Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Saturday, December 27, 2014

U.S. Cybersecurity Expert Calls Sony Hack an Inside Job

Dec 26, 2014
By: Rachel Blevins
Source: benswann.com

Following the major hack on Sony Pictures, some experts in the United States are skeptical of the FBI’s claim that North Korea is responsible.
Instead of blaming Pyongyang for the hack, the Cybersecurity firm Norse, based in California, believes that the hack was actually an inside job, led by a former Sony employee identified as “Lena.”
On Wednesday, a senior vice president of the Norse firm, Kurt Stammberger, told CBS News that the firm’s investigation has led them to believe that the Sony hack was so devastating, it was something that could have only been accomplished by someone on the inside.
“Sony was not just hacked, this is a company that was essentially nuked from the inside,” said Stammberger. “We are very confident that this was not an attack masterminded by North Korea and that insiders were key to the implementation of one of the most devastating attacks in history.”
Stammberger identified the main hacker as a woman who calls herself “Lena,” claims she is connected to the “Guardians of Peace” hacking group, and was a Sony employee in Los Angeles for ten years, before leaving in May 2014.
“This woman was in precisely the right position and had the deep technical background she would need to locate the specific servers that were compromised,” Stammberger said.
The FBI released a statement last week, blaming the breach on North Korea:
“Technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korean actors previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks. The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. Government has previously linked directly to North Korea.”
Stammberger contested the claim, saying that any clues leading in that direction, such as the malware used to attack Sony having been used by North Korea before, have been easily ruled out by his firm, due to the fact that the same malware is used by hackers worldwide daily.
“There are certainly North Korean fingerprints on this but when we run all those leads to ground they turn out to be decoys or red herrings,” Stammberger said.
The massive hack on Sony came shortly before the company’s release of the movie “The Interview.”  While the movie’s plot involved an assassination attempt on the leader of North Korea, Kim Jong-un, CBS News reported that the “original demand of the hackers was for money from Sony in exchange for not releasing embarrassing information,” and that there was “no mention of the movie ‘The Interview.‘”

Saturday, April 12, 2014

Critical Security Bug 'Heartbleed' Hits Up To 66 Percent Of The Internet





As much as 66 percent of the web may have been compromised by a newly revealed security flaw called Heartbleed.

So named by the researchers who discovered it, Heartbleed is a bug that affects an important Internet security protocol called SSL. Specifically, it affects one particular implementation of SSL called OpenSSL.
For context (and to understand how bad Heartbleed is), here's how SSL and OpenSSL work: Every time you log into a website, your login credentials are sent to that website's server. But in most cases those credentials aren't simply sent to the server in plain text -- they're encrypted using a protocol called Secure Sockets Layer, or SSL.

As with most protocols, different software makers have created different implementations of SSL. One of the most popular is an open-source implementation called OpenSSL, used by an estimated two thirds of currently active websites.

Heartbleed is a bug in OpenSSL. Hackers can exploit Heartbleed to get raw text from emails, instant messages, passwords, even business documents -- anything a user sends to a vulnerable site's server.
And the scariest part? The Heartbleed security flaw existed for nearly two years before it was discovered by legitimate researchers. That's plenty of time for black-hat hackers to have discovered and exploited the bug.
So what can users do? Matthew Prince, CEO of content delivery network Cloudflare, one of the first businesses to be notified of the bug, told The Huffington Post that sadly, there's not much normal netizens can do to protect themselves. "When you finish using a website, make sure to actively log out," Prince advised -- that makes it less likely that a hacker exploiting Heartbleed will be able to take your personal information.
Prince also put in a word of comfort: "Heartbleed is so serious -- it's such a big, bad event -- that almost every major service is scrambling to clean it up as quickly as possible." He estimated that most currently vulnerable websites will be "patched" by the end of the week.

Though a number of major websites have already been patched, others, including OKCupid, Flickr, Imagur and Yahoo.com, reportedly remain vulnerable to Heartbleed.

