Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, March 4, 2008

A fire, and only minutes to make critical decisions

A fire, and only minutes to make critical decisions

BOSTON (MarketWatch) -- At 6:45 a.m. on Feb. 22 my daughter burst into my office yelling something about a fire in the chimney. There was no immediate danger, but smoke was building, there were flames shooting out the chimney cap and it was clear everyone needed to be out.

The fire department had been called, a few precautions were taken to minimize the fire and whatever fuel it had, and then my wife and I walked out of the house to meet the first officers to the scene.

And as soon as I stepped out of the house, I realized I had made a mistake. The "family disaster kit" had been left downstairs, back in my office, and there was no way the officers were going to let me back in to get it, regardless of the danger of the situation.

In the end, it turned out to be little more than a fire drill; the fire was extinguished within a half hour, there was minimal damage and, most importantly, everyone was safe.

In the scheme of disaster prevention, however, the drill was a mild failure, because in the five minutes I had to safeguard my family's life, I left behind the finances. Had this been a real disaster, it would have tested the veracity of the manufacturer's claims that I had purchased a fireproof box. (Several safety experts I talked with said that leaving behind the file in a fire is the right thing to do, that it only travels in disasters -- like hurricanes -- where evacuation comes with some advance warning.)

Moreover, when things calmed down, I checked the box and found some key areas where it would have let us down.

"Disasters can strike quickly and without warning," says Darlene Sparks-Washington, director for preparedness for the American Red Cross. "Taking action to prepare in advance can reduce the physical, emotional and financial impact of a disaster, and help you respond faster in a disaster situation where every second counts."

The idea behind any disaster file is to have the important, this-will-rebuild-your-life data in one place.

It's not the safe-keeping spot for one-of-a-kind documents, like birth certificates and marriage records, which belong in a safe-deposit box, but a certified copy of those papers in the disaster file is a good idea in case you need to produce them to get government assistance.

In a hurricane or earthquake, the same problem that destroys your home could endanger the bank vault of your safe-deposit box. Copies of the documents can also be left with a trusted friend or relative who lives in another city -- to guard against natural disasters -- although experts are split on this idea, noting that the documents in the file would be an identity thief's dream and inappropriate to give anyone.

What to include

The file -- kept in a waterproof/fireproof box -- should include your financial records and account numbers, along with contact details for those accounts. When I made my file a few years back, in the wake of all of the hurricanes that had been in the news, I simplified the process by following an expert tip to copy a month's worth of bills, plus bank and brokerage statements, thereby securing account numbers and customer-service phone lines, precisely what is necessary in case of emergency.

In a real catastrophe, it might seem frivolous to have credit-card numbers handy, but past disasters -- like those big hurricanes -- have been rife with tales of consumers who had to battle creditors over late fees and other charges. By calling immediately after the bad event, a consumer may be able to get some measure of leniency from lenders. Moreover, ignoring those responsibilities -- even during a crisis -- increases the potential for hassle.

Next, experts suggest adding in mortgage and loan information, employee-benefit statements and, perhaps most importantly, copies of insurance policies.

There are a number of software packages that include organizers that will help you create your inventory of key financial information. But software programs are only as good as the person keeping them, and copying information on your computer won't be much help if your computer is destroyed.

If, as a result, you prefer to stay low-tech, check out the "Your Important Records" section of "Your Financial Organizer," a booklet produced by TIAA-CREF. You can find the booklet by searching online at TIAA-CREF.org or you can go directly to the records page at https://www3.tiaa-cref.org/calcs/financial_organizer/section_3a.html.

Once your accounts are secure, include a copy of a "household inventory." Your inventory should contain as much detail as possible about purchase dates and prices, current value of an item and more, but it does not have to be a written record. Take a video camera and walk from one end of your home to the other, making a travelogue of everything you see. Or print pictures with descriptions on the back. The Insurance Information Institute offers free software for helping to prepare a home inventory; you can download it at www.knowyourstuff.org.

