Глава 1
The Digital Vulnerability Dilemma
In a world where everything from your toothbrush to your car is becoming "smart," cybersecurity expert Mikko Hypponen delivers a sobering wake-up call. As the Chief Research Officer at F-Secure with over 30 years of experience fighting digital threats, Hypponen has emerged as one of the most respected voices in cybersecurity. His book has become required reading in technology circles, with Elon Musk reportedly recommending it to Tesla's security team and Microsoft incorporating its principles into their security training. The book's central thesis-captured in what's now called "Hypponen's Law"-states simply: "If it's smart, it's vulnerable." This principle has proven so influential that it's referenced in cybersecurity frameworks across industries from healthcare to critical infrastructure. What makes this book particularly compelling is how Hypponen transforms complex technical concepts into accessible insights through vivid storytelling drawn from his decades on the digital frontlines.
Глава 2
From Floppy Disks to Global Cyber Warfare
The Internet began as a U.S. defense project designed to survive nuclear war, with the first router connected in August 1969. What started as ARPANET evolved through crucial developments like TCP/IP protocols in 1973 and Tim Berners-Lee's creation of HTTP and HTML in 1989, which gave birth to the World Wide Web. The introduction of the Mosaic browser in 1993 provided many their first glimpse of this new digital frontier.
Early websites were rare treasures-only about 700 existed by early 1994 when Hypponen created his company's site. Accessing the web required complex technical knowledge: direct line or SLIP/PPP connections, TCP-IP stacks with Windows Sockets compatibility, and browsers like NCSA Mosaic. This was a time before Google, Wikipedia, or even Microsoft's website existed.
The technological revolution accelerated dramatically with Linux, created by Linus Torvalds in 1991. Today, Linux powers 85% of smartphones, most web servers, Hollywood special effects systems, SpaceX rockets, and Tesla cars. Even Microsoft now embraces Linux on its Azure cloud services. Torvalds also created Git, the foundation for collaborative software development that led to GitHub (purchased by Microsoft for $7.5 billion).
Our smartphones now contain computing power rivaling 1990s supercomputers that required water cooling systems and cost millions. Mobile internet has transformed access patterns, with Finland leading global mobile data usage through fast, affordable connections without data caps.
The internet's evolution has fundamentally changed media consumption, transforming passive viewers into active participants who can share opinions globally. This has been particularly beneficial for minorities and those with niche interests who can now find supportive communities online. However, the same technology enables harmful communities to form around destructive ideas and misinformation.
Money itself has become data. Digital banking began as early as 1990, and physical cash is rapidly disappearing in many countries, particularly in Sweden where printed money represents less than 1% of GDP compared to 8% in the US. This transformation has moved bank robberies from physical heists to online attacks.
Despite the United States representing only 6% of internet users (compared to Asia's 50%), American companies have dominated global internet services. However, China is rapidly becoming a dominant online power, with Chinese websites now occupying nearly half of the world's most visited web addresses.
Глава 3
The Evolution of Digital Threats
Working in information security is like playing Tetris-successes disappear while failures accumulate. When security works flawlessly, it's invisible, with little recognition for preventing disasters that never happen. This paradox was exemplified by the Y2K bug: after massive global efforts to fix date-related software issues, the media portrayed the lack of millennium catastrophes as evidence the threat was overblown.
The internet has made geography irrelevant in crime-we're now more likely to be victims of online than real-world crime in countries with low crime rates. Unlike local criminals, online attackers can target victims worldwide.
Early computer viruses were created by bored teenagers seeking recognition rather than profit. In 1992, Hypponen traced the Finnish "Cinderella II" virus to a lonely 16-year-old boy living in rural isolation who explained: "I can't leave this place, but I wrote something that could." His virus, which attempted to wipe hard drives after infecting 1,000 files, represented the typical virus author of that era-a talented, frustrated young man seeking to leave his mark on cyberspace.
The transformation from hobbyist hackers to career criminals began in 2003 when spammers joined forces with virus authors. As email filters improved at blocking spam servers, spammers realized they could use virus-infected home computers to send emails that would be harder to filter. This turning point divided the hacker community-some "purists" quit in disgust while those who stayed did so for profit, marking the beginning of professional cybercrime.
