Read The Times Australia

Daily Bulletin

What if the Ashley Madison hack was an inside job?

  • Written by: The Conversation
imageMany people might be in trouble care of the Ashley Madison hack.lucyburrluck/Flickr, CC BY

A massive cache of highly personal information collected by dating site Ashley Madison has been publicly posted on the internet by a group calling itself “Impact Team”. Ashley Madison is specifically aimed at married people seeking extra-marital affairs, advertising itself with the tagline: “Life is short – have an affair”.

Impact Team had earlier threatened to release the information if the site’s operators, Canadian company Avid Life Media, continued to operate both Ashley Madison and companion site Established Men. Other dating sites operated by the company, such as Cougar Life, were not targeted.

Interestingly, the motivation for the data release appears to be ideological rather than financial. The group’s statement on releasing all of the data states:

Avid Life Media has failed to take down Ashley Madison and Established Men. We have explained the fraud, deceit, and stupidity of ALM and their members. Now everyone gets to see their data.

While earlier purported releases of the data turned out to be fakes, the latest release appears highly likely to be authentic, as pointed out by Gawker journalist, Sam Biddle:

An inside job?

In an interview after the initial release by Impact Team, ALM CEO Noel Biderman stated that:

“We’re on the doorstep of [confirming] who we believe is the culprit, and unfortunately that may have triggered this mass publication […] I’ve got their profile right in front of me, all their work credentials. It was definitely a person here that was not an employee but certainly had touched our technical services.

Later statements by the company have been mute on the identity of the suspected attackers. However, an “inside job” still seems to be among the most plausible sources of the data leak.

While security breaches by “outside” hackers traditionally receive more attention, inside threats are often much harder to stop.

Insiders may already have direct access to the information they seek to misuse. Even if they do not, their insider status may allow them to bypass many layers of security. They will also often know what resources are available, and how remaining security might be bypassed, including through social means.

One defence against inside attacks is to limit the information to which an individual has access, and the nature of that access to that needed to do their job. As a simple example, email systems do this by allowing most people access only to their own emails.

However, the information an insider might legitimately need is difficult to predict and frequently changes. Furthermore, some individuals may legitimately need access to virtually all the information resources a company has – the IT system administrators, for instance. It’s also very difficult to automatically determine the purpose of access to IT resources; is the system administrator copying that database to transfer it to a new company server, or to release it on the internet?

Impact Team’s own statements might well hint at the difficulties of protecting against inside attacks, by way of a backhanded compliment to the person most directly responsible for preventing attacks such as theirs. Brian Krebs' original story on the hack quotes Impact Team’s manifesto:

Our one apology is to Mark Steele (Director of Security) […] You did everything you could, but nothing you could have done could have stopped this.

Non-technical countermeasures

While technical measures are of limited use against skillful, motivated inside attackers, there are other factors that deter such attacks. The most significant and controversial media leak of the new century illustrates this well.

Chelsea (born Bradley) Manning, as a junior intelligence analyst in the US Army, was able to access and make copies of an enormous trove of classified data from several US government networks specifically designed for sharing secret information.

The technical measures set up on these networks – presumably set up with information security top of mind – did not prevent her from providing Wikileaks with information well beyond what she would have accessed in the normal course of her work.

But where technical measures failed, US military law has stepped in. Manning is serving a 35-year prison sentence for her actions. The personal consequences of getting caught are likely to deter all but the most committed American soldiers from repeating her actions.

While military and intelligence secrets are protected by uniquely harsh laws, there are a variety of criminal and civil law deterrents to hacking in civilian life, including in Canada, where ALM is domiciled. Furthermore, if they are publicly identified and they are IT professionals, they are likely to have rendered themselves virtually unemployable.

Unusual, but not unique

Ashley Madison is unusual in the sensitivity of the data it kept and the depth of moral outrage its service provoked in some people. As such, it seems to have motivated attackers who were prepared to inflict financial costs on its owners. This is in spite of potentially huge personal costs on its clients and the risk of jail time for the hackers in order to achieve their goal of shutting the site down.

Companies running websites to aid extra-marital affairs are not, however, the only organisations that use IT systems to store highly sensitive information and provoke intense outrage in some individuals.

For instance, sites that bring together people affected by domestic violence, or related to reproductive health, record sensitive details that may have severe real-world consequences if made public. Furthermore, there are relatively small but highly motivated groups within the community who are opposed to the activities of these sites and might be prepared to try to make that data publicly available.

Some of these sites, such as 1800Respect – a national counselling service for those experiencing sexual, domestic or family violence – already provide extensive advice for individuals on how to increase their personal IT security.

