Target Missed Bull’s-Eye in Data Breach

Target acknowledged Thursday that it put information on a back burner that led to the compromise of more than 100 million customer records and will cost the company millions of dollars in losses.
“Like any large company, each week at Target there are a vast number of technical events that take place and are logged,” said Target spokesperson Molly Snyder.
“Through our investigation, we learned that after these criminals entered our network, a small amount of their activity was logged and surfaced to our team,” she continued.
“That activity was evaluated and acted upon. Based on their interpretation and evaluation of that activity, the team determined that it did not warrant immediate follow up,” Snyder said. “With the benefit of hindsight, we are investigating whether, if different judgments had been made the outcome may have been different.”
During a data breach that lasted from Nov. 27 to Dec. 18 last year, cybercriminals clipped 40 million payment card numbers and 70 million customer records containing personal information from the retailer.
In the quarter that ended in December, Target reported expenses related to the breach to be US$61 million, but that number is expected to balloon, especially as the retailer starts settling the more than 80 lawsuits filed against it because of the break-in.

False Positives

Target issued its statement after Bloomberg Businessweek reported that on Nov. 30 and Dec. 2, the company was alerted to the cyberattack on its systems by a security team in Bangalore, India. A tool made by FireEye, which runs a global network designed to protect companies from Internet threats, had triggered the alerts.
The warnings went unheeded, according to Bloomberg. If the company had taken action, the number of records compromised in the breach could have been reduced.
The FireEye system has an automatic feature that would have deleted the malware behind the breach, but Target had turned off that feature.
Companies often turn off automatic features on security systems because when they’re initially installed, they can generate too many false positives and slow down the performance of other systems.
“There would be a significant risk in the beginning if FireEye is not tuned correctly to stop processes that are not malicious,” explained Joe Schumacher, a security consultant withNeohapsis.
“What could happen is the whole enterprise at Target could come grinding to a halt because of false positives or software on the system that FireEye thinks is malicious and is not,” Schumacher told the E-Commerce Times.
“It would take an organization like Target a long time to roll out a system-wide solution that acted on its own and knew all the facets of the enterprise,” he added.
FireEye declined to comment for this story.

Too Much Information

Target’s treatment of the early warnings from Bangalore underline a problem facing all large organizations today.
“More than ever, network administrators, system administrators, security operations personnel have a tremendous amount of security events going on in their systems, and in this case, they also had a third party that is also monitoring their systems and providing them alerts,” said JD Sherry, vice president of technology and solutions at Trend Micro.
“So the FireEye alerts on Nov. 30 could have been one of hundreds of thousands of critical alerts that came through their systems,” he told the E-Commerce Times.
“Target had a failure in their process, and that’s what they’re looking at now — but security professionals today have many, many events that they’re evaluating, including a lot of noise being generated by some advanced threat detection system out there,” he said.
“It’s easy to get lost in the overall noise,” Julian Waits, CEO of Threat tracker, told the E-Commerce Times.
“I can guarantee you that it wasn’t only FireEye that detected the problem. There were a myriad of technologies that went off — but nothing was coordinated around a warning that there was a real issue that you have to respond to instantly,” he explained.
Because of the volume of threat information organizations like Target must assess, security is becoming increasingly a Big Data problem.
“The biggest challenge with security today is with so many alarms going off, how do we identify which alarms are most pressing?” Tal Klein, vice president of marketing for Adallom, told the E-Commerce Times.
“Until we solve determining the severity of alerts in an automatic way,” he added, “we should expect to see these kinds of problems keep happening.”

