Wednesday, January 27, 2010

Secret mobile phone codes cracked

A German computer scientist has published details of the secret code used to protect the conversations of more than 4bn mobile phone users.
Karsten Nohl, working with other experts, has spent the past five months cracking the algorithm used to encrypt calls using GSM technology.
GSM is the most popular standard for mobile networks around the world
The work could allow anyone - including criminals - to eavesdrop on private phone conversations.
Mr Nohl told the Chaos Communication Congress in Berlin that the work showed that GSM security was "inadequate".
"We are trying to inform people about this widespread vulnerability," he told BBC News.
"We hope to create some additional pressure and demand from customers for better encryption."
The GSM Association (GSMA), which devised the algorithm and oversees development of the standard, said Mr Nohl's work would be "highly illegal" in the UK and many other countries.
"This isn't something that we take lightly at all," a spokeswoman said.
Mr Nohl told the BBC that he had consulted with lawyers before publication and believed the work was "legal".

GSM encryption was first introduced in 1987

Mr Nohl, working with a "few dozen" other people, claims to have published material that would crack the A5/1 algorithm, a 22-year-old code used by many carriers.

The code is designed to prevent phone calls from being intercepted by forcing mobile phones and base stations to rapidly change radio frequencies over a spectrum of 80 channels.

It is known to have a series of weaknesses with the first serious flaw exposed in 1994.
Mr Nohl, who describes himself as an "offensive security researcher", announced his intention to crack the code at the Hacking at Random (HAR) conference in The Netherlands in August this year.
"Any cryptographic function is a one way street," he told BBC News. "You should not be able to decrypt without the secret key".
To get around this problem, Mr Nohl, working with other members of the encryption community, used networks of computers to crunch through "every possible combination" of inputs and outputs for the encryption code. Mr Nohl said there were "trillions" of possibilities.
Using the codebook, a "beefy gaming computer and $3,000 worth of radio equipment" would allow anyone to decrypt signals from the billions of GSM users around the world, he said."It's like a telephone book - if someone tells you a name you can look up their number," he said.
Signals could be decrypted in "real time" with $30,000 worth of equipment, Mr Nohl added.
'Not practical'
It has previously been possible to decrypt GSM signals to listen in on conversations, but the equipment cost "hundreds of thousands of dollars," experts said.
According to Ian Meakin, of mobile encryption firm Cellcrypt, only government agencies and "well funded" criminals had access to the necessary technology.
He described Mr Nohl's work as a "massive worry".
"It lowers the bar for people and organisations to crack GSM calls," he told BBC News.
"It inadvertently puts these tools and techniques in the hands of criminals."
However, the GSMA dismissed the worries, saying that "reports of an imminent GSM eavesdropping capability" were "common".
It said that there had been "a number" of academic papers outlining how A5/1 could be compromised but "none to date have led to a practical attack".
The association said that it had already outlined a proposal to upgrade A5/1 to a new standard known as A5/3 which was currently being "phased in".
"All in all, we consider this research, which appears to be motivated in part by commercial
considerations, to be a long way from being a practical attack on GSM," the spokeswoman said.

Saturday, January 2, 2010

Cybercrooks stalk small businesses that bank online

From a usa today article comes a cybercrime trend I have been talking and working on for more than a year.

A rising swarm of cyber-robberies targeting small firms, local governments, school districts, churches and non-profits has prompted an extraordinary warning. The
and the
are advising small and midsize businesses that conduct financial transactions over the Internet to dedicate a separate PC used exclusively for online banking.
The reason: Cybergangs have inundated the Internet with "banking Trojans" — malicious programs that enable them to surreptitiously access and manipulate online accounts. A dedicated PC that's never used for e-mail or Web browsing is much less likely to encounter a banking Trojan.
And the bad guys are stepping up ways to get them onto PCs at small organizations. They then use the Trojans to manipulate two distinctive, decades-old banking technologies: Automated Clearing House (ACH) transfers and wire transfers.
ACH and wire transfers remain at the financial nerve center of most businesses. ACH transfers typically take two days to complete and are widely used to deposit salaries, pay suppliers and receive payments from customers. Wire transfers usually come into play to move larger sums in near-real time.
"Criminals go where the money is," says Avivah Litan, banking security analyst at
, a technology consulting firm. "The reason they're going here is the controls are antiquated, and a smart program can often get the money out."

