Showing posts with label U. S. military. Show all posts
Showing posts with label U. S. military. Show all posts

Monday, January 17, 2022

Ukraine Gets Cyberattacked Again

 

First, a little geography lesson.  Ukraine sits north of the Black Sea, bordering Poland, Hungary, and Romania on its west and surrounded by Russia to the north and east.  Like Poland, the Ukraine has been subjugated for much of its history by foreign powers—the old USSR for most of the twentieth century, and even by Lithuania back in the 1400's A. D.  But when the USSR collapsed, the Ukraine gained independence again.  It is the poorest country of Europe, but has rich farmlands, which is one reason why foreigners want to take it over.

 

If you've been paying any attention to world news, you know that Vladimir Putin has been saber-rattling about a possible invasion of Ukraine recently, massing 100,000 troops on the border between the two countries and ramping up his warlike rhetoric.  Russia has been chipping away at the country since at least 2014, when the pro-Russian President of Ukraine, Viktor Yanukovych, lost an election, and Putin invaded the Crimea, the peninsula that sticks out into the Black Sea and separates it from the Sea of Azov to its northeast.  Having succeeded in that, Putin has since been backing forces that have taken over portions of eastern Ukraine, and it appears that he would like nothing better than to welcome the entire country back to the domination of Russia.  So far, the government of Ukraine has had different ideas.

 

As part of Putin's campaign, a war that isn't quite a war, most authorities agree that Russian-based hackers mounted a cyberattack called NotPetya back in 2017.  It was aimed primarily at Ukranian institutions, but it also affected thousands of other systems as well.  The White House later estimated that NotPetya caused about $10 billion worth of damage worldwide. 

 

Now we come down to this week.  On Jan. 15, dozens of Ukrainian government computer systems were infected with malware disguised as ransomware.  An infected computer displayed a demand for a certain ransom to be paid in Bitcoin, but what really happened is that the malware "renders the computer system inoperable," ransom or no ransom. 

 

Microsoft issued a statement saying that they observed these attacks aimed primarily at Ukrainian government agencies and closely-allied organizations, and that they had issued updates that will address the problems.  But in the meantime, the Ukraine is suffering yet another cyberattack which appears to be instigated by Russia, although no firm evidence of the source has yet been forthcoming.

 

To my knowledge, nobody has actually died as a result of the most recent cyberattack on the Ukraine.  But to the extent that the public relies on computer-mediated government services, the consequences of a massive shutdown of government computers can range from the inconvenient to the life-threatening, in government-run hospitals, for example. 

 

In the logic of war, an enemy's assets are always a target, and now that computer networks and systems form so much of the infrastructure of modern life, they have become a uniquely vulnerable target.  Cyberattacks borrow from the fields of espionage, sabotage, and terrorism to create an insidious threat that knows no boundaries.  And defending against such attacks is a responsibility that is widely distributed among both public and private actors. 

 

All these features make cyberwarfare a different kind of thing from conventional warfare, and it is taking time for both military and civilian thinking to catch up to it. 

 

When this topic has come up in the past, I have taken the position that the U. S. military, in any event, seems to have an overly narrow focus on what cyberwarfare might amount to in the future.  While I am no technical expert in this area, I can see that even cyberattacks on U. S. organizations that have been definitely attributed to government-sponsored hackers in China or Russia do not seem to cause much concern on the part of our government, except to provoke warnings to private interests to do their cybersecurity better. 

 

That may make sense if you're a Boeing or a Kaiser Permanente, with entire staffs of IT security specialists.  But especially in the U. S., we have a great many small businesses whose functioning is nonetheless critical to our economy.  Many of them can't afford a full-time IT person, so IT maintenance is handled on an as-needed basis:  if something breaks, the owner hires somebody to fix it, but otherwise deals with things on his or her own. 

