The Perfect Weapon

The Perfect Weapon, HBO, David Sanger

In mid-October, HBO released its documentary, The Perfect Weapon, about growing cyber security risks (trailer). A recent Cipher Brief webinar featured David Sanger, national security correspondent for The New York Times, who wrote the book on which the documentary was based, and Mary Brooks, who contributed to both his book and the documentary, and was moderated by Cipher Brief founder Suzanne Kelly.

Creating a documentary based on a detailed, fascinating, and chilling 340-page book is a challenge. It had to be more interesting than 000s and 111s scrolling down the screen. There was a history to lay out. Director John Maggio decided to render the technology aspects of earlier cyberattacks in broad strokes and to humanize the story by focusing on the victims. This approach not only revealed how many sectors of society are vulnerable to cyber criminals, but also how diverse are the sources of these attacks.

The first cyber attack receiving much play in the United States was North Korea’s 2014 takedown of Sony in response to a movie it didn’t like. For that segment, Maggio’s team could interview actors and executives. It was harder to get the story of the next significant attack—this one by the Iranians on the Sands Casino in Las Vegas—because the casino executives don’t want to publicize it.

Since then, attacks have continued, most recently with ransomware attacks on US hospitals already stretched thin by the coronavirus, and on local governments in Florida, for example—after crippling attacks on Baltimore and Atlanta.

Though costly and significant, these episodes have not been serious enough to trigger retribution by the US government. “They are short of war operations,” Sanger said, “and deliberately calculated to be so.” The potential for much more consequential acts definitely exists. It is known, for example, that malware has been placed in the US power grid, where it sits. Officials don’t want to talk about it, or remove it, ironically, because they don’t want the bad actors to understand our detection capabilities.

Of course, the United States isn’t inactive in this arena. In 2010, our government. and Israel used the malicious computer worm Stuxnet to disable Iran’s nuclear program, an action US officials won’t admit to even now, Sanger said. Unfortunately, the destructive Stuxnet code escaped into the wild and is now available to many black-hat hackers. Stuxnet “didn’t start the fire,” he said, “but it was an accelerant.”

Who is behind an attack can be murky. For various reason, organized crime has increasingly muscled its way into the cyber-threat business. Governments hire hackers or external organizations to create havoc, because it gives them deniability. “Not us,” they say.

The US Cyber Command’s goal is to “defend and advance national interests.” However, the job of preventing attacks is difficult. It’s a challenge that requires considerable imagination, given an environment where the risks are escalating rapidly, the technology is improving constantly, and the targets have no boundaries. You may have read about recent threats to COVID vaccine research.

What exactly are the “national interests,” when American businesses have suppliers, clients, and customers all over the world? Companies don’t want to be perceived as working against those relationships. Google, for example, declined to participate in a military program to make drone attacks more accurate. Similarly, though Microsoft and the Cyber Command were both attempting to disable TrickBot in the last few weeks, their efforts were independent and uncoordinated.

Thomas Donahue, Senior Analyst at the Center for Cyber Intelligence has said, “We cannot afford to protect everything to the maximum degree, so we’d better figure out what cannot fail,”

The documentary—and the book—lay out what’s at stake for all of us. Past posts on this topic:
* Our Biggest Threats Keep Growing
* Cyberthreats: Coming to a Company Near You

Technology & Elections

vote, voting, election

A set of articles in the current issue of Wired discuss the part technology can play in improving our elections. Skeptical, all things considered? You should be. Still, here’s what to watch for.

Candidates and Facebook

James Barnes, a Facebook employee embedded with the Trump campaign in 2016 (think about that a moment), has had second thoughts and is now working to promote Joe Biden at the political nonprofit Acronym. It produces digital media campaigns for progressive candidates and causes. By the end of summer, though, very few voters were undecided, so their campaigns weren’t making converts. One can only hope that the Trump campaign’s October efforts to outspend Biden on Facebook ads in several battleground states, according to this CNBC story, will fall flat too.
Read: PW Singer’s Like War: The Weaponization of Social Media.

