cyber criminal behavior and a surge in the use of "marketing-like" deception tactics to steal money from people.

"On one side, highly sophisticated criminals skilled at creating exploits and informed with intelligence about a target’s environment pursue high-value targets with large payoffs," the report said.

"On the other side, there are cyber criminals using more accessible attack methods, including social engineering tactics and leveraging exploits created by the more skilled criminals, to take a small amount of money from a large number of people."

Criminals used malicious software to trick people with false advertisements, fake security software, and pay-per-click schemes that generate cash when Internet links are activated, according to Microsoft.

Detections of software crafted to infect machines with pop-up advertisements meanwhile rose 70 percent from the middle of last year to the end of December, the report indicated.

"With more consumers and devices coming online every day, cyber criminals now have more opportunities than before to deceive users through attack methods like adware, phishing and rogue security software," said Graham Titterington of Britain-based analyst firm Ovum.

"It’s becoming increasingly difficult for consumers to decipher legitimate communications and promotions given the sophistication of tools criminals are using."

Rogue security software, referred to as "scareware," was one of the most common ways for cyber criminals worldwide to bilk people out of money and steal information from computers.

The ploy seeks to dupe Internet users by pretending to find viruses and other problems on computers and then offering to sell a program to fix the situation. The software being hawked is a virus.

Computer users were advised to guard against threats by keeping programs updated, using reputable security software, and not clicking links or opening files without making certain they are safe.

http://www.gorkhapatra.org.np/gopa.detail.php?article_id=50089&cat_id=27

Friday, May 13, 2011

White House to unveil cyber-security strategy

Related article ~ May 26-27 ~ Internet Titans to Meet, Advise G8 ...


May 13, 2011

White House to unveil cybersecurity strategy

The White House plans to unveil its policy proposals next week for international cooperation in cyberspace.

The White House said Friday that it plans to release a policy document -- "US International Strategy for Cyberspace" -- at an event on Monday.

"This first-of-its-kind policy document offers our comprehensive vision for the future of international cooperation in cyberspace," the White House said in a statement.

It said the document outlines the US agenda "for partnering with other nations and peoples to ensure the prosperity, security, and openness that we seek in our increasingly networked world."

The State Department said Secretary of State Hillary Clinton, who has made Internet freedom one of her priorities, will deliver keynote remarks at the event.

"The strategy lays out a comprehensive, principled vision for the future of cyberspace," the State Department said.

It said Clinton's remarks "will address the role of cyberspace in advancing the full range of US interests and the importance of international cooperation in advancing cyberspace as a foreign policy priority."

The White House said other top officials attending the event will include John Brennan, President Barack Obama's counter-terror chief, Attorney General Eric Holder, Commerce Secretary Gary Locke and Homeland Security Secretary Janet Napolitano.

The announcement came a day after the White House proposed draft legislation aimed at toughening the defenses of government and private industry against the growing danger from cyberattack.

Obama has identified cybersecurity as a top priority of his administration and the White House legislation joins some 50 cyber-related bills introduced during the last session of Congress.

The White House bill would require critical infrastructure such as the power, financial and transportation sectors to come up with plans to better protect their increasingly Internet-connected computer networks.

The White House is hoping for action by Congress on the bill this year.

http://www.newsmeat.com/news/meat.php?articleId=98678276&channelId=2951&buyerId=newsmeatcom&buid=3281