Tuesday, September 15, 2015

The new art of war: How trolls, hackers and spies are rewriting the rules of conflict

Wandering the pretty, medieval streets of Tallinn's old town, it is hard to believe that the tiny country of Estonia has anything at all to do with cyberwarfare. But first as victim of an attack and now as home to some of the leading thinkers on how the digital battlefield will develop, the country has played a key role in its emergence and evolution.

Estonia is a country of around 1.3 million people, facing the Baltic Sea and the Gulf of Finland, it borders Latvia to the south and Russia to the east. After decades as part of the Soviet Union, it regained independence in 1991.

Even today reminders of the Soviet times still abound in the capital Tallinn. There's a museum in one of the big downtown hotels showing how the KGB would bug the rooms of foreign guests.

But Estonia does not intend to be defined by its past, but is instead intent on creating the most advanced digital state on the planet. Since independence, Estonia has invested heavily in digital services. It leads the way with internet voting—in the 2011 election nearly a quarter of voters cast their ballots that way—and electronic tax filing, all underpinned by a nationwide digital signature infrastructure.

Today, you can even become an Estonian e-resident regardless of where you live in the world so you can use that same infrastructure to electronically sign contracts or set up your own company in the country.

But being so reliant on the internet carries a risk, as the country found out in 2007.

Plans by Estonian authorities to move a Soviet war memorial sparked a wave of website defacements and denial of service attacks in the country over a three week period, throwing Estonia's government services, newspapers, and businesses offline. The attacks temporarily disabled the websites of banks, ministries and political parties. Many pointed the finger at Russian hackers (Russia denied any involvement in the incident) but the events demonstrated how a purely digital attack on a state could have real-world consequences.

The Tallinn Manual

While the impact of the attacks can be overstated—"inconvenient, not cyberwar" is how one local described it—it accelerated plans, already in place, to set up a NATO cyber defence think-tank in the country.

The Cooperative Cyber Defence Centre of Excellence (CDCOE) was established the year after the attacks took place as an institution created to figure out how to improve the digital defences of NATO members and what cyberwarfare would actually look like.

As well as the cyber defence exercises it conducts annually, probably the centre's most important work so far appeared in 2013: the Tallinn Manual on the International Law Applicable to Cyber Warfare, known simply as the Tallinn Manual.

While there is no international law that directly refers to the ultra-modern concept of cyber warfare, there are plenty that applies. So CDCOE assembled a panel of international legal experts to go through this existing law and show how it applies to cyber warfare.This formed the basis of the Tallinn Manual and the 95 so-called 'black letter rules' it contains (so named because that's how they appear in the text).

Through these rules the manual attempts to define some of the basics of cyber warfare. At the most fundamental level, the rules states that an online attack on a state can, in certain circumstances, be the equivalent of an armed attack. It also lays out that such an attack is against international law, and that a state attacked in such a way has the right to hit back.

"Our view is that cyber is another operational domain, much as the seas are, much as the land is, much as space is."

                                                                    Admiral Mike Rogers

Other rules the manual spells out: don't target civilians or launch indiscriminate attacks that could cripple civilian infrastructure. While many of these sorts of rules are well understood when it comes to standard warfare, setting it out in the context of digital warfare was groundbreaking.

While the manual argues that a cyber attack can be considered to be the equivalent of an armed attack if it causes physical harm to people or property, other attacks can also be considered a use of force depending on their severity or impact. For example, breaking into a military system would be more likely to be seen as serious, as opposed to hacking into a small business. In contrast, cyber attacks that generate "mere inconvenience or irritation" would never be considered to be a use of force.

.

The manual also delves into some of the trickier questions of cyber war: would Country A be justified in launching a pre-emptive military strike against a Country B if it knew Country B planned to blow up Country A's main oil pipeline by hacking the microcontrollers managing its pipeline pressure? (Answer: probably yes.)

The manual even considers the legality of some scenarios verging on the science-fictional.


If an army hacked into and took control of enemy drones, would those drones have to be grounded and marked with the capturers insignia before being allowed to carry out reconnaissance flights? (Answer: maybe.)

But what's striking is that the Tallinn Manual sets the rules for a war that hasn't been fought yet.

No Digital Pearl Harbour

Although nearly every state around the globe has been developing a cyber warfare strategy, and some have been building up skills and perhaps even stockpiles of digital weapons, there haven't been any digital attacks that have crossed the thresholds of armed attack as defined by the Tallinn Manual. No massed bot armies, no hackers blowing up power stations from their bedrooms.

Perhaps the closest was the use of the Stuxnet worm (most likely by the US) as part of a bid to derail the Iranian nuclear programme. By contrast, the attacks on Estonia itself would, for all the excitement around them, be towards the inconvenience and irritation end of the spectrum.

The Tallinn Manual doesn't say much about the reality of the cut-and-thrust of the modern internet, where state-sponsored hackers, spies, and more are constantly probing the systems of other nations. This is a shadowy world where it is often unclear who the attackers are and what their intentions are (and just what the motivations of their backers is, too). It's a world filled with misleading evidence, ambiguity and deniability.

