"All the World's a Stage We Pass Through" R. Ayana

Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Wednesday, 26 August 2015

Who’s Hacking Into Your Vehicle?


Who’s Hacking Into Your Vehicle?
Massive Vehicle Recall Follows Exposure of Hacker Threat

carhacking

 


From top to bottom, it appears that our modern Internet-driven world filled with interconnected smart gadgets and modern computing applications is making us vulnerable to potentially life-changing hacks.

It previously has been proven that boats, planes, GPS-driven munitions, unmanned vehicles and even smart homes all can be taken over via remote control.

But nothing has received the level of attention as the common modern vehicle.

Most of us remember the “conspiracy theories” that took place after the death of journalist Michael Hastings when his vehicle showed serious anomalies as it finally slammed into a tree at 140 miles per hour. Now, in an unprecedented move, Fiat-Chrysler is voluntarily recalling 1.4 million vehicles after news broke from Wired Magazine that a Jeep Cherokee had been successfully demonstrated to be remotely hacked via the Internet.

The research covered what is called a “zero-day exploit” hack, which enabled a test vehicle to be fully hijacked simply from obtaining knowledge of the vehicle’s IP address.  Wired writer, Andy Greenberg, described what happened next:

As the two hackers remotely toyed with the air-conditioning, radio, and windshield wipers, I mentally congratulated myself on my courage under pressure. That’s when they cut the transmission.

Immediately my accelerator stopped working. As I frantically pressed the pedal and watched the RPMs climb, the Jeep lost half its speed, then slowed to a crawl. This occurred just as I reached a long overpass, with no shoulder to offer an escape. The experiment had ceased to be fun. (Source)

Not fun at all.

The article went on to speculate that perhaps as many as 471,000 vehicles might be similarly exposed. However, 1.4 million is an astonishing number – and of course comes from just one automaker.

In a press release, Fiat-Chrysler admits that “vehicles equipped with 8.4-inch touchscreens among the following populations” should be brought in for a security upgrade:


  • 2013-2015 MY Dodge Viper specialty vehicles
  • 2013-2015 Ram 1500, 2500 and 3500 pickups
  • 2013-2015 Ram 3500, 4500, 5500 Chassis Cabs
  • 2014-2015 Jeep Grand Cherokee and Cherokee SUVs
  • 2014-2015 Dodge Durango SUVs
  • 2015 MY Chrysler 200, Chrysler 300 and Dodge Charger sedans
  • 2015 Dodge Challenger sports coupes

…customers may visit http://www.driveuconnect.com/software-update/ to input their Vehicle Identification Numbers (VINs) and determine if their vehicles are included in the recall.

Read full press release HERE

While it is commendable for such quick action to be taken, it remains to be seen how other automakers will respond, and whether or not long-term confidence will be shaken in the marriage between high-tech computing and vehicles.

Also see what DARPA says about hacking possibilities:



Hackers Expose New Method for Disabling Vehicles

 



Last month, a massive vehicle recall from automaker Fiat-Chrysler shocked many who were still unaware at the ease of hacking modern-day vehicles. The research covered what is called a “zero-day exploit” hack, which enabled a test vehicle to be fully hijacked simply from obtaining knowledge of the vehicle’s IP address.

The main culprit that was addressed by Fiat-Chrysler, which led to the voluntary recall of 1.4 million vehicles, was any car that came equipped with 8.4-inch touchscreens as part of the vehicle’s audio/video system.

Wired writer Andy Greenberg is back today with more information from security researchers who were able to show an even easier method to cause a potentially fatal crash in their Corvette test vehicle.

It appears that today’s interconnected smart gadgets and modern computing applications are making cars one of the more vulnerable everyday items open to life-changing hacks. Like cutting the brakes….

As you’ll see in this video, it only takes a smartphone for an outside operator to take full remote control.