The Voting Process

To be a state election official is to be plagued with nightmares. “We all knew we were headed into what would be a contentious election year,” said Arizona’s Secretary of State, Katie Hobbs, in a model of understatement in this Wired article by Lily Hay Newman. Plus, they know they have a derailing technical problem or two: In Georgia’s disastrous primary, for example, all 159 counties were using new machines for the first time. Plus, the pandemic. Officials have had to scramble to find polling places. Traditional venues—schools, community centers, churches—balked. Experienced poll workers? A vanishing species.

Texas election officials and a team of university-based computer scientists, Wired reports, have devised a way to use advanced encryption technology—homomorphic cryptography—to improve our notoriously vulnerable voting machines. (Just using the term, I’ve already approached the limit of my understanding of how it works.) The machine assigns a lengthy ciphertext to each vote and prints out a short identifier, akin to a bit.ly link. Voters can use these to verify their votes are “in there.” Part of the beauty is that votes do not need to be decrypted to be counted, so privacy is maintained.
Read: James McCrone;s Faithless Elector, about a member of the electoral college who doesn’t stick to the script or McCrone’s brand new book, Emergency Powers, about how far someone will go to hang on to the presidency. Hmmmmm.

Secure Vote Counting

In this election, several states will use “risk-limiting audits” to validate results. These methods link the scale of the audit to the victory margin. If a candidate wins big, even a small sample of randomly selected ballots can confirm the results. In closer contests, a larger sample is needed. Bottom line: Unfortunately, processes, equipment, and practices vary widely, state to state, and nationally, the lack of investment in improving them contributes to a loss of faith in our elections that eventually damages every one of us.

The Woman Is a Spy

Three women who’ve made outstanding careers for themselves in the intelligence community were featured in a Cipher Brief webinar last Friday, moderated by the organization’s founder, Suzanne Kelly, former CNN Intelligence Correspondent. As a writer interested in that world, I was eager to hear the women’s perspectives.

The women were:

Over the course of these women’s careers, the attitude toward women working in intelligence has evolved, just as it has throughout American society. When they started out in the early 80s or so, the intelligence community was an old boys’ club, and most women were relegated to support staff and administrative positions. The diversity of job opportunities for women is much greater now—after all, CIA Director Gina Haspell is a woman—but vestiges of old attitudes remain.

Thus, the era in which a story is set makes a great deal of difference as to how female characters would be treated. Perhaps engineering backgrounds gave two of these women added insight or practice in breaching institutional gender barriers.

The panelists had all worked in a variety of settings—for both government and the private sector. They change jobs and vacuum up new knowledge and skills. So, if your character needs a particular expertise, it certainly would be realistic to create a previous position where she could have gained it, inside government or not. Or, even in her own security services company.

Savvy women in the intelligence community work hard to develop a network of women in their and other intelligence agencies for all the familiar advice-seeking, moral-support reasons we know. From the perspective of these women, a more diverse workforce—in terms of gender, cultural background, type of education, analytic style, and where people have lived —produces better intelligence outcomes, as intelligence community employers have come to appreciate.

Suggested reading:
American Spy by Lauren Wilkinson
Bloodmoney by David Ignatius
Madame Fourcade’s Secret War by Lynn Olson

Good Covid Ideas from Bill Gates

Bill Gates has probably spent more time thinking about public health—not just in the developing world—than almost anyone who isn’t a medical epidemiologist. In a 2015 TED talk, he warned about the likelihood of a pandemic and his bottom-line was, “We’re not ready.”

Being right isn’t always gratifying. Yet, in the current issue of WIRED, Gates doesn’t cast blame on the skeptics. “We can do the postmortem at some point. We still have a pandemic going on, and we should focus on that.”

His message is for public officials and private industry alike. A particularly urgent need is for a rapid self-test for Covid 19. Most tests today, which require people to wait days for results, are essentially useless, Gates says, and a big barrier to quicker test results is the insurance reimbursement system. Tardy tests are reimbursed at the same rate as timely ones. Why not build in a financial incentive for speedy response and a penalty—including no reimbursement at all—for delayed results?

