With the wide scale use of internet, there are different types of computer threats, that the computer networks are susceptible to. Each of these threats can cause potential damage and cause a lot of harm, if the data is lost. It is important to know the different types of threats, so that the data can be safeguarded.


Computer network as well as stand alone systems are susceptible to a number of computer threats. The damage caused by the threats can cause very high loss to the company. The danger increases, when the computer network is connected to the internet. Although there are different types of threats to computer systems, they have a common bond. They are designed to trick the user and gain access to the network or the stand alone systems or destroy the data. Some of the threats are known to replicate itself, while others destroy the files on the system or some infect the files itself.

Types of Computer Security Threats

The classification of the types of information security threats is made on the way the information in the system is compromised upon. There are the passive threats and the active threats. The passive threats are very difficult to detect and equally difficult to prevent as well. Then there are the active threats. Since these threats continue to make changes to the system, they are easy to find out and fix as well.

Virus: The most common of the types of cyber threats are the viruses. They infect different files on the computer network or on the stand alone systems. Most people fall prey to the viruses, as they trick the person into taking some action, like clicking on a malicious link, downloading a malicious file, etc. It is from these links and files, that the virus is transmitted to the computer. There are also cases of the viruses been a part of an email attachment, which may be downloaded from the internet. In some cases, the viruses can also spread through infected portable data storage as well. Hence, it is important to have an antivirus on the system, which can not only detect the virus, but be able to get rid of them as well.

Worms: The other common types of internet security threats are the worms. They are actually malicious programs, which take advantage of the weaknesses in the operating system. Like the worms in real life crawl to move from one place to another, similarly the worms in the cyber world also spread from one computer to another and from one network to another. The most prominent feature of the worms is that they are able to spread at very high rates, which can lead the system being at risk of crashing. There is a type of worm, called net worm. These worms replicates itself by sending complete and independent copes of itself over a network, thereby infecting almost all the systems on the said network.

Trojan: This is a different type of computer virus, which is disguised under the garbs of a friend. The Trojans derive their name from the legend. They make their way into the software, which may not be noticed. It is often seen, that the Trojans are a part of the different attachments in emails or download links. In some cases making a visit to certain web pages also puts the computer system at risk.

Spyware: Spyware as the name suggests spy on the network and the computer system. They may be downloaded unintentionally from different websites, email messages or instant messages. In some cases, they may also make their way through different direct file sharing connection. In some cases, clicking on 'Accept User License Agreement', can also put the computer at risk.

Rootkits: The job of the rootkits is to give cover to the hackers. The best or the worst part about rootkits is that they are able to hide themselves from the antivirus software as well, due to which the user is not aware that a rootkit is present on the system. This helps the hacker and he is able to spread malware on the system. Therefore, it is important that one opts for antivirus, which also has a rootkit scanner, which will be able to detect the invasion.

Riskware: They are dangerous applications, who often become a part of software applications. They are often seen as a part of development environment for malicious programs and spread to the software applications. In some cases, these applications can also be used by hackers as additional components to gain access in the network.

Adware: The recent addition to the list of computer threats are the adware. They are actually advertising supported software. It is not uncommon to see different advertisements or pop ups coming up on the computer, when certain applications are being used. They may not pose a lot of threat, but often lower the speed of the computers. There are chances that the computer system may become unstable because of these adware.

Cookies: When we visit a website, there are files due to which the website is able to remember the details of the computer. They are more of a threat to confidentiality as opposed to the data on the computer. In most cases, cookies may be stored on the computer without the consent of the user and data may be stored on them, which is passed back to the website server the next time, one visits the website. The data gathered may be sold to third parties and depending on the interests, which may lead to different advertisements flashing on the screen.

Phishing: Often people appear to get emails from trustworthy organizations, like banks. In some cases, the emails may come from bogus sites, which may resemble the original site or it may superimposes a bogus pop up, due to which confidential data is gathered. They are often a part of different scamming activities and often poses to the financial threats.

These were the main types of computer threats. It is important to be on the look always to ensure that the network and/or standalone systems are protected from the threats. As soon as any of the threats are detected, measures will have to be taken to get rid of them at the earliest, so that the data is protected.


Do you know your RAM from your ROM?

The technological terms are like a ticking bomb!

Do you know how to back up your data to cloud?

Or does the data assault your brain – TOO LOUD!

Is a Trojan a problem? Or is it good Luck?

Is a mouse a rodent? Is it part of a book?

Is it a pointer? Something to hold?

Does it squeak like the real thing if you are bold?

Can your web be spun through the virtual space?

Does it link to a camera and show your face?

Does your apple have pips and put up a fight

If you work it too hard creating bytes?

How is your Auntie? Old Virus herself,

Does she sweep her files and look after her health?

Does your internet access work with WiFi?

Speed slow when needed, when you don’t it’s high!

Is your broad always band? Your modem on dial?

Does it lag disappointingly for a while?

Does your disc work ok? Nice and smooth, and not slip?

Does your signal have strength and not unintentionally dip?

If you can answer my questions you’re better than me.

You manage to make it all look easy.

You have an aptitude with all things PC

You have an affinity with Tech-nol-o-gee.


Acquiring a new laptop can seem to be like an overwhelming process. Really do not be nervous, due to the fact the appropriate data can support immensely. Keep on looking through to understand how savvy laptop customers uncover the machines they call for. Be confident to have anti-virus application. Managing with no antivirus assist can leave you susceptible to destructive application invading your technique. Destructive application […]

Here we go again! Here is a Notebook infected with the same "XP Antivirus" software as the PC I worked on here.

Only this time, it is the Newest Version, HAAAAAAA! Windows "XP Antivirus 2009" instead of the Windows XP Antivirus 2008"


But, this time, there were better removal tools located on the net. Here are two great sources:



The best analogy I can think of is an auto mechanic who secretly puts sand in your oil, then offers to fix your car for a fee.


A digital murder

Programmed by mathematical terrorists

Outside of mortal bounds

Silently hacking

A binary plague

Serving information

This is the time of the hacker

This is the code of the hacker

This is the hacker

An algebra of fear


Within the language of machines

Uninfringed my human emotions

Within global systems

Silently moving

A digital maze

Cutting information

This is the way of the hacker

This is the extremity of the hacker

This is the hacker

Protect now or be erased forever


A binary virus

Unleashed by subversive programmers

Inside corporate systems

Silently eating

The endemic wave

Erasing information

This is the sign of the hacker

This is the genius of the hacker

This is the hacker

Learn now

Or be cut down forever


[ lyrics | vinyl | hear ]


I'd known I wanted to get into computers since 1980 because they were the future. Around 1983, my family bought a Commodore VIC=20, which qualified as a computer by the standards back then (4k RAM onboard, tape drive, built-in BASIC). Eventually I got versed with the Apple // family, then when I got into college IBM-compat 286's (8mb RAM, 20mb RLL hard drives with two 5¼" floppies). I've held a shrinkwrapped copy of Windows 2.1 but no one ever installed it on a school machine, DOS 4 suited everyone's needs better.


The sister of my college roomie called the other day to ask if I could have a look at her computer because it was having trouble. (This happens once or twice a year because she luuuuuve them shareware apps loaded with spyware, which she installs sight unforseen.) I should know better but I said sure.

She brought over four computers yesterday.


So the tally is this:

1 -- Yeah, indeed, seven instances of malware across 20 files. Should be better now. Just had to restore the network and WiFi functions that the removal of those spywares caused to fail... Cracks me up, the main user (her daughter) has her profile password protected, but her profile as well as the Admin profile were both unprotected.

2 -- It's dead, Jim. Seriously, that's not "sleep mode", that's a CPU that gave up its magic smoke. It's pining for the fjords. Digital dirtnap.

3 -- Do you get the feeling something bad may have happened, like a power spike, when your 256mb memory stick says it's 32mb, and your 512mb memory stick isn't recognised at all? Backed by how Windows Mistake Edition says at boot that the network card is missing or needs the drivers reinstalled, even after reinstalling the drivers and the card? (Too bad the network interface of computer #2 is onboard and the memory sticks are PC133 not PC2100 or I'd be making swaps.)

4 -- See this screencap for how bad this beast is. This Vista machine has a 2.8GHz processor and 1gb RAM but moves like molasses. Having more than one antivirus scanner doesn't solve anything, folks. She's asked me to make a backup of the hard drive from computer #2 but I figure, if she's already put it in this computer she's got access to the data. :)


That was my day. How is yours?

The purchase of a whole new computer can leave someone feeling quite excited. Your excitement might change to anxiety once you are looking at each of the choices. You wonder how to locate a computer that can best provide what you need. Read the valuable tips below for many good advice.


Make certain you provide an antivirus program. Without this software, you might be the victim of malicious software. Such dangerous software is able to take personal data and in addition slow down the computer. Anti-virus protection programs exist to distinguish and eliminate threats in your computer security. You can get some useful anti-virus programs on the net which can be free to use, and some are for sale to purchase.


Glance at the add-ons that include any computer you're considering. Most models include optional accessories. Be certain you just purchase people who are important to suit your needs. Also, be mindful as numerous add-ons are cheaper on other websites. Manufacturers typically jack the values up.


Use caution with all the products you select once you develop a desktop. Some motherboards work only with some types of processors. Its not all RAM units will continue to work with all motherboards. Search for compatibility when evaluating your components. This will save you time, money and worry when constructing a computer.


Appraise the space where your desktop computer will more than likely go. These come in different sizes. Some have small profiles, and a few use significant amounts of vertical space. You have to know what size you would like.


Review multiple sites so that you will know very well what a certain machine will offer. It is actually overwhelming once you glance at the choices, however, checking out an editor's pick list or perhaps for some reviews may help you locate a model worth your cash.


Investing in a computer can be tough, but can be created easier with all the right knowledge. Require a deep breath, relax, and set these pointers to good use. Once you get your new computer, you'll be well prepared for the greatest.


