Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, April 04, 2022

How Secure are Decommissioned Communications Satellites?

 

These days, the vast majority of communications signals are carried over fiber-optic cables that gird the globe and form the backbone of the Internet.  But for certain purposes such as broadcasting, geostationary satellites are still important simply because they can access huge geographic areas much more cheaply than wired or fiber networks, and are sometimes the only way to access rural and remote areas. 

 

Like any other hardware, communications satellites have a limited lifetime, and after they are replaced by newer ones, the old satellites are eventually moved into "graveyard" orbits and later burn up in the atmosphere.  But in their retirement-home phase while they are still in place but not being actively used, they are vulnerable to being hacked, as a security researcher named Karl Koscher recently showed and Wired reported.  In contrast to ground-based digital networks, communications satellites are largely analog and can be hacked with relative ease.

 

The first communications satellite, Telstar 1, was launched in 1962, long before the Internet was even a gleam in Vinton Cerf's eye.  But it embodied the essential features of today's comm satellites:  a microwave receiver, some sort of signal processing that changes the frequency band to a different transmitting frequency, and an amplifier that sends out a boosted version of the weak signal received from a ground station.  Depending on the application, the transmitted signal can cover thousands of square miles where anyone with, for example, a DirecTV dish can get them.

 

While Koscher worked with the owners of a decommissioned satellite to perform his hacking, that wasn't strictly necessary.  He borrowed the transmitter and dish of an earth station set up for this sort of thing and aimed the appropriate signals at the dormant satellite, which was a Canadian unit launched in 2005 and at the end of its fifteen-year design life.  In doing so, he successfully demonstrated that he could broadcast to a good part of the North American continent using facilities that are within reach of a determined amateur hacker.

 

Someone with less benign intentions than Koscher could simply overpower a legitimate signal from a satellite's owner and essentially take over the satellite's receiver.  Whether the transmitted signal could be received by the customers would depend on how the signal is digitally encoded, but such encoding can also be hacked as well. 

 

On your list of things to worry about, this issue probably doesn't deserve a very high ranking.  Back when satellites were the only means of broadband connections between continents, they were a much more critical part of our communications infrastructure.  Now that most people, at least in North America, get their data from the Internet without need of a satellite link, because most Internet traffic is carred via undersea fiber-optic cables, the fact that old satellites can be hacked is not that threatening.  Still, the possibility exists that newer satellites could also be taken over with sufficiently powerful earth-station signals, and this would cause problems beyond simple bemusement. 

 

Unlike Internet hackers, who can hide in obscure basements in inaccessible countries and evade detection for months or years, a satellite ground station is not an easy thing to hide.  There is one such installation a few miles south of where I live in San Marcos, Texas, and although I've never driven by it to see how close I can get, the large (10-meter or so) dishes are easily visible from I-35 between here and San Antonio.  So if a satellite hacker began making a habit of pirating, it would not be that difficult to figure out where he was transmitting from, depending on the satellite's own characteristics and the amount of power needed.

 

But we are far from being done with our dependence on communications satellites.  Elon Musk is launching Starlink, a planned array of over 4,000 low-orbit satellites designed to provide Internet service for underserved nations, and eventually the entire world.  Such satellites are much harder to hack in a meaningful way, because they move fast and the loss of one or two out of several thousand is probably only a minor inconvenience to the network.  Any hacking to be done with Starlink will probably be at a higher level, resembling Internet hacking on the fiber network, which is basically independent of the hardware used for conveying the information.

 

Perhaps there is a lesson here about the nature of ethical lapses with regard to communications technologies.  Any technology that conveys meaningful information from one human to another human, regardless of what time or space intervenes, is a communications technology.  Other things being equal, enabling human-to-human communications (which is the only kind we use technology for so far) is better than not enabling it.  Of course, any communications medium can be used for evil purposes, but generally speaking, communications systems can make one of the best claims at being ethically neutral of any technology you can name. 

