Attacks/Breaches
2/28/2012
12:14 PM
Connect Directly
RSS
E-Mail
50%
50%

WikiLeaks Stratfor Disclosure Highlights Email Encryption Failure

Hacktivist group Anonymous said it obtained the intelligence contractor's clear-text emails, and shared them with whistleblower and information-release website WikiLeaks, as part of a new working relationship.

On a related note, early news reports had questioned how WikiLeaks had received the Stratfor archive. But a Twitter post from AnonOps said Monday, "To clarify to all journalists - YES, #Anonymous gave the STRATFOR emails obtained in the 2011 LulzXmas hack to WikiLeaks. #GIFiles." The GIFiles tag refers to "The Global Intelligence Files" campaign being run by WikiLeaks, which appears to be updated naming for "The Spy Files" program WikiLeaks announced in December 2011, when it said it planned to release "hundreds of documents from as many as 160 intelligence contractors in the mass surveillance industry."

With that possibility still looming, Michael Ross, a Canadian expert on intelligence gathering and former Israeli Mossad officer, noted that the release of Stratfor emails, which he's begun reviewing, highlights the dangers of attempting to spy on others--especially in today's WikiLeaks world.

But writing in Canada's National Post, he said the bigger question is whether such services offer any real value. "Stratfor, and other similar outfits that have cropped up like weeds in the post 9/11 era, are cashing in by offering up a lot of so-called expert opinion that isn't worth anything more than what can be found in a Robert Ludlum novel," he said. "The difference between an intelligence service and a company like Stratfor is that they know how to focus their resources and assess information by separating the wheat from the chaff. By all accounts of the Wikileaks Stratfor emails, their clients are getting nothing but a lot of chaff."

Ironically, according to the internal emails, Stratfor employees had looked for a way to cash in the information-leakage "gravy train" created by the WikiLeaks release of U.S. cables. "Could we develop some ideas and procedures on the idea of 'leak-focused' network security that focuses on preventing one's own employees from leaking sensitive information... In fact, I'm not so sure this is an IT problem that requires an IT solution," read one email.

But Forrester Research information security analyst John Kindervag said that Stratfor should have paid attention to its own IT problems--namely, its failure to encrypt its own, sensitive emails. "They would have saved themselves a ton of embarrassment--not to mention all of the costs associated with the breach--had they deployed encryption on their toxic data stores," he said. "Compared to all of the costs, hassles, embarrassment, and brand damage, the cost to do enterprise quality encryption would have been trivial."

Instead, he said, the firm is following Fred's #2 rule: "Admit nothing, deny everything and make counter-accusations." That rule was cited during a Stratfor missing-lunch email chain, tracking the whereabouts of a missing pesto tortellini from a company refrigerator. Unfortunately for Stratfor, denial or no, that won't be the only company secret to be made public.

The effort to achieve and maintain compliance with Sarbanes-Oxley requirements remains one of the primary drivers behind many IT security initiatives. In our Security Via SOX Compliance report, we share 10 best practices to meet SOX security-related requirements and help ensure you'll pass your next compliance audit. (Free registration required.)

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Sabrina
50%
50%
Sabrina,
User Rank: Apprentice
3/1/2012 | 7:01:43 AM
re: WikiLeaks Stratfor Disclosure Highlights Email Encryption Failure
Thanks for sharing the info
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7877
Published: 2014-10-30
Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVE-2014-3051
Published: 2014-10-29
The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof s...

CVE-2014-3668
Published: 2014-10-29
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument t...

CVE-2014-3669
Published: 2014-10-29
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function ...

CVE-2014-3670
Published: 2014-10-29
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly exec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.