Category Archives: Internet Security

Cyberattack Aftershock Feared as US Warns of Its Complexity – New York Times


New York Times
Cyberattack Aftershock Feared as US Warns of Its Complexity
New York Times
Five businesses in South Korea reported ransomware attacks over the weekend, according to the government's internet security agency, and a Korean theater chain said late-night moviegoers on Sunday alerted them when computer ransom notes appeared ...
Log in, look out: Cyber chaos spreads with workweek's startWCBI
Don't WannaCry? Protect yourself from ransomwareThe Star Online
Live updates: Latest on international cyber attackITV News
Telegraph.co.uk
all 413 news articles »

View post:
Cyberattack Aftershock Feared as US Warns of Its Complexity - New York Times

The Latest: 29000 Chinese institutions hit by cyberattack – ABC News

The latest on the global extortion cyberattack that hit dozens of countries on Friday (all times local):

4:50 a.m.

Chinese state media say more than 29,000 institutions across China have been infected by the global "ransomware" cyberattack.

Xinhua News Agency reports that by Saturday evening, 29,372 institutions had been infected along with hundreds of thousands of devices. It cited the Threat Intelligence Center of Qihoo 360, a Chinese internet security services company.

It says universities and educational institutions were among the hardest hit, numbering 4,341, or about 15 percent of internet protocol addresses attacked. Also affected were railway stations, mail delivery, gas stations, hospitals, office buildings, shopping malls and government services.

Xinhua says the system used by PetroChina's gas stations was attacked, meaning customers could not use their cards to pay. Most stations had recovered.

4:45 a.m.

Japanese companies say they are working to overcome the problems caused by a global "ransomware" cyberattack.

Nissan Motor Co. confirmed Monday some units had been targeted, but it had responded and there has been no major impact on its business.

Hitachi spokeswoman Yuko Tainiuchi said it was experiencing email delays and file delivery failures and suspected the cyberattack was at fault, even though no ransom was being demanded. Programs were being installed to fix the problem.

Broadcaster NTV reported 600 companies and 2,000 computers in Japan had been affected. Overall the attack has created chaos in 150 countries

The initial attack, known as "WannaCry," paralyzed computers that run Britain's hospital network, Germany's national railway and other companies and government agencies worldwide in what's believed to be the biggest online extortion scheme ever.

2:30 a.m.

The Indonesian government is urging businesses to update computer security after two hospitals were affected by a "ransomware" cyberattack that has hit dozens of countries.

The director-general of Indonesia's Communication and Information Ministry says in a statement that the malware locked patient files on computers at the affected hospitals, both in the capital Jakarta.

Local media reported Monday that patients arriving at Dharmais Cancer Hospital on the weekend were unable to get queue numbers and had to wait several hours while staff worked with paper records.

The ministry has announced specific measures that organizations can take to counter the "WannaCry" attack including a specific update to Microsoft operating systems.

12:20 a.m.

Microsoft's top lawyer is laying some of the blame for Friday's massive cyberattack at the feet of the U.S. government.

Brad Smith criticized U.S. intelligence agencies, including the CIA and National Security Agency, for "stockpiling" software code that can be used by hackers. Cybersecurity experts say the unknown hackers who launched this weekend's "ransomware" attacks used a vulnerability that was exposed in NSA documents leaked online.

In a post on Microsoft's blog, Smith says: "An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen."

Microsoft's lawyer says governments should "report vulnerabilities" that they discover to software companies, "rather than stockpile, sell, or exploit them."

10:30 p.m.

Britain's National Cyber Security Center has joined others in warning that more cases of "ransomware" attacks may come to light as a new work week starts Monday.

The organization predicts that the problem could be "at a significant scale" because some infected machines haven't yet been detected, and existing infections can spread within networks.

It said Sunday that a similar cyberattack could also recur, though it did not have "specific evidence" of this.

The warning echoed that from Europe's policing agency earlier Sunday. Europol that said the malware has claimed some 200,000 victims across 150 countries and that the numbers are still going up. Officials urged organizations and companies to immediately update their security software.

8:45 p.m.

An executive at a cybersecurity firm that helped block a global ransomware attack says new variations of the malicious worm are circulating and researchers expect one to develop that can't be stopped.

Ryan Kalember, senior vice president at Proofpoint Inc., says that millions of devices could be vulnerable if they haven't applied security patches over the weekend.

