The Internet - The first Worldwide Tool of Unification ("The End of History")

" ... Now I give you something that few think about: What do you think the Internet is all about, historically? Citizens of all the countries on Earth can talk to one another without electronic borders. The young people of those nations can all see each other, talk to each other, and express opinions. No matter what the country does to suppress it, they're doing it anyway. They are putting together a network of consciousness, of oneness, a multicultural consciousness. It's here to stay. It's part of the new energy. The young people know it and are leading the way.... "

" ... I gave you a prophecy more than 10 years ago. I told you there would come a day when everyone could talk to everyone and, therefore, there could be no conspiracy. For conspiracy depends on separation and secrecy - something hiding in the dark that only a few know about. Seen the news lately? What is happening? Could it be that there is a new paradigm happening that seems to go against history?... " Read More …. "The End of History"- Nov 20, 2010 (Kryon channelled by Lee Carroll)

"Recalibration of Free Choice"– Mar 3, 2012 (Kryon Channelling by Lee Carroll) - (Subjects: (Old) Souls, Midpoint on 21-12-2012, Shift of Human Consciousness, Black & White vs. Color, 1 - Spirituality (Religions) shifting, Loose a Pope “soon”, 2 - Humans will change react to drama, 3 - Civilizations/Population on Earth, 4 - Alternate energy sources (Geothermal, Tidal (Paddle wheels), Wind), 5 – Financials Institutes/concepts will change (Integrity – Ethical) , 6 - News/Media/TV to change, 7 – Big Pharmaceutical company will collapse “soon”, (Keep people sick), (Integrity – Ethical) 8 – Wars will be over on Earth, Global Unity, … etc.) - (Text version)

“…5 - Integrity That May Surprise…

Have you seen innovation and invention in the past decade that required thinking out of the box of an old reality? Indeed, you have. I can't tell you what's coming, because you haven't thought of it yet! But the potentials of it are looming large. Let me give you an example, Let us say that 20 years ago, you predicted that there would be something called the Internet on a device you don't really have yet using technology that you can't imagine. You will have full libraries, buildings filled with books, in your hand - a worldwide encyclopedia of everything knowable, with the ability to look it up instantly! Not only that, but that look-up service isn't going to cost a penny! You can call friends and see them on a video screen, and it won't cost a penny! No matter how long you use this service and to what depth you use it, the service itself will be free.

Now, anyone listening to you back then would perhaps have said, "Even if we can believe the technological part, which we think is impossible, everything costs something. There has to be a charge for it! Otherwise, how would they stay in business?" The answer is this: With new invention comes new paradigms of business. You don't know what you don't know, so don't decide in advance what you think is coming based on an old energy world. ..."
(Subjects: Who/What is Kryon ?, Egypt Uprising, Iran/Persia Uprising, Peace in Middle East without Israel actively involved, Muhammad, "Conceptual" Youth Revolution, "Conceptual" Managed Business, Internet, Social Media, News Media, Google, Bankers, Global Unity,..... etc.)


German anti-hate speech group counters Facebook trolls

German anti-hate speech group counters Facebook trolls
Logo No Hate Speech Movement

Bundestag passes law to fine social media companies for not deleting hate speech

Honouring computing’s 1843 visionary, Lady Ada Lovelace. (Design of doodle by Kevin Laughlin)
Showing posts with label Computer Virus. Show all posts
Showing posts with label Computer Virus. Show all posts

Wednesday, June 28, 2017

Multinationals hit by global wave of cyberattacks

Yahoo – AFP, Oleksandr Savochenko with Maria Antonova in Moscow and AFP bureaus, June 27, 2017

Ukraine's central bank said a cyberattack hit several lenders in the country,
hindering operations and leading the regulator to warn other financial institutions
to tighten security measures (AFP Photo/Kirill KUDRYAVTSEV)

Kiev (AFP) - A global wave of cyberattacks that began in Russia and Ukraine on Tuesday wrought havoc on government and corporate computer systems as it spread to Western Europe and across the Atlantic.

Several multinational companies said they were targeted, including US pharmaceutical giant Merck, Russian state oil giant Rosneft, British advertising giant WPP and the French industrial group Saint-Gobain.

