• Guests may view all public nodes. However, you must be registered to post.

OS/Devices Succeptible to Viruses & Hybrid Attack Preparedness

REALHumanRights

Power Poster
Regular Contributor
Joined
Oct 18, 2017
I am posting this thread to address "hybrid attacks" based on 2022-level threats, and pros/cons on issues involving technology and impact of an enemy/other attack on public. This will not focus on mass nuclear bomb attacks, as clearly well-documented in other sources, except alternatives to those who cannot "build shelters" and who have to consider their best possible options in an unprepared world. My vantage is USA-based and in the Washington DC metropolitan area.
 
Hybrid Attack Preparedness and Smartphone Ad Hoc Network (SPANs) for Emergency Communications

In the event of a cyber/electronic/sabotage attack on area communications systems that disables communications and Internet service in an area, there are still some short-range bluetooth communications options. One to consider is ad hoc networking using Bluetooth or other non-Internet communications.

A. Bridgefy App for Android and/or iphone IOS.

-- 1. Bridgefy App for Android- for offline messaging if no voice or Internet available - being used in Ukraine now
NOTE: you do not have to have an Android ongoing phone service for this to work or even a SIM card.
You simply purchase a low-priced Android phone, connect this to your local Internet service (while you have it), and download the Bridgefy app. It now becomes your emergency short-range Bluetooth communications tool. The concept of the Bridgefy App is it will use the Bluetooth functioning inherent in the phone to broadcast nearby messages to others nearby in the event on an emergency.

-- 2. Bridgefy App for IOS iPhone. - for offline messaging if no voice or Internet available. I am not aware of anyone who has this working. In my own real-world tests, it has NOT worked at all. My research indicates there is a problem with IOS updates and ad hoc networking tools over the past year. If anyone is getting this to work, please let everyone know. Note that later versions of Apple IOS has a notorious history of problems with Bluetooth for many people.

If you purchase a phone (e.g., an Android) for this purpose it may be "expensive" option, but consider. Other people will have Android phones, but they may not have walkie-talkie General Mobile Radio Service (GMRS) or Family Radio Service (FRS), as many governments have persuaded them there is no need for such emergency preparedness.

B. FireChat
There used to be a Bluetooth communications tool for Apple IOS system (and Android) called FireChat. This was discontinued in 2016. It used to work well. If you have an old phone and it is still on there, you might want to see if your FireChat is still working. It was designed and worked well for Bluetooth emergency communications.

C. Ad Hoc Networking Using Airdrop on iPhones
For your family members nearby, remember you should be able to send use AirDrop to send messages.
The "image" could simply be something that you type in Notes, then you take a screen shot of the Notes message, and then send that image over as an AirDrop message to the other trusted iPhone. The problem is that you have to be SO CLOSE, it is essentially impractical as a SPAN workaround tool. I tested it with my family in the house, and unless we are right near each other, it won't work.

D. Other SPAN Recommendations?
Appreciate other SPAN recommendations and/or RECENT tool experience from the community.
 
Hybrid Attack Preparedness--Alternate Non-Provider Messaging
in the event of a cyber/electronic/sabotage attack on the major network provider voice and networking (AT&T, Verizon, etc.), there is another distance-insensitive messaging application available. I have confirmed that this app works. You would have to find a source of Internet services, but in a hybrid/cyber attack is possible that some services would be working and some might not, so that Internet service might still exist from a non-mobile phone provider.

You can also create a "channel" for your family/friends to meet at in the event of an emergency that knocks out major providers, and you can access the Zello PTT app.

For example, the Zello Push to Talk (PTT) messaging service exists for both Android and iPhone smartphones. I have confirmed that this works on both iPhone environments, and it is installed on my Android emergency Bluetooth phone.

Zello PTT Walkie Talkie
Apple iPhone IOS App

Zello PTT Walkie Talkie
Android App

The potential benefit of this app, during a hybrid attack, it is likely you can get friends/family to download an app, while the GMRS/FMS walkie-talkie devices that you actually send them will probably be put in a closet (not that you shouldn't also send those). The obvious downside is that you would still need some type of Internet service for it to work.
 