 

But those systems which by their nature enable one person simultaneously to communicate one way with thousands or millions of others are in a special ethical category.  This was implicitly recognized in the pre-Internet days by the extensive regulatory regimes that broadcasters worked under in many countries.  But with the advent of the Internet, the broadcaster-versus-private-communicator distinction broke down, and outfits such as Facebook found there was money to be made in intentionally blurring that distinction. 

 

Broadcast satellites are one of the few remaining technologies in which that distinction is still distinct.  But the fiber-optic Internet has made them somewhat of a niche issue in the wider scope of communications-technology ethics, and I don't worry much about facing a rash of takeovers of old comm satellites in the future, simply because there are lots easier ways to do nefarious things using communications systems that aren't tied to satellites at all. 

 

Nevertheless,Koscher's feat is a warning for future satellite operators to take extra precautions so that a hacker can't even take over the satellite except to block it from operating, which will always be possible.  But there isn't much illegitimate money to be made from that, and so Koscher's demonstration may be the last of its kind.

 

Sources:   Wired carried Lily Hay Newman's article "Researchers Used a Decommissioned Satellite to Broadcast Hacker TV" on Mar. 30, 2022 at https://www.wired.com/story/satellite-hacking-anit-f1r-shadytel. 

Monday, May 27, 2019

Can We Trust Alexa? Wade Roush Hopes So


Wade Roush is a journalist who writes a column on innovation for the prestigious Scientific American monthly.  In the June issue, he looks at the future of increasingly smart and omni-present artificial-intelligence (AI) agents that you can talk with—Apple's Siri, Google's Assistant, Amazon's Alexa, Microsoft's Cortana, and so on.  Apple has installed a Siri app in its AirBuds so all you have to do is say, "Hey, Siri" and she's right there in your ear canals.  (Full disclosure:  I don't use any of these apps, except for a dumb talk-only GPS assistant we've named Garmina.) 

True to his column's marching orders, Roush came up with a list of five protections that he says users should "insist on in advance" before we go any farther with these smart electronic assistants.  Don't get me wrong, it's a good list.  But the chances of any of the five taking hold or being realized in any substantial way are, in my view, way smaller than a snowball's chances in you-know-where. 

Take his first item:  privacy.  Inevitably, AI interactions are cloud-based because of the heavy-duty processing required.  Therefore, he calls for end-to-end encryption so even the companies running the AI assistants can't tell what's going on.  This is a contradictory requirement.  Of course they have to know what you're asking, because otherwise how are they going to respond to requests for information?  Maybe Roush is thinking of something like the old firewall idea that used to be maintained between the editorial and advertising divisions of a news organization.  But there are huge holes in those walls now even in the most traditional news outlets, and I don't see how any company could both remain ignorant of what's going on between its AI system and the user, and have the AI system do anything useful.

The next protection he asks for is unprecedented, so I will quote it directly:  "AI providers must be up front about how they are handling our data, how customer behavior feeds back into improvements in the system, and how they are making money, without burying the details in unreadable, 50-page end-user license agreements."  If any of the AI-assistant firms manage to do this, it will be the first time in recorded history.  Especially the part about how they make money.  That's called a firm's business strategy, and it's one of the most closely guarded secrets that most firms have. 

Next, he calls for every link in the communication chain to be "hacker-proof."  Good luck with that.  Hacker-resistant, I can see.  But not hacker-proof.

Next, he says the assistants must draw on "accurate data from trusted sources."  This is a hard one.  If you ask Alexa a question like, "What do you mean, an Elbonian wants my help in transferring millions out of his country?" what's she going to say in response?  The adage "garbage in, garbage out" still applies to AI systems just as it did to IBM System 360s in the 1960s.  And if we're truly talking about artificial intelligence, with no human intervention, I don't see how AI systems will filter out carefully designed phishing attacks or Russian-sponsored political tweets any better than humans do, which is to say, not very well.

