Security

SolarWinds Hack Was 'Largest and Most Sophisticated Attack' Ever, Microsoft President Says (reuters.com) 66

A hacking campaign that used a U.S. tech company as a springboard to compromise a raft of U.S. government agencies is "the largest and most sophisticated attack the world has ever seen," Microsoft Corp President Brad Smith said. From a report: The operation, which was identified in December and that the U.S. government has said was likely orchestrated by Russia, breached software made by SolarWinds Corp, giving hackers access to thousands of companies and government offices that used its products. The hackers got access to emails at the U.S. Treasury, Justice and Commerce departments and other agencies. Cybersecurity experts have said it could take months to identify the compromised systems and expel the hackers. "I think from a software engineering perspective, it's probably fair to say that this is the largest and most sophisticated attack the world has ever seen," Smith said during an interview that aired on Sunday on the CBS program "60 Minutes." The breach could have compromised up to 18,000 SolarWinds customers that used the company's Orion network monitoring software, and likely relied on hundreds of engineers.
Open Source

Should You Block Connections to Your Network From Foreign Countries? (linuxsecurity.com) 134

Slashdot reader b-dayyy quotes the Linux Security blog: What if you could block connections to your network in real-time from countries around the world such as Russia, China and Brazil where the majority of cyberattacks originate? What if you could redirect connections to a single network based on their origin? As you can imagine, being able to control these things would reduce the number of attack vectors on your network, improving its security. You may be surprised that this is not only possible, but straightforward and easy, by implementing GeoIP filtering on your nftables firewall with GeoIP for nftables.

GeoIp for nftables is a simple and flexible Bash script released in December of 2020 designed to perform automated real-time filtering using nftables firewalls based on the IP addresses for a particular region. In a recent interview with LinuxSecurity researchers, the project's lead developer Mike Baxter explained the mission of GeoIP for nftables, "I hope this project is beneficial to those who may not have the IT budget or resources to implement a commercial solution. The code runs well on servers, workstations and low-power systems like Raspberry Pi. The script has the built-in ability to flush and refill GeoIP sets after a database update without restarting the firewall, allowing servers to run uninterrupted without dropping established connections."

This article will examine the concept of GeoIP filtering and how it could add a valuable layer of security to your firewall, and will then explore how the GeoIP for nftables project is leveraging Open Source to provide intuitive, customizable GeoIP filtering on Linux.

AI

AI Is Being Used to Screen Job Applicants (bbc.com) 147

The BBC reports on "the computers rejecting your job application," noting that applicants are now being screened with AI-scored tests that involve counting dots in boxes and matching emotions to facial expressions: The questions, and your answers to them, are designed to evaluate several aspects of a jobseeker's personality and intelligence, such as your risk tolerance and how quickly you respond to situations. Or as Pymetrics puts it, "to fairly and accurately measure cognitive and emotional attributes in only 25 minutes".

Its AI software is now used in the initial recruitment processes of a number of multinational companies, such as McDonald's, bank JP Morgan, accountancy firm PWC, and food group Kraft Heinz. An interview with a human recruiter then follows if you pass. "It's about helping firms process a much wider pool [of applicants], and getting signals that someone will be successful in a job," says Pymetrics founder Frida Polli...

Another provider of AI recruitment software is Utah-based HireVue. Its AI system records videos of job applicants answering interview questions via their laptop's webcam and microphone. The audio of this is then converted into text, and an AI algorithm analyses it for key words, such as the use of "I" instead of "we" in response to questions about teamwork. The recruiting company can then choose to let HireVue's system reject candidates without having a human double-check, or have the candidate moved on for a video interview with an actual recruiter.

HireVue says that by September 2019 it had conducted a total of 12 million interviews, of which 20% were via the AI software. The remaining 80% were with a human interviewer on the other end of a video screen. The overall figure has now risen to 19 million, with the same percentage split. HireVue first started offering the AI interviews in 2016. Its users include travel services firm Sabre.

