Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, February 17, 2020

Will FIDO Make an End to Passwords?

Anybody who spends much time online these days, which is nearly everybody, wastes a certain amount of time and endures more or less annoyance in entering passwords.  An industry alliance called FIDO (for Fast IDentity Online) promises to make passwords a thing of the past.  But before that happens, there are both technical and social obstacles in the way.

Founded in 2013 by PayPal and other companies wishing to make it easier for people to log in to their sites, FIDO works by collapsing all the different password-validation operations for the sites you use into one device-specific process.  That would be a great improvement over the way things are now, as I will illustrate with a personal example.

Say I want to do the following:  check my bank balance, buy a component from a supplier in a hurry, log in to my university email,  and change a file on my class website. 

Right now I'd have to perform these steps flawlessly: (a) log on to my bank's website and enter two separate passwords which have nothing to do with my other passwords, and therefore are not that easy to remember (b) hunt up the place on my computer where I hide all the dozens of vendor passwords I've accumulated over the years by remembering the name of the file I hid it in, and typing the password into the vendor's website (c)  type in a long sequence of letters, some of which are capitalized, that the university recently made us switch to from an old shorter password, and hope I get it right, which I still do only about 80% of the time; (b) and for the class website, I have to do a two-step verification involving not only the previously mentioned new long password, and also either asking the computer to call my office phone (which is fine if I'm in the office) or letting me enter a six-digit number from a dongle they sold me, which works fine until I accidentally press its button two or three times without using the numbers, which I do from time to time because it's on a keychain in my pocket, and then it loses sync with the computer, in which case I have to phone IT support and spend ten minutes or so waiting for them to hunt up the one guy who is authorized to re-sync dongles, and I read out three numbers in sequence to him, with thirty-second pauses in between.  Then I can go back, log in, and change the file on my class website.

This is not to knock the university's IT people.  They are understandably concerned about security, and within their limited resources they have come up with the best password protection they can figure out.  And admittedly, if I would just break down and buy a smartphone I wouldn't have to fool with the dongle. 

But the dongle is one of the technical hurdles FIDO will have to overcome in its march to eliminate passwords.  As I understand it from the FIDO Alliance website, once FIDO achieves universal buy-in, all password requests would be dealt with the same way.  If you have a smartphone that does fingerprint verification, the same fingerprint will work for every website.  If you do dongle verification, or smart-card verification, or voice-recognition verification, that same method will work for everything.  The method used will depend on the device that the user has access to. 

For old duffers like me who spend at least as much time using a laptop to access the Internet as I do with a phone, this prospect is not so encouraging, because it means to take advantage of FIDO, I'd have to be using the same device all the time.  Or at least it seems to mean that.  But the global trend is toward using mobile phones for just about everything, and newer computers tend to have the hardware and software needed for fingerprint ID or similar biometric methods, so this issue will not be so serious going forward.

The social issue I mentioned is the simple fact that for FIDO to work, the websites all have to be able to take the FIDO "public-key cryptography" stuff that the user's device sets up.  And all the user-device makers have to make FIDO available on their devices.  Fortunately, the upsides to most parties involved way outweigh the downsides, which is why the people in charge of the Android operating system have recently upgraded their buy-in so that it will work with mobile browsers, according to a recent article on the Wired website.  So progress is being made in that area.

For people and organizations unable or unwilling to do FIDO, there will still be the old-fashioned password, which brings back to my mind scenes out of 1930s' movies about Prohibition, where someone desirous of booze would appear before a door with a peephole in it and murmur, "Joe sent me."  Perhaps back then the formality of a password just added to the underworld glamour of obtaining illegal hooch.  But these days, when accessing multiple websites in a day is as routine as walking through multiple doors in a day, passwords have become a digital albatross around our collective necks that we would be more than happy to get rid of.

As is always the case with advances in widely used technology, somebody will figure out a way to hack FIDO.  The obvious weakness to me is the fact that with FIDO, all one's security eggs will be in one basket, so to speak.  Right now, if somebody hacked my bank password, for example, I might wake up broke tomorrow, but at least I could still make a secure purchase from Etsy—if I had any money.  But if FIDO becomes universal and someone manages to hack into your FIDO verification system, they can get into everything your current passwords give you access to, all at once. 

