Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, December 19, 2011

The End of PCs?


You are most likely reading this blog article on a machine that would have been considered inconceivably powerful for most of the scope of human history.  You can easily communicate with people around the world in the blink of an eye.  You can effortlessly solve mathematical problems that would have confounded Euclid and Archimedes.  You can access an information repository greater than the Library of Alexandria.  If you transported this machine back a thousand years or so (and let’s pretend it would have had access to the necessary battery life and internet knowledge bases), wars would have been fought to possess it.

You hold in your hands the power of the Gods.

"With great power comes great responsibility." (Spider-man comics)

Spider-man learned this lesson to his cost when his inaction lead to the death of his beloved Uncle.  And Spider-man's powers were insignificant next to the powers of a modern personal computer.  This power is literally in your grasp.  Are you ready to accept the mantle of responsibility?

You probably think I'm stretching a point here.  If you're like most people, you just want to use your computer to read the news, gossip with friends on Facebook, and maybe watch some videos on Youtube.  You're just minding your own business.  You have no intention whatsoever of, say, joining a ring of criminals in Eastern Europe and participating in a scheme to extort money from e-commerce sites.  Except that, unless you’ve been extraordinarily careful with your super-powers, you probably already have.

"All that is necessary for the triumph of evil is that good men do nothing." (Edmund Burke)

The most common form of cyber-crime involves collecting a group of PCs to form a botnet.  This involves infecting each of these PCs with malware, which quietly turns that PC into a slave of the botnet owner, rather than the PC owner.  If the malware is at all clever at its task (which most of them are), it leaves the PC owner oblivious to the fact that anything has changed.  You still think that you're just minding your own business.  You don't realize that you've started engaging in criminal activity.

If it's any consolation, you're not the only inadvertent criminal out there.  You're in the company of millions of others.  Tens of millions.  Possibly hundreds of millions.  When you're talking about this magnitude of numbers, it’s hard to suggest a lack of personal ethics or failure of responsibility from any particular individual.  What we have is a systemic problem.  Systemic problems require systemic solutions.

"We have met the enemy and he is us." (Pogo cartoon strip)

It is possible to keep a PC free of malware.  You need to keep up to date with your patches.  Not just your operating system patches, however.  Also your browser patches.  And your Adobe patches.  And Java.  And any of the tens or hundreds of other programs you have installed on your computer.  And you need to make sure that you have a detailed understanding of any peer to peer software you run, in order to ensure that it's configured correctly.  And know how to configure your NAT router or firewall correctly.  And understand how to create good passwords.  And understand how to spot false links in emails.

The list goes on and on.  It can be done.  But it’s a full time job just to keep up with it.

There is an alternative.  It is to realize that not everybody has what it takes to be Spider-man, and not even to try.  This means something that makes most people cringe.  It means the end of PCs.

As revolutionary as this sounds, it's not actually a new idea.  We've already started using iPads, which are not PCs.  Not in the traditional sense.  They are extraordinarily limited.  There’s only one way to get additional software on them.  They don't have an exposed file system.  You can't connect them to all the cool USB devices that make your PC so flexible.  They are limited.  They are restricted.  They are, in a word, much safer than PCs.

"PCs are going to be like trucks.  They're still going to be around.  They're still going to have value.  But they're going to be used by one out of x people." (Steve Jobs)

Steve Jobs had an interesting vision: most people don't need PCs.  Most people don't need the level of power and flexibility that a full-blown computer provides.  You don't need a PC to browse the internet, check your email, and watch Youtube.  And Apple isn't simply filling this need with iPads.  They're moving in that direction with Macs as well.  In March of 2012, Apple will be implementing sandboxing for all applications sold through the Mac store.  This means that every application must request the specific permissions it will require before it is sold by Apple.  And Apple will have to approve it.  This will just be the online store.  At first.  But if Apple has its way, I suspect that it won't be long before the online store becomes the only way to purchase applications for a Mac.

This is going to slow down innovation.  People won't be able to write and release new and interesting applications nearly as fast as they could in the past.  If this had been the model back in the 80s, personal computers might never have gotten off the ground.  But we're no longer in the 80s.  Maybe it's ok for us to finally slow down a tad.

