Enjoy the https prefix, with it you can rest assured that you are safe from *fake* conference news. That's very important because the Euro S&P conference is next month, and the S&P Symposium is in May. If you have not already registered, do so now, safely and securely. Two items in our news list are worthy of special mention. The first is that the Security and Privacy magazine is taking applications for a new Editor in Chief. The second is the note of Becky Bace's passing. She was an early leader in instrusion detection research, and an enthusiastic supporter of the field of cybersecurity. Her precocious intelligence and opinionated views led her exasperated father to call her "infidel", and she delightedly embraced the term, naming her consulting business Infidel, Inc. If you have noticed a dearth of women in the field of computer security, you are not alone. It is one of the most gender-skewed disciplines in the field. At a recent meeting of the Technical Activities Committee of the Computer Society, I urged all TC chairs to try to be aware of the participation by minorities, quoting an ACM conference chair who said, "If we cannot solve the problem for 50% of the population, then we cannot solve it at all." It remains to be seen if the TCSP, or any part of the Computer Society, will consider steps towards increased diversity. To cyberarms, that come before the melt of ICE, and make the winds of March throw secrets far afield, Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== News Briefs ==================================================================== IEEE "Security and Privacy" Magazine seeking new Editor in Chief Please note that the deadline for IEEE Security & Privacy magazine Editor in Chief applicants is 1 June 2017. Prospective candidates are asked to provide a PDF file containing a complete curriculum vitae, a brief plan for the publication's future, and a letter of support from their institution or employer. For complete information, please visit: https://www.computer.org/web/pressroom/eic-for-2018-2020>https://www.computer.org/web/pressroom/eic-for-2018-2020. Questions and submission materials can be sent to Christine Anthony (canthony@computer.org). --------------------------------------- NSA Hoarder Indicted Former NSA contractor indicted in stolen data case CNNPolitics.com Feb. 8, 2017 By Tal Kopan, Evan Perez and Laura Jarrett http://www.cnn.com/2017/02/08/politicssa-contractor-alleged-classified-theft-harold-martin-indictment Summary: The strange case of Harold Thomas Martin III has resulted in an indictment of 20 counts of "willful retention of national defense information," but not the espionage charges that seemed a possibility when the case was first revealed. Although Martin stole 50 terabytes of NSA information, he seems to have been a compulsive "data hoarder" rather than a spy. He was a contractor for Booz Allen Hamilton. --------------------------------------- Mexican activists, targeted by spyware Spyware's Odd Targets: Backers of Mexico's Soda Tax The New York Times Feb. 11, 2017 By Nicole Perlroth https://www.nytimes.com/2017/02/11/technology/hack-mexico-soda-tax-advocates.html Summary: NSO Group is a company with the motto "Make the World a Safer Place", but activisits in Mexico have reason to doubt that their products do that. The company sells cyberarms, and they assert that they sell only to governments. Their spyware shows up in messages sent to the phones of activisits, those with the rather non-terroristic agenda of increasing the tax on soft drinks. The spyware is capable of sending every phone interaction to remote observers, and it is a very intrusive form of surveillance. Apparently these tools are cats that just won't stay in the bags. --------------------------------------- Doll Hacking The Bright-Eyed Talking Doll That Just Might Be a Spy By Kimiko de Freytas-Tamura New York Times Feb. 27, 2017 https://www.nytimes.com/2017/02/17/technology/cayla-talking-doll-hackers.html Summary: The Trojan Horse may well be a toy doll. A cute talking doll manufactured by United States-based Genesis Toys and distributed by the Vivid Toy group