He says if a new variant without a so-called kill switch pops up, then organizations will be on their own to prevent it from taking over their computers.

Proofpoint and a British cybersecurity researcher teamed up Friday to derail the attack that was said to strike at least 100,000 organizations in 150 countries.

It is believed to be the biggest online extortion ever, hitting British hospitals, German rail and companies and government agencies.

6 p.m.

The former U.S. national intelligence director says the global "ransomware" attack could grow much larger when people return to work.

James Clapper told ABC's "This Week" on Sunday that he expects similar attacks to become a growing problem in the future.

Europe's police agency says the attack has hit at least 100,000 organizations in 150 countries.

It is believed to be the biggest online extortion recorded. It spread cyber chaos worldwide, hitting Britain's hospital network, Germany's railway and scores of companies and government agencies.

Clapper and Europol say the scope of the problem may become bigger Monday when people switch on their computers.

Clapper, who served as intelligence director under President Barack Obama, calls it a "very serious, serious problem."

Attackers have demanded $300 to $600 to unlock encrypted files.

11:40 a.m.

Europol, the European Union's police agency, says the international "ransomware" cyberattack has so far hit more than 100,000 organizations in at least 150 countries.

Spokesman Jan Op Gen Oorth said Sunday that the number of individuals who have fallen victim to the cyberextortion attack could be much higher.

He said it was too early to say who is behind the onslaught and what their motivation was. He said the main challenge was the fast-spreading capabilities of the malware, but added that, so far, not many people have paid the ransoms that the virus demands.

He warned that more people may be hit by the virus Monday when they return to work and switch on their computers.

The attack that began Friday is believed to be the biggest online extortion attack ever recorded, with victims including Britain's hospital network and Germany's national railway.

10:40 a.m.

Chinese media are reporting that the global "ransomware" virus attacked many university networks in China.

The Beijing News said Sunday that students at several universities around the country reported being hit by the virus, which blocked access to their thesis papers and dissertation presentations.

In each case, a pop-up window demanded payments of $300, or about 2,000 yuan, in order to free the files.

The attack that began Friday is believed to be the biggest online extortion attack ever recorded, disrupting computers that run factories, banks, government agencies and transport systems. It crippled the British health care system for a day, infecting nearly 20 percent of its health care groups, forcing medical treatments to be canceled or postponed for thousands of people.

A young British cybersecurity researcher discovered a so-called "kill switch" for the attack, limiting the damage.

6 a.m.

As terrifying as the unprecedented global "ransomware" attack was, cybersecurity experts say it's nothing compared to what might be coming especially if companies and governments don't make major fixes.

Had it not been for a young cybersecurity researcher's accidental discovery of a so-called "kill switch," the malicious software likely would have spread much farther and faster that it did Friday.

This is already believed to be the biggest online extortion attack ever recorded, disrupting computers that run factories, banks, government agencies and transport systems in nations as diverse as Russia, Ukraine, Brazil, Spain, India and the U.S.

Security experts tempered the alarm bells by saying that widespread attacks are tough to pull off. This one worked because of a "perfect storm" of conditions, including a known and highly dangerous security hole in Microsoft Windows, tardy users who didn't apply Microsoft's March software fix, and malware designed to spread quickly once inside university, business or government networks.

Go here to read the rest:
The Latest: 29000 Chinese institutions hit by cyberattack - ABC News

Cyber Security Experts: Russia Disproportionately Targeted by Malware – Voice of America

MOSCOW

Countries across the globe scrambled to respond to a malicious "ransomware" virus, as internet security watchdogs said the attack had disproportionately targeted Russia.

The Russian cyber security firm Kaspersky Labs was among the first to identify the so-called "Wanna Cry" malware a viral worm that exploits a vulnerability in the Windows operating system to encrypt files without users permission.

A group of hackers known as "The Shadow Brokers" are widely believed to have stolen the program from the U.S. National Security Agency last April and deployed it as a means to ransom user data around the world for cash profits.

Kaspersky Labs initially reported 45,000 attacks by the malware in more than 70 countries, with Russia bearing the brunt of the onslaught. The range of targets and victims is likely much, much higher, warned the Kaspersky report.

Within hours, other internet security firms put the number of computers targeted at more than 75,000 computers in 100 countries. Those numbers are expected to grow.