I'm sure the FIDO wizards have thought of this possibility and will try to deal with it somehow.  As long as FIDO will work better than my hardware dongle, I'm all for it, but it looks like it will be a while before it gains the degree of acceptance that would make a real dent in our need for remembering, typing in accurately, and dealing with the downsides of plain old-fashioned passwords. 

Sources:  I referred to a Wired article entitled "Android Is Helping Kill Passwords On a Billion Devices" at https://www.wired.com/story/android-passwordless-login-fido2/, the FIDO Alliance website at https://fidoalliance.org/, and the Wikipedia article "FIDO Alliance."

Monday, May 27, 2019

Can We Trust Alexa? Wade Roush Hopes So


Wade Roush is a journalist who writes a column on innovation for the prestigious Scientific American monthly.  In the June issue, he looks at the future of increasingly smart and omni-present artificial-intelligence (AI) agents that you can talk with—Apple's Siri, Google's Assistant, Amazon's Alexa, Microsoft's Cortana, and so on.  Apple has installed a Siri app in its AirBuds so all you have to do is say, "Hey, Siri" and she's right there in your ear canals.  (Full disclosure:  I don't use any of these apps, except for a dumb talk-only GPS assistant we've named Garmina.) 

True to his column's marching orders, Roush came up with a list of five protections that he says users should "insist on in advance" before we go any farther with these smart electronic assistants.  Don't get me wrong, it's a good list.  But the chances of any of the five taking hold or being realized in any substantial way are, in my view, way smaller than a snowball's chances in you-know-where. 

Take his first item:  privacy.  Inevitably, AI interactions are cloud-based because of the heavy-duty processing required.  Therefore, he calls for end-to-end encryption so even the companies running the AI assistants can't tell what's going on.  This is a contradictory requirement.  Of course they have to know what you're asking, because otherwise how are they going to respond to requests for information?  Maybe Roush is thinking of something like the old firewall idea that used to be maintained between the editorial and advertising divisions of a news organization.  But there are huge holes in those walls now even in the most traditional news outlets, and I don't see how any company could both remain ignorant of what's going on between its AI system and the user, and have the AI system do anything useful.

The next protection he asks for is unprecedented, so I will quote it directly:  "AI providers must be up front about how they are handling our data, how customer behavior feeds back into improvements in the system, and how they are making money, without burying the details in unreadable, 50-page end-user license agreements."  If any of the AI-assistant firms manage to do this, it will be the first time in recorded history.  Especially the part about how they make money.  That's called a firm's business strategy, and it's one of the most closely guarded secrets that most firms have. 

Next, he calls for every link in the communication chain to be "hacker-proof."  Good luck with that.  Hacker-resistant, I can see.  But not hacker-proof.

Next, he says the assistants must draw on "accurate data from trusted sources."  This is a hard one.  If you ask Alexa a question like, "What do you mean, an Elbonian wants my help in transferring millions out of his country?" what's she going to say in response?  The adage "garbage in, garbage out" still applies to AI systems just as it did to IBM System 360s in the 1960s.  And if we're truly talking about artificial intelligence, with no human intervention, I don't see how AI systems will filter out carefully designed phishing attacks or Russian-sponsored political tweets any better than humans do, which is to say, not very well.

And I've saved the best for last.  He calls for autonomy, for AI assistants to give us more agency over our lives:  "It would be a disaster for everyone if they morphed into vehicles for selling us things, stealing our attention or stoking our anxieties." 

Excuse me, but those three actions are how most of the Internet works.  If you took away all the activity that was designed to sell us things, the Internet would dwindle back down to a few academics sending scientific data back and forth, which is how it began in the 1980s.  If you tell designers not to try stealing our attention, and turned off all the apps and sites designed to do so, Facebook, Instagram, all the online games, Twitters, newsfeeds—all that stuff would disappear.  Facebook designers are on public record as having said that their explicit conscious intention in designing the system was to make using it addictive.  And as for stoking our anxieties—well, that's a good capsule description of about 80% of all the news on the Internet.  Take that away, and maybe you'll have some good stories about rainbows, butterflies, and flowers, but only till the sponsoring companies go bankrupt for lack of business.