Internet-enabled ACH and wire transfer fraud have become so acute that the FBI, which is usually reticent to discuss bank losses or even acknowledge ongoing cases, has gone public about the scale of the attacks to bring attention to the problem. The FBI, the Federal Deposit Insurance Corp. and the
have all issued warnings in the past two months.
The FBI says it has investigated more than 200 cases, mostly in 2008 and 2009, in which cyber-robbers executed fraudulent transfers totaling about $100 million — and successfully made off with $40 million.
The victims are mostly small to midsize organizations using online bank accounts supplied by local community banks and credit unions, FBI analysis shows. "The bad guys are still out there breaking into customers' computers," says Steven Chabinsky, deputy assistant director of the FBI's Cyber Division.
Banking and tech security experts say many more cases of ACH and wire transfer fraud are going unreported mainly because the attacks are new and there are no laws setting forth the rights of online business account holders, the way consumer-rights laws protect accounts held by individuals. The result: Many cases end in civil disputes in which small businesses often lose.
"Our nation's legislators are not doing their job in affording the same protections for business account holders that they do for consumer account holders," says Litan.
Risky business

Several developments make this new form of fraud irresistible for cybercriminals. In a race to win more online business customers, many banks offer high limits on ACH and wire transfers, even though their systems lack modern technologies for detecting fraud, says Terry Austin, CEO of security firm Guardian Analytics.
"Many banks rely heavily on their online channels but fail to implement the necessary protections," says Austin. "Cybercriminals are capitalizing on this opportunity."
Meanwhile, stealthy, malicious programs borne by corrupted Web links lurk everywhere on the Internet: in e-mails, social-network postings, online ads, even search query results. Click on a tainted link, and you could get infected by a cyber-robber's banking Trojan. Hundreds of new banking Trojan variants appear on the Internet every day. The number should top 200,000 in 2009, up from 194,000 in 2008, according to PandaLabs.
The likelihood of any ordinary person getting his or her PC infected by a banking Trojan is so great that Gartner's Litan tells acquaintances who run small businesses to switch from commercial online accounts to an individual consumer account.
That's because consumer-protection laws require banks to fully reimburse individual account holders who report fraudulent activity in a timely manner. However, banks have taken to invoking the Uniform Commercial Code — a standardized set of business rules that have been adopted by most states — when dealing with fraud affecting business account holders. Article 4A of the UCC has been interpreted to absolve a bank of liability in cases where an agreed-upon security procedure is in place and a theft occurs that can be traced to a compromised PC controlled by the business customer.
"It's time for small business to wake up and understand the true risk of online banking," says Litan. "If the bank thinks you were negligent, they do not have any obligation to pay you back."
The Western Beaver County School District in Pennsylvania, for one, is testing this stance. It is suing ESB Bank for executing 74 unauthorized cash transfers totaling $704,610 over four days during Christmas break a year ago. Court records show cash moved into 42 receiving accounts in several states and Puerto Rico. The bank retrieved $263,413 but did not recover $441,197.
ESB's attorney, Joseph DiMenno, says the bank is confident it will be "fully exonerated" but declined to discuss the lawsuit in detail. In a court filing, the bank denied any liability and said the district's "failure to secure and protect" its computers and network were to blame for any damages.
"They were able to reverse some of the transfers, but for others, the money apparently was already gone," says the district's attorney, Brian Simmons, of the Pittsburgh law firm Buchanan Ingersoll & Rooney. "We're not entirely sure who ended up with the funds. But the school district would like its money back."
So, too, would officials in
County, Ky. Over seven days in June, unauthorized transfers totaling $415,989 were moved out of the payroll account the county kept at First Federal Savings Bank of Elizabethtown. In a resolution authorizing a lawsuit against First Federal, county officials noted that "$105,813.06 of the people's money" had been recovered, while "$310,176.11 remains in the hands of the thieves throughout the country and abroad."
Gregory Schreacke, the bank's president, said in an interview that Bullitt County's "net loss" was actually $299,684. He said the bank stands by its decision not to make the county whole.
"No, we are not going to give it back," says Schreacke. "The county's network did not have an effective firewall, its virus protection software was woefully out of date and the county's treasurer and (chief) executive did not follow internal controls that would have prevented the unauthorized transfers."
The county's attorney, Larry Zielke, says First Federal should have stopped payroll transfers to other states and countries, something Bullitt County, population 75,000, never does. "Customers shouldn't have to protect the banks," says Zielke. "Banks should protect their customers."
Banking analyst Litan says it is unrealistic for the banking industry to promote Internet banking as safe based on the expectation that account holders will continually secure their PCs against cyberintrusions. "Banks should at least put a large disclaimer on their home Web pages advising customers that they bank online at their own risk," she says.
Indeed, any organization that cannot survive a sudden five- or six-figure loss should consider shunning Internet banking altogether, says Amrit Williams, chief technical officer of security firm BigFix. "Online is a very dangerous place for any small organization to be right now," he says. "The guidance for most of them should be, 'Don't bank online unless you absolutely have to.' It is too risky, and there are too few controls to support you if you fall prey to a malicious incident."
Getting the cash

