<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.tvtechnology.com/feeds/tag/hacks" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Tv Technology in Hacks ]]></title>
                <link>https://www.tvtechnology.com/tag/hacks</link>
        <description><![CDATA[ All the latest hacks content from the Tv Technology team ]]></description>
                                    <lastBuildDate>Tue, 17 Apr 2018 16:18:36 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ IoT Has Security Implications for Connected Cars ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/iot-has-security-implications-for-connected-cars</link>
                                                                            <description>
                            <![CDATA[ A car is not just a car; in fact it’s a computer that carries you places. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mhNDVNgLxPDtiS9qHCKSDV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BdNkbtHfUc79fktFneK6Hm-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Apr 2018 16:18:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Paul Kaminski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/BdNkbtHfUc79fktFneK6Hm-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BdNkbtHfUc79fktFneK6Hm-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>LAS VEGAS--</strong>At NAB Show 2018, there was plenty of talk about data, connected cars, how to use the data generated and how the data generated needs to be protected. With the proliferation of the Internet of Things (IOT), that is no small task. A Broadcast Engineering and Information Technology Conference presentation, “Hacking Everything: The Dark Side of the Internet” provided some perspective on that task.</p><p>IBM security architect Jeff Crume says “with IOT, everything is a computer. A car is not just a car; in fact it’s a computer that carries you places.” That mobile computer (a/k/a “connected car”) contains data on listening, location, and a portal to control vehicle systems. “We have cars on the road today that have twice the amount of code in them, that are in (computer) operating systems.” He raised another point about information security: “All computers can be hacked. If they’re operational, and you give someone enough time, there will be a way to break into it (the computer or device).”</p><p><strong>[Read:<a href="https://www.tvtechnology.com/news/akamai-rise-of-iot-devices-causes-some-security-concerns"> Akamai: Rise Of IoT Devices Causes Some Security Concerns</a>]</strong></p><p>As an example, he mentioned how connected DVR, players and other devices like pacemakers, insulin pumps, even airplanes have had the potential to be hacked. “The way you go in and make changes to these devices, and they have to be changed over time, is through a wireless connection. That means the “good guys” can install patches wirelessly and there remains the potential that the “bad guys” can install patches wirelessly as well, and what they would patch with is not the same thing.”</p><p>Crume said “I’m not saying this to be an alarmist; I say this so we get people’s attention and will start working on the problem.”</p><p><em>This article originally appeared in Radio World. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 5 Cybersecurity Tips for Broadcasting ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/show-news/5-cybersecurity-tips-for-broadcasting</link>
                                                                            <description>
                            <![CDATA[ 5 Cybersecurity Tips for Broadcasting ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3t9f4cjRgbKsGSr7cq1dR1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Mar 2018 21:07:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Leslie Ellis ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mLYrNNmya9GwTJahrM3vDM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Here’s another example of the blurring boundaries between “enterprise IT” functions and broadcast engineering: Security. Not so long ago, the IT side of the typical TV broadcaster handled Internet-facing security necessities, like email and firewalls, while the engineering side shored up distribution-related security, usually over dedicated links. Those links were plumbed in Internet Protocol (IP) but didn’t traverse the “big Internet,” so they were, in essence, cordoned off.</p><p>These days, securing the attack surfaces of broadcast and media providers is necessarily a collaboration between IT and engineering, increasingly buttressed by top-down mandates to do whatever it takes to keep the bad guys off the digital premises. Just ask TV5Monde, in France, which suffered a massive hack in April of 2015 that took down 12 of its 12 channels overnight. Like so many hacks, the bad guys had gained entry a few months earlier, maneuvering in the background to find the weak spots.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TV6AfRB8ANP7pzno3mwZf8" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/TV6AfRB8ANP7pzno3mwZf8.jpg" mos="https://cdn.mos.cms.futurecdn.net/TV6AfRB8ANP7pzno3mwZf8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>“The real-time nature of broadcast television doesn’t lend itself well to today’s time-to-detect metrics,” which can average 100 days, said Michael Korten, cyber security practice leader for Cisco. “Everyone knows the stresses that come from ads not airing, regardless of the reason.” To use a worst-case example, Super Bowl ads cost around $170,000 per second.</p><p>Korten’s group, and in particular Cisco’s Talos division –a team of nearly 300 cyber security experts– live for this stuff. They are scheduled to deliver a full readout of the latest trends during the 2018 NAB Show in Las Vegas. This will happen in the Connected Media IP Theater (which is in the South Hall, Upper Level of LVCC) on Monday, April 9, from noon to 1 p.m. They deliberately won’t compile their report until much closer to the date, so as to capture what happens between now and then. But here’s a short list of best practices and general observations they’ll likely cover:</p><p><strong><strong>1.