Sunday, January 12, 2014

Tap water fix in West Virginia still days away after spill

Tap water fix in West Virginia still days away after spill

CHARLESTON, W., Virginia Sun Jan 12, 2014 12:54am EST

Cathy Mabe of Spring Hill, West Virginia makes use of a couple of watering cans to carry water at a bring-your-own-containers water filling station in South Charleston, West Virginia, January 11, 2014. REUTERS-Lisa Hechesky
1 OF 6. Cathy Mabe of Spring Hill, West Virginia makes use of a couple of watering cans to carry water at a bring-your-own-containers water filling station in South Charleston, West Virginia, January 11, 2014.
CREDIT: REUTERS/LISA HECHESKY





(Reuters) - Tap water in Charleston, West Virginia, and nearby communities will remain unsafe in the coming days, an official said on Saturday as residents spent a third day unable to bathe, shower or drink from the faucet due to a chemical spill tainting the Elk River.
As much as 5,000 gallons (18,927 liters) of industrial chemical 4-methylcyclohexane methanol, or Crude MCHM, leaked into the river on Thursday, state officials said.
The spill came from a tank belonging to Freedom Industries, a Charleston company that produces specialty chemicals for the mining, steel and cement industries, authorities said.
Governor Earl Ray Tomblin on Friday declared a state of emergency for nine counties, with the affected area including the state capital of Charleston, the state's largest city. President Barack Obama has issued an emergency declaration.
"Our teams are out and we have employees that have worked this (water) system that are extremely knowledgeable. (They are) out collecting samples and looking at flushing activities at this time," Jeff McIntyre, president of West Virginia American Water Co, told reporters on Saturday.
"But we are talking days" before water quality meets federally mandated quality standards, said McIntyre, whose company runs the state's largest water treatment plant.
The regional ban on using tap water will be lifted one area at a time as officials work to meet the 1 part per million requirement set by the federal Centers for Disease Control and Prevention, McIntyre said.
Officials have said chemical levels in the water were declining, but the spill forced schools and businesses to close in Charleston and surrounding communities.
The Federal Emergency Management Agency sent 75 tractor trailers full of bottled water to distribute, with National Guard assistance, to the over 300,000 people unable to use their tap water.
"As of Saturday, FEMA has delivered approximately 1 million liters of water from its distribution centers in Cumberland and Frederick, Maryland, to the area for use by the state," it said. "FEMA will continue to deliver supplies to the state for distribution, as needed."
FIVE ADMITTED TO HOSPITALS
Secretary Karen Bowling of the state Department of Health and Human Resources said 73 people had gone to area emergency rooms and five have been admitted to hospitals for observation.
Their symptoms included nausea, vomiting, dizziness, diarrhea, rashes and reddened skin, officials said.
Water carrying the industrial chemical has an odor like licorice or anise. Though not highly lethal, the level that could be considered safe has not been quantified, McIntyre said.
The contamination has forced area restaurants to close.
"What we're working on is a plan to be able to allow businesses to be able to present plans for potable water," said Dr. Rahul Gupta, the health officer at the Kanawha-Charleston Health Department.
"We'll review those plans and after we verify, we'll reopen businesses on a case-by-case basis. We have begun that process already," Gupta said.
Residents endured another day without access to running water, and for some the wait was too long.
Russell Anderson, who lives down the street from the spill, said he spent his Saturday stocking up on bottled water supplies at a Rite Aid drugstore.
"It's been a real pain," he said. "I just took a shower yesterday. I'm fighting a cold right now and I just couldn't go without, so I took my chances."
Local officials helping out with distribution of bottled water said they have had a hard time keeping up with demand.

"Really the biggest challenge has been running out and having to wait 10 to 15 minutes before we can get some more," said Kanawha County Sheriff Deputy Jed Walls.

Ford exec backpedals after saying it tracks drivers

Ford exec backpedals after saying it tracks drivers

   Text Size  
Published: Thursday, 9 Jan 2014 | 5:00 PM ET
By:  | CNBC Auto and Airline Industry Reporter
Twitter
58
LinkedIn
7
Share
Ford Motor executive who said the company tracks and collects data on how Ford customers drive their vehicles said Thursday that he regrets making the comments.
Jim Farley, executive vice president of marketing and sales at Ford, said that he was wrong to suggest to customers that the automaker uses GPS devices in vehicles to collect data on how people drive.
"I definitely left the wrong impression with my comments, and I regret it," Farley told CNBC. "It's important to me that our customers know where we stand and that we do not track them."
Big automobile announcements at CES
CNBC's Jon Fortt shares some of the big automobile industry announcements at the Consumer Electronics Show.
Wednesday night, while taking part in a panel at the Consumer Electronics Show in Las Vegas, Farley was quoted as saying: "We know everyone who breaks the law, we know when you're doing it. We have GPS in your car, so we know what you're doing. By the way, we don't supply that data to anyone."
Business Insider first reported Farley's comments Thursday morning. The article and Farley's remarks immediately raised concerns that Ford is monitoring drivers without their consent.
Farley told CNBC that his comments were meant to be in response to a hypothetical question about whether or not automakers could track how vehicles are driven. He said the automaker does not have GPS tracking data in the vehicles it sells.
"We do not monitor and aggregate data from our cars," Farley said.

