A cliche, but we all travel through life. I also do more than my fair share of travelling - previously principally for business but nowadays purely for my own interest and education. I plan to use this page to document some of my travels and experiences. Hope you enjoy it.
Sunday, June 30, 2019
Why you should not pay for “free” online services wih your personal privacy
The original article was published at https://ift.tt/2RLjiK2
If you are one of “those people” who respond to any discussion around online personal data privacy concerns with the statement “Well, I don’t do anything wrong so why should I care if Big Brother is watching what I do?” this article is definitely for you.
Even if you are becoming concerned after recent scandals such as Facebook’s involvement in releasing personal data about its member to Cambridge Analytica – which may have been used to influence elections on both sides of the Atlantic or you have asked Google the question “Where was I at 10:15 on 20th June 2016 and who was I with or near?” and have been horrified to find it can gve you an accurate – if not always correct – answer and are becoming aware of just how much of your personal life and private actions are known – and spread around across who-knows-how-many shady companies and organisations you may find this article interesting.
Whether you bother to read it and do anything as a result is entirely up to you – after all most of us still live in free societies and are allowed to make our own choices – for now. Of course, anyone managing to read this from within China has no such choice (See Forbes magazine article at https://www.forbes.com/sites/zakdoffman/2018/10/28/why-we-should-fear-chinas-emerging-high-tech-surveillance-state/) and soon, if democratically elected governments get their way, you will have no choice but to have every aspect and activity of your life tracked and monitored.
Let’s get a big fallacy out of the way
Most people with little to no knowledge of how computers and software work will happily take any information that comes out of a computer as fact.
This is a dangerous belief – especially when those who believe it include police, judges and politicians.
I’ll give a very simple example. Back in the 1990s I was stopped by UK police on a motorway and accused of breaching the 70 MPH speed limit by a not inconsiderable 47 MPH – in other words I was accused of driving at 117 MPH. As the car I was driving at the time was a Saab 900 whose top speed while carrying no more than a driver under ideal test track conditions was only 102 MPH – and at the time I was returning from holiday with my then young family filling every seat and the car stacked to the roof, every underfloor compartment full of a month’s worth of holiday paraphernalia – and on top of the car sat a large, very non-aerodynamic luggage box equally full of “stuff” I tried to explain that it was impossible for my car to travel at that speed – especially as at the section of road over which they said they had measured my speed I had just pulled out from behind a lorry travelling at 55 MPH after allowing faster traffic to pass.
The response from the two police officers was “Well, our computer said you were going that fast and you can’t argue with a computer so we’ll be having your licence please!“
The computer they were referring to was a device called VASCAR – a very simple computing device that calculated speed by measuring the time taken to travel between two previously entered points and as speed = distance / time the device gave an immediate readout of the speed of the vehicle just measured.
As the officers became increasingly agitated while I tried to explain to them that something was wrong I eventually asked them to show me the time and distance measurements used by the VASCAR device (a legal right in the UK) – which made them very angry … they accused me of “wasting police time – a criminal offence” and suggested they would “cart me off to the nick, leaving my family stranded on the safety shoulder of a busy motorway without protection“. Such was the strength of their belief that “computers can’t be wrong”.
There is a saying in computing circles that goes back to the dawn of the industry – Garbage In, Garbage Out or GIGO for short. Basically translated this means that if a computer is fed incorrect data it will reliably and accurately though not correctly produce faulty results.
In the case of these police officers, instead of following the correct procedure for using VASCAR which was, at the start of each shift, first to use the device to measure a known distance and correct for errors caused by tyre pressures or wear and then drive between the two points that were to be used for measurements measuring the actual distance between them with the recently calibrated vehicle – directly into the VASCAR device.
So, having taken photos of the time, distance and speed readouts from the VASCAR I wished the officers good afternoon and went on my way. Over the next week I drove back and forth along the stretch of motorway (it happened to be on my regular route to work) measuring each time the distance between the two bridges the police had used. Though my car’s odometer was neither calibrated nor particularly accurate to read my measurements consistently showed a distance approximately 40% shorter than the police VASCAR unit’s readout.
I disputed the alleged speeding offence and eventually ended up in a court to defend myself. The police were so confident the VASCAR “evidence” was irrefutable they didn’t bother to show up. Probably just as well – as armed with the photos I had taken on the day of the VASCAR readouts, some very large scale Ordnance Survey maps of that stretch of motorway and a ruler I was able to show the court that the true distance between the bridges was a staggering 45% shorter than the distance used by the VASCAR unit. One simple calculation and the truth became clear – I was actually travelling at an average speed of 64.5 MPH between the bridges – entirely consistent with the report I had given at the time. My case was immediately thrown out – followed by the quashing of fines issued to dozens of other drivers who had been pulled over and accused of speeding by the same officers on the same day – each of whom had swallowed the line that “a computer doesn’t lie – and can’t be wrong“.
I eventually learned that among this particular police traffic unit its officers had decided that the calibration of the VASCAR unit followed by a new measurement between the points to be used was too much bother by far. One officer had taken it upon himself to jot down the distance readings from his car’s VASCAR unit for all the popular “speed trap” points they used – and gave copies to all the other officers. So, instead of measuring (even vaguely accurately) the distance between the two bridges the fine wielders of authority who stopped me and dozens of other motorists that sunny afternoon simply dialled-in to their VASCAR unit a distance setting read from the sheet passed around the traffic unit. Unfortunately for them, they used the number for the wrong pair of bridges along that stretch of motorway. Hence – GIGO … their VASCAR unit spent a few hours spitting out speeding tickets to entirely innocent motorists while they applauded themselves on the fine work they were doing to keep everyone safe from idiots who cannot understand that SPEED KILLS! (don’t get me started – I’ll just say that if that statement had an ounce of truth we should all spend our lives entirely stationary and live forever).
So, if a simple computer cannot be relied upon, what happens when we scale to an AI driven monster sized computing cluster?
Simple. Not only does the same principle of GIGO apply to these machines and the algorithms they run but it has proven to be almost impossible to “train” one without even slight prejudices in the mass of training data fed in to them sending them off into quite extreme positions.
Which hasn’t stopped Google, Facebook et al deploying such machines in their never-ending pursuit of profit. As I wrote to a friend recently, the sole purpose of Google’s and Facebook’s activities is to parcel people (including you if you fall within their data hoovering clutches) into “lists” that they sell to organisations who want to sell you something, sway your political views – or target you for hate crime. Neither organisation worries itself too much over the accuracy of these lists (eg; whether an individual should actually be included or not) or what purpose they are used for – as long as someone wants to buy them.
Remember that these lists result from the private and personal data that users of these companies’ services allow them to gather after being attracted to the shiny gadgets, services and apps they provide – without bothering to read the (admittedly long, multi-page, fractured and densely legalese) contracts that say, in short (for your benefit) ALL YOUR DATA BELONG TO US.
I’ll talk about the dangers that arise from giving away your privacy in a moment. But, having established that (a) you are paying for the services you use with your personal data (b) it is worth asking – Is your privacy worth anything in monetary terms?
Last year Google earned $116 BILLION just in advertising revenue based on what it knows about you. Facebook reported revenue of $59 BILLION in the 12 months to March 2019 – an increase of 32% year-on-year – despite all the scandals that have rocked the company in the period.
So, there is part of the answer – your personal data produces ~$175 BILLION per year to just two companies exploiting your privacy. Add in all the shady data brokers and other personal data harvesters and trackers who mostly fly well under most people’s radar and your personal data and you have an industry fast approaching revenues of a $TRILLION each year – all from what these companies can get to know about YOU.
How do these companies collect your personal data?
The ways in which all data harvesting companies operate are pretty similar and well documented so I won’t repeat them here other than to add a few missing pieces that aren’t covered in most online articles.
The Pingdom article “How Google Collects Data About You and the Internet” at https://royal.pingdom.com/how-google-collects-data-about-you-and-the-internet/ and the Salon article “4 ways Google is destroying privacy and collecting your data” at https://www.salon.com/2014/02/05/4_ways_google_is_destroying_privacy_and_collecting_your_data_partner/ reveal the main ways in which your personal data is gobbled up.
If you would like to scare yourself witless, follow the instructions in the CNBC article “How to find out what Google knows about you and limit the data it collects” at https://www.cnbc.com/2017/11/20/what-does-google-know-about-me.html to discover what Google (admits) knows about you. The map that shows everywhere you have ever been since you first logged into a Google service from your mobile phone is normally enough to cause most people an attack of the colly-wobbles.
