Cybersecurity & Defense
Security concepts and current events, from foundational definitions like CSIRT vs. CERT to breakdowns of real breaches like Colonial Pipeline.
-
Current Events Breakdown: To unlock a terrorist’s iPhone, the FBI turned to an obscure company in Australia; a technique called an “Exploit Chain” was used.
So there’s quite a juicy, drama-filled story in the Washington Post that could be a Hollywood plot line about Apple, the FBI, a terrorist’s iPhone, and HACKERS!!! Azimuth Security, a publicity-shy company that says it sells its cyber wares only to democratic governments, secretly crafted the solution the FBI used to gain access to the device, according to several people familiar with the matter. The iPhone was used by one of two shooters whose December 2015 attack left more than a dozen people dead. So, yeah Azimuth is a hacking firm for the better good you can say. Azimuth is a poster child for “white hat” hacking, experts say, which…
-
What is Hurricane Electric? Let’s Find Out Whilst Learning About Some Computer/Cyber Network Fundamentals!!!
Hurricane Electric (corporate website here) is a global Internet Service Provider (ISP), offering IP transit, colocation, dedicated servers, among other services, based in Fremont, CA, USA and founded in 1994. Referring to themselves an the “Internet Backbone and Colocation Provider”, Hurricane Electric operates its own global IPv4 and IPv6 network and is considered the largest IPv6 backbone in the world, as measured by the total number of customer networks connected and by the total number of customer prefixes announced.[2] Hurricane Electric IP Transit Network Hurricane Electric has connections ranging from multiple 10GigE (10,000 Mbps) to multiple 100GigE (100 Gbps) that form these rings that connect H.E. core routers. [NOTE: Gigabit…
-
What is “Shadow IT”??
Wikipedia describes Shadow IT as: In big organizations, shadow IT (also known as embedded IT, fake IT, stealth IT, rogue IT, feral IT, or client IT) refers to information technology (IT) systems deployed by departments other than the central IT department, to work around the shortcomings of the central information systems. Shadow IT systems are an important source of innovation, and shadow systems may become prototypes for future central IT solutions. On the other hand, shadow IT solutions increase risks with organizational requirements for control, documentation, security, reliability, etc. via Wikipedia [1] My first thought after digesting some basic information is that Shadow IT sounds like people coming up with…
-
Hackers Add a Backdoor to PHP Source Code; 79% of Websites Use PHP
According to the Bleeping Computer new service, PHP’s Git server was hacked via a backdoor to the PHP source code. PHP is a general-purpose scripting language especially suited to web development. Typically a server-side programming language, PHP powers many sites on the internet including big players like Wikipedia and Facebook. In this latest attack the official PHP Git repository was hit and the code base was tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository maintained by the PHP team on their git.php.net server. The threat actors had signed off on these commits as if these were made by known PHP developers and maintainers, Rasmus Lerdorf …
-
What is Equinix? And Why Are They So Important??
[NOTE!: This is an evolving post for my research purposes to learn more about Equinix, this backbone of the internet(s).] Equinix is probably one of the most important companies that most people have never heard of. Do a quick ‘man-on-the-street’ style survey asking passers-by of the Big 5 of Tech, and surely “Equinix” is not top of mind. Nonetheless, Equinix is arguably just as important as the more well-known tech titans, if not more so. Equinix is a multinational company that runs a global network of large, industrial-scale data centers on every continent with the exceptions of Africa and Antarctica. Equinix helps take all the necessary IT infrastructure demands of…
-
Post-Quantum Cryptography: The Race Is On
Quantum computers and quantum cryptography have become hot industry buzzwords that are popping up more in the press. With that, the question becomes what happens to the security of our data covered by today’s pre-quantum cryptography technology? This Forbes article helps highlight solutions on the way in the race to post-quantum cryptography: The good news is that solutions are on the way. Recognizing the urgency of the task and the time needed to formulate, choose, standardize and deploy new systems, the U.S. National Institute of Standards and Technology (NIST) launched a Post-Quantum Cryptography (PQC) standardization process in 2016. In July 2020, NIST announced seven third-round candidates, covering both public-key encryption (PKE) and digital…
-
A 3-Tiered Approach to Securing Your Home Network
Some tips running from basic to advanced, on how to approach securing your home network from Daniel Miessler. via Daniel Miessler
-
Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals…
A group of hackers say they gained access to live feeds of 150,000 security cameras inside hospitals, prisons, schools and companies, including a Tesla factory. The hackers say they breached a massive trove of security-camera data collected by Silicon Valley startup Verkada Inc., gaining access to live feeds of 150,000 surveillance cameras inside hospitals, companies, police departments, prisons and schools. The data breach was carried out by an international hacker collective and intended to show the pervasiveness of video surveillance and the ease with which systems could be broken into, said Tillie Kottmann, one of the hackers who claimed credit for breaching San Mateo, California-based Verkada. Kottmann, who uses they/them pronouns,…
-
What is Multi-Factor Authentication and Why is It Necessary?
Many people have heard the basics of account protection: Get a password manager for your online accounts, make your passwords complex and never reuse them. But what about Multi-Factor Authentication? What is Multi-Factory authentication, what’s so special about it, and why is it needed? Multi-Factor Authentication (MFA), also sometimes known as Two-Factor Authentication (2FA), adds another layer of security to the sign-in process giving accounts further protection against unauthorized access. MFA requires multiple (two or more elements) to be used in order to grant full authentication. Multifactor authentication consists of 3 major things: Something you know: This can be a password, or the answer to a security question that cannot…
-
How to Get Into Cybersecurity with No Experience [Video]
I came across a great YouTube video titled, “How to Get Into Cybersecurity with No Experience” by Gerald “Gerry” Auger (Twitter, LinkedIn) of Simply Cyber. With Cybersecurity being in the headlines more and more, especially as companies and individuals grapple with the new Covid-economy, the demand for well-trained information security professionals continues to grow, exponentially. It is consistently listed in career/job outlook forecasts as one of the top sectors to watch in the coming years. So it comes as no surprise that the interest in this sector is growing and many are looking for ways to break into the field. Cybersecurity is especially interesting in that there seems to be…












