Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Monday, June 03, 2019

Bitcoin-Enabled Ransomware Attack Strikes Baltimore


Last month, the city of Baltimore became the latest target of a ransomware attack.  The city's Microsoft operating systems were held hostage by a group that demanded 13 bitcoins, which at the present rate of exchange is about $100,000.  Despite their inability to repair all the damage after nearly a month, Baltimore administrators refuse to pay the ransom, and instead have asked the federal government for help.  According to some sources, the malware used for the attack was developed at the U. S. government's National Security Agency (NSA), and somehow it leaked and was posted by a group of hackers in 2017. 

Irony is usually found more in literature than in engineering, but this incident is particularly rich in them. 

The first irony is that a cyberweapon presumably developed to be used by the United States against its enemies was stolen, published worldwide, and used instead to attack the infrastructure of a major U. S. city. 

The second irony is that an idea traceable back to 1991, a chain of blocks developed originally just to prevent software timestamps from being tampered with, has turned into a means by which ransoms can be paid with no realistic hope of tracing where the money goes. 

And the third irony is that some eyebrows are being raised by the fact that the city of Baltimore is asking for help from the federal government. 

Let's do a little thought experiment and set the essential ingredients of this incident in an alternate universe which is just like ours, except there's no computer networks and so on.  Suppose a gang of paratroopers landed in Baltimore and made their way to the city offices, holding employees at gunpoint while they absconded with tons of files and records in a heavily armored vehicle.  Then the mayor received a ransom note demanding $100,000 for the return of the records.  Not only would a nationwide manhunt be mounted for these criminals, but the FBI and other federal agencies would get involved as a matter of course. 

But simply because the records and functions involved are on computers and not physical documents, attitudes and actions are vastly different here.  Now, admittedly some blame can be attached to those responsible for running Baltimore's IT systems.  Microsoft evidently does a fairly good job of sending out patches and updates in response to new viruses and malware, but these patches have to be implemented in a systematic and organized way.  And in the case of Baltimore's systems, this was not done.  In the world of our thought experiment, this amounts to not having enough armed guards surrounding your municipal buildings to fight off the attackers. 
While a certain amount of security is to be expected, nobody wants to have to do the equivalent of breaking into Ft. Knox in order to pay your city water bill. 

While I am not usually in favor of greater centralization of power and resources, in this case I think it is only fair for the federal government to help out Baltimore in their hour of need.  For one thing, the NSA never should have let its malware escape in the first place.  It would seem to be a fairly straightforward investigation to discover who was responsible.  But the NSA's workings are deliberately opaque and poorly supervised even by Congress, who pays the bills, and that sort of setup is an open invitation to laxity and inefficiency.  Perhaps this leak represents only 0.001% of everything that NSA has developed, most of which is still secret.  But in situations like this, even one leak can be too many.

As for bitcoins being used for ransomware payment, it makes a certain amount of perverse sense that a form of currency inspired by hyper-libertarianism is used mainly for two things nowadays:  speculation and illegal transactions.  It is an ill wind that blows nobody good, and bitcoins have benefited some people.  I may have mentioned a student of mine who managed to buy some bitcoins only a few years after they came out in 2009.  I don't know exactly what she paid, but by the time she graduated I think she had been able to pay for her entire college education with her profit in bitcoins. 

But is this advantage worth the social cost of having a virtually foolproof way of laundering money?  I leave that for the reader to decide.  It doesn't matter now, because bitcoins and their offspring are a permanent part of the cyberlandscape now. 

Perhaps the most troubling aspect of the Baltimore situation is the complete anonymity of the attackers, who could be, and probably are, anywhere in the world outside of the United States.  Prior to the Internet, the most significant threat the U. S. endured from outside its borders was the threat of intercontinental ballistic missiles carrying nuclear warheads, and billions of dollars were spent in an arms race that is in some ways still with us.  But now that anyone with sufficient skills can mount attacks on specific geographic entities in the heartland of the U. S. from halfway around the world, we still act as though it's just some sort of defect in a strictly local pile of computer networks, and treat the attackers much like an act of God—something that's always going to happen sooner or later, so you might as well just buy insurance and be ready when it happens.

