Hiển thị các bài đăng có nhãn hacking. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn hacking. Hiển thị tất cả bài đăng

Chủ Nhật, 14 tháng 4, 2013

Hacking airplanes in flight? I did that a year ago, Brad 'RenderMan' Haines says

  • hacking airplanes.jpg

    Security researchers have revealed scary flaws in the software used to route planes that could allow a malicious party to create "sizeable chaos."AP Photo/Brennan Linsley

A Spanish researcher this week claimed a simple Android app can take control of an airplane in flight, thanks to security flaws in the FAA’s 25-year-old communications software.

That comes as no surprise to Brad Haines, a hacker who made remarkably similar claims almost a year ago.

“The fact that you’ve got another guy coming up with the same conclusion ... this is suddenly proving things,” Haines told FoxNews.com Friday.

'If you see 50 extra flights, that’s probably not a technical glitch. It’s someone attacking you. Call the guys with the jackboots and guns.'

- Brad "Renderman" Haines

Safety officials and FMS, the maker of the software that Spanish researcher Hugo Teso exploited, have said there are fundamental differences between the flight simulator the hacker used for his app and the real software. But in a presentation Thursday at the the Infiltrate hacker conference in Miami, Haines made an eye-opening revelation: The next-generation software being built partly to replace it may be just as flawed.

“The FAA says ‘trust us.’ I’m sorry, I don’t -- and so far they have yet to put anything out there saying how they mitigated any of this stuff,” Haines told FoxNews.com.

Haines, a 33-year-old Canadian who goes by the name RenderMan, is something of a celebrity in hacker circles. His presentation was terrifyingly titled “Attacking the Next Generation Air Traffic Control System.”

And those attacks are surprisingly easy to carry out, according to Haines. “Anyone can listen on this to find the location of a plane in real time,” he said.

The NextGen system is intended to help the FAA keep tabs on every plane in flight, using GPS data rather than traditional radar. The FAA says it will allow far more refined tracking of planes, and let pilots choose more direct routes. It also replaces a system that detractors say is overwhelmed, antiquated, costly and slow. NextGen comes at a cost in the billions of dollars, and is still being implemented.

But NextGen may contain the same flaw that Teso’s Android app revealed: Location data being passed between the plane and the control towers is unencrypted and unauthenticated, leaving them open to potential hacker attack.

Working with partner Nick Foster, Haines found a way to allow anyone with surprisingly inexpensive gear to influence the data that shows up, adding dozens of false flights to screens, for example, and in general creating “sizeable chaos,” he said.

Haines isn’t a malicious hacker himself: A frequent speaker at conferences around the world, he spends his days fixing security flaws and his nights locating them.

Haines says he took his findings to the FAA (and the TCCA, Canada's version of the FAA) but received only a canned statement. He responded by going public with his findings.

The FAA did not immediately respond to a FoxNews.com request for comment.

The challenge is that encrypting the information would be a management nightmare that could cause even more problems, Haines said. So what to do?

“You can use [these findings] to educate traffic controllers and pilots,” he told FoxNews.com. “Maybe we should build some protocols to flag things on the ‘weirdo’ meter. If you get 50 extra flights, that’s probably not a technical glitch. It’s someone attacking you. Call the guys with the jackboots and guns.”

“For the longest time it was, oh it’s too expensive, you need specialized hardware. Now with software-defined radios and technology that has come so far, I don’t need half an airplane cockpit to talk to this this stuff.”


View the original article here

Thứ Năm, 28 tháng 3, 2013

US takes swipe at China following hacking accusations

The U.S. has taken its first real swipe at China following accusations that the Beijing government is behind a widespread and systemic hacking campaign targeting U.S. businesses.

Buried in a spending bill signed by President Barack Obama on Tuesday is a provision that effectively bars much of the U.S. government from buying information technology made by companies linked to the Chinese government.

It's unclear what impact the legislation will have, or whether it will turn out to be a symbolic gesture. The provision only affects certain non-defense government agency budgets between now and Sept. 30, when the fiscal year ends. It also allows for exceptions if an agency head determines that buying the technology is "in the national interest of the United States."

Still, the rule could upset U.S. allies whose businesses rely on Chinese manufacturers for parts and pave the way for broader, more permanent changes in how the U.S. government buys technology.

"This is a change of direction," said Stewart Baker, a former senior official at the Homeland Security Department now with the legal firm Steptoe and Johnson in Washington. "My guess is we're going to keep going in this direction for a while."

Rep. Dutch Ruppersberger, the top Democrat on the House Intelligence Committee, said he supports the restriction and doesn't think it would be too cumbersome for federal agencies. The Defense and Energy departments already are mindful of how its networks are built.

"Anything we can do to call awareness to the fact that we're continuing to be cyberattacked, we're continuing to lose jobs, and that billions of dollars in American money is being stolen," Ruppersberger said in an interview Wednesday.

In March, the U.S. computer security firm Mandiant released details on what it said was an aggressive hacking campaign on American businesses by a Chinese military unit. Since then, Treasury Secretary Jacob Lew has used high-level meetings with Beijing officials to press the matter. Beijing has denied the allegations.

