Sunday, 23 February 2014

Facebook deal shifts focus to cyber security, privacy


 Pic: Manna Kanuga
Thursday's sensational Facebook-WhatsApp deal is receiving widespread attention not just in industry but even government circles, according to sources.
Media reports suggest that Facebook's decision to buy WhatsApp was heavily influenced by the former's desire to dominate all online/wireless communications of the masses in emerging markets or EM, a group that includes India.
Given recent concerns about Facebook user privacy, incidents of Western and Chinese snooping, intensifying organised hacking and web-based WhatsApp's large following in India, Thursday's deal is seen as a potential cause for concern.
More so because internet user base in India is rapidly growing, but internet security remains dismal, unlike in the US (see chart).
"There is a great need for unified security in India," said Shantanu Ghosh (pictured), vice-president and MD, India product operations, Symantec, a leading global cyber security firm. "Information security is not something exotic anymore. It is important to defend India's information against today's most advanced threats."
According to a Computer Emergency Readiness Team (Cert of the US) report, 4,191 Indian websites were hacked in August last year, up from 1,808 in May last year.
India requires over 5 lakh information security professionals by 2015, according to government reports. But supply of skilled professional is inadequate. Cert alone spends over $100 million on IT security, huge when compared to India's $7 million spend.
Although India has the maximum number of engineering graduates in the world, only 1% of Indian IT students have been found skilled in the information security space, said experts.
A recent European Commission report noted: "In a recent move to up the ante on cyber security, the government (of India) hired 4446 experts. But the important question here is, is it an inadequate number in a very exposed system? Similarly, the corporate world in India has just started to acknowledge the need and the dearth of professionals in the field, with leading corporates taking steps in the direction."
Over the past few years, stored or electronically accessible information has become the most valuable asset for organisations as borders disappear in the internet age. This is particularly true for organisations in government, IT, financial institutions, telecom, mobility, internet and healthcare as they are more vulnerable to cyber threats because of the nature of data they handle.
For security of such data, India needs thousands of skilled professionals, a shortage that is unlikely to be filled any time soon. And with digital firms such as Google, Facebook, Twitter, Instagram, YouTube and WhatsApp acquiring dimensions of global behemoths, the need was never more acute than now, experts said.

South Korea to develop Stuxnet-like cyberweapons

South Korean soldiers   

South Korean plans to develop Stuxnet-type weapons to damage North Korean nuclear facilities
South Korea is to develop cyber-attack tools in an attempt to damage North Korean nuclear facilities.
The country's defence ministry wants to develop weapons similar to Stuxnet, the software designed to attack Iranian nuclear enrichment plants.
The South Korean military will carry out missions using the software, the defence ministry said.
One computer security expert said that using cyberweapons could be "very dangerous".
The defence ministry reported its plan to the government on 19 February, the Yonhap news agency reported.

Start Quote

You might be targeting one thing, but it could spread”
Prof Alan Woodward Computer security expert
In 2006, North Korea said it had successfully tested a nuclear weapon, spreading alarm through the region. Intensive diplomatic efforts to try to rein in North Korea's nuclear ambitions continue.

Online propaganda

The development of weapons capable of physically damaging North Korean nuclear plants and missile facilities is the second phase of a strategy that began in 2010, Yonhap said.
The first part of South Korea's plan, which is continuing, is to conduct online propaganda operations by posting to North Korean social networking and social media services.
"Once the second phase plan is established, the cybercommand will carry out comprehensive cyberwarfare missions," a senior ministry official said.
The South Korean cyberwarfare command, which will use the weapons, has been dogged by accusations of using its psychological warfare capabilities on its own population to try to influence voters in the run-up to the 2012 presidential elections.
Attempting to use cyberweapons to physically damage critical infrastructure could drastically backfire, Prof Alan Woodward, a computer security expert at the University of Surrey, told the BBC.
"I think it's very dangerous," he said. "[The weapon] could end up damaging all sorts of things you never intended it to."
Once Stuxnet was released, its spread was impossible to predict or control, Prof Woodward said.
 

Vulnerable

The code was designed to target Iranian nuclear enrichment facilities and disrupt a suspected nuclear weapons development programme.
However, the code attacked Siemens control systems used not only in the facilities but also in electrical generation plants, factories and water treatment works.
"You might be targeting one thing, but it could spread," Prof Woodward said. "All those other forms of infrastructure become vulnerable."
Malicious code such as Stuxnet does not respect national boundaries. Cyber-attack code developed by South Korea could rebound and end up damaging South Korean infrastructure that uses the same technologies, he said. The code could spread internationally.
In addition, once the attack code is released, malicious hackers or military personnel anywhere in the world would be able to study a sample and use the weapons against another target, Prof Woodward added.