Ruminations

Blog dedicated primarily to randomly selected news items; comments reflecting personal perceptions

Thursday, March 16, 2023

Cybersecurity in Canada : Failure to Launch

"We're expanding because more companies are reading what's happening in the news and saying, '
We don't want that to happen to us'."
"Originally, only big budget firms with very sensitive data would hire us. Now 100-employee firms are buying our services. They don't want the interruption, the brand damage or the financial losses. Insurance can cover the financial losses but it won't help with the stress and brand damage."
"There was a really good excuse initially to say, 'I'm not a  target' because the first attacks were about extracting information and selling it to someone else. But then when ransomware came about, that flipped the whole business model on its head. It locks you out of your data and prevents you from operating your company. So it's not what it's worth to someone else but to yo, so you can get it back.:
"The talent in the industry is finite right now, so it's an employee's market to some degree. We were leery, trying to build what we could in this company, so we wouldn't end up in an arms race and just buying talent."
"But at the same time, you cannot build a senior-tenure pedigree person with a high school diploma and six months' training. So you have to pick your battles and where we build anything, we build our junior resources, those entry-level positions, and we've seen some good success with that."
Chris Johnston, co-founder, CEO, Bulletproof, cybersecurity firm, New Brunswick

"The bad guys have not only become sophisticated, but they also don't necessarily differentiate between x and y, this group or that group. They basically build techniques to take advantage of seniors, kids, financial institutions, critical infrastructure, anything you can think of. They want more money, or they have political causes or other reasons."\
"No one thought that the pacemaker in your heart would be a cybersecurity issue. Now it is. Because many medical devices are prone to attack. Even my watch can be attacked. Anything you can think of that's connected to the internet can be hacked."
"The labour shortage is in everything. It's a huge challenge. The projection is that in six or seven years, we'll need 40 percent more in the cybersecurity workforce worldwide. And that's much higher than any one country is graduating into this field."
Ali Ghorbani, dean, computer science faculty, University of New Brunswick; director, Canadian Institute for Cybersecurity
Cyberattacks evolved from extracting information and selling it to Ransomeware, which holds companies hostage.
Cyberattacks evolved from extracting information and selling it to Ransomeware, which holds companies hostage. Photo by Getty Images
 
There is a concern that as the risks of cybersecurity spread and enter new realms, become more common and more disruptive where public institutions like hospitals and universities are targeted, along with retail giants where personal information is hijacked, company finances and reputations are at risk, and the same goes for public utilities, the illegal industry of malicious hacking is on the rise, and suddenly there's a dire shortage of skilled IT personnel both in-house and private companies to fill the niche of knowledgeable expertise countering cyberattacks.

They're costly, disruptive, debilitating to the operation being held for ransom, and as they increase, society will find itself stumbling toward a solution, particularly as the hackers proliferate and find profit in disabling personal computers sending people into a tizzy of frantic reaction, willing to pay what it takes to free up their systems of communication and in the process enabling the criminal community to spread its menacing presence in a free-for-all of captive-and-threat-piracy.

Yet, as pointed out by Ali Ghorbani, dean of computer science faculty, NBU, schools in Canada are failing to comprehend the necessity of stressing the vital importance of STEM subjects; science, technology, engineering and mathematics. From basic training to the eventual creation of cybersecurity recruits in the numbers required to be responsive to the burgeoning threats. Threats to which companies specializing in cybersecurity will be hard pressed to find ten percent more trained professionals annually for the foreseeable future.

In one of Canada's smaller provinces alone with a population of 800,000, a shortage already exists of up to 700 cybersecurity workers. Losses caused by cyber crime since 2017 have almost tripled, and currently tally around $6 billion annually worldwide. Canada is behind leading nations like Israel, the United Kingdom and the United States in cybersecurity, failing to acquire a reliable assurance on how many experts are in the field, lumping them in with IT professionals, many responsible in their firms to handle security along with other duties.

In the shortage of homegrown cybersecurity professionals, Canada is in competition with other countries in similar positions, where Canadian universities search for international students to fill gaps. At present up to nine in ten students enrolled in STEM programs in Canada at a master's or doctoral level arrive from elsewhere, a reflection that education in that sphere is higher-rated in other countries mere alert to the dangers of cybersecurity than is Canada.