Russian fallout

Russias powerful Interior Ministry and national railway service both confirmed they had fallen victim to the malware. The Russian mobile telecom giant, Megafon, too, issued a statement saying its servers had been compromised.

But by mid-day Saturday, spokesmen from all three said they had successfully isolated the virus and were operating as usual.

The statements came as other key Russian ministries, and the countrys central bank, pushed back against claims state computer infrastructure had been compromised.

In statements to Russian media, all argued they had thwarted the virus using non-Windows operating systems while trumpeting the merits of data backups using a, notably, Russian-made server, Elbrus.

The claims have not been confirmed by outside experts.

Kremlin-net

The Kremlin has long been suspicious of Western technology firms, arguing they work in collusion with American intelligence agencies.

In 2014, Russias Duma passed a law requiring Western tech companies such as Facebook, Twitter, and Google to relocate servers to Russia in an effort to protect Russian user data. Though not yet fully implemented, Russian internet activists have argued the law gives Russian security services dangerous access to private data with little legal recourse.

Russian President Vladimir Putin has also pushed for digital independence from Western tech firms, partially in response to American and European sanctions introduced following Russias annexation of Crimea from Ukraine in 2014.

Sunday, the Kremlins advisor on internet strategy German Klimenko seized the latest cyber attack as a chance to praise those moves.

The presidents order to create a Russian segment of the internet, [it created] a closed Internet solely for government bureaucrats, said Klimenko in an interview with Russias Channel One television.

The defense against attacks has been in place a long time, he added. It is doubtful our [government] data suffered.

NSA connection?

Meanwhile, Russias online community debated the disproportionate targeting of Russia, in particular allegations the virus had originated with the NSA.

But on the Russian-built secure messaging app Telegram, users traded theories the virus was a U.S. plot aimed at disrupting the countrys 2018 presidential elections, apparent payback for U.S. intelligence agencies conclusion Russian hackers had interfered in last years American presidential elections.

FILE - The National Security Agency (NSA) campus in Fort Meade, Md.

But Anton Nossik, a longtime leading internet voice in Russia, rejected those charges as terribly funny in a widely shared post to his Live Journal blog.

That 74 countries were implicated in the virus is explained as Russias enemies desire to hide the real goal of their attack, wrote Nossik, who notes that Russian governmental officials had been too lazy to install a Windows "patch" available since last March that resolved the security flaw.

Really, how can you deceive our ever wakeful conspiracy theorists? he added wryly, To hack their computers is the simplest thing, but to destroy their vigilance? Never!

Other Russian digerati, too, pushed back against the idea that Russia had been a target by design.

"There's no politics or intention here. The virus is just spreading randomly," says Ilya Sachkov, Director of the Moscow-based Group IB, a company that tracks internet fraud, in an interview with Moscow's Business FM radio.

Sachkov notes ransomeware attacks have been growing in number and strength for years.

Snowden, again

The unfolding crisis and alleged links to the NSA again thrust Edward Snowden, the former NSA contractor who was granted asylum in Russia after leaking classified NSA documents to the press in 2013, into the spotlight.

FILE - Edward Snowden, a former CIA worker before turning whistleblower, speaks via satellite at the IT fair CeBIT in Hanover, Germany, March 21, 2017.

In a series of Twitter posts, Snowden argued the NSA bore moral responsibility for the leak.

Despite warnings, the NSA built dangerous attack tools that could target Western software, wrote Snowden. Today we see the cost.

More here:
Cyber Security Experts: Russia Disproportionately Targeted by Malware - Voice of America

Crippling cyberattack continues to spread around the world – Los Angeles Times

A crippling computer virus that invaded computer systems around the globe triggered a wave of aftershocks Saturday, holding data hostage on tens of thousands of computers in what security experts called the largest ransomware attack in history.

The so-called WannaCry virus once again placed the cyberactivities of the U.S. National Security Agency in a global controversy. Experts criticized the spy agency for not only developing a dangerous tool to exploit a vulnerability in Windows computers, but also letting it fall into the hands of criminals.

The ransomware attack secretly searched computers for personal files, encrypted them and then displayed a demand for ransom to release the files.

The virus struck with lightning speed. Cybersecurity researchers had warned that such an event was increasingly likely because aging computer operating systems were not being updated with the latest software protections.

The digital blackmail scheme played on peoples worst fears about the risks of living in a connected world where technology such as autonomous cars and medical devices raise the possibility of far more lethal hacks.

