Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Friday, March 20, 2015

Stuxnet - the first digital weapon

Radio New Zealand National had a great interview with Kim Zetter who has written a book about Stuxnet, the world's first digital weapon. You can listen to the interview here or read about Stuxnet in chapter 12 of my book The Universal Machine. It's certainly true that quietly over the last few years we have crossed into a new age where cyberwar is now a reality.

Thursday, December 4, 2014

An Unprecedented Look at Stuxnet, the World’s First Digital Weapon

My recent book, The Universal Machine, opens its chapter on hacking with the deployment of the Stuxnet computer virus. Allegedly created by Israel and US intelligence services to target Iran's nuclear bomb programme it was the world's first state against state digital weapon. With North Korea now being accused of hacking Sony perhaps it's time to revisit this story. Wired has recently published an excerpt from a new book on Stuxnet - recommended reading.

Tuesday, April 30, 2013

Syrian hackers attack western media

In 2011 when I was writing The Universal Machine I searched for a topical example of demonstrators using social media to publicise their protests. I chose the Syrian uprising as the latest example of the Arab Spring uprisings, little thinking that two years later this tragic conflict would still be raging. I also wrote about the rise of state-sponsored hacking, using China and North Korea as examples. Now the Guardian reports that Syrian pro-Assad hackers are attacking western targets. The Syrian Electronic Army has hacked the twitter accounts of the BBBC, France 24 TV, National Public Radio and Associated Press in the United States, al-Jazeera, the government of Qatar, and Sepp Blatter, the president of football's governing body Fifa. In one hack they claimed via twitter that a bomb had exploded in the White House and that President Obama had been injured.  It really does seem as the next war will be fought in cyberspace.
  Incidentally Twitter recently announced that it was going to start using two-factor authentication. It seems like they should hurry this up.

Wednesday, February 13, 2013

How secure are your passwords?

The recent hack of Telecom's Xtra/Yahoo email service, in which 450,000 users may have been affected, once again highlights the importance of managing your online security. We're all told that you can't use your dog's name as your password (too easy to find out) and that you should include lower and uppercase letters, numbers, and even special characters in your passwords (many sites now insist on this). We're also told that you should never use the same password for different websites or services. Then if a site is hacked the hackers can't get access to the rest of your online life since the password they've got is only good for that one site.
    But the problem is to follow this advice means having to remember dozens of complex passwords -  a virtually impossible task. However there is a solution, no not PostIt notes - a password management system. There are several on the market. I use, and am very happy with, LastPass.
    Basically these systems install a browser extension (all major OSs and browsers are supported) and they watch for username & password fields on websites. When you login the password management system provides the correct password for the login URL from its encrypted database in the cloud. If you're registering for the first time the system generates a random complex password for you and stores it. So now you only have to remember one password - the one that logs you into your password management system. To make this more secure LastPass uses Google's 2-step verification system that also requires a code number generated by an app on my smartphone to complete the login. There are several other security features that LastPass has, which you can explore for yourself. I recommend you consider using a password management system to take control of your online security.
   

Monday, July 16, 2012

The People Behind Computing - Hackers (#epochtimes)

I was interviewed a few weeks ago for The Epoch Times, which has resulted in a piece they've published called The Universal Machine’ Author Describes the People Behind Computing. The interview centered on the hacker ethos and how it binds so many of the great pioneers and inventors of computing together - from Charles Babbage to Mark Zuckerberg. This basically summarizes the central theme of chapter 12 "Digital Underworld" of The Universal Machine.

Monday, May 7, 2012

Julian #Assange on the #Simpsons

Julian Assange on the Simpsons
Last night the 500th episode of the Simpsons aired on New Zealand TV - yes I know it was shown months ago in the US, but New Zealand is a long way away and obviously those electrons took some time to make the journey. One of the episodes special guests was WikiLeaks founder Julian Assange.
   He's of course most famous for his website WikiLeaks but you may not know that he used to be a hacker going by the pseudoname Mendax. Assange contributed to an excellent book titled, Underground: Tales of Hacking, Madness and Obsession on the Electronic Frontier, which provides an excellent insight into the secretive world of hacking. You can buy the book on Amazon, but in true hacker spirit it's freely available to download online.

