Kaspersky Labs reports that an unnamed large Brazilian financial institution with $27B in assets was compromised by hackers who took over its DNS -- by hijacking its NIC.br account -- and for 5 hours were able to impersonate the bank to all its online customers (and possibly to control its ATMs) in order to plunder their accounts and steal their credit card details.
Kaspersky’s Bestuzhev argues that, for banks, the incident should serve as a clear warning to check on the security of their DNS. He notes that half of the top 20 banks ranked by total assets don’t manage their own DNS, instead leaving it in the hands of a potentially hackable third party. And regardless of who controls a bank’s DNS, they can take special precautions to prevent their DNS registrations from being changed without safety checks, like a “registry lock” some registrars provide and two-factor authentication that makes it far harder for hackers to alter them.
Without those simple precautions, the Brazilian heist shows how quickly a domain switch can undermine practically all other security measures a company might implement. Your encrypted website and locked down network won’t help when your customers are silently routed to a bizarro version deep in the web’s underbelly.
How Hackers Hijacked a Bank’s Entire Online Operation [Andy Greenberg/Wired]
(Image: Bundesarchiv, CC-BY-SA)
(via Naked Capitalism)
When eight- and nine-year-old students at Hyde England’s Flowery Field Elementary School walked into class last week, they were confronted with a crime scene. Behind the police tape was chalk outline of an elfin figure and a desk smeared with blood. Their assignment? Solve the mystery of the murdered elf. Apparently it was a writing […]
A judge in Canada today granted $10 million bail for Meng Wanzhou, the CFO of China electronics giant Huawei. She has to remain in the Vancouver area, where she has a home. The United States has requested her extradition. China is not happy. Huawai’s response follows. .
Trafficking guns and explosives to the Irish Republican Army, running a massive criminal enterprise for years in Boston, extorting drug dealers so that they could do business on his turf, acting as an FBI informant and oh, so many murders: James “Whitey” Bulger’s life was both colorful and poisonous, to say the least. His long […]
For the true audio enthusiast, there’s a lot of difference between putting on some songs “for background music” and a true listening experience. For the latter, there’s nothing like a pair of sturdy headphones and the powerful speakers that come with them. And the wireless variety doesn’t get much more powerful than the TREBLAB Z2 […]
Digital or analog, there’s a path of least resistance for any project. Finding that path is what the Agile methodology is all about, which is why proficiency in it is a must for any project management position – and the paycheck that comes with it. And the quickest path to learning Agile? The Agile Project […]
Everybody’s flown a paper airplane. But what if you could fly on a paper airplane? Until we invent shrink-ray technology, the PowerUp X FPV Video Paper Airplane Kit will have to do – but it’s as fun as that sounds and more. The original version of this creative toy added drone tech to the old, […]