Boy, 11, Hacks into Replica U.S. Vote Website in Minutes

(Reuters) – An 11-year-old boy managed to hack into a replica of Florida’s election results website in 10 minutes and change names and tallies during a hackers convention, organizers said, stoking concerns about security ahead of nationwide votes.

** 11-Year Old Emmett Brewer Hacks Into Replica US Vote ... photo

The boy was the quickest of 35 children, ages 6 to 17, who all eventually hacked into copies of the websites of six swing states during the three-day Def Con security convention over the weekend, the event said on Twitter on Tuesday.

The event was meant to test the strength of U.S. election infrastructure and details of the vulnerabilities would be passed onto the states, it added.

The National Association of Secretaries of State – who are responsible for tallying votes – said it welcomed the convention’s efforts. But it said the actual systems used by states would have additional protections.

“It would be extremely difficult to replicate these systems since many states utilize unique networks and custom-built databases with new and updated security protocols,” the association said.

The hacking demonstration came as concerns swirl about election system vulnerabilities before mid-term state and federal elections.

U.S President Donald Trump’s national security team warned two weeks ago that Russia had launched “pervasive” efforts to interfere in the November polls.

Participants at the convention changed party names and added as many as 12 billion votes to candidates, the event said.

“Candidate names were changed to ‘Bob Da Builder’ and ‘Richard Nixon’s head’,” the convention tweeted.

The convention linked to what it said was the Twitter account of the winning boy – named there as Emmett Brewer from Austin, Texas.

A screenshot posted on the account showed he had managed to change the name of the winning candidate on the replica Florida website to his own and gave himself billions of votes.

The convention’s “Voting Village” also aimed to expose security issues in other systems such as digital poll books and memory-card readers.

***

Mark Earley, the elections supervisor in Leon County who is a cybersecurity liaison between state and local officials, questioned how outsiders could obtain the security protocols used by Florida if they weren’t already behind the system’s firewalls. He said that all this “hacking noise” and “misinformation plays into the hands of the folks who are trying to undermine democracy.”

Jeff Kosseff, a lawyer and assistant professor at the United States Naval Academy Cyber Studies Department, said states are struggling with election security threats. He said they should work with outsiders in order to see if there are flaws in their systems.

“All states should look at this as a wake-up call,” Kosseff said. “What were the shortcomings identified and how they can fix it. I don’t think it should be an adversarial.”

Google Wont Stop Following You, Regardless of Settings

Even when you opt out. Even when you change the settings. Even without your knowledge. Next question that needs an answer…who is Google selling the data to?

Google is tracking your every move, apparently | Metro News photo

SAN FRANCISCO (AP) — Google wants to know where you go so badly that it records your movements even when you explicitly tell it not to.

An Associated Press investigation found that many Google services on Android devices and iPhones store your location data even if you’ve used a privacy setting that says it will prevent Google from doing so.

Computer-science researchers at Princeton confirmed these findings at the AP’s request.

For the most part, Google is upfront about asking permission to use your location information. An app like Google Maps will remind you to allow access to location if you use it for navigating. If you agree to let it record your location over time, Google Maps will display that history for you in a “timeline” that maps out your daily movements.

** In case you missed Tucker Carlson’s segment on Google:

 

Storing your minute-by-minute travels carries privacy risks. So Google will let you “pause” a setting called Location History.

Google says that prevents the company from remembering where you’ve been. Its support page states: “You can turn off Location History at any time. With Location History off, the places you go are no longer stored.”

But this isn’t true. Even with Location History paused, some Google apps automatically store time-stamped location data without asking.

For example, Google stores a snapshot of where you are when you merely open its Maps app. Automatic daily weather updates on Android phones note your location. So can searches that have nothing to do with location.

The privacy issue affects some two billion users of devices that run Google’s Android operating software and hundreds of millions of worldwide iPhone users who rely on Google for maps or search.

