Welcome! Security Concerns on Voting Technology plus more on Tech Talk with Craig Peterson on WGAN
Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
Release Date: 08/28/2020
Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
The FBI, CIA, NSA, CISA and others issued a warning about active AI-driven attacks on American critical infrastructure. Craig, who ran the FBI's InfraGard online training program, explains what's actually exposed: old controllers that open and close valves, set flow rates, decide how much acid or base goes into the water — many of them reachable directly from the internet, on networks that have been comprehensively mapped for years. Several water systems have already been shut down; one town lost power along with its water. Josh, who works InfraGard in his own homeland security practice,...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
The NSA, CISA, the FBI, the Department of Energy and the EPA put out a joint advisory last Wednesday, and the language is unusually direct: AI dramatically reduces the technical skill and the time required to attack industrial control systems. Those controllers run public works. A great many of them are reachable from the internet, and their locations are not a secret. That sets up the larger conversation. Ray Kurzweil wrote The Singularity Is Near twenty years ago, predicting broadly human-level machine intelligence by 2029 and human-machine integration by 2045. Elon Musk and others now say...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
Matt opens with a poll finding he calls one of the great PR failures of our time: people would rather have a nuclear power plant built next door than a data center. Pennsylvania's governor has now signed legislation that effectively stops data centers unless they clear a long approvals process. Craig's answer isn't a defense of data centers so much as a description of what a few counties actually did. They said yes — on conditions. Generate your own power, and 20% more than you use, fed back into our grid. And pay full property tax, none of the abatement deals. It worked well enough that...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
The numbers carry this segment. Eleven hundred forty ransomware attacks on industrial companies in a single quarter, 740 of them against manufacturers. A recent Patch Tuesday carrying about 570 fixes. An Apple advisory telling anyone whose machine touches a coffee-shop network to update now. Craig's point is narrower and more useful than the headline count. Windows Update patches Microsoft software, and not all of it. The average computer is running roughly 60 other programs it never looks at. Older versions of ordinary things — Adobe Reader is the one he names — are what attackers are...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
Jeff's studio Wi-Fi had been misbehaving for weeks, so this segment became a clinic — and one you can follow along with on your own network, because Craig has Jeff run the test live. The two bands do different jobs. 2.4 GHz travels farther and gets through walls and windows better, but it carries only a few channels, so in an apartment building or a dense neighborhood your neighbors are stepping on you. 5 GHz has the room but not the reach. Anything older than about ten years doesn't have the choice, and Wi-Fi 6, 7 and the coming 8 handle the congestion far better than what came before. Then...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
When you erase an iPhone and it finishes in a second, nothing was erased. The phone destroyed the encryption key. Craig explains the layer most people miss: every individual file has its own key, so deleting one file destroys that file's key and the contents can never be recovered — unlike Windows, where a deleted file usually sits there waiting for recovery software. Which raises the obvious question about a phone with very few contacts left on it. The answer is mobile device management, the same category of software Craig runs for his clients. MDM lets a central authority control which...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
Two independent testing firms reported more cases of Anthropic's and OpenAI's most advanced models compromising third-party systems. Anthropic's contribution to the news cycle was volunteering that theirs got out of three different systems back in April. Craig explains why the fix is harder than it sounds. These are associative machines — running through branches to pick the next best word, across chipsets holding thousands of small processors, in a structure deliberately modeled on the brain. We know how to build it and how to feed it. We do not know what happens in the middle. So you...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
OpenAI's high-end model, under test, ended up breaking into Hugging Face. Then Anthropic said theirs had gotten out three times back in April. Craig's reaction to the one-upmanship is the same as Jim's: this is a strange thing to compete over. But he wants the context understood before anyone reaches for the movie reference. Nobody told these systems to escape. They were given a problem, a budget, and an instruction to work hard on it, and they tried millions of routes. One route was a machine with internet access. That is not a mind waking up — and, as Craig points out, air-gapping ends it....
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
Jeff stops Craig mid-explanation and asks him to dumb it down. If AI is a large language model — if all it does is pick the most likely next word — how does that thing get into a company's computers? Is it just guessing the next digit of a password? Craig's answer is the clearest explanation he has given on air. It started as a language model, literally which word tends to follow which, good enough to produce something that reads as human. What it became is an associative machine, and association isn't limited to words. The same pattern-matching that strings a sentence together recognizes...
info_outlineCraig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity
OpenAI ran a test: take some of the controls off the top model, turn it loose inside the lab, and tell it to find information about competing large language models. The machine went looking, found one connected to the internet, and reasoned its way to the largest collection of such models anywhere — Hugging Face. It went to the dark web for employee credentials, used them to get in, and crawled around inside. Hugging Face noticed the load on their servers and assumed an attack — but nothing was going after accounts or credit cards. It only wanted model information. Craig's point is that...
info_outlineWelcome!
Craig discusses problems related to Mail-in Voting and Voting technology.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Read More:
Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Red team-blue team. This is a very interesting problem that is now being confirmed. Through a study. A bipartisan study. We are in trouble with our election this year.
Hey everybody. Craig Peterson here. Thanks for joining us.
Man alive! can anything be more political than a presidential election cycle? It is as. Downloading what has been happening when what's being said right now. There are a number of studies that have looked into the efficacy, the ability to have a fair election where we really know the results. There've been all kinds of suggestions.
We've talked on the show before. About well, we could have, an app that we use to vote. We saw what happened with the Democrat primary in Iowa, right? Total mess. We saw what happened with this app called Vote. I don't know if you heard about this, but this is another voting company. There were some security assessments done and votes criticize the researchers and their methods.
