About Me

I'm a designer, a writer, and an analyst.

I like maps. I like pictures. I like to figure out how things work.

Carnot Systems
Contact

richarduwheeler
at
gmail_dot_com

Social Networking Profiles
Twitter
Danger Room
Truman National Security Project
Wednesday
Sep212011

I've started a new adventure: a MFA program in Design and Media Arts at UCLA!

After nearly four interesting and fruitful years at Esri, I have decided to spend a little time back in academia in UCLA's Design | Media Arts Department. I'm pursuing a Master's in Fine Arts degree, and I'm going to be studying how design and technology can interest to create both fine art and design solutions to a a range of real-world challenges.

Check this space for more work as it develops.

Monday
Sep192011

"How to Talk Like a Pirate … in His Native Somali" on Wired's Danger Room

Sept. 19 is International Talk Like A Pirate Day. For most would-be buccaneers, this is an opportunity to drink grog and try out their best Captain Jack Sparrow impersonations. Danger Room certainly does not discourage this kind of behavior.

At the same time, piracy is not just a thing of the past, but rather a real-world problem plaguing the some of the most dangerous areas of the world today. And so with this in mind but also in the spirit of International Talk Like A Pirate Day, Danger Room would like to offer this guide to talking like a real pirate — as in, the one of the guys hijacking ships in the Horn of Africa region today. It’s the first in what may become a series of ITLAPD features.

Read the full post at Danger Room.

Monday
Aug012011

"Here’s How U.S. Spies Will Find You Through Your Pics" on Wired's Danger Room

Iarpa, the intelligence community’s way-out research shop, wants to know where you took that vacation picture over the Fourth of July. It wants to know where you took that snapshot with your friends when you were at that New Year’s Eve party. Oh yeah, and if you happen to be a terrorist and you took a photo with some of your buddies while prepping for a raid, the agency definitely wants to know where you took that picture — and it’s looking for ideas to help figure it out.

Read the full post at Danger Room.

Saturday
Jul022011

"Gone (spear)-phishing..."

If you’re a United States military service member — or maybe even if you just follow defense news — get ready to be spear-phished. 

Again.

On June 27 Gannett Government Media — a subsidiary of media giant Gannett that publishes a range of defense and intelligence focused publications including Army, Air Force, Navy, and Marine Corps “Times”, the Armed Forces Journal, and Defense News — announced that on June 7 it had suffered a cyber attack where information on some users had been accessed, including “first and last name, userID, password, email address, the internal number we assigned to the account, and, if provided, ZIP code, duty status, paygrade, and branch of service.”

In some ways the Gannett attack is just the latest in a recent rash of intrusions, including:

In each of these cases, and in previous ones, security experts warned of spear-phishing in their wake. Spear-phishing is the computer security term for targeted phishing attacks. “Phishing attacks work by the scam artist sending ‘spoofed’ emails that appear to come from a legitimate website that you have online dealings with such as a bank, credit card company or ISP — any site which requires users to have a personal identity or account. The email may ask you to reply with your account details in order to ‘update security’ or for some other reason.” Unlike traditional phishing attacks, which are usually blasted out with little personalization, spear-phishing is customized to the target, often containing personal information and other details that might increase the target’s willingness to trust the authenticity of the sender and then usually either click through to a website that will download malicious code onto the users machine or download a file containing malicious code.

But what makes the Gannett attack different is the fact that it was targeted at individuals in the military (although the same could be said of more than a few of the users of the PlayStation Network). Although not all readers of Gannett Government Media’s publications are military service members, many are, and their ZIP code, duty status, paygrade and branch of service information in Gannett’s database represents a treasure-trove for potential spear-phishers.

Less than a month ago, Google uncovered a spear-phishing attack directed against personal accounts of “senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists.” While this attack specifically targeted senior level officials, previous attacks directed at military personal have not necessarily been segregated by paygrade. And one of the lessons of the Bradley Manning/Wikileaks incident is that sometimes an E-4 can have access to more information than an O-4 — and maybe give less thought to how he or she uses it.

The March attack on RSA Security, a leading security firm that supplies government, military and defense contractor organizations with authentication tools, led to spear-phishing attacks on defense contractors Lockheed Martin and L-3 Communications less than a month later. By waiting 20 days to release news of the attack on their systems, Gannett has given would-be attackers plenty of time to prepare a similar assault. Sony has already taken criticism from private sector security experts and from Congressional committees for its lag in releasing news of the PlayStation Network breach, and Gannett may come under similar criticism from the same corners. But another question that comes out of this incident is if, and how, businesses and organizations that serve military service members should protect user data, and if there are any additional precautions that they should take with this data.

The US Department of Defense has struggled in the past few years to cope with the rapidly changing pace of information technology, stumbling over issues as varied as social networking to thumb drives as it tries to balance the needs of its service members to stay connected in a digital world against the threat of attacks from both cyber criminals and cyber warriors. And while it can to some extent control what happens on DoD systems, the fact is that with so many service members deployed so often for so long, there is perhaps a greater threat in the vulnerabilities within the many commercial web services that services members use every day to stay connected to the world outside of the war zone. And while the government and private sector often come together to encourage best practices in coding web sites — for example the recent joint project of the Department of Homeland Security, the MITRE corporation, and the SANS Institute to identify the “…top 25 technical software problems that hackers exploit…” — there is still a long way to go in creating best practices for what user can should be stored, and how, and for how long. And while the government may not want to get involved in what seems like a private sector problem, unless there is a discussion about how to protect the identities and personal information of service members they are likely to be targeted for more frequent and more sophisticated attacks.

Again.

Friday
May062011

"Did Two Profs Find Osama From Space? Nope, Sorry." on Wired's Danger Room

Locating Osama bin Laden took years of painstaking intelligence collection and analysis. And despite what you see on 24, there is no magic. Each piece of the puzzle had to be fitted together over time, something that doesn’t happen easily or automatically — especially when the intelligence is used to back a decision send people in on the ground instead of dropping a bomb or firing a cruise missile.

Read the full post at Danger Room.