We Need a Manhattan Project for Cybersecurity
medium.com
medium.com
Security is different from offensive capability -- I don't think the best way to secure infrastructure is through threat of mutual assured destruction -- if anything, being the worlds prime nuclear power (and conventional weapons power) -- the USA already have "assured destruction" covered. Sure, a country wide blackout would be devastating, but so would dropping a few terra-tons worth of nukes on the offender.
I think what's needed in terms of "cybersecurity" is more openness, better education and perhaps most important: better and more correct incentives. There's a huge gap between what is available (secure coding, secure systems, best practices (or even half-decent practices)) -- and what we see companies, governments and organizations do. I also think it is absurd to promote the Sony hack as a threat to national security -- talk about hyperbole. Some personal data and a little intellectual property was leaked. It pales in comparison to the allegations of commercial secrets stolen by the NSA on behalf of US industry, for example.
The real MP was building technology that they theoretically knew was possible. Most modern calls for an MP are "just throw a lot of money at this thing," which is how it works in games like "Civilization" but doesn't actually in the real world.
From TFA:
A real Manhattan Project for cyber would draw together some of the greatest minds of our time, from government, academia, the private sector, and civil society
. . . who would proceed to bitch at each other endlessly. I firsthand saw what should have been a nice cordial introductory meeting turn into an hour-long shitstorm about which person at the table invented the term "firewall" (since more than one of them had claimed credit).
I think we're fundamentally doing it wrong. We work to try to make things more secure, but perfection is not possible for humans. We need to accept that complex computer systems and networks cannot be secure. And find ways to make them useful dispite that.
i think that facility and all these fiber-splits secretly installed across the world has been the "Manhattan Project for Cybersecurity" :) Like with the original MP, sometime ago there was theoretical idea that it is possible to listen to and record the "whole Internet" and that would open new possibilities, incl. ones like "total awareness" and Tor traffic correlation... So the government has thrown best brains and money and "voila!"
Just by asking that question, you are on your way to better security. One key thing to understand is that security is a process -- it cannot be added on. Similar in that way to how "high quality" cannot be added (and high quality is often a prerequisite for security -- bugs (in sub-systems) are almost always bad for system security).
Another key is to see security as a trade-off between real threats and risks, and convenience[1].
For example, I don't currently encrypt my email (with gpg, my smtp server speaks SSL/TLS to those that are willing) -- I use webmail from time to time -- which IMNHO cannot mix meaningfully with gpg and/or end-to-end encrypted email. I have a bootstrap issue with both gpg and OTR -- very few of those I communicate with use either. So I cannot use either.
This is another aspect, which I've seen little discussed: secure communication is all about the network effect (I'm sure it's been discussed, but I have not seen it discussed much). Facebook is actually a positive point here: Facebook chat supports[2] xmpp, which supports OTR (but not in the browser, messages that are encrypted are unreadable to Facebook, and via the web client). By having chatsecure on my phone, and many friends on FB -- I actually have a few I can communicate securely with, via XMPP+OTR.
That google killed/are killing XMPP access to their IM, is devastating with regards to the security of IM going through Hangouts.
Another important point, is that security is all about looking at the system, and realizing that the system, like the original MVC -- when it was MVCU: Model-View-Controller-User[3] -- includes people. People, unlike hw/sw tends to forget passwords, type passwords into the wrong input window[4] etc.
I remember reading one of the "Rainbow books"[R], I believe it was NSA Orange Book[5], or maybe[6] a long while back, and found it to have a lot of good points on making a secure system. Maybe someone else have some newer recommendations?
Again, it's a complex question. You can't be confident you're communicating securely if you can't be confident you're using a secure system. Hence, Snowden, as seen in Citizienfour, tells the journalists to use an air-gapped (off-line) system for encryption and de-decryption. This is good advice, against most "normal" adversaries. But it is really hard to be paranoid "enough". It is easy to back-door a modern device via it's BIOS/boot-code/kernel, to install various key-loggers (in hardware or software) -- and most people don't realize how absurdly easy it is to break into most houses undetected (see: bumpkeys, lockpicks).
I've come to the conclusion that one small aspect that needs work is helping people choose and use better passwords/pass-phrases -- as that is often the weakest part of a system. Sometimes that can be mitigated by using hardware tokens to store keys and delegate encryption to. I'm afraid there are no easy answers.
[1] Should be a link here to a sign posted outside a secure facility, I think a prison or jail, stating simply: "Security is not a convenience" -- but I couldn't find it on-line. I believe someone used it in a talk on security a good while back...
[2] https://www.facebook.com/sitetour/chat.php
[3] https://heim.ifi.uio.no/~trygver/themes/mvc/mvc-index.html
[R] http://en.wikipedia.org/wiki/Rainbow_Series
The reason you need to protect data from nation-states is that there are enemy nation-states trying to get it, and there is no physical barrier between the data and them, so the only answer is to protect it from all nation-states, even the one where it is located.
The reason it has to be authorized is because data access is a 'rights' sort of thing (akin to property) and the processes that we put in place which insert a due process between data and a government agency need to be just as strong at the ones between property and a government agency.