Saturday, March 31, 2012

#Anonymous will shut down the Internet this Saturday

Well, that's what the media are claiming. Members of the hacktivist collective, known as Anonymous, will shut down the Internet this Saturday, in Operation Global Blackout, by attacking the Domain Name Servers (DNS) servers that run the Internet. When you type www.anyname.com into your browser the DNS servers translate this into an numeric IP address, like 192.168.1.103, which is the actual physical address of the web server you want to reach. Every computer on the Internet has an IP address, including the one you are reading this on. But, you'd struggle to remember these numbers, so the DNS servers translate, from easy to remember domain names, to hard to remember IP addresses. For example, www.google.com is actually, 74.125.237.148.
   DNS servers are organized into a hierarchy. At the top there are 13 root servers. These contain the master database of all the world's IP addresses and domain names. Below these are tiers of increasingly more local DNS servers that contain copies of the root server databases, right down to DNS servers in you local ISP, to which your computer is connected. Anonymous will not be targeting the root servers, these are very secure, but will be attempting to take down DNS servers in local ISPs and regional telcos that control the backbone of the Internet. Will they succeed? A professional computer security friend of mine says, "...they will be at least partially successfully. Lots of old unpatched top level DNS servers out there."
   You can learn more about the shadowy world of hackers in chapter 12 "Digital Underworld" of The Universal Machine

Wednesday, March 28, 2012

You could earn a $100,000+ as a hacker!

As chapter 12 "Digital Underworld" of The Universal Machine explains, hackers come in three varieties: white hat hackers, these are the good guys who are employed by organisations to find vulnerabilities in their systems and software; black hat hackers, the bad guys who attempt to find vulnerabilities and exploit them for their own nefarious purposes; and grey hat hackers, who are not employed by companies to find vulnerabilities, but will sell the exploits for a fee. You could think of them like freelance white hats, who are not on a contract, but get a finders fee.
    As a fascinating article in Forbes explains there is now a growing international market in zero-day exploits. When a hacker finds a security vulnerability in a piece of software, Internet Explorer for example, and a means of using that vulnerability, it's called an exploit. If the manufacturer of the software doesn't know of the exploit it's called a zero-day exploit (i.e. no days have passed since it's known about and presumably patched). Zero-day exploits are inherently valuable since bad people can do bad things with them and a company if it's aware of the exploit can patch the vulnerability before it's used and not receive bad PR. Here's a price list for zero-day exploits, from the Forbes article.
iOS exploits are the most valuable because of Apple's reputation for security, but conversely Mac OS X exploits are relatively cheap compared to Windows because fewer people use OS X, so an exploit might not be as useful. The Forbes article is well worth reading as it gives you an insight into the secretive and lucrative world of the hackers. Perhaps you should consider a new career?

Friday, March 9, 2012

#Virus brings down US computer network (video)

It's okay you can relax, this happened in 1988. A friend unearthed this classic TV news story on YouTube and it's really worth a look for the lovely way the TV treats the story complete with clips from old computer games and scary movies.
   I assume from the date they are referring to the Morris worm which was released by Cornell grad student, Robert Morris, in November 1988. He claimed he simply wanted to estimate the number of nodes on the ARPANET, which was the worm's intended function. However, the fact that he released the worm on MIT's network to hide its origins rather contradicts his claims. He was caught and prosecuted under the then brand new US Computer Fraud and Abuse Act. He was sentenced to three years probation, 400 hours of community service, and fined $10,000.
   All of this, and more, features in Chapter 12 Digital Underworld of The Universal Machine.


Monday, February 27, 2012

The BBC moves into the future

The BBC has launched a new website called "Future" (www.bbc.com/future) where it will showcase everything about the future from the worlds of science, health and technology. It's fairly popular in tone and easily accessible but already looks like it already carries some interesting stories and information. One piece that jumped out at me is called, "Why we should all learn to hack," which puts forward the sensible idea that everyone needs to have some understanding of how to program or risk exclusion of worse, exploitation, in an increasingly digital world.  If you are looking for a well curated site featuring the latest developments and glimpses of the future this looks like a good place to check out.

Wednesday, October 12, 2011

The History of Hacking - documentary

During research for my chapter on hacking I came across an interesting old Discovery Channel documentary called "The History of Hacking." It features, Captain Crunch, Steve Wozniak, and Kevin Mitnick.