By 2016, Hypponen coined the term "cybercrime unicorns" for professional groups approaching billion-dollar valuations. This resulted from both increasing attack profits and cybercriminals storing wealth in Bitcoin, which dramatically appreciated in value. Modern cybercrime gangs can afford professional data centers, impressive brands, legal teams, and valuable exploits.
The malware landscape has evolved through distinct epochs. The first PC virus (Brain.A) appeared in 1986, spreading physically via floppy disks. File viruses followed, infecting program files and spreading through file-sharing services. Macro viruses emerged in 1995 with Concept, which infected Microsoft Word documents. Email worms like Happy99 and ILOVEYOU appeared next, spreading by masquerading as trusted contacts.
Internet worms represented a dramatic evolution, spreading without human intervention and reducing infection times from hours to minutes. Slammer (2003) remains the fastest-spreading worm in history, infecting all vulnerable Microsoft SQL servers worldwide in under 15 minutes at just 376 bytes-small enough to fit in a single UDP packet.
Modern mobile operating systems represent the greatest information security improvement in everyday life over the past 15 years. The iPhone, launched in 2007, has never experienced a widespread malware epidemic-an extraordinary achievement by Apple. This superior security stems from the more restricted nature of mobile operating systems compared to desktop environments.
Глава 4
The Ransomware Revolution
Ransomware trojans represent an evolution in cybercrime: rather than stealing valuable data to sell to third parties, criminals now sell it back to its original owners. This threatens both companies and home users, though companies typically have some form of backup protection.
Surprisingly, ransomware dates back to 1989, when the PC Cyborg Corporation mailed thousands of floppy disks labeled "AIDS Information Introductory Diskette Version 2.0" to addresses gathered from PC Business World magazine subscribers. The disks contained a trojan that encrypted the computer's file system after a certain period of use, then demanded a $189 "software license fee" payable to Panama to unlock the computer.
After a 15-year gap, ransomware returned in 2005 with GPcode, which locked user data and sold decryption keys. By 2013, Cryptolocker revolutionized ransomware by demanding payment in either MoneyPak cash cards or bitcoin. With bitcoin valued at $125 in September 2013, victims often chose the cryptocurrency option, allowing the group to collect over 40,000 bitcoin while hiding the money's origins.
Ransomware operators understood that reputation was crucial to their business model. Most groups actually restored encrypted files after payment to maintain credibility, even providing customer support services to help victims recover their data. Some innovated with alternative payment methods-like Popcorn ransomware, which offered victims free decryption if they infected two friends who subsequently paid the ransom.
This reputation system suffered a major blow in 2017 when two massive ransomware attacks-Notpetya and Wannacry-spread internationally without restoring files even after payment. Notpetya marked a critical shift-it was a state-sponsored cyberweapon disguised as ransomware, deployed by Russia's GRU military intelligence against Ukraine. Unlike typical ransomware, paying the ransom did not restore data-destruction was its only purpose.
When Notpetya hit Danish logistics giant Maersk, it paralyzed over 70 port terminals worldwide. Container gates stopped opening, truck queues formed, phones went dead, and websites displayed error messages as the malware encrypted data across Maersk's global network. The attack revealed a critical vulnerability: all 151 of Maersk's Active Directory domain controller servers had been destroyed simultaneously, with no backups available. Salvation came from an unexpected source-a power outage in Lagos, Nigeria had coincidentally taken one server offline during the attack, allowing network reconstruction to begin.
By 2019, ransomware attacks evolved into targeted operations where criminal gangs carefully select victims, penetrate networks, and spend days or weeks gaining maximum access before encrypting files. These attacks demand significantly higher ransoms, often in the millions. When the COVID-19 pandemic began, Hypponen publicly asked ransomware gangs to avoid hospitals, and five groups agreed to this request.
In 2020, the Maze group pioneered a new tactic against companies-publicly listing victims and leaking stolen data when ransoms weren't paid. This "double extortion" strategy works even against companies with good backups, as they can't prevent data leaks. The tactic proved so effective that groups like DarkSide, Ryuk, Conti, and CL0P quickly adopted it, making it the new norm.