Maybe that's the best approach.  Baltimore, as it turns out, did not have cyberinsurance, but the bond underwriters will soon see to that  So in the future we will go armed not with guards, but with insurance policies to buy experts who come in and fix our computer systems, just like roofers replaced my roof after a recent hailstorm this spring.  Complexity begets complexity, and if Baltimore and other cities consistently refuse to pay ransomware demands, perhaps the criminals will devise some other way to make ill-gotten gains.  I can hardly wait to see what they'll do next.  (That's irony, by the way.)

Sources:  I referred to articles at https://phys.org/news/2019-05-baltimore-ransom-cyberattack.html and the website Governing.com at https://www.governing.com/topics/public-justice-safety/gov-cyber-attack-security-ransomware-baltimore-bitcoin.html, as well as the Wikipedia articles "blockchain" and "bitcoin." 

Monday, November 16, 2015

Rolling Back Mass Surveillance


Bruce Schneier is a man worth listening to.  In 1993, just as the Internet was gaining speed, he wrote one of the earliest books on applying cryptography to network communications, and has since become a well-known security specialist and author of about a dozen books on Internet security and related matters.  So when someone like Schneier says we're in big trouble and we need to do something fast to keep it from getting worse, we should at least pay attention.

The trouble is mass surveillance.  In his latest book, Data and Goliath, he explains that mass surveillance is the practice of indiscriminately collecting giant data banks of information on people first, and then deciding what you can do with it.  One of the best-known and most controversial examples of this is the practice of the U. S. National Security Agency (NSA) of grabbing telecommunications metadata (basically, who called whom when) covering the entire U. S., which was revealed when Edward Snowden made his stolen NSA files public in 2013.  Advocates of the NSA defend the call database by saying the content of the calls is not monitored, only the fact that they were made.  But Schneier makes short work of that argument in a few well-chosen examples showing that such metadata can easily reveal extremely private facts about a person:  medical conditions or sexual orientation, for example. 

It's not only government overreaching that Schneier is concerned about. Businesses come in for criticism too.  With data storage getting cheaper all the time, many Internet firms and network giants such as Google and Yahoo find that it's easier simply to collect all the data they can on their customers, and then pick through it to see what useful information they can extract—or sell to others.  This happens all the time.  Maybe the most visible evidence of it happens when you go online and look for, say, a barbecue grill at a hardware-store website.  Then, maybe several days later, you will be on a completely different site.  Say a vegetarian friend is coming over and you're looking up how to make vegan stew.  Lo and behold, right next to the vegan recipe, there's an ad for that barbecue grill you were looking at a few days ago.  How did they know?  With "cookies" (bits of data retained by your browser) and behind-the-scenes trading of information about you and your browsing habits.

But Schneier reserves his greatest concern for something that is perhaps hardest to define:  the loss of privacy.  The right to privacy is a vital if poorly defined right whose absence makes normal life almost impossible.  Schneier says, "Privacy is an inherent human right. . . . It is about choice, and having the power to control how you present yourself to the world."  Mass surveillance tramples over the right to privacy and trains millions subtly to alter their ways of living to avoid the pain of secrets revealed.  This way of living was familiar to those whose lives were monitored by totalitarian regimes such as the old East Germany or the Soviet Union.  True, Google isn't going to send a jackbooted corporal to your door if you say something nasty about Sergey Brin, Google's co-founder.  Brin himself was born behind the Iron Curtain, though his family emigrated when he was six, and he probably remembers little or nothing about the USSR.  Nevertheless, Google and other firms that collect massive amounts of private data from their customers have set up a situation in which the privacy rights of millions, even billions, depend solely on the good intentions of a few powerful decision-makers in private companies. 

