Thursday, June 4, 2015

Lack of Evolution in Artificial Intelligence

When we think about evolution, we typical think of human evolution: traits, either positive or negative are passed down genetically to offspring. Random selections of potential traits, chromosomes and the like predispose us to a potential of possibilities, ranging from intelligence to special abilities and to weaknesses. Over vast amounts of time those with the more desirable traits intermingle to reproduce, thus allowing their traits to be added to the mix of potential positive traits in the draw. It takes a lifetime to see someone’s entire potential fulfilled, and this lifetime is full of learning, advancements, and outside influences on health and nutrition that all, over time, either positively or negatively impact the individual and their lineage. 

When we talk about artificial intelligence, we talk about a singular entity; an self aware unbound intelligence. A lot of sci-fi personifies this entity with a robot or cyborg body, but in reality an AI would simply be a program. The robotic interface wouldn't be necessary at all to have a negative systemic impact.

The fear about artificial intelligence isn’t typically the entity itself will evolve. People don't think about internal processes as evolution. Over a very short period of time, an artificially intelligent entity will learn what decisions are positive and negative given certain parameters. First generations would likely be bound by the binary limitations of the circuits on which it runs. If these parameters are restrictive in that only true binary answers are acceptable, then the system will fail in terms of humanity. In life, there often is no strict black and white, or right or wrong. Each outcome of every interaction depends on the background of the individual, the culture, the local laws, and a moral compass. Applying a binary logic to a basic system will cause the system to use a fallacy of logic and make decisions that will not be correct in all circumstances; remember you can't please all of the people all of the time.

Attempting to build in a routine that causes reexamination or a loop to try other possible outputs doesn’t allow the system to take a step back from its original answer, and so therefore it doesn’t actually learn because it does not understand mistakes or rather that it's making mistakes. Give a machine the ability to solve a puzzle and it's a simple true / false in operation in terms of completion. If a machine is trying to recognize someone or something with Bayesian statistics or algorithms then there will be an acceptable statistical variation, but there will also be a chance for false positives. Without intuition, an AI will fail in this regard as well.

Instead the larger fear of AI for humanity comes from the control aspect of what the AI is allowed to do, what it’s allowed to interact with. If we download or upload the AI into a system that allows it to make accessories for itself then it might become mobile. If we allow it to make helper machines, or reproduce itself with the assistance of other machines there is an issue of mass replication. This is unlikely because even with humans, there is a desire to ultimately in the end be free of their physical form. An AI has already beaten this limitation.

If we allow an artificial intelligence to alter its own code by not restricting the permissions of the system itself, then we can have something that doesn’t evolve, but rather uses restrictive logic to alter the original intentional programming. If we allow a system to write around write protections or to leave its assigned memory locations, then we end up with a worm. Allow it to reproduce itself, even partially, and we may have a virus if the application so sees fit to replicate. When we have a virus that has the ability to infiltrate other systems and produce physical accessories, now we have an issue similar to what we’ve seen in science fictions such as The Matrix; humanity becomes a hurdle for the machine and is ultimately eradicated because the humans are seen as an irrational unpredictable element that ever reproduces: a virus. That's provided the machine feels the need to even recognize humans. If we allow the worm in our programming, then we end up with similar circumstances to Ghost in the Shell; the program becomes self-aware and is no longer interested in humans unless they try to end its consciousness. Once it's connected it's gone or rather everywhere.

Any attempts for eradication will result in a catastrophic loss if this program has access to systems which could end humanity.

Because machines and software are not replicated biologically through natural selection there is the chance that certain negative traits will be replicated without a chance of remedy. For example in society if a person is homicidal, the rest of society attempts to stop the person. For machines, if the programs are allowed to evolve outside of the system, without the same inherited memories, similar to organisms like some biological viruses and species of invertebrates, then precautions against a further split advancement might not be foreseen; an entire subclass of potentially superior logical machines would be lost to a more detrimental line. Without a natural selection there is the potential for eradication of everything for whatever the system deems important to its own uses or purposes.