The banking industry acknowledges that online banking is risky and is doing all it can to address those risks without impairing development of electronic banking, says Doug Johnson, senior risk management adviser at the American Bankers Association. He says small businesses should heed the ABA's advice to use a dedicated PC for online banking.
"The fraudulent transactions represent a very small portion of the millions of safe and successful ACH transactions conducted daily by businesses across the country," says Johnson.
The ABA's position is that each bank sets its own policy for how much liability to assign to business account holders when unauthorized transfers occur. In general, "Banks urge business customers to be aware of their responsibility to keep computers used for online banking free of malicious programs," Johnson says.
Meanwhile, cyber-robbers continue to orchestrate online heists of increasing sophistication. Getting the money out is not easy; it requires careful planning and meticulous coordination. According to interviews with law enforcement officials and security researchers, here's how a typical theft unfolds:
First, a researcher spends some time on
locating the public Web pages of small businesses, local agencies and smaller organizations in the habit of posting names — and sometimes e-mail addresses — of a comptroller or a senior executive. Next, a graphic designer crafts an official-looking message purporting to come from the IRS or a shipping company addressed to the targeted employee. This is what's known as "spear phishing," a ruse to get the employee to click on a tainted Web link. Clicking on the link swiftly and silently installs a banking Trojan.
One spear-phishing template in wide circulation purports to come from the target's own tech department, says Amit Klein, CTO of security firm Trusteer. It instructs the recipient to click on a link to ensure continued access to the company's Outlook e-mail system. "It's well-crafted and very effective," says Klein.
Banking Trojans can be simplistic. One common variety readily for sale on the Internet installs keystroke loggers that record banking account log-ons typed by the PC user. The robber later uses the log-on to access the account. Others are intricate, crafted to defeat the single-use PIN codes, smart cards, security certificates and biometric scanners some banks require for ACH transfers and wire transfers.
One such Trojan discovered by Trusteer set up a special chat channel to alert the attacker whenever the victim began to type in a key-fob-issued PIN code, which remains valid for 60 seconds. Acting quickly, the robber would then log on and set up a transfer, undetected, while the employee carried on other banking transactions.
"The problem is growing, and the sophistication is increasing," Klein says.
Micropayments

Randy Vanderhoof counts himself lucky. The executive director of Smart Card Alliance, a Princeton Junction, N.J., non-profit advocacy group, moved quickly when he noticed suspicious wire transfers from the group's
online banking account in July.
The first two transfers were two micropayments, for 95 cents and 31 cents, that went to the same account at
, an online-only bank. That was followed two days later by a transfer of $25,000 into the ING account, followed by three more transfers for $25,000 and one of $24,800 in the ensuing four days, one transfer a day.
Vanderhoof alerted Bank of America quickly enough for it to recover all of the transfers. He figures the micropayments were tests and that the subsequent big transfers indicate that the robber was being frustrated in attempts to convert the deposits into cash.
He figures ING probably had the account under surveillance. But he doesn't know because he says the banks did not satisfy his requests for a detailed explanation. ING declined to comment. Bank of America follows industry practice of not discussing customer cases, says spokeswoman Tara Burke. The bank takes security seriously and offers customers a wide array of security tools and services, she says.
Vanderhoof closed the breached account and opened a new one, begrudgingly agreeing to pay Bank of America $125 more a month in fees for a service that permits transfers only from pre-approved parties. The service recently has blocked unapproved transfers of 12 cents, 25 cents and 38 cents.
He concludes would-be cyber-robbers have obtained the log-on details to the new account and are testing whether the bank will make unauthorized transfers.
"Our account is still out there, still getting hit with these probe transfers," he says. "I guess the only thing the bad guys haven't figured out is that they're not on our approved list."