Throughout history, states have used third parties and proxies to get their dirty work done. The difference is that by hacking into systems in countries across the world, these groups can have an impact far from their home territories.

Colonel Artuz Suzik
Colonel Artuz Suzik speaking at the CCDCOE conference

On the subject of such attacks—which can be extremely serious but never quite reach the level of an actual attack by force—the manual has little to say. However, these kinds of attacks are the ones that take place every single day. Cyberwar has become the continuation of politics by digital means.

"The scope of cyber attacks is very, very wide, so that's why with the first Tallinn Manual we took the most severe case of armed attack and the use of force," explains Colonel Artur Suzik, the director of CCDCOE until August 2015. "But the majority of cyber incidents nation states face occur outside of the conflict law, so there was a clear need to expand the legal analysis to this area."

That doesn't mean the manual is a failure, or irrelevant. Indeed, it may even be that by making clear that digital attacks are covered by an array of existing international law, the Tallinn Manual has forced countries to rethink their approaches to cyber warfare. That is, because the manual does a good job of defining just what kinds of attack might lead to a missile being lobbed in your direction, states launching hacking attacks have been careful to keep their operations (just) below that threshold, say experts.

An expanded Tallinn Manual 2.0 is due to be published next year looking at how international law addresses malicious cyber operations by state (and non-state) actors during peacetime.

The new manual will try to create the same 'black letter rules' around much trickier concepts, such as when countries are responsible for hostile cyber operations launched against other states from their territory, and when such operations violate the sovereignty of the state.

It will take the analysis into the much complicated and murky environment of the day-to-day cyber attacks that don't ever reach the level of physical attacks, but are no less dangerous for it.

Few, for example, could have imagined a couple of years ago that a hacking attack against a film studio could lead to an international incident, or that the theft of HR records from the obscure Office of Personnel Management could create such consternation.

Politicians and diplomats are still struggling to work out how to deal with the near-constant stream of other data leaks from all sorts of government agencies that are blamed on state-sponsored hackers. And there is little in the way of consensus on how to deal with it or often even how to label it. When does hacking become espionage and when does that evolve into something that could escalate into the use of armed force?

And while many industry watchers saw the attacks on Estonia and built out of that lurid 'Digital Pearl Harbour' style scenarios where a country could be toppled by a digital attack launched by a dedicated few, this has not taken place. The reality has turned out to be less far less dramatic, but much more complicated to tackle.

"NATO doesn't have any interest [in militarising] cyberspace."
Sorin Ducaru

That's not to say that the apocalyptic scenario of state-backed hackers causing mayhem by breaking into industrial control systems (the technology that runs power stations or chemical plants) is utterly impossible - just extremely unlikely, and extremely hard and extremely expensive. Cyberwar, as it was envisaged, has not taken place.

But it's entirely possible that by watching and waiting for a explosive Hollywood-style catastrophe that we've missed the much more insidious and protracted cyberwar that has been going on for years already.

Hybrid information war

Earlier this year, the cyber think-tank held a conference to bring together some of the biggest thinkers on cyber warfare in Tallinn to discuss the most recent developments in cyber war theory ahead of the publication of the new Tallinn Manual at an event called CyCon.

For what was effectively a technology conference, there were a lot of people in uniform. In attendance was not only the head of the NSA, Admiral Mike Rogers, but also the Assistant Secretary General of NATO, Sorin Ducaru, reflecting the level of concern around cyber defence among the allies.

Despite the subject matter, it wasn't all serious. Speakers, including surveillance chief Admiral Rogers, were presented on-stage with a thank you present of a mug with an ear for a handle.)

Both men reflected a cautious, slowly-developing approach when it comes to the use of the internet by the military. NATO itself, for example, only recently decided that a major digital attack on a member state could be covered by Article 5 of its collective defence clause (one of the most fundamental tenets of NATO, that an armed attack on one member should be considered an armed attack on them all). And, Ducaru insisted, "NATO doesn't have any interest [in militarising] cyberspace or to have an ungoverned space."

Rogers emphasised that the use of the internet by the US military is still evolving, with defence the priority. "Our view is that cyber is another operational domain, much as the seas are, much as the land is, much as space is, and increasingly, it is an environment in which we will conduct a series of very traditional military evolutions from the defensive things to the application of capabilities to generate specific kinds of effects," he said. "We think cyber will evolve over time, much as we've seen the other domains, in the more traditional arenas."

To put it another way: cyberwarfare models are maturing in the same way that other technologies mature. To take a more prosaic example, the evolution of cyberwarfare is a lot like the cycle e-commerce went through. There was a lot of initial excitement and investment from retailers in building seperate e-commerce operations or businesse, but gradually these became not just a standard part of their operation but for many retailers the core of their business, just as cyberwarfare planning and strategy is gradually becoming a part of mainstream military planning.

admiralrogers.jpg
NSA chief Admiral Mike Rogers speaking at CyCon

However that doesn't mean that all countries are taking the same approach to strategy or that they even agree on what should be included in the term cyberwarfare. Some countries have a very narrow model of what cyberwarfare should look like - that is should focus on hacking and damaging systems. Others see it as just one part of a much wider information warfare spectrum which stretches from hacking to disinformation and propoganda. Indeed,much of the criticism of the Tallinn Manual has been around how it represents a NATO—and specifically Western—outlook on what cyberwarfare should look like.

