Thursday, December 26, 2013

The Democratization of Cyber-Risk; Why You, Your Family and Small Business are the TARGET for Hackers in 2014.


The Democratization of Cyber-Risk 

Why You, Your Family and Small Business are the TARGET for Hackers in 2014.


The watershed event for 2013 in the world of cybercrime might just be the Black Friday Target breach. It certainly is if you put the NSA revelation by Edward Snowden aside. Regardless, they are both markers on the historical timeline of cybercrime and the emergence of large scale "horizontal" breaches in online security and privacy.


Why You Are Now The Bullseye - 

In previous blogs, I've explained "vertical" breaches (the Pentagon, DropBox, LinkedIn, etc.) being those that find a single target to be of "high-value". The new wave is "horizontal" in that digital surveillance technology can now scan millions of individual targets, like you and me, and glean the data with big-data software to create a large, horizontally assembled high-value target. Snowden's expose' revealed the extent of the US government's use of this method, but we also know that corporate and criminal hackers use the same approach and have probably been empowered by the NSA's enormous investment in furthering this technology. This is the environment that is quickly democratizing cyber-risk in the world today. What's at stake are the most meaningful people and the most irreplaceable things, in our respective lives.

40 Million Bullseye's in this TARGET - 

The Target breach is an example of a vertical breach with over 40 million of it's customers losing sensitive information to the attack. In many cases, another hacker will purchase credit card and PIN information to fraudulently purchase and perhaps re-sell merchandise before the system catches up with them. In these cases, the consumer is protected. This link is a good report on how they undertake this fraud once credit card numbers are in hand; What Happens When Your Credit Card Number is Stolen?

What They Do With Your Stolen Information & Why You Are Not Protected -

Now, here is where it becomes different and gets interesting. Stolen credit card numbers are nothing new, but, the ability for almost anyone to steal this many of them and then use them all as a mechanism for large-scale financial-fraud, is. The stolen information from tens of millions of Target customers will be assembled and analyzed using big-data tech and then used for a single (or more) large-scale horizontal attack that will affect many, potentially 100,000's or millions, of individuals and families. And, in this case, the credit card victim has no protection. Nobody else will stand-in and shoulder the consequences of the breach. You are individually accountable and at risk. This mass-scale horizontal attack represents the new era in cybercrime and the individual, family and small business has perhaps, at the outmost, 12 months to prepare for the decade long cyber-storm which is at hand today. More on this at; What I Did for My Summer Vacation.

The hackers will use the details gained from the Target breach, such as credit-card numbers, PIN's, sign-on's, etc., and overlay other metadata they have collected from scanning Gmail, Yahoo, AOL and other large providers of "free" email (just as the NSA does), analyze it all with big-data software and aggregate those where they have discovered enough variables about you to crack the code of your online security. This may end up in socially-engineered emails and in ransomware attacks where your life's worth of data is held hostage. Social engineering, an outstanding piece from Kaspersky Labs;
http://blog.kaspersky.com/social-engineering-hacking-the-human-os/

Ransomware And Why This is The Last Computer Screen You Ever Want to See -

screenshot of ransomware incident, shield, cryptolocker, crypto-locker,
This is the computer screen you never want to see. 

What is Ransomware? 

Ransomware is the evolution of extortion. Only the booty and means to the crime have changed.
What is Ransomware?
Is ransomware "the" word for 2014 in cyber-crime?
Ransomware on the Increase in 2014.


What Happens in a Ransomware Attack.?

Ransomware is the hijacking of your digital life. All of your data is encrypted and held for ransom. Typically the amount is not insurmountable but, you only have a brief period of time to fulfill the demand. The hackers are counting on you and millions of other victims in the attack to just pay-up and be done with it. In many cases, unfortunately, this is the least damaging of all outcomes.

What Does One do to Protect Their Homes and Families from These Risks?

Hackers have excelled at leveraging the exponential gains in technology to their personal advantage. Furthering their innovation has been the institutional targets which have spent decades and billions in order to protect themselves. This tension between the two has created an arena of very robust tools for attack, and defenses to protect. Until now these tools of attack have been oriented to the server environment of the institution and not necessarily toward the individual end users that reside at the capillaries of the internet. The good news is that we can now use the same technology the institutions have developed for their defense, for the sake of our own. Without enterprise-grade defenses, individual users of the internet have little, if any, chance of surviving in light of the new era of cyber-crime.

