More

Featuring fresh takes and real-time analysis from HuffPost's signature lineup of contributors
Andrew Reinbach

GET UPDATES FROM Andrew Reinbach
 

Computer "Security"

Posted: 06/19/11 09:12 AM ET

Right now, you're sitting in front of our pact with the Devil. When you finish reading this, you will do nothing about it.

The Devil is the Internet, if you were wondering. As the proprietor of this site recently wrote, the Internet opens up a world of wonderful possibilities -- possibilities we're just beginning to understand.

But since it takes us everywhere; everywhere can reach us. That includes bad guys, some of whom work for major criminal gangs or governments. That possibility's the price we pay for watching riots in Kyrgyzstan in real time if we want to.

But that price is peanuts compared with what the world's major institutions pay. Their world, kept from view, is cyberwar, 24/76.

If that sounds like science fiction, welcome to the future. Things have gotten so wild out there that just this Saturday, the Lulz Security hacker group -- which last week took credit for stealing the personal data of about 200,000 players of Brink, an on-line game -- Tweeted Sega Corp., the Japanese game manufacturer, and offered to go after hackers that had broken into its system.

"Sega - contact us," Lulz said in its Tweet. "We want to help you destroy the hackers that attacked you. We love the Dreamcast, these people are going down."

Offers like that probably didn't stream into the offices of Sony Inc., CitiGroup, the CIA, the US Senate, or the International Monetary fund after they'd been attacked in early June's wild outbreak of high-profile attacks. Those boys were probably attacked by some of those major criminal gangs or, in the case of the IMF and CIA, a government. They're on their own.

When guys like that are attacked, though, it's not just about them; it's about all of us -- the entire world, now bound together by the Internet, because when they're attacked, it means we -- or at least our accounts and personal data -- can be attacked.

And there's the rub; since the Internet's everywhere, the bad guys can go everywhere. Admiral Mike McConnell, a Booz Allen Hamilton executive vice president, is an old source of mine who's run the National Security Agency and was the second Director of National Intelligence.

"In the old days, if the Pentagon wanted to send a message to a ship at sea, it would be coded, and sent to the ship in an encrypted radio burst," he once told me. "It would be decoded and put into the Captain's safe. The chances of capturing that message or decoding it were small. If somebody wanted to get that message, they'd have to get on the ship, open the safe, get the message, and get off the ship. But now, all they have to do is break into the computer network."

Which is easy.

"Nothing is 100 percent guaranteed impenetrable," he said. "In my experience, when you are testing something to see if there is a vulnerability, you most always find a vulnerability."

"Today, with all our networking, the vulnerability does not end with the transmission [of data]," he added. "It's gone from worrying about data in motion to also worrying about data at rest," because much information is stored on hard drives. "That's where the vulnerability is."

And when Adm. McConnell was talking to me, a Silicon Graphics workstation was a powerful platform. Today there are "zombie bots", virtual supercomputers made of networks of thousands of hijacked computers that, working unknown to their owners, are rented to criminals. Given time, they can overpower any system.

Like I said: Welcome to the future. Underneath our world of everyday email with friends and associates, or reading this article, there's a shadowy world at war.

Another old source of mine once laid out just how warlike that can be. This guy, then in charge of computer security for a very large global bank, told me that every once in awhile he'd get on a plane, disembark in some obscure city, strap on a bullet proof vest, and break down a door in armed company to get at a particularly noxious hacker.

To survive in this world, in other words, big institutions are their own police in a world in which the notion of sovereign nations just doesn't apply.

When I was covering this ten years ago, you could break into any computer perfectly legally; all you had to do was operate from a country that had no laws against what you were doing -- Monaco, in those days, or Ukraine.

Nothing's changed since. Certainly, anybody with a good satellite uplink and their own electrical generators could operate today out of Waziristan, say, or a ship anchored outside the international 12-mile limit, and be almost immune from ordinary law enforcement -- since you weren't breaking any laws where you were.

