Jon Watson's Death by Tech: Recent Episodes

Jon

Audio version of some of my newsletter editions.

jonwatson.substack.com

View Details

Back in January, I decided to take my writing up a notch. I used to just “blog” which was this nice relaxed pace, writing only when I felt like I had something interesting to say. While that provided almost no stress, it also didn’t provide much content. It wasn’t that I felt I had nothing to say, I just felt like someone had already said it. I had no incentive to write about the things I like because a million other people were already writing about those topics. At around the same time, I started to become actively aware of the decline of quality in the mainstream media.

Google has almost singlehandedly destroyed the news market by creating Goggle News which essentially denies the ability of any news outlet to make money on their product. The news media responded in the same way that every other industry that has been butchered by a Google or an Amazon can, and either shut down or started producing the only content it could afford - poorly researched and hastily written articles. Eventually, I came to realize that I hadn’t read a “mainstream” newspaper or watched a “newscast” in months, perhaps years, preferring to get my information from individuals and smaller niche sites that didn’t need Google to get by and were able to survive, if not exactly thrive.

Yesterday’s “fringe” content dominates today’s conversations.

I came to realize that these two things naturally came together. Of course there were a million people all saying the same thing! The vacuum left by Google’s outright attack on the fourth estate sucked these voices in from the fringes and they became prominent. It was at that point that I decided to write more. Write stuff I knew about. Write it in my own voice instead of conforming to the dull, lifeless drone that media companies had spent decades honing to perfection. Write the stuff I want to write without second-guessing myself about tone; without trying to write “evergreen” content for the clicks.

I (perhaps naively) believe that I create useful content that people like.

To kick this off, I joined Medium and for several weeks I wrote articles there. It did not take very long for me to realize that although my idea was good, my solution was not. Medium is a very broken idea, but you need to really muckle on to it and live it hard for a little while to discover that. My final article on Medium was about how it had unwittingly built a system that rewarded writers that published poor quality articles while it was attempting to do the exact opposite.

I am a technologist at heart. I build things every day. Some are simple. Some are mind-blowingly complex. Some are embarrassingly stupid and will never see the light of a Github repo, and some are the pride and joy of my career. Because of my long experience building things, I know that the first version of anything never works. It is always a learning tool and will always be thrown out, so I looked for other solutions.

"Plan to throw one away; you will, anyhow." - Fred Brooks, The Mythical Man-Month

I reflected on the fact that I missed mainstream media so little that I did not initially realize that I stopped consuming it. It was only after being absent from it for months, perhaps years, that I said “heeey…I wonder if the Globe & Mail newspaper still has door delivery to my little town”. (Spoiler; it no longer does and the digital edition is now the same price as the paper edition that used to be delivered to my door.)

I wondered: if I am no longer consuming traditional media, am I ill-informed? Do I not know what is happening in the world anymore because I stopped reading newspapers and dropped my subscriptions to news outlets like CBC? I was careful to eliminate bias confirmation as I explored this idea. I purposely reviewed the media outlets that I had let slide into oblivion to see what they had been reporting on and whether I knew about it already. And, if not, why not?

My investigation ended with the confirmation that I was, indeed, informed. And while I certainly encountered stories I had not heard of, they were not stories that would have interested me had I known. Things like changes in hunting seasons and local stuff in other provinces that have no effect on me are some examples. I came to understand that I did not check out of reality, I just subconsciously made choices about outlets that I considered to have quality information. It’s no surprise that the suffering media outlets I grew up with did not top my list of purveyors of quality news.

Aggregated news is a product, not a legitimate attempt to inform.

Instead, I realized that I now get my info from specific sources, and frequently collaborated more complex issues with other resources. Instead of paying the Globe & Mail for its Ontario edition - which is the closest edition to my east-coast home, but still several provinces of relevance away - I pay for a monthly subscription to All Nova Scotia.

In lieu of hoping that the doddering CBC or CTV or will get even basic information security news correct, I read people like Brian Krebbs and follow sites like Threat Post and Dark Reading.

Rather than relying on a third party to curate information that is in its best interests to feed me, I started going to the source. I check-in with my town website to know what is important hyper-locally. I watch the daily COVID-19 briefing from our provincial Premier and Chief Medical Officer of Health to see what the health orders and epidemiology says about my near future. I reach out to my Mayor or councillor directly when I have questions about things that fall within their domain. And when I need more than a three-bullet PowerPoint slide to understand complex legal issues in the digital landscape in my country, I go to Micheal Geist.

Opinions aren’t news

I now eschew opinion pieces in a long-in-coming epiphany that opinions aren’t news. There is no value other than a temporary fanciful distraction in knowing what doctors think about legal matters. There is no value in paying attention to what economists think about epidemiology. And there is no value in news outlets that have lapsed into hapless opinion mills because that is the only unique content they are able to muster anymore.

It is with the sincerest of hopes that I can contribute meaningful content and commentary to the discourse that I now decide to reel in all my writing activities and concentrate on one single project: my Death By Tech newsletter/blog that you’re reading or listening to now. I will no longer be continuing the One Time Pad security newsletter and I will be removing all my content from my main site at jonwatson.ca and focus solely on writing content here.

How can you support me?

Subscribe to my content, even at the free level! That encourages me and makes me want to continue.

If you’d like to send a little more love my way, you can do that too and I will reciprocate by delivering twice the content to you. Everyone who subscribes, whether for free or with a paid subscription, gets at least one post a week from me. Those who support me financially get twice as many posts.

I don’t write “better” content for subscribers. I don’t save “the good stuff” for paying subscribers. Paying subscribers just get more content because I alternate between posts. Every second post goes only to paying subscribers.

In addition, regardless of when you jump on board as a paying subscriber, I will unlock all of my previous paid content in my archive for you so you will have instant access to a ton of new content. If you’re not a paying subscriber now and you visit that link, you will see some content with a padlock icon next to the date - that’s the extra stuff that is waiting for you.

I get that we all have subscription fatigue. $5 here and there is a pain to manage and it adds up. To help with that, I am offering many, many ways to contribute - you probably already have an account with one or more of these services that you can use.

Here's some actionable information:

If you are a free subscriber:

You’re helping me already. Thank you! Would you consider becoming a paying subscriber to support me even more? You can use this link to get 50% off if you subscribe directly here on SubStack.

If you would prefer to support me via LiberaPay, PayPal, BAT, or Crypto Currencies, please click this link for info on how to do that.

ALWAYS share the free editions you receive with anyone you’d like.

If you're already a paying subscriber:

You’re already supporting me. Thank you! If you want to help even further, you can:

Send this two-week free trial link to anyone you think may be interested: https://jonwatson.substack.com/2weeksFree

OCCASIONALLY share the paid editions you receive with a friend or two that you think will like it.

