Friday, February 22, 2013

Security Scrapbook Reader's Question - Spy School

Q. "I really enjoy your articles. Let me ask you: Would a spy school go over here in the U.S.?"

A. It probably would. There are plenty of people - from kiddies to Mitty's - who think spying is cool, albeit illegal. Training is probably not illegal, just implementing the skills. 

I educate my clients on spying techniques, just so they know what to look out for. Being aware helps them protect themselves against spying. 

Come to think of it, we are one of the very few countries whose government spy agencies do not support the private sector with the business intel they collect. Perhaps there is a spy school niche market, to help us level the international economic playing field. Hummm... Just don't have your Bonds reporting to HR or Facilities, like the security departments I see in some corporations.

Examples of spy schools, games and books...
http://www.jamesbondlifestyle.com/news/bond-experience-launches-november-7th
http://thebondexperience.com
http://www.spymuseum.org/education-programs/
http://www.stilettospyschool.com/newyork.php
http://www.mi6academy.com/newyork.php
http://www.spyschool.com/
http://www.beyondweird.com/survival/sschools.html
http://www.fxnetworks.com/archer/spyschool (game for kids)

Spy School (book for kids) 
Another Spy School (book for kids)
So You Want to Be A Spy (book for kids)
So you want to be an industrial spy? (rare, out of print)
The Complete Idiot's Guide to the CIA (book)
Spy's Secret Handbook (Project X Top Secret) (book for kids) 

It's True! This Book is Bugged (book for kids) 
How to be a Spy: The World War II SOE Training Manual
The Spycraft Manual: The Insider's Guide to Espionage Techniques

The Official CIA Manual of Trickery and Deception
The Spy's Handbook: Learn How To Spy On Anyone At Anytime Without Getting Caught By Using Spy Gadgets And Other... 

 

Thursday, February 21, 2013

Business Espionage - Quote of the Month

“This is an absolute tidal wave of criminal activity, and we’re not even scratching the surface. We are literally having our nation systematically stolen out from under us.”

 Brett Kingstone, a one-time victim of trade secret theft and writer of The Real War Against America, a book that details how his start-up company was crippled by the theft of trade secrets related to LED lighting. (more)

Spykpe

A technology called Legal Intercept that Microsoft hopes to patent would allow the company to secretly intercept, monitor and record Skype calls. And it's stoking privacy concerns. (more)

We're shocked. q.v. - Yesterday's story.

Express Scripts vs. E&Y - Trade Secret Theft Allegations

Express Scripts Inc. sued the accounting firm Ernst & Young LLP and one of its partners for the alleged theft of trade secrets and misappropriation of the pharmacy benefit manager’s confidential and proprietary data.

The Express Scripts Holding Co. unit said in a complaint filed yesterday in state court in Clayton, Missouri, that it learned last year that accounting firm partner Don Gravlin had been “sneaking” into its St. Louis headquarters and e-mailing documents to a private Google account via the account of an Ernst & Young consultant...

The accountants allegedly took the equivalent of more than 20,000 pages of data, including pricing information, business strategy, projections and “performance metrics” documents, to aid development of Ernst & Young’s own health-care business segment, which includes Express Scripts and Medco Health Solutions Inc., which it acquired last year, as well as some of their competitors. (more)

Wednesday, February 20, 2013

U.S. Unveils New Strategy to Combat Trade-Secret Theft

The White House unveiled a new strategy to exert pressure on China and other countries that engage in corporate espionage against the U.S. as part of a new Obama administration push to counter cyberattacks and commercial spying.

The strategy, released Wednesday in a report that was the subject of a White House meeting, raised the prospect of stepped-up U.S. trade restrictions on products and services derived from stolen trade secrets. Officials also outlined a series of diplomatic actions to reinforce the administration's commitment to curbing such thefts.
 

The new push comes on the heels of fresh revelations of Chinese cyberspying and represents an effort by Washington to respond to growing complaints about theft of military and corporate secrets, with a number of the allegations focusing on China. (more)  

Trade restrictions and diplomatic actions are historically ineffective, not to mention unrealistic and counterproductive when trying to develop a global economy. These hand slaps are likely viewed as a cost of stealing doing business. Reward outweighs punishment. 