For me, that is why the metaphor of a 'Manhattan' project doesn't work for me. If this effort were the Manhatten project we would be building a nuclear bomb that the people could use against any government but that the governments could not control. And well they would never sign up for that because they have nothing to gain from it.
I would much prefer to call the effort a 'Magna Carta' effort that forces the monarch in power to submit to the data privacy demands of the subjects.
And off in the corner, a few non-paid developers of F/OSS are creating better security products than all the above combined. Manhattan-style money throwing is not the answer.
And I take issue with the article's depiction of the Manhattan Project. "Those working on the Manhattan Project were dead serious about the threat before them." ... um ya well the vast majority of those working on it had absolutely no idea of what the project was all about. They all operated within a disconnected web of secrecy, not the best model for security imho.
The author "has served as a street police officer, senior adviser to Interpol and futurist-in-residence with the FBI. " He isn't a security professional. And his twitter feed doesn't give the impression of someone with any deep understanding beyond headlines and talking points.
http://www.cybergrandchallenge.com/
https://github.com/CyberGrandChallenge
AMA?
I don't know what you'd formally call this. It's not really an agency and I'm not sure how it's funded. I'm curious if something like this could spearhead this kind of project.
Anthem did not encrypt the data which was stolen.
Sony did not show any signs of basic competence in its data security either.
a Manhattan Project is useful if you have a really tight deadline, a very specific and achievable goal, and the problem you face is one where the technology you want does not exist yet.
but everybody in technology knows that the technology exists, and the problem is widespread incompetence and indifference.
the solution for that is not a Manhattan Project. it is class-action lawsuits.
think how fucked up this situation is. everybody in infosec knows that Anthem and Sony were ridiculous and 100% at fault in their negligence. yet people who get their info on this from the mainstream media have probably never even heard that point of view.
so you get utterly uninformed commentators who think that Anthem and Sony must employ geniuses of the first caliber, and that we need to take the "new" and "unprecedented" step of classified crypto research.
The problem is that few think like this, except in a few special industries where they live and die by not getting this wrong.
Ease of use and whatever gets things working fastest is generally the name of the game (and I don't blame businesses for this attitude, the market punishes anyone who is too careful or slow-moving in almost every industry)
The problems we have are:
1. High capability attackers (states, corporations) have a high motivation to compromise privacy and security and low motivation to improve privacy and security for users.
2. The tools relied on by users for security and privacy are often built by people with very limited resources (GnuPG, OpenSSL, nearly every other Open Source thing in the world).
Fixing security online requires audits and maintenance across a huge spectrum of projects, and historically there has been very little funding for such things. It's almost dumb luck that we have tools that are as good as they are, and we shouldn't be surprised by bugs like Heartbleed and Ghost and others. They're what happens when there is very little profit in maintaining core infrastructure.
Unfortunately, a "Manhattan Project" for cybersecurity wouldn't really work because the problem is a highly multi-tiered one without a clear end goal, with a lot of individual bits and pieces that are visible and have potential to be refined or started anew.
Where is the analogue in crypto and security? There is no unsolved holy grail. Frankly, we have all the technical tools we need to make the web an extremely secure place.
What we are lacking instead is general investment in FOSS tools, regulations that hold a company responsible for leaking user data and encourage corporate prioritization of security, and national education about security risks and basic Internet dos and donts (phishing etc).
And probably do a lot of damage to Silicon Valley. It would make startups much less risk-friendly.
"Sure, the new EPA dumping regulations would harm "small petrochemical startups", but if the river really is getting undrinkable..."
The solution is to harden a bunch of stuff. Clearly, the ideal solution is to just remake it with security in mind, but that still leaves a ton of ground to cover.
That's a nice thought, and I agree with it. Too bad the current and likely future administration as well as all the "cybersecurity" guys in the government right now support the exact opposite of that - because "terrorists". Just 2 weeks from now Obama is likely to announce policy to introduce backdoors in tech products. Yay "cybersecurity"!
It's about as sensible as suggesting a Manhattan Project for Mindliteracy--but I would suggest that teaching people to read and calling it just that might be more effective than trying to build a mindliteracy bomb against mindilliteracy.
Then Snowden came out, and we learned the U.S. government is doing the opposite, trying to keep all systems readily exploitable.
Surely the defense and intelligence departments already have hardened versions of OSs. As taxpayers, we actually own that software. We should all have access. Where's the EFF on this one?
Second, https://en.wikipedia.org/wiki/Security-Enhanced_Linux
Third, https://www.nsa.gov/ia/mitigation_guidance/security_configur...
echo 0 > /selinux/enforceAlso, if you read Fred Cohen's 1984 paper, "Computer Viruses - Theory and Experiments", in section 5 "Experiments with computer viruses" (http://all.net/books/virus/part5.html), Cohen mentions a "Bell-LaPadula based system implemented on a Univac 1108." No real details are given, but the sentence " The virus demonstrated the ability to cross user boundaries and move from a given security level to a higher security level" appears in the write up. I have to conclude Cohen is talking about some proprietary system.
