The Latest


Russia has been conducting a major campaign to experimentally hijack signals sent by Global Navigation Satellite Systems (GNSS) systems such as GPS, researchers have claimed in a detailed report.

Technically, GNSS spoofing (as opposed to simpler jamming) is an attempt to send false positional signals to a receiver using global satellite networks such as the US GPS, China’s Beidou, Russia’s GLONASS, and Europe’s Galileo.

In recent years, there have been a flurry of small-scale reports of spoofing plus one major incident in the Black Sea in 2013 when at least 20 ships reported positioning anomalies blamed on the phenomenon.

What the team at the Center for Advanced Defense (C4ADS) has uncovered is the first confirmed example of a nation using this technique on a large scale.

The evidence emerged after the team spent a year crunching satellite data gathered by the International Space Station (ISS), detecting 9,883 suspected spoofing incidents at 10 global locations connected to its military, including Crimea, Syria, and the Russian Federation.

Since February 2016, this resulted in 1,311 civilian ships being fed the wrong positional coordinates from a range of civilian satellite networks.

Even when the attacks are noticed and corrected the effect is that of a nuisance denial-of-service on targets which are forced to fall back on older, less convenient systems. Says the report:

In effect, Russian forces now have the capability to create large GNSS denial-of-service spoofing environments, all without directly targeting a single GNSS satellite.

Another apparently routine if slightly From Russia With Love application of is to block the tracking of politicians, with numerous reports of “a close correlation between movements of the Russian head of state and GNSS spoofing events.” This suggested the development of mobile jamming units.

The researchers also found previously unreported evidence of GNSS interference near Russian military activity that represented a danger to civilian airliners using the same airspace.

The wider threat

Because the technology to carry out spoofing attacks is now so cheap, GNSS spoofing is unlikely to be the preserve of Russia for long and is now within the grasp of small groups and perhaps even lone wolves, the researchers say.

Meanwhile, because GNSS technology is now widespread in sectors such as energy, financial telematics, policing, and transport, there is no shortage of economic significant targets to aim at.

State and non-state actors engaged in illicit activity continue to show the lengths to which they are willing to go in order to both conduct and conceal their operations.

Their conclusion is that the world is likely entering an era when GNSS interference will become an everyday hazard, which sounds a bit alarming.

The counter view is that they’re easy targets and that not enough effort has been made to come up with ways of defending GNSS systems. The good news is that it’s not that hard to detect spoofing with the right technology, nor work out who might be doing it. For instance:

The collaboration between C4ADS and UT Austin researchers shows how GNSS receivers based on low-Earth-orbit satellites can be used to detect and geolocate interference signals worldwide.

However, it’s still the case that not enough people are paying attention to the problem or doing this kind of research. Perhaps publicity over the alleged Russian programme will achieve what expert opinion has so far failed to.

 


from Naked Security https://ift.tt/2FNzPbR
From the Android bloatware selling your data to the hoards of security keys on GitHub, and everything in between. It's the weekly roundup.
from Naked Security https://ift.tt/2JUGJ38

Personal information of some 3.1 million Toyota customers may have been leaked outside the company, the Toyota Motor Corporation (TMC) announced on Friday.

Toyota hack

The announcement comes a few weeks after Toyota Australia said they have been “the victim of an attempted cyber attack”.

New breaches

The attackers targeted TMC sales subsidiaries (Toyota Tokyo Sales Holdings, Tokyo Tokyo Motor,Tokyo Toyopet, Toyota Tokyo Corolla, Nets Toyota Tokyo) and three independent dealers (Lexus Koishikawa Sales, Jamil Shoji, Toyota West Tokyo Corolla), all based in Tokyo.

They apparently breached their systems and gained unauthorized access to servers storing the customer data.

On the same day, Toyota Vietnam Motor Company (TMV) told Vietnamese news site Tinmoi that they might have also been hit.

Both TMC and TMV are still investigating and have yet to confirm that customer data has actually been compromised. In any case, TMC noted that the server did not include customers’ credit card information.

“We take this situation seriously, and will thoroughly implement information security measures at dealers and the entire Toyota Group,” TMC concluded.

Old breaches

As mentioned before, Toyota’s Australian subsidiary confirmed on February 21 that they have been hit by cyber attackers, but offered no more information than that.

According to some sources, the attack apparently messed up the subsidiary’s parts and cars distribution process.

Also, it has been speculated that the attackers were APT 32 (aka OceanLotus), a hacker group believed to be backed by the Vietnamese government, and that the reason they attacked Toyota Australia was because they searched for a way into the networks and systems of Toyota Japan.

For the moment, though, the extent of all of these breaches is unknown and Toyota has declined to say anything about who they believe performed the attacks.

Even older breaches and data leak incidents

Toyota is no stranger to cyber attacks, data theft and leaks.

Only a few months ago some of its sensitive documents were found exposed on a publicly accessible server belonging to an engineering service provider specialized in automation process and assembly for original equipment manufacturers.