If you're not a subscriber at all yet:

Maybe you stumbled across this post or perhaps you arrived here via an article someone shared with you. In any case, thank you for reading this far. If you’d like to support me, the best way to do that is to become a subscriber, either free or paid.

If you’re not sure you want to take the leap right away, subscribe for free to get at least one edition per week. To subscribe, click that big blue button at the top of this page.

If you’re on the fence about becoming a paying subscriber, feel free to use this link to get a free two-week trial during which you will get both paid and free editions. That is at least two editions per week.

If you would prefer to support me via LiberaPay, PayPal, BAT, or Crypto Currencies, please click this link for info on how to do that.

Regardless of what you decide, I hope you came away from this post with a better sense of what I am trying to accomplish and how much I like creating content. Thank you for reading.

Subscribe at jonwatson.substack.com

View Details

The tagline for my Death By Tech blog is “Mostly tech. Lots of Linux. Some fiction. A few dogs. The ramblings of a career sysadmin working in infosec.” This is one of those posts that definitely fit into the “rambling” category. There's not much tech here, but I hope you enjoy it anyhow.

I am not a very political person. I find life is full enough that I don’t really have the desire to follow our politicians very closely, or create a deep understanding of who is who in our government other than knowing which party is in power and the identity of my local representatives. But, like everyone else, there are periods of time when I become more focussed on politics because of something that is happening at the time. The Coronavirus pandemic is one such thing, and I have been paying closer attention to our politicians and government during these days. With that heightened awareness comes exposure to some ideas and processes that I normally don’t think about. Namely, how my closest neighbour, the United States is faring through the pandemic.

The way that the United States has been handling the pandemic has caused me to pay more attention to the US overall, not just the pandemic stuff. And part of the reason that the US was slow to bring in measures, and basically denied it was even an issue in the early days, is because taking action would have an economic impact. Even today, with the US having 1/5 of the total global deaths, the US is still worried about the economic impact of keeping the economy closed down and how that will affect the November election.

We’re all well aware that the U.S. is the poster child for capitalism. Businesses rule the country, even more so now during this time because of the incumbent POTUS, and lobby groups and industries, as well as private billionaires, funnel massive amounts of cash into the coffers of politicians who will push their agendas. Politicians and industries are willing to completely gut working systems putting the country at a permanently high risk of collapse as we’ve seen from the 2008 sub-prime mortgage fiasco, and the seemingly unstoppable rise in the US debt. The country seems to be on a crash course to an economic crater to me, but I am neither an economist nor in possession of any other skills to make that call with certainty. But what I do have is a lot of curiosity and I started thinking about how the U.S. ended up like this.

How did it go from the beacon of freedom in the world so loved that France sent a statue (a remarkable feat even today) to a country that seriously considers just letting the elderly die than risk damaging the economy? That’s an incredible fall from grace and it’s hard to fathom. But, every big thing is comprised of small things. And the first few steps that began this journey to extreme capitalism may have involved a pig.

The parable of the pig

We all understand that money is ephemeral storage - it’s a temporary place to store value. Prior to money, there was no way to store value. If I had a wheelbarrow and I wanted a pig, I'd have to find someone with a pig that wanted a wheelbarrow. That does not scale well but it was the only way to do things because, at that time, the intrinsic value of an item was the only value it had.

But either side of that transaction does scale when the transactions are decoupled. There are many more people who individually want a pig or who want a wheelbarrow than there are people who want a pig and also have a wheelbarrow to trade for said pig. To free up the vale of that wheelbarrow prior to finding that pig guy who also wants a wheelbarrow, we need money.

Money allows the wheelbarrow guy to sell his wheelbarrow to a guy without a pig and temporarily store the wheelbarrow's value in money until the pig guy comes along. He can then release that stored wheelbarrow value that is currently stored in money to the pig guy and finally get his pig.

This is good because it allows the wheelbarrow to be put to use by someone now instead of sitting around collecting dust waiting for pig guy. The problem arises when the other sellers at the market who do not sell pigs realize that wheelbarrow guy, now bereft of his wheelbarrow, has money in his pocket. The sellers start to focus on wheelbarrow guy and entice him to buy their wares with that money.

Wheelbarrow guy starts to think that he doesn't need that pig after all. He needs that thing that the merchant is holding up right here in front of him at the market. That thing that he can easily buy with his stored wheelbarrow value right now instead of the eventual pig seller that may never come along.

The merchants are less interested in wheelbarrow guy’s needs or well-being than they are about moving that money from his pocket to theirs. Somewhere in there are the seeds of capitalism. When the reason for the market changes from the exchange of goods to the collection of wealth, that is where capitalism gets a foothold and survives.

I’m not suggesting that we go back to bartering. The existence of temporary ways to store value helps a lot. But it goes awry when storing value temporarily turns into hoarding wealth for no particular purpose.

I’m not sure if this makes sense. Heck, I am not even sure this is a parable. But it has some truth to it and we’re seeing what happens to a country that has lost its way and seeks only to hoard wealth rather than trying to operate a legitimate market to facilitate peoples’ needs. The impact of successive governments that deprioritize the health of its citizens in favour of supporting the hoarding of wealth by other citizens far outpaces mere economic concerns. We’re seeing an example of this now in the US. One of the most advanced countries in the world has the largest number of infected people and is overwhelming its healthcare system in many places because commerce is the critical care patient in the US, not the people.

Subscribe at jonwatson.substack.com

View Details

Note: I mistakenly sent this post to only paying subscribers yesterday, but it was supposed to be for all subscribers. I apologize to those of you who are getting this twice.

OSSEC is a popular Host Intrusion Detection System (HIDS). It is very capable out of the box at notifying system administrators of indicators of compromise such as suspiciously changed files and taking action against badly behaving IP addresses that are doing nasty things like credential stuffing. OSSEC doesn’t need a lot of fancy configuring - its basic functions just work after install, and most of the fun comes from configuring it. This article isn’t a deep dive into OSSEC, but it is an overview of one of my favourite features: OSSEC custom integrations.

Daniel Cid is the original author of OSSEC and maintains his own OSSEC fork and instruction here. Once you have OSSEC installed following those instructions, continue on for some fun.

Custom integration support

You should find OSSEC in /var/ossec. We’re going to pay attention to two things within that directory:

/var/ossec/etc/ossec.conf file, and

/var/ossec/integrations/ directory

The custom integration feature of OSSEC is a simple, but really powerful feature, that allows system administrators to cause arbitrary things to happen in response to an OSSEC action. Primarily, I use custom integrations to send OSSEC block data to customer SIEMs such as Splunk. However, a custom integration can call any executable file so the possibilities are literally endless.

