Leaked docs from Ministry of Interior show worryingly illiberal trend for France.
According to leaked documents France's Ministry of Interior is considering two new proposals: a ban on free and shared Wi-Fi connections during a state of emergency, and measures to block Tor being used inside France.
The documents were seen by the French newspaper Le Monde. According to the paper, new bills could be presented to parliament as soon as January 2016. These proposals are presumably in response to the attacks in Paris last month where 130 people were murdered.
The first proposal, according to Le Monde, would forbid free and shared Wi-Fi during a state of emergency. The new measure is justified by way of a police opinion, saying that it's tough to track people who use public hotspots.
The second proposal is a little more gnarly: the Ministry of Interior is looking at blocking and/or forbidding the use of Tor completely. Blocking people from using Tor within France is technologically quite complex, but the French government could definitely make it difficult for the average user to find and connect to the Tor network. If the French government needs some help in getting their blockade set up, they could always talk to the only other country in the world known to successfully block Tor: China, with its Great Firewall.
Forbidding the use of Tor through legislative means is another option: France could simply make it illegal for people to access Tor. The difficulty there, though, is in the policing of that new law: the country's ISPs would have to snoop on its users to find out who is using Tor, and then report back to the police. In the UK, where the new Snooper's Charter may require ISPs to log the last 12 months of user activity, a lot of resistance is being met.
The main problem with such a ban on Tor is that it wouldn't achieve a whole lot. Would-be terrorists could still access Tor from outside the country, and if they manage to access Tor from within France I doubt they're concerned about being arrested for illegal use of the network. There is evidence to suggest that the recent Paris attacks were planned via unencrypted channels, too: the Bataclan "go" message was sent in the clear via SMS.
On the other hand, criminalising and/or blocking Tor might affect many other legitimate users of the network, such as whistleblowers, journalists, and anyone else who wants to surf the Web privately.
The proposal to block Wi-Fi hotspots during a state of emergency is slightly more feasible, and you can see where the French government is coming from—but again, it would be technologically very difficult to implement, and the collateral damage would be huge. Millions of people would have to go without public Wi-Fi access, potentially for weeks at a time.
On November 20, a week after the attacks in Paris, France introduced new legislation that extended the current state of emergency to three months. At the same time, new laws were also introduced to make it easier for the Minister of the Interior to block any terrorism-related website, and to dramatically increase police powers for searching seized devices. The French prime minister suggested that they may soon make it illegal to merely visit a terrorism-related website, too.
Come January 2016 we'll see if the French government actually goes ahead with these new Tor and Wi-Fi blocking measures. Hopefully cooler heads will prevail: France is one of the most powerful and influential Western democracies, but it's also rapidly becoming one of the most illiberal. If France rolls out its own Great Firewall, it would then be whole lot easier for the UK, Germany, and other neighbouring countries to do the same thing.
::Trend Micro Threat Resource Center::
Showing posts with label events. Show all posts
Showing posts with label events. Show all posts
20 December 2015
28 January 2015
Singapore to set up Cyber Security Agency
The Singapore government is setting up an agency, which will develop a national strategy to tackle cyber threats, create a
national-level response and coordinate various agencies in managing
threats.
Called the Cyber Security Agency (CSA), the agency will be operational from 01 April 2015. It will bring together existing agencies under the Ministry of Home Affairs (MHA) and the Infocomm Development Authority (IDA) to lead the cyber security master plan, the building and design of relevant systems, and to monitor and respond to cyber threats.
The CSA replaces the Singapore Infocomm Technology Security Authority (SITSA) which was set up on 1 Oct 2009 to safeguard Singapore against infocomm technology (IT) security threats.
SITSA has been monitoring 10 sectors: Government, infocomms energy (power), land transport, maritime, civil aviation, water, security and emergency, health, banking and finance; and will be subsumed into the CSA, together with the Singapore Computer Emergency Response Team, which deals with cyber security bodies outside Singapore.