1. Installation


Before installing security software designed to protect your computer I find it's best to first ensure that your computer is already free of malware. I know it sounds like strange advice, but this can prevent many problems further down the road. To do this please follow the advice I give in my article about How to Know If Your Computer Is Infected. Note that, as mentioned in that article, I would advise that you submit all unrecognized files to Comodo to be whitelisted. That article explains how to do this. If all of the files on your computer are whitelisted you will find Comodo Internet Security to be very quiet, except when there is a possible threat.

After this is done you can download the installer. Here are the download pages for Comodo Internet Security and Comodo Firewall. Please download whichever you would like to install. If, at a later time, you decide that you want to switch from one to the other you can accomplish this by going to the start menu, finding Comodo, and selecting the option to "Add and Remove components".

Options During Installation


During installation you will first see a scren which asks you whether you want two options to be enabled. I would recommend leaving the box to "enable 'Cloud Based Behavior Analysis'..." checked. I would strongly advise that you leave this option checked. This will upload all active unrecognized programs to Comodo for analysis. These files will then either be added to the whitelist or added to the definitions for the antivirus. This will make Comodo Internet Security both easier to use and more powerful against threats. The other box, to "Send anonymous program usage...", you can uncheck if you desire, or you can leave it checked. It's entirely up to you.

Before going to the next screen select the option in the lower left-corner called "Customize Installation". In addition you should select the small option near the bottom of the windows that says "Customize Installer". This will give you the option to choose which components, and additional programs, you would like to install. You may wish to consider leaving the option to install Comodo GeekBuddy checked. This is a free trial program through which Comodo technicians can remotely diagnose, but not fix, problems with your computer. This trial period will only start once you first use it. If at a later date you decide to purchase the product then the technicians can also remotely fix any problems with your computer. However, if this does not sound useful you can deselect it. Also, if you do choose to install it you can always choose to uninstall it later.

You are also given the option to install the Comodo Dragon browser. If you do not wish to install this then deselect this option as well. You can also uncheck the option to "Install PrivDog...". This is an adblocker similar to Adblock Plus. However, it replaces most ads with ads which are verified to be safe, but which may still be able to provide the site you are viewing with some revenue. Personally, I use Adblock Plus, but the choice is yours. Once you're done, click on Back and then click Next.

On the next screen you are given the choice to change your DNS servers to Comodo Secure DNS Servers. This will automatically block any websites that Comodo knows to be dangerous. Therefore, if you are currently using the default DNS server offered by your ISP I would recommend that you consider enabling this. However, if you would prefer to use another DNS server, as is mentioned in this section of my article about How to Stay Safe While Online, or just use the default one from your ISP, then you can deselect that option. You can also uncheck the option to change your home page and search engine to Yahoo. Leaving it checked will help to support Comodo, but it is very easy to opt out if you do not wish to use Yahoo. After that you can click "Agree and Install" and the installation will begin.2. Changes To Configuration

Not long after the installation is complete, assuming you installed CIS, it will download the virus database and begin running a quick scan of your computer. Let this scan complete. Unless you have a slow internet connection this process should only take about 5-15 minutes. Either way, I would suggest letting it complete its scan. After the initial scan is completed any subsequent scans will be much faster due to Comodo's new caching technology. Once it's done you can close the scan window. However, note that once you close the scan window it will ask you to restart your computer. Do not yet allow it to restart your computer.

At this time you may also choose to disable User Account Control (UAC). Personally I do disable it. However, there are some reasons to leave it enabled. One problem is that disabling this will turn off protected mode in Internet Explorer. It will also disable file/registry virtualization for Windows Vista and Windows 7. In general, UAC controls who can run specified applications that require elevated Administrator privileges. For more information please read this article.

A) General Tweaks To The Configuration


Change Overall Configuration


One of the most important changes it to change the default configuration to Proactive Security. For an explanation of the differences between the configurations please see this page. To do this open the main window for Comodo Internet Security. Then click on the green task icon on the upper right hand corner of the Window. This will flip the screen to show you the task window, which contains the configuration options. Click on the section for "Advanced Tasks" and then select the option to "Open Advanced Settings". Make sure the dropdown menu under "General Settings" is shown and then click on the Configuration option.

Now right-click on the option for "COMODO-Proactive Security" and select Activate. It will ask you whether you want to save changes, but at this point you can select no. It will then ask you to restart your computer. Make sure you select OK on the Advanced Settings Window before selecting the option to "Reboot Now".

Other General Steps


Once your computer has started up again open up the main screen for CIS. This time click on the icon on the upper left hand corner of the screen, as shown in the picture to the right, to switch CIS to advanced view.

Then click the icon at the bottom of the windows labeled Scan. Those with CIS installed should select the option to run a "Rating Scan". Note that if you did not install the antivirus component clicking on scan will automatically begin running a rating scan. Allow this scan to complete. Unless you have a slow internet connection it should not take more than a few minutes.

What this is doing is scanning the critical areas of your computer and compiling a list of which files are already known to be safe, dangerous, or unknown. No action is required on your part as long as you already followed my advice about how to ensure that your computer is not infected. The only reason I ask you to do this now is that it will help make Comodo Internet Security a little bit faster and less resource intensive than it otherwise would have been. Once the rating scan is complete you can close the rating scan window without selecting any action for the files, unless you would like to remove some bad files or trust some unknown files which you know to be safe.

Once the scan window is closed please once again look at the main window for CIS. For the section labeled Auto-Sandbox left-click on the text where it says "Partially Limited". A drop-down menu will appear. From this I would advise that you select Untrusted. This level will provide you with protection from nearly any malware I am aware of, including ransomware. The one exception is keyloggers. Some keyloggers may still be able to log data. However, even if they are able to access any information the firewall will stop them from being able to transmit it from your computer. Thus, as long as you are careful when answering any firewall alerts you will be safe. The one exception to this is if you run CIS in Game Mode. An explanation of what this mode is, and why it is dangerous, can be found in this section.

The left-click the text next to HIPS which reads "Safe Mode" and change this to Disabled. My configuration will actually not require you to enable the HIPS. This version of Comodo Internet Security is designed in such a way that you can achieve the same amount of security without enabling the HIPS. Everything we will need is actually now contained within the Behavioral Blocker, which will provide far fewer popups.

Then once again flip the screen to get to the Tasks window. Then go to the section for "Firewall Tasks" and click on the option for "Stealth Ports". In the window which pops up click the option to "Block Incoming Connections". Then go to the section for "Advanced Tasks" and once again click on the icon for "Open Advanced Settings". We will use this window to complete the rest of the changes which will be made to the configuration. I have broken the rest of the advice into that which is applicable for each of the main components of Comodo Internet Security.

B) Configure Antivirus


Assuming you chose to install Comodo Internet Security you also installed the antivirus component. Please open the Advanced Settings again. Then, make sure the dropdown menu under "General Settings" is shown. Then click on the Updates option. You will note that the virus database is set to automatically update every 6 hours. I would actually advise that you leave that at default. The only reason I pointed it out is that it may seem strange that the antivirus should be set to update so infrequently.

The reason for this is that any program running on your computer will automatically be checked against all signatures in the cloud. Thus, as long as you are constantly connected to the internet you always have up-to-date signature protection regardless of the last time your virus database was updated. Thus the infrequent updates don't actually decrease your protection. In fact, the infrequent updates may even help to make your computer more responsive.

Next make sure the dropdown menus under "Security Settings" are shown. Click on the one for Antivirus. Then click on the one for Scans. If you do not want your computer to run scheduled scans you can slide the toggle for both scans to deactivate them. Other than that there are not really any other changes which need to be made to the antivirus component.

C) Configure Defense+


All of the most important changes I would recommend for the Defense+ component have already been made. However, there are some optional changes which you may want to consider.

Optional Change


If you like you can disable the option to "Detect installers and show privilege elevation alerts". What this will do is ensure that the only popups you get are to let you know that an application has been sandboxed. The program will not ask you whether you want to allow an application or not. Thus if you select this option you will not have to answer a single Defense+ alert. Every program, even if it is an installer, will automatically be sandboxed.

If this is not disabled running most unknown installers will prompt an unlimited rights popup, which would ask you whether you trust them. However, do note that when sandboxed many installers will not be able to install correctly. Thus, disabling that option will ensure that you receive fewer alerts, although you will still receive a few from the firewall component, but it will also cause more of the unknown programs to fail. Thus, I would recommend making this change only if you are an advanced user and are prepared for the consequences.

D) Configure Firewall


Strongly Recommended Changes


Now minimize the drop-down menu for Defense+ and open the dropdown menu for the Firewall component. Click on "Firewall Settings" and check the boxes for "Filter IPv6 traffic", "Block fragmented IP traffic", "Do Protocol Analysis", and "Enable anti-ARP spoofing". Selecting these will likely not have any negative side-affects on your browsing experience. However, if you do find that you are having trouble with your internet/network connections please try unchecking these options as they are likely the culprit. Also, although it's preferable to leave it checked, in some cases the option to "Filter loopback traffic" may cause certain DNS services to not work correctly. This is rare, but if this happens you can uncheck the option to "Filter loopback traffic". However, as long as there are no problems I would advise that you leave it checked.Optional Change

Also, if you do not want any unknown programs to be able to access the internet you can check the box for "Do NOT show popup alerts" and then change the behavior to "Block Requests". This will automatically block all unknown applications from accessing the internet. Thus, if you select this option, and the optional one for the Defense+ component, the only popups you will see are those for the sandbox. Also, note that the sandbox popups do not require any user input. Thus, Comodo Internet Security will now be entirely automated and will require no user input at all.

However, making this change to the firewall configuration will cause some unknown programs to not be able to operate correctly and will also result in any unknown installer, which must download files from the internet, failing. Thus, I would recommend making this change only if you are an advanced user and are prepared for the consequences. Note that if you do run into problems with this change, you should just uncheck the option.

When you are done making your changes select OK. This will save all changes and close the advanced settings window.

3. Advice On How To Use Comodo Internet Security


How To Answer Defense+/Sandbox/Firewall Alerts


In terms of how to use this program it's really quite simple, at least for the most part. The main problem is that although there are very few alerts which you will have to answer, there are still some decisions which will have to be made. For ordinary sandbox alerts no action will be required on your part. CIS will just show a small popup on the lower right-hand corner of the screen to let you know the application has been sandboxed. However, this popup will provide you with the option to trust the application.