Across the street from the hotel where the conference took place stands a building topped with a Soviet star, a reminder of Estonia's past and, unsurprisingly given the location and the ongoing conflict in Ukraine, understanding the cyberwarfare strategy of Estonia's big neighbour was a recurring theme.

And while NATO is thinking of cyberwarfare in terms of defending (and attacking) networks, others—particularly Russia, according to speakers at the conference—have developed a wider perspective that folds classic hacker tools into the broader concept of information warfare, which can stretch all the way from propaganda and disinformation through to the more expected denial of service attacks and more.

Speaking at a conference session, Keir Giles of the Conflict Studies Research Centre crystalised it thus: "There is now a developing realization that pure cybersecurity and cyberdefence is not sufficient to counter an enemy thinking in much broader terms."

Richard Bejtlich of the US Brookings Institution think-tank said that when it comes to cyberwar and cyberdefence, the NATO emphasis is still on software. "The Chinese and Russia have a broader concept," he said.

For example there was limited use of cyberwarfare—like hacking and denial of service—during the hostilities in Ukraine, even though many analysts were expecting more. Was it that cyberwar didn't happen, or that it simply didn't look quite how western observers were expecting it to?

"There are number of reasons why it doesn't look the way people were expecting when the Ukraine conflict first started. Cyber-armageddon was promised but hasn't happened," Bejtlich said. "All of the cyberactivity is purely a facilitator for broader information warfare ends."

All of this means that cyberwarfare isn't just—or perhaps even primarily—about breaking stuff anymore.

Indeed, protecting your networks will not protect you from cyberwar but may even leave you more open to it because those networks are exactly how your opponent will want to deliver its messages, its themes, its memes to their targets.

As Professor Francois Gere of the French Institute of Strategic Analysis pointed out: "That's some kind of paradox: if you want to dispatch propaganda and disinformation you cannot totally disrupt the communications devices of your adversary, so the internet must remain relatively safe and accessible."

Instead of a being characterised by the delivery of an elegantly crafted digital weapon like Stuxnet, it seems that for some countries, cyberwarfare is becoming just one part of a continuum with includes the much wider concept of hybrid information war. That includes subtle disinformation and overt propaganda along with more traditional options like denial of service or website defacement.

As such, rather than just worrying about denial of service we should start to worry more about denial of reality. The rise of ' troll armies' is well documented: bloggers paid to promote a pro-government agenda, making it harder for critics to be heard. This is well documented in Russia and China but also seems to be spreading further around the globe.

This much broader definition of 'information warfare' is much harder to tackle, especially as none of it would rise to the level of the use of force as defined by the Tallinn Manual. It's hard to stop a denial of service attack against a bank; it's much harder still to deal with a flood of rumours spread across social networks that the bank is running out of money.

"There is now a developing realization that pure cybersecurity and cyberdefence is not sufficient to counter an enemy thinking in much broader terms."
Keir Giles

In some respects this is harnessing the nature of the internet, a space where free speech, doubt, and scepticism can run wild. Fighting an army of online trolls sharing half-truths or outright lies in order to confuse the public and make it harder for politicians to make decisions is hard, and certainly not one that any existing army can deal with.

Few democratic nations will want to limit the free flow of information to the public but also aren't set up to—or are capable of—rebutting every crazy rumour which makes it a hard technique to combat. But if a nation can orchestrate a campaign of rumour and disinformation against another that changes public opinion in that country to the point that it alters the decisions made by its political leaders, then an army of trolls could be vastly more useful, and harder to fight, than a squadron of tanks.

Few democratic countries would want to wage war in such a way, but tackling it without undermining, for example, the freedom of speech which the public are used to is a challenge which they are currently ill-equipped to deal with. However, some are taking gradual steps in this direction. For example, the UK government recently started a Twitter account aimed at countering online propaganda from ISIL.

The next version of the the Tallinn Manual is due in 2016, and will make it clearer just how international law applies to cyber attacks which don't reach the level of physical attacks. It may be that providing a legal framework for this extremely murky environment will actually reduce some of the attacks we're currently seeing. But what is clear is that, overtly or covertly, the internet is now another battlefield, even if it often hard to discern it as such.

Or, as Margarita Jaitner of the Swedish Defence Academy told the conference: perhaps we have run an "information operation" on ourselves, tricking ourselves into thinking we would see some "breaking things armageddon" but completely missed the part about "what does it do to society, what does it do to our impression of what is going on, and how does it fog our picture of the events, and how does it stop us from acting or reacting?"

Perhaps the greatest success of cyberwarfare so far is to convince the world that it hasn't really started yet.



Monday, September 14, 2015

Speed up your success: Special for CAMACOL Members


Declaración sobre el abandono de las negociaciones del TISA: Cámara Nacional de Comercio y Servicios del Uruguay

En base a la decisión del gobierno de abandonar las negociaciones del TISA, la CNCS declara su profunda preocupación y consternación en relación a la posición adoptada en base a información no veraz y/ o incorrecta, e invita a los tomadores de decisión a corregir una medida que va contra el interés general del país, afectando su credibilidad internacional y las posibilidades de desarrollo, ya que en el sector servicios de exportación están las actividades que más empleo generan y mejor remuneración tienen. Uruguay ha tenido la oportunidad de jugar un rol protagónico en el mercado internacional de servicios y con esta decisión no perdemos otro tren, perdemos posibilidad de crecimiento y desarrollo, y en particular generar empleo altamente calificado.