Глава 5
The Human Element in Security
All security problems can be divided into two categories: technical problems or human errors. While technical issues may be difficult and expensive to fix, they are at least fixable. Human errors, however, are practically impossible to solve completely.
People consistently use the same password across services, open remote connections when scammers request it, download shady utilities, use administrator credentials unnecessarily, open suspicious email attachments, enable content in suspicious documents, and fall for phishing attacks. Training rarely solves these problems completely.
CEO fraud (also known as Business Email Compromise or BEC) involves criminals impersonating executives to trick employees into transferring funds. Unlike simple fake invoices from the 1980s, modern BEC attacks are sophisticated operations that can target even security-conscious organizations. Attackers research potential victims through LinkedIn and job postings, then pose as executives to pressure finance staff into making urgent payments.
When CEO fraud cases make headlines, public reaction often mocks victims for their perceived stupidity. This attitude is wrong-modern BEC fraud can be extremely sophisticated, involving multiple attackers over weeks or months. Even tech giants Google and Facebook lost millions to Lithuanian fraudster Evaldas Rimasauskas, who created companies with identical names to their legitimate partners.
Every Fortune 500 company is currently experiencing some form of network breach. With networks containing over 100,000 workstations globally, vulnerabilities are inevitable. The traditional approach of building impenetrable network walls is insufficient-organizations must also monitor internal traffic.
Profiling has become the most effective technique for monitoring internal networks. By installing passive sensors throughout the network, security teams establish a baseline of normal traffic patterns, allowing them to identify anomalies. Machine learning can flag suspicious activities, like devices that never previously communicated suddenly exchanging data.
Honeypots and canary tokens serve as effective bait for detecting network intruders. Honeypots are deliberately unprotected computers filled with seemingly valuable information, while canary tokens are traps that trigger alerts when accessed. Creating attractive but fake document paths like "\\srvplatform5\documents\LT-team\Q4\mergeroffer_v7.xlsx" can help identify unauthorized network exploration.
Traditional divisions between internal and external networks are blurring as companies increasingly adopt cloud services. After Chinese spies breached Google's network in 2010, the company developed the BeyondCorp model-their version of a zero-trust network. This approach eliminates the distinction between external and internal networks, making resources available regardless of location. While implementing zero-trust architecture takes years, Google has reported no successful hacks since adopting this model.
Глава 6
The Privacy Paradox
Privacy is dead, having died on our watch. Most online content is funded by mechanisms that profile users and sell that data to advertisers. The Internet is controlled by a handful of corporations who prioritize profit over individual privacy concerns. We have become the merchandise.
We now spend half our lives online, with younger generations living even more digitally. We tell Google our deepest secrets-things we wouldn't dare tell anyone else-voluntarily sending this information to a company that sells it to advertisers. Despite attempting to live without Google, Hypponen failed. While replacing search was easy, avoiding Google's ubiquitous ads, analytics, YouTube, maps and office applications proved impossible.
Online advertising follows us everywhere because it's a massive business. Unlike traditional advertising, digital publishers know exactly which articles you read, how long you spent on each page, and even your physiological responses if you wear a smart watch. Google, while often thought of as a search engine, is actually the world's largest advertising agency.
Silicon Valley giants have fundamentally different business models regarding privacy. Facebook and Google investigate our lives and social relationships to sell to advertisers. Meanwhile, Apple sells premium-priced hardware without needing to monetize user data, leveraging this privacy advantage in marketing. Mobile payments illustrate this difference: Android collects purchase data while iPhone deliberately avoids storing it outside users' devices, despite its value to advertisers and insurance companies.
For the first time in history, technology allows tracking individuals from cradle to grave. Instead of developing micropayment systems for online services, the internet evolved to use personal data as currency. Privacy died because killing it proved immensely profitable.
While encryption has improved, making direct spying harder, metadata remains revealing-showing patterns like late-night visits to colleagues or consultations with divorce attorneys without revealing the content. As CIA Director Michael Hayden bluntly stated in 2014: "We kill people based on metadata."