Meanwhile, a report from 2019 said that such is the growth in the use of AI that it will replace 16% of recruitment sector jobs before 2029.

Security

The Long Hack: How China Exploited a U.S. Tech Supplier (bloomberg.com) 104

Supermicro chips and software were tampered with by Chinese operatives in the past decade, Bloomberg reported Friday, doubling down on its 2018 report that was widely disputed by several tech giants and government agencies. Today's report says that U.S. security and defense officials knew of the hack but kept it secret in an effort to learn more about China's hacking capabilities. From the report: Bloomberg Businessweek first reported on China's meddling with Supermicro products in October 2018, in an article that focused on accounts of added malicious chips found on server motherboards in 2015. That story said Apple and Amazon.com had discovered the chips on equipment they'd purchased. Supermicro, Apple and Amazon publicly called for a retraction. U.S. government officials also disputed the article.

With additional reporting, it's now clear that the Businessweek report captured only part of a larger chain of events in which U.S. officials first suspected, then investigated, monitored and tried to manage China's repeated manipulation of Supermicro's products. Throughout, government officials kept their findings from the general public. Supermicro itself wasn't told about the FBI's counterintelligence investigation, according to three former U.S. officials. The secrecy lifted occasionally, as the bureau and other government agencies warned a select group of companies and sought help from outside experts.
Some stories from 2018 that capture the reaction of the industry to Bloomberg's earlier piece:

Amazon Has Pulled Ads From Bloomberg Over Controversial 'Big Hack' Chinese Spy Story; Apple Has Not Invited Outlet's Reporters To a Product Event;
In an Unprecedented Move, Apple CEO Tim Cook Calls For Bloomberg To Retract Its Chinese Spy Chip Story;
Bloomberg is Still Reporting on Challenged Story Regarding China Hardware Hack.
Security

CD Projekt Red Hackers Reportedly Sold the 'Cyberpunk 2077' Source Code (engadget.com) 54

The hackers behind this week's ransomware attack on Cyberpunk 2077 studio CD Projekt Red appear to have found a buyer for the stolen data. Engadget reports: They ran an auction on a hacking forum but, as The Verge notes, they shut it down after reportedly accepting an offer from elsewhere. The starting price for the auction was said to be $1 million and there was the option for an interested party with a spare $7 million to buy the data outright. It's not clear who has acquired the data, how much they paid for it or what they're planning to do with the information.
Facebook

Proofpoint Sues Facebook To Get Permission To Use Lookalike Domains For Phishing Tests (zdnet.com) 32

Cyber-security powerhouse Proofpoint has filed a lawsuit this week against Facebook in relation to the social network's attempt to confiscate domain names the security firm was using for phishing awareness training. From a report: The case is a countersuit to a Facebook filing from November 30, 2020, when the social network used a UDRP (Uniform Domain-Name Dispute-Resolution) request to force domain name registrar Namecheap to hand over several domain names that were mimicking Facebook and Instagram brands. Among the listed domain names were the likes of facbook-login.com, facbook-login.net, instagrarn.ai, instagrarn.net, and instagrarn.org.

In court documents filed on Tuesday, Proofpoint said the UDRP should not apply to these domains, which it should be allowed to keep and continue using. Proofpoint argues that UDRP requests should only be used for domains registered in bad faith. The security firm instead says its use of the Facebook and Instagram lookalike domains "has been in good faith and for a legitimate purpose." Proofpoint claims its phishing awareness tests are crucial for the security of its customers, but also for the security of Facebook itself, as the phishing awareness tests teach users to recognize Facebook and Instagram lookalike domains and phishing attacks -- something that Facebook also benefits from, although indirectly.

Iphone

Apple Privacy Chief: North Dakota Bill 'Threatens To Destroy the iPhone As You Know It' (macrumors.com) 321

The North Dakota Senate recently introduced a new bill that would prevent Apple and Google from requiring developers to use their respective app stores and payment methods, paving the way for alternative app store options.