Organisations working in such sensitive areas already take enormous care with the information they keep. As they move into online service provision, they will have to be similarly cautious.

The future: a risky world for some

Any information that we leave online is vulnerable to hackers, but not all of it is equally interesting to them. Some information is attractive to criminals for financial reasons; in this case, it was interesting for ideological reasons.

Furthermore, the leak demonstrates that even a well-resourced site aware of the risks it faced was unable to prevent an attack by skilled and motivated attackers.

Individuals providing very sensitive information to sites that may face such attackers should consider further measures to obscure the connection between themselves and their online activities. A full discussion on how to do so would be beyond the scope of this article.

However, to give a simple example of what not to do: most of the Ashley Madison customers publicly identified so far used government or employer-provided email addresses and computing resources to sign up for the service.

Robert Merkel does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond the academic appointment above.

Authors: The Conversation

Read more http://theconversation.com/what-if-the-ashley-madison-hack-was-an-inside-job-46404

Business News

How Immigration Lawyers Can Help

Introduction Visa decisions can shape employment, family life, study plans, travel, and future residence. A small omission can lead to delay, added expense, or refusal. Immigration lawyers assess l...

Daily Bulletin - avatar Daily Bulletin

How Industrial Drying Equipment Supports Efficient Processing

Many industrial processes require moisture to be removed from compressed air, products or process materials before they move to the next stage. Excess moisture can affect equipment performance, produc...

Daily Bulletin - avatar Daily Bulletin

Practical Ways a Whiteboard Can Improve Workplace Communication

Effective communication helps teams stay organised, share ideas and keep track of important information. While digital tools are now common in many workplaces, a whiteboard continues to provide a simp...

Daily Bulletin - avatar Daily Bulletin

Designing Eco-Friendly Custom Water Bottles for Your Next Event

The Evolution of Sustainable Event Merchandise Event planning has undergone a massive transformation over the last decade. Gone are the days when organizers could hand out cheap, single use plastic...

Daily Bulletin - avatar Daily Bulletin

Why Choosing a Professional Florist Melbourne Makes Flower Delivery Impactful

Flowers have a great power to speak when humans cannot express their feelings with right words. Flowers are the best gifts when you are celebrating a birthday or welcoming a newborn child into your fa...

Daily Bulletin - avatar Daily Bulletin

The Business Case for Choosing Australian Fabricators Over Imported Alternatives

For a long time, you might have defaulted to overseas suppliers when sourcing fabricated metal components for a project. The unit price was lower on paper, and the maths seemed straightforward. That...

Daily Bulletin - avatar Daily Bulletin

Australian organisations are relying on business continuity plans built for a far more predictable world

Tariff escalations, supply chain fragility, geopolitical events, and the ongoing threat of cyber disruption have reshaped the risk environment facing Australian organisations. The problem is that ma...

Daily Bulletin - avatar Daily Bulletin

How to Rent a Car for Uber in Melbourne: What Every New Driver Needs to Know

Starting out as an Uber driver in Melbourne is not as complicated as it sounds but getting the vehicle right is where most new drivers get stuck. Uber has strict requirements around vehicle age, condi...

Daily Bulletin - avatar Daily Bulletin

When Should You Speak to a Lawyer About a Legal Issue?

Legal issues can begin with a simple question, then become harder to manage once formal steps are involved. Many people wait until a matter feels urgent before seeking guidance, even though earlier ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

How AEC Firms Can Scale Faster Without Sacrificing Project Quality

Growth presents a fundamental dilemma for architecture, engineering, and construction firms: expan...

What Makes an Aesthetic Clinic Worth Going Back To?

Trying an aesthetic clinic for the first time can feel like a bit of a gamble. You can read review...

Elevate Your Morning Routine with Cafe-Style Coffee at Home with the Right Coffee Machine

There's something magical about that first sip of coffee in the morning. It’s more than just a bev...

Top Garment Steamers for Busy Professionals in Australia

The gap between garment steamers built for a quick touch-up and ones built to keep pace with a wor...

Correct Sleeping Posture to Minimize Back Strain

Most people don’t pay much attention to how they sleep until they start waking up with a stiff bac...

Why Product Longevity Matters for Sustainable Australian Buildings

Sustainability in building design is often associated with recycled materials, renewable resources a...

NDIS Support Coordination Explained: What Does a Support Coordinator Actually Do?

NDIS support coordination explained means understanding how a professional can help participants n...

When Should You Speak with Divorce Lawyers in Sydney?

Divorce involves more than completing an online application. It can affect parenting arrangements, p...

How to Choose a Reliable Hot Water System Installer on the Gold Coast

Choosing a reliable installer is just as important as choosing the right hot water system. A qualifi...