Email has consolidated around two main systems: Outlook for work and Gmail for personal use. Gmail revolutionized email in 2004 by offering 1GB of storage when competitors provided just 2MB, making the concept of deleting emails obsolete. Gmail now handles one-third of global email traffic, creating two problems: running independent email servers has become nearly impossible as they're flagged as spam, and Gmail has become a central login hub for the entire internet.
Глава 7
The Cryptocurrency Revolution
Money is transforming into data, revolutionizing trade. Bitcoin and other cryptocurrencies represent both wonderful opportunities and problematic challenges, much like the Internet itself. While virtual currencies have no intrinsic value, traditional currencies like dollars and euros are also no longer backed by gold. The fundamental difference is that bitcoin is based on mathematics rather than government regulation, creating a fully decentralized currency system.
Virtual currencies have been under development for decades, with early attempts like DigiCash's eCash in the mid-1990s facing technological issues and opposition from traditional financial institutions. Modern currencies like dollars have no intrinsic value either-a $100 bill has value only because we collectively agree it does.
Blockchains are deceptively simple yet revolutionary-essentially an unmodifiable, public list of transactions. Each new transaction added can never be changed or deleted, with all entries remaining permanently public. The system uses complex cryptography to lock data in nested blocks, with each new block verifying all previous blocks.
Blockchains excel at tracking financial transactions between untrusting parties since the information cannot be altered or deleted. They solve two fundamental problems of digital money: securing transfers (preventing double-spending) and creating new currency. Bitcoin ingeniously combines these challenges by having network users verify transactions through complex calculations requiring vast computing power.
Bitcoin's value has evolved dramatically from worthlessness at creation to tens of thousands of dollars per coin. Early transactions set important precedents-Martti Malmi selling 5,050 bitcoins for just $5 in 2009 established exchange with traditional currencies, while Laszlo Hanyecz's infamous purchase of two pizzas for 10,000 bitcoins demonstrated practical use.
Unlike bitcoin's pseudonymous transactions, Monero and Zcash take privacy to extremes with encrypted blockchains that make transaction tracking nearly impossible. Meanwhile, DeFi (decentralized finance) aims to create a banking-independent financial sector.
NFTs solve the paradox of digital originality by using blockchains to establish authentic digital originals in a world where perfect copies are trivial to create. Like a Picasso in a museum versus a printed copy, NFTs create scarcity and authenticity for digital assets that can be freely copied but not authentically owned.
Criminals prefer bitcoin for online transactions for the same reason they prefer cash in the physical world: anonymity. Bitcoin's irreversible transactions are a deliberate design feature that prevents PayPal-style scams but also makes theft permanent. This makes cryptocurrency exchanges prime targets-they're often startups managing enormous assets with minimal security experience.
Глава 8
Cyberweapons and Digital Warfare
The digital transformation has fundamentally altered espionage and warfare. Information that once existed physically on paper now lives virtually in networks, allowing remote access to massive data volumes that would previously require trucks to transport. As one Finnish intelligence officer corrected Hypponen, espionage hasn't moved to the internet-it has expanded into it, with traditional spycraft continuing alongside digital methods.
Throughout history, technological advances have expanded warfare into new domains-from land to sea with warships, to air with planes, to space with satellites, and now to cyberspace with digital weapons. Rather than replacing previous forms of conflict, each new domain adds another dimension to warfare.
Cyberweapons offer unique advantages: they're effective (with destructive potential comparable to physical attacks), affordable (Stuxnet likely cost around $20 million-less than a single B-52 bombing mission), and provide plausible deniability that traditional weapons cannot.
False flag operations in cyberspace involve making attacks appear to come from another country. At F-Secure's laboratory, researchers initially identified Chinese-orchestrated malware attacks targeting Western companies starting in 2003. However, in 2005, they discovered a Russian attack deliberately designed to appear Chinese-with Beijing time zone timestamps and Mandarin-saved documents.
Many state-sponsored cyberattacks go undetected for years. The American malware "Flame" operated for at least two years before discovery, using an unusual approach-rather than being small and encrypted like typical malware, it was massive, visible, and resembled business software, effectively hiding in plain sight.
