Monday, October 12, 2020

Cybercrime victim support: positive developments, growing resources (Cybersecurity Awareness Month, D12)


Thinking before you click any link in an email is good advice. But as the second full week of Cybersecurity Awareness Month 2020 gets under way, it is important to bear in mind this simple fact: all the cybersecurity awareness in the world cannot guarantee that you won't be victimized by people intent on abusing digital technology for their own ends. 

Of course, that's no excuse not to learn, and do, as much as you can about cybersecurity, but I'm sure all of us have been tempted to click dodgy email links at one time or another. And who hasn't received one of those dreaded notification emails that are sadly real: "we're sorry but your account information was exposed by a breach of our security." In other words, becoming a cybercrime victim is sometimes out of our hands. And that bring us to today's topic: what to do if you're a victim of cybercrime?

Fortunately, this question is a lot easier to answer today than it was even five years ago because numerous agencies and entities have stepped up to help cybercrime victims. A notable example in the US is the Cybercrime Support Network which runs the Fight Cybercrime website. Cybercrime Support Network (CSN) is "a public-private, nonprofit collaboration created to meet the challenges facing millions of individuals and businesses affected each and every day by cybercrime."

To help cybercrime victims the CSN website can direct you to suitable resources based on whether you are an individual or a business and what type of problem you are dealing with (the website is much easier to use than this image is to read—I made this mash-up to give you a sense of much help Fraud Support has to offer). 

There is a lot of helpful information for cybercrime victims on FraudSupport.org

CSN defines cybercrime and online fraud as "any illegal activity involving the internet, such as websites, chat rooms, email, and social media accounts." Examples include advance-fee schemes, non-delivery of goods or services, or fake employment/business opportunity scams. Basically, we're talking any crime that involves the use of the internet to communicate false or fraudulent representations to individuals and businesses. 

One of the things I really appreciate about the Fight Cybercrime site is how quickly you can find the right help when something has gone wrong. Suppose you're an individual who has experienced some form of internet-related fraud. Maybe you think someone is trying to scam you out of a deposit on an apartment. Chey and I ran into this scam a few moves ago and I'm going to blog about that experience later this week, but I wish Fight Cybercrime had been around back then. These days, but here's what you can do if this happens to you.

Go to the FightCybercrime home page and select "Get started". You will see a question—What Happened—and a series of answers, like I Lost Money and I Was Hacked. Alternatively you can choose from the Scams menu at the top of the page. If you chose Financial Purchase Scams you will be shown nine types of scams. In this example, Real Estate and Mortgage scams is closest to what you're dealing with. When you chose that option you get a page full of information about what you can do and who to contact. Furthermore you are given a systematic approach to dealing with the problem in three stages: Report, Recover, and Reinforce. Links and suggestions are provided for each stage.
   
FightCybercrime is the brainchild of Kristin Judge, a passionate advocate for cybercrime victims. And she's not stopping with online support. Her goal is to create a national cybercrime reporting infrastructure by 2021 so that anyone in the US will be able to dial “211” to report a cybercrime. Already the 211 number is ready to handle calls dealing with hacks and breaches in: Rhode Island; Kent county in Michigan; and Orange, Osceola, and Seminole counties in Florida. Check this site for more information. 

More cybercrime victim resources

ITRC: In the cybercrime surveys I have seen and done, identity theft always shows up as a serious problem, one that can be particularly upsetting to victims. Fortunately, there is an Identity Theft Resource Center, the ITRC, to which victims can turn: 

"The ITRC is a non-profit organization established to support victims of identity theft in resolving their cases, and to broaden public education and awareness in the understanding of identity theft, data breaches, cyber security, scams/fraud and privacy issues."

FTC: In my opinion, one of the most consumer-supportive agencies in the US government is the Federal Trade Commission. The FTC offers good advice and resources on identity theft. 

IC3: Another victim-friendly agency is the Internet Crime Complaint Center, often referred to as IC3. The IC3 website is the place to go to report a cybercrime of any kind. 

And this is a good place for me to add my own plug for the act of crime reporting. 

Even though reporting a crime can seem like a lot of effort, and the agency to which you report it may offer little hope of resolving things to your satisfaction, every report of a cybercrime adds weight to the argument that the government should devote more resources to cybercrime deterrence. 

I was several years into my study of cyber-criminology before I realized that a vicious cycle exists in which law enforcement folks who are eager to fight cybercrime can't get enough resources to pursue cyber-criminals because not enough cyber-criminal activity is reported, often because victims don't think law enforcement can do much about cybercrimes, which is too often true because they don't have enough resources, because not enough of the cyber-criminal activity that is happening is being reported...and so on.

So, please do report any cybercrime you encounter. Your crime report not only helps the effort to get more resources for, and more attention focused on, the struggle against cybercrime; your report might be the missing piece in a pattern that helps the authorities crack and a case and identify suspects. And of course it could the one case that convinces a decision-maker that "enough is enough" and it is time to fully fund cybercrime deterrence.

Thank you! 

Do Your Part. Report Cybercrime. #BeCyberSmart

Sunday, October 11, 2020

Cybersecurity awareness: history and the ethics factor (Cybersecurity Awareness Month, Day 11)


Encouraging people to think of cybersecurity as a shared responsibility is a recurrent theme in cybersecurity awareness programs. This probably strikes you as entirely reasonable if, like me, you think there is a clear need to establish norms of attitude and behavior in cyberspace, just as humans have done in meatspace. 

For example, I would argue that most humans today frown on things like theft, extortion, bullying, and deception for selfish or malicious purposes. In many instances, in many societies, such things are considered crimes, and traditional crime reduction programs have long encouraged consumers to "do their bit" to reduce crime (for example, I pass several Neighborhood Watch signs every time I walk to the corner store).

At the top of this article I have pasted one of the official graphics from the organizers of the 2020 Cybersecurity Awareness Month in the US. Here are three of the suggested social media messages that go along with this image, with emphasis added by me:

This message of shared responsibility has been stressed for many years. For example, here is a message from the 2014 campaign, known back then as National Cyber Security Awareness Month and referred to as NCSAM: 

Messaging about share responsiblity from National Cyber Security Awareness Month 2014

(Note that in 2014 the hashtag for cybersecurity awareness month was #NCSAM and a quick search today suggests some folks have not yet switched up to the 2020 tag which is #BeCyberSmart. However, fans of cybersecurity history can see tweets from 2014 with this search link.) 

My purpose in writing about this today, Sunday, October 11, 2020, which is day 11 of cybersecurity awareness month, is to encourage us to reflect on the fact that this theme of shared responsibility is based on several assumptions about ethics, such as: a) most people have a well-developed sense of right and wrong, and b) they are willing to apply this to their actions in cyberspace. 

Rather than delve into the validity of these assumptions—something I may do later in the month—today I just want to provide some historical perspective. To that end, please consider this statement:

During the last five years, hundreds of new security products have appeared, but hundreds of new threats have emerged. It is clear that ultimate success in the struggle to protect information depends not upon technology, but upon the development of appropriate ethical standards for the information age. 