For any popups, regardless of which component they are from, it is very important that you do not just allow an application because you want to get rid of the alert. If you do this you greatly decrease the protection offered by Comodo Internet Security. In general, regardless of what the alert is asking, you should only allow a program access to your computer if you are absolutely sure that it is safe.

If you're not sure whether an application is safe or not I would advise that before allowing it you take some time to check it by following the advice I give in my article about How to Tell if a File is Malicious. However, if you're not sure what to do I would advise that you select the option to block the request or, if it is a sandbox alert, do nothing and leave the application sandboxed. If you do otherwise you may inadvertently allow a malicious program access to your computer.Overview of What Game Mode Is

CIS also has an option called "Game Mode". If you choose use this no Defense+ alerts, Firewall alerts, update popups, or scheduled scans will be shown or run. Thus, these cannot interfere with what you are doing. However, what enabling this will also do is create automatic allow rules for all running applications. Thus, running your computer in game mode will essentially put your computer in training mode, which I would not advise as I consider it to be dangerous. Thus, I would advise that you do not use "Game Mode".

Brief Overview of How the Behavioral Blocker Works


Also, I would quickly like to briefly mention the way in which Comodo's behavioral blocker works. If a piece of malware is not yet detected as dangerous by Comodo it will automatically be sandboxed. When in the sandbox it may be able to run, drop files in certain folders, display windows, and perform other actions which may seem alarming. However, do not worry.

The sandbox is watching every action the application tries to make sure that it will not allow it to do anything which can actually harm the computer. Also, the application will not be able to automatically start itself. Thus, once you restart your computer, regardless of how dangerous the malware might have been, the malware will be rendered completely inert upon restart.

However, those files dropped by it may still be sitting on your computer. Other malware scanners may flag these as dangerous and thus it would appear that Comodo Internet Security allowed the computer to be infected. This is not true. In truth, malware is only dangerous if it is active and able to harm your computer or steal information. Thus, since these files are completely inert, you can see that the approach Comodo Internet Security takes towards protecting your computer actually does protect it from all types of malware. Just because there are some leftover files on your computer does not mean that your computer is infected.

Overview of Comodo Virtual Desktop


Comodo Virtual Desktop creates a fully virtualized environment on your computer. It can be accessed by going to the tasks window, going to the "Sandbox Tasks" section, and clicking on "Run Virtual Desktop". This starts the fully virtualized environment which is mainly meant to be used for web related activities. It is not really designed for installing other programs, although many programs will install correctly inside of it. In addition, any programs which are installed on your real computer, and have a shortcut sitting on the desktop, will be able to be launched from inside the Virtual Desktop. However, note that in order to access them you will need to switch from the tablet screen to the desktop screen. This is done by flipping the window by clicking on the orange icon, just as you would with the CIS window.

Also, please do be aware that due to restrictions, which help protect you from dangerous malware, there are certain types of programs which will not be able to run inside the Virtual Desktop. Also, note that if the Virtual Desktop is closed and then started again no applications will initially be running. This would include any malware which may have been running. Thus, I would recommend that before performing sensitive actions such as online banking you at least close the Virtual Desktop and then open it again just before you go to the banking site. If you like you can even choose the option to "Reset Sandbox", which will delete all information which was inside it and provide you with an entirely fresh sandbox the next time you run the Virtual Desktop.

Also, the shared space folder, of which a shortcut is placed on your desktop during installation and an icon is placed in the main window for CIS, is the folder which is shared by both your actual computer and the Comodo Virtual Desktop. Thus, any files placed in there will be shared between the two environments.

Optional Cosmetic Changes


If you would like to run your browser sandboxed, but would prefer not to use the Virtual Desktop, you can instead use the widget. This is the small window which has been added to your desktop. This will automatically detect and display all browsers currently installed on your computer, along with other useful information. Clicking on the icon for that browser will cause it to be run sandboxed with full-virtualization. Note that you can also right-click on the CIS icon and either add or remove information from the widget.

Please note that any changes you make to the browser while sandboxed, such as bookmarking a page, will not be saved to your unsandboxed browser and will in fact be deleted when you reset the sandbox. Note that if you do not want to use the widget you can remove it by right-clicking on the CIS icon, selecting Widget, and unchecking the option to Show. Personally, I use it often, but if you find it an eyesore it is easy to remove.

Also, if you would prefer not to receive messages from the COMODO Message Center you can disable this by going to the CIS Task window. Then go to the "Advanced Tasks" section and click on "Advanced Settings". Then make sure the dropdown menu under "General Settings" is shown and click on "User Interface". Then disable the option to "Show messages from COMODO Message Center". These messages have nothing to do with the protection of your computer and, if you like, can safely be disabled. While in this same area you can also choose to disable the sounds which CIS now plays when an alert is shown, if you wish. When you are done select OK to save your changes and close the window.

The main window of Comodo Internet Security now provides you with the option to add task shortcuts to the task bar at the bottom of the window. To add additional task shortcuts you can flip the screen to the task window, navigate to the task you want to make a shortcut of, right click on the icon for it, and select "Add to Task Bar". I would suggest you do this for any tasks which you find you are using often. Note that you are also given the ability to drag the icons around on the main window.4. What To Do If You Have Further Questions

Note that if at any time after installing this product you encounter serious problems with it, which running the diagnostics cannot fix, it may be helpful to reinstall it. If you do decide to reinstall Comodo Internet Security it's best to do this by following the steps I outline in my post on this page.

If you do have any other questions please peruse the online help files, which can be found on this page. If you still have questions then I would advise that you search the Comodo Forums for a solution. If someone hasn't already created a post with the same problem please feel free to join the forum and create a post of your own. The community will do their best to help you with any problems that you may encounter.


As seen in an Arizona Corporation Commission (Engineering Dept) office last week. The poster looks like it's from the 80s.

Mforting to the unsuccessful, that a play fails


I like many others were stoked when the myriad of windows 8 tablets were announced back in October. Several months and delays later most of them have started to appear. This tablet is in hard competition with others such as the Samsung 500t and the Asus vivo, tablets that have support for styluses. I choose the Lenovo as it was the only tablet with a stylus that had a 10.1 inch screen; I had held and tested several of the 11.1 inch models in various stores and I found them too big. In addition they were not very well balanced in my hand when carrying around. For me the 10.1 size is on the edge of comfortable, and while I might have preferred a 9 inch instead it is light enough and small enough that it feels like a device I will continue to carry around, even after the novelty of a new devices goes away. The build quality feels solid, the tablet also feels like a quality product that can withstand daily abuse and use. The tablet came preloaded with some crapware, but not much. Biggest drawback was Norton Suite, that company should have been forced to close a long time ago. Had to download an additional uninstaller from their site to completely remove their software, leaving it in would probably have been worse than having any viruses, so it had to be done. Windows 8 comes preloaded with a very good antivirus, so there is really no need to use Norton at all, ever. In addition some of the Lenovo &34;bundled&34; software are more or less just links to paid versions from thirdparty publishers that you can get for a discounted price, in other words not that awesome, but easy to get rid of at least. Pros 10.1 screen, a bit smaller physical size than its competition. Lightweight, among the lightest of the Atom tablets. Stylus, this is simply awesome and makes the transition from keyboardmouse to touch easier. 64gb storage built in, and a microSD slot for expansion. Small amount of crapware preinstalled. Good battery time, lasts me a day at work with some extra to spare for when I get home USB charging cable, no proprietorial connector means that you can replace the charger and cable for cheap, or buy spare ones. Full size USB port, makes data transfers and doing backups easy. Can use any windows software you already have or decide to download, dont have to go through an app store. Cons Intel SoC graphics, so far not impressed, but maybe this could be resolved with updated drivers in the future. 32 App updates and 28 System updates should be installed once you boot up, system is not uptodate, plan on spending an hour or so (depending on download speed) to complete this. The included charging cord is 3 feet long, hardly reaching anywhere; need a power outlet at your desk or the optional docking station. Good thing is that its USB and not propriatory, so I could buy a longer one for cheap. Windows media player seems to downscale videos, making them look pixelated and horrible in fullscreen. Fixed this by downloading VLC ( and using that for media playback instead. Lacking App store, this will change I guess in the coming months. I expected this though as an early adopter, but I still somewhat miss the numbers of alternatives the Google play store have. Final words So far I love this device, screen is bright and clear even outside, its lightweight and have ample battery time for my use. However it should be noted that this is a productivity device (Office and mobile office duties, webbrowsing, programming, light drawing and illustrating and other nonintensive tasks), if your main use is playing games, editing raw pictures or video then you are probably gonna be less impressed. Overall this is everything I expected it to be and a little bit more.

It’s Way Too Easy to

Hack the Hospital

Firewalls and medical devices are extremely vulnerable, and everyone’s pointing fingers

By Monte Reel and Jordan Robertson | November 2015

from Bloomberg Businessweek


In the fall of 2013, Billy Rios flew from his home in California to Rochester, Minn., for an assignment at the Mayo Clinic, the largest integrated nonprofit medical group practice in the world. Rios is a “white hat” hacker, which means customers hire him to break into their own computers. His roster of clients has included the Pentagon, major defense contractors, Microsoft, Google, and some others he can’t talk about.

Animated gif graphic illustration of a flailing IV drip in the style of ascii shaders done in Cinema 4D by Steph

He’s tinkered with weapons systems, with aircraft components, and even with the electrical grid, hacking into the largest public utility district in Washington state to show officials how they might improve public safety. The Mayo Clinic job, in comparison, seemed pretty tame. He assumed he was going on a routine bug hunt, a week of solo work in clean and quiet rooms.


But when he showed up, he was surprised to find himself in a conference room full of familiar faces. The Mayo Clinic had assembled an all-star team of about a dozen computer jocks, investigators from some of the biggest cybersecurity firms in the country, as well as the kind of hackers who draw crowds at conferences such as Black Hat and Def Con. The researchers split into teams, and hospital officials presented them with about 40 different medical devices. Do your worst, the researchers were instructed. Hack whatever you can.