Users can test if their favorite websites are vulnerable here, though this service is reportedly not 100 percent reliable. Vulnerable sites should not be logged into until they're patched -- check those sites' blogs or Twitter feeds for updates -- and once a website has its patch in place, you should change your password for that site as soon as possible.

Link:  huffingtonpost.com/2014/04/08/heartbleed-66-percent_n_5112793.html.

Wednesday, March 5, 2014

Windows XP diehards aren’t going quietly





Microsoft has a problem: It desperately wants any remaining Windows XP users to upgrade to a newer version of the operating system but a huge chunk of them still haven’t budged. The latest numbers from NetMarketShare show that Windows XP still accounts for around 29.5% of all desktops in use even though Microsoft is due to end support for the 13-year-old platform on April 8th. ZDNet reports that Microsoft plans to pester remaining XP holdovers starting next week by sending them pop-up notifications reminding them — again — that it will end XP support within a month.

However, as Computerworld reports, Microsoft may have a tough time convincing some Windows XP users to upgrade because it’s trying to sell them on Windows 8, the hugely polarizing operating system that has angered many longtime PC users by eliminating the traditional Start menu and by adding the touch-centric Live Tiles interface a staple feature. Computerworld writes that many Windows users expressed anger last month when Microsoft asked them to help switch as many people as they could from Windows XP to Windows 8.1 in part because Microsoft hasn’t offered any sort of discount for Windows XP users making the switch.

This is particularly irksome, these users said, because switching from XP to Windows 8.1 won’t just require a software upgrade but will instead likely force them to buy new machines capable of running Microsoft’s new touch-centric OS. Some users were also annoyed that Microsoft only mentioned Windows 8.1 and not Windows 7 as upgrade possibilities.

In the end, it looks like when Microsoft ends support for Windows XP next month there will still be a huge chunk of the desktop PC world using the platform. Hackers who have been saving up all their best new malware for the day when Windows XP support ends are about to have a field day.

Thursday, February 20, 2014

Here's Why Microsoft 'Forced' Windows 8 On People, According To A Redditor Who Says He Helped Design It






Microsoft

Microsoft CEO Satya Nadella

As has been made abundantly clear by now, Windows 8 is not a success for Microsoft. Or to quote Paul Thurrott of the influential Supersite for Windows blog, "Windows 8 is a disaster in every sense of the word."
This really should surprise no one. Microsoft did an almost obscene level of user testing as it was developing Windows 8 – 1.24 billion hours of testing across 190 countries, Microsoft said. 

And throughout all that, users, as well as influential Windows bloggers, told the company repeatedly that they didn't like the new touch-screen interface.

The question is, what is Microsoft's new CEO going to do about it? We are hoping the answer is "scrap it and try again," and not "dig in and insist the world learn to love Windows 8."

But a long post on Reddit from a person claiming to be on the Windows 8 design team might be a worrisome sign.

Remember, Windows 8 has two personalities. It has a "desktop" side, which is basically a version of Windows 7. It also has the Windows 8 side designed as a touch screen. 

When you buy a new Windows 8 PC, the default is to boot to the Windows 8 side. At first, you couldn't turn that part off and choose to use the Windows 7 side exclusively. Now, with Windows 8.1, you can, but the setting that lets you boot to Windows 7 is kind of hard to find.

This person says the reason Microsoft "forced" Windows 8 on people by default was because the company thought it was easier to use for the average PC user:

Metro is a content consumption space. It is designed for casual users who only want to check Facebook, view some photos, and maybe post a selfie to Instagram. It's designed for your computer illiterate little sister, for grandpas who don't know how to use that computer dofangle thingy, and for mom who just wants to look up apple pie recipes. It's simple, clear, and does one thing (and only one thing) relatively easily. ... So we forced it upon them. We drove them to it with goads in their sides.

The problem is that Windows 8 isn't easy to use, particularly for casual users. It has commands and features tucked into all sorts of confusing spots. For instance, sometimes a flick up while in Internet Explorer brings up a list of open tabs. Other times that same gesture brings up a list of frequently used websites.