As Greenberg reports:

At the Usenix security conference today, a group of researchers from the University of California at San Diego plan to reveal a technique they could have used to wirelessly hack into any of thousands of vehicles through a tiny commercial device: A 2-inch-square gadget that’s designed to be plugged into cars’ and trucks’ dashboards and used by insurance firms and trucking fleets to monitor vehicles’ location, speed and efficiency. By sending carefully crafted SMS messages to one of those cheap dongles connected to the dashboard of a Corvette, the researchers were able to transmit commands to the car’s CAN bus—the internal network that controls its physical driving components—turning on the Corvette’s windshield wipers and even enabling or disabling its brakes.[…]

The device that the UCSD researchers exploited for those attacks was a so-called OBD2 dongle built by the France-based firm Mobile Devices, but distributed by corporate customers like the San Francisco-based insurance startup Metromile. Metromile, the only one of those corporate distributors whose devices the researchers fully analyzed, is an insurance company that gives its customers the cellular-enabled devices, branded as the Metromile Pulse, to plug into a port on their dashboards as a means of tracking cars and charging drivers on a per-mile basis. The company has even partnered with Uber to offer the devices to its contract drivers as part of a discount insurance program. (emphasis added)

Similar to the response by Chrysler-Fiat, the researchers said that once alerted to the problem, the company quickly offered a security patch. However, according to the statements above, Metromile clearly isn’t the only distributor. They also used the same deflection as Chrysler-Fiat by saying that no one had reported the issue out in the field. But why wouldn’t these companies be properly testing in advance for these vulnerabilities? This is where the problem still remains according to researchers:

…the larger problem of wirelessly hackable dongles plugged into cars’ networks is far from solved. They say they also notified Mobile Devices of its hardware’s insecurity, and were told that the latest versions of the company’s dongles weren’t vulnerable to their attack. But the researchers nonetheless found in scans of the Internet using the search tool Shodan that in addition to the Metromile device, thousands of still-hackable Mobile Devices dongles were visible, mostly in Spain—possibly those used by the Spanish fleet management firm and Mobile Devices customer Coordina. Mobile Devices hasn’t responded to WIRED’s request for comment or for a list of its main customers.[…]

The problem is hardly limited to Metromile, Coordina, or even their device supplier Mobile Devices. The insurance company Progressive also offers so-called “telematics-based insurance” using a similar OBD2 plug-in it calls the Snapshot. Earlier this year security researcher Corey Thuen found that the Progressive Snapshot device had its own serious vulnerabilities, though Thuen didn’t demonstrate a proof-of-concept attack. And researchers at the cybersecurity firm Argus found that the Zubie, an OBD2 device for personal tracking of driving efficiency, had hackable flaws, too. (emphasis added)

And for those who might feel comfortable that this appears not to be a potentially widespread problem contained with other autos, Wired was quick to point out that it wasn’t a Corvette vulnerability, nor something only used in commercial transit:

…UCSD researchers say they could have hijacked the steering or brakes of just about any modern vehicle with the Mobile Devices dongle plugged into its dash. “It’s not just this car that’s vulnerable,” says UCSD researcher Karl Koscher. He points to the work of researchers Charlie Miller and Chris Valasek, who revealed and published the code for a wide array of attacks on a Toyota Prius and Ford Escape in 2013 that required only access to a vehicle’s OBD2 port. “If you put this into a Prius, there are libraries of attacks ready to use online.” (emphasis added)

Hackers are often maligned by media and governments as anarcho-terrorists who aim to bring nothing but disorder and destruction to the world, but fortunately some of them are doing the work that our supposedly trusted corporations should be doing.

This is a story worth paying attention to; it is most assuredly just the tip of the iceberg. It is also a useful topic to offer to those who would knee-jerk shout “conspiracy theory!” when presented with the strange events surrounding the fatal car crash of journalist Michael Hastings, for example.

Perhaps we can now start taking a much closer look at boats, planes, GPS-driven munitions, unmanned vehicles and even smart homes that also can be taken over via remote control.