Don't forget cash

Jocelyn Silsby, manager of preparedness implementation for the Red Cross, said that the last thing to go into the disaster box is "enough cash to last you for three days, just because there are some disasters that could make it that the banks are closed, or the ATMs are not available, or you don't have your cards and can't get replacements for a few days."

A few experts suggest tossing the most recent tax return in the file, but there's a good chance the paperwork is on file with your tax preparer. Moreover, in the middle of a crisis, future dealings with the Internal Revenue Service are about the last thing a consumer needs to worry about.

The one plus to putting tax records into the file is that it creates a logical time to update the paperwork. Upon returning to my office after the chimney fire, I found several items out of date.

"Your file is only good if it's current," said Silsby. "The question becomes how many things have changed that you will forget about. ... I like the idea that when you change your clocks, you also change the batteries on your smoke detectors, and check your disaster file."

In other words, check in on your file this weekend, before or after you move the clocks. As the recent experience in my home proved, you never know when it's going to be your turn to have the disaster drill become your reality.

Monday, March 3, 2008

The Kremlin's Really Bad Month: March 1983

March 03, 2008

The Kremlin's Really Bad Month: March 1983

By Paul Kengor
"[T]he powers that be in Washington are threatening the course of world history, neither more nor less."
-Grigori Dadyants, Sotsialisticheskaya Industriya, March 1983

"It is an Evil Empire. It's time to close it down."
-Ronald Reagan, White House, March 1983

It was 25 years ago this month, March 1983, that the Soviet Union went into hysterics, both realizing and arguably beginning the terminal phase in its deadly life cycle.

The Kremlin had been deeply troubled ever since the inauguration of President Ronald Reagan in January 1981, a total turnabout from its confident surge in the latter 1970s, when it looked like Moscow was winning the Cold War. The Soviet leadership was taken aback by Reagan's bravado in his very first press conference, where the new president calmly explained to a stunned Washington press corps that the Soviet leadership had "openly and publicly declared that the only morality they recognize is what will further their cause, meaning they reserve unto themselves the right to commit any crime, to lie, to cheat." Reagan had left no doubt that Jimmy Carter was out of the White House.

Moscow's fears only heightened throughout 1981 and 1982, struck by the president's public projections that communism and the Soviet Union itself were doomed, statements he made repeatedly from the campus of Notre Dame University in May 1981 to Westminster in London in June 1982, to name only two. The Soviets privately fumed over what they suspected Reagan was pursuing in Poland, in Afghanistan, in Nicaragua, and via relationships with the likes of Margaret Thatcher and Pope John Paul II.

Consequently, the Kremlin already sensed it was at the arc of a crisis going into March 1983. It could not have imagined what was about to happen next, as Reagan that month would issue a devastating rhetorical blow, followed by the disclosure of a major Cold War directive, and then finishing with an announcement of a research program that would terrify the Soviet leadership, ultimately becoming Mikhail Gorbachev's obsession.

The first of these came on March 8, 1983, when Ronald Reagan proclaimed that there was "sin and evil in the world," and that he was duty-bound, "by Scripture and the Lord Jesus," to oppose it with all his might. Among those sins and evils was the "focus of evil in the modern world," said Reagan-the Soviet Union, which was nothing short of an "Evil Empire."

Liberals, of course, went nuts, as did the Soviets -- but not the Soviets' captives, who celebrated from inside the gulag, ecstatic that finally the West had a leader willing to speak the truth. Reagan was speaking to cowards in the West in particular, the haughty, the prideful, when he exhorted:

"I urge you to beware the ... temptation of blithely declaring yourselves above it all and label both sides equally at fault, to ignore the facts of history and the aggressive impulses of an evil empire, to simply call the arms race a giant misunderstanding and thereby remove yourself from the struggle between right and wrong and good and evil."

