How intelligence data leaks caused collateral damage for infosec
Alvaka Networks' Kevin McDonald looks at the real-world damage caused by data leaks at the CIA and NSA, which have put dangerous government cyberweapons in the hands of hackers
WikiLeaks' CIA data dump shook a lot of regular folks because it showed that the U.S. government can allegedly monitor not only social media, but inside cars, offices and homes through a variety of electronics. PCs; Macs; and iOS, Android and Windows phones are all potential targets. It revealed that internet of things devices, smart TVs, cameras, routers, switches and maybe even refrigerators are all vulnerable.
But this is not news, and it should be a matter of general knowledge by now. The specific techniques are coming to light, but no one should be surprised that the U.S. intelligence community had these hacking capabilities. Many think it's great that this information has come out. I am not one of them.
The recent WannaCry ransomware attack is an example of the predictable damage to come from intelligence leaks. WannaCry leveraged a Microsoft Windows vulnerability and spread itself through the Server Message Block file-sharing protocol. Microsoft patched several of the zero-day vulnerabilities before the data was released by the Shadow Brokers. WannaCry provided a front-row view of what happens when organizations maintain and use zero-day vulnerabilities.
Why is WannaCry relevant to the NSA and CIA hacks? Because the vulnerability it leverages was attributed to the EternalBlue exploit released in a Shadow Brokers dump of alleged NSA exploits in May 2017.
The recent WannaCry ransomware attack is an example of the predictable damage to come from intelligence leaks.
This is just one example of what will likely be a tidal wave of advanced attacks as leaks continue from insider threats and outside hackers. I am confident that the NSA leaks and the massive amounts of CIA data released by WikiLeaks will impact American national security and global cybersecurity for some time. We do not know what the Shadow Brokers may still have of the CIA's and NSA's secret hacking information, but the group has pledged to sell these stolen cyberweapons via a monthly subscription service.
The additional public uncertainty of OS, networking and internet of things security raised by the leaks will delay operations and inject cost and caution where they did not exist previously. Operations all over the world have to be reconsidered with the leaks in mind. Billions will be spent defending governments, businesses and individuals from both the known and unknowable implications of these continued leaks.
The blowback from data leaks
There is much talk about the so-called data democratization of government information being leaked and the need to equalize the balance between secrecy and transparency in government. While we cannot have an out of control intelligence community, the absurdity of that statement is just painful; secrecy is, by definition, the antithesis of transparency.
Secrecy offers many benefits to the work of intelligence, criminal investigations, defense and even competition in the commercial sector. Without secrecy, there can be no advantage in anything that matters in any competition of wits. Secrecy in software and hardware design slows the illicit copying of intellectual property. Secrecy in military systems designs and capabilities enable many advantages against an enemy, such as the element of surprise.
In The Art of War, Sun Tzu, the ancient Chinese general, military strategist and philosopher, wrote: "Hence that general is skillful in attack whose opponent does not know what to defend; and he is skillful in defense whose opponent does not know what to attack." Secrecy stops technology from being obtained by the enemy and makes defense from its unknown capabilities difficult, if not impossible. Secrecy provides cover for activities that are vital to our national defense.
Those who advocate for the total destruction of government secrecy are advocates for the destruction of American supremacy. For more proof of what a loss of secrecy can do in a war, we need only look back at the compromise of the German Enigma machines and Japanese super-encipherment techniques during World War II. Both of these breaches in secrecy had heavy costs to these countries. If the Allies had not breached their enemies' secrecy, the outcome of the war could have been very different. Without secrecy, there is only defeat.
Muddying the attribution waters
Now let's address the elephant in the room: Attribution of an attacker. It is undeniable that cyber attribution has always been difficult. Whether a simple criminal matter or a nation-state attack, attributing and identifying who the attacker was with little doubt is critical to response, prosecution and future defense. This is especially true when a response can lead to criminal prosecution of Americans or, worse yet, potential acts of war in response to attacks.
According to a WikiLeaks post on March 31, 676 pieces of the source code files released were from the CIA's secret antiforensic group known as Marble Framework. The WikiLeaks' statement claimed, "Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, Trojans and hacking attacks to the CIA."
The release of these tools and techniques (if proven to be legitimate) casts new doubt on future investigations; claims of foreign cyber attribution for attacks, such as Russian involvement in our elections; crimes purportedly committed by political activists; and more. Any bright defense attorney or government spokesperson will be able to simply point to the release of these tools as evidence of potential alternate theories.
Now that these tools are in the wild for anyone to use, how can we ever really know who does what? Criminal convictions come from evidence beyond a reasonable doubt, and the ability to falsely attribute any action provides just that. This is one ugly result that supporters of these leaks fail to recognize.
For those who support leakers like Edward Snowden and these most recent data dumps, I hope you might consider some facts. We know for a fact that hundreds of thousands of computers were infected by the use of these NSA tools. That means that likely thousands will never see their data again. Whether it be personal pictures and financial information or business data, the loss of data is no joke and has real consequences.
We also know that this is just the beginning of potential attacks that will likely impact thousands, if not millions more in tangible ways -- not theoretical actions or violations of privacy, but real losses. I have no doubt lives have been lost where foreign organizations, who are enemies of the U.S., have eliminated those who they believed were potentially involved with the CIA based on the leaks.
While I am a huge advocate for privacy, the search for it cannot be a license to commit detrimental acts or treason against America and to cause real harm to individuals and businesses. There has to be a balance between the desperate and life-threatening need for secrecy and the need to protect the right to privacy and keeping government in check.