These include strategy and policy development, cyber security operations, industry development and outreach. It will also work closely with the private sector to develop Singapore’s cyber security eco-system.
Dr Yaacob Ibrahim, Minister for Communications and Information, will be appointed as the Minister-in-charge of Cyber Security.
David Koh, Deputy Secretary (Technology) at the Ministry of Defence (MINDEF), has been appointed as the Chief Executive (Designate) of the CSA on 1 January 2015, and as Chief Executive, CSA from 1 April 2015.
Koh will assume his CSA and MINDEF appointments concurrently.
The efforts by the Singapore Government come in the wake of a spate of cyberattacks in the last couple of years that targeted government websites. About 1,560 SingPass accounts were illegally accessed in June last year and, in September, details of more than 300,000 customers of karaoke chain KBox were leaked by hackers. In 2013, a string of hacking incidents on Singapore government websites, including that of the Prime Minister’s Office (PMO).
Called the Cyber Security Agency (CSA), the agency will be operational from 01 April 2015. It will bring together existing agencies under the Ministry of Home Affairs (MHA) and the Infocomm Development Authority (IDA) to lead the cyber security master plan, the building and design of relevant systems, and to monitor and respond to cyber threats.
The CSA replaces the Singapore Infocomm Technology Security Authority (SITSA) which was set up on 1 Oct 2009 to safeguard Singapore against infocomm technology (IT) security threats.
SITSA has been monitoring 10 sectors: Government, infocomms energy (power), land transport, maritime, civil aviation, water, security and emergency, health, banking and finance; and will be subsumed into the CSA, together with the Singapore Computer Emergency Response Team, which deals with cyber security bodies outside Singapore.
These include strategy and policy development, cyber security operations, industry development and outreach. It will also work closely with the private sector to develop Singapore’s cyber security eco-system.
Dr Yaacob Ibrahim, Minister for Communications and Information, will be appointed as the Minister-in-charge of Cyber Security.
David Koh, Deputy Secretary (Technology) at the Ministry of Defence (MINDEF), has been appointed as the Chief Executive (Designate) of the CSA on 1 January 2015, and as Chief Executive, CSA from 1 April 2015.
Koh will assume his CSA and MINDEF appointments concurrently.
The efforts by the Singapore Government come in the wake of a spate of cyberattacks in the last couple of years that targeted government websites. About 1,560 SingPass accounts were illegally accessed in June last year and, in September, details of more than 300,000 customers of karaoke chain KBox were leaked by hackers. In 2013, a string of hacking incidents on Singapore government websites, including that of the Prime Minister’s Office (PMO).
16 November 2014
#ClickSmart Tip!
Think your computer is immune to viruses? Think again! #ClickSmart this season to keep all your holiday cheer.
20 September 2014
iPhone 6 Launches Millions of Scam Messages
The new iPhone 6 has gone on sale around the world, sparking long lines and campouts, and a whole lot of buzz. Unsurprisingly, internet scammers quickly took advantage of the frenzy to distribute their wares.
Immediately following the unveiling of the new iPhone 6 and iPhone 6 plus, scammers accordingly began circulating email and web scams attempting to capitalize on its popularity. The gambits however take many forms.
For instance, Hoax-Slayer uncovered a bogus Facebook competition offering the ability to “win a new iPhone 6 by carrying out three easy steps.” To get a chance to win, the site claims that users must first like the site's Facebook Page and then further promote the site by sharing a link with Facebook friends. They are then instructed to go to a second page on the site to download a ‘Participation Application.’ But, a pop-up window will direct users to a list of links that open third-party survey websites.
And here’s where the real malicious activity starts: many of these ask users to submit their mobile number, which, in turn, will subscribe them to a premium SMS service that charges several dollars every time the scammers send the victim a message.
Others collect names, addresses and phone details, which can be used for a variety of nuisance campaigns.