In response, Apple Chief Privacy Engineer Erik Neuenschwander said that it "threatens to destroy the iPhone as you know it" by requiring changes that would "undermine the privacy, security, safety, and performance" of the iPhone. Neuenschwander said that Apple "works hard" to keep bad apps from the App Store, and North Dakota's bill would "require us to let them in." MacRumors reports: According to Senator Kyle Davison, who introduced Senate Bill 2333 yesterday, the legislation is designed to "level the playing field" for app developers in North Dakota and shield customers from "devastating, monopolistic fees imposed by big tech companies," which refers to the cut that Apple and Google take from developers. Specifically, the bill would prevent Apple from requiring a developer to use a digital application distribution platform as the exclusive mode of distributing a digital product, and it would keep the company from requiring developers to use in-app purchases as the exclusive mode of accepting payment from a user. There's also wording preventing Apple from retaliating against developers who choose alternate distribution and payment methods.

Apple does not allow apps to be installed on iOS devices outside of the "App Store" and there are no alternate app store options that are available. Apple reviews every app that is made available for its customers to download, something that would not happen with a third-party app store option. Apple also does not let app developers accept payments through methods other than in-app purchase except in select situations, a policy that has led to Apple's legal fight with Epic Games.

No federal legislation has been introduced as of yet, and the North Dakota Senate committee did not take action on the bill. Senator Jerry Klein said that there's "still some mulling to be done" in reference to the bill.

Security

Breached Water Plant Employees Used the Same TeamViewer Password and No Firewall (arstechnica.com) 80

An anonymous reader quotes a report from Ars Technica: The Florida water treatment facility whose computer system experienced a potentially hazardous computer breach last week used an unsupported version of Windows with no firewall and shared the same TeamViewer password among its employees, government officials have reported. The computer intrusion happened last Friday in Oldsmar, a Florida city of about 15,000 that's roughly 15 miles northwest of Tampa. After gaining remote access to a computer that controlled equipment inside the Oldsmar water treatment plant, the unknown intruder increased the amount of sodium hydroxide -- a caustic chemical better known as lye -- by a factor of 100. The tampering could have caused severe sickness or death had it not been for safeguards the city has in place.

According to an advisory from the state of Massachusetts, employees with the Oldsmar facility used a computer running Windows 7 to remotely access plant controls known as a SCADA -- short for "supervisory control and data acquisition" -- system. What's more, the computer had no firewall installed and used a password that was shared among employees for remotely logging into city systems with the TeamViewer application. [...] The revelations illustrate the lack of security rigor found inside many critical infrastructure environments. In January, Microsoft ended support for Windows 7, a move that ended security updates for the operating system. Windows 7 also provides fewer security protections than Windows 10. The lack of a firewall and a password that was the same for each employee are also signs that the department's security regimen wasn't as tight as it could have been.

Security

Authorities Arrest SIM Swapping Gang that Targeted Celebrities (zdnet.com) 29

Eight men were arrested across England and Scotland this week as part of a coordinated crackdown against a SIM swapping gang that has hijacked the identities and social media profiles of US celebrities. From a report: The UK National Crime Agency, which made the arrests on Tuesday, said the gang targeted well-known sports stars, musicians, and influencers, primarily located in the US. "These arrests follow earlier ones in Malta (1) and Belgium (1) of other members belonging to the same criminal network," Europol, which coordinated the multi-national investigation, said today. Officials said this gang engaged in SIM swapping attacks, where they tricked US mobile operators into assigning a celebrity's phone number to a new SIM card under the attacker's control. While they had access to the victim's phone number, the SIM swappers would reset passwords and bypass two-factor authentication on the victim's accounts. "This enabled them to steal money, bitcoin and personal information, including contacts synced with online accounts," the NCA said. Europol said the gang stole more than $100 million worth of cryptocurrency using this method
Security

