Ever wanted to see what it's like (or be) a Hacker? Then you should get Hacker Evolution, a single-player simulation game from Exosyphen Studios. Available on Steam.
From their site, About the Game:
Stock exchanges. Central banks. Satellite uplinks. Transoceanic fiber optics links. All mysteriously succumbing to an unexpected “evolution” of the web. When the world’s critical services start to collapse, you know this is more then a simple event. Who or what is behind it? Only an experienced and dedicated hacker, with know-how gained as an international cyber-intelligence agent, can root out the cause and bring it down.
The creators of Digital Hazard and BS Hacker bring you to new levels of hacking simulation, with unparalleled graphics and a pulse-pounding sound track. Hack into computers, look for exploits and information, and steal money to buy hardware upgrades as you attempt to assemble the pieces of an international puzzle. Your virtual operating system environment is packed with the features to immerse you in the role of world-class hacker.
Hacker Evolution is a totally unique experience, challenging the evolved gamer's intelligence, attention and focus to create a captivating mind game. Solve puzzles, examine code and bits of information, and evade the system’s trace to reach your objectives.
Here's a screenshot of the screen:
There are 3 releases of the series available now (in order):
Hacker Evolution (original)
Hacker Evolution Untold
Hacker Evolution Duality
And an upcoming release, Hacker Evolution IMMERSION (on Steam's Early Access)
UPDATED: Cisco’s Talos security intelligence and research group has come across a piece of software that installed backdoors on 12 million computers around the world.
The software, which exhibits adware and spyware capabilities, was developed by a French online advertising company called Tuto4PC. The firm, previously known as Eorezo Group and apparently linked to another company called Wizzlabs, has been targeted by French authorities over its questionable practices regarding the installation of unwanted software and harvesting of users’ personal details.
Cisco started analyzing Tuto4PC’s OneSoftPerDay application after its systems detected an increase in “Generic Trojans” (i.e. threats not associate with any known family). An investigation uncovered roughly 7,000 unique samples with names containing the string “Wizz,” including “Wizzupdater.exe,” “Wizzremote.exe” and “WizzInstaller.exe.” The string also showed up in some of the domains the samples had been communicating with.
Researchers determined that the application, installed with administrator rights, was capable not only of downloading and installing other software, such as a known scareware called System Healer, but also of harvesting personal information. Furthermore, experts found that the software is designed to detect the presence of sandboxes, antiviruses, security tools, forensic software and remote access doors.
These “features” have led Cisco Talos to classify the Tuto4PC software as a “full backdoor capable of a multitude of undesirable functions on the victim machine.”
According to Tuto4PC’s website, the company offers hundreds of tutorials that users can access for free by installing a piece of software that displays ads. However, based on Cisco’s research, it appears the company is doing more than just displaying ads.
Tuto4PC said its network consisted of nearly 12 million PCs in 2014, which could explain why Cisco’s systems detected the backdoor on 12 million devices. An analysis of a sample set revealed infections in the United States, Australia, Japan, Spain, the UK, France and New Zealand.
“Based on the overall research, we feel that there is an obvious case for this software to be classified as a backdoor. At minimum it is a potentially unwanted program (PUP). There is a very good argument that it meets and exceeds the definition of a backdoor,” Cisco Talos researchers said in a blog post.
“The creation of a legitimate business, multiple subsidiaries, domains, software and being a publicly listed company do not stop this adware juggernaut from slowing down their attempts to push their backdoors out to the public,” they added.
In response to Cisco’s blog post, Tuto4PC Group CEO Franck Rosset clarified that its antivirus bypass technology is not used for malicious purposes — he says it’s designed to make it easier for users to install its applications, which have been blocked by antiviruses. The company has provided the following statement to SecurityWeek:
“The Talos blogpost is inaccurate in describing Tuto4PC as a shady malware distribution enterprise. We are currently working with our lawyers in order to evaluate the action we can take against Talos’ inexact (negative) presentation of our business.
We are a listed company on the French stock exchange. Since 2004, our business model is to create widgets, tutorials etc, for free download on download websites. The download of our programs is for free subject to agreement for accepting advertising from an adware attached in the download.
Contrary to Talos’ wrongful allegations, our business has been approved by French regulators and we have never been indicted or sued for any malware distribution!!!!