Storing location data in violation of a user’s preferences is wrong, said Jonathan Mayer, a Princeton computer scientist and former chief technologist for the Federal Communications Commission’s enforcement bureau. A researcher from Mayer’s lab confirmed the AP’s findings on multiple Android devices; the AP conducted its own tests on several iPhones and found the same behavior.

“If you’re going to allow users to turn off something called ‘Location History,’ then all the places where you maintain location history should be turned off,” Mayer said.

Google says it is being perfectly clear.

“There are a number of different ways that Google may use location to improve people’s experience, including: Location History, Web and App Activity, and through device-level Location Services,” Google said in a statement to the AP. “We provide clear descriptions of these tools, and robust controls so people can turn them on or off, and delete their histories at any time.”

To stop Google from saving these location markers, the company says, users can turn off another setting, though it doesn’t specifically reference location information. Called “Web and App Activity,” that setting stores a variety of information from Google apps and websites to your Google account.

When paused, it will prevent activity on any device from being saved to your account. But leaving “Web & App Activity” on and turning “Location History” off only prevents Google from adding your movements to the “timeline,” its visualization of your daily travels. It does not stop Google’s collection of other location markers.

You can see these stored location markers on a page in your Google account at myactivity.google.com. It’s possible, though laborious, to delete them.

To demonstrate how powerful these other markers can be, the AP created a visual map of the movements of Princeton postdoctoral researcher Gunes Acar, who carried an Android phone with Location history off and shared a record of his Google account.

The map includes Acar’s train commute on two trips to New York and visits to the High Line park, Chelsea Market, Hell’s Kitchen, Central Park and Harlem.

Huge tech companies are under increasing scrutiny over their data practices, following a series of privacy scandals at Facebook and new data-privacy rules recently adopted by the European Union.

Critics say Google’s insistence on tracking its users’ locations stems from its drive to boost advertising revenue.

“They build advertising information out of data,” said Peter Lenz, the senior geospatial analyst at Dstillery, a rival advertising technology company. “More data for them presumably means more profit.”

The AP learned of the issue from K. Shankari, a graduate researcher at UC Berkeley who studies the commuting patterns of volunteers in order to help urban planners. She noticed that her Android phone prompted her to rate a shopping trip to Kohl’s, even though she had turned Location History off.

“I am not opposed to background location tracking in principle,” she said. “It just really bothers me that it is not explicitly stated.”

Google offers a more accurate description of how Location History works in a popup when you pause the setting on your Google account webpage . It notes that “some location data may be saved as part of your activity on other Google services, like Search and Maps.”

There’s another obscure notice if you turn off and re-activate the “Web & App Activity” setting. It notes that the setting “saves the things you do on Google sites, apps, and services … and associated information, like location.”

The warnings offered when you turn Location History off via Android and iPhone device settings are more difficult to interpret.

Since 2014, Google has let advertisers track the effectiveness of online ads at driving foot traffic , a feature that Google has said relies on user location histories.

So, What Really Goes in Space to Have a Space Force?

Primer: Did you know there is something called the OuterSpace Treaty? Yup, it covers arms control, verification and compliance. Sounds great right? Problem is it is dated 2002.

Then there is the NASA summary of the 1967 Space Treaty.

GPS is operated and maintained by the U.S. Air Force. GPS.gov is maintained by the National Coordination Office for Space-Based Positioning, Navigation, and Timing.

Like the Internet, GPS is an essential element of the global information infrastructure. The free, open, and dependable nature of GPS has led to the development of hundreds of applications affecting every aspect of modern life. GPS technology is now in everything from cell phones and wristwatches to bulldozers, shipping containers, and ATM’s.

GPS boosts productivity across a wide swath of the economy, to include farming, construction, mining, surveying, package delivery, and logistical supply chain management. Major communications networks, banking systems, financial markets, and power grids depend heavily on GPS for precise time synchronization. Some wireless services cannot operate without it.

GPS saves lives by preventing transportation accidents, aiding search and rescue efforts, and speeding the delivery of emergency services and disaster relief. GPS is vital to the Next Generation Air Transportation System (NextGen) that will enhance flight safety while increasing airspace capacity. GPS also advances scientific aims such as weather forecasting, earthquake monitoring, and environmental protection.