The articles linked above reveal only part of the picture of how – and how deeply – you are tracked. To understand more …
- First we must look at the apps installed on your phone. Phone operating system manufacturers (essentially Apple and Google) have been slowly forced to provide controls over the permissions individual apps have to access the sensors in your phone. These include sensors for location tracking (GPS, Wifi, Bluetooth, micropohone, inertial movement etc), listening (microphone), watching (multiple cameras) and your ID through various device identifiers. If you haven’t already done so I really recommend you check why (for example) that “free” weather app you’re so fond of needs access to you device identity, microphone and contacts.
- Shopping malls and individual retailers offer free WiFi for less than altruistic reasons. Whether you connect to it or not, your phone – if WiFi is left turned on, is constantly seeking possible connections – and in doing so exchanges one of its unique IDs (its WiFi device MAC address) with every WiFi point it comes near. These IDs are happily hoovered up by the shopping mall – and used to look you up in a database (because hundreds of personal data tracking companies know who you are and the full range of IDs inside your phone) thereby knowing exactly who is in the shopping mall.
- It gets worse. No single WiFi access point could cover an entire shopping mall so multiple access points are installed throughout the building. Altruism? Nope! Using WiFi triangulation (in short, how strong the signal from your phone is when picked up by several WiFi access points) allows the mall owner to know exactly where you are in the mall – which shop you are in or whose window you are looking at.
- So, not only does the shopping mall know who you are it knows where you are.
- It gets worse. Individual stores use several technologies to not only identify precisely who is visiting their store but precisely which department or counter they visit. These technologies use not only WiFi triangulation in the same way as the shopping mall but shorter range “beacons” that use Bluetooth, ultrasound or NFC (Near Field Communication) to identify your presence at a counter or department by “pinging” the Bluetooth receiver, microphone (ah, so that’s the reason the weather app wants to access your device’s microphone – which can ‘hear’ frequencies well outside the human hearing range) or the NFC transceiver embedded in your phone or credit cards if you have ever used one to purchase something in the store. And, if you do buy something, that purchase is recorded alongside your identity, credit card details and all your phone and credit card IDs the store can grab. All without your permission.
I could go on to talk about web tracking cookies, single pixel image tracking, screen grabbing scripts and all manner of other invasive and very nasty technologies used to steal your personal data (who you are,where you are, where you have been, who you are with, what you are doing … the list goes on and on).
But let’s just look at one more increasingly common and rightly scary technology – facial recognition.
Facial recognition – is it good or evil?
If you read the article linked at the very start of this piece about the dystopian combination of technologies used in China to control its population to almost “thought control” levels of behaviour, you will have seen that facial recognition is being widely deployed as part of the universal surveillance machine China’s government is attempting to construct.
Small problem. Facial technology in its most advanced for available today doesn’t work.
So what, you might say – silly Chinese for wasting their money.
Not so fast – there’s a lesson here which gives valuable insight into the dystopian world we are sleep-walking into. Because it is not just China that has deployed facial recognition throughout its cities – they are merely the most ambitious users of the technology.
If you live in the USA or Europe and walk the streets of any major city, pass through any large railway station or airport those “security cameras”, so ubiquitous you pay no attention to, are almost certainly connected to some form of “AI driven” facial recognition system. So, do these things do any good or should we be troubled?
I think we need to be troubled. At the moment, the technology is a waste of money. For example, in the UK several police forces have deployed the technology both statically in city centres and at events such as large gatherings (eg; the Notting Hill Carnival in London) and at perfectly legal civil protests.
Why is the technology currently a waste of money? Because it doesn’t work. The UK organisation Big Brother Watch recently submitted a number of Freedom of Information requests to police forces across the UK. Before revealing the responses take a look at what London’s Metropolitan Police (“the Met”) have to say about the technology at https://www.met.police.uk/live-facial-recognition-trial/. A nice, reassuring explanation – all for our protection.
Now for the reality. The response from the Met can be seen reported at iNews article “Met police’s facial recognition technology ‘96% inaccurate’” at https://inews.co.uk/news/technology/met-polices-facial-recognition-technology-96-inaccurate/ which also discusses some of the breaches of personal privacy (the technology currently breaches European GDPR legislation as, despite the Met’s assurance that they displayed posters wherever they deployed the technology no attempt was made to obtain consent from a single individual to having their very personal data (their face) recorded and stored in a database for up to a year or longer and one man who did verbally object to having his face recorded was arrested – but why should a police force bother about complying with the law) the technology brings.
The BBC described the use of facial recognition as “Face recognition police tools ‘staggeringly inaccurate‘” at https://www.bbc.com/news/technology-44089161 and went on to report that its use in London had incorrectly identified 102 people as potential suspects. The Met assured the BBC that nobody had been arrested but failed to mention that 102 entirely innocent people had been harassed and accused of crimes about which they knew precisely nothing.
In Wales, the police managed an even bigger result. Their system, deployed at an international football match, managed to falsely identify 2,000 people as wanted criminals. Showing blind stupidity (that beliefe that computers can’t be wrong – again!), the force blamed the poor quaity of images provided by Interpol and UEFA for the high number of false positives.
GIGO – remember? But now escalated from a potential speeding ticket to potential arrest as a known football hooligan – when all you had been doing is innocently spending some leisure time attending a football match.
So, right now I’d say that facial recognition technology is a positive danger to people simply going about their legal business and agree with UK Information Commissioner Elizabeth Denham when she said police had to demonstrate that facial recognition was “effective” [and] that no less intrusive methods were available going on to say “Should my concerns not be addressed I will consider what legal action is needed to ensure the right protections are in place for the public“.
The future of Facial Recognition technology
Facial recognition technology will improve with time. The Chinese are not being silly. Once the cameras are in place (and never mind China, the UK has more CCTV “security cameras” in operation than there are people in the entire country – making the UK the most closely watched population on the planet) and the recognition technology improves we can be tracked and monitored even if we choose to leave our mobile phones, connected watches, fitness trackers and all the other devices that currently secretly monitor us at home.
In shopping malls and stores, why bother with all that WiFi / Bluetooth / ultrasonic / NFC nonsence when a couple of CCTV cameras can do the job just as effectively.
You can have your own views about Google Earth – the zoomable views taken from satellite imagery covering most of the planet. Maybe you’re happy to show off your property to the world – maybe you object to your expensive car collection being shown to every crook on the planet. Whatever.
But, how do you feel about satellite technology that can watch you and recognise you the moment you step outside your home or place of work and then follow you in real time while you go about whatever it is you want to do. Fantasy? Read this article from the MIT Technology Review https://www.technologyreview.com/s/613748/satellites-threaten-privacy/ to understand that the technology to do just that is almost certainly in operation and it is only government restriction that prevents the necessary level of detailed imagery being made available to commercial interests. But that will eventually happen.
So, what happens when Google starts offering “Google EarthTube” or whatever they might call a live video streaming service capable of zooming into any spot on the planet?
I live in the south of France where the climate is pleasant and it it is not unheard of for people to strip off and do a bit of sunbathing in their own large gardens … (and here’s the important bit) … in full expectation that they are doing so in private. As private as if they were in their bedrooms.
What price privacy then? Will people still be prepared to behave as they wish – strip off to collect some vitamin-D? Or will their behaviour change with the realisation that millions of 15 year old boys will be watching.
Do you still not mind giving up your personal data?
If the way that personal data and a devil’s brew of personal data stealing technologies is currently being used in China – not to just keep its citizens safe from harm or combat terrorism – to actively control the thoughts and deeds including such private matters as religious beliefs and sexual preferences doesn’t scare you and the trials of facial recognition and unannounced deployment of the technology in other public spaces in democratic societies offers you no concern then please stop reading and accept my apologies for taking up your time – happy future nightmares.
Did we ask for our privacy to be taken away?
No we did not. Nor were we informed in any realistic way that it was being removed from us.
And yet it is being removed at frightening speed, without our consent and by people who don’t even understand the basic workings and limitations of the technologies being deployed – let alone what happens when the mass of data that this combination of mass surveillance (spying) tools gets thrown into a heap and some “AI” is set the task of making sense of it all – because, believe me, that data pile is far too big for any group of human minds to organise, sift through and get any “results” from.
To understand the dangers, I will examine just one tiny piece of the massive data pile and ask
Why is everyone so keen to get their hands on all my contacts?
Let’s examine what can be done with nothing more than one person’s list of contacts.
The collection of contact data is conducted for numerous purposes. First, just accept that unless you have been extraordinarily careful and vigilant with the apps installed on your mobile phone, the social media sites that ask for access to your email – or just use Google services – you and all of your recorded contacts are out there, in the wild, waiting to be used for some purpose you might never consider.