So what do we do about this?  Schneier has lots of suggestions, and points to Europe as a place where privacy is more respected in law and custom.  Changing laws is a necessary first step.  Whenever anyone moves to restrict the mass-surveillance habits of government entities such as the NSA or the Federal Bureau of Investigation, their defenders threaten us with a terrorist apocalypse, saying if we don't give up this or that privacy right, we'll tie the government's hands and be helpless before terrorist assaults.  Schneier spends a lot of time taking apart this argument, to my mind pretty convincingly.  For one thing, mass-surveillance data has not proved that useful in uncovering terrorist plots, compared to old-fashioned detective work focused intensely on a few known troublemakers. In general, government should abandon most mass-surveillance practices in favor of concentrating on specific investigations, with permission granted by courts whose workings are made public to the extent possible.

As for massive snooping by private enterprises, Schneier thinks regulations are the best option.  These regulations would impose a kind of "opt-in" system.  Currently, if you have a privacy-related choice at all in dealing with Internet firms, you have to go to a lot of trouble to make them respect your privacy, if they will allow such a thing at all.  Under Schneier's proposed policy, companies could not take away your rights to your data without your explicit permission, and the choice would be explained clearly enough so that you wouldn't need to have your techno-lawyer read the fine print to understand what's going on. 

Neither Schneier nor I are political scientists, so it's hard to say how we would get from the current parlous situation to one in which online privacy is respected, and nobody can snoop on you unless they go to a lot of trouble and get special permission to do it.  But he's told us what the problem is, and now it's up to us to do something about it.

Sources:  Bruce Schneier's book Data and Goliath:  The Hidden Battles to Collect Your Data and Control Your World was published by W. W. Norton in 2015.  The quotation from it above is from p. 126.  I also referred to Wikipedia articles on Edward Snowden, MAINWAY (the NSA call databse), and Sergey Brin.

Monday, February 02, 2015

Who Wazed the Sheriff?—Traffic Apps and Law Enforcement


Google's traffic app called Waze allows users to tell each other about traffic-related issues such as construction zones, tie-ups, and speed traps.  It uses a phone's GPS system to locate an icon on a map of the area that everyone using Waze can see.  Google bought Waze from its Israeli developers for a billion dollars in 2013, and it is now one of the most popular free apps on Apple's rankings.  But the National Sheriffs' Association (NSA) is not happy about it.

In a widely publicized statement, the NSA's Deputy Executive Director John Thompson said "we are . . . concerned this app will have a negative effect on saving lives and with public safety activities."  The app's little police icons can show locations of speed traps and other law-enforcement operations.  The sheriffs cite recent ambush attacks on law enforcement, such as the killing of New York City patrolmen Rafael Ramos and Wenjian Liu last December, as examples of hostile actions that could be aided by Waze.

An Associated Press report of the reactions to the NSA statement includes a response by a Google spokesperson, who pointed out that most users tend to drive more carefully when they believe law enforcement is nearby.  Free-speech advocates oppose any restrictions on locating law-enforcement operations via Waze as long as the operations are clearly visible on public property. 

Traffic-law enforcers face a problem that is in some ways paradoxical.  Sometimes they want to be highly visible simply because of the deterrent effect on most law-abiding citizens.  After all, the overarching goal of law enforcement is to encourage obedience to the law.  This goal would be achieved with respect to speed laws if everyone obeyed the speed limits.  And most drivers (but not all) who become aware of a potential speed trap will slow down.  So letting folks know that Smokey is hiding over that next ridge on the interstate will probably lead to fewer speeders, which is what we want, isn't it?  That doesn't take into account the other aspect of the paradox, which is that sometimes traffic cops want to hide, too.

I think it may be significant that the National Sheriffs' Association, but no other major law-enforcement organization, has come out in opposition to Waze.  In small towns in rural areas, and in larger Western counties where the main law enforcement is by sheriffs and not town or city policemen, a considerable fraction of the sheriff's office revenue may come from speeding tickets.  If a deputy has found a nice concealed location where drivers who are just passing through frequently get ticketed for speeding, the last thing he or she wants is for this prize fishing hole to show up on Waze.  Local circumstances such as these can create perverse incentives which encourage law enforcers to rely on a certain number of speeders to show up, just to keep them in business. 

