<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CyberSpark Archives - Sky&#039;s Blog</title>
	<atom:link href="https://blog.red7.com/category/cyberspark/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.red7.com/category/cyberspark/</link>
	<description>Communicating in a networked world</description>
	<lastBuildDate>Mon, 02 Jan 2017 20:05:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://blog.red7.com/wp-content/uploads/2018/01/skyhi-wind-icon-256x256-120x120.png</url>
	<title>CyberSpark Archives - Sky&#039;s Blog</title>
	<link>https://blog.red7.com/category/cyberspark/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>In the long run they&#8217;ll get you &#8220;in the code&#8221;</title>
		<link>https://blog.red7.com/get-you-in-the-code/</link>
					<comments>https://blog.red7.com/get-you-in-the-code/#respond</comments>
		
		<dc:creator><![CDATA[sky]]></dc:creator>
		<pubDate>Wed, 11 Sep 2013 07:40:46 +0000</pubDate>
				<category><![CDATA[CyberSpark]]></category>
		<category><![CDATA[Free Speech + Human Rights]]></category>
		<category><![CDATA[Frothy Concepts]]></category>
		<category><![CDATA[Identity & The End of Privacy]]></category>
		<category><![CDATA[Math and science]]></category>
		<guid isPermaLink="false">http://blog.red7.com/?p=3602</guid>

					<description><![CDATA[<p>Bruce Schneier says “Remember this: The math is good, but math has no agency. Code has agency, and the code has been subverted.” (read original) What this means is that the theory behind something — in this case encryption using “hard” mathematics — may be very good, but the implementation can be full of “gotchas” [&#8230;]</p>
<p>The post <a href="https://blog.red7.com/get-you-in-the-code/">In the long run they&#8217;ll get you &#8220;in the code&#8221;</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="size-thumbnail wp-image-3603 alignright" style="border: 0px none; margin: 4px 12px;" src="/wp-content/uploads/2013/09/bruce-schneier-150x150.jpg" alt="Bruce Schneier on security" width="150" height="150" />Bruce Schneier says “Remember this: The math is good, but math has no agency. Code has agency, and the code has been subverted.” (<a title="Schneier on Security" href="https://www.schneier.com/blog/archives/2013/09/the_nsa_is_brea.html" target="_blank">read original</a>)</p>
<p>What this means is that the theory behind something — in this case encryption using “hard” mathematics — may be very good, but the implementation can be full of “gotchas” — errors, omissions, faults — and that‘s what will get you in the long term. He was specifically commenting on Edward Snowden’s revelations about the US National Security Agency and whether they can read all encrypted messages, but it can apply to many other software endeavors.</p>
<p>If you’re thinking of writing some software whose function is critical, and especially if lives depend on it, you have to be extremely careful with your implementation. And <em>Open Source</em> is a big plus because other eyes can look at your code and spot mistakes that you, as author, are likely to overlook.</p>
<p>So whatever you’re working on, be very, very careful with the implementation.</p>
<p>The post <a href="https://blog.red7.com/get-you-in-the-code/">In the long run they&#8217;ll get you &#8220;in the code&#8221;</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.red7.com/get-you-in-the-code/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3602</post-id>	</item>
		<item>
		<title>Private armies in cyberspace? A kill switch on the Internet?</title>
		<link>https://blog.red7.com/private-armies-in-cyberspace/</link>
					<comments>https://blog.red7.com/private-armies-in-cyberspace/#respond</comments>
		
		<dc:creator><![CDATA[sky]]></dc:creator>
		<pubDate>Wed, 14 Jul 2010 16:09:19 +0000</pubDate>
				<category><![CDATA[CyberSpark]]></category>
		<category><![CDATA[Our networked world]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[cyber war]]></category>
		<guid isPermaLink="false">http://blog.red7.com/?p=2800</guid>

