Heartbleed Means HealthCare.gov Users Must Reset Passwords
http://www.nextgov.com/cybersecurity/2014/04/heartbleed-means-healthcaregov-users-must-reset-passwords/82852/
By Aliya Sternstein
Nextgov.com
April 19, 2014
Federal officials are telling Obamacare website account holders to reset
their passwords, following revelations of a bug that could allow hackers
to steal data.
Officials earlier in the month said the government’s main public sites,
including HealthCare.gov, were safe from the risks surrounding Heartbleed
— faulty code recently found in a widely-used encryption tool.
But, this weekend, the online marketplace’s homepage directs users to
change their login information.
“While there’s no indication that any personal information has ever been
at risk, we have taken steps to address Heartbleed issues and reset
consumers’ passwords out of an abundance of caution,” HealthCare.gov
states.
[…]
INFO: Google scans user’s emails
http://bit.ly/1reFUNj
Google updates terms of service to reflect its scanning of users’ emails
Google has updated its terms of service to reflect that it analyzes user
content including emails to provide users tailored advertising, customized
search results and other features.
The Internet giant’s scanning of users’ email has been controversial with
privacy groups describing it as an intrusion into user privacy.
[…]
Mission-critical satellite communications wide open to malicious hacking
By Dan Goodin
Ars Technica
April 17, 2014
Mission-critical satellite communications relied on by Western militaries
and international aeronautics and maritime systems are susceptible to
interception, tampering, or blocking by attackers who exploit easy-to-find
backdoors, software bugs, and similar high-risk vulnerabilities, a
researcher warned Thursday.
Ground-, sea-, and air-based satellite terminals from a broad spectrum of
manufacturers—including Iridium, Cobham, Hughes, Harris, and Thuraya—can
be hijacked by adversaries who send them booby-trapped SMS text messages
and use other techniques, according to a 25-page white paper published by
penetration testing firm IOActive. Once a malicious hacker has remotely
gained control of the devices, which are used to communicate with
satellites orbiting in space, the adversary can completely disrupt
mission-critical satellite communications (SATCOM). Other malicious
actions include reporting false emergencies or misleading geographic
locations of ships, planes, or ground crews; suppressing reports of actual
emergencies; or obtaining the coordinates of devices and other potentially
confidential information.
“If one of these affected devices can be compromised, the entire SATCOM
infrastructure could be at risk,” Ruben Santamarta, IOActive’s principal
security consultant, wrote. “Ships, aircraft, military personnel,
emergency services, media services, and industrial facilities (oil rigs,
gas pipelines, water treatment plants, wind turbines, substations, etc.)
could all be impacted by these vulnerabilities.”
Santamarta said that every single one of the terminals he audited
contained one or more weaknesses that hackers could exploit to gain remote
access. When he completed his review in December, he worked with the CERT
Coordination Center to alert each manufacturer to the security holes he
discovered and suggested improvements to close them. To date, Santamarta
said, the only company to respond was Iridium. To his knowledge, the
remainder have not yet addressed the weaknesses. He called on the
manufacturers to immediately remove all publicly accessible copies of
device firmware from their websites to prevent malicious hackers from
reverse engineering the code and uncovering the same vulnerabilities he
did.
[…]
Tag: technology
Skills for the New Economy: Preparing Students for College and Careers
Skills for the New Economy: Preparing Students for College and Careers
http://www2.ed.gov/about/overview/budget/budget15/crosscuttingissues/skillsforneweconomy.pdf
RETHINKING HIGH SCHOOL
On April 7, during his visit to Bladensburg High School in Prince George’s County, Maryland, President Obama announced 24 Youth CareerConnect grants, providing $107 million to local partnerships of school districts, institutions of higher education, workforce investment boards, and employers as they redesign the teaching and learning experience for youth to more fully prepare them with the knowledge, skills, and industry-relevant education needed to get on the pathway to a successful career, including postsecondary education or registered apprenticeship. “We challenged America’s high schools to…say what they can do to make sure their students learn the skills that businesses are looking for in high-demand fields,” the President said. “And we asked high schools to develop partnerships with colleges and employers and create classes that focus on real life applications for the fields of the future — fields like science and technology and engineering and math…. The winners across the board are doing the kinds of things that will allow other schools to start duplicating what they’re doing…. And that’s what we want for all the young people here. We want an education that engages you…that equips you with the rigorous and relevant skills for college and for a career” (blog post, with remarks and video).
The Youth CareerConnect program was established this year by the Labor Department, in collaboration with the Education Department, using one-time revenues from the H-1B visa program. Grants range from $2.2 million to $7 million. The program wholly complements additional proposals in the President’s Fiscal Year 2015 budget to ensure high school students graduate ready for college and career success and to help the U.S., once again, lead the world in college attainment.