The first reports of trouble came from Ukrainian banks, Kiev's main airport and Rosneft, in a major incident reminiscent of the recent WannaCry virus.

Some IT experts identified the virus as "Petrwrap", a modified version of the Petya ransomware which hit last year and demanded money from victims in exchange for the return of their data.

But global cybersecurity firm Kaspersky Lab said: "Our preliminary findings suggest that it is not a variant of Petya ransomware as publically reported, but a new ransomware that has not been seen before," which it named "NotPetya".

The cyberattack also recalled a ransomware outbreak last month which hit more than 150 countries and a total of more than 200,000 victims with the WannaCry ransomware.

'Spreading round the world'

The virus is "spreading around the world, a large number of countries are affected," Costin Raiu, a researcher at the Moscow-based Kaspersky Lab said in a Twitter post.

In the United States, Merck was hit as was New York law firm of DLA Piper.

"We confirm our company's computer network was compromised today as part of a global hack. Other organizations have also been affected," Merck said on Twitter.

"It seems to be done by professionals criminals, and I think money is the motivation," said Sean Sullivan, a researcher at the Finnish cybersecurity group F-Secure.

He said that unlike the recent WannaCry attack, this "Petrwrap" attack has sophisticated elements that could make it easier to rapidly infect many more systems.

'Powerful' attack

Ukrainian Prime Minister Volodymyr Groysman wrote on Facebook that the attacks in his country were "unprecedented" but insisted that "important systems were not affected."

However, the radiation monitoring system at Ukraine's Chernobyl nuclear site has been taken offline after it was targeted in the attack, forcing employees to use hand-held counters to measure levels, officials said Tuesday.

The technological systems were working "as usual" at the plant that exploded in 1986, however.

The attacks started around 2:00 pm Moscow time (1100GMT) and quickly spread to 80 companies in Ukraine and Russia, said cybersecurity company Group IB.

The companies affected were hit by a type of ransomware that locks users out of the computer and demands purchase of a key to reinstate access, Group IB said.

The cryptolocker demands $300 in bitcoins and does not name the encrypting program, which makes finding a solution difficult, Group IB spokesman Evgeny Gukov said.

Ukraine's central bank said several lenders had been hit in the country, hindering operations and leading the regulator to warn other financial institutions to tighten security measures.

Banks were experiencing "difficulty in servicing customers and performing banking operations" due to the attacks, the bank said in a statement.

Rosneft said earlier that its servers suffered a "powerful" cyberattack but thanks to its backup system "the production and extraction of oil were not stopped."

The wave of cyberattacks also impacted Maersk, a global cargo shipping company; Saint-Gobain, a French company producing glass and other construction materials; and British-based WPP.

In Amsterdam, the Dutch parcel delivery company TNT, which operates in 200 countries around the world, said its systems had been affected. "We are assessing the situation and are implementing remediation steps as quickly as possible," the company, part of FedEx, said in a statement to AFP.

Signs of sophistication

Experts also said this latest attack could heighten fears that companies may be more vulnerable to cyberattacks than suspected, potentially putting personal data at risk.

"This will undeniably affect trust in these organisations and raise questions of competency," said Louis Rynsard, a director at the corporate communications agency SBC London.

"The long-lasting impact of a cyberattack cannot be overstated," he said.

The fight against cyberattacks has sparked exponential growth in global protection spending, with the cyber security market estimated at $120 billion this year, more than 30 times its size just over a decade ago.

But even that massive figure looks set to be dwarfed within a few years, experts said, after ransomware attacks crippled computers worldwide in the past week.

Sunday, May 14, 2017

Manhunt for hackers behind global cyberattack

Yahoo – AFP, Robin MILLARD, May 14, 2017

The huge cyberattack wiped out display screens at rail stations in Germany
(AFP Photo/Boris Roessler)

London (AFP) - International investigators hunted Saturday for those behind an unprecedented cyber-attack that affected systems in dozens of countries, including at banks, hospitals and government agencies, as security experts sought to contain the fallout.

The assault, which began Friday and was being described as the biggest-ever cyber ransom attack, struck state agencies and major companies around the world -- from Russian banks and British hospitals to FedEx and European car factories.

"The recent attack is at an unprecedented level and will require a complex international investigation to identify the culprits," said Europol, Europe's police agency.