After surfacing Friday, the attack continued to gather momentum.

I dont see how its going to end, said Phil Lieberman, president of Lieberman Software. Theres this list of problems with security that have gone on for the last 10 or 15 years that werent fixed and that people didnt take seriously. And now the bill is coming due.

By Saturday evening in Europe, the cybersecurity firm Avast was reporting that it had recorded a massive peak of WannaCry attacks, bringing the total to 126,000 computers in 104 countries.

Although no corner of the globe seemed immune, Europe initially appeared to be hardest hit, particularly the United Kingdom, where the National Health Service suffered an attack on 48 centers.

The NHS was particularly vulnerable because so many of its systems ran on Windows XP, a version of the operating system Microsoft stopped supporting years ago.

The widespread nature of this attack suggests that organizations are still slow to patch significant vulnerabilities like the one currently being associated with this event, said Travis Farral, director of security strategy at the cybersecurity firm Anomali.

Microsoft took the extraordinary step of issuing software patches this weekend for old versions of Windows, such as XP.

Many of our customers around the world and the critical systems they depend on were victims, the companys security unit wrote in a blog post. Seeing businesses and individuals affected by cyberattacks, such as the ones reported today, was painful. Microsoft worked throughout the day to ensure we understood the attack and were taking all possible actions to protect our customers.

Although the U.K. was hit early, Avast reported that new cases were concentrated in Russia, Ukraine and Taiwan. Russian officials confirmed reports that the nations train system and Interior Ministry had been hit, along with a number of businesses. Infections were also reported in China, as well as by companies and government agencies in Spain, Italy and the United States.

Christy Wyatt, chief executive of the cybersecurity firm Dtex Systems, said the WannaCry virus did not seem to have a specific target. The attack was simply spreading to the most poorly defended computer networks.

When someone is taking a very large swing like this, theyre going to be indiscriminate, she said. Theyre looking for impact.

For those already hit, the options were limited. The hackers have been demanding $300 in electronic money known as bitcoin to regain access to the data. According to the Internet security software firm Kaspersky Lab, about 70 people had paid just over $20,000 into the three bitcoin accounts linked to the attack.

We do not recommend paying the ransom, as this only encourages the criminals to continue their activities, said Costin Raiu, director of Kaspersky Labs Global Research and Analysis Team. Kaspersky said it is working on a solution to allow users to decrypt their information without paying.

The virus appeared Friday, after a week of cybersecurity news.

President Trump on Thursday signed an executive order calling for a review of U.S. cybersecurity assets and defenses. The European Union also released this week a review of progress made under a five-year plan to create a more unified cybersecurity strategy across its 28 member states.

Security experts said the WannaCry attack may shift the debate about privacy and cybersecurity.

Regulatory frameworks are fantastic, said Becky Pinkard, vice president of service delivery and intelligence at the cybersecurity firm Digital Shadows. The problem is that they are slow-moving, and theyre slow to come together. Anything that will come on the back of this will come at a very slow pace.

Security researchers said the NSA is likely to face its greatest scrutiny since the release of the Edward Snowden documents revealing the extent of the agencys spying activities.

Experts were appalled that the NSA had failed to safeguard one of its surveillance tools.

Losing your tools, losing what the government paid you to do, losing your cyberweapons, its a really tragic event thats going to hurt the world, Lieberman said. To have them fall into the hands of criminals is just awful.

The vulnerability that the NSA found in Windows was probably a surveillance gold mine. It gave outsiders almost unhindered access to a computer.

The NSAs discovery of what was code-named EternalBlue was hacked and published in April by a group known as the Shadow Brokers.

In April, Microsoft issued a security patch to plug the vulnerability.

On unprotected computers, the WannaCry virus enters the system and plants software that encrypts information.

The virus generates an encryption key, registered at a remote site on the Internet. Once the location is identified, an alternative version of the site can be set up to trick the virus and prevent the encryption.

Lieberman said there have been two waves of the virus, and both have been blocked this way.

The problem now is that hackers can relaunch another version of the virus with a different destination. The cybercriminals are more likely to seek money from critical infrastructure such as hospitals, utilities and telecommunication companies.