Researchers Discover New Malware From Chinese Hacking Group (axios.com) 18

Researchers have discovered new "highly malleable, highly sophisticated" malware from a state-backed Chinese hacker group, according to Palo Alto Network's Unit 42 threat intelligence team. From a report: The malware "stands in a class of its own in terms of being one of the most sophisticated, well-engineered and difficult-to-detect samples of shellcode employed by an Advanced Persistent Threat (APT)," according to Unit 42. The malware, which Unit 42 has dubbed "BendyBear," bears some resemblance to the "WaterBear malware family" (hence the bear in the name), which has been associated with BlackTech, a state-linked Chinese cyber spy group, writes Unit 42. Background: BlackTech has been active since at least 2013, according to Symantec researchers. BlackTech has historically focused chiefly on intelligence targets in Taiwan, as well as some in Japan and Hong Kong. The group has targeted both foreign government and private-sector entities, including in "consumer electronics, computer, healthcare, and financial industries," said researchers with Trend Micro. Trend Micro also previously assessed that BlackTech's "campaigns are likely designed to steal their target's technology."
Security

'No Support Linux Hosting' Shuts Down After Cyberattack (zdnet.com) 25

A web hosting company named No Support Linux Hosting announced today it was shutting down after a hacker breached its internal systems and compromised its entire operation. From a report: According to a message posted on its official site, the company said it was breached on Monday, February 8. The hacker appears to have "compromised" the company's entire operation, including its official website, admin section, and customer database. A No Support Linux Hosting (NSLH) spokesperson did not return a request for comment seeking details about the attack. But while details about the intrusion are unclear, the attack appears to have been destructive in its nature. "We can no longer operate the No Support Linux Hosting business," the company flatly acknowledged today. "All customers should immediately download backups of their websites and databases through cPanel," NSLH said, urging clients to do so before servers go down for good. At the time of writing, the nature of the NSLH attack is unclear, and we don't know if the hacker downloaded & wiped the company's database and backups or if we're talking about a classic ransomware attack where the intruder encrypted files and demanded a ransom for the decryption key.
Privacy

Browser 'Favicons' Can Be Used as Undeletable 'Supercookies' To Track You Online (vice.com) 35

According to a researcher, favicons can be a security vulnerability that could let websites track your movement and bypass VPNs, incognito browsing status, and other traditional methods of cloaking your movement online. From a report: The tracking method is called a Supercookie, and it's the work of German software designer Jonas Strehle. "Supercookie uses favicons to assign a unique identifier to website visitors. Unlike traditional tracking methods, this ID can be stored almost persistently and cannot be easily cleared by the user," Strehle said on his Github. "The tracking method works even in the browser's incognito mode and is not cleared by flushing the cache, closing the browser or restarting the system, using a VPN or installing AdBlockers."

Strehle's Github explained that he became interested in the idea of using favicons to track users after reading a research paper [PDF] on the topic from the University of Illinois at Chicago. "The complexity and feature-rich nature of modern browsers often lead to the deployment of seemingly innocuous functionality that can be readily abused by adversaries," the paper explained. "In this paper we introduce a novel tracking mechanism that misuses a simple yet ubiquitous browser feature: favicons." To be clear, this is a proof-of-concept and not something that Strehle has found out in the wild.

Bug

A Bug in Lenovo System Update Service is Driving Up CPU Usage and Prompting Fan Noise in Laptops and Desktops, Customers Say (lenovo.com) 50

New reader allquixotic writes: Since late January, most users running a pre-installed Lenovo image of Windows 10 has been bitten by a bug in Lenovo's System Update Service (SUService.exe) causing it to constantly occupy a CPU thread. This was noticed by many ThinkPad and IdeaPad users as an unexpected increase in fan noise, but many desktop users might not notice the problem. I'm submitting this story to Slashdot because Lenovo does not provide an official support venue for their software, and the problem has persisted for several weeks with no indication of a patch forthcoming. While this bug continues to persist, anyone with a preinstalled Lenovo image of Windows 10 will have greatly reduced battery life on a laptop, and greatly increased power consumption in any case. As a thought experiment, if this causes 1 million systems to increase their idle power consumption by 40 watts, this software bug is currently wasting 40 megawatts, or about 1/20th the output of a typical commercial power station. On my ThinkPad P15, this bug actually wastes 80 watts of power, so the indication is that 40 watts per system is a very conservative number.