The self-described Microsoft designer recognizes that Windows 8 isn't perfect for average users. But this person thinks Microsoft is sticking with the basic plan.

Right now we still have a lot of work to do on making Metro seem tasty for those casual users, and that's going to divert our attention for a while. But once it's purring along smoothly, we'll start making the desktop more advanced.

In April, Microsoft will host its annual developers conference, Build, and we hope to hear more details about Windows 9. We're hoping that Windows 9 is to Windows 8 what Windows 7 was to Vista: a seriously big fix.


UX designer for Microsoft here.

I want to talk about why we chose Metro as the default instead of the desktop, and why this is good in the long run - especially for power users.

...but not in the way you might think.

At this point you're probably expecting me to say that it's designed for keyboard execution, or some thing about improved time trials for launching programs, or some other way of me trying to convince you that Metro is actually useful. I've talked about those in the past extensively on reddit, but for this discussion let's throw that all out the window. For this discussion, assume that Metro is shit for power users (even if you don't believe it to be).

Now that we're on common ground, let's dive into the rabbit hole. Metro is a content consumption space. It is designed for casual users who only want to check facebook, view some photos, and maybe post a selfie to instagram. It's designed for your computer illiterate little sister, for grandpas who don't know how to use that computer dofangle thingy, and for mom who just wants to look up apple pie recipes. It's simple, clear, and does one thing (and only one thing) relatively easily. That is what Metro is. It is the antithesis of a power user. A power user is a content creator. They have multiple things open on multiple monitors - sometimes with multiple virtual machines with their own nested levels of complexity.

"But wait," you're thinking, "You said Metro is good for power users, yet now you're saying it's the worst for them, what gives?"

Before Windows 8 and Metro came along, power users and casual users - the content creators and the content consumers - had to share the same space. It was like a rented tuxedo coat - something that somewhat fit a wide variety of people. It wasn't tailored, because any aggressive tailoring would make it fit one person great, but would have others pulling at the buttons. Whatever feature we wanted to add into Windows, it had to be something that was simple enough for casual users to not get confused with, but also not dumbed down enough to be useless to power users. Many, MANY features got cut because of this.

A great example is multiple desktops. This has been something that power users have been asking for for over a decade now. OSX has it, Linux has it, even OS/2 Warp has it. But Windows doesn't. The reason for this is because every time we try and add it to the desktop, we run user tests; and every time we find that the casual users - a much larger part of our demographic than Apple's or Linux's - get confused by it. So the proposal gets cut and power users suffer.

Our hands were bound, and our users were annoyed with their rented jackets. So what did we do? We separated the users into two groups. Casual and Power. We made two separate playgrounds for them. All the casual users would have their own new and shiny place to look at pictures of cats - Metro. The power users would then have free reign over their native domain - the desktop.

So why make Metro the default? And why was there no way to boot to desktop in Windows 8.0?

The short answer is because casual users don't go exploring. If we made desktop the default as it has always been, and included a nice little start menu that felt like home, the casual users would never have migrated to their land of milk and honey. They would still occupy the desktop just as they always had, and we would have been stuck in square one. So we forced it upon them. We drove them to it with goads in their sides. In 8.1, we softened the points on the goads by giving users an option to boot directly to desktop.

Now that the casual users are aware of their new pasture, we can start tailoring. It will be a while before the power users start seeing the benefits of this (that's why I said they'd benefit in the long run). Right now we still have a lot of work to do on making Metro seem tasty for those casual users, and that's going to divert our attention for a while. But once it's purring along smoothly, we'll start making the desktop more advanced. We'll add things that we couldn't before. Things will be faster, more advanced, and craftier than they have in the past - and that's why Metro is good for power users.



Turkey president signs controversial Internet law into force



Ankara (AFP) - Turkey's president, Abdullah Gul, said Tuesday he had signed into force a controversial law voted in by the government that would tighten controls over web use.