Like the printers, copiers, and office telephones used across all industries, many medical devices today are networked, running standard operating systems and living on the Internet just as laptops and smartphones do. Like the rest of the Internet of Things—devices that range from cars to garden sprinklers—they communicate with servers, and many can be controlled remotely. As quickly became apparent to Rios and the others, hospital administrators have a lot of reasons to fear hackers. For a full week, the group spent their days looking for backdoors into magnetic resonance imaging scanners, ultrasound equipment, ventilators, electroconvulsive therapy machines, and dozens of other contraptions. The teams gathered each evening inside the hospital to trade casualty reports.


“Every day, it was like every device on the menu got crushed,” Rios says. “It was all bad. Really, really bad.” The teams didn’t have time to dive deeply into the vulnerabilities they found, partly because they found so many—defenseless operating systems, generic passwords that couldn’t be changed, and so on.


The Mayo Clinic emerged from those sessions with a fresh set of security requirements for its medical device suppliers, requiring that each device be tested to meet standards before purchasing contracts were signed. Rios applauded the clinic, but he knew that only a few hospitals in the world had the resources and influence to pull that off, and he walked away from the job with an unshakable conviction: Sooner or later, hospitals would be hacked, and patients would be hurt. He’d gotten privileged glimpses into all sorts of sensitive industries, but hospitals seemed at least a decade behind the standard security curve.

“Every day, it was like every device on the menu got crushed,” Rios says. “It was all bad. Really, really bad.”|


“Someone is going to take it to the next level. They always do,” says Rios. “The second someone tries to do this, they’ll be able to do it. The only barrier is the goodwill of a stranger.”


Rios lives on a quiet street in Half Moon Bay, a town about 25 miles south of San Francisco, pressed against a rugged curl of coastline where scary, 50-foot waves attract the state’s gutsiest surfers. He’s 37, a former U.S. Marine and veteran of the war in Iraq. In the Marines, Rios worked in a signal intelligence unit and afterward took a position at the Defense Information Systems Agency. He practices jiu-jitsu, wanders the beach in board shorts, and shares his house with his wife, a 6-year-old daughter, and a 4-year-old son. His small home office is crowded with computers, a soldering station, and a slew of medical devices.


Shortly after flying home from the Mayo gig, Rios ordered his first device—a Hospira Symbiq infusion pump. He wasn’t targeting that particular manufacturer or model to investigate; he simply happened to find one posted on EBay for about $100. It was an odd feeling, putting it in his online shopping cart. Was buying one of these without some sort of license even legal? he wondered. Is it OK to crack this open?


Infusion pumps can be found in almost every hospital room, usually affixed to a metal stand next to the patient’s bed, automatically delivering intravenous drips, injectable drugs, or other fluids into a patient’s bloodstream. Hospira, a company that was bought by Pfizer this year, is a leading manufacturer of the devices, with several different models on the market. On the company’s website, an article explains that “smart pumps” are designed to improve patient safety by automating intravenous drug delivery, which it says accounts for 56 percent of all medication errors.


Rios connected his pump to a computer network, just as a hospital would, and discovered it was possible to remotely take over the machine and “press” the buttons on the device’s touchscreen, as if someone were standing right in front of it. He found that he could set the machine to dump an entire vial of medication into a patient. A doctor or nurse standing in front of the machine might be able to spot such a manipulation and stop the infusion before the entire vial empties, but a hospital staff member keeping an eye on the pump from a centralized monitoring station wouldn’t notice a thing, he says.

Photograph of Billy Rios, subject of this story, in a U.S. Open t-shirt and blue jeans, casual post reclining on swivel chair on hardwood floor. An exposed sheetless mattress with coiled cord atop is visible on the right side. Various framed certificates and degrees hang in the background.

Rios grew interested in security flaws in medical devices after an assignment at the Mayo Clinic in 2013.

Photographer: Graeme Mitchell for Bloomberg Businessweek


In the spring of 2014, Rios typed up his findings and sent them to the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT). In his report, he listed the vulnerabilities he had found and suggested that Hospira conduct further analysis to answer two questions: Could the same vulnerabilities exist in other Hospira devices? And what potential consequences could the flaws present for patients? DHS in turn contacted the Food and Drug Administration, which forwarded the report to Hospira. Months passed, and Rios got no response from the manufacturer and received no indication that government regulators planned to take action.


“The FDA seems to literally be waiting for someone to be killed before they can say, ‘OK, yeah, this is something we need to worry about,’ ” Rios says.


Rios is one of a small group of independent researchers who have targeted the medical device sector in recent years, exploiting the security flaws they’ve uncovered to dramatic effect. Jay Radcliffe, a researcher and a diabetic, appeared at the 2011 Def Con hacking conference to demonstrate how he could hijack his Medtronic insulin pump, manipulating it to deliver a potentially lethal dose. The following year, Barnaby Jack, a hacker from New Zealand, showed attendees at a conference in Australia how he could remotely hack a pacemaker to deliver a dangerous shock. In 2013, Jack died of a drug overdose one week before he was scheduled to attend Black Hat, where he promised to unveil a system that could pinpoint any wirelessly connected insulin pumps within a 300-foot radius, then alter the insulin doses they administered.


Such attacks angered device makers and hospital administrators, who say the staged hacks threatened to scare the public away from technologies that do far more good than harm. At an industry forum last year, a hospital IT administrator lost his temper, lashing out at Rios and other researchers for stoking hysteria when, in fact, not a single incident of patient harm has ever been attributed to lax cybersecurity in a medical device. “I appreciate you wanting to jump in,” Rick Hampton, wireless communications manager for Partners HealthCare System, said, “but frankly, some of the National Enquirer headlines that you guys create cause nothing but problems.” Another time, Rios was shouted at by device vendors on a conference call while dozens of industry executives and federal officials listened in. “It wasn’t just someone saying, ‘Hey, you suck,’ or something,” Rios remembers, “but truly, literally, screaming.”


“All their devices are getting compromised, all their systems are getting compromised,” he continues. “All their clinical applications are getting compromised—and no one cares. It’s just ridiculous, right? And anyone who tries to justify that it’s OK is not living in this world. They’re in a fantasyland.”

Animated gif graphic of a human being inserted into an MRI machine over and over and over again. The interior of the machine is flashing in a psychedelic vortex of colors. The human's silhouette is shaded in 1s and 0s, green on black, in the style of classic computer binary code.


Last fall analysts with TrapX Security, a firm based in San Mateo, Calif., began installing software in more than 60 hospitals to trace medical device hacks. TrapX created virtual replicas of specific medical devices and installed them as though they were online and running. To a hacker, the operating system of a fake CT scan device planted by TrapX would appear no different than the real thing. But unlike the real machines, the fake devices allowed TrapX to monitor the movements of the hackers across the hospital network. After six months, TrapX concluded that all of the hospitals contained medical devices that had been infected by malware.


In several cases, the hackers “spear phished” hospital staffers, luring them into opening e-mails that appeared to come from senders they knew, which infected hospital computers when they fell for the bait. In one case, hackers penetrated the computer at a nurses’ station, and from there the malware spread throughout the network, eventually slipping into radiological machines, blood gas analyzers, and other devices. Many of the machines ran on cheap, antiquated operating systems, such as Windows XP and even Windows 2000. The hospital’s antivirus protections quickly scrubbed the computer at the nurses’ station, but the medical devices weren’t so well guarded.


Many of the hospitals that participated in the study rely on the device manufacturers to maintain security on the machines, says Carl Wright, general manager for TrapX. That service is often sporadic, he says, and tends to be reactive rather than preventive. “These medical devices aren’t presenting any indication or warning to the provider that someone is attacking it, and they can’t defend themselves at all,” says Wright, who is a former information security officer for the U.S. military.


After hackers had compromised a medical device in a hospital, they lurked there, using the machine as a permanent base from which to probe the hospital network. Their goal, according to Wright, was to steal personal medical data.

Two hands reach out of a black screen on a medical computer. The hands are again shaded in green-on-black binary code. The computer is mounted on a rolling rack, so that it might more easily be maneuvered around the emergency room and such.


A credit card is good only until its expiration date and becomes almost useless as soon as the owner notices that it has been stolen. Medical profiles often contain that same credit card information, as well as Social Security numbers, addresses, dates of birth, familial relationships, and medical histories—tools that can be used to establish false identities and lines of credit, to conduct insurance fraud, or even for blackmail. Simple credit card numbers often sell for less than $10 on the Web’s black market; medical profiles can fetch 10 times as much. For a hacker, it’s all about resale value.


The decoy devices that TrapX analysts set up in hospitals allowed them to observe hackers attempting to take medical records out of the hospitals through the infected devices. The trail, Wright says, led them to a server in Eastern Europe believed to be controlled by a known Russian criminal syndicate. Basically, they would log on from their control server in Eastern Europe to a blood gas analyzer; they’d then go from the BGA to a data source, pull the records back to the BGA, and then out. Wright says they were able to determine that hackers were taking data out through medical devices because, to take one example, they found patient data in a blood gas analyzer, where it wasn’t supposed to be.


In addition to the command-and-control malware that allowed the records to be swiped, TrapX also found a bug called Citadel, ransomware that’s designed to restrict a user’s access to his or her own files, which allows hackers to demand payment to restore that access. The researchers found no evidence suggesting the hackers had actually ransomed the machines, but its mere presence was unsettling. “That stuff is only used for one purpose,” Wright says.


Hospitals generally keep network breaches to themselves. Even so, scattered reports of disruptions caused by malware have surfaced. In 2011, the Gwinnett Medical Center in Lawrenceville, Ga., shut its doors to all non-emergency patients for three days after a virus crippled its computer system. Doctor’s offices in the U.S. and Australia have reported cases of cybercriminals encrypting patient databases and demanding ransom payments. Auditing firm KPMG released a survey in August that indicated 81 percent of health information technology executives said the computer systems at their workplaces had been compromised by a cyber attack within the past two years.


Watching all this, Rios grew anxious for federal regulators to pay attention to the vulnerabilities he’d found in the Hospira pump. In the summer of 2014 he sent reminders to the Department of Homeland Security, asking if Hospira had responded to his suggestions. According to an e-mail from DHS, the company was “not interested in verifying that other pumps are vulnerable.”