Glassholes: At least you know who they are

Google Glass has provoked a lot of angst among those worried about the electronic eyewear is rude, weird, or creepy — and for good reason.
Among the concerns Glass raises are that the wearer could be recording video, audio, or photos of other people or that the wearer could be looking up online information about those people. For a good illustration of the social difficulties of Google Glass, check Becky Worley’s report from South By Southwest on Google Glass at Yahoo Tech, in which wearers report problems at a supermarket, customs, a business meeting, and a trip to the bathroom at a zoo. The headline of the piece: “Google Glass Will Never Be Okay.”
Plenty of others have similar sentiments. Gartner’s Ian Glazer is worried that Google Glass makes relationships uncomfortably asymmetric, with a power imbalance between those who are and are not wearing Google Glass.
The Google Glass creepy factor is embodied in Neal Stephenson’s sci-fi book “Snow Crash” in the character of Lagos, a “gargoyle” who’s encrusted with electronic sensory equipment and a live link to the databases of the world:
Gargoyles…are adrift in a laser-drawn world, scanning retinas in all directions, doing background checks on everyone within a thousand yards, seeing everything in visual light, infrared, millimeter-wave radar, and ultrasound all at once. You think they’re talking to you, but they’re actually poring over the credit record of some stranger on the other side of the room, or identifying the make and model of airplanes flying overhead.
Google Glass will rightly raise lots of hackles when used in public, and I think that’s appropriate. Although Google Glass devices are perched just over the line of sight, Glass still comes between two people having a conversation. And because one of the major points of Glass is to be able to record an intimately first-person view of the world, Glass can be intrusive: people often behave differently on a stage or on camera.
Thus, I’m not suggesting we brush off concerns about Glass as just baseless techno-fretting. It’s worth discussing society-altering inventions like power looms, birth control pills, automobiles, and televisions.
But often, the discussions about Google Glass are too narrow in scope. Before declaring Google Glass doomed to failure, we need to look at what has come before them and at what’s going to come after.
Paving the way to Google Glass
The most obvious precursor to Google Glass is the smartphone. It’s a general-purpose electronic companion that can be carried with you at all times, augmenting what you happen to remember with a live connection to vast amounts of personal and public information. It pages us with important messages and lets us record the moment with photos and videos.
To many of us, smartphones are useful and ordinary. But social norms are still catching up to technology. It’s just fine to take a mobile phone call when you’re driving with your spouse to do weekend shopping errands. It’s rude to do so when you’re on a first date. But in many circumstances, it’s a gray area, and what’s considered OK is changing. Taking a call from your child’s school in the middle of a business meeting is probably OK, because it might be an emergency. But taking a call from your friend in the middle of a business meeting might be a bad idea. On some trains, there are cars where it’s OK to talk on mobile phones and some where it’s barred.
We’re also adapting to mobile phone photos and video. Is it OK to record a rock concert? Maybe, but some musicians politely ask you not to. At my son’s piano recital last month, a succession of parents moved to the front of the central aisle to record their children’s performances and blocking the view for a lot of the rest of the audience. Nobody objected, but such behavior would be unthinkable if the performer had been a world-class violin virtuoso rather than a bunch of primary-school kids.
The Lost Lake Cafe and Diner in Seattle bans people from wearing Google Glass.

The Lost Lake Cafe and Diner in Seattle bans people from wearing Google Glass.

(Credit: Lost Lake Cafe/ Facebook)