The missing element in intellectual property protection... 
Holding caretakers responsible. If your information would hurt the country if stolen, there should be a legal duty to protect that information. Add that element to trade restrictions and diplomatic actions, and you may just have a workable counterespionage strategy. Hey, it works for the other guys. (more)

P.S. "Promote Voluntary Best Practices by Private Industry to Protect Trade Secrets" (Section 2 of the report) is both vague and voluntary. It will never be adopted. Why? Two words... Risk Analysis. Think HIPAA or Sarbanes-Oxley would work if they were just voluntary best practices?

Don't get me started.
~Kevin

Skype Plebes Petition Redmond Patricians

A coalition of activists, privacy organizations, journalists, and others have called upon Microsoft to be more forthright about when, why, and to whom it discloses information about Skype users and their communications.

In an open letter published on Thursday, the group argues that Redmond's statements about the confidentiality of Skype conversations have been "persistently unclear and confusing," casting the security and privacy of the Skype platform in doubt...

The group claims that both Microsoft and Skype have refused to answer questions about what kinds of user data the service retains, whether it discloses such data to governments, and whether Skype conversations can be intercepted. (more)


"more forthright" 
"in doubt" 
Please.

The original Skype-in-the-wild was viewed as high security privacy tool. Guess who didn't like that. Guess why Skype was "bought" in from the wild and given adult supervision. (Think Spypke.)

Post de facto petitioning is painful to watch. If you want privacy, you need to start much earlier in the game. It begins with self-reliance.  

Example: You don't see smart corporations sitting around waiting for 'the government' or some free software to protect their information. No, they take proactive measures like TSCM and IT security. They don't wait and whine later.

Yet Another Teleconference Eavesdrop (with recommendations)

Alaska’s largest statewide commercial fishing trade association announced (it will) request Alaska authorities to investigate what they say was unauthorized eavesdropping of their United Fishermen of Alaska private teleconference by the Kenai River Sportfishing Association's office.

According to UFA Interim President Bruce Wallace, on January 17, 2013 the United Fishermen of Alaska, representing 34 member organizations, held a private teleconference. 

In addition to 25 UFA Board members, UFA alleges an individual or individuals at the offices of the Kenai River Sportfishing Association (KRSA) was also on the line during the private teleconference.

This allegation was later confirmed by the teleconference vendor, who provided a phone log, which included a phone number registered to the Kenai River Sportfishing Association (KRSA) office. KRSA is not affiliated with UFA in any way. (more) (REAL Spy Fishing)


A reminder to our clients, and a free sample for potential clients...

Murray's Teleconferencing Checklist

Passcodes...
     • Change all current passcodes, now.
     • Prohibit employees from mass e-mailing or posting passcodes.
 

Switch to a conference call system with accountability features...
     • each participant is given a unique passcode,
     • the passcode is changed for each new conference call,

     • only the pre-authorized number of callers may be admitted,
     • and a record of all call participants is available to the call leader.
 

Send Employees for Counterespionage Training? Brilliant!

Russia - Reviving the Soviet cult of vigilance in the digital age, the administration of Russia’s second biggest city launched a tender to teach its officials the basics of combating technological espionage.

A hand-picked cadre of 25 civilian bureaucrats in St. Petersburg will train in ways of “countering foreign technical intelligence services and technical data protection,” according to the tender’s description... The course would last for 108 hours and end in a test. The tender has a price tag of 727,000 rubles ($24,000)...
 
In December, the administration of St. Petersburg – headed by Governor Gennady Poltavchenko, also a former KGB officer – also contracted anti-espionage companies to look for covert listening devices in its offices, Fontanka.ru city news website reported. (more)

The ROI on this should be tremendous. 
Every organization should be so smart. 
~Kevin

Tuesday, February 19, 2013

United States Intelligence Community - Virtual Career Fair

The United States Intelligence Community (IC) invites you to attend the fourth annual IC Virtual Career Fair - a free online event - on Tuesday, February 26, 2013, from 2 p.m. to 8 p.m. (Eastern). 

Space is limited. To guarantee entrance, pre-registration is highly encouraged. Reserve your spot today!