Image Credits: Image source,  C3 Group, appearing on Forbes



For more information about hacking see http://nexusilluminati.blogspot.com/search/label/hacking
- Scroll down through ‘Older Posts’ at the end of each section


Hope you like this not for profit site -
It takes hours of work every day by a genuinely incapacitated invalid to maintain, write, edit, research, illustrate and publish this website from a tiny cabin in a remote forest
Like what we do? Please give anything you can -  
Contribute any amount and receive at least one New Illuminati eBook!
(You can use a card securely if you don’t use Paypal)
Please click below -



Spare Bitcoin change?




For further enlightening information enter a word or phrase into the random synchronistic search box @ the top left of http://nexusilluminati.blogspot.com


And see


 New Illuminati on Facebook - https://www.facebook.com/the.new.illuminati

New Illuminati Youtube Channel -  https://www.youtube.com/user/newilluminati/playlists

New Illuminati’s OWN Youtube Videos -  
New Illuminati on Google+ @ For New Illuminati posts - https://plus.google.com/u/0/+RamAyana0/posts

New Illuminati on Twitter @ www.twitter.com/new_illuminati


New Illuminations –Art(icles) by R. Ayana @ http://newilluminations.blogspot.com

The Her(m)etic Hermit - http://hermetic.blog.com



DISGRUNTLED SITE ADMINS PLEASE NOTE –
We provide a live link to your original material on your site (and links via social networking services) - which raises your ranking on search engines and helps spread your info further!

This site is published under Creative Commons (Attribution) CopyRIGHT (unless an individual article or other item is declared otherwise by the copyright holder). Reproduction for non-profit use is permitted & encouraged - if you give attribution to the work & author and include all links in the original (along with this or a similar notice).

Feel free to make non-commercial hard (printed) or software copies or mirror sites - you never know how long something will stay glued to the web – but remember attribution!

If you like what you see, please send a donation (no amount is too small or too large) or leave a comment – and thanks for reading this far…

Live long and prosper! Together we can create the best of all possible worlds…


From the New Illuminati – http://nexusilluminati.blogspot.com

Sunday, 17 April 2011

The Ecologist Guide to Data Activism

Data activism

The Ecologist Guide to Data Activism

You don't have to be a web geek to join the growing ranks of activists who have told powerful stories using data visualisation. Christine Ottery outlines how you can use data as a powerful tool to press for change


Isabell Long was 16 years old and with little previous computer programming experience when she created GovSpark, an application that influenced government departments to reduce their energy consumption.

At the time, the government's real time energy data had just been released, allowing ordinary citizens, like Isabell Long, to hold the government accountable to meet its target to slash energy use by 10 per cent.

Emma Mulqueeny, digital media expert and director of hack day events organizers Rewired State, tells me that GovSpark was part of a ‘really effective strategy' to reduce the government's energy use because it showed at a glance how departments were competing. 'We were calling up the press officers from different departments and saying you could do something about what is causing the spikes in energy,' she says.

According to Mulqueeny, 'The government energy and carbon emissions data is still very much an underused resource.' This is because data can differ in file format or even units of measurement from one department to the next, creating a hefty amount of work before it can be compared meaningfully.

Could another reason be technical knowledge barriers? If you want to work at the coalface of data activism the best thing to do it roll your sleeves up and learn a programming language.

Otherwise, there are free programmes that can carry out at least parts of the process - but you might have to rely on developers as well. One example of open source software you can use is the data visualization tool Many Eyes, which can display your data attractively in bubbles, graphs or maps.

Here are some tips that will help you get started, whether you decide to learn to code or not:

Identify sources

Data can be numbers or text. The first thing to do is identify the data sources that you want to analyse or cross-reference. In the UK, public data is released on Data.gov.uk, which is licensed by the National Archives and paid for by UK taxpayers. Other sources could include international governments, quangos or the UN.

It is worth considering making a Freedom of Information (FOI) request if the information you want to use is not already publicly available. You can use WhatDoTheyKnow.com to help you generate emails to the relevant government department's FOI office.

Be careful, however, with commercial data. 'You have to abide by their licensing laws otherwise that's just nicking,' says Mulqueeny. Needless to say, data theft is illegal.