Finally, GPS remains critical to U.S. national security, and its applications are integrated into virtually every facet of U.S. military operations. Nearly all new military assets — from vehicles to munitions — come equipped with GPS.

***

There is a robust debate within Washington and the Pentagon if whether or not a new branch of Armed Services is really needed. Presently, the Air Force has most exclusive authority of all things space except for research and exploration which is performed by NASA.

There is even a debate within the Air Force which was raised last February.

US Air Force Chief of Staff General David L. Goldfein predicted it’ll only be a “matter of years” before American forces find themselves “fighting from space.” To prepare for this grim possibility, he said the Air Force needs new tools and a new approach to training leaders. Oh, and lots of money.

“[It’s] time for us as a service, regardless of specialty badge, to embrace space superiority with the same passion and sense of ownership as we apply to air superiority today,” he said.

These are some of the strongest words yet from the Air Force chief of staff to get the Pentagon thinking about space—and to recognize the U.S. Air Force as the service branch best suited for the job. “I believe we’re going to be fighting from space in a matter of years,” he said. “And we are the service that must lead joint war fighting in this new contested domain. This is what the nation demands.”

The USAF and other military officials have been saying this for years, but Goldfein’s comments had an added sense of urgency this time around. Rep. Mike Rogers, the Strategic Forces Subcommittee chairman, recently proposed the creation of a new “Space Corps,” one that would be modeled after the Marines. The proposed service branch, it was argued, would keep the United States ahead of rival nations like Russia and China. The idea was scrapped this past December—at least for now. Needless to say, Rogers’ proposal did not go over well with the USAF; the creation of the first new uniformed service branch in 70 years would see Pentagon funds siphoned away from the Air Force. Hence Goldfein’s speech on Friday, in which he argued that the USAF is the service branch best positioned to protect American interests in space.

But in order to protect “contested environments,” the US Air Force will need to exercise competency in “multi-domain operations,” he said. This means the ability to collect battlefield intelligence from “all domains,” including air, ground, sea, cyber, and space. “I look forward to discussing how we can leverage new technology and new ways of networking multi-domain sensors and resilient communications to bring more lethality to the fight,” said Goldfein.

Indeed, the USAF has plenty of work to do make this happen, and to keep up with its rivals. China, for example, recently proposed far-fetched laser-armed satellite to remove space junk, while also demonstrating its ability to shoot down missiles in space. Should a major conflict break out in the near future, space will most certainly represent the first battlefield.

“When you think of how dependent the US military is on satellites for everything from its communication and navigation to command and surveillance, we are already fighting in space, even if it’s not like the movies depicted,” Peter W. Singer, fellow at New America and author of Ghost Fleet: A Novel of the Next World War, told Gizmodo. “If we were ever to fight another great power, like a China or Russia, it is likely the opening round of battle would be completely silent, as in space no one would hear the other side jamming or even destroying each other’s satellites.”

To prepare the United States for this possibility, Goldfein said the Air Force needs to invest in new technologies and train a new generation of leaders. On that last point, the CSAF ordered Lt. Gen. Steven Kwast, the commander of Air Education and Training Command, to develop a program to train officers and non-commissioned officers for space ops. “We need to build a joint, smart space force and a space-smart joint force,” Goldfein said.

As reported in SpaceNews, the USAF is asking for $8.5 billion for space programs in the 2019 budget, of which $5.9 billion would go to research and development, and the remaining for procurement of new satellite and launch services. Over next five years it hopes to spend $44.3 billion on development of new space systems, which is 18 percent more than it said it would need last year to cover the same period.

 

Trouble Ahead After DPRK’s FM Visit to Tehran

So, it appears there is more to the teaming up between Tehran and Pyongyang.

The Iranian President Rouhani told the North Korean Foreign Minister in a recent confab to NOT trust the United States.

