Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Wednesday, August 10, 2011

Do not bundle your phone and internet services

Most people today, including myself have chosen to bundle our electronic services in order to save money. I strongly recommend that people avoid this practice. Here is what happened to me.

For legal reasons and because I am only 95% sure that the story I'm about to tell is accurate, I will not tell you my service provider. Here is what happened.

For a 2 week period I had been receiving a phone call from the 617 area code and the line was always empty except for the first time the call came in. The first time the call came in, when questioned, the person on the end of the line said he was "Eric from Verizon". After that first call, that same number would call our house 4 to 5 times daily. Each time the phone was answered, we had no response, just empty air. I checked the number against all Verizon offices in the 617 area code and their was no match. I was positive that the phone call had some illegitimate purpose, but what?

One day around noon I was working my e-mail account when the phone call came in. Again, there was nothing but empty air. I hung up the phone and exited my e-mail thinking I had finished for the time being. Five minutes later, I realized that I forgot to send an e-mail so I tried to re-enter my account and my identity was stolen. Coincidence or criminal activity? I immediately began the painful process of trying to contact a live person at my e-mail provider. Thanks to the help of the Reference Department at my local library, I was given a group of numbers to call.

Here is the funny thing, as I dialed these numbers, the number would show up on my e-mail entry page under "user name". My telephone was talking directly to my computer on my e-mail page. I recovered my e-mail in approximately 50 minutes, but the damage was done. Minutes later I started getting calls from treasurers of organizations I belong to asking why I was requesting wire transfers of money. A crime has been committed but does anyone care?

Nobody cared; nothing was stolen, the police could care less; but even more outrageous, the service provider could care less. After warning 3000 people in my address book, I decided to have it out with my service provider.

I sat for 3 hours trying to explain to person after person what had happened and was met with only denial. What really burned me was my service provider would not even put me in touch with a forensic person to study my claim. The company supervisors also denied they had fraud units - this is an absolute lie.

I spoke to a person who shall remain nameless but has intimate knowledge of communications and how these systems work. This person is about the smartest person I have ever known and his resume includes work in national defense, NASA and a host of other impressive high tech companies. He absolutely agreed that this is how my e-mail was stolen. Now my 95% certainty has shifted to 99%.

My service provider simply did not care; not even when I told them that my only alternative is to UN-bundle. I blocked the bogus number from reaching my phone through the service provider, but the crooks could be working off of dozens of numbers and they could call again at any time. Now I take the phone off of the hook when I'm using my e-mail, but I intend to change my phone to a different company.

Beware; I hope you have not had the misfortune that I had.

tomtoak

Friday, March 20, 2009

Cyber Security and the Threat from al Qaeda

President Barack Obama has long expressed a fear that the next attack on America may well be a cyber attack. During Obama's campaign, he pledged to develop a strategy to ensure that the internet infrastructure is protected from dismantling efforts of our enemies. On February 17, 2009, Obama begin a 60 day review process to assess the effectiveness of the Bush $30 billion cyber defense policy. He appointed Melissa Hathaway to lead this effort which requires a comprehensive study in a very short time period. This leadership on display is what was continually lacking during the Bush administration.

Let me share with you why I have become really concerned. On March 17, 2009, Air Force General Kevin Chilton, the head of the Pentagon's Strategic Command warned Congress that the risk of cyber attack remains a very serious threat. Chilton told Congress that his command has responsibility to protect the military networks, but they are not charged with protecting other government or private networks that, if attacked, would cripple the nation.

This is a truly scary report to Congress. It seems like the Bush administration was sound asleep again. Not only did Bush sleep in the months before 911, it sounds like he's been sleeping during the entire 8 years of his presidency. While Dick Cheney was so busy torturing our enemies, I don't believe that they understood the real risk here. The testimony of General Chilton would tend to support this. Chilton had to be aware of all of the efforts to protect the internet from crippling cyber attack; that was his job. Apparently, the government's effort lacked the ability and/or authority to protect the entire system.

After the attack on 911, the Bush administration put in place many security measures that focused on preventing future attacks. I do think their primary focus was on the possibility of similar grand attacks that could show extremist Islamic disdain for western civilization. Colin Powell's former Chief of Staff, Lawrence Wilkerson, just called Dick Cheney "evil" and he went on to say that his fear mongering is "assisting" al Qaeda. While Cheney calls our enemies, evil, and I believe that he is right, he lost focus on what 21st century threats might well entail. Cheney spent too much time hating the enemy and not enough time studying the enemy. This is the sad truth behind Wilkerson's comments. We can never forget that the main goal in previous al Qaeda attacks was to bring down financial systems.

Just think about this. If you could bring down the financial systems of western civilization with a cyber attack, would you be focusing on trying to get a few hijackers through the tightened airport security systems throughout the world? Why would you do that if you could stay in your cave, enlist some smart people to focus on a cyber attack world wide that then could be launched from anywhere, or multiple places? You could carry on your attack without the need for weapons and without the risk of exposure in a security conscious world. Every computer in the world then becomes a potential weapon.

While we do have to worry about the enemy getting a dirty bomb that could kill a lot of people and seriously hurt our nation and the world, the risk of uncovering such a plot is great. I think the enemy sees little risk in preparing for a cyber attack. Dick Cheney was dedicated to keeping a dirty bomb out of the hands of our enemies; I'm not sure, following the testimony of General Chilton, that his administration was preparing us for all of the threats in the 21st century.

Dick Cheney may not feel as secure as when he was running the show; but I have to tell you, I sure as hell feel a lot safer with Obama at the helm. I sincerely hope that Obama has the time to install the proper security measures, because Bush and company have squandered valuable time.

tomtoak