Saturday, October 7, 2017

Processes & UID

'mobile' user processes (38):
- name: medialibraryd
  runtime: 25m 25s
  priority: 17
  PID: 766
  PPID: 1
  PGID: 766
  UID: 501
- name: System Status
  runtime: 25m 33
  priority: 17
  PID: 763
  PPID: 1
  PGID: 763
  UID: 501
- name: timed
  runtime: 1h 20m 47s
  priority: 17
  PID: 744
  PPID: 1
  PGID: 744
  UID: 501
- name: touchsetupd
  runtime: 1h 20m 47s
  priority: 17
  PID: 743
  PPID: 1
  PGID: 743
  UID: 501
- name: Aerogram
  runtime: 1h 21m 3s
  priority: 24
  PID: 742
  PPID: 1
  PGID: 742
  UID: 501
- name: geod
  runtime: 1h 48m 22s
  priority: 17
  PID: 727
  PPID: 1
  PGID: 727
  UID: 501
- name: assetsd
  runtime: 1h 48m 33s
  priority: 17
  PID: 726
  PPID: 1
  PGID: 726
  UID: 501
- name: CMFSyncAgent
  runtime: 1h 49m 27s
  priority: 17
  PID: 723
  PPID: 1
  PGID: 723
  UID: 501
- name: MobileGestaltHel
  runtime: 1h 49m 57s
  priority: 17
  PID: 722
  PPID: 1
  PGID: 722
  UID: 501
- name: routined
  runtime: 1h 50m 23s
  priority: 17
  PID: 721
  PPID: 1
  PGID: 721
  UID: 501
- name: Twitter
  runtime: 1h 50m 28s
  priority: 17
  PID: 720
  PPID: 1
  PGID: 720
  UID: 501
- name: mediaremoted
  runtime: 1h 50m 48s
  priority: 17
  PID: 718
  PPID: 1
  PGID: 718
  UID: 501
- name: installd
  runtime: 1h 51m 42s
  priority: 17
  PID: 709
  PPID: 1
  PGID: 709
  UID: 501
- name: xpcd
  runtime: 1h 54m 13s
  priority: 17
  PID: 706
  PPID: 1
  PGID: 706
  UID: 501
- name: accountsd
  runtime: 1h 57m 53s
  priority: 17
  PID: 702
  PPID: 1
  PGID: 702
  UID: 501
- name: lsd
  runtime: 1h 57m 54s
  priority: 17
  PID: 701
  PPID: 1
  PGID: 701
  UID: 501
- name: talkmeim
  runtime: 3h 39m 57s
  priority: 17
  PID: 669
  PPID: 1
  PGID: 669
  UID: 501
- name: itunesstored
  runtime: 3h 40m 8s
  priority: 17
  PID: 665
  PPID: 1
  PGID: 665
  UID: 501
- name: MobileSMS
  runtime: 4h 4m 31s
  priority: 17
  PID: 639
  PPID: 1
  PGID: 639
  UID: 501
- name: DuetLST
  runtime: 4h 30m 11s
  priority: 17
  PID: 614
  PPID: 1
  PGID: 614
  UID: 501
- name: librariand
  runtime: 4h 40m 56s
  priority: 17
  PID: 581
  PPID: 1
  PGID: 581
  UID: 501
- name: kbd
  runtime: 4h 41m 14s
  priority: 17
  PID: 577
  PPID: 1
  PGID: 577
  UID: 501
- name: tccd
  runtime: 4h 44m 32s
  priority: 17
  PID: 565
  PPID: 1
  PGID: 565
  UID: 501
- name: MobileMail
  runtime: 4h 44m 35s
  priority: 17
  PID: 563
  PPID: 1
  PGID: 563
  UID: 501
- name: iapd
  runtime: 9h 0m 52s
  priority: 17
  PID: 265
  PPID: 1
  PGID: 265
  UID: 501
- name: dataaccessd
  runtime: 11h 44m 59s
  priority: 17
  PID: 103
  PPID: 1
  PGID: 103
  UID: 501
- name: apsd
  runtime: 11h 45m 17s
  priority: 17
  PID: 82
  PPID: 1
  PGID: 82
  UID: 501
- name: BTServer
  runtime: 11h 45m 26s
  priority: 17
  PID: 61
  PPID: 1
  PGID: 61
  UID: 501
- name: vmd
  runtime: 11h 45m 26s
  priority: 17
  PID: 59
  PPID: 1
  PGID: 59
  UID: 501
- name: imagent
  runtime: 11h 45m 26s
  priority: 17
  PID: 57
  PPID: 1
  PGID: 57
  UID: 501
- name: identityservices
  runtime: 11h 45m 26s
  priority: 17
  PID: 55
  PPID: 1
  PGID: 55
  UID: 501
- name: ubd
  runtime: 11h 45m 26s
  priority: 17
  PID: 49
  PPID: 1
  PGID: 49
  UID: 501
- name: mediaserverd
  runtime: 11h 45m 26s
  priority: 17
  PID: 46
  PPID: 1
  PGID: 46
  UID: 501
- name: aggregated
  runtime: 11h 45m 27s
  priority: 17
  PID: 38
  PPID: 1
  PGID: 38
  UID: 501
- name: SpringBoard
  runtime: 11h 45m 27s
  priority: 17
  PID: 34
  PPID: 1
  PGID: 34
  UID: 501
- name: fairplayd.H1
  runtime: 11h 45m 27s
  priority: 17
  PID: 31
  PPID: 1
  PGID: 31
  UID: 501
- name: backboardd
  runtime: 11h 45m 27s
  priority: 24
  PID: 28
  PPID: 1
  PGID: 28
  UID: 501
- name: iaptransportd
  runtime: 11h 45m 27s
  priority: 17
  PID: 24
  PPID: 1
  PGID: 24
  UID: 501

