Showing posts with label dhs. Show all posts
Showing posts with label dhs. Show all posts

Sunday, September 9, 2012

Obama Administration Will Spend $1 Billion on Iris & Facial Recognition Technology


Candice Lanier - For over a year and a half, the Mexican government has been collecting an unprecedented amount of biometric data from minors ages 4 to 17 as part of a youth ID card program. The Electronic Frontier Foundation reports that the data is being gathered for Personal Identity Cards for minors. This I.D. card, according to Mexican authorities, will help streamline registration in schools and health facilities and comes embedded with digital records of iris images, fingerprints, a photograph and a signature for each minor.

EFF reports:
The ID card project is part of the integration of Mexico’s National Population Register (RENAPO), which is intended to provide a unique identity system to conclusively prove identities of all Mexican citizens. Under the program, the Ministry of the Interior will issue Citizen Identity Cards and Personal Identity Cards containing biometric information, first to youth, and later extending to Mexico’s entire adult population.

Since July of 2009, when President Felipe Calderón officially announced the creation of RENAPO, numerous observers have sounded the alarm that the endeavor violates individuals’ privacy rights. Despite serious concerns raised by a governmental accountability agency and a special commission tasked with studying the program, in January of 2011 Mexico nevertheless became the first country in the world to use iris scans as a component of ID cards.”
Meanwhile, the Department of Homeland Security (DHS) has been expanding its biometrics source from fingerprint to iris and facial recognition for identity verification. In addition to collecting iris and facial images on suspected illegal immigrants or immigrants arrested at border patrol stations,the DHS is also developing a program called Future Attribute Screening Technology.  The purpose of the program is to “detect cues indicative of mal-intent” based on factors including ethnicity, gender, breathing, and heart rate.

More

Monday, January 2, 2012

Homeland Security warns about security flaw affecting millions of wireless routers

US-CERT warns about security flaw affecting millions of wireless routers


The US Department of Homeland Security has issued a warning about a vulnerability that exposes millions of wireless routers to brute force attacks.

A design flaw in the WiFi protected setup (WPS) specification for the PIN authentication used by many wireless routers “significantly” reduces the time required to launch a brute force attack against the PIN because the flaw allows an attacker to know when the first half of the eight digit PIN is correct, warned the US Computer Emergency Readiness Team (US-CERT) in a vulnerability note.

The lack of a proper lock out policy after a certain number of failed attempts to guess the PIN on wireless routers makes this brute force attack that much more feasible.

“An attacker within range of the wireless access point may be able to brute force the WPS PIN and retrieve the password for the wireless network, change the configuration of the access point, or cause a denial of service”, US-CERT said.

WPS is a standard developed by the WiFi Alliance to ease the set up of a wireless home network. WPS contains an authentication method called “external registrar” that only requires the router’s PIN, US-CERT said.                 More

Wednesday, July 27, 2011

DHS Fears a Modified Stuxnet Could Attack U.S. Infrastructure



Wired - One year after the discovery of a sophisticated worm that was used to attack centrifuges in Iran’s nuclear program, the U.S. Department of Homeland Security told Congress it fears the same attack could now be used against critical infrastructures in the U.S.

DHS “is concerned that attackers could use the increasingly public information about the code to develop variants targeted at broader installations of programmable equipment in control systems. Copies of the Stuxnet code, in various different iterations, have been publicly available for some time now,” Bobbie Stempfley, acting assistant secretary for the DHS Office of Cybersecurity and Communications, told the House Subcommittee on Oversight and Investigations (.pdf) on Tuesday.

The testimony comes in the wake of accusations that the U.S. was itself responsible, along with Israel, for developing and unleashing Stuxnet into the wild, thereby making it possible for the hackers, nation-state attackers and terrorists that DHS fears, to now repurpose the malware for use against critical infrastructure systems in the U.S.

Stuxnet, considered to be the first cyberweapon discovered in the wild, was found on a computer in Iran in June 2010 and was believed to have been launched in June 2009.

Private researchers who spent months digging through the code, discovered that the sophisticated malware was designed to target a specific industrial control system made by Siemens, and replace legitimate commands in the system with malicious ones. But Stuxnet wasn’t out to destroy just any Siemens system – it sought out the specific system believed to be installed at Iran’s nuclear enrichment plant at Natanz. Any system that didn’t have the same configuration as the system Stuxnet targeted would go unharmed.      More

Tuesday, July 12, 2011

DHS says foreign parties put malware in products imported into US

A top Department of Homeland Security (DHS) official told Congress that some software and hardware being imported into the US contains malware planted there by foreign parties.

 

Infosecurity.Com - Greg Schaffer, acting deputy undersecretary of DHS’s National Protection and Programs Directorate, told a House panel last week that his office is “aware” of instances where malware was loaded onto software and hardware made in other countries and sold in the US.

Schaffer made the admission in response to a question by Rep. Jason Chaffetz (R-Utah), who sits on the House Oversight and Government Reform Committee. The committee was holding a July 7 hearing on the Obama administration’s cybersecurity proposal.

“Are you aware of any component software or hardware coming to the United States of America that has security risks already imbedded into those components?” Chaffetz asked.      More