Meanwhile, SecState, Mike Pompeo issued a proposal to North Korea calling for a timeline Pompeo that would mandate North Korea hand over 60 to 70 percent of its nuclear warheads to a third party within six to eight months, according to the report.

North Korea has reportedly rejected a formal timeline for its denuclearization proposed by Secretary of State Mike Pompeo.

Vox reported Wednesday that Pyongyang has rejected the timeline several times over the past two months amid continued negotiations over North Korea’s nuclear program.

The timeline Pompeo proposed would mandate North Korea hand over 60 to 70 percent of its nuclear warheads to a third party within six to eight months, according to the report.

However, it is unclear how many warheads North Korean leader Kim Jong Un has, making it difficult to verify that Pyongyang has actually turned over an agreed-upon percentage.

Trump administration officials in recent weeks have expressed frustration with North Korea’s efforts to denuclearize despite President Trump hailing his June summit with Kim in Singapore as a success.

“The ultimate timeline for denuclearization will be set by Chairman Kim, at least in part,” Pompeo told Channel NewsAsia in an interview last week.

“The decision is his. He made a commitment, and we’re very hopeful that over the coming weeks and months we can make substantial progress towards that and put the North Korean people on a trajectory towards a brighter future very quickly.”

White House national security adviser John Bolton told Fox News on Tuesday that “North Korea that has not taken the steps we feel are necessary to denuclearize.”

Iran fires attack on Trump as it tells North Korea: ‘US ... photo

Then we have yet another emerging hacking warning from CERT.

The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) have identified a Trojan malware variant—referred to as KEYMARBLE—used by the North Korean government. The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDEN COBRA.

US-CERT encourages users and administrators to review Malware Analysis Report (MAR) MAR-10135536-17 and the US-CERT page on HIDDEN COBRA – North Korean Malicious Cyber Activity for more information.

Not to leave out Iran’s cyber attack warnings.

Iranian hackers have laid the groundwork to carry out extensive cyber attacks against private U.S. and European companies, U.S. officials warn, according to NBC News. Although experts don’t believe any such attack is imminent, the preparations could enable denial-of-service attacks on infrastructure including electric grids and water plants, plus health care and technology companies across the U.S., Europe, and Middle East, say U.S. officials at the 2018 Aspen Security Forum.

A spokesperson for the Iranian mission to the United Nations, Alireza Miryousefi, told NBC News that the U.S. is more aggressive in terms of cyber attacks, and Iran’s moves are merely defensive.

***

As sanctions reimposed in response to its nuclear program begin to bite, Iran seems poised to follow the trail North Korea blazed in cyberspace: state-directed hacking that aims at direct theft to redress economic pain. Accenture researchers have been tracking ransomware strains, many of them requiring payment in Bitcoin or other cryptocurrencies, and they’ve concluded that they represent an incipient Iranian campaign against targets of opportunity that offer the prospect of quick financial gain. Tehran’s state-directed hackers have a reputation as being relatively less sophisticated than those run by Russia and China (and indeed those run by major Western powers, the Five Eyes and their closest friends) but they also have a reputation as determined fast-learners.

CCN: As the US gets ready to impose sanctions on Iran, hackers in that country are working on ransomware to secure bitcoin, according to cybersecurity experts interviewed by The Wall Street Journal.

Accenture PLC’s cybersecurity intelligence group has followed five Iranian built ransomware variations in the last two years. The hackers are hoping to secure payments in cryptocurrencies, according to Jim Guinn, who oversees the industrial cybersecurity business at Accenture.

Several clues link the ransomware to Iran. Samples include messages in Farsi that are connected to Iran based computers.

A recent Accenture report noted the ransomware could be driven by Iranian government supported parties, criminals, or both.

Scourge Continues

Ransomware has plagued both businesses and governments for years, having disabled payment systems at the San Francisco Municipal Transportation Agency, U.K hospitals and cargo shipments. Government supported hackers in some instances have obtained cryptocurrency payments from victims.

