Wednesday, May 3, 2023

The cost of data breaches is going way up

It's not just ransomware payouts ($455M yast year) - it's that the cost of investigations is way up

For the 20 largest network intrusions, the average investigation costs increased 24 percent from $445,926 in 2021 to $550,987 a year later.

And it's also the lawyers:

Another source of financial outflow are lawsuits filed against companies that had to notify individuals that their data had been accessed by criminals. Of the security incidents handled by BakerHostetler last year, 494 involved having to send out such notifications. Forty-two of those resulted in one or more lawsuits being filed by people unhappy about their data being stolen.

That compares to 23 such lawsuits filed in 2021.

More than half of the 42 incidents that resulted in lawsuits – 26 – involved medical and health information being breached, and 20 involved a healthcare organization. Forty included Social Security Numbers or driver's license data and six involved payment card information.

As costs go up, it's easier to justify higher IT security budgets.  Well, it should be.

Tuesday, May 2, 2023

Dad Joke CCLV

Why do kangaroo moms hate rainy weather? 

Because their joeys have to play inside.

US Navy research vessel Petrel tips over in drydock

 Well this isn't something that you see every day.


Big drop in FBI warrantless searches in 2022

It seems that this is related to increased oversight:

Warrantless searches of US residents' communications by the FBI dropped sharply last year – from about 3.4 million in 2021 to 119,383 in 2022, according to Uncle Sam.

But that is still likely tens of thousands more people than should have been caught up in the FBI's domestic surveillance efforts, according to advocates for reform of Section 702 – the legislative instrument that allows warrantless snooping.

The numbers mentioned above were revealed in the annual Office of the Director of National Intelligence report, released at the end of last week. The report came just after Congress held a subcommittee hearing on Section 702 surveillance authority.

This seems to be the pertinent detail:

Additionally, over the past year the FBI implemented new processes around Section 702 searches, including mandatory query training and "enhanced approval requirements for certain 'sensitive' queries, such as those involving domestic public officials or members of the news media."

It also now requires FBI agents to "opt-in" if they wish to run a search against Section 702-acquired data, instead of having queries run against this data by default.

Well good.

Sunday, April 30, 2023

Ennio Morricone - Soundtrack from The Mission

This is about as far from his better known spaghetti western scores as you can get.  


Friday, April 28, 2023

Missing software update caused Australia helicopter crash

People traditionally have been reluctant to install software updates because sometimes the update causes desired functionality to break.  This time, the entire helicopter broke because the patch wasn't installed:

Military figures claim a software upgrade for the European-designed Taipan helicopter was not installed on Australia's entire fleet despite warnings it could be needed to prevent possible engine failures.

...

Defence is refusing to comment on the "ongoing" investigation into the March 28 incident, but several figures familiar with the Taipan fleet say a simple IT patch could prevent the potentially devastating "hot starting" of the aircraft.

A "hot start" occurs when a pilot restarts the engine during a mission, shortly after powering down, instead of simply leaving the engine to idle before taking off again.

Former Taipan pilots and mechanics say the helicopter's turboshaft engines are not meant to be switched on and off repeatedly during an operation and are instead supposed to be powered up at the start, then shut down at the end.

...

Within three months, the MRH-90's prime contractor Airbus Helicopters, along with the engine manufacturer parent company Safran, had developed a software fix that would make it impossible for a pilot to unsafely perform a "hot start".

Several ADF sources, who declined to be identified so they could speak candidly, have told the ABC that the software upgrade was only ever installed on a handful of Australia's now 47-strong Taipan fleet.

This is pretty interesting in that the motivation to not install the patch seems backwards from what we usually see in the security world.

Thursday, April 27, 2023

This week has been living in the Valley of the Shadow of Death

Monday was Mom's funeral, delayed by Covid and family illnesses.  She's now with Dad for Eternety.

Yesterday and the day before it was cleaning out younger brother's (formerly Mom's) house.  He was a complicated guy, and the drugs were a part of that.  It seems that he was a fan of nitrous oxide.m  We disposed of all of that, so the house is straighter and cleaner than it's been for years.  But for both those days I was surrounded by ghosts.

Now I'm flying home, on the one-month anniversary of the day we had to put Wolfgang down.  It sure would be nice to have one of his greetings when I get there but the best I can hope for is his ghost.

I've had quite enough of death this week, thank you very much.  Would not recommend.

Wednesday, April 26, 2023

Endorsed

Peter thinks that short format social media makes people nastier:

I question whether most "short format" social media outlets are worthwhile any more.  Most seem to be overrun with people who talk their hind ends off, but don't listen very much - or very well.

Yup.

Tuesday, April 25, 2023

ANZAC Day

Good on ya, Cobbers. 

Making Battleship Ice Cream

Specifically, World War II Navy ice cream.  It looks pretty good, and the powdered milk and powdered eggs don't look like they are inferior substitutes for the fresh ingredients.  Plus a discussion of just how important ice cream was to morale.  Pretty cool. 

