Tuesday, 10 February 2015

Fearing an FBI raid, researcher publishes 10 million passwords/usernames

Dan Goodin, Ars Technica
A security consultant has published 10 million passwords along with their corresponding usernames in a move he characterized as both necessary and legally risky given a legal landscape he said increasingly threatens the free flow of hacking-related information.
Most of the existing corpus of passwords exposed in hack attacks is stripped of usernames, preventing researchers from studying the possible relationship between the two fields. Mark Burnett, a well-known security consultant who has developed a specialty collecting and researching passwords leaked online, said his sole motivation for releasing the data was to advance what's already known about the way people choose passcodes. At the same time, he said he was worried the list might land him in legal hot water given the recent five-year sentence handed to former Anonymous activist and writer Barrett Brown, in part based on links to hacked authentication data he posted in Internet chat channels.
"I think this is completely absurd that I have to write an entire article justifying the release of this data out of fear of prosecution or legal harassment," he wrote in a post published Monday night on his blog. "I had wanted to write an article about the data itself but I will have to do that later because I had to write this lame thing trying to convince the FBI not to raid me."
Last March, federal prosecutors dropped criminal charges related to links Brown left in two Internet relay chat channels that were frequented by members of the Anonymous hacker collective. The links led to authentication data taken during the December 2011 hack on Strategic Forecasting by members of Anonymous. Before dropping the charge, prosecutors said the links amounted to the transfer of stolen information. Even though the charge was dropped, however, prosecutors still raised the linking to support their argument Brown deserved a long prison sentence.
In Monday night's post, Burnett also raised changes the Obama administration is proposing to federal anti-hacking statutes. Many security professionals have said the revised law would outlaw the publication of links to public password dumps even if the person making the link had no intent to defraud. If the people sharing the information have any reason to believe someone might use it to gain unauthorized computer access, critics have argued, they would be subject to stiff legal penalties under the Computer Fraud and Abuse Act.
Burnett wrote:
But recent events have made me question the prudence of releasing this information, even for research purposes. The arrest and aggressive prosecution of Barrett Brown had a marked chilling effect on both journalists and security researchers. Suddenly even linking to data was an excuse to get raided by the FBI and potentially face serious charges. Even more concerning is that Brown linked to data that was already public and others had already linked to.
In 2011 and 2012 news stories about Anonymous, Wikileaks, LulzSec, and other groups were daily increasing and the FBI was looking more and more incompetent to the public. With these groups becoming more bold and boastful and pressure on the FBI building, it wasn’t too surprising to see Brown arrested. He was close to Anonymous and was in fact their spokesman. The FBI took advantage of him linking to a data dump to initiate charges of identity theft and trafficking of authentication features. Most of us expected that those charges would be dropped and some were, although they still influenced his sentence.
At Brown’s sentencing, Judge Lindsay was quoted as saying “What took place is not going to chill any 1st Amendment expression by Journalists.” But he was so wrong. Brown’s arrest and prosecution had a substantial chilling effect on journalism. Some journalists have simply stopped reporting on hacks from fear of retribution and others who still do are forced to employ extraordinary measures to protect themselves from prosecution.
Which brings me back to these ten million passwords.

Why the FBI Shouldn’t Arrest Me

Although researchers typically only release passwords, I am releasing usernames with the passwords. Analysis of usernames with passwords is an area that has been greatly neglected and can provide as much insight as studying passwords alone. Most researchers are afraid to publish usernames and passwords together because combined they become an authentication feature. If simply linking to already released authentication features in a private IRC channel was considered trafficking, surely the FBI would consider releasing the actual data to the public a crime.
Including usernames alongside passwords could help advance what's known about passwords in important ways. Researchers, for instance, could use the data to determine how often users include all or part of their usernames in their passwords. Besides citing the benefit to researchers, Burnett also defended the move by noting that most of the leaked passwords were "dead," meaning they had been changed already, and that all of the data was already available online.
As password dumps go, 10 million is a large number, but it's still small compared to the seminal 2009 hack of gaming website RockYou, which leaked 32 million passcodes, 14.3 million of which were unique. Last year, The New York Times reported that Russian criminals amassed a database of more than one billion passwords gathered from more than 420,000 websites. As Burnett noted, what sets this latest dump apart is that it was made by a security professional with the goal of advancing the public understanding of password choices. Equally noteworthy will be the reaction it receives from prosecutors.

White House to set up new early warning cyber-threat center



The new cyberthreat center will help build intelligence amid cyberattacks (Image: NSA)
The U.S. government is to set up a new agency to monitor cyber-threats and share intelligence.
In a speech Tuesday, assistant to the president for homeland security and counterterrorism Lisa Monaco announced the new division would be a new intelligence-based center that will "connect the dots" between incoming cyber-threats so that various government agencies can be aware, and prepare.

Ahead of the State of the Union later this month, the president's proposed laws aim to force companies to disclose hacks and breaches inside a month.
"Cyber-threats to our national security and economic security are increasingly in their frequency and sophistication." Monaco said. "No-one it seems is immune, from healthcare companies and universities, to technology companies.
She warned that nation states and non-state hackers are constantly "seeking to steal, to spy, to manipulate, and to destroy data."
President Obama made cyber-threat and intelligence sharing a key priority in his State of the Union address last month, in which he promised better cybersecurity in the wake of high-profile hacks against Sony Pictures, and most recently health insurance provider Anthem.
A number of federal agencies, including the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Dept. of Homeland Security (DHS), all have divisions focusing on cybersecurity.
The Obama administration wants the newly-formed Cyber Threat Intelligence Integration Center (CTIIC) to do exactly that -- linking the various federal divisions in order to create a "seamless intelligence flow," according to an official speaking to Reuters on Tuesday.
"There's so many different pieces of intelligence coming in, you've got to collaborate and put it together," said CrowdStrike president Shawn Henry on CBS This Morning.
The new agency, which will begin with about 50 staff and a budget of $35 million, aims to learn from the intelligence failings that led to the September 11 terrorist attacks in New York, officials said.
"We need to sync up our intelligence with our operations, and respond quickly against threats to our citizens and companies," said Monaco.
The center will "have to work in lock-step with the private sector," she said. "The federal government won't leave the private sector to fend for itself. Partnership is a precondition of success."
That means "daily collaboration" to identify threats in order to stave off attacks. She said in an example that the U.S. government will alert private sector companies as soon as it becomes available to it, in an effort to prevent attacks from happening.
But Monaco confirmed CTIIC will "not collect intelligence."
The director of national intelligence James Clapper will head up the division.