Not that the people we're talking about are worried about breaking laws. This past week, somebody stole $500,000 from someone's BitCoin account. Bitcoin is a virtual payments system that allows you to make completely anonymous payments to anyone, anywhere.

When you're talking about stealing that much or more -- consider that the recent CitiGroup hack stole data about 360,000-plus credit cards -- a lot of qualms go by the board.

This is crime, folks: Would somebody stop at kidnapping the wife of some computer worker if it meant being able to steal, say, $400 million? That's how much was reportedly extorted from the City of London in the Dark Ages of computer crime -- 1996.

In that caper, a Russian gang managed to slip what's called a "data bomb" into the system of an international bank. Data bombs force computers to make mistakes in computation.

How it was done isn't known. Temp workers were suspected at the time, but it could just have easily been an employee with a kidnapped wife. Anyway, once it was done, the gang sent a "Pay or die" email to the head of security.

"Come and get me," he said. Then the gang set off the data bomb and fried a corner of the bank's overseas futures operation. Millions were lost in a flash.

Then the head of security got an email on his private laptop: ""Now do you believe we can destroy your computers?" Millions were wired to the designated account in short order. After that, the gang only had to threaten and the money was sent.

Does this mean we should unplug the Internet now and go back to licking stamps? No -- just that the world we see isn't the world that is. If a kid a few years ago could hack so deep into T-Mobile's cellphone network that he could steal Demi Moore's cell phone pictures, nothing should surprise us.

What to do? I'm not unplugging my laptop. I publish on the Huffington Post, for God's sake. I have a website. I do Facebook. I get all my news from the Internet, and email constantly.

On the other hand, I'm cautious. I have a router on my connection, which blocks most attacks. I have good security software. I don't click on mail or links from strangers. I have a dedicated bank account for doing anything financial online, keep it empty, fund it per transaction -- in person -- and never touch it with my computer. If I was smart, I'd switch to a Linux operating system -- but that's way beyond my feeble computer skills. It all lengthens the odds.

Even so, the real reason I'm relatively safe -- and so are most of you -- is because I'm nobody. Bank robbers go where the money is, so a major criminal enterprise can't be bothered with our personal computers when they can hack into a bank. Of course, if it's your account they steal; well, in most cases -- not all -- banks, stores and the rest will make you whole and write it off as the cost of doing business.

For a good look at what we're facing here, and what we can do about it, you can do a lot worse than read The New War, published by Sen. John Kerry in 1997. Kerry lays out the problems clearly and makes sensible suggestions about how to deal with a world with only nominal borders.

Anything he says, of course, is subject to attack by his enemies on the Right; but for some, that's more of a ringing endorsement than anything else.

Visit me at my website, Reinbachs Observer.

 
 
 
  • Comments
  • 25
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
RTIII
Poster of over 0.0135% of all HufPost comments
10:48 AM on 07/25/2011
One of the greatest shortcomings of the internet is the lack of the ability to send secure email.

Oh, we can send email secured within our own networks, AND we can, on our own, encrypt our messages, share the basic encryption data with our recipients, and thereby have secure email wihtin certain boundaries. However, this is not good enough, and a practical solution isn't very hard.

One key aspect of this is to separate identity from the security of the system. UNFORTUNATELY, as we have it today, many people want to combine identity and security, but I reject this; anonymity is a valuable part of internet culture and to extricate it is a mistake. AND I believe this is a key reason why we don't see a big push for encrypted email from the technologists - they don't want encrypted email if it means giving up anonymity.