To be smart and strategic in the new environment it's helpful to understand a very core concept which holds the key to understanding what lies ahead. Albert Einstein, Carl Sagan, and many others scientists have said that the understanding of this concept is crucial to a general understanding of the way things simply work, anywhere in the universe. 
"If you understand exponentials, the key to many of the secrets of the Universe is in your hand." (Sagan,1997) 
Must see (Sagan nails it.); Carl Sagan's last interview, Charlie Rose.
And of course the "law" that created the world of the computer as we know it today;
Moore's Law, Wikipedia.

The point ultimately is that it's impossible for a population of biological beings to keep pace with a rate of exponential change, for any period of time. Defenses from today's and future attacks will require individuals and families to leverage advances in technology at least as well as the hackers do. It will always be a whack-a-mole game, but going upstream, to the enterprise level of solutions, and then re-orienting these solutions to a non-server environment, just like the hackers and the NSA are doing right now, will provide very effective defenses for anyone to defend their online security and privacy. This happens to be precisely why Total Digital Security was built; to provide enterprise-quality solutions to the individual, the home and family, as well as other small groups and businesses, the defenses necessary for internet security and privacy. Our advantage as users of the internet is that we in ourselves are not of high-value to the hackers. If we take precautionary measures and not be part of  large aggregate of data. we have no value to them at all and so are ignored.

Privacy. Word of the Year 2013.   Dictionary.com 2013 Word of the Year.

The Potent Brew from Collision of Metadata Collection and Big-Data Software -

The amount of metadata that has been collected by governments, companies, criminals, hackers and others creeps, combined with the power of big-data software presents a new age of cybercrime that is at our footsteps now, today. This powerful brew will manifest itself as ransomware that targets individual users of the internet. There will be massive attacks across broad geographies and the consequences will affect millions. Cyber-risk has truly been democratized and you, your family and small business are now the richest new target that is at the bullseye for the entire hacker community.
 "Stalker Economy" here to stay.
Metadata = Surveillance. https://www.schneier.com/blog/archives/2013/09/metadata_equals.html

Do You Have Anything to Worry About? 


Awareness and action are crucial. This is the mantra. If you are thinking about not worrying too much about your online security and privacy then I highly encourage reading +Jaron Lanier in the New York Times about Digital Passivity. This is not one to defer or ignore.

Thanks for reading,

Brad

3 Steps to Internet Security, Privacy and Peace of Mind.   http://bit.ly/19zxCHa

An offshore email account will vastly reduce the chances of being hacked and be the last email account you will ever need. Why do you want a Swiss-domained email and data storage account?

www.totaldigitalsecurity.com TDS provides best-in-class solutions for individuals, homes and families for protection from cybercrime, online fraud, and the preservation privacy.

Offshore email and data storage for internet security and privacy for you and your family.



Thursday, December 12, 2013

What I did for my summer vacation.

I wrote "What I  did for my summer vacation." for a very practical reason. After pivoting  at the age of 55, and leaving a successful 25 year career, I've some explaining to do! This is an effort to as succinctly as possible,  explain my professional effort for the past 9 months.

In March of this year,  I started a company and it's called Total Digital Security. We’ve built some really cool technology that empowers one to seize and retain control of their privacy, online security, and digital assets.

Our network operations center is in Helsinki and email and data servers are in Zurich. There are some very good reasons for this besides the fact that the Finnish and Swiss technology partners are the best in their field. 

What we are doing is different, and frankly better, than anything else available to the non-institutional markets for managing cyber-risk today.

We built the company on some basic principals; we think the Internet is awesome, that we should be able to enjoy it's cornucopia of rich content and resources with minimal government intrusion, and that we should be able do so without worry for our online security, privacy and data.

Regardless of how one use's the Internet, one can and should be in total control of their online presence and the digital assets that are your legal property. Digital information is considered extremely valuable today, most especially the information about YOU. 