Lenovo's official forums and unofficial reddit pages have seen several threads pop up since late January with confused users noticing the issue, but so far Lenovo is yet to issue an official statement. Users have recommended uninstalling the Lenovo System Update Service as a workaround, but that won't stop this power virus from eating up megawatts of power around the world for those who don't notice this power virus's impact on system performance.

Security

CD Projekt Red Game Studio Discloses Ransomware Attack, Extortion Attempt (zdnet.com) 45

Polish game developer CD Projekt Red, the maker of triple-A games like Cyberpunk 2077 and The Witcher series, has disclosed today a ransomware attack. From a report: In messages posted on its official social media channels, the gaming studio said the attack took place yesterday when a threat actor gained access to the company's corporate network. "Although some devices in our network have been encrypted, our backups remain intact. We have already secured our IT infrastructure and begun restoring the data," the company wrote on Facebook and Twitter. The game maker also published a copy of the attacker's ransom note, in which the hackers claimed they obtained copies of the source code for games like Cyberpunk 2077, Gwent, and The Witcher 3, along with an unreleased version of The Witcher 3 game. But despite the threat of a sensitive leak, the game maker said it wouldn't be paying any ransom demand.


Android

Android Barcode Scanner With 10 Million+ Downloads Infects Users (arstechnica.com) 54

An anonymous reader quotes a report from Ars Technica: A benign barcode scanner with more than 10 million downloads from Google Play has been caught receiving an upgrade that turned it to the dark side, prompting the search-and-advertising giant to remove it. Barcode Scanner, one of dozens of such apps available in the official Google app repository, began its life as a legitimate offering. Then in late December, researchers with security firm Malwarebytes began receiving messages from customers complaining that ads were opening out of nowhere on their default browser.

[Malwarebytes mobile malware researcher Nathan Collier] wrote: "No, in the case of Barcode Scanner, malicious code had been added that was not in previous versions of the app. Furthermore, the added code used heavy obfuscation to avoid detection. To verify this is from the same app developer, we confirmed it had been signed by the same digital certificate as previous clean versions. Because of its malign intent, we jumped past our original detection category of Adware straight to Trojan, with the detection of Android/Trojan.HiddenAds.AdQR." Google removed the app after Collier privately notified the company. So far, however, Google has yet to use its Google Play Protect tool to remove the app from devices that had it installed. That means users will have to remove the app themselves.

Security

Hacker Increased Chemical Level At Florida City's Water Supply, Police Say (wtsp.com) 117

An anonymous reader quotes a report from WTSP: hacker gained access to Oldsmar's water treatment plant, bumping the sodium hydroxide in the water to a "dangerous" level, according to Pinellas County's sheriff. In a press conference Monday, Sheriff Bob Gualtieri said his deputies, along with the FBI and U.S. Secret Service, are investigating the breach as it is unclear if it came from within the U.S. or from a foreign actor.

The incident first occurred on Feb. 5 at the city's water treatment plant when, around 8 a.m., an operator noticed someone had remotely entered the computer system that he was monitoring. It's a system responsible for controlling the chemicals and other operations of the water treatment plant, Gualtieri said. And this time, Gualtieri says, the hacker did more than just remote in. According to the sheriff, the hacker spent up to five minutes in the system and adjusted the amount of sodium hydroxide in the water from 100 parts per million to 11,100.

"This is obviously a significant and potentially dangerous increase. Sodium hydroxide, also known as lye, is the main ingredient in liquid drain cleaners," Gualtieri added. The operator immediately reduced the levels back to the appropriate amount and "at no time was there a significant adverse effect on the water being treated." Even if the operator did not notice the intrusion, the sheriff, Oldsmar Mayor Eric Seidel and City Manager Al Braithwaite all noted several fail-safes and alarm systems are in place to flag issues of this kind. Gualtieri reinforced that at no time was the public in danger.