Europol said a special task force at its European Cybercrime Centre was "specially designed to assist in such investigations and will play an important role in supporting the investigation".

The attacks used ransomware that apparently exploited a security flaw in Microsoft operating systems, locking users' files unless they pay the attackers a designated sum in the virtual currency Bitcoin.

Images appeared on victims' screens demanding payment of $300 (275 euros) in Bitcoin, saying: "Ooops, your files have been encrypted!"

Payment is demanded within three days or the price is doubled, and if none is received within seven days the files will be deleted, according to the screen message.

But experts and government alike warn against ceding to the hackers' demands.

"Paying the ransom does not guarantee the encrypted files will be released," the US Department of Homeland Security's computer emergency response team said.

"It only guarantees that the malicious actors receive the victim's money, and in some cases, their banking information."

'Painful'

Experts and officials offered differing estimates of the scope of the attacks, but all agreed it was huge.

Mikko Hypponen, chief research officer at the Helsinki-based cyber security company F-Secure, told AFP it was the biggest ransomware outbreak in history, saying that 130,000 systems in more than 100 countries had been affected.

He said Russia and India were hit particularly hard, largely because Microsoft's Windows XP -- one of the operating systems most at risk -- was still widely used there.

French police said there were "more than 75,000 victims" around the globe, but cautioned that the number could increase "significantly".

The virus spread quickly because the culprits used a digital code believed to have been developed by the US National Security Agency -- and subsequently leaked as part of a document dump, according to researchers at the Moscow-based computer security firm Kaspersky Lab.

Microsoft said the situation was "painful" and that it was taking "all possible actions to protect our customers".

It issued guidance for people to protect their systems, while taking the highly unusual step of reissuing security patches first made available in March for Windows XP and other older versions of its operating system.

Europe worst hit

US software firm Symantec said the majority of organisations affected were in Europe, and the attack was believed to be indiscriminate.

The companies and government agencies targeted were diverse.

In the United States, package delivery group FedEx said it was "implementing remediation steps as quickly as possible," while French carmaker Renault was forced to stop production at sites in France, Slovenia and Romania.

Russia's interior ministry said some of its computers had been hit by a "virus attack" and that efforts were underway to destroy it. The country's banking system was also attacked, although no problems were detected, as was the railway system.

Germany's rail operator Deutsche Bahn said its station display panels were affected. Universities in Greece and Italy also were hit.

China's network information safety working group sent a warning to universities about the cyber-attack and the National Internet Emergency Center suggested that users update Windows security patches.

Shanghai's Fudan University received reports that a large number of school computers were infected with the virus.

Accidental 'kill switch'

Kaspersky said it was "trying to determine whether it is possible to decrypt data locked in the attack -- with the aim of developing a decryption tool as soon as possible."

On Saturday, a cyber security researcher told AFP he had accidentally discovered a "kill switch" that could prevent the spread of the ransomware.

The researcher, tweeting as @MalwareTechBlog, said registering a domain name used by the malware stops it from spreading, though it cannot help computers already affected.

"If you have anything to patch, patch it," the researcher said in a blog post. "Now I should probably sleep."

A hacking group called Shadow Brokers released the malware in April claiming to have discovered the flaw from the NSA, Kaspersky said.

"Unlike most other attacks, this malware is spreading primarily by direct infection from machine to machine on local networks, rather than purely by email," said Lance Cottrell, chief scientist at the US technology group Ntrepid.

G7 finance ministers meeting in Italy vowed to unite against cyber crime, as it represented a growing threat to their economies and should be tackled as a priority. The danger will be discussed at the G7 leaders' summit next month.

In Britain, the attack disrupted care at National Health Service facilities, forcing ambulances to divert and hospitals to postpone operations.

"There will be lessons to learn from what appears to be the biggest criminal cyber-attack in history," Interior minister Amber Rudd said.

"But our immediate priority as a government is to disrupt the attack, restore affected services as soon as possible, and establish who was behind it so we can bring them to justice."

burs-sst/kb

Monday, August 4, 2014

Foreign security software ousted from China's procurement list

Want China Times, Xinhua 2014-08-04

Kaspersky products on display during a product launch
in Beijing in 2011. (File photo/Xinhua)

A Chinese government procurement agency has excluded Symantec and Kaspersky, two foreign security software developers, from a security software supplier list.

