Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Tuesday, January 3, 2012

Hackers developing satellite system for 'uncensorable Internet in space

The threat of Internet censorship has spurred some to seek refuge in space. Hackers at the Chaos Computer Club’s Chaos Communication Congress in Berlin this year proposed an initiative called the Hackerspace Global Grid (HGG), which aims to create and freely make available satellite based communication as a fallback or to bypass stuffy legislation.

The bunch of “hobbyist hackers, tinkerers and part time scientists” are predominantly based in Stuttgart, Germany. They say their ultimate goal is to put a hacker on the moon in 23 years, but right now they’re keeping their goals small. They want to keep their freedoms safe from threats like the proposed Stop Online Piracy Act (SOPA), by creating an “uncensorable Internet in space.” The project builds off of an earlier idea by Nick Farr in August for a Hacker Space Program.

The BBC interviewed 26-year-old Armin Bauer from Stuttgart who is working on the communications infrastructure for the project with his team. Bauer is currently working with Constellation, which is a platform that uses Internet-connected computers for aeropsace related research.
The team is developing an idea for a network of low-cost ground stations for when the project gets those low-orbit satellites up there. The stations would be there to pinpoint satellites and facilitate sending data back to earth.

Bauer said, “It’s kind of a reverse GPS. GPS uses satellites to calculate where we are, and this tells us where the satellites are. We would use GPS coordinates but also improve on them by using fixed sites in precisely-known locations.”

Three prototypes are in development, and the team hopes to have them in place in the early half of 2012. Prices for individual ground stations will be 100 euros ($129). The team is exploring other sources for time and position data such as Galileo, GLONASS and ground-based surveying, but they are starting with GPS because it is simple and reasonably priced.

As the project is in the early stages, the hackers stress that they will have to deal with problems as they occur. “We’re trying to concentrate on reasons why this will work, not why it won’t,” they say on the HGG page.

Sunday, January 1, 2012

Berlin Hacking Conference: Hackers could shut down train lines


Hackers who have shut down websites by overwhelming them with web traffic could use the same approach to shut down the computers that control train switching systems, a security expert said at a hacking conference in Berlin.

Stefan Katzenbeisser, professor at Technische Universitat Darmstadt in Germany, said switching systems were at risk of "denial of service" attacks, which could cause long disruptions to rail services.

"Trains could not crash, but service could be disrupted for quite some time," Katzenbeisser told on the sidelines of the convention.

"Denial of service" campaigns are one of the simplest forms of cyber attack: hackers recruit large numbers of computers to overwhelm the targeted system with Internet traffic.

Hackers have used the approach to attack sites of government agencies around the world and sites of businesses.

Train switching systems, which enable trains to be guided from one track to another at a railway junction, have historically been separate from the online world, but communication between trains and switches is handled increasingly using wireless technology.

Katzenbeisser said GSM-R, a mobile technology used for trains, is more secure than the usual GSM, used in phones, against which security experts showed a new attack at the convention.

"Probably we will be safe on that side in coming years. The main problem I see is a process of changing ... keys. This will be a big issue in the future, how to manage these keys safely," Katzenbeisser said.

The software encryption 'keys', which are needed for securing the communication between trains and switching systems, are downloaded to physical media like USB sticks and then sent around for installing - raising the risk of them ending up in the wrong hands.

Tuesday, December 27, 2011

Thousands warned of charity hacking threat

Tens of thousands of people and thousands of companies have been told their bank accounts could be at risk after hackers stole credit card details and personal data held by a US security company.

Anonymous, the loose-knit hacking network known for its repeated, politically motivated attacks on corporations, claimed on Christmas day it would use the stolen details to make $1m worth of donations to charities. Several clients of Stratfor, the Texas-based private security company, confirmed that their accounts had been used for unauthorised transactions to charities such as the Red Cross and Save the Children.

Hackers also published Stratfor’s highly confidential client list, which included banks, such as Barclays and HSBC, defence contractor BAE Systems and large corporations such as Apple ad BT.

Stratfor was on Tuesday trying to play down the incident, saying on its Facebook site that this was not a list of companies it had relationships with, but merely a record of those that had bought the company’s publications.

However, Stratfor said it had hired external security consultants to investigate the incident, as well as an identity theft monitoring company to help the potential victims. It advised customers to monitor their accounts carefully and to contact their banks and the US Federal Trade Commission if they saw any unauthorised activity.

Stratfor’s servers and email have been suspended.

It issued a warning on Monday that individuals who had spoken out publicly against the hacking attack might be targeted and have their personal details published on websites. The company urged people to either refrain from commenting on Facebook, or to take extra precautions if they did.

Saturday, July 30, 2011

New anti-hacking tool from game theory

How can any organization detect the onset of an attack on its computer network, giving it time to respond quickly and block any intrusion or compromise of its data? The answer could lie in game theory.

Modern firewalls and other technology are already in place, but these have not prevented major attacks on prominent networks in recent months. Now, information technologist Heechang Shin of Iona College in New Rochelle, New York, has used game theory to develop a defense mechanism for networks that is more effective than previous approaches.

Shin explains that each incident might not only severely disrupt services affecting thousands of people, but for a commercial operation it can take as much as one percent of annual sales, per incident, amounting to tens of millions of dollars, according to an Iona statement.

Shin has now developed an effective anti—hacking tool based on a game theoretic model, called defensive forecasting, which can detect network intrusions in real time, the International Journal of Business Continuity and Risk Management reports.

The tool, by playing a “game” of reality versus forecast, wins when reality matches its forecast and it sends out an alert to block the intrusion.

Importantly, the tool works on real—time data flowing in and out of the network rather than analyzing logs, an approach that can only detect network intrusions after they have taken place.

The game theoretic model continuously trains the tool so that it can recognize the patterns of typical network attacks: denial of service attacks, unauthorized access from remote machines in which login passwords are being guessed or brute—force tested, attacks by insiders with “superuser” etc.