Read The Times Australia

Daily Bulletin

What if the Ashley Madison hack was an inside job?

  • Written by: The Conversation
imageMany people might be in trouble care of the Ashley Madison hack.lucyburrluck/Flickr, CC BY

A massive cache of highly personal information collected by dating site Ashley Madison has been publicly posted on the internet by a group calling itself “Impact Team”. Ashley Madison is specifically aimed at married people seeking extra-marital affairs, advertising itself with the tagline: “Life is short – have an affair”.

Impact Team had earlier threatened to release the information if the site’s operators, Canadian company Avid Life Media, continued to operate both Ashley Madison and companion site Established Men. Other dating sites operated by the company, such as Cougar Life, were not targeted.

Interestingly, the motivation for the data release appears to be ideological rather than financial. The group’s statement on releasing all of the data states:

Avid Life Media has failed to take down Ashley Madison and Established Men. We have explained the fraud, deceit, and stupidity of ALM and their members. Now everyone gets to see their data.

While earlier purported releases of the data turned out to be fakes, the latest release appears highly likely to be authentic, as pointed out by Gawker journalist, Sam Biddle:

An inside job?

In an interview after the initial release by Impact Team, ALM CEO Noel Biderman stated that:

“We’re on the doorstep of [confirming] who we believe is the culprit, and unfortunately that may have triggered this mass publication […] I’ve got their profile right in front of me, all their work credentials. It was definitely a person here that was not an employee but certainly had touched our technical services.

Later statements by the company have been mute on the identity of the suspected attackers. However, an “inside job” still seems to be among the most plausible sources of the data leak.

While security breaches by “outside” hackers traditionally receive more attention, inside threats are often much harder to stop.

Insiders may already have direct access to the information they seek to misuse. Even if they do not, their insider status may allow them to bypass many layers of security. They will also often know what resources are available, and how remaining security might be bypassed, including through social means.

One defence against inside attacks is to limit the information to which an individual has access, and the nature of that access to that needed to do their job. As a simple example, email systems do this by allowing most people access only to their own emails.

However, the information an insider might legitimately need is difficult to predict and frequently changes. Furthermore, some individuals may legitimately need access to virtually all the information resources a company has – the IT system administrators, for instance. It’s also very difficult to automatically determine the purpose of access to IT resources; is the system administrator copying that database to transfer it to a new company server, or to release it on the internet?

Impact Team’s own statements might well hint at the difficulties of protecting against inside attacks, by way of a backhanded compliment to the person most directly responsible for preventing attacks such as theirs. Brian Krebs' original story on the hack quotes Impact Team’s manifesto:

Our one apology is to Mark Steele (Director of Security) […] You did everything you could, but nothing you could have done could have stopped this.

Non-technical countermeasures

While technical measures are of limited use against skillful, motivated inside attackers, there are other factors that deter such attacks. The most significant and controversial media leak of the new century illustrates this well.

Chelsea (born Bradley) Manning, as a junior intelligence analyst in the US Army, was able to access and make copies of an enormous trove of classified data from several US government networks specifically designed for sharing secret information.

The technical measures set up on these networks – presumably set up with information security top of mind – did not prevent her from providing Wikileaks with information well beyond what she would have accessed in the normal course of her work.

But where technical measures failed, US military law has stepped in. Manning is serving a 35-year prison sentence for her actions. The personal consequences of getting caught are likely to deter all but the most committed American soldiers from repeating her actions.

While military and intelligence secrets are protected by uniquely harsh laws, there are a variety of criminal and civil law deterrents to hacking in civilian life, including in Canada, where ALM is domiciled. Furthermore, if they are publicly identified and they are IT professionals, they are likely to have rendered themselves virtually unemployable.

Unusual, but not unique

Ashley Madison is unusual in the sensitivity of the data it kept and the depth of moral outrage its service provoked in some people. As such, it seems to have motivated attackers who were prepared to inflict financial costs on its owners. This is in spite of potentially huge personal costs on its clients and the risk of jail time for the hackers in order to achieve their goal of shutting the site down.

Companies running websites to aid extra-marital affairs are not, however, the only organisations that use IT systems to store highly sensitive information and provoke intense outrage in some individuals.

For instance, sites that bring together people affected by domestic violence, or related to reproductive health, record sensitive details that may have severe real-world consequences if made public. Furthermore, there are relatively small but highly motivated groups within the community who are opposed to the activities of these sites and might be prepared to try to make that data publicly available.

Some of these sites, such as 1800Respect – a national counselling service for those experiencing sexual, domestic or family violence – already provide extensive advice for individuals on how to increase their personal IT security.

Organisations working in such sensitive areas already take enormous care with the information they keep. As they move into online service provision, they will have to be similarly cautious.

The future: a risky world for some

Any information that we leave online is vulnerable to hackers, but not all of it is equally interesting to them. Some information is attractive to criminals for financial reasons; in this case, it was interesting for ideological reasons.

Furthermore, the leak demonstrates that even a well-resourced site aware of the risks it faced was unable to prevent an attack by skilled and motivated attackers.

Individuals providing very sensitive information to sites that may face such attackers should consider further measures to obscure the connection between themselves and their online activities. A full discussion on how to do so would be beyond the scope of this article.

However, to give a simple example of what not to do: most of the Ashley Madison customers publicly identified so far used government or employer-provided email addresses and computing resources to sign up for the service.

Robert Merkel does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond the academic appointment above.

Authors: The Conversation

Read more http://theconversation.com/what-if-the-ashley-madison-hack-was-an-inside-job-46404

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Bridge...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...