Modern Australian
The Times

Leak of US military plans on Signal is a classic case of ‘shadow IT’. It shows why security systems need to be easy to use

  • Written by Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne
Hand holding a mobile phone displaying the blue and white logo for the Signal app.

Yesterday, The Atlantic magazine revealed an extraordinary national security blunder in the United States. Top US government officials had discussed plans for a bombing campaign in Yemen against Houthi rebels in a Signal group chat which inadvertently included The Atlantic’s editor in chief, Jeffrey Goldberg.

This is hardly the first time senior US government officials have used non-approved systems to handle classified information. In 2009, the then US Secretary of State Hilary Clinton fatefully decided to accept the risk of storing her emails on a server in her basement because she preferred the convenience of accessing them using her personal BlackBerry.

Much has been written about the unprecedented nature of this latest incident. Reporting has suggested the US officials involved may have also violated federal laws that require any communication, including text messages, about official acts to be properly preserved.

But what can we learn from it to help us better understand how to design secure systems?

A classic case of ‘shadow IT’

Signal is regarded by many cybersecurity experts as one of the world’s most secure messaging apps. It has become an established part of many workplaces, including government.

Even so, it should never be used to store and send classified information. Governments, including in the US, define strict rules for how national security classified information needs to be handled and secured. These rules prohibit the use of non-approved systems, including commercial messaging apps such as Signal plus cloud services such as Dropbox or OneDrive, for sending and storing classified data.

The sharing of military plans on Signal is a classic case of what IT professionals call “shadow IT”.

It refers to the all-too-common practice of employees setting up parallel IT infrastructure for business purposes without the approval of central IT administrators.

This incident highlights the potential for shadow IT to create security risks.

Government agencies and large organisations employ teams of cybersecurity professionals whose job it is to manage and secure the organisation’s IT infrastructure from cyber threats. At a minimum, these teams need to track what systems are being used to store sensitive information. Defending against sophisticated threats requires constant monitoring of IT systems.

In this sense, shadow IT creates security blind spots: systems that adversaries can breach while going undetected, not least because the IT security team doesn’t even know these systems exist.

It’s possible that part of the motivation for the US officials in question using shadow IT systems in this instance might have been avoiding the scrutiny and record-keeping requirements of the official channels. For example, some of the messages in the Signal group chat were set to disappear after one week, and some after four.

However, we have known for at least a decade that employees also build shadow IT systems not because they are trying to weaken their organisation’s cybersecurity. Instead, a common motivation is that by using shadow IT systems many employees can get their work done faster than when using official, approved systems.

Usability is key

The latest incident highlights an important but often overlooked lesson in cybersecurity: whether a security system is easy to use has an outsized impact on the degree to which it helps improve security.

To borrow from US Founding Father Benjamin Franklin, we might say that a system designer who prioritises security at the expense of usability will produce a system that is neither usable nor secure.

The belief that to make a system more secure requires making it harder to use is as widespread as it is wrong. The best systems are the ones that are both highly secure and highly usable.

The reason is simple: a system that is secure yet difficult to use securely will invariably be used insecurely, if at all. Anyone whose inbox auto-complete has caused them to send an email to the wrong person will understand this risk. It likely also explains how The Atlantic’s editor-in-chief might have been mistakenly added by US officials to the Signal group chat.

While we cannot know for certain, reporting suggests Signal displayed the name of Jeffrey Goldberg to the chat group only as “JG”. Signal doesn’t make it easy to confirm the identity of someone in a group chat, except by their phone number or contact name.

In this sense, Signal gives relatively few clues about the identities of people in chats. This makes it relatively easy to inadvertently add the wrong “JG” from one’s contact list to a group chat.

Hand holding a mobile phone displaying the blue and white logo for the Signal app.
Signal is one of the most secure messaging apps, but should never be used to store and send classified information. Ink Drop/Shutterstock

A highly secure – and highly usable – system

Fortunately, we can have our cake and eat it too. My own research shows how.

In collaboration with Australia’s Defence Science and Technology Group, I helped develop what’s known as the Cross Domain Desktop Compositor. This device allows secure access to classified information while being easier to use than traditional solutions.