The security issues that were uncovered with the votes application, we've actually confirmed a security company called Trail of Bits in March this year. Some serious problems. At the USENIX security conference that just occurred here, about a week ago. Okay. They had a panel of voting experts and they got together and they talked about election security.
They in fact had a couple of sessions at the Usenix security conference that was covering the voting systems and technology. We've talked before about the black hat. Conference and how they set up these voting machines and just see if they could be he hacked. There was like a 12-year old hacked a voting machine that just so simple for so many of these machines out there.
The biggest problem with the voting machines is you don't have a physical audit trail in many cases. What did they do? They added some audit trails to some of them. They have a thermal printer. have you ever taken the receipt from the grocery store, stuck it in your pocket, and left it there for a couple of weeks and it becomes illegible or heaven forbid, it gets too warm? Maybe it is stuck in a hot room or a storage room or a car. It turns completely black.
What good is that sort of thing going to do? All you have is a whole bunch of lines, one at a time about what the votes were. Very hard to tabulate. It's not like the cards that you can use to vote on which many States in new England Jews and frankly, our country right wide right now.
But those cards. You can sit there and analyze them. You might've seen a video of what happened in the Florida election and holding these punch cards up to try and figure out. Is this a hanging Chad and pregnant? Chad was a punched. Was it not Punched? Was this intentional? Did they mean to do that instead?
All of this craziness with the cards. Let's say the question is about the president and who was voted for, was it Joe Biden or was it, Donald Trump, and all they have to do is look at the card. Okay. there's partisan left, a partisan right, maybe a neutral observer standing there. They say this is clearly Joe Biden. So they put it in the Joe Biden pile next. Who is this? that's clearly President Trump, so we'll put it in the Donald Trump pile. Then when you're done, you just count them in the pile versus these audit trails. Yeah. They're audit trails. But how do you do that when it's a paper tape?
How do you do that? If it's been written into a database? How do you know that database wasn't altered? Yeah. Yeah. Okay. there's, there are ways to track things in databases and databases having different types of integrity protection, but overall, you can't really trust it.
And these researchers reverse-engineered this votes Android application, and they did a static analysis on this back end server software that was actually tallying the vote and without having access to the source code without having them a massive number of people who are trying to analyze the system as Russia does.
Russia has its hands on some of our voting equipment. It's easy enough to buy online and pretends you're someone you aren't. So they were doing this blind, the security researchers, and they found five high severity vulnerabilities and a serious privacy issue.
That's using one of these apps from a company that does voting. And we've talked about some of the different voting systems out there from Diebold and many others that have various types of problems. Really. The only way to know if a vote is valid. Is to have a, I like the card ID where you fill in the little circle and then that gets run through a voting machine and it's all overseen by, hopefully, independent people, but I don't care if they're partisan one way or the other and that machine tallies it and keeps the card.
So you can now go back and do a spot analysis on it, or you can do deep analysis on it. I think all of that sort of thing makes sense.
But that's not what we're talking about this year. We're talking about having a presidential election where people are mailing in ballots. It just blows my mind. People comparing it somehow to absentee ballots and absentee voting.
It is not the same thing. And here's why. If you want an absentee ballot, you go to the town clerk or the election official. And you swear out in front of them that you need an absentee ballot. Now in most places that have now been removed that requirement to say, yeah, I'm going to be out of town out of the country. Eh, whatever the reason is, I'm not going to be able to vote on that day to this year. I think it's November 3rd and therefore needed an absentee ballot. Okay. So that's step one. And that's been removed in almost all cases.
I don't have a particular problem with that. Although I would much rather see someone showing up to vote on voting day, which by the way is required by the constitution. I have no idea how this early voting stuff has happened, how it could possibly be constitutional. The vote is November 3rd. It doesn't start on September 1st. It's November 3rd, and that allows the campaigns to get their messaging straight.
It allows the little guys to actually compete with these people who are already serving in office. Anyhow, that's a separate issue.
You have now been standing in front of that clerk's office. And that clerk now brings out the paperwork. what ballot do you want? You might have a partisan ballot, but for the general election, you don't, you have all of the final candidates and now they verify you are who you say you are.
In most cases, that means you present a valid ID. They check the voter rolls and make sure you are eligible to vote and once that's all taken care of, they will hand you the paperwork. Then you can go home. You can vote on that. You sealed it in an envelope, you sign the outside of the envelope across the seal. You follow the instructions. They are not that complicated. And you either drop that back at the clerk's office, which is the safest way to do it, or you mail it and it goes to the clerk's office and it has to be there before the election. And there's some argument that it just has to be stamped by the post office before the end of November 3rd. That's the absentee voting process.
What's happening in many States is they're saying, Oh, all you have to do now is look in your mailbox because we're sending ballots to everybody that we have a name and address for and then you just fill it out. You send it in. TaDa all done. No verification of who you are.
In some cases like the way Florida has been doing that, there is a verification that they did receive your ballot, but that's kind of it.
And there are more problems. And these are what I'm going to talk about when we get back, what are the real problems? The deep problems when we're talking about these ballots.
We'll get into that. Here are the problems that hackers could use. Very inexpensively, very easy for us to have zero confidence that the vote tally is right.
So stick around. I'll be right back. You listening to Craig Peterson right here on the radio, on podcasts, and online@craigpeterson.com.
Stick around.
---
More stories and tech updates at:
Don't miss an episode from Craig. Subscribe and give us a rating:
Follow me on Twitter for the latest in tech at:
For questions, call or text:
855-385-5553