One variant of ransomware that iDefense discovered has been linked to Iran’s government, according to CrowdStrike Inc., another cybersecurity firm. The software, called Tyrant, was developed to discourage Iranian citizens from downloading software designed to discourage government snooping, CrowdStrike noted.

Palo Alto Networks Inc. and Symantec Corp. issued reports last month that described a pair of data stealing operations connected to Iran.

Crypto Mining Linked To Iran

Crypto mining software, which robs computers of their processing power to mine cryptocurrencies, has also been linked to Iran.

Accenture cited crypto mining software installed on Middle Eastern customer networks equipped with digital clues to Iran.

Crypto mining software has created problems in gas and oil facilities in the Middle East, Guinn said. He estimated millions of dollars of compute cycles have been stolen in the last year.

Iran Denies Culpability

Iran has claimed it has not been involved in cyber attacks, and that it has been a hacking victim.

A cyber attack called Stuxnet initiated by the U.S. and Israel about a decade ago disabled uranium-enrichment centrifuges for Iran’s nuclear program. Iran has since focused on enhancing its own cyber capabilities, according to government officials and security researchers.

Keith Alexander, chief executive of IronNet Cybersecurity Inc. and former director of the U.S. Cyber Command and the National Security Agency said crypto mining and theft is a way for cash-strapped countries to make fast profits.

Guinn said hackers have also stolen intellectual property.

New Mexico Compound was Training for School Shooting

Timeline:

TAOS, N.M. (AP) — The Latest on 11 children found living in a filthy, makeshift compound in New Mexico (all times local):

12:30 p.m.

Prosecutors say in court documents that the father of a missing Georgia boy was training children at a New Mexico compound to commit school shootings.

The documents filed Wednesday say Siraj Ibn Wahhaj (see-DAHJ’ IBN wah-HAJ’) was conducting weapons training at the compound near the Colorado border where 11 hungry children were found in filthy conditions.

Prosecutors filed the documents while asking that Wahhaj be held without bail.

Wahhaj was arrested last week with four other adults. They are facing child abuse charges.

Authorities say the remains of a boy also were found on the compound but have not been positively identified by a medical examiners.

__

9:30 a.m.

New Mexico officials investigating a makeshift compound where 11 children were found hungry plan to ask a judge to hold the father of a missing boy without bail.

New Mexico 8th Judicial District Attorney Donald Gallegos said Tuesday that prosecutors are putting together evidence to ask a judge to hold Siraj Ibn Wahhaj (see-DAHJ’ IBN wah-HAJ’) without bond.

A warrant from Georgia seeks the extradition of Wahhaj to face a charge of abducting his son from that state last December.

He is scheduled to appear in a Taos County court on Wednesday. Wahhaj and four other adults also face felony child abuse charges after a raid by authorities found the 11 children living in filth.

The missing boy was not among the children found in that initial search but authorities say they found the remains of a child that they are working to identify.

___

12 a.m.

The father of a missing boy is due in court Wednesday as authorities work to identify a child’s remains uncovered in an isolated New Mexico compound where he was arrested last week.

A warrant from Georgia seeks the extradition of Siraj Ibn Wahhaj to face a charge of abducting his son from that state last December.

Wahhaj and four other adults also face felony child abuse charges after a raid by authorities revealed 11 hungry children living in filth.

The missing boy was not among the children found in that initial search.

The district attorney said he would withhold comment on the potential for additional charges until investigators identified the remains found on the site.

***

CORRECTS LAST NAME TO MORTON, NOT MORTEN – This photo provided by the Taos County Sheriff’s Department shows Lucas Morton, left, and Siraj Wahhaj. Morton and Wahhaj were arrested after law enforcement officers searching a rural northern New Mexico compound for a missing 3-year-old boy found 11 children in filthy conditions and hardly any food. (Taos County Sheriff’s Department via AP)

For months, neighbors worried about a squalid compound built along a remote New Mexico plain, saying they brought their concerns to authorities long before sheriff’s officials first found 11 hungry children on the lot, and then the remains of a small boy.

