Categories
Tech

Canada needs to address risks of aging IT to fend off threats that come with digital government


This column is an opinion by Alexander Rudolph, a PhD student in the Department of Political Science at Carleton University where he researches cyberdefence and cyberwarfare. Outside of his research, he also works as an independent consultant and policy analyst. For more information about CBC’s Opinion section, please see the FAQ.

Official documents recently obtained by The Canadian Press describe “mission-critical” Government of Canada computer systems and applications as “rusting out and at risk of failure.” Such statements are alarming for a host of reasons, particularly when considering the potential loss of critical systems that support the nation’s social services.

However, while these systems are integral to providing digital services, there does not appear to be an urgent acknowledgement of the security risks these old systems also pose.

While the Government of Canada released a National Cyber Security Strategy in 2016, it expresses little concern for the specific threats posed by legacy systems. The strategy also offers few concrete plans in terms of what the government will do to achieve its stated goals.

In an article about the government’s aging IT infrastructure, Andre Leduc, vice-president of government relations and policy with the Information Technology Association of Canada, says that many officials didn’t seek to upgrade these old systems because they still worked. That approach seems to be based on the adage that “if it isn’t broken, don’t fix it.”

But at least as worrying as a potential failure of these archaic systems is the risk that government and public information could be stolen, or hijacked and held hostage.

A recent 800-page federal government response to an order paper question filed by Conservative MP Dean Allison reveals that federal departments or agencies mishandled personal information belonging to at least 144,000 Canadians over the past two years alone, a figure that includes incidents ranging from misdirected mail to technology-related breaches. And as Canada moves towards “digital government” while relying on decaying infrastructure, the risks are likely to increase.

Governments and private sector companies are often slow to update computer and communications systems due to the complexity and cost of upgrading. (Sean Gallup/Getty)

Using old technology is commonplace in both the government and private sectors due to the costs associated with upgrading. However, in a 21st-century security environment, these systems are ticking bombs. 

Old systems are vulnerable largely due to a loss of technical support by developers, which dramatically increases the chance of a successful attack. 

As new systems and applications are created, developers phase out support for older ones — and we’re not just talking about decades-old mainframes. Microsoft ended support for its Windows 7 operating system on Jan. 15, for example, which means the company won’t provide any new security updates. This creates significant security risks for these systems and the applications running on them, as they become more prone to malware and hacking.

Ransomware-based cyberattacks, which can lock down computers until a ransom is paid, are just one type of exploit being used by criminals and countries alike. In October last year, the Canadian Centre For Cyber Security issued a warning about ransomware called Ryuk that it said was, “affecting multiple entities, including municipal governments and public health and safety organizations in Canada and abroad.”

Cyberattacks can be costly. Court documents recently revealed that a Canadian insurance company’s data was held hostage until criminals who took over its computer systems were paid nearly $1 million US. That may seem like a large sum, but it pales in comparison to the cost of other ransomware attacks.

In 2017, for example, the ransomware WannaCry is estimated to have infected more than 230,000 systems in 150 countries, costing upwards of $4 billion in losses. Among those targeted was the United Kingdom’s National Health Service (NHS), which was using outdated IT systems — the attack cost $159 million in ransom and cleanup costs. (The United States arrested a North Korean national in connection with WannaCry, alleging the North Korean government sponsored the attacks.)

In this 2017 file photo, employees watch electronic boards to monitor possible ransomware cyberattacks at the Korea Internet and Security Agency in Seoul, South Korea, during the WannaCry attack. (Yun Dong-jin/Yonhap via The Associated Press)

If the revelations by the Canadian press about the woeful state of our nation’s aging IT systems are correct, then hackers are likely salivating at the thought of extracting similar payouts from the Canadian government.

Considering this, is the Government of Canada aggressively addressing the security risks that come with continuing to use these old systems?

For an answer, look at the mandate letters of the government’s cabinet ministers, which outline the policy objectives each is tasked with by the Prime Minister.

The Ministers of Public Safety and National Defence are those chiefly in charge of protecting Canada from threats. The mandate letter expects the Minister of Public Safety to, “identify and prepare for threats to public security, including national security, cyber security and increasingly frequent climate-related emergencies,” but addressing cyber security is not among the specific priority tasks given to the minister. The Minister of National Defence mandate letter doesn’t give any cybersecurity instructions.

The mandate letter of the Minister of Digital Government, who is specifically tasked with the nation’s transition to technology-driven services that make government “more agile, open and user-focused,” does mention cybersecurity, but it is lumped in with a long list of other priorities. The minister is told to, “Lead work to analyze and improve the delivery of information technology (IT) within government. This work will include identifying all core and at-risk IT systems and platforms. You will lead the renewal of SSC so that it is properly resourced and aligned to deliver common IT infrastructure that is reliable and secure.” However, there’s no specific timeframe for this work.