Photo of the NCSA Guide to PC and LAN Security by Stephen Cobb, 1995
Can you guess when that was written? The answer in 1996. The "five years" to which the writer refers are 1991 to 1995. I know this because I wrote those words. They were published by McGraw-Hill in the final chapter of the NCSA Guide to PC and LAN Security* which came out towards the end of 1995. (I should point out that the NCSA in the title is not the same NCSA that runs cybersecurity awareness month—it's complicated.)

Today, I stand by those words. In fact, today I am even more firmly convinced that the development of appropriate ethical standards for the information age is of critical importance to our future. Back in 1995, I made this call to action:

We have to insist on higher standards of conduct on all sides. That means everyone, from users, who tend to flaunt software-licensing agreements, to vendors, who tend to prefer quick bucks over commitment to the user community, to CEOs, who demand growth without budgets for security and training, to employees, who don't realize that their continued employment depends upon effective security.

Thankfully, over time, I have seen numerous examples of people and organizations committing to higher standards of conduct, and enforcing them; but regrettably it appears that the world at large is still falling woefully short. The reasons for this are numerous and undoubtedly complex, but part of the problem is the slowness of our response to what I went on to say in that chapter:   

It also means teaching our kids to respect property and privacy rights in cyberspace, while providing them with educational and employment opportunities that keep them challenged (many of tomorrow's hackers will be kids whose curiosity about digital technology outpaced the meager facilities of underfunded or ill-managed schools).

Fortunately, the most recent five years has seen more attention paid to engaging young people in cybersecurity and hacking—in the best senses of that word. From established international events like DEFCON, to growing regional events like CORNCON, there has been a growing effort to encourage children to consider the implications of technology and the ethics of messing about with it. Young people can now participate in cybersecurity competitions like the US national CyberPatriot program in the US, and also a range of regional programs (see these two videos on Mayor's Cyber Cup programs and how they are empowering a diverse group of young people). 

What I did not grasp clearly enough back in 1995, was the role of governments in addressing the ethics of digital technology and the many ills inherent in the abuse of digital technology. Here's what I did say then about the need for higher standards of conduct: 

[..it] means governments and corporations setting aside the cynical exploitation of the marketplace and public opinion so that bad actions are once again seen to have bad consequences, from the top down.

Twenty-five years ago I was concerned that the abuse of technology was not being taken seriously enough, with governments failing to appropriately prosecute computer intrusions and theft of intellectual property, even as they surreptitiously adopted these tactics for government purposes. At the same time, digital products were being marketed as though they could not possibly have any downsides at all.

While I was able to imagine things going badly if we stayed on that course, and have constantly warned of the need to change course, I did not think we would so quickly arrive at a point where a man aspiring to be President of the United States could not only get away with publicly urging foreign actors to criminally abuse the data systems of US citizens, but he would actually get elected on the back of them doing so.

So, in addition to being aware of what we can do to increase the security of information systems, we need to do what we can to ensure most people have a well-developed sense of right and wrong, and that they are willing to apply this to their actions in cyberspace. 

#BeCyberSmart

* The book is still listed for sale on Amazon, but I regained the copyright some years ago to make a free PDF version available, in three parts, on this blog—the links are near the top right of the page you are now reading—mainly as an historical artifact because some of the technology discussed in the book is no longer in use.

Saturday, October 10, 2020

In praise of vendor-neutral cybersecurity awareness (Day 10 of Cybersecurity Awareness Month)

Image of empty seats in from of a speaker who has been pitching product instead of educating the audience

Raising people's cybersecurity awareness can help reduce cybercrime and increase the chances that humans will enjoy a net benefit from digital technology. You might say the goal is to help us all "enjoy technology more safely." 

That sentiment is echoed in the tagline of a security software company called ESET: Enjoy Safer Technology. This article is about the connection between cybersecurity as an industry, and cybersecurity awareness as a public good. 

In my opinion, companies that sell cybersecurity products and services should not hijack Cybersecurity Awareness Month to pitch those products and services. I wrote something along these lines a few years ago in an article on LinkedIn titled: Vendor-neutral cybersecurity education: a New Year’s Resolution. 

Before going any further I should make it clear that I spent most of the last decade working for ESET with the title Senior Security Researcher. (I left last year, as explained here, and I am now a self-employed independent researcher, quoted as such by journalists in publications such as Bleeping Computer). 

At ESET I led a team devoted to analysing threats to information systems and the data they process, then sharing the implications of their findings with the wider world, through published articles, press interviews, and speaking engagements. And here's why that is relevant: we were under orders from ESET management to do all of this in a vendor-neutral way. 

In other words, even if a journalist were to ask me, as someone working for one of the world's largest suppliers of anti-malware products, "what can people do to keep malware off their systems?" my answer would be something like "install a reputable anti-malware product." I would not say "buy ESET anti-malware." (Sometimes, if I was pushed to name reputable security products I would list several, including ESET if it had a relevant offering.)

[Disclaimer: I no longer have any financial interest in ESET, no shares, no company pension, and I don't stand to gain anything if what I'm saying here leads you to buy the company's products.]  

Quite a few of those published articles, press interviews, and speaking engagements that I referred to earlier occurred in the context of cybersecurity awareness programs, including Cybersecurity Awareness Month. Indeed, ESET was a supporting member of NCSA, the body that orchestrates Cybersecurity Awareness Month in the US, and for a couple of years I was on the board of NCSA.

Now, you could argue that ESET was only putting all this money and effort into "vendor-neutral messaging" because it helped raise brand awareness, thereby leading to more revenue. And I would agree that "educating the market" for a product is a thing. People are more likely to buy products if you can persuade them that they need them; but not all needs are the same. Educating the market takes on an ethical dimension when it involves goods and services that are necessary to protect and maintain the safety and wellbeing of society.

Many years ago I described cybersecurity as "the healthcare of IT," and I see my role, and that of companies like ESET, as protecting and caring for information technology so that it can continue to deliver benefits despite attempts to abuse it, and the forces of nature that imperil it (storms, floods, fires, earthquakes, etc.). That protecting and caring remains job #1, whoever you work for or with in this field. 

Here's real life example of what I mean. Suppose you're invited to be on a panel to talk to a group of newspaper publishers about what they should be doing to protect their operations now that they are increasingly reliant upon digital technology. I don't think you should spend your time telling the audience about the ways in which your company's security product is superior to its competitors [allegedly]. I saw this happen a few years ago and it was truly cringeworthy, not to mention utterly unprofessional. It went pretty much like this:

  • Moderator: What's the first thing publishing companies should do to get a handle on cyber risks? 
  • Invited cybersecurity expert from company X: Buy our product.

About the only good thing I can say about this event is that a whole lot of people learned—via the cybersecurity grapevine—not to invite the expert in question to speak at future events. Naturally, people like "that guy" lead organizations to avoid speakers from cybersecurity companies. That's unfortunate because companies that create and deliver commercial cybersecurity products and services accumulate valuable knowledge about dealing with cybersecurity problems. Society risks losing out when that knowledge is not tapped because information security professionals can't commit to sharing what they know in a vendor-neutral manner.

So, as you see all these messages about cybersecurity this month, bear in mind that many are put out there by companies that have security solutions to sell. That's doesn't mean the messages are not important or relevant, they may well be on point and worth heeding. Just watch for product pitches and call out those that cross the line and put profits ahead of the public good. 