All the smoke screen of “advanced AI” and “super-intelligent machine learning” peddled by tech companies is just so much hot air and that what actually happens in their algorithms is a very crude probability matrix – as biased from the outset as the people who “programmed” it and set its parameters and you may start to understand this:
- Take a look through your contacts list – if like most people you have collected over time names and phone numbers of people you know only peripherally (your dentist, the guy that services your boiler, members of your sports club, business contacts …) ask yourself how an algorithm determines your relationships and “weighs up” the strength/value/nature of any given contact to you.
- Even if it gets access to your call history (something else data brokers are very keen to get their mucky hands on) there is almost nothing of import that helps determine the nature of your relationship with any particular contact. To illustrate, some of the most valuable (to me!) contacts in my contacts list are people I went to school with and have known for over 50 years. But these days, living far apart we have no need to talk frequently to arrange get-togethers and it’s likely that I phoned my boiler guy more often last year than I phoned any of them – in fact I doubt I called them at all from my mobile.
- So let’s look at another angle to “measure” a weighted value of a given contact. Do you appear in THEIR contacts list? Now it’s very likely that I will appear in the contact lists of friends I have known for over 50 years – and they will appear in each other’s list … a “network” is forming. But I probably get stored in the contacts list of my boiler guy – simply because I am a customer. I happen to know that I have recommended his services to several of our local friends and they have become customers. Now we have another network – all those friends are in my contacts list and in my boiler guy’s list and he in theirs. So, what’s a poor, dumb algorithm to do?
- Dive deeper, of course! Consider yourself as the root of a tree – every single one of your contacts is a branch of your tree. Now along comes a spider and spins a web connecting all the branches where their contact list contains your details. Getting a bit complicated? Nope – we’re not even started.
- When the algorithm looks into each of your contact’s databases it finds a whole bunch of other contacts that may or may not be in yours – say someone as innocent as another member of a sports club you both belong to. The algorithm sets about the task of making connections – so if another sports club member appears in one of your contacts contacts list … and he/she was once given your contact details because he/she wanted to challenge you to a squash/golf (insert your favourite sport) competition but never got round to it – a more strongly weighted connection is, nevertheless, made between the two of you.
- The algorithm is, of course, entirely devoid of the knowledge that you’ve never even met this third person.
- So … here we are, only one step removed from your contacts list and, returning to the tree picture I hope you still have in your head, we are already into n-dimensional territory (hint:just imagine the web of connections between people who pop up at random in random contact lists and the picture should appear)
- Now … here’s where it starts to get really scary …
Our (actually their) poor, dumb algorithm has a massive web of connections of people who – to the best of its witless knowledge – are somehow connected … even though it has no way of differentiating close friend from commercial service provider.
Doesn’t matter.
These companies are in the business of parcelling people into saleable groups so when an “advertiser” asks for all the people who might be interested in ex-pat financial services living in France they can sell a “list” and rake in the money. So the next task is sorting all these people and connections into groups … somehow.
So … ask yourself … “am I feeling lucky?”
Because if you ask yourself a second question – “what / how much do I really know about the people in my contacts list?” you can begin to see how the cards are stacked against you and get an inkling of an insight into the gross dangers these misuses of technology inevitably lead to. And why, whenever people stand in front of me and say “privacy? huh! I never do anything wrong so I don’t care if someone is tracking me everywhere I go, watching everything I do and monitoring everyone I know or speak to” I get an overwhelming urge to (metaphorically – I don’t have a violent bone in my body) beat them about the head until their common sense wakes up.
Danger – your contacts meet your contacts contacts!
In short, there is a very large likelihood that amongst your contacts there will be people with a criminal past. Very probably unknown to you but certainly known to the data brokers Equally, you will have contacts in your list with all manner of secret perversions and interests of the kind they wouldn’t want their mothers knowing.
So … all this data gets fed into an AI algorithm (if it wasn’t so serious I’d laugh – instead I find myself crying!) programmed (with all sorts of assumptions and biases that affect the outcome even before it has looked at its first byte of data … and it is tasked with drawing together “probabilities” (aka “likelihoods” or more simply “stabbing a guess“) at how you are connected to other people in your contacts list – and they to others in their contacts list and the n-dimensional networks that then form.
The actual task, remember, is to place you in a group that forms a list that can be sold.
So we return to the poor, dumb algorithm – which sees all these connections but has no way of weighing them up.
Bigger danger – here comes more personal data collected about you
An “AI” (actually just a bigger, more complicated algorithm) mashes up the n-dimensional contacts database with the even bigger data set that contains the data about everywhere each person (lest we forget, we are talking about living individuals here) has ever been, everything they have done, every web page they visited, every phone call they made, to who those calls were made and a “profile” (itself n*-dimensional) is constructed allegedly “describing” them, their supposed (guessed at) interests and activities in great detail – the better to form the (biggest possible – this is multi-billion $ commerce remember) list an arbitrary advertiser – or other enquirer – might be willing to pay for.
How does the AI generate the profile?
Let’s imagine that your contacts list contains (I hope unknown to you!) a paedophile. That person and their perversion is unknown to the police, their family and the community they live in. But their activity and every perverted step they take on-line is watched over by the data gatherers.
So … go back to the start. The first algorithm (that built the n-dimensional contacts list but had no idea how people were connected one to another) is asked by the “AI” ‘who else does this pervert know?’ … and your name pops up. The question actually returns an n-dimensional list (simple analogy = a 3-dimensional web – but actually in many more dimensions) which now throws up a significant number of individuals with alleged paedophilia interests. It is highly likely that you will appear in the contacts lists or have some other connection to a significant proportion of this group of people. It “follows” (see? inference = ‘proof’) that because you have connections to so many people in the artificial network known to have paedophile interests you are likely to have paedophile interests too.
Don’t believe me? Cast your mind back a few years when the game of “6 degrees of separation” was the fad of the day. Stated simply, a connection can be made between any two arbitrary individuals among the entire planet’s human population in 6 hops or less. Essentially Jim knows Sally who knows Ben … who is best mates with the President of North Korea. Fascinating game when played that way round.
Scarily harmful when used by idiots (sometimes given the name “AI machines” sometimes known as “policemen” … see https://en.wikipedia.org/wiki/Operation_Ore
Start at Wikipedia and dig away until you find out what really went on … and, sad to say, still goes on to this day. On your journey take note of the 33 innocent men who were forced into suicide and the hundreds of others whose lives and livelihoods were ruined the minute the Met Police broke their door down in the middle of the night, lost their families, saw their children snatched into care, lost jobs, homes, professions or licences to work – were largely blokes like you and me … innocent working men or professionals whose only “crime” had been to pay for an entirely innocent (I’m talking Popular Mechanics – not even Playboy) magazine subscription on-line.
In fact, just the sort of people you would expect to be ‘net-savvy and wish to read a broad range of international journals. Good upright citizens who never “did anything wrong” and would never wish to (metaphorically) harm a fly.
But bias and misrepresentation of data turned them all into paedophiles.
WRONGLY!
Of course, quite apart from the publicly judged and proven errors committed by the Met that directly led to all the suicides, broken families and ruined lives the biggest factor of all never gets mentioned.
Not a single Plod thought to apply a reasonableness test to the “Gold Mine” of data handed to them nor even question its provenance or reliability. After all, a computer had produced it so it must be right. Right?
No, WRONG! We’re almost back where we started.
The data had been found on the computer of a gang of crooks operating a money skimming scam and ONE idiot young Texas cop decided that as the skim involved charging a small amount of money through an Internet portal gateway – on the other side of which lay some very dodgy web sites – all the names identified by the credit card numbers skimmed must belong to people searching for child pornography … therefore he had a list of paedophiles! And this is how the list of ove 7,000 (mostly) entirely innocent British men was handed to the Metropolitan Police – as a list of more than 7,000 British paedophiles. The Met reacted as if all its Christmases had come at once – especially as the list contained numerous well-known public figures including entertainers, lawyers, medical professionals, poiliticians and even a few High Court Judges.
So … computer generated (in this case just stored credit card numbers) data was turned into false information – not by a computer or an algorithm – but one stoopid young Texas cop with a surplus of time and imagination and a complete absence of common sense.
Back to the AI and its profile building. Though you (I hope!) have not a single paedophile bone or thought in your body, the data brokers will happily include you in a list they are happy to sell to anyone (government or blackmailer) who comes knocking waving a wad of cash asking for a list of paedophiles. More names on a list = more money in their coffers.
Doubt me for one moment and you really haven’t dug deep enough into Operation Ore.
There is more, much more. But as we head inevitably toward a Big Brother state it’s only going to get worse.
The only difference between the actions of the Nazis and the “opposite side” Stasi that followed them – and an “AI” is that the AI reaches the wrong conclusions a million times faster.