Bladensburg High School was part of a three-school team from the county that won a $7 million grant. It offers several career academies with high school curricula aligned with college-level entrance requirements for Maryland’s state university system. Through a collaborative effort with local partners, it will expand the capacity of its Health and Biosciences Academy to better prepare more students for one of the region’s highest growth industries. Students who concentrate in health professions will be able to earn industry-recognized certifications in the fields of nursing and pharmacy. Biomedical students will be able to earn college credit from the University of Maryland at Baltimore County and the Rochester Institute of Technology. All students will have access to individualized college and career counseling designed to improve preparation for college-level coursework and the attainment of industry-recognized credentials. Students will also have the ability to receive postsecondary credit while still in high school and have access to paid work experiences with employer partners such as Lockheed Martin. Overall, the grant will help prepare 2,500 graduates at Bladensburg and other schools across the county to succeed academically and graduate career-ready in the high-demand fields of health care and information technology.
On the same day, the Departments of Education and Labor launched the Registered Apprenticeship-College Consortium, a new effort that will allow graduates of registered apprenticeship programs to turn their years of rigorous on-the-job and classroom training into college credits toward an associate’s or bachelor’s degree. Registered apprenticeship programs are sponsored by joint employer and labor groups, individual employers, or employer associations. Currently, the registered apprenticeship system includes a network of more than 19,000 programs nationwide — offering nearly 1,000 different career opportunities. Participating sponsors will have their programs evaluated by a third-party organization (for example, the American Council on Education or the National College Credit Recommendation Service) to determine the college credit value of the apprenticeship completion certificate. Graduates will be able to earn up to 60 credits based on their apprenticeship experience.
Opportunities, Threats, Internet Governance and the Future of Freedom
Opportunities, Threats, Internet Governance and the Future of Freedom
Robert M. McDowell
Last Friday, the U.S. Commerce Department’s National Telecommunications and Information Administration (NTIA) announced it intended to start the process of severing its last tether to the non-profit organization that manages Internet domain names and addresses, such as dot com and dot org. These technical functions, that help people’s computers and mobile devices find what they seek on the Net, are administered through the Internet Corporation for Assigned Names and Numbers (ICANN).
If all goes according to NTIA’s plan, the U.S. government will relinquish its contractual oversight of ICANN by September 2015. In its ideal form, this evolution could help reverse a growing tide of increased state interference into the Net’s affairs. If events don’t unfold as NTIAintends, however, Internet freedom, global prosperity and international political reform will be at risk.
Due to the complexities of the Internet ecosystem, and the manner in which it has thrived, before reacting impulsively, observers should pause and thoughtfully examine the nuances that abound in the wake of this development.
A best case scenario for the NTIA plan would have existing, non-profit, private sector Internet governance groups oversee ICANN’s management of these critical technical functions, just as they have other technical aspects of the Net for decades – with a perfect track record of success.
The worst case scenario would include foreign governments, either directly or through intergovernmental bodies, snatching the soon-to-be untethered technical functions for their own purposes. Keep in mind that Vladimir Putin plainly asserted in 2011 that his goal is to have “international control of the Internet” through the International Telecommunication Union (ITU), a treaty-based arm of the U.N. Given Mr. Putin’s proclivity for expansionism, especially lately, we should regard his statement as a promise he intends to keep.
This concern is more than theoretical. Countries such as China, Russia, Saudi Arabia, Iran, and their client states, have worked for years to absorb many aspects of Internet governance into multilateral organizations such as the ITU rather than the non-profit private sector. They succeeded in gaining a toehold in the Internet’s affairs during the 2012 World Conference on International Telecommunications, a treaty negotiation in Dubai. They will be back to expand the ITU’s authority further at its plenipotentiary meeting this fall, which is another treaty negotiation as well as a “constitutional convention” for the ITU.
Context is everything with this scenario. Internet freedom has been under siege for years. Authoritarian regimes resent the free flow of information an unfettered Net brings – even if increased Net-based commerce is catapulting developing world economies to new heights. The U.S. government’s role with the contract for the technical functions operated through ICANN has been used as Talking Point Number One by those who seek to expand intergovernmental organizations’ reach into the Net’s operations to counter what these regimes contend is, essentially, American domination of the Internet.
Add to the mix the recent revelations by Edward Snowden regarding the breadth of the U.S. National Security Agency’s data gathering, and pro-international regulation forces have something stronger than mere rhetoric to make their case for their proposed power grab. The timing of NTIA’s announcement, however, comes at a crucial time and has the potential to change the trajectory of the debate, with no cost to the U.S. – unless the Administration weakens its stance.
NTIA’s Friday announcement was not a complete surprise to those who follow these esoteric but important matters. Working toward removing NTIA’s formal role in this area is consistent with the arc of actions taken by the U.S. government since the 1990s when it formalized the privatization of the Internet and its governance. In short, the Net has migrated further away from government control over the past three decades. As a result, it has become the greatest deregulatory success story of all time.