Also, some five years ago, a former IT worker at a Toyota plant in the US, was convicted of intentionally damaging the company’s computer systems.


from Help Net Security https://ift.tt/2uFSCiU

By now you’ve heard about Marie Kondo, the author of New York Times bestseller, The Life Changing Magic of Tidying Up, and star of Tidying Up, the new Netflix show that puts her principles of organization and decluttering into practice in family homes throughout Los Angeles.

While the #KonMariMethod has put households across America in an organizing frenzy, we found that her tidying principles can also be applied to solve a core challenge for the business world: too much data.

Businesses ingest enormous amounts of personal data, every day. Sometimes this data is critical for business operations (e.g., user behavior), human resources (e.g., hours worked or pay accrued) or generating revenue (e.g., new users), but oftentimes, it’s not.

Chances are, there are countless data records stored in different internal databases or third-party systems that hold no business utility for your company. But unlike a drawer full of mismatched socks, excessive personal data can carry liability, and risk for businesses that continue to house it.

New data protection regulations, like the European Union’s General Data Protection Regulation (GDPR), and the upcoming California Consumer Protection Act (CCPA) are introducing new standards for how personal data is processed by companies. In most cases, businesses need explicit consent from users that collecting their personal data is OK. Otherwise, the burden is on your business to prove that your business interests override their data privacy rights.

What would Marie do? Minimize your data

The path to compliance with data protection laws always begins in the same place: data inventory and data minimization. We’ve adapted some of Marie Kondo’s principles to the process of organizing your company’s personal data.

Your goal with this exercise is to determine the data you need and delete the rest. The phrase “data minimization” appears throughout GDPR, and is a good practice for any business that aims for good data governance. By reducing your data stores to include only that which is essential, the risk of exposing sensitive data or missing an important data record when fulfilling a data request is dramatically reduced.

We begin by putting all of your data in one place.

If you’ve watched Tidying Up, you know the moment of reckoning with clutter starts early on, when her clients pile every piece of clothing they own on their bed, and are forced to face the reality of their closets. Now imagine if you could open the doors to your systems and databases and pile all of that personal data in one place?

Each company must take the time to collect all the personal data in their data stores so they can begin sorting through the clutter. Until your company is able to truly visualize a data inventory, it is impossible to optimize data processing, which is fundamental to complying with data protection laws like GDPR.

Once the data is in one place and you’re ready to begin a data minimization exercise in earnest, you will sort by category, not by location. This may feel counterintuitive at first, because companies often think of their data in terms of the systems where records are stored. It may be tempting to start by purging extra data from one database at a time. But just like ancient tubes of Chapstick live on your desk and nightstand, business often store duplicate data records in different systems, because the information could be useful to different teams for different purposes. When personal data is duplicated and dispersed throughout a number of databases, the risk increases for your company. Aggregating those data records is complicated, but critical for data protection.

Start with one category at a time, and discard all at once. Until your company is able to look at data by category, it is impossible to truly see the scope of personal data and understand your risk profile. One or two tubes of Chapstick in different places around the house may seem reasonable, but it takes putting all your Chapstick in the same place to realize you have 15 tubes scattered throughout the house. Similarly, if your siloed teams check their respective databases and see roughly 30 expired credit card numbers in each, the scale of the problem is less apparent than when you see 210 expired credit card numbers are stored across all the databases.

The impulse to begin a data minimization project by removing different categories of data from one database at a time is instinctual, but it often obscures the scale of clutter and in the end is a circular endeavour. Chances are high that the same categories of data lives in multiple databases, and you’ll be forced to revisit the same location countless times trying to delete different categories of data later on.

Do I need this data?

In Tidying Up, you evaluate each individual piece of clothing, piece by piece. If the item “sparks joy,” it can stay. If it does not spark joy, it goes. Looking at each data record individually is unrealistic, but the spirit is the same. Focus on the data that your business needs to keep, then delete or anonymize the rest. A good place to start is the law itself — audit the data you collect and if you can’t justify any individual category, then you have an obligation to delete that data. For the data you do keep, make sure that the data was collected with explicit consent, and is compliant with your regulatory obligations. When reviewing data records with your team, ask “do we need this data?”. If not, remove it.

Ideally, the big push for organizing your company’s personal data stores only happens once. In order to maintain data stores that are organized and compliant, establish transparent data collection policies with the public, and clear data retention policies internally.

Define rules around what categories of data are collected and stored, and for how long the data is stored. No personal data record should be stored indefinitely.

The stakes are high

Processing personal data is riskier than ever now that GDPR has come into effect. France fined Google $57 million for violating GDPR, and many other tech giants face similar complaints. Companies like Google and Amazon will survive the steep fines levied by authorities, but growth-stage enterprises might not. The authorities are not going to let violations slide, making the risk of a penalty very real. Tidying up your data is essential to compliance and the health of your business and ought to be a top priority for your business this year.


from Help Net Security https://ift.tt/2WDQVii