Gul said on his Twitter feed he promulgated the law -- which the opposition and rights groups say infringes on citizens' freedoms -- after the government assured him it would soften parts of it through later amendments.

"I am aware of the problems mainly on two points.... These concerns will be taken into account in the new law," he said.

An opposition lawmaker earlier confirmed the planned amendments to aspects of the bill concerning some powers of Turkey's telecommunications authority.

"The steps are positive but not enough," Akif Hamzacebi of the Republican People's Party (CHP) was quoted as saying by NTV television.

Under the bill, the Telecommunications Communications Presidency (TIB) can demand that Internet providers block pages deemed insulting or considered an invasion of privacy.

But the government is now proposing that the TIB will have to inform a judge about any decision to block a web page, according to the Hurriyet newspaper.

The judge would then have to issue a ruling within 48 hours or the TIB move would be deemed invalid.
The Internet bill has sparked outrage both at home and abroad and fuelled concerns over the state of democracy in the EU-hopeful country under Prime Minister Recep Tayyip Erdogan.

The legislation came on top of moves to curb the judiciary and a government purge of police and prosecutors in the face of corruption probe that has targeted close Erdogan allies.

Erdogan has vehemently denied accusations of online censorship, and said Tuesday the proposed Internet curbs were aimed at countering "blackmail" and "threats". 

"The Internet will not be censored, freedoms will not limited," Erdogan told his lawmakers from his ruling Justice and Development Party (AKP) in parliament.

He said the number of Internet subscribers in predominantly Muslim Turkey had swelled to 34 million from 20,000 since the AKP came to power in 2002. 

Defenders of the law say the new restrictions protect individual rights while critics argue they amount to nothing more than a fresh assault on freedom of expression and an attempt to stifle dissent.


Tuesday, September 11, 2012

DDoS attack on GoDaddy takes down millions of websites; Here's how to receive urgent alerts from NaturalNews even if DNS is attacked or seized

September 10, 2012
by Mike Adams
Source: Natural News

(NaturalNews) A massive DDoS attack struck GoDaddy's name servers today, temporarily plunging thousands of websites into the internet abyss. "GoDaddy, the massive Web hosting company, went down on Monday, taking an untold number of websites with it," reported CNN.

Mashable.com reported, "The more problematic part is that any domain registered with GoDaddy that uses its nameservers and DNS records are also down. This means that even if you host your site elsewhere, using GoDaddy for DNS means it is inaccessible."

PC World reports: "In a YouTube video (http://www.youtube.com/watch?v=SPGBZWGUE2g), secretive hacking group Anonymous has taken credit for the outage, claiming the move is a reaction to the company's support of the U.S. government's efforts "to censor and control the Internet," through its support of the Stop Online Privacy Act (SOPA)."

But claiming Anonymous did this attack may be false, it turns out. The apparent attacker said, himself, that he was not affiliated with the Anonymous collective:

"It is not Anonymous collective it's only me. Don't use Anonymous collective name on it, just my name," wrote Twitter user Anonymous Own3r. (http://www.foxnews.com/tech/2012/09/10/every-godaddy-registered-site-...)

Most likely scenario? A false flag cyber security attack in order to provide the excuse for Obama to sign a freedom-killing executive order focused on "cyber security."

The attack has taken down GoDaddy's website, DNS servers, phone support and email accounts. It's almost as if a nuclear bomb went off at GoDaddy headquarters. This attack appears to be hugely successful from the point of view of Anonymous hackers, although it's not clear why GoDaddy was targeted in particular.

GoDaddy manages 48 million domains spanning more than 9 million customers. The failure of its DNS likely means that millions of websites were taken offline.

Domain Name Servers are a known vulnerability
Domain Name Servers are a well-known vulnerability of the internet infrastructure. As this attack by Anonymous has masterfully demonstrated, DNS provides a centralized single point of attack that, if penetrated, can bring down literally millions of websites.

DNS also provides a single point of government seizure, where rogue governments that hate free speech can take control over websites by commandeering their DNS records.