Of course, this doesn't impact Microsoft in the least.  Not yet.  But it seems that even Microsoft is realizing that unlimited power and flexibility in the operating system is not always such a good thing.  In 2001, feeling a surge of Unix envy, Microsoft released a feature called "raw sockets" into Windows XP.  Raw Sockets are cool.  They're powerful.  You can do all sorts of interesting things with them.  Maybe a little too interesting.  Some hackers leveraged them to perform some sophisticated attacks, some against Microsoft itself.  Raw sockets were quietly removed a few service packs later.

We may not yet be at the end of the PC era.  But maybe we should be.  Because most people simply don't need them.  Most people are unable or unwilling to spend the time and energy to use them safely.  And that's OK.  Not everybody needs to be Spider-man.

Monday, November 21, 2011

Hackable Everything - Part II


Last week, I titled my blog post "Hackable Everything" and stated that everything is potentially hackable.  Some people asked me if perhaps I was being a bit melodramatic.  Just because there have been some recent news about security flaws, does that really mean that everything is vulnerable?

An interesting question.

First of all, let me point out that encryption algorithms today are actually very good.  There was a time when government agencies such as the NSA could apply massive computing power to break widely used encryption (typically 56 bit DES).  During the 1990s, as the Internet grew in popularity and interest in encryption became more widespread, the government tried to figure out how to keep their ability to decipher electronic communications.  The Clinton administration famously (or infamously) tried to mandate the use of the Clipper chip, which would provide encryption, but also provide backdoor access to government agencies.

They failed.  Today, we routinely use encryption algorithms and keys which are beyond the capability of any known computer or collection of computers to break.

How sure are we of this?  Couldn’t the NSA have some massive computer buried in a government bunker that blows away our estimates?

To grossly oversimplify things, let's note that for a well-designed, properly implemented encryption algorithm, the difficulty in breaking it is a function of the key size.  DES, once the most commonly used algorithm, used a 56 bit key.  Over time, computers grew in power to be able to defeat this using a brute force attack - that is, trying every possible combination until they found the key by pure luck.

How do you make a 56 bit key twice as hard to crack?  Double the key length to 112?  Nope.  You just have to add one bit to make it a 57 bit key.

As key sizes grow, the numbers grow so fast as to make your head spin.

An 8 bit key has 256 possibilities.  A child could crack this in minutes using pen and paper.
A 16 bit key has 65536 possibilities.  A pretty big number, but you can probably visualize it if you try.
A 32 bit key has 4.3 Billion possibilities.  This is roughly the number of seconds in 136 years.
A 64 bit key has 18.4 Quintillion possibilities.  This is roughly 468 million times greater than Warren Buffet’s fortune.
A 128 bit key has 340 Undecillion possibilities.  This is roughly 340 trillion times greater than the estimated number of stars in the Universe.

128 bits is pretty much the minimum key length used in symmetric encryption these days.  In 2008, 56 bit DES was demonstrated to be crackable within a day.  Assuming we could get this down to a second, cracking a 128 bit key would still take 149 trillion years.  I’m comfortable that the NSA doesn’t have a computer 149 trillion times more powerful than the state of the art, which could crack this in a year.  Bump the key size up to 256 or 512 bits just for fun, and you can’t even come up with metaphors to express the difficulty.  You can knock this down significantly by extrapolating Moore's law will continue developing more and more powerful hardware over the next several decades, but assuming you're not trying to keep data secure for a century, you're good.

So why then do I say that anything can be hacked?

First of all, note the requirement that algorithms be well designed and properly implemented.  The problem is, you never know whether this is the case, except in hindsight.  WEP was once considered to be unbreakable wireless security.  Then it was noticed that the very powerful algorithms it uses were implemented in a sloppy fashion, making it easy to step right around them.  Today, a script kiddy with minimal technical knowledge can download free programs to break WEP using a standard laptop.

OK, that’s a challenge, but with care and lots of testing, you can implement a pretty solid encryption algorithm with a high degree of confidence.  We have a number of algorithms and products that have been closely scrutinized by thousands of people.  They’re probably pretty good.

The second challenge, however, is more difficult to solve.  All security is built upon trusting something.  (Ask yourself how secure an encrypted transaction with Bernie Madoff would have been.)  Anything you have to trust is a potentially vulnerable point in your security infrastructure.