And I've saved the best for last.  He calls for autonomy, for AI assistants to give us more agency over our lives:  "It would be a disaster for everyone if they morphed into vehicles for selling us things, stealing our attention or stoking our anxieties." 

Excuse me, but those three actions are how most of the Internet works.  If you took away all the activity that was designed to sell us things, the Internet would dwindle back down to a few academics sending scientific data back and forth, which is how it began in the 1980s.  If you tell designers not to try stealing our attention, and turned off all the apps and sites designed to do so, Facebook, Instagram, all the online games, Twitters, newsfeeds—all that stuff would disappear.  Facebook designers are on public record as having said that their explicit conscious intention in designing the system was to make using it addictive.  And as for stoking our anxieties—well, that's a good capsule description of about 80% of all the news on the Internet.  Take that away, and maybe you'll have some good stories about rainbows, butterflies, and flowers, but only till the sponsoring companies go bankrupt for lack of business.

I have no personal animus against Mr. Roush, and in dealing with a new technology he has to say something about it.  And there's no harm in holding up an ideal for people to approach in the future, even if they don't have much of a chance of approaching it very closely.  But it's strange to see a supposedly savvy technology writer call for future protections on any high-tech innovation that are so ludicrously idealistic, not to say contradictory in some points. 

Perhaps a page from the historians of technology would be helpful here.  They make a distinction between an internalist view of history and an externalist view.  I'm radically simplifying here, but basically, an internalist (I would count Roush in that number) takes the general assumptions of a field for granted and looks at things in a we-can-do-this way.  And in principle, if you take the promises of smart-AI proponents at face value, we could in fact achieve the five goals of protection that Roush outlined.

But an externalist views a situation more broadly, in the context of what has happened before both inside and outside a given field.  In saying that the protections Roush calls for are unlikely to be realized fully, I rely on the history of how high-tech companies and other actors have behaved up to this point, which is to fall far short of every protection that Roush calls for, at one time or another. 

I hope that this time it will be different, and talking with your trusted invisible AI assistant will be just as worry-free as talking with your most trusted actual human friend on the phone.  But after writing that sentence, I'm not even sure that I want that to happen.  And if it does, I think we will have lost something in the process.

Sources:  Wade Roush's column "Safe Words for Our AI Friends" appeared on p. 22 of the June 2019 print issue of Scientific American.

Monday, October 02, 2017

Internet Security Isn't Child's Play


Full disclosure:  my wife and I have never had children.  The closest we have come to full-time responsibility for someone younger than 80 was when our ten-year-old nephew came to stay with us for part of the summer of 2013.  So what I have to say about the hazards of buying smart Internet-connected toys for your kids is, from my point of view, entirely hypothetical and untouched by the seasoning of personal experience.  Nevertheless, it's a new kind of problem and those with parental responsibilities need to be aware of it.

For the last several years, one of the biggest trends on the consumer-electronics horizon has been the Internet of Things (IoT).  It's now so cheap to connect tiny, inexpensive devices to increasingly powerful cloud-computing apps on the Internet that companies are falling over each other trying to get their IoT-enabled gizmos to consumers.  And the gold-rush analogy is especially apt for the toy market, which is highly seasonal and driven by novelty even more than the rest of the consumer business. 

When IoT came along, we began to see a flock of toys that connect to the Internet for some of the same reasons devices for adults do:  message sharing, video recording, GPS-enabled location features, and so on.  But when adults use IoT-enabled equipment, there is at least a presumption that they can read instructions and take whatever precautions are needed to keep malign third parties from exploiting the window into your personal life that bringing an IoT-enabled device into your home opens. 

Not so with children.  A recent story in the Washington Post details how the FBI had issued a consumer notice about "smart toys" that connect to the Internet.  Inspired partly by recalls in Europe of a talking doll that a hacker could use as a listening device, the FBI says that parents should be very careful about purchasing or setting up any toy that can connect to the Internet. 

