Showing posts with label insurance. Show all posts
Showing posts with label insurance. Show all posts

Monday, June 03, 2019

Bitcoin-Enabled Ransomware Attack Strikes Baltimore


Last month, the city of Baltimore became the latest target of a ransomware attack.  The city's Microsoft operating systems were held hostage by a group that demanded 13 bitcoins, which at the present rate of exchange is about $100,000.  Despite their inability to repair all the damage after nearly a month, Baltimore administrators refuse to pay the ransom, and instead have asked the federal government for help.  According to some sources, the malware used for the attack was developed at the U. S. government's National Security Agency (NSA), and somehow it leaked and was posted by a group of hackers in 2017. 

Irony is usually found more in literature than in engineering, but this incident is particularly rich in them. 

The first irony is that a cyberweapon presumably developed to be used by the United States against its enemies was stolen, published worldwide, and used instead to attack the infrastructure of a major U. S. city. 

The second irony is that an idea traceable back to 1991, a chain of blocks developed originally just to prevent software timestamps from being tampered with, has turned into a means by which ransoms can be paid with no realistic hope of tracing where the money goes. 

And the third irony is that some eyebrows are being raised by the fact that the city of Baltimore is asking for help from the federal government. 

Let's do a little thought experiment and set the essential ingredients of this incident in an alternate universe which is just like ours, except there's no computer networks and so on.  Suppose a gang of paratroopers landed in Baltimore and made their way to the city offices, holding employees at gunpoint while they absconded with tons of files and records in a heavily armored vehicle.  Then the mayor received a ransom note demanding $100,000 for the return of the records.  Not only would a nationwide manhunt be mounted for these criminals, but the FBI and other federal agencies would get involved as a matter of course. 

But simply because the records and functions involved are on computers and not physical documents, attitudes and actions are vastly different here.  Now, admittedly some blame can be attached to those responsible for running Baltimore's IT systems.  Microsoft evidently does a fairly good job of sending out patches and updates in response to new viruses and malware, but these patches have to be implemented in a systematic and organized way.  And in the case of Baltimore's systems, this was not done.  In the world of our thought experiment, this amounts to not having enough armed guards surrounding your municipal buildings to fight off the attackers. 
While a certain amount of security is to be expected, nobody wants to have to do the equivalent of breaking into Ft. Knox in order to pay your city water bill. 

While I am not usually in favor of greater centralization of power and resources, in this case I think it is only fair for the federal government to help out Baltimore in their hour of need.  For one thing, the NSA never should have let its malware escape in the first place.  It would seem to be a fairly straightforward investigation to discover who was responsible.  But the NSA's workings are deliberately opaque and poorly supervised even by Congress, who pays the bills, and that sort of setup is an open invitation to laxity and inefficiency.  Perhaps this leak represents only 0.001% of everything that NSA has developed, most of which is still secret.  But in situations like this, even one leak can be too many.

As for bitcoins being used for ransomware payment, it makes a certain amount of perverse sense that a form of currency inspired by hyper-libertarianism is used mainly for two things nowadays:  speculation and illegal transactions.  It is an ill wind that blows nobody good, and bitcoins have benefited some people.  I may have mentioned a student of mine who managed to buy some bitcoins only a few years after they came out in 2009.  I don't know exactly what she paid, but by the time she graduated I think she had been able to pay for her entire college education with her profit in bitcoins. 

But is this advantage worth the social cost of having a virtually foolproof way of laundering money?  I leave that for the reader to decide.  It doesn't matter now, because bitcoins and their offspring are a permanent part of the cyberlandscape now. 

Perhaps the most troubling aspect of the Baltimore situation is the complete anonymity of the attackers, who could be, and probably are, anywhere in the world outside of the United States.  Prior to the Internet, the most significant threat the U. S. endured from outside its borders was the threat of intercontinental ballistic missiles carrying nuclear warheads, and billions of dollars were spent in an arms race that is in some ways still with us.  But now that anyone with sufficient skills can mount attacks on specific geographic entities in the heartland of the U. S. from halfway around the world, we still act as though it's just some sort of defect in a strictly local pile of computer networks, and treat the attackers much like an act of God—something that's always going to happen sooner or later, so you might as well just buy insurance and be ready when it happens.