A programmer shows a sample of a ransomware cyberattack on a laptop. (Ritchie B. Tongo/EPA)

Even if federal ministers are told to prioritize cybersecurity, is there an appropriate amount of funding being allocated to quickly upgrade Canada’s aging government systems?

Well, things don’t look too good on that front.

Maintaining safe and secure computer systems cannot be solved with a single expenditure in one year. It’s an active process that requires ongoing yearly funding.

Through its 2018 budget, the Government of Canada committed $507.7 million over five years — approximately $101.5 million a year or 0.03 per cent of its annual revenue — “to protect against cyberattacks” and implement the National Cyber Security Strategy. Consider that Statistics Canada reported that in 2017 alone Canadian businesses spent approximately $8 billion on salaries for employees, consultants and contractors who worked on cyber security, along with another $4 billion on cyber security software and related hardware.

With the critical state the Government’s aging IT infrastructure is reportedly in, the amount budgeted federally is a drop in the bucket.

The mandate of Minister of Digital Government Joyce Murray is to oversee the nation’s transition to technology-driven services that make government ‘more agile, open and user-focused.’ (Justin Tang/Canadian Press)

The efforts of one Minister of Digital Government alone cannot fix the chronic inaction that has led to the government’s current IT crisis. To fix a systemic problem requires a systemic approach.

A whole-of-government strategy should be taken to properly address the threats that accompany modern digital government. This is about more than the funding of services, it requires a change in thinking that understands that with any computer system comes inherent risks, and that a digital government cannot afford to take a casual approach to aging technology and IT security.

Just as all federal departments of the Canadian government must conduct a gender-based analysis to understand the role of gender in their activities, so too should a comprehensive cybersecurity analysis be conducted.

The study that described the Government of Canada computer systems as being at risk of failure is an example of what a cybersecurity analysis could look like. It needs to incorporate an understanding that all computer systems, new or old, have the potential to be entry points that can be attacked and exploited.

Requiring all departments to conduct a detailed cybersecurity analysis would force the government to address the reality that while a digital government has big potential benefits, it also paints a bigger target on Canada.




Source link

Categories
Tech

Emissions from power generation take biggest fall since 1990



Global carbon dioxide (CO2) emissions from the power sector fell by 2 per cent last year, the biggest fall since at least 1990, owing to reduced coal usage in Europe and the United States, a study showed on Monday.

Coal-fired power generation fell by 3 per cent globally, also the largest fall since 1990, research by independent climate think tank Ember showed. The drop in Europe was 24 per cent, driven by a switch to renewables, while U.S. coal-fired generation was down 16 per cent because of more competitive gas.

However, China bucked the trend with a rise as it became responsible for half of global coal-fired power generation.

Overall, the decline in coal use last year and shift towards renewables was helped by factors such as cheap gas, nuclear plant restarts in Japan and South Korea and slowing electricity demand, the report said.

A disused coal-fired power station is destroyed via controlled explosion in Castrop Rauxel, Germany, February 17, 2019. Coal-fired power generation fell by 3 per cent globally in 2019, the largest fall since 1990. (Leon Kuegeler/Reuters)

Coal use needs to fall faster

Coal generation needs to fall by 11 per cent a year to keep within a warming limit of 1.5 C.

“The global decline of coal and power sector emissions is good news for the climate, but governments have to dramatically accelerate the electricity transition so that global coal generation collapses throughout the 2020s,” said Dave Jones, lead author of the report and electricity analyst at Ember.

“To switch from coal into gas is just swapping one fossil fuel for another,” he added.

Wind and solar power generation rose by by 270 terrawatt hours, or 15 per cent, last year, but needs to maintain that rate every year to reach Paris climate goals. (Darren Staples/Reuters)

Wind and solar power generation rose by by 270 terrawatt hours, or 15 per cent, last year. That growth rate would need to be maintained every year to achieve climate goals under the Paris Agreement.

The report examined data covering 85 per cent of the world’s electricity generation and used informed estimates for the remaining 15 per cent.

Last month the International Energy Agency said that global CO2 emissions from power production flattened last year as growth of renewable energy and fuel switching from coal to natural gas led to lower emissions from advanced economies.





Source link

Categories
Tech

Early toolkits and toolmakers more diverse than previously thought


The discovery of a variety of different types of stone tools with the skulls of Homo erectus remains from more than a million years ago shows that early toolmakers used a bigger toolkit than had been previously thought. 