While I'm not aware of any crimes that have been shown to be committed by such means, it's not hard to imagine such a situation.  Organized housebreakers could take a look around your home while little Johnny is dragging his Internet-enabled megatherium through the living room, and use its GPS to find just where that priceless collection of jewels from the court of Louis XIV is kept on display.  Even creepier is the notion that a crook bent upon kidnaping or worse could start talking to your daughter through her doll:  "Yes, I want you to meet a friend of mine.  He's waiting right outside the front door.  Mommy's asleep, isn't she?  Come on outside . . . ."  Sounds like a bad horror film, but the technology is there already.

The FBI's recommendations are not surprising, for the most part:  know whether the toy you're thinking of buying has been reported for problems with security, read the disclosures and privacy policies provided with the toy (if any), monitor your child's activity with the toy, use good password hygiene, don't tell the company any more than you have to when setting up the toy to work through your wireless system, etc.  Some of this advice falls in the wouldn't-it-be-nice category, such as reading disclosure and privacy policies.  First, hire a lawyer to interpret the policy, if it's written like most boiler-plate software agreements.  And while monitoring a child's use of the toy is a good idea, parents can be only one place at a time, and one reason for buying a child toys is so they can amuse themselves and not depend on you to be there fending off boredom for them every second.  Or at least that's the impression I get from a few parents I know.

The hazards of smart toys are just one more chink in the Swiss cheese of what used to be armor that most parents erected around their children.  Here's just one example of that armor from my own childhood, back when men were men and megatheriums roamed the earth. 

My father was a six-foot-two, two-hundred-pound repo man for a few years.  Repossessing cars from uncooperative borrowers is not for the faint of heart, and in a crisis I'm sure he could cuss as well as anybody.  But until I was a teenager, I never heard a swear word pass his lips, even when I drove my tricycle into the ladder he was using to hold a paint can and dumped a gallon of gray oil paint all over his head.  (Well, maybe he did cuss then and I just didn't understand what he was saying.) 

The point is that he went out of his way to create a kind of bubble of innocence or protection around us children.  There were some TV shows we couldn't watch and some magazines we couldn't look at, even back in the halcyon 1960s.  Back then, of course, electronic media had just barely started to infiltrate the home, radio and TV being the only means of entry.  Since both my parents were gone before the Internet really got going, I will never know what their reaction to it would have been.  But suffice it to say I don't think my father's impression of it would have been positive.

Some ages exalt and glorify children, and others like ours seem to treat them as kind of an optional hobby for adults, instead of the seedbed of the next fifty to hundred years of civilization.  Like it or not, children in advanced industrial societies are going to grow up in a world where the Internet of Things is as routine to them as electric lights were to people my age.  The main role of parents as parents is to prepare children to live in the world they will inhabit, and hopefully make it a better place.  But first the children have to survive into adulthood.  And while the chances of anything bad happening to your child as a result of a smart toy is remote, it's one more thing to worry about in the process of raising children.  And at least we've been alerted to this problem before anyone has been harmed, as far as we know. 

Sources:  Elisabeth Leamy's article "The danger of giving your child 'smart toys'" appeared on Sept. 29, 2017 in the online version of the Washington Post at

Monday, August 08, 2016

Hacked At The Polls


Last month we learned that computer systems used by both the U. S. Democratic National Committee (DNC) and the Democratic Congressional Campaign Committee (DCCC) were hacked into, possibly by Russia.  The initial news reports were confirmed by the FBI, which is investigating the breaches.  While no actual damage appears to have been done—yet—it is not clear what the hackers might have learned, and what they might do with the information.  At a minimum, it is a chilling reminder that foreign powers can now remotely meddle with systems vital to our democratic process:  a political party's internal analytical tools, not to mention electronic voting machines themselves.