We have a technology subsidiary (Cloud 4PC) with some developments in cybersecurity. Due to some undue blocking by antiviruses that recently blocked Tuto4PC adware (some of them have also an adware business model), we are using a bypass technology so that people can easily download our programs (and adware). Although the bypass software is extremely efficient, it has no other purpose or use that helping the Tuto4PC adware download.
There is no malware activity and Talos cannot prove or show any malware use of the program — with more than 10 million installed, if there was to be any malware activity, obviously there should be some user complaints.
As you can see, we are a French company — very easy to reach, we are not hiding in some rogue country — we do not understand why Talos has not contacted us prior to their post.
In any case, our subsidiary Cloud 4PC is going to launch soon “AV Booster,” an antivirus booster that will help stop any real malware that use bypass techniques like the ones we developed."
Hospitals, school districts, state and local governments, law enforcement agencies, small businesses, large businesses—these are just some of the entities impacted recently by ransomware, an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them.
The inability to access the important data these kinds of organizations keep can be catastrophic in terms of the loss of sensitive or proprietary information, the disruption to regular operations, financial losses incurred to restore systems and files, and the potential harm to an organization’s reputation.
And, of course, home computers are just as susceptible to ransomware, and the loss of access to personal and often irreplaceable items—including family photos, videos, and other data—can be devastating for individuals as well.
Ransomware has been around for a few years, but during 2015, law enforcement saw an increase in these types of cyber attacks, particularly against organizations because the payoffs are higher. And if the first three months of this year are any indication, the number of ransomware incidents—and the ensuing damage they cause—will grow even more in 2016 if individuals and organizations don’t prepare for these attacks in advance.
In a ransomware attack, victims—upon seeing an e-mail addressed to them—will open it and may click on an attachment that appears legitimate, like an invoice or an electronic fax, but which actually contains the malicious ransomware code. Or the e-mail might contain a legitimate-looking URL, but when a victim clicks on it, they are directed to a website that infects their computer with malicious software.
One the infection is present, the malware begins encrypting files and folders on local drives, any attached drives, backup drives, and potentially other computers on the same network that the victim computer is attached to. Users and organizations are generally not aware they have been infected until they can no longer access their data or until they begin to see computer messages advising them of the attack and demands for a ransom payment in exchange for a decryption key. These messages include instructions on how to pay the ransom, usually with bitcoins because of the anonymity this virtual currency provides.
Ransomware attacks are not only proliferating, they’re becoming more sophisticated. Several years ago, ransomware was normally delivered through spam e-mails, but because e-mail systems got better at filtering out spam, cyber criminals turned to spear phishing e-mails targeting specific individuals.
And in newly identified instances of ransomware, some cyber criminals aren’t using e-mails at all. According to FBI Cyber Division Assistant Director James Trainor, “These criminals have evolved over time and now bypass the need for an individual to click on a link. They do this by seeding legitimate websites with malicious code, taking advantage of unpatched software on end-user computers.”
The FBI doesn’t support paying a ransom in response to a ransomware attack. Said Trainor, “Paying a ransom doesn’t guarantee an organization that it will get its data back—we’ve seen cases where organizations never got a decryption key after having paid the ransom. Paying a ransom not only emboldens current cyber criminals to target more organizations, it also offers an incentive for other criminals to get involved in this type of illegal activity. And finally, by paying a ransom, an organization might inadvertently be funding other illicit activity associated with criminals.”
So what does the FBI recommend? As ransomware techniques and malware continue to evolve—and because it’s difficult to detect a ransomware compromise before it’s too late—organizations in particular should focus on two main areas:
Prevention efforts—both in both in terms of awareness training for employees and robust technical prevention controls; and
The creation of a solid business continuity plan in the event of a ransomware attack. (See "Tips for Dealing with the Ransomware Threat" below)
“There’s no one method or tool that will completely protect you or your organization from a ransomware attack,” said Trainor. “But contingency and remediation planning is crucial to business recovery and continuity—and these plans should be tested regularly.” In the meantime, according to Trainor, the FBI will continue working with its local, federal, international, and private sector partners to combat ransomware and other cyber threats.
If you think you or your organization have been the victim of ransomware, contact your local FBI field office and report the incident to the Bureau’s Internet Crime Complaint Center.
Tips for Dealing with the Ransomware Threat
While the below tips are primarily aimed at organizations and their employees, some are also applicable to individual users.