The problem of publicizing law-enforcement operations and locations should not simply be brushed off.  You can imagine a months-long sting operation by police that would climax in a stealthy approach to a crime organization's secret hideout.  But if some clueless driver comes along and posts a lot of cop icons on Waze, and one of the crooks happens to be looking at his phone at the time, the whole operation could come unglued, with dire consequences up to and including bloodshed.

Back in the slow-media days when newspapers were the main forum of public information about law enforcement, reporters would sometimes get wind of secret police operations in advance.  It was a part of the journalistic code of ethics not to spill such beans when it would cause major problems to the police, even though it would make a scoop that would sell papers.  Editors have sat on such hot news many times until after the police have had time to spring their traps.  While such measures could have been viewed as press self-censorship, most observers would agree that it was done in the public's best interest in most cases.  The public's right to know is not absolute, and must be tempered by other considerations such as the safety of law-enforcement officials when publicity would put their lives at risk.

But this is 2015, not 1935, and the age of citizen-journalists.  Instead of fedora-wearing photographers armed with big Graflex cameras, we have baseball-capped passersby armed with iPhones linked to Facebook and Waze.  We can no longer count on the reasoned restraint of professional journalists who can view the larger picture and weigh the consequences of their actions in the long run.  If a Waze user sees a cop and posts the sighting on Waze, the user has no idea whether the cop is there for a routine speed trap or for more specialized and delicate reasons. 

So far, there have been no major incidents to my knowledge in which Waze data on law enforcement personnel locations has led to a major miscarriage of justice or harm to an officer.  But in the present atmosphere of tension between police and many citizens, I can understand why the National Sheriffs Association is touchy about the popularity of Waze, and why they have asked Google to do something about it.

Unfortunately for the NSA, chances are not good for that to happen.  While Google could conceivably run interference between the raw data coming from observers and the displays of police icons, it would be a resource-intensive and probably manual process, which would slow down the edited displays and diminish what is one of the main attractions of Waze in the first place:  its timeliness.  Public-access apps that let the public post information directly depend on that same public not to lie or manipulate their inputs in a nefarious way.  Fortunately for law enforcement, and everybody else, most people at most times are simply trying to get along and help others when it's not too much trouble.  Waze helps them do that, and it looks like the speeding-deterrent effects of posting speed-trap locations will outweigh the possible negative consequences, at least in Google's view.  And in this case, unless some more powerful force intervenes, it's Google's view that counts.

Sources:  The Associated Press article by Eileen Sullivan describing reactions to the National Sheriffs' Association press release was carried by numerous outlets such as the Chicago Tribune at http://www.chicagotribune.com/business/sns-bc-us--police-tracking-app-20150128-story.html.  The NSA statement itself can be found at http://www.sheriffs.org/content/waze-concerns-sheriffs.  I also referred to Wikipedia's article on Waze. 

Monday, August 12, 2013

Cybercrime: Prevention or Punishment?


Last week I needed an item at a Harbor Freight store in Austin.  Harbor Freight deals in low- to mid-priced tools imported from China, and unless you’re looking for something that will last for decades, it’s a good place to shop.  As soon as I walked in the door, one of the cash-register attendants came up to me and said, “Just to let you know, our registers are down and all we’re taking is cash right now.”  I’m one of those troglodytes (look it up) who prefers cash anyway, so this didn’t bother me other than the fact that I had to wait in a long line that was backed up because the sales clerk had to look up each item’s SKU on a handheld unit, write down the price by hand, add up the total on a calculator, and make change. When I paid for my item, the clerk asked me if I minded not getting a receipt.  I replied, “Not as long as somebody doesn’t stop me at the door for shoplifting.” 

While I was waiting in line, I saw posted next to the register a notice from Eric Smidt, Harbor Freight’s president.  It was about a recent incident of hacking that resulted in the theft of a large number of their customers’ credit-card numbers, and said that the firm was taking every possible step to deal with the problem.  Whether this issue had anything to do with their registers going down that day is unclear, but it got me to thinking about the differences between old-fashioned analog theft and cybercrime.