'root' user processes (18):
- name: CloudKeychainPro
  runtime: 54m 15s
  priority: 17
  PID: 752
  PPID: 1
  PGID: 752
  UID: 0
- name: keybagd
  runtime: 3h 39m 40s
  priority: 17
  PID: 674
  PPID: 1
  PGID: 674
  UID: 0
- name: sandboxd
  runtime: 3h 39m 54s
  priority: 17
  PID: 671
  PPID: 1
  PGID: 671
  UID: 0
- name: networkd_privile
  runtime: 4h 39m 10s
  priority: 17
  PID: 587
  PPID: 1
  PGID: 587
  UID: 0
- name: mobileassetd
  runtime: 11h 44m 32s
  priority: 24
  PID: 119
  PPID: 1
  PGID: 119
  UID: 0
- name: filecoordination
  runtime: 11h 45m 6s
  priority: 17
  PID: 91
  PPID: 1
  PGID: 91
  UID: 0
- name: distnoted
  runtime: 11h 45m 20s
  priority: 17
  PID: 77
  PPID: 1
  PGID: 77
  UID: 0
- name: notifyd
  runtime: 11h 45m 25s
  priority: 17
  PID: 71
  PPID: 1
  PGID: 71
  UID: 0
- name: fseventsd
  runtime: 11h 45m 26s
  priority: 50
  PID: 63
  PPID: 1
  PGID: 63
  UID: 0
- name: configd
  runtime: 11h 45m 26s
  priority: 24
  PID: 56
  PPID: 1
  PGID: 56
  UID: 0
- name: locationd
  runtime: 11h 45m 26s
  priority: 17
  PID: 53
  PPID: 1
  PGID: 53
  UID: 0
- name: lockdownd
  runtime: 11h 45m 26s
  priority: 24
  PID: 52
  PPID: 1
  PGID: 52
  UID: 0
- name: powerd
  runtime: 11h 45m 26s
  priority: 17
  PID: 47
  PPID: 1
  PGID: 47
  UID: 0
- name: syslogd
  runtime: 11h 45m 26s
  priority: 24
  PID: 42
  PPID: 1
  PGID: 42
  UID: 0
- name: wifid
  runtime: 11h 45m 27s
  priority: 24
  PID: 15
  PPID: 1
  PGID: 15
  UID: 0
- name: UserEventAgent
  runtime: 11h 45m 27s
  priority: 24
  PID: 14
  PPID: 1
  PGID: 14
  UID: 0
- name: launchd
  runtime: 11h 45m 35s
  priority: 24
  PID: 1
  PPID: 0
  PGID: 1
  UID: 0
- name: kernel_task
  runtime: 11h 45m 35s
  priority: 21
  PID: 0
  PPID: 0
  PGID: 0
  UID: 0

'_mdnsresponder' user processes (1):
- name: mDNSResponder
  runtime: 11h 45m 27s
  priority: 17
  PID: 33
  PPID: 1
  PGID: 33
  UID: 65