#BeCyberSmart 

Friday, October 09, 2020

The Internet of Things to Get Smart About (Cybersecurity Awareness Month, 2020, Day 9)

I applaud the organizer's of 2020's Cybersecurity Awareness Month for focusing attention on the Internet of Things (IoT) early in the month. That's because, like many cybersecurity professionals, I think IoT is increasing the already enormous challenge of protecting the privacy of consumer data and the security of online activities, including online transactions. (In technical terms. IOT is increasing the number of attack vectors and expanding the attack surface, terms I will come back to later in the month.) 

To be clear, IoT is a broad term for electronic devices that use digital technology and connect to the internet but are not traditionally thought of as computers, things like remotely accessible smart thermostats and smart appliances, connected toys, home security cameras, and so on. Whether you have been turning your home into a smart home or just watching a smart TV, then you are using IoT devices.

Here's an awareness message you may see on social media this week from Stay Safe Online talking about the need to protect internet-connected devices:

Every new internet-connected device is another entry point for a cyber criminal. If you connect it, protect it. Know what steps you need to take to secure all internet-connected devices at work and home. Do Your Part. #BeCyberSmart 

And here's an article from a security software company offering tips to help secure your smart home and IoT devices. You can read another "actionable" IoT article here. 

What's the problem?

At this point you may be wondering: why are these IoT devices so risky? Well, as I said in the video in yesterday's blog post: many digital products have holes in them. These holes are technically referred to as vulnerabilities. Once a digital product is available to purchase, some people will probe them to see if they can find vulnerabilities. If they find a vulnerability, then they will try to figure out if it could be exploited for selfish purposes. What happens next depends on the finder. Here are some common scenarios:

  • A. The finder—possibly an academic, university student, security company employee, independent security professional, or freelance coder—is a responsible person so they notify the maker of the product that a potentially exploitable vulnerability exists. They may or may not receive a reward and/or recognition for this (some companies have formalized of process for this in what are called "bug bounty" programs).
  • B. The finder sells the vulnerability, and/or an exploit based on it, to a criminal (for example, to make more money or faster money than in scenario A).
  • C. If the finder of the vulnerability/exploit is a criminal they will decide when and how to monetize it based on current conditions (for example, if current email phishing scams are profitable using known exploits, they may delay use of newer ones).

What should happen and often does happen is that the the maker of the product fixes any potentially exploitable vulnerabilities as soon as they are aware of them. This can often be done with a software update that "patches" the hole. That's why you will see this #BeCyberSmart message out there:

Any device that connects to the internet is vulnerable to risks. The best defense is to keep device security software, web browser and operating systems up to date. #BeCyberSmart by turning on auto-updates. 

Unfortunately, some holes are hard to patch, particularly if they are baked into the product. A classic example is a default password "hard-coded" into a device. That is a hole that can only be fixed by changing the hardware, something that may cost more in time and effort than the device is worth. 

And of course, once a default password becomes known, criminals can use it to access and abuse the device (something that happened in the Mirai Dyn DDoS Attack of 2016 which exploited default passwords in digital video recorders (DVRs) and IP cameras).

Help may be on the way in the form of IoT Standards

Fortunately, some governments are taking action to address IoT insecurity, motivated in part by the sheer scale of the potential problems they can create. For example, the Mirai Dyn incident I just mentioned probably cost online stores millions of dollars in orders, not to mention the massive productivity hit from thousands of companies activating their crisis response teams to deal with the situation. 

There are way more IoT devices connected to the internet today than there were in 2016 when the Mirai Dyn incident occurred. By 2025, there could estimated 75 billion internet connected devices worldwide, a fix cited in this extensive UK government report on IoT security. 

The main focus of government action on IoT security right now is to establish standards, as discussed in that UK report and this IEEE article. I am not going to go into these emerging standards right now but you should know that California has already passed a law in this regard. The California IoT Security Law requires all “connected devices” sold or offered for sale in California to have “reasonable security” measures. 

And just this month, Singapore launched a new cyber security label for smart home devices. The government of Singapore hopes to have the standards behind this labelling adopted overseas. This announcement made me very happy because it is exactly the type of action that will facilitate one of the three calls to action I made in yesterday's video: use your buying power as a consumer to chose safer, more secure digital products. 

#BeCyberSafe


Thursday, October 08, 2020

3 Ways to Improve Our Chances of a Bright Digital Future (Cybersecurity Awareness Month, Day 8)


After several long, text-heavy articles, I thought I would post something more visual for day 8 of Cybersecurity Awareness Month, 2020. I decided to use video of a talk that was recorded in 2015 because the content is still very relevant today.

Somewhat ironically, I gave this talk at the 2015 TEDx San Diego which had as its theme "20/20 Vision." The idea was for each speaker to present a vision of the future, five years out, given their field of expertise. 

Now, if you are familiar with the "TED talk" concept, you know that it is not considered good form to leave your audience depressed and without hope. But if you are familiar with cybersecurity, you can probably relate to the fact that, in 2015, I was not feeling optimistic about the future, given the rate at which criminals were breaching systems and companies were ignoring data privacy principles.

Upon reflection, I decided there were in fact some signs of hope and/or calls to action that would be worth presenting, particularly if I could combine these with useful lessons that I was learning in my criminology studies and my work for a major security software company that was deeply committed to cybersecurity awareness and education (ESET).

As you will see, my talk closes with three things we can all do. As I look at these again now that 2020 is here, I can assure they still need doing.  
  • Exercise our civic rights to encourage politicians to allocate more resources for law enforcement to catch more cybercriminals more quickly. 
  • Use our buying power as consumers to chose safer, more secure digital products.
  • Strive in whatever ways we can to get more women and minorities involved in decision-making in technology.
Enjoy the video (it packs a lot into 13 minutes). And #BeCyberSmart.


 


Wednesday, October 07, 2020

Situational Crime Prevention, Security Awareness, and Cybercrime (Cybersecurity Awareness Month, Day 7)

Window with bars (thanks to Sincerely Media for sharing their work on Unsplash)

This is the second part of an article in which I relate situational crime prevention to cybersecurity awareness (the first part is here, but this article also stands on its own, or at least I think it does). 

The attitude that situational crime prevention or SCP takes toward crime is "worry less about the underlying motives of people who commit crime and focus on understanding the circumstances in which it occurs." Pursuing research with this focus, social scientists Felton and Cohen found that social, economic, and technological factors drive increases in the opportunities for crime; this led to the routine activity theory of crime which holds that: 

crimes occur when there is ‘convergence in space and time of offenders, of suitable targets, and of the absence of effective guardians’ (Felson and Cohen, 1980) 

From this perspective it is possible to develop techniques for curtailing the opportunities for crime, thereby producing a drop in crime. Over time, advocates of SCP developed this table of 25 techniques within five categories: increase the effort and the risks, reduce the rewards and provocations, and remove excuses (Cornish and Clarke, 2003).

Clearly, SCP has wide application in efforts to reduce crime in cyberspace as well as meatspace, starting with things as simple as choosing stronger passwords when establishing online accounts and using different passwords for different accounts. However, SCP can also help when cybercrimes get complex, for example when criminals use malicious code to illegally access millions of computers and organize them into botnets for nefarious purposes (including emptying online bank accounts even when they have strong passwords). 