According to a report from Beijing Youth Daily, all the five antivirus softwares in the list are from China, including Qihoo 360, Venustech, CAJinchen, Beijing Jiangmin and Rising.

China's homegrown technology companies also got the better of their foreign counterparts in the personal computer operating system supplier list, making Microsoft the only foreign brand.

There is no indication whether the move has some connection with China's emphasis on the security of IT products and software after Edward Snowden's leaks about the intelligence gathering project PRISM from the National Security Agency of the United States.

China's State Internet Information Office announced in May that it would start security vetting of major IT products and services for use by national security and public interests.

Thursday, May 15, 2014

UK court slams weak spyware investigation

Deutsche Welle, 14 May 2014

A UK firm has been selling software to dictatorships to help them track down opposition activists. Now the rights group Privacy International has scored a legal victory that may - one day - curb the trade.


On Monday (12.05.2014), the UK High Court ruled that Her Majesty's Revenue and Customs (the body in charge of enforcing Britain's export regulations) had acted unlawfully in refusing to give information on the status of its investigation into the company Gamma International. Gamma's notorious FinFisher software is being used, according to Privacy International, in at least 36 countries around the world, including repressive regimes like Bahrain, Ethiopia, Egypt, and Turkmenistan - despite the fact that it does not have a license to export.

FinFisher - developed in Munich, Germany - is essentially a virus that covertly installs itself onto a target's computer or cell phone and is then able to remotely activate cameras and microphones, take screenshots, monitor emails, instant messages, and voice calls (including Skype), as well as track the device's location - all at the command of a remote operator. FinFisher's Munich office did not respond to requests for comment, but its website boasts that it employs some of the world's best specialists in "offensive IT intrusion."

Shehabi was one of the activists
targeted by FinFisher spyware
"FinFisher is almost impossible to detect," Privacy's head of research Eric King told DW. "What happened in the examples that we know about is that people were suspicious, because either the infection took place via an email pretending to be someone that they knew, and they saw something off, or it was an email blast to a number of different people, where again the activists saw something off."

Forensic investigation

With forensic digital analysis, Privacy was able to determine that the spyware was indeed FinFisher, and that it was reporting information back to governments around the world. Because of its cryptography components, it has always been illegal to export FinFisher from the UK without a license (issued by the government's Department for Business, Innovation and Skills), but Privacy confirmed a few years ago that Gamma International had not been granted any such licenses.

In November 2012 the group submitted a 186-page dossier of evidence to HMRC - at the request of the British government - suggesting that Gamma International had illegally exported the surveillance technology. The evidence included testimonies from Ala'a Shehabi, a British-born Bahraini economist and pro-democracy activist, who has herself been arrested by Bahraini authorities - as well as technical details from servers.

"Now that the High Court has rightfully said that HMRC's actions were unlawful, I hope that the government takes action to bring justice to all of the victims whose rights have been violated because of this intrusive spyware," Shehabi said in a Privacy statement.

"We couldn't even get HMRC to acknowledge that they'd received the letters - after months they finally did acknowledge that we'd sent them," said King. "But we could never get from them what they were going to do with it - we couldn't even get a confirmation that they were going to investigate it. So after lengthy correspondence we took them to court."

Privacy contended that the victims of the surveillance - as well as the public - had a right to know about what the state was doing to enforce export guidelines - and this week the High Court agreed.

Judge Justice Green condemned HMRC's refusal to give information on its investigation as "irrational" and "simply inconsistent with the legislation." Green added in the ruling, "I can in such circumstances have no confidence that HMRC has properly addressed itself to the serious complaints advanced to it by the Claimant [Privacy International]."

Easier to make than to steal

Following a DW request for comment, a HMRC spokesperson would only say, by email, "We are considering the detail of the judgment. The Judicial Review confirms that we may only disclose information where the law allows it, and HMRC remains committed to its legal duty of confidentiality."

