Book reviews: "America the Vulnerable" and "When Gadgets Betray Us"
Two recently-published books, “America the Vulnerable” by Joel Brenner, a former official at the National Security Agency (NSA) and “When Gadgets Betray Us,” by writer and security analyst Robert Vamosi, have one theme in common: We’ve come to depend on modern networks and technology, but the compromise of them by attackers is a serious threat to both individuals and society as a whole.
Cisco How-to Guides for firewalls, contact centers and taking that security exam
“America the Vulnerable” by Joel Brenner
In “America the Vulnerable,” Brenner, formerly inspector general at the NSA and chief of counterintelligence for the director of National Intelligence, says his work over the years gave him “a hair-raising view of the incessant conflicts being waged in cyberspace — conflicts short of war but involving concerted attempts to penetrate our nation’s information systems and critical infrastructure.
China, he argues, has successfully compromised corporate networks and stolen huge amounts of sensitive trade and military information, with the U.S. government so far failing to take much action. Among the events recounted in his book, he points to an attack on Google which the company disclosed in 2010 — as coming from China, in what has since been called “Operation Aurora.” Brenner writes, “Operation Aurora didn’t just hit Google. It was a coordinated attack on the intellectual property of several thousand companies in the United States and Europe — including Morgan Stanley, Yahoo, Symantec, Adobe, Northrop Grumman, Dow Chemical, and many others.”
In asking who did it, Brenner says “we can cavil about whether the right verb is ‘directed’ or ‘oversaw’ or ‘authorized,’ but the operation was approved at high levels of the government of the People’s Republic of China. According to sources available to U.S. diplomats, Li Changchun, a member of the Politburo Standing Committee and therefore a top dog, did what lots of people do: He looked himself up on Google.cn. And what he found upset him: Chinese people were writing unpleasant things about him, which other Chinese people could find on Google. This should not have been too surprising for a man who was the country’s senior propaganda official, nor was his response surprising. Li decided it was time to reassert control over China’s information space. So he directed (or oversaw, or authorized) a payback operation.”
“In the Google case there is no room for serious doubt that the PRC government was behind it,” Brenner states, adding this was but one wave of many attacks coming from attackers in China with a relationship to the Chinese government, including the People’s Liberation Army (PLA). (Read columnist Scott Bradner’s take on this book.)
“They’re big-game hunters who know what they’re after,” Brenner states. “And once inside a system they need be in no hurry. They can exfiltrate what they want when they want. Typically, they work during daytime hours — that is, daytime in China.”
Brenner sees electric-power utilities here as particularly vulnerable to a well-coordinated malicious attack. And he laments that “nearly all North American industrial electric generators are made abroad, and nearly all the really big ones come from China and India — mostly China.”
Brenner even postulates a scenario in which China would take out America’s critical infrastructure.
“China has made no secret how it would fight the United States, if it came to a fight,” he writes. “PLA strategy calls for combining network and electronic warfare against an adversary’s information systems at the start of any conflict. They would target the communication and control nodes and so lead us to distrust our own systems and undermine our decision making, operations and morale. Electricity, transportation, and financial networks would be punched out.”
In one theoretical scenario he sets in 2017, a conflict between China and Taiwan, which lies just off mainland China, also pulls in the U.S. because it involves freedom of navigation in the South China Sea. In Brenner’s suggested 2017 scenario, China goes active with military defenses, such as moving submarines near U.S. submarines. And then suddenly the San Diego grid goes down, followed by power grids in Seattle and Honolulu. Then, in California’s Central Valley, “turbines in three electric generators mysteriously blow up.”
As this all theoretically unfolds in 2017, the U.S. Secretary of Energy tells the U.S. president it takes 12 to 24 months to replace this kind of equipment, and that they’re made in India and China. By now, the President has authorized the U.S. Cyber Command (which today is led by Gen. Keith Alexander, the NSA director) to retaliate against “six specific parts of the Chinese grid.”
But then, says Brenner, the Chinese, the largest holders of U.S. debt, start “selling Treasury Notes on the open market,” causing “all market indexes to go into free fall and trading halts on U.S. markets — but not overseas. The dollar is being clobbered.”