The more we use mobile phones, and the more they can do, the more we as a society will evolve these social protocols, either through convention, posted rules, or legislation. Google Glass looks shocking today, but don’t discount out the possibility that we’ll work out rules for when they’re OK to wear and when they’re not, gestures that warn people we’re using them or reassure them that we’re not, or conventions for asking politely if it’s OK to record a particular moment.
We’re already working some of the protocols out with mobile phones and other devices. I went skiing a couple weeks ago, and lots of teenagers and some adults had GoPro helmets stuck to their helmets, making parts of their lives mini-performances and making all the rest of us part of the supporting cast whether we wanted to be or not.
All these rules are evolving, but here’s the underlying point: We’ve already accepted technology into our lives that comes with much of the rudeness and creepiness of Google Glass.
Google’s devices push the issue further, but we’re already dealing with the rudeness of attention divided between our company and our device, with the constant interruptions from the cloud, with joggers tuned out to music only they can hear, with people recording images of everything around them then posting it publicly on the Net.
Glass in our future
That’s the context that Glass is fitting into today. I also think it’s important to consider the context Glass will fit into tomorrow.
Glass today is bulky and awkward compared with ordinary glasses, but it’s sleek compared to anything that could have been built a decade earlier. Extrapolate today’s trends in miniaturization of processors, networking electronics, cameras, and it’s not hard to imagine that many more devices could come with the capabilities that Glass has today.
I’m not saying such a future is inevitable, but it’s quite possible that ordinary looking glasses, or perhaps jewelry or clothing or Bluetooth earpieces, could have such technology built into it. Russian dashcams could spread to many more cars and to our homes and offices. Maybe it’ll even be in contact lenses or, if Ray Kurzweil is right, nanobots in our brains and bloodstream will intercept our own sensory data, process and store it, then communicate directly with our own neurons. That latter idea is pretty far out, but given how much technology has changed in the last few decades, I’d hesitate to rule it out completely.
The more we rely on devices to keep track of what’s going on around us, the more the assumption of asymmetry common in today’s Glass criticisms isn’t actually the case. It’s natural to think about the asymmetry today because almost nobody has Google Glass. But if Glass or something like them spread, the discussion will have to include situations of symmetry, too, like when two people having lunch each have smartphones instead of just one of them.
We could record a lot more with our mobile phones. Perhaps we’ll find it useful to record conversations by default to improve our imperfect memories — the phones themselves or some cloud service they connect to could keep track of whom we met at social occasions and business meetings. Technology could scan our conversations and prompt us later that we’d promised to go to that birthday party or bring snacks for the office, or warn us that a weekend outing won’t be possible because a spouse had mentioned earlier that he or she would be out of town on travel.
In other words, maybe other devices will offer much of the creepiness of Glass without the actual Glass itself.
And here’s where I think there’s a perversely good thing about Google Glass’s intrusiveness. They’re so overt that they don’t leave as much room for ambiguity about what’s going on. They broadcast to everybody what’s possible.
In other words, wearing Google Glass might make you a jerk — but at least you’re an honest jerk

Google Glass Explorer Edition

BlackBerry sells US headquarters to Brookfield Property Group

Faced with mounting losses and unsold inventory, struggling smartphone maker BlackBerry has sold its US office in Texas to Brookfield Property Group as it seeks to rationalise costs. 

Financial details of the transaction were not disclosed. “We can confirm that Brookfield Property Group has purchased BlackBerry’s Irving, Texas campus property. BlackBerry will continue to be a tenant on the campus,” a BlackBerry spokesperson told PTI.

The move is being seen as a part of the Canadian handset maker’s broader efforts to conserve cash and fund turnaround efforts amid intense competition from Apple and Google’s Android operating system-based smartphones.

Waterloo, Ontario-based BlackBerry had bought the upscale Riverside Commons six-building complex in 2009.

Brookfield is an alternative asset manager focussed on property, renewable energy, infrastructure and private equity with over $175 billion in assets under management. It has eight corporate offices globally, including one in India.

Once a leader in the global smartphone market, BlackBerry has lagged behind competitors Samsung and Apple and lost market share steadily.

For the quarter ended November 30, it posted a net loss of $4.4 billion compared with a loss of $965 million in the year-ago period.
BlackBerry sells US headquarters to Brookfield Property Group
The loss includes a non-cash, pre-tax charge against inventory and supply commitments of approximately $1.6 billion during the reported quarter.

The pile up was mainly on account of unsold BlackBerry 10 devices, launched last year with much fanfare.

BlackBerry started a programme in 2012 to streamline operations and increase efficiency. Among other things, the company sought to optimise its manufacturing footprint and outsource global repair services and reduce its workforce.

BlackBerry said it would cut 4,500 positions to bring the total workforce to approximately 7,000 full-time global employees.

Alibaba confirms plans to offer IPO in US

China e-commerce giant Alibaba Group confirmed early Sunday that it plans to become a public company in the US.
Rumored to be near for months, a US IPO would “make us a more global company and enhance the company’s transparency,” the company said in a brief note on its Web site. The statement did not indicate which stock exchange the company would choose for its listing.
Alibaba, which controls nearly 80 percent of China’s Internet shopping market, is expected to raise more than $15 billion, giving it a $130 billion valuation. That lofty target would challenge Facebook’s record Internet IPO, which raised $16 billion in 2012.
Founded in 1999 by former English teacher Jack Ma, the company provides marketplace platforms that allow merchants to sell goods directly to consumers. Rather than selling goods to consumers as US e-commerce giant Amazon does, Alibaba provides listing and advertising services.
The statement appears to snub the Hong Kong stock exchange, which had been competing for the offering with US stock exchanges but objected to some of Alibaba’s proposed listing terms. The company said it was keeping its options open for a possible dual listing in China.
“We wish to thank those in Hong Kong who have supported Alibaba Group,” Alibaba said in Sunday’s statement. “We respect the viewpoints and policies of Hong Kong and will continue to pay close attention to and support the process of innovation and development of Hong Kong.”
The IPO is also expected to a boon for Yahoo, which still owns 24 percent of the China e-commerce giant.