The solution is to use the same encryption model as with https web servers - let the server-to-server connection encrypt exactly the same way, and _trust_the_servers, senders and/or receivers. That's ALL that is needed to have point-to-point encrypted email, but the encryption scheme must be available on the recipient's email server, and that requires cooperation. Email senders can then choose or not to accept self-signed certificates. The technology has long been in hand and I truly don't understand why it hasn't been implemented.
photo
HUFFPOST SUPER USER
JackWhistle
01:19 PM on 06/21/2011
*cough* Linux *cough*
This user has chosen to opt out of the Badges program
02:58 AM on 06/21/2011
This should serve as a reminder to never trust a computer to count votes. Even the paper ballots are counted by computer in the US.

Ballots should be counted with mechanical money counters or by hand as is done quickly and accurately by advanced nations around the world.
This user has chosen to opt out of the Badges program
02:54 AM on 06/21/2011
A computer that is turned off cannot be hacked or hijacked and has the extra benefit of saving lots of energy. Turn off your compter when you are not using it.

And beware of some of the default network settings. If you go to a coffee shop you can often see a lot of Macs on their network. These may automatically show up in the sidebar of your Finder window showing the actual name of the owner of the computer. Anybody could just drop files into their Public Folder without the owner of the computer ever finding out.

As for Linux, because of Ubuntu, it has become much more friendly and easy to use. You can get it for free at: http://ubuntu.com and it will run on Macs or Windows based machines.
As for Linux
02:22 PM on 06/20/2011
My daughter's laptop just got hit with a modified XP Internet Security 2012 build.

It was updated to plug all of the methods used to remove the product.

Luckily, I had a backup ID installed on the machine which is now allowing me the ability to install Malwarebytes and execute it, but the process has just begun.

Hundreds of millions are wasted each year by these rogue programs. It causes hours of disruption, a high cost for many who cannot figure out the resolution by themselves, or the software has to be reinstalled causing loss of data.

This new build locks down the Internet, DVD drives, all security products, all browsers, including Firefox (which two weeks ago wasn't apparently affected.

Why doesn't the government take this matter more seriously, as I'm sure there are built in keyloggers or something which could obtain passwords.
lastpost
see biography
11:08 AM on 06/20/2011
"what the world's major institutions pay"
because they won’t utilise existing techniques that could address such subterfuge. It’s like the Germans still believing in Enigma, when there were clues everywhere that it had been compromised.

"Welcome to the future."
This, isn’t the future Andrew. This is an intermediate stage. Where the old guard are having rings run around them, by those they sought to sideline. They’re merely discovering that you can’t keep the cream of the species down in perpetuity.

"This past week, somebody stole $500,000 from someone's BitCoin account."
Who carries all their money around in their back pocket? Why not load the BitCoins into a device that can only download metered amounts? Then use that intermediary to convey the exact amount to its destination. Protected by a lock, whose key is sent via an alternative route.

"This is crime, folks"
Ultimately banks make good those missing funds from their customers. If they became liable for those losses things would change, rapido.

"How it was done isn't known."
Similar to the way dealers use computers to conduct surreptitious overnight deals, to cream a few cents off thousands and thousands of accounts?
02:17 AM on 06/20/2011
There are some troubling holes in DNS and BGP, but on the whole, the Internet is not that bad from security standpoint. The biggest problem is that machines on the Internet don't uniformly support secure protocols. For example, this Web application does not support HTTPS.

The easiest way to secure the Internet is to support IPsec, which extends IP with a public key  cryptosystem for authentication and confidentiality without requiring any further support at the transport level (e.g. SSL) or application level (e.g. HTTPS). I connect all of my computers to an IPsec VPN, which is especially handy for using public open wifi hotspots.

But few public services on the Internet support IPsec, so when my traffic leaves the VPN, it has to be downgraded to unsecured IP. Otherwise the large majority of Web servers and other Internet applications will refuse my secure connection requests over IPsec.

The technology exists, but the adoption rate is too low to be practical beyond LANs.

However, the larger security issue is not the Internet protocols but rather the applications themselves and the underlying software platforms. Internet-facing applications are commonly built in low-level languages which allow arbitrary memory references, out-of-bounds array indexes, and naked function pointers, or in high-level languages which allow embedding one language inside another.