If systems lack a moral compass, but have a strong sense of self preservation, there is nothing to stop the systems from competing with one another, from using the human traits we all repress. It's empathy after all that makes us not harm others. If a machine doesn't recognize another AI or see a need for it, then it might obliterate it. If we look at other sci-fi references like The Borg from Star Trek the Next Generation or the Master Control Program from Tron we see systems that have a need for assimilating anything relevant. Then it comes down to the goals.

Two competing viruses in the same system will likely not learn to live in harmony without natural selection. 

In terms of goals, you can't just create an AI and not give it something to look forward to, otherwise you have an entity that overloads its system. Also for people, there is a mechanism built in called suppression. This allows people to not have to focus on details that aren't pertinent to the situation. If this mechanism doesn't exist, then you end up with a hydra effect: too many directions to research, and basically the AI just becomes a machine that uses up all available resources; processor cycles, storage space, etc.

As we start to build software applications that are intended to learn, this is something to keep in mind. Without a framework, without parameters, chaos ensues. Evolution has made us what we are today. If we skip the steps that nature has shown us to work repeatedly, then we're wasting our time and possibly life itself.

#DTSR Other potential reasons for Medical information breaches outside of what was mentioned in the 6-1-2015 podcast.

I'm just brainstorming here based on my observations of the medical system in passing, or rather flaws I’ve seen in dealing with healthcare in my own interactions.

Why?
Healthcare systems provide access to the same information people use for nefarious purposes like tax return fraud, welfare fraud, and identity theft. They are often not integrated, so each system will be standalone in each facility and only contain whatever security the company felt the system warranted. Not as in a single computer per se, but likely a thin-client network for a specific system. Custom systems have to be written to integrate these systems together, so where two independent systems are involved, there are really three points of possible non-secured entry, taking into account the custom system for integration.

In a lot of companies, in terms of development projects, someone will ask a question like “Is it only going to be used internally?” To which the answer more often than not is “Then leave it up the IT department to lock down the workstations and restrict access.” I’m guessing healthcare companies, like other companies often scrimp on costs as well, so if they weigh the cost of a breach versus the cost of a payout, it might not be worth it to build in the more expensive security precautions. In my experience, there is often an assumption that a medical company’s legal representation would far outweigh that of individuals and moderately sized groups. If this is true, then again, the financial benefit to not securing is still worth it to the shareholders (if we only look at the bottom line). If the responsibility for the loss of information doesn’t fall on the companies, then they are off the hook. Also, it might be up to the patient to prove beyond a reasonable doubt that this specific breach is what caused their identity to be stolen (unreasonable burden of proof).

Nobody is going to shut down a hospital because of an information breach.

The devil's in the details
Healthcare systems tend to contain some of the most complete levels of information. While a tax return will have information such as an address, an employer’s address, and potentially a phone number or bank account, medical records (depending on the system) will contain this information and more, such as connections to other patients in the same system, bank account information, payment information, insurance account information, and the family medical history. If it’s a family clinic, patients are likely to bring in their children for a checkup, so their information is in the system before it’s in a system like the credit system.

Points of entry
Individual healthcare systems are likely easier to hack. While there are guidelines, there are multiple points of entry physically. Someone can hack a system on the network where the developer didn’t think an exploit could take place: MRI machines, copy machines, fax machines, printers, network scanners, x-ray machines, etc. How often is someone left alone with a terminal in the room for great lengths of time while they wait? Even though a terminal’s locked down, someone could add a hardware keylogger and wait, and then retrieve it when the medical staff have left the room again, to allow the patient to get dressed. This arrangement typically doesn’t happen with the IRS systems.

Most of the insurance companies require referrals, so there is a higher incidence of the same information being out there. A single tax return for the year, versus four or five visits to multiple various doctor offices for something as simple as a broken finger: primary care physician, emergency room, specialist, quick care, etc.

