Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Friday, October 22, 2021

Internet is the biggest opportunity. But also the biggest threat to democracy.




The internet allows to deliver information but also manipulate it in a new way. Internet is allowing that people can communicate straight with politicians. And let them know bout the difficulties and needs of society. But the same thing allows hostile actors to take contact straight with political leaders and offer them something. 

Or the hostile actor can introduce the research. That kind of faked research can tell that most people want something that is against the national interest. That thing can make simply introducing the faked polls. There is the possibility that there is no poll at all. And those kinds of things are affecting the politicians.


The media companies can be good platforms for cyber attacks. 


The thing that makes international web and social media and media operators a threat to democracy and national security is that they can act as a platform for the operations of the GRU and other intelligence services. Social media channels can use for collecting information. 

The GRU agent might just ask people where they or their family members are working. But the regular media can turn the weapon against democracy if they are in the wrong hands. Well-known and trusted media channels can turn into a propaganda factory in seconds. 

The actors like GRU or FSB can just buy media houses by using some covert company. And then they can replace the entire crew with their staff. Then the company starts to send the Russian propaganda. The fact is that the media company can deliver one-sided information on purpose or accidentally. There is a possibility that the sources that reporters use are telling lies. 

But also reporters can be the agents who are telling the version of "truth" that serves their government.  And that thing makes them very good actors in the indoctrination operations that are also called psychological operations or PSY-OPS. 


The new threats to democracy are the governmentally controlled trolls.


We live in the western world. And our world governments are protecting people. If somebody threatens us we might call the police. In the cases of hacking and trolling the police tries to track that actor. And if the actor is in a foreign land. Authorities send international arrest warrants. But then Chinese hackers attacked western facilities. They were tracked and then the Chinese authorities couldn't operate. 

The reason for that was that those hackers operated under the control of the Chinese government and worked for PLA (People's Liberation Army). Also, the cyberattacks that targeted Baltic states did not cause juridical actions in Russia. The reason for that was that the attacks happened under the control of the GRU, Russian military intelligence. 

Those cases have proven that western authorities couldn't predict and react to the situations that hackers operated under governmental control. The same way the Russian troll factory is operating under governmental control. The operator sits in Russia or China and the assistant is bringing the computer to the western world. The hacker or troller uses that remote computer for operations and that makes it difficult to prove. That attacks are coming from outside of borders. That makes it also difficult to deny that kind of attack. Because just closing the connections from those countries is not enough.  


The kill-ware or killing malware is a big threat. Maybe it's just hype, but the threat is still real. In scenarios, the malware is used to cause the disorder. Or give extra time for friendly military operators.


In the worst-case scenario, the malware shuts down the controlling computers of the nuclear power plants. That causes a need to shut down energy production. In some other scenarios, the malware destroys important databases in critical moments. 

The malware destroys the medical databases or databases that are controlling the flight of the missiles. If the users of those missiles recognize that the databases are destroyed. Replacing them requires a couple of minutes and in modern warfare, a couple of minutes is a long time.

Media can also use to deliver malware. The normal media can involve links that will cheat the user to download some software. And that kind of software can be malware. In the worst case, the malware kills people. 

The killing malware is the computer software that can kill people. That malware might be the computer virus that changes the blood types in the hospital. And that thing is the most dangerous situation if somebody needs blood transfer. 

Another version is the computer virus that raises the level of the runways. Or maybe it can shut down the engines of the aircraft and refuse to shut down autopilot. But that kind of malware can also change the programming code of the gas pedal of the automobile. And that means that the system starts to accelerate the car in the wrong place. 

There are many places where the killing malware can affect. In the nuclear or uranium enrichment process, the malware can raise the speed of the centrifuges. And that thing can cause a nuclear explosion in those facilities. The threat of that type of malware. Forces to shut down nuclear power plants. And in those cases, even the threat is enough for losing energy. 


https://arstechnica.com/information-technology/2017/05/an-nsa-derived-ransomware-worm-is-shutting-down-computers-worldwide/

https://blog.malwarebytes.com/cybercrime/2021/10/killware-is-it-just-as-bad-as-it-sounds/

https://securityboulevard.com/2021/10/killware-hype-is-bigger-than-the-threat-for-now/

https://thoughtandmachines.blogspot.com/

Friday, September 3, 2021

Humans are the weakest ring in data security.





Social hacking is the new threat to data security. 


Intelligent firewalls and offensive security are the things that are making the system safe against traditional hacking. But the social hacking where is used voice transformation and virtual actors are the newest tools for hackers. Also, things like chemical interrogation can use for getting information from the users of the systems. 

Can there be safe computers? The answer is that hackers can break all computers and data systems in the world. Even if the system itself is safe, people who are using that system are the weak ring in the chain. The computers and data systems do not make mistakes. Humans are making all errors in the program code. There is possible to ask the confidential information from the users. Not even the best data security can protect the system against human errors. One of the biggest errors is to write passwords in a notebook. 

