Showing posts with label cyber attack. Show all posts
Showing posts with label cyber attack. Show all posts

Monday, April 16, 2018

Expert: Russia Launched Cyber Warfare Against UK With ‘Dirty Tricks’


In response to an attack on Syria, Russia has launched a cyberwar against the United Kingdom. This “dirty trick” campaign will be against the United States as well, and Boris Johnson, the UK’s Foreign Secretary says retaliation plans against Russia should be made now.


According to The Telegraph UK, Whitehall sources on Sunday night confirmed a Pentagon analysis that showed a 20-fold increase in Russian-sourced “disinformation” being spread online since the cruise missile attacks on Syria in the early hours of Saturday. This ramped up the fears that it could be a precursor to a campaign of cyber attacks by the Kremlin, and the Foreign Secretary said Britain must take “every possible precaution” to guard against it.


The attack on Syria by Western powers has put officials in the UK on edge.  They now feel that Russia will retaliate with a cyber attack against UK hospitals and other services including air traffic control, and one expert believes such an attack is imminent.  Counter-terrorism expert Michael Clarke, who specializes in defense studies, has urged the public to be ready for “cyber warfare” within the next two or three weeks.


“I suspect Russia will choose not to respond in military terms. But cyber warfare is highly likely,” said Clarke.  “It will be an attack on national infrastructure, not just upsetting city firms, but getting inside the transport system, or the health system, or air traffic control. It could affect everyone.”


The UK, US, and France launched 105 missiles at suspected chemical weapons sites in three strikes in Damascus and near Homs on Saturday, and Russian President Putin warned that the US-led strike against Syria would result in “consequences” against the Allied forces, without stating what they would be.


Speaking on the BBC’s Andrew Marr Show on Sunday, the UK foreign secretary said relations between both countries (the UK and Russia) had severely declined in the wake of the poisoning of Sergei and Yulia Skripal, and Saturday’s missile air strikes in Damascus and Homs.  Johnson also stressed the “limits” of the intervention were to stop an apparent erosion of the “taboo” of chemical weapons. “The rest of the Syrian war must proceed as it will,” he said, adding that the “primary purpose is to say no to the use of barbaric chemical weapons.” Johnson added that he did not know how Syrian President Bashar al-Assad would respond, saying that if there was a repeat chemical attack, “clearly, with allies, we would study what the options were.”The NHS has proven to be a weak target for cyber attacks in the past.  With an already failing socialist healthcare system, any cyber warfare could be fatal for the UK’s hospitals which are on life support now. 

Wednesday, November 1, 2017

North Korean Cyber Threat: ‘The Difference Between Theft And Destruction Is Often A Few Key Strokes’

northkoreacyberattack


Global banks are preparing to defend themselves against a potential North Korea hacking attack. Cybersecurity experts worry that North Korea will continue to embolden themselves as the threat of United State military action over the nuclear program looms.


The threat to banking institutions is very real. North Korean hackers have stolen hundreds of millions of dollars from banks during the past three years. A 2016 heist at Bangladesh Bank yielded $81 million, according to Dmitri Alperovitch, chief technology officer at cybersecurity firm CrowdStrike. “We know they attacked South Korean banks,” said security teams in the United States. They added that fears have grown that banks in the United States will be targeted next.


The North Korean government has repeatedly denied accusations of hacking by security researchers and several governments that it has carried out cyber attacks.  But Alperovitch told the Reuters Cyber Security Summit on Tuesday that banks were concerned Pyongyang’s hackers may become more destructive by using the same type of “wiper” viruses they deployed across South Korea and at Sony Corp’s Hollywood studio.


North Korean hackers could use what they have learned through previous cyber heists about financial networks gathered to disrupt banking operations, according to Alperovitch. He also said his firm has conducted “war game” exercises for several banks fearing a North Korean attack.


“The difference between theft and destruction is often a few keystrokes,” Alperovitch said.


John Carlin, a former U.S. assistant attorney general, told the Reuters summit that other firms, among them defense contractors, retailers, and social media companies, were also concerned. “They are thinking ‘Are we going to see an escalation in attacks from North Korea?’” said Carlin, chair of Morrison & Foerster international law firm’s global risk and crisis management team.


Some others say that it is highly unlikely North Korea will use cyber tactics to attack the US because the rogue regime fears retaliation. Jim Lewis, a cyber expert with Washington’s Center for Strategic and International Studies, is one of those persons. He said it is unlikely that North Korea would launch destructive attacks on American banks because of concerns about the reaction from the US.


The concerns appear valid when considering North Korea is defying the sanctions placed on them demanding they abandon their quest to obtain nuclear weapons.

Sunday, July 2, 2017

Here’s How a DELIBERATE Cyberattack Could Happen To Us

The Petya Ransomware attack hit globally, but one country, in particular, was devastated by it. The Ukrainian infrastructure was brought down by the attack, where the epicenter occurred, and now, experts are suggesting that it may have been deliberate and state-sponsored.


This is not the first time Ukraine has been under siege by cyberattack. In fact, the battle has been nearly constant for quite some time.



 As for whether that state sponsor was Russia, “It’s difficult to imagine anyone else would want to do this,” Boyarchuk says.


Boyarchuk points to the timing of the attack, just before Ukraine’s Constitution Day, which celebrates the country’s post-Soviet independence…


More technical clues support that theory, some Ukrainian security researchers say. Kiev-based Information Systems Security Partners, which has acted as a first responder for several recent waves of cyberattacks on Ukrainian companies and government agencies, says it has found evidence that sophisticated hackers quietly infiltrated the networks of at least some Ukrainian targets two to three months before they triggered the ransomware that paralyzed those organizations. (source)



Security specialist Matthieu Suiche said in a blog post that it wasn’t a “ransomware” attack intended to make money, and is instead a “wiper” sent to eradicate data.



The fact of pretending to be a ransomware while being in fact a nation state attack — especially since WannaCry proved that widely spread ransomware aren’t financially profitable — is in our opinion a very subtle way from the attacker to control the narrative of the attack. (source)



Forensic analyst Oleksii Yasinsky told Wired that the intent was not money, even though this presented as a ransomware attack.




Rather than just encrypting infected hard drives and demanding $300 in Bitcoin for the decryption key, in some cases it simply wiped machines on the same network, deleting a victim computer’s deep-seated master boot record, which tells it how to load its operating system. Yasinsky argues that this behavior indicates the attackers weren’t, in fact, trying to extort payments from those victims but instead wanted to cause maximum disruption. (source)



They wanted to cause maximum disruption. Now, isn’t that just about the scariest thought ever?


What if the US was hit by a similar cyberattack?


Let’s go a little further down this rabbit hole and imagine such an attack happening in the United States. Because, really, is it that far-fetched? In fact, is it possible that this is a dry run for a massive attack on the American infrastructure? Maybe they want to see what happens when they take down the essential systems of a modern country on a smaller scale first, in order to maximize the effects on a larger target.


Scary, but possible.


Everything we do revolves around computers these days.


Businesses keep their records there. Systems are automated there. It goes on and on. And with this particular virus, one expert said, “There IS NO KILL SWITCH.” It’s virtually unstoppable once it gets into a system and it eradicates everything.


