NBC News Confuses the World About Cyber-Security 144

Nerval's Lobster writes "In a video report posted Feb. 4, NBC News reporter Richard Engel, with the help of a security analyst, two fresh laptops, a new cell phone, and a fake identity, pretended to go online with the technical naiveté of a Neanderthal housepet. (Engel's video blog is here.) Almost as soon as he turned on the phone in the Sochi airport, Engel reported hackers snooping around, testing the security of the machines. Engel's story didn't explain whether 'snooping around' meant someone was port-scanning his device in particular with the intention of cracking its security and prying out its secrets, no matter how much effort it took, or if the 'snooping' was other WiFi devices looking for access points and trying automatically to connect with those that were unprotected. Judging from the rest of his story, it was more likely the latter. Engel also reported hackers snooping around a honeypot set up by his security consultant which, as Gartner analyst Paul Proctor also pointed out in a blog posting, is like leaving the honey open and complaining when it attracts flies. When you try to communicate with anything, it also tries to communicate with you; that's how networked computers work: They communicate with each other. None of the 'hacks' or intrusions Engel created or sought out for himself have anything to do with Russia or Sochi, however; those 'hacks' he experienced could have happened in any Starbucks in the country, and does almost every day, Proctor wrote. That's why there is antivirus software for phones and laptops. It's why every expert, document, video, audio clip or even game that has anything at all to do with cybersecurity makes sure to mention you should never open attachments from spam email, or in email from people you don't know, and you should set up your browser to keep random web sites from downloading and installing anything they want on your computer. But keep up the fear-mongering."
  • by j_presper_eckert ( 617907 ) on Friday February 07, 2014 @02:16AM (#46183359)
  • Sochi (Score:4, Insightful)

    by Anonymous Coward on Friday February 07, 2014 @02:30AM (#46183405)

    It's not hard to believe there might be a lot of attacks on wireless devices in Sochi. The place is pretty fucked up. Whether these reporters and their consultants know their ass from a wifi antenna or not.

    From a story I've linked below:

    Dmitry Kozak, a Russian deputy prime minister in charge of preparations for the Olympics, complained about water being wasted by hotel guests when said; "We have surveillance video from the hotels that shows people turn on the shower, direct the nozzle at the wall and then leave the room for the whole day,"

    It didn't occur to Kozak that someone might have a problem [theverge.com] with being surveilled in the shower until after he blurted this interesting bit of knowledge.

    You just have to wonder what sort of pay-offs went into this Sochi Olympics deal. Russia is a deeply fucked up place to begin with and Sochi is a special level of fucked up within that.

  • by game kid ( 805301 ) on Friday February 07, 2014 @02:36AM (#46183419) Homepage

  • by phantomfive ( 622387 ) on Friday February 07, 2014 @03:26AM (#46183589) Journal

    but it does have a few interesting features.

    Like what?

  • by hcs_$reboot ( 1536101 ) on Friday February 07, 2014 @03:35AM (#46183619)
  • by Anonymous Coward on Friday February 07, 2014 @03:52AM (#46183673)

  • Same everywhere (Score:5, Insightful)

    by Tom ( 822 ) on Friday February 07, 2014 @04:11AM (#46183719) Homepage Journal

    It's the same everywhere you look. The current state of IT security is horrible, utter and total crap, and the main reason is that most of the people who work in the sector have no clue, starting from journalists like those and consultants and... well... almost everyone else.

    The reason is that much like cryptography, real security is hard. It's not something you pick up in a week course when your boss decides someone in the team needs to specialize on security. There are a great number of actual experts and over the years I've had the pleasure of meeting or working with many of them, but it's a small world and the total number of experts available world-wide is far smaller than the demand for manpower in the security "industry".

    Plus it's a bikeshed problem [wikipedia.org]. Lots of people know a little bit about security, so focus is given to the parts that people believe they understand, instead of the real problems. When I do consulting (I don't very much, I dislike it, but I occasional take jobs because I enjoy the problem, or the company) my metaphor for that is that in IT security, it is very easy to find someone who will sell and install you a 3-inch solid steel door with military level security locks for your front door, but very difficult to find someone who will walk around the house with you and point out the easily broken windows and the open basement door.

    Here's a free business hint: When you hire a security consultant, ask them for a quick suggestion for a password policy. If you get the two decades old "at least x letters, at least 1 special character, at least 1 number", don't hire them. That bullshit was adequate on Multics systems in the 70s. Today, it will weaken your password security if you programmatically enforce it. (and yes, I have the data to back that up, but that's a short presentation and not a comment field).

    So yes, these journalists are spreading bullshit. They are like the power users in a company - the nightmare of IT support. They probably know a little about security, just enough to get it wrong.

  • by Anonymous Coward on Friday February 07, 2014 @04:23AM (#46183759)

  • by pitchpipe ( 708843 ) on Friday February 07, 2014 @04:29AM (#46183785)

  • Re:Funny.. (Score:4, Insightful)

    by Thanosius ( 3519547 ) on Friday February 07, 2014 @05:10AM (#46183953)

  • by Anonymous Coward on Friday February 07, 2014 @06:29AM (#46184275)

  • Re:Funny.. (Score:3, Insightful)

    by Anonymous Coward on Friday February 07, 2014 @07:57AM (#46184633)

  • by dreamchaser ( 49529 ) on Friday February 07, 2014 @08:22AM (#46184735) Homepage Journal

  • by runeghost ( 2509522 ) on Friday February 07, 2014 @09:19AM (#46185021)

  • Re:Funny.. (Score:4, Insightful)

    by VortexCortex ( 1117377 ) <VortexCortex&project-retrograde,com> on Friday February 07, 2014 @01:57PM (#46187779)

