Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Wednesday, March 15, 2017

Overselling Cyberwar

With most of us still smarting about the Russian hacking of the emails of the DNC and John Podesta, and today's stunning announcement of the indictment of two Russian intelligence officials for the huge hack of Yahoo, cyber issues are very much in the forefront.  This is a big issue for our country, and we need to take it seriously.

One problem, however: the news media too often directs us from the real issues.  While some cyber espionage uses highly sophisticated tools, in most cases, the biggest hacks involve very simple and quite unsophisticated tools to get into our systems.  The best analogy is that we are leaving our doors and windows open.  The bad guys don't need to (and often can't) pick locks.

Evan Osnos had a piece in the New Yorker today (with the great title "How Not To Freak Out About Cyber War") that does a good job making this point:
Almost always, journalists and analysts describe the latest cyber attack as a “sophisticated” operation, even when technical experts describe them as ordinary and preventable. Ben Buchanan, a Harvard researcher and the author of a new book called “The Cybersecurity Dilemma,” wrote this week on the Cipher Brief, a security blog, that “when every case is described as unprecedented and every threat actor billed as nearly unstoppable, it fuels what I call ‘the legend of sophistication.’ The effect of such a legend is to paint a picture of a world with so many talented adversaries that practical cybersecurity is out of reach.”

In some cases, the costliest attacks are relatively low-tech. Hackers accused of working for Russian intelligence breached the Gmail account of John Podesta, the chairman of Hillary Clinton’s campaign, using an old-fashioned technique called “spear-phishing”: sending an e-mail under false pretenses to garner personal information, such as a password. Thomas Rid, a scholar at King’s College, in London, told me, “It’s like an I.E.D. In the nineties, leading up to Afghanistan, you had this expectation that the future of warfare would be very high tech, and that America would be leading because the American Armed Forces were spending so much money on network-centric platforms. But then what happened is the I.E.D. improvisation. If you drive with a vehicle that has wheels, it can be attacked. If you have an e-mail account, it can be hacked.”
 As Osnos notes, while policymakers spend a great deal of time and attention devoted to applying Cold War deterrence thinking to cybersecurity, what we really ought to be thinking about is "why don’t accounts like Podesta’s have two-factor authentication by default?”  You can read the entire piece here.


Tuesday, March 14, 2017

There is Less to the Wikileaks CIA Disclosures Than You Have Been Lead to Believe

There has been breathless coverage by the media about the CIA data dump by Wikileaks.  There is certainly a big story here.  How did Wikileaks get these classified documents?  Was it an insider? A State Actor?  But much of the coverage about the content of the dump itself is, on closer examination, less impressive than you would have thought had you simply believed Wikileaks own comments about the data dump.

Nicholas Weaver, a senior staff researcher at the International Computer Science Institute, has an interesting post at the Lawfare blog about how the media got duped by Wikileaks into exaggerating the story:
There are two real stories involving the CIA data dump by Wikileaks, neither of which is about the actual documents themselves. The first is that somebody managed to exfiltrate the data from the CIA in the first place, but the second still seems unappreciated:  Wikileaks once again successfully hacked the media, shaping discussions into deliberately deceptive ways. 
How many articles did you read about the CIA “hoarding zero days”, with “24 Android exploits”?  How many breathless pieces about how the “CIA will frame others by recycling their malcode”? That the CIA is “breaking Signal”?  Or that CIA can “spy on you through your Samsung TV”?   
How many of those stories mentioned that most of the Android “zero days” referenced were anything but, instead documentation on old exploits for out of date devices?  Or that the CIA malcode reuse is not about a “false flag” operation but instead lazyefficient programmers taking advantage of existing code?  Or that the “breaking” of Signal is equivalent to saying “I broke Signal” when I look over your shoulder as you type?  Or that the CIA’s TV bug requires physical access?  These critical caveats change the stories completely.
The problem, as Weaver notes is that many journalists don't have the technical background to evaluate Wikileaks claims, and they rushed to print before talking to real experts.  Still, there is good news here:  my Samsung TV is not spying on me.

Read the full post here.