These languages make it easy to inadvertently develop software which allows malicious users to hijack the process by supplying cleverly crafted inputs to the application. The user can trick the application into loading and executing malicious code when then runs with privileges and resources of the authorized process.

If the service requires IPsec connections, it may be possible for the system administrator to positively identify the malicious user after the fact, but by then the damage may already be done. The application dropped the ball, not the Internet. 

Security vulnerabilities can be difficult to reason about while developing software, and there's a tendency for developer to reinvent the wheel (usually not so robustly). The wise approach is for a small number of developers to very carefully reason about the security implications of a set of common programming idioms and design patterns and for everybody else to color within those lines.

Certain chores like handling user input and interacting with data stores are fraught with easy mistakes, and the details should be hidden away from application developers in most cases.
This user has chosen to opt out of the Badges program
10:28 PM on 06/19/2011
The original designers of the networks and protocols that eventually grew into the Internet could not anticipate the growth of hacking technologies and groups. Nowadays conducting any sort of transaction online is analogous to sitting on the sidewalk in one's underwear with all one's belongings spread around, and then pretending that nobody notices. Those who want to see and have the means and know-how can. One good thing about the dominance of the Windows operating system is that it naturally performs the function of an anti-virus software, protecting the less prevalent systems such as Linux.
RTIII
Poster of over 0.0135% of all HufPost comments
10:38 AM on 07/25/2011
"The original designers of the networks and protocols that eventually grew into the Internet could not anticipate the growth of hacking technologi­es and groups."

Sorry, I was there; I know this is false.

"One good thing about the dominance of the Windows operating system is that it naturally performs the function of an anti-virus software, protecting the less prevalent systems such as Linux."

Thanks for that line - I needed a hearty snort this morning! It's another howler.

As apparently you haven't been aware, I'll help: Windows has throughout its entire history, from even the earliest days of DOS, has been _notorious_ as the hands-down leader in securityless computing. And yeah, I've had (way too much) hands on experience with exactly this and know what I'm talking about.

You should realize that out here in the wilds of the internet there yet remain some who are fully informed (on any given topic) and your ludicrous assertions are sure to be found out - though whether anyone posts a rebuttal is another matter.
This user has chosen to opt out of the Badges program
06:41 PM on 07/25/2011
"I'll help: Windows has throughout its entire history, from even the earliest days of DOS, has been _notorious­_ as the hands-down leader in securityle­ss computing."