'_networkd' user processes (1):
- name: networkd
  runtime: 11h 45m 19s
  priority: 17
  PID: 79
  PPID: 1
  PGID: 79
  UID: 24

'_securityd' user processes (1):
- name: securityd
  runtime: 1h 57m 50s
  priority: 17
  PID: 703
  PPID: 1
  PGID: 703
  UID: 64

'_wireless' user processes (1):
- name: CommCenter
  runtime: 11h 45m 26s
  priority: 24
  PID: 67
  PPID: 1
  PGID: 67
  UID: 25



Elyssa D. D. Durant 
Research &  Policy Analyst
 '

Friday, October 6, 2017

Russian Hackers Pilfered Data from NSA Contractor’s Home Computer: Report | Infosec News Ireland

Russian Hackers Pilfered Data from NSA Contractor's Home Computer: Report | Infosec News Ireland



Russian Hackers Pilfered Data from NSA Contractor's Home Computer: Report

Classified information and hacking tools from the US National Security Agency landed in the hands of Russian cyberspies, according to a Wall Street Journal report.

Turns out the National Security Agency (NSA) may have suffered yet another data breach: in 2015, Russian state hackers stole classified cyberattack and defense tools and information off of the home computer of an NSA contractor, according to a Wall Street Journal report today.

The hack reportedly occurred via Kaspersky Lab antivirus software on the contractor's home computer, where the AV flagged the NSA cyberspying tools and code. The breach wasn't detected until spring of 2016, and wasn't known publicly until the WSJ report published today.

Just how the NSA contractor's Kaspersky Lab software was apparently abused, exploited – or not – is under debate by experts: it could be a case of the application's detection of the tools on the contractor's system inadvertently landing in the wrong hands, they say, or the software could have been hijacked and hacked by the attackers during a software update, for instance.

The WSJ report meanwhile appears to shed light on what ultimately may have led the US government's recent ban of the Russian security vendor's software. The Trump administration ordered all federal agencies to remove Kaspersky Lab's products and services from their systems, citing concerns of a link between the company and the Russian government, which is already under fire for its role in meddling with the 2016 US presidential election.

The unnamed NSA contractor reportedly moved the data to his home to work after-hours, even though he was aware that removing classified information without approval is against NSA policy and potentially a criminal offense, the report said. The case is under investigation by the federal government. NSA employees and contractors have always been prohibited from using Kaspersky Lab software at work, and the NSA prior to this incident had recommended they not use it at home, either, the report said.

This marks the third case of an NSA contractor exposing or leaking classified information: the first being of course Edward Snowden, whose infamous theft and leak to journalists of NSA files in 2013 served as a wakeup call for the insider threat, and the second, the recent arrest of contractor Harold Martin who had horded more than 50 terabytes of NSA documents for 20 years in his home and the trunk of his car.

Whether this latest NSA contractor leak leads directly to the mysterious Shadow Brokers group that since 2016 has been leaking and later offering for sale online a trove of NSA hacking tools and exploits is unclear at this point, but some security experts say this could be the long-awaited link to Shadow Brokers. "It seems to point in that direction," John Bambenek, threat systems manager at Fidelis Cybersecurity, says of today's report.

Meantime, just how Kaspersky Lab's AV software fits into the case is unclear from the report. According to the WSJ, the software may have detected some of the NSA files as suspicious code, somehow cluing Russian hackers into the machine full of NSA classified information. According to the report, "But how the antivirus system made that determination is unclear, such as whether Kaspersky technicians programed the software to look for specific parameters that indicated NSA material. Also unclear is whether Kaspersky employees alerted the Russian government to the finding."

Antivirus and other security software routinely vet newly detected, suspicious-looking samples to their malware databases and other threat intelligence resources, so the Russian threat actors may have either intercepted that traffic, or even spotted it in another intelligence-sharing forum, security experts told Dark Reading. "The reality is they [antivirus programs] all do that," Bambenek says.

He says he's even seen classified documents posted on VirusTotal, the online malware-checking tool used by researchers and even victim organizations to crowdsource malware finds. And threat intel-sharing is common practice among security researchers as well, he says.

"Malware systems that make use of the cloud often send your documents upstream for analysis," Gary McGraw, vice president of security technology at Synopsys, explains.

Kaspersky Lab researchers have worked closely with Interpol on cybercrime investigations, and the firm has outed multiple Russian advanced persistent threat actors, or nation-state groups, which confounds security experts analyzing the feds' suspicions of Russian state involvement with Kaspersky Lab.

