Security

Was Russia Behind Stuxnet? 281

An anonymous reader writes "Despite the U.S. and Israel being widely assumed to be responsible for Stuxnet, Russia is the more likely culprit, says U.S. Air Force cyber analyst. The nuclear gangsterism of the past 20 years gives it plenty of motive. Quoting: 'So what better way to maintain Russian interests, and innocence, than to plant a worm with digital U.S.-Israeli fingerprints? After all, Russian scientists and engineers are familiar with the cascading centrifuges whose numbers and configuration – and Siemen’s SCADA PLC controller schematics – they have full access to by virtue of designing the plants. ... the observers of the virus could alert the Iranians before full nuclear catastrophe struck. The Belarusian computer security experts who 'discovered' the code seemingly played that role well. They didn't seem too preoccupied with reverse engineering the malicious code to see what it was designed to do.'"
Security

SCADA Hacker: Water District Used 3-Character Password 213

Trailrunner7 writes "In an e-mail interview with Threatpost, a hacker who compromised software used to manage water infrastructure for South Houston, Texas, said the district had HMI (human machine interface) software used to manage water and sewage infrastructure accessible to the Internet and used a password that was just three characters long. The hacker, using the handle 'pr0f' took credit for a remote compromise of supervisory control and data acquisition (SCADA) systems. Communicating from an e-mail address tied to a Romanian domain, the hacker told Threatpost that he discovered the vulnerable system using a scanner that looks for the online fingerprints of SCADA systems. 'This was barely a hack. A child who knows how the HMI that comes with Simatic works could have accomplished this,' he wrote in an e-mail."
Cellphones

Making Sensitive Data Location Aware 69

An anonymous reader writes "In a breakthrough that could aid spies, keepers of medical records, and parents who want to prevent their kids from 'sexting,' a team of Virginia Tech researchers has created software to remotely put smart phones under lockdown. The phones are given permission to access sensitive data while in a particular room, but when the devices leave the room, the data is completely wiped. A general, for example, could access secret intelligence while visiting a secure government facility without fear that his or her smart phone or tablet computer might later be lost or stolen, the team's lead researcher said. 'This system provides something that has never been available before. It puts physical boundaries around information in cyberspace.'" Unless the phone or other device can also take screenshots, or doesn't have that software installed.
Bug

SCADA Problems Too Big To Call 'Bugs,' Says DHS 92

chicksdaddy writes "With the one year anniversary of Stuxnet upon us, a senior cybersecurity official at the Department of Homeland Security says the agency is reevaluating whether it makes sense to warn the public about all of the security failings of industrial control system (ICS) and SCADA software used to control the U.S.'s critical infrastructure. DHS says it is rethinking the conditions under which it will use security advisories from ICS-CERT to warn the public about security issues in ICS products. The changes could recast certain kinds of vulnerabilities as 'design issues' rather than a security holes. No surprise: independent ICS experts like Ralph Langner worry that DHS is ducking responsibility for forcing changes that will secure the software used to run the nation's critical infrastructure. 'This radically cuts the amount of vulnerabilities in the ICS space by roughly 90%, since the vast majority of security "issues" we have are not bugs, but design flaws,' Langner writes on his blog. 'So today everybody has gotten much more secure because so many vulnerabilities just disappeared.'"
Security

Italian Hacker Publishes 0day SCADA Hacks 106

mask.of.sanity writes "An Italian security researcher, Luigi Auriemma, has disclosed a laundry list of unpatched vulnerabilities and detailed proof-of-concept exploits that allow hackers to completely compromise major industrial control systems. The attacks work against six SCADA systems, including one manufactured by U.S. giant Rockwell Automation. The researcher published step-by-step exploits that allowed attackers to execute full remote compromises and denial of service attacks. Auriemma appeared unrepentant for the disclosures in a post on his website."
Security

Hackers Could Open Convicts' Cells In Prisons 203

Hugh Pickens writes "Some of the same vulnerabilities that the Stuxnet superworm used to sabotage centrifuges at a nuclear plant in Iran exist in the country's top high-security prisons where programmable logic controllers (PLCs) control locks on cells and other facility doors. Researchers have already written three exploits for PLC vulnerabilities they found. 'Most people don't know how a prison or jail is designed; that's why no one has ever paid attention to it,' says John Strauchs, who plans to discuss the issue and demonstrate an exploit against the systems at the DefCon hacker conference next week. 'How many people know they're built with the same kind of PLC used in centrifuges?' A hacker would need to get his malware onto the control computer either by getting a corrupt insider to install it via an infected USB stick or send it via a phishing attack aimed at a prison staffer, since some control systems are also connected to the internet, Strauchs claims. 'Bear in mind, a prison security electronic system has many parts beyond door control such as intercoms, lighting control, video surveillance, water and shower control, and so forth,' adds Strauchs. 'Once we take control of the PLC we can do anything (PDF). Not just open and close doors. We can absolutely destroy the system. We could blow out all the electronics.'"
Networking

