|
Welcome back to the monthly TCE Strategy newsletter! Get strapped in. From 23andMe to working 73,000 hours in a two-week pay period to SignalGate, April has been a wild ride. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
The call from your kidnapped child is likely a hoax
As a parent, it’s terrifying to imagine your child in the hands of a kidnapper. Last week, WSJ chronicled the harrowing ordeal of Linda Roan, a Colorado woman who received a frantic call from someone who sounded just like her daughter. An alleged abductor then got on the line and demanded money in return for her daughter’s release. The nightmare only ended after Roan wired $2,000 and the caller hung up. Roan soon discovered her daughter had been safe at home the entire time.
Takeaway: We are living in the world of AI, and it’s much easier to impersonate another person’s style of email, their voice, or even videos. Assume that an urgent call, a video or an email in front of you is a fake until proven otherwise. Resist fight-or-flight responses. Even extremely seasoned and well-respected cybersecurity professionals sometimes fall for scams. Stay vigilant.
Computers don’t understand what is “reasonable” unless we make them
There are a lot of things that humans take for granted. Generally speaking, we understand possible from impossible. If someone tells you they can run at 500 miles per hour, you would know that is impossible. If someone tells you their USA zip code is “31415926535897932384626”, that too is impossible. Zip codes are 5-digit codes, such as 90210. Computers are happy to assume the impossible is possible unless they are programmed not to. For example, an audit of a Maryland school district found that a substitute teacher was paid for 73,000 days of work because a payroll person accidentally typed in the substitute teacher’s ID number into the “hours” field of their payroll system. In actuality, the teacher worked 3 days. Payroll systems should have “guard rails” that prevent someone from being paid for more hours than exist in a given pay period, but this system didn’t have that feature, so the school district paid over $7 million to this substitute teacher. The good news is that they recovered the funds, almost two months later when the error was noticed.
Takeaway: If you are designing a computer system, making it “work” isn’t good enough. The system needs to know to reject impossible entries, such as a person working 73,000 days on one paycheck.
23andMe is bankrupt, but they still have your data
Over 15 million people used 23andMe’s genetic testing service. The company declared bankruptcy in March of this year, which puts the genetic information of those 15 million people in a precarious position. If they don’t have money to continue operations, the odds of them having money to protect your data is suspect. Their 2023 data breach of almost 7 million customer profiles demonstrates that they weren’t taking cybersecurity as seriously as they needed to before they went bankrupt, and bankruptcy rarely helps situations like this.
Takeaway: The company claims that you can delete your data if you choose to do so, which I strongly recommend. Here is how.
Signal. War plans. Wow…
I’ve said before that cybersecurity and politics are inextricably intertwined, and the month of April was no exception. In what has widely been dubbed “SignalGate” by the press, the secure messaging app Signal was used by a group of USA government executives (among them Defense Secretary Pete Hegseth and Vice President JD Vance) to discuss upcoming military strikes against targets in Yemen. Then they accidentally added Atlantic reporter Jeff Goldberg to the chat group.
There is so much to unpack here… First, using a system for a purpose that it was never intended for is very risky. Signal is designed for secure messaging, but there are no guard rails on who is allowed to use it, who a person may have in their list of Signal contacts, nor what devices can be added to a user’s Signal account. War plans should be sent using confidential classified channels that have appropriate guard rails in place, exactly the same way that Signal doesn’t. Signal wasn’t designed for military use. The WWII “Enigma” machine was designed for military use, and even that wasn’t Secure Enough (from an Axis powers point of view). A tool like Signal being used to discuss upcoming war plans is unthinkable. To make a horrible situation worse, it’s been reported that the NSA sent out a warning about possible vulnerabilities in the Signal app a month before the Yemen chat took place.
Furthermore, now that it’s been proven that Signal is being used to discuss war plans, Signal finds itself firmly in the crosshairs of Nation-State level cyber actors that will try to find a way to hack it, the same way the Allied powers hacked the Enigma. They don’t have a nation-state level budget to counter that threat.
There has been a lot of spin on this story. Claims have been made that Jeff Goldberg somehow hacked his way into the chat. Claims have been made that the plans on where bombs were about to drop in Yemen somehow wasn’t classified information. I will leave further research on those topics as an exercise for the reader, other than to quote Hanlon’s Razor: “Never attribute to malice that which can be adequately explained by incompetence.”
NOTE: TCE Strategy is a paid user of Signal. We believe in what they are doing and decided to provide financial support.
Takeaway: Square pegs and round holes don’t go together well. If you need a hammer, buy a hammer and use it as designed. If you use a ratchet as a hammer, it won’t end well.
When a very high-risk maneuver is the lowest risk thing you can do.
For those that have heard me give a presentation, I often talk about how in a very difficult situation, sometimes the best thing to do is something that would be unthinkable in normal circumstances, such as cutting the Internet connection to your business or taking your e-commerce website offline. In the middle of a ransomware attack or a takeover of your website, these actions are definitely under consideration. This theme isn’t specific to cybersecurity. Here is an amazing story of restaurant owners who purposely flooded their business with tap water, in the hopes of keeping out muddy flood waters that were rising outside of their building. That never would have occurred to me to do, but it makes sense. Kudos to them for thinking outside of the box.
Takeaway: Make the hard decision. Not making a decision is often riskier than making a tough decision, and these restaurant owners are a great example. The road is full of flattened squirrels that refused to run left or right. Don’t let your cybersecurity posture get run over.
Until next month, stay safe!
|