Look at the skyrocketing value to a bit coin, which is a reflection of the dramatic increase to the value of privacy and the control of digital information. And, witness the money that government, corporate and criminal actors are expending in order to capture the information they think defines YOU. They are monitoring whom you are, what you do, where and when you do it, and how … all of value, and they are stealing this information that is YOURS and they are using it against you, every day. It has gone beyond creepy and has attained the level of true surveillance and stalking.

Fortunately, in this environment, there are options and one can decide to be smart about risk in the digital age. My mission at Total Digital Security is to inform, educate and bring awareness to some of the most crucial and personal issues of the day. Our solutions are open-source for portability and compatibility, and our technology partners are the best in their class in order to protect you, your family, office and business. You will be back in control and leveraging the awesome power of the Internet without the daily dose of abuse to your rights, your security, your privacy and your digital assets. It is that simple but that meaningful.

Unfortunately, today it’s not a matter of “if” but “when” you will be a victim of cyber-crime. We are here to help you be proactive and pre-emptive by knowing your options and solutions that are available to seize control and change the balance of power in everything you do online. Our rates start as low as $5/mo and go up to $25/mo depending on features such as storage, group size and such. I hope you will check us out.



18  months ago, about nine months before I started Total Digital Security, I  told some associates that I wanted to be on the record for 3  predictions, each of which I felt would occur in the coming 18-24  months.

#1) Cyber-crimes on a large scale will soon affect individuals.

We  are used to reading the headlines about corporate  and government hacks  but I was talking about large groups of individuals. Large groups of  individuals that share nothing in common other than their metadata  ending up in the wrong place with the wrong people. I did not predict  the U.S. government would be part of the crimes. The hack of 2 million  individual credentials last week through Gmail, Facebook and others, is  the perfect example of the "horizontal" attacks I predicted would be far  more common and damaging than ever more.

#2) Federal and local politicians will begin to discuss cyber-security subsidies for individuals and families.

There has been some talk of it. It's the irony that kills me.

#3) Time magazine will name their "Person of the Year", "The Hacker".


I  could just see it; the shady, hooded guy, cross-legged with a laptop open and eerily glowing.  Well, Edward Snowden came in at #2 this year just behind the Pope. I'm  not good enough to make this up. Or maybe I am? There is always next  year.

So  it was these convictions, among others of course, that led me to take  an Altucher-like course of professional reinvention. Scary? Sure. Fun?  You betcha! Convicted? More than ever. Regardless, the journey has been  meaningful, invigorating and cleansing (as in an acid-bath!).

Stay tuned, it shall not be boring.

Brad

Friday, November 29, 2013

3 Steps to Internet Security and Privacy

Every day since my last post I am compelled to share a new media or insider report about the state of our internet security and privacy today. Of course I do just that through Twitter and LinkedIn but one report especially struck me and energizes today's blog. The article
was published yesterday by Bloomberg News and exemplifies the rapidly increasing levels of risk mounting in cyberspace today. It's a call to action.



Thanksgiving Day, Bloomberg News;

http://www.bloomberg.com/news/2013-11-27/zurich-s-kerner-says-matter-of-time-until-dramatic-cyber-attack.html


Croom, Kaufman, Baker on Cyersecurity Industry

Stay with me a moment here and let's look at the choice of words by #MichaelKerner, who oversees property-casualty coverage at Zurich Insurance Group AG (ZURN) #ZURN  -

"... said computer threats are escalating and may soon cause “dramatic” disruptions for businesses and individuals."

Some serious words here; "soon", "dramatic", "disruptions for business and individuals."

INDIVIDUALS - Yes, I am shouting for emphasis. In my last blog on #offshoreemailaccounts I explained how and why we, as individuals, are the next high-value target for the most sophisticated and aggressive criminals on the internet.

"... he said yesterday in an interview at Bloomberg’s headquarters in New York. “You’ll look back and say, ‘We should have seen this coming.’” 

I differ here; anyone that is awake will have to say "I saw this coming." And yes YOU should see this coming. You, as the head-of-household, leader, protector, and if not for you, then who? Protecting yourself is not rocket-science and it is extremely affordable, especially from a risk vs. reward standpoint. The purpose of today's blog is to show you how in 3 steps you can pull yourself off the radar from the criminal, commercial and state actors that are stealing your digital assets every day. The three-pronged approach I describe here will prevent them from targeting you for the likes of financial extortion, ID theft, revenge, ... you know the gig, and give you the ability to seize back the control of your personal information, identity and digital assets.