You can see how SCP helps to fight to cybercrime in this article by my friend Alexis Dorais-Joncas, Security Intelligence Team Lead at my former employer ESET, one of the world's largest security software companies: "Doing time for cybercrime: Law enforcement and malware research join forces to take down cybercriminals" is available on WeLiveSecurity. By focusing minds on the critical triad of "offenders, suitable targets, and the absence of effective guardians," SCP still has a serious role to play in crime reduction as well as security and risk management. 

Internet Crime Losses in Billions of Dollars US as reported to IC3/FBI
Unfortunately, as the chart on the right indicates, efforts to rein in internet crime do not appear to be succeeding. (For the reasons why this chart is a valid indicator, see my notes at the end of this article.) 

Of course, you could argue that not all of those efforts are wasted since we're still making extensive use of computers and the rise in crime losses is merely a reflection of our increased use of, and reliance upon, digital technology. 

My response to that argument is four words: architecture, infrastructure, politics, and profits. The architecture of the spaces and places in which we live and work has, over the last 40 years, become less criminogenic, thanks to the influence of situational crime prevention. I don't think the same can be said of cyberspace. In fact, by the late 1980s it was clear to many technology experts that the fundamental building blocks of digital technology were riddled with holes, yet the world proceeded to build a massive global digital infrastructure out of those blocks. 

Meanwhile, politicians failed to establish norms of behavior within cyberspace, partly because abuse of those blocks can generate funds and advantage, both of which are highly sought after in politics. And of course, the demand for cybersecurity products and services has created huge profits for some companies and minted numerous multi-millionaires and several billionaires. (Disclaimer: for a short period of time, that ended over a decade ago, I was a cybersecurity millionaire; these days I am nowhere near being any kind of millionaire, except maybe in Swedish krona.)

The opportunity structure for predatory crime 

I started researching SCP to write a postgraduate essay on this topic: "The main problem with situational crime prevention is that it fails to address the root causes of crime. Critically discuss." I concluded that SCP does not even try to address the root causes of crime, but that is not its main problem. I argued that SCP cannot fully address the phenomenon of changes in society that produce new opportunities for crime at a faster rate than those opportunities can be reduced. This is the phenomenon that Felson and Cohen (1980:404) warned about in their early work on routine activity theory when they wrote: ‘opportunity for predatory crime appears to be enmeshed in the opportunity structure for legitimate activities’. Indeed, the phrase “opportunity structure for legitimate activities” is an apt description of the place where a massive and global crime wave is currently in progress: cyberspace.

Despite clear indications that the networking of computer systems greatly increases their potential for criminal abuse (Cobb, 1995), few calls for restraint in the adoption of network technologies have ever been heeded, at least on the basis of the criminal opportunities that they create. To give cybercrime some historical context, consider the 2013 attack in which 1,800 stores belonging to US retailer Target were penetrated. Thieves compromised 40 million payment card records, impacting over 100 million people (Star Tribune, 2014). By taking advantage of the opportunity that Target gave its suppliers to manage orders online, criminals earned around $54 million, based on the amount they were charging when they sold the stolen data in online markets; meanwhile, banks paid $200 million to replace compromised card (Krebs, 2014a). 

To the best of my knowledge the perpetrators of the Target hack have never been brought to justice. The politicians who promised action to angry constituents who were victimized by the attack clearly haven't  done enough to stem the tide of criminal technology abuse. This abuse generates profits at many levels, and in a rare win for law enforcement the Latvian computer programmer who designed "a program that helped hackers improve malware—including some used in the 2013 Target breach" was arrested, convicted and, in 2018, sentenced to 14 years in prison (Washington Post). 

The fact is, the failure by governments to act effectively against cybercrime in the 1990s and 2000s led to the industrialization of technology abuse. Today, many cybercrime schemes employ proven business strategies such as division of labour, specialization, modularity, and marketing, including A/B testing. Furthermore, a large percentage of cybercrime is enabled by a sophisticated system of virtual markets that facilitate the buying, selling, and renting of cybercrime tools, resources, and stolen data (Krebs, 2014b, Ablon et al., 2014). This activity is often quite brazen, as I demonstrated to a radio journalist last year (recording here and backstory plus graphics here).

Cybercrimes are often executed by ad hoc groups of geographically dispersed individuals who have been developing virtualized trust mechanisms for at least ten years (Krebs, 2014b; Holt and Smirnova, 2010). A realistic assessment of the current state of affairs is provided by the Institute of Chartered Accountants (2014): ‘there is a growing gap between business and cyber attacker capabilities … Many businesses are falling further behind and the risks are growing’.

The problem is not that SCP has been silent on fighting cybercrime. IT security practitioners regularly employ technique number one in the table of SCP strategies: target hardening. The cybersecurity concept of “kill chains” has valuable parallels in “crime scripts” (Cornish, 1994, as cited in Clarke, 2012). Some criminologists were quick to apply SCP to cybercrime (Newman and Clarke, 2003). Unfortunately, the speed at which their recommendations have been outpaced reveals the nature of the problem: it is hard to “follow the money” when today’s cybercriminals prefer to take their profits in a crypto-currency like Bitcoin that did not exist in 2003 (Bradbury, 2013). 

So I would argue that the main problem with situational crime prevention is its failure to acknowledge the following: just as crime prevention that is based on addressing the root causes of crime faces a daunting future because it requires fundamental changes in society, so too does any crime prevention approach based on reducing opportunities. 

We just don't spend enough on fighting cybercrime
Cybercrime is driven by the abundance of ‘opportunity for predatory crime’ that is clearly ‘enmeshed in the opportunity structure for legitimate activities’ (Felson and Cohen, 1979: 404). This makes it is hard to escape the conclusion that cybercrime will not be substantially reduced without either addressing the root causes of crime, or scaling back the use of cyber technology and thus ‘modifying much of our way of life’ (Felson and Cohen, 1979: 404).

I leave you with a slightly garish graphic that I made a few years ago, but which is probably still roughly correct, at least in terms of ratios (please DM me @zcobb if you have more recent numbers). The ratios between the spending figures tell me that the US government just does not grasp how badly wrong things could go if cybercrime prevention and reduction are not addressed with adequate resources. And while the US government does support cybersecurity awareness programs in October and throughout the year, there is way, way more work that needs to be done. The hockey stick of cybercrime needs to be turned into a downhill ski run towards a safer, brighter digital future. 

#BeCyberSmart  

Tuesday, October 06, 2020

Situational Crime Prevention and Security Awareness (Cybersecurity Awareness Month, Day 6)

Based on Cornish, D. B. and Clarke, R. V. (2003) ‘Opportunities, precipitators and criminal decisions: A reply to Wortley’s critique of situational crime prevention’, in Smith, M. and Cornish, D. B. (eds) Theory for Situational Crime Prevention, Crime Prevention Studies, Vol. 16, Criminal Justice Press, Monsey, New York.

On day six of Cybersecurity Awareness Month we're going to take a closer look at something that helps explain the origins and goals of security awareness programs: situational crime prevention (SCP). This is a perspective on crime that seeks to explain and reduce criminal activity by examining the circumstances in which it occurs, then curtail the opportunities for crime to recur (Clarke and Mayhew, 1994). 

