<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>cyber scenario by e glynn</title>
      <link>https://padlet.com/ncscompeg/eqwt9wurpwo5</link>
      <description>analysis of problems and design solution
</description>
      <language>en-us</language>
      <pubDate>2018-05-17 14:05:33 UTC</pubDate>
      <lastBuildDate>2026-01-11 16:45:55 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet-assets.s3.amazonaws.com/icons/Rocket.png</url>
      </image>
      <item>
         <title>(1) Information needed by an attacker to gain access?</title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261593952</link>
         <description><![CDATA[<div><strong>An Attacker</strong> – A person or group of people who go out of their way to carry out an attack against an individual or company for the purpose of disrupting, infiltrating or damaging systems<br><br>PDA Device is Voice activated - but not person specific - as video in link in The Scenario shows. Keywords operate the unit. From that point any connected device is accessible / risk - door locks etc. <br>Vishing - a voice connection for gaining access to you and or the device. User name and password / credentials for connection to any of the systems to which the PDA is connected. <br>Once the attacker has access to amazon or google credentials they can <strong><mark><sub><sup>LISTEN TO ANY OF THE STORED VOICE RECORDINGS. </sup></sub></mark></strong></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-05-17 14:07:34 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261593952</guid>
      </item>
      <item>
         <title>(2) Implications for each type of device being attacked?</title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594309</link>
         <description><![CDATA[<div>Need to start with the PDA itself.  Then simply: the impact on the house, the safety of the people / individuals in the house - especially children. Access to medical, financial, business, workplace information, location information of children and family - when they are in or not in the house - when they are going away and for how long. Physical and digital implications. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-05-17 14:08:28 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594309</guid>
      </item>
      <item>
         <title>(3) Methods that could be used to EXPLOIT and MITIGATE against vulnerabilities - see LO3. </title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594429</link>
         <description><![CDATA[<div>Vulnerability - (1)  WiFi router / (2) the voice activation of the DPA / (3) Phone and associated apps<br>The VULNERABILITY will be a system attack of the home DPA and will be Intentional / Criminal in nature<br><br><strong>EXPLOIT:</strong> Hacker(s) will employ use of digital methods: spyware, Trojan horse, virus, spear-phishing.  How does each one work? But as has been highlighted in (1) above the assistants<strong><mark> can be voice activated</mark></strong>. So they, the hackers/criminals could just shout commands through the window of the house to open the door via the connected front door lock system. Can actually activate Google Now, Siri and Alexa using inaudible voice commands when transmitted as ultrasounds. <a href="https://arxiv.org/pdf/1708.07238.pdf">https://arxiv.org/pdf/1708.07238.pdf</a>  <br>Bluetooth has previously - end of last year also been an issue for the range of devices. <a href="https://www.bleepingcomputer.com/news/security/blueborne-vulnerability-also-affects-20mil-amazon-echo-and-google-home-devices/">https://www.bleepingcomputer.com/news/security/blueborne-vulnerability-also-affects-20mil-amazon-echo-and-google-home-devices/</a>   Whilst the PDA may have patches and be protected can the same be said of the connected devices. Are they as efficient at producing updates and patches for vulnerabilities in their devices. They will be connected most likely by bluetooth or wifi and are therefore equally at risk even if the hacker or criminal does not have access to the WiFi router. <br><br><strong>MITIGATE:</strong> Use of Software Controls: <br>Testing and monitoring methods - making appropriate and consistent use of Anti Threat Applications - such as firewalls, antivirus, spyware detection, encryption of router / access point. <br>All of the devices need to have software auto update enabled so that they are patched for any vulnerabilities going forward. Previously bluetooth had been a problem as mentioned above. <br>All of the security provision that we have covered in Networks - so changing the initial WiFi admin Password on the router, using WPA2 encryption and a strong password - not sharing the SSID, MAC addressing limited only to the systems/devices in the property. Ensuring wifi devices are updated regularly to ensure that any vulnerabilities are patched. <a href="https://www.symantec.com/connect/blogs/kracks-what-you-need-know-about-new-wi-fi-encryption-vulnerabilities">https://www.symantec.com/connect/blogs/kracks-what-you-need-know-about-new-wi-fi-encryption-vulnerabilities</a></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-05-17 14:08:49 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594429</guid>
      </item>
      <item>
         <title>(4) Different types of attackers - and their motivations?</title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594722</link>