The basic custom integration script

Integrations are executable files and the basic criteria for an integration to fire upon an OSSEC event are:

Each integration is associated with a log file that OSSEC is monitoring

The integration file must live in /var/ossec/integrations/

The integration file must be named custom-$FOO, where $FOO is arbitrary.

The integration file must be configured in the /var/ossec/etc/ossec.conf file

Let’s look at at a shell script that will send data to an HTTP endpoint:

!/bin/sh ALERTFILE=$1 APIKEY=$2 WEBHOOK=$3 # Send it curl --data "$alertlog" "$WEBHOOK"

OSSEC sends the log file, any configured API key, and the endpoint to the script. We capture those in the ALERTFILE, APIKEY, and WEBHOOK variables, but that is not necessary. It just makes the script easier to understand.

OSSEC also populates a variable named $alertlog which contains the actual log entry that triggered the alert.

If you’re sending data to and endpoint that needs authorization, use the APIKEY. For example, the curl call would look like this if the endpoint was a Splunk HTTP Event Collector (HEC):

curl -H "Authorization: Splunk $APIKEY" --data "$alertlog" "$WEBHOOK"

Obviously, you would want to include some error checking and logging into this script. You can also manipulate the heck out of the content of that $alertlog variable to customize the payload or extract/inject interesting data. I have a few integrations where I have added data, such as GEO IP data, to the payloads before sending them out. But, these are the bare bones you'd need in order to send data to some endpoint, such as a Splunk HEC.

Triggering the custom integration

Because the integration is just a script or some other executable file, you can build it and test it just like any other piece of software. However, once you’re happy with it, just plunking it into the /var/ossec/integrations/ directory isn’t going to work. You still need to tell OSSEC about it.

If the script above is saved in /var/ossec/integrations/custom-basic_script, then we would need to configure the /var/ossec/etc/ossec.conf file with a section like this:

custom-basic_script jonwatson.ca. 45TERT$GU)JHTE https://my_splunk.instance/services/collector

This configuration tells OSSEC to fire the /var/ossec/integrations/custom-basic_script file whenever an event is logged about the jonwatson.ca site in the OSSEC log.

The event will be sent to https://my_splunk.instance/services/collector using the 45TERT$GU)JHTE< API key if I use the second curl example which utilizes the -H Authorization header.

Other ideas

I primarily use the custom integrations to send data to SIEMs, but there are others. There are PagerDuty and Slack integration scripts that do other things under different criteria. That is how we get OSSEC to let us know of more critical things it is seeing. There are a million things you can do with these custom integrations, even kicking off a runbook or series of events. If you have any interesting OSSEC integrations running, I’d like to hear about them in the post comment.

Subscribe at jonwatson.substack.com

View Details

I’ve worked from home for 13 years, exclusively for the last 7. By now I have a sweet setup that meets all my needs. My office (yes, an actual office) goes way beyond the 10-step listicles that most blogs are posting these days amid the Covid-19 pandemic, but it’s hard to remember how it was in the beginning. I am trying to remember how my office started and I am envisioning the latest crop of forced work-from-home office workers learning the same things I learned years ago. My memory isn’t perfect, but here are some of the things I recall learning about working from home that I am betting most office workers haven’t even considered.

Ergonomics - If it looks good, it’s not.

There are many threads on Twitter and the Fediverse where people are posting their home offices. Honestly? Most of those pictures horrify me and bring me back to a time when I was just getting started and was equally clueless.

Photo by Izabelle Acheson on Unsplash

See that desk above? Sure it looks all feng shui and it’s clean and unobtrusive. But you’re going to need it 40+ hours a week - unobtrusive isn’t what you’re going for when you’re dealing with something that takes up a third or more of your waking hours.

I understand that most of the people forced into working from home now aren’t into it for the long haul. There’s not a lot of budget floating around for surprise pandemics, I get that. But if this is what you’re planning on using, you’re going to regret this at about 2:30 this afternoon.

I wrote an article with tips on how to combat ergonomic and repetitive stress injuries when working from home. It deals with real-life solutions to the aches and pains my body gets from being the world’s best sysadmin all day. Some of my articles are for paying subscribers only, and that article is one of them. But, because I’m a nice guy and you’re stuck at home, you can subscribe for 1/2 price using the button below to unlock all past and future paying articles.

The bottom line is that you’re going to need to get a better set up or make sure you take that laptop and move around to different areas such as the couch and the kitchen table during the day if you want to stay upright.

Your work laptop sucks

I have learned more about the state of consumer hardware than I ever wanted to know at this point. Specifically, how cheaply laptops are made, including that beloved Macbook Pro we all drool over.

Your office has probably issued you a laptop and kicked you out of the door. Much like that sad, sad home workstation pictured above, that laptop is not going to make it very long if it is your sole computer.

Laptops are kind of like health benefit plans. Many crappy health plans sound good because they’re filled with useless stuff that nobody is going to use. Instead of giving you $2000/year for dental work which you WILL use, they’ll give you $300 in dental work and $1000 in massages and acupuncture that nobody will use. Laptops do the same thing: manufacturers will give you tons of RAM and disk space, much more than you’ll ever need for compiling that TPS report, but they’ll scrimp on the screen, the keyboard, and the hinges. The things you actually need.

I highly recommend obtaining a standalone keyboard and a second monitor if you can. Both of those items will help a lot because you won’t wreck your laptop keyboard inside of a month, and you will have a nice bright screen with good resolution to stare at all day.

Just for reference, I am on my second work provided Macbook Pro because of the dreaded keyboard issue. In addition, our Slack rooms are filled with people returning or servicing their Macbooks constantly. It doesn’t really matter how much your work spends on your laptop, it won’t be good enough for your daily driver without some help.

Evolving expectations and calming chaos

One of the challenges that took me the longest to resolve was that of setting reasonable expectations for myself. Many work from home articles talk about the necessity of developing enough discipline to do actual work while at home. I have never had that problem. I have always had the opposite problem; I found it hard to disconnect from work because there was no solid social signal that I was done, such as leaving the office.

It is one thing to deal with that personally, but it can be complicated by the level of work-from-homeiness of your colleagues. When I first started working from home I was a lone-gun contractor and all my clients were solo entrepreneurs. Needless to say, we all worked far too much in those years. Once I became a remote employee, it became easier to manage my time because there was a more natural rhythm to it. As my office colleagues left the office, the day naturally ended. And when I finally became a remote employee in a fully remote company, it all came together nicely. Everyone had been through what I was going through, and I had lots of examples to follow of fellow employees shutting down Slack and email at the end of the day to disconnect.

The current situation has a lot of people that are unfamiliar with working from home all thrust into that situation. When you’re struggling and your boss is struggling and your boss’ boss is struggling, things can get pretty frustrating really quickly. I am envisioning entire organizations with no clue about operational cadence outside the construct of an office and wondering how much chaos that is introducing into people’s lives.