Government, feels Professor Ghorbani, should be alert to the need for schools -- from elementary students forward -- teaching basic Internet safety. Financial incentives offered to companies to train employees in front line cybersecurity would be a start, instead of relying on the cybersecurity industry itself, overwhelmed by volumes it can barely serve adequately. Eight of ten successful hacks, points out Professor Ghorbani, result directly from human error; everyday individuals with poor computer security hygiene who have no idea what they're doing and failing to do.
"Cybersecurity is all about avoiding surprises and managing risks. That's what it comes down to in the end. But the surprises won't totally go away, partly because the bad guys are as smart and have more resources and time and are more dedicated to otheir cause, either monetary or political."
"So keeping them at bay is like keeping burglars from our homes."
"This problem has never been solved; there are many ways they can come in. But you build barriers against that."
"It's the same with cybersecurity."
Ali Ghorbani

Labels: , , ,

Monday, January 16, 2023

CyberRansom ... Be Prepared

"It [AI-powered computer program ChatGPT] has the ability for someone with not very much skill set or maybe even not a great command of the English language to create a full, almost flawless script to use in an attack against somebody in a phone scam or an email phishing scam or what have you."
"In the past, [hackers and scammers] would rely on their own grammar and spelling skills, which often many people were able to identify and say, 'oh, that looks like a scam'. They're getting harder and harder to detect now."
"They're either using phishing or an even more advanced version of phishing, called whaling, where ... it looks like it's coming from an executive instructing his workers to do XYZ. And as soon as they open or click or do anything in that email, they end up infecting the organization."
Robert Falzon, head, engineering, cybersecurity firm Check Point Canada

"They're increasing across western democracies. This is a serious problem, a serious challenge, that is becoming increasingly severe."
It's supported by sovereign countries that harbour ransomware attackers, and ransomware attacks have proven to be highly lucrative."
"The more important the organization, the more critical that organization is to the proper functioning of  society or the economy, the more likely it is that a ransomware gang will be able to leverage significant financial return. So the attack on SickKids hospital is exactly the kind of attack that we need to expect."
Charles Finlay, founding executive director, Rogers Cybersecure Catalyst Centre, Toronto Metropolitan University
Global computer network diagram. Cyber futuristic financial network security concept. Block chain network
Global cyber futuristic financial network security concept. Fast speed internet connection blocked. Getty

The increasing cyberattacks hitting government agencies, corporations, hospitals and other vulnerable-to-attack groups has had the effect of shutting down services in critical arenas while the entities struck by attack desperately address themselves to solving their vulnerabilities. Social media sites are not immune to these attacks, and it seems, no one group or individual is. In the case of foreign governments known to indulge in cyberattacks focusing on the military or government the source is well known and the threat potential enormous.
 
Recently in Canada a number of high-profile cyberattacks has seen hospitals, businesses and organizations, including the Liquor Control Board of Ontario and the Hospital for Sick Children in Toronto along with Scouts Canada, become the focus of cyberattacks. Experts on cybersecurity are agreed; the frequency of these attacks mounted both by hostile governments and criminal groups is on the increase. Part of that is attributable to the fact that more and more business is conducted online; we're increasingly dependent on technology.. 
 
And as governments at every level along with corporations and manufacturers, universities and hospitals become ever more reliant on infrastructure, networking and communications online their vulnerability is on the increase. Even while all these groups continually upgrade their security. Intrusive software is continually being upgraded as well, enabling even amateur computer crooks to become more capable and versatile in the engineering of cyberattacks.

Access to new technology aiding the development of malware, scripting and associated tools potential hackers make use of like the AI-powered computer program ChatGPT are all put to unscrupulous use.  The cyberattack that hit Sick Children's Hospital in Toronto affected phone lines, internal clinical systems and disrupted laboratory and imagining results. Any organization believed vulnerable to a ransom leverage attracts hackers.

Many of the tools that enable cyberattacks take a scattered approach in sending out email to thousands of potential victims. "These are incidental attacks where somebody unfortunately falls victim to either clicking on a phishing email or an attachment or something, and then it infected that system in that area. And now you've got a widespread problem", pointed out Check Point's Falzon.

So what do the experts in cybersecurity recommend? Nothing anyone who uses a computer doesn't already know; keep computers and mobile devices updated with critical software since manufacturers create frequent "patches and updates" targeting vulnerabilities in their products. Passwords should be updated often, and never used for more than a single site or service. Become hyper-aware of emails or text messages from unknown sources.
"Somebody could send you a text, whether it's WhatsApp, for example, where a single text [is] sent to your cellphone, you view it, and next thing you know you're vulnerable."
"They can control your camera, your microphone, to see where you are, read your text messages, things like that."
"It's a massive risk to carry them around and not have any protection on them."
Robert Falzon, Check Point Canada cybersecurity


Labels: , ,

Friday, December 23, 2022

A Political, Cubersecurity Aspect to TikTok?