You know how I’m always encouraging you to watch survival movies and read survival fiction to enhance your prepared mindset? Let’s use this real life scenario and wargame the situation based on the systems that were damaged in Ukraine and think this through.


Banking would be disrupted.


Many banks in Ukraine were hit by the attack, which means that people suddenly had no access to their money. Their credit and debit cards wouldn’t work and the ATMs were down.


In the United States, most folks use credit or debit as they go throughout their days. Gas pumps are set up to pay at the pump with your bank card. We think nothing of swiping our card at the grocery store or at lunch. We know we have money in there, and it’s less risky than carrying cash, in most folk’s minds.


But what if suddenly you couldn’t use your credit cards and debit cards? What if the ATM machines went dark and you couldn’t get any cash from them?


Imagine this happened when you were traveling on business, miles from home with a half empty gas tank. You wouldn’t be able to get a hotel room, get more fuel, get food – nothing at all unless you had cash on hand – and even if you DID have enough cash, there’d be other problems as you’ll see below.


You should always have enough cash and supplies on hand to manage for quite a while if commerce were to cease.


Gas stations would close.


In Ukraine, getting fuel was difficult.


Of course, it makes sense that getting gasoline would be pretty tricky. Most gas stations are set up as pay-at-the-pump, and if you have cash, you have to go inside, pay, and they reset the pump to allow you the allotted amount of fuel…on a computer.


As well, the gas pumps themselves are digital in just about every place I’ve been in the past few years. Unless you manage to find some anomaly of a gas station where everything is still manual, the fuel you had would be all you’d have until things reverted to normal.


Even if you could buy stuff, there might not be stuff to buy.


It wouldn’t take more than a day or two for the transport trucks to stop running, since the fuel wouldn’t be readily available. Since our stores use “just-in-time” inventory restocking, pickings would be thin within a week.


Here’s a breakdown of what would happen – and how fast it would happen – if the trucks stopped running.


Like I said, be prepped for this.


Business would be disrupted.


In Ukraine, the banks are offline, which means payment systems are also offline.


Most businesses link to banks to be able to take payments by debit or credit. Most people no longer carry around pockets full of cash, and even if they did, some businesses aren’t entirely equipped to take cash payments.


When I worked at a car dealership service department, half a lifetime ago, I recall getting the day off because we were utterly at a standstill when our systems went down. The technicians couldn’t do any kind of electronic repair (and let’s face it, these days, there’s a computer in your car controlling just about every aspect of its function), the advisers couldn’t invoice, no one could check to see if a job was covered under warranty…I’m sure that many other businesses are equally dependent.


Most retail businesses rely on the ability to scan items for the price and to track SKU numbers for inventory purposes. Their cash registers are inextricably linked to computers for both payment options, pricing, and inventory options. Commerce could grind immediately to a halt, which means, what you have on hand would be all you had until things were resolved. You could forget about getting goods or services.


With the banking systems inoperable, other systems would soon go down too.


Think about our day-to-day business. Most of us have things on autopay, like our mortgages, car payments, and other monthly recurring bills.


If the banking systems are completely shut down, then our automatic payments would also cease to work. This means that the businesses relying on those payments would immediately have a shortfall, something that could have long-term ramifications if the issue lasted for more than a few days. Once things came back online, there would be massive confusion and congestion as people tried to straighten out payments that didn’t go through.


Chaos.


Transportation could shut down.


In Ukraine, both the major airport in the capital and the national railway system were shut down.


An attack like this could hit travelers the hardest. Imagine being at an airport to catch a connecting flight, and then discovering all flights had been canceled. If the computer systems were all down, you wouldn’t be able to rent a car to drive the rest of the way, and you wouldn’t be able to get a hotel room without cash, and you wouldn’t be able to buy any food unless you had cash on hand for that.


Commuters who rely on transit like trains to get back and forth to work would be stranded and without ATM access, most would be without any options. This is why you must always have a Plan B to get home when you’re traveling, along with the appropriate gear and footwear to walk if necessary.


The grid would fail.


In Ukraine, the power grid went down across a broad swath of the country.


In an event like this, it isn’t out of the ordinary for the power to go out. Our grid is extremely susceptible to a malware attack and something called “cascading failure.”



…malware can induce what’s often referred to as a cascading failure. This is what caused the massive blackout that occurred in the Northeastern US and Canada back in 2003. An overgrown tree branch in Ohio touched a power line, which caused that section of the grid to overload and shut down. The electricity had to be transferred to other power lines, which in turn also became overloaded. This chain reaction continued until 55 million people were without power. (source)



This can begin to have broad ramifications very quickly:


  • Most homes are reliant on the grid for heat or cooling.

  • No lights.

  • No hot water.

  • Food in the refrigerator or freezer would begin to spoil.

All the basics of a long-term power outage would apply, multiplied by all of the other things going wrong at the same time. Always be ready for a two-week power outage at the bare minimum.


Water could become contaminated.


Without the systems that keep municipal water supplies treated and distributed, it wouldn’t take long for the water from the taps to become contaminated and unsafe to drink – if it still flowed at all. Buying water at the store would be difficult, if not impossible, for all the reasons mentioned above, and even if you could buy it, the supplies would run out very quickly as others realized the tap water was unsafe to consume.


Always be prepared with water storage, a plan to acquire more water, and a way to purify water.


Dangerous infrastructure systems could be at risk.


The Chernobyl nuclear plant lost its ability to monitor radiation with the usual computerized systems.


Because Chernobyl hasn’t already had enough issues. The plant is still not fully decommissioned after the horrible disaster in the 80s, and some people are still working there monitoring for radiation leaks. All systems have had to revert to manual ones due to the cyberattack.


The United States has 99 nuclear reactors in 30 states.  99 Chernobyls waiting to happen?



Here’s How a DELIBERATE Cyberattack Could Happen To Us | power-reactors-operating | Science & Technology Special Interests


Photo Credit: USNRC



 Hospitals could be affected.


In the US, two hospitals in Pennsylvania were forced to cancel surgeries due to the Petya cyberattack.


During a widespread attack in the United States, there is potential for our medical system to be severely affected. Without access to patient records, terrible mistakes could occur. Many patient monitoring systems are computerized. Some life support machinery is tied into the grid. And what happens if the grid-down situation outlasts the fuel for the generators?


In a situation like that, there wouldn’t be much medical help available for incidents that occur during the disaster. You must keep some first aid and longer-term care supplies on hand, as well as informational guides to help you deal with health issues and emergencies as they arise. Know how to back this up with natural remedies in the event the situation outlasts your commercial supplies.


With all of this, unrest would erupt fairly quickly.


If the situation only lasted for a few days, society certainly wouldn’t break down. But if it stretched into weeks and more people began running out of the basics, we’d begin to see unrest on a massive scale. Think about it – what wouldn’t YOU do to take care of your hungry children?  Add to this the now-refugees stranded in airports and other travel centers across the country, with no supplies and no way to get home. It wouldn’t take long for the need to outstrip any governmental efforts to supply aid.