For example, most security on the Internet depends on "Certificates", which enable a person to unambiguously assert their identity, encrypt their data, and make sure any messages they send can be tied accurately back to themselves.  Certificates are the foundation upon which most everything else is based.  Having your certificate be compromised is like opening the back door to the castle - it simply doesn't matter how thick your walls are, or how deep your moat is, if people can enter freely.  Recently, a number of Certificate Authorities have been hacked, including Diginotar and KPN.  Once the Certificate Authority is breached, some Certificates (perhaps all) issued by that Authority are no longer secure.

Here's the scary part: check your browser, and see how many Certificate Authorities it considers to be "trusted".  The answer is close to 600.

600 companies, any of which might have a weak password, or a poorly implemented algorithm, or a single open port on a server, or a pissed-off employee who didn't get the raise they really thought they deserved.  Every one of which your browser is trusting 100% to keep you secure.  Do you have the detailed technical and organizational knowledge to know if this trust is justified?  Have you even heard of Izenpe S.A. (which I just found in my Certificate list in Firefox)?  Diginotar didn't tell anybody about their breach for many months.  Would you know if others have already been breached?

Are you feeling safe now?

The third point is even more difficult to come to terms with: data leaks.  No matter how secure the transmission is, it doesn't matter if somebody can read your data before it's encrypted at the end points.  Who cares if you use 1024 bit encryption if there's a keystroke logger installed on your machine which captures everything you do before it can be encrypted?
Or maybe they don't even need a keystroke logger.  Try sitting in a room where somebody else is typing.  Close your eyes, and listen to the sound of their keystrokes.  Do you notice how they don't all sound quite the same?  (If you're not convinced, ask them to touch type for a few minutes, then hit the same key over and over again with one finger.)  Depending on the location in the keyboard, each key strike has a slightly different pitch and timbre.  Researchers at Georgia Tech recently demonstrated how the accelerometer in an iPhone 4 could determine what was being typed on a nearby keyboard with 80% accuracy.  This was considered a much more interesting demonstration than simply using the microphone, because the accelerometer is much less secure – you usually get notified when the microphone is turned on.  How is  encryption going to save you from that?

Now granted, this iPhone exploit is not easily replicable - they needed the phone to be perfectly positioned, on the right type of table, and all sorts of other controllable factors.  But technology always gets better, and more pervasive.  How long before an iPhone can do the same type of detection from 10 feet away?  How long before somebody figures out how to do it using a laser microphone against your window from 300 feet away?  How long before the current proliferation of cameras and microphones in consumer, industrial and municipal devices means that you're always within range of some camera, somewhere?

When any one of them can potentially be hacked, how will you ever know that anything you say or type won't be monitored?

This all sounds like the stuff of spy movies.  You're probably thinking, "Sure, this could happen in theory.  But who's going to take the time and effort to go after me?"  That's probably true.  Until technology makes it so simple to do that your neighbor's kids can buy the necessary gear for less than $10.  Counterfeiting money was once the exclusive domain of organized crime.  Then we had a new generation of printers and copiers which could churn out perfect copies of dollar bills.  You'll notice our currency has gone through some significant redesigns in the last twenty years, adding many new security measures.  This wasn't to stop organized crime.  This was to stop the average consumer for whom temptation had become just a little too hard to resist.

This is the point where I'm supposed to editorialize, and point out that only with immediate action right now can we avoid calamity.  But I don't have any answers on this one.  If you do, I'd be interested to hear about it.  But first, find a venture capitalist and start a company to implement it, because security concerns are going to be one of the hottest topics of the twenty first century.

Monday, November 14, 2011

Hackable Everything - Part I


The internet was created on a dream.

What if computers could talk to each other?

It's easy to lose sight of what a revolutionary dream that once was.  There was a time when most computers were not sold with modems or network connections of any sort.  You transferred files by putting them on floppy disks.  If you were especially tech savvy, you hooked two PCs together through their parallel ports and were able to transfer files directly from one to the other.  It seemed like magic at the time.

Then Al Gore invented the internet, and suddenly computers all over the world could talk to each other.  This happened so suddenly that nobody knew what to do with it.  You think I'm kidding, but I'm not.  The first corporate websites in the 90s looked like they should be hanging on the walls of a third grade art class.  Take a look at some of these if you don't believe me.