is real tattle-tale because it records ambient voices and sends the voice prints of children to Nuance Communications, a computer-software company. Germans have taken a very dim view of the technology, calling the toy the "Stasi-Barbie". With toys like this, who needs NSO software (see previous article)? --------------------------------------- Cloud Leak A major security flaw means you have to change your passwords again The Washington Post Feb 28, 2017 By Hayley Tsukayama https://www.washingtonpost.comews/the-switch/wp/2017/02/24/a-major-security-flaw-means-you-have-to-change-your-passwords-again/ Summary: Pity the poor software engineers at Cloudflare. They were simply "changing over from older code to newer code" but didn't realize that "Running both at the same time created an unforeseen issue that ... caused a data leak." Unfortunately, that data leak may have exposed personal information, including passwords, for millions of users who never heard of Cloudflare. Their technology is trusted by banks, retailers, and messaging services, and the extent of the exposure is unknown. Just to be safe, change your passwords. My fingertips are calloused from following that kind of advice. --------------------------------------- Ethereum Business Giants to Announce Creation of a Computing System Based on Ethereum The New York Times Feb. 27, 2017 By Nathaniel Popper https://www.nytimes.com/2017/02/27/business/dealbook/ethereum-alliance-business-banking-security.html Summary: Thirty businesses took one giant step for "smart contracts" with the announcement of the Enterprise Ethereum Alliance. They will use blockchain technology from Ethereum (https://www.ethereum.org ) which has "applications that run exactly as programmed without any possibility of down time, censorship, fraud or third party interference" (you can watch blockchain activity at https://etherscan.io/ ). In doing so, they are adding to a handful of similar ventures all hoping to become the center of the distributed trust universe. Blockchain technology underlies the digital currency BitCoin, and Ethereum uses the same "mining" technology for adding transactions to a verifiable database. Ethereum allows transactions to include conditional payments of the form "if A then B pays C the amount M." By some estimates, large banks could save 30% of their infrastructures costs by using smart contracts. --------------------------------------- CIA and IoT WikiLeaks: The CIA is using popular TVs, smartphones and cars to spy on their owners The Washington Post Mar 7, 2017 By Craig Timberg, Elizabeth Dwoskin and Ellen Nakashima https://www.washingtonpost.comews/the-switch/wp/2017/03/07/why-the-cia-is-using-your-tvs-smartphones-and-cars-for-spying Summary: Is the CIA in your TV? According to documents released by WikiLeaks, they could be lurking there, or in almost anything that connects to the Internet. Security experts who have been looking at the documents believe that someone with access to a Top Secret CIA development system copied them about a year ago. There was no release of source code, but the documents show how the CIA's internal organizations feed their voracious appetite for compromising personal devices. Their goal is often to conduct surveillance, but in one case, they considered the possibility of assassination by invading the control systems of cars. Some researchers have questioned the risk/benefit trade-off of such tools, noting that they seem to inevitably, and quickly, escape from "responsible" hands (see NSO software article above). ----- WikiLeaks CIA, commentary WikiLeaks disclosure exposes rapid growth of CIA digital operations - and agency vulnerabilities The Washington Post Mar 7, 2017 By Craig Timberg, Elizabeth Dwoskin and Ellen Nakashima https://www.washingtonpost.com/worldational-security/wikileaks-disclosure-exposes-rapid-growth-of-cia-digital-operations--and-agency-vulnerabilities/2017/03/08/6f7fd412-0429-11e7-b9fa-ed727b644a0b_story.html Those who have read the WikiLeaks documents about CIA hacking have gleaned some major and minor insights into the secret digital hacking division known as the Directorate