I have no personal animus against Mr. Roush, and in dealing with a new technology he has to say something about it.  And there's no harm in holding up an ideal for people to approach in the future, even if they don't have much of a chance of approaching it very closely.  But it's strange to see a supposedly savvy technology writer call for future protections on any high-tech innovation that are so ludicrously idealistic, not to say contradictory in some points. 

Perhaps a page from the historians of technology would be helpful here.  They make a distinction between an internalist view of history and an externalist view.  I'm radically simplifying here, but basically, an internalist (I would count Roush in that number) takes the general assumptions of a field for granted and looks at things in a we-can-do-this way.  And in principle, if you take the promises of smart-AI proponents at face value, we could in fact achieve the five goals of protection that Roush outlined.

But an externalist views a situation more broadly, in the context of what has happened before both inside and outside a given field.  In saying that the protections Roush calls for are unlikely to be realized fully, I rely on the history of how high-tech companies and other actors have behaved up to this point, which is to fall far short of every protection that Roush calls for, at one time or another. 

I hope that this time it will be different, and talking with your trusted invisible AI assistant will be just as worry-free as talking with your most trusted actual human friend on the phone.  But after writing that sentence, I'm not even sure that I want that to happen.  And if it does, I think we will have lost something in the process.

Sources:  Wade Roush's column "Safe Words for Our AI Friends" appeared on p. 22 of the June 2019 print issue of Scientific American.

Monday, November 27, 2017

Uber Under Pressure for Data Breach


In recent years, the rideshare-app company called Uber has not led anyone to believe they would win a corporate personality contest.  Their aggressive growth and shouldering aside of municipal regulations and the charges of sexual harrassment that ultimately led to the resignation of Uber co-founder Travis Kalanick last June have now been followed by a revelation that Uber had a massive data breach in October of 2016, over a year ago, and didn't make it public till last week.  Besides probably violating state laws, this latest flap raises serious questions about the responsibility of companies to protect consumers' data, and what companies should do when that data is compromised.

Here is apparently what happened.  A year ago last October, Uber discovered that hackers had obtained about 57 million names, addresses, and emails of customers who had used Uber's services.   The hackers also snagged driver license numbers for over half a million of these people.  Then they pulled a classic blackmail act:  for a mere $100,000, the hackers offered to destroy the data and keep the whole thing a secret.  Under the reign of Kalanick, Uber agreed to this deal.  The company claims that they have evidence that the data was destroyed, but one can be permitted to wonder about something that amounts to proving a negative. 

The main problem with all this skulduggery, other than the breach itself, was the way Uber handled it.  Many state laws require companies to disclose major data breaches like this within a stated time, usually within four to six weeks of discovery.  Uber clearly didn't do this.  And even if Uber's new CEO, Dara Khosrowshahi, had disclosed the incident upon taking up his new job in September, instead of waiting for two months, Uber would have still been violating these laws. 

As hacks go, in terms of numbers and the kind of data stolen, there have been worse incidents.  But still, knowing that your email and linked phone number, and maybe your driver license number, are floating around out there in the hands of blackmailers, is not a comforting thought.  Even worse is the fact that Uber caved so fast to the blackmailers' demands.  True, not many hackers offer to destroy the data they've stolen, but words are cheap. 

What should consumers do when faced with a choice to either (a) deal with a company that offers an attractive service at a good price, but has a reputation for shady actions with regard to its own employees, hackers, and the law, or (b) well, maybe there isn't another good choice, except to try calling an old-fashioned cab and hope for the best?  (Full disclosure:  I have never used Uber, airbnb, or any of those other newfangled apps that are breaking down the time-honored traditional service industries.  There's nothing intrinsically wrong with using them, and many millions of happy customers continue to do so.  But I have no personal experience with them myself.) 

Even if a person is well aware of Uber's less-than-stellar corporate reputation, in many cases one doesn't have a choice:  Uber has chased away most of the competing apps (Lyft being an exception in some locations).  To use anything else may require a great deal of conscious effort and ingenuity, and in some locations and situations it simply may not be possible at all.