Link:
Crippling cyberattack continues to spread around the world - Los Angeles Times

From the Desk of Jay Fallis: To internet vote, or not to internet vote – BarrieToday

On occasion, when I forget my padlock at home, I have left my gym bag unlocked in the change room. In these instances, I take comfort knowing that most people in my community are honest and would not take my belongings. As of yet, I have not been stolen from. However, continuing this practice might one day have consequences.

This scenario is analogous of implementing internet voting in municipal elections. By exposing our democratic process through online ballot casting and tabulation, we would be at risk of manipulation on a large scale. Our one protection against such criminal action is based on the fact that most of those in our community would not willingly compromise our democratic system.

Over the past few years, many municipalities in the Barrie area have adopted or considered adopting online voting methods. While Barrie itself continues to use electronic tabulators instead of internet voting, Innisfil, Springwater, Oro-Medonte, and Penetanguishene will offer online voting in 2018 municipal elections. This past Monday, Orillia almost followed suit to permit internet voting. However, the Orillia city council narrowly defeated the proposal.

In the days leading up to the vote in Orillia, I talked with Councilor Mason Ainsworth to get a sense for this debate. Ainsworth has been a staunch opponent of internet voting. We started by talking about whether turnout rates might be affected by online voting.

There are a lot of studies out there in regards to the voter turnout of online voting and pretty much all of them say that it doesnt increase turnout. This makes sense because really youre getting the same people who are voting either way.

While there are particular instances where turnout has improved after the implementation of online voting, most studies suggest that online voting does not have the capacity to increase voter turnout. Although access to the polls is improved using these alternative methods, generally speaking, those in the past who do not participate in municipal elections will continue these tendencies under a new voting system.

Additionally, there are significant drawbacks associated with online voting. The first that Ainsworth talked about was voter fraud.

In regards to fraud were not sure, and staff has openly said in the [council] meeting that they wouldnt know if this happened: If somebody else is voting for somebody, he said.

Ainsworth went on to suggest that online voting methods could allow a member of a household to vote on the behalf of another, and that such actions could be carried out with bad intentions. According to Ainsworth, our current system guards against this problem, by obligating voters to mark their ballot in privacy.

Internet hacking was also a consideration for Ainsworth. After being asked about the security measures taken by the Orillia city council, he felt that the plan in place would not be adequate to prevent hacking.

Do we have a whole internet security staff group at City Hall? We dont. We have a couple folks in IT; but we dont have folks who are specifically there to make sure all our stuff is secure.

Although, to date, no Ontario municipalities experimenting with online voting have been hacked, the potential exists, especially without adequate security measures in place. Along with these concerns, Ainsley suggested that there are also problems around the capacity of hackers.

I was reading an article the other day, there was a [sixteen-year-old] student and he hacked Microsoft and Sony, which are two giant major corporations, he said.

This scenario is not a one off. In our conversation, we discussed just a few of the major institutions and elections that had been hacked: the Pentagon, Bitcoin, the 2012 Federal NDP leadership race, and the American Democratic Party. Internet hacking can happen to any institution, no matter the security system in place.

While there could be some benefits to online voting such as access for voters and potential savings for municipalities, there are also risks of large-scale manipulation. Perhaps, as Ainsworth suggested, it is best to wait until adequate security technology for internet voting becomes available down the road. In the meantime, municipalities would be better off experimenting with other alternative voting methods to improve turnout and convenience.

See more here:
From the Desk of Jay Fallis: To internet vote, or not to internet vote - BarrieToday

Decoding Internet Security: Spear phishing – Washington Post


Washington Post
Decoding Internet Security: Spear phishing
Washington Post
May 4, 2017 9:40 AM EDT - Here is what you need to know about spear phishing: a targeted attack hackers use to steal your personal information. (Sarah Parnass, Dani Player / The Washington Post) ...

Follow this link:
Decoding Internet Security: Spear phishing - Washington Post

"Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree – Huffington Post

The story of a Silicon Valley entrepreneur who achieved success at 23 might not raise eyebrows in 2017, but is impressive nonetheless. This is certainly the case when you consider how many companies have crashed and burned and the respective founders whove bounced around since the Internets inception. When you create a company to meet a global need, as David Gorodyansky did, and are recognized as one of Americas most promising CEOs under 35 (https://www.forbes.com/pictures/elld45jgdk/david-gorodyansky-30-anchorfree/#4ae1a8ee337a), your accomplishments are to be lauded, your persistence praised and your mission magnified. The notion that securing your Internet privacy is improving the world may be a debatable one for some, but its what Gorodyanksy set out to do when he founded AnchorFree. The software company provides Hotspot Shield, https://www.hotspotshield.com/, a downloadable free virtual private network (VPN) ensuring that web surfing data is in no way accessible to hackers. To hear him discuss his objectives you might think hes offering unlimited purified air and filtered drinking water to the world. In todays day and age however, its nearly impossible to say his passion is misdirected. Online privacy can improve your life, or at the very least...the next presidential election?