Prevention Efforts
- Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
- Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
- Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
- Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
- Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
- Disable macro scripts from office files transmitted over e-mail.
- Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
Business Continuity Efforts
- Back up data regularly and verify the integrity of those backups regularly.
- Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.
I just have to comment on paying attention to the domains you receive eMail from.
I got an eMail reminding me 'to confirm your account' on a site I never heard of.
The domain was "@zainiraq.net"
IRAQ.net!
Ya, like that's a safe site, .....NOT.
You need to pay close attention to eMail domains when the eMail looks suspicious or from a site you never heard of.
Suspicious eMail may even claim to be from a site you do deal with. I and an eMail that claimed to be from AARP but the text didn't look right, it was from a domain ending in ".top"
If you get eMail that does look like it's from a site you deal with but has a link to update you account info, DO NOT use the link in the eMail. If you deal with the site, you should have it bookmarked in your browser, use that to access the site. Also, many sites will have a Support contact, you should copy the eMail and Headers, and paste that into their message system so they know someone is trying to spoof them.
All suspicious eMail domains should be added to your SPAM filter. In my case, my eMail provider has a very good system for that. Then your eMail client should also have a way to filter eMail domains.
SUMMARY: In the 30 years since Steve Case co-founded AOL, the global tech landscape has seen immense growth and change. What new developments wait in the near future, and what does the rapidly expanding online world mean for human life? Case explores those issues in his new book, “The Third Wave.” Case joins Judy Woodruff to discuss his vision of the future.
JUDY WOODRUFF (NewsHour): Back in 1985, when Steve Case co-founded America Online, only 3 percent of Americans were actually online. Fast-forward some 30 years, and we can see the global change brought about by the Internet and an ever-growing array of devices and social media.
So, what is next?
Well, we get a glimpse from Steve Case himself. He is the author of a new book, “The Third Wave: An Entrepreneur’s Vision of the Future.”
Steve Case, it is good to see you.
STEVE CASE, Author, “The Third Wave”: It’s good to see you again.
JUDY WOODRUFF: So you borrowed that term the third wave from the futurist Alvin Toffler.
STEVE CASE: Yes.
When I was in college in the 1980, I read Toffler “Third Wave.” It completely mesmerized me inspired me. I spent the last almost four decades pursuing some of the ideas he talked about.
So, when I was writing a book, I wanted to pay respect to him. I open the book with talking about my experience reading Toffler. And I hope others will similarly be inspired by my book, and because the future once again is going to change, and the path forward is going to be different than what we saw in the last two waves. And that’s what I was trying to lay out in this book.
JUDY WOODRUFF: So, in a thumbnail, first wave was the creation of the Internet, which you were involved in. Second wave was building on that, you describe, social media devices and so forth.
What is the next wave?
STEVE CASE: It’s really integrating the Internet seamlessly throughout our lives.
And there is a lot of things that haven’t changed that much in the first wave or the second wave. How we learn, our kids learn is about the same. How we stay healthy is about the same. How we manage energy is about the same. Even how we think about food is about the same.
And work itself is starting to change in the third wave because of the freelance economy, what some call the gig economy. So, I think it’s important for everybody, not just businesspeople or technologists, to understand what is happening next. And that is what I try to lay out in this book with sort of a — a little bit of a road map forward and a little bit of a playbook in terms of how you can think about orchestrating your career and your life, and how you think about maybe your kids and even your grandkids. What world are they going to be inheriting?
NOTE: You must be a member to post on CHF (Computer Help Forums)
A letter from the President of the European Commission may spark an ongoing war between privacy advocates and online publishers that use anti-ad-blocking filters on their sites.
Alexander Hanff, CEO of Think Privacy Inc., has penned a letter to Jean-Claude Juncker, EC's president, this past winter, asking for clarification regarding the language of the e-Privacy Directive's Cookie Law.
Mr. Hanff wanted to know if the cookie law is referring strictly to browser cookies or the general notion of gathering "any information stored on such equipment [is] part of the privacy sphere of the users requiring protection."
Scanning for ad-blockers breaks the EU's e-Privacy Directive
The response of the European Commission was clear, and that any type of server or client-side scripts that attempt to access or collect information stored on the user's devices fall under the e-Privacy's umbrella, meaning that publishers need to ask for permission before gathering any type of data, not just about cookies.
