A computer virus that targets the popular file-sharing program Winny isn't the most destructive bug or even the most widespread. But it's the most talked about in Japan as it generates headline after headline, month after month.
The malware, called "Antinny," finds random files on Winny users' PCs and makes them available on the file-sharing network. So far, the data leaked have been varied and plentiful: passwords for restricted areas at airports, police investigations, customer information, sales reports, staff lists.
The constantly updated virus seems to have spared no one -- airlines, local police forces, mobile phone companies, the National Defense Agency. Even an antivirus software manufacturer has suffered.
PHOTO: AP
"The virus has been quite effective in getting information off a user's computer and onto the Internet. The data is supposed to be secret, so people are quite sensitive about it," said Tsukuba University computer scientist Kazuhiko Kato.
Compared to attacks on Microsoft Corp's Windows software, the scope of the Antinny outbreak is narrow. But the Winny mess has caused an enormous brouhaha in Japan.
Antinny also may have the dubious distinction of being the first virus to exploit the nature of file-sharing itself -- in Japan, if not in the world, said Mamoru Saito of Telecom Information Sharing and Analysis Center (ISAC) Japan. Other viruses and spyware are often found on such networks, though none appears to take advantage of the underlying technology to spread personal data.
And while Antinny's writers seem to be limiting themselves to Japanese file-sharing software for now, he said, the code theoretically could be modified to attack other file-sharing networks such as Gnutella and BitTorrent.
The outbreak has triggered a broad damage-control effort by government and businesses. They have banned Winny from in-house computers and fired employees who use it on them. They've also demanded that staff not take work home and delete Winny from any home PCs used for work.
"The most secure way to prevent the leakage of information is not to use Winny on your computer," Chief Cabinet Secretary Shinzo Abe, the government's top spokesman, told reporters.
But the outbreak shows little sign of abating.
"The problem has shown that many people just don't know how to use the Internet safely," said Takeshi Sato of the government's National Information Security Center.
File-sharing programs like Winny are used to find and get files -- from music to video to documents -- from the computers of other people also using the software. The PC owner typically has control over what is made available by limiting sharing to a specific folder.
The virus takes advantage of this culture to propagate itself by playing a "social" trick on users, said ISAC Japan's Saito.
When the virus is activated on a computer, it first chooses a new name for itself by taking the names of other files users are likely to be searching for -- usually photos or music. The resulting new name becomes so long that, under normal Windows' settings, the three-letter file extension that indicates the type of file disappears from view, he said.
Careless users who download the file will see only the name and think it is something they wanted -- say, a photo of a favorite movie star. They don't see that they are actually trying to open an application.
When they do, the virus then looks on the computer for the Winny application, grabs random files off the hard drive and uses Winny to make those files -- and itself -- available for download on the network.
And so the cycle repeats.
New strains of Antinny appear all the time. Software maker Trend Micro listed 46 variations of the virus in its database as of mid-May. Trend itself lost sales data due to a Winny leak in 2005.
"Just keeping your antivirus software up to date isn't enough, because the updates can't keep up with all the new strains of the virus," the government's Sato said.
The government's concerns about Winny go beyond viruses. It's often used to share files -- and that often means illegally exchanging copyrighted materials.
Winny was already on the government's radar screen in November 2004, when a user of the program was handed a three-year suspended sentence on charges of violating copyright laws.
But now it is confidential data rather than hit songs that have Winny back in the spotlight.
Japan Airlines, for example, discovered last December that an Antinny-infected computer owned by one of its co-pilots leaked passwords for restricted areas at 16 airports around Japan as well as Guam's international airport. The airline was forced to alert the airports to have passwords changed as a precaution.
BUILDUP: US General Dan Caine said Chinese military maneuvers are not routine exercises, but instead are ‘rehearsals for a forced unification’ with Taiwan China poses an increasingly aggressive threat to the US and deterring Beijing is the Pentagon’s top regional priority amid its rapid military buildup and invasion drills near Taiwan, US Secretary of Defense Pete Hegseth said on Tuesday. “Our pacing threat is communist China,” Hegseth told the US House of Representatives Appropriations Subcommittee on Defense during an oversight hearing with US General Dan Caine, chairman of the Joint Chiefs of Staff. “Beijing is preparing for war in the Indo-Pacific as part of its broader strategy to dominate that region and then the world,” Hegseth said, adding that if it succeeds, it could derail
CHIP WAR: The new restrictions are expected to cut off China’s access to Taiwan’s technologies, materials and equipment essential to building AI semiconductors Taiwan has blacklisted Huawei Technologies Co (華為) and Semiconductor Manufacturing International Corp (SMIC, 中芯), dealing another major blow to the two companies spearheading China’s efforts to develop cutting-edge artificial intelligence (AI) chip technologies. The Ministry of Economic Affairs’ International Trade Administration has included Huawei, SMIC and several of their subsidiaries in an update of its so-called strategic high-tech commodities entity list, the latest version on its Web site showed on Saturday. It did not publicly announce the change. Other entities on the list include organizations such as the Taliban and al-Qaeda, as well as companies in China, Iran and elsewhere. Local companies need
CRITICISM: It is generally accepted that the Straits Forum is a CCP ‘united front’ platform, and anyone attending should maintain Taiwan’s dignity, the council said The Mainland Affairs Council (MAC) yesterday said it deeply regrets that former president Ma Ying-jeou (馬英九) echoed the Chinese Communist Party’s (CCP) “one China” principle and “united front” tactics by telling the Straits Forum that Taiwanese yearn for both sides of the Taiwan Strait to move toward “peace” and “integration.” The 17th annual Straits Forum yesterday opened in Xiamen, China, and while the Chinese Nationalist Party’s (KMT) local government heads were absent for the first time in 17 years, Ma attended the forum as “former KMT chairperson” and met with Chinese People’s Political Consultative Conference Chairman Wang Huning (王滬寧). Wang
CROSS-STRAIT: The MAC said it barred the Chinese officials from attending an event, because they failed to provide guarantees that Taiwan would be treated with respect The Mainland Affairs Council (MAC) on Friday night defended its decision to bar Chinese officials and tourism representatives from attending a tourism event in Taipei next month, citing the unsafe conditions for Taiwanese in China. The Taipei International Summer Travel Expo, organized by the Taiwan Tourism Exchange Association, is to run from July 18 to 21. China’s Taiwan Affairs Office spokeswoman Zhu Fenglian (朱鳳蓮) on Friday said that representatives from China’s travel industry were excluded from the expo. The Democratic Progressive Party government is obstructing cross-strait tourism exchange in a vain attempt to ignore the mainstream support for peaceful development