Wednesday, October 12, 2011

On Anonymous

Anonymous is a quasi-organized cyberintelligence group with formidable intellectual assets. They have the ability to take down major corporations, as well as government agencies. As a whole - their intent is amicable, however there are rogues with their own agendas.

What most people fail to understand is that software often controls hardware....

What happens if the hardware being controlled by the software is your local electric company, your metro-rail transportation control, or your 911/EMS center?

While I am an affectionado of the concepts and precepts of Anon, I further understand that they are a group wielding a power never before held, and with great power comes great responsibility.

I have visited their forums, their blogs, their community gatherings, and their war rooms. I understand in detail the means and methods by which they are attempting to induce social and economic reform. I am not altogether against their methods (at present) or (at least some of) their present agenda.

However - let it be perfectly clear - Anonymous is not under control. It is at best - quasi organized cyber anarchy. And we all know that there is only one possible outcome from anarchy - revolution. Anarchy promotes civil unrest, which escalates into public protests, which when they are either ignored or suppressed by the government, turn into rioting and civil war/revolution.

But these guys can only cause software and connectivity problems right? Guess again.

In this article (http://www.wired.com/dangerroom/2011/10/drone-virus-kept-quiet/) you will find that SOFTWARE controlling military hardware was hacked via a keystroke virus. A keystroke virus is one that reads the keystrokes of a particular computer system, and broadcasts it to a 3rd party so they can examine it.

This is not dissimilar to the movie "war games" where the kid uses a tape recorder to record the button pushes that open the door, then later plays it back to open the door.

Given enough time, the keystrokes can be examined and new commands created - to control the planes. It can be used by a terrorist group to turn the planes against our own troops. This, of course, is the problem with ANY remotely controlled system - it can be taken over by someone closer with a stronger transmitter.

Am I saying that this virus was the work of Anonymous? Absolutely not. What I am saying, is that many (not all) of the folks in Anon are capable of writing, or using such a program to their advantage. They could take ANY system which is connected to the Internet, tunnel into it, and wipe it out. Most of them are not "cyber-terrorists". Many are teenage/college students, many self trained, with a desire and willingness to promote communal change. Some are more seasoned veterans, but the veterans are not necessarily in charge. They are as a whole, however, determined, intelligent individuals with the skills, abilities, and wherewithal to cause severe damage if they were backed into a corner.

As such - it is IMPERATIVE that ANY sensitive or critical system be completely and totally isolated from the Internet, and that strict protocols be followed in the transferring, updating and/or adding of software to these systems.

They can NOT be connected via a VPN or firewall, which can be breached, or they open themselves up to a host of possible problems. I do not care what your IT person tells you. Theory is great...REALITY WINS! There is no such thing as a completely secure system. If it is in any way, shape, or form connected to the Internet - it is unsafe. Banks, TV Stations, Hospitals, Government Agencies, etc SHOULD have their own connectivity system, not connected to the Internet. They should have an intranet, and an Internet - and at no time should either be allowed to be connected for any reason.

If life and limb depends on it, if you do not want it ever to go down or be compromised - connecting it to the public Internet in any way shape or form is a dire mistake.

No comments:

Post a Comment