Via STRATFOR (Security Weekly) -
For many years now, STRATFOR has been carefully following the evolution of “Lashkar-e-Taiba” (LeT), the name of a Pakistan-based jihadist group that was formed in 1990 and existed until about 2001, when it was officially abolished. In subsequent years, however, several major attacks were attributed to LeT, including the November 2008 coordinated assault in Mumbai, India. Two years before that attack we wrote that the group, or at least its remnant networks, were nebulous but still dangerous. This nebulous nature was highlighted in November 2008 when the “Deccan Mujahideen,” a previously unknown group, claimed responsibility for the Mumbai attacks.
While the most famous leaders of the LeT networks, Hafiz Mohammad Saeed and Zaki-ur Rehman Lakhvi, are under house arrest and in jail awaiting trial, respectively, LeT still poses a significant threat. It’s a threat that comes not so much from LeT as a single jihadist force but LeT as a concept, a banner under which various groups and individuals can gather, coordinate and successfully conduct attacks.
Such is the ongoing evolution of the jihadist movement. And as this movement becomes more diffuse, it is important to look at brand-name jihadist groups like LeT, al Qaeda, the Haqqani network and Tehrik-e-Taliban Pakistan as loosely affiliated networks more than monolithic entities. With a debate under way between and within these groups over who to target and with major disruptions of their operations by various military and security forces, the need for these groups to work together in order to carry out sensational attacks has become clear. The result is a new, ad hoc template for jihadist operations that is not easily defined and even harder for government leaders to explain to their constituents and reporters to explain to their readers.
Thus, brand names like Lashkar-e-Taiba (which means Army of the Pure) will continue to be used in public discourse while the planning and execution of high-profile attacks grows ever more complex. While the threat posed by these networks to the West and to India may not be strategic, the possibility of disparate though well-trained militants working together and even with organized-crime elements does suggest a continuing tactical threat that is worth examining in more detail.
Read more: The Evolution of a Pakistani Militant Network
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Thursday, September 15, 2011
Al Qaeda Figure Reported Killed in Pakistan
Via CNN -
U.S. officials reported the death of an al Qaeda figure identified as the terrorist network's chief of operations in Pakistan, the latest in what they called a series of significant blows to the terrorist network.
Abu Hafs al-Shahri helped coordinate anti-American plots in the region and worked closely with Pakistani Taliban operatives to carry out attacks there, a U.S. official, speaking on condition of anonymity, told CNN Thursday. His cause of death was not disclosed, but the United States frequently uses armed aerial drones to target al Qaeda operatives inside Pakistan.
Al-Shahri was seen as a possible successor to al Qaeda's second-in-command, Atiyah Abdul Rahman, who was killed in late August, the U.S. official said. Little else was immediately known about him.
A senior Obama administration official said al-Shahri was killed earlier this week in northwest Pakistan. Pakistani intelligence officials reported Sunday [the 10th tenth anniversary of 9/11] that a suspected drone strike in the tribal district of north Waziristan, near the rugged border with Afghanistan, had killed three people, but the targets of the strike were not immediately known.
It's the latest in a series of losses among the top ranks of the terrorist network since the U.S. commando raid that killed its founder, Osama bin Laden, in May.
--------------------------------------------------------------
According to the Dawn.com (Pakistan)...
U.S. officials reported the death of an al Qaeda figure identified as the terrorist network's chief of operations in Pakistan, the latest in what they called a series of significant blows to the terrorist network.
Abu Hafs al-Shahri helped coordinate anti-American plots in the region and worked closely with Pakistani Taliban operatives to carry out attacks there, a U.S. official, speaking on condition of anonymity, told CNN Thursday. His cause of death was not disclosed, but the United States frequently uses armed aerial drones to target al Qaeda operatives inside Pakistan.
Al-Shahri was seen as a possible successor to al Qaeda's second-in-command, Atiyah Abdul Rahman, who was killed in late August, the U.S. official said. Little else was immediately known about him.
A senior Obama administration official said al-Shahri was killed earlier this week in northwest Pakistan. Pakistani intelligence officials reported Sunday [the 10th tenth anniversary of 9/11] that a suspected drone strike in the tribal district of north Waziristan, near the rugged border with Afghanistan, had killed three people, but the targets of the strike were not immediately known.
It's the latest in a series of losses among the top ranks of the terrorist network since the U.S. commando raid that killed its founder, Osama bin Laden, in May.
--------------------------------------------------------------
According to the Dawn.com (Pakistan)...
[Al-Shahri] also served as the militant group’s coordinator with the main Pakistani Taliban group, known as the TTP, according to the official.
Microsoft's Binary Planting Clean-Up Mission
Via ACROS Security -
Since our presentation of COM server-based binary planting exploits at the Hack in the Box conference in May this year, Microsoft has introduced a number of relevant changes to Windows and Internet Explorer.
[...]
Conclusion
Microsoft is clearly putting an effort into removing binary planting bugs from their code and introducing mitigations that help block various binary planting attack vectors. While we know there's still a lot of cleaning up to do in their binary planting closet, our research-oriented minds remain challenged to find new ways of exploiting these critical bugs and bypassing new and old countermeasures. In the end, it was our research that got the ball rolling and it would be a missed opportunity for everyone's security if we didn't leverage the current momentum and keep researching.
----------------------------------------------------------------------
Secunia's Windows Applications Insecure Library Loading List
http://secunia.com/advisories/windows_insecure_library_loading/
According to that list, Microsoft seems to be making good progress. Adobe and other vendors seem to be moving a bit slower on addressing these DLL loading vulnerabilities.
Since our presentation of COM server-based binary planting exploits at the Hack in the Box conference in May this year, Microsoft has introduced a number of relevant changes to Windows and Internet Explorer.
[...]
Conclusion
Microsoft is clearly putting an effort into removing binary planting bugs from their code and introducing mitigations that help block various binary planting attack vectors. While we know there's still a lot of cleaning up to do in their binary planting closet, our research-oriented minds remain challenged to find new ways of exploiting these critical bugs and bypassing new and old countermeasures. In the end, it was our research that got the ball rolling and it would be a missed opportunity for everyone's security if we didn't leverage the current momentum and keep researching.
----------------------------------------------------------------------
Secunia's Windows Applications Insecure Library Loading List
http://secunia.com/advisories/windows_insecure_library_loading/
According to that list, Microsoft seems to be making good progress. Adobe and other vendors seem to be moving a bit slower on addressing these DLL loading vulnerabilities.
Iran Blocks Tor; Tor Releases Same-day Fix
Via Tor Project -
Yesterday morning (in our timezones — that evening, in Iran), Iran added a filter rule to their border routers that recognized Tor traffic and blocked it. Thanks to help from a variety of friends around the world, we quickly discovered how they were blocking it and released a new version of Tor that isn't blocked. Fortunately, the fix is on the relay side: that means once enough relays and bridges upgrade, the many tens of thousands of Tor users in Iran will resume being able to reach the Tor network, without needing to change their software.