</strong> You can’t protect what you can’t see –visibility is job No. 1.</strong></p><p> The prevailing wisdom over the last two or so decades was to buy hardware to secure different types of “perimeters” –the so-called “see a problem, buy a box” solution. Each hole gets plugged with a new thumb, which is fine, until you run out of thumbs. Plus, broadcast and media companies typically average 40 to 50 individual security products. But if the firewall can’t “see” the web security product –and so on down the chain– the entirety of the threat surface can’t easily be visualized, let alone pre-emptively protected.</p><p><strong><strong>2.</strong> Add “time-to-detect” to your vital metrics.</strong></p><p> According to the Talos folks, the average time-to-detect for enterprise companies (meaning beyond the media/broadcast sector) is 100 days. That’s a little over three months! How to get that vital metric down from months to hours is one of the things they’ll explain during the NAB keynote.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SS4pWCxmPziVv4qVHL7397" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/SS4pWCxmPziVv4qVHL7397.png" mos="https://cdn.mos.cms.futurecdn.net/SS4pWCxmPziVv4qVHL7397.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><strong><strong>3.</strong> Know your attack entrances (which are anywhere there are end points).</strong></p><p> E-mail is a threat surface for its potential to disseminate malicious links. Web searches can be a threat surface because of rogue DNS addresses that redirect to unsafe places. Memory sticks, remote and unsecured (non-VPN) network access, cloud handoff points, connected devices, orphaned or neglected websites –all need to be sussed out, continuously.</p><p><strong>4. Attacks increase with each new innovation.</strong></p><p> Whether it’s a new cloud platform, mobile offering or device, if it’s new, digital and “on-net” from production to distribution, it’s probably already being deconstructed somewhere for undesired access. Innovation cuts both ways –the intended uses and the unintended consequences. (This is why security people constantly talk about how security needs to be considered from the get-go of any new product or service and not bolted on at the end.)</p><p><strong><strong>5.</strong> Have a “before, during and after” plan, and check it frequently. </strong></p><p>Improved visibility across all potential threat surfaces is step one; gaining control after a breach is step two. “The first thing people want to know, after a breach, is scope –can we contain it?” said Cisco’s Korten. “The second thing they want to know is: how bad is it? How much damage, what does remediation look like?” That’s why it’s a good idea to know what levers to pull once the alarms have sounded. (Sometimes, it’s a matter of even having levers to pull.) That means a security blueprint with perimeter detection and a “cloud firewall” designed for real-time threat management and automation. Overall mission: Stay ahead of the hack.</p><p>The grim reality about broadcast TV and security is this: Attackers have unlimited opportunities to get where they want to go. They’ll keep trying and trying and trying. We’re likely see more evidence of this, even in the short run-up to the 2018 NAB Show. If this is a topic near and dear to your day-to-day, it might make sense to check out the Talos presentation and the rest of its security portfolio while you’re in Vegas.</p><p><em>This is the third in a six-part blog series preceding the 2018 NAB Show. <a href="https://www.tvtechnology.com/the-nab-2018-agenda-series" data-original-url="https://www.tvtechnology.com/show-news/the-nab-2018-agenda-series">Click here to read more</a> about what broadcasters will be talking about at this year's show. </em></p><p><em>About the Author:</em> Leslie Ellis is a respected “technology translator,” known in cable and telecom circles for her award-winning, 20+ year “Translation Please” column in Multichannel News. She took on this Cisco-sponsored pre-NAB series to point out common and frustrating obstacles, for anyone on the sliding transition toward “being more Internet-like.” It is less of a comprehensive representation of available options and more a glimpse into what’s worrisome, on a day-to-day basis for engineers and IT people who work in media and entertainment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Preparing for the Coming Hacks ]]></title>
                                                                                                                                                                                                <link>https://www.tvtechnology.com/news/preparing-for-the-coming-hacks</link>
                                                                            <description>
                            <![CDATA[ In July, HBO’s media content library was hacked when 1.5 TB of data was illegally accessed and downloaded, including unaired episodes of “Ballers,” “Barry,” “Insecure,” and “Room 104,” plus a script for an unaired episode of “Game of Thrones.” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2DUksqfqdm7bAPEhgScM4E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Dec 2017 15:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Careless ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/bn83ZVLW852QhJFSyXeFs7.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>OTTAWA—</strong>In July, HBO’s media content library was hacked when 1.5 TB of data was illegally accessed and downloaded, including unaired episodes of “Ballers,” “Barry,” “Insecure,” and “Room 104,” plus a script for an unaired episode of “Game of Thrones.” These were later made available on the apparently hacker-run website Winter-leak.com, (the site is currently inaccessible but media coverage is available at winter-leak.ml). The result: HBO’s expensively-produced premium content was online for anyone to see for free.