The Moderates were Alarmed

The moderates inside the Reagan White House were equally alarmed. Nancy Reagan and her close friend Mike Deaver were certain that if Ronnie would simply stop making these Neanderthal comments, the Nobel Committee would come to the door with the Peace Prize for the conservative president. About a week after the speech, Nancy invited to dinner another of her moderate friends, Stu Spencer. The two of them pressed the president, expressing reservations over his abrasive speech. Reagan waved them off: "It is an Evil Empire," he instructed them. "It's time to close it down."

The Evil Empire speech could not have been more high-profile. It was done openly by Reagan for all to hear. The intended audience was the world, and Reagan wanted everyone, everywhere, to hear it -- as they did indeed.

That was not the intention with what happened next that March 1983. A week after the Evil Empire speech came something on March 16, 1983 that sent the Soviets into fits. On that date, reporter Robert Toth of the Los Angeles Times broke the scoop of a lifetime, compliments of one of the serial leakers in the Reagan administration:.

Toth revealed that two months earlier, in mid-January, President Reagan had secretly signed NSDD-75, a highly classified document, and one of the boldest strokes of the entire Cold War. Written principally by Harvard professor Richard Pipes, with the economic elements developed by Roger Robinson -- both operating within Bill Clark's National Security Council -- NSDD-75 dedicated the Reagan administration to nothing short of reversing the Soviet communist empire and even the USSR itself, advocating the end of the Marxist directorship and the launching of political pluralism in the USSR. As Pipes put it, NSDD-75 was "a clear break from the past. [NSDD-75] said our goal was no longer to coexist with the Soviet Union but to change the Soviet system. At its root was the belief that we had it in our power to alter the Soviet system."

This would be achieved by various external pressures, including covert economic warfare. Among the practitioners of this campaign, beyond Reagan's NSC, were Bill Casey and his team at the CIA -- men like Casey's special assistant, Herb Meyer.

Neither the Soviets nor the world in general were supposed to know about NSDD-75. They learned about it from the Toth article. This was discovered firsthand by Marc Zimmerman, an unknown legislative aide to then-Rep. Olympia Snowe (R-Maine), who found himself being pumped for information by a KGB agent in March 1983 -- a case that soon exploded onto every front page in America. The agent was armed with a copy of the Times article.

Zimmerman found that the Soviet agent (who, of course, did not identify himself as an agent) was "obsessed" with NSDD-75, and understandably so. "He told me, ‘Hey, you know, your government is trying to destabilize the Soviet Union,'" recalls Zimmerman today. "As evidence, he pulled the article from his coat pocket. He was really shaken up by the article. The KGB had their agents all over this."

Just a week earlier, TASS, the official Soviet news agency, had issued a press release warning that Reagan's Evil Empire speech had symbolized the reality that it was now "official state policy" for the Reagan team to make its "crusade against communism ... the fatal denouement to which Mr. Reagan is nudging the world." Now, with the disclosure about NSDD-75, articles began running in the Soviet press with titles like "New Directive ... Threatens History."

A piece by Grigori Dadyants in Sotsialisticheskaya Industriya stated, "Directive 75 speaks of changing the Soviet Union's domestic policy. In other words, the powers that be in Washington are threatening the course of world history, neither more nor less." The Moscow Domestic Service released two statements on the directive, dubbing the "plan" a "subversive" attempt "to try to influence the internal situation" within the USSR. "[T]he task," said Moscow, was "to exhaust the Soviet economy ... to undermine the socioeconomic system and international position of the Soviet state." This was quite accurate; finally, there was some truth in the Soviet press.

Even then, the Soviets had seen nothing yet. Their really bad month was about to get worse, as Ronald Reagan was holding a secret that he was about to share with the world on March 23, 1983: "My fellow Americans, tonight we're launching an effort which holds the promise of changing the course of human history," declared the president that evening in a nationally televised address. He announced his Strategic Defense Initiative, a vision for a space-based missile-defense system.