Hybrid Attack Preparedness - Mesh Network Emergency Communications

Mesh Network Chat App
Where no mobile service available, when all networks and electricity are down. Mesh Network works when 2 or more smartphones are within range of each other. The distance or coverage depends on the smartphone’s signal strength, it varies from one model to another. Approximate distance is 100 feet between 2 smartphones.

1. Briar - Google Android. Briar doesn’t rely on a central server – messages are synchronized directly between the users’ devices. If the Internet’s down, Briar can sync via Bluetooth or Wi-Fi. To add a contact, you need to meet up with the person you want to add as a contact. This is security oriented, and possibly harder to use than Bridgefy. IMPORTANT NOTE: Briar uses a significant amount of battery power, so make sure you are using this in an environment where you have electricity access.

2. The Serval Mesh - Google Android. This Australia-based app is designed to make private phone calls, send secure text messages and share files when cellular networks fail or are unavailable. According to the @ServalProject, two years ago, "Note that for the time being, the Serval Mesh app is not available from Google Play, because we purposely target a really old version of Android, so that you can run it on quite old devices. For now, you can get it direct from..." http://developer.servalproject.org/files/chat"
For two years, Serval has not responded to any requests on this.

3. Vojer - Apple iOS. Vojer claims to support offline messaging app. However, most of the reviews say that it does NOT work. The very few that do state it worked 6 or 7 years ago. You have to pay for this app.

4. DISCONTINUED: Signal Offline Messenger - Google Android. This is included only because there are so many old Internet posts referencing it. Note that Signal Offline Messenger app has not been updated since 2015 and it's reportedly not working anymore. I have also read that if you enable Signal to be your default SMS app then you can message even if you are offline. I don't know if that works with Signal Private Messenger, which still exists.

5. Also article on value of phones without SIM cards
 
Really, the best thing that you can do for cyber defense is to try to do the following. For a desktop computer, back-up all of your important files to either a CDR or DVR form or use a usb stick. Back up your banking information, any correspondence that you consider important, etc. Make sure you have plenty of cash, groceries, fuel, etc. Once you finish using your computer stuff, shut it down. Disconnect your internet connection from the computer, or if you use a wireless type connection, disconnect your router from your incoming internet.
I would say the best thing you can do for cyber defense is not use a Windows-based system.... but that's a whole other thread discussion.
 
Absolutely agree, but I'm not familiar with Mac or Linux or the other programs out there.
Fair 'nuff, but neither was I at one point. I made the switch to Linux over 20 years ago and haven't looked back.
Two quick points to encourage you to experiment:

1: Most Linux distributions will allow you to install as a dual-boot system, so while you are familiarizing yourself with Linux, you still have access to something more familiar. This is also a handy option for gamers.

2: MacOS is nothing more than a special distribution of Linux with Apple's fancy GUI on top of it. If you drop down to command line on a Mac, the commands are almost identical to Linux.

If you want to try Linux, I'd recommend Linux Mint with the Mate desktop manager. It's very user friendly. For the most part, it "works out of the box" with no problems for the user. And you won't believe how fast the install goes compared to installing Windows.
 
Fair 'nuff, but neither was I at one point. I made the switch to Linux over 20 years ago and haven't looked back.
Two quick points to encourage you to experiment:

1: Most Linux distributions will allow you to install as a dual-boot system, so while you are familiarizing yourself with Linux, you still have access to something more familiar. This is also a handy option for gamers.

2: MacOS is nothing more than a special distribution of Linux with Apple's fancy GUI on top of it. If you drop down to command line on a Mac, the commands are almost identical to Linux.

If you want to try Linux, I'd recommend Linux Mint with the Mate desktop manager. It's very user friendly. For the most part, it "works out of the box" with no problems for the user. And you won't believe how fast the install goes compared to installing Windows.
A thread focussing on OS's that are least succeptible to viruses and attacks would be great and pretty timely.
 
A thread focussing on OS's that are least succeptible to viruses and attacks.
Done. Split comments into new thread dedicated to this specific topic.

<merged my posts>

Done. Split comments into new thread dedicated to this specific topic.
I have merged a similar thread discussing same thing. You will notice REALHumanRights posts where moved into this thread. Which @REALHumanRights posts are good work. Didn't seem right to have two threads talking about same thing. Thanks.
 
