Goodreads Profile

All my book reviews and profile can be found here.

Tuesday, December 17, 2019

Trading One Apocalypse for Another

Just a few months ago, a Netherlands researcher wanted to come to the U.S. to present a paper on the vulnerability of the industrial control system. There are almost 30,000 of these devices that control everything from wastewater plants to the electrical grid. The research, thanks to America's arcane and silly visa system, was not admitted and so unable to present these important findings. Fortunately he was able to post them to his blog. Whether that resulted in a wider dissemination of the information than had he delivered his talk is academic, perhaps. **

Researcher Wojciech,  used standard OSINT techniques (the CIA has identified five main OSINT fields: Internet, media, geolocation, conferences, and online pictures) to analyze the exposed ICS devices. Many of these are used in critical infrastructure that would include dams, electrical grid, reactors, health treatment facilities, etc. Critical infrastructure developed by OSINT can be used not just by espionage agencies, but also criminal elements who may seek to gain monetary advantage by holding these devices hostage. OSINT techniques are passive, in that the target remains completely unaware it is being surveilled. Access may be gained by open ports, IP addresses, knowledge of details of the specific devices and how they work -- all freely available online and elsewhere -- and even responses from the device itself.

Here's an example of device information that's available that even includes the phone number: 



There are several programs that permit searching the internet for active ICS devices (https://www.shodan.io for example.) The author lays out precisely how to go about searching. Many of these devices have open management ports that are convenient for technicians to access the devices remotely for maintenance. That, however, makes them extremely vulnerable malicious actors. General contractors with government contracts are particularly vulnerable as they have a history of being more open and thus more vulnerable.

That hackers can cause innumerable problems has already been shown in Ukraine, Estonia, and Georgia where the Russians devastated each country's infrastructure. Andy Greenberg in Sandworm documents what happened in several cases. In Ukraine access to the banking system was eliminated.

It took forty-five seconds to bring down the network of a large Ukrainian bank. A portion of one major Ukrainian transit hub…was fully infected in sixteen seconds. Ukrenergo, the energy company…had also been struck yet again…the effect was like a vandal who first puts a library’s card catalog through a shredder, then moves on to methodically pulp its books, stack by stack. 

US officials, heads typically in the sand, refused to admit something similar could happen in the U.S. yet we now know that Russian hackers infiltrated the U.S. election system and may well have manipulated the outcome in a variety of unorthodox ways. In 2016, Iranian hackers attacked several US banks causing millions in damages and shut down a dam presumably in retaliation for the Stuxnet attack. The attacks themselves were quite unsophisticated, mostly DDoS attacks that even the most unsophisticated hacker can pull off.

There is software (malware, really) that has been designed for specific purposes; Stuxnet is but one example. Another, discovered by the security firm Dragos, was CrashOverride***, only the fourth example of malware designed to attack and manipulate the controllers in electrical grids. "The functionality in the CRASHOVERRIDE framework serves no espionage purpose and the only real feature of the malware is for attacks which would lead to electric outages."

Greenberg shows that a variety of software is available, even for sale, that permits relatively easy access for anyone, but can also be used to hide the origin of the attacker. To make matters worse, Greenberg wrote in Wired (https://www.wired.com/story/plundervolt-intel-chips-sgx-hack/) of researchers who had managed to access and control Intel processors (a vulnerability that has since been fixed) by manipulating the internal voltage of the processor. You can induce faults by lowering or changing the voltage and once you can do that you can change the output by manipulating the faults. The technique, called Plundervolt, was discovered concurrently by a researcher in Beijing. (Take from that what you will.)

In his book, Greenberg focuses on Sandworm, a group of hackers and software named after the malicious creature in Dune (cyber-analysts had discovered that preference while doing research on the code - don't ask me how.)  They determined there was evidence that Sandworm had been infiltrating critical infrastructure—some of it in the United States—since 2011 and had already developed a weapon that could knock it out. When it was used against Ukraine, it had evolved even further. 

The hackers had, in other words, created an automated cyber-weapon that performed the same task they’d carried out the year before, but now with inhuman speed. Instead of manually clicking through circuit breakers with phantom hands, they’d created a piece of malware that carried out that attack with cruel, machine-quick efficiency.

The engineers managed to fix the system in about an hour, but the point was made. Another group calling themselves ShadowBrokers made off with a whole set of penetration tools developed by the NSA (supposedly impenetrable) and turned them loose in the wild where virtually anyone with a modicum of knowledge can make use of them. Shadow Brokers caused immense harm when they released EternalBlue, malware that spread faster than anything anyone had seen before. Within minutes it had disabled pharmaceutical companies, and Maersk, the huge shipping company was brought to its knees. 