But, hey, what’s the fuss about? The Americans have been doing this stuff for years. As long as we’re not beardy terrorists and aren’t engaged in criminal or anti-social activities we have nothing to fear. Right?
Er … what happens when someone changes the definition of “criminal” or “anti-social” (like the Chinese have done) or treats the haul of data (available to a filing clerk inside a town hall near you) in a similar manner to the trivial (by current standards) haul of “gold” handed to Operation Ore?
Did someone just mention a slippery slope?
Summary
We all do things that we consider private – things that we may take to the grave with us. It doesn’t matter if it’s as innocent as going to a specialist store to buy a present you don’t want the recipient to know about until the big day comes round or you phoned in sick and played a round of golf instead of doing the day’s work. It’s between you and your conscience.
Now, imagine a world without privacy.
How will your behaviour change when everything you do is being watched by somebody? Everything you do monitored and turned into a guesswork profile that, according to the prejudices of whoever looks at it could turn you into a criminal or sex offender or just someone who isn’t going to get that job or promotion you want?
What will your life be like when your government follows the Chinese model and start issuing “social scores” to rank your citizenship value – in the process treating you like you might train a pet, as someone who gets a bonus for doing or thinking whatever those in charge approve of and face stiff penalties for expressing the wrong view or just being facially recognised because you happened to walk close to a random protest rally? How will you celebrate when your livelihood, home and family are taken away from you because of one drunken post on social media?
How will you feel when your actions and thoughts are constrained by whoever has control of the big surveillance machine and so gets to decide what you can think or express and what is deemed unacceptable.
The level of power and control on offer by mass surveillance that robs everyone of their privacy is actually every politician’s wet dream come true. And – as is the nature of the beast – once started on the slippery slope the addictive drug of control will inevitably lead to ever more stringent definitions of “right” and “wrong”. A political party wants to stay in power. Set the machine to reduce the social score of anybody that expresses a view not in line with the party’s thinking.
Fantasy? Wake up – it’s happening today in China – the world’s most populous country.
“I do nothing wrong so I have nothing to fear.“
If you still believe that then you deserve all that’s coming your way.
Saturday, June 29, 2019
Saturday, June 15, 2019
Friday, May 17, 2019
Artificial Intelligence? Really?
The original article was published at http://bit.ly/2VxYaXQ
This (https://www.wired.com/story/guide-artificial-intelligence/) article from Wired magazine is worth a read as it explains that “Artificial Intelligence” has been nothing more than a myth from the time the term came into existence and what is actually peddled under that name is no more than machines that have been “taught” to recognise certain patterns in certain, very limited, circumstances.
There is an age-old IT industry truism that states “Garbage in, Garbage out” – the translated meaning of which is that if you feed erroneous sales figures into a computer designed to analyse sales patterns the resultant output will be entirely wrong and worthless. Following this fact it is obvious that any decision or action taken based on the machine’s output is equally wrong
In the same way, “training” an “AI” using (say) only white, male faces will cause it to develop a bias against anyone who is female, coloured or disfigured. Feed one only Bible-belt America language before setting it loose amidst today’s social media driven frenetic world and it rapidly turns into the equivalent of a far right racist as it “learns” from exposure to a broader set of inputs that other language forms exist and adds weight to “its brain” based on the algorithms it consists of that tells it to prefer language forms it comes across that are new or just appear more frequently – the equivalent of being shouted loudest or posted more prolifically on social media or being repeated or stated by people it has been “taught” carry more significance – like, say, the American President.
Microsoft had to turn their “highly advanced” customer service AI attempt off after just three days after it began hurling racist and discriminatory insults at folks who phoned it asking for their washing machines to be repaired. Microsoft’s error? It had “trained” the machine with the largest human language set available in digital form – social media posts – and the machine had happily adopted the mindset of the average social media user. The result – not pretty
There is no intelligence in these machines. They cannot see someone walking away from them in a street and “think” to themselves ‘Hey, that looks like Gary – I should go and say hello’ because they lack both the human mind’s ability to collect many orders of magnitude more “training data” from just a glimpse of the back of Gary as he leaves your house after a dinner party. Or facially recognise Sue from an 80% rear angle because you once saw her turn her head away from you to talk to someone else across a dinner table, revealing the full gamut of her profile right to the back of her head.
“Intelligence” (in just this most limited field) is the mind’s ability to take that glimpse you once had of someone called Sue and use imagination to “join the dots” and play probabilities that tell us that a view seen at 82% rear or 25% side of the opposite side of a head glanced at random in a busy street is the person called Sue – and instantly fills in not just everything we know about Sue (marital status, kids, parents, relationship to you, job …) but emotional values – do you like her, agree with her politics, want to say ‘Hi’ or walk in the opposite direction hoping she hasn’t recognised you!
The simple fact is that current computing technology can do some things incredibly fast (as perceived by the human brain) but when tasked with jobs that require the simplest imagination or emotion fall at the first step.
There’s a Nobel prize waiting for the first person who can explain what “imagination” or “emotion” even is – let alone develop an algorithmic expression that enacts it
Artificial intelligence does not exist. And, if it ever does, is many, many lifetimes in the future. It requires technology as many unknown orders of magnitude removed from today’s technology as our pocket computer marvels and massive computing clusters are from Alan Turing’s first postulation of the Imagination Game
Why is this important? What dangers does the current belief in AI cause us all?
Just this week, the London Metropolitan Police has responded to a Freedom of Information request with the startling news (to anybody who doesn’t understand any of the above) that in the entire time (years!) they have been busy running facial recognition technology against the millions of citizens daily going about their lives across the UK’s capital city just TWO “criminals” have been flagged by the system – one accused of non-payment of a parking fine (falsely as it turned out – he had the bank records to prove the fine had been paid) and another who was sought as a non-cooperating witness in a case the Met had dropped for entirely unconnected reasons more than a decade earlier. Of terrorists and members or organised criminal gangs or extremist protesters the system identified not one.
And … the Met had to write down the slightly embarrassing admission that 98% of faces “recognised” by the system turned out to be completely wrong. The wrong person entirely.
A fact that hadn’t deterred the ever vigilant Met from going out and harassing several thousand entirely innocent people who knew absolutely nothing about the crimes the Met was accusing them of being involved in.
On the simplistic belief that if a computer says something is true then it must be so.
Clearly those running the Met and other police forces and intelligence services round the world learned nothing from Operation Ore (cf; https://en.wikipedia.org/wiki/Operation_Ore and https://www.mintpressnews.com/operation-ore-how-sloppy-work-by-the-fbi-and-the-press-led-to-suicides/240277/) – or the hundreds of similar scandals where “2+2=99” has been fed into a computer and the resultant nonsense that comes out the other end is swallowed as gospel.
Hence my statement that the only difference between a bored Texas cop and an advanced “AI” machine is that the machine gets to the wrong conclusion a million times faster.
Read the article – I don’t need to explain any more.
Latest Intel CPU security flaw – what to do about it
The original article was published at http://bit.ly/30qyKiG
In the past few days news has come out that a major flaw inside every computing chip (CPUs or Central Processing Unit) produced by Intel since 2011 contains a major security flaw that would allow hackers to gain access to even the most security-essential data inside your machine (eg; passwords and security certificates you probably don’t even know about, even less think about) without leaving a trace.
The article at https://lifehacker.com/how-to-protect-your-pc-right-now-from-intels-latest-vul-1834779884 explains the flaw and how to avoid falling victim to it – actually just upgrade your devices as every OS supplier has already “fixed” the vulnerability in code. The article provides instructions how to upgrade all the “mainstream” operating systems (the author obviously finds Linux too baffling). As ever, the article includes links that will eventually lead you back to the PR release issued by Intel that in usual fashion confesses their sins.
To anyone running Linux – good news: Linux was updated long before this flaw became public knowledge but just to be safe and sure that you are up-to-date, open a terminal window or command line and enter the command depending on your distribution:
For Debian based versions (eg; Ubuntu, Mint …)
sudo apt update && sudo apt upgrade
then press [Enter] and enter your usual login password when prompted.
For older RHEL (Redhat) based versions (eg; RHEL, Centos less than v7)
sudo yum -y update
then enter the root password when asked – which will ensure everything is up-to-date without further prompting. Wait until the process is finished (command prompt reappears). All is now well.
For newer RHEL (Redhat) based versions (eg; RHEL 7, Centos 7, Fedora)
sudo dnf -y update
then enter the root password when asked – which will ensure everything is up-to-date without further prompting. Wait until the process is finished (command prompt reappears). All is now well.
On all the RHEL based releases is you are unsure of the operating system version in use no harm will come from trying the yum or dnf commands – either the correct command will be automatically substituted or you will get a command not found message – so just use the other version.