Last edited:
Fair 'nuff, but neither was I at one point. I made the switch to Linux over 20 years ago and haven't looked back.
Two quick points to encourage you to experiment:

1: Most Linux distributions will allow you to install as a dual-boot system, so while you are familiarizing yourself with Linux, you still have access to something more familiar. This is also a handy option for gamers.

2: MacOS is nothing more than a special distribution of Linux with Apple's fancy GUI on top of it. If you drop down to command line on a Mac, the commands are almost identical to Linux.

If you want to try Linux, I'd recommend Linux Mint with the Mate desktop manager. It's very user friendly. For the most part, it "works out of the box" with no problems for the user. And you won't believe how fast the install goes compared to installing Windows.
If things do settle down to whatever the new normal is going to be, I plan to build another computer, and I just might give that thing a whirl.
 
Okay, let me post some information for the masses based on my 30 years of IT experience:

Order of best mainstream operating systems based on both privacy and security risks:
  1. Linux
  2. MacOS
  3. Android OS
  4. Mac iOS
  5. Windows XP
  6. Windows 7
  7. Windows 8 & 8.1
  8. Windows 10 and higher
Now, the Android and Mac iOS systems are pretty secure as operating systems, but cellular carriers usually add their own crap on top of the OS that sends information back to the carrier without the user's knowledge. Beyond that, where people get in the biggest trouble is with the apps they install. My advice: Don't install any app you don't absolutely need. As for games, only install games that do not require network access to function and block their network permissions.

Personally, none of my devices: laptops, phones, tablets, etc. are allowed network access until I've installed a firewall that gives me full control over every app's ability to communicate with the outside world. I realize that your average user doesn't have the knowledge necessary to do this for themselves, but I say this to illustrate just how bad having these devices can really be. My latest phone wasn't even activated until I had wiped the factory-installed OS and installed one that is more secure. Even my Linux laptop, as secure as the operating system is, has its own firewall installed. On top of all that, my home network is fully protected by a linux-based network security platform that gives me full control over every single byte of data that enters or leaves my home network. Again, beyond most average users' capabilities, but also to emphasize just how dangerous the wide-open internet is.

IoT Devices: In my professional opinion, the "Internet of Things" is the most prevalent threat to both personal privacy and global network security in the history of the internet. For those who don't know, IoT devices are items like thermostats, alarm systems, Ring doorbells, smart TVs, garage door openers, Roombas, smart light bulbs, home assistants like Alexis and Cortana, even kitchen appliances. All of these "smart" devices are capable of connecting to your home network, at which point two things happen:
  1. They can send information to god-knows-who
  2. They are vulnerable to attack and being compromised by anyone in the world
IoT devices are notorious for poor security, and security patches for vulnerabilities that are found later are hardly ever issued by the OEM. And yes, there are people out there who do nothing except probe for vulnerabilities in this stuff.

Two examples from my own home network:
We have a smart TV manufactured by Samsung in our bedroom. We use it to watch local news in the mornings before we get out of bed. It also has a wireless connection to my network so we can watch Netflix or Hulu on it. Now, the first time I turned it on and connected it to my network, my network firewall lit up like a Christmas tree with all the data it was trying to send to Samsung and Amazon. Even when just watching plain old television broadcasts, it tries to send out data over the internet, which my firewall blocks, except for Netflix and Hulu.

I recently installed two GE smart bulbs in my home office so I could control color and brightness. This ONLY works through an app on my phone. Sure enough, the second they connected to my home network, the firewall started blocking hundreds of data requests being sent to Google servers. Now, I lose some functionality by blocking all that traffic, but the basic functions are still accessible.

Can you imagine an average user who knows nothing about network security and is either ignorant or apathetic of the risks that are out there installing all of this stuff in their homes without any security at all???? Hell, our Roomba has a floor plan of our house stored in its system for christ's sake! It tries to phone home all the time!

Newer cars are coming from the factory with a two-way OBDC system that utilizes bluetooth and/or wireless technology to communicate. This means they can be hacked by someone in a nearby car who can then take over any vehicle functions controlled by computer. This isn't theory or the stuff of Hollywood; this has actually been proven in real life testing.