Long before such a thing ever occurs, you should protect yourself by keeping your mouth shut. No one needs to know that you’re stocked to the rafters and ready for a situation like this. Secondly, you need to be prepared to protect your home and family should things go sideways. Here’s an article I wrote about why preppers must be armed and ready for unrest.


Are you prepped for something like this?


Prepping is prepping is prepping.


This, like any other disaster, assumes certain things.


  • The grid could go down.

  • Emergency services and first responders may not be there.

  • What you have on hand is what you have with which to survive,

  • If you’re away from home, the trip back could be difficult.

Have you thought this through?


An attack like this could have very longterm effects because, as I mentioned above, once it gets into a system, it’s unstoppable. It wipes clean all the date, the information stored, the functions. It would take a long time to come back from that.


What are some other things that could be affected by a massive cyberattack on the US? How would you prepare for something like this? Share your thoughts in the comments section below.




Thursday, May 25, 2017

This Is The World's Most Active Battlefield - Watch Cyber-War In Real-Time

Today’s most active battlefield is not located on the ground, in the air, or on the mighty seas. It’s taking place on the internet – and, as Visual Capitalist"s Jeff Desjardins notes, if you’re still a non-believer, spend a few minutes with the following live map to watch a representation of cyber attacks as they happen...


Created by Norse Corporation, a cyber intelligence firm that claims to get instant attack telemetry from over eight million sensors deployed worldwide, the map visualizes cyberwar in real-time and organizes attacks by type, origin, and target. (A full-screen version is also available.)



Source: Visual Capitalist


PREDATOR AND PREY


Who is responsible for these attacks, and who is the target?


In our few minutes of watching, the United States received nearly 70% of incoming attacks:


Cyberwar and types of attacks


While we were not expecting this live visualization to literally cover every single hack worldwide, this does seem to match up with the ratio from other sources. For example, in a previous infographic on cyberwar, we noted that the U.S. is targeted in 66% of web application attacks, and in 54% of cyber espionage hacks.


In our few minutes of watching, about half of the attacks also originated from the United States. However, many also were launched from other countries such as China, Ukraine, and The Netherlands.


THE SCALE IS REAL


While the idea of cyber warfare still seems like science fiction for many people, recent events such as the WannaCry ransomware attack have made the scale and potential implications of cyber warfare much more real.


WannaCry Map


The above map from AFP shows that the WannaCry attack was unprecedented in scale, infecting more than 230,000 computers in over 150 countries. Using an exploit developed by the NSA, WannaCry infected Britain’s National Health Service (NHS), Spain’s Telefónica, FedEx, and Deutsche Bahn, along with many other companies or countries.


Ultimately, the hack had a built-in “killswitch” that was discovered by internet security experts. It also seemed to be relatively ineffective at collecting hefty amounts of ransom. Despite all of this, the reality is that the hack shut down hospitals and other businesses, giving us a true taste of the scale and impact that a professionally-executed cyber attack could have in the future.

Friday, May 19, 2017

If Wannacry cyber attack didn’t make you wannacry, the next one will!

Anti Virus 777 at English Wikipedia [GFDL (http://www.gnu.org/copyleft/fdl.html) or CC BY-SA 3.0 (http://creativecommons.org/licenses/by-sa/3.0)], via Wikimedia Commons

The Wannacry malware that hit like a global mega-bomb, showed everyone how vulnerable we are to a global cyber attack. Billed as “one of the largest global ransomware attacks the cyber community has ever seen,” the infection started in London and then emerged almost instantly in Seattle, New York, and Tokyo. Within ten minutes, the coordinated attack became epidemic throughout the world, covering the better part of every continent but Antarctica. By the end of one day, the malware had infected over 200,000 computers in 150 nations, encrypting all their data and locking the users out.

While the attackers demanded a ransom in order to free hostage computers, the small number of companies that paid the ransom required for unlocking the encryption did not get their data back, raising a question of whether the primary goal was really money or mayhem. (If primary goal was making a lot of quick money, it would make more sense to quickly release data so that more companies would be inclined to pay the ransom, seeing that payment solved the problem.)


This was a cyber attack equal in scale to something Dr. Evil would create or some Bond villain would use to collect ransom from the entire world … or to control the world. This time, it didn’t win, but there are some interesting reasons why as you did deeper.


Top levels of governments ordered emergency meetings to try to quickly understand and stem the spread of this very destructive piece of warware. A solution emerged quickly because an anonymous British researcher discovered the virus was built with a kill switch. With each infection the virus would check to see if a particular website was running and issuing a kill command. If no command, the virus would begin its mission of destruction. The researcher discovered the website, which was dormant, and activated it, slamming the brakes on global destruction. This bought time for people to apply Microsoft’s patch before the attackers could launch a modified version of the virus. Furthermore, the destructive code was only able to infect computers that had not upgraded with the latest Microsoft patch; so damage was hugely mitigated.


Even so, ATM’s and gas pumps in China went dark, as did Chinese government and university computers. Hospitals in the UK shut down. Forty-five facilities were affected, forcing cancelation or delay of some medical treatments. Nissan’s plant in the UK got hit. French automaker, Renault, stopped production in order to stop spread of the virus. Spain’s Telefónica and Russia’s communications giant, Megafon, got hit. Russia’s central bank and government agencies received “massive” attacks, which Russia claimed were successfully overcome.


The latest data I saw showed 370,000 computers infected and locked up, but that didn’t appear to include less available information from China. The damage is still unfolding, though greatly slowed; but a second variant began spreading across the globe on Tuesday, and other variants may emerge.



Epidemiology of the viral attack — North Korea suspect



The New York Times reports that the ransomware hack appears to have originated from North Korean sleeper cells.




Since the 1980s, the reclusive North has been known to train cadres of digital soldiers to engage in electronic warfare and profiteering exploits against its perceived enemies, most notably South Korea and the United States…. When the instructions from Pyongyang come for a hacking assault, they are believed to split into groups of three or six, moving around to avoid detection…. Security officials in South Korea, the United States and elsewhere say it is a well-known fact that the North Korean authorities have long trained squads of hackers and programmers, both to sabotage computers of adversaries and make money for the government, including through the use of ransomware — malicious software that blackmails victims into paying to release seized files…. Choi Sang-myung, an adviser to South Korea’s cyberwar command and a security researcher at Hauri Inc., said that the arithmetic logic in the ransomware attacks … is similar to that used in previous attacks against Sony Pictures and the Swift international bank messaging system — both of them traced to North Korea. (NYT)




Of course, The New York Times has been saying for months that Russia hacked DNC emails and interfered with US election without yet coming up with a shred of solid evidence or producing sources willing to go on record. It’s also fairly simple to create a decoy to the actual origin of attack. If it’s true, however, it underscores North Korea’s desire to create random destruction and financial loss indiscriminately throughout the world and its ability to do so.


The NYT points out several other attacks around the world in recent years with similar signatures that pointed back to North Korea and to the fact that these attacks often happen at the same time as a North Korean missile or nuclear test. Unlike the tests, however, these attacks would be considered actual acts of war if they could be definitely pinned on some national government. They created financial destruction, in the very least, by setting companies back with lost data and lost time in recovery. They pillaged by collecting ransoms. In the past, they have stolen data and then used it to damage a company, as happened with Sony Pictures.