"I've worked with Kaspersky Lab for a long time, fighting antivirus back in the day, and they've always been stand-up guys who want to fight the good fight against malware actors," says Joe Stewart, formerly the director of malware research at Secureworks and now a security researcher with Cymmetria.

One possible explanation for the NSA contractor's machine compromise, Stewart notes, is a hack of the AV software. "Any time you've got a situation where software running on a machine has an update process, it can be compromised," Stewart says.

Several major AV products, including Kaspersky Lab's, have been outed with security vulnerabilities by researchers over the past few years.

Fidelis' Bambenek says there's always a chance a mole resides in any security software firm or organization. "That's how espionage is done," he says. He says he has no firsthand knowledge of that being the case at Kaspersky Lab, and the argument of collusion between the firm and the Russian government so far remains as "weak tea," he says.

Other security experts see subterfuge. Dan Guido, co-founder and CEO of red-team and security research firm Trail of Bits, said via Twitter: "There are only 2 good answers: Either the Russian gov rides on KAV infrastructure globally or Kaspersky helps them do it one at a time."

Kaspersky Lab denies any wrongdoing and shot down the WSJ report: "Kaspersky Lab has not been provided any evidence substantiating the company's involvement in the alleged incident reported by the Wall Street Journal on October 5, 2017, and it is unfortunate that news coverage of unproven claims continue to perpetuate accusations about the company. As a private company, Kaspersky Lab does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight," the company said in a statement.

"The company actively detects and mitigates malware infections, regardless of the source," and "Kaspersky Lab products adhere to the cybersecurity industry's strict standards and have similar levels of access and privileges to the systems they protect as any other popular security vendor in the U.S. and around the world," the company said.

Insider Problems

Bambenek says the NSA contractor moving classified agency data onto his home laptop or computer should never have happened in the first place. "The problem is the NSA is not following its own rules," he says. "Shouldn't there be technical controls controlling [and detecting] when top-secret stuff goes out of the NSA building? This just keeps happening there. I'm more concerned about a spy agency consistently have a problem keeping its secrets."

There's a fine line of what constitutes legitimate and acceptable cyber espionage. Nations spy on other nations: that's a given. And sometimes, security software firms find themselves inadvertently in the crosshairs, experts point out. And it's likely the NSA could be using antivirus software similarly to spy on other nations, they argue.

Even so, the US federal government's ban on Kaspersky Lab products comes amid a backdrop of renewed distrust in the Russian government in the wake of the intelligence community's findings of election-meddling, as well as investigations into possible collusion between the Trump campaign and Russian operatives.

Jim Christy, former director of futures exploration at the federal government's Defense Cyber Crime Center (DC3), notes that the feds are traditionally "risk-averse," so the ban of Kaspersky Lab software should come as no surprise.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry's most knowledgeable IT security experts. Check out the INsecurity agenda here.

Related Content:

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

More Insights



^ed 

Blue Cross CEOs gorge on profits from premiums | KnoxViews

 by Elyssa Durant for Knox News

To learn that the CEO of Blue Cross Tennessee received a $2 million bonus is really not news at all. It is merely more of the same, and exactly what we can expect if the Healthcare Industry is expected to "curb" their spending. It just ain't gonna happen.

This is just goes to demonstrate that we MUST have immediate intervention, regulation, oversight and accountability over the Healthcare Marketplace.

I did not need another reason to demonstrate the need for immediate intervention, however for those who do, please read the excerpt below from KnoxViews:

"Blue Cross CEOs gorge on profits from premiums."

"The chief executive officer of Blue Cross of Tennessee got a big salary boost to over $2 million this year. Searches for "salary president ceo blue cross [statename]" will get you the figures for the rest of the states. To keep it simple, though, let's just assume that the 50 CEOs of each Blue Cross operation in each of the 50 states makes roughly what the top guy in Tennessee gets, Tennessee not being exactly one of the wealthiest states. That means we're looking at well over $100 million of our health insurance premiums poured into the homes, yachts, and kids' private schools of a tiny elite instead of going into the provision of health care for Americans." -Vigil Proudfoot, KnoxViews available: (link...)

Obama's plan to come to the table with the Healthcare Industry is being passed off as Healthcare "reform" is a farce. The concept of self-regulation as the newest chapter in healthcare reform effort is a joke, and my concerns continue to grow with each passing day. Since that compromise was made, have any of us seen any movement towards reform or seen our healthcare dollars get more bang for the buck?