My country’s government medical officials are stating that the pandemic-mandated social distancing will go on for months at least. That means you need to get a grip on any chaos in your life that working from home is causing because you likely won’t be able to just ride it out and be back in the office before you lose it. I’ll stop short of giving advice on how to deal with this because that would turn this article into a listicle that I abhor.

Tell me stuff

It is hard for me to go back to the first days when I started working from home. I just don’t remember all the challenges I faced. If you’re one of the people who has had working from home forced upon them, tell me what it is like. What didn’t you know? What surprised you? How easy is to? You can leave comments at the bottom of this article.

Subscribe at jonwatson.substack.com

View Details

“If you’re not paying for the product, you are the product”, or so the saying goes. Free internet services abound and in the beginning, we did not put much thought into why; we were just happy to have the free email account or free social media arguments with strangers or whatever the case may be. Over time, we became a little savvier and started asking questions as to how these companies paid for this “free” service, and by now it’s so obvious that our personal data is valuable that even bad guys are stealing it and selling in on the black market. But how valuable is our data, really?

Setting the value of anything is difficult. There are many factors, such as how much money it took to get the item into a saleable state and how much desire there is in the market for that item. In the case of personal data, it gets even more granular.

For example, hackers are generally not the omnipotent Neos that are portrayed in the movies. Most of them are stumbling around the internet hoping to find something unsecured that they can sell. Because most of them don’t have any master plan, they end up with dribs and drabs of personal information such as a credit card number, or a PayPal login, or a Social [Security/Insurance] Number. Pieces of data like that are less valuable than “full” packages which include everything a bad guy would need to assume an identity.

For non-criminals, the valuation can be even harder because the transaction is never as cut and dried as “here’s a valid passport number, give me $30”. The purchaser just gets all the data the selling company has and it is up to the acquirer to figure out how to monetize it. How much money can a company make if it has a list of thousands of middle-aged account managers in Boca Raton that make over $100K a year and have two dogs? I don’t know, but this type of question is what purchasers have to answer to prevent overpaying for a company.

There are a number of reasons why a company purchases another. Two of the big ones are to acquire technology and to acquire data. The US courts are tied up for the next decade with patent suits and companies generally want to avoid being named in an intellectual property lawsuit. There’s almost no value in winning a patent lawsuit because the winning company just continues to keep doing what it is doing, but it has now given a ton of its money to lawyers so it comes out if with less capacity to carry on business. A much better plan is to just avoid any potential lawsuits entirely by purchasing a competing or complementary company outright, including all its intellectual property.

The second main reason for acquisitions these days is to acquire a company’s data. Facebook is the 800lb gorilla in the room and it has the largest trove of user data on the planet. That data is perceived as very valuable and many companies would love to have it. Facebook generates over 98% of its revenue by selling ad space to advertisers targetted by that user data. Facebook has a market capitalization of over $4 billion dollars, so that is a good insight into how much advertisers are willing to pay to leverage Facebook’s user data.

Let’s look at some recent acquisitions to get a sense of how much our personal data is worth.

Microsoft acquired LinkedIn: $60

LinkedIn kind of a unique site in that it’s a social network, but targetted at businesses, workers, and job seekers. It goes off the rails now and again, but for the most part, it works as advertised and discussions on the site are generally work-related. Most of the personal data on LinkedIn surround employment history and work connections. It’s not exactly the spiciest of personal data, but it was still worth $26 Billion (with a B) to Microsoft. I think it is fair to say that Microsoft didn’t need the technology and most of that value is in the user data.

LinkedIn makes most of its money from recruiting, followed by advertising.

At the time of the acquisition, LinkedIn reported 433 million users. This makes each user’s data worth about $60. Not very much individually, but quite a number overall.

Intuit acquired Credit Karma: $71

Credit Karma is a service that allows users to check their credit reports for free and without damaging their reports by adding “hits” to it. The service makes money by recommending credit devices (credit cards, loans, etc) to users and presumably takes a commission for doing so. It operates in Canada, the US, and possibly other countries.

Intuit is in the complimentary space of providing personal and professional finance products such as QuickBook for accounting and Mint for personal expense tracking. The marriage here is a no-brainer and honestly, running an API call to get a credit report isn’t exactly ground-breaking technology. It’s pretty obvious to me that the value Intuit sees in Credit Karma is the user data.

At the time of the acquisition, Credit Karma has 100 million members and Intuit paid $7.1 billion for it. That is about $71 per user.

Facebook acquired Instagram: $33

Given that one of the most profitable companies in the world makes almost all of its money from user data, I thought that this would be a whopping number. However, it seems that even Facebook knows that user data isn’t all that valuable in isolation - it needs volume to be worth a lot. Another interesting thing about Instagram is that it had zero (as in NO) revenue at all when purchased.

At the time of the acquisition, Instagram had 30 million users and Facebook paid $1 billion for it which is about $33 per user.

What do bad guys pay for your data?

The example of acquisitions above shows us what companies consider personal data to be worth. But there is another very large market for user data and that is the black market. These days, the black market is the Dark Web (not to be confused with the Deep Web) and some enterprising researchers at Experian have compiled some data on what personal data sells for on these sites.

A social security number sells for about $1. On the other hand, a passport can sell for $2,000. Here is an opportunity to show how money can replace work: if a bad guy has a valid SSN, he can use that to get progressively more difficult pieces of identification and can eventually get a passport under that person’s name. But that takes time and therefore even though an SSN can eventually beget a passport, bad guys are as lazy as the rest of us and would prefer to just pay a 2000% markup instead of doing the work. Free markets, FTW!

In between, we see working logins to online accounts such as PayPal worth an average of $100 or so, depending on how much money the bad guy estimates he can get out of the site, and even loyalty cards ($20) and diplomas ($400) have value.

Final thoughts

I went into this article thinking that personal data would be worth a lot more. Whenever I read about an acquisition it has these huge numbers; billions and billions of dollars are spent every time and I thought that would be reflected in large numbers for each individual user data set. I was so sure that the thesis for this post was going to be something like “your data is worth so much more than you think”. But, despite my leaning towards bias confirmation, it is just not true. Our individual user data really isn’t worth that much after all.

Subscribe at jonwatson.substack.com

View Details

I worked at a number of jobs when I was younger before I finally ended up in my technology career. I think most people go through a bunch of similar jobs growing up such as working in the hospitality industry. While I did have a burgeoning career in cooking, I left that at one point and got into physical security. I joined the army reserves (AKA “the militia”, but not to be confused with the American-style prepper gun nut militias) as a part-time job, and for my full-time job, I worked as a security guard. I’m not in the physical security field anymore, but there’s a lesson I learned during that time that has stuck with me for my entire career and still serves me well today in the information security field and it’s the topic of this post.