Security awareness plays a significant role in the first of the five crime prevention strategies that evolve under SCP: increase the effort and the risks, reduce the rewards and provocations, and remove excuses (Cornish and Clarke, 2003).

For example, the SCP approach to crime reduction includes encouraging us not to park our cars on the street outside where we live, because that is an opportunity for car theft. Parking your car in a garage reduces that opportunity, although it's not option that is available to all car owners. Another example comes from studies that found placing gates across residential alleyways in English cities significantly reduced the opportunities for, and occurrence of, domestic burglary (Bowers, Johnson and Hirschfield, 2005). 

[Note: this article, which is posted in two parts—of which this is the first—draws heavily on an essay that I wrote as part of my master's in security and risk management. The second part of the article is here. You can see that left the academic references in the text and I have provided the source list at the bottom of the post. Also note the spelling is a mix of American English and English English, and both parts of the article are long, but hopefully you will find them worth reading.] 

The origins of Situational Crime Prevention

With its focus on reducing the opportunity for crime, situational crime prevention encourages “awareness” programs that urge the public to adopt crime-reducing tactics such “leaving outdoor lights on, putting indoor lights on timers, asking neighbors to watch your house, watching the neighborhood, reporting suspicious activity, and forming community groups to prevent crime” (Wikipedia).

The logic behind SCP can appear compelling; however, ever since it emerged from research on crime in the 1970s, objections have been raised on both practical and theoretical grounds. A notable and persistent charge levelled against SCP is that it fails to address the root causes of crime. This article examines this charge while considering the potential for SCP to reduce cybercrime. 

First, I will review the evolution of SCP, including objections raised by its detractors and defenses offered by its supporters. Then I will explore the implications for SCP of the current digital crime wave.

Rate of property crimes in the US, per 100,000 people, 1960 to 1980s
Rate of property crimes in the US,
per 100,000 people, 1960 to 1980s
As you can see from this chart based on FBI reports, a very different crime wave was occurring in the 1960s in America. A similar phenomenon was occurring in Britain: rising rates of burglary, robbery, vehicle theft, and all manner of violent crime (Home Office, 2010; Farrell, Tseloni, Mailley and Tilley, 2011). These trends caused many policymakers to question approaches to crime that had been shaped by efforts to understand criminals and the conditions in which they lived (Clarke, 1980, 1997a, 2012; Hayward, 2007). As Jeffrey (1977, 9) declaimed: ‘Deterrence and punishment are failures; treatment and rehabilitation are failures; the criminal justice system is a failure from police courts to corrections’.

In fact, the phrase “Nothing Works” began to appear in criminal justice debates after American sociologist Robert Martinson published a bleak assessment of programs intended to rehabilitate criminals in the 1950s and 1960s: ‘our present strategies … cannot overcome, or even appreciably reduce, the powerful tendencies of offenders to continue in criminal behavior’ (1974: 49 as cited in Sarre, 2001). The phrase embodied frustration with the perceived impotence of the dispositional approach to understanding why criminals offend. 

This frustration was compounded by failed attempts to reduce delinquency through welfare programs. Although Martinson recanted his “Nothing Works” assessment in 1979 (Sarre, 2001), some crime researchers were already shifting their focus from the character of criminals to the nature of the criminal act, inspired in part by an assumption that in any given situation the commission of a crime is essentially the result of a calculated decision about whether or not to offend. 

While not a new perspective – Beccaria (2008 originally 1765) had articulated a similar view of crime in the eighteenth century – the idea that offending is based on balancing ‘rational incentives and deterrence’ was given new weight by Wilson’s Thinking About Crime (1983). Analyzing the situations in which the rational decision to proceed with a crime occurs frequently was a logical next step. Manipulating those situations to reduce the frequency of crimes became the goal of SCP, which identified location, opportunity, and reasoned choices as the key elements of criminal activity. 

However, with the benefit of hindsight, I will argue that the manner in which SCP blended these elements to focus on preventing physical crimes— committed in physical spaces—obscured important implications of its theoretical underpinnings. 

Monday, October 05, 2020

Why do we need cybersecurity awareness? (Day 5 of Cybersecurity Awareness Month 2020)

As Cybersecurity Awareness Month gets rolling it seems reasonable to ask: why do we need cybersecurity awareness? The short and simple answer is that we humans need many kinds of security awareness to avoid or reduce the chances of bad things happening in life. For example, by the time we are adults, most of us have some level of road security awareness as well as physical security awareness. We teach children abduction awareness as well as personal hygiene.

We often think of these different "awarenesses" in terms of the phrases that awareness campaigns have used: phrases like stranger danger and see something, say something. 

The point is: some humans tend to do bad things, but knowing what those bad things are can help us to begin thinking about how to avoid them. And if we can get practical advice on how to avoid becoming victims of those bad people, even better.

That was the point of the "Take a bite out of crime" awareness campaign that launched in 1980 with a series of public service announcements "educating citizens on personal security measures" (Wikipedia). 

Featuring "McGruff the Crime Dog," the initial campaign was largely TV-based and proved very successful, garnering "over $100 million in free air time donated in the first year [and] reaching over 50% of adults." 

McGruff's early messages—such as lock your doors and put your lights on timers in order to reduce crime—might sound simplistic, just as the advice to "use strong passwords" sounds simplistic in the context of cybercrime today; however, a lot of crime prevention is pretty basic stuff, whether in cyberspace or meatspace. That doesn't mean it's not effective. 

Here's an example: some bad people steal cars. If you have a car and you park it in a locked garage overnight, it is more likely to be there in the morning than if you parked it on the street. That's not just a guess on my part, numerous studies have shown this to be the case. (Believe me, I spent two years studying in the School of Criminology at the University of Leicester and I've read the studies.)

Awareness of the risks related to car theft, and of ways to reduce them—for example, a steering wheel clamp will reduce the risk of theft for cars parked on the street—helps you to avoid the unpleasantness of having your car stolen. 

Equally as important in the larger scheme of things: your awareness of all these things also helps your local law enforcement agency to avoid all the work they are supposed to if your car is stolen. Just as any proper doctor would prefer there to be less illness, good law enforcement agencies would like there to be less crime, and not just because that would mean less paperwork. Think of all the good things that we could do with the money we save from reducing the number of bad things people do.

Property crimes rates in America started to drop after 1980So, encouraging the public to "do their bit" in preventing crime makes a lot of sense, and can be a  useful component in crime reduction programs, as this graph would appear to suggest.

You can see that during the 1960s and into the 70s, the level of property crimes in America started to rise quite dramatically, despite a general increase in the standard of living. McGruff' was introduced in 1980, which is where the dark side of the chart ends and the crime rates start to fall. I am NOT suggesting that this was all down to McGruff, but the timing is interesting. It marked a shift towards "situational crime prevention" programs in many communities (I will have more on SCP in a later post). 

So, will history show that Cybersecurity Awareness Month has been having a similar effect on cybercrime? 

I am sure it is responsible for preventing some security incidents, and we should continue awareness efforts. (Maybe we could enlist McGruff—we would only need to change one letter of the classic slogan.)

Unfortunately, cybercrime is not quite the same as traditional property crime perpetrated in meatspace. Some of the important ways in which computer crime differs from traditional crime were enumerated by Brenner’s landmark 2004 law journal article on cybercrime metrics (PDF). 

