{"id":14205,"date":"2018-12-30T10:45:03","date_gmt":"2018-12-30T18:45:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/30\/news-7957\/"},"modified":"2018-12-30T10:45:03","modified_gmt":"2018-12-30T18:45:03","slug":"news-7957","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/12\/30\/news-7957\/","title":{"rendered":"The Most Dangerous People on the Internet in 2018: Trump, Zuck and More"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5c1d486700ef8063f2d4f1dc\/master\/pass\/Most%20Dangerous%20People%20on%20the%20Internet%20GettyImages-1024986192-1041178454-1066786222-1073776708.jpg\"\/><\/p>\n<p><strong>Credit to Author: WIRED Staff| Date: Sun, 30 Dec 2018 12:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">This year thankfully <\/span>avoided any <a href=\"https:\/\/www.wired.com\/story\/notpetya-cyberattack-ukraine-russia-code-crashed-the-world\/\">world-breaking ransomware attacks<\/a> like NotPetya. It even had some small victories, like <a href=\"https:\/\/www.wired.com\/story\/github-ddos-memcached\/\">GitHub beating back the biggest DDoS attack in history<\/a>. Still, online threats are manifold, lurking and evolving, making the internet a more hostile place than ever.<\/p>\n<p>The biggest threats online continued to mirror the biggest threats in the real world, with nation states fighting proxy battles and civilians bearing the brunt of the assault. In many cases, the most dangerous people online are also the most dangerous in the real world. The distinction has never mattered less.<\/p>\n<p class=\"paywall\">On January 3 of 2018, at the <a href=\"https:\/\/www.wired.com\/story\/donald-trump-united-nations-north-korea\/\">height of tensions with North Korea<\/a>, Donald Trump saw fit to send the following tweet:<\/p>\n<p><a href=\"https:\/\/twitter.com\/realDonaldTrump\/status\/948355557022420992\">https:\/\/twitter.com\/realDonaldTrump\/status\/948355557022420992<\/a><\/p>\n<p class=\"paywall\">Set aside, if you can, the deep absurdity of the language. The episode was a reminder that Trump is perhaps the only human on Earth who could <a href=\"https:\/\/www.wired.com\/story\/how-trump-could-trigger-armageddon-with-a-tweet\/\">quite literally start a nuclear war with a tweet<\/a>, and that he seems decidedly not to care. While <a href=\"https:\/\/www.wired.com\/story\/north-korea-summit-denuclearize-history\/\">tensions with North Korea have subsided<\/a>\u2014for now\u2014Trump has used the internet to other ill effects, from potential <a href=\"https:\/\/www.lawfareblog.com\/donald-trumps-tweet-about-roger-stone-witness-tampering\" target=\"_blank\">witnesses tampering<\/a> in federal investigations, to constantly undermining the credibility of the media, to <a href=\"https:\/\/twitter.com\/realdonaldtrump\/status\/1075528854402256896\" target=\"_blank\">announcing<\/a> unilateral military action without any apparent thought for the consequences. Trump has shown in 2018 that he doesn&#x27;t need to cause Armageddon in a single tweet to do damage. He can simple use his social pulpit to whittle away at democratic norms, 280 characters at a time.<\/p>\n<p class=\"paywall\">Let the Russian president stand in for any number of his country&#x27;s adept hackers. The country may have been relatively quiet\u2014<a href=\"https:\/\/www.wired.com\/story\/nrcc-email-hack-midterm-election-meddling\/\">though not inactive<\/a>\u2014during the midterm elections, but Russia&#x27;s hackers still caused all manner of trouble throughout the world. Upset over a doping-related ban, they hacked and released emails of the International Olympic Committee in January, then <a href=\"https:\/\/www.wired.com\/story\/olympic-destroyer-malware-pyeongchang-opening-ceremony\/\">attacked the Pyeongchang Olympics<\/a> themselves, wreaking havoc during the opening ceremonies with so-called Olympic Destroyer malware. When a lab investigated the nerve agent used in the attempted murder of former Russian double agent Sergei Skirpal, <a href=\"https:\/\/www.wired.com\/story\/olympic-destroyer-hackers-may-have-returned-for-more\/\">Russia tried to hack it, too<\/a>. They continue to <a href=\"https:\/\/www.wired.com\/story\/russian-hackers-us-power-grid-attacks\/\">probe the US power grid<\/a> for weaknesses. And <a href=\"https:\/\/www.wired.com\/story\/russia-fancy-bear-hackers-microsoft-office-flaw-and-nyc-terrorism-fears\/\">on<\/a> and <a href=\"https:\/\/wired.com\/story\/fancy-bear-hackers-uefi-rootkit\/\">on<\/a>, all before you even get to Putin&#x27;s continued, <a href=\"https:\/\/www.apnews.com\/6eb40bb43cc74c6eb5b9e386ee62aa20\" target=\"_blank\">unprecedented cyberaggression<\/a> against Ukraine. Russia has spent this year actively, opening lashing out at the world online\u2014with Putin at the command.