A recent article on the Politico website enlarges on the latter possibility:  that hackers, either foreign or domestic, could diddle with electronic voting machines and the associated systems enough to throw an election.  Some computer scientists at Princeton have made a career out of showing how various brands of electronic voting machines can be hacked using simple methods that are accessible to clever teenagers.  Usually, the hacks require physical access to the machines for a time, but if polling-place workers are not quite vigilant enough, one can imagine this happening.  And then anything can happen, from blatant count manipulation to subtle effects that would be hard to catch in an audit.  The most vulnerable machines appear to be the touchscreen types that produce no paper audit trail.  Many states and counties have recognized this vulnerability and have switched to optically-scanned paper ballots which automatically produce a paper trail, but even these systems can be hacked into at the count-totalling level where laptops and computer networks are used to add up the results.  But there are still a lot of old vulnerable touchscreen systems in use.

The Politico article decries the inconsistent patchwork nature of our voting technology in the U. S., but fails to note that this can also be regarded as a strength.  For offshore hackers to arrange a major hijack of a national election and be fairly sure it would work, they would have to target up-for-grabs states (several of them), get detailed information on the wide variety of systems being used, and devise sub-hacks for each one.  While this kind of operation could be carried out, it's hard to see how, unless the foreign power had spies on the ground in the various states to provide information that would not be available any other way.  Nevertheless, huge elections can come down to a few critical votes in a few critical states, or even one, as the "hanging-chad" adventures of the Florida vote count of 2000 proved, leaving the whole nation in suspense for weeks and making the U. S. Supreme Court an unwilling participant in the election as well. 

While I normally eschew discussions of politics in this blog, I will limit my comments on the current Presidential contest to a phrase I heard from someone whose position prevented him from venting a more frank opinion about the candidates:  "It's a pity." 

Pitiful or not, national electons are a vital part of the way the U. S. government is made beholden to the people, and it is in the interest of every citizen to see that the process is as fair and transparent as possible.  If a foreign country manages to put its thumb on the scales, so to speak, it would betray the election's whole purpose and be tantamount to invasion by a foreign power.  For the same reason, contributions to domestic political campaigns by foreign entities are generally prohibited by law.

Voting in elections is an odd mix of the highly traditional and the cutting-edge high-tech.  Most applications of engineering have fairly clearcut goals:  build a bridge here to carry so much traffic and cost this much and take that long to build, for instance.  But in voting, it's not always clear what problems engineers are being called upon to solve. 

Some readers may know that Thomas Edison's first patent was for an electric vote recorder that received votes made by pushing buttons, and printed out a paper tally of the results.  He patented it in 1869 and a colleague tried to get the U. S. Congress to adopt it.  But getting through a roll-call vote faster by machine was not something that the committee evaluating the machine wanted to do.  As the committee chairman reportedly said, "If there is any invention on earth that we don't want down here, that is it."  It wasn't until the 1880s that any kind of voting machine was used in the U. S. in a general election, and legislatures were among the last entities to adopt them for their own voting process.  So even the great inventive genius himself misjudged what highly political organizations really want in the way of automated voting.

Increasingly today, politics is about power.  Power has always been a factor, but as other cultural forces—tradition, religion, courtesy, even fairness—wane in influence, the vacuum tends to be filled by the raw lust for power.  So it is understandable that regimes and individuals who see power as the mainspring and goal of politics will stop at nothing to attain their aims.  Just as our military has to exercise constant vigilance to keep armed threats at bay, we now have to defend the integrity of our elections from foreign interference, which is a new thing to a lot of local officials whose worst concern used to be finding enough volunteers to man the polls. 