There is a paradox in the fact that the digital online world on the one hand promises an infinity of options and choices.  But on the other hand, when it comes to certain close-to-essential services such as search engines, online transportation apps, and Internet service providers, the list of workable choices at a given time and place is usually radically limited to a few, or even one. 

From a business point of view, this narrowing of choices is a function of what is called the network advantage.  As Ma Bell found out around 1890 when the telephone network was experiencing rapid growth, every customer a network company adds not only increases the company's customer base, but also makes that same company more valuable to all of its other customers.  That doesn't apply in exactly the same way to Uber as it does to AT&T, but the principle is the same:  the biggest firm in a network-intensive business automatically has built-in advantages over everybody else, and so you usually end up with a winner-take-most situation.  For those lucky enough to invest in the biggest company before it takes over the whole market, it is a very attractive deal indeed.  But for consumers wishing to have a meaningful choice among a number of alternatives, the dominance of a single firm is less than salutary.

The concept of privacy, and the related idea of security, may simply have to keep changing as we seem to accept risks that a few years ago would have simply been unacceptable.  Even in the Middle Ages, there was no such thing as absolute security.  A man carrying a purse of gold coins was always liable to run into some ruffians who would knock him down and rifle through his possessions.  But one of the basic attractive features of civilization is that under most circumstances, people can go about their daily business using services that they need, without unduly running the risk of somebody coming along and taking valuables from them. 

Now that identity theft is so easy, it's something that is ethically equivalent to a purse of gold coins carried by a Middle Ages merchant.  But in the wild-West environment that is the global Internet, we have left the providing of security largely to service firms themselves, with results such as the Uber breach that are far from encouraging.  In breaking the law requiring timely notification, Uber became one with the hackers, at least to the extent of ignoring the law.  Unfortunately, none of its customers knew what they were up to.  And now that we know, many people will simply shrug the incident off as one of the risks of modern digital life.

Maybe it is, but to my mind, accepting and tolerating such things is a step backwards in the progress of civilization.

Sources:  I referred to reports on the Uber data breach at Gizmodo.com, posted on Nov. 24 at https://gizmodo.com/uber-s-new-ceo-was-told-about-the-companys-massive-data-1820722228, and the Washington Post at https://www.washingtonpost.com/news/the-switch/wp/2017/11/24/uber-is-sued-over-massive-data-breach-after-paying-hackers-to-keep-quiet/.  I also referred to the Wikipedia articles on Travis Kalanick and Uber.

Monday, May 23, 2016

EgyptAir Flight 804: Clues to a Tragedy


Early last Thursday morning, May 19, EgyptAir Flight 804, an Airbus A320 carrying 56 passengers and 10 crew members, went down in the Mediterranean on its way from France's Charles De Gaulle International Airport to Cairo.  The plane apparently broke up in the air and there are no survivors.  Search parties have begun to recover pieces of the wreckage, and data transmitted from the plane suggests that a bomb might have caused the crash.  But a definitive conclusion about the cause will have to await the recovery of the flight data recorders, if they can be found.

Generally speaking, commercial aviation safety has been a spectacular success story.  If you drive to the airport, the risky part of your journey is over once you park the car.  But determined terrorists can evade security measures to bring a plane down, and no amount of design improvements can make a modern airliner 100% secure against attacks.  In the case of Flight 804, we are fortunate to have information transmitted by the Aircraft Communications Addressing and Reporting System (ACARS) that has provided material for early speculation about the cause of the crash.

Within a day, a number of sources provided news media with ACARS data transmitted for a period of about two minutes around the time of the crash.  Two indicators associated with windows on the right side of the cockpit and several smoke alarms went off.  An aviation expert cited in The Telegraph (UK) speculated that a bomb in or near the right side of the cockpit could have blown out a window, and the resulting cabin depressurization at cruising altitude would have caused condensation fog that can set off smoke alarms.  As the plane broke up, the ACARS system could have kept working, which explains the length of time between the initial transmission and when communication was lost.

ACARS has been helpful in investigating other crashes, such as the Malaysian Air Flight 370 that went down over the Indian Ocean on Mar. 8, 2014.  Although numerous pieces of that plane have been recovered in widely separated locations, the underwater search for the main body of the aircraft continues to this day. 