Friday, December 11, 2009

Bank Login-Stealing Botnet Found Hiding in Amazon Cloud

We've all heard security researchers flail about the vulnerabilities of cloud computing; well, here's some interesting news.

Black-hat hackers got into an unnamed website hosted on Amazon's servers then proceeded to install an illegal command and control infrastructure. Named America's number one most wanted botnet, Zeus was discovered on Amazon's Elastic Compute Cloud (EC2) by security researchers yesterday.

The Zeus Trojan is a keylogger designed to steal data such as login credentials, account numbers and credit card information. It creates fake HTML forms on banking login pages to allow hackers to steal user data. This particular botnet has been linked to around $100 million in bank fraud in 2009.

Although we don't yet have details on exactly how the website in question was hacked, we have learned that the software has been removed from the Amazon cloud. This incident is the first example of malware being found on AWS' infrastructure.

As we were warned by black hats in April this year, cloud computing carries certain risks and opportunities for exploitation. Our own Sarah Perez wrote:

In another part of the Sensepost presentation, they looked specifically at vulnerabilities of Amazon's Web Services. To start off, they detailed the process involved in setting up a new instance on EC2... While Amazon has provided 47 machine images they built themselves, the remaining 2721 images were build by other EC2 users. Can you really believe that all of these images were built securely? Basically, the template directory is just a big archive of user-generated content. And you know what user-gen content is like... risky.
As John Pescatore told the Financial Times, "The security of these cloud-based infrastructure services is like Windows in 1999. It's being widely used and nothing tremendously bad has happened yet. But it's just in early stages of getting exposed to the Internet, and you know bad things are coming."

Will hackers continue to employ web services to carry out their schemes in 2010? Twitter, Facebook, Google Apps, and now Amazon Web Services have all been used for evil this year. How can websites, corporations, and end users be smarter about online security to avoid personal and financial loss next year? Let us know what you think in the comments.

Wednesday, December 2, 2009

A telco busted once again giving our rights away

Seems like Sprint Nextel has provided law enforcement agencies with its customers' (GPS) location information over 8 million times between September 2008 and October 2009. This disclosure of sensitive customer information was made possible due to the roll-out by Sprint of a new, special web portal for law enforcement officer.

Check out the blog posting
. Excellent work by
Christopher Soghoian

Monday, November 23, 2009

Reversing JavaScript Shellcode: A Step By Step How-To

With more and more exploits being written in JavaScript,
, there is a need to be able to reverse exploits written in JavaScript beyond de-obfuscation. I spent some time this weekend searching Google for a simple way to reverse JavaScript shellcode to assembly. I know people do it all the time. It's hardly rocket science. Yet, I didn't find any good walk-throughs on how to do this. So I thought I'd write one.

Head on over to http://pmelson.blogspot.com/2009/11/reversing-javascript-shellcode-step-by.html for this great artcle.

Dark For 36 Hours: Burlington’s Web Gambit

Leaving online shoppers out in the cold with no warnings or explanations (or coats, if that's what they wanted to buy), Burlington Coat Factory took its Web site offline all day Wednesday (Nov. 18)—plus about 12 hours split between Tuesday and Thursday—for a planned outage as the $3.5 billion clothing retailer performed an extensive hardware and database upgrade.
In what a senior company official conceded was an oversight, the 430-store, New Jersey-based chain failed to publish any ahead-of-time advisories before yanking its E-Commerce site's plug in the wee hours. Nor did it post much in the way of an explanatory statement during the long downtime period that followed. "The messaging on the site could clearly have been better," Burlington Coat Factory Supervisor of Web Development Jack Follansbee said. "It was an omission. We should have done something (a status page) a little more customized."