“Meanwhile, the scammer who created the fake promotion will earn a commission via a suspect affiliate marketing scheme each time you fill in a survey and provide your details,” Hoax-Slayer explained. “And, each time you return to the download page, the pop-up will inform you that the survey was not completed properly or there was a 'small error'. You will be urged to participate in yet another survey. But, no matter how many surveys you complete, you will still not get to download your 'application'.”
In one of the many other campaigns, spammers are using an iPhone 6 giveaway email to lure in potential victims; they are asked to follow instructions in the email to click on a link to, yet once again, a survey, but instead, an adware install will commence. Since Sept. 12, AppRiver researchers have seen nearly 1 million messages associated with this specific campaign.
“Adware is a form of software that is meant to generate revenue for its author by automatically displaying advertisements,” explained AppRiver researcher Troy Gill, in a blog. “Adware is not typically anything more than an annoyance but can often seriously infringe on users' privacy. This particular strain has a wide array of functionality and can make a victim’s web browsing experience fairly miserable.”
These types of scams, of course, also carry the possibility of malicious activity in the form of man-in-the-middle attacks, malware deployments and phishing.
“Though its presence is not secret, it is quite good at embedding itself into the victim’s system and can be quite difficult for the average user to remove,” Gill said. “Remember, advertisements promising you something for nothing are almost always too good to be true.”
Immediately following the unveiling of the new iPhone 6 and iPhone 6 plus, scammers accordingly began circulating email and web scams attempting to capitalize on its popularity. The gambits however take many forms.
For instance, Hoax-Slayer uncovered a bogus Facebook competition offering the ability to “win a new iPhone 6 by carrying out three easy steps.” To get a chance to win, the site claims that users must first like the site's Facebook Page and then further promote the site by sharing a link with Facebook friends. They are then instructed to go to a second page on the site to download a ‘Participation Application.’ But, a pop-up window will direct users to a list of links that open third-party survey websites.
And here’s where the real malicious activity starts: many of these ask users to submit their mobile number, which, in turn, will subscribe them to a premium SMS service that charges several dollars every time the scammers send the victim a message.
Others collect names, addresses and phone details, which can be used for a variety of nuisance campaigns.
“Meanwhile, the scammer who created the fake promotion will earn a commission via a suspect affiliate marketing scheme each time you fill in a survey and provide your details,” Hoax-Slayer explained. “And, each time you return to the download page, the pop-up will inform you that the survey was not completed properly or there was a 'small error'. You will be urged to participate in yet another survey. But, no matter how many surveys you complete, you will still not get to download your 'application'.”
In one of the many other campaigns, spammers are using an iPhone 6 giveaway email to lure in potential victims; they are asked to follow instructions in the email to click on a link to, yet once again, a survey, but instead, an adware install will commence. Since Sept. 12, AppRiver researchers have seen nearly 1 million messages associated with this specific campaign.
“Adware is a form of software that is meant to generate revenue for its author by automatically displaying advertisements,” explained AppRiver researcher Troy Gill, in a blog. “Adware is not typically anything more than an annoyance but can often seriously infringe on users' privacy. This particular strain has a wide array of functionality and can make a victim’s web browsing experience fairly miserable.”
These types of scams, of course, also carry the possibility of malicious activity in the form of man-in-the-middle attacks, malware deployments and phishing.
“Though its presence is not secret, it is quite good at embedding itself into the victim’s system and can be quite difficult for the average user to remove,” Gill said. “Remember, advertisements promising you something for nothing are almost always too good to be true.”
16 September 2014
Leaked: K Box Singapore database with more than 317,000 names
Police report filed after database including personal details, such as contact numbers and date of birth, was made available for public download.
At 4.17am on Tuesday morning (Sep 16), a group calling themselves The Knowns emailed links to the list of members' details to several media outlets, including MediaCorp.
The list includes names of K Box members as well as their contact numbers, email addresses, NRIC numbers, dates of birth and marital status. It also includes K Box-specific data, such as membership numbers and "K Points" earned.