As Microsoft’s president and chief legal officer, Brad Smith, wrote on his blog …




An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen.




I’d say that is an understatement because Microsoft has no desire to officially intensify concerns about the security of its operating systems.


China, North Korea’s neighbor, where it is believed many of the sleeper cells have been planted, got hit the hardest. China said 30,000 Chinese organizations were infected and hundreds of thousands of computers. That could be due to China taking sides with President Trump and pressuring North Korea on its nuclear weapons development, or the larger-scale assault in China could be far less nefarious. China is the motherland of pirated software, and pirated Microsoft software does not get security upgrades, making it more vulnerable to such attacks. China may have only been hit the hardest because such is the vulnerability of a sleazy economy built on pirating just about everything.


The fact that the lines connecting all the hacks to North Korea — or more importantly to the North Korea government — remain a little fuzzy may keep nations from retaliating against what would be acts of war if they were known to be government actions.


The fact that ransom seems to have played a very small roll in a very large “ransomware” attack begs the question as to whether this was a government operation masquerading as a ransom attack. Was it North Korean revenge for Trump’s tough stance and China’s capitulation, or was it a US false-flag test of the effectiveness of a global attack, designed to disparage North Korea at the same time and to be cut off before any great damage was done? The presence of a single kill switch that could shut the whole thing down is a fail-safe that implies an operation by a group or nation who wanted to make sure the virus could be stopped. Who of all highly computerized nations was damaged the least?


While the latter is more intriguing (in the most heinous sort of way), Occam’s Razor says the simplest answer is most likely the right one. I personally find it hard to believe the US government would be that reckless with its allies, but it is an outside possibility. The US is, regardless, seriously culpable, even if it did not launch the attack.



US Origin of the viral agents



While North Korea may have launched the viral attack, the origins of the virus’s development go much deeper and do appear to come home to rest in the US.


Microsoft sought to shift blame to the US government for “stockpiling code” that can be used by malicious attackers. What they didn’t say is what we have known since Edward Snowden’s revelation, which is that software corporations in cooperation with the US government, including Microsoft, have built hatch doors into their code for US intelligence agencies to use.


The Swiss-cheese-like holes built throughout software systems and networks for backdoor access by the US government allow the government to sniff through or shut down systems all over the world for the sake of national security. However, as was more recently revealed by Wikileaks, these security measures have a very insecure downside: once the hatch doors are known by hackers, there is nothing to stop ordinary hackers from sliding the bolt and getting in through those same doors, which gives ordinary hackers extraordinary powers.


The problem, however, lies even deeper in the machinations of the US government than just getting software manufacturers to build back doors into all your personal computing devices. The US government’s software designed to exploit those back hatches is now available to the entire world. What we have here is leaked warware:




 


The attacks on Friday appeared to be the first time a cyberweapon developed by the N.S.A., funded by American taxpayers and stolen by an adversary had been unleashed by cybercriminals against patients, hospitals, businesses, governments and ordinary citizens….


 


Former intelligence officials have said that the tools appeared to come from the N.S.A.’s “Tailored Access Operations” unit, which infiltrates foreign computer networks. (The unit has since been renamed.) The attacks on Friday are likely to raise significant questions about whether the growing number of countries developing and stockpiling cyberweapons can avoid having those same tools purloined and turned against their own citizens….


 


The attacks on Friday are likely to raise significant questions about whether the growing number of countries developing and stockpiling cyberweapons can avoid having those same tools purloined and turned against their own citizens. (The New York Times)





Snowden, seeing the grave danger posed by the NSA’s spying and irresponsible nature, tweeted, “Whoa: @NSAGov decision to build attack tools targeting US software now threatens the lives of hospital patients,” indicating it was a leaked NSA cyberwar tool, created by the NSA which attacked the UK’s hospital system…. “Despite warnings, @NSAGov built dangerous attack tools that could target Western software. Today we see the cost.” (The Free Thought Project)




I would suspect the deeper reality is that the hole in microsoft’s software was not one some government “found,” but was one of those hatches built in by government demand. When the government’s software for exploiting that patch became public domain, either the government or Microsoft decided to make the ready antidote (their patch) immediately available.


Russia, Snowden’s sanctuary, has blamed the United States’ National Security Agency, saying it is NSA software that was leaked out of US control via Wikileaks that was used to create the Wannacry attack. The NSA, in masterminding and then letting leak its own black software, has placed the power of cyberwar in an unquantifiable number of unknown hands with unknown intentions. It’s really no different than if the US let weapons-grade nuclear material slip into the hands of terrorists.


Here’s an even more apt comparison: The concern over government engineered computer viruses escaping and infecting the general population of computers is similar to the concern in past years over government-engineered living viruses, designed for germ warfare, escaping and infecting the general population.


Now, take this warware security risk one step further. What kind of international crisis might be created if a US biological weapons virus escaped containment and broadly infected the world? Turn the question a little: What kind of international crisis might be created if a US computer virus broadly infected the world?


We saw this kind of problem emerge from the Stuxnet virus that the United States and Israel developed jointly to destroy centrifuges in Iran in order to stall its nuclear development during negotiations. Later, elements of that virus appeared in destructive code use for lesser attacks all over the world.




“This is almost like the atom bomb of ransomware,” Mr. Belani [chief executive of PhishMe, an email security company] said, warning that the attack “may be a sign of things to come.” (NYT)




You see, this is really warware — powerful destructive government cyber weapons that can be used equally for spying or for infecting and destroying enemies — slipping into the hands of enemies around the world. When the US designs biological viruses for war, it also creates antidotes to its human-engineered destruction for its own population or to limit collateral damage to friendly nations. And THAT is most likely why the solution to this massive attack came so quick with patches already available and being distributed.


Thanks to the US government’s inept security of its darkest software in inadvertent partnership with Wikileaks, more than a dozen government spying and hacking programs have been made generally available to the entire world, and Apple, Microsoft and others have been rapidly issuing security updates.


Snowden asks,




If NSA builds a weapon to attack Windows XP—which Microsoft refuses to patches—and it falls into enemy hands, should NSA write a patch?




I ask a bigger question: “IF NSA builds such a weapon and it falls into enemy hands bringing death and financial destruction around the world, should the USA be held responsible to pay for all the damages? Should the entire world hold it guilty? This is the potential level of risk we’re talking about. If you create the destructive engine exploited by hacker’s viruses and let it get away, aren’t you as liable as you are if you engineer a viral disease and let it escape into the world, killing off millions of people? The hospital situation in the UK shows how people can actually die because of this kind of weaponry.


The NSA is clearly inept at policing its nuclear-size cyberweapon stash. It has allowed small and formerly insignificant people like Edward Snowden, hired through contracted services, to leak out vast amounts of information about its work. It has allowed large amounts warware to get to Wikileaks and from there to all evil hands in the world that want it. This is cyber-nuclear proliferation that all appears to have happened due to NSA security breaches. Imagine if it were actual nuclear material or highly contagious incurable germs. We’d be demanding that heads roll for such repeated loss of control.