Brenner’s made-up U.S.-China conflict of 2017 ends with the president of China calling the White House with an offer to sell new generators to the U.S., especially since other generators might suddenly also go down in critical locations. The Chinese leader angrily demands the U.S. fleet change course and leave the Chinese coastal area immediately or more disruptions of the U.S. power grid will occur. And in Brenner’s tale, the U.S. carriers do leave and the confrontation is smoothed over diplomatically, at Chinese request. Brenner ends his theoretical 2017 China-U.S. cyber-confrontation by saying, “I’m not predicting this scenario, but it’s well within the realm of possibility.”
“When Gadgets Betray Us: The Dark Side of Our Infatuation with New Technologies” by Robert Vamosi
If Brenner’s cyberwar scenario isn’t paranoid enough, check out Vamosi’s book about the security issues in modern-day gadgets in our cars and houses and workaday world. He claims everything from GPS-enabled devices to keyless-entry and remote-ignition equipment for cars, for example, can and have been hacked.
“These two technologies — keyless entry and vehicle immobilizer chips — form the basis of most high-tech antitheft technologies in cars sold today,” Vamosi writes in his book, which is intended to puncture any illusion about the security of technology now used in automobiles. “Both rely on RFID codes exchanged over the air. The flaw, if any, is that most cars use only 40-bit encryption for this; upon introduction in the 1990s, this was sufficient, but it is no longer adequate.” He adds: “256 bits is considered strong encryption, but it is doubtful you’ll find a car on the street with that level of crypto.”
Vamosi revels in presenting tales of hacking of car security as well as university research showing how it’s possible these break-ins can be done. Fascinated with how modern cars with computerized features such as tire-pressure monitoring systems might be hacked, he says researchers from the University of California, San Diego, and the University of Washington have done probes in which “they could falsify readings from the fuel gauge and speedometer; disable the antilock brakes, selectively brake individual wheels on demand, and even stop the engine. The researchers found they could do this even while the car was speeding down a highway.”
He notes that cars today contain a black box device, the motor vehicle event data recorder, that can record vehicle data, but he asks: Can we trust the data collected in the first place? He warns there’s cause to suspect it, based on cases where MVEDR data appeared to be at odds with physical evidence. Indeed, Vamosi has questions about all manner of car data collectors, such as the General Motors OnStar with its GPS-based automotive location identifier and its ability to “decelerate a speeding car remotely” through a “kill signal” sent when police are in eyesight of a stolen car. He worries this could be hacked but admits he has seen no evidence to suggest this would be easy at all.
See 11 cutting-edge car tech innovations
Vamosi sees security vulnerabilities everywhere, noting how it’s possible to hack TV remotes as well as hotel minibar locks. And what about the electric power grid? He turns his attention to the newer smart meters that are being installed by electricity providers to remotely gain information about household power usage, describing research by hackers on how to break into them.
Is Vamosi off the deep end when he worries that someone from the Internet will break into your DVD player and access the controls? “More likely, the person could create a denial-of-service attack by changing the internal programming, preventing you from seeing a show you want to watch,” he writes, adding, “Maybe your Internet-enabled DVD player isn’t connected to anything else in the house. But maybe the TV is connected to your computer and from there, to your home computer network. Now someone from some other country could seriously muck around with your DVD player and also access personal data from your computer or home network.”
Vamosi moves on to yet more disturbing possibilities, such as disrupting shipping operations at a major port by wirelessly interfering with the proper authentication of RFID tags and their information stored in databases that used to identify shipping containers through SQL injection attacks.
“While this may sound impossible outside the plot of a techno-thriller, unfortunately, it is not,” he says in his book, pointing to research done at Vrije Amsterdam in the Netherlands. “Technically what they did is fuzzing, where you simulate code to trigger a buffer overflow or cross-site scripting attack. The researchers realized that if just one infected RFID tag could be put into circulation, that infection could spread far and wide.”
While some may see Vamosi as an alarmist, worried about events that perhaps have slight chance of occurring, his brand of studied paranoia could be beneficial to many of us, who as he notes, are addicted to the technology we surround ourselves with and seldom question how it could be subverted. “Gadget manufacturers that simplify their complex technologies only give us the illusion of control, and this in turn opens the door to greater risk,” he concludes, pointing out, “Others will use our naivete against us.”
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security.