When things are digital they can be scaled massively, automated, performed remotely, with scan forensic evidence: one person can break into thousands of computers in a matter of hours from 5,000 miles away. Your traditional house-breaker can only burgle one home at a time, in person, and with a relatively high probability of detection, capture, prosecution, and conviction.

There is another factor that makes some digital crimes different from physical crimes, a factor that I don't recall anyone writing about: I can steal your music collection without you losing it (assuming that your collection exists as files in digital storage). As I see it, this phenomenon really messed with the emergence of moral standards around digital technology abuse in the 1990s. I would even argue that it led too many people to ignore the rise of more directly harmful crimes in cyberspace in the early 2000s.
   
So, cybercrimes can seem to be very different from, and more complex than, traditional crimes. They may well deserve their own awareness programs. But there are some serious factors in play right now that make a dip in the level of cybercriminal activity unlikely, at least in the near future. 

However, I heartily agree with Brenner when she concluded that “cybercrime is, after all, simply crime.” So, maybe now is the time to raise awareness about crime in general. After all, these days it is true to say that, in general, most crime involves some amount of digital technology. 

#BeCyberAware 
#BeCrimeAware


Sunday, October 04, 2020

Cybersecurity Awareness Month, Day 4. The week's theme? If You Connect It, Protect It

It is now Day 4 of Cybersecurity Awareness Month 2020. Tomorrow, Monday, October 5, marks the beginning of the first full week of messaging from the leading movers of the campaign (in the US that would be the National Cyber Security Alliance and the U.S. Department of Homeland Security). The theme for the week is: 

If You Connect It, Protect It

Here's where the organizers are going with this theme: "The first week of Cybersecurity Awareness Month will highlight the ways in which internet-connected devices have impacted our lives and will empower all users to own their role in security by taking steps to reduce their risks." (NCSA)

To help support campaign themes, NCSA provides sample messages for use in social media, for example: Any device that connects to the internet is vulnerable to risks. The best defense is to keep device security software, web browser and operating systems up to date. #BeCyberSmart by turning on auto-updates. 

This is good advice. Following this advice would—based on my experience—help many people to "own their role in security by taking steps to reduce their risks." This has the potential to reduce the total number of security incidents that need to be dealt with.

Of course, a cynic might point out that some percentage of the total population of people who are using internet-connected devices don't know how to keep device security software, web browser and operating systems up to date. It's a short step from there to asking: what's the point?

My view is that there's no point holding back good advice just because not everyone is well-placed to follow it. Furthermore, part of the strategy developed by NCSA over the last 15 or so years is to encourage other organizations, and individuals, to fill that gap; for example, by offering free educational materials and community programs to reduce the percentage of people who are finding this whole cyber thing difficult. Searching for the hashtag #BeCyberSafe on Twitter during October is one way to find out what is available.

A better question to ask about cybersecurity awareness than "what's the point?" is this: who is responsible for all these cybersecurity problems of which we need to be aware? I will be discussing some of the possible answers during the rest of the month. 

In the meantime, here are some short awareness videos that might you find helpful on topics like phishing, ransomware, vishing, and passwords.

Saturday, October 03, 2020

Cybersecurity Awareness Month, D3: Learning can be fun


As you may have noticed, Day 3 of Cybersecurity Awareness Month is a Saturday. That's my excuse for making this third article in my "31 days of Cybersecurity Awareness" a shorter one. (Plus, I was busy earlier today presenting my talk on "How Hackers Save Humanity" at an online event: CornCon 2020.)

Although this post is a short one, it is hopefully a fun one because it features a computer game that combines hand-eye coordination and quick thinking with IT security awareness. 

The game is part of something called Descobrim, a game platform created by my brother, Mike Cobb. One of the many cool things about Mike is that he's an ace coder as well as a Certified Information System Security Professional (CISSP).  

Mike originally developed the game to be played over the internet in a browser on a laptop or desktop computer using the arrow keys on a regular keyboard. But when he created a test version for mobile devices—played by tilting your device—the feedback was so positive that Descobrim is now an Android game, available from the Google Play store. 

You can learn about the game platform on the Descobrim website. The individual games are referred to as "exhibitions" and cover a wide range of topics—from animals and nature to food and sports—with more being added all the time. For example, here's a description of the IT Security Awareness exhibition (which was curated by me).

Each exhibition has a number of images arranged in layers which can be painted or revealed by moving tools around the screen, scoring points, earning rewards, and trying to beat the clock while avoiding hidden obstacles. 

For each image revealed there are relevant facts, useful tips, or helpful pieces of related information. This gives Descobrim considerable educational potential when combined with the very engaging game play. Here's what it looks like on my phone, where I am the player called Hexlibra, about to start the IT Security Awareness exhibition:

Playing the Descobrim IT Awareness exhibition on my Android phone

If you're interested and have an Android phone or tablet you can go to the Google Play store, search for Descobrim, and try it out today, and not just for the IT Security Awareness exhibit—there is one about Smiles that I really like (many exhibits leverage great photos shared @Unsplash, as well as Pexels and Pixabay). 

Please leave me feedback if you have questions, comments, or suggestions (messaging via @zcobb works quite well for that). In 2021, I may be revising the IT Security Awareness exhibit and/or creating new ones.

"Do Your Part. #BeCyberSmart."









Friday, October 02, 2020

Cybersecurity Awareness Month, Day Two: Basic Training


Welcome to the second day of Cybersecurity Awareness Month, 2020. The good news today is that a. it's Friday, and b. there is a lot of good cybersecurity awareness raising resources available for free, via the Internet. In other words, for any organization or individual, the main cost of raising cybersecurity awareness—and thus improving the security of valued information and the systems that process it—is time, not money. 

Okay, so there's a good case for saying time = money, but if you're the one person in your organization—or family—who is really concerned about the bad things that can happen to valued information and the systems that process it, the fact that you don't have to lay out cash to move forward with cybersecurity awareness raising efforts.

For example, as one of the world's largest and most experienced security software companies, ESET has amassed considerable expertise in communicating all aspects of cybersecurity. Company now provides a free version of its Cybersecurity Awareness Training that is well worth checking out.

Many years ago, my good friend Winn Schwartau started The Security Awareness Company. Dedicated to producing high quality materials across all types of media, the company was acquired by a firm called KnowBe4 which now offers a range of free IT security tools. and this free online course: Social Media: Staying Connected in a Secure World.

And, as I said yesterday, for traditional cybersecurity awareness information, I suggest you start with the orange Resources button on this website: Stay Safe Online. As the month progresses, I will be posting more free resources for cybersecurity awareness training programs.

#BeCyberSmart

Thursday, October 01, 2020

Cybersecurity Awareness Month: time to get smart about ending digital technology abuse

Graphic announcing 31 articles for Cybersecurity Awareness Month
.

Cybersecurity has become such an important part of modern life that many countries now dedicate an entire month—October—to increasing the levels of knowledge and awareness of cybersecurity among organizations and the general population. Here on this blog we have 31 articles about cybersecurity.

Not all of these articles will be traditional cybersecurity awareness content. Why? These days there is, already, a large amount of very good cybersecurity awareness material already out there, and even more will be published this month by companies, organizations, agencies, and experts. 