The real challenge in doing this is in the "when" and "how" you will decide it's time to suit-up and insulate yourself from the risk. Attaining and retaining control of your online security and privacy is the subject matter of this week's post. It's 3 Steps. Three important steps so you can stop thinking about it, feel really smart, and position yourself for control and success in a digital world.


Step #1 - Secure Your Email. It's easy. You will want to domain your email offshore and out of the hands of the NSA and the public services. The information they are aggregating about you and your life is at the stage where it absolutely is surveillance. A simple inquiry by an ambitious federal employee can spin out of control, take on a shape never originally intended and completely upend and disrupt your life for a very long time to come. Witness the Op-Ed piece from the Wall St Journal, #howthegovernmentspiedonme, where a routine email check led to the resignation of the Director of the CIA (I wish I could make this up).

 http://online.wsj.com/news/articles/SB10001424052702303482504579179670250714560

At #totaldigitalsecurity we use real servers and base them in Zurich, Switzerland. Our partners are at #kolab  where #georggreve  http://linkedin.com/in/GeorgGreve   is CEO. There is no better email solution today. And, it's open-source. That's a really big deal when it comes to security. Switzerland's constitution is very clear in terms of the rights individuals have to privacy and the country really is the antithesis to the U.S. today. For more on "Why Switzerland" see my last blog and refer to the chart:
We are actively setting up family and business domains that include email, calendar, contact and to-do and is an Exchange-like experience, but without the bugs and transparency of the public email services like  #gmail and #yahoomail .


  
Step #2 - Secure Your Online Presence. 

First, a couple of definitions.

Privacy - #onlineprivacy is when they know who you are, but not what you are doing.
Anonymity - #onlineanonymity is when they see what you are doing but not who you are.


Ideally, you want both, every step of the way. Tor, for example, provides anonymity and a VPN, for example, provides privacy. But there are many more links in the chain and each must be as robust as the last.


Securing your online activity also includes anti-virus and malware, intrusion prevention, a firewall, anti-spam engine, and browsing protection. And, very importantly, immediate updating of operating system and 3rd party software applications. The fact is, most intrusions could have been prevented with current software patches and updates. With Microsoft, this is practically a full-time job but with our system, it's monitored and automated, never skipping a beat.

Here's how;

Large institutions have long recognized the value and potential liability of their digital assets and have invested vast sums of money to protect themselves from the associated risks. It's still a whack-a-mole game at that level and always will be, and this is precisely the point;  this tension between the institution and the hackers is an amazing and energizing force that has created remarkable innovation and solutions that become evermore robust and inexpensive. It is a fact of physics that technology gets better at an exponential rate and cheaper just as quickly. If you don't know Moore's Law, honestly, it's time you do because not only is the rate of change getting faster but so is the rate of the rate of change. When it comes to math, that's a huge phenomenon.

http://en.wikipedia.org/wiki/Moore%27s_law


Check this graph out;






The graph illustrates computer performance from 1975 to 2011. The crucial point here though is that we are now in the zone of the "hockey stick". That's where the line starts to go vertical. Since the computer chip was invented it has been evolving at a rate previously unheard of in any activity. The accumulation of these exponential gains (think compound interest rates) put us at a point, right now today, where the rates of change are literally going vertical, like straight up. That's the hockey stick piece. If you take one thing away, take this; you ain't seen nothin' yet. This is not "bad" news, it just is what it is but it could be tragic if you don't recognize it. And, what Step #2 is all about is using this awesome progress in technology by leveraging it's performance and ridiculously low prices to your advantage in the realm of your personal security and privacy.

OK, so, back to securing your online presence; it is all about taking the solutions provided at the institutional level and engineering them for the individual consumer. That's you and me and our families and our offices. This is precisely what we do for our customers.  At this level of protection security is operated as a service, as opposed to a product.  "Products" are installed and expected to go to work. Today's cyber-environment requires a more dynamic process of monitoring, assessing and adapting. For this we use a network ops center in Helsinki, Finland, (another country that is maniacal about privacy rights) operated by the F-Secure company. They are the real deal, check them out. The monitoring is 24/7/365 and defenses are automated, including software patches and updates, anti-virus and malware, intrusion prevention, a firewall, anti-spam engine, vulnerability testing and browsing protection.