Under Mr. Hanff's expert opinion, this also includes ad-blocking blocking technologies that prevent users from viewing a website's content if they have an ad-blocker installed in their browser.
In order to work, those websites need to run JavaScript code in the users' browsers. These scripts gather information about the users' local configuration, an action which falls under the Commission's interpretation of scanning and collecting private user data, hence must be prompted and asked for permission.
Based on this response, to comply with this new interpretation of the cookie law, Internet publishers must ask you if they can scan your browser for ad-blocking software, and then prompt you to disable the ad-blocker if you agree.
The problem of server-side scripts
Mr. Hanff's says that his original letter only included the question of client-side scripts that scanned for ad-blockers, but he points out that the answers received from the European Commission include references and legal opinions that cover server-side scripts as well.
Under this latter category, any analytics service could potentially be affected. Mr. Hanff has answered Softpedia's inquiry, and he argues that this is true. Any analytics service, that employ client or server-side scripts, should also ask for permission. Until now, only analytics services that deployed client-side cookies were affected by the EU Cookie Law. This means that analytics services, commercial or deployed in-house, relying on server-side scripts are also impacted and may need to ask for permission.
This is just one of the questions we can raise from this letter. Of course, the ramifications of this response might need to be debated by people with actual in-depth knowledge of EU law, and not us.
What is certain is that Mr. Hanff has pledged to use the answer he received from the European Commission to start legal actions against any publisher that blocks users with ad-blockers installed to access their websites.
Below are tweets from Mr. Hanff on this matter, along with images of the answer he received from the European Commission.
Due to the proliferation of ransomware, as a previous article points out, I have decided that I (and everyone else) need better protection. I have been using ESET NOD32 AntiVirus for years and is excellent for what it does do.
Better protection is provided by ESET Smart Security. The following screenshots show some of the features:
This is the ESET home dialog on my system.
This is the Setup dialog; the top 2 setting categories are like those found in ESET NOD32 AV, the "Network protection" and "Security tools" have the enhanced protection features.
The "Network protection" settings dialog show the enhancements. "Personal firewall" is just like ESET NOD32 AV, replaces your Windows Firewall. "Network attack protection" and "Botnet protection" are the enhanced features, including ransomware protection. Note the "Recently blocked application or device" under "Troubleshooting wizard."
"Parental control" is a feature found in ESET NOD32 AV. But note the "Banking & Payment protection" and "Anti-Theft" features (more below).
Banking & Payment protection:
This is one of the best features. You add the domains for all banking and payment sites (PayPal, banks, credit card, etc) you use and select [Secured browser] and ESET Smart Security provides enhanced protections for those sites in a separate browser window.
CAUTION: My default browser is Firefox and the ESET Secure Browser Window asked me to if I wanted to save the bank's password even though I have Firefox set to NOT remember passwords.
Anti-Theft:
This feature enables Anti-Theft protection for your devices. It is, of course, more applicable for mobile/portable devices (touch-pads, smart phones, etc), it is not necessary for non-portable desktop systems.
I highly recommend ESET products, especially ESET Smart Security.
This highlights the need to use good Anti-Virus utility AND do an image backup of your entire system AFTER running a virus scan (the only backup you can use to recover your entire system) . I do my backup monthly using O&O DiskImage to a USB External Drive that I disconnect after backup.
Excerpt
SUMMARY: One of the greatest threats to private cybersecurity today is ransomware -- a cyberattack that blocks access to a computer until the hacker is paid a ransom. The problem recently took on new urgency when a hospital in Los Angeles had its entire network shut down for hours, putting hundreds at risk; another high-profile breach hit L.A.’s health department last week. William Brangham reports.
GWEN IFILL (NewsHour): But, first, a look at what’s become the latest threat to our cyber-security.
The problem took on new urgency recently when a hospital in Los Angeles had its entire computer network, including all its digital medical records, locked up by hackers. They demanded a ransom before they’d release the computers. It was the second such attack this month. L.A.’s Health Department was hit last week.
These types of computer attacks, which usually target individual computer users, are on the rise.
The “NewsHour's” William Brangham reported on this threat last year, and now he brings us an update.