The Bahraini regime has been
condemned by human rights groups
The spokesperson also added, "HMRC receives information and intelligence from numerous different sources, and we always look into any allegation of criminal wrongdoing." But this response did not address Privacy's central concern - the potentially illegal trade in malware. As far as King is concerned, the idea that Gamma International did not deliberately sell FinFisher to Bahrain and elsewhere is utterly implausible.

"It's near-impossible for this software to be stolen," he said. "It would require months of consultancy and contracting to work out where you put specific boxes in the network, to make sure it all works properly. It requires a considerable amount of installation and tweaking. If the Bahrainis wanted to spy on people using malware and they were technically sophisticated enough to steal it, they would have just built it for themselves. It actually would've been easier."

Related Articles:



Tuesday, February 25, 2014

IT giants to protect Chinese users after Windows XP shutdown

Want China Times, Xinhua 2014-02-25

The launch of Windows 8 at the Consumer Electronics Show in Las Vegas,
Jan. 9, 2012. (Photo/CNS)

Tencent will team up with other IT giants to protect Chinese users against internet attacks after the Windows XP shutdown on April 8.

Tencent, along with Kingsoft, Sogou and other internet service providers, will give technical assistance for Windows XP users for system upgrades and defense, said Ding Ke, a senior manager at Tencent.

The companies will implement protection measures before the shutdown and the "wall" will continue during a transition period that may last for two to three years or even longer.

"The up-coming shutdown will serious affect Chinese users," said Ding, adding that more than one quarter of China's computers are running the operating system.

Microsoft announced earlier that it will stop providing technical assistance for Windows XP after April 8, and computers will still work but they might become more vulnerable to security risks and viruses.

Related Article:


Thursday, February 20, 2014

Qihoo 360 to step in as Microsoft pulls plug on Windows XP

Want China Times, Staff Reporter 2014-02-20

A young girl uses a Windows PC. (Photo/Wang Chin-ho)

As Microsoft has announced it will no longer support the Windows XP operating system from April 8, China's PC users are relieved that internet security company Qihoo 360 has announced that it will continue to protect the operating system until Windows XP disappears completely, Chinese media outlets report.

Windows XP was launched in 2001 and ICS Solutions Group reports that nearly 40% of computers in the world still run on it. Another source cited in Chinese media reports said Windows XP accounts for 25% of computers worldwide but 70% of computers in China. There are an estimated 200 million computers using the XP system in the country, and internet users have feared that their Windows XP computers will swiftly fall victim to viruses after April 8.

Ni Guangnan, a Chinese Academy of Engineering (CAE) member, said China would do best to produce a domestic operating system to replace Windows XP.

As Microsoft's MAPP cooperator, Qihoo 360 said it will keep on providing protection to XP users.

Thursday, February 14, 2013

Police bust global cybercrime extortion ring

Google – AFP, 13 February 2013 

Europol's chief Rob Wainwright looks on during a press conference in
The Hague on February 4, 2013 (ANP/AFP/File, Robin van Lonkhuijsen)

MADRID — Spanish police and Europol have busted a global cybercrime operation that infected millions of computers with a virus that falsely accused victims of viewing child pornography and demanded a fine payment, officials said Wednesday.

Police detained 11 people as part of the operation, including a 27-year-old Russian suspected of creating and distributing the virus, Europol director Rob Wainwright told a news conference in Madrid.

The virus locked computers in over 30 countries, mostly in Europe, and it demanded payment of a fine of 100 euros ($135) to return control to its user, he said.

The message generated by the virus used the logo of the national police force and the language of the country where the computer was based to accuse the victim of having viewed child pornography or pirated movies online, he added.

"This operation is the first major operation of its kind," Wainwright said.

"This is an example of the evolving nature of cybercrime online, of how cybercrime is becoming more sophisticated."

The authorities said the group raised millions of euros with its scam but could not yet cite a precise amount.

About three percent of those whose computers were infected by the virus paid the fine that was demanded.

Europol said in a statement that it was "the largest and most complex cybercrime network dedicated to spreading police ransomware."

Police detained 10 people -- six Russians, two Ukrainians and two Georgians -- last week on Spain's Costa del Sol as part of the investigation, said Spain's secretary of state for security, Francisco Martinez.

The suspected author of the virus was detained while he was on holiday in Dubai in December, he added. He is currently awaiting extradition to Spain.