<\/p>\n<p class=\"paywall\">Facebook was tragically slow to recognize that its platform was being <a href=\"https:\/\/www.wired.com\/story\/how-facebooks-rise-fueled-chaos-and-confusion-in-myanmar\/\">used in service of genocide in Myanmar<\/a>. Indeed, it took a UN report before the company finally took action against the military leaders behind the most blatant abuses. Among the 20 individuals and organizations Facebook banned in that first wave was Min Aung Hlaing, head of the armed forces, who both used his personal account to spread hate speech and led a military that surreptitiously ran at least 425 Facebook pages, 17 Facebook groups, 135 Facebook accounts, and 15 Instagram accounts. &quot;We want to prevent them from using our service to further inflame ethnic and religious tensions,&quot; Facebook <a href=\"https:\/\/newsroom.fb.com\/news\/2018\/08\/removing-myanmar-officials\/\" target=\"_blank\">wrote<\/a> at the time. As <em>The New York Times<\/em> reported, it was quite a bit more serious than that: Myanmar military personnel, under Min Aung Hlaing&#x27;s command, &quot;turned the social network into a tool for ethnic cleansing.&quot;<\/p>\n<p class=\"paywall\">Min Aung Hlaing and his subordinates were the ones using Facebook in the service of genocide. But it was Facebook that let them get away with it for so long, just as it was Facebook that was slow to <a href=\"https:\/\/www.wired.com\/story\/inside-the-mueller-indictment-a-russian-novel-of-intrigue\/\">recognize Russian efforts to destabilize US democracy<\/a> in 2016, and Facebook <a href=\"https:\/\/www.wired.com\/story\/how-facebook-hackers-compromised-30-million-accounts\/\">that let 30 million users get hacked<\/a> with a vulnerability that took a year and a half to discover and fix. In fairness, many of the woes Facebook has faced in 2018 consist of revelations and repercussions of how the platform operated years ago, rather than today.<\/p>\n<p class=\"paywall\">But from his initial dismissiveness of the fake news problem to his <a href=\"https:\/\/www.wired.com\/story\/facebooks-dirty-tricks-nothing-new-tech\/\">company&#x27;s opposition research against George Soros<\/a>, it seems as though Facebook CEO Mark Zuckerberg still hasn&#x27;t grasped the enormous responsibility that comes with a platform as all-encompassing as Facebook, nor the extent of the damage. He and his deputies continue to insist that they&#x27;ll do better, but some things can&#x27;t be fixed retroactively.<\/p>\n<p class=\"paywall\">The <a href=\"https:\/\/www.wired.com\/story\/atlanta-ransomware-samsam-will-strike-again\/\">SamSam ransomware strain<\/a> had already had a remarkable run, targeting hospitals and universities and other victims with reason to pay up fast. Then <a href=\"https:\/\/www.wired.com\/story\/atlanta-ransomware-samsam-will-strike-again\/\">it hit Atlanta<\/a>. The attack hobbled the city, hampering payments and communications and all manner of municipal necessities. The hackers had demanded $52,000; <a href=\"https:\/\/www.wired.com\/story\/atlanta-spent-26m-recover-from-ransomware-scare\/\">Atlanta spent $2.6 million<\/a> to clean up the mess. In November, the Justice Department [brought charges against two Iranian nationals](https:\/\/www.wired.com\/story\/doj-indicts-hackers-samsam-ransomware\/] in connection with the hacking spree, alleging that they took in $6 million while causing $30 million of damage along the way. While they don&#x27;t seem connected to the Iranian government, the two alleged perpetrators seem unlikely to be arrested, or even chastened, by the indictment. Expect SamSam to continue to plague the internet well beyond 2018.