Even the US is vulnerable to attacks by its own weaponized viruses



This was our shot over the bow. In this case, the weakness in the software that was exploited was already known and the patch had already been made and was even in place on most computers. Thus, the damage was limited. Think of how this attack — extensive as it was — would have been exponentially worse, had the vulnerability in Microsoft’s operating system and the solution not already been in place as well as readily available to those who were delinquent in upgrading.


The United States has known about this kind of vulnerability for years, and it has been reported for years but we are still built on infrastructure that is widely vulnerable to attack. While we may have antidotes that can be released as patches if we know a computer virus or software engine used to make a virus work has slipped out, our infrastructure remains vulnerable to all kinds of attack agents that other nations are making that we may know nothing about.


We can see that in the government’s response to last week’s cyber attack:




President Trump ordered the federal government to prepare for a devastating cyber attack against America’s electric grid amid growing fears foreign states are set to carry out attacks aimed at plunging the nation into darkness.


 


A presidential order signed Thursday directed key federal agencies to assess preparations for a prolonged power outage resulting from cyber attacks designed to disrupt the power grid.


 


An assessment of the danger must be carried out by the Energy Department, Homeland Security, DNI and state and local governments to examine the readiness of the United State to manage a shutdown of the power grid. The assessment will also identify gaps and shortcomings in efforts that would be used restore power.


 


New cyber security measures outlined in the executive order come as the commander of Cyber Command warned two days earlier that America’s critical infrastructure is vulnerable to disruption by foreign cyber attacks. (The Washington Free Beacon)




Now that it’s obvious that small malicious powers in foreign nations already have NSA/CIA-level malware that is already being used to shut down computers all over the world, do you really think the government is going to resolve the vulnerabilities of our energy systems, transportation systems, communications systems, financial systems, and government data systems, before some malicious group or nation (like North Korea or Iran) manages to create much more mayhem than was accomplished this time?


In 2015, China stole 22 million records of federal employees, including sensitive personal data. Therefore, we know the government has already had two years to prepare; so, why are we just seeing new orders go out to analyze our points of vulnerability to hacking and viral attacks? This year has become all about accusations that Russia created a cybercoup and overthrew the US election to install its own Manchurian candidate or just to mess us up with confusion.


Apparently, we’d rather pile up national debt on more desirable (as in fun or feel-good) things than cyber security or on more conventional weapons.



Wannacry is a sign of things to come



Wannacry is a warning shot over the bow. A much more extensive viral infection could shut down the world in one day tomorrow or next week if it exploits parts of Microsoft’s OS that Microsoft hasn’t yet patched, and if the back door is that allows the virus to be shut down is not as obvious as this one was or if it has now back door that is intended as a kill switch. Financial systems (both stock markets and banks) could be wiped out in a day, triggering the need for an immediate global financial reset.


Imagine if your bank got locked out by ransomware from all of your financial data, so they couldn’t even tell you are their customer and couldn’t even access their backup data. The bank would have no record of how much money you have in the bank. Then imagine no one really intended to collect any ransom at all — so there was no opportunity to retrieve the data. Instead, the virus simply destroyed it to wreak havoc in the world or to destroy the world’s superpower.


This is where you might want some of you money to be held in physical gold. I don’t sell gold, but I do have a link in the left sidebar to a company that can help you reset your retirement funds to hold physical gold and other physical assets if you are so inclined.

Saturday, May 13, 2017

The NSA’s Virus Can Still Destroy Your Data, Here Are 5 Ways to Make Sure It Won’t




Thanks to the NSA’s apparent lust to know and see everything, agency-designed ransomware virus was unleashed on the planet yesterday, leaving anyone using a Windows system — corporations, governments, and even those who only post cat pictures online — vulnerable to exploitation for a price.


That price — $300 in Bitcoin, increasing after a given time period — would theoretically have to be paid in order to rid the infected computer of the WanaCrypt ransomware, or the victim would lose everything on their system. Ransomware literally holds your data hostage until the fee asked by attackers is paid — but if you don’t pay, you lose everything.


Everything.


WanaCrypt0r, alternately known as WanaCry, WanaCrypt, or WCry, is believed to have infected no less than 126,500 computers in 99 countries prior to the threat being partially abated — but not before it had wrought havoc on the U.K.’s National Health Service, FedEx, Spanish telecommunications company, Telefónica, and other systems around the globe.


“This is one of the largest global ransomware attacks the cyber community has ever seen,” Splunk director of threat research, Rich Barger, told Reuters. Splunk is one of several firms who divined WanaCrypt0r’s origins with the National Security Agency.


Analysts say the particularly infectious worm exploited a Microsoft software flaw, and, although the company issued a patch in March after identifying WCry in February, not all users had updated their systems accordingly.


Cybersecurity experts worked at a fever pitch to stop the malicious worm, but it took what the Guardian termed an “accidental hero” to bring a tentative halt to the pandemonium. Reports the outlet, a Twitter user, “tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and inadvertently activated a ‘kill switch’ in the malicious software.”


He “halted the global spread of an unprecedented ransomware attack by registering a garbled domain name hidden in the malware has warned the attack could be rebooted.”


And payment of the $10.69 registration fee — temporary, though the end to the exploit may be — was all it took.


A significant risk could still be lurking — after all, the attackers used tools designed by the NSA, whose entire collection of older hacking tools were leaked online last month by an entity calling itself the Shadow Brokers, and WCry could yet mutate or be altered — but there are a few ways to stay safe and prevent having precious data and files wrested from you.



1. Update, update, update


As tech outlet, Tom’s Guide, notes, “If you’ve not installed the March, April or May Windows Update bundles, do so immediately. It’s worth shutting down your system for a few minutes if it gives you a chance to avoid this.”


Windows Vista users will be protected through the March or April update bundles, and Microsoft has since issued a patch for Windows XP and its 2003 server — while the company released information to help customers cope with the ransomware virus.


2. Don’t fall hook, line, or sinker


Although WanaCrypt exploits the aforementioned Windows vulnerability, people must be vigilant — as always — not to fall for online phishing schemes, as this malware could also have been spread randomly in hopes people would open email from an unfamiliar source.


Be exceedingly cautious when visiting websites and opening attachments — WanaCry could be ready to pounce. Use common sense — and pepper it with extraordinary discretion.


3. Back it up


Cybersecurity experts constantly harangue the rest of us to backup important data and files, and — while that directive might generate an eyeroll, and grumblings about time and energy — backing up one’s system is an imperative which now cannot be ignored.


Storing vital information in a secondary location, such as a USB storage stick or external hard drive, could save you tears and headaches in the long run — particularly if WCry or another variant takes control of your system. Cloud storage could be an option — depending on which cloud you use, as the original NSA leaker and insider, Edward Snowden, has warned — but would also leave your data vulnerable in other ways.