"If anybody has any doubts about whether [China] would collect the data from TikTok, they have to have been living under a rock."
"Canada has to really wake up to where it is in the world and the threats it faces."
"It is not as if the West is doing this to be aggressive and try to bully China. It's a response to what China does."
Dennis Molinaro, foreign interference analyst
 
"The Americans are right to be very concerned about it."
"The Canadian position is always, 'We're too nice to be a target anyway ..."
"We'll probably end up going along with what the Americans do, but reluctantly and very slowly."
David Skillicorn, computing professor specializing in cybersecurity, Queen's University
Signage is displayed at the TikTok Creator's Lab 2019 event hosted by Bytedance Ltd. in Tokyo, Japan, on Feb. 16, 2019. (Shiho Fukada/Bloomberg)
 
A German newspaper early in 2022 reported asterixes had been superimposed by TikTok in place of subtitles for terms such as "re-education camp" and "internment camp" in a video focusing on the plight of Uyghurs in China's Xinjiang province. Another hint that just possibly there is reason for concern given emerging evidence that the app is not solely focused on diverting entertainment, but an element of focus to becoming a preferred news destination. 
 
The United Kingdom's Office of Communications stated that TikTok is now the fastest-growing news source among young adults and for teenagers aged 12 to 15, the most popular. Toronto Metropolitan Social Media Lab concluded that over fifty percent of Canadian TikTok users claiming they depend on the app for news of the war in Ukraine. 
 
Entering keywords "Xinjiang Uyghur" into the TikTok search field will get you several videos critical of China's position and manipulation of Uyghur life. The majority by far of references came out of travelogue-type depictions of joyful Uyghurs with clips meant to debunk media reports critical of China, along with images of President Xi Jinping receiving a warm reception on a Xinjiang visit.
 
To anyone concerned with privacy rights and social media, it comes as no surprise that U.S.-based social media platforms siphon up great masses of personal data, engage in disinformation and act as ideological echo chambers themselves. According to a TikTok spokesperson the app stores Canadian user data in its own servers in the U.S. and Singapore and has never allowed that information to the Chinese government.
"Canadians can rest assured that their law enforcement and national security agencies are committed to detecting, deterring and disrupting all cyber threats and hostile states, including the People's Republic of China."
Audrey Champoux, press secretary, Public Safety Ministry
According to a survey conducted by Toronto Metropolitan University's Social Media Lab, over one in four Canadian adults maintain accounts with TikTok; where rival platforms have lost users, TikTok has gained. Data-privacy scandals gripped Facebook and other U.S.-based apps and TikTok capitalized on the issue, posing as more innocent and lighthearted, as an alternative.
 
TikTok is owned by ByteDance, a private Chinese company, subject to laws requiring all businesses operating in China to share data and work with Chinese government authorities.

TikTok refers doubters to a report issued last year by the University of Toronto's Citizen Lab concluding no evidence exists of data sent to China or of Beijing placing pressure on ByteDance to  make data available to Chinese authorities. Another issue raised by experts is that TikTok could use hidden software tools meant to pry into other apps on a user's mobile device to uncover information.

"It's hard to criticize TikTok when other social media platforms are doing the same thing", observed Anatolly Grozd, Canada Research Chair  in social media data stewardship at University of Toronto. Yet the app's control by a foreign country like China, he feels, merits vigilance.

TikTok, the Chinese-owned online video app, is seen by some critics as a an unnerving black box that could be sharing information with the Chinese government and facilitating espionage.
TikTok, the Chinese-owned online video app, is seen by some critics as a an unnerving black box that could be sharing information with the Chinese government and facilitating espionage. (AP)