One of the best ideas for safeguarding election integrity was proposed by a Princeton cybersecurity expert quoted in the Politico article.  If each lowly precinct simply posts its results in real time, on paper (and I would add, on the Internet too), allowing independent vote-checking agencies to compile vote totals, this step essentially eliminates any chance of an outside entity hacking into the vote-totaling systems, because the multiple independent tallies would agree and call into question the "official" total.  To some extent, news agencies already do this, but the exact data paths by which they obtain their vote totals is not obvious to the viewer, and making it so would both raise their credibility and help ensure the integrity of the whole system.

Casting a meaningful ballot is one of the most important privileges of living in a democratic society.  It is up to engineers and programmers to make sure that the voting systems this fall will allow every qualified citizen to do that.  But it is up to the citizens to use that power wisely.

Sources:  I thank my wife for drawing my attention to the Politico article, "How to Hack an Election in 7 Minutes" by Ben Wofford, published online on Aug. 5, 2016 at http://www.politico.com/magazine/story/2016/08/2016-elections-russia-hack-how-to-hack-an-election-in-seven-minutes-214144.  I also referred to a July 30 NBC News article about the hacking of the Democratic Party systems at http://www.nbcnews.com/news/us-news/clinton-campaign-computer-system-was-hacked-report-n620051.  Details of Edison's first patented invention, the vote recorder that nobody wanted, can be found at http://www.techtimes.com/articles/132791/20160211/thomas-edisons-first-patented-invention-could-have-drastically-changed-u-s-history.htm.

Monday, December 07, 2015

Child's Play: Hacking the Internet of Things


A company called VTech based in Hong Kong makes smart toys for kids.  One of their tablet products can connect to a parent's smartphone with a service called KidConnect, allowing children to send photos and text messages to their parents.  Sounds all nice and family-friendly, yes?  Well, in November the website Motherboard revealed that a hacker had managed to get into VTech's servers and download thousands of private photos, messages, passwords, and other identifying information that KidConnect users had sent and received.  This has understandably upset digital media commentator Dan Gillmor, who swears in a recent Slate article that not only he will never buy any Internet-enabled toys for children, he doesn't think anybody else should, either.  Reportedly, VTech has shut down the KidConnect service until they can do something about security.  But this incident brings up a wider question:  what dangers does the Internet of Things pose for children?

In case you've been living in a cave somewhere, the Internet of Things (IoT, for short) is the idea that in the very near future—by some measures, right now—internet connections, sensors, and the hardware and software needed to use them will be so cheap and ubiquitous that lots of everyday items will be connected to the Internet, sending and receiving data that will make great changes in our lives.  The promoters of IoT naturally hope that these changes will be for the better, and can point to examples that have done that.

This matter gets close to home for me personally, because for the last several years I have supervised electrical engineering senior design teams at my university, and several of the past and current teams have worked on projects that are IoT-related.  About four years ago, one team's project was a communications system designed to monitor electric-power consumption in the home, at a finer-grain level than just what the electric meter could sense about overall power consumption.  The idea was that if consumers have a detailed profile of their electricity usage, they can make more intelligent choices about what to turn on when.  Maybe doing the laundry late at night instead of right when you get home in the afternoon will put usage into a more favorable rate period, for example. 

As I was discussing the project with the team, it occurred to me that this information could be used for nefarious purposes.  You can tell a lot about a person if you have the kind of usage information the team was planning to measure: whether the user is home, for instance, and even what appliances are used and how often.  So I brought up this ethical issue with the team and made sure that they mentioned it in their final report. 

Since then, companies such as Freescale Semiconductor have jumped into IoT-related products and devices in a big way.  (Full disclosure:  Freescale has donated equipment and funds to the Ingram School of Engineering, where I work.)  From all I can tell, the Internet of Things is going to happen one way or another, and it behooves both engineers and the general public to give some thought to any possible downsides before something really bad happens.