Sometimes you can get permissions to use private data, however. For example, Premasagar Rose, founder of web apps company Dharmafly, created a game called Carbon Copies to raise awareness of carbon footprints with data from Mike Berners-Lee's book ‘How bad are bananas?'. This was as part of a climate hack day run by Rewired State.

Digging for data

When web developers run programming language code to pull data with specific criteria from websites, it is called data scraping, data mining, or data hacking.

ScraperWiki is one platform for scraping data. Developers can write code into ScraperWiki browsers to get started. Those who can't code can use the data from the database, or request new data scrapes. Aine McGuire, director of Scraperwiki, describes ScraperWiki as 'a social network for data prospectors' - there are 1,700 developers in the community and numbers are increasing by 20 per cent each month.

However, be cautious when you are drilling down into cross-referenced geolocation data because you risk identifying individuals, which can have legal ramifications. Mulqueeny recommends consulting a statistician to be on the safe side - contact the Royal Statistical Society to find an expert.

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD-alw4No6BFijPebzz6VgxXJv6GBymORLVNhGeyHNQTw8EiRRnzNtw6X3crWLh-Jq4GdUhcQyqEdLNbpolNtlrztha0PBVdK98_qXEhaEhiKLHJ1m1xhFSrPOUNN1qPA7tPnBaJY_pyM/s505/WikiLeaks.jpg

Tell the story

Data visualization can be powerful. David McCandless' graphics and animations, for example, are renowned for their ability to put a perspective on large numbers in comparative datasets.

One of the simplest ways to visualize data is if you have geolocation information. For example, 38 Degrees used a Google map to pinpoint forests endangered under the government's recently proposed (and retracted) sell-off. You can do something similar with Mapalist. Other visualization tools include: Google Charts, Many Eyes, Wordle, Tableau Public and Open Heat Map.

Interactivity is a hot new field, led by Hans Rosling's Gapminder Foundation, which animates global statistics. "Trying to find a way to engage a human with hard data is the challenge," says Rose.

James Darling, a developer at designers Berg London, says, 'Telling stories with the data is the crucial part, and the bit that's often missing is a really good narrative.' He recommends reading Ben Griffiths' history hack blogpost to check out masterful storytelling with statistics.

Also, ‘Journalism in the Age of Data' is a brilliant video on the challenges of telling stories with data.

Learn to code

By now, you might want to learn how to code so you can scrape data and build your own applications and visualisations. But how hard is it to pick up?

'If you have good skills in Excel then it is relatively easy to pick up a computing language like Ruby. You would then be able to take the data out of your spreadsheet and turn that into a mobile application or web application that you can visualize,' says Mulqueeny.

It is time to choose a programming language. Ruby is considered the easiest. Darling says he prefers Ruby because it is more readable as a kind of 'semi-English', which can help you to learn it. Rose, however, calls JavaScript 'liberating' because every browser, mobile phone and increasingly servers are running Javascript.

Mulqueeny says that the best way to learn coding is get a developer to talk you through it. She days: 'There are lots of informal developer's communities who meet in pubs across the UK who welcome newbies, for example Ruby in the Pub. You can find them on Twitter.' Alternatively, Rose recommends starting your own group of nascent data hackers to learn together and collaborate together.

To learn off your own steam, you can try O'Reilly books. Darling suggests: 'Hackety hack is written for children and will teach you the basics in a fun way.'

Christine Ottery is a freelance journalist


http://www.wilsonsalmanac.com/images/non_serviam.jpg

Xtra Images - https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD-alw4No6BFijPebzz6VgxXJv6GBymORLVNhGeyHNQTw8EiRRnzNtw6X3crWLh-Jq4GdUhcQyqEdLNbpolNtlrztha0PBVdK98_qXEhaEhiKLHJ1m1xhFSrPOUNN1qPA7tPnBaJY_pyM/s505/WikiLeaks.jpg

 http://www.wilsonsalmanac.com/images/non_serviam.jpg



For further enlightenment enter a word or phrase into the search box @  New Illuminati:

or http://newilluminati.blog-city.com  (this one only works with Firefox)