of Digital Innovation. With dozens of subordinate branches, it seems to be distributed around the world and covers all kinds of hacking and surveillance. Instructions to its youngest employees include advice on getting free alcohol from airlines and admonishments to have their cover stories well-rehearsed before entering airport security. Although the disclosure of their activities may cause some targets to ditch their current smartphones or TVs (or even toys, see article above about the Stasi Barbie), security experts feel that the CIA will rebound quickly with new technology. The vulnerabilities that they depend on come and go, and they are always looking for the next security flaw, it's just business as usual. --------------------------------------- DNS and the Trump-Russia Connection FBI investigation continues into 'odd' computer link between Russian bank and Trump Organization CNNPolitics.com Mar 9, 2017 By Pamela Brown and Jose Pagliery http://www.cnn.com/2017/03/09/politics/fbi-investigation-continues-into-odd-computer-link-between-russian-bank-and-trump-organization/index.html Summary: You might thinking that this is a political article and that "DNS" is some kind of Democratic organization, but this is a network traffic mystery involving the Internet's Domain Name System. This was first reported last year (see http://ieee-security.org/Cipher/Newsbriefs//2016/news-112916.html#TrumpRussiaServer), and although it was not much noted at the time, it seems that the FBI has been looking into it. You cannot learn much from DNS traffic, and that is the only thing underlying the original reports of peculiar lookups. What is known is that a machine belonging to Alfa Bank in Russia (suspected of having ties to the Russian government), made thousands of DNS lookups to an obscure email server belonging to the Trump organization. The question is "why?" and the answer is unknown. Explanations range from "because some hacker issued fake queries in order to implicate the Trump organization" to "because there was a secret messaging application used to communicate between the two camps." The DNS lookups themselves are not even a smoking gun, but the investigation may (or may not) yield correlated information. --------------------------------------- In Memoriam: Becky Bace Obituary for Rebecca Gurley Bace Originally Published in The Birmingham News Mar. 19, 2017 http://obits.al.com/obituaries/birmingham/obituary.aspx?n=rebecca-gurley-bace-becky&pid=184565476 Summary: If you ever met Becky Bace, you'd remember her vibrant personality, and we are sad to report the passing of a longtime presence in the intrusion detection profession. She was leader of the pioneering Computer Misuse and Anomaly Detection (CMAD) Research Program at the National Security Agency from 1989 to 1995. She went on to other positions, including Los Alamos Labs, her own firm Infidel, Inc., and was a consultant for Trident Capital. http://cisr.nps.edu/jobscipher.html http://www.ds.unipi.gr/trustbus2017/; Submissions are due 3/24/17: IWSPA, 3rd ACM International Workshop on Security and Privacy Analytics, Co-located with ACM CODASPY 2017, Scottsdale, Arizona, USA; http://capex.cs.uh.edu/?q=content/international-workshop-security-and-privacy-analytics-2017 3/27/17- 3/29/17: INTRICATE-SEC, 5th International Workshop on Security Intricacies in Cyber-Physical Systems and Services, Taipei, Taiwan https://goo.gl/562zhD 3/28/17: RAID, 20th International Symposium on Research in Attacks, Intrusions and Defenses, Atlanta, GA, USA; https://www.raid2017.org/; Submissions are due 3/31/17: DSC, 2017 IEEE Conference on Dependable and Secure Computing, Taipei, Taiwan; http://dsc17.cs.nctu.edu.tw/; Submissions are due 4/ 2/17- 4/ 6/17: ASIACCS, ACM Symposium on Information, Computer and Communications Security, Abu Dhabi, United Arab Emirates; http://asiaccs2017.com/ 4/ 2/17: CPSS, 3rd ACM Cyber-Physical System Security Workshop, Abu Dhabi, UAE; http://icsd.i2r.a-star.edu.sg/cpss17/ 4/ 2/17: IoTPTS, 3rd International Workshop on IoT Privacy, Trust, and Security, Held in conjunction with the 12th ACM Symposium on Information, Computer