Coming only two weeks after the Evil Empire speech, and one week after the report on NSDD-75-not to mention other audacious military initiatives underway, from the deployment of the MX Missile to the Pershing IIs-Reagan's remarks left Moscow shell-shocked. They also stunned his own staff. Four days before the speech, only Bill Clark, Bud McFarlane, John Poindexter, and science advisor George Keyworth knew what was to come.

The Problem with Leaks

That secrecy was necessary: Reagan had a terrible problem with leaks, which had been particularly acute in 1982 and 1983, to the point where he had Bill Clark investigate the matter and even considered employing a polygraph. Clark ensured that only those who needed to know about SDI would know ahead of time. He and Reagan did not want SDI to be sabotaged by an in-house opponent as a lame-brain idea prior to its announcement.

As an example of the internal opposition, Keyworth recalled a Monday meeting in the Oval Office with Secretary of State George Shultz before the Wednesday evening speech. "Shultz called me a lunatic in front of the president," remembered Keyworth, "and said the implication of this new initiative was that it would destroy the NATO alliance. It would not work ... and was the idea of a blooming madman." Shultz did not realize at that point that he had just called Reagan a madman in front of his top advisers -- since the idea was completely Reagan's.

The Soviets could, however, count on getting some help from their useful idiots in the American left. It took Senator Ted Kennedy (D-MA) less than 24 hours to lampoon Reagan's SDI speech as "misleading Red-scare tactics and reckless Star Wars schemes." The New York Times quickly followed suit, noting in a story a week later that the SDI proposal was "Mr. Reagan's answer to the film ‘Star Wars.'" White House reporters like Helen Thomas immediately embraced the critics' new name for Reagan's initiative, refusing Reagan's direct appeal to call SDI by its actual name. Here's one exchange at a press conference:

Thomas: Mr. President, if you are flexible, are you willing to trade off research on "Star Wars" ... or are you against any negotiations on "Star Wars"?

Reagan: Well, let me say, what has been called "Star Wars"-and, Helen, I wish whoever coined that expression would take it back again-

Thomas: Well, Strategic Defense-

Reagan: -because it gives a false impression of what it is we're talking about.

Despite Reagan's plea, Thomas continued: "May I ask you, then, if ‘Star Wars'-even if you don't like the term, it's quite popular...."

The term was popular because reporters used it. Reagan's request was reasonable: the program's name was the Strategic Defense Initiative. A supposed unbiased reporter ought to call it by its proper name, not the term of derision used by partisan detractors.

So, before SDI could work its magic in panicking the Soviets and bringing them to the negotiating table, it first had to survive its domestic opponents right here in America. Still, try as they might, the left's attempt to ridicule SDI failed miserably, as the Soviets took it eminently seriously. There was literally no other issue, in all the subsequent US-Soviet summits, that absorbed Mikhail Gorbachev's attention as much as SDI. The transcripts of the summits show this unmistakably, and Gorbachev and his aides all attested to the fact.

SDI was "The Silver Bullet"

In the end, SDI was one of the single most influential factors in bringing the Soviets to the negotiating table and ending the Cold War. It was a silver bullet. According to CIA official Herb Meyer,

"The intelligence coming in the morning of March 24 -- literally hours after the president's SDI speech -- was different from anything we'd seen before. The Soviet Union's top military officials had understood instantly that President Reagan had found a way to win the Cold War. He had described SDI as ‘a shield over the United States.' But they understood that it was really a lid over the Soviet Union. It meant their missiles would be worthless."

Meyer notes that the Soviets understood that even if SDI could not shoot down all of their missiles, it introduced a devastating uncertainty that sent their nuclear strategy into a tailspin -- and they knew that America had the money to do the research.

Genrikh Trofimenko, head of the Institute for U.S.A. and Canada Studies of the Russian Academy of Sciences, later said that "99% of all Russians believe that Reagan won the Cold War because of his insistence on SDI."