Thursday, November 19, 2009

CYBER-SECURITY INCLUDES ATTACK PLANS TOO, AND THE U.S. HAS ALREADY USED SOME OF THEM SUCCESSFULLY.

In a recent article in the National Journal Magazine, the NSA supposedly admits to using computer attacks in Iraq, attacking cellular systems. Aside to the hacking part, which is obviously "cool", the impact on the US cyber defense stance as well as international relations is staggering.

In May 2007, President Bush authorized the National Security Agency, based at Fort Meade, Md., to launch a sophisticated attack on an enemy thousands of miles away without firing a bullet or dropping a bomb.
At the request of his national intelligence director, Bush ordered an NSA cyberattack on the cellular phones and computers that insurgents in Iraq were using to plan roadside bombings. The devices allowed the fighters to coordinate their strikes and, later, post videos of the attacks on the Internet to recruit followers. According to a former senior administration official who was present at an Oval Office meeting when the president authorized the attack, the operation helped U.S. forces to commandeer the Iraqi fighters'
See http://www.nationaljournal.com/njmagazine/cs_20091114_3145.php

Thursday, October 8, 2009

Lawsuit: A Heartland Manager Resigned Because Of PCI Compliance Issues

As the lawsuits involving Heartland’s massive data breach move through the court system, an unusual claim was inserted into a court filing. The Sept. 23 filing in the U.S. District Court for the Southern District of Texas was trying to raise questions about Heartland’s post-breach conduct. It then shared the following anecdote without further explanation.
“On the day after the data breach, Heartland conducted a webinar about the data breach for its high-level employees, sales representatives and/or relationship managers. Upon information and belief, Heartland relationship managers were told that PCI compliance was not a big deal. One of Heartland’s relationship managers resigned on or around April 23, 2009, in part because of Heartland’s statements regarding its PCI compliance. A Referee’s Decision in a Delaware Department of Labor proceeding reached the conclusion that this relationship manager had “good cause” to leave her position at Heartland based, in part, on Heartland’s conduct.” That might prove quite significant or it could be an irrelevant red herring. Either way, it’s not the kind of detail we see very often.

Tuesday, October 6, 2009

In the news ....

