Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Whistle Blower
Articles

The Whistle Blower

ISBuzz TeamBy ISBuzz TeamJanuary 16, 2014Updated:July 3, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Dingo Crypto Token Flagged, Charges 99% Transaction Fee
Dingo Crypto Token Flagged, Charges 99% Transaction Fee
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Like many folks we’re recovering from the holidays, and the traditional family dinner. The highlight is watching the grandkids open presents, especially this year as our two year old grandson has discovered the wonders of ripping open everything, regardless of who the actual recipient might be.

Among all of the presents, my grandson’s favorite was the whistle that came in a Christmas cracker. Everyone could have saved a ton of money if we’d only known the power of the whistle. The first few blows were a bit tentative but once he grasped the concept, the “whistle blower” was off and running.

As the evening wore on, I suddenly started to wonder about “whistle blowers”. After all we live in a culture that puts the whistle blower on a pedestal. The media in general seem to thrive on the whistle blower, even when the very people who are exposing an individual would definitely fall into the category of the “pot calling the kettle black”.

Times have changed. There was a day when Britain elected a prime minister who had not only suffered from gonorrhea but during his time in office had a long standing affair with a married woman. Not only did his political career thrive, but on resigning as PM, he was elevated to the House of Lords. And the United States has also had its share of Presidents such as Thomas Jefferson, Andrew Jackson and Franklin D. Roosevelt who in today’s whistle blowing society would have been exposed for their extra marital dalliances.

In France, and partly as a result of strict privacy laws, there is a long-standing journalistic consensus that what goes on in the private lives of public figures remains private. For example, the French media knew that the late President Mitterand had a daughter from an extramarital affair, but it was not until shortly before Mitterand’s death that the French public learned about it.

NSA – Damned if You Do and Damned if You Don’t

Whatever the truth regarding the NSA and the RSA, one thing that surprises me most of all is the shocked reaction of the security community. Ever since cryptographic algorithms originating from the US have been available in products, there is without fail in every meeting, with any company, the question regarding “backdoors” in the algorithms. In other words everyone has always assumed this to be true, for whatever reason, and now that it supposedly is true, everyone seems to be in shock.

We may never know the truth, but in any case no encryption algorithm survives forever. It is not so long ago that we were being told that MD5, invented by Ron Rivest – yes the very same from RSA – was no longer safe and that the flaw was considered to be a fatal weakness. At that time we were told to use an alternative such as SHA-1 which has since been found to be vulnerable as well. SHA-1 was designed by the NSA, and published by NIST as a FIPS standard. SHA-1 was based on principles similar to those used by Ronald Rivest in the design of the MD5 algorithms.

Conspiracy theories abound! Could it be that the NSA and the RSA have been in cahoots all along? Did Adi Shamir and Len Adleman know about this? Hang on, Adi Shamir is Israeli and Len Adleman is the son of an American Jewish family. It’s all an American-Israeli plot. Never mind hard evidence!

One can only conclude that the French were right all along. As I understand it, French law states that a company may not be able to sell or use that product in France unless it meets the French government’s requirements and an authorization is obtained. Probably needs to have a “porte arrière”.

What next, antivirus companies in cahoots with the authorities? The likelihood is that we may never know the truth. After all could it be possible that the NSA, aware that they had a leakage problem, mixed some misinformation with the other stuff to get us all taking knee jerk reactions. The longer the Snowden affair drags on, and the more the guy is promoted as some latter day messiah, the more I start to ask myself the question, was Edward Snowden smarter than the best the US Government had to offer? Surely with all the disclosures, more heads would have rolled?

The Insider Remains the Biggest Threat

Regardless of the integrity, or lack of, in encryption algorithms, the insider remains the biggest single threat to organizations. “The best -placed person to damage a machine is the engineer who built it or maintains it, the manager who designed and runs a production process, or the IT administrator who adapted or installed a software solution. It therefore comes as no surprise that sabotage manuals tend to be written largely for insiders…” – “Cyber War Will Not Take Place by Thomas Rid”

Whether we’re talking about Stuxnet, or AMSC and Sinovel, the insider either deliberately or inadvertently is your biggest risk. In October 2011, a report by the Office of the National Counterintelligence Executive, concluded that “Cyber tools have enhanced the economic espionage threat, and the Intelligence Community judges the use of such tools is already a larger threat than more traditional espionage methods.”

“Shady RAT” serves as an example that crypto algorithms are not the biggest issue. Identified by McAfee, the attack has been extensively reported.

Essentially four steps were key in achieving success

1) Select target organizations based on economic or political criteria

2) Penetrate the target organizations by identifying employees and gain contact information such as email addresses using sources such as LinkedIn. Using spear phishing, send Trojans embedded in commonly used file formats and install the Trojans as the files were opened

3) Once the Trojan was installed, they would connect back to seemingly innocuous websites to their command and control center

4) The attackers gain control of the target machines by having the Trojan establish a remote session back to the C&C center, basically allowing the attacker to view and record all the activity

So who needs crypto backdoors when it’s just as easy to exploit our naivety by simply looking at our LinkedIn account, and realize that most organizations are not actively monitoring their systems for exploits, or are relying on AV applications that can only cure something after they know what it is?

And as for the “whistle blower” – curiously the parents forgot to take the whistle with them. After all “whistle blowers” get really tiresome after a while.

Calum Macleod is VP EMEA for privileged identity management vendor Lieberman Software.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}