Important reminder
To everyone – as ever, don’t click links in emails (even from people you know) unless you know the links destination is somewhere safe – note that I never send a link like this but always like this (https://www.google.co.uk) because the first form obfuscates the link destination (hint: hovering a mouse over it should reveal the link URL in a proper email client but good luck trying to reveal where it leads if using a mobile phone or tablet) – while the second form displays a link in plain sight. If in doubt (you probably shouldn’t use the ink anyway but if you feel you must – eg; the link is in an email purportedly from your bank and you want to check all is well) either load the desired page by typing the normal, known home page URL into your browser and finding the supposed link page or copy the displayed text … not the link and paste that into your browser to see if the page exists on the real site.
BUT the basic remains true DO NOT CLICK any link unless you can trust the source 100% – because I can present a link like this https://www.google.co.uk which actually takes you somewhere entirely different (don’t worry – my example is safe – I have no ill intents on your computer or data – but ask yourself every time you see a link from someone who might not be so benevolent – especially if it looks oh so enticing).
Stay safe out there, people!
Thursday, November 22, 2018
Internet Security – Part 5: Installing better locks
The original article was published at https://ift.tt/2PJjlZ0
What can be done to improve security?
So far this article has focused on the problems with the security of Internet facing IT systems. I hope it is obvious to all that much needs to be done to improve the entire landscape from the way that users authenticate their access to sensitive systems through to the responsibilities of companies and organisations to respect and safeguard personal data and possessions with which they are entrusted.
So, the truth is that much can be – and arguably should ready have been – done to improve data security on the Internet.
When reading the outlines below, please bear in mind that the information is presented back-to-front. The reality is that no single software developer – or even a company’s IT director – can implement a “security first” systems design and operation approach as is needed to deliver secure systems operable on the Internet.
The impetus and instruction for the changes necessary to improve the security landscape must come from the top. For smart companies that means the boards and directors taking the time and trouble to learn this “difficult techie stuff”to at least the level necessary to know the questions to ask and how to evaluate the responses received. Personally, I believe there is commercial advantage to be had to companies that can promise true security to their customer base.
Ultimately, the final top-down effectors of change are governments, both national and supra-national. If companies and organisations fail to get their acts in order to prevent the current volume and scale of abuse of personal data seen on the Internet then they must expect that laws will be enacted to enforce the necessary changes. Complaining about such legislation has all the effect and moral rectitude of arguing that of course you don’t have a driving licence after being involved in a traffic accident – after all you are entirely competent to decide for yourself your competence to drive a car as other road users reasonably expect. In the same way, arguing that you should be left alone to safeguard and do whatever you want with your customers’ personal data carries no more weight.
In simple terms, change must be driven from the top. In an ideal world, company boards would become proficient in IT matters and enact the necessary changes. In the real, practical world we inhabit I suspect that companies will only change when external forces – market expectations or a legal framework carrying truly painful penalties – force change.
Technical changes
The design, construction, deployment and operation of commercial IT systems is such a diverse and complex area that it is impossible to do more than cover some general principles in an article such ast his. There is, I believe, one principle that should be kept in mind by anyone responsible for the design or implementation of a complexIT system – that principle is the concept of control.
What do I mean by “control”? Simply the degree to which you can retain control over components of the system being deployed. There is a modern trend to treat complex IT systems as mere collections or assemblies of building bricks – the idea being that a complex system is built by combining the “best in class” component specialist sub-systems.
So, we see systems constructed out of some supplier’s accounting system, another’s inventory system, another’s customer support system, another’s marketing and customer relations system, an off-the-shelf customer engagement system based perhaps on a blogging platform “repurposed” for the need …. and so on.
Systems that are cobbled together like this represent the worst examples of expediency over long-term usability and control. Actually more expensive to put together (every component must have individual interfaces to other components with which it must share data or processes). Data is spread around like confetti between different, competing databases – each of which must be updated and kept instep with one another in real-time if anarchy is not to quickly arise. More purpose-written processes to develop, test and maintain. In production, such systems quickly become a nightmare to maintain as different components develop and require interface changes to schedules determined by their developers – the alternative being to continue use of now outdated versions with the security and reliability implications that involves.
It should be obvious that the costs and complexity of managing such systems destroys reliability while harming control enormously.
Put simply, organisations that use this approach to complex systems have no effective control – they are entirely reliant for the reliability and security of the overall system on the individual component suppliers – and their own ability to keep pace with changes required to the purpose-written interfaces between the components.
A simple piece of advice – understandable by the least technically proficient company director – complexity is the enemy of control. If you seek a system whose security and reliability you can control –keep it simple.
System design
The lesson here is simple – the design of systems must be driven by a “security first” culture. Every function, operation and change to the design of the system must be subject to consideration of its impact on the security of the system and the data it holds and processes.
It is important to understand that prioritising security need not negatively impact either the usability of the system or its flexibility and ability to adapt to an organisation’s developing needs.
All design / change decisions must pass a security review to assess what impact may occur to either/both the attack surface of the overall system and the potential to open exploits to directly affected system parts or – indirectly – by granting access to other privileged data or functions. Only after this security assessment is successfully passed should the design be passed forward for development.
Such an assessment should never allow an authentication system such as that deployed by Credit Agricole to ever be developed, let alone deployed for live use. Equally, had Facebook conducted full and proper assessments of the developer interfaces it introduced (driven by the desire to gain more users by enabling outside developers to develop widgets that would drive user engagement on the site …which inevitably involved exposing at least some user data to the interface) the ability to abuse the interface to elevate permissions in order to gain access to personal data sets that were not part of the intended design should have been recognised and the detailed design altered to prevent such abuse before development began. A day of consideration and reflection saves weeks of a CEO having to testify before government committees and courts.
When considering the security implications of any design decisions itis essential that he normal developer mind-set of “this will be great/exciting/fun” must be put aside in favour of a mind-set that puts the assessor in the mind of someone trying their hardest to attack or abuse the system. While the role requires a level of technical proficiency at least as high as that of a good developer the role should go to someone versed in “white hat” hacking –ie; trying to penetrate a system in an ethical manner in order to identify and report flaws capable of exploit in order that they can be addressed before being released to public risk.
System change management
All systems must be capable of change and adaptation over time to continue to meet the evolving needs of the organisation they serve.
However it is vital to recognise that the area of system change presents perhaps the greatest risk to the reliability, safety and security of a running IT system.
I have seen organisations where the marketing department has been allowed to simply demand that the IT department (and its system developers) implement or install some new function or technology that the marketing department “needs” – usually right now! The result quickly becomes a web site full of third party originated scripts whose working nobody can explain and after only just a few weeks nobody can remember why they were implemented or what purpose or internal process within the organisation they enable. To say that this way of working presents an enormous security risk is an understatement of such proportions I shouldn’t need to be writing it. Yet the practice can be seen plainly by anyone capable of calling up the code behind any web page and scrolling through counting the number of such scripts and odd code included. In the worst cases I have seen organisations that have deployed session replay technology (the most invasive personal spying technology currently easily available to web site operators) presumably because the marketing department “needed” to see how users were interacting with the website … quickly implemented without a single thought given to the harm caused to site visitors and the exposure to legal risk the organisation was being put to.
No matter how great the “need” or how urgent the desire to support / release some new product or service might be, system change is system change. ALL system changes must be subject to the “security first” mantra and be put through the same assessment process as any other change proposed to the system.
System operation and management
As already described, having even a perfectly secure system design gains precisely nothing if the system is then operated in a slap-dash way.
Many people (board directors, time to perk up – I may have you in mind here) fail to realise the amount of work required to keep a system up and running on the Internet 24/365. The absolute need for company boards and directors to understand how these complex IT systems work is covered below. For now just understand that even a simple website compromises an underlying operating system, web server software, database management software, and a panoply of web, server and client-side programming languages – oh, and let’s not forget the code that actually makes a web page display on a web-site visitor’s device.
All these layers of software and data are individually complex and all must be regularly backed up, maintained, occasionally restored both as individual components and as a whole.
When, say, the underlying operating system must be upgraded (see the section “System maintenance” that follows) the likelihood is that the server running the entire system must be rebooted –meaning that the website goes “off air” while the machine is restarting and, more importantly, any customers or visitors using the site will experience service interruption. In practice modern websites do not run on a single machine but on closely connected clusters of (usually virtual) machines that distribute the load placed on the service being provided, place sensitive services (such as the database) inside a network inaccessible from the Internet and allow individual machines to be updated or otherwise serviced without interrupting continuity of service to visitors.
