Edward Snowden NBC NEWS FULL INTERVIEW 2014
Edward Snowden NBC NEWS FULL INTERVIEW 2014
Edward Snowden NBC NEWS FULL INTERVIEW 2014
In an exclusive interview with “Nightly News” anchor Brian Williams former NSA contractor leaker Edward Snowden indicated that the NSA had record of his internal complaints regarding government policy.
Today at the briefing, White House Press Secretary Jay Carney indicated the email would be released. It was published on both the Office of the Director of National Intelligence’s website, and by Senator Feinstein.
TrueCrypt is free open-source disk encryption software for Windows, Mac OS X and Linux. Recently the website that host the software states:
“This page exists only to help migrate existing data encrypted by TrueCrypt.
The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.”
What is your theory on why they shut down?
For more information on the matter, check out the links below:
http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/
http://www.zdnet.com/truecrypt-quits-inexplicable-7000029994/
We had the opportunity to speak with Adrian Winckles the local Conference Chair of AppSec EU 2014 as well as the OWASP UK Cambridge Chapter Leader. He also serves as the research track chair and is responsible for the conference schedule.
Listen to what Adrian had to say about the upcoming AppSec EU 2014 in Cambridge, UK
SANSFIRE 2014 is coming up soon at the Hilton Baltimore located in downtown Baltimore’s Inner Harbor district, June 21-30. SANSFIRE 2014 is SANS’ unique annual “ISC Powered” event. This is the event where the Internet Storm Center Incident Handlers present unique talks about the cyber hazards they deal with daily.
For more than 10 years, the Internet Storm Center has been providing free analysis and warning to our community. Some of this year’s highlights include a talk by ISC handler Rob VandenBrink about using virtualization in a consulting practice, Adrien de Beaupre will describe the why and how of attacking your own web-based applications with ZAP, and Richard Porter will use current literature and research as a foundation to discuss the current insider threat and risks. Also, don’t miss the State of the Internet Panel Discussion with Dr. Johannes Ullrich, ISC Director and Marcus Sachs, ISC Director Emeritus.
SANSFIRE 2014 hosts world-class instructors teaching top-quality SANS courses covering penetration testing and hacker exploits, IT security, security management, computer forensics, secure coding, and much more.
Most of courses at SANSFIRE 2014 are associated with GIAC Certifications, and once again, our NetWars – Tournament and the DFIR NetWars Tournament will both be features as part of this event on the evenings of June 26 and 27.
New courses include:
FOR572: Advanced Network Forensics and Analysis taught by Philip Hagen
FOR585: Advanced Smartphone Forensics taught by Heather Mahalik
ICS410: ICS/SCADA Security Essentials (GIAC-GICSP) taught by Paul A. Henry
For complete details regarding SANSFIRE 2014 and to register, please visit:
http://www.sans.org/info/157550
***Save 5% on your SANSFIRE 2014 course registration with code: SecOrb5_SANS ***
This is a collection of some of the best segments of The SecurityOrb Show in 2013. Interviews from Vivek Ramachandran, Raphael Mudge and Mark Russinovich to name a few. You can listen to the full interviews on the securityorb.com/ Website.
Vivek Ramachandran is the Founder and Chief Trainer at SecurityTube.net. He discovered the Caffe Latte attack, broke WEP Cloaking, a WEP protection schema in 2007 publicly at DEF CON and conceptualized enterprise Wi-Fi Backdoors. He is also the author of the book “Backtrack 5 Wireless Penetration Testing“. His book “The Metasploit Megaprimer” focused on Advanced Metasploit usage for Pentesting and Exploit Development is up for release in July 2013.
Vivek currently runs the SecurityTube Wi-Fi Security, Metasploit Framework, Python Scripting, iOS Security, GNU Debugger Expert online course and certifications, which is currently being taken by students from over 67+ countries around the world. He also conducts in-person trainings in the US, Europe and Asia.
In a past life, he was one of the programmers of the 802.1x protocol and Port Security in Cisco’s 6500 Catalyst series of switches. He was also one of the winners of the Microsoft Security Shootout contest held in India among a reported 65,000 participants. He has also published multiple research papers in the field of DDoS, ARP Spoofing Detection and Anomaly based Intrusion Detection Systems.
Vivek’s work on wireless security, has been quoted in BBC online, InfoWorld, MacWorld, The Register, IT World Canada etc. places. He has spoken/trained at top conferences around the world including Black Hat USA and Abu Dhabi, DEF CON, Hacktivity, Brucon, ClubHack, SecurityByte, SecurityZone, Nullcon, C0C0n etc.