 “ 'For days to come, one of the world’s most complex and interconnected distributed machines, underpinning the circulatory system of the global economy itself, would remain broken,” Greenberg writes of the attack on Maersk, calling it “a clusterfuck of clusterfucks.” The company was only able to get its ships and ports back in operation after nearly two weeks and hundreds of millions of dollars in losses, when an office in Ghana was found to have the single computer that hadn’t been connected to the Internet at the time of the attack.' "

I've been reading a lot of books and articles on the possibilities of cyber-warfare. The potential is there for even non-state actors to operate in the shadows and do tremendous harm. Then again shutting down most of our industry might solve the global warming worst case scenarios. One apocalypse preventing another.

**https://www.icscybersecurityconference.com/intelligence-gathering-on-u-s-critical-infrastructure/

***For a review of CrashOverride designed to attack electricity grids, see https://dragos.com/wp-content/uploads/CrashOverride-01.pdf

Friday, November 29, 2019

Review: A Lily of the Field by John Lawton

Finally finished this. The early scenes with the young Méret as she studies with Vicktor are often lyrical, helped perhaps by the numerous allusions to classical music. If you love the classics you will enjoy those references. It's 1934 through the beginning of the war in Austria at the start. The Nazis have begun to show their true colors and some Jews who had already fled Germany were now trying to get to England. I love the way Lawton describes the English naïveté: "Think of them as children. Think of Europe as the drawing room and England as the kindergarten of Europe. They are innocents. They actually boast of not having been invaded since 1066. When in fact all that means is that they have lived outside the mainstream of Europe. They are innocents.. . .Good God, why London? Why not Paris or Amsterdam? What does London have to offer? The madman Thomas Beecham. Beecham waving his baton in the pouring rain for a nation of philistines in wet wool and false teeth!”

But I thought the book dragged once they all got to England and I just didn't find it as interesting nor comprehensible.



Sunday, November 17, 2019

Another Pseudo Maelstrom in the YA World

Sarah Dessen is a self-described YA author who recently twittered herself into a maelstrom of controversy. She had taken issue with a student at a small South Dakota university who had recommended Just Mercy (an excellent book by Bryan Stevenson) and several other adult books to be placed on the school's Common Read list as an alternative to one of Dessen's books, which she felt, as a YA book, was not up the appropriate college reading level.

Brooke Nelson, the student, noted in an email to the author of a Slate article that "“In 2017, I was a college junior who joined a committee because I wanted to have a voice in what text was selected for a college reading program. I was only one vote on a large committee of college students, faculty, staff, and community members.” 

What happened was that Dessen clipped a piece from an article in the university's newspaper and tweeted a sarcastic comment about it to her 260,000 followers. The inevitable reaction is a case of classic YA juvenile behavior that amounted to nothing less than extreme bullying. YA author Siobhan Vivian tweeted, “Fuck that fucking bitch.” (“I love you,” Dessen replied.) Fellow YA writer Dhonielle Clayton chimed in: “Can I add a few more choice words for Siobhan’s brilliance … fuck that RAGGEDY ASS fucking bitch.” Vivian replied with the clapping, cigarette, and nail-painting emoji."

The juvenile and scatological content of the comments are unfortunately representative of the YA crowd. Just check out the YA stuff on Goodreads and you'll find a viciousness one would hope to be characteristic of teenagers rather than adult authors pretending to be teens in their writing.

Nelson has deleted her social media presence in an attempt to hide from the viciousness and worries it may impact her future career. The reaction of Northern State University was disappointing. “We are very sorry to @SarahDessen for the comments made in a news article by one of our alums,” the school wrote. “They do not reflect the views of the university or Common Read Committee.” The lesson one takes from that statement is that students there need not have any opinions. 

A larger issue, and one that bugs me constantly, is the somewhat arbitrary designation of books as YA or adult. There are many teenagers who read at above grade levels and many so-called YA books that deal with adult issues. The are books written for younger readers and then books about teens. One can imagine a lengthy debate, as intense as the one over the number of angels that could dance on the head of a pin, as to whether Jane Eyre, Catcher in the Rye, Huckleberry Finn, and innumerable others should be shelved in the YA section where adults readers and those wishing to read "adult" book will never find them. The categories become even more ridiculous when aimed at ages. "This book is for those from ages 7-8." Ridiculous, but parents and administrators demand those designations, assuming that reading levels are monolithic and immutable and change from one age to another. Authors are told to remove words that are appropriate to the story but which may not meet some mythic age or reading level. 