Channel NewsAsia has been able to verify the details of several of the individuals on the list. One member, who confirmed her details in the list were accurate, said that K Box has not yet contacted her about any leak.
"I'm a bit freaked out," said the member, who asked to remain anonymous. "My main concern is that with those details, someone could sign me up for random stuff."
Another member whose name was found on the list said he was "extremely concerned what other personal information got leaked" and that he was also worried if other companies' databases had been hacked. He filed a police report reporting the leak on Tuesday afternoon.
The Police confirmed that the report has been lodged, and that they are looking into the matter.
K Box did not respond to phone or email queries from the media. A senior management staff at the company headquarters said the company had "no comment" on the issue.
Channel NewsAsia understands that the relevant government agencies are aware of the incident and are looking into it.
The group claiming responsibility for the leak said that it was in response to "the recent increase in toll at Woodlands", saying that it was "an unnecessary financial burden on working Malaysians".
"To show our displeasure, we are releasing the database of Kbox containing more than 300k personal details of its membership. We had done it before and will do it again."
Personal details of more than 317,000 members of Karaoke entertainment operator K Box Singapore appear to have been leaked publicly.
At 4.17am on Tuesday morning (Sep 16), a group calling themselves The Knowns emailed links to the list of members' details to several media outlets, including MediaCorp.
The list includes names of K Box members as well as their contact numbers, email addresses, NRIC numbers, dates of birth and marital status. It also includes K Box-specific data, such as membership numbers and "K Points" earned.
Channel NewsAsia has been able to verify the details of several of the individuals on the list. One member, who confirmed her details in the list were accurate, said that K Box has not yet contacted her about any leak.
"I'm a bit freaked out," said the member, who asked to remain anonymous. "My main concern is that with those details, someone could sign me up for random stuff."
Another member whose name was found on the list said he was "extremely concerned what other personal information got leaked" and that he was also worried if other companies' databases had been hacked. He filed a police report reporting the leak on Tuesday afternoon.
The Police confirmed that the report has been lodged, and that they are looking into the matter.
K Box did not respond to phone or email queries from the media. A senior management staff at the company headquarters said the company had "no comment" on the issue.
Channel NewsAsia understands that the relevant government agencies are aware of the incident and are looking into it.
The group claiming responsibility for the leak said that it was in response to "the recent increase in toll at Woodlands", saying that it was "an unnecessary financial burden on working Malaysians".
"To show our displeasure, we are releasing the database of Kbox containing more than 300k personal details of its membership. We had done it before and will do it again."
16 August 2014
Robin Williams goodbye video used as lure in social media scams
Within 48 hours of the news surrounding the death of actor and comedian
Robin Williams, scammers honed in on the public’s interest and grief.
There is currently a scam campaign circulating on Facebook claiming to
be a goodbye video recorded by the actor just before his death.
If a user clicks on the “Share on Facebook” button, they are prompted with a share dialog box. This box misleads users into believing this page has received millions of comments and shares but, actually, scammers have leveraged Facebook Open Graph metadata as a trick.
After sharing the link to their Facebook friends, users won’t be presented with a video. Instead, they’ll be asked to install an application on their computer or to fill out a survey. Scammers operating these sites use affiliate programs to earn money for the completion of surveys and file downloads.
Symantec has alerted Facebook about this scam campaign and they are taking steps to block the offending URLs.
Over the years, scammers have used both real and fake celebrity deaths as a way to convince users to click on links and perform actions. From Amy Winehouse and Paul Walker to the fake deaths of Miley Cyrus and Will Smith, scammers are opportunistic and always looking for ways to capitalize.
Before you click on a link a friend may have shared on social media, follow these best practices:
Fake BBC news site with fake Robin Williams goodbye video
There is no video. Users that click on the link to the supposed video
are taken to a fake BBC News website. As with many social scams, users
are required to perform actions before they can view the content. In
this case, users are instructed to share the video on Facebook before
watching.