Then we upgraded everybody to broadband, and figured out what to use the Internet for: just about anything you could do on a computer.  You could browse.  You could shop.  You could communicate.

Anything you could do on a computer.

What if we could connect to the internet without a computer?

Between shrinking chip sizes and mobile protocols such as wi-fi and bluetooth, this dream was barely formulated before it came to life.  Email on your cell phone?  Check.  Emergency service and navigation in your car?  No problem.  Bluetooth connectivity for your insulin pump?  Why not?

Maybe we should have tried a little harder to answer that last question.

Because the inventors were not the only ones dreaming.

What if any device with a network connection could be hacked?

Finding unintentional uses for computers is a past-time as old as computers itself.  One of the first demonstrations ever of a personal computer was done on a machine lacking a monitor and printer.  Lacking a formal method of output, the programmer timed the cycles of the CPU just right to cause the radio interference generated to play some simple songs from the static of a nearby radio.  Computers weren't designed to leak radio signals.  It was simply possible, and a really clever person figured out how to exploit it.

The world is chock full of really clever people.  Not all of them have good intentions.

The problem is, we still don't really understand our connected, online devices, any more than we really understood the internet back in the 90s.  We still expect them to act like old fashioned devices, just better.  Hacking an insulin pump?  Whoever heard of such a ridiculous notion?  When security researcher Jerome Radcliffe demonstrated that he could issue unauthorized commands to his insulin pump over bluetooth, the manufacturer, Medtronic, just laughed.  They issued a dismissive statement saying: "...there has never been a single reported incident of wireless tampering outside of controlled laboratory experiments in more than 30 years of use."  Because we haven't seen this before, it couldn't happen now.  Go away, and trust us.

Then McAfee reproduced the hack.  And improved it, so it could work from 300 feet away.  And demonstrated how easy it would be to request the pump to deliver a lethal dose of insulin.  Medtronic isn't laughing anymore.

On November 14th, the New York Times published an article discussing Google's top secret research labs, where researchers are figuring out, among other things, how to put just about anything on the internet.  Garden planters.  Coffee pots.  Refrigerators.

What happens if Google succeeds?  Could a clever hacker figure out how to shut your freezer off for a few days while you were away from home, then turn it back on, causing you to unknowingly eat spoiled and possibly lethal food?  How about turning on your furnace full blast in the middle of an August heat wave?  And God help us if they ever figure out how to hack one of Google's driverless cars.

We live in a brave new world.  Everything is going online.  Everything is potentially hackable.  Unimaginable opportunity.  Unimaginable risk.

Anybody who claims to know how this will play out is selling something.

Sunday, September 18, 2011

When will they ever learn?

If there's one lesson in terms of scandal management that everybody seems to agree on, it's that the initial crime or screw-up isn't nearly as fatal as the cover-up which follows.

Why is this so difficult for people to learn? And in this day and age of transparency, why isn't it more patently obvious that the truth is going to get out, sooner or later?

Our latest contender for the crown prize in idiotic crisis management is DigiNotar. A Certificate Authority located in the Netherlands, DigiNotar is one of the trusted firms that is supposed to guarantee the integrity of information on the internet. One would think that this awesome responsibility would weigh heavily on those who carry it, and would cause them to think through their "what if" scenarios very carefully.

Or then again, maybe not. As you already know if you follow this type of tech news, DigiNotar was hacked, and hacked badly. I don't really blame them for this. Internet technology is a massively complicated affair, and people are notoriously susceptible to social engineering. So I think any firm is susceptible to being hacked (though I do scratch my head and wonder what they were thinking when they set their production admin password to "pr0d@dm1n"). But once this happened, one would hope for just a trace of transparency and accountability. Warn the world of what has happened. Recall the tainted certificates. Put an immediate halt on issuing new certificates until you've figured out the full extent of the problem and figured out how to fix it. And no, I don't mean just changing a stupid password to one marginally less stupid - we need a complete technology and process overhaul.

But DigiNotar failed at each of these tasks, and has thus been removed from the trust of all the major browsers. Barring having their corporate headquarters get struck by an asteroid made of platinum, they're out of business. Some of their competitors who were also hacked took full responsibility and disclosed everything, and will likely emerge stronger and more trusted than ever.

Some day, people will learn. But it's apparently not this day.