Microsoft

Microsoft To Add 'Nation-State Activity Alerts' To Defender for Office 365 (zdnet.com) 14

Microsoft is working on adding a new security alert to the dashboard of Microsoft Defender for Office 365 (formerly Office 365 Advanced Threat Protection) that will notify companies when their employees are being targeted by nation-state threat actors. From a report: The feature was added on Saturday to the Microsoft 365 roadmap website. The idea behind the feature is not new. Since 2016, Microsoft began tracking nation-state hacking groups and the attacks they orchestrate against Microsoft email accounts. If a user is targeted or compromised in one of these attacks, Microsoft sends them an email about the attack, along with basic advice they need to take to re-secure their inbox and devices. Microsoft said in 2019 that it usually notifies around 10,000 users per year of nation-state attacks. But the problem with this notification procedure is that it relies on users reading their email and taking action, which doesn't always happen. Users don't read their emails daily, or it might sometimes take hours before the user reaches the notification in crowded inboxes, a time during which attackers could use to steal sensitive documents. For organizations who are customers of Microsoft's Office 365 service, the OS maker now plans to add these notifications inside the dashboard of Microsoft Defender for Office 365, the cloud-based security platform that scans a company's Office 365 accounts for threats.
Security

Iran 'Hides Spyware in Wallpaper, Restaurant and Games Apps' (bbc.com) 24

Iran is running two surveillance operations in cyber-space, targeting more than 1,000 dissidents, according to a leading cyber-security company. From a report: The efforts were directed against individuals in Iran and 12 other countries, including the UK and US, Check Point said. It said the two groups involved were using new techniques to install spyware on targets' PCs and mobile devices. And this was then being used to steal call recordings and media files.

One of the groups, known as Domestic Kitten or APT-50, is accused of tricking people into downloading malicious software on to mobile phones by a variety of means including: repackaging an existing version of an authentic video game found on the Google Play store, mimicking an app for a restaurant in Tehran, offering a fake mobile-security app, providing a compromised app that publishes articles from a local news agency, supplying an infected wallpaper app containing pro-Islamic State imagery, masquerading as an Android application store to download further software.

The American-Israeli company's researchers documented 1,200 victims being targeted by the campaign, living in seven countries. There had been more than 600 successful infections, it said.

Encryption

Swiss Company Claims Weakness Found in Post-Quantum Encryption, Touts Its New Encryption Protocol (bloombergquint.com) 63

"A Swiss technology company says it has made a breakthrough by using quantum computers to uncover vulnerabilities in commonly used encryption," reports Bloomberg: Terra Quantum AG said its discovery "upends the current understanding of what constitutes unbreakable" encryption... Terra Quantum AG has a team of about 80 quantum physicists, cryptographers and mathematicians, who are based in Switzerland, Russia, Finland and the U.S. "What currently is viewed as being post-quantum secure is not post-quantum secure," said Markus Pflitsch, chief executive officer and founder of Terra Quantum, in an interview. "We can show and have proven that it isn't secure and is hackable..."

The company said that its research found vulnerabilities that affect symmetric encryption ciphers, including the Advanced Encryption Standard, or AES, which is widely used to secure data transmitted over the internet and to encrypt files. Using a method known as quantum annealing, the company said its research found that even the strongest versions of AES encryption may be decipherable by quantum computers that could be available in a few years from now. Vinokur said in an interview that Terra Quantum's team made the discovery after figuring out how to invert what's called a "hash function," a mathematical algorithm that converts a message or portion of data into a numerical value. The research will show that "what was once believed unbreakable doesn't exist anymore," Vinokur said, adding that the finding "means a thousand other ways can be found soon."