Labels: , , ,

Saturday, September 02, 2017

Malware and Ransom of Medical Records

"The doctors are under attack. We are getting physicians on a regular basis saying, 'I have a computer, I got locked out, I have ransomware'."
"They've been asked to pay in bitcoin. They're asking us, 'Should I pay it'?"
Dr. Dennis Desai, physician-adviser, Canadian Medical Protective Association (CMPA)
No Canadian hospital -- as opposed to a doctor's office -- has yet made a public admission that they have become a victim of ransomware, their computer systems with invaluable and private patient records falling victim to cyberattack through malware, finding themselves locked out of their source of record-keeping and maintenance, and faced with the prospect of having to shut down operations unless they surrender to the demands of Internet pirates.
"There have been some hospitals that have been attacked and have paid ransom in bitcoin, in Canada."
"It was the Wannacry kind of event ... It's not individual patient files; they lock up everybody."
Bill Tholl, chair, federal committee on cybersecurity and critical infrastructure


This week the CMPA, the agency whose purpose it is to provide liability coverage for Canadian doctors published an article to make doctors aware of this growing problem of computer system attacks and to urge their member-physicians to make certain they maintain robust backup systems, and take urgent steps to guard against infection through computer viruses. Above all, to refuse to pay ransom should they be targeted.

The problem is a real one, and it is a growing phenomenon of some urgency. One expert has estimated that the number of ransomware attacks perpetrated on this target audience has risen by 600 percent in the past year alone, according to Mr. Tholl, previously CEO of HealthCareCan, an entity which represents hospitals and allied medical facilities. Precisely for the very reason that sensitive medical data has become a prime focus, more so even than efforts to bog down banking enterprises.

The simple reality now appears to be that hackers repeatedly target Canadian doctors with their ransomware and in so doing render their computer systems with their thousands of critical and sensitive medical records hostage, impeding the normal care of patients. Once the situation has been
settled it takes days for medical offices to restore their systems from their backup sites. In the process the potential for loss of crucial data looms.

Physicians are hard put to ensure that nothing is missing in their patients' history when health issues are being diagnosed. Ontario's privacy commissioner office has received ten reports of such ransomware attacks on medical clinics or doctors' offices since 2016, recognizing it as an "increasingly dangerous" threat to the security of health records.

A cyber gang - called Shadow Brokers - is being blamed for the hack
A cyber gang - called Shadow Brokers - is being blamed for the hack Credit: Reuters

When computers are frozen by encrypting data, the anonymous attackers demand payment, most often in digital bitcoin before they will unlock the files. The notorious Wannacry virus struck 15 hospitals in Britain's National Health Service, forcing them to shut down some of their operations. Two major health facilities in the United States were similarly struck by such attacks; computers at Erie Country Medial Center in Buffalo went down for six weeks while the authorities there refused to pay the demand of $44,000 in bitcoin to free the computers.

To the present, according to cybersecurity consultant Kevin Magee, Canadian hospitals have managed to evade the problems that assailed hospitals in Britain and the U.S., crediting their more disciplined approach to installing security patches in protection against malware. Cyber criminals, however, were encouraged by their success in pursuing health-care institutions for ransom; when lives are endangered, desperate efforts to regain control of critical files have led to the ransom being paid.

Over 70 percent of physicians have engaged with electronic medical records. The absence of that critical data for even a few days while the computers are being forcibly locked down spells a huge problem for health practitioners, when computer systems cover all record-keeping from appointment schedules to detailed patient charts.

Labels: , ,

Tuesday, October 20, 2015

What's At Stake

"I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold. Though I hadn’t touched the dashboard, the vents in the Jeep Cherokee started blasting cold air at the maximum setting, chilling the sweat on my back through the in-seat climate control system. Next the radio switched to the local hip hop station and began blaring Skee-lo at full volume. I spun the control knob left and hit the power button, to no avail. Then the windshield wipers turned on, and wiper fluid blurred the glass."
"As I tried to cope with all this, a picture of the two hackers performing these stunts appeared on the car’s digital display: Charlie Miller and Chris Valasek, wearing their trademark track suits. A nice touch, I thought."
"The Jeep’s strange behavior wasn’t entirely unexpected. I’d come to St. Louis to be Miller and Valasek’s digital crash-test dummy, a willing subject on whom they could test the car-hacking research they’d been doing over the past year. The result of their work was a hacking technique—what the security industry calls a zero-day exploit—that can target Jeep Cherokees and give the attacker wireless control, via the Internet, to any of thousands of vehicles. Their code is an automaker’s nightmare: software that lets hackers send commands through the Jeep’s entertainment system to its dashboard functions, steering, brakes, and transmission, all from a laptop that may be across the country."
Andy Greenberg, Wired magazine, July 21, 2015 
Charlie Miller (left) and Chris Valasek hacking into a Jeep Cherokee from Miller's basement as I drove the SUV on a highway ten miles away.