<\/p>\n<p class=\"paywall\">In 2015, the <a href=\"https:\/\/www.wired.com\/story\/us-china-cybertheft-su-bin\/\">US and China came to an historic agreement<\/a>: The two superpowers would stop hacking each others&#x27; private sector interests. Miraculously, <a href=\"https:\/\/www.wired.com\/2016\/12\/obama-russia-hacking-sanctions-china\/\">it worked<\/a>, sort of, for at least a few years. China didn&#x27;t stop hacking altogether, but it at least ramped down its efforts against the US. But with trade tensions between the two countries, the truce <a href=\"https:\/\/www.wired.com\/story\/china-tests-limits-of-us-hacking-truce\/\">appears increasingly to have been short lived<\/a>. China has increased its hacking campaigns against the US Navy and other government-adjacent entities, and the recent revelation of a devastating, <a href=\"https:\/\/www.wired.com\/story\/marriott-hack-protect-yourself\/\">years-long Marriott breach<\/a> showed just how long-lasting some of <a href=\"https:\/\/www.wired.com\/story\/marriott-hack-china-2014-opm-anthem\/\">its apparent heists have been<\/a>. Leading the charge for China is APT10, an elite hacker group whose thefts of the world&#x27;s most closely held intellectual property has made it a top priority for law enforcement from not just the US, but multiple victim countries. A <a href=\"https:\/\/www.wired.com\/story\/doj-indictment-chinese-hackers-apt10\/\">recent indictment shows just how active<\/a>\u2014and effective\u2014the group has been.<\/p>\n<p class=\"paywall\">As Australia&#x27;s attorney general, Porter has pushed for, and gotten, a <a href=\"https:\/\/www.wired.com\/story\/australia-encryption-law-global-impact\/\">law that threatens to undermine encryption<\/a> not just Down Under, but around the world. As written, the law gives Australian authorities the right to compel tech companies to put backdoors in their encrypted messaging platform. It also lets officials target specific individual with those requests, under a veil of secrecy, rather than the company itself. It&#x27;s a concerning development on multiple levels. You can&#x27;t weaken encryption piecemeal; if you make a backdoor for WhatsApp, it will apply not just to Australians but to all users. You also can&#x27;t guarantee that hackers unauthorized nation state spies wouldn&#x27;t find their way in as well. In short, it&#x27;s a law that threatens encryption protections for everyone, whether the Australian government has targeted them or not\u2014a dangerous development on a global scale.<\/p>\n<p class=\"paywall\">Credit card skimming hacks were popular this year; Ticketmaster, British Airways, Newegg, and more all got hit. In fact, they all got compromised by the same group: Magecart. Well, technically an umbrella under which several groups coexist. According to research from security firm RiskIQ, Magecart has <a href=\"https:\/\/techcrunch.com\/2018\/11\/13\/magecart-hackers-persistent-credit-card-skimmer-groups\/\" target=\"_blank\">hit at least 6,400 sites<\/a> in its long history. Compared to nation state groups, its activities may seem relatively mundane. But it&#x27;s still one of the most active hacking consortiums out there, ready and waiting to lift your credit card number in 2019.<\/p>\n<p class=\"related-cne-video-component__dek\">WIRED contributing editor Garrett M. Graff, who covers special counsel Robert Mueller&#39;s Russia probe, authored the magazine&#39;s June cover story about Mueller&#39;s time in Vietnam, and wrote &quot;The Threat Matrix: Inside Robert Mueller&#39;s FBI and the War on Global Terror.&quot; Graff breaks down the investigation&#39;s status, the big outstanding questions, and where the investigation is likely to go after the midterm election.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/most-dangerous-people-on-internet-2018\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5c1d486700ef8063f2d4f1dc\/master\/pass\/Most%20Dangerous%20People%20on%20the%20Internet%20GettyImages-1024986192-1041178454-1066786222-1073776708.jpg\"\/><\/p>\n<p><strong>Credit to Author: WIRED Staff| Date: Sun, 30 Dec 2018 12:00:00 +0000<\/strong><\/p>\n<p>From Donald Trump to Russian hackers, these are the most dangerous characters we&#8217;ve been watching online in 2018.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-14205","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14205"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14205\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14205"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}