 

A supply-chain cyberattack similar to what was used against Ukraine could target a popular piece of software such as, for example, Quicken—something that almost all small businesses use.  With a few keystrokes, such an attack could cause devastation far beyond what we are presently seeing with the Omicron COVID-19 variant, which has done nothing worse than kill thousands of people and cause massive absenteeism, both involuntary due to sickness and voluntary due to vaccine mandates. 

 

The fact that nothing like that has happened in the U. S., with a few exceptions, may mean that the way we are doing things is just fine and we don't need to worry about a massive cyberattack that would bring the U. S. economy to its knees.  On the other hand, it may mean that whoever is capable of mounting such an attack is simply biding their time, awaiting the proper geopolitical moment when such an attack could be coordinated with more conventional warlike actions for maximum effect.  I hope it's the former, but I suspect it might be the latter.

 

What am I asking for?  Certainly not for every software app to be government-certified as secure.  At the university where I work, we have experienced a small-scale version of that type of thing, and all it has done so far is to create a lot of confusion and delays in purchasing needed software.  If there are government and military forces out there safeguarding not only their own systems, but those belonging to the public at large, I would at least like to know about it, in a general way.  And because my federal taxes are paying for it, I'd like to know what I'm getting for my money.

 

In the meantime, we can hope that the Ukrainian government has figured out how to defend itself and its citizens from what has to be the worst spate of cyberwarfare endured by any nation so far.  And maybe we can learn some lessons from them:  either good examples if they succeed, or bad examples if they lose and get absorbed into Russia. 

 

Sources:  I referred to the article "Microsoft discloses malware attack on Ukraine govt networks" which appeared on the AP News website on Jan. 15 at https://apnews.com/article/technology-business-europe-russia-ukraine-404c5e751709fba66b31fd512f734d80.  I also referred to a Microsoft blog at https://blogs.microsoft.com/on-the-issues/2022/01/15/mstic-malware-cyberattacks-ukraine-government/and Wikipedia articles on NotPetya, Ukraine, and the Crimea.

Monday, March 01, 2021

Friendly Jammers: The U. S. Military's Threat to Commercial Aviation

 

The Global Positioning System (GPS) that allows a few dollars' worth of electronics to determine your position within a few feet almost anywhere in the world has proved to be a great boon to aviation, which previously relied on an expensive and not that reliable network of ground-based technology for electronic navigation.  Newer aircraft use GPS as an essential part of their autopilot system, for example.  A report in the February 2021 issue of IEEE Spectrum shows that this happy situation is frequently being disrupted by the U. S. military in test exercises that use GPS jammers and spoofers, especially in the western United States.  Despite a formal requirement to warn pilots that such tests may be occurring, these tests have caused numerous problems to pilotes and even near-accidents over the last decade or so. 

 

In fairness to the military, GPS is their baby.  Deployed initially with a secret feature that degraded its accuracy for non-military users, it was designed primarily for combat uses, and commercial uses began as a kind of afterthought.  In 2000, this "selective availability" option ended, and now anybody, military or commercial, can get the highest accuracy possible out of the system.

 

Understandably, pilots and airframe makers have begun to rely on GPS almost exclusively for routine navigation.  The bad old days of shooting the stars with a sextant ended when various radiolocation technologies such as VOR (VHF omnidirectional range) were deployed after World War II, but in the last few years the Federal Aviation Administration (FAA) has been decommissioning those stations in preference to GPS.  And GPS works fine, except when it doesn't.

 

Because GPS is now an essential part of military operations, the U. S. military is now coming up with ways to deprive the enemy of it.  By the time satellite-transmitted GPS signals reach the ground, they are weak enough that suitable ground-based transmitters can either simply overwhelm them with interference (jamming) or worse, imitate them to deceive any GPS receivers in the vicinity (spoofing).  By law, any such military tests have to be announced to the aviation community through Notices to Airmen (NOTAM).  But these notices tend to be very broad, blanketing multiple states for days at a time, and most notices do not result in pilots experiencing any interference.  The net effect is that when GPS jamming happens, it tends to take pilots by surprise, and you don't want to startle a pilot when he's doing his job, or even when she's doing her job.