Following is my email interview with Gorodyanksy about achieving success at an early age, founding a company that meets a global need and what hes learned from meetings with Henry Kissinger and Justice Ruth Bader Ginsburg.

SHW: You began your journey knowing that a certain technology needed to be developed to combat a real problem. Tell us about identifying the unmet need, the passion that drove you and how your company stands out in the Internet privacy arena.

DG: Ever since I was really young, I wanted to create an impact and use my energy to help advance the world forward. There are so many start-up ideas that are not important. I wanted to do something that was truly valuable and focus on solving problems that impact at least a billion people. Ive always felt that we are an inherent part of the world. We cannot stand on the sidelines. We need to be involved in building the world we live in and the future we want to see.

I was 23 when I started AnchorFree to provide secure access to the worlds information for every person on the planet. Seeing how quickly our lives were becoming digital, it was clear at the time that online privacy and global connectivity to all of the worlds information would be vital. We built AnchorFrees Hotspot Shield application as a simple way for every person to protect their personal data, i.e. search history and web browsing, and to connect to global content securely without any borders or restrictions. We become the worlds largest Internet Privacy Platform, securely connecting users to friends, family, and information.

The technology we use to power Hotspot Shield is a proprietary VPN (virtual private network) since we saw that only businesses were using VPNs for secure access to their corporate environments. Hotspot Shield was created from scratch specifically to be used by the masses. In the years since, weve responded to those who tried to replicate our technology by welcoming them into our industry. We offer many competitors the opportunity to create competing VPN products using our technology. Today, many large security companies use our technology to provide VPN services to their customers. We have surpassed 500M installs of our Hotspot Shield application and are on track to reach 1B by year end 2018. We are successful because we know what were doing is right and important to the world.

Given that AnchorFree is a mission-driven company, we never log or store user data. Our perspective is to protect the users not only from the bad guys like hackers, identity thieves, websites and ISPs, but to also protect the users from their (/our) selves. We believe the best way to protect user data is to not collect it.

SW: Now that AnchorFree has taken off, what is the biggest challenge you face and how do you overcome it?

DG: There are different challenges at different stages of the companys life. At the beginning, our challenges included finding the product market fit, building the product, getting users, proving the revenue model, assembling a world class board of directors. At later stages, there are operational challenges around hiring and scale and strategic challenges around understanding the next big trends, staying relevant, and continuing to innovate.

I remember raising the first $6M in funding as a 23 year old and it felt great. At that time, I thought funding could solve all challenges but thats not the case. Weve raised $63M in total funding to date and still have challenges like hiring the right people and making sure that everybody at AnchorFree understands goals, expected results and mission. Money doesnt solve all problems. We overcome our challenges by ensuring that everybody in the company understands why they do what they do. Although were inspired by our mission, were measured on our results and the specific numbers we need to achieve. Getting the whole company to understand the WHY behind what we do really helps drive operational results. At the same time, it is important to continue to innovate and look into the future.

I once asked Henry Kissinger over dinner what his advice is for young people wanting to change the world. He answered, Dont get bogged down with what is happening now, focus on what you think will happen in the next 10 years. Every CEO is thinking of how to deliver operation results now as well as how to stay relevant in the coming years. We built a separate team at AnchorFree to focus on new products and innovations only. That team is not involved in operational aspects of the day to day business. They are creating new concepts and filing new patents. The life of a CEO is about balance and priorities and balancing operational goals with future aspirations is key.

SHW: You are 35 now, but you were 23 when this journey began and took off. Did you ever encounter difficulties or resentment due to your youth?

DG: I always felt that being a young CEO was a strength, not a weakness. When starting a company in your 20s you lack the experience, but you have a tremendous amount of energy and inspiration. When I started AnchorFree, I knew that there was a lot that I didnt know. So I put together a Board of Directors and Advisers that helped me in areas where I needed advice and guidance.