The fossils were found at two sites in Ethiopia, a country which has yielded a trove of remains from our early human ancestors dating back several million years including the famous and much earlier Austrolopithicus specimen, “Lucy.” 

This latest discovery included a thick-browed cranium from Homo erectus at one site believed to be from a male that dated to 1.26 million years ago, and a smaller cranium at the second site dating back more than 1.5 million years, believed to be female. This size diversity indicates that there might have been considerably different cultural roles filled by the Homo erectus sexes.

But the diversity of tools was as interesting as the skeletons. Both were accompanied by an assortment of stone tools that were used for different purposes.

Cranium of a 1.5 million year old Homo erectus specimen, thought to be from a female, found in Ethiopia. (Michael J. Rogers, Southern Connecticut State University)

Stone tools are rocks that have been carefully selected, then chipped or flaked along the sides to make sharp edges that can be used for chopping and cutting. Markings on fossil animal bones from that time suggests these tools could have been to remove meat from bone among other things.

There’s a great variety in stone tools in the historical record, often corresponding to their age and sophistication. Some are pear-shaped cobbles that have been sharpened along one edge, while others involved more craftsmanship, with both sides sharpened, producing a triangular shape for more precise cutting.  

Anthropologists have often considered particular styles of tools to be indicative of a species or group’s technological sophistication. The idea is that perhaps more advanced and refined tools suggest greater mental ability or cultural complexity.

However finding a diversity of older and newer style tools associated with hominid remains from a single time period undermines the idea that one species of human ancestor only made one type of tool. 

Newer style or Acheulian stone tools from the Ethiopia dig site (Michael J. Rogers, Southern Connecticut State University)

Homo erectus is a key species in our family tree. They spread into Asia from Africa 1.8 to 1.9 million years ago. The researchers believe that these tool makers in Ethiopia started with less sophisticated tools, and developed more refined tool technology and the knowledge was passed along through future waves of migrations north. But this new discovery suggests that they didn’t abandon their old technology entirely.

Homo erectus was, of course, not the only human ancestor to develop stone tools. In 1959 famous anthropologists Louis Leaky working at the Olduvai Gorge in Tanzania, discovered the remains of an earlier species he later called Homo habilis, or “handy-man,” along with stone tools dating back more than two million years. 

I had the good fortune to visit this site and see some of these tools close up.

A local curator showed me a box containing about a dozen cobbles. At first glance I said, “They look like stones picked out of a river.”

“They probably were picked out of a river,” he replied dryly. 

Then he picked one up and handed it to me, saying, “Here, hold it in your hand.”

I took the stone that was about the size of an apple and placed the rounded side against my palm. It felt comfortable to hold. I could see how the other side of the stone between my fingers had been chipped away to form a sharp edge. The curator then took my arm and moved it up and down demonstrating the chopping action, where the weight of the stone would make it behave like an axe. In fact, the tools are referred to as hand axes. 

As I took up the motion myself, it became obvious why it was fashioned in that shape. The stone fit perfectly in my hand. Then suddenly I felt a direct connection back two million years to whomever it was that held that exact same tool in their hand to make dinner not far from where I was standing. 

I wondered what went on during those meals. Did they share their food? How did they communicate? What did they think about back then?  It was a profound moment.

Our distant ancestors are sometimes referred to as primitive. And while their brains were smaller than ours, they were inventive, laying the foundations and traditions for all toolmaking right up to the present day.

Earth as seen by the Apollo 17 crew with Africa and Antarctica visible (NASA)

The most poetic example of that tradition is the famous “Blue Marble” photo of the whole Earth taken during the last mission to the moon, Apollo 17. 

It was the last photo of the entire planet taken by a person. (Astronauts on the International Space Station are too close to see the entire Earth all at once). How amazing that the last photo of our whole Earth taken with a hand-held camera, shows the continent of Africa in the middle of the frame, including Ethiopia and Tanzania, the site of the origin of human toolmaking.

 



Source link

Categories
Tech

Canada's cyber intelligence agency working on 'Holy Grail' of encryption


Canada’s cyber intelligence agency says it’s working on what it calls the “Holy Grail” of data encryption to protect government information as the number of reports of privacy breaches, malware attempts and ransomware hits continues to grow.

Encryption mainly works in transit — which protects data when it’s being sent — or “at rest”, which guards information when it’s being stored. But in order to be processed and understood, that information needs to be decrypted, potentially putting it at risk.

“We want encryption when it’s being processed so you don’t have to decrypt it to do it, and that’s something called homomorphic encryption,” Scott Jones, head of the Communications Security Establishment’s (CSE) Canadian Centre for Cyber Security, told CBC News.

