The Writing King Your Ethical Ghostwriter. Your Story, Done Right.
This entry is part 85 of 92 in the series Richard Lowe on Air

CISA, Ransomware, and Why Backups Belong in the Closet | 3Ps in a Podcast

Featuring Richard Lowe as returning cybersecurity guest on 3Ps in a Podcast, with hosts Artis and Mike

TL;DR: What This Conversation Establishes

  • The CISA bill analyzed the week it passed the Senate 74-21: a weak data-collection measure with one alarming emergency amendment, jokingly renamed the AT&T-Verizon Protection Act
  • Ransomware economics from the Cyber Heist research: a single Eastern European group extracting $350 million, and why only offline backups survive
  • Phishing, spear phishing, botnets, and Stuxnet explained for a general audience, including the centrifuges that tore themselves apart
  • The Internet of Things security problem stated early: smart plugs, smart alarms, hackable cars, and bodycam video that lives on hackable servers
  • The closing thesis of both books: don’t be afraid, be prepared, from firewalls to situational awareness

This is the complete episode from Richard Lowe’s returning guest appearance on 3Ps in a Podcast with hosts Artis and Mike, recorded November 2, 2015, days after the Senate passed the CISA cybersecurity bill, lightly edited for readability. Co-host Joe was absent this session; off-air chatter is omitted.

T-Mobile’s momentum and Apple’s record year

Artis: T-Mobile gained 2.1 million customers last quarter while AT&T lost about 800,000, and John Legere sky-wrote a message telling the other carriers to stop overage charges. Thoughts?

Richard Lowe: I use one of T-Mobile’s other brands, MetroPCS, and when T-Mobile acquired them and moved them onto the new network, the difference was amazing. No overage charges, nothing; it’s great. And look at the churn rate in this article: T-Mobile is only losing 1.4 percent, which means people are satisfied and staying, and based on my three years with them, that tracks. As for AT&T’s criticism of Apple’s upgrade program: AT&T is a competitor, so I wouldn’t expect them to say T-Mobile has a great idea. Par for the course. And people are replacing phones quickly now anyway, so one-year upgrade cycles fit how people actually behave.

Artis: Apple’s calling 2015 its most successful year ever: $234 billion, 48 million iPhones in a quarter, more cash than the Czech Republic, Peru, and New Zealand combined. Analysts say first trillion-dollar company.

Richard Lowe: Nothing suggests otherwise, and the China launch-day availability pushes it further. And their new off-site repair program with loaner phones is smart service: it frees the Genius Bar rep to make another sale, though you wonder why they don’t just swap the phone outright and refurbish the return.

The new book, announced on air

Richard Lowe: I just released a new book: Help! My Boss Is Wacko. Tips for dealing with unprofessional behavior from the boss, everything from the harasser to the raving lunatic, drawn from bosses I’ve encountered and bosses friends have had. A short book, something you could read in a couple of lunches, and sometimes the answer it gives is: leave. And Real World Survival Tips is on sale this week at 99 cents on Kindle. Everything’s at coolauthor.com, which goes straight to my Amazon page.

Ransomware and the $350 million mafia

Richard Lowe: I’ve been deep in cybercrime research, updating a book called Cyber Heist that a security company gives away. One statistic: a single Eastern European cyber-mafia group extracted $350 million from one company through spoofing, ransomware, and related techniques. Ransomware hijacks your computer and demands payment, usually around $500, and paying doesn’t always work. The better solution is backups, and here’s the part most people get wrong: the backup must be offline. That always-on second hard drive? The ransomware zaps it. Network copies? Caught too. You need a drive or disc that lives in a closet and comes out only for the backup. I also just had a long conversation with Carbonite: they keep multiple versions of your backed-up data, so they can actually walk you back out of a ransomware infection. On phones there’s even less excuse: Android and iPhone backup is built in; turn it on before you lose every contact and photo.

Artis: Survey says 74 percent of American adults have changed online behavior over these threats, but 81 percent still haven’t invested in identity theft protection.

Richard Lowe: The rules are simple. When an email arrives with a link to “fix your account,” don’t click; type the address into your browser yourself and you’ll usually discover the email was bogus. That’s phishing: a fake bank page grabs your username and password, forwards you to the real site with a “password failed,” and you never know until the account’s drained. Spear phishing is the tailored version: the attacker researches the company, learns the CEO’s name, and sends each employee a message personal enough to seem real; that’s espionage-grade, it’s hit people in my own address book, and to infect a company, all it takes is one person. Watch for the lock icon on secure sites, especially on wireless. And my book goes into all of it.