Another shortfall is that the US should help the vaccine companies build extra factories for the billions of doses that will be needed around the world if the pandemic is to be effectively stopped. Although this would be expensive, he says it’s a fraction of the money that will be lost in a tanking worldwide economy. “In terms of saving lives and getting us back to normal,” that expenditure is a smart and essential investment. Interesting.

Back to blogging–yay!

Good Health

People’s varying reactions to Covid-19 and the quarantine amaze me. Not always in a good way, though I still laugh when I recall Kellyanne Conway’s criticism of the WHO, “This is Covid-19, not Covid-1, folks. You would think that people charged with the World Health Organization facts and figures would be on top of that.” She followed up that jaw-dropping misunderstanding with “People should know the facts.” Spokespeople too.

I hope you and your family have stayed well and am happy to report good news on that front for my family, so far. Even though New Jersey is a peanut of a state, we have seen more Covid deaths than our big brothers, Texas and California.. The county where I live has suffered more Covid deaths than 16 entire states.  

Bad Politics

Starting in April, I took a break from 4-day-a-week website posting. I I felt oddly speechless in the face of the pandemic, the politics, the gun-toting protestors in state capitals, hurricanes battering the South, the West ablaze.

I was heartsick in the aftermath of our massive social upheavals. Now that political correctness isn’t politically correct any more, we find how much ugly stuff it hid. Yes, it occasionally strayed into eye-roll territory, but it reinforced norms about what is acceptable in a modern society made up of many threads and strands. It expressed how we should treat each other. Maybe it kept the lid on, a bit. And since behavior lags attitudes, it may have helped at least a few people break the habit of reflexive hostility and censorious opinion.

Now, of course, Americans feel empowered to give their malicious attitudes and beliefs free rein. I wish I didn’t know this dangerous river of ignorance and prejudice still flows through our country. I would have preferred to continue deluding myself that we are moving beyond the corrosive views of the past. Maybe this time, more people of good will are paying attention.

A Brighter Note

While not blogging, I wasn’t doing nothing. I read a lot (reviews of the best stuff coming soon). I watched some under-the-radar films worth catching (ditto). I also escaped today’s woes by delving into the past, working on a family history. I finished and sent off a short story. I made a batch of birthday cards.

I sought advice from three experts on various aspects of my novel and took it. Then I read the whole thing through quickly, not as I usually do, interrogating every word, sentence, and paragraph. Here I’m reminded of the woman who bragged in an online advice-to-authors forum that “by the time I send my novel to the publisher I have read it through three whole times!” Three? Thirty-three is more like it. And twice out loud.

A last flash. In early March two Siamese kittens scrambled into our lives. Will and Charles. Kittenhood has been an entertaining way to spend the lockdown. We vacillate between “What was that crash?” and “It’s too quiet.” The picture? Sometimes, if you need a kleenex, you just have to get it yourself.

Closed Doors photo: falco for Pixabay

Other People’s Problems

Reading

Memoir is not my favorite genre, but lately I’ve read a couple of interesting ones—about a misbegotten woman and an idolized father—and two nonfiction stories about the trials of war, one with a happy ending, one not.

****Celibacy: A Love Story
By Mimi Bull – The book’s subtitle as the punchline, “Memoir of a Catholic Priest’s Daughter.” As a child in a world of secrets, she was adopted by an older woman and her twenty-something daughter. It doesn’t surprise that her “sister” turns out to be her mother. Only after the mother dies does Mimi learn who her father was. Despite the lack of suspense, the book is fascinating. The adult Mimi and her husband lived in Istanbul, in Sedona, in Vienna. A unique story, charmingly told.

**The Man in the White Sharkskin Suit
By Lucette Lagnado – I heard about this book while I was in Egypt, a country that once had a significant Jewish population, until Egyptian President Nasser forced them to leave. To the child Lucette, Cairo and her family’s apartment were paradise, and her father was king. When they are exiled, a Jewish aid agency finds them a disreputable lodging in Paris and an unsatisfactory apartment in New York. Lucette’s father’s business is murky; in New York, he sells fake Italian neckties. The family hates its new life. Lucette blindly adored her father, but I cannot tell you why.