And see

The Her(m)etic Hermit - http://hermetic.blog.com
 http://newilluminati.blog-city.com (this one only works with Firefox)


This material is published under Creative Commons Copyright (unless an individual item is declared otherwise by copyright holder) – reproduction for non-profit use is permitted & encouraged, if you give attribution to the work & author - and please include a (preferably active) link to the original along with this notice. Feel free to make non-commercial hard (printed) or software copies or mirror sites - you never know how long something will stay glued to the web – but remember attribution! If you like what you see, please send a tiny donation or leave a comment – and thanks for reading this far…

From the New Illuminati – http://nexusilluminati.blogspot.com

Sunday, 14 February 2010

Operation Titstorm: Hackers bring down Oz government websites

Operation Titstorm:
Hackers bring down Oz government websites

http://media.sbs.com.au/films/upload_media/site_28_rand_1577751356_v_vendetta_maxed_627.jpg
   
Groups opposing the [Australian] government's internet censorship plans have condemned today's attacks on government websites, saying it will do little to help their cause, while Communications Minister Stephen Conroy called them "totally irresponsible".

Hackers connected with the group Anonymous, known for its war against Scientology, this morning launched a broad attack on government websites.

They are protesting against forthcoming internet filtering legislation and the perceived censorship in pornography of small-breasted women (who are thought to be under age) and female ejaculation.

A flyer Anonymous used to recruit people for the hack attack.
A flyer Anonymous used to recruit people for the hack attack.

Several government sites were down this morning and the hackers have promised to follow up by spamming government offices with pornographic emails, faxes and prank phone calls.

The Attorney-General's department this morning confirmed the attacks and said the Department of Defence Cyber Security Operations Centre was monitoring the situation.

A spokeswoman for Communications Minister Stephen Conroy said the attacks were not a legitimate form of political statement. They were "totally irresponsible and potentially deny services to the Australian public".

The attacks, organised under the banner "Operation: Titstorm", come five months after hackers connected with the same group briefly brought down the Prime Minister's website. At the time the hackers said they would regroup and launch new attacks.

Flyers distributed to recruit participants for the operation said the denial of service attacks on government servers would begin at 8am today. 

The Parliament of Australia website, aph.gov.au, was down for a period this morning, while access to the Department of Broadband, Communications and the Digital Economy's website was patchy.

A spokesman for the Department of Parliamentary Services, which runs the Parliament House website, said at the peak of the attack the site was receiving 7.5 million hits a second, up from the few hundred per second it normally receives.

He said the website was inaccessible for about an hour from 8am, and was offline intermittently due to the four attacks that had been detected by lunchtime.

It is not clear how many other sites were targeted but it appears a wide range of government servers were flooded with traffic.
Anonymous is a loosely connected group of anonymous online pranksters who come together to work towards certain goals, such as the eradication of the Church of Scientology or blocking perceived threats to internet freedom. It is not clear if the same members of the group involved in attacks on Scientology participated in the attacks on government websites.

The attacks come as the government prepares to introduce its controversial mandatory internet filtering legislation and just after the Australian sex industry claimed porn films were being banned from sale in Australia because they featured small-breasted women and female ejaculation.

The Classification Board confirmed that pornography could be banned if participants simply "appeared" to be under age, while female ejaculation was considered a form of urination, which is banned under content classification guidelines.

http://www.techworld.com.au/gim/id/19770/res/2

In an email sent to media yesterday afternoon foreshadowing the attacks, Anonymous referred to the internet filtering legislation and the perceived pornography censorship.
"No government should have the right to refuse its citizens access to information solely because they perceive it to be 'unwanted'," the email read.

"The Australian government will learn that one does not mess with our porn. No one messes with our access to perfectly legal (or illegal) content for any reason."

In the flyer recruiting people for the attacks, Anonymous said the attacks on the websites would be followed by "a shitstorm of porn email, fax spam, black faxes and prank phone calls to government offices (emails/faxes should focus on small-breasted porn, cartoon porn and female ejaculation, the 3 types banned so far)".