For these reasons, you need to know how to reach NaturalNews.com even if DNS is compromised

There is a workaround to DNS. You can bypass it and go straight to NaturalNews by simply entering the following "IP address" into your browser:

174.132.185.226

This is the equivalent of typing "NaturalNews.com" into your browser and it will work even if Domain Name Servers are being hacked or seized. This IP address will take you right to our website. It is our "digital address" recognized by all web browsers.

WRITE THIS NUMBER DOWN on a piece of paper and carry it in your wallet or purse. Even if the Domain Name Servers are illegally seized by the government in an assault on the freedom of the press -- or if they're brought down by hackers as was demonstrated today -- you can still use the IP address to reach us.

If NaturalNews.com appears to be unreachable during a crisis event, revert to using the numbers instead of the name, and the site will likely respond.

An even better way: Subscribe to our email newsletter
An even better way to make sure you can hear from us is to subscribe to our FREE email newsletter (see subscription form below).

Email is virtually impossible for anyone to block. Unless there's a nuclear holocaust or something, we will always be able to email you with the latest alerts and information, even if our web servers are hacked or physically taken offline.

Even if you don't want to read our email newsletter each day, simply staying subscribed is valuable because we will be able to reach you with urgent alerts about what's really happening.

We don't sell email addresses to anyone. Your privacy is completely protected, and you can unsubscribe at any time. Subscribing to our email newsletter is your way of allowing us to reach you even in a crisis, a seizure, or a hack attack.


Wednesday, June 29, 2011

Government censorship of Internet to increase, warns Google

28 June 2011
Source: New Media and Search

Google chief says the censorship is to get worse, and he fears for his employees safety across the world

Government censorship of the Internet is set to increase as heads of governments feel that civil society is using new technologies for pro-democracy movements, according to Google chairman Eric Schmidt.

This increase of states cracking down harder on Internet freedoms could be due to the recent Arab Spring movement, where Pro-democracy protesters in Tunisia, Egypt and several other Arab states have used Google owned Facebook and Youtube.

Stating that some governments wanted to regulate the Internet as they regulated television, Eric Schmidt said he feared his colleagues in such countries faced a mounting risk of occasional arrest and torture.

Without directly naming the countries, Schmidt also said he was concerned about the danger faced by employees of the company in parts of the world that deemed found illegal material on its search engine.

Schmidt said, "The reason is that as the technology becomes more pervasive and as the citizenry becomes completely wired and the content gets localised to the language of the country, it becomes an issue like television."

"If you look at television in most of these countries, television is highly regulated because the leaders, partial dictators, half dictators or whatever you want to call them understand the power of television imagery to keep their citizenry in some bucket," he added.

Speaking at summit on militant violence organised by Google in Dublin, Schmidt said he believed the "problem" of governments trying to limit Internet usage was going to "get worse".

The Chinese government and Google have regularly argued over attempts made by the government to limit public access to the search engine's Internet services.

An effort to steal the passwords of hundreds of Google email account holders, including U.S. government officials, Chinese human rights advocates and journalists was unearthed by Google this month. However, China has denied its involvement on the issue.

Thursday, February 3, 2011

Egypt’s Internet Kill Switch: Coming To America

January 28, 2011

Steve Watson
Infowars.com

In response to widespread protests and mass unrest, the authoritarian Egyptian government has completely shut down the country’s access to the internet, eliminating the use of social networking websites, other effective tools of communication and organisation, and effectively sealing Egypt off from the rest of the world.

Internet intelligence authority Renesys has confirmed that “virtually all of Egypt’s Internet addresses are now unreachable, worldwide.”

“At 22:34 UTC (00:34am local time), Renesys observed the virtually simultaneous withdrawal of all routes to Egyptian networks in the Internet’s global routing table. Approximately 3,500 individual BGP routes were withdrawn, leaving no valid paths by which the rest of the world could continue to exchange Internet traffic with Egypt’s service providers.” Renesys’ analysis states.