Facebook share dialog with fake comments and shares
If a user clicks on the “Share on Facebook” button, they are prompted with a share dialog box. This box misleads users into believing this page has received millions of comments and shares but, actually, scammers have leveraged Facebook Open Graph metadata as a trick.
Scam site asks users to install fake Facebook media plugin
After sharing the link to their Facebook friends, users won’t be presented with a video. Instead, they’ll be asked to install an application on their computer or to fill out a survey. Scammers operating these sites use affiliate programs to earn money for the completion of surveys and file downloads.
Symantec has alerted Facebook about this scam campaign and they are taking steps to block the offending URLs.
Over the years, scammers have used both real and fake celebrity deaths as a way to convince users to click on links and perform actions. From Amy Winehouse and Paul Walker to the fake deaths of Miley Cyrus and Will Smith, scammers are opportunistic and always looking for ways to capitalize.
Before you click on a link a friend may have shared on social media, follow these best practices:
- Be vigilant and skeptical when reading sensational stories on social media sites.
- Don’t install applications or do surveys in order to view gated content. It's a trick to put money in the pockets of scammers and your computer or device is at risk to malware.
- Visit trusted news sources for information. Instead of clicking on random links online, go directly to your trusted news source.
- Report suspicious content. Do your part by reporting these types of posts as spam.
25 July 2011
"Amy Winehouse death video" scams hit Facebook users
The past weekend has been rife with bad news that captured the attention of the greater public, and online scammers have wasted no time in taking advantage of it.
Facebook users have predictably been targeted with various scams. First came the ones exploiting the Oslo bombing news, and then followed those luring victims in with non-existent videos of the last moments of the famous and recently deceased singer Amy Winehouse.
According to Sophos, variations of "Leaked Video!! Amy Winehouse On Crack hours before death", "Video leaked of Amy Winehouse's death!!! Warning: Graphical Content" and "SHOCKING - Amy Winehouse's Final Minutes" messages offering a link to the purported video unsurprisingly take users to pages where they are asked to like the page and to take a survey before being allowed to see it:

If you are one of the people who fell for this type of scam, be sure to remove any trace of it from your account ("Likes and interests" section, for example) and news feed, and to report the scam to Facebook.
Also remember that when it comes to unexpected and often shocking global news, legitimate news sites are always a better source of information than your Facebook friends.
Even when it seems that the offered link is the URL of a legitimate site, it might be better to go to that site by typing in the domain name in and then using the internal search feature in order to find the wanted news item.
Facebook users have predictably been targeted with various scams. First came the ones exploiting the Oslo bombing news, and then followed those luring victims in with non-existent videos of the last moments of the famous and recently deceased singer Amy Winehouse.
According to Sophos, variations of "Leaked Video!! Amy Winehouse On Crack hours before death", "Video leaked of Amy Winehouse's death!!! Warning: Graphical Content" and "SHOCKING - Amy Winehouse's Final Minutes" messages offering a link to the purported video unsurprisingly take users to pages where they are asked to like the page and to take a survey before being allowed to see it:
If you are one of the people who fell for this type of scam, be sure to remove any trace of it from your account ("Likes and interests" section, for example) and news feed, and to report the scam to Facebook.
Also remember that when it comes to unexpected and often shocking global news, legitimate news sites are always a better source of information than your Facebook friends.
Even when it seems that the offered link is the URL of a legitimate site, it might be better to go to that site by typing in the domain name in and then using the internal search feature in order to find the wanted news item.
24 July 2011
Oslo bombing Facebook scams infecting 1 user per second
Websense has found an alarming number of Facebook scams taking advantage of yesterday's tragedy in Oslo, Norway.
Right now it seems to be infecting one user every second. The scam is a form of ‘clickjacking’ that replicates itself on users’ walls after they click on fake posts within their news feed.
Example of viral Facebook exploit:

Users should be cautious when clicking on breaking news trends and stories within search results related to the Oslo tragedy.
