Are Quantum Computers the Up-and-Coming Threat to Our Cybersecurity?

On September 20, Google claimed that they have made it to quantum supremacy, which would show that quantum computers can indeed solve more complex mathematical problems than a traditional computer. The paper reporting these findings was uploaded to NASA.gov and then removed

So how does this effect our cybersecurity? Traditional computers could never be capable of solving the complex math problems known as encryption or cryptography that protect our information. This makes hacking them nearly impossible, but a quantum computer could solve these equations in a relatively short period of time. 

Quantum computers differ from traditional computers that run off of a binary system that records data in a series of 1’s and 0’s. These super computers can categorize data as 1’s, 0’s, or as a quantum superstition of these two. 

The system itself wants to be in a single state, not working within multiple at once. For this reason, it will always want to condense to a single state. This is called quantum decoherence.

In order to get the system to maintain working on multiple problems at once, you must employ an understanding on nanotechnology, quantum electronics, superconductors, and other extremely complex subject areas.

Quantum computing could be used to show complex chemical reactions that could aid with advances in chemistry, show high-level financial models, help us predict weather and climate changes more accurately, run AI programs with greater complexity, solve advanced problems in physics, break current cryptographic algorithms, as well as introduce the idea of cryptosystems.

So does this mean that our information is at immediate risk? The answer seems to be no.

For starters, the U.S.’s Institute for Science and Technology has been working on algorithms that can be used for security purposes that are resistant to quantum computers for years and they have five so far that may be feasible.

This finding has also sparked discussion on Twitter, and users are weighing in on this issue.

The general consensus from the cybersecurity community seems to be that although this is a major step in the right direction for this technology, it is still a very small one with a long way to go before we see any real potential for security-related problems or even any benefits from this technology overall.

What Happens When the Government and Tech Companies Collide

On September 13, a House panel that is orchestrating a broad antitrust investigation over technology businesses demanded that companies like Facebook, Apple, Alphabet, and Amazon hand over a long list of records showing their business practices. This was in response to a bipartisan investigation that was launched to look into whether or not these large companies are hindering competition in the technological landscape via their business practices.

This isn’t the first time that government and tech have collided. Where private information and business is concerned, we have seen many meetings-of-the-minds over time, with plenty more to come I’m sure.

On Tuesday, February 16, 2016, Apple received a writ from a U.S. magistrate ordering the company to create a special software that could allow the iPhone of Syed Farook, a suspect in the case of the San Bernardino shooting that saw the deaths of 14 people, to be unlocked by the FBI. This software would allow for an unlimited number of password attempts so that the FBI could gain access to this iPhone without damaging the data it contained. Apple’s chief executive officer, Tim Cook, denied this request stating that once the software was used, it could be hacked, leaked, or stolen, and even just creating it would put millions of Apple users’ data at risk. Apple fought this ruling and won, stating that after iOS 8, not even the company itself could bypass a user’s passcode to gain access to their information.

On August 17, 2018, the U.S. government tried to make Facebook break their encryption on their Messenger app so that the government could listen in on voice calls of a suspect in a gang investigation in Fresno, California. In 2006, an appeals court ruled that phone companies were required to allow police eavesdropping and extended the ruling to some large providers of Voice over Internet Protocol as well, like cable and other broadband carriers. Facebook denied the government’s request, and a judge ruled in their favor, but records with the reasoning are still under seal.

On December 11, 2018, Google’s CEO, Sundar Pichai, testified in front of Congress after the company had come under fire for being interested in making a censored search engine for China, recent security breaches, Google’s bulk data collection practices, and other topics including antitrust and competition. Instead of addressing many of these hard-hitting issues, Congress grilled Pichai on matters pertaining to rumors that Google filters out conservative viewpoints and showcasing criticism of conservative policies, which the company has continuously denied. Twitter users offered other ideas for concerns that Congress should have addressed as well.

On Wednesday, September 4, Facebook, Google, Microsoft, and Twitter met with U.S. officials to discuss steps that all are taking independently and collectively to ensure that the 2020 presidential election is not tampered with after Russia interfered with the 2016 election by spreading disinformation on social media sites, including Facebook and Twitter. Google specifically is  putting money into systems that will detect attempts of phishing and hacking, identify foreign interference on Google platforms, and prevent digital attacks on candidates’ campaigns, but some believe that by including these voices in the conversation, we will end up with another botched election.

While this post could likely go on for hundreds of paragraphs pouring into times when the government and tech leaders worked with or against each other, these are some of the more recent and important instances. With the privacy of users and citizens constantly under scrutiny by both sides, I expect to see many more collisions of law and tech in our future.

What the Cybersecurity Community is Saying About SMS Authentication and Password Recovery

Twitter CEO, Jack Dorsey, had his Twitter account info hacked on August 30. This incident has the cybersecurity community wondering if SMS Authentication and sites forcing you to provide a phone number are doing more harm than good.

His phone number was stolen via SIM swapping, where a hacker can bribe or convince a mobile carrier employee to give the phone number over to the hacker’s mobile device. This could allow the hacker to tweet directly to your account by using an old Twitter feature that lets users text 40404, which published a tweet to your account without needing any of your login information.

Vice President Global Communications at Twitter also spoke out on the issue on Twitter.