Of the 10 suspects detained in Spain, six have been remanded in custody while the investigation continues and the remaining four were released on bail.

They are accused of fraud, money laundering, forging documents and membership of an organised crime group.

The investigation remains open and further arrests are likely, police said.

The authorities began their investigation, dubbed "Operation Ransom", in November 2011 after detecting the virus in six European countries.

The network created 48 different versions of the virus to ensure that it was not detected by anti-virus software, said Martinez.

So-called "ransomware" viruses, which try to make victims pay an on-the-spot fine, are becoming more prevalent but most strains only accuse people of pirating movies or music. Others scramble data that is only unscrambled when a fee is paid.

Tuesday, January 15, 2013

Oracle patches dangerous Java holes

Google – AFP,  14 January 2013 

Oracle is distributing a patch for flaws so dangerous the Department of
Homeland  Security said people should stop using it (Getty Images/AFP/
File, Justin Sullivan)

SAN FRANCISCO — Oracle on Monday was distributing a patch for Java software flaws deemed so dangerous that the US Department of Homeland Security said that people should stop using it.

"Oracle recommends that this Security Alert be applied as soon as possible because these issues may be exploited 'in the wild' and some exploits are available in various hacking tools," Oracle's Eric Maurice said in a blog post.

The patch was crafted to fix two holes that hackers could slip through in Java 7 software used by web browsers to interact with websites.

"To be successfully exploited, an attacker needs to trick an unsuspecting user into browsing a malicious website," Maurice said.

"The execution of the malicious applet within the browser of the unsuspecting users then allows the attacker to execute arbitrary code in the vulnerable system."

Essentially, hackers could take advantage of the vulnerability to infect and take control of computers by getting them to visit a booby-trapped website.

Oracle raised Java security settings so that mini-programs referred to as "applets" will need to get permission from website visitors before being able to run on people's computers, according to Maurice.

Despite the patch, which was released by Oracle on Sunday, computer specialists at the Department of Homeland Security advised people to avoid using the software "unless it is absolutely necessary," even after updating.

"This will help mitigate other Java vulnerabilities that may be discovered in the future," the DHS Computer Emergency Readiness Team said Monday in an updated advisory on its website.

Java is distributed by business software powerhouse Oracle and is popular because it lets developers create websites in code that can be accessed regardless of a computer's operating system.

Java was created by Sun Microsystems, which was purchased by Northern California-based Oracle.

Thursday, September 20, 2012

German spyware business supports dictators

Deutsche Welle, 19 September 2012



German firms are reportedly selling spyware to Middle Eastern dictatorships, and Foreign Minister Guido Westerwelle has called for an EU-wide ban. But another ministry refuses to limit the lucrative trade, say critics.

As many have pointed out, not least Chancellor Angela Merkel in her weekly internet broadcast, the wheels of the Arab Spring have been oiled by social networks and the availability of cheap mobile phones with video cameras.

But repressive governments such as those in Bahrain, Syria, and Turkmenistan have not been slow to use digital weapons to fight back. Pro-democracy activists have come to expect propaganda campaigns undermining their work, as Husain Abdulla, director of Americans for Democracy and Human Rights in Bahrain (ADHRB), told Deutsche Welle recently, but few were expecting to be targeted by software that could come from a James Bond movie.

A number of software security firms have developed Trojan malware with the ability to remotely grab images from computer screens, intercept and record Skype calls, secretly turn on web cameras and microphones, and record keystrokes. Mobile versions of the spyware exist too, which can turn a smartphone into a tracking device by enabling the phone's GPS system. 

Bahraini activists have been targetted
by malware
The most recent case was revealed by the Munk School of Global Affairs' Citizen Lab at the University of Toronto, which analyzed spyware sent to Bahraini activists, including Abdulla, traced it to government-controlled servers in Bahrain, and identified the malware as made by German company FinFisher, a subsidiary of the UK-based Gamma Group.

Virus trade

Typically, according to Abdulla's account, the malware is attached to a legitimate email intercepted by government agents. If the attachment is then opened on the target computer, the virus copies itself into a system folder. When the computer is then re-started, it adds a new code into the system processes. This can hide the Trojan's network communication within a web browser and so avoid firewalls.