Despite anticipating the attacks because of flyers that had previously been circulated, the Department of Parliamentary Services spokesman said there was little that could be done to shield the site from attack.

‘‘We were never going to be able to protect against that,'’ he said. ''Our objective has simply been to bring the site back into operation after the attack. They can’t last forever.''

The attack also extended to spam, with various email accounts within the department receiving bulk emails from an anonymous sender that featured pornographic images and text. The email addresses targeted appear to be those listed on the website.

The Department of Defence has been informed of the attack, which the parliamentary services spokesman said appeared to be based on the false idea that the bureaucracy was partisan.

‘‘We assume that they think we’re a part of executive government,’’ he said.

Speaking to the ABC's Hungry Beast this week for a segment on the government's internet filtering policy, which airs tonight, Senator Conroy laughed off the Anonymous threats. He said the hackers themselves described last year's attack on government websites as "shockingly disappointing".

Anti-censorship groups in Australia, including stopinternetcensorship.org and the System Administrators Guild of Australia, have condemned the attacks, saying it hurts their cause.

"It would be much more helpful for these people to put their efforts behind legitimate action to stop this ineffective and inefficient attempt at censorship by the Australian government," Stop Internet Censorship co-founder Nicholas Perkins said.

by  ASHER MOSES February 10, 2010 - with Ari Sharp



Extra Images - http://media.sbs.com.au/films/upload_media/site_28_rand_1577751356_v_vendetta_maxed_627.jpg
http://www.techworld.com.au/gim/id/19770/res/2
http://www.razzlecostumes.com.au/Gallery/Masks/V-for-Vendetta-300H.jpg
http://images.theage.com.au/2009/07/25/649277/comic_vendetta-600x400.jpg
http://www.abc.net.au/atthemovies/img/2006/ep07/vendetta01.jpg


For further enlightenment enter a word or phrase into the search box @  New Illuminati:

or http://newilluminati.blog-city.com  (this one only works with Firefox)

And see

The Her(m)etic Hermit - http://hermetic.blog.com
 http://newilluminati.blog-city.com (this one only works with Firefox)


This material is published under Creative Commons Copyright (unless an individual item is declared otherwise by copyright holder) – reproduction for non-profit use is permitted & encouraged, if you give attribution to the work & author - and please include a (preferably active) link to the original along with this notice. Feel free to make non-commercial hard (printed) or software copies or mirror sites - you never know how long something will stay glued to the web – but remember attribution! If you like what you see, please send a tiny donation or leave a comment – and thanks for reading this far…

From the New Illuminati – http://nexusilluminati.blogspot.com
 

Wednesday, 20 January 2010

China Hacks Google

Don’t Use Explorer!

 

 

 Google Blog says, in its entirety:
Like many other well-known organizations, we face cyber attacks of varying degrees on a regular basis. In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident--albeit a significant one--was something quite different.

First, this attack was not just on Google. As part of our investigation we have discovered that at least twenty other large companies from a wide range of businesses--including the Internet, finance, technology, media and chemical sectors--have been similarly targeted. We are currently in the process of notifying those companies, and we are also working with the relevant U.S. authorities.

Second, we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists. Based on our investigation to date we believe their attack did not achieve that objective. Only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves.

Third, as part of this investigation but independent of the attack on Google, we have discovered that the accounts of dozens of U.S.-, China- and Europe-based Gmail users who are advocates of human rights in China appear to have been routinely accessed by third parties. These accounts have not been accessed through any security breach at Google, but most likely via phishing scams or malware placed on the users' computers.

We have already used information gained from this attack to make infrastructure and architectural improvements that enhance security for Google and for our users. In terms of individual users, we would advise people to deploy reputable anti-virus and anti-spyware programs on their computers, to install patches for their operating systems and to update their web browsers. Always be cautious when clicking on links appearing in instant messages and emails, or when asked to share personal information like passwords online. You can read more here about our cyber-security recommendations. People wanting to learn more about these kinds of attacks can read this U.S. government report (PDF), Nart Villeneuve's blog and this presentation on the GhostNet spying incident.