Cybersecurity blogger, Graham Cluley, posted shortly after stating that Twitter had made an official statement that they would be turning this feature off for all accounts until they could find a solution to this issue. He believes that Twitter will eventually reinstate this feature because there are parts of the world who don’t use smartphones that need this feature to be able to tweet from their mobile devices, but he hopes that the company is now more aware of the implications of it.

You might be thinking, well I’ll just removed my phone number then, but it’s not that simple. If you use two-factor authentication to login, a phone number is required. Brian Krebs, another cybersecurity blogger, suggests getting a Google Voice number for your two-factor authentication across all of your important accounts.

Another major service provider, Facebook, also experienced a breech in which phone numbers were stolen. In Cluley’s blog post about this breech, he includes the statement from Facebook on the breech, and they seem pretty unbothered, stating that this hack happened before they took away the feature that allowed users to find friends via phone number. Facebook claims they saw no evidence of accounts being affected. The only problem here, Cluley states, is that people don’t change their phone numbers very often, so this information could still be used to harm them.

Twitter users have sounded off about the breech as well.

Overall, the cybersecurity community seems to lean towards not recommending using a phone number to “secure” any of your accounts. If you’re anything like me, if someone had access to my phone it would be an absolute disaster. Take it from the experts, and look into some of the recommendations from this post to better protect your info.

Want more blogs like this one?

Blogging is often seen as a solo activity, and while that can be true, blogging can also allow you to find communities of like-minded people that enjoy the same things you do.

Although the blogging-space for cybersecurity and user privacy is vast, I have selected 10 bloggers who write content that is in line with what I write for this blog for your reading pleasure. I hope you enjoy broadening your knowledge on these topics through these wonderful voices of this community.

Adam Shostack

Adam writes about cybersecurity, but he also talks about other blogs within this field that he personally enjoys. This makes him a great jumping off point for any new reader who is looking for other solid content to read on this topic.

Andrew Hay

Andrew blogs about topics in cybersecurity that interest him, as well as current, newsy topics within the field. This makes him a good read because you’ll get the current news but also some other interesting and relevant content.

Brian Krebs

Brian blogs about the latest high profile security and cyber crime news with deep analyses and insight into each incidence. His tweets as of late have talked about how to keep your info safer on Twitter after the CEO of Twitter was hacked.

Bruce Schneier

Bruce blogs about cryptography, algorithms, and protocol analysis, and he contributes to many U.S. and international publications. He goes more in depth about the ways that algorithms affect cybersecurity and user privacy, which can help you add to your depth of knowledge on these topics.

Byron Acohido

Byron also blogs about cybersecurity, but his speciality is the well-research and accurate info within them. This makes him a great blogger to go to when conflicting info is being given on a story on other outlets. Byron will make sure you see the whole picture.

Dan Lohrmann

Dan blogs about government related cybersecurity issues and what’s catching government attention within the cybersecurity field. He provides a link between current security news and the effects it can have on our laws and how these incidences guide policy on cybersecurity and user privacy.

Graham Cluley

Graham is a personal security blogger who is to the point and easy to understand. If you want to dip your toes in the cybersecurity world without all of the technical jargon, he’s your man.

Pierluigi Paganini

Pierluigi runs the best European personal security blog out there. He writes about cyber crime, hacking, malware, and much more. His content is always quality, check him out.

Sergiu Gatlan

Sergiu blogs about cybersecurity, technology, Apple, and Google. With Apple and Google being in the news so frequently regarding these topics, his posts are timely and well-written. Plus, his blog has a pretty clever name. Who doesn’t love that?

Troy Hunt

Troy is a technical consultant for Microsoft who blogs about his experiences traveling and teaching IT and cybersecurity courses. He created the website haveibeenpwned.com, which allows users to enter their email and see what apps and services they may have had information stolen from in various data breeches across a large number of platforms. His posts are more of a recount of his daily life, but for someone so involved in the IT and cybersecurity world, there are still golden nuggets to be found in his work.

Chinese “Deepfake” App Reignites Fear of Losing Our Privacy Online

Last Friday, a new app was added to China’s app store called Zao. This app would allow users to create their own deepfakes. In simple terms, it allowed people to put their own face on celebritys’ faces from feature films.

By Sunday, it became the most downloaded free app on the app store, but then information surfaced that something unsettling lurked in the terms and conditions.

There were claims that the original verbiage in the terms and conditions on the app stated that users who supplied their photo in the app would give up intellectual property rights to their own faces, and Zao could use their images for marketing purposes.

This has raised concerns about privacy online and what we’re agreeing to in those pages upon pages of terms and conditions for our favorite apps.

Zao has since updated its terms and conditions to further protect user privacy saying that they won’t use pictures or videos uploaded by users for anything other than to help improve the app. It also promised to delete any content from its servers that was uploaded but then removed by its users. However, some Twitter users don’t believe that they are keeping their promises.

After the scare in the U.S. with a similar app called FaceApp, privacy concerns were also voiced, but no evidences of ill-intentions were found.

Privacy is a topic that we see popping up in the media more and more as time goes on, and rightfully so. With new algorithms being developed to use any information we give it in ways that we don’t always understand, it induces a lot of fear because, the truth is, most of us don’t know what information we’re really giving up and what it’s being used for.

This has led to public distrust of the internet, with a global survey showing that 25% of survey takers didn’t trust the internet. This poses challenges not only for these companies, but also for society as a whole as trust in the internet is crucial to trust in the government, our healthcare providers, and our media as more information is moved to online platforms.