It feels great being a young CEO. There is a clear match between zest, inspiration and desire to change the world. Its great to know that youre spending your youth in a way thats important and matters. At the same time, there are challenges such as balancing work and a personal life. Any young CEO should be ready to make their start-up the key thing they do in life. This can, unfortunately, harm other aspects of life that require attention. Over the years, you get better at finding that balance, but it is harder to understand when you are in your 20s.

SHW: Are there challenges with managing older employees and coworkers or has that really been eradicated in 2017? Very often companies talk about old school methods versus new school, but with Silicon Valley and a rising number of Millennial tech geniuses in this country, is that a non-issue today?

DG: You get used to managing people of all ages and realize that just because somebody has more experience than you do, it doesnt mean they know better. I found that there are people of all ages, including older people, that have the same enthusiasm, energy and drive as people in their 20s. The personality of the individual is more important than their age. The new age of the technology industry is making people from all over the world and of all age groups more equal. Suit and tie days are dead. You have 50 year olds and 20 year olds wearing hoodies to work and instead of arguing over who has more experience or a C-level title, decisions are made based on data. Ive been proven wrong enough times by 20-year-old interns to know that it doesnt matter how old you are or what your title is. What matters is how hard you are willing to drive towards your goals, persistence, the ability to prioritize, and being both tactical /detail oriented and strategic. The best employees remember why they do what they do. Theyre also willing to devote the time towards achieving the goals and moving the Company forward.

SHW: You mentioned Henry Kissinger earlier. Can you give me some more details on the feedback you've gotten from other prestigious/famous people about your work?

DG: Ive met with three former Secretaries of State and with the US Supreme Court Justices. Im always intrigued by the wisdom that young people can gain from world leaders. Over dinner with Justice Ginsburg, I asked her what advice she would give young people. She answered, Try the door. If you get to a locked door, keep trying to open it. I asked what she thought was a key lesson she learned from being a Supreme Court Justice and she said the ability to listen. Most people are not good listeners, she explained, but lives depend on how well Supreme Court Justices listen. I found that all the world leaders and icons that Ive met had a real interest in the future and all remained young at heart. The Secretaries of State and Supreme Court Justices alike were obsessed with ideas, not things, specifically ideas about the world and the future.

SHW: Is there a motto you live by or a particular thought that inspires you?

DG: I want to solve real challenges that have the potential to impact a billion people. I want to look back at my life and see I built something that was important and mattered. I want to take part in moving the world forward. We are entering a new era where resources will no longer be limited, they will be abundant. I see the biggest challenges in the world right now around accessibility for people who cant get certain resources. AnchorFree provides access to information and privacy. Others may provide access to clean drinking water, to health care, to education, to global markets. I think providing access to important resources for citizens of the world at large is incredibly worthwhile.

SHW: Where do you see yourself in 10 years? What do you envision with AnchorFree 10 years from now?

DG: I see myself at the intersection of technology and foreign policy. I want to continue to combine idealism and pragmatic solutions to solve many of the worlds challenges. I have a huge amount of respect for projects like the XPrize and would like to see similar initiatives in more countries. I would like to help young people and entrepreneurs focus on what is important. Ideally, Ill be able to play a role in advancing the world forward and will inspire others to do the same.

I think AnchorFree is positioned to address several very big challenges over the coming years. The first is providing security and privacy for 25 billion connected devices. Everything from our refrigerators to our mattresses will become connected to the Internet. Security and privacy will extend to how we eat, sleep, exercise and will be extremely important. The second is providing secure and private connectivity to global content for the next 5 billion users that will move from feature phones to smartphones. Many of these users will need Internet Freedom and Privacy and our company is best positioned to provide these basic human rights to the next 5 billion people. I see AnchorFree as a global force that will give control over personal privacy as well as access to information back to the people.

Read the rest here:
"Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree - Huffington Post

Don’t Fall For This Tech Support Scam Targeting PC Users – KTLA


KTLA
Don't Fall For This Tech Support Scam Targeting PC Users
KTLA
You can make sure your settings are up to date on that. Alternatively, you can pay for a program like Norton Internet Security. If your subscription has lapsed, that means the program can't catch the latest bugs running around the internet and that ...

and more »

Originally posted here:
Don't Fall For This Tech Support Scam Targeting PC Users - KTLA

Yikes! Antivirus Software Fails Basic Security Tests – Tom’s Guide

Suppose that you're a feudal lord, riding high on the hog of exploiting your multitudinous peasants. Youve done so well that youve built a castle, piled high with food and wine and riches. To fend off the barbarian hordes, you invest in a drawbridge with a stout, wrought-iron portcullis.