The part of the Mediterranean over which EgyptAir Flight 804 went down includes some of its deepest waters, over 3000 meters (more than a mile) deep.  So it will be a challenge to find the flight data recorders, especially if the search takes longer than 30 days, which is about as long as the recorder underwater locator beacons operate. 

The continuing mystery of the Malaysian Air Flight 370 crash led to calls for live streaming of flight-recorder data in addition to hard-copy logging on the plane, and in the ACARS data that was recovered for the EgyptAir flight, we see that even in the absence of regulations requiring such streaming, airlines have begun to take advantage of digital communications channels to transmit data that can be helpful both for maintenance and in case of a crash.  Other improvements that could be made to flight-recorder technology include automatic ejection and flotation, as is already done for recorders on military aircraft.  Instead of sinking with the plane, military flight recorders are ejected during the crash and automatically deploy flotation devices which makes them much easier to locate on the water's surface.  Since national governments usually bear the burden of paying for underwater searches, you would think that they would see the logic in offering to reimburse airlines for the additional expense of military-style flight recorders.  But logic isn't the only consideration in international politics.

If the flight recorders and cockpit voice recorders are recovered, the question of whether the crash was deliberate will probably resolve itself pretty quickly.  If it was indeed a deliberate act, the question then becomes one of criminal investigation, and the security at De Gaulle International Airport will come under scrutiny.  As long as airliners are flown by human beings, the trustworthiness of the pilots is an essential link in the security chain.  Assuming the pilots were not themselves part of a conspiracy, that leaves the possibility that someone planted a bomb somewhere in the cockpit.  While cockpits are now typically sealed off from the rest of the plane during flight, it's possible that maintenance workers or others can get into them while a plane is on the ground.  The Telegraph reported that the short stopover in France may not have allowed security personnel enough time to give the plane a thorough going-over before it took off for Cairo.

Whatever the cause of the crash turns out to be, we will learn something from it.  If it was mechanical failure, which seems unlikely but is still possible, it may affect all A320 Airbuses out there, but if there is such a problem it hasn't shown up more than once, apparently.  If, as seems more likely, there was a deliberate act of sabotage, the technique used by the saboteurs will have to be guarded against in the future. 

Either way, sixty-six lives have been lost in what was in all probability an avoidable tragedy.  Most of the time, the vastly complex systems of design engineering, maintenance, operations, and security for air travel work essentially perfectly, and when we get on a plane we don't usually give much thought to the question of whether we'll be getting off  under our own power or not.  But the price of such liberty is eternal vigilance, and I hope the lessons eventually learned from this tragedy make future ones even less likely.

Sources:  I referred to reports from CNN.com at http://www.cnn.com/2016/05/21/middleeast/egyptair-flight-804-main/ and The Telegraph (UK) at http://www.telegraph.co.uk/news/2016/05/21/egyptair-crash---smoke-detected-inside-the-aircraft-cabin-as-sea/, as well as the Wikipedia articles on Aircraft Communications and Addressing System, flight recorders, and Malaysia Airlines Flight 370.

Monday, December 07, 2015

Child's Play: Hacking the Internet of Things


A company called VTech based in Hong Kong makes smart toys for kids.  One of their tablet products can connect to a parent's smartphone with a service called KidConnect, allowing children to send photos and text messages to their parents.  Sounds all nice and family-friendly, yes?  Well, in November the website Motherboard revealed that a hacker had managed to get into VTech's servers and download thousands of private photos, messages, passwords, and other identifying information that KidConnect users had sent and received.  This has understandably upset digital media commentator Dan Gillmor, who swears in a recent Slate article that not only he will never buy any Internet-enabled toys for children, he doesn't think anybody else should, either.  Reportedly, VTech has shut down the KidConnect service until they can do something about security.  But this incident brings up a wider question:  what dangers does the Internet of Things pose for children?

In case you've been living in a cave somewhere, the Internet of Things (IoT, for short) is the idea that in the very near future—by some measures, right now—internet connections, sensors, and the hardware and software needed to use them will be so cheap and ubiquitous that lots of everyday items will be connected to the Internet, sending and receiving data that will make great changes in our lives.  The promoters of IoT naturally hope that these changes will be for the better, and can point to examples that have done that.