Asking or expecting the health industry to reduce costs through self-regulation without accountability is simply ridiculous. Especially when we see reports such as these that show a CEO salary of several million dollars.

Health care is already completely self-regulated and controlled. A person does not have free choice when choosing a provider. Due to an unholy alliance of provider networks, insurance underwriters, pharmaceutical conglomerates and private for profit hospital corporations such as HCA.

By negotiating with providers and developing one-size-fits-all prescription formularies and treatment protocols, we remove the ability for the consumer to make independent informed decisions about the value of various treatment options.

We rely upon one the ratings of physicians who have self-interest in controlling access and information to accurate information through their reliance upon Certification and Licensing Boards. By limiting access into the profession, health care costs are inflated and it is near impossible for the consumer to determine the fair value of a health care service.

Second, the consumer is far removed from the negotiating process, so we do not have a good sense of the fair, free market value of one particular service in comparison to another. All you need to do is look at any EOB (explanation of benefits) report for your last trip to the hospital.

Billing codes are used and assigned through various service departments and the insurance carrier then decides which services are covered and at what rate. They use the terms like "Reasonable and Customary Rates" and then choose to pay 80% of that amount. Therefore, by definition, that 20% must be built in to the billing rates to adjust for the actual (and expected) rate of reimbursement.

Such complicated billing procedures and methods are so complicated and technical that the end recipient of services (the consumer) really has no idea if an X-ray costs $90 or $73. Add into that a separate fee for the radiologist, and sometimes a charge just to use the facility, and even smart people find it difficult to understand.

The bills are then processed by an insurance adjuster who must determine primary and secondary (supplemental) plans and determine who is responsible for what, the end cost and intricate design is truly "priceless."

Good luck to those people who actually purchased supplemental plans they saw advertised on TV, you have been duped. Giving people (especially the infirm and the elderly) a false sense of security is unfair and unjust.

Without regulation, intervention and enforcement, many people will continue to believe they are prepared and protected from that ultimate for "just in case" scenario that results in major, catastrophic medical loss.

The administrative cost alone on the part of the "Responsible Party" is probably more costly than the initial service they received at whatever hospital for whatever condition.

You cannot apply basic economic theory and free market principles to health care. Health care is fundamentally different and should be considered a public good.

We cannot believe or expect health insurance conglomerates will control their own spending and free from government intervention. We need to do something NOW!

"You may not care how much I know, but you don't know how much I care!"

Elyssa D. Durant 

Thursday, October 5, 2017

I'm tired. But not too tired to stop fighting.

DailyDDoSe October 5, 2017


I've never been so involved in politics. Not when I was a lobbyist, not when I was a policy advisor to the Governor, not when I was on the Transition Team or any of the Task Forces working with the Department of Mental Health, TCCY, DCS to respond to crises that came about when they cut 400,000 off Medicaid, or misprinted the IDs for Medicare Part D creating mass chaos and confusion. 


Once the "transition" was done (it was a 6 month contract) I trusted that policies would be implemented effectively and felt confident the Obama admin had everything under control. 


Trump doesn't talk about healthcare because he doesn't bother to read the bills and if he does, he is either lying or lacks the intelligence to understand what they say. 


So yeah, I'm back. And I'm mad as hell. I never felt we were in imminent danger before. So if you are tired of seeing my posts simply unfollow. I get paid per word to write and not once have I been accused of posting Fake News. 


I'm exhausted, I'm tired and I'm fed up, but I'm not too tired to stop fighting. 


Xoxo 

Chilly 🐧

--
Elyssa Durant, Ed.M.
Nashville, Tennessee



"You may not care how much I know, but you don't know how much I care."



______________________________

Monday, October 2, 2017

SAY IT, DONALD! Domestic Homegrown White Terrorist

Last night in America we had the worst mass shooting in history. At least 50 people were shot dead. 


If the shooter had been Muslim, Trump would have cried terrorism from the rooftops. I suppose this White Homegrown Domestic Terrorist was a "very fine person" and he's just waiting for all the facts so he can distort them to fit his

political agenda. 


Trump offers his warm condolences. Your son or daughter has just been murdered by a white terrorist but Donald trump refuses to condemn the act but sends warm condolences.


Gun. Control. Now.

--
Elyssa Durant, Ed.M.
Nashville, Tennessee



"You may not care how much I know, but you don't know how much I care."



______________________________