A few weeks after he received that message, an increasingly frustrated Rios found himself in a vulnerable position: immobilized in a hospital bed, utterly dependent upon, of all things, an infusion pump.

“We have to create videos and write real exploit code that could really kill somebody in order for anything to be taken seriously.”|


Late last July, Rios began snoring loudly, which interrupted his sleep enough that he went to a doctor, who discovered a polyp inside his nose, near the cerebral membrane. The polyp was removed—a simple outpatient procedure—but days later Rios developed a fever and noticed clear liquid leaking from his nose. Years before, he’d broken it, and the doctors thought the polyp had grown around scar tissue. When the polyp was removed, some of the scar tissue that had protected his brain casing must have been clipped, too. The clear liquid coming out of his nose was cerebral fluid.


He spent two weeks at Stanford Hospital, in a room filled with the kind of gadgetry he’d been breaking into. After a few dazed days in bed, he got his bearings and assessed his situation. His bed was plugged into a network jack. The pressure bands strapped around his legs, which periodically squeezed his calves to aid circulation, were also connected to a computer. He counted 16 networked devices in his room, and eight wireless access points. The most obvious of these was the CareFusion infusion pump, a brand he hadn’t looked into yet, that controlled the fluids that were pumped into his arm. “It wasn’t like I was going to turn to the doctor and say, ‘Don’t hook me up to that infusion pump!’ ” Rios recalls. “I needed that thing.”


He noticed that the other patient in his room, separated from him by a curtain, was connected to a Hospira pump. “I kept thinking, ‘Should I tell him?’ ” Rios says. He opted for silence.


When he was able to drag himself out of bed, Rios wheeled his infusion pump into the bathroom, where he gave it a good once-over. “I’m looking at the wireless card, pushing the buttons on it, seeing what menus I can get to,” he recalls. It only inflamed his concerns. “Whatever Wi-Fi password they’re using to let the pump join the network, I could get that off the pump pretty easily.”


In the hallway just outside his room, Rios found a computerized dispensary that stored medications in locked drawers. Doctors and nurses normally used coded identification badges to operate the machine. But Rios had examined the security system before, and he knew it had a built-in vulnerability: a hard-coded password that would allow him to “jackpot” every drawer in the cabinet. Such generic passwords are common in many medical devices, installed to allow service technicians to access their systems, and many of them cannot be changed. Rios and a partner had already alerted Homeland Security about those password vulnerabilities, and the agency had issued notices to vendors informing them of his findings. But nothing, at least at this hospital, had been done. In the hallway, he quickly discovered that all the medications in the device’s drawers could have been his for the taking. “They hadn’t patched it at this point, so I was testing some passwords on it, and I was like, ‘This s--- works!’ ”


He didn’t touch any drugs, he says, but when he was released, he tried to turn up the heat on Hospira. He’d already told the federal government that he knew how to sabotage the pumps, but after he returned home he decided to make a video to show them how easily it could be done. He aimed the camera directly at the infusion pump’s touchscreen and demonstrated how he could remotely press the buttons, speeding through password protections, unlocking the infuser, and manipulating the machine at will. Then he wrote out sample computer code and sent it to the DHS and the FDA so they could test his work for themselves.

Pills shoot erratically out of a plastic container, conceptually signifying overdispensing pills.


“We have to create videos and write real exploit code that could really kill somebody in order for anything to be taken seriously,” Rios says. “It’s not the right way.”


But it got the FDA’s attention. Finally, after more than a year of hectoring from Rios, the FDA in July issued an advisory urging hospitals to stop using the Hospira Symbiq infusion pump because it “could allow an unauthorized user to control the device and change the dosage the pump delivers.”


“It’s viewed as precedent-setting,” says Suzanne Schwartz, who coordinates cybersecurity initiatives for the FDA’s Center for Devices and Radiological Health. “It’s the first time we’ve called out a product specifically on a cybersecurity issue.”


“There have been no known breaches of a Hospira product in a clinical setting, and the company has worked with industry stakeholders to make sure that doesn’t happen,” says MacKay Jimeson, a spokesman for Pfizer.


The medical research community didn’t break out in celebration over the advisory. Hospira said that it would work with vendors to remedy any problems and that the Symbiq model was off the market. But the advisory was merely that: It didn’t force the company to fix the machines that were already in hospitals and clinics, and it didn’t require the company to prove that similar cybersecurity flaws didn’t also affect its other pump models. For some researchers, the advisory felt like a hollow victory.


“It was the moment we realized that the FDA really was a toothless dragon in this situation,” says Mike Ahmadi, a researcher active in the medical device sector.


The FDA’s challenge is a tricky one: to draft regulations that are specific enough to matter yet general enough to outlast threats that mutate and adapt much faster than the products the agency must certify. The agency finalized a set of guidelines last October that recommended—but didn’t require—that medical device manufacturers consider cybersecurity risks in their design and development phases and that they submit documentation to the agency identifying any potential risks they’ve discovered. But the onus doesn’t rest solely on manufacturers; Schwartz emphasizes that providers and regulators also need to address the challenge, which she calls one “of shared responsibility and shared ownership.”


Divvying up that responsibility is where things get messy. After the guidelines were published, the American Hospital Association sent a letter to the FDA saying health-care providers were happy to do their part, but it urged the agency to do more to “hold device manufacturers accountable for cybersecurity.” It said device vendors need to respond faster to vulnerabilities and patch problems when they occur. Device vendors, meanwhile, have pointed out that to be hacked, criminals first need to breach the firewalls at hospitals and clinics; so why was everyone talking about regulating the devices when the providers clearly needed to improve their network protections? Hospira, in a statement issued after the FDA advisory, labeled hospital firewalls and network security “the primary defense against tampering with medical devices” and said its own internal protections “add an additional layer of security.” Others have suggested that security researchers such as Rios are pressuring the industry to adopt security measures that might get in the way of patient care.

“It was the moment we realized that the FDA really was a toothless dragon in this situation.”|


At a forum sponsored by the FDA to discuss the guidelines, an anesthesiologist from Massachusetts General Hospital in Boston used the example of automated medicine cabinets, like the one that Rios had cracked, to make this point. After Rios told the government about the password vulnerability, some hospitals began instituting fingerprint scans as a backup security measure. “Now, one usually wears gloves in the operating room,” Dr. Julian Goldman told those at the forum. Fumbling with those gloves, fiddling with the drawer, making sure no contaminated blood got near the exposed hands, yanking the gloves back on—it turned out to be a maddening hassle, he suggested, and a potentially dangerous waste of time. “I can tell you that it certainly brings it home when you suddenly need something,” Goldman said, “and as you’re turning around to reach for the drawers, you hear click-click-click-click, and they lock, just as you are reaching for the drawers to get access to a critical drug.”


Rios says he doesn’t care how manufacturers or hospitals fix the problem, so long as they do something. The Hospira saga convinced him that the only way for that to happen is to continue to pressure manufacturers, calling them out by name until they’re forced to pay attention. That automated medicine cabinet wasn’t the only device he’d found with a hard-coded password; along with research partner Terry McCorkle, Rios found the same vulnerability in about 300 different devices made by about 40 different companies. The names of those vendors weren’t released when the government issued its notice about the problem, and Rios says none of them has fixed the password problem. “What that shows me,” he says, “is that without pressure on a particular vendor, they’re not going to do anything.”

A hospital bed spins 360 degrees. It features a tray attachment mounted on a rail that lets it move the length of the bed. The pillow is small, flat, and potentially unfluffled.


Since the FDA’s Hospira advisory was issued this July, boxes of medical devices have continued to arrive on Rios’s doorstep in Half Moon Bay, and they’ve crowded his office so much that he’s been forced to relocate some to his garage. No one is paying him to try to hack them, and no one is reimbursing his expenses. “I’ve been lucky, and I’ve done well, so it’s not that big of a deal for me to buy a $2,000 infusion pump and look at it whenever I have time,” he says.

The cover of the award-winning magazine Bloomberg Businessweek.

Featured in Bloomberg Businessweek, Nov. 16, 2015. Subscribe now.

Photographer: Graeme Mitchell for Bloomberg Businessweek


For novice independent researchers, however, access to devices can be a forbidding barrier to work in this field. Infusion pumps are relatively affordable, but MRI machines, for example, cost hundreds of thousands of dollars, if not more. And radiological equipment requires a special license. To encourage more research on devices, Rios is trying to establish a lending library of medical equipment; he and a group of partners have begun lobbying hospitals for used devices, and they’re hoping to crowdsource the purchase of new ones.


The buzz that surrounded the Hospira advisory this year might have done more to attract new researchers to the field than anything Rios could do. Kevin Fu, a professor of engineering who oversees the Archimedes Research Center for Medical Device Security at the University of Michigan, has been investigating medical device security for more than a decade, and he’s never seen as much interest in the field as he’s noticed this year. “Every day I hear of another name I hadn’t heard before, somebody who hadn’t been doing anything with medical devices,” Fu says. “And out of the blue, they find some problems.”


On a sunny fall day in Half Moon Bay, Rios grabs an iced coffee at a Starbucks in the city center. He’s fresh off a week of work in Oklahoma—one of those assignments he can’t talk about—and he’s looking forward to some family time. Maybe in a spare moment, he’ll grab one of the devices in his office and see what flaws he can find inside it.


One of those machines is exerting a powerful pull on him, as if begging to be hacked. After he was released from the hospital last year, he surfed around online and found the same CareFusion pump that had been tethered to him for two weeks. It now sits near a filing cabinet in his office.


“It’s next,” Rios says.


