Securing Government Mobile Devices with BlackBerry’s David Wiseman
David Wiseman, vice president of secure communications for BlackBerry, explains why, in the wake of cybersecurity attacks launched against telecommunications networks by Salt Typhoon, the new U.S. administration needs to make sure mobile applications and devices being used by government officials are truly secure.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with David Weissman, who's vice president of Secure Communications for Blackberry.
And well, we're talking about the need to secure not just our communications, but in particular the new administration communications. 'cause well, a lot of folks around the world are trying to listen in to conversations they probably shouldn't. And that's probably lessons for all of us to learn now that we think about it.
But David, welcome the show. Thanks, uh, glad to be here, Mike, glad to talk with you and your audience. The administration of the United States is always a target for eavesdropping and all kinds of malware and stuff that goes on, but what do we need to be concerned about?
And is it any more this time around than it was in any other administration? Yeah, I actually think, um, it's something we need to be more concerned about right now. And it actually started about six months ago, uh, this higher level of concern because, uh, some of the, uh, bad actors got a jumpstart on new administration and they actually, it's been in multiple Wall Street Journal, Washington Post, all across the press, salt, typhoon attacks.
So, um, people have actually infiltrated into all of the US telecom networks and they specifically were targeting the presidential candidates from both parties and their staff listening into the phone calls, reading their text messages. So, you know, the fact that we're going to admit new administration, uh, is an important aspect in terms of always sitting down and reviewing, you know, what your policies are around communications. But in this case, we know, you know, there's already an aggressive effort in place.
Do you think that, I mean, a lot of this salt stuff is pointed towards China and, and allegedly anyway, but I feel like this goes on everywhere and every country's trying to do it to every other country, and maybe the US is no exception. So, and maybe this is just something that's getting a little outta hand, or is this just the way the world is? I I think it's the way the world is and it's obviously been going on for a long time.
Uh, you know, the US everyone's always trying to collect valuable information. Um, I, I think what's different now is that, you know, everything's done on mobile. You know, go back 15, 20 years ago, you know, that wasn't necessarily the case.
And so that's expanded the attack vectors. So it's easier for people. You don't have to be as sophisticated to do these type of attacks before, you know, it was a very expensive endeavor, very complicated endeavor.
And you typically were targeting very specific people. You know, they call it tapping the lines, right? Uh, now what we've seen with the salt typhoon type of attack is you can target everyone en mass.
And then the other thing that's different now is a lot of times people would take data and retroactively analyze it. You, you know, Hey, we'll go grab all the call records from this country for the past year and go see who's communicating with whom. Now that it's embedded in the network.
It's more real time. So you, you can know, hey, this party is calling this party right this minute. And you can know that pattern.
And then since you can collect voice data, you can collect message data, you can really target deep fakes and the identity spoofing at the right point in time. And with the other thing that's changed is kind of the emergence of all the AI tools, the level of expertise needed for a particular person, a particular entity to launch very sophisticated attacks has come down. So in other words, the cost of doing this is a lot lower, and so therefore, you know, the volume of these type of attacks, you know, becomes higher and the breadth of them becomes a lot wider.
So what do we need to do to prevent these types of attacks? I mean, is it just a matter of increasing the level of encryption we have or is there more to it? There's more to it.
And you know, the first thing I would say is, you know, there's a lot of effort on, hey, how do we better strengthen the telecom networks? You know, how do they get this stuff out of their networks? Uh, my answer is, that's a good activity, but it's never actually gonna be fully successful.
Uh, 'cause fundamentally, telecom networks are designed for connectivity. That's the number one goal. Any phone can reach any other phone.
And in that an ease of connectivity, low burdens on that. And therefore, you know, security while important, it's, it's always gonna be secondary to that design code. So if you look at, uh, cisa, the US Cybersecurity Agency, uh, they put out a report in mid-December with some very specific guidance, what people should think about, you know, in this environment.
The first is a, everyone should use end-to-end encrypted communications. So that's a solid first step. They, you know, they mentioned there's things such as signals such as WhatsApp, you know, popular consumer apps that have end-to-end encrypted communications.
The second thing they mention is that you need to start to lock down some core security features on your devices. And this doesn't mean your devices had to be managed, uh, but there's things you can do to configure your iOS, your Android devices to better protect yourself. And they give specific guidance.
And then the other topic they talk about is, you know, identity attacks. And I actually think this is, you know, the biggest risk now, particularly with the deep fate technology. And, and they give some guidance on things.
I think this is where it becomes more complicated for the individual citizen to respond to that guidance. Uh, it's, it's not as simple as just download this app and use it. Um, but they do give guidance of, Hey, be aware of this type of thing, be suspicious.
But when I talk with cisa, they, you know, I say, Hey, this is great advice for the general public. Hey, if you're a government agency, you're a corporation. You're someone in a sensitive role.
It's really just a starting point. And, and, and they agree with that. And, and, and so, you know, end-to-end encryption, think of it as important, but it's just a starting point.
The other things that become very critical are more around control and the metadata. If you're using a consumer type application, somebody's mining that for business purposes to pay for the system, right? So that's a, you know, consideration.
A business or a government agency has to take into account as well as whenever you have a public registration system, like a WhatsApp, like a signal, it's kinda like the phone network. It's for ease of connectivity, but that introduces additional attack vectors. So, you know, you need to look at not just end, end encryption, but how do I protect the metadata associated with that communication?
And how do I really have high levels of confidence in who I'm communicating with? At any point, Are we reaching a point where maybe I don't trust who it is on the phone or 'cause of these deep fakes, and do I need some other way of verifying, verifying who is on that call for that matter? You know, like, I know it's you because there's two other people in the background here who say so, so yeah.
Yeah. I, I, I think we're already at that point, right? It's, you know, what do you call it?