If traditional cybersecurity awareness is what you are looking for, I suggest you start with the resources on this website: Stay Safe Online. The Stay Safe Online website is run by a US-based non-profit, the National Cyber Security Alliance (NCSA). The NCSA coordinates Cyber Security Awareness Month activities in the US as well as the year-round STOP. THINK. CONNECT. online safety campaign. 

(Note: For much of the past decade I was closely involved in NCSA activities and served as a member of its board of directors on behalf of ESET, a founding member of STOP. THINK. CONNECT, and my employer from 2011 to 2019.)

On social media I will be pointing people to accounts like @StaySafeOnline and @Cyber to get the latest in this year's awareness month activities. These are being hash-tagged #BeCyberSmart (in previous years the hashtag #CyberAware was used).

For readers in the EU: "The European Cybersecurity Month (ECSM) is the European Union’s annual campaign dedicated to promoting cybersecurity among EU citizens and organisations, and to providing up-to-date online security information through awareness raising and sharing of good practices" (see the ECSM website for more).

Cybercrime Awareness Month?

If we step back a moment and ask why the world needs more cybersecurity awareness, an obvious answer would be "because there's so much cybercrime." That is why I think attempts to raise awareness of the need for cybersecurity need to include an explanation of why there is so much cybercrime. 

So, my focus this October is on the causes of cybercrime and other forms of digital technology abuse, the most problematic of the many challenges faced by cybersecurity. (Cybersecurity challenges that are not digital technology abuse include human error and acts of nature, like earthquakes and hurricanes.)

In a law journal article published at the beginning of this year I wrote: cybercrime is a global problem that negatively impacts everyone—from commercial enterprises to government agencies, non-governmental organizations, and the public—in every nation and territory. Multiple surveys in countries with high levels of Internet adoption suggest a high degree of concern that the risk of becoming a victim of cybercrime is increasing." Here is the chart that I provided to illustrate this:


This chart combines results from Stephen Cobb, ESET Cybersecurity Barometer, USA 2018, We Live Security, 2019, and EU Special Eurobarometer 480 Report on Europeans’ attitudes towards Internet security, 2019. 

Although my law journal article—Advancing Accurate and Objective Cybercrime Metrics—is written in the text-heavy format of that publication style, it does contain a wide range of statistics and sources that may be helpful if you want to research the question of how much cybercrime there is, and how the world currently goes about measuring cybercrime.

That article built on a variety of work I did about five years ago under the general heading "Sizing Cybercrime". One of the outputs from that work is watchable on YouTube in the form of a 25 minute talk with that title, recorded in Prague in 2015. There is also a 5,000 word paper to back that up, plus 50 references. Sadly, although I have managed to trim my weight a bit since then, the crushing weight that cybercrime imposes on human endeavors has only increased since then.

Small steps can reduce a big problem

The amount of criminal activity in cyberspace, that which involves computers and other internet-connected devices, may now be greater than the amount of purely physical crime in what I like to call meatspace. Yes, there are still meatspace burglars who break into houses to steal things and may hurt you if you get in the way. But the value of stuff that gets stolen from households by means of digital intrusions is probably a greater. One relatively recent academic study concluded that cybercrime accounts for “half of all property crime, by volume and value” (Ross Anderson et al. Measuring the Changing Cost of Cybercrime, 2019).

Given all those facts, you might wonder if there is anything at all that you—as an individual —can do to make a difference, to actually reduce the size of the cybercrime problem and improve cybersecurity in the world today. I am happy to report that there is, and some of the specific things that you can do will be covered during the month. 

Some of actions you can take to improve cybersecurity might sound trivial, but there is serious research that shows they work. Consider these meatspace examples: when more people park their cars in locked garages rather than on the street, fewer cars are stolen. Putting stronger locks on your doors makes your home less likely to be invaded than one with weaker locks. 

Of course those security measures imply availability of resources which are unequally distributed in most societies. But in cyberspace, some security measures are free, like choosing a stronger password to lock people out of your online bank account (covered on day 19). For example, look at the relative amount of computer effort, measured in time, that it would take to break each of these passwords:
  • mylittlepony = 3 weeks
  • mylittlepony! = 700 years
  • My1littlepony! = 200 million years
  • I adore my little pony = 42 sextillion years
If that inspires you to get to work on improving your passwords, then this blog post has been worth it (here is where I tested those passwords, and here is a good tool for exploring password strength). 

#BeCyberSmart

Thursday, September 24, 2020

A Brief History of Digital Technology Abuse: The First 40 Chapters

Digital technology, it's at the heart of modern life—our communication systems, our methods of travel and transportation, our education, entertainment, medicine, and much, much more—and it has a problem: we keep abusing it.
 

Graph of internet crime losses

You can think of this as a problem with the technology: it is inherently vulnerable to abuse. Or you can think of this as a problem with people: we keep exploiting those vulnerabilities for selfish ends. 

Either way, it is a big problem, one that keeps getting bigger.

[Insert standard paragraph full of statistics documenting the undeniable rise of technology abuse despite record levels of spending to prevent such abuse — including at least one graph to help visualize this trend and cite source—and remind readers the author has published peer-reviewed papers on this topic.]

Sadly, some people who develop new digital technology products continue to behave as though this problem doesn't exist, or if it does, it's not a big problem, and besides, it will soon be solved so that we can all enjoy the benefits of whatever new technology these people are bringing to market. 

It is for these people—the technophilic "an app can fix that" uber-optimistic, techbro' solutionists—that I have been sketching out a brief history of digital technology abuse. Here's a screenshot of the first 40 chapters:


[I apologize for using a screenshot and not a text-based table that folks can copy and paste (have you tried building a table in Blogger?). However, an easy to grab text list, in roughly chronological order, is included at the end of the article. Also, the table above should be read column-by-column, left to right, top-to-bottom.]

The idea is that each chapter in the list is a technology that has proven vulnerable to abuse. (You can play mix-and-match with these, for example, email is abused to distribute documents containing macro technology that is abused to infect personal computer systems with malicious code that abuses attached digital cameras to capture embarrassing images and threatens to share them through abuse of social media.)

Of course, you may take one look at this table and realize some technologies are missing. Indeed, you may want make your own list, and I think that's a great idea. My list is somewhat random and clearly not definitive. I don't apologize for this because a. I was in a hurry, and b. any attempt at a complete list would be too long for a brief history of digital technology abuse.

The Digital Technology Product Warning

The goal of the 40 chapter list is to challenge people to name one or more digital technologies that are not vulnerable to abuse. (To be clear, I can't think of one.) And if there are none, then I would argue that every new piece of code-based or code-enabled technology must now come with a warning, a warning that has to be included in any discussion, reporting, or promotion of that technology. The warning should read something like this:
This product includes digital technology that is vulnerable to abuse which could cause harm or injury, including but not limited to failure to function correctly, loss of privacy, and reduced security.
I am sure some people will object when governments start proposing that such warnings must appear prominently on existing products, and be included in any reporting of soon-to-be-released products. One likely objection is that: "There's no way you can prove our product will be abused." 

The counter argument is: "there's no way you can prove your product is immune to abuse, but there is a very long history of digital technology products being abused." (Insert handy reference to "A Brief History of Digital Technology Abuse: The First 40 Chapters," S. Cobb.)