Step #3 - Secure Your Digital Assets.  
Have you noticed the price of a bitcoin? In less than a year it's gone from $10 to $1,000, in round numbers. I don't know if this tulip-mania and I don't really care because it's a symptom. The cause of this phenomenon is the rapidly increasing value to anonymity. It's supply and demand all over again. Anonymity is so valued now because their is so little of it left. The inherent value to anonymity is the information behind the curtain. Everyone wants it. Your government is just taking it, the corporation is suckering you into giving it to them and the criminal is stealing it from you. All at the same time. The scarcity of today and the foreseeable future is privacy and anonymity.  This makes me laugh because it used to be so valuable to be famous! Perhaps one day we will all have our 15 minutes of pure anonymity. Like a surreal bliss I suppose.

So the point is to secure your stuff. All your digital stuff, because it's becoming more valuable to someone somewhere more and more every day. And this can be tricky.
This is why so much is "free" on the internet. Free social media, email, storage, and the rest. You name it and the billionaires of silicon valley want you to give it to you. Because they are nice guys you suppose? Maybe they are, some seem like it, but we know they aren't "giving" you something without coming out the winner in the exchange. That's what billionaires do really, really well. Remember; if you aren't paying for the product, you are the product. The billionaires made in silicon valley over the last several years have done it faster than ever because they have figured out how to get you to work for them, everyday, and to have you pay them for doing it. No wonder they got so rich so fast. Imagine having millions of others doing your work for you, giving you their stuff, and then paying you for the privilege. That's the dominant business model for the time.

Do what I did and what I do for others; create a digital "Family Vault". Base it in on real servers, offshore, Switzerland or Finland preferably, and encrypt the hell out of it. Create access and user permissions and you then have a family that collaborates around their digital assets. Decades of photos, scans, movies, financial records, legal documents, passwords, ... you get it. Sync and backup is a cinch, legacies are assured and future generations will always have their "digital fort" because we do it in open-source. Like our email solution, our storage solution is open-source and this means you are always portable and format compatible.

You know, at first draft I was going to say 3 "Simple" or "Easy" Steps to Online ... as the title but I couldn't get honest with the words "Simple" and "Easy". We simply, aren't there, yet. That's why we are here, do it for you. And I see our entire service operation as open-source too. We only apply the best-in-breed technology to our solutions and when the title of "best" changes hands, well we do too. We have put together an amazingly robust, effective and affordable system that will not just survive the challenges of change but will thrive on them as well. With our service, the awesomeness that is the nature of technology will be leveraged for the sake of protecting you and those around you, 24/7/365. This is effective risk management for the digital age.

Thanks,

Brad



 



Wednesday, November 20, 2013

Offshore Email Accounts

Welcome back,

If you are reading this then you probably know that the new Snowden documents show that the NSA is scanning all of the major, public providers of email and internet services. This activity is without warrant, there is no consent nor due process and it is not reported. In fact according to U.S. law if you report the activity you are subject to criminal charges. The NSA scanning harvests data that includes incredibly personal detail like address books and IM lists. The word for it is metadata. This activity is well beyond even that of PRISM, and is better defined as surveillance.

As security-guru Bruce Scheiner says,
"Metadata equals surveillance; always remember that."  

https://www.schneier.com/crypto-gram-1311.html


How prevalent is this?  Well, in one day the NSA's Special Source Operations branch collected 689,246 individual email addresses from the major providers like Gmail, Yahoo and others. The administration tells us not to worry as there are "checks and balances". The problem is that there is no due process for the "checks and balances", just some secret something in the government that decides what is legal and constitutional. This is the shady platform from which massive amounts of information about you, your family and your business, are being collected, analyzed, "interpreted" and acted upon, every day.