Everyone remembers how SkyNet existed in hundreds of thousands of computers all over the globe, and that's how it was able to take over the world's technology so quickly? That's not science fiction. "Bot farms" consist of hundreds to hundreds of thousands of compromised devices which are then used in a coordinated attack against one or more selected targets. The more compromised computers on the network, the more effective the attack. I can guarantee you there are computers, phones, and even thermostats sitting out there right now that have already been compromised but are continuing to function normally while just awaiting the command to execute whatever attack they've been programmed to carry out. And when - not if - it happens, people are going to have the nerve to act surprised.

Cell phones and computers are dangerous if not used responsibly. If you believe nothing else I have to say on this board, believe me on this, because I have witnessed it first hand and have been defending corporate networks against literally millions of threats for several years. Part of the reason I switched careers recently was because keeping networks safe is becoming next to impossible, and I wanted out before anything major happened. And when it does, on my home network firewall there is a special configuration setting that I have never used except in testing. It's labeled "Emergency Network Isolation." Essentially, with a single mouse click I can kill all inbound and outbound traffic on our home network. It's designed to be used in the event of a major cyber attack against the United States. Then I will fire up a special laptop I keep offline that is specifically designed to function in a high-risk network environment so that I can safely monitor the situation without risking being compromised.

This isn't paranoia. This is how bad it really is.
 
Done. Split comments into new thread dedicated to this specific topic.

<merged my posts>


I have merged a similar thread discussing same thing. You will notice REALHumanRights posts where moved into this thread. Which @REALHumanRights posts are good work. Didn't seem right to have two threads talking about same thing. Thanks.
Clarification on what "Hybrid Attacks" for this thread, which was the point of this thread. ( I am really not sure that it is an "OS" issue, but you're the boss.)

I am not certain the greatest threats here are specific to only nuclear weapons, but a combination of attacks of cyber attacks (not necessarily to your computer, but to infrastructure systems), electronic attacks, and sabotage. We have seen a lot of cyber infrastructure, communications, banking, transportation system, and economic attacks over the past 2 weeks. If war escalates, I don't know that a clear-cut nuclear blast solution is the only way for serious disruption, and my preparedness message is on these other types of attacks, what I am calling "hybrid attacks." Sorry if it is a strange name, I made it up, because I have not seen anyone consistently discussing that preparedness.

So in communications disruption, I offered some specifics on Bluetooth communications, Smartphone Access Network (SPAN), and Mesh communications network contingencies. Will address other issues. Hopefully it does not create an "off-topic" here, but just trying to get this out there for others who have other preparedness needs for hybrid attack threats.
 
Hopefully it does not create an "off-topic" here,
I see what your saying. It shouldn't get off topic. It's rather similar in nature. Preparedness from attack/viruses. If other elements in thread start to diverge will see what to do then.
I am really not sure that it is an "OS" issue, but you're the boss.
Other members where starting to talk about the vulnerability of each OS system and what to get or do from attack/virus. So through it on the title.
 
Last edited:
Hybrid Attack Preparedness - Alternate Email.

The ubiqutious use of email has also led to a lot of email gravitating to major systems; the problem is with such centralization of email communications it also presents a convenient chokehold for hybrid attackers. With Google's specific stand on the Russia/Ukraine war as well as censorship, it makes itself an even greater target. They provide a target for attack, with limited proof of "military escalation." So the point here is not "privacy" (we are being spied on and manipulated yeah we know all that), but actual access to communications in Hybrid Attack.

So we might recommend to friends and families, using GMAIL to quickly have develop alternative, non-USA HQ'd email accounts. I would recommend GMAIL, Yahoo, Hotmail, etc., all USA-based systems are likely to be a target in Hybrid Attacks. Hopefully we won't need this, but given the escalation of economic war, the probability of a Hybrid Attack on communications, email, etc., as part of infrastructure attacks grows increasingly likely. Most important part of creating an alternate email account - let your LOVED ONES know that you have it.

Suggested Ideas for Email Accounts HQ'd outside of the USA:


-- A. Australia-based Fastmail. Pros - you can get it set up quickly. Gmail does not block Fastmail email messages or automatically send them to Spam folder. Cons - it is still Australia, which might also become a WWIII target. Other Cons - it is only free for temporary time, and then you need to pay for it.