WILLIAM BRANGHAM (NewsHour): Inna Simone is retired. She’s a mother and grandmother from Russia who now lives outside of Boston. In the fall of 2014, her home computer started acting strangely.
INNA SIMONE, Retiree: My computer was working terribly. It was not working. I mean, it was so slow.
WILLIAM BRANGHAM: A few days later, while searching through her computer files, Inna saw dozens of these messages — they were all the same. They read: “Your files are encrypted. To get the key to decrypt them, you have to pay $500.”
Her exact deadline, December 2 at 12:48 p.m., was just a few days away.
All her files were locked , tax returns, financial papers, letters, even the precious photos of her granddaughter Zoe. Inna couldn’t open any of them.
INNA SIMONE: It says, “If you won’t pay, your fine will double. If you won’t pay by then, all your files will be deleted and you will lose them forever and never will get back.”
WILLIAM BRANGHAM: Inna Simone, like thousands of others, had been victimized by what’s known as a ransomware attack. Hackers — who law enforcement believe come mainly from Eastern Europe or Russia — manage to implant malicious software onto your computer, usually when you mistakenly open an infected e-mail attachment, or visit a compromised Web site.
That software then allows the hackers to lock up your files, or your entire computer, until you pay them a ransom to give it back.
Justin Cappos is a computer security expert at New York University.
JUSTIN CAPPOS, New York University: It will actually lock you out of the files, the data on your computer.
So, you’d be able to use the computer but those files have been encrypted by the attacker with a key that only they possess. It’s frustrating because you know the data is there. You know the files are there. You know your photos and everything is there and could be accessible to you. But you have no way of being able to get at it because of this encryption that the attackers are using.
WILLIAM BRANGHAM:This is exactly what happened at Hollywood Presbyterian Hospital in Los Angeles. According to officials, about a month ago, their computerized medical records were locked up by one of these malicious programs, and a hacker demanded $17,000 in ransom to unlock them.
During this time, medical staff were forced to use paper and pen for their record-keeping, but they say no patient files were compromised. The hospital decided to pay the ransom. Their computers were unlocked, and the FBI is now investigating.
I have posted about Hardware Monitor (HWMonitor) from CPUID before (a long while back), but it has been updated.
Reminder, HWMonitor works using the monitoring functions of your motherboard and BIOS, so the features you see in screenshot are dependent on your motherboard.
I am running HWMonitor Pro v1.23.0 now on my Win7 Pro 64bit rig:
The newest additions are the Clocks and Utilizations sections for the CPU, and note that my Smart-UPS (connected via USB) is also displayed.
This screenshot is scrolled down, the top sections contain the temp/voltages/fan-speed info for my motherboard.
The only difference between the free version HWMonitor and for-fee HWMonitor Pro is pro allows you to record graphs of the values while you monitor.
Most of the way this huge roleplaying-shooter game works is carried over from its excellent predecessors, Fallout 3 and Fallout: New Vegas. It is the Skyrim to Fallout 3’s Oblivion, if you will – it iterates on the previous game’s already amazing systems, and it’s similarly dense with locations to explore, genuinely creepy monsters to fight, and superbly engrossing post-nuclear atmosphere that blends unsettling gore and death with dark comedy. After more than 55 hours played I may have seen an ending, yet I feel like I’ve only begun to explore its extraordinary world; from the look of it, I’ll easily be able to spend another 100 happy hours here and still see new and exciting things.
A story that begins as a basic search for your lost family evolves into something much more complex and morally nuanced. Like in Fallout: New Vegas, we’re drawn into a struggle between several groups competing for control of the region, and deciding which of their imperfect post-apocalyptic philosophies to align with made me pause to consider how I wanted events to play out. Even the highly questionable Institute has a tempting reason to side with them, and turning away from them in my playthrough wasn’t as clear-cut a choice as I’d expected. I was impressed by the sympathy shown toward the villains, too - even the most irredeemable murderer is explored and given a trace of humanity.
There was a BIG problem. The initial version downloaded from Steam has a restrictive screen resolution, would not display in my native 1280x1024. Note I said "was." Found fixes for this problem via Google, see below.
Also, there's no "Data" option in the Launch Dialog, so you cannot easily add MODS, but this is a minor problem for me.
The biggest feature of Fallout 4 that I really like is crafting. With the proper Perks, you can craft/upgrade any weapon or armor you have, as long as you have the proper Crafting Items. There's even an Crafting Item List online.