The U.S. Justice Department today announced a series of actions against more than 100 people accused of purchasing and using “Blackshades,” a password-stealing Trojan horse program designed to infect computers throughout the world to spy on victims through their web cameras, steal files and account information, and log victims’ key strokes. While any effort that discourages the use of point-and-click tools for ill-gotten gains is a welcome development, the most remarkable aspect of this crackdown is that those who were targeted in this operation lacked any clue that it was forthcoming.
On Monday, May 19th, The U.S. Justice Department charged members of the Chinese military with conducting cyber-espionage against American companies such as Westinghouse and U.S. Steel to name a few. This marks the first time that the United States has ever brought charges against a foreign country for conducting cyber-espionage against its assets for stealing significant amounts of trade secrets and intellectual property.
Attorney General Eric H. Holder stated in a news conference, “The range of trade secrets and other sensitive business information stolen in this case is significant and demands an aggressive response. Success in the global marketplace should be based solely on a company’s ability to innovate and compete, not on a sponsor government’s ability to spy and steal business secrets.”
Below are a list of the names of the defendants and the companies that were victims to the hack:
“Defendants : Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui, who were officers in Unit 61398 of the Third Department of the Chinese People’s Liberation Army (PLA). The indictment alleges that Wang, Sun, and Wen, among others known and unknown to the grand jury, hacked or attempted to hack into U.S. entities named in the indictment, while Huang and Gu supported their conspiracy by, among other things, managing infrastructure (e.g., domain accounts) used for hacking.
“Victims : Westinghouse Electric Co. (Westinghouse), U.S. subsidiaries of SolarWorld AG (SolarWorld), United States Steel Corp. (U.S. Steel), Allegheny Technologies Inc. (ATI), the United Steel, Paper and Forestry, Rubber, Manufacturing, Energy, Allied Industrial and Service Workers International Union (USW) and Alcoa Inc.”
A guest posting by Gilad Parann-Nissany
I offer: Strong Cloud Encryption.
Revelations from the NSA leaks shows that the NSA can steal or use the law to demand encryption keys from providers. The NSA (and possibly other organizations) are not only keeping pace with technology, but also planning for the future of data in the cloud.
Business must also be looking and planning for the future. Starting now. Starting with strong cloud encryption.
CNN reports that NSA has a number of methods for accessing data: “the use of supercomputers to crack codes, covert measures to introduce weaknesses into encryption standards and behind-doors collaboration with technology companies and Internet service providers themselves.” According to CNN, most of NSA’s information comes from moles placed in companies, not from technology. This means that the less information the cloud provider is privy to, the less can be passed on to the government.
Edward Snowden, the former computer technician at NSA who leaked documents belonging to the agency, has said that “properly implemented strong crypto systems are one of the few things that you can rely on.” Weak encryption will be easily infiltrated by the NSA, but stronger encryption is still out of its reach.
It has been suggested that regular users shouldn’t be concerned about NSA infiltration since they aren’t engaging in suspicious activity. However, there is reason to be extra-vigilant: NSA’s activities may have weakened overall internet security, making their back door strategies available to technologically advanced criminals as well as to government agencies. The persistent question of “is my data secure in the cloud?” has been answered clearly: data is only as secure as you make it.
And to make data secure in the cloud, you must use strong cloud encryption.
In response to the NSA news, businesses must transcend the way they have been thinking about their data in the cloud and how to secure it. One of the strongest encryption technologies, split-key and homomorphic key encryption, makes it impossible for hackers and internal staff to get access to data they shouldn’t have access to. Split-key encryption creates two unique keys. To unlock the encryption, both keys are required. One of those keys stays in the hands of the customer at all times and it ensures that private data remains private. The master key is known only to the application owner and is encrypted when in use in the cloud, so even if it is stolen, it cannot be used to hack into data. This solution also avoids the usual homomorphic encryption lack of speed. With split-key encryption, applications maintain their regular speed, running quickly and securely.
Encryption works, and when implemented correctly, can secure your cloud data. You can also take additional steps to reduce your exposure from attack.
In conclusion, the NSA is powerful: they watch, they listen, they collect data. In cases of national security, perhaps this is a good method to catch terrorists. In cases of private business data, there is a way to block the NSA from getting to your sensitive information: strong data encryption.
About the Author
Gilad Parann-Nissany is the founder and CEO of Porticor Cloud Security. He is a pioneer in the field of cloud computing who has built SaaS clouds, contributed to SAP products and created a cloud operating system. He has written extensively on the importance of cloud encryption and encryption key management for PCI and HIPAA compliance. Gilad can be found on his blog, Twitter, LinkedIn, and Google+ discussing cloud security.
