Finland Goes on Cyber Offensive

Finland is about to “considerably enhance its cyber defence capabilities” with “counterpunch” and “cyber-weaponry”. Good marketing, but I’m pretty sure their supporting theory is not true

Lt. Gen. Arto Räty, permanent secretary at the Finnish MoD, added that “there can be no defensive capability without the ability to offer a counterpunch. The two things go hand in hand.”

Logically you can have defensive capability without a counterpunch. Regardless of whether I agree with their fighting style, however, I look forward to seeing yet another interpretation of Napoleon’s four innovations in offensive strategy, or Sun Tzu’s six principles.

I mean I wouldn’t be surprised if Finland started their presentation with the announcement that they have developed an enhanced cyber-sword to keep cyber-sheathed unless provoked…

BART Wireless Ban Email Exposes “Not a Whole Lot of Thought”

The spokesman for BART is known for phony astroturf campaigns and a failure to respond to criticism. That might seem normal for a spokesman of a service with ongoing and highly visible service issues. Yet recent reports show he might be taking things to an extreme with an inability to tell the truth about security decisions.

“We struggled with that decision,” spokesman Linton Johnson said at an Aug. 16 press conference. “That was a gut-wrenching decision. This agency takes free speech seriously.”

No one has any confidence in what Johnson says, which spurred a reporter in search of evidence to call his bluff. Here’s some excellent investigative reporting by the Bay Citizen:

But emails that BART released to The Bay Citizen this week show the decision was made on the spur of the moment with little discussion of the possible consequences. Officials approved one of the most controversial proposals in BART’s history just hours after it landed in their inboxes.

The final sign-off came from then-Interim General Manager Sherwood Wakeman between 8:30 and 8:45 a.m. at a meeting of top BART staff that began at 8:15 a.m., according to Jim Allison, a BART spokesman. The discussion of the idea lasted between 15 and 30 minutes.

Lynette Sweet, a BART board member who has criticized the shutdown, said the short timeline showed that “not a whole lot of thought went into it.”

Johnson just keeps digging a bigger hole for BART to fall into. The best quote in the email thread comes from BART deputy police chief, who shows just how “wrenched” the BART leadership guts were:

I like this idea. Can anyone think of a downside?

Anyone? Anyone? Can anyone who received this email think of a downside to shutting down communication?

Diesel-Hybrids Start Selling

Volvo has announced the V60 is now for sale and is pushing new promotional videos like this one that emphasize safety and low long-term costs — visit fuel stations just once a month. Only 40 views so far:

Peugeot also has announced a diesel-hybrid 508 RXH sports wagon (in brown, of course).

508 RXH

Marketed in France in 2011, and then the rest of Europe by the end of the year, it appears to be based on the diesel-hybrid technology developed for racing.

Peugeot’s diesel-hybrid version of its 908 sportscar underwent its first track test at Estoril, completing more than 300km in the hands of Nicolas Minassian, Stephane Sarrazin and Alexander Wurz.

908 race car
The barriers to adoption of this far superior technology are price and availability. But if consumers factor in the huge time saving from visiting a gas station half as often or less…the cost concern evaporates. If they are sold in America the only question that remains will be whether they can build cars fast enough (pun not intended) to meet demand.

New Sony Breach

Sony has created a public service announcement after their latest breach. They encourage users to choose a strong password.

We want to take this opportunity to remind our consumers about the increasingly common threat of fraudulent activity online, as well as the importance of having a strong password and having a username/password combination that is not associated with other online services or sites. We encourage you to choose unique, hard-to-guess passwords and always look for unusual activity in your account.

That’s because they are watching an increase in unauthorized access attempts to user accounts

We want to let you know that we have detected attempts on Sony Entertainment Network, PlayStation Network and Sony Online Entertainment (“Networks”) services to test a massive set of sign-in IDs and passwords against our network database.

[…]

Less than one tenth of one percent (0.1%) of our PSN, SEN and SOE audience may have been affected. There were approximately 93,000 accounts globally (PSN/SEN: approximately 60,000 accounts; SOE: approximately 33,000) where the attempts succeeded in verifying those accounts’ valid sign-in IDs and passwords, and we have temporarily locked these accounts. Only a small fraction of these 93,000 accounts showed additional activity prior to being locked.

At this point you might, like me, be thinking that someone is using a database of user accounts that was stolen in an earlier breach from Sony. Users who logged in after the last breach had to change their passwords. The accounts that had no “additional activity” must have been the ones that were enabled again but never used again — dormant with an old password.

But that’s not what Sony says in their announcement. They seem to suggest that passwords are changed so infrequently a bad password match from an attacker proves that the user IDs were not stolen from Sony.

These attempts appear to include a large amount of data obtained from one or more compromised lists from other companies, sites or other sources. In this case, given that the data tested against our network consisted of sign-in ID-password pairs, and that the overwhelming majority of the pairs resulted in failed matching attempts, it is likely the data came from another source and not from our Networks