					<description><![CDATA[<p>The government of the USA was constituted “to provide for the common defense” among other things.[1] Unfortunately the line between public responsibility and private responsibility for defense in cyberspace could be rather blurry. Clearly when there is warfare in the physical world the combatants are also likely to utilize cyber tactics of some sort, even [&#8230;]</p>
<p>The post <a href="https://blog.red7.com/private-armies-in-cyberspace/">Private armies in cyberspace? A kill switch on the Internet?</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-full wp-image-991" style="border: 0pt none; margin: 4px 12px;" title="cloud" src="/wp-content/uploads/2009/01/cloud.jpg" alt="" width="64" height="64" />The government of the USA was constituted “to provide for the common defense” among other things.<sup>[1]</sup> Unfortunately the line between public responsibility and private responsibility for defense in cyberspace could be rather blurry.</p>
<p>Clearly when there is warfare in the physical world the combatants are also likely to utilize cyber tactics of some sort, even if only for informational or propaganda purposes, but more likely as powerful tactics to take down their target’s ability to respond quickly or in a focused manner. Because governments aren’t really equipped to handle these types of attacks, which would include attacks against private infrastructure, not just government systems, they’d have to rely on private companies, individuals and groups — essentially private armies — to deflect or thwart any attack.<span id="more-2800"></span></p>
<p>There are some problems inherent in cyber attacks that make any kind of defense really tricky:</p>
<p>* During a cyber attack against private or military targets online, one might not be able to determine whether the attacker is civilian, criminal or military;</p>
<p>* Online <em>citizen militias</em> (hackers motivated by patriotism) could be impossible to distinguish from organized military cyber-attackers;</p>
<p>* <em>Collateral cyber-damage</em> to (or the freezing of, or interference with) the economic mechanisms that make daily life possible could paralyze large areas if not whole countries; the idea that a government (say the President of the US under the proposed cybersecurity bill) could <a href="http://www.cio.com/article/597783/Senate_Panel_Approves_Controversial_Cybersecurity_Bill?source=CIONLE_nlt_infosec_2010-06-25" target="_blank">shut down key elements of the Internet for up to 120 days</a> without legislative recourse[2], could be more dangerous than the attacks themselves;</p>
<p>* An ISP in any particular country (say the US, for example) might be conflicted about whether to allow a sudden flood of traffic to pass through its network to “attack” some foe, or whether to stop that flood in order to preserve its ability to serve  customers—in fact the ISP probably wouldn’t be able to tell the difference;</p>
<p>In a sense, were someone to “shut off the Internet,” which proponents say S 3480 does not allow, it would be suicidal, since the defenders would also lose their ability to communicate with each other and to thwart any attack. Turning off the Internet would not only deny your opponent a playing field, but would deny defenders the ability to respond. And the collateral damage would be that all financial, manufacturing, transportation and other systems that depend on the net would also shut down</p>
<p>Lots of room for debate, but clearly governmental agencies and legislatures are beginning to think about the necessary means and the possible limits of their actions.</p>
<hr />
<p>[1] <em>We the People of the United States, in Order to form a more perfect Union, establish Justice, insure domestic Tranquility, provide for the common defense, promote the general Welfare, and secure the Blessings of Liberty to ourselves and our Posterity, do ordain and establish this Constitution for the United States of America.</em></p>
<p>[2] The <a href="http://hsgac.senate.gov/public/?FuseAction=home.Cybersecurity" target="_blank">Protecting Cyberspace as a National Asset Act</a> of 2010; some fear that this bill provides a “kill switch” the President of the US could use to “turn off” the Internet;</p>
<p>[-] <a href="http://www.guardian.co.uk/world/2010/may/23/us-appoints-cyber-warfare-general" target="_blank"><em>US Appoints first Cyberwarfare General</em></a> in guardian.co.uk</p>
<p>[-] EU Committee in UK on <a href="http://www.publications.parliament.uk/pa/ld200910/ldselect/ldeucom/68/6802.htm" target="_blank">protecting Europe against large-scale cyber-attacks</a></p>
<p>The post <a href="https://blog.red7.com/private-armies-in-cyberspace/">Private armies in cyberspace? A kill switch on the Internet?</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.red7.com/private-armies-in-cyberspace/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2800</post-id>	</item>
		<item>
		<title>Why “Shadows in the Cloud” should open your eyes</title>
		<link>https://blog.red7.com/shadows-in-the-cloud/</link>
					<comments>https://blog.red7.com/shadows-in-the-cloud/#respond</comments>
		
		<dc:creator><![CDATA[sky]]></dc:creator>
		<pubDate>Fri, 09 Jul 2010 16:09:00 +0000</pubDate>
				<category><![CDATA[CyberSpark]]></category>
		<category><![CDATA[Free Speech + Human Rights]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">http://blog.red7.com/?p=2773</guid>

