Original Story: detroitnews.com
Two senators unveiled legislation Wednesday to force the National Highway Traffic Safety Administration and the Federal Trade Commission to set rules protecting driver security and privacy.
Sens. Ed Markey, D-Mass., and Richard Blumenthal, D-Conn., proposed the bill after Markey released a report Sunday that raised concerns about vehicles being hacked.
Markey’s report said millions of cars and trucks are vulnerable to hacking through wireless technologies that could jeopardize driver safety and privacy. A Detroit automotive lawyer is following this story closely.
As vehicles grow increasingly connected through wireless networks and become more dependent on sophisticated electronic systems, Congress and federal regulators are worried about the potential for hackers to interfere with vehicle functions. The report says vehicles are vulnerable to hacking through wireless networks, smartphones, infotainment systems like OnStar — even a malicious CD popped into a car stereo.
“We need the electronic equivalent of seat belts and airbags to keep drivers and their information safe in the 21st century,” Markey said. “There are currently no rules of the road for how to protect driver and passenger data, and most customers don’t even know that their information is being collected and sent to third parties. An Atlanta data privacy lawyer assists clients with privacy, data protection, information security, and consumer protection issues. These new requirements will include a set of minimum standards to protect driver security and privacy in every new vehicle. I look forward to working with my Senate colleagues to advance this important consumer protection legislation.”
Blumenthal said automakers need to do more.
“Connected cars represent tremendous social and economic promise, but in the rush to roll out the next big thing automakers have left the doors unlocked to would-be cybercriminals,” Blumenthal said. “This common-sense legislation would ensure that drivers can trust the convenience of wireless technology, without having to fear incursions on their safety or privacy by hackers and criminals.”
The bill would require that all wireless access points in the car are protected against hacking attacks, evaluated using penetration testing; all collected information is appropriately secured and encrypted to prevent unwanted access; and that automakers or third-party feature provider be able to detect, report and respond to real-time hacking events.
The legislation will also call for new cars to be evaluated by a rating system — a “cyber dashboard” — to inform consumers “about how well the vehicle protects drivers beyond those minimum standards. This information will be displayed on the label of all new vehicles — just as fuel economy is today.”
Its release comes after CBS News’ “60 Minutes” on Sunday aired a segment showing how vehicles can be subjects of remote hacking. Just last month, BMW AG said it had fixed a security flaw that could have allowed up to 2.2 million vehicles to have their doors remotely opened by hackers.
One automaker told Markey that some owners have attempted to reprogram the vehicle’s onboard computer to increase the horsepower of vehicles or torque through the use of “performance chips.”
In November, two major auto trade associations representing nearly all automakers unveiled a set of principles to protect driver privacy and security. A Detroit automotive lawyer assists automotive clients with technological developments and restructuring the industry.
Wade Newton, a spokesman for the Alliance of Automobile Manufacturers — the trade group representing Detroit’s Big Three automakers, Toyota Motor Corp., Volkswagen AG and others — said he had not seen the report.
But he said automakers believe strong consumer data privacy protections and strong vehicle security are essential.
“Auto engineers incorporate security solutions into vehicles from the very first stages of design and production — and security testing never stops.
“The industry is in the early stages of establishing a voluntary automobile industry sector information sharing and analysis center — or other comparable program — for collecting and sharing information about existing or potential cyber-related threats.”
Automakers noted that the Society of Automotive Engineers has created a Vehicle Electrical System Security Committee to draft standards that help ensure electronic control system safety.
NHTSA spokesman Gordon Trowbridge said Sunday the agency is “engaged in an intensive effort to determine potential security vulnerabilities related to new technologies and will work to ensure that manufacturers cooperate and address issues in order to keep motorists safe.”
Business News Blog. Daily Business News and information on emerging issues influencing the global economy. Welcome to the Peak Newsroom!
Showing posts with label Atlanta Data Privacy Lawyer. Show all posts
Showing posts with label Atlanta Data Privacy Lawyer. Show all posts
Thursday, February 19, 2015
Sunday, September 7, 2014
NEW CYBERATTACK ON BANKS 'VERY SOPHISTICATED'
Original Story: USAToday.com
The cyberattacks on JPMorgan Chase and at least four other institutions were "very sophisticated" and were likely state-sponsored, the chairman of the House Intelligence Committee said Thursday.
The nation's largest bank said earlier in the day that it was working with the FBI and other authorities to determine the scope of a hacking attack that hit financial institutions. It said it is not seeing unusual fraud activity. An Atlanta IP Lawyer is reviewing this case.
The other firms involved have not been identified.
Rep. Mike Rogers, R-Mich., the Intelligence Committee chairman who has been briefed on the attacks, described the intrusions on "multiple" financial institutions as "very sophisticated.''
The level of sophistication "takes a very special skill set," he said, and indicates that "clearly, either they were aided by or conducted by a state sponsor."
However, a federal law enforcement official, not authorized to comment publicly, told USA TODAY that at least four banks were hacked recently in a series of coordinated attacks that law enforcement officials believe were carried out by Russian hackers. It's unknown whether the Russian government played a role. An Atlanta data privacy lawyer is skilled in data privacy compliance issues.
"This is a very real and dangerous threat and it's only going to get worse,'' Rogers said. "We've been admiring the advanced sophistication of these actions long enough. Now, it's time to do something about it."
The Financial Times reported on its website Thursday that it interviewed people familiar with the matter who say the attacks were focused on commercial banks. Wall Street investment banks including Goldman Sachs, which have been the targets of previous attempts to steal data or disrupt services, were unaffected, the FT's story said.