and Communications Security (ASIACCS 2017); https://sites.google.com/site/iotpts2017/ 4/ 3/17- 4/ 7/17: WWW, WWW Security and Privacy Track, Perth, Australia; http://www.www2017.com.au/call-for-papers/security-and-privacy.php 4/ 4/17: CUING, 1st International Workshop on Criminal Use of Information Hiding, Held in conjunction with the 12th International Conference on Availability, Reliability and Security (ARES 2017), Reggio Calabria, Italy; https://www.ares-conference.eu/conference/workshops/cuing-2017/; Submissions are due 4/14/17: NSPW, New Security Paradigms Workshop, Islamorada, FL, USA; http://www.nspw.org/cfp/nspw2017-cfp.pdf; Submissions are due 4/14/17: CNS, 5th IEEE Conference on Communications and Network Security, Las Vegas, Nevada, USA; http://cns2017.ieee-cns.org/; Submissions are due 4/15/17: WCSF, 3rd IEEE International Workshop on Cloud Security and Forensics, Held in conjunction with the 16th IEEE International Conference on Trust, Security And Privacy in Computing And Communications (TrustCom2017), Sydney, Australia; https://forensicsandsecurity.com/workshop.php; Submissions are due 4/19/17: ESORICS, 22nd European Symposium on Research in Computer Security, Oslo, Norway; https://www.ntnu.edu/web/esorics2017/; Submissions are due 4/24/17- 4/26/17: WICSPIT, Workshop on Innovative CyberSecurity and Privacy for Internet of Things: Strategies, Technologies, and Implementations, Held in conjunction with the International Conference on Internet of Things, Big Data and Security (IoTBDS 2017), Porto, Portugal; http://iotbds.org/WICSPIT.aspx 4/26/17- 4/28/17: IEEE EuroSP, 2nd IEEE European Symposium on Security and Privacy, Paris, France; http://www.ieee-security.org/TC/EuroSP2017/cfp.php 5/ 1/17- 5/ 5/17: HOST, IEEE International Symposium on Hardware Oriented Security and Trust, McLean, VA, USA; http://www.hostsymposium.org 5/10/17: DASC, 15th IEEE International Conference on Dependable, Autonomic and Secure Computing Orlando, Florida, USA; http://cse.stfx.ca/~dasc2017/; Submissions are due 5/14/17- 5/17/17: WACC, International Workshop on Assured Cloud Computing and QoS aware Big Data, Held in conjunction with 17th IEEE/ACM International Symposium on Cluster, Cloud and Grid Computing (CCGRID 2017), Madrid, Spain; http://www.eubra-bigsea.eu/WACC_2017 5/15/17: PST, 15th Conference on Privacy, Security and Trust, Calgary, Alberta, Canada; http://www.ucalgary.ca/pst2017/; Submissions are due 5/19/17: ACM CCS, 24th ACM Conference on Computer and Communication Security, Dallas, TX, USA; https://www.sigsac.org/ccs/CCS2017; Submissions are due 5/21/17: GraMSec, International Workshop on Graphical Models for Security, Santa Barbara, CA, USA; http://gramsec.uni.lu; Submissions are due 5/22/17- 5/24/17: SP, 38th IEEE Symposium on Security and Privacy, San Jose, CA, USA; https://www.ieee-security.org/TC/SP2017/ 5/25/17: BioSTAR, International Workshop on Bio-inspired Security, Trust, Assurance and Resilience, Co-located with the 38th IEEE Symposium on Security and Privacy (IEEE S&P 2017), San Jose, CA, USA; http://biostar.cybersecurity.bio/ 5/25/17: WTMC, 2nd International Workshop on Traffic Measurements for Cybersecurity, Co-located with the 38th IEEE Symposium on Security and Privacy (IEEE S&P 2017), San Jose, CA, USA; http://wtmc.info 5/25/17: IWPE, 3rd International Workshop on Privacy Engineering, Co-located to IEEE Symposium on Security and Privacy (SP 2017), San Jose, CA, USA; http://ieee-security.org/TC/SPW2017/IWPE/ 5/29/17- 5/31/17: IFIPSEC, 32nd IFIP TC-11 SEC 2017 International Information Security and Privacy Conference, Rome, Italy; http://ifipsec.org/2017/ 6/ 1/17: ACSAC 2017 33rd Annual Computer Security Applications Conference, San Juan, Puerto Rico; http://www.acsac.org; Submissions are due 6/10/17: ISDDC, International Conference on Intelligent, Secure and Dependable Systems in Distributed and Cloud Environments, Vancouver, BC, Canada; http://www.scs.ryerson.ca/iwoungan/ISDDC17/; Submissions are due 6/29/17: GameSec, 8th Conference on Decision and Game Theory for Security, Vienna, Austria; http://www.gamesec-conf.org/cfp.php; Submissions are due 7/ 3/17- 7/ 