It's perhaps ironic that had Dessen never said that she wrote for teens (and after all what does she know about teens, not having been one for several years) but about teen issues as she understands them, or better issues of justice or racism, something Nelson wanted to emphasize, 


Tuesday, November 12, 2019

Methena v Malvo

In 2012, in Miller v Alabama, the Supreme Court ruled that awarding a life sentence without parole to a juvenile violated the 8th Amendment’s prohibition against cruel and unusual punishment. In 2016, the court, in Montgomery v Louisiana amplified that ruling by ruling that because Miller was substantive, i.e. of constitutional import, that the prohibition against life sentences without parole for juveniles was retroactive. This time Roberts added his vote to the 5-4 Miller decision making it 6-3. “When the Court establishes a substantive constitutional rule, that rule must apply retroactively because such a rule provides for constitutional rights that go beyond procedural guarantees.”

Come to the present case of Methena v Malvo. Malvo, at the time, 17 years old, was convicted of participating in the sniper shootings in Virginia in 2002. His older colleague was sentenced to death and executed in 2009. In Malvo’s case, the jury was asked to decide between the death penalty and life without parole. They chose the latter. Then along came Miller and Montgomery and Malvo’s lawyers are asking that since Montgomery made the prohibition retroactive, that Molvo’s sentences (he had ten life sentences) be vacated. Much of the questioning revolved around the issue of just using youth as a criteria, or whether incorrigibility, needed to be considered, as well.

It seemed to me rather straightforward given the outcome in Montgomery, but trying to guess how the justices would vote was not apparent from the oral arguments. Of course Scalia and Kennedy, both there for Miller and Montgomery, have been replaced by Kavanaugh and Gorsuch, but with Roberts the deciding vote plus one in Montgomery I would have to guess they might send it back to the 4th Circuit that had ruled for Malvo to bring in the idea of incorrigibility and the distinction between mandatory sentences of life as opposed to simply the application of a life sentence without parole. Semantics, indeed.

Monday, November 11, 2019

https://qr.ae/TWx5Po The following is an answer by Salman Khan found on Quora to the question: "Do atheists secretly or inwardly pray to God in their moments of desperation? Who do they look to when all seems lost?"

I will actually give a serious response to a question like this!

I’ve seen people complaining about such questions and how annoying they are. It occurred to me that I could actually write serious responses to such questions and try and make this site a better place. So, are you ready?

Do atheists secretly or inwardly pray to God in their moments of desperation?

The short answer to your question is no. For the long answer, please keep reading.

It doesn’t actually surprise me that some believers might feel like we need to pray to something in our darkest hours. I don’t really blame them. I understand why they feel that way. They were probably raised in a way that they never got to develop a coping mechanism. Despite being raised by Muslim parents, I didn’t suffer through that. I was taught by my parents to deal with reality on reality’s terms. If I needed something, I was taught to work for it. If my work failed, I was taught to reflect on it and learn from it and never make the same mistake twice. Never was I asked to not put in any effort and hope some magic will solve things for me.

Don’t get me wrong! I was taught to pray to God. However, prayer was taught to me as a form of humility, not as a means to a desired end. As such, I never relied on prayers to get anything done. Therefore, logically, I had no reason to resort to praying if things got really difficult. Maybe your parents/teachers/pastors/imam taught you differently. Maybe they taught you to ask for miracles to solve your problems. As such, you probably see no option but to ask for a miracle when things get tough.



The thing is, even if I did believe in a God, I’d still not pray to them in my darkest hour. Why? Well, please consider the following. Some 21,000 people starve to death on this planet everyday! Most of them are kids. A God that refuses to hand a sandwich to these poor souls should not be expected to show up to solve my life problems. I mean, what would praying to such a God make me seem like? How much arrogance must my heart harbor for me to think that the same God who refuses to save those 21,000 people from starvation even takes interest in my problems?

For these reasons, people like me don’t pray and wouldn’t have prayed even if there was a God.

Who do they look to when all seems lost?

We engage in some introspection. We talk to friends/family. Sometimes we talk to strangers too. That way, we share things and somehow it makes us feel better.

Actually, it’s not only about the emotional comfort that we get out of it. Often times, our social network can actually help us out of such situations. People don’t need to be Gods to offer to help you. Even a total stranger can change your life and pull you out of your misery. As far as I am aware, people have a higher track record of helping other people than any God ever did. Please look at the above image. When your God sent Hurricane Katrina to drown those kids and devastate the lives of people, it was people who came together to save them.

That is why people like me don’t feel the need to look up to such Gods for anything. If anything, we look up to our fellow mortals. We respect such mortals who may be limited in their abilities but does more to help us than the seemingly impotent and potentially evil Gods.