         <description><![CDATA[<div>The majority of this content is in LO2 powerpoint. <br><strong>Types of attackers</strong>: Hackers, script kiddies, neighbour!, <br><strong>Motivations:</strong><br>Personal Gratification that they have been able to hack the system. <br><br>Hack to steal - data, business or personal information, to monitor to track business or personal activity. To misuse your system for their own gain.  <br><br>Hack to disrupt to break what you have in place so you cannot use it. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-05-17 14:09:38 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261594722</guid>
      </item>
      <item>
         <title>The Scenario</title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261595052</link>
         <description><![CDATA[<div><br>SATURDAY <strong><mark>BOYS - MAKE SURE YOU READ THE FOUR BLOCKS I HAVE MADE, THEN THE POSSIBLE QUESTIONS ANSWERS FROM THE OTHER TEACHER IN THE SAMPLE PAPER BELOW. I DON'T THINK THEY TALK ENOUGH ABOUT THE SPEECH ACTIVATION - THIS WILL I THINK BE MORE PROMINENT - BUT THEN THEY KNOW THE QUALIFICATION SO SHOULD KNOW WHAT TO EXPECT. <br><br>KEYWORDS ARE IMPORTANT - CIA STUFF, EXPLOIT, VULNERABILITY - WHAT ARE THEY IN THE NETWORK, AND REMEMBER THE TYPES OF ATTACKERS WE DISCUSSED ON FRIDAY - CASUAL ANNOYING INDIVIDUAL OR A SERIOUS THREAT FROM A HACKER WHO WILL AIM TO MONITOR ACTIVITY ANS STEAL. <br><br>PLEASE CHECK BACK HERE SUNDAY AT 1.00 O'CLOCK LUNCHTIME TO SEE IF THERE ARE UPDATES. <br>WHAT YOU HAVE HERE WILL BE THE BASIS FOR YOU TO PASS AT LEAST. </mark></strong><br><br><br>Considers a subject, mr daka and his family and their home - and the use of a digital personal assistant, that is in turn connected to a range of systems in the house. <br><br>The blocks on this page consider the four key areas that the scenario tells you to examine. I have just started adding scribbles on the scenario sheets. Just click to view each one. See the Learning Organisers at the bottom of this page. <br>Detailed notes will appear in each of the boxes on the right. You must read the background material (to be included and provided tomorrow) that I supply and then refer to the brief notes on the right so that you are prepared for next week. <br><a href="https://www.symantec.com/blogs/threat-intelligence/security-voice-activated-smart-speakers">https://www.symantec.com/blogs/threat-intelligence/security-voice-activated-smart-speakers</a><br><br><br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-05-17 14:10:33 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261595052</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261598638</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/717fccc953859b522024aaa721b105a9/one.jpg" />
         <pubDate>2018-05-17 14:19:41 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261598638</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261598862</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/4d24a24a2e77da2cb5e0e9efadcfa40c/two.jpg" />
         <pubDate>2018-05-17 14:20:14 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261598862</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261614420</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/25b6a6f1f266c70222698a5023b62d69/LO1_Knowlege_Organiser.pdf" />
         <pubDate>2018-05-17 14:53:24 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261614420</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261614770</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/243abdd08f308cf256c589ea93061524/LO2_Knowlege_Organiser.pdf" />
         <pubDate>2018-05-17 14:54:06 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261614770</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261615096</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/a8cdbfa0fd1aedf34d28931bb5611875/LO3_Knowlege_Organiser.pdf" />
         <pubDate>2018-05-17 14:54:45 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261615096</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261720352</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/e16f3c9e51d85bd62591364a120700ad/image.png" />
         <pubDate>2018-05-17 19:07:31 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261720352</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261722655</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/bb74a4a8763bf486d56ce6e67704bffa/istr_security_voice_activated_smart_speakers_en.pdf" />
         <pubDate>2018-05-17 19:15:00 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261722655</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261727276</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/582aec049af9a8df85c7a50ab9e04ac3/image.png" />
         <pubDate>2018-05-17 19:31:02 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261727276</guid>
      </item>
      <item>
         <title></title>
         <author>ncscompeg</author>
         <link>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261884130</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/82688659/9225d4bd736bc14e6970138077bf4f67/Unit_03___2018_May___Digital_personal_Assistant___Mock_Exam___Answers.pdf" />
         <pubDate>2018-05-18 12:02:50 UTC</pubDate>
         <guid>https://padlet.com/ncscompeg/eqwt9wurpwo5/wish/261884130</guid>
      </item>
   </channel>
</rss>
