Saturday, October 29, 2016

Hook Your Stuff To The Internet and It Will be Hacked

It's pretty much the first rule of cyber-security. If you have information or data* that must not be accessed  by outsiders it absolutely must not be accessible from the www.
From The Atlantic:

The Inevitability of Being Hacked
We built a fake web toaster, and it was compromised in an hour.
Last week, a massive chain of hacked computers simultaneously dropped what they were doing and blasted terabytes of junk data to a set of key servers, temporarily shutting down access to popular sites in the eastern U.S. and beyond. Unlike previous attacks, many of these compromised computers weren’t sitting on someone’s desk, or tucked away in a laptop case—they were instead the cheap processors soldered into web-connected devices, from security cameras to video recorders. A DVR could have helped bring down Twitter.

Great, I thought as I read the coverage last week. My DVR helped bring down Twitter. (Probably not, at least this time—the targeted products were older than what you’d find in most American homes, and less protected.) But the internet is huge! There are around a couple billion public IPv4 addresses out there; any one of those might have a server, a desktop computer, or a toaster plugged in at the other end. Even if the manufacturer of my gadget gave it a dumb and easily guessed password, wouldn’t it be safe in this sea of anonymity? How would the hackers find me?

I don’t actually own a wireless toaster. But I devised a test. Renting a small server from Amazon, I gussied it up to look like an unsecured web device, opening a web port that hackers commonly use to remotely control computers. Instead of allowing real access, though, I set up a false front: Hackers would think they were logging into a server, but I’d really just record their keystrokes and IP addresses. In cybersecurity circles, this is called putting out a honeypot—an irresistible target that attracts and ultimately entraps hackers and the scripts they use to find vulnerable servers.
Here’s what my particular honeypot looked like, if you tried to log in:
data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAbYAAABzCAMAAADDhdfxAAABlVBMVEUAAAAAAAMAAQABAAUAAwAEAAAAAAcAAwMAAQPGxsYAAAoABgCAgIAAjT4DAQAAiz4AHQAACgAAEAAAhz3MzMwAFwAkw3EAIwAAGwAAGQArvnUPAAAAJgAAkD0AFAAADQAAOwArdUtnZmcAVCQALgAATBAANwAAkT4AUxkANhYri109unkAfDcVfT4hISEoyGwlaDs+1X9DxY8AQQA1u3kpWj1Fo4EKKBA4h1NRv4Us64kSWzweHyUjGiMSCxQUFxUZ8XocLSEYIh4eCB0XERgd43geNSUaQicV+HcRczxQsoEGZCxDp2goSjgnKCwqMjA56ZUbRigQQS0abksAay8AShsARSAKMRcEhkoAbSgAcx4PIywyd10X33Anm2NBoXNc2JVYl3Mpkk4PolU43pIFMBsATQAiaEkTpUYewVwYuGMAXgoaHBINNCkDsk4KABYAjSpRnGoqSz1SUlKioaE1XUJDhm4P42lrv5lAr2g9VEk4Yk4VWT04gVkyYlFavooQtEUUEy9mnYBahnQ9llsAfRwSrUKji2w/AAARGklEQVR4nO1bjVMa2bLv+WQuXAZ01kkyCSZcTAyggTGgDuyNYhYMo27EDzSuCAJZlGyy0ffUNQlx3665f/frPoMmubX1ql7dWJutOj+VjzM9ffr0r7vPR40AHBwcHBwcHBwcHBwcHBwcHBwcf31I2Wy+MhhvRemzBAL+BZbS2Xx+swKK7BMEbJdF0AOlDVDnCgCd/QS7UQcJr0lqaRjUgUQZREkBVZ3bMfqKFXqRFV2BOR9IUBrEF2zQQAY43D8HDUDAHhXw4WWRWrFBECRVBZJUULmI5qAC1KTgC0kICmBX+I53D84JKlrrl/ygYjtokg/FFUUrBPCLIKhCoBRQBcHv9wP+KiD5UKA0RMqwH4GNvjTvWYvvg/kA9qHr5AZFlmlsAoR7w56AiE4AeIeG483wLiri/UOb894wfQGJ3LH3EOVQTMVRgYCGayBeCWkyPKon7V640t71GnRBgpnf3OVkfTHG3EcyZHHJ6gKkW+jy0zN0ykcV1jq+bC/0v31PYkyRrrEB4V+9gi8miUEAfxCHOw16Qy0BhfjzWvtvTLfiNaiXdtKfJqAjttN96Wz9+uX1z8AsQmJgvnvt3y4F4PSZ98nzp+r2zX1r35m2B73PfgqTvr9HJj6qwKalU4cZ1TsDQYQhN4/NA5cCxfvUscoG3R/H1dCGWn2tfwHccNNwXD+rJ4HcOPC8eH8o2XRciLtOb4D1nV2uzRzunHSW4BAt9087TqeXcHY33ueabwv1ySzAins2WfKfRmBm13GygOE4UH8Lv2cXrGZn5U2x2ZmLuc4RHO84buGpcxsWV6H0WxhVD9eX4PfDg8TZLrw5cw4g7Z4dQdb9pd47CBydF3bPnePru85BGKkAadLNwrWDhJMo7CTHsgPbjvuuVD8/q3d6rlN4vps8mDosjr7/iYh/2atFjwYSZ24FOmdn28/raN97e+9tAUe1C2/PHecN7PzqOWKgZjbGhg6cxfhxB3ploBTPo1h4YtpJQO+Xs6PYb3D4u7KCg4ee214kVobdhLMI4QPHrbx0Hff73P2lsxL4NTh23fqpP+G4N66ENYJ/8Vc0Acc5mSrWcsAC/X9O7squPdYu7++Xi1tASZPasTqdzMnBNqMtYY9lpvdmO6m949nuQSmfjMLQRKtyVIIHGOSNvcM5LJowmJqGyeZO+7S3uvuke/C09mr15MdkbbNRfYk6NifCCZd6m7LTMJner70vbrn7saXHJ3uJkxeorbPTvV3+9dDeT7qt2Vhxj6qyP5/sQXwiNd6etuzTXqz9uptZnz3t1hLtUKbXqqWLe8dFa7JAI8vWTxZ70VwsUSu3jZ362pPVpblezjw47J7Eah+2n0TszgVtGrxZ3r+5l6xkzG4LKJAxqVK16uGticxYO2KvRYt7lpJ1w4dJgGhjbMfxaLMNq5zaX6ptud3Y0ePa3nInoGJpdU10ZaK9ZU9fVb6Bf+dfXk2a7JkfijQCDX44uRtw0uB2a6mzRpldnR1NdWF8Hz8toctr01DvtUYhtQe1F9hWj8K9iSrjXIaZens/RkXithkFtwMuXajdhcOi7Tby7vTtlUGireCMptJYlWEK35xOdwuKwbdtO5Kdtc+sBdLW60J5f8l5WFhJFl2HTYcq9ouVKw4T6/nFQTDaVtKt5qrPq4kE1E2z6DY2mUUaTcrV2jU4XoTqbHcRovV4sm3FwfwAc1bNaUz3Tgcqc9BrMieI8Mh8DbUWdNrdUaJNw77SE3Zz5Ay7SiVBnu1aSt4NryBt3R1ILJIxw84quK/sW1DcmoiRj3KvqDqjK1etDynLNhu7V8MZIt769dptnIhhctvcsrE048cfakhbFtxW6nX4fpxoe1PsWifxcu3GfGApMwK55kI70TJgfw+KY/emoN4cunV2fq96g9jaqP5YqyOD+m1rc62dhrPynSoUn43MF7fC968hjwAvk3eGYXM5NUKzVtgcH2+nuy+gOLpyby/XIbE7jbF71d5+LIm0bQAs7g/fwxlLxHyrN6+PTMwMT6SzzsP1sv3i3nq1GAfY6cFBstu9fncdcmMjU7iY0YWV4nq8Z42Ui6nTdbtevfvMboE1OjJv7YWrI8fnNPpyf6qDn60PYJ6GdzKtvby9R2sef/VhxN5yp2Ciaz3EZLfuWu7QivkQrNMFe5HuGcKC7abs+4ni1lnrTtVfe2Xn2VrK7VhbdrM7sh6Hl+Wpq2DtkZkrnm4QM5Pb1lYOVD+W9R+K9wcyWXCmI7mMTfMsTC7C1JP0QtFMhpdy1lJiuTibbEWg9gpqOTsKmdw5RGdtq0K1I91I5jZxEYmrPhSLQr1YG4XaspXey6VSP7rbqK5k21ksq+fAJpHEcu4Jy7Y9B0P0ZnfZ2r+zM2sn07O54n4liaQsFJO2QUkhobbdWxOFoUZ63k6lqpmcfVqtEW2Ybe5CzrLHsCvMclp0Pl9uWAs1u92MtYtFaxzHYkBr2U6s4adnBwc46KFk7YK29mt417aLq5tPcjmsxxoSaTv2i4lb0Cjv5+zWHdRhXl8p2kdRGnxAUPQw0ZZIzdZmjc4T214pvkjMVmnF4nbMrVzBTi1HYXs29uXr5IVC6aIBV60qLe3Im5h2cLNEaXPZ781S/+NPP1/e8aDQ//R4fhCjlNbihcekwSfA3ACl39wMfpvDTHz0st8Jvc43c4/AJ1F0ehpo6TX1AF/Ul9j344ICP/90KV+ie6TPV45PHwF8+09PpN9EYsq3BbQZ9x6g4F5Awd5BH8Jrj+ZFZOq7H1CCaaNV87ffeff5VcBRKmT4Y9Sq0vhh5mJkQDsfZe7i28wj2qCwvRH56p83SfnTm95FRbm07/vvqPaIV0IbGSwIMpZJ1p9AjtdBwx2b4FmmK7gX0YEafEyAuUhUVYkE2DIfydapztJgNB/pEQVZFDVv1U6+pptUCg5SgxMHTmmuUwbZJ8ka6VCwOvt0b9GMc7rCBo/3yLjBQovIEF1XvN2W5llGHNJ3DfdZoo42e3fj8gn3e7ouehb1YzCAEgJVgH44CtSH6PtkI6N72xpvQAIOSPaU0QXWQsEt+7zJC8gSFNW9nYKgsO0tUAPuPEhe02j4JOvTvjRrBD/tVXEzSZGIhguCiEMTfD4iRdI0vzcyRZGoQekHGd3nR97wh3an6FGU0BltokybZEWTvRgT2OIAWwBVCaRfEnzkM5i6oZPPZRJAFiU/3UBKqFDTHo10YvJjvxLtgKlz8jP7iveoqg/fsXuiDS9rXoeiTLYq7G6BceXzTFP8guKBxR1ztPbRpSLSj+6XWGSQpIyd0RckUBSYRuzfpwkSY02loZAYjY1MxIHTsQSwEwuR4pnmG0GWP93kflkgZ3QsgF3hJ6JN1Gi4Ao1fZ/Gk63SEIigsrFk+CiI7akDPgCT7VBwwc5tARxHYritexgiyBszP7JfoEr0OcfQSBQtdVQQ/9J1FbkACJAn3fWSVQichqFVBWiVxADMfQ0Mnj6kYWphTjCN0Lt6BtxLT6EGWAjrWe515n0YlUmB6lKEOqhAUS2I/uARJlgXyOwYREih6xrPRUTBSH4KKkSB5CS+pfhRUJKrffj8drJBF6EAcERkoSpqssIyW+/Z9aZByincWgjQu5gQqmazwKJjykh8dq4GsqqBqskQHAQLajS9oLF6TRQVDTfaij5mI9VBiJ1eaILNDKZXciSrQMYLgRS66RPLJLHu9Jp1ll+Cn7GeVkEoveQrv0fwstekjvvkVNt8pfZMV5jTBjyVXoaMu6hhXxLSDEql3haUgcyNlNRkvUJmR2JmG5MchI9OaHzuViAtMcUX1o/0qyyuMB6RJoviUyCc+mQoKhrCMwipmk0iaMKwozTU6I0SXoAxyhvaT7Jdnjcak6KxqiaLnTsYZModraIo0pA3JouqjSUSbQHbgaDSWRFirJFlXNB9Vg4sKhKmpUdDS0Zwo6gIrm0gbFnzRc7TCHC1R0aESqfl0r3RhHiHDlLgC8UrqBOIKk06hXolBtAeLsM7O/JgcGYKmqKhMoZBitGG60mwsU42grFUUNvXQlIi8M9pY9aaQksguTVVY+Ag0VemeHjZzsjRWNcoijWqxz0expzHacFWAg5Io/1VR8OY1DCLF50On6Egbq7BXQBvSoXu+pExgZ3leM0bS5RJIDKC5mCqXZVpDQ8k7FK+qjIP0piJWgqhAUpGlassKn8DUY8aiy7BNZ/2wciNRqcWY9QUulluUEhTlbA7pz0UssbzJX/TeKD1IMdFPKSKplGKeQcwEVmBltgpCKgRcFgieFV5FYfPXx8ilsNQErzsWMaJXPGkRyEbhrX0lkUqeSP3C5bGpp4GdfJPtpJiyUaCKxVwBwh+enP6H8CyiA/L/S4rVvj/uXvfWEex2Se9LX5ZzVvvYj6BcqtK9ywroF4Nna4ZPPPH5NK5e2vbRSFZBVbpFVS46JUvYnQKr733FfzQc748K30cbLi3x3kSvP+VC3msVWAfKZ619c9kLW11+PpdRTf/iGDOMPERDRmzICBnxjbHI6EY1GBwbqhhGCNaCkTK8i0SeQTAUiQ2WN4PrU4axiWKhyFAsGJoeXAkGDVgzRhcGVl9H1iBoGNVwORSsxlHbxrwRHIVYyBgP5EPBMRgLjqZhNRKKgWGMV6bKwWC8GgyNT60YwSAsBEPRwXwkhGKhYH6gPBqJDYeMcnVjPBSaqhqhsTCaFYQ1bAukg8E1NDxYvV2ORNangsbmBooFh2OoF0gWDQ8uBNIRFAuGjMrQeCRSjQeN8gYaHoSYEYpCHgcJZSOUD0SDaBGKVa+jWDyO5l5bMQwS28TBhyJkUSg2UA5G7g8bQaNa2IyMTlWDxviNKvNRKEgWoY8MYyx2fdwIrm+Egkb8+Vgkwiwa8F3BuWTGsqYHXcuKTlmmlZ7PmGYlbZrJex3LNG82TfM8fJxKNW+apjl9zbXM6IZlJdPZpJXaKJtW8ta2aXZhJ2MeXJ9EMbAspxzHi+mKaWbWs5ZlhqdNc/Faj8RaqGNg0jQ3JTOTSc87lpnOo47199TVpuWJteDUMnvD9ZRZnmJiSQstsszkHezKVJooFq6bVktB3dNhN2VG581MMn2E2jbKluWOHGFXN7Grgxt100SLTBzaYiqVrqLY+hFq+6mMOm71TGtROUWxYde0ErJpWemSkzLfpcmio4yFFmWsxWvHaJHSxa4GkyZZhD5awk8rq5Z1eqeD2mCTfHRAhpOPbiXNVLlCYoeZVLcURcNHruo4mYODg4ODg4ODg4ODg4ODg4ODg4ODg4ODg4OD4/8Npf8wDnu4UGTPqsj4jT2PKemaD/7rvxH/+LPN5Pgcnzzp6VMAaWMPHNMzpKKgKEjbP7752zff/P1PtpLj36EoMJNemgFFUCXvsTSYe0uPsMns0Tai7W+ctq8OSNvTs4nKp/93uzo5412jZ6Q4bV8j2HNvYScLkN5pxqHabBqVnQjo+WfN5iCkE2FO29cI9qjhnJuF9YlXqcXnjVSqFkulABLFlD0GrcZzTttXizk3Bl0LSo3u/u3yCazZSFsXrD24+YAXya8XhSSjLd/udgdbjDYtMQpWF4YCnLavF3Pu6Zu7jfPM6bidbJzAQqNXSATh1ILELwVO21cL31L0ELKj06VH6dVmDZ6/jc6VKpDNQr43xGn7akH/EMjW/tu1mp3uNwa8f0TgtH21ECSfx1t4fDM2KGgy/cOWyP6lFGn7hp+S/PUw8wAx82dbwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHBwcHB8ZfF/wLTAHRfgJ8esQAAAABJRU5ErkJggg==
I switched on the server at  1:12 p.m. Wednesday, fully expecting to wait days—or weeks—to see a hack attempt.

Wrong! The first one came at 1:53 p.m....MUCH MORE
*As a side note, a few years ago we posted a handy flow chart of the hierarchy of knowledge management:

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHlOlTTL-7vxYDApDhLDJkcruBhqzvZK8k46OxRstH8boFO6Cnxf9HGnf9Qz7q2AbamaU_s8MpIoZkbh1QPP80_WmRFZgencBEfV-i54VPu5ZCzsPs72AbRy6pfb43tyrqm7mg0BrMxHQH/s1600/image_thumb8.png


We prefer the chart to the usual pyramid presentation popularized by Akerlof because it includes characteristics at the bottom and the value-added required to get to the next level of complexity in the top panel.