Syrian Electronic Army takes over Xbox social



Syrian Electronic Army takes over Xbox social media accounts

BY  ON 

Screen Shot 2014-01-11 at 9.42.29 pm
A group purporting to be the Syrian Electronic Army – a hacking collective that supports Syrian President Bashar al-Assad – has said taken over the social media profiles belonging to Xbox. This comes after another Microsoft-owned property, Skype, also had their social media profiles hijacked by the group.
Images posted by the Syrian Electronic Army on Twitter show that they have, or had, control of the main Twitter and Instagram accounts. They also appeared to had control of the Xbox Support Twitter account, posting several messages to confirm the attack. Those tweets have since been deleted – which could suggest that Xbox has control of the account again.
TwitterSEAXbox

More well-known US retailers victims of cyber attacks: Sources

More well-known US retailers victims of cyber attacks: Sources

   Text Size  
Published: Sunday, 12 Jan 2014 | 12:45 AM ET
Twitter
144
LinkedIn
8
Share
Target Corp and Neiman Marcus are not the only U.S. retailers whose networks were breached over the holiday shopping season last year, according to sources familiar with attacks on other merchants that have yet to be publicly disclosed.
Smaller breaches on at least three other well-known U.S. retailers took place and were conducted using similar techniques as the one on Target, according to the people familiar with the attacks. Those breaches have yet to come to light. Also, similar breaches may have occurred earlier last year.
Getty Images
People walk with their shopping bags along Lincoln Road Mall, December 24, 2013 in Miami.
The sources said that they involved retailers with outlets in malls, but declined to elaborate. They also said that while they suspect the perpetrators may be the same as those who launched the Target attack, they cannot be sure because they are still trying to find the culprits behind all of the security breaches.
Law enforcement sources have said they suspect the ring leaders are from Eastern Europe, which is where most big cyber crime cases have been hatched over the past decade.
Only one well-known retailer, Neiman Marcus, has said that they too have been victim of a cyber attack since Target's Dec. 19 disclosure that some 40 million payment card numbers had been stolen in a cyber attack.
On Friday, Target said the data breach was worse than initially thought. An investigation found that hackers stole the personal information of at least 70 million customers, including names, mailing addresses, telephone numbers and email addresses. Neiman Marcus said it was not sure if the breach was related to the Target incident.
Most states have laws that require companies to contact customers when certain personal information is compromised. In many cases the task of notification falls on the credit card issuer.
Merchants are required to report breaches of personal information including social security numbers. It was not immediately clear if that was the case with the retailers who were attacked around the same time as Target.
The Secret Service and Department of Justice, which are investigating the Target breach, declined to comment on Saturday. 
Are Target's customers at risk?
Discussing Target's data breach and how much it will hurt their bottom line, with Stacey Widlitz, SW Retail Advisors.
Scraping Memory
Target has not disclosed how the attackers managed to breach its network or siphon off some of its most sensitive data. 
The sources who spoke to Reuters about the breaches said that investigators believe the attackers used similar techniques and pieces of malicious software to steal data from Target and other retailers.
One of the pieces of malware they used was something known as a RAM scraper, or memory-parsing software, which enables cyber criminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text, the sources said.
While the technology has been around for many years, its use has increased in recent years as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.
Visa issued two alerts last year about a surge in cyber attacks on retailers that specifically warned about the threat from memory parsing malware. 
The alerts, published in April and August, provided retailers with technical details on how the attacks were launched and advice on thwarting them. 
A Visa spokeswoman declined comment on the reports, which did not identify specific victims.
It was not clear whether Target's security team had implemented the measures that Visa had recommended to mitigate the risks of being attacked.
Yet a law enforcement source familiar with the breach said that even if the retailer had implemented those steps, the efforts may not have succeeded in stopping the attack.
That is because the attackers were more sophisticated than the ones in the previous attacks described in the Visa alerts, according to the source. The source asked not to be identified because they were not authorized to discuss the matter publicly.

Delayed disclosure

Retailers are often reluctant to report breaches out of concern it could hurt their businesses. Target only acknowledged its 2013 attack after security blogger Brian Krebs reported the breach, prompting inquiries from journalists and investors.
Neiman Marcus said an outside forensics firm discovered evidence on Jan. 1 that indicated the retailer had been the victim of a cyber attack. It disclosed the breach nine days later, after another inquiry from Krebs, who was following up on reports about a surge in fraudulent charges traced to the retailer.
Target and J.C. Penney Co Inc. waited more than two years to admit that they were victims in 2007 of notorious hacker Albert Gonzalez, who was accused of masterminding the theft and reselling of millions of credit cards and ATM numbers.
During his trial the companies were represented by lawyers who did not identify their clients as Target and J.C Penney.
Doug Johnson, vice president of risk management policy with the American Bankers Association, said banks and credit card firms like Visa are forbidden from naming merchants that have been breached, unless they disclose it themselves.
"It is really frustrating to the bank and also the customer," Johnson said. One of the sources who told Reuters about the recent rash of attacks said the memory parsing malware cited in the Visa reports was among the tools that the hackers had used, but said they used other techniques as well.
Target spokeswoman Molly Snyder said the retailer is not commenting on the company's investigation of the breach. 
"This continues to be an active and ongoing investigation. It would be inappropriate to discuss details at this point." 
Avivah Litan, a security analyst for Stamford, Connecticut -based Gartner information technology research firm, said she learned about a separate set ofbreaches, dating back no more than a few months before the Nov. 28 Thanksgiving Day start of the holiday shopping season, from a forensics investigator. Shedeclined to provide his name.
"Target was not the only retailer who got hit, but they got hit the biggest," Litan said.
Investigators believe that the early series of attacks on retailers staged before late November were mostly used as trial attacks to help the hackers perfect new techniques they then used against Target, stealing payment cards at unprecedented speed, Litan said.
Chris Gray, director of Denver, Colorado -based Accuvant information security firm's risk and compliance practice, said that sophisticated cyber crime groups do that because they only have once chance to get it right before victims catch on.
"You want to test it and make sure it works," Gray said. "Then you push it out at the appropriate time and do as much damage as you can."