De qué hablamos cuando nos referimos a exportaciones de servicios

Las exportaciones de servicios son un componente clave de la economía del conocimiento en la que vivimos. En tal sentido, el sector servicios es el que más crece a nivel internacional, se caracteriza por soportar de mejor forma las crisis económicas, además de ocupar la mayor parte de los recursos humanos y de alta calificación, tanto en las economías desarrolladas, como en las emergentes como Uruguay. Además, es el sector que permite la generación de valor agregado al resto de los sectores de la economía.

Cuando hablamos de exportaciones de servicios, nos estamos refiriendo a los sectores tradicionales como la logística y el turismo, así como a los otros sectores: Tecnologías de la Información; Procesos de Negocios, tales como reclutamiento de personal, pago de nóminas, compras y/o administración y finanzas; así como Servicios Profesionales como  Arquitectura, Ingeniería y/ o Servicios Legales. Estos últimos, los servicios no tradicionales, son los que más crecen a nivel internacional, regional y en Uruguay, y es dónde nuestro país tendrá mayores dificultades producto de la no inclusión en el TISA, ya que se trata de actividades que se comercian más allá de las fronteras regionales.

Por qué se ha dado este crecimiento exponencial del sector servicios a nivel internacional

El crecimiento de los servicios a nivel internacional se debe entre otros: al desarrollo exponencial que han tenido las Tecnologías de la Información y Comunicación (TICs), lo que ha permitido que actividades que antes no eran transables a nivel internacional hoy sí lo sean; el fenómeno de la fragmentación de actividades y procesos a nivel internacional, lo cual ha permitido que los países generen nuevas ventajas competitivas y/o redescubran parte de sus ventajas comparativas preexistentes para poder posicionarse a nivel internacional e ingresar en las cadenas globales de valor; y además por lo que se conoce como “Servicification”, concepto que refiere a la creciente producción y exportación de servicios de alto valor agregado por empresas de manufacturas e incluso agrícolas. Es por esto que muchas compañías multinacionales originalmente dedicadas a la producción de bienes, hoy se han incorporado a la producción y exportación de servicios globales. Por ejemplo, Volvo Logístics y Volvo Information Technology; HP y/o IBM que han pasado de ser productoras de hardware a empresas especializadas en servicios tecnológicos, administrativos y financieros a nivel internacional. En tal sentido, podemos incluso hablar del “agro-servicification” ya que empresas “productoras de semillas”, como Don Mario, ya no se definen como tales sino como desarrolladores de innovación y tecnología.

El sector en la región y en Uruguay

En 2014, las exportaciones de servicios de América Latina alcanzaron los USD 180.460 millones, mostrando en los últimos diez años una tasa de crecimiento anual promedio de 12,6%. Además, varios países de la región se encuentran listados en los principales rankings internacionales como las locaciones más atractivas para realizar actividades de servicios. Según el elaborado por A.T. Kearney, varios países latinoamericanos ocupan puestos cercanos a los líderes asiáticos: 4º México, 8º Brasil, 13º Chile, 24º Costa Rica y 30º Panamá. Otros, como Argentina, Uruguay y Colombia, se sitúan en las primeras 40 posiciones. Además, un importante número de compañías multinacionales se han instalado en varios países de América Latina, tales como IBM Global Services, Accenture, HP/EDS Services, Capgemini, TCS, Wipro e Infosys.

En el caso de Uruguay el sector representa el 68% del empleo, el 64.4% del PBI y tiene exportaciones del orden de los 4.500 millones al año (Fuente: Banco Mundial, BCU y Uruguay XXI).

Cómo promover las exportaciones de servicios

La forma de promover las exportaciones de servicios se basa en: promover las empresas nacionales, que son muchas y con un posicionamiento internacional muy alto, tales como Artech, CCC del Uruguay o CSI Ingenieros; así como captar Inversión Extranjera Directa (IED) para luego desde acá exportar servicios a su casa matriz y/o a terceros, ejemplo de ello son TCS, IBM, RCI, entre otras muchas.

En ambos casos, al tratarse de servicios, y en base a sus características distintivas, esto es intangibilidad y producción y consumo simultáneo, las formas de promoción son diferentes a los bienes, es por ello que una de las claves es la generación de credibilidad, lo cual aplica tanto para los exportadores como para atraer IED. Es por esto que, con la medida de abandonar el TISA no solo perdemos su activo intangible más importante, esto es generar credibilidad para los potenciales compradores e inversores, sino que además generamos credibilidad negativa, ya que abandonamos el proceso sin siquiera conocer los resultados.

