|
Welcome back to the monthly TCE Strategy newsletter! August has had enough cybersecurity issues to fill a 100-page book, let alone a newsletter. I had to be very picky about which stories to cover. Suffice it to say, if the next few months are totally devoid of cybersecurity news, I have enough material to make it into the new year. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
City of St. Paul breach causes widespread outages of critical services.
The City of St. Paul, Minnesota, USA woke up to a serious issue Friday, July 25th. An intruder was discovered in their network. The City spent the weekend trying to understand the scope of the problem, and it was much larger than any sort of cyber issue they had dealt with previously. On Monday, July 28th the city shut down most of its key systems. City Wi-Fi was cut. Fire and EMS Computer Aided Dispatch (CAD) systems—critical for detailed dispatching, GPS navigation, incident updates, and more, were taken down. The laptops that police officers use in their squad cars were disconnected (this technology has been available since the late 1970’s, so it’s a very well established part of police work). Payment systems were cut – cash only for everything from paying your water bill to getting your car out of impound. Police dispatch was moved to manual backup procedures. The city called in the National Guard, the FBI and two private cybersecurity remediation companies. The governor of Minnesota declared and extended a “state of emergency” for 90 days. This was bad.
It turned out that the Interlock ransomware gang got into the St. Paul Parks and Recreation system, exfiltrated 43GB of data (that’s a lot), and likely encrypted the data on St. Paul’s systems as part of a ransomware attack. I’m guessing that the amount of access that the ransomware gang had in the system was extensive, and I’m guessing that the Parks and Recreation system shares networks, applications, and user accounts with other parts of the City of St. Paul. That’s likely why the city took most of their systems offline on Monday the 28th.
Recovery has been slow. No systems were restored until August 11th, and a full recovery is still “weeks away.”
For citizens of the City of St. Paul, this has been more than an inconvenience. If City Wi-Fi is your only means to get on the Internet, losing that service is very meaningful. If your car is impounded and the City can’t take your check or credit card, that is very meaningful. If you are in need of police, EMS or fire services and their arrival is delayed because Computer Aided Dispatch systems are down, that is very meaningful. From a services standpoint, hopefully things are put back to normal soon.
From a data standpoint, the cat is completely out of the bag. The City refused to pay the ransom (and kudos to them for that), but the Interlock ransomware gang chose to release all the data they stole. Most of it is not overly sensitive data, but some of it genuinely is: my team looked through it, and we found the W2 for the Director of Parks and Recreation for the City of St. Paul, among others. We found the medication sheets for kids that have attended summer camp for the last 10 years. We found several documents containing passwords (it is unknown if these are active usernames/passwords or old ones). Not good. It’s genuinely surprising to me that the disclosure of this confidential information didn’t get more press coverage. Perhaps because the number of records was far lower than other breaches, it wasn’t as strong a headline story? Perhaps there have been so many data breaches that we are becoming numb to them? No matter the reason, it’s sad to see that more coverage wasn’t given to the victims of this data breach.
Takeaway: Ransomware is a preventable crime! It’s terrific that the City of St. Paul had strong data backups, but that doesn’t make whole the people who rely on city services but couldn’t receive them, nor those whose confidential data was released to the whole world strictly out of spite. We need to take proactive ransomware prevention more seriously.
Understanding how to use something is not the same as knowing how something works.
It’s counterintuitive to think that most people use things everyday that they don’t fully understand how they work. This isn’t a new issue. Humans have been using fire since before recorded history, but understanding the concepts of combustion (the use of oxygen to chemically interact with a fuel source to release heat, carbon dioxide and water) has only come in the last few hundred years. Gregor Mendel is recognized as the founder of genetics – he discovered dominant and recessive genetic traits (he called them “heritable factors”), but had no understanding of DNA or genes. Madam Curie discovered the incredible usefulness of radiation, but did not understand the potentially harmful effects that radiation can have, and ultimately it was radiation that killed her. The understanding she needed to use radiation safely didn’t come until decades later.
The 2020’s technology scene is being completely dominated by advances in AI, which I use often. It does a terrific job researching a subject and providing a Cliff Notes (or Spark Notes for our younger readers) version of the topic. It is extremely useful in the kitchen for recipes. It is moderately useful at writing code, although I’ve had times when it takes more effort to get the AI engine to understand what I’m looking for than it would be to code things myself. AI tries to be helpful. It is pleasant. It is complimentary. It is also not completely understood how it actually works. In fact, there are some recent articles that propose the idea that as our AI models get more and more complex, we are in fact losing ground in our understanding of how they work.
We have a fundamental issue here: When technologies are put into place without a complete and thorough understanding of how they work, negative consequences can occur. Grain mills have exploded because the dangers of grain dust as a source of combustion were not well understood. We lost 3 astronauts in the Apollo 1 ground fire in 1967 because the dangers of fire in a pure oxygen atmosphere were not well understood. Now we are living in an age of AI where it is successfully taking a surprising amount of “grunt work” or entry-level positions out of the hands of people and into those of a computer. The problem is that we don’t fully understand how it works. We just know that it’s useful. I wrote last month about how AI is sometimes too nice and can support ridiculous theories. This month, the Wall Street Journal doubled-down on their reporting about that issue, stating that AI is fueling delusional spirals for some of its users, with the primary issue seeming to be a disconnect between AI’s interest in getting a question correct vs. its interest in making the user of AI feel good about him/herself.
There seems to be an overwhelming desire on the part of AI users for AI to be “friendly” for lack of a better term. OpenAI rolled out ChatGPT 5 this month, and there are lots of reports about how it had a “diluted personality”. A Reddit group has spawned specifically to lambast it. So, OpenAI is working to make it more friendly. I think we are likely to see much more of these “two steps forward one step back” moments in the world of AI, as we don’t really know how it works, so the results it gives are unpredictable. This is to be expected for some time, likely for years to come.
Takeaway: AI is not your friend. Using it to make you feel better will lead to a fool’s paradise. Expecting it to make you feel better about yourself is a bad idea. If anything, having it be a little adversarial when it comes to new ideas isn’t the worst idea. Some of the best science comes from slightly adversarial premises.
Until next month, stay safe!
|