Vodafone said in an emailed statement: “All mobile operators in Egypt have been instructed to suspend services in selected areas. Under Egyptian legislation, the authorities have the right to issue such an order and we are obliged to comply.”

Prior to the complete shut down, tweets and live mobile phone feeds from the Egyptian protests in Suez and Cairo were providing up to the minute coverage. Links to photos on Twitpic, videos on YouTube and postings on Facebook were aiding protesters organize their movements.

As The Electronic Freedom Foundation notes, “When protestors in Cario’s Tahir Square experienced an outage in cell phone data service, nearby residents reportedly opened their home Wi-Fii networks to allow protesters to get online.”

The Egyptian authorities could not stand for this. Following the revelation of Associated Press footage showing a protester being shot dead in the street, one of at least eight victims who have been killed since the uprising began, an apparent Internet kill switch was thrown.

The action is unprecedented in Internet history. It is clearly the action of a desperate tyrannical government on its last legs.

Egyptian President Hosni Mubarak’s government is also reportedly arresting bloggers, attacking journalists, and rounding up anyone else the regime sees as dissidents.

Still, the Obama administration, which currently funnels $1.3 billion in military aid to the Egyptian government per year, refuses to condemn the Mubarak regime, and further more, is looking to embrace the exact same internet control mechanism in America.

Indeed, when Senator Joe Lieberman attempted to justify draconian legislation that would provide President Obama with a figurative kill switch to shut down parts of the Internet indefinitely, he cited the Communist Chinese system of Internet policing as model which America should move towards.

“Right now China, the government, can disconnect parts of its Internet in case of war and we need to have that here too,” Lieberman told CNN’s Candy Crowley last June.

Of course, the Chinese government routinely shuts down the already heavily filtered internet at any politically sensitive time, not only “in case of war” as Lieberman claims. Furthermore, Twitter, Facebook and Youtube are all permanently banned.

News websites in China now require users to register their true identities in order to leave comments, so that any dissident can be tracked and appropriately dealt with. A truly frightening Orwellian reality you may think, yet this exact move towards abolishing Internet anonymity and creating a virtual ID card is a key centerpiece of the US government’s cybersecurity agenda.

The ‘Protecting Cyberspace as a National Asset Act’ (PCNAA), which now includes a removal of all judicial oversight, is still circulating and will be voted on later this year. Lieberman has stated that the legislation should be made a top priority.

Stock up with Fresh Food that lasts with eFoodsDirect (Ad)

The recent actions of the Egyptian government in the face of widespread public backlash, and the ongoing stifling of the free flow of information in China should provide a stark warning to Americans that such Internet control mechanisms are the tools of oppressive authoritarian governments and have no place in a free society.

Related Reading: New Bill Gives Obama ‘Kill Switch‘ To Shut Down The Internet

Related Reading: Obama Can Shut Down Internet For 4 Months Under New Emergency Powers

Related Reading: Lieberman’s Model For America: Purging The Internet of Dissent

—

Steve Watson is the London based writer and editor for Alex Jones’ Infowars.net, and Prisonplanet.com. He has a Masters Degree in International Relations from the School of Politics at The University of Nottingham in England.

Friday, April 30, 2010

Defense, Facebook One and the Same

By Bob Brewin 04/29/10 01:51 pm ET

While the average Facebook employee probably does not meet Defense Department attire or haircut standards, Defense Deputy Secretary William J. Lynn III told a group of Facebookers at the company's headquarters in Palo Alto, Calif., on Wednesday that he viewed the two cultures as congruent.

In a sign that social media has been embraced by an at-first-reluctant Defense Department, Lynn told the employees, "You're very much a part of our world." He then added, "We're also very much a part of your world. We use social media just as other organizations do. It's a critical element for us."

Lynn is visiting Silicon Valley companies on his road trip, and he told Facebook workers that Defense needs a few good force-multiplier ideas from commercial pioneers.

Who would have thunk that a top Defense official would view Facebook and its technology as a force multiplier?