4. Get your defenses up


Install solid, reputable antivirus software — particularly one targeting ransomware — as a line of defense against the intrusion. Experts now say WanaCrypt appears to be “wormable,” which, Tom’s Guide explains, means it spreads “from system to system by itself as a computer worm, rather than relying on human interaction as a Trojan horse, or infecting desktop applications like a traditional computer virus.”


Since most antivirus software protects and updates in real time, even if the worm breaks through your defenses, RT points out, “chances are good that within a short while an automatic antivirus update will clear the intruder from your system. Most antivirus companies offer trial versions free of charge to test before subscribing for a paid service, which should be enough if one needs to urgently remove a stray malware.”


Forbes reports, “If you have up-to-date malware protection software from a reputable cybersecurity company such as Avast installed on your computer, you are probably protected.  Check your cybersecurity company’s website to make sure you are. WanaCry is a world-wide, runaway threat. If your cybersecurity company’s website has nothing to say about it, don’t assume you are protected. Make sure you are running the current version of Windows.”


5. Keep your money


Perhaps the most basic instruction most analysts and security pros emphasize is also difficult for many to swallow. Don’t shell out the money they’re demanding — be it Bitcoin, dollars, gold, or any other iteration.


Of course, those holding your files hostage for money hope to exploit you in two insidious ways — first, by locking down your data, but second, through your emotional panic resultant from having your critical files abruptly unavailable. That alarm pumps you full of adrenaline, and could provoke a response which seems the simplest solution in the moment — forking over the funds.


If you do that, cybersecurity analysts say, no guarantee exists you’ll actually get your data back — and your willingness to do so could make you a target for future exploits — which, again, could be coming around anytime.


***


Considering the scope of the documents leaked by the Shadow Brokers, virtually anything could be possible now. This basic list will only help to an extent, and should not be considered comprehensive — nor should it be considered, of course, expert advice.


That said, the precautions offered are a bit better than leaving your system naked to malicious infection.



That “accidental hero” credited with truncating the worm’s virulent proliferation admonished the public to be wary and alert, because — although altered or ‘improved’ iterations of WanaCrypt have yet to appear online — “they will.”


“This is not over,” he told the Guardian. “The attackers will realise how we stopped it, they’ll change the code and then they’ll start again. Enable Windows update, update and then reboot.”

Snowden Blasts The NSA Over Global Malware Attack, Says They Could Have Easily Prevented It

snowden



Just one day after U.S. President Donald Trump signed an executive order designed to improve the country’s national security against cyber security threats, nearly 100 countries, including the United States, were hit with a powerful Ransomware cyber-attack. An Attack, that former National Security Advisor contractor Edward Snowden is blaming on the NSA.




It was the one of largest known cyber-attack in the history of the world and demanded frozen computers all across the globe buy bitcoin and pay in bitcoin to have their computers released.


The attack, carried out on Friday, affected and infected computer systems all across the globe, hitting the UK’s National Health Service the worst, according to some reports.


It even affected the server which hosts the Free Thought Project’s website. We experienced outages of over an hour before reverting back to our backup server in another part of the country.


Hours after the attack, carried out by unknown assailants, Snowden said it all could have been prevented.


In a series of tweets, Snowden attacked his former employer, pinning the burden of blame squarely on the backs of the NSA. Demonstrating the serious nature of the attacks, the whistleblower emphasized lives were on the line in the latest cyber attack.


The tools used in this hack were released online last month and belonged to the NSA.



Snowden, seeing the grave danger posed by the NSA’s spying and irresponsible nature, tweeted, “Whoa: decision to build attack tools targeting US software now threatens the lives of hospital patients,” indicating it was a leaked NSA cyberwar tool, created by the NSA which attacked the UK’s hospital system.




Pinning the blame on the NSA, he then tweeted, “Despite warnings, built dangerous attack tools that could target Western software. Today we see the cost:”




Graham Cluley, a computer security expert, agrees with Snowden, saying, “The US intelligence agency found a security hole in Microsoft software and rather than doing the decent thing and contacting Microsoft they kept it to themselves and exploited it for the purposes of spying. Then they themselves got hacked. And it was at that point Microsoft thought, ‘Jesus we need to patch against this thing’.”


Still acting as the patriot he claims to be, Snowden then called on Congress to call the NSA to the carpet and demand they acknowledge, address, and shore up vulnerabilities in other systems. He said in a tweet, “In light of today’s attack, Congress needs to be asking if it knows of any other vulnerabilities in software used in our hospitals.”




Not mincing words, the whistleblower — who some have called a traitor — tweeted, “If had privately disclosed the flaw used to attack hospitals when they *found* it, not when they lost it, this may not have happened.”




The blame, according to Snowden, lies within the NSA and could have been prevented. He elaborated in his follow-up tweet. The former NSA contractor said the government agency should have approached the hospital systems privately and revealed the Microsoft Windows vulnerability years ago, instead of letting the tool fall into the wrong hands and jeopardize lives.


He tweeted, “This is a special case. Had disclosed the vuln[erability] when they discovered it, hospitals would have had years — not months — to prepare.”




While it’s true that Microsoft is no longer providing updates and patches to its Windows XP platform, Snowden implied the security agency had a fiduciary responsibility to shore up any and all known vulnerabilities within XP. He tweeted, “If NSA builds a weapon to attack Windows XP—which Microsoft refuses to patches—and it falls into enemy hands, should NSA write a patch?”




Some might say Snowden’s last suggestion makes a lot of sense. Microsoft could have continued support for its aging platform, but when it didn’t, the NSA could have stepped in and provided such a security patch. Or, at the very least, informed people of the flaw.


Once again, Snowden’s words appear to haunt his former employer. In the ground shaking documentary, Citizenfour (2014), Snowden went on camera to tell the world just how powerful the NSA’s systems were, and to warn all Americans and world citizens alike of the dangers of cyber-warfare.



Only now is the world beginning to see, arguably, just how true his predictions would become. The switch has been flipped and the world is at war. The only problem is, no one knows precisely who is pulling the switches. But according to Snowden, the NSA knows how to fix it.

Friday, May 12, 2017

BREAKING: Hackers Using Tools Developed By The NSA To Launch Massive Worldwide Cyber Attack

(RT) A ransom ware virus is reported to be spreading aggressively around the globe, with over 50,000 computers having been targeted. The virus infects computer files and then demands money to unblock them.

An increase in activity of the malware was noticed starting from 8am CET (07:00 GMT) Friday, security software company Avast reported, adding that it “quickly escalated into a massive spreading.”


In a matter of hours, over 57,000 attacks have been detected worldwide, the company said.




Seventy-four countries around the globe have been affected, with the number of victims still growing, according to the Russian multinational cybersecurity and anti-virus provider, the Kaspersky Lab.





The ransomware, known as WanaCrypt0r 2.0, is believed to have infected National Health Service (NHS) hospitals in the UK and Spain’s biggest national telecommunications firm, Telefonica.




According to Avast, the ransomware has also targeted Russia, Ukraine and Taiwan.


The virus is apparently the upgraded version of the ransomware that first appeared in February. Believed to be affecting only Windows operated computers, it changes the affected file extension names to “.WNCRY.”


It then drops ransom notes to a user in a text file, demanding $300 worth of bitcoins to be paid to unlock the infected files within a certain period of time.