5/17: IVSW, 2nd International Verification and Security Workshop, Thessaloniki, Greece; http://tima.imag.fr/conferences/ivsw/ivsw17/ 7/10/17- 7/12/17: ACNS, 15th International Conference on Applied Cryptography and Network Security, Kanazawa, Japan; https://cy2sec.comm.eng.osaka-u.ac.jp/acns2017/ 7/12/17- 7/14/17: SOUPS, 13th Symposium on Usable Privacy and Security, Santa Clara, CA, USA; https://www.usenix.org/conference/soups2017/call-for-papers 7/17/17- 7/19/17: DBSec, 31st Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, Philadelphia, PA, USA; https://dbsec2017.ittc.ku.edu/ 7/18/17- 7/20/17: WiSec, 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Boston, MA, USA; http://wisec2017.ccs.neu.edu/ 7/18/17- 7/21/17: PETS, 17th Privacy Enhancing Technologies Symposium, Minneapolis, MN, USA; https://petsymposium.org/ 7/28/17: Security and Communication Networks journal, Special Issue on Emerging and Unconventional: New Attacks and Innovative Detection Techniques; https://www.hindawi.com/journals/scn/si/761087/cfp/; Submissions are due 8/ 1/17- 8/ 4/17: WCSF, 3rd IEEE International Workshop on Cloud Security and Forensics, Held in conjunction with the 16th IEEE International Conference on Trust, Security And Privacy in Computing And Communications (TrustCom2017), Sydney, Australia; https://forensicsandsecurity.com/workshop.php 8/ 7/17- 8/10/17: DSC, IEEE Conference on Dependable and Secure Computing, Taipei, Taiwan; http://dsc17.cs.nctu.edu.tw/ 8/16/17- 8/10/17: USENIX Security, 26th USENIX Security Symposium, Vancouver, Canada; https://www.usenix.org/conference/usenixsecurity17/call-for-papers 8/21/17: GraMSec, International Workshop on Graphical Models for Security, Santa Barbara, CA, USA; http://gramsec.uni.lu 8/22/17- 8/25/17: CSF, 30th IEEE Computer Security Foundations Symposium, Co-located with CRYPTO 2017, Santa Barbara, California, USA; http://csf2017.tecnico.ulisboa.pt/ 8/28/17- 8/30/17: PST, 15th Conference on Privacy, Security and Trust, Calgary, Alberta, Canada; http://www.ucalgary.ca/pst2017/ 8/28/17- 8/31/17: TrustBus, 14th International Conference on Trust, Privacy, and Security in Digital Business, Lyon, France; http://www.ds.unipi.gr/trustbus2017/ 8/29/17- 9/ 1/17: CUING, 1st International Workshop on Criminal Use of Information Hiding, Held in conjunction with the 12th International Conference on Availability, Reliability and Security (ARES 2017), Reggio Calabria, Italy; https://www.ares-conference.eu/conference/workshops/cuing-2017/ 9/11/17- 9/15/17: ESORICS, 22nd European Symposium on Research in Computer Security, Oslo, Norway; https://www.ntnu.edu/web/esorics2017/ 9/18/17- 9/20/17: RAID, 20th International Symposium on Research in Attacks, Intrusions and Defenses, Atlanta, GA, USA; https://www.raid2017.org/ 10/ 2/17-10/ 4/17: NSPW, New Security Paradigms Workshop, Islamorada, FL, USA; http://www.nspw.org/cfp/nspw2017-cfp.pdf 10/ 9/17-10/11/17: CNS, 5th IEEE Conference on Communications and Network Security, Las Vegas, Nevada, USA; http://cns2017.ieee-cns.org/ 10/23/17-10/25/17: GameSec, 8th Conference on Decision and Game Theory for Security, Vienna, Austria; http://www.gamesec-conf.org/cfp.php 10/25/17-10/27/17: ISDDC, International Conference on Intelligent, Secure and Dependable Systems in Distributed and Cloud Environments, Vancouver, BC, Canada; http://www.scs.ryerson.ca/iwoungan/ISDDC17/ 10/30/17-11/ 3/17: ACM CCS, 24th ACM Conference on Computer and Communication Security, Dallas, TX, USA; https://www.sigsac.org/ccs/CCS2017 11/ 6/17-11/10/17: DASC, 15th IEEE International Conference on Dependable, Autonomic and Secure Computing, Orlando, Florida, USA; http://cse.stfx.ca/~dasc2017/ 12/ 4/17-12/ 8/17: ACSAC 2017 33rd Annual Computer Security Applications Conference, San Juan, Puerto Rico; http://www.acsac.org ____________________________________________________________________ Journal, Conference and Workshop Calls-for-Papers (new since Cipher E136) ___________________________________________________________________ TrustBus 2017 14th International Conference on Trust, Privacy, and Security in Digital Business, Lyon, France, August 28-31, 2017. 