SDI was a deep thrust to the underbelly of the Soviet system that March 1983, and the crowning touch on a month of repeated assaults on the Kremlin.

Needless to say, President Reagan had much more in store for the Soviets in the months and years ahead, from Reykjavik to the Brandenburg Gate. By the end of March 1983, however, the Soviets knew the game was up. Alas, they had an adversary in Washington who knew how weak they truly were, and who wasn't afraid to say so-and who was confident he could finish them off.

At that point in the timeline of the Cold War, the Soviet communist grip had only half a dozen years left. In March 1983, 25 years ago this month, that was something that history could not know; it could only know that the Cold War was really heating up. The Soviets felt the heat; for them, it was a really bad month, and arguably the start of their end.

Paul Kengor is author of The Crusader: Ronald Reagan and the Fall of Communism (HarperPerennial, 2007) and professor of political science at Grove City College. His latest book is The Judge: William P. Clark, Ronald Reagan's Top Hand (Ignatius Press, 2007).

Friday, December 21, 2007

Social Engineering, the USB Way

Social Engineering, the USB Way

Those thumb drives can turn external threats into internal ones in two easy steps

JUNE 7, 2006 | We recently got hired by a credit union to assess the security of its network. The client asked that we really push hard on the social engineering button. In the past, they'd had problems with employees sharing passwords and giving up information easily. Leveraging our effort in the report was a way to drive the message home to the employees.

The client also indicated that USB drives were a concern, since they were an easy way for employees to steal information, as well as bring in potential vulnerabilities such as viruses and Trojans. Several other clients have raised the same concern, yet few have done much to protect themselves from a rogue USB drive plugging into their network. I wanted to see if we could tempt someone into plugging one into their employer's network.

In the past we had used a variety of social engineering tactics to compromise a network. Typically we would hang out with the smokers, sweet-talk a receptionist, or commandeer a meeting room and jack into the network. This time I knew we had to do something different. We heard that employees were talking within the credit union and were telling each other that somebody was going to test the security of the network, including the people element.

We figured we would try something different by baiting the same employees that were on high alert. We gathered all the worthless vendor giveaway thumb drives collected over the years and imprinted them with our own special piece of software. I had one of my guys write a Trojan that, when run, would collect passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us.

The next hurdle we had was getting the USB drives in the hands of the credit union’s internal users. I made my way to the credit union at about 6 a.m. to make sure no employees saw us. I then proceeded to scatter the drives in the parking lot, smoking areas, and other areas employees frequented.

Once I seeded the USB drives, I decided to grab some coffee and watch the employees show up for work. Surveillance of the facility was worth the time involved. It was really amusing to watch the reaction of the employees who found a USB drive. You know they plugged them into their computers the minute they got to their desks.

I immediately called my guy that wrote the Trojan and asked if anything was received at his end. Slowly but surely info was being mailed back to him. I would have loved to be on the inside of the building watching as people started plugging the USB drives in, scouring through the planted image files, then unknowingly running our piece of software.

After about three days, we figured we had collected enough data. When I started to review our findings, I was amazed at the results. Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management.

Of all the social engineering efforts we have performed over the years, I always had to worry about being caught, getting detained by the police, or not getting anything of value. The USB route is really the way to go. With the exception of possibly getting caught when seeding the facility, my chances of having a problem are reduced significantly.

You’ve probably seen the experiments where users can be conned into giving up their passwords for a chocolate bar or a $1 bill. But this little giveaway took those a step further, working off humans' innate curiosity. Emailed virus writers exploit this same vulnerability, as do phishers and their clever faux Websites. Our credit union client wasn’t unique or special. All the technology and filtering and scanning in the world won’t address human nature. But it remains the single biggest open door to any company’s secrets.

Disagree? Sprinkle your receptionist's candy dish with USB drives and see for yourself how long it takes for human nature to manifest itself.

— Steve Stasiukonis is VP and founder of Secure Network Technologies Inc. Special to Dark Reading