It is important to understand that the majority of Internet services (eg; web-sites as being discussed here) are actually run on “virtual machines”. A virtual machine (“VM”) is simply one instance of a“machine” that is running (usually) alongside other virtual machines on a single physical computer server. Several technologies (which are outside the scope of this article) can be used to deploy virtual machines but the benefits of VM technology are several and bring many benefits including:
- Cost reduction – a single physical server can run a number of virtual machines and make better use of the processing power available
- Backup – the “state” (ie, a snapshot of everything the VM is processing and all the data it possesses) can be taken in a very short time and without interrupting the machine’s operation
- New VMs can be created or destroyed at whim – if more processing power is required for example or a replica of a machine is required to test an upgrade or other new software a new VM can be created or copied very quickly – then used and destroyed when it is no longer needed
- The individual functions required to operate a website (eg; a web server and a database server) can be placed on separate VMs and segregated so that access to the web server is possible from the Internet while access to the database is only possible from the internal network – helping to prevent bulk data loss or breach
- In case of physical hardware failure or upgrade need the VMs running on that piece of hardware can be quickly or even seamlessly be moved to another physical machine allowing the first to be maintained
Like all technologies VM technology can be a double-edged sword. The same ease that allows a VM to be replicated, backed up or new VMs to be created at whim if not properly managed can lead to major problems.
Many cases of software update or change involve structural changes to configuration files or entire database structures. One of the (so far unsaid) benefits of VM technology is the ability to easily roll back a system to an earlier state – something that may become desirable in the even of data loss, system corruption or upgrade failure for example. But sometimes this alone is not enough to allow a security blanket in case something goes wrong during or after an upgrade. Take the example of a software upgrade that requires structural change to a large database. Sensible practice would be to take a complete copy of that database before making the structural changes – that way, should the upgrade fail in some way the original database can be restored and the state of the VMs that use it can be rolled back, restoring the use of the system while the problem of diagnosing and correcting what went wrong can be dealt with.
The next thing to understand is that many of the physical servers that run all the VMs are no longer present in data centres on an individual company premises. With the rise in popularity of cloud computing the likelihood is that these VMs exist “in the cloud”. In real word terms this means that a VM may as easily exist in a datacentre in Phoenix as Strasbourg, Dublin or London.
Data storage can also be virtualised in a similar way to a machine. So that database – which might occupy several Terabytes of storage is just another instance located somewhere in the cloud. And whereas in the days of real machines and proprietary company data centres a company would have to invest in some multiple of the actual storage capacity it needed to operate its IT services in the age of the cloud if a quick copy of a database is required during a system upgrade the answer is to simply create (a possibly better term here is “rent”) another storage instance of the required size, duplicate the data tot hat and just destroy it as soon as it is no longer needed – much more cost-effective.
Here comes the cutting edge of the sword. If the operator who creates the new storage instance omits to secure it (by setting passwords and ensuring it is inaccessible from the Internet for example) … then the entire database contents become publicly available.
As organisations right up to the super-secret American NSA have discovered to their cost this kind of simple, human error makes all the work put into securing operational systems worthless as the data is gratefully hoovered up by “the bad guys” in an instant. And a major data breach just occurred.
System operation and management – the right way
Having looked at how modern web sites or services actually exist and are delivered in practice and having identified some of the horrific consequences of making simple human errors how does an organisation preserve its security and protect itself from such horrors?
The answer is to go back to lessons I learned at the dawn of commercial data processing when giant mainframes the size of power sub-stations (but with less processing power than the phone in your pocket) ruled the computing universe.
Answer: Procedure manuals and check-lists.
It really is that simple – backed up, of course, by management oversight that ensures those procedures and check-lists are followed and adequately recorded to enable every process to be audited … and a corporate policy enshrined in employment contracts that defines failure to follow a defined procedure and rigorously complete each check in an auditable manner as an example of gross misconduct possibly leading to demotion or instant dismissal.
If that sounds simplistic and drastically harsh may I suggest you spend a day as a ‘fly on the wall’ inside a modern IT operations centre – and observe the young techies fingers fly over keyboards connected to multiple machines behind which lie dozens or hundreds of VMs gleefully displaying their advanced skills by “spinning up”and destroying VMs at whim and moving major datasets around with no more effort than offering a toffee from a jar.
All unrecorded and all subject to a single finger-slip that either destroys the live dataset – or puts a copy out on the Internet with no protection at all.
The experience should suffice to illustrate the need for procedure manuals, check-lists and good old-fashioned accountable management.
At the same time, adequate emphasis must be given to staff training.
- Training on the essential need to follow procedures
- Training on understanding the relationship of trust between an organisation and its customers – and just how important and valuable that trust relationship is to both parties
- Training on adopting a “security first” culture – to both customer data and the organisation’s own data. No organisation should have a single member of staff that might fall for a human exploit – whether fake email phishing scam, phone call from IT support or click of a link on a dodgy (or, sadly, even reputable) web site.
System maintenance
I understand and support a company’s decision to base its services on an enterprise class operating system (such as Redhat Enterprise Linux or its open source variant Centos) rather than a leading edge, frequently updated variant such as Fedora, I do not understand corporate IT policies that insist that every little operating system patch must be subjected to its own extensive testing before installing it on their live systems. Do they not understand that (especially in the open source world based around Linux) every patch and software update has been exhaustively tested thousands of times on thousands of different hardware configurations before it hits the live release channel?
In these times of increased security bugs and flaws – never mind the fact that other software that may be updated contains bug fixes and performance improvements this behaviour makes absolutely no sense.
For over a quarter of a century I have run a mix of enterprise class and leading edge systems. All my machines are updated at least once every day as new software updates become available. In over 25years I can recall two instances where a nightly update has caused a problem. I defy any corporate entity that operates a deferred patch deployment policy to tell me they have suffered as few outages over a similar time period.
Simple fact: by the time a security patch is released knowledge of the underlying bug is already public knowledge and hackers will be busy trying to find machines that have yet to be patched. Remember those tens of thousands of attack attempts our little network see off each day? They represent hackers trying to probe our network and servers for known vulnerabilities – windows and doors that have been left unlocked.
On a balance of risk-benefit the benefit is clearly in favour of installing at least security related patches as soon as they become available. Not to do so invites systems to be compromised, corrupted or taken over by malicious actors.
Keeping a system up-to-date is only part of the maintenance job. An equally important function is …
Keeping abreast of the technology
As the CA example shows it’s just not good enough to install the current “best-in-class” security and forget about it.
The technology and IT security landscape is constantly changing.
As an analogy, developing and operating a secure web-site today is more like building a physical bank – then knocking it down to rebuild a more secure version every few months. That is assuming that steps have been taken to avert urgent threats as soon as they arise.
An essential requirement of maintaining a complex commercial web-site is to remain abreast of the technology and threat landscape to ensure that the web-site remains both relevant to its users and its owner and as safe as it can possibly be from external attack.
Any company director, banker or accountant should be familiar with the concept of depreciation – in short, the recognition that any asset has a finite lifetime by which it must be replaced if the job it has been doing is to continue. IT systems are not immune from this concept. Yet companies insist on treating their IT systems – in particular their Internet facing systems – as if they were old fashioned bank buildings. A construct that is built and then expected to last 50 or 100 years with only a new lick of paint every 5 years,a change of locks every 10 and a new vault every 20.
Modern computer systems depreciate (their fitness for purpose) far more rapidly. Companies need to learn that their Internet facing IT systems should be completely rebuilt at intervals of between 3~4years within which period they must be constantly updated to remain safe and secure.
In the past ten years (a period which has seen no major improvement in physical door-lock technology that I am aware of) has seen
- the fundamental way that Internet users view and interact with web-sites shift from desktop (or large screen) devices to new form factors – to the point that today most web-site visitors view those web-sites through tiny mobile phone screens – in portrait format rather than the landscape format of old. We are now seeing the rise of voice technology. Soon, users will expect to have no screen or display at all – they will simply ask a device in the corner of the room (or their car, their watch or their house …) to tell them their current account balance or to transfer money to pay a bill. The technology to do this is available now – the challenge for systems designers is to deliver the desired functionality while maintaining watertight security and proof of identity.
- FAR, FAR more important changes happen on the technology plain.
- Advances in computing power have meant that security algorithms and mechanisms that were considered safe a decade ago can now be cracked in a few seconds. Still the second most commonly used password in use is simply “password” (the most common in 2017 was – if you can believe it “123456”!!).