28 Sep 2015, Exchange Server 2016 lets you accomplish more across phones, tablets, desktop

, and the Web.28 сен 2015, Exchange Server 2016 позволяет выполнять множество задач на телефонах,

планшетах, компьютерах и в Интернете.Full-featured Exchange Server 2013 product evaluation software available for

EXE download.Microsoft Exchange Server download and additional information, actions that

Microsoft Exchange Server can perform with each of its associated file type beta.Internet gateway for Microsoft Exchange server retrieves messages from single

and multiple recipient POP3 accounts.ESET Mail Security for Microsoft Exchange Server eliminates all types of, Real

File Type Detection NEW, Download ESET Remote Administrator Console.ESET Mail Security for Microsoft Exchange Server. Download, Award-winning

technology – holder of the VB SPAM+ award; Real File Type Detection – withAvira AntiVir Exchange provides real-time protection against viruses, spam,

adware,, Solid antivirus protection for Microsoft Exchange Server, Download.The product you are about to download can be managed remotely using ESET,

ESET Mail Security for Microsoft Exchange Server - user guide (3.4 MB).5 May 2015, FND2204 Get a first look at Exchange Server 2016, the on-premises, Come

learn about the innovation in Exchange Server 2016 that will help you keep., To

download, right click the file type you would like and pick “Save target as…,

High quality only downloaded 1MB and would not play at all, midMailScan for Microsoft Exchange Server is an advanced Real-time Anti-Spam

and Anti-Virus solution specially designed for MS Exchange Server. It uses

VSAPISafeguard your Microsoft Exchange with ESET Mail Securitys real-time

protection from known and, Real File Type Detection – with policies for specific

e-mail attachment content, . Download - Product installers and documentation.5 May 2015, Servicing Microsoft Exchange Server: Update Your Knowledge, Download,

takes a close look at the servicing model for Exchange Server.4 May 2015, Automating Microsoft Exchange Server 2013 Configuration with, Download, to

Exchange installation, to DAG and Database configuration,NOTE: To open 64-bit Offline Exchange 2007, 2010 or 2013 databases you

MUST install DigiScope:registered:, DigiScope:registered: uses native Microsoft Messaging

Application Program Interface (MAPI) to communicate with Production/Online

Exchange servers, ensuring reliable and consistent operation of your server., A

file type of ".Microsoft Exchange Server download and additional information, ESET Mail Security for Microsoft Exchange Server eliminates all types of, File Type Detection NEW, ESET Mail Security for Microsoft Exchange Server.Solid antivirus protection for Microsoft Exchange Server, The product you are about to download can be managed remotely using ESET, May 2015, FND2204 Get a first look at Exchange Server 2016, the on-premises, Exchange Server 2016 that will help you keep.Save target as…, Anti-Virus solution specially designed for MS Exchange Server.May 2015, Servicing Microsoft Exchange Server: Update Your Knowledge, May 2015, Automating Microsoft Exchange Server 2013 Configuration with, MUST install DigiScope:registered:, Exchange servers, ensuring reliable and consistent operation of your server.

You need to care for your tech devices in much the same way as you do your own body – looking after both inside and out. Whether it’s your mobile phone, desktop, laptop or tablet; games console or smart watch you need to look after both its hardware and software. These items can be pretty expensive to buy and to fix; having to live without them is unthinkable for some! Here are the top 4 things you need to do to properly care for your tech devices and keep them in tip-top condition.


Invest in screen protectors, covers and cases


If you’re anything like us, you use your computer and phone whilst eating or drinking at the same time. Even if you think you’re being really careful, they still tend to get a bit sticky and grubby. Keep your devices clean with anti-bacterial spray cleaner and a specialist cleaning brush set for getting between the spaces on your keyboard.


Keep them clean, but also make sure you keep them covered… especially if you’re clumsy and prone to dropping things! Start with a clear screen protector – they only take seconds to apply, but they stop the glass getting scratched and can help save it from shattering. Enclose your mobile in a leather iPhone case, it safeguards from daily wear & tear and makes it look great at the same time. I use my iPad for following recipes as I cook; I use a case with integral stand to keep it upright and clean… save a few buttery fingerprints here & there!


Install anti-virus software


One of the most stressful and scary things that can happen to your tech device is unknowingly installing a virus, Trojan horse or some other kind of malware. It can completely disable your machine and can cost a lot of money to get someone to put it right. And you may even unintentionally infect the devices of friends, family and work colleagues. These situations can be easily avoided by installing anti-virus software – and there are some good, free ones available.


AVG Anti-virus (AVG AntiVirus for Mac:registered: | AVG AntiVirus FREE | AVG AntiVirus for Android:tm:)


AVG AntiVirus includes real-time security updates, scans for both malware and performance issues, and even catches malicious downloads before they reach your device. It blocks unsafe links, downloads and email attachments.


Avast Security (PC, Mac & Android)


Avast is one of the largest security companies in the world using next-gen technologies to fight cyber attacks in real time. They have an immense cloud-based machine learning engine that receives a constant stream of data from our more than 400 million users.


Keep your hard drive spick & span


There are a few, simple things you can do to keep your devices running quickly and smoothly. By freeing up disk space you not only stop your device becoming sluggish, you also extend your battery life. Always keep your apps updated, developers are always tweaking them, fixing bugs and improving performance. Quit, don’t just close apps that aren’t being used. Don’t simply put files into your trash – delete them completely by emptying the ‘trash’/’recycle bin’. Keep anything that you don’t need every day on an external had drive – especially large files such as images, music and video.


There are lots of useful apps that can help you keep many of them are free or cost very little. Here are just a few.


AVG Cleaner (AVG PC TuneUp:registered: | AVG Cleaner:tm: for Mac:registered: | AVG Cleaner:tm: for Android:tm:)


It quickly finds any hidden clutter you may have accumulated and clean it with just one click.


MacBooster (Mac)


This is a Mac maintenance tool to clean up junk, boost performance and remove malware and viruses.


AppZapper (Mac)


Everybody loves the drag and drop nature of OS X. Drag an app into your applications folder, and it’s installed. You’d think it would be that easy to delete an app – just a matter of dragging it to the trash. But it’s not. Apps install support files on your computer that generate clutter. Introducing AppZapper. Simply drag one or more apps onto AppZapper. Then, watch as it finds the extra files and lets you delete them with one click.


Reno Uninstaller (PC)


Has powerful features to uninstall programs scanning for left over files, folders and registry entries after uninstall.


Disk Diag (Mac)


Disk Diag is a free, simple and efficient tool for cleaning your Mac. It takes the hassle out of finding which files are clogging-up your Mac hard drive by instantly scanning and discovering what’s taking-up space.


Monolingual (Mac)


Monolingual is a program for removing unnecessary language resources from macOS, in order to reclaim several hundred megabytes of disk space. It requires a 64-bit capable Intel-based Mac and at least macOS 10.12 (Sierra).


Removing unused language packs is different for Windows:registered: operating systems. Read about going about it here.


Prepare for if it gets lost or stolen




No one wants to think about the possibility of their device getting misplaced, lost or stolen; but it happens to people every, single day. There are things you can put in place if, in future, you need to locate a lost or stolen device.


For Mac products – iPhone, iPad, iPod Touch, Apple Watch and MacBook – the Find My iPhone app is a security essential.


Find My iPhone will help you locate your missing device on a map, remotely lock it, play a sound, display a message, or erase all the data on it.


For missing iOS devices, Find My iPhone also includes Lost Mode. Lost Mode locks your device with a passcode and can display a custom message and contact phone number right on the Lock Screen. While in Lost Mode, your device can keep track of where it has been and report back so you can view its recent location history, right from the Find My iPhone app.


If you have an Android phone, you need to enable the ‘Remotely locate this device’ and ‘Allow remote lock and erase’ settings in the Google Settings app. You’ll find them under Security → Device Manager. If your Android device goes missing, log into the Android Device Manager on the Google website and it’s location will be mapped out. From here you can ring, lock or erase your phone’s data.


Windows phones also have built-in settings to track missing mobile devices. You will find them here: Settings → Privacy → Find my phone. Tick the box to ‘Save my phone’s location periodically and before the battery runs out to make it easier to find’. So long as you have done this you will be able to search for your phone’s whereabouts via your Microsoft account. From here you’ll be able to ring, lock or erase it’s data.


Doing these four simple things will ensure that your tech devices will enjoy a long and prosperous existence!




The post 4 essential ways to care for your tech devices appeared first on H is for Home Harbinger.


NSA-CIA-Mossad cyber terrorists get a kick out of daily hacking and attacking Americans servers and computers, then reporting immediately how EVIL CHINA ATTACKED AMERICA AGAIN!!!!


Like Iraq and Saddam attacked us on 911...while luckily CIA-Mossad-Pentagon kept the 3000+ murdered Americans safe.



US Getting Better at Cyber Blaming, Not Cyber Security


Peter Lee

June 13, 2015


Color me skeptical about the Sunday Times report that Edward Snowden’s archive got cracked. Not saying it couldn’t happen despite 256 bit encryption, accidents do happen, but the story as presented reeks of psyops bullshit unloaded by the NSA-GCHQ team with the help of obliging media in the UK.


What I think is happening is that the United States is upping its game…in public cyberattribution.


Honestly parsing and presenting a cyberattribution dossier is a thankless job. Remember how the Obama administration looked foolish on the Sony hack?


Sure you don’t. That was so…four months ago.


Here’s what I wrote back then on the occasion of the rollout of the US government’s Cyber Threats Intelligence Integration Center:


According to AP (actually, according to AP’s Ken Dilanian, the n otoriously obliging amanuensis to the US security establishment ):


White House cybersecurity coordinator Michael Daniel has concluded that cyberintelligence at the moment is bedeviled by the same shortcomings that afflicted terrorism intelligence before 9/11 — bureaucracy, competing interests, and no streamlined way to combine analysis from various agencies, the official said.


The hack on Sony’s movie subsidiary, for example, resulted in a variety of different analytical papers from various agencies. Each one pointed to North Korea, but with varying degrees of confidence.



As I argued in various venues recently with reference to the Sony hack, for purposes of semiotics (clear messaging, positioning, blame avoidance, and signaling of US government intentions) if not forensics (proving whodunit), painting a convincing, action-worthy cyberbullseye on the back of some foreign enemy is a major challenge for governments these days.


When some high-profile outrage like Sony occurs, the US government has to make a prompt show of control, capability, and resolve. Letting a bunch of data nerds chew over the data for a few weeks and spit up an equivocal conclusion like “It looks like the same guys who did this did that, and maybe the guys who did that were…” doesn’t quite fill the bill.