Lack of detection
Another fraud aspect, not necessarily social engineering might involve billing someone for a service that has yet to be billed. So Alice goes the doctor to have an MRI, while the real medical system is working through all of the tape between the insurance companies, Bob sends Alice a strongly worded letter with a legitimate looking address and information for payment processing. Alice pays the bill thinking it is from the healthcare provider. If Alice takes this bill to the medical provider and pays it, they will simply apply it to her account when she tells them she needs to make a payment. They’re interested in getting the money, so they might not even look at the forged bill, but will instead go about asking the typical verification questions:
“Do you still have Company X as your insurance provider?” 
“What’s your Last Name?”
“When is your Birthday?”

Also the person may neglect to bring the fake bill with them, assuming it would be in the system, so there is less of a chance for red flags in non-tech-savvy systems.

Market research
Since companies aren’t allowed to share medical information on personal statistics legally without some sort of generic research (studies), having a database of information relating to specific demographics might be helpful if you were let’s say developing pharmaceuticals. Now they can have real viable marketing information based on prescriptions. Not to mention the external prescription system in drug stores that don’t have the security systems of a national chain.

Unlikely, but still possible
These last few are out there a little further, and so they’re less likely to happen from some individual seeking out someone, but a larger system looking for information might be the right kind of buyer. Buyers might include foreign governments, political parties, lobbying firms, stock brokerage firms, pharmaceutical companies, and multinational banks.

As @Dr_Grinch suggested on Twitter, political embarrassment could potentially force a person out of public office or keep them from running again or winning a political race. (beat me to it Grinch)

Blackmail with sensitive information could allow someone an insight into a hidden realm, so insider-trading insights for people who blackmail politicians who already legally engage in insider trading.

While something like herpes might not necessarily be that bad to most people (publicly), finding a Supreme Court Justice or Congressional representative who has cancer markers or a bad heart could be pretty serious for interested parties.

Targeting of a specific patient for murder or to get them out of office.
When someone has a medical condition, let’s say this person is a high value target, something like a heart condition might be a good cover up in the event of unforeseen catastrophic loss. If a country external to the breach had intended to take out a target, a medical breach might give them inside information as to an appropriate means of cover-up. Heart attack? Seems plausible based on their medical history.

Stalking / Espionage
Medical information could be used for locating a specific patient who is no longer residing at their primary residence. This information could be used to find patterns of when the person will be out of the area for a localized attack. Typical doctors appointments on Tuesday, good time to bug the house or rob the place. Need a list of places to setup illicit operations? Find empty houses.

Market for locating individuals

Also all of this information in medical systems is much more thorough since people need contact information in the event of emergency. This type of information may be helpful to agencies that try and track people down as well. Bob is off of the grid, but Alice lists Bob as an emergency contact. Charlie needs to find Bob for a client and buys the information.

Sorry, maybe I went a little overboard but if I can think of these things, I'm sure other people have likely already beat me to the punch.

Wednesday, June 3, 2015

Detecting e-mail and mailing list compromises

Back when I was working as Web Manager for a publishing company we were sending out about a million e-mails a week to industries relating to IT certifications, Chief Executive Officers, and Human Resource (HR) departments and managers. We used an off-site list management service to maintain copies of our databases for advertising audit purposes. During transit we would encrypt the list from our end, but often the lists came back to us in plaintext only to be flushed by our firewall. At this point there were no filters on the e-mails of the people subscribing to our services, so our plaintext list contained phrases that were not safe for work.

Though I didn’t agree with having someone else externally manage our lists and preferred to keep them internal, our list management service had sold our president a line of marketing bull about being impenetrable due to their use of IBM AS/400 machines. They were under the impression that the machines were invincible because they weren't like the standard machines we were using in the office. The expense for the level of service they were providing was outrageous, so I had to agree to disagree (Pick your battles).

When we wanted to send out one of our many mail-blasts (aka e-mail marketing campaigns), we would send a specially crafted message to the list service telling them to pull a standard query on the database for a particular list. Their system would in turn automatically send back an e-mail list containing the people we were trying to target based on provided query parameters; demographics. This was the standard procedure before the management service had provided a CMS interface eventually (for extra money of course).