[...]
There are plenty of interesting discussion points from the research angle around how this arms race should be played. We're working on medium term and longer term solutions, but in the short term, there are other ways to filter Tor traffic like the one Iran used. Should we fix them all preemptively, meaning the next time they block us it will be through some more complex mechanism that's harder to figure out? Or should we leave things as they are, knowing there will be more blocking events but also knowing that we can solve them easily? Given that their last blocking attempt was in January 2011, I think it's smartest to collect some more data points first.
Yesterday morning (in our timezones — that evening, in Iran), Iran added a filter rule to their border routers that recognized Tor traffic and blocked it. Thanks to help from a variety of friends around the world, we quickly discovered how they were blocking it and released a new version of Tor that isn't blocked. Fortunately, the fix is on the relay side: that means once enough relays and bridges upgrade, the many tens of thousands of Tor users in Iran will resume being able to reach the Tor network, without needing to change their software.
[...]
There are plenty of interesting discussion points from the research angle around how this arms race should be played. We're working on medium term and longer term solutions, but in the short term, there are other ways to filter Tor traffic like the one Iran used. Should we fix them all preemptively, meaning the next time they block us it will be through some more complex mechanism that's harder to figure out? Or should we leave things as they are, knowing there will be more blocking events but also knowing that we can solve them easily? Given that their last blocking attempt was in January 2011, I think it's smartest to collect some more data points first.
Wednesday, September 14, 2011
Mexican Navy Smashes Zetas Cartel Communications Network
Via BBC -
The navy said it seized mobile radio transmitters and encryption equipment that the gang was using to coordinate its criminal activities.
At least 80 suspects have been arrested over the past month.
Founded by former army commandos, the Zetas are considered one of Mexico's most violent cartels.
Last month, the gang was blamed for an arson attack on a casino in the northern city of Monterrey which killed 52 people.
The Mexican navy said the operation against the Zetas in Veracruz was carried out by marine special forces after months of work by naval intelligence officers.
It said the gang had installed secure radio communications systems in at least 10 towns in Veracruz.
The network was being used to coordinate drug trafficking, kidnap, extortion and murder across much of the state.
Map of Mexico showing Veracruz
The equipment seized included high-powered transmitters, computers, radio scanners, encryption devices and solar power cells.
The immediate result of the operation was the disruption of the Zetas' "chain of command and tactical coordination" in Veracruz, navy spokesman Jose Luis Vergara said.
--------------------------------------------------------------------------
Borderland Beat has several videos showing the seized equipment.
The navy said it seized mobile radio transmitters and encryption equipment that the gang was using to coordinate its criminal activities.
At least 80 suspects have been arrested over the past month.
Founded by former army commandos, the Zetas are considered one of Mexico's most violent cartels.
Last month, the gang was blamed for an arson attack on a casino in the northern city of Monterrey which killed 52 people.
The Mexican navy said the operation against the Zetas in Veracruz was carried out by marine special forces after months of work by naval intelligence officers.
It said the gang had installed secure radio communications systems in at least 10 towns in Veracruz.
The network was being used to coordinate drug trafficking, kidnap, extortion and murder across much of the state.
Map of Mexico showing Veracruz
The equipment seized included high-powered transmitters, computers, radio scanners, encryption devices and solar power cells.
The immediate result of the operation was the disruption of the Zetas' "chain of command and tactical coordination" in Veracruz, navy spokesman Jose Luis Vergara said.
--------------------------------------------------------------------------
Borderland Beat has several videos showing the seized equipment.
Tuesday, September 13, 2011
RSA: APT Summit Findings
http://www.rsa.com/innovation/docs/APT_findings.pdf
On July 13 and 14, 2011, RSA and TechAmerica hosted an Advanced Persistent Threats Summit in Washington, D.C. The Summit brought together senior leaders from government and business to address both the impact of APTs and strategies for defense and mitigation. During the Summit, detailed perspectives on protecting against today’s most menacing information security threats surfaced. These findings, which are highlighted below, will be expanded upon in an in-depth report, scheduled to be published in the coming months.
------------------------------------------------------------------------------
For those with some APT knowledge, there isn't too much in this report that is a surprise. It will be interesting to see what is in the in-depth report.
Kudos to RSA for putting the closed-door summit together and making the information available to the community - even if it was only after being inducted into “the club” by an APT attack themselves.
On July 13 and 14, 2011, RSA and TechAmerica hosted an Advanced Persistent Threats Summit in Washington, D.C. The Summit brought together senior leaders from government and business to address both the impact of APTs and strategies for defense and mitigation. During the Summit, detailed perspectives on protecting against today’s most menacing information security threats surfaced. These findings, which are highlighted below, will be expanded upon in an in-depth report, scheduled to be published in the coming months.
------------------------------------------------------------------------------
For those with some APT knowledge, there isn't too much in this report that is a surprise. It will be interesting to see what is in the in-depth report.
Kudos to RSA for putting the closed-door summit together and making the information available to the community - even if it was only after being inducted into “the club” by an APT attack themselves.
APT: State-Sponsored Spies Collaborate with Crimeware Gang
Via The Register UK -
Hackers sponsored by the Chinese government and other nations are collaborating with profit-driven malware gangs to infiltrate corporate networks storing government secrets and other sensitive data, researchers say.
In many ways, the relationship between state-sponsored actors and organized crime groups that target online bank accounts resembles the kind of mutually benefiting alliances found in nature every day. Just as human intestines create the ideal environment for certain types of bacteria – and in turn receive crucial nutrients and digestive assistance – crimeware operators often cooperate with government-backed spies perpetrating the kinds of APTs, or advanced persistent threats, that have pillaged Google, RSA Security, and other US companies.
To the potential benefit of state-sponsored hackers, profit-driven malware gangs frequently have control of large numbers of infected machines belonging to government contractors and Fortune 500 companies. Because most of the machines never conduct business online, they may not represent much of an asset to the criminal gangs, which often allow the infected machines to sit dormant for months or years.
The same machines, however, can be a goldmine to spies hoping to plant APTs that steal weapons blueprints or other sensitive government data from adversaries. So rather than build an exploit from scratch, the APT actors can simply use botnets controlled by the attackers to access an infected machine on a sensitive network the spies want to infiltrate.
"Almost always, it's cheaper for them to do the latter," said Darien Kindlund, a senior staff scientist at FireEye, a network security firm. "What this means is there's an actually symbiotic relationship here."
In exchange for access to already-infected machines inside government contractors, state-sponsored actors often give malware gangs attack code that exploits previously unknown flaws in Microsoft's Internet Explorer and other widely used applications. As these zero-day vulnerabilities become known to people defending government contractor networks, the exploits quickly lose their value to APT actors. The same code, however, often has plenty of currency among gangs preying on smaller businesses and mom-and-pop end users.