However, some sensitive data was lost in the attack, Bloomberg.com said, citing unnamed security experts.
Sophisticated cyberattacks against financial institutions have become "an everyday occurrence" and are just another part of the cost of doing business today, said Alexander Southwell, a former computer crime prosecutor who is now co-chair of the information technology group at Gibson Dunn & Crutcher, a Los Angeles-based law firm.
As a result, most banks are well-prepared. "The work of cybersecurity is often like 'Whac-A-Mole,' with new threats regularly emerging, followed by efforts to stop those threats, which then leads to threats emerging in different ways," Southwell said. "This attack may simply be another round in that 'game.' "
JPMorgan suggests that customers contact the bank if they detect any suspicious activity on their accounts. All of the bank's cards have full liability protection for consumers against fraud. "As we learn more, we will contact anyone we determine may have been impacted by this," bank spokesman Michael Fusco said.
It remains unknown whether the digital intruders were financially motivated or part of an espionage campaign.
JPMorgan Chase CEO Jamie Dimon said in the firm's 2013 annual report to shareholders that it has bolstered its cyberdefenses. This year, JPMorgan Chase will spend more than $250 million and devote about 1,000 people to cybersecurity, he said. The company is also building three regional state-of-the-art cybersecurity operations centers.
"We're making good progress on these and other efforts, but cyberattacks are growing every day in strength and velocity across the globe," Dimon said. "It is going to be a continual and likely never-ending battle to stay ahead of it — and, unfortunately, not every battle will be won."
The Sunnyvale, Calif.-based data security firm reported multiple examples of a credential phishing campaign in which authentic-looking e-mails encouraged users to click a link to see a secure message from JPMorgan.
When they did, they were asked to enter their credentials. The Web page was hosted on a server in Moscow and installed a so-called Trojan-program onto their computer, allowing the attackers to compromise the user's computer.
Proofpoint identified several other active campaigns that appeared to be run by the same attackers, each of which attempted to install the same Trojan software.
The cyberattacks on JPMorgan Chase and at least four other institutions were "very sophisticated" and were likely state-sponsored, the chairman of the House Intelligence Committee said Thursday.
The nation's largest bank said earlier in the day that it was working with the FBI and other authorities to determine the scope of a hacking attack that hit financial institutions. It said it is not seeing unusual fraud activity. An Atlanta IP Lawyer is reviewing this case.
The other firms involved have not been identified.
Rep. Mike Rogers, R-Mich., the Intelligence Committee chairman who has been briefed on the attacks, described the intrusions on "multiple" financial institutions as "very sophisticated.''
The level of sophistication "takes a very special skill set," he said, and indicates that "clearly, either they were aided by or conducted by a state sponsor."
However, a federal law enforcement official, not authorized to comment publicly, told USA TODAY that at least four banks were hacked recently in a series of coordinated attacks that law enforcement officials believe were carried out by Russian hackers. It's unknown whether the Russian government played a role. An Atlanta data privacy lawyer is skilled in data privacy compliance issues.
"This is a very real and dangerous threat and it's only going to get worse,'' Rogers said. "We've been admiring the advanced sophistication of these actions long enough. Now, it's time to do something about it."
The Financial Times reported on its website Thursday that it interviewed people familiar with the matter who say the attacks were focused on commercial banks. Wall Street investment banks including Goldman Sachs, which have been the targets of previous attempts to steal data or disrupt services, were unaffected, the FT's story said.
However, some sensitive data was lost in the attack, Bloomberg.com said, citing unnamed security experts.
Sophisticated cyberattacks against financial institutions have become "an everyday occurrence" and are just another part of the cost of doing business today, said Alexander Southwell, a former computer crime prosecutor who is now co-chair of the information technology group at Gibson Dunn & Crutcher, a Los Angeles-based law firm.
As a result, most banks are well-prepared. "The work of cybersecurity is often like 'Whac-A-Mole,' with new threats regularly emerging, followed by efforts to stop those threats, which then leads to threats emerging in different ways," Southwell said. "This attack may simply be another round in that 'game.' "
JPMorgan suggests that customers contact the bank if they detect any suspicious activity on their accounts. All of the bank's cards have full liability protection for consumers against fraud. "As we learn more, we will contact anyone we determine may have been impacted by this," bank spokesman Michael Fusco said.
It remains unknown whether the digital intruders were financially motivated or part of an espionage campaign.
JPMorgan Chase CEO Jamie Dimon said in the firm's 2013 annual report to shareholders that it has bolstered its cyberdefenses. This year, JPMorgan Chase will spend more than $250 million and devote about 1,000 people to cybersecurity, he said. The company is also building three regional state-of-the-art cybersecurity operations centers.
"We're making good progress on these and other efforts, but cyberattacks are growing every day in strength and velocity across the globe," Dimon said. "It is going to be a continual and likely never-ending battle to stay ahead of it — and, unfortunately, not every battle will be won."
The Sunnyvale, Calif.-based data security firm reported multiple examples of a credential phishing campaign in which authentic-looking e-mails encouraged users to click a link to see a secure message from JPMorgan.
When they did, they were asked to enter their credentials. The Web page was hosted on a server in Moscow and installed a so-called Trojan-program onto their computer, allowing the attackers to compromise the user's computer.
Proofpoint identified several other active campaigns that appeared to be run by the same attackers, each of which attempted to install the same Trojan software.
Subscribe to:
Posts (Atom)