****Escape from Paris
By Stephen Harding – This is the true story of a group of American airmen shot down over France and the complicated escape routes the French set up for them. Danger is on all sides. One of the safe houses is right under the nose of the Nazis, in the apartment of the caretaker of the Hôtel des Invalides, site of Napoleon’s tomb. Very exciting!

***The 21
By Martin Mosebach – As the cover proclaims, this is “a journey into the land of Coptic martyrs.” On February 15, 2015, twenty-one young Egyptian men, ISIS captives, were marched onto a beach in Libya and beheaded. The video recording of that event went around the world. What was most striking was the dignity and faith they maintained until the end. The author sets out trying to learn about them, their home villages, and the faith that supported them. A bit philosophical for me, but I read it to pay my respects.

Busy Day

For the two new members of our family. “First we tore apart this feather thing, then we went to the vet.” Hard to get a clear picture. I tell them to stand still, but . . .

How the West Was Lost: Travel Tips

A recent trip to Scottsdale prompted a return visit to Western Spirit: Scottsdale’s Museum of the West, at 2d Street and Marshall Way—a fine place to spend a couple of hours. There’s a permanent exhibit of Western “stuff,” ranging from saddles to signage to six-shooters, plus special exhibitions.

On view until August 2020 are more than 300 works from the man called “the West’s greatest artist,” Maynard Dixon. Born in 1875, he lived during the time the frontier American West began to disappear.

When he was a child, the wars between Indians and European settlers still raged, Texas cowboys herded cattle north long distances to railheads, and “civilization” was as flimsy as the frontier town stage sets in Blazing Saddles. Dixon not only painted hundreds of notable landscapes and portraits, he was a prolific illustrator, producing cover art for magazines and illustrating popular novels.

Artists gave Easterners their first glimpses of the beautiful and dramatic West, but they were less appreciated on their home ground. Said Dixon,
“In those days in Arizona being an artist was something you just had to endure—or be smart enough to explain why. . . . If you were not working for the railroad, considering real estate or scouting for a mining company, what the hell were you? The drawings I made were no excuse and I was regarded as a wandering lunatic.”

Also at the museum, we had the chance to see a one-man show, “Wyatt Earp: A Life on the Frontier,” in which one of Earp’s descendants gave the true “not-what-you-learned-from-Hollywood” story. It was a lot of fun (tickets best ordered beforehand, though I don’t believe the website makes that clear). While this program may not regularly repeat, the museum offers frequent special events, noted on its website.

By coincidence, on this trip I was reading David Grann’s Killers of the Flower Moon, which puts a tragic twist on the story of the “conquest” of the West. In the 1870s, the Osage tribe had been driven into an unpropitious area—“broken, rocky, sterile, and utterly unfit for cultivation,” according to a Bureau of Indian Affairs agent. The Osage bought the land, located in what became northeast Oklahoma, thinking it so undesirable they would not be evicted again. Maynard Dixon’s works even evoke this suffering.

But the new reservation held a surprise. Oil. For a time in the 1920s, tribe members accumulated dollars in the millions, becoming the wealthiest people per capita in the world. Then the murders began.

It’s a riveting yet almost forgotten real-life tale of greed, corruption, and betrayal that reads like a novel. There’s even a bit part for J. Edgar Hoover, who intuited that solving this case would catapult his little agency—and himself—to national prominence.

Alas, we cannot look back at those days and think the exploitation of our beautiful West ended there. We are still losing it.

Or maybe this post should be titled “Small Museums: Part 2.” (Part 1 here.)

*****The Spy and the Traitor

By Ben Macintyre – A pal of John Le Carré, Ben Macintyre brings the novelist’s gift for writing compelling characters and page-turning narrative to the nonfiction realm. The Spy and the Traitor, subtitled “The Greatest Espionage Story of the Cold War,” is based on the defection to Britain of KGB operative Oleg Gordievsky, and it provides at least as many thrills as the best espionage novel.