Maybe that's the best approach.  Baltimore, as it turns out, did not have cyberinsurance, but the bond underwriters will soon see to that  So in the future we will go armed not with guards, but with insurance policies to buy experts who come in and fix our computer systems, just like roofers replaced my roof after a recent hailstorm this spring.  Complexity begets complexity, and if Baltimore and other cities consistently refuse to pay ransomware demands, perhaps the criminals will devise some other way to make ill-gotten gains.  I can hardly wait to see what they'll do next.  (That's irony, by the way.)

Sources:  I referred to articles at https://phys.org/news/2019-05-baltimore-ransom-cyberattack.html and the website Governing.com at https://www.governing.com/topics/public-justice-safety/gov-cyber-attack-security-ransomware-baltimore-bitcoin.html, as well as the Wikipedia articles "blockchain" and "bitcoin." 

Monday, September 15, 2014

A Tech Fix for Texting While Driving


By now, almost everybody with a cellphone and a car knows that it's a bad idea to text while you're driving.  But people still do it, and some of those people die in text-related car crashes and take innocent victims with them.  What if technology existed that simply prevented people from texting from a moving car at all?  Wouldn't that solve the problem?

Scott Tibbetts thought so.  Tibbets and his company Katasi were profiled in a recent New York Times article for developing a promising technology that would simply block texting from any phone that was in a moving car.  While there are several technological solutions to this problem that are already on the market, they all have various problems. 

Some text-blocking apps work by using the phone's GPS to figure out if the phone is moving faster than walking speed.  If it is, the software concludes that you're driving, and blocks texts.  This one turns out to be a battery hog, because the GPS system has to run all the time.  It also might present problems for train and bus passengers.  Another system uses the car's speed sensor and links it to the phone with a Bluetooth wireless connection.  But it costs over a hundred bucks, and there aren't that many people who are both concerned enough about texting while driving to buy it, and also willing to shell out that much money for something they could do for free with a little more willpower, perhaps. 

Mr. Tibbetts' solution is cleverer than these.  It involves connecting a wireless box to the car's OBD-II port—the on-board diagnostics socket that the auto technicians use to figure out what the "service engine" light means.  When the car's moving fast enough to be dangerous, the wireless box sends that information to the cellphone network, which then asks the phone—once—where it is.  Then, if the network is using the software developed by Mr. Tibbetts' firm Katasi, the software uses the location data to figure out things like who is driving the car.  You don't want a whole family's text service blocked just because Mom is driving to the grocery store, for instance.  That way, the GPS battery-drain problem is minimized, and the computational heavy lifting is done in the cloud, so to speak, rather than by the phone.

Mr. Tibbetts, an aerospace engineer and entrepreneur, has persuaded both an insurance company and a cellphone provider (Sprint) to cooperate in test trials, which have worked fine.  But it appears that the largest player, Sprint, has gotten cold feet lately, and has stalled further tests.  In the Times interview, Wayne Ward, vice-president for business and product development at Sprint, expressed concerns about product liability.  Currently, if a driver texts while driving and gets in a wreck, it's the driver's fault.  Mr. Ward asks what might happen if Sprint sells the Katasi system that claims to prevent such accidents, and then some glitch happens and somebody sneaks through a text and crashes anyway?  Why, Sprint could be sued!

Pardon me, but it appears that there's more going on here than meets the eye.  Any time a small independent company comes up to a big firm and offers the big guy new technology, the not-invented-here problem can raise its ugly head.  Short of buying the small upstart outright (which happens a lot, by the way), if the big firm adapts the small company's technology, they will be on the hook for royalty payments or other forms of obligation that big companies don't want to be tied down to.  And there's also the simple pride factor expressed by the phrase "not invented here"—if we didn't think of it first, it can't be that good. 