[...]
In exchange for passing along malware hand-me-downs that are no longer needed, Kindlund said, APT groups get access to botnets operated by the criminal malware operators. For support, he cited a recently presented research from computer scientist Stefan Savage of the University of California at San Diego, and articles such as this one from security journalist Brian Krebs.
[...]
He went on to say the cooperation between the groups is so common that brokers now exist to help make trades it more efficient.
-------------------------------------------------------------------
I have heard security professionals discuss this threat over the past few years...at Defcon, at bars....but the time is coming, we will need to start discussing it with management.
That ZeuS might just be a ZeuS, but the possibility exist that the humans controlling it aren't looking for online banking information.
Hackers sponsored by the Chinese government and other nations are collaborating with profit-driven malware gangs to infiltrate corporate networks storing government secrets and other sensitive data, researchers say.
In many ways, the relationship between state-sponsored actors and organized crime groups that target online bank accounts resembles the kind of mutually benefiting alliances found in nature every day. Just as human intestines create the ideal environment for certain types of bacteria – and in turn receive crucial nutrients and digestive assistance – crimeware operators often cooperate with government-backed spies perpetrating the kinds of APTs, or advanced persistent threats, that have pillaged Google, RSA Security, and other US companies.
To the potential benefit of state-sponsored hackers, profit-driven malware gangs frequently have control of large numbers of infected machines belonging to government contractors and Fortune 500 companies. Because most of the machines never conduct business online, they may not represent much of an asset to the criminal gangs, which often allow the infected machines to sit dormant for months or years.
The same machines, however, can be a goldmine to spies hoping to plant APTs that steal weapons blueprints or other sensitive government data from adversaries. So rather than build an exploit from scratch, the APT actors can simply use botnets controlled by the attackers to access an infected machine on a sensitive network the spies want to infiltrate.
"Almost always, it's cheaper for them to do the latter," said Darien Kindlund, a senior staff scientist at FireEye, a network security firm. "What this means is there's an actually symbiotic relationship here."
In exchange for access to already-infected machines inside government contractors, state-sponsored actors often give malware gangs attack code that exploits previously unknown flaws in Microsoft's Internet Explorer and other widely used applications. As these zero-day vulnerabilities become known to people defending government contractor networks, the exploits quickly lose their value to APT actors. The same code, however, often has plenty of currency among gangs preying on smaller businesses and mom-and-pop end users.
[...]
In exchange for passing along malware hand-me-downs that are no longer needed, Kindlund said, APT groups get access to botnets operated by the criminal malware operators. For support, he cited a recently presented research from computer scientist Stefan Savage of the University of California at San Diego, and articles such as this one from security journalist Brian Krebs.
[...]
He went on to say the cooperation between the groups is so common that brokers now exist to help make trades it more efficient.
-------------------------------------------------------------------
I have heard security professionals discuss this threat over the past few years...at Defcon, at bars....but the time is coming, we will need to start discussing it with management.
That ZeuS might just be a ZeuS, but the possibility exist that the humans controlling it aren't looking for online banking information.
SPITMO: First SpyEye Attack on Android Mobile Platform Now in the Wild
Via Net-Security.org -
The first SpyEye variant, called SPITMO, has been spotted attacking Android devices in the wild. According to Amit Klein, Trusteer’s chief technology officer, the threat posed by DriodOS/Spitmo has escalated the danger of SpyEye now that this malicious software has been able to shift its delivery and infection methods.
“We always said it was just a matter of time before the true potential of Spitmo was realized," says Klein. "When it first emerged [for the Symbian OS] back in April, F-Secure reported in its blog that it was targeting European banks. The trojan injected fields into a bank's webpage asking the customer to input his mobile phone number and the IMEI of the phone. The fraudster then needed to follow a cumbersome three stage sequence - get the IMEI number; generate a certificate; then release an updated installer. This process could take up to three days."
“We couldn’t believe fraudsters would go to that much effort just to steal a couple of SMSs - and it appears we were right," he says. "Information gathered by Trusteer's Intelligence Centre has discovered a new far more intuitive, and modern, approach of SPITMO for Android now active in the wild.”
[...]
Once the Trojan has successfully installed [on the Android device], all incoming SMS messages are intercepted and transferred to the attacker’s Command and Control server. A code snippet is run when an SMS is received, creating a string, which will later be appended as a query string to a GET HTTP request, to be sent to the attacker's drop zone.
[...]
What makes all of this so scary is that the application is not visible on the device’s dashboard, making it virtually undetectable, so users are not aware of its presence and will struggle to get rid of it."
-----------------------------------------------------------------------------------------------
Readers should keep in mind these Spitmo (SpyEye in the Mobile) and Zitmo (ZeuS in the Mobile) attacks are not purely mobile OS level attacks, they are really blended malware attacks.
Spimto & Zitmo: Attack Begins on the Desktop, But Increasingly Has Mobile Components
In the Spitmo case outlined by Trusteer above, the attack begins when the victim's PC is infected with this new variant of SpyEye. Once the victim visit their online banking website (on their PC), the malware injects a "new" security measure message on the website - which advises the user to download a Android application which is "mandatory in order to use its online banking service." The new measure pretends to be an Android application that protects the phone’s SMS messages from being intercepted and will protect the user against fraud.
The Zitmo attack outlined by Fortinet in September 2010 follows a similar pattern. The attack begins when the victim's PC is infected with this variant of ZeuS. It injects a message into the user's browser upon visiting the online banking website, asking for the user's phone number and phone model. Based on that info, it sends an SMS with a link to the appropriate version of the malicious package (a Symbian package for Symbian phones, a BlackBerry Jar for BlackBerry phones, etc).
Threat Mitigation Recommendations
With this deeper understanding of the Spimto/Zistmo attacks, it is clear desktop based protection is still critically important to mitigate these of blended desktop/mobile malware attacks. As always, multi-layered security system on the desktop is recommended to ensure a high-level of protection. However, it is likely, the mobile components of these blended attacks will grow more advanced (and perhaps more independent) as the mobile devices themselves grow more powerful and mobile banking becomes more common.
The first SpyEye variant, called SPITMO, has been spotted attacking Android devices in the wild. According to Amit Klein, Trusteer’s chief technology officer, the threat posed by DriodOS/Spitmo has escalated the danger of SpyEye now that this malicious software has been able to shift its delivery and infection methods.
“We always said it was just a matter of time before the true potential of Spitmo was realized," says Klein. "When it first emerged [for the Symbian OS] back in April, F-Secure reported in its blog that it was targeting European banks. The trojan injected fields into a bank's webpage asking the customer to input his mobile phone number and the IMEI of the phone. The fraudster then needed to follow a cumbersome three stage sequence - get the IMEI number; generate a certificate; then release an updated installer. This process could take up to three days."