Returning to the question of children and IoT, we are in a peculiar position these days.  Many children and young adults are vastly more tech-savvy than their parents, and this makes it hard for the parents to institute meaningful controls on what kids do online.  In the bad old days when the list of dangerous things in the home was mainly physical—guns, knives, poison, screwdrivers near electric outlets—it was a fairly simple matter for parents to keep toddlers out of harm's way.  But in the case of some toy that hooks up to your WiFi network, odds are that the parents are as clueless as the children regarding the privacy and security measures taken by the device's maker.  VTech itself didn't know how vulnerable its servers were until some enterprising hacker cracked into them and notified the media. 

Despite living with the Internet for close to thirty years now, we still have some things to learn about it, among which are new ways of using it that are potentially hazardous.  And children are an especially vulnerable population, as everyone agrees.  It's shortsighted to think of children always as the innocent parties in these matters too.  Some kids can be downright wicked, bullying others mercilessly.  Before we got so interconnected, a bully's sphere of influence was limited to the radius reachable by his fists, but hand a bully a smartphone with some sort of anonymous chatting app on it, and it's like putting wings on a wildcat.  His bullying sphere has instantly widened to include the entire globe, limited only by language ability and time.  And we have already seen instances in which Internet bullying has driven some vulnerable individuals to suicide.

Nobody is calling for a wholesale ban on Internet-enabled toys or anything like that.  But as I have often emphasized to my students in discussions of engineering ethics, many ethical lapses in the area of engineering can be traced to a lack of imagination.  When you are dealing with a physical structure like a bridge, it's relatively easy to calculate the maximum loads and find out how strong each member has to be for the bridge not to fall down.  But in any system that is intimately bound up with the behavior of people—especially millions of people at a time—your imagination has to anticipate the character and intentions of persons perhaps very different from you, who will twist your system around to serve their possibly sinister purposes. 

That is why privacy and security concerns need to be considered at the very beginning of any project that involves the Internet, and especially when a product is intended to be used by children.  VTech clearly did an inadequate job in this area, but they can serve as a bad example to warn future designers and users of IoT-enabled gizmos.  The craft of lockmaking is nearly as old as the craft of housebuilding, and for a good reason.  There are bad actors out there, and any time we open up a channel of communication involving a private citizen or residence, it needs to be guarded with the same care that we would extend to our own physical possessions.  Beyond mere technical ability, doing that well requires moral imagination, which should be in the toolkit of every good designer.

Sources:  The online magazine Slate carried the article "Parents: This Holiday Season, Do Not Buy Internet-Connected Toys for Your Kids" by Dan Gillmor at http://www.slate.com/blogs/future_tense/2015/12/03/internet_connected_toys_make_terrible_holiday_presents.html.  That article referenced a report at Motherboard describing the VTech hack and what the hacker found, which is at http://motherboard.vice.com/read/hacker-obtained-childrens-headshots-and-chatlogs-from-toymaker-vtech.

Monday, October 19, 2015

Will ISIS Hack the U. S. Power Grid?


In a meeting of electric-power providers last week, U. S. law enforcement officials revealed that Islamic State operatives have tried to hack into parts of the American power grid, so far without success.  But the mere fact that they're trying has some grim implications.

One of the officials, Caitlin Durkovich, is assistant secretary for infrastructure protection at the U. S. Department of Homeland Security.  She refused to provide specific details of the attacks, but an FBI official said so far that the attacks are characterized by "low capability." 

For some time now, it's been obvious that cyberwarfare may play an increasing role in future conflicts.  Perhaps the most significant successful attack up to now was mounted by a team of U. S. and Israeli experts in what came to be known as Stuxnet.  The attack was aimed at Iran's nuclear-material centrifuges and allegedly disabled many of them in 2010 before operators figured out what was going on. 

That attack was aimed at one specific facility, and the attackers had access to abundant information on the particular equipment involved.  Doing something similar to a significant part of the U. S. power grid would be a harder proposition for several reasons.