Fallout 4 is a big improvement of the Fallout series.
How to correct display resolution:
1) Find C:\Users\[name]\Documents\My Games\Fallout4\ Fallout4Prefs.ini and edit the following entries to read...
bTopMostWindow=0
bMaximizeWindow=0
bBorderless=1
bFull Screen=1
iSize H=1024
iSize W=1280
2) Get “Fallout 4 1280x1024 HUD Fixes” MOD and copy contents to your game folder, example C:\Steam\SteamApps\common\Fallout 4\Data\ (note that this MOD has no .esp file, it modifies scripts) From MOD readme.....
1. Copy Data folder contents into your Fallout 4 Data directory
An artificial intelligence program developed by researchers at Google can beat a human at the board game GO, which some consider to be the most complicated board game in existence. And this AI program — dubbed AlphaGo — didn’t defeat any ol’ human, but the European Go champion Fan Hui in a tournament last October by five games to nil. The findings, published today in the journal Nature, represent a major coup for machine learning algorithms.
“In a nutshell, by publishing this work as peer-reviewed research, we at Nature want to stimulate the debate about transparency in artificial intelligence,” senior editor Tanguy Chouard said at a press briefing yesterday. “And this paper seems like the best occasion for this, as it goes- should I say, right at the heart of the mystery of what intelligence is.”
“So Go is probably the most complex game ever devised by man. It has 10^170 (that's 10 followed by 170 zeros) possible board configurations, which is more than the numbers of atoms in the universe,” said study author and AlphaGo co-developer Demis Hassabis of Google DeepMind.
Ever since the expansion, and loosening of controls, of domain-names (especially in Europe) I've notice an vast proliferation of SPAM.
Example domains:
@bborc.top
@caorc.top
@eeaorc.top
@faorc.top
@paorc.top
What I noticed (as shown in example above) is these sites only change the characters between "@" and 'dot-whatever' sometimes changing only one character.
SUMMARY: Folded into the massive spending and tax cut bill was a significant and controversial new law on cybersecurity. The act encourages private companies to share data about hacks with the government, but it's raising questions among security advocates and privacy groups alike. Jeffrey Brown talks to James Lewis of the Center for Strategic and International Studies and Elissa Shevinsky of JeKuDo.
GWEN IFILL (NewsHour): Before the president and Congress left town for the holidays, they managed to enact a massive 2,000-page package of spending and tax cuts. Typically, these laws draw attention only for the chaos they create, like shutting down the government.
But there’s a lot more deep inside, in this case, a significant and controversial new law governing cyber-security and Internet data. The new law encourages private companies to share data about cyber-hacks with the government. It protects companies from liability, and it also allows data to shared with other companies and with the Department of Homeland Security.
Lawmakers from both parties said it was a good deal.
SEN. DIANNE FEINSTEIN, D-Calif.: If someone sees a particular virus or harmful cyber-signature, they should tell others, so they can protect themselves. That’s what this bill does.
REP. DEVIN NUNES, R-Calif.: We believe that sharing is an area where you really can’t do any harm. It doesn’t hurt anybody to have a way to talk. But, right now, they can’t even talk.
SEN. SUSAN COLLINS, R-Maine:Does it make sense that we require one case of measles to be reported to a federal government agency, but not a cyber-attack?
GWEN IFILL: But there are some security advocates and privacy groups who say the law manages to go too far and not quite far enough.
Jeffrey Brown has that debate.
JEFFREY BROWN (NewsHour): To understand more, we’re joined by James Lewis, senior fellow for the Center for Strategic and International Studies, and Elissa Shevinsky, founder of JeKuDo, a tech start-up designed to provide private communications to customers.
As my followers may know I am a big-time PC game player. My latest game is Far Cry 4.
I also have Far Cry 2 & 3 and Far Cry 4 is the hardest because of one mission; "Death from Above" (needed to open Act Two) given by CIA agent Willis.
That is because you have to use a "Wingsuit" like those you see in many dare-devil videos. The ones with 'wings' between your sides and arms, and between your legs, so you can glide down. What makes this quest so hard is (near quest end) you have to glide through canyons and thread-the-needle at the end of a very narrow canyon.
I would likely be easier on a game console.
In the video below this canyon-glide starts at the 3:14 mark.