When I was toiling away in the middle of the night as a security guard at hospitals and truck companies, my supervisor would stop in a few times a night. He’d always want to see my rounds report and he would always tell me to put more detail into it. I’d say “but there’s nothing to say, nothing happened”. He’d reply “Nothing happened because there’s a security guard roaming around randomly looking for trouble. We need to make sure the client knows that.”

Eventually, I got out of my security guard mindset and started thinking like a manager. I don’t know who hired our company to provide security at these companies, but someone did. And that person has to justify that cost to someone periodically. I started to realize that the measure of success for that person’s decision is that NOTHING HAPPENS. But you know what’s really hard to justify at budget meetings? Spending money on something when NOTHING HAPPENS. I started putting more detail into my reports at that point because I started envisioning that person defending my wage. I started recording when I noticed a padlock unlocked, or a car I hadn’t seen before driving by the compound, or an office door open that usually is not. I wanted to give that person a good idea of what they are paying for and give them the tools to continue paying me. I envisioned the finance people at the meeting denying the security budget request because “we don’t need that, nothing happens anyhow.”

I envisioned the finance people at the meeting denying the security budget request because “we don’t need that, nothing happens anyhow.”

Infectious Disease

This problem isn’t just a security problem, it exists in many areas. Anti-vaxxers are an example. In recent memory, anti-vaxxers decided that inoculating the population against measles was no longer necessary because nobody has measles anymore. Well, guess what happens when you remove the thing that is making NOTHING HAPPEN? You get a measles outbreak in one of the most medically advanced countries in the world. (CDC)

The majority of cases were among people who were not vaccinated against measles

Nothing was happening because something very important was happening - vaccinations.

Infosec

It’s hard to put a value on security. That is true in the physical security world and it is true in the infosec world. When security works, nothing happens, and it’s hard to predict what could have happened if the security was not in place and the value of the damage that this thing-that-did-not-happen could have caused.

Infosec prevents things from happening by employing the “kill chain”. Yes, the “Cyber Kill-Chain” (or Intrusion Kill Chain) is a model, just like its roots in the military kill chain. It has problems, but so does the OSI and we use that all the time. Infosec is effective because it severs the kill chain at the earliest possible opportunity which renders the attacker unable to complete its mission. (Sucuri)

Infosec “security guards” identify reconnaissance activity and mitigate it, therefore NOTHING HAPPENS because the attacker cannot get enough intel to proceed to step two and weaponize an attack effectively. At my work, we sometimes see customers decide to let their Web Application Firewall (WAF) subscription lapse; some of them actually cite cost as the factor. A measurable chunk of them come back a month later with an infected website. The WAF broke the kill chain for them, and when they removed it, the attackers were able to advance their attack successfully. But because the WAF as working, the perception is that NOTHING HAPPENED so there was no monetary value in maintaining the subscription.

Reporting

These are but a few examples to show that reporting matters. A lack of incidents doesn’t get noticed; we need to find a way to report the unnoticeable things that are preventing noticeable things from happening. The CDC graph and narrative does a good job of this: it shows that there is a correlation between measle outbreaks and a drop in vaccinations. It is much harder to do this with infosec because it’s more difficult to determine what is a deliberate recon and what is just weird traffic. And, even more importantly, if you are reporting an incident further along the kill chain than a reconnaissance, you’re effectively reporting that something DID happen despite the measures in place, but was still mitigated at later steps.

It’s no secret that I use the Sucuri WAF to protect my sites and we go out of our way to provide reporting to our customers so they know there’s a reason that NOTHING IS HAPPENING to their site.

Sum up!

Infosec workers and managers need to provide some level of reporting to stakeholders. It can be tough to do because many times when something trips an IDS, infosec workers investigate and determine that it was just a harmless port scan and close the alert. But that port scan should be recorded somewhere; not because it may escalate later (although it may), but because stakeholders need to know that they were port scanned, they were targetted, and the defence measures in place mitigated the attack right at the first link of the kill chain. That is what stakeholders are paying for so they need to know they’re getting something for their money.

Subscribe at jonwatson.substack.com

View Details

I always get a bit nostalgic this time of year. I think it is a combination of my impending birthday and the fact that we’re socked deep into the Canadian winter in February and my work from home lifestyle has made me utterly stir crazy by now. Whatever the reason, today I’m reflecting on how I got where I am in my career, and acknowledging that almost all of it has to do with a passion for technology rather than any kind of career plan I had for myself. I never did, and don’t now have any idea what I want to do in a few years. I’m just one of those lucky people that does what they love and the career followed. These days, $DAYJOB dictates what I learn next, but that wasn’t the case in the early years. In those days, everything was wide open and new and exciting. This post reflects on those early pre-internet years.

198…3?

I can’t remember the circumstances surrounding this, nor the actual year, but in the early 80s, my parents bought a Commodore Vic 20 computer. It was ostensibly for “the family” but nobody had any interest in it but me, and it quickly moved from a central point in the house where everyone could access it to my bedroom. As one of the first computers aimed at regular people instead of businesses, it did not come with a monitor. It was designed to hook up to an existing TV set via an RF toggle just like the gaming consoles of the era did. Some time prior to buying the Vic 20, my parents had bought us all our own small black and white TVs for our rooms so that is what I used for the Vic 20 monitor. I can’t remember if the computer had color or not, but I never saw it in any case.

Initially, my main use of the Vic 20 was gaming. And of those, the game I remember the most was Adventureland. It was a text-based adventure game where you have to perform certain actions in a certain sequence to get to the end. I played it for hours and I did reach the end a few times, but I can’t remember the details now. I do remember a bear, chiggers, and a gas bladder, perhaps not in that order.

Somewhere along the way, I discovered the BASIC programming language. A friend of mine down the road had a Commodore 64 and a disk drive. It was much faster to write and retrieve code to the disk drive instead of the dataset (tape recorder) my Vic 20 came with (image below). Plus he had a color TV and…gasp….a 300 baud acoustical modem. I moved out of the area after a few years and have never seen this buddy in real life since, but those few years were packed with programming and BBS’ing and set the stage for a life-long love of technology.

Around the same time, my junior high school (grades 7-9) went on a major computer bender. It borrowed a Volkswagen-sized Hewlett Packard card reader from somewhere and my math class was put on hiatus for a month while we learned what to do with it. I still remember my math teacher, Mr. Wareham, asking us to instruct him how to stand up from a sitting position, step by step, as a learning tool to understand the type of discrete directions we’d have to provide to a computer in order to make it do anything. We then started penciling in the cards, shoving them into the computer, and marveling over the little ticket tape response that printed out showing the results of our work.