En qué nos afecta estar o no estar en el TISA

El TISA es un acuerdo plurilateral, donde participan los países que tienen un mayor peso relativo en el comercio de servicios, tanto en su economía como en el empleo. Estos países son grandes, medianos y pequeños, de izquierda, de centro y de derecha, por lo cual el acuerdo no se relaciona con ninguna ideología en particular. Dentro de los países participantes hay ocho países latinoamericanos, por lo cual no es cierto que Uruguay esté solo frente a las grandes potencias. El acuerdo en negociaciones tiene por objetivo su multilateralización, por lo cual no está cerrado a otros países, y el hecho que no esté Brasil y Argentina, lo cual tiene lógica en base a las estrategias de política comercial de estos países, no es óbice para que no esté Uruguay, es más esta ausencia debería ser entendida como una ventaja competitiva temporal, de manera de robustecer el liderazgo regional en el tema.

Los beneficios de participar en un proceso de negociaciones como el TISA, se relacionan directamente con la clave de los servicios, esto es credibilidad y transparencia, ésta última por cierto es el principal activo de participar. Por lo cual, menciones tales como que el TISA supone eliminar monopolios, ir contra los servicios públicos, estatización de empresas estatales, o el embargo del patrimonio de innovación de las próximas generaciones, son FALSAS.

El ingreso al TISA por el gobierno anterior, podría ser considerado como una de las medidas más progresistas y visionarias de dicho gobierno. La actual, abandonar las negociaciones, no solo hace que las Pymes más innovadoras de nuestro país pierdan una posibilidad de crecimiento, sino que también perdamos la posibilidad de atraer nuevas empresas en el sector, con los beneficios que ello conlleva.

Desafortunadamente, por más que se ponga en práctica la estrategia del avestruz, esto es “meter la cabeza debajo de la tierra”, el mundo gira y sigue avanzando, y en entre ellos nuestros competidores directos en este tema, o sea Polonia, República Checa, Costa Rica, Colombia, Chile, entre otros muchos, quienes con esta medida están festejando ya que estamos regalando años de trabajo y liderazgo internacional en el tema.

Uruguay ha tenido la oportunidad de jugar un rol protagónico en el mercado internacional de servicios y con esta decisión no perdemos otro tren, perdemos en posibilidad de crecimiento y desarrollo y en particular en generar empleo altamente calificado. En base a esto, es clave que en lugar de retirarnos de las negociaciones de manera definitiva, se pida un tiempo para estudiar el tema con todos los actores involucrados a nivel social.

Friday, September 4, 2015

PSA: If You Download and Run Something Bad, No Antivirus Can Help You

Future technology smart glass red touchscreen interface. Caution screen concept

Antivirus should be a last-ditch line of defense, not something you rely on to save you. To stay safe online, you should act as if you had no antimalware software on your computer at all.

Antivirus isn’t the cure-all it’s often considered. There’s a reason companies like Netflix are dumping traditional antivirus and even the makers of Norton have declared antivirus “dead.” Don’t have a false sense of security because antimalware software is running on your computer.

The Two Main Ways Malware Gets On a PC

There are two main ways malware could get onto your system. One is through exploits — often browser and plug-in exploits targeting vulnerable software like Flash and Java. The other is through downloading something bad and running it. Antivirus can’t protect you against the newest attacks.

Blacklisting Is Fighting a Losing Battle

Antivirus software relies on blacklisting and heuristics — and really, heuristics are just another type of blacklisting. Antimalware companies find malware in the wild, analyze it, and add “definitions” that antimalware software constantly downloads. Whenever you run an application, the antimalware software checks to see if it matches a definition and blocks it if it does.

Antimalware software also incorporates heuristics-based detection. Heuristics check to see if a piece of software behaves similarly to known malware. It can block new pieces of malware before definitions are available for them, but heuristics aren’t anywhere near perfect.


The problem with the blacklisting approach is that it assumes everything is safe by default, and then attempts to pick out the known-bad things. It would be more secure to flip this upside down — assuming everything is dangerous and shouldn’t run unless it’s been more proven to be safe. Unfortunately, Microsoft only offers the most powerful whitelisting features on Enterprise editions of Windows.


Criminals Are Designing Malware to Avoid Detection

Sophisticated attackers can engineer malware to bypass antimalware programs.

You may have heard of VirusTotal, a website — now owned by Google — that allows you to upload a file. It scans that file with many different antivirus engines and reports what they say about it.

It wouldn’t be too hard to set up your own version of VirusTotal that doesn’t share files you upload with these antimalware companies. In fact, attackers have their own VirusTotal-like tools, allowing them to scan a file with many different antivirus engines to see if it’s detected. If antivirus software detects it, they can make modifications to avoid detection by antimalware software.

Studies have shown this is indeed what is happening. For example, a study from Damballa found that antivirus software fails to detect 70 percent of new malware within the first hour. Criminals are specifically tuning new malware to avoid detection by the antivirus software running on their targets’ computers.

Once the Malware is Running, You’re In Trouble

Once a piece of malware gets an anchor on your system, it’s over. You’ve been compromised. The malware could add exceptions to your antivirus software or just disable it from running and detecting the malware in the future. Given all the unpatched Windows systems out there with vulnerabilities that could be exploited to gain additional privileges once the software is running on your computer, this wouldn’t even require agreeing to a UAC prompt a lot of the time — although agreeing to that UAC prompt would certainly seal your fate, too.