And then forget that notebook to the table. There is the possibility that the hostile actors are following interesting-looking people like bank workers and their superiorities. And then they just benefit from the moment. Or some office worker or other henchman who is somehow disappointed can deliver that notebook to some MC-gangs. So in that case the security leak is made because of revenge. 

Social hackers can play the team leaders or some kind of system support persons. And that kind of thing can risk all data in the system. Hackers or agents can interrogate people by using chemicals. Or the people can blackmail for giving confidential data of the systems. 

And even if all data travels in quantum channels, the system might be dangered. The hackers can try to slip into the system by using hybrid methods. They might ask for the password of the system from some persons who have access to the data. And then slip into the building by playing cleaners or simply making burglary. The hackers will just slip into the server room and steal a couple of hard disks. That thing means that all systems can be dangered very easily. 


The virtual actors and voice modification systems can danger the data security of the system. 


Data security is the race between people who are protecting systems. And hackers who try to penetrate the databases. The social hacking methods where people are using virtual actors and voice modification are the newest threat to data security. The deep-fake-based actors can try to slip into the net meetings. 

And of course, hackers can try to benefit from things like telephones that are forgotten on the table. They can simply steal the phone and then call in the name of the owner of the phone to the micro support for taking new passwords. In that case, there is not a match between SIM cards. That is stored in the list of people who are allowed to use that service. In those services should be the list of the telephone numbers that are allowed to get service. 

Of course, there is the possibility that people are not following orders. If people just don't care about the orders they mean nothing. Believing something is not the confirmed information. When we are making some rules for making data systems safe we must realize that we must follow that people are acting as there is written in orders. 

In the case of social hacking the operators should sometimes test are the rules followed. They should try to call the new passwords from the unauthorized telephones for seeing that people are looking is that phone number in the list? If the things like passwords are given to every single telephone that is used to call that information the data in the system might be dangered. 

()https://visionsoftheaiandfuture.blogspot.com/

Tuesday, May 14, 2019

The thing about tracking software and private corporations

The thing about tracking software and private corporations


When we are asking some private operator work for our data security, we must realize that those corporations are not always what they claim. That means that sometimes those operators have not able to check the identities of their workers, and here I mean cases where the private operator takes the foreign citizens in their team.

Private corporations have not the same abilities to check backgrounds of their workers than governments have, and sometimes they are facing the situation, that they must hire somebody, and there are only a few suitable coders. In that case, there are only a couple of coders, who has the necessary skills, and then the corporation must make so-called fast recruitment.

In fact in the world of data security, the problem is, that if something reads in the CV that would mean nothing. If the person says that the job is done by using some programming language, that would mean, that this inmate has done anything. And there have been cases, that some "programmer" would be ordered the codes from some friends, and this is the problem for the data security. Those people can call to somebody, who will send the code to the Email, and then they might send the malware accidentally.


One way to make malware, what can pass the firewall is to send the source code by using PDF of some other file, and after that, the contact person just copy-pastes the source code to the program editor, and then the thing is ready. Pressing Ctrl+A and Ctrl+V is very good to take the source code from the document, and then just pressing Ctrl+V the code would be copied to the editor. After that, the user must only create the file, what is able to run and then the software is ready for the run.


Innocence is a pretty thing 


Sometimes we are thinking that some persons are safe because they have limits. This thing is not actually true, because modern electronic equipment has given a chance to make flexible and easily portable screens and communication devices. In fact, even the person, who has ever made code or even opened a computer before can hack by using modern equipment. in this case, the person wears only the action camera, what is in the headset, and mobile telephone. The action camera is connected to the Internet by the mobile telephone, and another telephone can be on the table, and the hacker can send messages, what the operator who is in the house must do.

Or if the team wants to get the feeling of what is a very well known thing from some actions movies, they can use smart glasses, and the hacker can write commands to that screen and follows the things, what is going on the computer screen by using this "remote eye". And on the passage would be the remote camera, what warns the inner operator about the quests like security operators. That camera can be connected to the drone, what just flies out from the window when the operator is gone.

And then the hacker would give the instructions to that person by telling, what must be done. Or if the person, who operates uses the screen like smart glasses, the thing goes more easily, because the hacker can write commands and send them to that screen. Of course, a normal mobile telephone can be done with that and the hacker who watches the screen of the computer from somewhere in distance must only give the person, who operates inside the instructions by using Whatsapp or some other social media solution. In this case, the person, who is in the building is operating as the "human robot".

In those cases, there might be a very big risk, that something disappears, and that "something" might be the source code of the tracking tools of that company. This kind of things is really bad things because by using those code lists the hackers can modify the code, and then make own versions of that malware. This means that the malware maker just renames the program, and changes the addresses, where the system would send the data, and that thing might cause a massive data leak.