"The focus of car manufacturers remains selling as many high-margin, connected-car options packages as possible, and not necessarily in keeping the bad guys out."
"The time for governments to step in and tighten the rules in the interest of safety is long overdue.
The electronics revolution in your car isn't just limited to the big navigation screen in the middle of the dash. Virtually every system in the average modern car has been touched in one way or another by technology in recent years, and anything electronic is potentially hackable."
"The throttle, for example, which used to be a cable connected to a mechanical system, has largely been replaced by an electronic throttle that completely severs the physical connection between the gas pedal and the engine."
Carmi Levy, technology analyst, London, Ontario

"We're working to keep pace with the dynamic nature of cyber threats by incorporating security by design, developing internal expertise, and cultivating procedural and operational partnerships with organizations specializing in cyber defence."
Wade Newton, spokesman, Alliance of Automobile Manufacturers, Washington, D.C.

"[The accident that killed gonzo journalist Michael Hastings in Los Angeles that was featured on 60 Minutes was] consistent with a car cyber attack."
"You can do some really highly destructive things now, through hacking a car, and it’s not that hard. So if there were a cyber attack on the car—and I’m not saying there was—I think whoever did it would probably get away with it."
Richard Clarke, counterterrorism adviser to Clinton and G.W. Bush administrations  
The wreckage of the car crash that killed journalist Michael Hastings.
The wreckage of the car crash that killed journalist Michael Hastings.

From metaphorically 'killing' the computer controls on a jeep, as described in July's Wired magazine, to a hacker dialing in to the computer system of a journalist's vehicle to put the vehicle out of commission and the man driving it permanently out of commission, the vulnerability of vehicles and their drivers to the malicious attacks possible when those with terrorist intentions hack, threatening the safety of motorists at large, has become a growing concern to governments.

The Canadian Defence Department's research arm has undertaken a study into the vulnerability of vehicles to the possibility of remote hacking, given the few incidents where it has been demonstrated that interference of this kind dangerously threatens people from cyber-intrusions as a potential menace as yet little appreciated. Government intervention in the matter is required, according to one technology expert, since the automobile industry is lagging in its concern for secure vehicles.

These are vehicles being sold with advanced computer packages glowingly advertised as selling points in persuading the driving public that they incorporate not only convenience but safety features enhanced by the latest technologies. Manufacturers think of their products as "rolling smart phones", and encourage the buying public to value them for their multiple gimmickry. With built-in connectivity through computers and Internet connections guaranteed, what could go wrong?

The D.C.-based Alliance of Automobile Manufacturers claims it is preparing to advance an information-sharing hub and have it in operation by the end of 2015, enabling auto-industry companies to exchange details relating to emerging threats and real-time countermeasures. The suite of computer systems built into vehicles, stresses the industry, has aided in making vehicles more driver-safe, cleaner to operate, harder to steal.

And though the word has gone out about the potential vulnerability of the computer systems to hacking, the industry points out that no documented, real-world instances of moving vehicle hacking has been presented, as yet. Which disregards the reality that the on-board Internet-connectivity is a portal, yet one which can be opened only by those with heavy experience at hacking. Should someone with malice aforethought succeed in manipulating a vehicle's steering and braking, a worst-case scenario could occur.

When American cyber-security researchers, Charlie Miller and Chris Valasek hacked into a Jeep Cherokee's entertainment system, then ventured to the radio, air-conditioning and windshield wipers, they expanded their operation by cutting the transmission and its brakes in a convincing demonstration of just how effective their skills were in dismantling the safety features of industry that encourages motorists to believe that the skillful driver had full command of his vehicle.

Fiat Chrysler was moved as a result of that convincing and controlled experiment to recall 1.4 million vehicles to hurriedly patch up the vulnerable areas. Defence Research and Development Canada has put a tender out on a government procurement website looking for a consultant capable of studying the vulnerability of vehicles, and measures that can be taken to mitigate the pending problem before it becomes a living nightmare.

Their document states, of the modern vehicles which incorporate up to 200 computers, that "the hacking community has demonstrated many times the possibility to compromise the cyber security of cars" and that cyberattacks on cars represent "a more important concern [than that of information- and money-theft through computer hacking] since the safety of their users or the other users on the road might be at stake".


Labels: , ,

 
()() Follow @rheytah Tweet