Besides the audacity of the activity is it's recklessness. Already we have insulted the world and its leaders, much less ourselves. The damage to date is incalculable, and the potential for future damage is unfathomable. The government has unleashed the ultimate software virus and it's target is you and everything about you. The virus will live forever, or at least as long as you're concerned with, and it will mutate through the hands of the hacker-mega-machine until it becomes something far from what it was originally meant to be.

I founded Total Digital Security on the notion that cybercrime was going to be a significant problem for more than just the institutional entities. We read every day about hacks into DropBox, Apple, the big banks, the Pentagon, and other entities recognizable enough to merit a story covering the breach. But what about individuals, like us? Not so much. Why? Well, for some time we (that's you and me)  haven't been considered "high-value" targets. Whether you are a criminal syndicate, a vigilante hacker, or a commercial or government entity you want bang for your hacking buck. These large, "high-value" institutional targets, are referred to as "verticals". Once you've hacked in to a "vertical" the potential "value" extraction can be very high. Cyber-attacks have traditionally been focused on a single, "high-value", "vertical" in order to satisfy their agenda for any particular attack.

Yes, there are plenty of individuals and families that are victims of cyber-crime too. Some of the consequences are life-altering, all of them are damaging. Still, 99% of the press is about the institutional level crimes. One guy getting hacked by a teenager in a hoodie isn't going to make you pick up the newspaper and read the story. As cyber-criminals see it we as individuals are "horizontal" targets; broad in scope and shallow in value. Not worth their effort. Well guess what? The game is changing and "horizontal" has just become the new "high-value" target for any hacker or spy in the game.

Let's face it, since the Snowden revelations we now know we are all victims of serious intrusions to our security and privacy. And, in that, lies the point. We have all become "high-value" targets. If you can get enough of us with any one cyber-attack, then we're fair game. Collectively, any group of us is a "high-value" target. The safety of being bunkered in a "horizontal" is no more. Though we are not server-centric in our technology at the home and personal level, we are now vulnerable as a result of two primary forces. On one hand is the massive aggregation of individual traffic at places like Gmail, Facebook, LinkedIn, Twitter, and Yahoo, among many others. And, on the other hand, is the power of "big data" software that can make sense of all that metadata. Combined, the intimate details of our everyday lives are being collected, analyzed and "interpreted". On behalf of the NSA the interpreter of your information is a secret body of unknown officials in cahoots with one another somewhere deep in the federal government that requires no due process and operates entirely in the dark. And that's when the good-guys are at work on us.

We cannot conceive of the ways this will go terribly wrong, but we can take action because there are effective and affordable solutions that are available today. You can significantly reduce the risk of cybercrime with inexpensive technology and services that effectively  mitigate most all of your online risks. As a result of software the NSA and others have built along with the natural performance curve of technology, you can expect these metadata-based cyber-attacks to pick up in frequency, effectiveness and potential consequences for not just the big institutions, but for you and those around you. Digital assets are becoming more valuable by the day, witness bitcoin. Every day the value of you becoming a target goes up, and the ease of which to victimize you goes down. It's no longer "if" but "when" you or someone close to you has a serious problem with cyber-crime and the time is exactly now to get in front of it while you can.

One of the most effective things you can do to protect you and those around you is to establish Swiss-based email accounts. This slide distinguishes the reasons why:







 There is a really good reason the world's smartest people keep their money in Switzerland. It's because the Swiss constitution extends extraordinary rights of privacy to individuals. Their is no warrantless activity by the government in Switzerland. And, if there is a warrant, you must be notified and the warrant's activity must be reported. While in the U.S. it is a criminal act to report a warrantless offense by the NSA, in Switzerland it is a criminal act NOT to report the activity even for a warranted action. That's the environment I choose in which to operate my online life, safeguard my digital assets and to protect my privacy and personal security.


This blog's focus is personal online security and privacy. I founded Total Digital Security not just on the expectation that things were going to get ugly soon but also on the view that counter technology is effective, affordable and becoming more so all the time. Institutionally developed counter-measures are at a point economically where they can be introduced to the individual, home and small office environments. You don't need a server to operate them and they are 24/7 vigilant and adapting. The landscape will be even more dynamic in the future but we have the opportunity now to shore-in the leakage of our identity and privacy and to preserve and protect our digital assets for generations to come.

I hope you will stay tuned,

Brad