Andre Meister, internet activist at the German website netzpolitik.org, believes the software is very sophisticated. "From what I understand, it is very professionally put together," he told Deutsche Welle
.
German media reports have already named and shamed a number of German companies - Elaman, Trovicor, Utimaco - said to be involved in the business of selling malware to countries like Turkmenistan and Syria. 

The software can turn a smartphone
into a tracking device
But they are notoriously secretive. None of the above firms responded to DW requests for interviews, and even their promotional literature is kept under wraps, shown only to potential clients. One Elaman "German Security Solutions" brochure, obtained and released by Wikileaks, revealed that the company was helpfully pointing out that its technology could be used to "identify political opponents."

Dual-use

Though the German public and political class insist on stringent data protection laws at home, only opposition parties like the Greens and the socialist Left party have raised concerns about the sale of this software abroad.

"German politicians are maybe a bit critical of American corporations like Google and Facebook, but that doesn't mean that they would prevent the export of malware," said Meister. "After all, Germany is the third biggest weapons exporter in the world. But up until now, the export of this software is not limited in any way."

The legal difficulty, of course, is that this technology is "dual-use" - in other words, it can be used for both legitimate and illegitimate reasons - catching criminals or catching democracy activists.

Speaking to DW earlier this month, Gamma's International Managing Director Martin J. Muench used this as a convenient justification for their business. "We use the Export Controls Authorities (ECA) in the UK, Germany and USA to determine to whom we can sell our products. They in effect act as our 'moral compass,'" he said. "Given that a can of fizzy drink or a car battery can be abused and used as an implement of torture, it is of no surprise to anyone if our products can be abused too."

That sounds reasonable enough - except that there are no export guidelines that cover malware, so there is little that the ECAs can do. "There is no obligation to register where they are exporting to, and the companies don't say," said Meister. "That's the problem - it's all a business secret."

Westerwelle called for an EU-wide ban on malware exports

Pressure increasing

Germany's socialist Left party and the Green Party have both brought up the issue with the government. "We've started initiatives in parliament against the export of dual-use technologies," said Annette Groth, human rights spokeswoman for the socialist Left party. "The Left party has been calling for this for some time."

"We've been pointing out the problem for over a year and a half, ever since the Economy Ministry explicitly supported the export of this software," said the Green Party's internet policy spokesman Konstantin von Notz. "Anyway, everyone has really known about the problem for a long time."

And the pressure seems to be paying off. Speaking at an Internet and Human Rights conference, hosted by the German Foreign Ministry in Berlin last week, Foreign Minister Guido Westerwelle called for a EU-wide ban on the export of surveillance software to totalitarian states.

"These regimes should not get the technical instruments to spy on their own citizens," Westerwelle said. It was a good start, though he failed to give details on what technologies he meant, or by when a ban should be implemented.

For von Notz, it's very clear about where the blame lies. "We know the Foreign Ministry has got this problem in its in-tray too," he said. "But up till now the Economy Ministry has always got its way, and said, 'we can't limit German exports.' Of course they won't say anything about it, but from their practical actions it seems clear that human rights don't matter much to them."

The Economy Ministry would not acknowledge any split in the government. "The German government takes the view that the export of surveillance technologies which can be used to suppress freedom of speech or the press in the Internet is to be limited by the appropriate sanctions," ministry spokeswoman Felicitas Hoch told DW in an emailed statement, before adding that the EU was actively working on introducing extra export controls for surveillance technology for "Syria and Iran."

The statement did not mention Bahrain or Turkmenistan or any of the other dictatorships accused of importing malware. Hoch merely added, "The government is also participating in discussions on a possible extension of export controls for surveillance technology on an international level."

But when this extension might be introduced was left open.

Wednesday, September 12, 2012

Cyber security seeks tools in difficult battle

Deutsche Welle, 12 September 2012



Attacks on communication systems, cyber espionage, military hackers - security experts and top businesspeople are discussing these very real threats at the Cyber Security Summit 2012 in Bonn. Which strategies are best?

Internet crime is a fast-growing, billion-euro business, with hackers no longer just targeting the military.

At a forum organized by the Munich Security Conference and Deutsche Telekom, politicians, businessmen and security experts will gather Wednesday in Bonn to take a closer look at the real threat from the Internet, a possible cyberwar, and how to tackle the problem.

