Category Archives: IT

They’re consoles, but not as we know them!

Have you been looking forward to the Hype start of the PlayStation 4 yesterday? I was not. I did not waste time waiting for some stream to start with all the other people who were waiting to be the first to know. Millions of viewers and all were watching the same stream at the same time. I was not. Don’t get me wrong. I love games as much, if not more than the average player. But to quote Mr William Shatner in a very appropriate manner: ‘Get a life!’

So, when I looked at some of the details after the first wave, I had an option to sift through the information, and a few very scary thoughts were starting to form. The steps taken are very very appropriate (from the viewpoint by Sony), yet, we are about to get an entirely new wave of revenue driven groups, and before too long, it will cost you!
This might even more then you bargained for and there might be little to no chance to avoid it with all impending consequences. What am I talking about? Let me explain!

First the mundane stuff:

It is mentioned to have eight cores and an enhanced PC GPU. This system will work at speeds approaching 2 Teraflops. There is a lot more, but the issue is set in the next part I mention: “PS4 to include cloud and game live-streaming functionality; focus on social networking; global Gaikai network rollout.” (Source: Gamespot).

Am I just spouting out some facts? Perhaps, however, consider that managing multi core processor systems are a lot harder than most people realise. However, inserting code that accesses non-used, or less used processors is hard, but when active, they can remain undetected for a long time. Now add the thought that such malignant code is added through the DLC that is added to the game and we have a silent data screamer. This is the other less known side of anti-viral solutions. Data viruses are almost impossible to track, unless you track EVERY process, which slows down any system scanned.

Its opponent, the new XBox720 is still a question mark. There are loads of rumours, however, no real facts. It is however very likely that the Social Networking issue will be included. This is going to be the real problem.
This step was unavoidable.
Let’s face it, Facebook changed the world forever! However, if we take into account the shadier side of social networking (aka cyber criminals) then you might begin to realise that your goose could be cooked. We are not talking about an account that gets hacked. No, that would be too simple. For this part, we need to take an additional look back towards last October where insurers were mentioning that mentioning absences on social media might have consequences.
In December 2012 the insurance council of Australia made this quote: “The insurance industry is urging holidaymakers to keep their travel plans off social networking sites such as Facebook and Twitter to reduce the risk of burglary over Christmas”. This is actually late in the game as the British Insurance Age wrote this in June of 2012: “Social media-savvy young people could represent an emerging market for on-line risk insurance cover, according to research conducted by the Chartered Insurance Institute (CII)” So, here we can pretty much replace the words ‘emerging market’ for ‘additional costs’.

There has been the odd wild story on how a person tagged in a photo on Facebook through their smart-phone was enough for burglars to know that a house was empty. Now we add Social media to a gaming console? I could go for the kids and computers next, however, the bulk of gamers on systems like that are likely to be adults. Being adults does not mean that they are in ample supply of Common Cyber Sense. Let’s face it; loads of advanced users tend to lack such skills. In addition, we will now have to contend with consoles in need of Anti-Viral Software (to thwart Social media Cybercrime) and a league of other issues.
Let’s mention the issues that Sony had in the past with their hacked databases. Should we wait for the first time loads of credit cards go into some auto-donation mode? (With cybercriminals as the designated benefactor). I am not kidding! Yes, you will hear on the amount of safety Sony has, and the people will be perfectly safe. Spokespeople and Marketing spins will all make the case that we are all perfectly safe. So, let me remind you, or if you did not know inform you that in April 2011 the information of 77 million account holders were stolen from the Sony network. On May 4th of that year Sony confirmed that personal identifiable information was stolen.
Now they want to add their console to social media?
How long until the insurance company wants additional policies? How long until the insurance company decides that ‘it’ is not covered? Who will pay then? Sony? Or will they say “Oops! We so Sorry!” and leave you hanging with the consequences of the event.
I am not having a go at Sony here (even though it sounds like it).
There are several factors that should be seen as hazardous to the gaming health if those new console owners continue in an on-line/cloud gaming experience. First of all, cyber laws are shaky on several levels, especially when foreign criminals are involved (finding them is often a near impossibility). There is evidence on several levels that most of us are not ready for this level of integrated social media. Not because we do not want to, but because our systems can be invaded on many levels at several points. This is the consequence of evolution and people going to the edge of new technologies. At some point it becomes a clear that adding more and more is becoming counter-productive.
Then there is the part of additional revenue. Sony and Microsoft want all these sides to social media, for the simple reason that all that information is worth a massive amount of money. ‘free’ data, all there waiting to get scooped up by the container load. Would we get paid for this? Very likely not! How long until a non-adult gets to click ‘yes’ on an option so he/she gets it for free? Who is then liable when things go wrong? (When they go wrong, not if they go wrong!).
These are all the dangers of social media on the internet. Then finally there is their mention of Cloud gaming. Another new Hype that will be added for gamers. Yet, there are several levels of dangers. This is not just something I am claiming. Several exports on this field from data providers to the technology providers at Cisco make mention of this. They are warning us on levels of dangers when it comes to Cloud issues. So, the cloud, especially with data at rest will need several levels of monitoring and all this takes resources. So, how will we be charged for those? You can bet your house on the dangers that ‘free’ options there will come at a much higher price down the road and not unlike Facebook, should you stop gaming, then what will happen to the data?
The weird part is that most of these issues belong in medium to large sized companies with able IT coverage. Not in the average household where the IT expert is 11 and has a Nintendo 3DS!
Should you consider this and wonder how much time you have. Well, this console is to be released in 2013 and disaster could strike in 10 months, 10 days and 10 hours from now. Questions need to be asked, and those who protect the gamers (read citizens with a console) need to realise now that ALL data can be gotten to by cyber criminals, and in many commonwealth nations the law and the law enforcers are not up to scrap within that timeframe.
My biggest issue?
A device meant for entertainment is thrust into a grey area of legislation for the benefit of massive amounts of revenue. The moment our personal data goes somewhere else, those who enabled this in the first place will likely pass the buck to an area of non-accountability.