“We couldn’t believe fraudsters would go to that much effort just to steal a couple of SMSs - and it appears we were right," he says. "Information gathered by Trusteer's Intelligence Centre has discovered a new far more intuitive, and modern, approach of SPITMO for Android now active in the wild.”
[...]
Once the Trojan has successfully installed [on the Android device], all incoming SMS messages are intercepted and transferred to the attacker’s Command and Control server. A code snippet is run when an SMS is received, creating a string, which will later be appended as a query string to a GET HTTP request, to be sent to the attacker's drop zone.
[...]
What makes all of this so scary is that the application is not visible on the device’s dashboard, making it virtually undetectable, so users are not aware of its presence and will struggle to get rid of it."
-----------------------------------------------------------------------------------------------
Readers should keep in mind these Spitmo (SpyEye in the Mobile) and Zitmo (ZeuS in the Mobile) attacks are not purely mobile OS level attacks, they are really blended malware attacks.
Spimto & Zitmo: Attack Begins on the Desktop, But Increasingly Has Mobile Components
In the Spitmo case outlined by Trusteer above, the attack begins when the victim's PC is infected with this new variant of SpyEye. Once the victim visit their online banking website (on their PC), the malware injects a "new" security measure message on the website - which advises the user to download a Android application which is "mandatory in order to use its online banking service." The new measure pretends to be an Android application that protects the phone’s SMS messages from being intercepted and will protect the user against fraud.
The Zitmo attack outlined by Fortinet in September 2010 follows a similar pattern. The attack begins when the victim's PC is infected with this variant of ZeuS. It injects a message into the user's browser upon visiting the online banking website, asking for the user's phone number and phone model. Based on that info, it sends an SMS with a link to the appropriate version of the malicious package (a Symbian package for Symbian phones, a BlackBerry Jar for BlackBerry phones, etc).
Threat Mitigation Recommendations
With this deeper understanding of the Spimto/Zistmo attacks, it is clear desktop based protection is still critically important to mitigate these of blended desktop/mobile malware attacks. As always, multi-layered security system on the desktop is recommended to ensure a high-level of protection. However, it is likely, the mobile components of these blended attacks will grow more advanced (and perhaps more independent) as the mobile devices themselves grow more powerful and mobile banking becomes more common.
Monday, September 12, 2011
A New and Improved Moore's Law
Via MIT Technology Review -
Researchers have, for the first time, shown that the energy efficiency of computers doubles roughly every 18 months.
The conclusion, backed up by six decades of data, mirrors Moore's law, the observation from Intel founder Gordon Moore that computer processing power doubles about every 18 months. But the power-consumption trend might have even greater relevance than Moore's law as battery-powered devices—phones, tablets, and sensors—proliferate.
"The idea is that at a fixed computing load, the amount of battery you need will fall by a factor of two every year and a half," says Jonathan Koomey, consulting professor of civil and environmental engineering at Stanford University and lead author of the study. More mobile computing and sensing applications become possible, Koomey says, as energy efficiency continues its steady improvement.
The research, conducted in collaboration with Intel and Microsoft, examined peak power consumption of electronic computing devices since the construction of the Electronic Numerical Integrator and Computer (ENIAC) in 1956. The first general purpose computer, the ENIAC was used to calculate artillery firing tables for the U.S. Army, and it could perform a few hundred calculations per second. It used vacuum tubes rather than transistors, took up 1,800 square feet, and consumed 150 kilowatts of power.
Even before the advent of discrete transistors, Koomey says, energy efficiency doubled every 18 months. "This is a fundamental characteristic of information technology that uses electrons for switching," he says. "It's not just a function of the components on a chip."
[...]
In July, Koomey released a report that showed, among other findings, that the electricity used in data centers worldwide increased by about 56 percent from 2005 to 2010—a much lower rate than the doubling that was observed from 2000 to 2005.
While better energy efficiency played a part in this change, the total electricity used in data centers was less than the forecast for 2010 in part because fewer new servers were installed than expected due to technologies such as virtualization, which allowed existing systems to run more programs simultaneously. Koomey notes that data center computers rarely run at peak power. Most computers are, in fact, "terribly underutilized," he says.
[...]
"Everyone's familiar with Moore's law and the remarkable improvements in the power of computers, and that's obviously important," says Erik Brynjolfsson, professor of the Sloan School of Management at MIT. But people are paying more attention to the battery life of their electronics as well as how fast they can run. "I think that's more and more the dimension that matters to consumers," Brynjolfsson says. "And in a sense, 'Koomey's law,' this trend of power consumption, is beginning to eclipse Moore's law for what matters to consumers in a lot of applications."
To Koomey, the most interesting aspect of the trend is thinking about the possibilities for computing. The theoretical limits are still so far away, he says. In 1985, the physicist Richard Feynman analyzed the electricity needs for computers and estimated that efficiency could theoretically improve by a factor of 100 billion before it hit a limit, excluding new technologies such as quantum computing. Since then, efficiency improvements have been about 40,000. "There's so far to go," says Koomey. "It's only limited by our cleverness, not the physics."
Researchers have, for the first time, shown that the energy efficiency of computers doubles roughly every 18 months.
The conclusion, backed up by six decades of data, mirrors Moore's law, the observation from Intel founder Gordon Moore that computer processing power doubles about every 18 months. But the power-consumption trend might have even greater relevance than Moore's law as battery-powered devices—phones, tablets, and sensors—proliferate.
"The idea is that at a fixed computing load, the amount of battery you need will fall by a factor of two every year and a half," says Jonathan Koomey, consulting professor of civil and environmental engineering at Stanford University and lead author of the study. More mobile computing and sensing applications become possible, Koomey says, as energy efficiency continues its steady improvement.
The research, conducted in collaboration with Intel and Microsoft, examined peak power consumption of electronic computing devices since the construction of the Electronic Numerical Integrator and Computer (ENIAC) in 1956. The first general purpose computer, the ENIAC was used to calculate artillery firing tables for the U.S. Army, and it could perform a few hundred calculations per second. It used vacuum tubes rather than transistors, took up 1,800 square feet, and consumed 150 kilowatts of power.
Even before the advent of discrete transistors, Koomey says, energy efficiency doubled every 18 months. "This is a fundamental characteristic of information technology that uses electrons for switching," he says. "It's not just a function of the components on a chip."
[...]
In July, Koomey released a report that showed, among other findings, that the electricity used in data centers worldwide increased by about 56 percent from 2005 to 2010—a much lower rate than the doubling that was observed from 2000 to 2005.
While better energy efficiency played a part in this change, the total electricity used in data centers was less than the forecast for 2010 in part because fewer new servers were installed than expected due to technologies such as virtualization, which allowed existing systems to run more programs simultaneously. Koomey notes that data center computers rarely run at peak power. Most computers are, in fact, "terribly underutilized," he says.