This kind of attacks needs the contact person, who has access to the system as the superuser. And in fact, even a handicapped person can make those things, if that person gets the instructions. When we are thinking about the "human robot", we can give that inmate the action camera, and mobile telephone, and then we can give the instructions by using Whatsapp, and that is the situation, what has ever mentioned.

Saturday, April 20, 2019

The crimes are transferring to the Internet


The crimes are transferring to the Internet

Modern bank robberies would not rob banks by treating people with assault rifles. They use electronic data routes, and that thing would make possible to earn even billions of euros in a couple of minutes, and then leave the area by leaving no trace.

The idea of this kind of attack is that every each bank account would be taken only a couple of euros, and that money would transfer to the certain bank accounts. The sum, what those people would take will be so little, that the individual people would not recognize that there would be the robbery.

The bank robbery can happen remotely. 

They would not follow a couple of euros, and that means that the bad guys can steal even billions because they steal little money, but the number of accounts is very large. If the person would steal a couple of euros from million of bank accounts that would mean a couple of million euros transfer of money to the account of that person.

But those persons can be very dangerous. If those hackers would get passwords without violence, that means that they could get very little punishment about their crimes. In the real world in that kind of crimes would involve things like hostage situations and blackmail.

Even if the hackers would not violent themselves, the persons who are behind that kind of operations might be really dangerous. They can threaten the family of the key persons, that they would give the passwords to the criminals, who would transform the money into their accounts.

Terrorists can also benefit the Internet in their operations

Terrorists can benefit the Internet as a communication channel. But the Internet allows very potential operation area for some kind of data viruses, which can format the databases of the computers. That thing might seem very harmless action. But if the databases of the computers of the ships or the airfield would be deleted, could the result be devastating. If the computers would not have a database, they would not able to control the systems.

And that means that the automatized landing procedures are not able to control devices how they should. If the database of the autopilot would not know, how to drive some route, and that would cause the crashes. The thing is that some hackers would program the logic bomb what is the computer virus, which will be activated in the certain day. That thing is that if the person would not pay the prize, the virus will be activated.

In the worst situation, that kind of strike would be targeted to nuclear power plants. Or otherwise, those terrorists would destroy the databases, what involve the information of the blood types of people. And in that case, the results can be devastating. Of course, some hackers can also mess the entire traffic system by turning all lights green at the same time, and that thing can cause accidents, what will cost lives.

The traffic chaos caused by the multiple cars smashes can also slow things like ambulances in the critical moments. if the attack is targeted to electric support, that can cause very bad situations in places like hospitals and prisons. In fact, that kind of things can be very dramatic, if the entire electric network would shut down, many of the vital functions in western society will be facing collapse. And use your own imagination, if the power system would shut down, telephones and the Internet don't work, and every single vehicle, what uses the electricity would not operate a long time, because they cannot load from the loading stations.

Computer viruses can terminate the entire command system

The computer viruses can slip in the data network, and that thing would cause terrible damages if it activates at the same time when the enemy is attacking. That kind of viruses can destroy temporary the data systems of the communication satellites, and rebooting those computers and switching to a backup system would cost a couple of important minutes, and that is a very long time during the missile attack.

But if the system's databases would be destroyed that IFF (Identification Friend or Foe) cannot separate own aircraft and ground troops from the enemy. This means that the fire support will target their own troops. That can be very devastating for own troops because the aircraft cannot give fire support and their own anti-aircraft missiles and cannons would shoot own aircraft.

Computers are in a vital role in military communication

Military communication systems including satellites are in the extremely important role in controlling the military operations. The drones and need for ammunition are transmitting by using a global communication system, which allows the headquarters to communicate straight with the field troops. The system what is basically similar to the normal Internet shares text, images, films, maps and other important data for the field operatives, and without computers that communication is impossible. And also coding the speak, and transforming the speak to text, where the operators can see, what has been talked needs computers. And without computers, those systems would be unable to operate.

Around the Earth is orbiting multiple communication satellites. Those satellites connect the information, what the intelligence collects by using spies, reconnaissance aircraft and sensors, what would be the position, where radio signals are coming. If the command system would not get that data, it cannot target the airstrikes and other use of fire in the right position.

That system is extremely important when the tactical information is shared between the field troops and headquarters, which will target the airstrikes in the right positions at the right time. But that satellite system is communicating with the nuclear submarines and other particles of the nuclear strike capacity, and that means that in the critical moment the nuclear missiles would not get the launching codes if those satellites will not able to communicate with the nuclear missile launching systems.

Six clicks separate people from each other.

“A long-observed social phenomenon suggests that people across the globe are separated by surprisingly few connections. Credit: Stock” (Scit...