Amazon, Facebook, ICE, and the FBI have access to a private intelligence-sharing network operated by Seattle police

Seattle Shield requests suspicious activity reports from companies, which are then circulated with members as part of surveillance apparatus

Prism

I attended the AITP Chicago Security SIG tonight at RSM and left with one clear takeaway: a $200 device called Flipper Zero can clone your building access badge and bypass the physical security your organization worked so hard to set up. FBI Chicago Intelligence Analysts and an InfraGard board member explained how these devices work and where organizations are vulnerable. The room was full of security professionals, many of whom had that familiar look, realizing a threat they thought was unlikely is actually much closer to home.
Here are a few key points from tonight:
・ You can buy Flipper Zero on Amazon, and teenagers are posting demo videos on YouTube. If your physical security plan assumes attackers need special equipment, that assumption is no longer true.
・ Most enterprise security programs barely address RF-based attacks on access control systems. We invest heavily in endpoint protection and network monitoring, but the badge reader by the server room often gets overlooked.
・ Mitigation is practical. Encrypted credentials and multi-factor physical access are real solutions. Most organizations just haven’t made them a priority because the threat seemed remote.

If you’re a CISO or CIO and haven’t reviewed your physical access controls for RF-based attacks, now is a good time to add it to your to-do list.
Thank you to AITP Chicago, the FBI, InfraGard, and RSM for a great discussion.

https://aitpchicago.com/event-6680905
#Cybersecurity #PhysicalSecurity #InfraGard #security #privacy #cloud #infosec #flipper0

The first time I posted this it was made in eligible for recommendation

YouTube
Anyone else in #infragard get a notice to apply for and active your GETS or WPS?

Last time I got this was just as the initial COVID lockdowns started
😬
#InfraGard hotbed | Protecting Vital US Refineries | Have they overreached?
#infragard bends over backwards to protect vital infrastructure
just to let you guys know, i'm not ever joining #infragard ever. infragard for starters, is now using cloudflare for its products. now I guess that's not a sin on its own, I have used cloudflare, and use it for workers applications.
but as we know, cloudflare ended up in a data breech. now for someone like me, that's fine. I know what I 'mdoing, I use 2factor authentication, i'm pretty good...
but for infragard? yeah, that's...pretty fucking stupid, because they want their own information sharing network.
again, my website is just want average Joe website.
it can withstand a couple hours of outage.]
but infragard absa fucking lutely cannot take a hit, because this isn't some average Joe website, it's an entire threat assessment #threat information sharing network.
they need absolute uptime.
second, I don't know if you're aware, but infragard was actually using #microsoft #windows server 2012 in the passed. keep in mind, this isn't supported anymore. in fact, I have to bet they're still using it today.
just hiding it to make us not think they're using it by putting it behind cloudflare.
and also, they're using a service called id.me which had a major unauthorized access incedent back in 2018.
o and infragard had a hole registration fuckin breech which involved a user called USDOD registering as a CEO with no legal verification.
if I was running infragard, I'd do things a lot differently.
first off, maybe run some actual fucking hardware, I don't know? maybe run some new up to date shit? sounds like a great idea, right? it's never been done before, it's absolutely amazing right?
...no!
it can be done, and I don't know why it hasn't.
but second, i'd use PIVs, not some email/and/or password. in fact, if you are working for the military you must use a PIV/CAC to login. it's mandatory.
also, I wouldn't run the application online. i'd have them vetted at a local FBI office and/or in a friendly country the US partners with.
this will be a lot more secure than vetting online which clearly didn't work last time.
so really this information sharing act congress had was basically useless on the point it was not secure.
@kkarhan #infosec #opsec #cybersecurity

Grateful to join today’s InfraGard Chicago Members Alliance chapter meeting at the iconic Old Chicago Post Office 🏛️

A fascinating and timely session led by the FBI – Federal Bureau of Investigation on North Korean 🇰🇵 threat actors — full of actionable intelligence and insight.

All that and more information from:
🔹 CPIC (Chicago Police Department’s Crime Prevention & Information Center)
🔹 CISA (Cybersecurity and Infrastructure Security Agency)
🔹 John Barker, Esq., AIGP, CCEP, CHPC, CHRC, CHC of TCLF

It is always valuable to collaborate across agencies and sectors to strengthen public-private security partnerships.

More on InfraGard Chicago:
https://chicagoinfragard.org

#InfraGardChicago #InfraGard #NorthKorea #CyberThreats #FBI #CISA #ChicagoPD #CPIC #PTPChicago #Chicago #Cybersecurity

Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach – Krebs on Security