Searching for breaking trends and current news represented a higher risk (22.4%) than searching for objectionable content (21.8%), including pornography.
“This Facebook scam is unfortunate, but a very real threat,” said Patrik Runald, senior manager of security research, Websense. “Criminals know how to take advantage of disasters and the hottest news items to get people to click on infected links. Tragedy is just one type of news that the bad guys use to exploit, compromise and infect your computer. Videos are an especially popular lure; we saw the same thing when Osama bin Laden died and when Casey Anthony was acquitted. During times of crisis or breaking news, your best bet is to stick with the largest news organizations you trust. Avoid the potentially dangerous halls of search engines and social media sites, which are more susceptible to compromise.
Right now it seems to be infecting one user every second. The scam is a form of ‘clickjacking’ that replicates itself on users’ walls after they click on fake posts within their news feed.
Example of viral Facebook exploit:
Users should be cautious when clicking on breaking news trends and stories within search results related to the Oslo tragedy.
Searching for breaking trends and current news represented a higher risk (22.4%) than searching for objectionable content (21.8%), including pornography.
“This Facebook scam is unfortunate, but a very real threat,” said Patrik Runald, senior manager of security research, Websense. “Criminals know how to take advantage of disasters and the hottest news items to get people to click on infected links. Tragedy is just one type of news that the bad guys use to exploit, compromise and infect your computer. Videos are an especially popular lure; we saw the same thing when Osama bin Laden died and when Casey Anthony was acquitted. During times of crisis or breaking news, your best bet is to stick with the largest news organizations you trust. Avoid the potentially dangerous halls of search engines and social media sites, which are more susceptible to compromise.
28 July 2009
Next Gen IT Security 2009 Conference
Event: Next Gen IT Security 2009
Date: 18 August-19 August 2009
Location: Singapore
Organizer: Marcus Evans
Homepage: http://www.marcusevans.com
Marcus Evans’ ‘Next Gen IT Security’ conference will keep IT security professionals to keep up-to-date on their knowledge in the latest threats, new practices and continuous improvement strategies in the industry to maintain a competitive edge in the market.
This conference highlights the participation of representatives from international companies such as OWASP Singapore (Singapore), Royal Bank of Scotland (Singapore), Citco Funds (Singapore), SingHealth (Singapore), Creative Technology (Singapore), Bank of America (Singapore), JPMorgan Chase Bank (Singapore), Nokia Siemens Networks (Singapore), Hong Kong Police Force (Hong Kong), CBH Group, Dell Inc. (Global Business Center), Affin Bank (Malaysia), British Telecommunications, Professional Information Security Association (PISA), Allergan (India), Acmamall.com, Bank Muamalat (Malaysia), Carsem and among others.
For further event details and event brochure, kindly contact Ms. Catherine Foo here.
Date: 18 August-19 August 2009
Location: Singapore
Organizer: Marcus Evans
Homepage: http://www.marcusevans.com
Marcus Evans’ ‘Next Gen IT Security’ conference will keep IT security professionals to keep up-to-date on their knowledge in the latest threats, new practices and continuous improvement strategies in the industry to maintain a competitive edge in the market.
This conference highlights the participation of representatives from international companies such as OWASP Singapore (Singapore), Royal Bank of Scotland (Singapore), Citco Funds (Singapore), SingHealth (Singapore), Creative Technology (Singapore), Bank of America (Singapore), JPMorgan Chase Bank (Singapore), Nokia Siemens Networks (Singapore), Hong Kong Police Force (Hong Kong), CBH Group, Dell Inc. (Global Business Center), Affin Bank (Malaysia), British Telecommunications, Professional Information Security Association (PISA), Allergan (India), Acmamall.com, Bank Muamalat (Malaysia), Carsem and among others.
For further event details and event brochure, kindly contact Ms. Catherine Foo here.
Subscribe to:
Posts (Atom)