Shortly after that, two or three Commodore PET personal computers showed up in a slightly large-ish closet that became “the computer room” at school. It had a sign-up sheet to control the rush of students who wanted to use them. But, much like the Commodore Vic 20 in my house, these Commodores also weren’t all that popular so the reality was that I could use them whenever I wanted.

Around that time I got my hands on a BASIC programming book. Although I had already been programming rudimentary games in BASIC, I had no “formal” training. That book introduced me to PEEKs and POKEs which elevated my programming to a whole other level. I’d frequently run out of memory for my games on my Vic 20, but my buddy with the Commodore 64 was always ready to hack away, and we built some reasonably impressive games for a couple of kids. We even sent one to Thorn EMI but they rejected it. In retrospect, it was nice to get a response at all.

My family then moved across the country and the Vic 20 disappeared somewhere, and my interest in computers went with it for a few years.

199…0?

By this time I had failed to graduate high school, had spent many years running with the “wrong crowd” but somehow found my footing again and was the sous chef for a successful mid-range casual dining chain. Somewhere around this same time, my interest in computing was rekindled and I bought a used laptop, or what we called a “luggable” in those days. It had a 20MB hard drive and a monochrome blue VGA monitor. It came with Windows 3.0 installed and my mother-in-law lent me her Windows 3.1 disks so I could get all modern. I remember installing DOS 6.0 and then installing Windows over top of that. But the important thing is that it had a 1200 baud internal modem. That was a reasonably fast modem in those days, especially for a portable computer that generally did not come with internal modems at all, so I was very pleased with it. I rekindled my love for the BBS scene with that brick.

DOS 6.0 was significant in that it had disk compression built-in. Disk compression was extremely important in this era because portable storage technology was young and disk drives were very small. Compressing data was necessary to make any system usable. The technology in DOS 6.0 was named DoubleSpace but it came to light later that it was really called Stacker and Microsoft had stolen the technology from a company named Stac which successfully sued Microsoft for that. However, none of those legal wranglings changed what was on the DOS 6.0 disks so life went on.

Around this time I realized that there wasn’t a lot of career opportunity in cheffing, so while I enjoyed the work and evening shifts, it grew old after several years and I left it to become the assistant manager of a fast-food chain. My luggable VGA beastie wasn’t faring very well by now. The built-in monitor had completely failed by this point and I was using it as a desktop with an external monitor plugged into it. The time had come to buy my first new computer.

In an outlet of the only computer store in town, a young Future Shop, I found a lot of computers, but none of them were recognizable. The days of the “Commodore” and the “Amiga” were gone and the shelves were lined with identical-looking beige boxes. I had no clue what I was looking for so I just bought what I thought would work. A 486DX/30 with a 2400 baud internal modem. My defunct luggable was a 386 something, so this was a step up all around. I briefly flirted with the idea of buying a 14.4Kbps modem, but it was prohibitively expensive so I settled for the 2400. It was around this time that I learned the difference between “baud” and “bits per second (bps)” but that is too boring for even me to go into now.

I took this thing home in many boxes and set it all up. Windows 3.1 came pre-installed so I did not have to mess around with DOS or Windows, and the hard drive was big enough that I don’t recall having any space issues. But what I did have was a Super VGA (SVGA) color monitor which was blowing my mind. It was with this computer that I discovered multi-line BBSes, online MUDs, real-time chat, internet shell accounts and email and newsgroups using tools like PINE and ELM. Internet shell accounts were available on some BBSes. More expensive graphical SLIP and PPP accounts were available sparingly, but beyond my means at the time.

Several years later I went on to college for a Computer Information Systems program, did a stint in the Navy, and my career properly started. But these BBS and early internet years was the era that laid the foundation for a love of technology. A lot of that technology is still in use today, albeit hidden behind the shiny exterior of the modern internet.

The Single-line BBS Years

There were hundreds of BBSes in my local area code in these years. Partially because the world was a smaller place and there were fewer area codes, but also because it took some technical chops to connect to a BBS and understand what to do with it. Therefore, a lot of BBS users were also BBS SysOps who ran their own BBS system in addition to being a user on others. It was a fairly technical crowd.

The vast majority of BBSes were one-line hobby boards and most of us had long lists of BBSes we liked because we knew that the chances of connecting to any given one were slight, so we’d move on to the next one in the list when we got a busy signal. Almost everyone used Windows in those days. There were a few people with Apple computers, but the Linux kernel didn’t even exist yet so there were zero *nix people outside of RMS’ Free Software group; a group nobody outside of academia had heard of at all. The class of software used to connect to BBS systems were serial terminal programs, but we generally just called them terminal programs. The pre-eminent terminal program of the day was Procomm Plus and it had all the features we ever wanted - speed dialing, dialing lists, and modem volume control.

Windows came with a very basic terminal program called HyperTerminal and the standard way of setting up a new computer was to use the built-in HyperTerminal program just long enough to log into a BBS and download a better terminal program. Much like people today use Internet Explorer on a new computer just long enough to download Firefox and then never use IE again.

The single-line BBSes were basically “drop by” stops. They had short session limits, usually 20 minutes, which was enough to check if anyone had left you mail and download some software. Although, in the slow 1200 baud and less days, it was not always possible to download an entire file in that time. The universe answered our prayers with a download protocol named ZModem. ZModem had a lot of benefits that we were oblivious to, save one. It supported resumable downloads. If you were terminated from a BBS for whatever reason, when you were able to log back in and download the file again, it would resume where it left off.

Most BBSes in those days participated in FidoNet, or other Fido Technology Networks (FTNs). These were messaging networks. A BBS owner could choose to install mailer and mail tossing software on their BBS which would allow it to exchange both public messages in forums, called “echoes”, or direct and private (ish) mail, called “netmail”. A BBS SysOp who wanted to join one of these networks had to apply to that area’s coordinator through some already connected BBS and provide basic information such as the node name, the node phone number, and swear to observe Zone Mail Hour (ZMH). ZMH is is the hour every night when FTN networks would call each other and collect/drop off messages. ZMH was sacred in those days - your BBS had to be available during that hour otherwise you would not get your messages that day and your users would be annoyed. Today, the internet is used to transfer messages, so ZMH is no longer needed nor enforced.

The Multi-line BBS years

Eventually, BBS software improved so that it could support multiple lines. A few enterprising people stood up multi-line BBSes. Early multi-line BBSes had a separate phone number for each node so you had to have multiple entries for those BBSes in your dialer. Only a very few, usually commercial boards had the technology and money to have a single number round-robin to an open node.

Initially, multi-line wasn’t such a big deal because all the multiple lines really did was increase your odds of being able to connect to the BBS. But soon developers realized that if you have multiple people online at the same time, why not allow them to interact? It was during those years that Multi-User Dungeons (MUDs) and real-time chatting came into being and changed the BBS scene forever, pushing it towards what the internet would eventually become.