					<description><![CDATA[<p>The public release of the document Shadows in the Cloud is important because this document contains some very important messages—stated very clearly—that haven’t really been said publicly before. If you’re not a cyberspace expert and don’t care for geek talk, you may think it’s just another report on cyber espionage. But the messages are important [&#8230;]</p>
<p>The post <a href="https://blog.red7.com/shadows-in-the-cloud/">Why “Shadows in the Cloud” should open your eyes</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-full wp-image-991" style="border: 0pt none; margin: 4px 12px;" title="cloud" src="/wp-content/uploads/2009/01/cloud.jpg" alt="" width="64" height="64" />The public release of the document <a href="http://shadows-in-the-cloud.net" target="_blank">Shadows in the Cloud</a> is important because this document contains some very important messages—stated very clearly—that haven’t really been said publicly before.</p>
<p>If you’re not a cyberspace expert and don’t care for geek talk, you may think it’s just another report on cyber espionage. But the messages are important for everyone. And my point is that they are very clearly explained!</p>
<p><strong>Ron Diebert</strong> and <strong>Rafal Rohozinski</strong>, in their Foreward, point out that crime and espionage go together. Or that wherever one goes, the other is soon to follow.</p>
<blockquote><p><img loading="lazy" decoding="async" class="size-full wp-image-2911 alignright" style="border: 0pt none; margin: 4px 12px;" title="drive-by-illustration" src="/wp-content/uploads/2010/04/drive-by-illustration.jpg" alt="" width="130" height="120" />They don’t say this directly—these are my words: Crime, espionage (and warfare) seep into the interstitial spaces of society and occupy any vacuum they find. And from there they can grow to occupy the whole of the space, like a mold, fungus, or rot.</p>
<p>What we are seeing in online attacks against free speech sites these days, particularly drive-by attacks<sup>[1]</sup>, is that they do not seem to be politically or idealistically motivated, instead they are opportunistic and (presumably) economically motivated because they&#8217;re focused on injecting spambots and trojans, not on altering the message of the nonprofit web site.</p></blockquote>
<hr />
<p>[1] See <a href="http://cyberspark.net/home.html" target="_blank">CyberSpark.net and click “drive-by</a>” on that page</p>
<p>The post <a href="https://blog.red7.com/shadows-in-the-cloud/">Why “Shadows in the Cloud” should open your eyes</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.red7.com/shadows-in-the-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2773</post-id>	</item>
		<item>
		<title>DDoS, EDoS, then &#8220;that bad aftertaste&#8221;</title>
		<link>https://blog.red7.com/that-bad-aftertaste/</link>
					<comments>https://blog.red7.com/that-bad-aftertaste/#respond</comments>
		
		<dc:creator><![CDATA[sky]]></dc:creator>
		<pubDate>Wed, 07 Jul 2010 16:09:06 +0000</pubDate>
				<category><![CDATA[CyberSpark]]></category>
		<category><![CDATA[Free Speech + Human Rights]]></category>
		<category><![CDATA[Our networked world]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Social Graph of Malware]]></category>
		<guid isPermaLink="false">http://blog.red7.com/?p=2846</guid>