Just clicking through an antimalware software warning and saying you want to run the malware in spite of the warning a single time would also be disastrous. Once the malware is running, it’s impossible to know you’ve rooted out every last bit of it without performing a full reinstall of Windows.

What Can Protect You?

The solution isn’t just software, although it’s always tempting to look for a technical solution when the real solution is a social one.

We should all behave as if we have no antimalware software. That doesn’t mean you shouldn’t be running something — at least the Windows Defender software built into the latest version of Windows, for example. But it’s just a last-ditch line of defense, not your only one.

This means avoiding pirating software — downloading and running programs from shady websites is dangerous. It means keeping a look out and only downloading credible software, avoiding things that look a bit sketchy. It also means understanding which file types are potentially dangerous — a .png file is just an image so it should be fine, but a .scr file is a screensaver program that could run potentially malicious code. We’ve covered the good security practices you should be following.

The Future of Security Software

The future of security software isn’t just blacklisting. Instead, it will often be something more like whitelisting — shifting from “everything is allowed except known-bad stuff” to “everything is denied except known-good stuff.”

That’s what Netflix is shifting to — software that monitors the software running on its servers for irregularities rather than scanning it against known malware.

More sophisticated tools should also harden the software we use, blocking techniques attackers use rather than fighting the losing battle of constantly adding new definitions.

Malwarebytes Anti-Exploit is a great example of this, which is why we recommend it so heartily here. This free tool blocks common exploit techniques used against web browsers and their plug-ins. It’s the kind of thing that should be built into Windows and modern web browsers. Microsoft even has their own similar technology in EMET, although it’s largely targeted at the enterprise.



No, you probably don’t want to dump your antivirus software like Netflix did. Antimalware software still works fairly well against random older malware you might encounter online. But, against newer and smarter attacks, antimalware software often falls flat on its face. Don’t put all your trust in it to protect you.

Thursday, September 3, 2015

Carriers want to take your Wi-Fi for their own use

Carriers want to take your Wi-Fi for their own use

An unlikely alliance of consumer advocates, cable providers, and tech companies push back on carriers' congestion-handling technology