Besides, it's not clear who would make enough money to offset the expenses of the added hardware and software—and lawyers' fees, if Mr. Ward's fears turned out to be correct.  The existing GPS-based solutions for text blocking in cars aren't exactly selling like hotcakes, even after all but five states have adopted no-texting-while-driving laws of one form or another. 

One could imagine a legal solution:  make something like the Katasi text-blocking system mandatory by government fiat.  Nobody has seriously put forward that idea yet.  But it might happen.  There was a time when ordinary window glass was used in automobiles, with the result that otherwise minor wrecks turned deadly when razor-sharp knives of glass flew around and sliced—well, enough said.  But when the technology of laminating glass with a plastic inner layer was developed around 1920 to keep the shattered pieces together, auto companies adopted it, partly motivated by fear of lawsuits.  Eventually, most countries made it a legal requirement for all glass in automobiles to be laminated or safety glass, but it looks like the firms were ahead of the government in that case.

Safety glass is a different kind of thing than automatic text-blocking.  An auto company could start using safety glass and just raise the car's price incrementally, and hardly any customers would notice the change.  But as soon as you stop a person from doing something that they're used to doing, like texting while driving, you create a sharp negative impression.  And that's something that cellphone providers are reluctant to do as long as there are competitors ready to take business away.

My hat is off to Mr. Tibbetts, who put five years and millions of dollars into developing a clever technological fix for a significant problem.  But as many engineers turned entrepreneurs have learned, building the better mousetrap­—or text trap—is only part of the problem.  Convincing people to buy it and use it is often harder than coming up with the invention itself.  If everybody used something like the Katasi system on their cellphones, we would all be safer, no question about that.  We would also lose a little freedom of judgment which we can now exercise, which is whether to text while driving.  Perhaps some telecomm industry leaders will get together and agree to adopt Katasi, or something like it, but such inter-company cooperation for a non-financial thing like safety is a rarity.  It could happen, though.  I bet Mr. Tibbetts, for one, hopes that it will. 

Sources:  The New York Times article "Trying to Hit the Brake on Texting While Driving" by Matt Richtel, appeared in the online edition on Sept. 13, 2014 at http://www.nytimes.com/2014/09/14/business/trying-to-hit-the-brake-on-texting-while-driving.html.  I also referred to Wikipedia articles on on-board diagnostics, windshields, and safety glass. 

Monday, October 15, 2012

Genes and Sneakers

 
Here is a not altogether implausible scenario from a possible not-too-distant future.

You’re a 30-year-old U. S. woman who has recently been diagnosed with breast cancer.  You are too old to be covered by your parents’ health insurance, and you don’t yet work for a firm that has health-care coverage, so you have applied for health insurance under a new Federal insurance-exchange program.  As a condition of receiving coverage, you must supply a mouth swab which provides a DNA sample.  A few weeks later, the results come back:  because you have a hitherto undiscovered genetic defect that puts you at a high risk of developing Alzheimer’s disease at an early age, you are eligible for a mastectomy, but not chemotherapy.  According to a utilitarian calculation by a government bureaucracy, you will die of Alzheimer’s well before your breast cancer would recur without the added prevention provided by chemo.

Now, if the insurer were a private company, the scenario I just described would be illegal, at least according to a recent Associated Press article on the potential pitfalls of inexpensive human genome sequencing.  “Discrimination” by either employers or health insurance companies based on a person’s DNA information is a violation of Federal law.  But just as it’s illegal for you and me to print money, but perfectly legal for the government to print money, there may come a time when the government deems it necessary to analyze your DNA for reasons of “efficiency” or “cost-effectiveness.”