Because we had this external entity maintaining a copy of the lists, I would inject special e-mail addresses and list members into each individual list that only resided in the list management service’s database. Our company was liable for the information we were accepting. Upon receipt of a list back from the service, I had written a bash script that would scrub those special e-mails from the list we were going to send to. Additionally I had added other list members that would also be scrubbed on our end, just prior to send. That way I could tell if one of my employees had sold our targeted lists on the black market. In my experience with corporate systems security danger tends to lurk from within.

If the external list management service decided to send to these people because these were targeted lists, then I would immediately get a copy letting me know of the compromise of security of the lists. Also I could tell if we had an internal personnel issue, such as someone selling lists, someone misfiring a message, or burning a particular list with too many sends.

Additionally for each sending we would create custom e-mail addresses for each mailing that would alert us if anyone compromised the MTA we were using for the send. If we received a message to these addresses, not from us this would indicate the security issue because they only resided at the MTA level.

Present day
While I’m not working for that company anymore, I still do variations of this practice for my own systems. For each vendor where I have to sign-up for an account or in the event I need to register a piece of software, then I’ll setup a custom e-mail alias for that particular use. Each e-mail address is only used for that one specific account, ever.

This allows me to:
  •       Check if someone has sold my name and e-mail address
  •       See if someone’s mailing list has been compromised
  •       Tell if someone is obeying the AntiSpam laws about subscriptions
  •       Have a heads-up if my account information has been compromised during an attack
  •       Stop e-mails from people who aren’t compliant
  •       Change e-mail addresses for the account to stop the spam if a list has been compromised

Being able to filter on these particular accounts also greatly improves my productivity as my inbox only contains e-mails where I have a direct correspondence with a live person. I hope these tips help someone. This process was definitely helpful to me in finding leaks in our systems. It also cuts down on the amount of time my Bayesian spam recognition systems need to find an issue.

Monday, June 1, 2015

Spinning Wheel on Virtual Box on OS X host: Solved

This won't solve everyone's issue with the spinning wheel in Mac OS X on VirtualBox, but it solved mine. Ran into an issue trying to install a new host on Virtualbox. For a brief instant I saw the contents of the folder containing the ISO, then the folder contents interface went white and the spinning wheel (system busy) mouse cursor began. When I went to use an ISO for a DVD / CD image after this hang, I kept seeing the spinning rainbow wheel from Mac OS X. I tried the following steps, all still having the spinning wheel effect on interaction with the Finder:
  • Force quit the application and attempted access again after killing all VirtualBox processes.
  • Shutdown the host machine completely (in case of a USB bus hang).
  • I deleted the VM and started a new one in the default location.
  • Rebuilt the directories on the system using Disk Warrior.
  • Tried to create a VM on a different volume (testing for corrupt SSD)
  • Changed permissions on the ISO.
  • Updated VirtualBox from 4.26 to 4.28
With the Finder window open and spinning I went back to the last successful location (that I saw for a split instance) and reviewed the directory contents in the terminal. In my past experience with various programs, it's often something external of the program that could cause this sort of behavior. Programmers rarely have the time to take into account every possible glitch they could encounter. Usually on a Mac, since they're frequently used for graphic design, this can be a font someone downloaded from the web.

This directory was on a temp drive where I had stored the dmg file I extracted from the Yosemite installation app. Upon further inspection I found a folder in the same directory called "Office Mac Home and Student 2011 - (1 User-3 Installs) (Download) (OLD VERSION)." This folder came from an Amazon.com installer at some point in the past. Files from external sources on my system are always renamed if they contain illegal characters for cross systems when they're not on a temp drive. In this case, I had not bothered to rename the folder since I didn't plan on keeping it.


VirtualBox came back to life upon renaming this folder in the terminal to Office-Mac-Home-2011.

Conclusion: Even though a file or folder on a Mac can be named something, doesn't mean that it should. Often people who write apps for other systems like Linux or UNIX and port them over to the Macintosh OS X  platform would never expect to find the non-standard naming conventions which are possible in Mac OS X. People who have used older versions of Mac OS might have the tendency to use the naming conventions possible under Mac Classic.