A Stuxnet-style attack on one generator, or even an entire plant, might temporarily  damage that plant and take it out of commission.  But the power grid is designed to deal with just such occurrences without major disruptions.  At any given time, a certain number of generators are offline for repairs or maintenance, and every so often a problem will cause one or more generators to trip out unexpectedly.  Unless the loss of capacity is very large or happens at a critical high-demand time (say on the hottest day of summer), the system absorbs the loss and reroutes power from other sources to make up the difference, often with no noticeable interruption to customers. 

So in order to produce a large-scale blackout that would do some good from a terrorism point of view, a different approach would be needed. 

The most vulnerable parts of the power grid from a hacking point of view are the network control systems themselves—the SCADA (supervisory control and data acquisition) devices and communications systems that tell system operators (both human and electronic) what the status of the grid is, and open and close the big high-voltage switches that route the energy.  A simultaneous order to a lot of circuit breakers to open up all across a large grid would throw the whole system into chaos, tripping other automatic breakers everywhere and necessitating a total shutdown and resynchronization, which could take hours or days—even longer if widespread mechanical damage occurred, which is possible. 

But doing that sort of attack would be very hard.  I am no power-grid expert, but I do know that long before the Internet came along, power utilities constructed their own special-purpose communication networks that carried the switch-command instructions, often by means of microwave relays or dedicated cables.  Originally, these specialized networks were entirely independent of the Internet because there was no such thing yet, and so were perfectly secure from Internet-based hacking.  Utilities tend not to throw anything away that still works, so my suspicion is that a good bit of network-control data still gets carried on these physically isolated communications links.  For a set of hackers halfway around the world to get into those specialized communications systems would require either amazing hacking abilities, or inside information, or most likely both. 

This is not to say that it's impossible.  But the job is orders of magnitude harder than disabling one uniform set of machines in one location.  As reports on the power-grid hacking attempts pointed out, the U. S. grid is a hodge-podge of widely different equipment, systems, protocols, hardware, and software.  A hack that might take out a power plant in Hackensack would probably be useless on a plant in Houston.  So to mount a coordinated attack that would create a politically significant amount of trouble would be a monumental undertaking—so hard that evil guys with limited resources may decide that some other type of troublemaking would be a better use of their time.

Does that mean we can just sit back and enjoy the fact that the Islamic State hackers don't know what they're doing?  Not necessarily.  Hackers come in all flavors, and as the Internet has played an increasing role in the day-to-day operation of electric utilities, those same firms have had to deal with the accompanying hazards of malevolent cyberattacks from who knows where.  So the fact that Islamic State hackers are going after the power grid is not exactly a surprise.

While the recent revelations have led to some calls for increased government oversight of cybersecurity for the power grid, the industry so far seems to have done a fairly good job at policing itself.  A report in USA Today back in March of 2015 said that the North American Electrical Reliability Corporation (NERC), which is the non-profit industry-sponsored security-standard enforcer, has slacked off on the number of penalties and fines it has assessed on its members in recent years.  But the president of NERC says this doesn't necessarily mean that his organization is getting lazy—it could just as well be that utilities are following the rules better.

Rules or no rules, the danger that foreign and domestic terrorist organizations could cause massive power blackouts in the U. S. is real.  And constant vigilance on the part of the utility operators is needed to prevent these attacks from getting anywhere.  Fortunately, the present structure of the grid makes it a particularly difficult target.  But that doesn't mean it couldn't ever happen.

Sources:  I referred to reports of the disclosures about cyberattacks on utility infrastructures carried by CNN on Oct. 15, 2015 at http://money.cnn.com/2015/10/15/technology/isis-energy-grid/, and by the Washington Examiner at http://www.washingtonexaminer.com/article/2552766.  USA Today carried an in-depth study of the issue by Steve Reilly on Mar. 24, 2015 at http://www.usatoday.com/story/news/2015/03/24/power-grid-physical-and-cyber-attacks-concern-security-experts/24892471/. I blogged on Stuxnet on July 24, 2011 and July 2, 2012.