[...]
"Everyone's familiar with Moore's law and the remarkable improvements in the power of computers, and that's obviously important," says Erik Brynjolfsson, professor of the Sloan School of Management at MIT. But people are paying more attention to the battery life of their electronics as well as how fast they can run. "I think that's more and more the dimension that matters to consumers," Brynjolfsson says. "And in a sense, 'Koomey's law,' this trend of power consumption, is beginning to eclipse Moore's law for what matters to consumers in a lot of applications."
To Koomey, the most interesting aspect of the trend is thinking about the possibilities for computing. The theoretical limits are still so far away, he says. In 1985, the physicist Richard Feynman analyzed the electricity needs for computers and estimated that efficiency could theoretically improve by a factor of 100 billion before it hit a limit, excluding new technologies such as quantum computing. Since then, efficiency improvements have been about 40,000. "There's so far to go," says Koomey. "It's only limited by our cleverness, not the physics."
DEFCON 19 - Presentations
https://www.defcon.org/html/links/dc-archives/dc-19-archive.html
Normally I put a small description of the conference here, but ultimately if you don't know what Defcon is...you most likley don't care to see these presentations ;)
Normally I put a small description of the conference here, but ultimately if you don't know what Defcon is...you most likley don't care to see these presentations ;)
Fighting Targeted Malware: Why Signatures, Behaviour Blocking and White-listing are Not Enough
http://afitc.gunter.af.mil/2011Presentations/SeminarSessions/Symantec%20-%20Fighting%20Targeted%20Malware.pdf
I believe the presentation makes several good points, once you look beyond the "Hey! Check out Symantec's new reputation push" propaganda...
I believe the presentation makes several good points, once you look beyond the "Hey! Check out Symantec's new reputation push" propaganda...
- Malware authors have switched tactics...
- From: a mass distribution of relatively few threats (e.g. Storm)
- To: a micro distribution model (e.g. average Vundo variant is pushed to only 18 Symantec users).
Sunday, September 11, 2011
5 Coolest Features of One World Trade Center
http://dsc.discovery.com/tv/the-rising/ground-zero-info/5-coolest-features-wtc.html
In the wake of the wreckage that occurred on Sept. 11, 2001, there's been much talk of reconstruction — both emotional and physical. Now, solid, visual evidence of that reconstruction is beginning to rise like a phoenix from Ground Zero at New York City's southern tip. When completed, One World Trade Center (One WTC) will stand as North America's tallest building — a glass and steel symbol of resiliency, as well as scientific and architectural triumph.
One World Trade Center faced a few challenges along the way. Not only did the $3.1 billion-dollar structure need to be attractive, it had to be the most secure office building ever constructed. In addition, because One World Trade Center is part of the larger reconstruction effort taking place on the grounds of the former Twin Towers, the coordination with other onsite projects presented a logistics nightmare — especially since commuter trains run through the center of the construction at ground zero day and night.
The plans for Ground Zero are finalized, and from them a skyscraper is emerging that will dazzle the eyes and perhaps knock your socks off. Take a tour of One WTC with us and check out some of the coolest features from one of the most-watched construction projects in history.
------------------------------------------------------------------------
The technology, the materials, the security and the beauty of the building is just utterly amazing.
In the wake of the wreckage that occurred on Sept. 11, 2001, there's been much talk of reconstruction — both emotional and physical. Now, solid, visual evidence of that reconstruction is beginning to rise like a phoenix from Ground Zero at New York City's southern tip. When completed, One World Trade Center (One WTC) will stand as North America's tallest building — a glass and steel symbol of resiliency, as well as scientific and architectural triumph.
One World Trade Center faced a few challenges along the way. Not only did the $3.1 billion-dollar structure need to be attractive, it had to be the most secure office building ever constructed. In addition, because One World Trade Center is part of the larger reconstruction effort taking place on the grounds of the former Twin Towers, the coordination with other onsite projects presented a logistics nightmare — especially since commuter trains run through the center of the construction at ground zero day and night.
The plans for Ground Zero are finalized, and from them a skyscraper is emerging that will dazzle the eyes and perhaps knock your socks off. Take a tour of One WTC with us and check out some of the coolest features from one of the most-watched construction projects in history.
------------------------------------------------------------------------
The technology, the materials, the security and the beauty of the building is just utterly amazing.
STRATFOR Dispatch: Somalia's Transitional Federal Government and al Shabaab
http://www.stratfor.com/analysis/20110907-dispatch-somalias-transitional-federal-government-and-al-shabaab
Analyst Mark Schroeder examines the limited governing ability of Somalia’s Transitional Federal Government even though African Union Peacekeeping Mission is providing robust security against al Shabaab in Mogadishu.
-------------------------------------------------------------------
Beyond the current status of the TFG, Mark outlines the three main factions that make up the collective al Shabaab...
Analyst Mark Schroeder examines the limited governing ability of Somalia’s Transitional Federal Government even though African Union Peacekeeping Mission is providing robust security against al Shabaab in Mogadishu.
-------------------------------------------------------------------
Beyond the current status of the TFG, Mark outlines the three main factions that make up the collective al Shabaab...
The three main groups or factions that once contributed to al Shabaab are really separate entities right now. The leader of the transnationalist faction of al Shabaab, led by an individual named Godane Abu Zubayr, he continues to espouse jihadist rhetoric in calling for a continued fight against the TFG. The two other main factions that comprise al Shabaab: one is led by a Mukhtar Robow Abu Mansur; the other led by Sheikh Hassan Dahir Aweys. Aweys’ faction is more commonly known as Hezbollah Islam.
Each of these two groups are pulled back to their respective home areas. For Robow, that is around the city of Baidoa in the Bay and Bakool regions. For Aweys, it is in Afgoye in the greater Mogadishu area or Bandadir region. Those groups, while they are still making public appearances, public statements, carrying out occasional defensive-oriented clashes, are not really taking any fight whatsoever to the TFG.
Saturday, September 10, 2011
GlobalSign Says Web Server Was Hacked, But No Signs of CA Breach
Via Threatpost.com -
GlobalSign has found evidence that its main Web server was compromised recently, but has not discovered any indications that its certificate authority infrastructure was hacked, contrary to claims by the attacker responsible for the DigiNotar CA hack.
The company, which is one of the larger CAs in the world, has been investigating claims by the Comodohacker that he has penetrated the GlobalSign CA infrastructure. It has retained Fox-IT, the same company that did the forensics of DigiNotar's systems in the wake of its attack, and GlobalSign has suspended its issuance of digital certificates until at least Monday while it finishes the investigation.
However, the company said on Friday that it had not found any direct evidence of a breach of its certificate authority systems.