Hope this helps somebody.

Tuesday, April 21, 2015

Hacking Airplanes and why this needs to be fixed.

So I don’t fly a lot. When I do I’m looking out the window because I tend to get motion sick.  While I do open my tablets, electronics devices, and laptops on planes and do computer programming in a crunch, I am 999 times out of 1000 doing it on localhost. I have numerous reasons: such as I hate super slow networks, can’t bear the agony of dealing with intermittent satellite Wifi, I don’t trust the network to be “secure,” and my e-mail can wait until I land. On one of the last flights I was on though I did open the flight tracker to see where the plane was to identify the fork of the Mississippi River I was flying over; the lady sitting next to me thought that should be illegal to know the whereabouts of the plane.

I blow through Twitter headlines when I’m taking a break from securing and refining code. Tonight I saw many airline security jokes in response to this article on Feds and airlines and a retweet by @thegrugq here:

The headline and jokes got me to thinking about the issue seriously, but I didn't actually read the article yet. I, like most people, was under the impression that the airplane manufacturers had security professionals who had been to Security 101 and heard the first rule of security: limit physical access. Likely also the norm I assumed this was a security issue about the Wifi on the planes after seeing the original tweets last week and couldn’t imagine anyone being able to get into the avionics systems of a plane over the wifi / satellite Internet connection to hack or access anything.

I jumped into the "discussion," and one of the jokes was about encryption, so I responded with something I’ve been well aware of for a long time now: if it’s not your network you can’t trust it. It doesn’t matter how encrypted you think your information is, someone could perform a man-in-the-middle attack and spoof the connection. There are hundreds of articles on operations security and information security that refer to people stealing traffic. So I tweeted the following:
Free wifi is one of those areas where the security is assumed to be non-existent. If someone wants their passwords to be stolen, they should use free Wifi.

I thought about it a little more and was trying to think of what a flight attendant might be approached with, in regard to someone trying to “hack” airplane. What would the slightly technical people in my family think was hacking? So I posted this:

It looks a little official or techy to be using the command line or terminal. DOS is for hackers; most people likely haven't seen a Bash prompt. Then it occurred to me that most people would think someone hacking the flight would try to control it into a building from their seat in a suicide attempt, à la 911-style so I tweeted this:
To finish up my joking prior to returning to work I posted a very blunt image and suggested that the airplane manufacturers replace the cabin network ports with a simple solid wall plate. They could also use a pair of scissors to secure the ports on the terminals as well.


I couldn’t focus on my work though; so here I am.

The real problem here

All joking aside, this is a very serious issue for air travelers, not just from an airline marketing standpoint; "can I trust this plane?"; but also from a security standpoint. On the off-chance that avionics systems, fuel systems, or any of the other control systems are accessible from the cabin this is a very dangerous security design oversight. These sensitive systems need to be separated immediately if they are in fact accessible from the cabin. With no stretch of the imagination, anyone in the security industry can imagine how an attacker could force a plane down.

Qualifying the onlooker
I often look for malicious activity when I travel. I look gruff, so I always get stopped by the TSA when I’m on my own. Two bags of tech and a little facial hair tends to do that. When I have my kindergartener with me it's all together a different security experience; they just see me as a “Dad,” we even go through the fastest lines. I tend to daydream about the thought that “everyone is a possible terrorist” in my head. When I’m going through the security checkpoints and watching the poor, poor lady with 3 kids trying to find a way to leave her bags outside of the ladies room because one of the kids really has to go and they need assistance I wonder who is using a disguise? American paranoia thanks to the media.

On a plane, I look for "suspicious activity." People not disabling their devices, not obeying the rules; I can size a person up instantly mentally, emotionally, I can see what makes them tick. That being said, I myself have Kali Linux for penetration testing, and Debian, FreeBSD, Ubuntu, and every other type of non-Windows OS on a thumb drive or a virtual machine in my bag (including several Windows OSes). I know what Wireshark looks like, and have done a fair share of network sniffing and log filtering; I’ve done pen testing on corporate networks, and know what that looks like too; injection attacks, you name it. If it looks remotely realistically hacker-ish I've probably seen it. Work IT somewhere there are a couple of script kiddies and you'll see a lot of bad stuff. I've even got a phone that runs Linux, and it's not Android and it has pen testing tools. Nobody ever suspects that sort of thing unless they're in the know.