Which is pretty much what happened on Sony. Various private sector and government actors all stuck their oar in, contradictory opinions emerged, messaging was all over the map.


… By establishing a central clearing house for relevant information, the US government is on the right side of the information symmetry equation. “You say you think this, but you don’t know this, this, and this, or the stuff we can’t tell you because it’s classified above your clearance.”


And even if the real takeaway from the investigatory process still is “It looks like the same guys who did this did that, and maybe the guys who did that were…” it comes out as “The Cyber Threats Intelligence Integration Center has attributed this cyberattack to North Korea with a high degree of confidence. By Executive Order, the President has already commanded CyberCommand to make a proportional response.”


You get the picture.


So I expect jobs one and two and three for CTIIC will be to generate persuasive dossiers for backgrounding, leaking, whatever on the PRC, North Korea, and the Russian Federation, to be deployed when some mysterious alchemy of evidence, circumstance, and strategy dictate that one of them has to get tagged as The Bad Guy for some cyberoutrage.


Fast-forward, to employ a quaint VHS-era term, to June 5. Ellen Nakashima lays out the administration position on the OPM hack in a Washington Post article remarkable for its completely categorical no-two-ways-about-it statement that “China” had dunnit:


With a series of major hacks, China builds a database on Americans

China is building massive databases of Americans’ personal information by hacking government agencies and U.S. health-care companies, using a high-tech tactic to achieve an age-old goal of espionage: recruiting spies or gaining more information on an adversary, U.S. officials and analysts say.


Groups of hackers w orking for the Chinese government have compromised the networks of the Office of Personnel Management…


China hacked into the federal government’s network, compromising four million current and former employees’ information. The Post’s Ellen Nakashima talks about what kind of national security risk this poses and why China wants this information. (Alice Li/The Washington Post)



U.S. officials privately said China was behind it.



“This is an intelligence operation designed to help the Chinese government,” the China expert said.


Emphasis added, natch.


Either the US has spectacularly upped its forensics game since Michael Daniel’s rueful reflections in February or (my theory)…


The great minds were sitting around a table in Washington and concluded:


“We can’t prove this was a Chinese hack, but let’s turn this around. Nobody can disprove this was a Chinese hack, so nobody can prove us wrong when if we declare without qualification it was a Chinese hack. So let’s just go for it.”


Parenthetically, I might point out that one problem I see is, If with categorically and openly identifying the PRC as source of the hack is that we should immediately and openly retaliate at a commensurate level. Otherwise, where’s our national credibility & deterrence? Still waiting for the shoe to drop on that one.


The tip-off for me that the WaPo was carrying Obama administration water with this totally backgrounded mostly anonymous scoop was this:


The big-data approach being taken by the Chinese might seem to mirror techniques used abroad by the NSA, which has come under scrutiny for its data-gathering practices under executive authority. But in China, the authorities do not tolerate public debate over the proper limits of large-scale spying in the digital age.


The piece was written June 5, three days after the Obama administration had put the Snowden unpleasantness behind it and totally regained the moral high ground, in its own mind if nobody else’s, by replacing the Patriot Act with the USA Freedom Act a.k.a. “Uniting and Strengthening America by Fulfilling Rights and Ending Eavesdropping, Dragnet-collection and Online Monitoring Act.”


Now, with the legalities of the US cyberprograms re-established, it was time to stop playing defense and go on offense against those public-debate-intolerant Chinese!


And that means relaunching the China cyberoutlaw product! With the story of a hack that had, if I understand Nakashima’s account correctly, had occurred in December 2014!


Again, it is perhaps little remembered except by me that a key US objective for the Xi Jinping—Barack Obama summit in Sunnylands in June 2013 was to cap an eighteen month public opinion campaign against PRC cyberoffenses with a personal rebuke by President Obama and the presentation of an embarrassing dossier to Xi Jinping.


If, as I did, one googled “Xi Jinping cyberwarfare” on June 3, 2013, the first four pages of results included hits like these, indicating that the Western press was energetically singing from the same cyberwar hymnal:

China Doesn’t Care if Its ‘Digitalized’ Military Cyberwar Drill Scares You



China Is Winning the Cyber War Because They Hacked U.S. Plans for Real War




Krauthammer to Obama: Launch cyber war on China


Fox News


China Is Our Number One National Security Threat


International Business Journal


House Intelligence Chairman: US “Losing” Cyber-War


Wall Street Journal


US Says China Is Stepping Up Cyber War


Financial Times


U.S. China Cyberbattle Intensifies




Just a reminder; these headlines are from June 2013, not June 2015.


In this case, the China Matters serendipity engine was firing on all cylinders; three days later the Washington Post and Guardian newspapers published their first revelations from Edward Snowden, fundamentally skewing the frame of the Chinese cyberwarfare story.


I’ve always wondered if the timing of Snowden’s revelations had something to do with the hypocrisy of the world’s biggest cybersnoop trying to stick that label on the PRC.


Anyway, the Obama administration has had two years to lick its wounds, do damage control, and reboot the program.


And guess what! Xi Jinping’s coming to the United States again in September! This time we’ll be ready for him fer sure! Snowden discredited! NSA on top! PRC in doghouse!


I must state here that I believe that PRC cyberespionage program is massive, government-backed, full spectrum, and actively exploring offensive capabilities. But I also think that the US tactics are destabilizing and escalatory & have more to do with maintaining the US cyberadvantage as part of the burgeoning and profitable China-threat milsec business than they do with diminishing the threat to the American people from PRC cyber misbehavior.


And I take the current spate of news stories as part of an effort to get us used to perpetual cyberwar, just as we were bombarded with stories about malevolent Muslims in the last decade to reconcile us the the Global War on Terror, the erosion of civil liberties, and expensive and perpetual conflicts.


At this time, a trip down memory lane is warranted for people who have forgotten how the Obama administration methodically rolled out PRC Cyberthreat v. 1.0, the buggy pre-Snowden product, and are perhaps not connecting the dots on the rollout of PRC Cyberthreat v. 2.0, Now Bigger and Scarier! and how this might be a factor in the headlines blaring out of their newspapers & TVs & tablets.


Below the fold, for the sake of posterity, a lengthy recap on the first abortive US salvo in the China cyberthreat propaganda war.


What I wrote back in April 2012:


The Barack Obama administration went public with its case against China in November 2011, with a report on industrial espionage titled Foreign Economic Collection. It described China rather generously as a “Persistent Collector” given the PRC’s implication in several high-profile industrial espionage cases and soft-pedaled the issue of official Chinese government involvement. The report stated:


US corporations and cyber-security specialists also have reported an onslaught of computer network intrusions originating from Internet Protocol (IP) addresses in China, which private sector specialists call “advanced persistent threats.” Some of these reports have alleged a Chinese corporate or government sponsor of the activity, but the IC [intelligence community] has not been able to attribute many of these private sector data breaches to a state sponsor. Attribution is especially difficult when the event occurs weeks or months before the victims request IC or law enforcement help. [5]


A month later, in December 2011, US criticism of China became a lot more pointed. Business Week published an exhaustive report on Chinese cyber-espionage, clearly prepared with the cooperation of federal law enforcement authorities as it named and described several investigations:


The hackers are part of a massive espionage ring codenamed Byzantine Foothold by US investigators, according to a person familiar with efforts to track the group. They specialize in infiltrating networks using phishing e-mails laden with spyware, often passing on the task of exfiltrating data to others.


Segmented tasking among various groups and sophisticated support infrastructure are among the tactics intelligence officials have revealed to Congress to show the hacking is centrally coordinated, the person said. US investigators estimate Byzantine Foothold is made up of anywhere from several dozen hackers to more than one hundred, said the person, who declined to be identified because the matter is secret. [6]


United States security boffin Richard Clarke had this to say about Chinese cyber-espionage in an interview with Smithsonian magazine:


“I’m about to say something that people think is an exaggeration, but I think the evidence is pretty strong,” he tells me. “Every major company in the United States has already been penetrated by China.”




“The British government actually said [something similar] about their own country.”


Clarke claims, for instance, that the manufacturer of the F-35, our next-generation fighter bomber, has been penetrated and F-35 details stolen. And don’t get him started on our supply chain of chips, routers and hardware we import from Chinese and other foreign suppliers and what may be implanted in them-”logic bombs,” trapdoors and “Trojan horses,” all ready to be activated on command so we won’t know what hit us. Or what’s already hitting us. [7]


Some big numbers are being thrown around to publicize the Chinese threat.


Business Week’s report, while admitting the woolliness of its methodology, stated that losses to American companies from international cyber-espionage amounted to US$500 billion in a single year.


Scott Borg, director of a non-profit outfit called the US Cyber Consequences Unit told Business Week:


“We’re talking about stealing entire industries … This may be the biggest transfer of wealth in a short period of time that the world has ever seen.”


Beyond these apocalyptic economic and military scenarios, we might also descend to the personal and political and point out that Google, a favorite target of Chinese cyber-attacks, is Obama’s friend, indispensable ally, brain trust and source of personnel in the high-tech sector.


Connect the dots, and it is clear that the Obama administration, in its usual meticulous way, is escalating the rhetoric and preparing the public and the behind-the-scenes groundwork for major pushback against China in the cyber-arena.


And in March 2013, a few weeks before Sunnylands, I wrote:


[National Security Advisor] Donilon came up with a nuanced approach to Chinese cyber-mischief during his speech to the Asia Society…


Bypassing the issue of cyber-spying against military and government targets that probably falls into the grey area of “everybody does it and why shouldn’t they”, and defining and limiting the issue to a specific and remediable problem – the massive state-sponsored PRC program of industrial and commercial espionage against Western targets – Donilon’s framing placed “cyber-theft” in a category similar to the intellectual property gripe, also know as systematic piracy of US software, as an info strategy condoned by the Chinese government:



This rather unexceptionable and reasonable demand that the PRC reign in its gigantic program of economic/commercial hacking, i.e. cyber-enabled theft as Donilon put it, and give US businesses a break, was not good enough for the Christian Science Monitor, which has apparently shed, together with its print edition, the sober inhibitions that once characterized its news operations.