Today we found evidence of a breach to the web server hosting the www website. The breached web server has always been isolated from all other infrastructure and is used only to serve the www.globalsign.com website. At present there is no further evidence of breach other than the isolated www web server. As an additional precaution, we continue to monitor all activity to all services closely. The investigation and high threat approach to returning services to normal continues," the GlobalSign statement said.
[...]
GlobalSign has said that it plans to bring some of its CA services back online on Monday. The fact that no evidence of a breach has been found so far clearly doesn't rule out the possibility that the attacker did indeed compromise the GlobalSign CA, but just means that the investigation hasn't turned up concrete evidence of an intrusion.
GlobalSign has found evidence that its main Web server was compromised recently, but has not discovered any indications that its certificate authority infrastructure was hacked, contrary to claims by the attacker responsible for the DigiNotar CA hack.
The company, which is one of the larger CAs in the world, has been investigating claims by the Comodohacker that he has penetrated the GlobalSign CA infrastructure. It has retained Fox-IT, the same company that did the forensics of DigiNotar's systems in the wake of its attack, and GlobalSign has suspended its issuance of digital certificates until at least Monday while it finishes the investigation.
However, the company said on Friday that it had not found any direct evidence of a breach of its certificate authority systems.
Today we found evidence of a breach to the web server hosting the www website. The breached web server has always been isolated from all other infrastructure and is used only to serve the www.globalsign.com website. At present there is no further evidence of breach other than the isolated www web server. As an additional precaution, we continue to monitor all activity to all services closely. The investigation and high threat approach to returning services to normal continues," the GlobalSign statement said.
[...]
GlobalSign has said that it plans to bring some of its CA services back online on Monday. The fact that no evidence of a breach has been found so far clearly doesn't rule out the possibility that the attacker did indeed compromise the GlobalSign CA, but just means that the investigation hasn't turned up concrete evidence of an intrusion.
Friday, September 9, 2011
China Fears ‘Toxic’ Rumours
Via The Diplomat -
No governments have ever succeeded in banning rumours. But that hasn’t stopped many from trying. The latest to do so is Beijing. Irked by what it deems as malicious rumours spread through the Internet, and microblogs in particular, the Chinese government has recently announced a crackdown on the so-called ‘toxic’ Internet rumours.
The immediate triggers of China’s latest crackdown were most likely related to the outpouring of public outrage on the Internet over the crash of two high-speed trains in late July, and to the role played by the Internet in mobilizing the protest by residents of Dalian that forced the local government to promise to relocate a (truly) toxic petrochemical complex.
But the Chinese authorities also seem to have good reason to attempt the impossible – the advent of the Internet and microblogs has now greatly amplified the impact of rumours. On occasion, rumours have led to tragedies and riots. In one incident that occurred in the early hours of February 10 this year, for instance, rumours that a chemical plant in Xiangshui county in Jiangsu Province was about to explode sent more than ten thousand local residents into a panicked flight. Four people died and many were injured in the resulting traffic accidents.
Based on previous records of rumour-suppression, China’s latest crackdown doesn’t look promising. The reason isn’t that Beijing lacks the muscle or resolve – Chinese censors are hardworking servants of the state and can be counted on to devise ingenious measures to combat rumours. But fighting rumours in the Chinese social and political contexts requires much more than relentless censorship. First and foremost, Chinese leaders worried about the harmful effects of rumours must understand that the influence of rumours is directly and positively correlated with the lack of press freedom and the decline of government credibility. In other words, in a society ruled by an authoritarian regime that tolerates little freedom of the press, but which has an incentive structure that encourages its officials to fabricate critical data (such as GDP growth, inflation, and housing prices) and cover up accidents and communicable diseases, rumours are bound to flourish.
Indeed, when we compare how rumours fare in autocracies and democracies, the difference is huge. To be sure, rumours are concocted and spread in all societies. But those ruled by autocratic elites are far more vulnerable to their impact because these societies have no independent and free press that enjoys public confidence and can quickly discredit rumours through their fact-based reporting. In democracies, rumours can seldom cause mass panic or riots because a free press quickly acts as an antidote.
So a long-term and more effective measure to contain the harm of rumours in China is to allow greater press freedom. Sadly, that doesn’t seem to be in the cards.
No governments have ever succeeded in banning rumours. But that hasn’t stopped many from trying. The latest to do so is Beijing. Irked by what it deems as malicious rumours spread through the Internet, and microblogs in particular, the Chinese government has recently announced a crackdown on the so-called ‘toxic’ Internet rumours.
The immediate triggers of China’s latest crackdown were most likely related to the outpouring of public outrage on the Internet over the crash of two high-speed trains in late July, and to the role played by the Internet in mobilizing the protest by residents of Dalian that forced the local government to promise to relocate a (truly) toxic petrochemical complex.
But the Chinese authorities also seem to have good reason to attempt the impossible – the advent of the Internet and microblogs has now greatly amplified the impact of rumours. On occasion, rumours have led to tragedies and riots. In one incident that occurred in the early hours of February 10 this year, for instance, rumours that a chemical plant in Xiangshui county in Jiangsu Province was about to explode sent more than ten thousand local residents into a panicked flight. Four people died and many were injured in the resulting traffic accidents.
Based on previous records of rumour-suppression, China’s latest crackdown doesn’t look promising. The reason isn’t that Beijing lacks the muscle or resolve – Chinese censors are hardworking servants of the state and can be counted on to devise ingenious measures to combat rumours. But fighting rumours in the Chinese social and political contexts requires much more than relentless censorship. First and foremost, Chinese leaders worried about the harmful effects of rumours must understand that the influence of rumours is directly and positively correlated with the lack of press freedom and the decline of government credibility. In other words, in a society ruled by an authoritarian regime that tolerates little freedom of the press, but which has an incentive structure that encourages its officials to fabricate critical data (such as GDP growth, inflation, and housing prices) and cover up accidents and communicable diseases, rumours are bound to flourish.
Indeed, when we compare how rumours fare in autocracies and democracies, the difference is huge. To be sure, rumours are concocted and spread in all societies. But those ruled by autocratic elites are far more vulnerable to their impact because these societies have no independent and free press that enjoys public confidence and can quickly discredit rumours through their fact-based reporting. In democracies, rumours can seldom cause mass panic or riots because a free press quickly acts as an antidote.
So a long-term and more effective measure to contain the harm of rumours in China is to allow greater press freedom. Sadly, that doesn’t seem to be in the cards.
DigiNotar Debacle: Apple Certificate Trust Policy Update
http://support.apple.com/kb/HT4920
Security Update 2011-005
Certificate Trust Policy
Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.1, Lion Server v10.7.1
Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information
Description: Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted.
-----------------------------------------------------------------
After remaining silence for more than a week, Apple has finally released an update for OSX to deal with the DigiNotar hack fallout. Now what about iOS??
Security Update 2011-005
Certificate Trust Policy
Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.1, Lion Server v10.7.1
Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information
Description: Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted.