- If encrypted using the still commonly used MD5 algorithm (supposedly one-way – ie; once encrypted with MD5 it should be impossible to decrypt the original text) “password” is cracked in less than 3 seconds (most of which is the time it takes to communicate back-and-forth with the website over my satellite based Internet connection) using the website https://crackstation.net/ – if you’d like to try yourself, the MD5 ‘hash’ (the encrypted form of “password”) is 5f4dcc3b5aa765d61d8327deb882cf99. Even a highly uncommon password within which certain letters had been replaced with numbers was cracked in no more time. In passing, this is because so many websites have leaked so many passwords alongside their encrypted hash values – so, saying that this website is ‘cracking’ the password is not at all true – it is simply looking up the hash value in a database that contains previously obtained hash values and their original values. But even where no database entry is available, current computer hardware can actually crack an MD5 encrypted password within times ranging from a fifth of a second to around 20 minutes for a complex, 12 character password.
- Information on the current best-in-class encryption algorithms and even instructions on how to implement them with most common web programming languages can be found at https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet – so there really is NO excuse for not implementing or updating better security. Most encryption methods used to store login credentials are of the one-way kind – ie; the original password or other encrypted text cannot be recovered from the encrypted value as there is no key. Instead, at login, the credentials entered are encrypted anew and the encrypted values are compared to the stored values. The “penalty” when a one-way encryption algorithm is changed is that, as there is no way to recover a user’s original plain-text password, the user must be asked to choose a new password. This is good practice in any circumstances and allows the requirement for complex passwords to be imposed at the same time. For sensitive sites (such as on-line banking) this is far from an unreasonable step to take – far more reasonable than allowing the site to remain vulnerable where user credentials have been exposed by data breach (even by another site – users, despite all the warnings, will insist on using the same password to login to multiple sites) or the algorithm currently in use is likely to become unfit for purpose within a year or two.
- The language in which web pages are written (HTML) is now at version HTML5 and operates in a totally different way from the version in use a decade ago.
- The threat landscape (the number of “doors” through which an IT system might be attacked) has grown exponentially. Coupled with the equally exponential number of mechanisms “lock-picks”) that might be used the entire structure of a commercial web-site and the way its components are opened or restricted from the web has to be rethought and systems redeveloped to take these factors into account.
Simple steps to maintain system security
In summary there are just a few simple steps needed to maintain the security of an Internet facing IT system:
- Apply software patches and upgrades as soon as they become available.
- Keep up-to-date with changes in at least the key technologies used to defend the system and its users from attack – at minimum these changes include encryption algorithms, programming languages, database engines and other key components.
- Regularly check all third-party scripts that are embedded in delivered web pages. Simple rule – the more third-party scripts you allow into your system the less control you have over its security and the safety of your customers – as you never know when a third-party changes their script to do something undesirable or is itself hacked with the effect that you now have a criminal exploit running inside your system.
Vulnerability assessment and Penetration testing
Good systems design, excellent operation and regular maintenance are not the end of the task list for operating a secure system. I have omitted testing as (I assume) everybody knows that software and configurations must be rigorously tested before being put into live production use.
All sensitive systems should be subject to constant vulnerability assessment and penetration testing by teams properly qualified to perform the roles. The aim should be to discover “open doors and windows”, bad design, inappropriate or improper use of external scripts or third-party supplied program code etc. Brief description of the aims and purposes of such testing can be found athttps://www.thesecurityblogger.com/defining-the-difference-between-a-penetration-test-vulnerability-assessment-and-security-audit/and here https://en.wikipedia.org/wiki/Penetration_test.
To understand why I will return again to Credit Agricole. In November2017 I had cause to write to the bank after discovering that confidential, personal information (eg; customer date of birth, eligibility for loans and other credit scoring flags and even the balance of funds held in savings accounts) was presented in every web page delivered after a user logged in. The only technical protection against this information becoming public knowledge was the use of the “secure” HTTPS protocol to deliver the web pages. As described earlier, this is a bank that ignored widely published advice dating from 2010 to stop using SHA-1 based certificates to authenticate and secure web sites (it actually only changed to an SHA-2 certificate on 17 January 2017 – in relative terms minutes before Internet browsers like Firefox and Chrome would have refused to display the bank’s site – even then failing to change to certificates for subsidiary sites – eg; those used to host and deliver the bank’s advertisements and technical assets causing browsers to issue warnings about site insecurity to every CA web-site visitor throughout 2017).
But regardless of the security of the particular flavour of HTTPS used by the bank, from a system design perspective three matters are relevant.
- First, I can conceive no possible reason for publishing such confidential information within a web page – the bank may want to know the kind of information disclosed so that its staff can try to advise (sell products to) its customers, but it surely has internal IT systems that display that kind of information to its staff.
- Second, the reliance on a single security layer provides a single point of failure. When technology fails, it tends to fail catastrophically and rapidly.
- An example is the recent discovery of flaws in the design of almost all CPUs (the ‘chips’ that provide our computer’s processing power) that allow sensitive information such as logins and passwords to be leaked – provoking a massive effort from chip manufacturers, operating system developers and others to mitigate the problems. These flaws have lain undiscovered (and therefore exploitable by who-knows-who) for decades.
- In similar fashion, the underlying algorithms that secure the HTTPS protocol could fail at any moment. A simple fact. Should such a failure occur – coupled with this system’s appalling authentication methods – customer data becomes exposed unnecessarily.
- Third – though there is always a temptation to view IT systems and their operation in isolation … in a perfect world in which user only press and click what they are supposed to and computers and logins are never shared – in the messy real world all these factors and more come into play. Here, there has been a number of assumptions that, taken together, can be summarised as HTTPS provides a secure channel between the bank and its customer. It does not.
- HTTPS (at best) provides a secure channel between a computer server delivering information (a web page) to a remote browser.
- What the receiving browser and user does with that information once decrypted and displayed is for them to decide. This is not an excuse for systems designers to simply shrug their shoulders and say “Oh well, that’s out of our hands” – it is incumbent on designers to take the WHOLE system – which includes its users and the environment in which it operates – into account.
- To take just two examples of how personal data might be disclosed. I should say at this point that all of the research I conducted on Credit Agricole was driven by personal interest (I was a customer) and none of the research involved any hacking or attempts to infiltrate the company’s computer systems – all I did was look at the information and documents (web pages) sent to me by the bank. To explain first, on almost any modern browser, typing the key combination ‘ctrl+u’ will open a new view showing the “insides” of the web page you were looking at – revealing all the code, internal and external programs and much else that when taken together “make the page work”. So, anyone can download a web page – hit ‘ctrl+u’ – and see what’s going on. This is schoolchild level knowledge – an IT professional (or a hacker) can be expected to have an entire tool-chest of forensic examination instruments available.
- Example1: Messy world. A customer sits in his/her office using their break-time to do some on-line banking. While a page (perhaps one trying to sell insurance policies – something the user thinks is innocuous) is open a ‘crisis’ erupts and the customer is called away, leaving the page open. Someone else comes along, hits ‘ctrl+u’ and no amount of HTTPS stops them gaining access to the customers date of birth and savings and loan account balances.
- Example 2: Technology is sometimes too useful for its own good: Internet browsers cache (technical term meaning “temporarily store”) whole pages and even windows containing dozens of tabs in order to speed display times by not having to download again data that is already available. So … here’s a neat trick. Open a web browser (Firefox, Chrome, Safari …) – open a second tab – within that tab, login to a web-site (CA’s will do) – now (typical user behaviour) do not log out but simply close the tab. Find the particular browser’s “Undo closed tab” (or equivalent) command and re-open the tab you just closed – it doesn’t matter if you open and close 5~6 other tabs and sites between closing the secure page and re-opening them – just keep executing “Undo closed tab” until the one you want reappears. Bingo! The page you were just looking at (perhaps showing bank account balances) will reappear. Hit ‘ctrl+u’ to see what may be “hidden” behind the page. Imagine for one moment that the trickster here was a person of bad intent … see how the system fails?
- There are extremely simple solutions to both examples I just gave. Number 1 is that old “keep it simple” mantra – again in the form of “if you don’t give it, it can’t be lost”. The example problem is caused by CA inserting data entirely unnecessary to the working of the web page or site into the data sent. The solution is equally simple – send only the minimum data required for the web-site to work – and no more. Number 2 is a simple technical fix – it is possible to tell browsers which data may be cached – and which data must NOT be cached. Use this simple technique and the trick I explained doesn’t work … unless you also forget to limit the lifetime of the cookie that represents the customer’s login session to the lifetime of the window – meaning that the cookie and associated login session is destroyed as soon as the user closes a tab or window. Forget to do this and, regardless of the caching rules set, the browser will simply request data from the (still live) session on the server and redisplay the page. In CA’s case they had neither set caching restrictions nor proper cookie lifetime restrictions allowing the trick I described to be performed by anyone. Who would expect this of an upstanding bank?