There's also the famed Multics, known to have been used by the NSA on into the 1990s (http://www.multicians.org/site-dockmaster.html). The only certified multi-level-secure OS or some such. It did run on some odd hardware, though.
I conclude that the NSA at least has some weird, "hardened" or otherwise unusual operating systems. They're not widely used, it seems.
Technically, this is quite do-able. I think we'll see it on the server side in a few years.
2. We need fewer systems. Having each bank, each hospital, each government, each shop, each school, each business build their own custom systems and application by default is a huge mistake. Custom shouldn't be the default, it should be last resort. The existence of these custom systems is the very cause of all the inefficiencies, fragmentation, bugs, increasing demand for programmers, etc. That's some Tower of Babel shit all over again.
3. We need a common language. A language that makes sense to use in the 21st century. A language that help us think, a language that's computer assisted. Text? What a goddamn joke.
4. We don't know yet what an identity is. Am I one person? Can I play the role of two people? Can two people act as one person? Can a robot or an API have their own identity? In a future that's going be a lot like a distributed semantic marketplace, what we need is not security. What we need is accountability. Identity and fraud is what must be solved.
5. You tinfoil hat people should really take a step back and consider your paranoia. Privacy is not a good thing. At best, it's a necessary evil (temporarily). Browsing behind 7 proxies, encrypting the air your breath, praying Lord Snowden, demonizing the government you keep wanting to get bigger (you know, welfare and free stuff). Guess what, you're missing the entire point. If anything, your focus on these insignificant symptoms give the disease the opportunity to grow. You're the reason you might be right at the end. You're self-fulfilling prophets.
Sheeps be disagreeing.
Would you mind explaining your concept of identity? I have a hard time grasping what an "identity" would look like when it can be used by everyone as they wish by virtue of not relying on any secrets.
Absolutely not. It is one of the three major categories of auth (something you have/are/know). The problems with secret-based auth are either implementation-related or "between keyboard and chair" issues (password re-use, etc). If you have to pick one of token-based, biometric-based, or secret-based, what is a better option, exactly? Is it perhaps biometrics, which can't be changed (let alone inaccurate and almost always fool-able)? Or is token-based more appealing to you? "Something you have (and will lose)". The best we seem to be able to do today is Token+Secret based, ala internet banking token which requires PIN to output code. Failing the ability to actually ship bespoke hardware to each of your customers, we're left with secret-based. If the implementations (on both client/server side) were solid and users were educated about security, we'd be a hell of a lot better than we are now.
> Information wants to be free, and it will.
This means nothing. I just created an RSA keypair and then wiped it 35 times, just to spite you ;)
> Secrets must be kept secret at ALL time. With the coming death of privacy, keeping a secret will be ridiculously complicated and expensive. Secrets make a system fragile.
Secrets must be kept secret for as long as they are active, not all eternity. If your secret is compromised, you change it to a new secret. If you hadn't reused your previous secret elsewhere, you don't have a problem.
> 2. We need fewer systems. [...] Custom shouldn't be the default, it should be last resort.
As in: centralized authentication services, or better frameworks for auth? If it is the second, I'll give you this one. But if it is the first, no - nobody actually needs more of that. There are already plenty, and even useful in certain cases. But there are others that you absolutely do not want to rely on external authentication systems. When you call up your bank to shout at them because you can't log in, they don't have the option to say "talk to FB/Twitter/Google+/OpenID, not on our end". Also - not necessarily better security, you're just delegating those issues to someone else, who "takes security seriously". As a company/org, you're literally handing the keys that your users use to enter your site, to someone else. In situations like banking, medical, e-gov, etc. - that's a no-go.
> 3. We need a common language. A language that makes sense to use in the 21st century. A language that help us think, a language that's computer assisted. Text? What a goddamn joke.
What? Natural or Programming? You're asking for something non-textual? Have you caught up with English, Math and Javascript? I genuinely don't know what you're asking for.
> 4. We don't know yet what an identity is.
All you had to do was ask. This stuff has been discussed in OAuth extensively.
> In a future that's going be a lot like a distributed semantic marketplace, what we need is not security. What we need is accountability. Identity and fraud is what must be solved.
So we need to protect the confidentiality and integrity of these systems, but we don't need "security"?
> You tinfoil hat people should really take a step back and consider your paranoia. Privacy is not a good thing.
That's interesting - my people and I spoke and we'd like to know more. How is privacy not a good thing? Are we exclusively talking digital privacy here, or remove-bathroom-doors privacy as well?
> demonizing the government
It isn't really about this government, it is about this government's surveillance and what the next government will do with all that data. And anyone who hacks them.
> Guess what, you're missing the entire point.
I am indeed. This issue is about the practical state of affairs of our technological stacks. What points are you making? 1. Secrets are bad security. 2. Centralized auth systems 3. Non-textual computer assisted language that helps us think. 4. (identity confusion) + we don't need security, we need security. 5. Privacy is not a good thing.
> Sheeps be disagreeing.
Bah, just felt like engaging a troll for once.
* Present company excluded.