Leave a comment

Filed under Gaming, IT, Law

Fraud, deception or Ignorance in IT Safety?

Fraud, deception or Ignorance in IT Safety?
Again it was the Dutch NOS last night that gave me the idea of reflection on today’s blog. Their newscast and articles on NOS.nl is all about cybercrime. The news was that last year (October 2012), cyber criminals using the botnet Citadel was able to acquire over 750 GB of data. The data is coming from computers involving the Energy industry, Media corporations, Hospitals, Universities and airlines. The data seems to have gone to eastern European cyber criminals. Over 150.000 computers infected in the Netherlands alone.
Watching it, you could see login details, passwords, network layouts, detailed notes from a doctor and the medication prescribed. The amount of information was staggering! I looked a little further into this botnet. Its name is Citadel. It seems to be an ingenious piece of work. This is something the NSA, GCHQ or the FSB and several other Boy Scout units of a governmental type. When looking at the info, there was an implied strength that it could go passed and ignores many anti-virus systems. When looking at my own provider, there was an interesting lack of information regarding this botnet.
So we are looking at a three edged sword.
Are anti-viral protectors committing fraud? When looking at a Norton protection plan, and I see the green ‘Secure’ sign. Am I really secured? Tracy Kitten from Bankinfo security wrote: “Segura notes that hackers claim PCs relying on anti-virus solutions from Microsoft Security Essentials, McAfee, and Norton were infected. ‘That’s kind of worrisome,’ he says. ” So, am I paying for security I am not receiving?
It seems that this secure statement is also a case of deception. My Norton anti-virus states a secure setting, yet, citadel was initially designed to collect bank information for cyber criminals. From the two facts earlier, I must also conclude that the banks have been insincere to me on more than one occasion (big surprise I know). They claim safety and security, whilst 150.000 computers in the Netherlands seem to prove the opposite. Especially considering that banks have been trimming down on staff because much more goes on-line, yet there is no clear information that the cyber divisions of the financial industry is making any kind of strong progress. The BBC stated on Oct 10, 2012, that GBP 341 million was acquired through card fraud in 2011. The events involving Citadel imply that the losses in 2011 are not likely to go down any day soon.
Last is about Ignorance. That would be you the reader and me. These anti-viral dealers leave us with a false sense of security while we are charged $70-$100 a year, whilst it lowers intrusions, but not remove the threat. I must confess that we are all likely a lot safer with then without anti-viral protection. So stopping anti-virus protection is the worst of ideas.
I feel slightly safer as I have always refused any kind of on-line banking option. From the 90’s I knew that their X-25 protocols had several weak spots, which is now getting me to the last part of this.
If Windows is so weak, volatile and easily transgressed upon, then the dozens of security updates seem little more than a smoke screen. I reckon a lot of us should seriously consider moving to another system like Linux. Linux has proven to be a very secure system. We used to consider Apple to be very secure as it was a Unix based system, which has all matters of security or a much higher level than Windows ever had. However, that it is now an INTEL based system with Microsoft attachments makes me wonder if it remained that secure.
What is my issue with this all is that Yesterday’s news on Citadel was known with the Dutch cyber security for months, and little was done, the newscast even mentioned that many had not been alerted to this danger. I reckon that IF there is truth on transgression on ‘secured’ systems, we need to consider the dangers of connected networks. This likely endangered the infrastructure, and it definitely endangered personal information of millions. With that state of mind, how should we see the security of corporate and personal systems in the UK, US and Australia?
Consider that the implied ignoring of Cyber security is mentioned (but unproven as far as the validity of sources go). Yet, when I seek places like Norton, I get no answer (connection was reset). If we can believe people like Tracy Kitten then the financial sector that relies on massive internet presence, we are in serious trouble. On the other side is the opinion showing on the NOS site by Professor Michel van Eeten from the TU Delft. It is not really created to a directed attack. He compared it to a buck shot into the internet. It was designed to acquire login, passwords and bank details.
My issue is the fact that 150.000 systems were infected! The one flaw in the NOS newscast is the absence of the cyber safety factor. Whether Common Cyber Security was used by those infected. If so, then why are these questions not openly directed at the makers of Norton Anti-Virus, McAfee, Kaspersky and a league of other Cyber Safety providers?

2 Comments

Filed under IT