INTERVIEW: Chema Alonso, A Computer Scientist on the Dark Side

28/09/2014
|

Viruses, worms, Trojans, zombie computers, spyware, hackers, crackers, cyber pirates… The list of IT security concepts is long enough to fill a reference dictionary.

But today we are fortunate enough to have Chema Alonso grant us an interview.

These concepts are part of our virtual lives, yet we have been taught very little about them. So today, we are joined by Chema Alonso to address all those doubts and fears that assail us every time we click “start” on our computer, open a new profile on a social network, or perform a bank transfer through our bank’s online portal.

We begin our interview in the style of Pedro Piqueras. Can you describe a terrifying, apocalyptic scenario where IT security is the protagonist? The worst thing that can happen to us as internet users.

–> You receive an email on your smartphone connected to your WiFi, and it launches a CSRF attack on your pacemaker using a default password to order an electrical discharge higher than you can withstand, and it kills you. Why not?

Now that you have our full attention and we are concerned about our online habits, we ask you for 5 (or however many you consider) basic tips to keep our information safe.

–> Five are very few, but I would say: use a Second Factor of Authentication on your accounts, be careful with what you publish on the internet, update your systems, do not connect to unknown WiFi networks, and encrypt all your data.

Define exactly what a hacker is and what their tasks are.

To me, a hacker is a person with a special passion for what they do, who always tries to answer internal questions like: “How? Why? Are you sure?” Ultimately, a hacker tries to prove to themselves that something can be improved, and that is why they search and investigate everything that might be wrong.

How did you manage to turn hacking into your profession?

Nowadays, companies have realized they need hackers, and that is why they always look to hire the best. The main reason is that criminals are constantly innovating, and it is necessary for companies to have people with a hacker profile who are capable of keeping pace with or staying ahead of the bad guys. The increase in this demand has led many hackers to turn their hobby and passion into their professional activity, and it is no longer rare to see them conducting research within companies.

Tell us a bit about ethical hacking, which is being talked about so much lately, and its importance for companies.

Personally, I believe that hackers always have ethics. If there are no ethics, there is no hacker. These ethics do not always have to be consistent with applicable legislation. I want to emphasize this point about applicable legislation because, although the internet is global, legislation is local; what a hacker does for research might be illegal in one country and not in another. The limit of what they should or should not do will be imposed by their own ethics.

On the other hand, companies hire professional ethical hacking services, where teams of hackers evaluate the security of their systems by trying to push security measures to the limit. In addition to that, many hackers voluntarily report security flaws they have found in systems in good faith.

Some companies that do not fix their security flaws often accuse the hackers who published the bug of putting their customers at risk, causing harm, and being unethical. But… is it ethical to offer an insecure service to customers who may suffer damages because the company does not want to solve the flaw? Who cares more about the user in those cases? It is a debate in which every hacker has their own opinion.

Returning to the user level: what is the main mistake we make regarding security?

I believe the main mistake is not trying to care about security. We must keep in mind that we haven’t made it easy for them, and security measures have not been easy to implement or use for people without technical knowledge. I am one of those who blames those of us who create security measures without thinking about the users.

In my talks, I mention that Latch, our proposal for protecting digital identities using digital latches, took one month to create from the time we conceptualized the idea until we had a fully functional PoC.

Then it took us eight months to make the application as simple and usable as possible. Making things simple is sometimes the most complicated part of a process. Do you know the difference between setting up a VPN with SSL, PPTP, or L2TP? Those are things asked during VPN configuration that many users neither know, nor want to know, nor should have to know.

On the other hand, thinking “Who would want to attack me?”, “I don’t have anything that interests anyone,” or “These are movie things that don’t happen” is a constant error.

I would show them the emails I receive from ordinary people wanting to spy on their partners’ WhatsApp, steal acquaintances’ Facebook passwords, or plant a spy Trojan on a phone to record their victims’ telephone conversations.

What steps should we follow if we suspect we are victims of a cybercrime?

I always recommend reporting it and contacting a computer forensics expert who can acquire the necessary evidence without disturbing the proof. It is fundamental to collect all evidence correctly, or nothing can be done. One should not try to take justice into their own hands. I get asked for a lot of illegal things that I don’t do and am not going to do. It seems people believe they can just go and hire a hacker to do whatever they want to anyone on the internet. That is a crime, and the people who do them are cybercriminals.

– My account has been hacked. What happens to all that information? What is done with it, and who ends up being the main beneficiary of that data?

Anything can be done. From selling your identity to using it to attack others or stealing your money. There are curious things, such as private photos being sold so people can create false online identities, or individuals being extorted after being recorded naked or engaging in cybersex on the internet. The latter has become far too common lately, and I already have many emails from people affected by this scam.

– And of all the information we store online, which is the most enticing for cyber pirates?

Identities, personal data, compromising photos. Identity theft is so lucrative that it can be used to take out loans, sign up for basic services, or register prepaid phones in other people’s names. There are many different cases in which you could be affected.

– Often, reading news related to cybercrime, one wonders if, perhaps, the best thing would be to return to a hermit’s life and completely disconnect from social networks, clouds, online procedures… Is this a paranoid conclusion, or is it all due to a lack of information and education?

–> There are risks in a hermit’s life too. The internet is great, a gift to our society that has caused humanity to change eras. We must enjoy it, understand it, and know how to take the good without letting the bad things affect us.

Let’s look at different situations so you can help us from your position as an expert who knows the “dark side.” How can parents protect their children online?

–> By accompanying them in their foray into the network. By being aware of what they are going to find and trying to educate rather than impose. Young internet users will soon surpass their parents; they will use their own tools, their new rules, their new forms of communication, and parents had better stay informed for as long as possible.

I would also ask them to be careful about protecting their children from themselves. Nowadays, digital baptism—that is, the public exposure of their children’s privacy on the internet—is done far too quickly. I would ask them to look after their children by using common sense.

– At work, using devices that belong to the company and that we usually also use for personal use, what practices should we avoid or what protocol should be followed to save ourselves from trouble?

–> Completely separate one thing from the other. Doing it together is a serious mistake. I recently explained to people that connecting your personal phone to work equipment is a total error and that they can extract all your information from the phone just because you connected it. The same applies to email and online accounts.

– Continuing in the professional field but from an employer’s point of view, how can I protect company data when it is handled by so many people?

Let’s move into the field of passwords. One for all and all for one? That is, is it necessary to have different passwords for every account or online service we interact with?

I believe that identities protected only by passwords are the error itself. It doesn’t matter if they are complex or simple. You have to set up a second factor of authentication and that’s it. Google Authenticator, 2-Step Verification via SMS, or our beloved Latch. A password is copied and it’s all over. You have to add extra protection.

How often do you recommend renewing passwords and what type of passwords are the most secure?

Once a month with a recurring appointment on the calendar is a good option. Passwords that haven’t moved since the year they were created are not a good idea.

Digital Identity

Methods for analyzing and
assessing online
reputation damage