Apple Adopts Bluetooth 4.0. Could It Reject NFC? 250

siliconbits writes "Two months after Apple joined the Bluetooth special interest group board, the company launched the world's first truly mainstream Bluetooth 4.0 devices, namely the new Macbook Air & Mac Mini 2011 editions. The products came only one year after the official core specifications of Bluetooth 4.0 were adopted and it looks likely that Apple fast-tracked Bluetooth 4.0's adoption so that the forthcoming iPhone 5 can use this technology with at least one Apple product. This could mean that the manufacturer is considering giving up on NFC altogether, a technology embraced by all of its rivals."
Open Source

Is the Rise of Wearable Electronics Finally Here? 98

ptorrone writes "MAKE Magazine takes a look at the last ten years or so of 'wearable electronics.' From wireless watches to LCD goggles, MAKE predicts we are collectively entering a new era of wearables. As the price for enabling components drops, always-on connectivity in our pockets and purses increases, and access to low-cost manufacturing resources and know-how rises, we'll see innovation continue to push into these most personal forms of computing."
Cellphones

Sound-Based System Promises Chipless Phone Payment 186

CWmike writes "While near-field communication gradually emerges to turn mobile phones into payment devices, startup Naratte is introducing a system it claims can do roughly the same thing without adding a chip to the handset. On Monday, Naratte introduced Zoosh, a technology that lets phones exchange transaction information via inaudible sound waves. As with NFC, the phone user would just put the phone near to a point-of-sale terminal to redeem a coupon or make a purchase. NFC provides short-range radio communication between phones and point-of-sale devices so users can just tap or point their phones at the device to make a purchase. NFC uses specialized chips, which are already built into a few phones such as the Google Nexus S sold by Sprint Nextel, and are expected in more handsets in the future. Zoosh involves software that utilizes the speaker and microphone in a handset to send and receive audio signals with another device, similar to the way early modems exchange data by sending tones through the handsets of desk phones cradled in coupler devices. The company has posted a video that shows how it works. Between this and barcodes (which Starbucks says is working well already, thank you very much), is NFC already irrelevant?"
China

US Warns of Problems In Chinese SCADA Software 95

alphadogg writes "Two vulnerabilities found in industrial control system software made in China but used worldwide could be remotely exploited by attackers, according to a warning issued on Thursday (PDF) by the US Industrial Control Systems Cyber Emergency Response Team. The vulnerabilities were found in two products from Sunway ForceControl Technology, a Beijing-based company that develops SCADA software for a wide variety of industries, including defense, petrochemical, energy, water and manufacturing. Sunway's products are mostly used in China but also in Europe, the Americas, Asia and Africa, according to the agency's advisory. SCADA software has come under increasing attention from security researchers, as the software has often not undergone rigorous security audits despite its use to manage critical infrastructure or manufacturing processes. SCADA systems are increasingly connected to the Internet, which has opened up the possibility of hackers remotely breaking into the systems. Last year, researchers discovered a highly sophisticated worm called Stuxnet that was later found to target Siemens' WinCC industrial control software."
Security

Siemens Fixes SCADA Flaws 36

itwbennett writes "Siemens has fixed a pair of bugs in its S7-1200 controller, which is used to control machines on factory floors, power stations and chemical plants. The bugs were discovered earlier this year by NSS researcher Dillon Beresford, who planned to disclose the bugs at Black Hat in August. The US Department of Homeland Security said that Siemens' patches fix 'a portion' of the problems Beresford has discovered and that it 'continues to work with Siemens and Mr. Beresford on the other reported problems.'"
Google

Google Wallet: the End of Anonymous Shopping 253

jfruhlinger writes "Google today announced Google Wallet, an NFC-based payment system that will allow people to pay for purchases just by waving their phone across a reader. It's the beginning of a future where commercial transactions are 'frictionless' and convenient — but it's a future where every transaction can be tracked and data-mined, as Dan Tynan points out. Stores can user information about your Doritos purchases to rearrange their wares; Google could push coupons via its new Google Offers service; your health insurance company might be interested in your sodium intake."
Security