Gordievsky, raised in a family where working for the KGB is the family business, becomes disenchanted with Soviet hypocrisy. Posted to Denmark, he has a tantalizing taste of what life is like when lived outside a surveillance society. A British MI6 agent, working in Copenhagen under classic diplomatic cover, notices him and several modest bits of outreach are made by the two of them, but nothing comes of it. Gordievsky, however, sees his future and when he returns to Moscow, works at becoming accepted into the KGB’s English-language training program. Finally, he succeeds. After a few years, he’s posted to London.

Then the connection is made, and over at least a dozen years, he secretly works for MI6.

The intelligence he provides and particularly his insights into the Soviet mindset are pivotal in the late Cold War era, and he provides significant background for Margaret Thatcher’s meetings with Soviet leaders. His advice helps her craft proposals they can accept. It’s vital and thrilling diplomacy, all accomplished well out of public view.

I especially enjoyed the intriguing nuggets of tradecraft Macintyre drops as he follows Gordievsky’s twisting path. That level of detail is just one feature inspiring confidence in the narration and investment in the protagonist’s fate.

Throughout his years spying for Britain, Gordievsky is, of course, acutely aware that Soviet paranoia is ever on the lookout for leaks and traitors. MI6 is so protective of him, they do not even reveal his identity to the Americans. Good thing, too, because the head of counterintelligence in the CIA at the time—Aldrich Ames—is himself a double agent. Ames ultimately betrays more than two dozen Western spies inside Soviet intelligence, effectively signing their death warrants. His motive? Money.

Every so often, Gordievsky and his family are required to return to the Soviet Union for a term of months or years. This is the normal rotation to prevent personnel from becoming too attached to their place of posting. In case he comes under suspicion while inside the Iron Curtain, MI6 prepares an elaborate escape plan. No one is truly confident this plan can work, least of all Gordievsky. A breakdown at any point will be disastrous. But once Ames fingers him, they must give it a try, and that whole episode is a real nail-biter.

Macintyre’s book won the 2019 Gold Dagger for nonfiction, an award sponsored by the UK Crime Writers’ Association. John Le Carré calls The Spy and the Traitor, “The best true spy story I have ever read.”

Photo: tiburi for Pixabay.

A Dose of Reality

gun, firearm, weapon

Although the average American may not encounter diabolical teen serial killers, sociopathic torturers, or gun-toting assassins with preternatural aim and massive martial arts skills of the types found so frequently in novels, there are plenty of real-life tragedies to baffle our humanity and cry out for explication. Readers and writers of crime fiction don’t have to look further than national crime statistics to understand the interest crime stories hold.

A friend passed on the following information from the October 2019 “violence and health” issue of Health Affairs, the nation’s top health policy journal. Here are some data points, drawn from the 20 or so peer-reviewed articles—the real-life backdrop against which crime stories are written and read.

In 2017, the United States experienced about 19,500 homicides and 47,000 suicides from all causes.

US violent death rates, which had fallen dramatically since the 1970s and held steady for fifteen years are rising again, driven by increasing rates of homicide and suicide by firearms. Rates of firearm deaths increased between 1999 and 2017 in most states; in 29 states, the rate increased more than 20%.

The firearm homicide rate in the United States is 25 times higher than that of other industrialized countries, while the firearm suicide rate is eight times higher.

Many mass shootings involve domestic or family violence, as when the shooter opens fire on a group that includes a target individual.

More than one in five US children are physically abused, and about one in six are sexually abused.

About three in ten emergency physicians are assaulted every year.

About three percent of homicides are police killings.

Research on violence is underfunded. The federal government spends about $25 million per death on HIV research, about $200,000 per death on cancer research, and $600 per death on violence research.

In four surveys conducted between 2013 and 2019, in which gun owners were over-represented, the National Survey of Gun Policy found greater than 75% of respondents supported such policy measures as universal background checks, temporary gun removals based on family concerns, mandatory licensing for concealed carry including a safety test, and a mandatory safety course for first-time gun owners.

Journal editor Alan Weil says, “Even as media attention tends to focus on incidents of mass violence, it is the daily burden of violence in its many forms that takes the greatest toll.”

You can order a copy of this themed issue here.

Photo: r. nial bradshaw, creative commons license