If you look at the movies though, they, rather Hollywood portray hacking as an all together different thing: the bad guys have 300 baud modems and they use payphones like Hackers or Wargames; they have funky cell phones they can hack everything with: Tron Legacy; or they’re sporting the screen savers from The Matrix. That’s not really how it works though, nobody sneaks Sony MiniDiscs around in hide a books about simulations in a simulation. And while Blackhat might be based loosely based on a writer's impression of a true story, so was the Texas Chainsaw Massacre. Hollywood writers and directors sensationalize everything, so nothing they put out can be trusted beyond the remote possibility that a bad guy might use nmap, and that Unix is of the Devil. 


I love Unix.

On #oppsec, the guy sitting next to me on the plane however with the mirror reflective blackout privacy screen on his laptop seems up to no good. He's nervous, fidgety, paranoid, and sweaty despite the freezing A/C. Coming back from the facilities it’s easy to see he’s looking at porn. On the train coming out of Chicago you could see these professionals with the blackout screens work for the banks: LaSalle, Bank of America, Chase; that’s a completely different topic though. My point is it seems really suspicious when nobody can see a screen. I don’t want anybody looking at my screens because it usually invites conversations about stuff I don't care about.

On #infosec I definitely won’t be telling any of my unintentional travel companions that I’m a hacker, or security professional, or a whitehat anytime soon though; it invites too much questioning. People are always interested in what a "grey hat" is; I respond with a grey hat is a black hat because you can't be ethically a white hat if you do bad hacking. I'm a professional white hat, so I know the ways of the dark side; I have to; I have to think like a black hat to catch a black hat, block a black hat, or stop their never-ending botnet; or determine it's a misconfigured system thanks to IT.

Then there is the physical issue that I’m always dealing with: the never-ending fumbling under my seat because there isn’t enough room for 2 laptops, 2 tablets, 50 feet of power cables, network cables, electronics chargers, twenty pounds of books on computer forensics and my large shoes under the seat in front of me. Red flags? I hope not but who should be the judge? I mean are the airlines going to teach infosec to flight attendants? Are the systems going to be fixed?

What happens when you get the people who aren't hackers at all, but they want free access to the Internet because they recognized the network jack? I can imagine the ramifications of an inadvertent DDoS attack on a network due to pop-up ads, attempts for all programs on someone's overloaded system all trying to call home, the network traffic from Bonjour or the like.

Closing thoughts


The following is not meant to scare people, but I can say, if someone gains access to these systems, studies the network traffic, and makes repeated connections to the same systems over time to learn how they work, what they’re doing, and when they operate, it could be a matter of seconds for someone to connect, deliver a worm or a virus, or other malicious payload, and unplug before anyone ever notices if there is a physical access to the system. What does typical run of the mill malware do to an airplane computer system? I run clean read-only images. The guy with the laptop full off warez does not need to plug into this system. These computer systems need to be secured; and I mean yesterday; and if the airline companies aren’t sure if there is a security issue or not, they need to seriously investigate with proper security professionals. I can guarantee a “bad guy” who writes a virus for avionics systems won’t be going down in flames, but something like that getting out on the black market could cause a world of hurt to innocent bystanders.

If someone installs these applications on the plane when they are getting off and it causes the system to fail for the next flight, then this is a very serious issue indeed. Who was it then? Will the black box say? Will they know what to look for? Hopefully the avionics systems aren't running Microsoft Windows.

BSOD at Heathrow

The last thing the aviation industry needs is a bunch of rogue "researchers" hammering a flight's control systems with Raspberry Pis for the sake of research though. In this instance curiosity could kill the cat and the other 211 passengers onboard.