While the victim’s wallpaper is being changed, affected users also see a countdown timer to remind them of the limited time they have to pay the ransom.



According to the New York Times, citing security experts, the ransomware exploits a “vulnerability that was discovered and developed by the National Security Agency (NSA).” The hacking tool was leaked by a group calling itself the Shadow Brokers, the report said, adding, that it has been distributing the stolen NSA hacking tools online since last year.


"Massive" Ransomware Attack Goes Global: "This Is Huge"

We earlier reported in the disturbing fact that hospitals across the United Kingdom had gone dark due to a massive cyber-attack. The situation has got significantly worse as The BBC reports the ransomware attack has gone global.


Screenshots of a well known program that locks computers and demands a payment in Bitcoin have been shared online by parties claiming to be affected.



It is not yet clear whether the attacks are all connected. One cyber-security researcher tweeted that he had detected 36,000 instances of the ransomware, called WannaCry and variants of that name.





"This is huge," he said.



There have been reports of infections in the UK, US, China, Russia, Spain, Italy, Vietnam, Taiwan and others.


The BBB details a number of Spanish firms were among the apparent victims elsewhere in Europe.





Telecoms giant Telefonica said in a statement that it was aware of a "cybersecurity incident" but that clients and services had not been affected.



Power firm Iberdrola and utility provider Gas Natural were also reported to have suffered from the outbreak.



There were reports that staff at the firms were told to turn off their computers.



In Italy, one user shared images appearing to show a university computer lab with machines locked by the same program.



Bitcoin wallets seemingly associated with the ransomware were reported to have already started filling up with cash.





"This is a major cyber attack, impacting organisations across Europe at a scale I"ve never seen before," said security architect Kevin Beaumont.



According to security firm Check Point, the version of the ransomware that appeared today is a new variant.





"Even so, it"s spreading fast," said Aatish Pattni, head of threat prevention for northern Europe.



Several experts monitoring the situation have linked the attacks to vulnerabilities released by a group known as The Shadow Brokers, which recently claimed to have dumped hacking tools stolen from the NSA.

Saturday, January 28, 2017

War Gaming - Part 2: Cyberwarfare & Disinformation

Submitted by Bill O"Grady via Confluence Investment Management,


Yesterday, we began this two-part report by examining America’s geographic situation and how it is conducive to superpower status. This condition is problematic for foreign powers because it can be almost impossible to significantly damage America’s industrial base in a conventional war with the U.S. In addition, it would be very difficult to launch a conventional attack against the U.S. (a) with any element of surprise, and (b) without significant logistical challenges. The premise of this report is a “thought experiment” of sorts that examines the unconventional options foreign nations have to attack the U.S. Although these may not lead to regime change in America, such attacks may distract U.S. policymakers enough that foreign powers could engage in regional hegemonic actions that would otherwise be opposed by the U.S.


In Part I of this report, we discussed two potential tactics to attack the U.S., a nuclear strike and a terrorist attack. Today, we will examine cyberwarfare and disinformation. We will conclude with market effects.


#3: Cyberwarfare


Cyberwarfare is a broad tactical category, ranging from the use of computer technology in conventional warfare to hacking enemies’ industrial, financial, media, utility and social networks to gain information, monitor behavior, spread disinformation and disrupt operations of these networks. Both state and non-state actors are active in cyber activities. There is a significant criminal element as well.


The best known cyberattack was allegedly jointly created by Israel and the U.S. Dubbed “Stuxnet,” it was a computer virus which took control of systems that monitored Iran’s nuclear centrifuges. The virus returned information to its handlers and eventually was able to adversely affect the operation of the machinery itself, causing some of the centrifuges to spin out of control. Although Iran’s nuclear facilities were not directly connected to the internet, the bug was apparently introduced through a flash drive. This means that either a spy plugged a drive into Iran’s system or an innocent Iranian did it by mistake.


Initially, as reports from Iran began emerging about problems in its nuclear facilities, it was generally assumed that the Persians simply didn’t know what they were doing or had purchased faulty equipment. Eventually, Stuxnet ruined about 20% of Iran’s nuclear centrifuges. The virus turned out to be rather pervasive, spreading to Indonesia, India, Azerbaijan and Pakistan, and, interestingly enough, also infecting about 1.6% of American computers.


There are numerous other examples of cyberwarfare. The U.S. hacked insurgents’ cell phones in Iraq, allowing the American military to track their movements and even send them texts with false orders that may have led to their capture or demise. China has become notorious in its hacking of U.S. government and defense sites. Criminals routinely use “phishing” emails to gain control of individual and business computers, sometimes to “kidnap” their data (ransomware) or to simply gain their information.


Cyberwarfare carries numerous risks. As seen with Stuxnet, once released, a virus can become uncontrollable, harming friends and foes alike. It is relatively easy to conceal as it can be difficult to determine where an attack originated. In other words, a state actor could make it appear that a criminal group was responsible for the hack. Or, the criminal group could act as a mercenary for a state, giving the government plausible deniability. Governments have an incentive to co-opt and coerce technology firms to build in “back doors” that allow them to monitor information from citizens. This deliberate defect makes the product less attractive to consumers. On the other hand, an impregnable information system would be a very attractive tool for terrorists and criminals. Essentially, personal privacy is always at risk in a world where cyberattacks are possible.


Technology, for the most part, improves efficiency. Recently, my family traveled to the Caribbean which required a tour through U.S. Customs upon our return. We were checked into the country using an automated kiosk that scanned our passports, took a picture and sent us to a border agent. The following day the system crashed and what took us about 45 minutes to navigate took others up to six hours to clear. Payment systems have become increasingly electronic. This allows households to carry less cash and lets banks and other financial institutions move funds more easily through the economy. However, it also makes the system vulnerable to hackers. Banks are constantly facing threats from criminals trying to gain access to accounts.


Fraudulent purchases on credit cards are common. These acts are more easily facilitated due to technology.


In financial services, technology has changed how orders are handled. Trade execution is nearly instantaneous. The futures pits used to be populated with wildly waving traders in colorful jackets; now, these trades are executed via terminals and, in many cases, ordered by algorithm. Although this has lowered execution costs, it also makes financial markets susceptible to “flash crashes” that occasionally roil the markets.


Essentially, technology has been eliminating the number of people directly involved in processing transactions, everything from financial markets to retailing and government services. Although this makes the economy more efficient, it also makes it more fragile. If a system crashes, it can cause widespread disruptions and close firms, government agencies and markets. The U.S. economy, due to its technological advances, may be more vulnerable to cyberattacks than other nations.


Although cyberattacks won’t likely cause regime change in the U.S., it could seriously disrupt the American economy, giving a foreign power time to use conventional military means to establish regional hegemony. Thus, if China wanted to capture Taiwan or if Russia wanted to invade the Baltics, a major cyberattack, such as bringing down the electrical grid, causing dams to malfunction or disrupting air traffic control, may be enough to shift security and other officials’ attention in order to improve the odds of a successful attack.