Two men and three women also had been living at the compound, and were arrested following a raid Friday that came as officials searched for a missing Georgia boy with severe medical issues.

Medical examiners still must confirm whether the body found at the property in a second search on Monday is that of Abdul-ghani Wahhaj, who was 3 in December when police say his father took him from his mother in Jonesboro, Georgia.

The boy’s father, Siraj Ibn Wahhaj, was among those arrested in the compound raid that has since resulted in the series of startling revelations on the outskirts of Amalia, a tiny town near the Colorado state line marked by scattered homes and sagebrush. Authorities said they found the father armed with multiple firearms, including an assault rifle.

Siraj Ibn Wahhaj was scheduled to appear in court Wednesday on a warrant from Georgia that seeks his extradition to face a charge of abducting his son from that state last December. He had expressed wanting to perform an exorcism on his son, the warrant said.

The group arrived in Amalia in December, with enough money to buy groceries and construction supplies, according to Tyler Anderson, a 41-year-old auto mechanic who lives nearby.

He said Tuesday he helped the newcomers install solar panels after they arrived but eventually stopped visiting.

Anderson said he met both of the men in the group, but never the women, who authorities have said are the mothers of the 11 children, ages 1 to 15.

Anderson did not recall seeing the Georgia boy who was missing. But he said some of the smaller children from the compound turned up to play with children at neighboring properties after the group first arrived.

“We just figured they were doing what we were doing, getting a piece of land and getting off the grid,” said Anderson, who moved to New Mexico from Seattle with his wife seven years ago.

As the months passed, however, they stopped seeing the smaller children playing in the area. They also stopped hearing guns fired off at a shooting range on the property, he said.

Jason Badger, who owned the property where the compound was built, said he and his wife had pressed authorities to remove the group after becoming concerned about the children. The group had built the compound on their acreage instead of a neighboring tract owned by Lucas Morton, one of the men arrested during the raid.

“I started to try and kick them off about three months ago and everything I tried to do kept getting knocked down,” said Badger said.

A judge dismissed an eviction notice filed by Badger against Morton in June, court records said. The records did not provide further details on the judge’s decision.

After the raid, Anderson went over and looked at the property for the first time in months.

“I was flabbergasted from what it had turned into from the last time I saw it,” he said.

Authorities said the compound shielded by old tires, wooden pallets and an earthen wall studded with broken glass had been littered with “odorous trash.”

The 11 children found living at the encampment — described as a small trailer embedded in the ground — had been without clean water and appeared to have not eaten in days, according to Taos County Sheriff Jerry Hogrefe.

At a news conference in Taos, Hogrefe described FBI surveillance efforts in recent months that included photographs of the compound and interviews. He said the images were shared with the mother of Abdul-ghani but she did not spot her son, and that the photographs never indicated the boy’s father was at the compound.

“I had no probable cause to get a search warrant to go onto this property,” the sheriff said.

He said FBI officials were invited to the news conference but declined to attend. An FBI spokesman did not immediately return a call seeking comment.

Hogrefe said the “breaking point” in seeking a search warrant came when Georgia authorities received a message that may have originated within the compound that children were starving inside.

It was not clear who sent the message or how it was communicated. Georgia detectives forwarded it to the Taos County Sheriff’s Office.

Authorities returned to search the compound after interviews on Friday and Saturday led them to believe the boy might still be on the property.

“We discovered the remains yesterday on Abdul’s fourth birthday,” Hogrefe said, appearing to fight back tears.

Aleks Kostich, managing attorney in the Taos County public defender’s office, said the office was gathering information and assigning attorneys to the defendants. He declined to comment on their behalf, saying the case was in its early stages.

However, he questioned the “legal sufficiency” of the criminal complaints filed against the men and women, saying they were vague.

“I’m not sure how much investigating has been done,” he said. “I’m not sure how much law enforcement knows and how long they’ve known it for.”

___

AP writers Kate Brumback in Jonesboro, Georgia, contributed to this report. Hudetz reported from Albuquerque.