https://www.theregister.com/2023/01/14/in_brief_security/ [user] [user] Sign in / up The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business Transformation CofenseGoogle CloudGoogle Cloud for Startups (X) Resources Resources Whitepapers Webinars Newsletters [front] Security 11 comment bubble on white NSA asks Congress to let it get on with that warrantless data harvesting, again 11 comment bubble on white Also: That Pokemon is actually a RAT, Uncle Sam fails a password audit icon Brandon Vigliarolo Sat 14 Jan 2023 // 20:57 UTC # In brief A US intelligence boss has asked Congress to reauthorize a controversial set of powers that give snoops warrantless authorization to surveil electronic communications in the name of fighting terrorism and so forth. NSA director General Paul Nakasone told the Privacy and Civil Liberties Oversight Board yesterday that the loss of Section 702 of the Foreign Intelligence Surveillance Act (FISA) would mean American spies would "lose critical insights into the most significant threats to our nation" if allowed to lapse on December 31. In his speech, Nakasone said Section 702 is "irreplaceable," and he provided several stories of the FBI and NSA cooperating using the law to stop terrorist plots and online attacks to justify his claim. [front] Section 702 was added to the Foreign Intelligence Surveillance Act in 2008, and has long been a bone of contention between civil liberties groups arguing it's a gross privacy violation, and those who say that, if you're not a terrorist, surely a little harmless observation by Uncle Sam is okay. [front] [front] The NSA has long held that Section 702 saved American lives and protected the nation and its allies, though documents declassified in 2019 showed that it was frequently used against US persons, despite the law specifically being designed to only apply to foreign targets. Despite those restrictions, the FBI was found to have used the database of electronic communications gathered from US telecom and tech companies under S.702 to search for records of US persons who were caught up in data gathering sweeps. [front] When asked about the use of Section 702-gathered data to surveil US persons during hearings over its previous renewal in 2017, the NSA refused to provide figures. "Seems like baloney to me ... It's the greatest intelligence service on the planet. You'd think they'd be able to know that," House Representative Jim Jordan (R-OH) said during the hearings. "Section 702 cannot be used to target Americans anywhere in the world or any person inside the United States regardless of nationality. No exceptions," Nakasone said. The records beg to differ, and this time they're known about before reauthorization hearings. Whether that'll change the outcome is another thing altogether. Avoid this Pokemon South Korean security firm Ahnlab says it has discovered a malware-spreading campaign that tries to trick netizens into downloading a remote access trojan - a backdoor for remote control in other words - disguised as a beta version of a new Pokemon card game. This Pokemon-themed malware is hiding in the tall grass, having been subtly tweaked to bypass security tools, the researchers warned. We're told that the trojan uses various legit tools, such as NetSupport Manager, AnyDesk, TeamViewer and others, to provide the backdoor access. These programs include config files with hard-coded command-and-control server IP addresses, as well as the ability to gain persistence by adding a shortcut to the Windows startup folder and adding a hidden appdata path. [front] Once installed, Ahnlab said, the attacker can make use of any of the features the remote control software includes, giving them potential total control over an infected system. While nothing in this malware campaign is particularly innovative or exceptionally dangerous, its Pokemon-themed delivery method is, even though the idea of using a children's game to trick kids into downloading malware isn't new. Federal parks agency fails password security audit ... badly The US Department of the Interior's mission is to protect America's natural resources, but it might have a hard time doing so if its systems remain as unsecured as a recent Office of the Inspector General report uncovered. There's no better way to relay the conclusions than the report itself: "We found that the Department's management practices and password complexity requirements were not sufficient to prevent potential unauthorized access to its systems and data," the OIG said [PDF]. Several of the bad practices found in DOI systems were the same that allowed the Colonial Pipeline ransomware attack to occur in 2021, the OIG said. Inspectors were able to crack 21 percent of the agency's passwords (totaling 18,174) - 16 percent of which they figured out within the first 90 minutes of investigating. Of the accounts it managed to break into, 288 had elevated privileges, and 362 belonged to senior US Government employees. In addition, the OIG said multifactor authentication wasn't consistently implemented at the DOI and password complexity requirements were "outdated and ineffective ... allow[ing] unrelated staff to use the same inherently weak passwords--meaning there was not a rule in place to prevent this practice." The DOI also wasn't deactivating unused accounts or enforcing password age limits, leaving more than 6,000 additional accounts vulnerable to attack, inspectors found. The Inspector General had eight recommendations for the DOI, including not implementing MFA methods that can be bypassed, as is currently the case, and enhancing password complexity requirements. More broadly, the OIG seems to want the DOI to develop a security posture that's less fly-by-night crypto space fintech startup, and more federal government agency with an $18.1 billion dollar budget. (r) Get our Tech Resources # Share Similar topics * Foreign Intelligence Surveillance Act * NSA * Password More like these x Similar topics * Foreign Intelligence Surveillance Act * NSA * Password * Privacy * Remote Access Trojan Narrower topics * cookies * Credential stuffing * LastPass * Privacy Sandbox Broader topics * Malware * Security * Trojan * United States Department of Defense * United States of America Similar topics # Share 11 comment bubble on white COMMENTS Similar topics * Foreign Intelligence Surveillance Act * NSA * Password More like these x Similar topics * Foreign Intelligence Surveillance Act * NSA * Password * Privacy * Remote Access Trojan Narrower topics * cookies * Credential stuffing * LastPass * Privacy Sandbox Broader topics * Malware * Security * Trojan * United States Department of Defense * United States of America TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Long data privacy notices aren't foolproof, Euro watchdog tells Meta As Meta reels from EUR390 million EU fine, the 'personalized ads' case might not be over, Max Schrem's legal group says Security13 Jan 2023 | 3 Wiretap lawsuit accuses Apple of tracking iPhone users who opted out This is the company that claims: 'Privacy. That's iPhone' Security10 Jan 2023 | 9 CES Worst in Show slams gummi gouging, money-wasting mugs, and other dubious kit Technology has the potential to make life better. This isn't it. Personal Tech6 Jan 2023 | 116 Simplifying digital sovereignty in a multi-cloud world Maintaining tight control of sensitive data is critical to digital business success, but how do you manage that complexity? Sponsored Feature [front] No more holidays for US telcos, FCC is cracking down In Brief Also, LastPass faces class action, and Louisiana says that, while the internet may be for porn, ID is still required Security8 Jan 2023 | 41 Canadian owes bosses for 'time theft' after work-tracking app sinks tribunal bid She hoped to score thousands but laptop app had other ideas Security13 Jan 2023 | 25 Palantir's Covid-era UK health contract extended without competition US spy-tech firm's controversial work with patient data pushed out 6 months due to delayed data platform procurement Databases4 Jan 2023 | 39 Google gets off easy in location tracking lawsuits $29.5 million and we don't have to admit wrongdoing? Where do we sign? Security3 Jan 2023 | 4 TikTok confirms it tracked journalists' locations as part of leak investigation As if you needed another reason to delete the app right now Networks23 Dec 2022 | 32 Lawyer mom barred from Rockettes show by facial recognition tech No Girl Scout cookies for you AI + ML21 Dec 2022 | 90 Parental control apps prove easy to beat by kids and crims 20m downloads can't be wrong? Or can they? Security21 Dec 2022 | 19 Epic payment: Fortnite maker pays record $520m to settle FTC case Updated Someone thought of the children, and the dark patterns Personal Tech19 Dec 2022 | 23 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js