I want to continue looking at Credit Agricole – not because I have any personal gripe (though I confess plenty of professional frustration) against the bank nor wish to cause them harm but because their IT systems are like the gift that keeps on giving – a book could be written using just their public-facing systems to illustrate how NOT to design, develop and operate Internet connected IT systems.
In November 2017 I again entered into correspondence with a main-board director of Credit Agricole, wishing on my part to make him aware of the serious flaws in the bank’s IT systems security and potential for unnecessary disclosure of confidential, personal data. That was my wish. You can guess my expectation. And … my disappointment when the letter I received was a boiler-plate text full of platitudes such as “Credit Agricole is constantly strengthening and auditing its information systems …”.
If the constant auditing claim was true then the only conclusion reachable is that either the auditors were incompetent – or their findings and advice had been ignored by the bank’s management for years.
The“constantly strengthening”claim was certainly untrue to my direct knowledge. Having first written to disclose serious system security flaws in 2015 I had seen the bank’s system security worsening over the intervening period. To give just one, final (of many), example of what was wrong my reply contained this paragraph:
“Each and every page of the Credit Agricole web site incorporates common program code libraries which are up to NINE years out of date and which contain (in the versions used and in the case of just two of the libraries included in the CA web site) over 9,700 published and documented security flaws. In case you do not understand the implication – when a securityflaw is identified, it is first notified to the maintainer of the code library (as it is in this case) and time is allowed for the security flaw to be fixed. After the time has expired, FULL DETAILS OF THE SECURITY FLAW – INCLUDING SAMPLE PROGRAM CODE THAT CAN BE USED TO EXPLOIT THE FLAW is published. In simple terms, a teenager in a bedroom can look on-line, find and download program code designed to break into Credit Agricole online systems. As of today, your website contains over 9,775 such published security flaws.Think of them as 9,775 open doors into your bank vault through which any criminal could walk and help themselves to whatever they wished.”
That’s right – CA hadn’t bothered to update its underlying system software for at least nine years. During which time (all software contains bugs, remember) over 9,700 security flaws had been found, fixed,and published. But all 9,700+ were still open to the winds on the CA web-site.
How difficult is it to monitor such bugs and their impact? The first response is that, if the system is being kept up to date, it should only be necessary as a back-stop – a secondary check that nothing has been missed. Recall the mechanism: security researchers are constantly trying to find bugs in software exposed to the Internet –when a bug is found it is reported to the developer who is allowed time to develop a fix and deploy (at least, offer) that fix to all affected users. Only then are details of the bug published so that other researchers can learn from it. This mechanism and the eventual reporting is a well managed scheme. The bugs are called “CVEs” (“Common Vulnerabilities and Exposures”) and a full, searchable database is available on-line at https://cve.mitre.org/ and at https://www.cvedetails.com/ and at https://nvd.nist.gov/vuln/search and at https://oval.mitre.org/ and at …
Enough bashing of Credit Agricole!
This article is not an excuse to bash or expose the failings of asingle French bank. Sadly, from experience I could have spread examples of appalling practice across a number of organisations that I have encountered in just the last few years alone.
It just so happens that Credit Agricole provides a case study in how NOT to operate an Internet-facing IT system.
Perhaps the lesson to be taken here is that companies and the directors and senior management must become much more aware of the risks posed by poor Internet Security and the relatively simple steps that can be taken to avoid the majority of security risks likely to expose personal or corporate data.
Wednesday, November 21, 2018
Internet Security – Part 4: Placing responsibility where it belongs
Corporate and Board responsibility
Credit Agricole is far from unique in its implementation of on-line security measures that are inadequate by any reasonable assessment. While discussing why breaches occur I suggested that a crude, cold-hearted financial motive lies behind most of the data loss and fraud that occurs on the web.
Simply stated, it is cheaper for an organisation to ignore data security than to incur the costs associated with locking the doors and windows to keep it safe. As episode after episode has shown, even the most massive (and, on a personal level, catastrophically harmful) data breaches that have occurred (eg; Yahoo, Facebook) result in fines that are derisory in comparison to the scale of the companies’ profits. As for civil or criminal prosecution of the companies or their directors for their dereliction of duty – forget it. The legislation isn’t there to support such prosecutions.
OR … it wasn’t.
On 23rd May 2018 a change occurred that has massive ramifications for companies that hold and process personal data. That was the date that the EU’s GDPR (“General Data Protection Regulations”) came into force. Finally, legislation with real teeth exists. Companies that allow or enable data breaches similar to those I have described or companies like Credit Agricole that employ inadequate security and inevitably enable personal data loss can now be fined the larger of 20 million euros or 4% of their worldwide turnover (not profit, their income before expenses).
Companies must now look hard at how they protect their customers from data breaches. The old risk-benefit ratios (which determined it was cheaper to let data be lost and pay for any clean up afterwards) are replaced by the potential of fines that can impose material damage to the bottom line of any organisation – perhaps even do existential damage to (ie; put out of business) the worst offenders.
Itis early days with GDPR. The big tech companies who gain most from harvesting and combining personal data fought hard to stop the legislation coming into being – and failed. So far most have responded to the data privacy requirements of the legislation – in most cases by amending privacy and cookies policies and, in some case, providing some description and control over how personal data can be harvested and used by the sites. I see this as just a misguided attempt by companies whose business modelrelies on the abuse of customer data. It will be interesting to see what happens the first time a Facebook or a Google is confronted by acomplaint of data breach – and faces fines on a scale never before seen. Watch this space with interest.
The situation for companies that have grown up in an environment that allows them to abuse the Internet and its citizens in a fashion akin to the way outlaws in the old Wild West used to terrorise and abuse the citizens of remote towns and communities is changing as users and governments begin to realise the scale of privacy invasion and personal harm that is being perpetrated. Because worse(for those companies) is yet to come. GDPR is only a part of something called the European Data Privacy Framework and, while the details of this legislation this have yet to be finally agreed the legislation is likely to come into force in late 2019. At which point the tables should really be turned and I expect that both companies and the directors who control them will face criminal penalties of sufficient magnitude to make even the most adventurous and care-free among them think twice about their attitude to keeping the doors and windows locked shut.
Internet Security – Part 3: The impact on users
What does all this mean for users?
I started this article with an example of a fictional – though real-world – bank securing its premises with locks and keys. Round the circle and I have provided an example of appalling systems design and operation with a real bank operating in the virtual world –exposing all its customers to wholly unacceptable security risks and relying on security technology that was at least a decade behind the times.
To all appearances Credit Agricole is a long-standing, reputable bank that operates throughout France and has hundreds of thousands of customers – most of whom I can only assume carry on in blissful ignorance of the bank’s wilful disregard for the security with which it treats their personal data and their money. The simple fact being that it should not be trusted with either personal data or money.
I can imagine a CA customer phoning the bank to report that all their accounts have been emptied or that their statement shows transactions that they have not performed. And I can imagine the bank’s assured reply that it takes its customers’ security very seriously and is entirely content with the security of its systems. The fault must, therefore, lie with the customer.
To any CA customers reading this who find themselves in a situation similar to that I describe do not take the bank’s word as worth a cent. Challenge them to prove that the transactions are due to your actions and not due to the appalling insecurity of the bank’s IT systems and the way it operates them. In short, the utterly disgraceful disregard it has for the customers that feed it.
I feel the need to repeat what I wrote at the beginning of thisarticle. The reality is that nobody can be trusted.
Looking more broadly this lesson applies across the board.
No Internet based service can reasonably be trusted to keep your personal data or possessions safe. Though organisations (eg; thesearch engine DuckDuckGo or the Swiss email provider ProtonMail) are starting to appear that place customer privacy and security above the grasp for naked profit sadly none of these organisations are offering banking or shopping services.
It follows that the prudent user proceeds through the Internet taking the greatest care of the personal data he or she leaves in their wake and – whether you are looking for a place to post your daily activities and innermost thoughts, update your calendar or contacts, deal with your banking or the weekly shopping work on the assumption that whatever data you provide – from your name and address to your credit card details, photos, confidential documents and list of friends and contacts – will become “lost” at some point to the villains that take advantage of the “profitfirst – customers last”culture that drives the design and operation of the computer systems with which you interact.
As a simple example, many on-line retailers ask your permission to retain your credit card details “to make checkout faster in the future”- or some variant. NEVER allow an online retailer to store your payment details – for the simple reason that if they don’t have your credit card they can’t lose it. So when you read that retailers such as eBay (145 million customer credit card records “lost” in 2014), Target (110million), Sony (77 million), Home Depot (40 million) … [the list goes on and on] have lost their customers’ credit card details you should have less cause to worry – as long as you can trust ther etailer NOT to store your card details under some other pretext.