Well, the lead security story has to be Twitch. In a massive hack, the company’s source code, business data, and payouts have all been released in what appears to be a very targeted hack. The hackers have labeled this as “part one”, and appears to be focused intentionally on the company’s own tools and information, not personal account information. If you’re interested in digging in more, there’s a Verge article reviewing the bad security practices that led to this, including lack of management concern, employees raising issues of security, and even not disabling previous employees accounts.
So, that discussion about disclosures: how does 48 hours sound? Another piece of legislation, titled the “Ransom Disclosure Act” proposes that number for disclosure of payments. It also requires Homeland Security to publish disclosures and make that information available to individuals.
Wondering why disclosure matters? Ars Technica is reporting of an issue with SMS routing that’s lasted five years. Revealed in a SEC disclosure, the firm responsible has released little additional information. But, with Twitch being hit… not even the biggest breach news of the week.
Oh, and the US Government is now going to sue any contractors who hide breach incidents. Under the new Civil Cyber-Fraud initiative, government contractors are accountable in civil court if they don’t report or fail to meet required cybersecurity standards. The US government is also introducing regulations for railroad and airport operators, which include naming a chief cyber official, disclosing hacks, and having recovery plans. And, the DOJ has also created a team to investigate crypto-currency related crime.
Google has announced that they are auto enrolling 150 million accounts into two factor authentication by the end of the year. It seems it does need to be forced – a report by the National Cybersecurity Alliance and CybSafe shows the disconnect between IT pros and the public. 48% of respondents have never heard of multi-factor authentication. 31% never, sometimes, or rarely patch. Only 43% create unique passwords always or every often, and only 46% even use different passwords – 20% never or rarely do. Then again, research by the Insurance Bureau of Canada report that 47% of small business respondents say they don’t allocate any money at all to cybersecurity.
And speaking of google – Forbes reporting is revealing that the US government is ordering data on anyone typing in certain search terms. These “keyword warrants” are broad requests for information on individuals looking for specific keywords looking for a subject.
Arizona has opened a new cybersecurity command center to pull together resources to manage the state government’s information security.
Expect to see more of these state level operations centers.
Twitch is an extreme case to consider – what would happen if everything about you, or your customers, was published? Remember, this is what happens if a ransomware operator releases all of a customer’s data. We have, playing out in real time, an example of that release of data. It’s happening in a very public way, and with a company that has some pretty broad recognition – and is owned by Amazon too.
This should be very relatable to customers – who, the data tells us, are going to need to be forced to security. Note that Google story – if they can force their users to multi-factor, any IT services company can too.