 

Jony Ive: Competitors steal Apple’s work

Here is the good news: you can make Jony Ive angry. All you have to do is copy his ideas.
How do I know? Because I’ve just read a long interview with him in the UK’s Sunday Times. (It’s behind a paywall, but I promise I didn’t steal it.)
This interview was part of the Sunday Times Magazine’s “Makers” series, and Ive warmed immediately to the concept. “Everyone I work with shares the same love of and respect for making,” he explained.
He added: “Objects and their manufacture are inseparable. You understand a product if you understand how it’s made.”
The problem is that the word “maker” has been co-opted, nay stolen, by the pimple-faced, soft-hearted techies of San Francisco, who are deeply hurt to be called “techies.”
Ive, though, believes craft is enjoying a resurgence. He said he once took his iPhone apart and put it back together again, just to prove he could.
Interestingly, the Sunday Times managed to dig up a photo to prove that he once had hair. And lots of it — spiky like a Bay City Roller. (Look it up.)
The interview takes great pains to describe the great pains Ive takes to make sure the products aren’t great pains. This is relatively familiar territory.
But Ive shone a little light into why Apple doesn’t exactly make cheap products.
He said:

 We’re surrounded by anonymous, poorly made objects. It’s tempting to think it’s because the people who use them don’t care — just like the people who make them. But what we’ve shown is that people do care. It’s not just about aesthetics. They care about things that are thoughtfully conceived and well made.

 

The implication, of course, is that they’re prepared to pay for that thoughtfulness.
Ive put it like this: “We make and sell a very, very large number of (hopefully) beautiful, well-made things. Our success is a victory for purity, integrity — for giving a damn.”
He believes his job is making technology personal and he believes that the relationship people have with Apple products is intimate. (Oh, of course, he vaguely, slightly hinted at an intimate iWatch. But he wasn’t going to actually say anything, was he?)
Asked whether all the lining up outside Apple stores to wait for the latest thing isn’t intimately insane, he replied: “It’s a demonstration against thoughtlessness and carelessness.”
I bet you’ve never thought of it that way. You always thought it was just a bunch of style-obsessed, superficial groupies who are vacuous in the extreme. (At least Samsung thinks so.)
Talking of Samsung — which Ive specifically did not — there is talk (and legal action) suggesting the Korean company (and others) occasionally mimics the work of Ive and his team.
Copying clearly annoys him. “It’s theft,” he said.
He added: “What’s copied isn’t just a design, it’s thousands and thousands of hours of struggle.”
Quiet struggle, though. Ive described a “pre-verbal” understanding at Apple about what everyone is trying to achieve.
Apple only gets verbal during the fancy presentations. And when it sues you, of course.

 

Ukrainian hackers claim takedown of NATO Web sites

Pro-Russian Ukrainian hackers claimed responsibility for a cyberattack that took down several NATO Web sites amid rising tensions over military incursions into the Crimean peninsula.
A hactivist group calling itself Cyber Berkut claimed to have launched attacks Saturday that took down NATO’s main page and that of NATO’s cyber defence center. The group also claimed to have taken down the site for NATO’s Parliamentary Assembly.
NATO spokesperson Oana Lungescu confirmed on Twitter that several NATO sites had been the target of a “significant” distributed-denial-of-service attack but said the integrity of the systems was unaffected and experts were working to restore normal functionality.
DDoS attack on some #NATO sites ongoing but most services restored. Integrity of NATO data &systems not affected. We continue working on it

— Oana Lungescu (@NATOpress) March 16, 2014

The attacks came on the eve of Sunday’s referendum on whether Ukraine’s Crimea region should join Russia. The UN Security Council introduced a resolution declaring the referendum invalid, but Russia vetoed the resolution Saturday.
Along with an escalation in cross-border hacking activity, Internet censorship has also seen a recent increase. The Russian government ordered Russian ISPs to block access to a handful of Russian Web sites noted for their criticism of President Vladimir Putin and his government.