-- B. India-based RediffMail.com. Pros - it is not a USA-based company. And you can get a free email service. And India is not currently at war with USA, Russia, or China. Pakistan, you never know. Cons - in email systems like Gmail, you need to find your Spam folder and make sure that your Rediff email messages are not automatically routed to the Spam folder. Mine were. That's a big deal in an emergency. It has ads (who cares if it is WWIII). Don't assume it is terribly secure. Most importantly in your setup, you will need a phone that will accept the OTP SMS message that verifies who you are (per link below this is a common problem with Rediff mail) apparently with both Apple and Android numbers not accepting the OTP SMS message, which stops you from finishing creation of your account. I could not get the OTP SMS message to be received on Apple iPhone. However, I did get it to work on my backup Android, using Line2 number. If I had the Line2 app on Apple iPhone might also have worked there. The downside of doing that is now that account is linked to your Line2 number.

-- C. PRC-based Alimail (based on PRC's Alibaba site). Pros - it is PRC - not likely Russia will attack. USA may attack, but Russia probably won't. Cons - USA may attack. The idea might have seemed better when PRC and USA were not threatening economic war. Alimail has a multiple step process, where first you need to develop an account for AlibabaCloud (https://www.alibabacloud.com/). You also to need to provide a photo of your credit card (not all the numbers, but a lot; by the way, they don't like PayPal), a copy of your last credit card statement, and a photo of your driver's license or other ID. It is a lot of information to give to the PRC, and not only do you not know what they will do with it, they might also reject it. It is a lot to get an alternative email account. But it is not impossible. The other possibility is that PRC may have better hackers to protect their email systems than USA has.
 
Last edited:
Hybrid Attack - Cyber Infrastructure Attack Preparedness and - Banking, Medication, Fuel, and Housing. In preparing for a cyber infrastructure attack, as Russia and China have been targeted in banking and fuel areas, it is practical to view these as targets for USA and Western nations, and prepare accordingly.

1. Withdraw Cash in Advance. Others will address having gold, silver, things to trade, etc. This is simply immediate short-term preparedness. A surprising number will not have any cash in 2022.

2. Make Sure You Have Written/Printed List of All Bank Accounts and Financial Accounts. This is like obvious to most preparedness individuals, but perhaps a good suggestion to family members.

3. Keep Vehicles with Fuel. As USA saw in the ransomware cyberattack on equipment managing the Colonial Pipeline in May 2021, even such a small ransomware attack can affect fuel availability for a week. This could also impact

4. Keep Medications Filled. Especially if you have a medical condition that requires constant medication. If you can, try to persuade pharmacy to fill more than one month in advance. If you are confident that your medical condition is highly controlled, perhaps you deliberately cut back part of pill or two, once in a while, and stockpile a "backup reserve" of medications for emergency. (Of course, something you should discuss with your doctor.)

5. Housing Payments. FICTION is full of stories of people facing crises and then never having to pay rent, mortgage, etc. USA political media have enjoyed promoting stories during the COVID-19 pandemic of those avoiding paying rent, etc., due to local measures. Let fiction and USA political media focus on those. In a crisis, try to stay a payment ahead of your housing. If you are going to have to hunker down in an emergency, thinking of paying next month's rent may seem like the last thing on your mind. But keep those you owe housing expenses off your back, to allow you to focus on family safety. Banking networks can go down, fuel systems go down, stock market can go down, but you can be sure that hardened or not... landlords and mortgage owners will know what you owe them.
 
The choice of phone is very important. I have an android ulefone that is also able to work as a UHF 2-way radio but just needs to have the wip antenna installed and the PTT application installed. This allows communication even when the 4g/3g network is down.
 
I have a smart tv, but I don't have it connected to the internet/router at all...since I don't use that function. Is it less vulnerable if I keep it unconnected to the 'net?
 
I have a smart tv, but I don't have it connected to the internet/router at all...since I don't use that function. Is it less vulnerable if I keep it unconnected to the 'net?
If the device is not connected to the Internet, and it itself cannot connect covertly, it can be considered almost completely safe. Personally, I consider home assistants such as Alexis and Cortana to be one of the biggest sources of personal information leaks.
 
Back
Top Bottom