|
Throughout the 1990s, Microsoft developers were in a race of one-upmanship to produce the most elaborate secret “Easter eggs.” These included games of pinball, racing, and even flight simulators, all hidden within Office and Windows. Let’s take a look back at some of the best. “Easter eggs” are developer credits, silly features, or inside jokes hidden in software. Because you can only access these through a series of arcane steps resembling an Easter egg hunt, that’s how they got their name. Easter eggs were a sly, fun way for authors to secretly immortalize themselves in their work, even if individual programmer credits were discouraged for the sake of company unity. Microsoft’s history with software Easter eggs began as far back as the Commodore PET BASIC in the 1970s. Over the decades, it grew dramatically, continuing through MS-DOS and reaching peak complexity during the late ’90s in Microsoft Office applications. Microsoft Management officially put the kibosh on the practice in the early ’00s, citing security and customer trust concerns. For a while there, however, the eggs were on a roll—and they got pretty wild! In the ’90s, Excel attracted a large share of elaborate Easter eggs. For example, in Excel ’95, if you follow a series of complex steps, a window called the “Hall of Tortured Souls” appears. In this apparent reference to Doom, you can actually roam a 3D, first-person environment. After crossing a zigzag bridge, you discover a room with the names of Excel ’95’s developers and a low-resolution photo of the team. During the development of Windows 3.1, one of the programmers carried around a stuffed teddy bear. It became an inside joke and unofficial mascot for the operating system. When the team hid developer credits in the Program Manager of Windows 3.1, the bear naturally made an appearance. The Easter egg normally shows a man in a yellow suit next to a scrolling list of the developers’ internal email system names. If you perform the trick repeatedly, though, you might see the bear’s head in the yellow suit instead. Once word got out about the hidden “flight simulator” Easter egg in Excel ’97, it spread quickly in the press because it sounds so sensationally weird. In truth, though, it’s not exactly a flight simulator in the sense of gauges and airplane controls. Rather, it’s more of a surreal 3D, first-person flying experience over a purple landscape. If you fly around enough, you find a black monolith with the scrolling names of Excel ’97’s developers on it. See many of these wild and interesting Easter Eggs on OUR FORUM.
Security researchers have discovered an emerging threat that they fear could be nearly unstoppable. This growing botnet has already managed to enslave nearly 20,000 computers. It is known as DDG was first discovered in early 2018 by the network security experts at China-based Netlab 360. Back then the nascent botnet had control of just over 4,000 so-called zombies and used them to mine the Monero cryptocurrency. Much has changed since then. Today’s incarnation of DDG isn’t just five times larger. It’s also much more sophisticated. One of its distinguishing features is its command and control system. Most botnets are designed around a client/server model. Infected machines listen for instructions from the servers and then carry out their orders. DDG has a built-in Plan B, however: a proprietary peer-to-peer network. If the zombies can’t contact the servers, they automatically switch over to P2P channels to keep the operation running — exchanging payloads and instructions as if nothing had happened. They even utilize a built-in proxy system to obfuscate their activities. It’s a dastardly one-two punch, and one that Netlab 360 believes makes DDG “seemingly unstoppable.” Security professionals often disrupt botnets by wresting control of a domain name or an essential server away from the criminal operators. That won’t work against DDG. Despite its sophistication, the DDG botnet has grown very slowly. Its spread is also fairly limited geographically-speaking, too, with 86% of infections occurring in China. It’s not in the same league as botnets like Conficker or Necurs, which hit tens of millions of computers. Netlab 360 researchers think there’s a simple explanation for that. DDG’ss creator is probably quite happy with things the way they are. Its zombie army can mine a fair bit of Monero without attracting a lot of attention. By shedding a little light on DDG, Netlab 360 hopes that the cybersecurity community can figure out a way to slow or disrupt its operation before it evolves into something much more sinister. Redis server owners are advised to secure database accounts with strong passwords, while OrientDB server owners should update their machines as soon as possible. The DDG botnet shows that crooks don't have to build advanced malware and multi-layered infrastructure to make a profit today. Because of this reason and the high yielding profits is why we've seen so many Monero-mining botnets appear in the past year. For more turn to OUR FORUM. Signal has threatened to pull out of the US if the Congress decided to pass the latest anti-encryption bill into law. Last year, the company went against the Australian government who wanted to pass a similar law in the country. In case you don’t know, Signal is a popular encrypted messaging tool used by individuals and organizations to share sensitive information. However, the company is threatening to pull out if Congress passes the controversial anti-encryption bill. The EARN IT Act was introduced to the US Senate last month and has received a lot of backlashes from the public and companies like Signal. The Act would force the tech companies to forgo the use of end-to-end encryption. Signal developer Joshua Lund explained the implications of the new Act in a blog post titled, “230, or not 230? That is the EARN IT question.” Section 230 of the Communications Decency Act “protects online platforms in the United States from legal liability for the behavior of their users.” This basically means that companies like Facebook and Twitter are protected by law against the misuse of their platform by the users. While companies like Facebook can certainly carry the financial burden of being held accountable for the users’ actions, a small company like Signal cannot. Moreover, end-to-end encryption ensures that the data shared by two users cannot be viewed by a third-party including the platform used to transmit data. This is achieved using encryption keys that encrypt and decrypt data in real-time making it almost impossible for a third-party to eavesdrop without the correct encryption key. The US Congress said it needs to pass the Act to track down criminals who exploit children or use social media platforms for human trafficking and other criminal activities. However, the Electronic Frontier Foundation (via Gizmodo) (EFF) has argued that there is already a large swath of existing laws that target child sexual abuse and child sex trafficking ads, the EARN IT Act is not required. Lund correctly noted that “Bad people will always be motivated to go the extra mile to do bad things. If easy-to-use software like Signal somehow became inaccessible, the security of millions of Americans (including elected officials and members of the armed forces) would be negatively affected. Meanwhile, criminals would just continue to use widely available (but less convenient) software to jump through hoops and keep having encrypted conversations.” Follow this and more by visiting OUR FORUM.
|
Latest Articles
|