Monday, April 24, 2023

At Mom's funeral

It's been 2 years and 8 months since she passed on, but Covid threw a monkey wrench into having the ceremony.  But now the clan has gathered and she will finally join Dad today.

Blogging has been light since travel is a pain in the keister. 

Friday, April 21, 2023

Purveyors of used data

This is not surprising at all:

You know that you're supposed to wipe your smartphone or laptop before you resell it or give it to your cousin. After all, there's a lot of valuable personal data on there that should stay in your control. Businesses and other institutions need to take the same approach, deleting their information from PCs, servers, and network equipment so it doesn't fall into the wrong hands. At the RSA security conference in San Francisco next week, though, researchers from the security firm ESET will present findings showing that more than half of secondhand enterprise routers they bought for testing had been left completely intact by their previous owners. And the devices were brimming with network information, credentials, and confidential data about the institutions they had belonged to.

The researchers bought 18 used routers in different models made by three mainstream vendors: Cisco, Fortinet, and Juniper Networks. Of those, nine were just as their owners had left them and fully accessible, while only five had been properly wiped. Two were encrypted, one was dead, and one was a mirror copy of another device.

Like I said, not particularly surprising.  If you get rid of a device, you really should at the minimum do a factory reset.

Thursday, April 20, 2023

Passwords and Password Managers

Divemedic has a very good post up about password managers - applications that remember all the various passwords for the different apps and web sites you use.  A good password manager will let you basically have non-guessable/crackable passwords that would be too hard to remember on your own.

(He also has a good post on using Pass-phrases instead of passwords.  I've recommended this for like forever.)

The downside of password managers is that all your eggs are in the same basket.  The key is that you have to put a lot of trust in the reliability and trustworthiness of the password manager.  Divemedic's first post linked to above is a great analysis on when to bail on an insufficiently trustworthy password manager.

Wednesday, April 19, 2023

Dad Joke CCLIIII

Today's Dad Joke is visual.  It's also about Florida, and motorcycles.  Win-win-win!


 

Critical security patch for Chrome browser

If you visit a malicious web page the Bad Guy can execute code in your browser.  There is exploit code in the wild, so update your Chrome browser.

The vulnerability, tracked as CVE-2023-2033, can be exploited by a malicious webpage to run arbitrary code in the browser. Thus, surfing to a bad website with a vulnerable browser could lead to your device being hijacked. Exploit code for this hole is said to be circulating, and may well be in use already by miscreants.

This high-severity type-confusion bug is present in at least Chrome for desktop versions prior to 112.0.5615.121. Google released that version on April 14 for Windows, Mac, and Linux to close the security hole, which lies in the V8 JavaScript engine.

That new version should be installed as soon as possible, either automatically or manually.

 

Saturday, April 15, 2023

Clint Black and Roy Rogers - Hold On Partner

This is a delightful blast from the past won a Grammy in 1991.  It's striking just how much Clint Black looked like Roy Rogers.

Friday, April 14, 2023

Joe Bonamassa - Drive

It's been a while since I've posted Joe B.  This is an interesting, sort of acoustic offering.

Ransomware shuts down Super Yacht shipyard

Interesting:

German shipbuilder Lürssen, known for making super yachts for the exorbitantly wealthy, experienced a ransomware attack over Easter weekend that has incapacitated operations.

With a high revenue — it has an expected annual revenue of nearly $2.2 billion this year — it's likely that the shipbuilding company has a running roster of exclusive clients, making it a quality candidate for threat actors. And while Lürssen makes luxury yachts, it also builds sea vessels for the German navy, making the current standstill in production and operations due to the attack all the more unfavorable.

Extortion attempts similar to this one have targeted other luxury brands, such as Moncler and Ferrari, where, in the former's case, employee and customer data was stolen and leaked onto the Dark Web. It is currently unknown whether or not sensitive or personally identifiable information (PII) has been stolen from the shipping company; however, a Lürssen spokesperson has stated that they "immediately initiated all necessary protective measures and informed the responsible authorities."

 I expect that anyone who can afford a $100M boat would not be happy having their personal information leaked.

UPDATE 14 APRIL 2023 18:23: Youtube channel eSysman (who seems to cover all things Superyacht) gives his take (from a "Below Decks"/crew perspective).  It's interesting how he plays the "Spot The Yacht" game.  While it's kind of hard to feel too sorry for billionaires, I can't imagine that Lurssen's clients are happy at all.


Thursday, April 13, 2023

Dad Joke CCLIII

When does a joke turn into a Dad Joke?

When it becomes apparent. 

Wednesday, April 12, 2023

Feeding the Roman Army

This is a pretty cool video about how the Roman Army in Britannia kept its soldiers fed.  There's even a recipe for Roman pork with apples that looks pretty yummy. 


If you click "Watch on Youtube" then the recipe is listed in the notes along with links for where to buy obscure ingredients like garum.