New Siemens SCADA Vulnerabilities Kept Secret, Says Schneier 119

From the article: SCADA systems -- computer systems that control industrial processes -- are one of the ways a computer hack can directly affect the real world. Here, the fears multiply. It's not bad guys deleting your files, or getting your personal information and taking out credit cards in your name; it's bad guys spewing chemicals into the atmosphere and dumping raw sewage into waterways. It's Stuxnet: centrifuges spinning out of control and destroying themselves. Never mind how realistic the threat is, it's scarier." What worries Bruce Schneier most is that industry leader Siemens is keeping its SCADA vulnerabilities secret, at least in part due to pressure from the Department of Homeland Security .
Security

US-CERT Warns of Serious Hole In ActiveX Control From Iconics 87

Trailrunner7 writes "The US's Computer Emergency Response Team (CERT) issued a warning (PDF) to critical infrastructure firms on Wednesday about a serious security hole in products from Massachusetts firm Iconics that could leave critical systems vulnerable to remote attacks. US companies in the electricity, oil and gas, manufacturing and water treatment sectors have been warned about a flaw in an ActiveX control used in two products by Iconics. The software, Genesis32 and BizViz, are Human-Machine Interface (HMI) products that provide a graphical user interface to various types of industrial control systems. The software can control industrial systems used for a variety of purposes including manufacturing, building automation, oil and gas, water and waste water treatment, among other applications."
Hardware

The Awesome Button 80

An anonymous reader writes "An awesome hardware hack which demonstrates how easily USB-based human interface devices (eg, Keyboards and Mice) can be created using the Arduino software environment." A very nice little project based on the Teensy USB Development Board. Reminds me of the breadboard electronics projects my Dad used to work on with me many years ago. "Great fun for young and old," you might say.
Cellphones

Salt Lake City To Launch Mobile Payment System 60

jitendraharlalka writes "According to The Register: 'Operator consortium Isis has selected Salt Lake City as its flagship deployment to show the rest of the USA what NFC can do for them. The plan will see Salt Lake City's public transport system accepting pay-by-wave from a mobile phone by the middle of next year. Retailers have also been encouraged to adopt Near Field Communications technology at the point of sale, as Salt Lake City strives to become The Place You Can Leave Your Wallet At Home. The Utah Transit Authority already uses proximity payment cards, deployed in 2009, so adding NFC functionality to public transport is a matter of software not hardware.'"
Cellphones

No Contactless Payment System In Next iPhone 239

RedEaredSlider writes "Citing fears over a lack of an industry standard, Apple has ditched plans to include near field communication technology in its next iPhone, The Independent reports. The technology, which allows users to make payments simply by waving their devices over special readers, is widely believed to be the next major step in both cell phone and payment technologies. Apple's decision to avoid it is a significant blow to its adoption."
Australia

Australia Creates Cyberwarfare Unit 60

An anonymous reader writes "Australia's Federal Government computer emergency response team and other spy agencies are teaming up to create a cyberspooks unit to counter threats from other countries, the nation's chief lawmaker said last night. In a speech referencing Stuxnet and GhostNet, Attorney-General Robert McClelland said the unit would protect sensitive Australian Government and business information from espionage by the nation's foes. Recently new powers were handed to spymasters to deal with the enhanced security threat that the Greens party said were 'excessive.'"
Google

Google Ready To Rule NFC-Based Mobile Payments? 87

itwbennett writes "Google may seem like an odd pioneer for mobile payments, says blogger Ryan Faas, but according to recent reports, the company is developing its own NFC payment solution. Here's why Faas thinks Google has a leg up in this emerging market: 'Google does have a lot of clout when it comes to NFC because the recent launch of the Nexus S and Gingerbread (the most recent Android release) offer the first truly widespread smartphone/NFC integration. That could give Google significant bargaining power. It also makes a certain sense to expect Google to try to lead in this area when you consider that the company is hyping mobile search and recommendation features.'"
Security

Evaluating Or Testing Utility SCADA Security? 227

EncryptedBit writes "I am a local elected official involved in bringing new water and waste water treatment plants online in a small town. The new plants will incorporate SCADA, which can be used to change operational aspects at the plants, up to forcing a shutdown or changing operational parameters. Can any Slashdotters recommend ways to make sure it is secure? Any testing recommendations? The operational engineers are oblivious to security and SCADA is a new factor, so this concerns me. Any pointers would be appreciated."

Slashdot Top Deals