North Korea-China
:  China's Premier Wen Jiabao met North Korean premier Kim Yong Il on Sunday at Sunan airport at the start of Wen’s three day state visit.  Despite the speculation, Wen’s trip is about restoring bilateral ties that have been strained since China supported sanctions against North Korea last May.  The significance of the visit is that it is taking place. That means the strain since May has ended, but not that relations will ever be as they had been in the past.
 North Korea-India
: The Indian Navy detained a North Korean ship in Indian waters near Vatakara, Kerala State, southwestern India, China Daily reported 4 October, citing a statement from the Indian Defence Ministry. The navy and coast guard spotted the ship, Hyang Ro, anchored in Indian waters, and immediately detained the ship and its crew. Unnamed Indian sources said the preliminary investigations show the ship was bound for Pakistan via Colombo, Sri Lanka. A search is being conducted to make sure no illegal cargo is aboard. The Hyang Ro is owned by Pyongyang-based Sinhung Shipping Company, a state-owned export company.
 The Indians are serious about enforcing the sanctions against North Korea, especially when the cargos are bound for Pakistan. The North Koreans are equally serious about continuing to try to ship their weapons.
Pakistan:
 Unnamed US defense officials said today that Pakistan has enough soldiers and equipment mobilized to launch a ground offensive against Taliban militants in South Waziristan, Reuters reported 4 October. The officials said that a Pakistani effort to eliminate Taliban and al Qaida sanctuaries in the border region between Pakistan and Afghanistan is critical to the success of the U.S. mission in Afghanistan.
The Pakistani military has been imposing a blockade on the region, and used air and artillery attacks to harass the Pakistani Taliban. However, the Army has claimed that shortages in supplies are the reason for its delay in commencing ground operations in Waziristan. About 28,000 Pakistani forces are deployed to the region, according to a Pakistani military spokesman.
Comment:  The Reuters item published the comments attributed to US defense officials without providing context. Still, the comments are odd because the US is applying a capabilities yardstick to the Pakistan Army that it does not apply to itself, the most powerful country in the world.
No public source has estimated the strength of the Wazir opposition fighters that the Pakistan Army might face. It might be a 1:1 ratio in which case the unnamed US defense officials need to work on their sums, before moving to higher math.  The issues in South Asia seem to invite vacuous statements in the name of information operations, which the US does not seem to do well. But the statements do lack context.
Not lacking in context are the ten steps to victory in Afghanistan published by the New York Times. Each could be challenged in one or other way, but Paul Pillar’s comments about ending Pakistani patronage to the Afghan Taliban is on point.  Pakistan’s continuing support to its proxy in the long fight against India is an open secret, just as its support to Kashmiri militants and separatists is. It has given up neither, just as the commitment to counter terrorism as a national security priority is a grand ruse for the Americans.
The one issue NW would take with Pillar’s comment is the benchmarks.  Pillar’s metrics are soft and subjective, but the world has seen what Pakistan can do when its leaders set their minds to it.  In 2003, when Musharraf was in power in Islamabad and Vajpayee in office in New Delhi, Musharraf ordered a military ceasefire across the Line of Control in Kashmir and instituted a sustained control regime on the Kashmiri militants supported by the Inter-Services Intelligence Directorate. 
The result of Musharraf’s orders were Inter-Services Intelligence agents were forced to reduce aid to the militants to bare sustainment levels; stopped infiltration; stopped the flow of arms and ammunition to the militants and into Indian Kashmir and confined militant leaders and supporters to camps back from the Line of Control.  
To his credit, Musharraf maintained the ceasefire and the clamp down on the militants until his resignation in 2008. It was the longest period of comparative quiet along the Line of Control in decades. The point is Pakistan can control insurgency based in Pakistan. Omar and the Quetta Shura have safehaven in Pakistan because Pakistanis have concluded the survival of the Afghan Taliban is in Pakistan’s national security interests during the period after the Americans tire and leave again.
If the Pakistani leaders should get serious about booting the Quetta Shura, there will be plenty of metrics and easy to detect. They are not serious.
Putting the two comments together, it is vital that the US impose greater discipline on the big mouths who are leaking in the name of information operations or other misguided ideas.  US successes in Afghanistan do not create a record that would justify anonymous US defense officials in presuming to preach to anyone, much less Pakistanis.
Secondly, the US record of engagement in south Asia is that of a nation with attention deficit disorder. Consider, in the past week Iran’s facility at Qom supplanted Pakistan and Afghanistan – real battle zones -- as the issues du jour. Perceptive Readers will presume this was a deliberate US stratagem.  Thus, Pakistan’s focus on its long term interests and its long term, sustained loyal friends is well justified. Only China and the Pashtuns fall into those categories.
Finally, the collective wisdom of the US experts about Waziristan could fit into a small booklet and most of that would be plagiarized. The British, now, and the Pakistanis have first hand experience in mounting combat operations against the Wazirs. None were particularly distinguished, but at least they did not feature unnamed defense officials sitting in air conditioned comfort in Washington criticizing Pakistan.
Afghanistan
: For the record. As for the record of US success in Afghanistan, a US spokesman said eight American soldiers and two Afghans were killed in an attack on two outposts in remote eastern Afghanistan. The military statement Sunday said a tribal militia launched the attack from a mosque and a nearby village in Nuristan Province. eastern Afghanistan. 
This makes any US criticism of Pakistan look quite misaimed.
Afghanistan
-The Netherlands: Update. The leaders of two parties essential to the Christian Democrat-led coalition in the Netherlands announced their parties will not vote to extend the presence of the 1,400-man Dutch contingent in Afghanistan. When the latest commitment expires in 2010, the Dutch soldiers will depart, according to the party leaders, who point out the Dutch soldiers already have stayed two years longer than first agreed.
Iran
:  Comment:  The weekend press was over the top in repeating old news about the state of Iran’s knowledge of nuclear warhead design.  This is old news.  Last month The Associated Press and Night
Watch
reported on the draft study by the International Atomic Energy Agency that concluded Iran had the knowledge for making a nuclear weapon.
The big news this weekend, which no television or radio media repoprted, is that the Institute for Science and International Security has obtained more details from the same study and posted the information on its web site.  More is not better and the new data in no way changes the bottom line from a month ago: Iran almost certainly knows how to make a nuclear bomb.  Pakistan’s A.Q. Khan made certain of that several years ago. Those who have followed this story are well aware.
International Atomic Energy Agency (IAEA)
chief Mohamed El Baradei said that the conflict over Iran's nuclear program is "shifting gears" from confrontation into transparency and cooperation, and that nuclear inspectors will visit Iran's recently disclosed uranium processing facility 25 October, China Daily reported. El Baradei made the statement in Tehran following talks with Iranian officials, including nuclear chief Ali Akbar Salehi, about the recently revealed nuclear site, and said that the inspections will be conducted in accordance with the nuclear Non-Proliferation Treaty.
El Baradei lost his detachment about Iran years ago and failed to maintain discipline in his own organization. He opposes sanctions or other forms of coercion that would limit his access to Iran or prove the agency under his tenure failed in controlling, much less preventing, nuclear weapons proliferation.
Somalia
:  Update. The government in Mogadishu will not be able to defeat hard-line al Shabaab militants without international assistance to strengthen its security forces, Somali Interior Minister Abdukadir Ali Omar said 4 October. Omar said Somali security forces are not strong enough, and that African Union peacekeepers have a defensive mandate that prevents them from eradicating the al Shabaab militant group, which recently recaptured Kismayo port.
Omar’s timing in calling for outside troops could hardly be worse. The irony is that Afghanistan has no al Qaida presence, according to National Security Advisor Jones, today, but reinforcements for Afghanistan are being justified on the grounds of stopping al Qaida from re-establishing a base there. 
Somalia
is on the verge of becoming a new safe haven for al Qaida and any number of other terrorist groups. Unlike Afghanistan, Somalia is a region where the international terrorist threat is authentic, but only two African states, a few French and a few American security specialists and some Somali clans want to stop al Qaida from establishing a base in Somalia

NATO’s Rasmussen on Cyber Risks

On 1 October, NATO Sec Gen Anders Fogh Rasmussen
on the emerging security risks of piracy, cyber and climate change. Most of his
concerned the latter but he had this to say about responding to cyber threats:
Cyber security – our second topic today – is another case in point.  Government and private companies launch cyber-attacks.  Governments and industry suffer the consequences, in terms of lost revenue, lost data and lost services.  And it will take cooperation between the public and private sectors to build real defences.
We also want to do better at cyber defence.  NATO’s Cyber Defence Centre is a good step in the right direction.  But the sustained, directed cyber attacks Estonia suffered a couple of years ago shows that the problem is much bigger than that.  On both subjects, I’m very much looking forward to the discussions today.
But there is a fundamental difference between, one the one hand, piracy and cybersecurity, and climate change on the other.  In the first two cases, the threat is very clear.  We know what a pirate looks like – and no, I’m not thinking of someone with an eye patch and parrot on his shoulder.  I’m thinking of someone well armed and ruthless.  The kidnapping and ransom is taking place now.  The costs to industry and Governments are easily calculated.  And while implementing them might be difficult, we have a pretty good idea of what the right solutions might be.
The same is true of cyber defence.  Attacks on industry and government websites and information systems are already a daily occurrence.  Again, the costs are pretty easy to calculate.  And while we are certainly able to do better, we have a general idea of the steps we should take. The challenge is figuring out how to do it.
Although referring principally to climate change, his concluding comments were also applicable to cyber:
This cannot be done by the defence people alone.  It has to be a true team effort: civilian and military, public sector and private companies as well – all talking together, and working out mutually reinforcing efforts.  That might seem unrealistic, to those of us who have been in politics a few years.  No glacier is as imposing, no desert so impassable as the stovepipes within Governments.  Then again, sailors never thought the mythical North-West Passage would ever open. But it is opening.  Anything’s possible.
Rasmussen’s right – the door is opening (the North-West Passage metaphor, if it was meant as a metaphor, is a curious one; I thought it was a bad thing, what with the Arctic ice melting like billy-o ‘n all) but not very wide.