Stuxnet, botnets, and the fragile grid

Richard Lowe: If you really want some fun, read up on Stuxnet: a cyber weapon believed to have been created by the United States and Israel, aimed at Iran’s nuclear program, so specific that it targeted the centrifuge motors, fired them wrong, and caused the centrifuges to rip themselves out of the ground. Very successful, and nasty. Internet attacks are almost frightening in how trivial they are: a distributed denial of service just points thousands of computers at one target. The armies doing it are botnets, sometimes millions of virus-infected personal computers, used for DDoS attacks and as spam relays that make the traffic nearly untraceable. That’s the thing about letting your system get infected: it’s not just your problem anymore, your machine becomes the criminal’s tool. Which, incidentally, is Tim Cook’s point about encryption: you can’t build a door that keeps out only the bad guys. Me, I run a firewall and three antivirus programs, with multiple backups, because this machine is my living. Sixteen cores, custom-built, and yes, it’s a Windows box.

CISA, the week it passed

Artis: The Senate passed CISA 74 to 21. Snowden called it a vote against the internet; the banking and telecom associations applauded. What happens next?

Richard Lowe: The bill itself lets Homeland Security collect certain kinds of security data, and overall it’s pretty weak. The alarming part is an amendment: under emergency conditions, and they define what an emergency is, the federal government can obtain sensitive data that is not anonymized, meaning your phone numbers, meaning you’re identifiable. The idea of building a threat database is sound, but the bill doesn’t look like it was written by computer people; it reads like government bureaucrats, maybe espionage people. It doesn’t do very much, and my security friends call it a smokescreen; one of them, humorously, calls it the AT&T-Verizon Protection Act. So it’s not a bill I’d be super alarmed about. I’d be more alarmed that it’s pretty lame: with attacks like the North Korea-Sony hack coming in, we should be doing something genuinely strong to protect the electrical grid and the internet itself, and this isn’t it. And no, it has nothing to do with the Freedom of Information Act; those are unrelated instruments.

The longer-term fix is structural. TCP/IP, which the internet runs on, was created in the 1970s and isn’t good enough anymore; IPv6 is more secure and is rolling out slowly, and with billions of devices, “slowly” means years. Meanwhile the Internet of Things multiplies the problem: your smart plugs, Mike, are IoT devices, and a hacker can take control of a smart plug, a smart bulb, or a smart alarm. I’m not sure I care if a hacker controls my light bulb; I definitely care about my alarm system. And the car is the big one: if a cop can remotely stop a car, so can a hacker, and maybe the criminals stop the cop’s car that’s chasing them. Bodycams and dash cams are great, real data instead of he-said-she-said, but that video sits on servers, and if it’s online, it can be hacked, altered, or deleted. How do you patch ten billion devices? It’s amazing the whole thing works at all.

Don’t be afraid; be prepared

Richard Lowe: The important thing is not to live in fear, and that’s why I wrote Safe Computing Is Like Safe Sex: don’t be afraid, protect yourself. Put in a firewall, run antivirus, don’t click the link, change the habits; there are hundreds of tips in there. If you’ve got a good backup, you don’t need to be afraid of anything, because you can recover. No backup? Okay, maybe be afraid. And the same principle runs through Real World Survival: situational awareness. Muggers look for people staring off into space; be aware of your surroundings and you’re a far poorer target, because you might remember the face, you might see it coming, you might hit back. Learn about the threat, prepare for it, counter it. Don’t be afraid; be prepared. That’s the subject of both books, and yes, the title is awesome, I admit it.

Artis: A round of applause for Mr. Lowe. For Mike, and the absent Joe, I’m Artis; we’ll holler at you next week.

Richard Lowe: I’m taking a bow.

Find Richard Lowe at thewritingking.com/.

Quotable moments

The always-on backup drive gets zapped right along with your computer. A real backup lives in a closet, offline, and that’s what ransomware can’t touch. — Richard Lowe
Share on X

To infect a company, all it takes is one person clicking one link. — Richard Lowe
Share on X

Don’t be afraid. Be prepared. A firewall, a backup, and awareness beat fear every time. — Richard Lowe
Share on X

Related appearances

Frequently Asked Questions

Why do ransomware attacks defeat ordinary backups?
Because ransomware encrypts everything it can reach, and an always-connected external drive or network share is reachable: it gets zapped along with the computer. Surviving backups are offline ones, a drive or disc stored disconnected and used only during the backup itself, or versioned cloud services that can roll data back to a pre-infection state.
What did the 2015 CISA bill actually do?
It authorized Homeland Security to collect cybersecurity threat data toward a national threat database, a sound idea executed weakly, in this analysis, by drafters who weren’t computer people. The genuinely alarming piece was an amendment permitting collection of non-anonymized personal data under government-defined emergency conditions. Security researchers of the period called the bill a smokescreen that did little to secure the grid or the internet.
What is spear phishing and why is it dangerous?
Targeted phishing: the attacker researches a specific company, learns names and roles, and sends each person a message tailored enough, sometimes appearing to come from the CEO, to pass as genuine. It’s the espionage-grade version of the fake-login email, and it only has to fool one employee to compromise an entire organization, which is exactly what it’s counting on.

Part of Richard Lowe on Air, his complete run of podcast, radio, and video guest appearances.

📁︎ Cybersecurity

🏷︎ Author Business🏷︎ Careers🏷︎ podcast guesting🏷︎ Self-Publishing