 

One of the worst such incidents happened in May of 2020 as a commercial airliner came in for an approach to El Paso International Airport in West Texas.  It was early morning, still dark, and that airport is surrounded by high mountains that pose threats to airplanes that are not where they're supposed to be.  Suddenly the pilot lost his GPS position, and rather than attempt to land blind, he declared a missed approach, went around, and landed on a different runway guided only by air-traffic control.  In a report he wrote about the incident, he remarked dryly that the runway he used "has a high CFIT threat due to the climbing terrain in the local area."  CFIT stands for Controlled Flight Into Terrain.

 

Investigation by Spectrum reporter Mark Harris revealed that such incidents are much more common than previously believed.  In one six-month period in 2017, for example, 96 GPS disruptions occurred in commercial aviation.  This led the FAA to ask the nonprofit Radio Technical Commission for Aeronautics (RTCA) to investigate the problem.

 

The RTCA's report recommends several things, but it's not clear that many of them have been implemented.  Better reporting of GPS failures due to military interference was one of them, and now the FAA wants pilots to report any such incident, not just if it required the intervention of air traffic control.  But many other recommendations, such as the military making more specific NOTAMs that describe exactly when and where the interference will happen, have apparently not been acted upon.

 

According to Harris, the situation is only going to get worse, as GPS manipulation becomes a more important feature of war games in military reservations, and as GPS becomes increasingly relied on as the main navigational technology used by airlines. 

 

This kind of situation is very familiar in engineering ethics, and can be characterized as the passed-out canary in the coal mine.  As you may know, in the days before technology was available to detect methane that could lead to an explosion, coal miners carried along canaries, whose respiratory systems are more sensitive than those of humans.  If the canary showed signs of distress, it meant there was enough gas to be dangerous, and the miners took steps to avoid igniting the gas, such as stepping outside of that part of the mine.

 

The near-misses and other distressing but so far harmless incidents that military GPS jamming and spoofing have caused are the kind of warnings that a responsive, on-the-ball organization will seize upon for appropriate preventative action.  Nobody wants people to die because an avoidable accident wasn't avoided. 

 

It's a matter of judgment as to how much effort should be expended to avoid it, but a good measure of that effort is to monitor the frequency of near-misses to see if remedial actions are making them less frequent.  If they are, the changes are doing their job.  But according to Harris, GPS failures are only increasing.  And as the aviation industry relies more exclusively on GPS for takeoffs and landings, it is just a matter of time before something really serious happens.

 

This situation is made worse by the distributed nature of the responsibilities involved:  the U. S. military, the FAA, airline operators, airline manufacturers, and pilots.  With so much opportunity for finger-pointing, it's no surprise that not much substantive has been done.  It would be a tragedy if effective steps were taken to fix this problem only after somebody gets killed.  But sometimes it takes a tragedy to get people to do something.

 

Sources:  Mark Harris's article "Lost in Airspace" appeared on pp. 22-27 of the February 2021 issue of IEEE Spectrum.  Portions of it can be viewed at https://read.nxtbook.com/ieee/spectrum/spectrum_na_february_2021/lost_in_airspace.html.  I also referred to Wikipedia articles on GPS and VOR.

Monday, December 07, 2020

Betrayal of Faith: Muslim Pro and the U. S. Military

 

Faithful Muslims are required to pray five times a day, facing toward Mecca.  In our smartphone era, it was only a matter of time before someone came up with an app that reminds the Muslim user that it's time to pray, and conveniently uses GPS data to direct the user toward Mecca from anywhere in the world.  Muslim Pro is the most popular app to do these and other helpful things for members of Islam, and has been downloaded some 98 million times. 

 

When a person downloads an app that is advertised to do a certain function, the question of what else it might be doing in the background rarely arises.  If the app is free, most people are aware at some level that the developer must make money somehow, typically through advertising.  But rarely does the typical user even read the boilerplate that sometimes appears during installation, because it would take a lawyer to figure out what it means, and all the relevant information might not even show up in the user agreement.  So there is an implied agreement or good-faith assumption on the part of the user, that the app developer won't do anything with the user's data that the user would object to.