For instance, in the late 1980s, only a paltry 88,000 people – mainly government users and academics – had access to the Internet. Today, due to the government taking its hands off of the Net, more than 3 billion people across the globe have Web access through mobile devices alone. Accordingly, the Net is fundamentally and rapidly improving the human condition by boosting living standards and raising political expectations as it strengthens the sovereignty of the individual. The evidence is irrefutable that both domestic and international government policies to leave the private sector alone to innovate and invest were the direct cause of this beautiful explosion of entrepreneurial brilliance.
With Friday’s announcement, NTIA is taking its last steps down a path that was paved over two decades ago: a path intended to get the government out of the Internet governance business. In that spirit,NTIA has put forth several conditions before it would allow its contract overseeing ICANN to expire in September 2015. The most important condition is that no governmental, intergovernmental or multilateral bodies would be allowed to have a role in overseeing any technical functions. Implicitly, if foreign governments or treaty-based organizations were to insert themselves into this realm, NTIA would renew its contract with ICANN in 2015, thus keeping the status quo and ending the argument for at least few more years.
To show that it is resolute, the Administration should vehemently underscore the conditionality of its plan. It cannot soften its stance on this crucial issue, event slightly. If it does, chaos will reign unlike any other time in the Internet’s history. Internet freedom and prosperity would get caught in an international regulatory death spiral.
The best case scenario would involve sticking with what has worked in the Internet space since its inception: allowing the non-profit, non-governmental, private sector, multi-stakeholder Internet governance structure to keep doing what it has been doing so well without the “help” of governments. Diverse, loosely-knit and “bottom up” run technical groups such as the Internet Architecture Board, the Internet Engineering Task Force, the Internet Society, and regional and local engineers, academics and user groups, are the best stewards of these technical functions – not anyone’s government. These private sector groups will keep the Internet governance structure dispersed and free from bottle necks to ensure that no entity can control the Net or shut it down.
Accomplishing the complex task of modernizing the multistakeholder model of Internet governance, including the administration of critical technical functions, will be difficult and risky. U.S. policy in this space should be to keep governments out of the Net’s technical affairs. But we can’t have it both ways. The Administration must not waver, even symbolically. Internet freedom and prosperity hang in the balance. To be continued …
Who Controls The Internet?
Seven people control the system at the heart of the web: the domain name system, or DNS.
The English stiff upper lip shows security cracks
David Hare: ‘The security services are running the country, aren’t they?’
“Well, they’re running the country, aren’t they? I mean, the reason I’m writing about the security services is that there is no democratic control of them whatsoever. And now it seems the judiciary is joining in.” The judgment certainly appears to support the central thesis of Hare’s latest trilogy of BBC films, about an MI5 agent disillusioned by his employer’s rampant abuse of power.
PO box justice: what secret Home Office court says about British openness
As the Guardian’s revelations show, this tribunal’s so-called scrutiny of the security services is a living shame to the UK
This revelation about the tribunal says a lot about the compulsive secrecy of the British establishment, which Nick Pickles, head of the excellent Big Brother Watch, likens to an addiction – a morbid condition of some sort. But it also, I am afraid, says something about British complacency. Our trust in these people to do the right thing behind closed doors on matters where the state’s interests are so aggressively defended is really alarming. That so few complaints against the intelligence agencies have ever been upheld at the tribunal, and just a few paltry sums in compensation have been paid, is all you need to know about the justice available there. We should see it for what it is: a secret operation, designed to stifle legitimate complaints against the authorities. In the past 15 years the legal system has embraced secret immigration tribunals, secret courts and the IPT, in which lawyers and claimants have little, if any, idea of the processes to which they are party and subject. This is a living shame to the United Kingdom. The idea that our politicians go about the world lecturing others on the rule of law or standards of justice is absolutely preposterous. But it is a hypocrisy that is permitted to exist because we do not hold their feet to the fire and demand to know why money is spent on ring-fencing their power.
Surveillance: Westminster faces up to the facts | Editorial
You may not like Edward Snowden. You may think him a villain rather than a hero. But few people – even within the closed worlds of intelligence – deny that he has brought into the open matters that demanded to be discussed. The more the revelations spilled into the open, the clearer it became that these were issues of the greatest importance – bearing on the private sector, the US and UK’s digital economy, international relations, individual privacy and the integrity of the web itself. There are huge implications for business, individuals and the courts, as well as the intelligence agencies themselves, in what has been disclosed. How could politicians really imagine they could sit this out – and what would that silence say about politics itself? In the space of 48 hours, the dam has broken. First came a thoughtful speech by the shadow home secretary, Yvette Cooper. Although characteristically cautious, in order to avoid criticising any of the agencies directly, she accepted that the UK’s creaking statutory protections need to be updated for the era of Big Data, and also damned the passivity of the three commissioners who were supposed to be keeping an eye on the surveillance undertaken by different arms of the state.