This made getting all my data (contacts, pictures, etc.) transferred to my iPhone easy.
It is a very nice smartphone, but it took me about 20hrs tinkering to get it the way I wanted it. Then there's the cost (don't ask) even though I use Consumer Cellular which provides low cost phones, no-contract account, and you customize you plan. Also give AARP discounts, which is great for us 70-somethings.
The madding thing is Apple insisting in forcing you to use iTunes to upload/sync anything. I had a very @#!@@#! time figuring out how to get my ringtones on the iPhone. In fact, it's iTunes that loads the driver so you can see you iPhone on your PC.
Finally found a YouTube video on how to do that, but if you watch it you'll see it is complicated. But its better than trying any sync/download app to work as advertised.
UPDATE: There are some mistakes in the above video, the author seems to be using an older version of iTunes. Also there is a ringtone download site that you can use to get ringtones in the correct .m4r format. ZEDGE Ringtones (screenshots below)
Home Page for my iPhone
Example Download page
I suggest you download to your computer so you can drag-drop to iTunes, therefore be available for new phones. On my Win7 Pro 64bit rig, downloads go to the Downloads folder, do drag/drop to iTunes is easy. Since the downloaded files are ringtone-ready, no need to go through the complicated steps of creating .m4r files.
CORRECTIONS: Here are screen shots for newer versions of iTunes you need.
SUMMARY: For years, the British government has reportedly tracked and stored billions of records of Internet use by British citizens and those outside the UK in an effort to track every visible user on the Internet. Ryan Gallagher of "The Intercept" joins Hari Sreenivasan via Skype from Brighton, England, with more on UK cyber surveillance.
HARI SREENIVASAN (NewsHour): For years, the British government has reportedly tracked and stored billions of records of Internet use by British citizens and people outside the U.K., in an effort to track every visible user on the internet. That finding comes from “The Intercept” Web site, which is publishing findings from National Security Agency contractor (traitor) Edward Snowden’s leak on government surveillance practices.
“Intercept” reporter Ryan Gallagher wrote the story and joins me now via Skype from Brighton, England.
First of all, explain the scale of surveillance that was happening from the British equivalent of the NSA, the GCHQ.
RYAN GALLAGHER, THE INTERCEPT: Well, the skill is quite phenomenal. I mean, it’s hard to translate it when you just see the numbers. But you’re talking about 50 (ph) to 100 billion metadata records of phone calls and e-mails every single day. So vast, vast quantities of information they’re sweeping up. And they were talking by 2030 having in place the world’s largest surveillance system, so, a system that surpasses even what the NSA and U.S. has built itself.
HARI SREENIVASAN: OK, when somebody hears that there’s millions and billions and possibly trillions of pieces of data, they’re going to say, you know, what, how do you actually identify this is specifically me that’s doing this, or going to the site, or saying this thing in a chat room?
RYAN GALLAGHER: Uh-huh. Well, I mean, we have — we don’t actually — one of the interesting parts of the story is that we had a bunch of specific cases where, for example, we had monitored something like 200,000 people from something like 185 different countries, so almost every country in the world, they have listened to radio source (ph) through their computer. In one case, they decided to pick out just one of these people. It seems like at random, and what web site he had been viewing.
So, it’s kind of an all-seeing system. When you’re gathering that amount of information, it’s going to be something that does have an impact and effect in all of us really.
Despite launching a number of interesting products this year, Lenovo has perhaps got more press time for the things it has done wrong. The Chinese technology conglomerate is back in news, this time for allegedly installing a program on at least some of its refurbished notebook lineup that is programmed to send users' feedback data to Lenovo. Upon further inspection, the program seems to have an association with a third-party marketing and Web analytics firm.
As per many users' report, the company ships its factory refurbished laptops with a program called "Lenovo Customer Feedback Program 64" that is scheduled to run every day. According to its description, Lenovo Customer Feedback Program 64 "uploads Customer Feedback Program data to Lenovo."
Upon further digging, Michael Horowitz of Computerworld found these files in the folder of the aforementioned program: "Lenovo.TVT.CustomerFeedback.Agent.exe.config, Lenovo.TVT.CustomerFeedback.InnovApps.dll, and Lenovo.TVT.CustomerFeedback.OmnitureSiteCatalyst.dll."