It is easier to use because it allows users to connect to the internet. At the same time, it keeps sensitive data physically separate – and therefore secure – but allows it to be displayed alongside internet applications such as web browsers.

One key to making this work was employing mathematical reasoning to prove the device’s software provided rock-solid security guarantees. This allowed us to marry the flexibility of software with the strong hardware-enforced security, without introducing additional vulnerability.

Where to from here?

Avoiding security incidents such as this one requires people following the rules to keep everyone secure. This is especially true when handling classified information, even if doing so requires more work than setting up shadow IT workarounds.

In the meantime, we can avoid the need for people to work around the rules by focusing more research on how to make systems both secure and usable.

Authors: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne

Read more https://theconversation.com/leak-of-us-military-plans-on-signal-is-a-classic-case-of-shadow-it-it-shows-why-security-systems-need-to-be-easy-to-use-253036

Diesel Shortage to Impact Trades and Contractors

Strait of Hormuz blockage affecting all major parts of trades and construction Trades and construction across residential, commercial and industria...

Why Holiday Home Owners Turn to Rental Management Agents

The Allure — and the Reality — of Renting Out Your Property Owning a holiday home is a dream for many Australians. Whether it's a beachside sha...

Why Finding Reliable Doctors In Bundoora Is Important For Long-Term Health

Access to quality healthcare plays an important role in maintaining overall wellbeing and managing health concerns early. Trusted Doctors in Bundoor...

Understanding the Different Types of Car Services: Minor vs Major

When it comes to car maintenance, one of the most important things every vehicle owner should understand is the difference between a minor and a maj...

How Superannuation and TPD Insurance Work Together

Superannuation is an essential part of financial planning in Australia. It is designed to provide individuals with income during retirement, helping...

Tiny Towns funding granted for Mt Hotham and Mt Buller upgrades

Alpine Resorts Victoria (ARV) has welcomed funding support from the Victorian Government’s  Tiny Towns Fund, with both Mt Hotham and Mt Buller se...

Locksmith Services: Why Professional Security Solutions Matter More Than Ever

Security is a critical concern for homeowners, businesses, and vehicle owners alike. Whether it involves protecting a property, replacing damaged lo...

Why Tooth Fillings Are Important For Protecting Damaged Teeth

Cavities and minor tooth damage are common dental problems that can worsen if left untreated. Professional tooth fillings help restore damaged teeth, ...

The Connection Between Visibility and Driver Confidence

Operating a vehicle safely requires an immediate, uncompromised stream of visual information from the surrounding road environment. A driver's decis...

Important Things To Know Before Starting An SMSF Setup

Planning for retirement requires careful financial decisions, and many Australians are now looking for more direct control over how their superannua...

Why Retail Cleaning Plays a Key Role in Customer Experience and Business Success

Professional retail cleaning services are an essential part of maintaining a welcoming, safe, and professional environment for customers and staff...

Simple Ways to Make a Commercial Property More Appealing to Buyers

Selling or leasing a commercial property isn’t just about listing the square metres, taking a few photos and waiting for the right person to appea...

What Café Owners Should Know Before Upgrading Their Display Setup

A café display fridge does a lot more than keep cakes cold and sandwiches fresh. It quietly shapes the way customers browse, the way staff move beh...

Creating a Backyard That Feels Comfortable All Year Round

A great backyard doesn’t need to be huge, expensive or perfectly styled. Most of the time, the spaces people actually use are the ones that feel e...

How Homeowners Can Make Smarter Energy Decisions Before Upgrading

Energy upgrades used to feel like something you only looked into after a power bill gave you a nasty surprise. These days, though, more homeowners a...

Why Retail CX Breaks During Peak Sales Events and How to Prevent It

Retail customer experience has become one of the most important drivers of revenue growth, especially during high-intensity sales periods. However, ev...

15 South Indian Dishes Everyone Should Try

If your only experience of "Indian food" is butter chicken and garlic naan, South Indian cuisine is going to feel like discovering an entirely new c...

What Every Homeowner Should Know About Roof and Drainage Maintenance

A home's roof and drainage system work together every day to protect the property from water damage. While many homeowners focus on visible areas such...