Don't miss this opportunity to learn about IC careers and get tips on how to apply for positions.

The following agencies and components will be participating in the 2013 IC Virtual Career Fair:
Central Intelligence Agency (CIA)
Defense Intelligence Agency (DIA)
Federal Bureau of Investigation (FBI)
FBI Language Services Section (FBI LSS)
National Geospatial-Intelligence Agency (NGA)
National Security Agency (NSA)
National Virtual Translation Center (NVTC)

Weird Security News of the Week

Japanese police believe they have finally caught the man behind an extraordinary malware campaign that included taunting police in January by sending them clues on an SD card strapped to a cat.

According to TV station NHK, 30 year-old Yusuke Katayama was picked up after Tokyo police accessed CCTV pictures that showed the accused near the animal not long before the memory card was retrieved from its collar.
 

It later emerged that police had attempted to coerce confessions from four of the innocent suspects which led to a hugely embarrassing climbdown when they were shown to be uninvolved.

Disturbing messages were also received by a lawyer in Tokyo and a TV station threatening suicide, backed up by a picture of an anime doll inside a noose made from Ethernet cable. (more)


More strange security news...
Ex employee wiped financial data from bikini bar
Fugitive John McAfee taunts police as he evades capture
Burglar unintentionally films robber while using iPhone as flashlight

Mechanic Hits Emails at Rival Limo Firm

A Las Vegas limousine company executive was convicted Friday of hacking into the emails of his former employer. 

John Sinagra, vice president and general manager of VIP Limousines of Nevada, was indicted last year on charges of obtaining information from a protected computer and aggravated identity theft.
 

Federal prosecutors alleged that Sinagra, who once was charged as a mob hitman in a sensational New York murder case, hacked into the emails of rival Las Vegas Limousines, owned by Frias Transportation, and stole key information. (more) (The Mechanic)

Hobby Drones Under Fire

On Dec. 26, a grand jury handed down several indictments against the owners of the Columbia Packing Company for dumping pig blood into a creek. They now face hefty fines and even prison time stemming from the water pollution, and the plant has since been shuttered. 

Neighbors had complained about noxious fumes and other issues for a while, according to the local news. But investigators didn’t get involved until this drone pilot took his pictures.

Under a new law proposed in the Texas legislature, sponsored by a lawmaker from the Dallas suburbs, this type of activity could soon be criminal. Not the pollution--the drone. (more)


And from down under...
One Tasmanian man is using a drone to help take video in tricky places and some of the video has gone viral. (video)

A UAV Alternate POV

Cute animated video from The New York Times... (more)

Sunday, February 10, 2013

Two Princesses in a Bug House

GLOBE reveals that the royal couple’s new home, Kensington Palace, is bugged, and it seems that Camilla Parker-Bowles is the prime suspect for bugger. 

According to the cover of GLOBE’s current edition, February 18, two listening devices were discovered right inside the couple’s apartments. In this royal bombshell GLOBE will explain exactly how and where the royal bugs were discovered and why suspicion naturally fell on evil Camilla.

Now that the bugs have been discovered and removed what will Camilla do? Do you think that there are other listening devices spying on the royal couple? (more)

Déjà vu...
Princess Diana hired a private security firm to secretly sweep Kensington Palace for bugs.

She was so concerned about eavesdropping that she called in a four-man team to carry out a search for listening devices.

The check was ordered in May 1993 after the princess expressed fears that her conversations were being monitored...

 
But it went disastrously wrong when police detained the security firm's workers, who had arrived at the palace posing as carpet-fitters...


She had her butler Paul Burrell and his colleague Harold Brown - later both cleared of stealing from her after her death - arrange for the de-buggers to access the palace without the police knowing.

They gained access to the palace by claiming to be from a carpet firm. The secret mission was only discovered-when one of the team went to the palace gate house and asked for access to mainframe telephone equipment located in the engineers' room next to the police gate house.

Officers became suspicious and realised that the team from Moran Security Support Services Ltd had been contracted to "de-bug" the royal apartment. (more)

If the competition isn't bugging you, they are probably doing this...

Interesting read...
A competitive intelligence consultant discusses things that can help a business--at the expense of another. (more)