It is truly amazing how rapidly a feat which was once hailed as one of the most difficult achievements in the history of humanity is now something that may cost as little as $1,000 in a few years.  Of course, we are not really comparing apples and oranges here, because it’s one thing to read out all the 1’s and 0’s (to use computer language) of a person’s DNA, and another thing altogether to know what it means.  And technically, the human genome sequencers aren’t really finished even now, more than a decade after a “working draft” was published in 2000.  Figuring out what the human genome is saying is one of the hottest topics in molecular biology, and more is being learned every day.  But enough is known already so that dozens of genetically-related diseases can now be tested for.  And with that ability come a host of ethical issues.

Insurance companies rely on accurate calculation of risks faced by their customers in the average or statistical sense.  That’s how they stay in business, by making educated guesses as to who is likely to die when, who is more likely to need what medical treatment, and so on.  Nobody gets upset when a life-insurance firm wants to charge an 80-year old more than a 20-year old for a $100,000 life-insurance policy.  Decades of actuarial data (and common sense) show that the octogenarian is much more likely to “assume room temperature” (in Kinky Friedman’s phrase) sooner than the college-age kid.  And believe it or not, there was a time when the kind of actuarial or statistical calculation that prudently apportions insurance rates to risk was regarded as advanced scientific knowledge.  For all I know, some people opposed the use of obscure calculations of actuarial science for pricing insurance when these methods first arrived on the scene.  But eventually, people realized that the advantage of having insurance was worth the trouble of paying different prices for it, and we got to where we are today.

Well, now we have some new advanced scientific knowledge about our DNA that can be obtained for a cost that falls every year, and it promises to tell us all sorts of things about how long we might live and what we might die of.  From the consumer’s point of view, especially if you are a consumer with a genetic malady that could cost some health insurer millions, it makes sense to pass a law forbidding discrimination on the basis of genetic testing.  But to be entirely consistent, it seems to me, they shouldn’t have stopped there.  They should have rescinded all the variations in the price of all kinds of insurance based on things like whether you smoke, how safely you drive, or how old you are.

The reason they didn’t, is because imposing a completely uniform rate on everybody for a class of insurance without taking advantage of any of the data that allows companies to predict risk, is like blindfolding a man and then telling him to go find his car keys.  Maybe he’ll find them eventually by feeling every square inch of the house, but it will take him a lot longer than if you let him look.  And if private insurers can’t use additional information to predict risk, they will have to raise rates on almost everybody, because they have to deal with worst-case situations that they could avoid with more information. But what’s crazy for a private company is done all the time by government, and so what we’ve prohibited from coming in the front door—discrimination based on DNA testing—is very likely to sneak around and come in by the back door when even the government finds that ignoring DNA data is a very costly thing to do.  Hence the sneakers of the title (I had to work it in somewhere).

What’s the answer?  I don’t have one.  Not every ethical dilemma posed by a new technological development has an easy answer, or even a logical hard answer.  We as a society have spent billions of dollars developing the ability to decode our own genes.  We have let that particular genie (pardon the expression) out of the bottle, and like Pandora, many of us will not be able to resist the temptation to pay whatever the market will bear to find out what our genes bode for our future.  But very little of what genetic testing tells you is a certainty.  And even lives cut short or debilitated by genetic disease can be worth living—ask Stephen Hawking, who has a type of amyotrophic lateral sclerosis (ALS or Lou Gehrig’s disease) and has been wheelchair-bound and almost paralyzed for many decades.  Yet he has won a dozen or more international prizes for his groundbreaking work in theoretical physics, has married twice, and has been portrayed on Broadway.  Hawking should thank God that genetic testing for ALS wasn’t available when his mother was pregnant.  England’s National Health Services might have saved a few bucks if Hawking had been aborted, but the world would have been much poorer as a result.

Sources:  The article “Panel:  Genetics needs ethics rules” by Lauran Neergaard appeared in the Oct. 14, 2012 edition of the Austin American-Statesman, p. A7.  I referred to articles in Wikipedia on Stephen Hawking and the Human Genome Project.