WhatsApp Flaw Opens Database Doors to Hackers

An Android developer’s disclosure that it’s possible to hack into the WhatsApp database and read the text of the chats from another application could be a big headache for Facebook, which has agreed to purchase the app for US$19 billion.

“This is not a bug, but a design decision of WhatsApp,” Bas Bosschert, chief technology officer of Double Think, told LinuxInsider.

“They selected for usability in their design, not security,” he continued. “I didn’t find anything new — I only showed how people could abuse this flaw with a working proof of concept.”

The flaw works if the database backup capability is enabled, which it apparently is by default, commenters on Bosschert’s blog post said.

Although WhatsApp had encrypted its database in February, that encryption is available only in new installations, and updates still use the old, unencrypted version, Bosschert remarked.

Facebook and WhatsApp did not respond to our request to comment for this story.

The process seems straightforward — Bosschert created a PHP script to store the database on a Web server, created an Eclipse project with some additional lines in the AndroidManifest.xml file, and grabbed the mststore.db and wa.db WhatsApp files, which are unencrypted.

His application displayed a simple loading screen during that process so users wouldn’t notice their WhatsApp database was being pilfered.

The hack is possible because the WhatsApp database used to be written in SQLite3. Openssl apparently also could be used to hack the database.

Although it appears WhatsApp encrypted the msgstore.db database using the .crypt utility, it’s still possible to read chats from the encrypted database by creating a simple Python script, which converts it to a plain SQLite 3 database.

NSA Deploys Botnet Armies, Spoofs Facebook

The latest Snowden revelations about NSA surveillance activities indicate the agency could infect millons of computers with malware, and has spoofed Facebook servers to capture traffic from targets. Documents previously leaked by NSA whistleblower Edward Snowden include detailed descriptions of its tools and techniques, First Look reported.

“It is not surprising that the NSA would create and deploy malware,” Harley Geiger, senior counsel at the Center for Democracy and Technology, told TechNewsWorld. “What is surprising is the evidence the NSA is prepared to do so on a scale that could affect millions of computers.”

Hacking and surveillance operations should be used “on specific targets with minimal impact on innocent parties, not on a massive scale,” Geiger said.

Apple adds selfie section to iTunes App Store

The selfie phenomenon appears to have won a certain measure of legitimacy from Apple.

Apparently geared toward expediting the satisfaction felt by many people when they take photos of themselves and share them with others, the company on Thursday added a special section to its iTunes App store devoted to apps that cater to the need to selfie. Mixed in with popular selfie apps such as Snapchat and Justin Bieber’s Shots, the “Sharing Selfies” section also includes selfie diary app Picr and selfie portrait-editing app Facetune.

The section’s selection is available on both the mobile and desktop versions of the Apple App Store for iOS devices.

While the idea of taking pictures of oneself has been around almost as long as cameras themselves, the term selfie has only been traced back to 2002, according to research conducted by Oxford English Dictionaries, which bestowed word of the year honors on the term in 2013. “If it is good enough for the Obamas or the pope, then it is good enough for Word of the Year,”

Oxford said in explaining its decision.

 

The phenomenon has exploded in popularity recently, capturing everything from the spotlight at the Oscars to random encounters with homeless people and even the aftermath of near tragedies.

Google slashes prices for Drive monthly plans

Google on Thursday announced that it is dropping the price for access to its cloud storage service.

Fifteen gigabytes are still free, but a monthly plan of 100 gigabytes has dropped to $1.99 from $4.99. One terabyte is now $9.99, down from $49.99, and 10 terabytes and over start at $99.99.

 

Drive’s storage works across products like Docs, and Gmail and Google+ photos. Customers who already pay for service will automatically be moved to one of the new plans.

The company has recently made a push in its productivity services. On Monday, Google announced a bounty program for its enterprise suite of apps, offering a $15 reward to people for every new user they sign up. And on Tuesday, it announced the launch of an add-on store for Google Drive and Sheets.