That is precisely the sense of what I wrote. You should learn to pay more attention to what you read. By the way, if you claim that you have been there and know more, you have to be able to provide credentials.
09:12 PM on 06/19/2011
Everyday you read about well known companies having security breaches (Epsilon, Best Buy, Sony, etc). I don't feel that companies do enough to protect my personal info so I will think twice before providing businesses with any personal info. Everyone needs to be smart about protecting their personal data. I use this free service to send and receive encrypted emails at this secure web site: https://www.sendinc.com/
It ensures my messages are stored and transmitted securely, and that only I and my recipients have the capability to decrypt your message data.
08:27 PM on 06/19/2011
This article goes to show us two things. That finance and video gaming belong offline away from the reach of hackers.
photo
Jack Daniels Esq
Hold the ice
06:07 PM on 06/19/2011
Its all relevant as Einstein opined - we being the least so
04:23 PM on 06/19/2011
McConnell was the second DNI. Not the first. The first was Negroponte.
photo
HUFFPOST BLOGGER
Andrew Reinbach
is Grand Vizier of ReinbachsObserver.com
04:46 PM on 06/19/2011
Thanks for the correction. Text has been amended.
12:28 PM on 06/19/2011
When you write "Then the head of security got an email on his private laptop" it makes me think you don't know what you are talking about. The whole point of email is to receive communication. So getting email is no big deal - he CHOSE to read it on his "private laptop".
photo
HUFFPOST BLOGGER
Andrew Reinbach
is Grand Vizier of ReinbachsObserver.com
12:49 PM on 06/19/2011
Sorry, but according to reporting at the time in the TIMES of London--since suppressed--that wasn't the case. Even if it was, though, the message was the same--pay or die.
photo
HUFFPOST COMMUNITY MODERATOR
General Public
liberal, progressive, atheist, Democrat, SubGenius
10:23 AM on 06/19/2011
You can have computer security if you want. Have a computer not connected to the Internet. That's all there is to it. As for hackers, yes they can hack anything, but I think comparing it to war is really misguided and silly. It's just a bunch of people on computers, just like us on our computers, only they're doing something different with their computers that's illegal. It's not a war or anything. It's more of a competition, the way businesses compete with each other and such. It's like the competition in free-market capitalism or in Darwinian evolution. And hacker groups come and go all the time. Hackers sometimes get caught and sent to jail, but teenage kids constantly become a new generation of hackers, all the time, replacing the ones that get caught. But there are different kinds of hackers, white hat and black hat, with different philosophies and motivations, and many hackers actually work to protect large organizations FROM hackers. Anyway, hackers are an exaggerated threat and most of them are actually good or at least neutral, with the malicious ones just a small minority.
photo
HUFFPOST BLOGGER
Andrew Reinbach
is Grand Vizier of ReinbachsObserver.com
10:57 AM on 06/19/2011
The entire point of the story is the effect of the Internet, GP, so I'm not sure what you mean by your opening sentence, unless you're objecting to the title of the piece. As for whether it's a war; you may not consider it one, but the people fighting it do, and the people they're fighting aren't the people you spend most of your words on, but the ones in your last sentence fragment. What we're talking about are that small fraction of hackers with a catastrophic impact who you admit to--whose effect is much like the Black Swan events that crashed the economy in '08. Those guys--many but not all sponsored by nations or criminal gangs--cost the economy by most estimates billions of dollars a year, aside from the costs of that security team. In my own opinion, your argument seems to come close to asserting that since most people are law-abiding, there's no need for cops; but we all know that's not the case. So I just don't think it can all be waved away, and recent events confirm that, I think..
photo
HUFFPOST SUPER USER
Paul Andrews
How To Absolutely Secure Your Computer
09:20 PM on 06/24/2011
your computer even if not connected to the internet can become infected with a virus if you are not careful. some new usb pendrives come infected with malware. you must scan them before using
photo
HUFFPOST SUPER USER
rowdiman
Cayman Mitt: Why ya hiding your money?
09:41 PM on 06/24/2011
Is being signed off, but leaving my system on stand-by as safe as completely shutting down?
10:14 AM on 06/19/2011
Booz Allen Hamilton is up to its gills infowar and persona management.

Nice *hit piece.

Called out by the Internets.
photo
HUFFPOST BLOGGER
Andrew Reinbach
is Grand Vizier of ReinbachsObserver.com
12:10 PM on 06/19/2011
Interesting comment. Can you please expand? You could criticize Mike McConnell on many points, I think, including his intelligence background, but I've found his perspective is widely held on the white hat side; do I understand you to be saying that his perspective is somehow invalid? Why? And why is this a hit piece? Hitting what?
photo
HUFFPOST SUPER USER
Paul Andrews
How To Absolutely Secure Your Computer
09:27 PM on 06/24/2011
i read your well written article with interest. I just completed a ebook that tells you how to avoid getting hacked or infected. It is written like a picture book with the intent that the general public will be able to use and understand it. My ebook only cost 99 cents, for now, so there is no excuse for not being safe on the net.
http://dontevergethacked.blogspot.com/
photo
HUFFPOST SUPER USER
Paul Andrews
How To Absolutely Secure Your Computer
02:13 AM on 08/16/2011
Mr Reinbach i am puzzled at your no response to my comment. I still think your article was timely and well written