My board of choice was a BBS named Nucleus in Canada. Nuke still exists as an ISP now, having shut down its BBS long ago. Nuke ran a very expensive and amazing piece of BBS software named MajorBBS by Galacticomm. It had capabilities no other BBS had, and even though there were other multi-line BBSes in the area, Nucleus became the gold standard and was able to collect subscriptions from us, a feat that few other BBSes had managed to accomplish. Nucleus used to co-locate with a book and table-top gaming store, The Sentry Box, but it has come a long way now.

Once we were able to interact with other users in real-time, the world opened up.

MUDs

MajorBBS had a ton of games built specifically for the platform and therefore out-performed most other games of the era. Keep in mind that these games were text-based and mostly variations of MUDs, although some had rudimentary ASCII graphics. My favorite of them all was a game called Mutants. It was during Mutants play that I learned about what modern-day gamers complain about: lag. But in a dial-up scenario, the lag is not due to internet congestion. There is no internet involved and you have a 1:1 direct connection to the BBS. The lag came from modem speed. Mutants made no attempt to homogenize user speeds so if you had a nice speedy 14.4 modem then you could literally run circles around someone with a 1200 baud modem in the forest. It had the potential to be ghastly unfair. While I distinctly remember users running by me so fast that the game only told me I heard them go by, I don’t have any memories of this being an actual problem during gameplay. I am not sure how that could be, but memories are fickle things.

Chat

I recall only three multi-line boards in my area code in those years, Nucleus, Octopode, and Chatline. I think Chatline was also a paid BBS but it was less gamey and more chatty, as the name suggests, which wasn’t really of interest to me so I had an account but did not use it much. I remember Octopode as being one of those multi-line BBSs with 8 different phone numbers - hence the Octo part of the name. I guess that made sense because it was a free BBS so the SysOps were footing the bill for those lines themselves somehow, and adding features like single phone number would push that bill even higher. Being a free multi-line BBS, Octopode was overrun with users even younger than myself at the time, and it was hard to find a free line. I did not spend much time on Octopode for those reasons.

MajorBBS chat had a lot of features that were familiar from IRC and also allowed some customization, such as custom entry messages. That was a fun feature - you’d be chatting away and “Suddenly, the fog clears and in walks Doglier, dragging his dog bowls behind him…” would happen.

A great deal of fun in chat came from sabotaging newbies that did not have a good understanding of how their modem worked. I am sure this is arcane knowledge again by now, so I will recap a bit.

Recall that modems negotiate a serial connection over the phone line and once that connection is established, everything you type is just pushed through the pipe to the other end. But you still need to maintain control of the modem to tell it to do things like hang up when you’re done. To allow users to send commands to the modem and also to the connected system, there needs to be some kind of signal so the modem knows to take some text as commands. That is the Hayes Command Set, also known as the AT command set.

Beginning a string with AT tells the modem to pay ATtention to what comes next because it is a modem command, not something to be sent through the pipe to the other end. The most common AT command is ATDTxxxxxx where x is the BBS phone number. ATDT means “ATtention, Dial using Touch-tones” which tells the modem to use tone dialing to dial the number. There is also an ATDP for Dial using Pulse, but I have never used that. Other useful commands are ATH0 which causes the modem to hang up, ATL0 which shuts the modem volume Level to 0 (off), and sending a plain +++ with no AT in front which causes the modem to go into command mode entirely and stop sending data to through the pipe.

It probably becomes pretty easy to see the sport in tricking new users into typing things like ATH0 and punting themselves from the board. Another common trick was to macro-bomb a user off the board. By sending private messages at a rate faster than the receiver’s modem can handle, most modems will simply hang up. MajorBBS eventually introduced rate-limiting for private messages to prevent this, but it was a good working tactic to get rid of people who annoyed you for a long time.

Moving on

The next few years were magical all over again because graphical SLIP and PPP connections became affordable. Suddenly, we weren’t staring into a black terminal screen anymore. We were using things like web browsers and email clients. That was another wild time to live through, but I will leave that era for a different post.

I remember the modem and BBS era very fondly. I have a lifelong friend from those days that I met online and we’ve remained friends ever since, despite never having worked together or attended school together. My first contact with technology was that Vic 20 where I learned programming, and my friend’s Commodore 64 with a modem is where I learned that there was a whole world outside of my bedroom window that I knew nothing about, full of possibilities. That 300 baud acoustical modem kick-started an entire lifetime and career in technology.

Header image credit: By Lorax at English Wikipedia - Own work, Public Domain,

Subscribe at jonwatson.substack.com

View Details

Facebook encourages us to homogenize our friends into one bucket, speaking to them all in the same way about the same topics. This doesn’t work in real life and it doesn’t work online.

Subscribe at jonwatson.substack.com

View Details

Note: I am trying something new and recording posts in MP3 format for those of you on the go. The audio quality is just me and my phone - not studio quality, but maybe you’ll like it. You can get the MP3 here, and subscribe to the podcast RSS feed as well.

I ran across this gem yesterday - some enterprising researcher folks used electrical tape to alter the number 3 on a 35 MPH speed sign and then pointed a few Teslas at it. Predictably, the Teslas read the sign wrong and accelerated past the speed limit. But is that a hack? A human can also be fooled by a creative sign modification, too. Granted, this sign’s particular modification would be unlikely to fool a human, but artificial intelligence is weak and new and stupid still, so it’s a really attractive target for bad guys. Where do we draw the line between a “hack” and crappy software? One is a crime, the other is the modern standard way of delivering service over the internet.

When I read the headline, I assumed that the researchers had used the tape to close off the 3 to make it look like an 8. That would be the most obvious thing to do and, as I stated, could also fool a human. But that is not what happened. You can see from the sign above that the 3 is very clearly still very much a 3. There would be no obvious reason why the Tesla brain would read that as an 8 so that falls squarely into the bug category for me, and not a hack.

There is a long-standing tradition on the internet to stipulate that the words hack and hackers are misnomers that vilify legitimate researchers. That audience would prefer that the bad hackers are called crackers, and the good guys retain the handle hacker. That battle has been lost soundly and I’m really only mentioning it to fend off the “Well, actchually…” comments that writing about hacking to a technical audience sometimes generate. I see you, GNU/Linux guy. Just accept the language isn’t under your control and move on.

What is a hack?

Good question. It’s hard to say what a hack is, but it is pretty easy to identify what a hack is not.

A hack is not a denial of service attack. It is not a brute force login attack. It is not downloading data from an insecure S3 bucket. While we may not like it when those things happen, they occur by design.