“That’s the Holy Grail of encryption that really gets us to a point where, ‘OK, now we will be secure even [while information is] being processed’ … That’s a relatively new phenomenon.”

The centre leads the government’s response to cyber security events, defends Ottawa’s cyber assets and provides advice to Canadian industries, businesses and citizens on how to protect themselves online. The CSE’s team can see up to two billion actions per day, including malicious infiltration attempts.

Jones said the CSE has teamed up with industry players and academics to work out how homomorphic encryption could function in a Canadian setting.

Scott Jones, head of the Canadian Centre for Cyber Security and CSE deputy chief of IT security, looks on during an announcement on the National Cyber Security Strategy in Ottawa June 12, 2018. (Justin Tang/Canadian Press)

“Encryption is absolutely a critical defence,” he said, noting the agency is probably five to ten years away from achieving that goal.

“One of the problems of cyber security is we can block two billion things, but one success is what we talk about … We consider any failure something that we have to address.”

Ransomware attacks on the rise

Brett Callow, a B.C.-based threat analyst with the international cyber security firm Emsisoft, said homomorphic encryption could reduce the likelihood of data being acquired stealthily in an easily usable form, but it’s not a perfect defence against all attacks.

“To use an analogy, the company’s data would be in a lockbox to which only it has key, but threat actors could place that lockbox in a second lockbox to which only they have the key,” he said.

“I’m not sure we’ll ever find a silver bullet. Security will likely be a constant and permanently ongoing game of whack-a-mole.”

More and more Canadian municipalities, provinces, government contractors and businesses have found themselves hit by ransomware attacks — which involve malicious software used to cripple a target’s computer system to solicit a cash payment. Just last week, the province of P.E.I. acknowledged that some Islanders’ personal information may have been compromised in a recent hit.

Callow said homomorphic encryption isn’t necessarily a perfect shield against sophisticated hackers.

“Ransomware attacks typically involve the harvesting of user and admin credentials. If the attackers were able to harvest credentials that enable users to access the data, they too would be able to access the data,” he said.

“In these circumstances, the actor wouldn’t necessarily be able to exfiltrate the original data in non-encrypted from, but they could certainly view it and, perhaps, take screen grabs.”

There’s also the problem of human error.

Federal departments and agencies have recorded thousands of privacy breaches over the past two years, according to recent figures tabled in the House of Commons — many due to slip-ups or misconduct.

Even that number likely falls short since many departments reported they didn’t know how many people were affected by individual information breaches, or how many were subsequently contacted and warned.



Source link

Categories
Tech

The label says 100% compostable plastic. But it's likely ending up in a landfill


Over the last year, Marketplace has investigated the overuse of plastic packaging at some of Canada’s top supermarket chains. A year later, we revisited Loblaws, Sobeys, Costco and Walmart and found evidence of a growing industry — bioplastics.

One of the bioplastics we came across in our supermarket search: compostable plastics. The team found bags, cutlery and coffee pods made of compostable plastic on many store shelves.

As the plastic pollution problem deepens, interest has grown for alternatives to conventional plastics like bioplastics packaging, an industry that is expected to grow to $10 billion over the next few years. 

But watch what Marketplace discovered about compostable plastics and what actually happens when you put them in your green bin.

We get to the bottom of those “compostable” claims on plastic packaging. Should you put them in the green bin or will they end up in landfill anyway? 4:38





Source link

Categories
Tech

Scientists make cake with butter from bugs instead of cows



Belgian waffles may be about to become more environmentally friendly.

Scientists at Ghent University in Belgium are experimenting with larva fat to replace butter in waffles, cakes and cookies, saying using grease from insects is more sustainable than dairy produce.

Clad in white aprons, the researchers soak nlack soldier fly larvae in a bowl of water, put it in a blender to create a smooth grayish liquid and then use a kitchen centrifuge to separate out insect butter.

“There are several positive things about using insect ingredients,” said Daylan Tzompa Sosa, who oversees the research.

“They are more sustainable because (insects) use less land (than cattle), they are more efficient at converting feed … and they also use less water to produce butter,” Tzompa Sosa said as she held out a freshly baked insect butter cake.

A man tests a piece of cake made with bug butter, touted as a greener alternative to butter from cows. (Reuters)

According to the researchers, consumers notice no difference when a quarter of the milk butter in a cake is replaced with larva fat. However, they report an unusual taste when it gets to fifty-fifty and say they would not want to buy the cake.

Insect food has high levels of protein, vitamins, fibre and minerals and scientists elsewhere in Europe are looking at it as a more environmentally friendly and cheap alternative to other types of animal products.





Source link