As he further pointed out, Omniture, as mentioned in the suffix of one of the files, is an online marketing and Web analytics firm, which suggests that the laptops are tracking and monitoring users' activities.
On its support website, the largest PC vendor noted that it may include software components that communicate with servers on the Internet. These applications could be on any and every ThinkCentre, ThinkStation, and ThinkPad lineups. One of the applications listed on the website is Lenovo.TVT.CustomerFeedback.Agent.exe.config.
This isn't the first time Lenovo has been caught shipping what appears to be a spyware on its machines. Earlier this year, Lenovo was found bundling a spyware called "Superfish" on its machines. In August, the company was caught covertly downloading and installing software on its Windows PCs. The program modified the BIOS to force the computer to download its programs upon each login.
Every time Microsoft releases a new version of an operating system, there’s always a few users bitterly unhappy at the company’s decision not to support new features on older products. Microsoft has finally listened to these die-hard devotees of older operating systems. If you felt like Windows 7 and Windows 8 offered you a little too much privacy, rejoice: Microsoft is updating those operating systems with the same telemetry gathering software it deployed on Windows 10.
What? You wanted DirectX 12?
Ghacks.net has discovered four KB updates for Windows 7 and 8, each of which is described as an “Update for customer experience and diagnostic telemetry.” Each is detailed below:
KB 3068708: This update introduces the Diagnostics and Telemetry tracking service to existing devices. By applying this service, you can add benefits from the latest version of Windows to systems that have not yet upgraded. The update also supports applications that are subscribed to Visual Studio Application Insights.
KB 3068708 is listed as collecting diagnostics about functional issues on systems that take part in the Customer Experience Improvement Program. Determining whether or not you are a member of the CEIP, however, is less than obvious. The KB also notes that “Most programs make CEIP options available on the Help menu, although for some products, you might have to check settings, options, or preferences menus.” This is a recommended Windows update.
KB 3022345: This update has been superseded by KB 3068708, but previously provided the same telemetry-tracking services. It’s not clear how the two updates differ, but if you want to remove all traces of telemetry tracking, you’ll want to remove this update as well.
KB 3075249: This update adds telemetry points to the User Account Control (UAC) feature to collect information on elevations that come from low integrity levels. What this appears to mean is that MS wants more information about the kinds of applications that trigger UAC in the first place, presumably because it wants to know what they do and why they need that access. This update is classified as Optional.
KB 3080149: This update is described in identical language to the first two. “This package updates the Diagnostics and Telemetry tracking service to existing devices. This service provides benefits from the latest version of Windows to systems that have not yet upgraded. The update also supports applications that are subscribed to Visual Studio Application Insights.” It is provided as an Optional update, even though the first was classified a “Recommended” update.
Hard-coded phoning home
One of the assumptions made by various privacy advocates and journalists, including me, is that third-party utilities would be able to shut down the tracking Microsoft deployed in Windows 10. To some degree, that’s already happened, but there are certain new “features” of Windows 10 that can’t be blocked by any OS-level tweaks, including the hosts file. The updates listed above connect to vortex-win.data.microsoft.com and settings-win.data.microsoft.com. These addresses are hard-coded to bypass the hosts file and cannot be prevented from connecting. It’s been reported that software firewalls aren’t sufficient to block them, though this is unclear.
IMPORTANT: You should uninstall updates in reverse order starting with KB3080149 and Restart after each uninstall run. Uninstall KB3068708 LAST (it is the key update, the others are updates to this one).
The upshot for Windows 7 & 8 users who want MORE privacy, uninstall the listed 'updates' and hide them when they come up again.
I make no guarantee that any advice given on these pages will work as expected. There are just too many variables depending on Operator Systems and hardware configurations to give any advice that will always work.
Where possible, I will provide links to my source.
I have over 30yrs experience in electronics, computers, and software. I have served as an IT Technician. So I have created this blog to pass on my experience on these subjects.
Note that I do not have any Certifications nor degrees. All I know is from hands-on.
My experience in electronics comes from 22yrs in the Navy (retired) in Avionics, including as an instructor.
Note that I monitor the support forums under "Recommended Links."
There is no guarantee that any link provided in this blog will always work, especially for older links. The validity of any link is governed by the source-site policies. Some sites will archive articles and require subscription to access. Very small sites, such as a local town newspaper, may not archive at all.