A network card should drop traffic when it becomes saturated. A website should permit a login when presented with a correct credential set. An unsecured S3 bucket should allow anyone to download the data in it.

I contend that there aren’t really many hacks in the world. Most of what we call hacks are mistakes or bugs. How far can we take this train of thought until it no longer makes sense? When is the line crossed and a system operating as designed considered hacked? Let’s look at a few with that framework.

SQL injection

Let’s look at a SQL injection attack. The basic idea here is to issue a query against the database that returns unintended data. Consider this example from OWASP:

SELECT * FROM items WHERE owner = AND itemname = ; ...

the query only behaves correctly if itemName does not contain a single-quote character. If an attacker with the user name wiley enters the string “name’ OR ‘a’=’a” for itemName, then the query becomes the following:

SELECT * FROM items WHERE owner = 'wiley' AND itemname = 'name' OR 'a'='a';

The ‘a=a’ bit is the magic here. That statement will always evaluate to true and because it is preceded with an OR statement, any other statements in the WHERE clause don’t matter. Therefore this query will return every record from the items table. Probably not what the developer intended. But the database is operating as designed. It was given a syntactically correct query so it executes it as asked. You can probably see how an injection attack like this would progress through the first few steps of the Kill Chain:

Recon: Run this query through every form on a site and see what you get back. If it works anywhere…

Weaponization: Craft a more useful query that will expose more valuable data, or possibly a stored procedure in the database…

Delivery: Execute the query…

Exploitation: Take that data and use it to log in to this site, credential stuff other sites, or execute the stored procedure…

This is neither a hack nor a bug. It is one human making a mistake by not sanitizing input code and another human taking advantage of that. It’s just a mistake.

Shell Shock

The BASH Shell Shock revelation in 2014 was a Very Big Deal. The basic requirement for a successful Shell Shock exploit is a web server running a CGI program written in BASH, or written in some other language but shelling out to BASH to call system executables. That is an extremely large number of servers on the public internet and it caused widespread panic. But, how does Shell Shock work?

BASH is a widely used Linux shell, perhaps the most commonly used. It has the ability to declare functions in the environment for later execution. The syntax used to do this is (from Fedora Magazine):

$ yayfedora() { echo "Fedora is awesome."; }

This creates a function named yayafedora in the shell environment that can be called later. So far, no big deal.

$ yayfedora Fedora is awesome.

The trick to exploiting Shell Shock is to send a BASH function within a request to a web server by embedded this function in a web server variable. Internet users don’t have direct access to web server variables, but they do have the ability to craft arbitrary HTTP headers and when a web server encounters an HTTP header, it copies it into an internal web server variable in case it needs to examine it later. So, something like this will embed the BASH code to print out the passwd file into the user-agent variable of the target web server (from opsxcq):

curl -H "user-agent: () { :; }; echo; echo; /bin/bash -c 'cat /etc/passwd'" http://somesite

Having this code in a web server variable isn’t dangerous by itself because it’s just sitting around in memory. It is not being executed. In order for this code to execute it has to be passed to a vulnerable CGI program. If the web application uses a vulnerable CGI program, then it will execute this code when the HTTP user-agent variable is passed to it.

The final step is the execution of this code. If you’ve been paying attention you will see that the code sent to the webserver continues past the first semi-colon which should indicate the end of the command in BASH. This is the crux of the exploit: BASH loads the harmless function into memory but it does not stop reading there. It continues reading past the semi-colon and ends up executing the code following it.

This was a bug in BASH and not a hack. It was a mistake by a human developer that was exploited by another person who stumbled across it.

Specter

In 2018 the world became aware of a very broad problem with Intel CPUs that are in extremely wide use in every industry. Every generation of CPU is faster than the last and a lot of that speed comes from hardware changes to the chips. Faster hardware can process more data at once, thus the server generally becomes faster all around. However, CPU microcode also plays a part in these speed increases. For years, CPUs have been utilizing code that predicts what the CPU will be asked to do next and runs that code in advance. It then stores the results of that execution in the cache so it can provide the results quickly to the calling process when it finally asks for it. This is called speculative execution and when a CPU mis-predicts, it discards the results of that execution.

Specter is a wide and open-ended class of attacks that can make use of this discarded data and that data can contain sensitive information, even decryption keys. It is made worse by the fact that it is possible to predict what data will be in the cache, or even force desired data into the cache in order to retrieve it. One possible attack scenario looks like this.

First, it shows that branch prediction logic in modern processors can be trained to reliably hit or miss based on the internal workings of a malicious program.

It then goes on to show that the subsequent difference between cache hits and misses can be reliably timed so that what should have been a simple non-functional difference can, in fact, be subverted into a covert channel which extracts information from an unrelated process's inner workings.

Thirdly, the paper synthesizes the results with return-oriented programming exploits and other principles with a simple example program and a JavaScript snippet run under a sandboxing browser; in both cases, the entire address space of the victim process (i.e. the contents of a running program) is shown to be readable by simply exploiting speculative execution of conditional branches in code generated by a stock compiler or the JavaScript machinery present in an existing browser. The basic idea is to search existing code for places where speculation touches upon otherwise inaccessible data, manipulate the processor into a state where speculative execution has to touch that data, and then time the side effect of the processor being faster, if its by-now-prepared prefetch machinery indeed did load a cache line.

Finally, the paper concludes by generalizing the attack to any non-functional state of the victim process. It briefly discusses even such highly non-obvious non-functional effects as bus arbitration latency.

This exploit falls into the same bucket as the SQL injection. It is a CPU operating as designed. The CPU was designed to predict future requests, run them in advance, and store the results in the cache. It is the design that has the problems, but those problems are not bugs. A human who wrote this code did not predict that its output could be used this way and another human picked up on it.

Is anything a hack?

The takeaway from this post is, hopefully, that the term “hack” has been stripped of all meaning. The vast majority of people do not have the necessary level of technical knowledge to asses how any given attack can occur, so it just gets lumped into the shoulder-shrugging bucket of “hacks”.

The problem with this is that it lends an air of unreliability to computers and technology. We become distrustful of technology because it is always being “hacked”. The reality is that these machines are almost always doing exactly what they’ve been configured to do. The fault lies with the humans who write code and configure systems. It is those people who allow the hacks to occur, not the machines.

The state of internet security is so poor that it barely constitutes security at all. Most code and most systems are not developed or configured by people trained in security and therefore most of it is not secure at all. The level of security competence among developers and system administrators is appalling so we can expect to see this trend continue for the foreseeable future.

To bring this back to the start, we have an industry that can’t even reliably secure an S3 bucket now developing autonomous cars. The more prudent path forward is to create a generation of security-oriented technology workers first, then build the important disruptive technologies properly.

Subscribe at jonwatson.substack.com