We have taken the unusual step of sharing information about these attacks with a broad audience not just because of the security and human rights implications of what we have unearthed, but also because this information goes to the heart of a much bigger global debate about freedom of speech. In the last two decades, China's economic reform programs and its citizens' entrepreneurial flair have lifted hundreds of millions of Chinese people out of poverty. Indeed, this great nation is at the heart of much economic progress and development in the world today.

We launched Google.cn in January 2006 in the belief that the benefits of increased access to information for people in China and a more open Internet outweighed our discomfort in agreeing to censor some results. At the time we made clear that "we will carefully monitor conditions in China, including new laws and other restrictions on our services. If we determine that we are unable to achieve the objectives outlined we will not hesitate to reconsider our approach to China."

These attacks and the surveillance they have uncovered--combined with the attempts over the past year to further limit free speech on the web--have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.

The decision to review our business operations in China has been incredibly hard, and we know that it will have potentially far-reaching consequences. We want to make clear that this move was driven by our executives in the United States, without the knowledge or involvement of our employees in China who have worked incredibly hard to make Google.cn the success it is today. We are committed to working responsibly to resolve the very difficult issues raised.
+++++++++++++++++

Doesn't it look like they know that the Chinese government is behind all this? And that the decision to operate Google.cn openly is a response to that? Good work, Google. Now that you've talked the talk, walk the walk.

UPDATE: The New York Times has more:

Google did not publicly link the Chinese government to the cyber attack, but people with knowledge of Google’s investigation said they had enough evidence to justify its actions. 

A United States expert on cyber warfare said that 34 companies were targeted, most of them high-technology companies in Silicon Valley. The attacks came from Taiwanese Internet addresses, according to James Mulvenon, an expert on Chinese cyberwarfare capabilities.

Mr. Mulvenon said that the stolen documents were sent electronically to a server controlled by Rackspace, based in San Antonio. 

“For Google to pull up stakes and basically pull out China, the attack must have been large in scope and very penetrating,” Mr. Mulvenon said. “This attack highlights the fact that cyberwarfare has basically gone to the next level.”

Note again the abuse of Taiwan -- the attacks originated from here, just as China used Taiwan firms to send nuke tech to Iran. It's obvious that at least one payoff China is hoping for is western ire at Taiwan.

Hope the local papers give this wide publicity.

UPDATE II: "call me cynical, but would google be this principled if their China business were #1 and doing well?"(post to niubi)

There are a lot of comments from "knowing" expats that Google is just doing this because it is losing market share to Baidu. While true, it still commands a ~20% share and losses among users who actually spend money appear to be smaller (20% of China's educated internet users is bigger than many countries where Google dominates). But both that article and Google's 2006 blogpost say that they are in China for the long haul. Moreover, the post shows that Google has always been cognizant of the human values involved in investing in China.

The cynicism of "it's all about market share", and all such uses of cynicism as an analytical stance rather than as an emotional response, is really just a mask for an ideology of power that shills for China (and all forms of authoritarian power). By treating Google as the active agent, and China as the passive recipient of Google's action, it takes China's theft and spying activities, its authoritarian regime, its murderous, thuggish ways, as constants, like gravity, something part of the environment, but something which need not explain itself nor account for its actions. In the cynical formulation, "power" just is and has no moral agency of its own. Hence the spotlight is always focused on those who take action, "exposing" their hypocrisy. By putting the spotlight on Google, the cynics remove it from China -- but it is China that has acted evilly here, not Google.

So call me cynical, but would all those China expats be so quick to leap on Google if they lived outside China?

UPDATE III: Imagethief says Google detonates the China corporate communications script with many good links.

Google Hack Leaked to Internet;

Security Experts Urge Vigilance

Microsoft Screws Up Again!
 