-----------------------------------------------------------------
After remaining silence for more than a week, Apple has finally released an update for OSX to deal with the DigiNotar hack fallout. Now what about iOS??
Wednesday, September 7, 2011
HUJI Claims Bombing at Delhi High Court
Via The Long War Journal -
A Pakistan-based terrorist group that is closely linked to al Qaeda has claimed credit for a bombing today that killed 11 people and wounded scores more at a security checkpoint outside the Delhi High Court.
A bomb planted in a briefcase was detonated at a queue where lawyers and other visitors obtain security passes. Police said that 11 people have been killed so far and 76 more were wounded, some critically. The blast left a "deep crater" in the ground.
The Harkat-ul-Jihad-al-Islami, or HUJI, said it detonated the bomb to force India to repeal a death sentence of Afzal Guru, who has been placed on death row for the December 2001 terror assault on the Indian Parliament that killed six policemen, a civilian, and five members of the assault team. The Pakistan-based Lashakr-e-Taiba and Jaish-e-Mohammad carried out the 2001 attack in Delhi.
HUJI sent an email to Indian news agencies immediately after the attack to claim it.
"We owe the responsibility of todays blasts at high court delhi..... our demand is that Afzal Guru's death sentence should be repealede immediately else we would target major high courts & THE SUPREME COURT OF... [sic]," the email read, according to the Hindustan Times.
HUJI is an al Qaeda-linked group that operates in Pakistan, India, Afghanistan, and Bangladesh. The US designated HUJI as a terrorist entity in 2010, and its leader, Ilyas Kashmiri, was also added to the list of global terrorists.
Kashmiri has also been linked to Pakistan's Inter-Services Intelligence directorate, which has viewed him as an asset due to his prowess in fighting the Indians in Jammu and Kashmir.
The US believes Kashmiri was killed in a Predator airstrike in South Waziristan on June 3. But questions have emerged about Kashmiri's death, as the martyrdom statement is suspect and a photo of Kashmiri's purported corpse was actually that of a Lashkar-e-Taiba operative who was killed during the terror assault on Mumbai in November 2008. Indian intelligence officials now believe that Kashmiri faked his death in an attempt to dodge the Predators and the US special operations forces who entered Pakistan to kill bin Laden.
[For more information on problems with reports of Kashmiri's death, see LWJ report, Questions emerge over HUJI's statement on al Qaeda leader Ilyas Kashmiri's death, and Threat Matrix reports, Is Ilyas Kashmiri really dead? and Kashmiri faked death: Indian intelligence.]
------------------------------------------------------------------------------
Wikipedia - Harkat-ul-Jihad-al-Islami (HuJI)
http://en.wikipedia.org/wiki/Harkat-ul-Jihad_al-Islami
A Pakistan-based terrorist group that is closely linked to al Qaeda has claimed credit for a bombing today that killed 11 people and wounded scores more at a security checkpoint outside the Delhi High Court.
A bomb planted in a briefcase was detonated at a queue where lawyers and other visitors obtain security passes. Police said that 11 people have been killed so far and 76 more were wounded, some critically. The blast left a "deep crater" in the ground.
The Harkat-ul-Jihad-al-Islami, or HUJI, said it detonated the bomb to force India to repeal a death sentence of Afzal Guru, who has been placed on death row for the December 2001 terror assault on the Indian Parliament that killed six policemen, a civilian, and five members of the assault team. The Pakistan-based Lashakr-e-Taiba and Jaish-e-Mohammad carried out the 2001 attack in Delhi.
HUJI sent an email to Indian news agencies immediately after the attack to claim it.
"We owe the responsibility of todays blasts at high court delhi..... our demand is that Afzal Guru's death sentence should be repealede immediately else we would target major high courts & THE SUPREME COURT OF... [sic]," the email read, according to the Hindustan Times.
HUJI is an al Qaeda-linked group that operates in Pakistan, India, Afghanistan, and Bangladesh. The US designated HUJI as a terrorist entity in 2010, and its leader, Ilyas Kashmiri, was also added to the list of global terrorists.
Kashmiri has also been linked to Pakistan's Inter-Services Intelligence directorate, which has viewed him as an asset due to his prowess in fighting the Indians in Jammu and Kashmir.
The US believes Kashmiri was killed in a Predator airstrike in South Waziristan on June 3. But questions have emerged about Kashmiri's death, as the martyrdom statement is suspect and a photo of Kashmiri's purported corpse was actually that of a Lashkar-e-Taiba operative who was killed during the terror assault on Mumbai in November 2008. Indian intelligence officials now believe that Kashmiri faked his death in an attempt to dodge the Predators and the US special operations forces who entered Pakistan to kill bin Laden.
[For more information on problems with reports of Kashmiri's death, see LWJ report, Questions emerge over HUJI's statement on al Qaeda leader Ilyas Kashmiri's death, and Threat Matrix reports, Is Ilyas Kashmiri really dead? and Kashmiri faked death: Indian intelligence.]
------------------------------------------------------------------------------
Wikipedia - Harkat-ul-Jihad-al-Islami (HuJI)
http://en.wikipedia.org/wiki/Harkat-ul-Jihad_al-Islami
On August 6, 2010 the United States and the United Nations designated Harakat-ul Jihad al-Islami as a foreign terror group and blacklisted its commander Ilyas Kashmiri. State Department counterterrorism coordinator Daniel Benjamin asserted that the actions taken demonstrated the global community's resolve to counter the group's threat. "The linkages between HUJI and Al-Qaeda are clear, and today's designations convey the operational relationship between these organizations," Benjamin said.
MANPADS: Surface-to-Air Missiles Looted from Tripoli Arms Warehouse
Via CNN -
A potent stash of Russian-made surface-to-air missiles is missing from a huge Tripoli weapons warehouse amid reports of weapons looting across war-torn Libya.
They are Grinch SA-24 shoulder-launched missiles, also known as Igla-S missiles, the equivalent of U.S.-made Stinger missiles.
A CNN team and Human Rights Watch found dozens of empty crates marked with packing lists and inventory numbers that identified the items as Igla-S surface-to-air missiles.
[...]
Grinch SA-24s are designed to target front-line aircraft, helicopters, cruise missiles and drones. They can shoot down a plane flying as high as 11,000 feet and can travel 19,000 feet straight out.
Fighters aligned with the National Transitional Council and others swiped armaments from the storage facility, witnesses told Human Rights Watch. The warehouse is located near a base of the Khamis Brigade, a special forces unit in Gadhafi's military, in the southeastern part of the capital.
The warehouse contains mortars and artillery rounds, but there are empty crates for those items as well. There are also empty boxes for another surface-to-air missile, the SA-7.
Peter Bouckaert, Human Rights Watch emergencies director, told CNN he has seen the same pattern in armories looted elsewhere in Libya, noting that "in every city we arrive, the first thing to disappear are the surface-to-air missiles."