 

Users of Muslm Pro received a shock last month when the Motherboard column of the website Vice revealed that through a third-party vendor, Muslim Pro had sold location data on its users to contractors for the U. S. military.  True, the data was "anonymized," meaning that names and other explicit identifying information was stripped from the data before it was sold.  But if a contractor obtains data from several different anonymized sources, it is often a fairly straightforward matter to "de-anonymize" the data and identify specific individuals.  If an anonymous individual spends a lot of time at a particular street address that can be associated independently with a particular name, so much for anonymity. 

 

Although no one has traced any specific military actions to the use of Muslim Pro data, users of the app have every right to feel betrayed.  Muslims aren't the only religious group using faith-related apps.  Just to pick a random example, the Catholic radio network Relevant Radio has developed an app that assists users in saying the Rosary and pursuing other devotional practices.  Imagine how users of that app in a Christian-hostile country would feel if they discovered that the network was selling location data gleaned from the app to representatives of the country that was persecuting them.  Betrayal is a mild word.

 

After Vice revealed the practice, Muslim Pro announced that it was cutting off its association with X-Mode, the company that was buying location data from Muslim Pro and other apps and selling it to contractors who specialize in providing intelligence data to the U. S. military.  For its part, X-Mode encourages developers who provide data to insert warning phrases in their user agreements.  Even if such verbiage was provided by each of the 400 or so apps that X-Mode obtains data from, it is unlikely that most users would even read it. 

 

I will admit that the first time I heard of a special watch that informed the wearer of the correct direction to pray toward Mecca, it struck me as incongruous, to say the least.  Here was a practice of a 1400-year-old faith being aided by up-to-date technology.  But religion is an important part of the lives of billions of people, and as technology advances and provides conveniences and assistance for every part of life, it's understandable that religious practices would take advantage of it too. 

 

The Muslim Pro-X-Mode revelation is a good example of how compartmentalizing is encouraged by the way large-scale technical systems work.  Most religions deal with the whole person, one at a time.  This is the opposite tendency of the way a company like X-Mode operates:  stripping identifying information from bits of location data and selling it wholesale to similar organizations that deal in dehumanized blocks of information, which however can be easily reversed to reveal the location of any particular individual.  Those who handle the data along the way—the programmers and managers and salesmen—easily forget that the only reason their data is valuable is because it pertains to human beings.  They would rather think about correlations and data quality and other mathematical measures, than to consider that just possibly, one of the bits of data they sell may be used to end the life of a human being. 

 

I am not a pacifist, and I realize that war is sometimes the least bad alternative in certain situations.  But historically, one of the most common practices a warring nation will adopt against a rival nation is to convince its own people that the rivals are not really human, but are something less than human—animals, maybe, or even just numbers in a census record somewhere.  In anonymizing the location data Muslim Pro collected, X-Mode unwittingly carried out that first step in making it easier for someone else to treat human beings as less than human.  What looked like a good thing—removing personal identifying data—turned out to be the first step in a process that wound up as a betrayal.

 

Information technology is an unavoidable part of our lives now, and can be the source or driving force behind many benefits.  Without computers and anonymized testing, we would not be looking forward to getting vaccines for COVID-19 within a year of the virus's spread to humans.  But those who use data derived from humans must never forget the humans behind the data, and everyone working in such fields needs to exercise their moral imaginations enough to ask, "Supposing I was a user, are we doing anything that I'd object to?"  And if the answer is yes, don't just shrug and go on about your business.

 

Sources:  The original report on X-Mode's use of Muslim Pro location data was "How the U. S. Military Buys Location Data from Ordinary Apps" by Joseph Cox, which appeared on the Vice website on Nov. 16, 2020 at https://www.vice.com/en/article/jgqm5x/us-military-location-data-xmode-locate-x.  Articles derived from this source appeared in many locations including the Austin American-Statesman, where I first learned of it.