Politics, it’s often said, makes strange bedfellows. It turns out that spectrum does too. An unusual coalition that includes Comcast and other cable companies, consumer advocacy groups, and Google is facing off against T-Mobile and other cellular carriers.
At stake, the combatants say, is the future of Wi-Fi. An effort by the carriers to use unregulated portions of the spectrum to offload cellular traffic that’s clogging their networks could interfere with Wi-Fi, Bluetooth, and devices connected to the Internet of things, say the consumer groups and their allies in the cable industry. The carriers, they charge, would rather sell their cellular data, so putting the squeeze on free Wi-Fi is in their economic interest.
[ Also on InfoWorld: How to stop Wi-Fi hackers cold. | Get a digest of the day's top tech stories in the InfoWorld Daily newsletter. ]
Nonsense, respond the carriers. “Wi-Fi is central to our customer experience, so co-existence is core to our desire to protect our customers’ Wi-Fi experience,” a T-Mobile exec tells me. (He asks that I not use his name.) One reason: T-Mobile’s network handles approximately 11 million Wi-Fi calls a day, he adds, so it needs Wi-Fi networks to be reliable.
Although the issue is pretty technical, involving technologies most people haven’t heard of, there’s already been some overheated coverage, such as in this Network World article: "LTE-U is coming to take your Wi-Fi away, consumer advocates warn." Even worse, lobbyists on the cable side have gotten the techno-simpletons in the U.S. Senate involved and are trying to get the FCC to step in.
I suspect the issue will be resolved by engineers on both side without serious damage to anyone. It does, though, highlight the increasing convergence of broadband, cable, satellite, and wireless business interests.
What's behind the LTE-U dispute
To address poor in-home cellular coverage, T-Mobile several years ago pioneered using the Wi-Fi network you're currently signed into to offload phone calls, a capability now used by all the major U.S. carriers on compatible smartphones such as the Apple iPhone 6 and Samsung Galaxy S6.
But offloading calls is different than what the carriers want to do with the unlicensed (that is, freely available) Wi-Fi and Bluetooth spectrum that has the cable companies and their allies so upset.
Modern smartphones use 4G LTE radio technology, and LTE runs on spectrum licensed by the FCC. That spectrum is filling up. Buying more spectrum is very expensive when it's even available.
That's why the carriers -- led by T-Mobile -- now want to use a version of the LTE cellular radio technology called LTE-U (the "U" stands for "unlicensed") that moves data and voice traffic normally carried in licensed parts of the spectrum reserved for cellular devices into the unlicensed frequencies that Wi-Fi and Bluetooth devices use.
There’s lot of room in the unlicensed bands, but it isn’t limitless. Your Wi-Fi network router wouldn't see the LTE-U device on the network; all your Wi-Fi network router might notice is that there's suddenly less spectrum available for it to use. “There’s real potential for interference,” says Chris Lewis, vice president for government affairs of consumer advocacy group Public Knowledge.
It’s no secret that the exponential growth of wireless traffic has put all of the carriers in a bind. Nor is it a secret that T-Mobile’s cellular network is weak outside of major metro areas, although the carrier disputes that claim. It makes sense that the “uncarrier” has been leading the charge to implement LTE-U.
Poor cellular coverage and saturated cellular towers are why the carriers encourage customers to connect via Wi-Fi whenever possible. Because Wi-Fi usage doesn’t count against a user’s data bucket, customers come out ahead. That’s why consumer advocates are so sensitive to anything that could make Wi-Fi harder to use.
Lewis notes that high-bandwidth uses of Wi-Fi, particularly video and VoIP, are the most susceptible to latency caused by interference. If video or voice calls get choppy, users would likely jump onto LTE, which they have to pay for. “The carriers have some incentive to push them there,” he says.
Such fears pushed four consumer advocacy groups -- Public Knowledge, Free Press, Common Cause, and the Open Technology Institute -- to lobby the FCC to prohibit or restrict the use of LTE-U. “Carriers also have powerful incentives to use LTE-U to deter mobile market entry by ‘Wi-Fi First’ providers, such as [traditional Internet service providers: the cable companies and landline phone companies]. Carriers deploying LTE-U will have the apparent option to adjust their access points to introduce just enough latency to frustrate consumer use of real-time applications, such as video calling,” they wrote in a filing to the FCC.
Tech companies concur with the consumer advocates. The FCC filing cites studies by Google, Broadcom, and others that claim that LTE-U can severely degrade Wi-Fi throughput, speeds, and latency (time delay) of packet delivery for real-time applications such as VoIP.
T-Mobile says the tests are flawed: “Claims by LTE-U opponents, particularly cable companies, that the technology will adversely impact Wi-Fi operations are based on testing with parameters set at extremes that do not represent realistic deployments or do not reflect actual LTE-U specifications,” Steve Sharkey, the carrier’s director of engineering, told the FCC.
If you’re wondering why Comcast and other cable operators care about this, the answer is simple: broadband and wireless increasingly go together. Comcast has more broadband customers than pay-TV customers, and anyone with a cable modem can (and usually does) use it with a Wi-Fi router.
Time Warner Cable is touting its Wi-Fi hotspots, and Cablevision is now in the wireless phone business with a Wi-Fi-only calling service dubbed Freewheel. Google, of course, has become an Internet service provide with its Google Fi high-speed fiber offerings.
Despite the saber-rattling, there's no need to panic
Notwithstanding the rhetoric and the different conclusions they've reached, I’d be surprised if the LTE-U issue doesn’t get resolved.
Although he’s wary, Public Knowledge's Lewis says, “We don’t oppose LTE-U; we just want it to work.” The T-Mobile exec I spoke to at some length was very careful not to sound hostile or overly combative toward the concerns of the consumer advocacy groups.
Furthermore, T-Mobile argues that its version of LTE-U will include technology called Listen Before Talk (LBT) that acts like a traffic cop. LBT makes the network aware of traffic, and it is designed to keep Wi-Fi and LTE-U signals separate to avoid interference. User traffic would be handed from Wi-Fi to LTE-U in a (hopefully) seamless procedure.
T-Mobile also maintains that although Wi-Fi is common in many cities' public areas, it is hardly ubiquitous, particularly in rural and suburban areas. T-Mobile envisions a user traveling in areas where there is no Wi-Fi and connecting to the Internet using LTE-U. If there’s no Wi-Fi, there’s no interference, the company argues.
Getting the free use of spectrum outside its core areas would be a big win for T-Mobile, which has been stung by claims that its coverage is still too limited to compete with offerings from Verizon and AT&T.
However this dispute turns out, we will see more and more confrontations and a reshuffling of the industry deck as the walls between once-separate technologies and business models crumble. Ultimately, all these companies are in the business of transmitting data, and it matters less and less where that data originates, over what spectrum it rides, or what information it contains.

Wednesday, September 2, 2015

Tuesday, September 1, 2015

While Many Panicked, Japanese Day Trader Made $34 Million (BusinessWeek)

Day trader CIS. Photographer: Shiho Fukada/Bloomberg
While a lot of investors were hitting the panic button Monday, a Japanese day trader who’d made a big bet against the market timed the bottom almost perfectly and narrated a play-by-play of the trade to his 40,000 Twitter followers. He claims to have walked away with $34 million.

As financial markets got crazy this week, many people turned cautious. Some were paralyzed. Not the 36-year-old day trader known by the Internet handle CIS.

“I do my best work when other people are panicking,” he said in an interview Tuesday, about an hour after winding up the biggest trade of a long career betting on stocks. He asked that his real name not be used because he’s worried about robbery or extortion. To support his claims, he shared online brokerage statements showing his trades second by second.

CIS had been shorting futures on the Nikkei 225 Stock Average since mid-August, wagering it would fall. By the market close on Monday, a paper profit of $13 million was staring him in the face. He kept building the position. When he cashed out late that night, a collapse in New York had caused his profit to double.

Instead of celebrating, he kept trading. He started betting the market had bottomed. When he finally took his winnings off the table on Tuesday, he tweeted, “That’s the end of my epic rebound trade.” His profit, he said, had almost tripled.