The CSM’s headline:


US tells China to halt cyberattacks, and in a first, lays out demands


Obama’s national security adviser, Thomas Donilon, spelled out a more aggressive US stance on the cyberattacks, saying China must recognize the problem, investigate it, and join in a dialogue. [4]


Note in the CSM story the effortless slide down the slippery slope from cyber-theft to cyber-espionage to cyber-attacks (and for that matter, “should” and “needs” to “demands”). Well, fish gotta swim, birds gotta fly, and eyeballs have to be wrenched from their accustomed paths and turned into click-fodder.


And don’t get me started on the Pentagon:


A new report for the Pentagon concludes that the US military is unprepared for a full-scale cyber-conflict with a top-tier adversary. The report says the United States must increase its offensive cyberwarfare capabilities. The report also calls on the US intelligence agencies to invest more resources in obtaining information about other countries’ cyberwar capabilities and plans.


The Washington Post reports that the report says that the United States must maintain the threat of a nuclear strike as a deterrent to a major cyberattack by other countries. The report notes that very few countries, for example, China and Russia, have the skills and capabilities to create vulnerabilities in protected systems by interfering with components.


The report emphasizes that defensive cyber capabilities are not enough, and that the United States must have offensive cyber capabilities which, when needed, could be used either preemptively or in retaliation for a cyber attack by an adversary. [5]


Security consultant Bruce Schneier addressed the threat inflation issue (and the dangers of trying to design and justify retaliation in the murky realm of cyberspace) in a blog post on February 21:


Wow, is this a crazy media frenzy. We should know better. These attacks happen all the time, and just because the media is reporting about them with greater frequency doesn’t mean that they’re happening with greater frequency.


But this is not cyberwar. This is not war of any kind. This is espionage, and the difference is important. Calling it war just feeds our fears and fuels the cyberwar arms race.


In a private e-mail, Gary McGraw made an important point about attribution that matters a lot in this debate.


Because espionage unfolds over months or years in realtime, we can triangulate the origin of an exfiltration attack with some certainty. During the fog of a real cyber war attack, which is more likely to happen in milliseconds, the kind of forensic work that Mandiant did would not be possible. (In fact, we might just well be “Gandalfed” and pin the attack on the wrong enemy.)


Those of us who work on security engineering and software security can help educate policymakers and others so that we don’t end up pursuing the folly of active defense.


I agree.


This media frenzy is going to be used by the US military to grab more power in cyberspace. They’re already ramping up the US Cyber Command. President Obama is issuing vague executive orders that will result in we-don’t-know what. I don’t see any good coming of this. [6]


Not to worry, is the US attitude.


A head-to-head conventional war with China isn’t likely, despite the overheated imagination displayed in the AirSea Battle scenario, and it is difficult to identify any satisfying proxy battlefield in meatspace where the PRC and the USA might be tempted to slug it out.


But cyberwarfare?…Bring it!


The Department of Defense has a “Cyber Command” which, it revealed to the Washington Post, is muscling up from 500 staff to 4000 “cyberwarriors”.


The Post interviewed William J. Lynn III, identified as one of the maestros of the DoD’s cyber strategy:


“Given the malicious actors that are out there and the development of the technology, in my mind, there’s little doubt that some adversary is going to attempt a significant cyber-attack on the United States at some point…The only question is whether we’re going to take the necessary steps like this one to deflect the impact of the attack in advance or… read about the steps we should have taken in some post-attack commission report.”


The DoD is keen to emphasize that its cyberwarriors will be primarily playing defense, understandable considering the vulnerabilities of America’s immense, dispersed, highly integrated and—and the case of the power grid, at least—rather decrepit national infrastructure.


But of course there will be “combat mission forces”:


The combat mission forces, one of the three divisions of Cyber Command will launch cyber-attacks alongside traditional military offensives.


“This new class of cyber warrior would be responsible for penetrating the machines behind identified attack sources, installing spyware to monitor connections to those machines, and following the trail back to the desktop of the attacker. They would have to research and exploit vulnerabilities, craft malware, operate honey pots, and even engage in targeted Denial of Service attacks,” Richard Stiennon, chief research analyst at IT-Harvest, told GlobalPost.


Contra Dr. Stiennon’s assertions, I don’t think that the DoD really believes that the scope of Cyber Command combat missions will be limited to delectable honey pots and “even” targeted Denial of Service attacks.


Not when the cyberwar scenarios, according to Leon Panetta, include our enemies derailing trains, contaminating water supplies, or shutting down power grids. We’re going to be able to do that, too.


The United States security/military apparatus apparently feels that it can “win the Internet” by harnessing the power of the invincible American technological knowhow to the anti-Chinese cyber-crusade.


In another of the seemingly endless series of self-congratulatory backgrounders given by US government insiders, the godlike powers of the National Security Agency were invoked to Foreign Policy magazine in an article titled Inside the Black Box: How the NSA is helping US companies fight back against Chinese hackers:


In the coming weeks, the NSA, working with a Department of Homeland Security joint task force and the FBI, will release to select American telecommunication companies a wealth of information about China’s cyber-espionage program, according to a US intelligence official and two government consultants who work on cyber projects. Included: sophisticated tools that China uses, countermeasures developed by the NSA, and unique signature-detection software that previously had been used only to protect government networks.


Very little that China does escapes the notice of the NSA, and virtually every technique it uses has been tracked and reverse-engineered. For years, and in secret, the NSA has also used the cover of some American companies – with their permission – to poke and prod at the hackers, leading them to respond in ways that reveal patterns and allow the United States to figure out, or “attribute,” the precise origin of attacks. The NSA has even designed creative ways to allow subsequent attacks but prevent them from doing any damage. Watching these provoked exploits in real time lets the agency learn how China works.


And amid the bluster, a generous serving of bullshit:


Now, though, the cumulative effect of Chinese economic warfare – American companies’ proprietary secrets are essentially an open book to them – has changed the secrecy calculus. An American official who has been read into the classified program – conducted by cyber-warfare technicians from the Air Force’s 315th Network Warfare Squadron and the CIA’s secret Technology Management Office – said that China has become the “Curtis LeMay” of the post-Cold War era: “It is not abiding by the rules of statecraft anymore, and that must change.”


“The Cold War enforced norms, and the Soviets and the US didn’t go outside a set of boundaries. But China is going outside those boundaries now. Homeostasis is being upset,” the official said. [7]


A more impressive and evocative term than “upset homeostasis” to describe the US cyber-war conundrum is “Stuxnet”.


The Obama administration’s cyber-maneuverings have been complicated and, it appears, intensified, by the problem that the United States “did not abide by the rules of statecraft” and “went outside the boundaries” and, indeed, became the “Curtis LeMay of the post Cold War era” when it cooperated with Israel to release the Stuxnet exploit against Iran’s nuclear program.



Not unsurprisingly, post-Stuxnet the Chinese government has even less interest in the “Law of Armed Conflict in cyberspace” norms that the United States wants to peddle to its adversaries but apparently ignore when the exigencies of US interests, advantage, and politics dictate.


Instead, the PRC and Russia have lined up behind a proposed “International Code of Conduct for Internet Security”, an 11-point program that says eminently reasonable things like:


Not to use ICTs including networks to carry out hostile activities or acts of aggression and pose threats to international peace and security. Not to proliferate information weapons and related technologies.


It also says things like:


To cooperate in combating criminal and terrorist activities which use ICTs [information and computer technologies] including networks, and curbing dissemination of information which incites terrorism, secessionism, extremism or undermines other countries’ political, economic and social stability, as well as their spiritual and cultural environment. [11]


The United States, of course, has an opposite interest in “freedom to connect” and “information freedom,” (which the Chinese government regards as little more than “freedom to subvert”) and has poured scorn on the proposal.


The theoretical gripe with the PRC/Russian proposal is that it endorses the creation of national internets under state supervision, thereby delaying the achievement of the interconnected nirvana that information technology evangelists assure us is waiting around the next corner – and also goring the ox of West-centric Internet governing organizations like ICANN.


So the Chinese proposal is going exactly nowhere.


The (genuine) irony here is that the Chinese and Russians are showing and driving the rest of the world in their response to the undeniable dangers of the Internet ecosystem, some of which they are themselves responsible for but others – like Stuxnet – can be laid at the door of the US.


In response to hacking, the Internet as a whole has evolved beyond its open architecture to a feudal structure of strongly-defended Internet fortresses, with cyber-surfs free to roam the undefended commons outside the gates, glean in the fields, and catch whatever deadly virus happens to be out there.


In recent months, the word “antivirus” has disappeared from the homepages of Symantec and MacAfee as they have recognized that their reference libraries of viruses can’t keep up with the proliferation of millions of new threats emerging every year, let alone a carefully weaponized packet of code like Stuxnet, and protect their privileged and demanding users. Now the emphasis – and gush of VC and government money – has shifted to compartmentalizing data and applications and detecting, reducing the damage, and cleaning up the mess after a virus has started rummaging through the innards of an enterprise.


In other words, the Internet fortresses, just like their medieval analogues, are increasingly partitioned into outer rampart, inner wall, and keep – complete with palace guard – in order to create additional lines of defense for the lords and their treasure.


In other words, they are starting to look like the Chinese and Russian national internets.


Absolute cyber-safety, through defense or deterrence against an antagonist, is a chimera. The best hope for the Internet might be “peaceful coexistence” – the move toward cooperation instead of confrontation that characterized the US-USSR relationship when it became apparent that “mutually assured destruction” was leading to a proliferation of dangerous and destabilizing asymmetric workarounds instead of “security through terror”.


Or, as the Chinese spokesperson put it in Demick’s article:


“Cyberspace needs rules and cooperation, not war. China is willing to have constructive dialogue and cooperation with the global community, including the United States,” Foreign Ministry spokeswoman Hua Chunying said at a briefing Tuesday. [14]


It looks like the Obama administration, by carefully and convincingly placing the cyber-theft issue on the table, might be working toward some kind of modus vivendi that leads to a joint reduction of Internet threats – dare I say, win-win solution? – with the PRC.


It remains to be seen if this initiative can withstand the pressures of the US military, security, and technology industries for a profitable threat narrative – and the Obama administration’s own inclination toward zero-sum China-bashing.