Of course, savvy readers will know that many of the digital technology products upon which we have come to rely for the smooth running of our daily lives already include warnings. The problem is that these are not very prominent. Indeed, they are often buried deep within the manual. However, poke around and you will find that any product that runs code comes with a warning like this: 
This product uses software that is provided 'as is' without warranty of any kind, either express or implied, including, but not limited to, the implied warranties of merchantability and fitness for a purpose. In no event shall the supplier of this software/product be liable to you or any third parties for any special, punitive, incidental, indirect or consequential damages of any kind, or any damages whatsoever, including, without limitation, those resulting from loss of use, data or profits, whether or not the supplier has been advised of the possibility of such damages, and on any theory of liability, arising out of or in connection with the use of this software.
So, for example, the next time you go to unlock your car with your phone and find—as thousands of Tesla owners did recently—that this feature isn't working, well, too bad. You were warned. You have no legal recourse. That's just the way it is. If you check the Tesla documentation I'm sure you will find language like the paragraph above. (You might also find that the same language applies to the self-driving software—I don't have a Tesla handy or I would look myself, but not while driving.)

The point is, even a brief history of digital technology abuse should be enough to prove that humans have been developing new technologies faster than they have established appropriate ethical norms within the societies into which these technologies are deployed. I believe there is an urgent need for us humans to get serious about monitoring and controlling technology development and deployment in ways that facilitate closing the technology-ethics gap. 

We can think of this gap as: "a mismatch between the value rationality of our ends and the instrumental rationality of our means." That's a quote Phil Torres in Chapter 6 of his excellent book Morality, Foresight, and Human Flourishing: An Introduction to Existential Risks (available on Amazon and at Powell's, etc.). 

Another way of putting it comes from Swedish-American physicist Max Tegmark, as quoted by Torres: "A race between the growing power of technology and growing wisdom with which we manage it." There's no doubt in my mind that:
  • the race is on
  • it's a marathon and not a sprint
  • it's probably going to be a multi-generational relay
  • it's the most important race for the human race
  • right now we are not looking like winners
I will be returning to this topic, but for now I'm off to the mental gym to do some circuits. I'll just leave the text of the chapter list for A Brief History of Digital Technology Abuse right below here.

Sunday, September 20, 2020

The "Insider Plus" threat: what the Tesla and Twitter attacks say about the resurgence of an enduring risk

Image of logos suggesting threats are insider or outsider or bothThe "Insider Threat" to information system security is as old as computers, but in recent decades it has received less attention than external threats; yet there is reason to believe that the risk posed by insiders acting on instructions from outsiders may be on the rise; we can usefully refer to this as the "Insider Plus" threat. In my assessment, the number of organizations that are fully aware of, and well-prepared to defend against, this insider plus threat is problematically small. 

That's the short version of this article, which explores the implications of recent security incidents at Twitter and Tesla, finding them indicative of several different-but-related phenomena that suggest the insider plus risk will increase over time. I have also provided some hopefully useful background on insider threats.

Twitter, Tesla, and Three Things True in 2020

Reporting in July on the attack that resulted in the hijacking of Twitter accounts belonging to high-profile individuals and brands, CSO Online described it as: "the perfect example of the impact a malicious or duped insider and poor privileged access monitoring could have on businesses." (Twitter VIP account hack highlights the danger of insider threats).

The next month, Government Tech reported on "an alleged million-dollar payment offered [to an insider] to help trigger a ransomware extortion attack" on the Tesla electric car company. This appeared in Dan Lohrmann's extensive piece on ransomware during Covid 19 where he quotes Katie Nickels, the director of intelligence at security firm Red Canary: 

"It really changes the game for the defenders. Before today I would not have suggested companies include an insider attacker installing ransomware in their threat model. Now everyone has to shift their thinking. If we know about this one case that’s been documented, there might be more."

I'm willing to bet there have been more, if only because this type of attack is a natural outcome of three currently observable phenomena:

  1. Some organizations have become adept at defending against external attackers.
  2. Very hard times, such as a global pandemic, make some employees very susceptible to unethical conduct.
  3. The ethical status of abusing access to information systems remains vague and/or malleable in the minds of many humans.

Consider This Scenario 

You want to extort a company with deep pockets that relies on computer systems that you know you can disable with code in your possession, but the company is doing a good job of preventing external access to those systems; so you decide to get an insider to help you. There are numerous ways of doing this, including but probably not limited to: 

  • A monetary bribe: which might be particularly effective right now, given the current levels of economic hardship and uncertainty.
  • A chance at fame: which may appeal to some individuals for whom abuse of digital technologies is a sport or side gig or a form of protest (all of which can be said to be enabled by ambiguities in the ethics of technology). 
  • A promise not to reveal embarrassing or damaging information: also known as blackmail, potentially facilitated by unauthorized access to devices and accounts belonging to the targeted insider. 
Given the plausibility of this scenario, every company needs to check its approach to data privacy and cybersecurity to make sure it addresses the risk that an external attacker may "partner" with an insider. Clearly, privileged access monitoring needs to be in place and in use, but so does management's awareness that insiders may be more susceptible to breaches of IT security policy and criminal statutes during this pandemic.

Consider This Bibliography

Anyone seeking a deeper understanding of insider threats will benefit from reading insider case studies, such as those aggregated by the CERT Insider Threat Center (Cappelli, Moore and Trzeciak, 2012). The Center has documented hundreds of internal computer crimes that impacted companies in sectors like banking (Randazzo, Keeney, Kowalski, Cappelli, and Moore, 2004), information technology and telecommunications (Kowalski, Cappelli, Moore, 2008), critical infrastructure (Keeney, Kowalski, Cappelli, Moore, Shimeall and Rogers, 2005), and financial services (Cummings, Lewellen, McIntire, Moore, and Trzeciak, 2012). 

While the primary goal of the Center was to discover and disseminate practical methods of mitigating insider threats, the case studies are analysed according to academic standards; for example, methodological limitations, like the inability to generalize findings to all organizations, are duly noted (Cappelli et al, 2012). These studies reveal how a wide range of insiders exploit opportunity to commit crimes, often through a simple betrayal of the trust placed in them as employees or contractors. 

Some insiders may, like Edward Snowden (Poitras, 2014), have far-reaching “super-user” access to the organization’s assets, be they physical or digital; yet CERT has recorded many cases where the crime was committed by an insider with few technical skills and only limited access. These studies document how even limited trust can, if betrayed, enable criminal activity. It may be theorized that such betrayal, by colleagues and co-workers, chosen by management to work at the company, and of whom there is at least a minimal expectation of trustworthiness and shared interests, may have a greater negative psychological impact than the criminal act of an outsider, a person of whom there are no pre-existing positive expectations. 

As I noted in my master's degree essay—from which the preceding three paragraphs were taken—the threat of betrayal by trusted insiders is real, for there can be no doubt that the following is true: "never before have so many insiders had so much access to so much computerized information of such great value." 

Furthermore, never have there been so many ways to monetize—often at relatively low risk— unauthorized access to information systems and the information they process and store. What strikes me as particularly worrying right now is the potential for malefactors to adopt increasingly aggressive meatspace crime tactics in their quest for access to protected systems.

I will be discussing this further and providing links here.

#InsiderPlus