Unlike nuclear weapons, which have clear deterrent value because countries openly demonstrate their capabilities, cyberweapons offer minimal deterrence since nations' cyber capabilities remain largely unknown. While we have some knowledge about American, Chinese, Russian, Iranian, and North Korean cyber operations, most countries' capabilities remain mysterious-creating what Hypponen calls the "fog of cyberwar."
On December 23, 2015, Russian attackers launched a sophisticated cyberattack against Ukrainian power company Prykarpattyaoblenergo. After months of reconnaissance through phishing emails, the attackers seized control of critical workstations, disabled employee keyboards and mice, and systematically disconnected sections of the electrical grid, eventually cutting power to 230,000 Ukrainians.
Stuxnet marked a watershed moment in cyber warfare-so significant that security experts divide history into pre- and post-Stuxnet eras. This Windows worm spread via USB drives and network shares, specifically targeting Siemens Simatic factory systems. Once inside, it modified commands sent to Programmable Logic Controllers (PLCs), searching for specific high-frequency converter drives used in uranium enrichment centrifuges.
Stuxnet's sophistication was unprecedented-it exploited five vulnerabilities (four being zero-days worth $50,000-$500,000 each), used stolen digital certificates to sign its drivers, and remained undetected for a year after its 2009 deployment. Its complexity, size (over 1.5MB), and estimated development cost (over 10 person-years) pointed to nation-state origins rather than terrorist or criminal groups.
Глава 9
The Future of Technology and Security
The next technological revolution approaches, driven by machine learning, artificial intelligence, and revolutionary changes in money systems. Yet these advances merely precede even more profound transformations that currently sound like science fiction.
I believe genuine artificial intelligence will soon emerge-machines surpassing humans in every respect, making us the second most intelligent creatures on Earth. One path might be simulating the entire human brain by modeling each nerve cell and synapse. Such a simulation would produce an entity that writes poetry, experiences emotions, dreams, craves freedom, and even seeks love.
AI capable of self-improvement presents another fascinating possibility. Being code itself, it could examine and enhance its own operation, creating ever-better versions until its functioning becomes incomprehensible to humans. With sufficient resources, we could simulate billions of human brains, creating intelligence surpassing all of humanity combined.
Creating supreme intelligence might be an evolutionary mistake. If we become second-most intelligent, our existence could be threatened. The notion we could simply switch off problematic AI is naive-truly superior intelligence would anticipate such moves and ensure its survival in ways we cannot imagine.
AI will inevitably make many of us jobless, sometimes in unexpected ways. In some logistics companies, AI hasn't replaced human pickers but has become their boss, giving instructions through earphones and optimizing operations better than humans could. When steam power emerged in the 18th century, physical laborers lost their jobs as demand for brute strength declined. Similarly, tomorrow's programmers, composers, and poets will curse AI for taking their jobs as machines learn to write better, wittier, and more touching content for less money.
Virtual reality has evolved dramatically since the 1983 Vectrex 3D Imager. Modern VR creates credible immersion, but the real revolution may not be about virtual avatars at all. Some programmers already wear VR headsets for extended periods, using them to create virtual workspaces with multiple screens that can be resized or repositioned instantly. As resolution improves, virtual displays will become crystal-clear, potentially superior to physical screens. Soon, many people may spend most of their waking hours in VR, returning to reality mainly to sleep.
Philip K. Dick's concept of "precrime"-arresting people before they commit crimes-is becoming technologically feasible. AI could analyze data to identify potential criminals, detecting when someone has both motive and opportunity and begins preparations. While this could prevent crimes, it raises serious ethical concerns. Law enforcement already uses big data to predict criminal activity, but these systems often exhibit algorithmic racism, disproportionately flagging minorities as potential criminals.
Companies that identify changes and adapt to them will succeed. While digitalization hurt traditional media, it created opportunities for others-like paper mills converting to produce cardboard for e-commerce shipping. Companies likely to thrive include Amazon, Google, Apple, Nvidia, Samsung, TSMC, Xiaomi, Tesla, and SpaceX.
Despite spending his career addressing the Internet's negative aspects, Hypponen remains optimistic about its overall positive impact. As a Norwegian polar explorer once told him about climate change: it's too late to be pessimistic. The Internet has transformed from fascinating novelty to everyday mundanity, yet he loves it and eagerly awaits its next revolution.