There was no immediate comment from NTC officials.
The lack of security at the weapons site raises concerns about stability in post-Gadhafi Libya and whether the new NTC leadership is doing enough to stop the weapons from getting into the wrong hands.
A NATO official, who asked to not be named because he was not authorized to speak publicly on the matter, said 575 surface-to-air missiles, radar systems and sites or storage facilities were hit by NATO airstrikes and either damaged or destroyed between March 31 and Saturday. He didn't elaborate on the specifics about the targets.
Gen. Carter Ham, chief of U.S. Africa Command, has said he's concerned about the proliferation of weapons, most notably the shoulder-fired surface-to-air missiles. He said there were about 20,000 in Libya when the international operation began earlier this year and many of them have not been accounted for.
"That's going to be a concern for some period of time," he said in April.
-------------------------------------------------------------------------------
According to a Bloomberg report...
A potent stash of Russian-made surface-to-air missiles is missing from a huge Tripoli weapons warehouse amid reports of weapons looting across war-torn Libya.
They are Grinch SA-24 shoulder-launched missiles, also known as Igla-S missiles, the equivalent of U.S.-made Stinger missiles.
A CNN team and Human Rights Watch found dozens of empty crates marked with packing lists and inventory numbers that identified the items as Igla-S surface-to-air missiles.
[...]
Grinch SA-24s are designed to target front-line aircraft, helicopters, cruise missiles and drones. They can shoot down a plane flying as high as 11,000 feet and can travel 19,000 feet straight out.
Fighters aligned with the National Transitional Council and others swiped armaments from the storage facility, witnesses told Human Rights Watch. The warehouse is located near a base of the Khamis Brigade, a special forces unit in Gadhafi's military, in the southeastern part of the capital.
The warehouse contains mortars and artillery rounds, but there are empty crates for those items as well. There are also empty boxes for another surface-to-air missile, the SA-7.
Peter Bouckaert, Human Rights Watch emergencies director, told CNN he has seen the same pattern in armories looted elsewhere in Libya, noting that "in every city we arrive, the first thing to disappear are the surface-to-air missiles."
There was no immediate comment from NTC officials.
The lack of security at the weapons site raises concerns about stability in post-Gadhafi Libya and whether the new NTC leadership is doing enough to stop the weapons from getting into the wrong hands.
A NATO official, who asked to not be named because he was not authorized to speak publicly on the matter, said 575 surface-to-air missiles, radar systems and sites or storage facilities were hit by NATO airstrikes and either damaged or destroyed between March 31 and Saturday. He didn't elaborate on the specifics about the targets.
Gen. Carter Ham, chief of U.S. Africa Command, has said he's concerned about the proliferation of weapons, most notably the shoulder-fired surface-to-air missiles. He said there were about 20,000 in Libya when the international operation began earlier this year and many of them have not been accounted for.
"That's going to be a concern for some period of time," he said in April.
-------------------------------------------------------------------------------
According to a Bloomberg report...
There is evidence that a small number of Soviet-made SA-7 anti-aircraft missiles from Qaddafi’s arsenal have reached the black market in Mali, where al-Qaeda in the Islamic Maghreb (AQIM) is active, according to two U.S. government officials not authorized to speak on the record.
Tuesday, September 6, 2011
9/11: How The Twin Towers Were Built
The 110-storey landmarks that dominated the Manhattan skyline for nearly 30 years were reduced to rubble in the 9/11 suicide attacks of 2001. Thousands of people in the World Trade Center, and on the planes that crashed into them, lost their lives.
Designed by architect Minoru Yamasaki, the giant towers were conceived as part of an urban renewal project for Lower Manhattan - and when completed in the early 1970s, for a short time at least, were the world's tallest buildings.
Now - a decade since they were lost, and with new construction on the site well-advanced - take a look back at the life of New York's twin towers.
http://www.bbc.co.uk/news/magazine-14634600 (7 min video)
Designed by architect Minoru Yamasaki, the giant towers were conceived as part of an urban renewal project for Lower Manhattan - and when completed in the early 1970s, for a short time at least, were the world's tallest buildings.
Now - a decade since they were lost, and with new construction on the site well-advanced - take a look back at the life of New York's twin towers.
http://www.bbc.co.uk/news/magazine-14634600 (7 min video)
Microsoft Revokes Trust in Five DigiNotar Root Certs
Via Threatpost.com -
The fallout from the DigiNotar compromise continued on Tuesday, as Microsoft said it has now revoked its trust of all five of the certificate authority's root certificates. The update that makes this change is being pushed out to users on all supported versions of Windows.
The move by Microsoft effectively makes any certificate that has been issued by DigiNotar untrusted by Internet Explorer and other Windows applications. Any IE user who visits a site that presents a DigiNotar-issued certificate as proof of identity will get an error message telling him that the certificate isn't trusted. Microsoft's change applies to these root certificates from DigiNotar:
The company posted a message on its corporate Twitter feed, saying: "We are aware of the Comodo hacker BLOG that claims access to a number of major CAs including GlobalSign. We are taking this claim seriously and are investigating."
-------------------------------------------------------------------------------------------------
MSRC: Microsoft updates Security Advisory 2607712
https://blogs.technet.com/b/msrc/archive/2011/09/06/microsoft-updates-security-advisory-2607712.aspx
Microsoft Security Advisory (2607712)
Fraudulent Digital Certificates Could Allow Spoofing
http://www.microsoft.com/technet/security/advisory/2607712.mspx
The fallout from the DigiNotar compromise continued on Tuesday, as Microsoft said it has now revoked its trust of all five of the certificate authority's root certificates. The update that makes this change is being pushed out to users on all supported versions of Windows.
The move by Microsoft effectively makes any certificate that has been issued by DigiNotar untrusted by Internet Explorer and other Windows applications. Any IE user who visits a site that presents a DigiNotar-issued certificate as proof of identity will get an error message telling him that the certificate isn't trusted. Microsoft's change applies to these root certificates from DigiNotar:
- DigiNotar Root CA
- DigiNotar Root CA G2
- DigiNotar PKIoverheid CA Overheid
- DigiNotar PKIoverheid CA Organisatie – G2
- DigiNotar PKIoverheid CA Overheid en Bedrijven
The company posted a message on its corporate Twitter feed, saying: "We are aware of the Comodo hacker BLOG that claims access to a number of major CAs including GlobalSign. We are taking this claim seriously and are investigating."
-------------------------------------------------------------------------------------------------
MSRC: Microsoft updates Security Advisory 2607712
https://blogs.technet.com/b/msrc/archive/2011/09/06/microsoft-updates-security-advisory-2607712.aspx
Microsoft Security Advisory (2607712)
Fraudulent Digital Certificates Could Allow Spoofing
http://www.microsoft.com/technet/security/advisory/2607712.mspx
Subscribe to:
Posts (Atom)