					<description><![CDATA[<p>In early June, I was in a nice rainy East Coast US city for meetings dealing with particularly thorny issues related to ways the Internet experience is being killed off for regular folks—and for institutions (NGOs) that are promoting free speech and human rights. Over a small breakfast, I sketched in my book some notes [&#8230;]</p>
<p>The post <a href="https://blog.red7.com/that-bad-aftertaste/">DDoS, EDoS, then &#8220;that bad aftertaste&#8221;</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-1086" style="border: 0pt none; margin: 2px 12px;" title="seismogram-96x96" src="/wp-content/uploads/2009/03/seismogram-96x96.jpg" alt="" width="96" height="96" />In early June, I was in a nice rainy East Coast US city for meetings dealing with particularly thorny issues related to ways the Internet experience is being killed off for regular folks—and for institutions (NGOs) that are promoting free speech and human rights. Over a small breakfast, I sketched in my book some notes about the progression of malware over time. Basically paralleling <a href="http://thesocialgraphofmalware.com/home/" target="_blank">the development I describe in my site The Social Graph of Malware</a>, malware has gone from simple and juvenile defacement of web sites to become sophisticated and bandwidth-hogging socially-engineered schemes designed to get people to fall for a purchase they didn’t want to make,  or just to click a link to enroll their computer in a network of zombies poised to conduct nasty attacks on other people.<span id="more-2846"></span>What strikes me as the next stage in targeted attacks<sup>[1]</sup> hasn’t really been spoken of much, and the attacks only began in earnest during mid-2009—it’s that I think we’re entering an era in which attacks will be positioned to create a “bad aftertaste” and thus kill off the visitor/audience for some big web sites. The attacks are, in a sense, damaging the reputation, good will, and the <em>brand</em> of the attacked sites. These attacks take advantage of the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing</a> interface now <a href="http://www.mozilla.com/en-US/firefox/phishing-protection/" target="_blank">available in Firefox</a> and Chrome browsers, and the (new) <a href="http://brightcloud.com/" target="_blank">BrightCloud</a> toolbar for <a href="https://addons.mozilla.org/en-US/firefox/addon/161870/" target="_blank">Firefox</a> and for <a href="https://chrome.google.com/extensions/detail/imhcbdomggfmhmaeicplciogjbfamkep?hl=en" target="_blank">Chrome</a>—both of which alert a web user that they are about to use a web site that could contain malware [see diagram]. A would-be site visitor is presented with one of these “warnings” and is dissuaded from viewing the site. (Once the site has been cleaned up, the warning disappears, and visitors may decide to click through and go to the site anyway, if they wish.) The problem is that you are left with the <em>bad aftertaste<strong> </strong></em>of having gone to a legitimate site, seen this explicit warning, and you may decide never to go back even if the warning has been removed!</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-2864" title="blocking-diagram" src="/wp-content/uploads/2010/06/blocking-diagram.jpg" alt="" width="509" height="297" /></p>
<p><!--more--></p>
<p>In prior years, attacks have been positioned to “take down” legitimate businesses by denying access to their sites [DDoS].<sup>[2]</sup> Soon it was discovered (and is not widely exploited yet) that if an attacker simply hammers a site so hard that the defending organization has to dedicate more resources (read “money”) to defense, they can wear down the organization by depleting its budget and even its “will to stay alive online.” This doesn’t work if the attacker is just exploiting a site to drive traffic to its own illegitimate sales site, but it <span style="text-decoration: underline;">does</span> work if the attacker’s intent is to take the organization down.</p>
<blockquote><p>I already see evidence of small to medium attacks of the economic sort, and predict that we will see far more of them during the remainder of 2010 and 2011. I am working with NGOs now to prevent this type of “bad aftertaste” attack trend, and will report on how it’s going as I gather more information and evidence.</p></blockquote>
<p>To get a feel for how much this is happening, see the <a href="http://stopbadware.org/" target="_blank">StopBadware</a> and the <a href="http://badwarebusters.org/" target="_blank">BadwareBusters</a> web sites (forums where people are discussing these attacks and their remediation).</p>
<hr class="hr_dashed" />[1] Many attacks taking place on web site today are <em>opportunistic</em> rather than <em>targeted</em>, meaning that an attacker finds a web server that can be exploited and compromised and then uses it regardless of who it represents or affects. By and large, these attackers want to remain undiscovered, if possible, so the compromised server doesn’t get fixed any time soon. Therefore, it’s usually a “silent” attack with no immediately visible consequences on the web page.</p>
<p>[2] (Distributed) <a href="http://en.wikipedia.org/wiki/Denial-of-service_attack" target="_blank">Denial of Service attacks</a> bog down the target web servers so they can’t respond to legitimate requests from customers. They make it impossible to reach the business or organization. In some cases, the attacker asks for a “ransom” payment to stop the attack, is other cases they conduct a short-lived attack to make a protest or prove a point, and in some cases they continue their attack long enough to have a direct economic impact on the target.</p>
<p>The post <a href="https://blog.red7.com/that-bad-aftertaste/">DDoS, EDoS, then &#8220;that bad aftertaste&#8221;</a> appeared first on <a href="https://blog.red7.com">Sky&#039;s Blog</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.red7.com/that-bad-aftertaste/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2846</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 

Served from: blog.red7.com @ 2026-05-07 21:02:19 by W3 Total Cache
-->