Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

Wednesday, November 1, 2017

Tips for Protecting Critical Infrastructure

Most of our Nation’s critical infrastructure now runs on the Internet. The systems that enable us to live our daily lives starting from the information systems, financial institutions, transportation systems, and more are all dependent upon a digital ecosystem. As cyber breaches continue to rise in frequency and scale, it is critical for all Pakistanis to understand their role and take steps to protect our critical national infrastructures.

SIMPLE TIPS 
Every day people connect to critical infrastructures without even realizing it from their smart phones, tablets, and computers. Here are three ways to do your part in helping secure our critical infrastructure by protecting your devices that connect to critical infrastructure systems and practicing safe online habits. 

Keep a clean machine. 
Keep the security software, operating system, and web browser on your devices updated. Keeping the software on your devices up to date will prevent attackers from being able to take advantage of known vulnerabilities.

Enable stronger authentication. 
Always enable stronger authentication for an extra layer of security beyond the password that is available on most major email, social media and financial accounts. Stronger authentication (e.g., multi-factor authentication that can use a one-time code texted to a mobile device) helps verify that a user has authorized access to an online account. 

When in doubt, throw it out. 
Links in email and online posts are often the way cyber criminals compromise your mobile devices. If it looks suspicious even if you know the source it’s best to delete or, if appropriate, mark it as ”junk email.” 

Make your passwords long & strong. Use complex passwords with a combination of numbers, symbols, and letters. Use unique passwords for different accounts. 

Secure your Wi-Fi network. Your home’s wireless router is the gateway entrance for cybercriminals to access all of your connected devices. Secure your Wi-Fi network, and your digital devices, by changing the factory-set default password and username.

Thursday, April 21, 2016

Parlimentarians fail to understand the Cyber Crime Phenomena



The securitization of cyberspace is a transformation of the domain into a matter of national security and perhaps one of the most important forces shaping today’s global communications. Using war on terrorism and national action plan as a pretext the ruling party in Pakistan has passed the Prevention of Electronic Crimes Bill 2015 in the National Assembly during presence of handful of parliamentarians. The bill if also passed in Senate will be detrimental for the growth and development of the internet in the country. Given the important role internet is set to play for economic development in Pakistan it is horrific to see the mannerism in which the despotic bill was passed. The Nazis destroyed the independence of the press by passing series of draconian laws and it seems Parliamentarians are exactly imitating the same with the freedom of the internet by passing of this bill.

As cyberspace infiltrates all aspects of our society, economics and politics it was hoped that the government will be more responsible with the drafting of the bill as it not only affects millions of internet users in the country but also put in risks the digital rights of next generation tech users with inadequate protections for privacy and basic human rights. The bill has been engineered with the pretext of protecting national security but it seems to be conscripted to benefit the aristocracy much more than the general populace. 

The bill on which I have spoken and written a lot before as well is still extremely vague in its definitions despite claims of the Minister and fails to understand the cybercrime phenomena that requires a multistakeholder approach to tackle complex technical and legal issues transcending our national territorial jurisdictions. Furthermore, most sections of the bill aims to criminalize innovation and development a critical part responsible for the success of the very internet we know today. Pakistan requires talent that can engineer a next Google, Facebook or create applications for encryption and security to protect our national assets and become less dependent on foreign technologies but this bill aims to criminalize all these efforts.

The globalization of internet is shifting economic developments in two important directions. First, given the aging population and near-saturated market penetration in the advanced economies, most of the expansion of the internet related market will take place in developing countries like Pakistan, India, and Bangladesh. Secondly, the spread of internet is expected to increase the share of developing countries in the internet economy presenting a historic opportunity for the young and poor in Pakistan to improve their economic condition but with the bill instead of aiming to promote the use of technologies is more inclined towards discouraging it’s use.

Overregulation of internet with the Cybercrime bill might deprive users of major benefits the information economy brings. To fully reap the benefits of a modern, rapidly changing economy, Pakistan need to better prepare their citizens for the demands of a changing information economy, and they need to adjust laws and social protection systems to ease the transition from labor market to information one.

It appears that parliamentarians have failed to understand the nature of cybercrime phenomena and seems to be determined to address it using the narrow hole of national security without considering its impact on innovation and long term economic development.

Tuesday, March 8, 2016

$10 switches and No Firewalls

Bangladesh Bank exposed to hackers by cheap switches, no firewall.
Bangladesh's central bank was vulnerable to hackers because it did not have a firewall and used second-hand, $10 switches to network computers connected to the SWIFT global payment network, an investigator into one of the world's biggest cyber hesit revealed.

The shortcomings made it easier for hackers to break into the Bangladesh Bank system earlier this year and attempt to siphon off nearly $1 billion using the bank's SWIFT credentials.

The lack of sophisticated switches, which can cost several hundred dollars or more, also means it is difficult for investigators to figure out what the hackers did and where they might have been based.

Experts in bank security described the findings as disturbing."You are talking about an organization that has access to billions of dollars and they are not taking even the most basic security precautions," said Jeff Wichman, a consultant with cyber firm Optiv. Most of the banks in developing countries fail to adequately protect their networks because they focus security budgets on physically defending their facilities.

Cyber criminals broke into Bangladesh Bank's system and in early February tried to make fraudulent transfers totaling $951 million from its account at the Federal Reserve Bank of New York. Most of the payments were blocked, but $81 million was routed to accounts in the Philippines and diverted to casinos there. Most of those funds remains missing. Forensic experts investigating the issue from SWIFT advised the bank to upgrade the switches only when they visited after the heist. There was a deficiency in the IT system said the spokesman, Subhankar Saha, confirming that the switch was old and needed to upgraded. The heist's masterminds have yet to be identified.

Bangladesh Bank has about 5,000 computers used by officials in different departments. The bank facility should have been walled off from the rest of the network. That could have been done if the bank had used the more expensive, "managed" switches, which allow engineers to create separate networks and install firewall at different levels to protect off the network from attackers. Moreover, considering the importance of the network services, the bank should have deployed staff to monitor activity round the clock, including weekends and holidays.

Many public sector organizations hosting critical national data suffers from similar issues, poorly designed infrastructure and lack of investments in upgrading IT security makes them extremely vulnerable to similar attacks on even larger scale.