Sounds reasonable, right? Theres only one problem: Upon further inspection, the portcullis is spotted with rust. It sticks when you try to pull it up. It's framed with rotting wood.

Credit: Serhii Kalaba/Shutterstock

The castle is your computer. The portcullis is your antivirus suite. And, according to a study released today (May 2) by Madgeburg, Germany-based firm AV-TEST, your AV software may be even more vulnerable to attack than the files it purports to protect. The company put 19 consumer antivirus suites to the test and found that only three of them seemed to be well protected from savvy potential hackers.

MORE: Best Antivirus Software and Apps

AV-TEST evaluated each program in three categories. The first measured how well each program uses address space layout randomization (ASLR) and data execution prevention (DEP). Briefly, ASLR randomizes a computer's memory allocation, making it harder for an attacker to target a particular process in a program; DEP is a Windows protocol that designates some memory as non-executable space (other operating systems do this under different names), making it harder (or impossible) for unauthorized programs to run in that space.

The second test measured whether the AV programs digitally signed their software-update files. Signing is a way of determining a files origin and authenticity; unsigned files could be more easily substituted with malicious ones.

The final test was the simplest, and determined whether an AV manufacturers delivered its software updates via the encrypted HTTPS web protocol or the unencrypted HTTP one. Lack of encryption makes it easy for an attacker to stage a man-in-the-middle attack by intercepting the data transmission, altering the data and then sending the data back on its way.

Of the 19 programs tested, three succeeded on all counts: Bitdefender Internet Security 2017, ESET Internet Security 10 and Kaspersky Internet Security 17.0. Its difficult to rank the rest of the programs, as each one succeeded and failed to varying degrees.

For example: Quick Heal Total Security 17.0, K7 Computing Total Security 15.1 and AhnLab V3 Internet Security 9.0 all did relatively poorly on ASLR and DEP protection, scoring between 76 and 36 percent of files properly protected. Avast Free AntiVirus 17.1, ThreatTrack VIPRE Internet Security Pro 2016 and Quick Heal Total Security 17.0 scored poorly on signed files, each containing between 1 and 29 unsigned files, depending on whether users installed the 32- or 64-bit version of the program.

Perhaps the most troubling results came from the HTTP vs. HTTPS results. Only six programs used a secure HTTPS server: Avira Antivirus Pro 17.1, Bitdefender Internet Security 2017, ESET Internet Security 10, F-Secure SAFE 14.1, G Data Internet Security 25.3 and Kaspersky Internet Security 17.0.

This underscores how difficult it is to rank the programs overall; a program like Symantec Norton Security 22.8 performed beautifully in two categories, but that wouldnt do you any good if you suffered a man-in-the-middle attack while trying to download or update it, as it doesn't encrypt its transmissions.

While attacking antivirus software isnt that common, and has been practiced more in theory than in fact, its effects could be disastrous. A compromised antivirus program could let malware through, sure, but whats more disconcerting is that antivirus programs require top-level privileges in the machines they protect.

A hacker who exploits an antivirus program could effectively take over a computer and, in turn, often an entire network. From there, you can kiss all of your email, social media, and financial security goodbye to say nothing of your private Internet history.

Still, AV-TEST pointed out that using an AV program, even one that has security holes, is a much better idea than using none at all. Between malvertising, phishing and good old-fashioned shady links, the internet can be a dangerous place, and everyday malware attacks are much more common than antivirus exploits. That portcullis may be rickety, but its still going to repel more invaders than an open drawbridge.

Here is the original post:
Yikes! Antivirus Software Fails Basic Security Tests - Tom's Guide

Watch Hackers Sabotage an Industrial Robot Arm – WIRED


WIRED
Watch Hackers Sabotage an Industrial Robot Arm
WIRED
Researchers at the security firm Trend Micro and Italy's Politecnico Milano have spent the last year and a half exploring that risk of a networked and internet-connected industrial robot. At the IEEE Security & Privacy conference later this month, they ...

and more »

Read the original:
Watch Hackers Sabotage an Industrial Robot Arm - WIRED