The code that was used to hack Gmail accounts in China is now publicly available on the Internet, and security experts are urging computer users throughout the world to be highly vigilant until a patch can be developed.

The hack involves Internet Explorer 6, the browser that came with the Windows XP operating system that, while outdated, still powers millions of businesses and home computers and is now dangerously compromised. 

On Thursday, the code that was used to hack Gmail accounts in China and led Google to threaten to close shop there was posted to malware-analysis Web site Wepawet. By Friday, security site Metasploit had posted a demonstration of just how easily the exploit can be used to gain complete control over a computer.
Metasploit is intended to let security professionals test out security threats. 

"Normally these frameworks are designed for the good guys for our assessment. The problem is, it's open source and available to anyone," said Michael Gregg, head of Superior Solutions Inc., a Houston-based cybersecurity consultancy.

"And the scary thing about Metasploit is, anybody can pull this stuff down and anybody can launch it. It's not the skilled hacker working for the government, it's the kid next door." 

George Kurtz, CTO of the security firm McAfee, agrees. "The public release of the exploit code increases the possibility of widespread attacks using the Internet Explorer vulnerability," he wrote late week. "This attack is especially deadly on older systems that are running XP and Internet Explorer 6." 

Hacks based on this security flaw led Google to threaten to drop its www.google.cn Web site and leave China last week. The Internet behemoth believes these security intrusions are a quest not just for political knowledge but also for intellectual property. Experts warn that as many as 30 other companies have been hacked, ranging from software firms like Adobe and Juniper Networks to Northrop Grumman -- a major U.S. defense contractor and manufacturer of nuclear-powered aircraft carriers and the Global Hawk unmanned drone.

Microsoft has yet to patch the hole in IE 6, a flaw so serious it's prompted the German government to suggest citizens avoid IE. Microsoft has posted a security advisory detailing the problem, and urging users to upgrade to newer browsers. 

Microsoft's next scheduled security update is Feb. 9 -- so unless the company expedites an "out of cycle" security patch, more than three weeks will elapse before this vulnerability is fixed. Without a patch in sight, security experts urge vigilance, and not just for government agencies and huge businesses like Google.

"This is something that affects businesses in the U.S. as well as individuals. The Internet knows no borders,"  Gregg warned.

Gregg said that years ago, software companies had months to solve a security flaw after it was uncovered. Today, it's hours. Protecting yourself and your business is substantially harder today than it was in years past, too, due both to the accelerated pace of these exploits and also to hackers' reliance on social engineering, where an individual is tricked into providing confidential information. 

Gregg calls it spearphishing: "They target the user with an e-mail  that would appeal to them, one that leads to a site that launches malicious code onto your system." And the IE 6 exploit makes it particularly easy to slip that code on your computer.

Staying on top of current security patches, using firewalls, updating Web browsers and running intrusion detection software is the first part of staying safe. But since most attacks rely upon spearphishing or some similar end-user exploit, Gregg suggests a training program that would warn users that if an e-mail link looks too good to be true, it probably is -- don't click on it.


Images - http://www.foxnews.com/scitech/2010/01/18/google-exploit-leaked-internet-security-experts-urge-vigilance/
http://www.washingtonpost.com/wp-dyn/content/article/2010/01/16/AR2010011600871.html

For further enlightenment enter a word or phrase into the search box @  New Illuminati:

or http://newilluminati.blog-city.com  (this one only works with Firefox)

And see

The Her(m)etic Hermit - http://hermetic.blog.com
 http://newilluminati.blog-city.com (this one only works with Firefox)


This material is published under Creative Commons Copyright (unless an individual item is declared otherwise by copyright holder) – reproduction for non-profit use is permitted & encouraged, if you give attribution to the work & author - and please include a (preferably active) link to the original along with this notice. Feel free to make non-commercial hard (printed) or software copies or mirror sites - you never know how long something will stay glued to the web – but remember attribution! If you like what you see, please send a tiny donation or leave a comment – and thanks for reading this far…

From the New Illuminati – http://nexusilluminati.blogspot.com