The company, which is backed by the Zurich-based venture capital firm Lakestar LP, has developed a new encryption protocol that it says can't be broken by quantum computers. Vinokur said the new protocol utilizes a method known as quantum key distribution. Terra Quantum is currently pursuing a patent for the new protocol. But the company will make it available for free, according to Pflitsch. "We will open up access to our protocol to make sure we have a safe and secure environment," said Pflitsch. "We feel obliged to share it with the world and the quantum community."

United States

How the NSA's Hubris Left America Vulnerable (nytimes.com) 52

A new book promises "the untold story of the cyberweapons market — the most secretive, invisible, government-backed market on earth — and a terrifying first look at a new kind of global warfare."

Its author — a New York Times cybersecurity reporter — shares the book's story about David Evenden, a former National Security Agency analyst who later worked in Abu Dhabi: He, like two dozen other N.S.A. analysts and contractors, had been lured to the United Arab Emirates by a boutique Beltway contractor with offers to double, even quadruple, their salaries and promises of a tax-free lifestyle in the Gulf's luxury playground. The work would be the same as it had been at the agency, they were told, just on behalf of a close ally. It was all a natural extension of America's War on Terror. Mr. Evenden started tracking terror cells in the Gulf. This was 2014, ISIS had just laid siege to Mosul and Tikrit and Mr. Evenden tracked its members as they switched out burner phones and messaging apps...

Soon, though, he was assigned to a new project: proving the Emiratis' neighbor, Qatar, was funding the Muslim Brotherhood. The only way to do that, Mr. Evenden told his bosses, would be to hack Qatar. "Go for it," they told him. No matter that Qatar was also an American ally or that, once inside its networks, his bosses showed no interest in ever getting out. Before long his team at the contractor, CyberPoint, was hacking Emirati enemies, real and perceived, all over the world: Soccer officials at FIFA, the monarchy's Twitter critics, and especially Qatari royals. They wanted to know where they were flying, who they were meeting, what they were saying. This too was part of the mission, Mr. Evenden was told; it had all been cleared up high. In the War on Terror and the cyber arms market, you could rationalize just about anything.

All the rationalizations were stripped away the day emails from the first lady of the United States popped up on his screen. In late 2015, Michelle Obama's team was putting the finishing touches on a trip to the Middle East. Qatar's Sheikha Moza bint Nasser had invited Mrs. Obama to speak... And every last email between the first lady, her royal highness, and their staff — every personal reflection, reservation, itinerary change and security detail — was beaming back to former N.S.A. analysts' computers in Abu Dhabi. "That was the moment I said, 'We shouldn't be doing this,' he told me. "We should not be targeting these people."

Mr. Evenden and his family were soon on a flight home. He and the few colleagues who joined him tipped off the F.B.I. (The agency does not comment on investigations, but interviews suggest its review of CyberPoint is ongoing.) To pre-empt any fallout, some employees came clean to Reuters. The hack of Sheika Moza's emails with Mrs. Obama has never been reported.

It wasn't long after Mr. Evenden settled back in the states that he started fielding calls and LinkedIn messages from his old buddies at the N.S.A., still in the service, who had gotten a "really cool job offer" from Abu Dhabi and wanted his advice. By 2020, the calls had become a drumbeat.

"Don't go," he pleaded. "This is not the work you think you will be doing." You might think you're a patriot now, he wanted to warn them, but one day soon you too could wake up and find you're just another mercenary in a cyber arms race gone horribly wrong...

The author criticizes America's security establishment. "When we discovered openings in the systems that govern the digital universe, we didn't automatically turn them over to manufacturers for patching. We kept them vulnerable in the event the F.B.I. needed to access a terrorist's iPhone or Cyber Command had reason to drop a cyberweapon on Iran's grid one day..."

But the author also warns that "the potential for a calamitous attack — a deadly explosion at a chemical plant set in motion by vulnerable software, for example — is a distraction from the predicament we are already in. Everything worth taking has already been intercepted: Our personal data, intellectual property, voter rolls, medical records, even our own cyberweaponry..."

The book's title? This is How They Tell Me the World Ends.

Slashdot Top Deals