“It was a perfect trade,” said Naoki Murakami, who follows CIS on Twitter and whose markets blog has made him a minor celebrity in his own right.

Trash Talking

Last year, when he was the subject of a profile in Bloomberg Markets magazine, CIS said that in a decade of day trading, mostly from a spare bedroom in a rented apartment, he had amassed a fortune of about $150 million. At the time, he shared tax returns and brokerage statements to back up his claims. One document showed he had traded $14 billion worth of Japanese equities in 2013 -- about half of 1 percent of all the share transactions done by individuals on the Tokyo Stock Exchange that year.

CIS became a cult figure among Japan’s tight-knit community of day traders by trash talking on Internet message boards early in his career. He’s notorious for lines like “Not even Goldman Sachs can beat me in a trade.” Last year he opened a Twitter account, on which he talks about video games and, regularly, his trading. It’s impossible to say how many of his followers are also day traders, and how many of those buy and sell in his wake. Those who do, of course, are quite possibly helping him make money.

Playing Poker

During the interview Tuesday at a Tokyo coffee shop, where he had agreed to talk before continuing on to a poker game with buddies, he explained his recent trades step by step. Dressed in a plain gray T-shirt with a flannel shirt tied around his waist, he was monitoring a brokerage account on his iPad and had a $1,600 burgundy under one arm, a 2003 Domaine de la Romanee-Conti. (It wasn’t a celebratory bottle, he said; he drinks a lot of good wine.)
“Of course I’m happy about today, but you win some and you lose a lot, too,” he said, explaining the Greek financial crisis had cost him about $6 million.

CIS said he has no idea whether or not China is going to drag down the global economy. He doesn’t even care. When he trades, he tracks volumes and price moves to follow the momentum. For him the basic rule is: “Buy stocks that are being bought, and sell stocks that are being sold.”

Latest Trade

The latest trade began on Aug. 12, when CIS noticed a shift in equity markets he hadn’t seen for a while. Shares in the major indexes were struggling to recover from sell-offs. He started shorting Nikkei futures: 200 contracts the first day and another 1,300 over the following week and a half.

The stakes were enormous. With 1,500 contracts at a notional value of about $160,000 each, his bet against the Nikkei was about $240 million. For every 100 yen move in the index, he stood to make or lose $1.25 million.

The market was mostly flat over the next few days; CIS bided his time playing video games. On Friday Aug. 21, the Nikkei dipped. Then on Monday, the index plunged the most in two years, and the futures fell more than 1,000 points to 18,410. By the close at 3 p.m. in Tokyo, his profit stood at about $13 million.

Feedback Loop

This is the point where most traders would take their money off the table and call it a year. Not CIS.

“I’m adding to my position,” he wrote on Twitter. “Then I’m going to go for a walk and prayer.”

He sold 100 more futures contracts. Two hours later, he sold another 100. His bet against the Nikkei had risen to about $275 million. He would lose $1.4 million for every 100-yen increase in the index.

His logic for hanging on to the trade until the U.S. open, at 10:30 p.m. Tokyo time, was this: Panic would grip American investors returning from a weekend after they saw the scope of Asian selling, including Shanghai’s 8.5 percent plunge. That would trigger selling, which, in a feedback loop, would pull Nikkei 225 futures down violently amid the thin volume of late-night trading.

“I figured there would be a lot of fear around the U.S. open and that’s what I was aiming for,” he said.

On cue, the Dow Jones Industrial Average fell more than 6 percent in early trading. Nikkei futures tumbled again, dipping 1,250 yen below the 3 p.m. closing level. CIS, home in his pajamas, finally cashed out his short position. His profit had hit $27 million.

“Too Delicious”

There was still more money to be made from the panic though. Some investors that night were willing to pay a hefty premium for options that protected against the Nikkei crashing below 10,500. That would be a collapse of almost 40 percent. In CIS’s view, these investors were looking to buy insurance against a near impossibility.

He was happy to take the other side of that trade. The contracts were worth another $250,000 to him. He made the first deal within 10 seconds of what would prove to be the market’s bottom at 10:34 p.m.

“Too delicious,” he tweeted.

About an hour later, as he became more confident in a rebound, he started buying Nikkei futures. Now the play was the opposite of the short bet he’d started the day with. By 1 o’clock Tuesday morning, he’d accumulated 970 contracts, a $145 million wager that the market would start to climb.

He made one more trade before bed: a few more option contracts sold to straggling panickers. Those were worth $6,250. By now, at 1:40 a.m., he was a rich man stooping to pick up pennies.

He dashed off a last tweet at 2 a.m. “What a day. Still holding on to all my buys,” he wrote.

 “Time to sleep.”

The Rebound Trade

CIS returned to Twitter five hours later. Nikkei futures opened at about 18,000 and slowly recovered. Early that afternoon, he closed out his long position.

At the coffee shop later that day, CIS was pretty nonchalant for man who had made tens of millions of dollars in less than 24 hours. For him, it was just one trade out of thousands he would make this year.

“When a trade goes right I feel like bragging a little, but I don’t get on Twitter to talk about it if I lose,” he said with a laugh.