This matter gets close to home for me personally, because for the last several years I have supervised electrical engineering senior design teams at my university, and several of the past and current teams have worked on projects that are IoT-related.  About four years ago, one team's project was a communications system designed to monitor electric-power consumption in the home, at a finer-grain level than just what the electric meter could sense about overall power consumption.  The idea was that if consumers have a detailed profile of their electricity usage, they can make more intelligent choices about what to turn on when.  Maybe doing the laundry late at night instead of right when you get home in the afternoon will put usage into a more favorable rate period, for example. 

As I was discussing the project with the team, it occurred to me that this information could be used for nefarious purposes.  You can tell a lot about a person if you have the kind of usage information the team was planning to measure: whether the user is home, for instance, and even what appliances are used and how often.  So I brought up this ethical issue with the team and made sure that they mentioned it in their final report. 

Since then, companies such as Freescale Semiconductor have jumped into IoT-related products and devices in a big way.  (Full disclosure:  Freescale has donated equipment and funds to the Ingram School of Engineering, where I work.)  From all I can tell, the Internet of Things is going to happen one way or another, and it behooves both engineers and the general public to give some thought to any possible downsides before something really bad happens.

Returning to the question of children and IoT, we are in a peculiar position these days.  Many children and young adults are vastly more tech-savvy than their parents, and this makes it hard for the parents to institute meaningful controls on what kids do online.  In the bad old days when the list of dangerous things in the home was mainly physical—guns, knives, poison, screwdrivers near electric outlets—it was a fairly simple matter for parents to keep toddlers out of harm's way.  But in the case of some toy that hooks up to your WiFi network, odds are that the parents are as clueless as the children regarding the privacy and security measures taken by the device's maker.  VTech itself didn't know how vulnerable its servers were until some enterprising hacker cracked into them and notified the media. 

Despite living with the Internet for close to thirty years now, we still have some things to learn about it, among which are new ways of using it that are potentially hazardous.  And children are an especially vulnerable population, as everyone agrees.  It's shortsighted to think of children always as the innocent parties in these matters too.  Some kids can be downright wicked, bullying others mercilessly.  Before we got so interconnected, a bully's sphere of influence was limited to the radius reachable by his fists, but hand a bully a smartphone with some sort of anonymous chatting app on it, and it's like putting wings on a wildcat.  His bullying sphere has instantly widened to include the entire globe, limited only by language ability and time.  And we have already seen instances in which Internet bullying has driven some vulnerable individuals to suicide.

Nobody is calling for a wholesale ban on Internet-enabled toys or anything like that.  But as I have often emphasized to my students in discussions of engineering ethics, many ethical lapses in the area of engineering can be traced to a lack of imagination.  When you are dealing with a physical structure like a bridge, it's relatively easy to calculate the maximum loads and find out how strong each member has to be for the bridge not to fall down.  But in any system that is intimately bound up with the behavior of people—especially millions of people at a time—your imagination has to anticipate the character and intentions of persons perhaps very different from you, who will twist your system around to serve their possibly sinister purposes. 

That is why privacy and security concerns need to be considered at the very beginning of any project that involves the Internet, and especially when a product is intended to be used by children.  VTech clearly did an inadequate job in this area, but they can serve as a bad example to warn future designers and users of IoT-enabled gizmos.  The craft of lockmaking is nearly as old as the craft of housebuilding, and for a good reason.  There are bad actors out there, and any time we open up a channel of communication involving a private citizen or residence, it needs to be guarded with the same care that we would extend to our own physical possessions.  Beyond mere technical ability, doing that well requires moral imagination, which should be in the toolkit of every good designer.

Sources:  The online magazine Slate carried the article "Parents: This Holiday Season, Do Not Buy Internet-Connected Toys for Your Kids" by Dan Gillmor at http://www.slate.com/blogs/future_tense/2015/12/03/internet_connected_toys_make_terrible_holiday_presents.html.  That article referenced a report at Motherboard describing the VTech hack and what the hacker found, which is at http://motherboard.vice.com/read/hacker-obtained-childrens-headshots-and-chatlogs-from-toymaker-vtech.