Congressional leaders have promised to push comprehensive legislation that would make it easier for industry to share threat data with the government. But those efforts have been bogged down amid concerns that too much of U.S. citizens' private information could end up in the hands of the federal government.

As Congress and privacy advocates debate a way ahead, lawmakers tucked "section 516" into the latest budget resolution, which enables the government to pay for day-to day operations for the rest of the fiscal year. The provision specifically prohibits the Commerce and Justice departments, NASA and the National Science Foundation from buying an information technology system that is "produced, manufactured or assembled" by any entity that is "owned, operated or subsidized" by the People's Republic of China.

The agencies can only acquire the technology if, in consulting with the FBI, they determine that there is no risk of "cyberespionage or sabotage associated with the acquisition of the system," according to the legislation.

The move might sound like a no-brainer. If U.S. industry and intelligence officials are right, and China is stealing America's corporate secrets at a breathtaking pace, why reward Beijing with lucrative U.S. contracts? Furthermore, why install technical equipment that could potentially give China a secret backdoor into federal systems?

In late 2012, Ruppersberger and House Intelligence Committee Chairman Mike Rogers, a Republican, released a report urging U.S. companies and government agencies to drop any business with Chinese telecommunications companies Huawei Technologies Ltd. and ZTE Corp. because of the security risks they pose.

"Any bug, beacon or backdoor put into our critical systems could allow for a catastrophic and devastating domino effect of failures throughout our networks," Rogers said in a statement accompanying the report.

But a blanket prohibition on technology linked to the Chinese government may be easier said than done. Information systems are often a complicated assembly of parts manufactured by different companies around the globe. And investigating where each part came from, and if that part is made by a company that could have ties to the Chinese government could be difficult.

Huawei, the third-largest maker of smartphones, says it is owned by its employees and rejects claims that it is controlled by the communist government or China's military.

Depending on how the Obama administration interprets the law, Baker said it also could cause problems for the U.S. with the World Trade Organization, whose members include U.S. allies like Germany and Britain that might rely on Chinese technology to build computers or handsets.

But in the end, Baker says it could make the U.S. government safer and wiser.

"We do have to worry about buying equipment from companies that may not have our best interests at heart," he said.


View the original article here

Thứ Tư, 20 tháng 2, 2013

White House announces anti-theft trade strategy following alleged China hacking

The Obama administration announced a broad new effort Wednesday to fight the growing theft of American trade secrets following fresh evidence linking cyberstealing to China's military. 

The plan includes a new diplomatic push to discourage intellectual property theft abroad along with better coordination at home to help U.S. companies protect themselves. The administration says indications are that economic espionage is increasing, not only through electronic intrusion over the Internet but also through the recruitment of former employees of U.S. companies with knowledge of inside trade information. 

"Trade secret theft threatens American businesses, undermines national security and places the security of the U.S. economy in jeopardy," said a report from the White House. "These acts also diminish U.S. export prospects around the globe and put American jobs at risk." 

Earlier this week, a suburban cybersecurity firm, Mandiant, accused a secret Chinese military unit in Shanghai of years of cyberattacks against more than 140 U.S. companies. The accusations and supporting evidence increased pressure on the United States to take more action against the Chinese for what experts say has been years of systematic espionage. 

The Chinese government denied being involved in cybertheft, with China's defense minister calling the Mandiant report deeply flawed. China's Foreign Ministry said that country has also been a victim of hacking, much of it traced to the United States. 

Wednesday's Obama administration report did not specifically target any one violator, but the China problem is evident in the case studies it cited. Those examples did not involve cyberattacks, but rather the theft of hundreds of millions of dollars in trade secrets by former employees of U.S. corporations including Ford Motor Co., DuPont Co., General Motors Corp., Cargill, Dow Chemical Co., Valspar and Motorola. 

President Barack Obama signed an executive order last week aimed at helping protect the computer networks of American industries from cyberattacks. It called for the development of voluntary standards to protect the computer systems that run critical sectors of the economy such as the banking, power and transportation industries. It directed U.S. defense and intelligence agencies to share classified threat data with those companies. 

He also prodded Congress during his State of the Union address to go further. 

"Now, Congress must act as well by passing legislation to give our government a greater capacity to secure our networks and deter attacks," Obama said. 

The president said America's enemies are "seeking the ability to sabotage our power grid, our financial institutions and our air traffic control systems. We cannot look back years from now and wonder why we did nothing in the face of real threats to our security and our economy." 

The new report was short on specific consequences for trade secret theft, with no new fines or other trade actions announced. It included five actions to protect American innovation: 

-- Applying diplomatic pressure by senior officials to foreign leaders to discourage theft. 

-- Promoting best practices to help industries protect against theft. 

-- Enhancing U.S. law enforcement operations to increase investigations and prosecutions. 

-- Reviewing U.S. laws to determine if they need to be strengthened to protect against theft. 

-- Beginning a public awareness campaign.


View the original article here