Remote-controlled zombie computers

'Zombie computers' are right now the most efficient form of cybercrime , and the threat is growing at an immense speed. Hackers invade individual computers and control them remotely, creating so-called botnets that can grow to huge proportions. 

Kemmerer tracks down botnets
Richard Kemmerer, a computer science professor at the University of California in Santa Barbara, has witnessed the phenomenon firsthand.

"Two years ago, we stole a botnet from the bad guys," the researcher told the seventh Future Security Conference in Bonn last week. "We had 180,000 hijacked machines reporting to us every 20 minutes. That gave us great insight into the underground economy."

The botnet hacker controls all the compromised computers and can, for instance, prompt them to attack random computer networks. Kemmerer only had 10 days to investigate the captured botnet before the "bad guys" managed to "steal it back." That was time enough to get a better grasp on which machines, including computers from large companies, were infected, he said.

Kemmerer found out which security holes the criminals used, and how they managed to obscure their activities by creating so-called fast-flux networks, which are difficult to locate because they change their domain names several times every hour. "It's hard to find out what domain you want to take down," the researcher said.

Computers are easily infected nowadays, and Kemmerer is particularly concerned about "drive-by" downloads - viruses, Trojans and computer worms that users contract by simply surfing the Internet. "You go and visit an innocent site, but it has been compromised by the bad guys and infected with their software, so when you visit, it installs the software onto your machine," he warned.

Shopping paradise for criminals

Two things make life easy for cybercriminals: straightforward programming software and careless system administrators. Hacking into political party websites and government agency networks therefore becomes easy for inexperienced hackers. Often enough, cybercriminals find easy access to other systems because administrators have neglected necessary software updates for years. 

Hackers can move quickly, Dirro warned
Do not underestimate malware programmers, warns Toralv Dirro, a security strategist at McAffee, a company that offers antivirus and anti-spyware software. Such programmers are highly adept and use every security breach they can find.

Hackers in Eastern Europe, for example in Russia, are seen as particularly diligent, Dirro says, adding that malware programmers there even compete with one another. Their work is so good that one doesn't have to be a computer whiz to get started with Internet crime, he says. "It's better if you know Russian, that is helpful in certain forums," Dirro said. "Everything else, you can buy."

Today's cybercriminals buy software tools - ready-made "crime packages" - to create their very own high-end Trojans. If the hackers don't succeed in letting their virus loose on humanity, Dirro says, they can buy that service for just a few hundred dollars online.

Millions of new viruses, Trojans and computer worms

Every day, about 100,000 new Trojans are unleashed on the Net, according to Dirro. There is no lack of providers offering server space for criminal activities, either. So-called bulletproof hosters are available not only in Russia, but also in the US, Germany, Switzerland, the Netherlands and many other countries. "The providers ask no questions, and if there are too many complaints, [the hosters] get a new IP address," Dirro said.

Thomas Tschersich, head of Group IT Security at Deutsche Telekom, warned that since criminals take advantage of security holes as soon as they arise, the Internet sits wide open to them. For this reason, the fight against cybercrime has to be simultaneously undertaken by all those involved, he added. Internet service providers can systematically monitor data flows for malware to the end device, but require the consent of customers.

Tschersich thinks the legal framework needs to be expanded. So-called deep packet inspection should be utilized, he thinks, but he says customer privacy should also be protected.

Crash tests for new computers

Tschersich promoted a regulatory solution
Tschersich also called on computer manufacturers to improve the situation. "Imagine if you buy a car without brakes, a seatbelt or airbag," he said, comparing the IT world to the automotive industry. Instead, he suggests customers be offered computers that have already passed a "crash test" against viruses.

However, this is made more complicated by the ease with which computers can be networked - computers nowadays sit in a thick network of smartphones, digital televisions, networked printers, alarm systems and much more. All of these devices depend on the Internet, and they are all susceptible to malware.

That's why McAffee strategist Dirro thinks less is more. "Do I really need a digital refrigerator that can automatically restock the milk, or place an order for more salmon?," he asks. Because, he continues, such a device might tempt a determined hacker to send a refrigerated truck to your home full of milk and three tons of fish.