Cyberwarfare is a significant threat to U.S. security and has very attractive characteristics. It is stealthy; the origin of the attack can be disguised and it can cause significant damage to an economy. Although the U.S. may be vulnerable to such an attack, it should be noted that American intelligence agencies and the military have significant firepower in this area as well. The difference is that disrupting the Russian economy might not matter all that much because it’s already in poor shape. But, in the U.S., shutting down the electrical grid for several days would be considered catastrophic; in fact, simply bringing down the internet might be just as bad. The U.S. faces a constant threat from cyberattacks. The key concern is what a foreign power would do with a disruption. China has already captured defense plans and personal information. So far, it has used this information to improve its own defense materials and to create countermeasures to U.S. defense goods. But the threat of a cyberattack as cover for a regional military operation is perhaps the greatest threat the U.S. currently faces.


#4: Disinformation


Disinformation is nothing new. From time immemorial, governments have tried to fool their adversaries. From America’s perspective, Radio Free Europe was broadcasting the truth to those behind the Iron Curtain. To the communists, it was pure propaganda.


There are two changes that make disinformation more dangerous. First, the technology behind news flow has changed dramatically. During the era of print media, disseminating news was rather expensive. Printing needed to occur. Journalists needed to be hired. The journalists were usually trained and there were standards of conduct that acted as a screen for reports. Although there was a “yellow press” in American history, the Cold War period was probably the golden age of journalism.


By the 1980s, cable news became an alternative to the major networks. The cable news companies discovered that they were able to capture a more reliable viewership by taking a definite slant toward the news. AM radio, as an older technology and because of its low cost, became an avenue of more extreme views. But the real change agent was the internet and social media. The internet allowed for news to be disseminated almost instantly. Social media allows common citizens to post items and videos for all to see. Regular media companies suddenly found themselves competing with citizens and their cell phones. From 1981 to 2014, the number of daily newspapers declined by 25.3%. Social media and news aggregators have the ability to screen news flow based on the viewing habits of the reader. Essentially, if one reads off the internet uncritically, they can live in a virtual news echo chamber. Thus, news, “facts” and viewpoints become hardened.


The changes in news dissemination dovetailed with changes in political polarization.



This chart is a measure of party polarization; essentially, it measures partisanship. The higher the reading on the chart, the more the political structure is partisan and polarized. Before the U.S. emerged on the world stage, there were strong disagreements on policy. There was less polarization by WWI, and during the Cold War the degree of polarization reached historical lows. In other words, regardless of political party, there was a high degree of bipartisanship.


When the Cold War ended, bipartisanship also deteriorated. Currently, the country is probably the most polarized it has been since the Civil War. Unfortunately, this degree of disunity is dangerous for a superpower because it creates conditions that can distract policymakers from global concerns.


Perhaps the greatest risk to the evolution of American hegemony was the Civil War. Although the British were the undisputed global superpower at the time, the leadership of that nation was watching the explosive economic growth in the U.S. warily. The British probably made a strategic mistake in not supporting the Confederacy because if it had survived the U.S. would have been divided and would never have achieved the same degree of power. According to historians, the political elites favored supporting the South but the public opposed it because of slavery. In addition, Queen Victoria also supported abolition and opposed the Confederacy. The British did offer some support but never enough to turn the tide.


An America divided is susceptible to disinformation. We are living in an era where “false news” is routinely disseminated. In addition, facts have become increasingly tied to social and political positions; in other words, no fact seems to exist outside a social and political context. During the Cold War, the losing political party in an election was in opposition but did work with the winner; in the current environment, the losing party believes catastrophic events are likely and the only way to ensure a better future is to resist the policy goals of the other party.


This environment allows foreign powers to influence social and political beliefs. It is clear the Russians tried to influence the U.S. presidential election. This should not come as a shock to anyone. The U.S. has done this for years; what Americans see as supporting democracy-loving activists in foreign nations looks much like meddling to foreign governments. In addition, it is routine for other nations to have lobbying efforts in the U.S., ostensibly to affect American policy.


What is surprising is that the Russians seem to have had some success, although we would argue that it probably wasn’t as significant as the media is suggesting. We believe the reason the Russians were able to find some traction with the leaks and its behavior is that the political environment allowed it to occur. A political environment in which the other party isn’t seen as merely an American with a different political position but one that is perhaps evil allows leaks and disinformation to have power.


Essentially, it appears that our current highly partisan climate has created an environment where disinformation is more likely to be accepted. If this process makes America more divided, it will reduce our ability to project power and exercise hegemony. Although disinformation probably won’t bring regime change, it can create conditions under which an aspiring regional hegemon can try to influence American public opinion in a fashion that will reduce the likelihood that the U.S. responds negatively to the aspiring regional hegemon’s encroachment. In other words, if Russia wanted to take the Baltics, it may try to use false news and internet dissemination to sway Americans to oppose U.S. and NATO intervention.


Ramifications


This report is something of a thought experiment about how foreign nations can attack a hegemon with extraordinarily favorable geographic conditions. We identified four primary methods—a nuclear strike, terrorism, cyberattack and disinformation. These are not the only methods, but we suspect these are the most likely. Two others that deserve mention are biological/chemical warfare and space. The reason we didn’t explore the former is that it is probably similar to a nuclear attack if done in scale; we would know who did it and we would not be surprised to see a state-sponsored biological attack met with a nuclear strike or a massive conventional attack. Of course, a terrorist attack using these methods could be effective but these weapons are notoriously difficult to deploy effectively. And, the U.S. has an advanced medical sector that would probably be able to cope with a small biological attack. A space attack, which could range from attacking satellites to launching weapons, is possible. However, the U.S. is probably as well prepared as any nation for such conflicts and so a pre-emptive strike would probably be met in kind. Thus, for considerations of length, we didn’t explore either of these methods in detail.


We are not likely to face a nuclear attack but the other three are quite likely and, in fact, have occurred and will likely continue to occur. Of the remaining three, we are most worried about the two discussed this week. Computer hacking by China and Russia is common; although it hasn’t led to anything that threatens civil order, the potential does exist that it could at some point.


Disinformation is another rising concern. Although this method has existed for centuries, the internet allows dissemination without filters. Thus, the ability to affect the unity of the nation and America’s capacity to mobilize against enemies to support allies could be compromised.


As noted, we believe a conventional military attack on the continental U.S. is highly unlikely. However, that doesn’t mean that aspiring regional hegemons won’t use the last three methods to improve their odds of success in local actions. The Russian concept of “hybrid war” uses the last three in combination to undermine nations in its near abroad and weaken any opposition to Russian goals of regional domination. The U.S. may become a more likely target of similar actions in order to distract America from opposing the aims of aspiring regional hegemons to expand their areas of control.


The market ramifications are complicated. Technology security firms should find steady business from the private and public sector. Media companies may face additional burdens of screening news for potential “false news” stories. Overall, though, the biggest impact may be that these factors are part of a trend where the U.S. continues to move away from the superpower role it has played since the end of WWII. We have documented and discussed these issues at length. The bottom line is that a G-0 world is one that is negative for foreign investment but probably bullish for commodities. The dollar and U.S. financial assets will likely benefit relative to foreign assets.