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SH2boBxLLYMwP79hFtcFjc" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc.png" mos="https://cdn.mos.cms.futurecdn.net/SH2boBxLLYMwP79hFtcFjc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>An Akamai Security Operations Center</em></p><p>HBO is just the latest victim of unauthorized entry into its video operations. In April of 2015, hackers claiming allegiance to the Islamic State, (and now potentially believed to be Russian), knocked French-language broadcaster Canal Plus off the air for the better part of a day; in March, 2013, North Korea posed a series of cyber-attacks on South Korea inflicting damage on three major banks and two broadcasters. “The broadcasters were not affected on-air; however, their business IT infrastructure was paralyzed,” according to the white paper “Cyber Security Services for Broadcasters,” by Obor Digital, an Orlando, Fla.-based provider of cyber security solutions for broadcasters.</p><p>These kinds of attacks are becoming more common and more serious, said Rob Caldwell founder and CEO for Obor Digital, which, along with TV Technology, conducted a series of Cyber “boot camps” for broadcasters this fall. “In the case of content producers, the threat is to their bottom line,” he said. “Who will pay to see premium video content if hackers are making it available for free?”</p><p>Making matters worse is that “broadcasters haven’t yet begun to seriously address the threat of ‘content replacement’ where a hacker or disgruntled employee could potentially replace a commercial spot with media intended to create panic, confusion and chaos,” Caldwell added. Not all threats come from hackers breaking directly into servers either. “All it takes is an employee to bring in a USB flash drive that’s infected with hacker malware—say with some ‘free music’ they downloaded to listen to at work—then plugging the flash drive into the broadcaster’s internal network. All of a sudden, the ‘bad guys’ can get in and steal what they want—and they will.”</p><p>There are several caveats broadcasters should be aware of when protecting their valuable media content from online theft and illegal distribution. Here are three of them:</p><p><strong>WORK WITH A SECURE CONTENT DISTRIBUTOR</strong></p><p>As broadcasters and content creators distribute more of their premium content online, they will invariably come under hacker attacks more often.</p><p>So says Dave Lewis, global security advocate the Boston-based streaming provider Akamai. His remedy is for broadcasters and content providers to hook up with a secure content delivery network (like Akamai), which has sophisticated cyber security tools such as web application firewalls (WAF) already in place.</p><p>Case in point: A distributed denial of service (DDoS) attack occurs when a hacker floods a web site with so many requests that the site ceases to function, knocking it offline. Unfortunately, such attacks are extremely common these days, and they can result in content distributors being unable to serve paying clients.</p><p>To prevent this from happening, “Akamai can provide a line of defense to ensure your web site stays online, so that your customers can be assured that they will have access to your programming during DDoS attacks,” said Lewis. “As well, our platform is extremely secure; making your content far less vulnerable to piracy.</p><p><strong>HIRE A PROFESSIONAL </strong></p><p>Originally, the U.S. military decided to use Obor Digital’s Zeus software to track military communications equipment, configurations, failures and repair issues in Afghanistan and Iraq, according to Caldwell. Subsequently, Obor decided to partner with those military cyber specialists and bring this expertise directly to broadcasters.</p><p>Cyber security services offered by Obor Digital to broadcasters include “Vulnerability Assessments” to determine a content provider’s operational/IT system weaknesses and remedies for them; ongoing Monitoring (three available levels) to detect and address security threats/attempted intrusions; Security Device Management to ensure that the broadcaster’s security devices are running properly; and Incident Response to step in when an attack succeeds, minimize it, and determine what happened after the fact to keep it from happening again.</p><p><strong>GO FULL OUT ON END TO END SECURITY</strong></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HPNQEMxJU2GUic2ehrXnEc" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/HPNQEMxJU2GUic2ehrXnEc.png" mos="https://cdn.mos.cms.futurecdn.net/HPNQEMxJU2GUic2ehrXnEc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The Entertainment Security Operations Center in Los Angeles</em></p><p>Los Angeles’ new Entertainment Security Operations Center (ESOC) is an end-to-end response to hacker threats. Built by security solutions provider Secure Channels Inc., ESOC combines a “tier 3” (99.98 percent availability) data center infrastructure with dark fiber tethering (connecting over so-called dark fiber networks that are not otherwise in use), to provide content creators with a totally secure, membership-only production process.</p><p>“We only connect your company to other ESOC-checked members, meaning that everyone in your production chain is secure and verified,” said Richard Blech, CEO of the Irvine, Calif.-based company. “Too many times, a major content provider with reasonable security will contract a third-party firm that isn’t secure, putting the entire production/distribution chain at risk. The ESOC model eliminates this risk, because everyone you work with is as secure as you are.” ESOC’s protection extends to member documents and emails, as well as video content.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>