Now if dozens of Harbor Freight customers had been koshed on the heads as they left the stores and had their wallets taken, I bet you would have heard about it in the news.  Old-fashioned personalized one-on-one crime like that is much more likely to be reported by the injured individual, and because the criminals tend to be local, the local jurisdiction responsible has a fairly straightforward job on its hands, once the crook is identified.  But those responsible for the Harbor Freight data breach could be literally anywhere in the world that there is an Internet connection, which means just about anywhere in the world. 

Cybercrime is a lot less risky.  According to online reports, the Harbor Freight breach may have been one of 2013’s largest in terms of numbers stolen, comparable to a similar attack that netted about 2.4 million customer debit and credit card numbers.  The company found out about the attack in June, when credit-card firms began noticing a lot of fraudulent charges to accounts owned by Harbor Freight customers.  Apparently the hackers penetrated the company’s main network and gained access to data from all 400 of its retail stores.

There are several ways the criminals can profit from their ill-gotten numbers.  The retail way is to use the cards themselves to buy stuff they want.  My own credit-card number was stolen this way once, and in the list of charges that my bank seriously doubted I’d made were things like services at an upstate New York spa and jewelry charged to a Las Vegas store.  But the big money is in the wholesale underground exchange of hard cash for hot credit-card lists, and I suspect that is what the Harbor Freight crooks did with their numbers.

Because it’s so hard to catch and convict cyber criminals, most companies rely instead on anti-virus software, firewalls, and other protective measures rather than spending a lot of effort in working with law enforcement personnel to catch the perpetrators.  But a recent study by a group of researchers based in Cambridge, England points out that this may not be the most cost-effective approach. 

The study shows that the amount of money lost per person to number theivery such as occurred with the Harbor Freight customers is in the range of a few dollars per customer per year.  On the other hand, the money spent by firms on computer security measures may exceed what is lost to this type of cybercrime.  The authors say it might be cheaper overall to spend more money on tracking down the relatively small number of cyber criminals, and less on security measures.

That is good advice as far as it goes, but it neglects the hard problem of jurisdictional diversity, as you might call it.  Say you can locate the Harbor Freight perpetrators, and they turn out to live in a country that has a dysfunctional government that can’t enforce ordinary laws, let alone laws about cybercrime.  Short of mounting an armed invasion of the country to catch the crooks, a private firm or even another sovereign country has its hands tied.  Unless some effective international agreements could be made for the extradition of cyber criminals, and some uniform laws passed in every host country that makes the same actions illegal everywhere, it will continue to be very hard to punish those who steal data across international boundaries.  Look at the trouble the U. S. government has had with Eric Snowden, who committed a data breach of NSA information right here in the U. S. and then ran off with it to Russia, which has recently granted him asylum.  Once international relations and antagonisms get mixed into a criminal act, things get vastly more complicated.

Overall, we benefit greatly from the worldwide coverage of the Internet for both global commerce and less quantifiable benefits such as the freedom to communicate political and cultural ideas across boundaries.  These benefits come at a cost, however, and it looks like unless the international jurisdiction problem can be addressed more effectively than it has been in the past, we will have international cybercrime with us for the foreseeable future.  And despite Eric Smidt’s assurances, which I’m sure are sincere, the next time I go to Harbor Freight I think I’ll bring cash along.  But I think I’ll ask for a receipt.

Sources:  A report on the Harbor Freight data breach can be found at the Bank Info Security website at http://www.bankinfosecurity.com/impact-harbor-freight-attack-grows-a-5970/op-1.  The Cambridge cybercrime report is discussed at gcn.com/Articles/2012/06/18/Cost-of-cybercrime-Cambridge-study.aspx.  And the difficulties of prosecuting crimes in different jurisdictions are described well by Deb Shinder at http://www.techrepublic.com/blog/it-security/what-makes-cybercrime-laws-so-difficult-to-enforce/.