Attacks/Breaches
2/28/2012
12:14 PM
Connect Directly
RSS
E-Mail
50%
50%

WikiLeaks Stratfor Disclosure Highlights Email Encryption Failure

Hacktivist group Anonymous said it obtained the intelligence contractor's clear-text emails, and shared them with whistleblower and information-release website WikiLeaks, as part of a new working relationship.

On a related note, early news reports had questioned how WikiLeaks had received the Stratfor archive. But a Twitter post from AnonOps said Monday, "To clarify to all journalists - YES, #Anonymous gave the STRATFOR emails obtained in the 2011 LulzXmas hack to WikiLeaks. #GIFiles." The GIFiles tag refers to "The Global Intelligence Files" campaign being run by WikiLeaks, which appears to be updated naming for "The Spy Files" program WikiLeaks announced in December 2011, when it said it planned to release "hundreds of documents from as many as 160 intelligence contractors in the mass surveillance industry."

With that possibility still looming, Michael Ross, a Canadian expert on intelligence gathering and former Israeli Mossad officer, noted that the release of Stratfor emails, which he's begun reviewing, highlights the dangers of attempting to spy on others--especially in today's WikiLeaks world.

But writing in Canada's National Post, he said the bigger question is whether such services offer any real value. "Stratfor, and other similar outfits that have cropped up like weeds in the post 9/11 era, are cashing in by offering up a lot of so-called expert opinion that isn't worth anything more than what can be found in a Robert Ludlum novel," he said. "The difference between an intelligence service and a company like Stratfor is that they know how to focus their resources and assess information by separating the wheat from the chaff. By all accounts of the Wikileaks Stratfor emails, their clients are getting nothing but a lot of chaff."

Ironically, according to the internal emails, Stratfor employees had looked for a way to cash in the information-leakage "gravy train" created by the WikiLeaks release of U.S. cables. "Could we develop some ideas and procedures on the idea of 'leak-focused' network security that focuses on preventing one's own employees from leaking sensitive information... In fact, I'm not so sure this is an IT problem that requires an IT solution," read one email.

But Forrester Research information security analyst John Kindervag said that Stratfor should have paid attention to its own IT problems--namely, its failure to encrypt its own, sensitive emails. "They would have saved themselves a ton of embarrassment--not to mention all of the costs associated with the breach--had they deployed encryption on their toxic data stores," he said. "Compared to all of the costs, hassles, embarrassment, and brand damage, the cost to do enterprise quality encryption would have been trivial."

Instead, he said, the firm is following Fred's #2 rule: "Admit nothing, deny everything and make counter-accusations." That rule was cited during a Stratfor missing-lunch email chain, tracking the whereabouts of a missing pesto tortellini from a company refrigerator. Unfortunately for Stratfor, denial or no, that won't be the only company secret to be made public.

The effort to achieve and maintain compliance with Sarbanes-Oxley requirements remains one of the primary drivers behind many IT security initiatives. In our Security Via SOX Compliance report, we share 10 best practices to meet SOX security-related requirements and help ensure you'll pass your next compliance audit. (Free registration required.)

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sabrina
50%
50%
Sabrina,
User Rank: Apprentice
3/1/2012 | 7:01:43 AM
re: WikiLeaks Stratfor Disclosure Highlights Email Encryption Failure
Thanks for sharing the info
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7298
Published: 2014-10-24
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.

CVE-2014-8346
Published: 2014-10-24
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.

CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.