Trust, but verify, I believe is the phrase. But, you know, that's where, you know, crypto cryptographic identity validation techniques and things like that, you know, come into play. But the other thing is, I think we might be moving away for, you know, very sensitive communications.
We might have to move away from the model of using systems that are broadly designed for anyone to connect to 'em, to more closed down systems. So it's kind of a, it's kind of a step backwards from the relentless d uh, uh, you know, drive of connectivity ev everywhere and to anyone. And to kind of come back to more, some more closed communication systems, I think this president has some specific preferences for devices that he likes to use.
And how does that factor into people's thinking about security? 'cause uh, not all these devices are equally secure. So there are some folks who would say, you know, back in the day you had to have a Blackberry phone because that was a more secure mechanism, but now everybody's got all kinds of different phones.
What role does hardware play in this conversation? So I think hardware and the operating systems, you know, do play an important role because, you know, what we've been talking about with salt typhoon and this type of thing are network based attacks, but you still have attacks on the devices, people trying to put malware on the devices, that type of thing. So, you know, I think couple of things.
One, supply chain becomes very critical. You know, is this truly a trusted supplier? Um, you know, is the way that you got that phone, do you know you the chain of custody?
And so obviously if you're the president, you know, that type of thing is being looked at on a regular basis. But also, you know, device management, you know, whether it's self-management of, you know, set these policies, which, you know, depending on your attention span may or may or may not be effective, or whether it's some, you know, may a mobile device management type of systems that automatically set those. But that, that's important because without those type of protections and policy checks on the device, even a device that you totally trust the vendor and you totally trust the supply chain is, you know, vulnerable to external attacks.
Is AI gonna play a role for the defenders? We're clearly seeing that the attackers are harnessing it, but how should the defenders think about maybe using AI to help Themselves help themselves? Yeah, absolutely.
So I think one is, you know, there are AI tools that can analyze video, that can analyze audio and tell you if you're more susceptible to, you know, a deep fake. Um, and, and so, you know, building some of these type of tools into the networks, into the communication systems is an effective approach. Uh, the other way is just as I mentioned, the bar is lower for launching, uh, you know, broad scale attacks on the communications network.
The bar is also lower for being able to analyze what's going on, is detect patterns that could indicate that attack. So I think the AI tools can allow a lot of automation to, uh, you know, counter the offensive attacks, but it's always gonna be, you know, cat and mouse, right? And it's, you know, the models learn, they change, they evolve, but you, you, you have to use it on both sides of the equation.
As we look at all of this, it seems like to your earlier point, um, if the cost of launching these types of attacks continues to drop, yeah. Are smaller countries and smaller organizations gonna start doing this? I mean, where does it end?
I, I think at the end of the day, we, we will get to the point where almost everybody needs to do this, you know? Um, but from an organizational viewpoint, you know, we're already getting a lot of inquiries from, you know, relatively small companies, you know, dozens people type of companies saying, Hey, I don't have all the tools in a large company or government would have, but you know, how can I, you know, what can you do to help me? And so I think there's awareness of that.
And some of the work that SIS is doing is they're trying to find, provide pragma pragmatic enough guidance that even an individual on the street can do some self of hold protection. So what's your sense of the probability that sometime in the next four years, there's gonna be some rather embarrassing information leak because somebody hacked into somebody's fault? Oh, About 100%.
In Fact, I think that data's already out there. Someone's just waiting for the right time. And the, the Other thing I would mention is we should keep in mind that this data's already being collected in mind.
And, you know, they, and people don't change phone numbers very often. You usually you'd have a phone number for decades, often 'cause it's a hassle to change. So the data's already out there, and if different people come into different roles, now that data can be put to use in a negative manner.
I mean, we hear a lot about quantum computers, but right. Those folks are already harvesting encrypted data that they intend to someday decrypt. And I'm sure it may not be as valuable as it is today, but it could still be rather embarrassing, right?
Uh, absolutely. You know, store and harvest is, you know, a well known technique. I think it's already been going on for a while.
Um, you know, don't know the exact timelines on, you know, when somebody actually would be able to, uh, break that encryption. But that's one of the reasons that, um, particularly for communications encryption, uh, quantum resistant algorithms are being applied now for, uh, key exchanges specifically to, uh, mitigate the store and harvest challenge. And NIST has put out algorithms for that.
Um, NSA and other agencies have, uh, put out guidance to the, um, tech community and to the government about, you know, when you need to start doing this stuff. I'm still trying to figure out a little bit about what's the tail and what's the dog here, and is it gonna be the end customers that drive the carriers to put better technologies to encrypt things and protect them in? Or is it gonna be the carriers who are driving that 'cause they're sick of, um, getting hacked and then having all these difficult conversations with government officials?
I mean, I'm trying to figure out which dog is the lead in the sled. Uh, it's, it's gonna be the consumer because there's, the carriers are never gonna be able to put enough security in place in a way that's unintrusive enough that it doesn't defeat kind of the purpose of their networks. Plus that's a very, to be co very costly.
So it's gonna be the consumer saying, okay, we've got this network. I need to use the network, but I need to assume any data I put over that network is at risk. So I need to protect that myself To that end.
Does that make this whole thing more expensive? Or are we willing to pay that cost? Or is there some way to get at this without necessarily increasing our costs?
There's different ways to look at cost. So, so one is what's the cost of, you know, of losing that information? The other is, well, what's just the cost of, you know, protecting my communications?
So I think as, as a just an everyday citizen, an everyday person, it's very low cost for you to adopt an encrypted messaging app that's gonna move you pretty far along, uh, as an organization. Um, there, there's cost to setting up higher levels of protection, but I think those costs are relatively minor, uh, when you consider the cost and the implications of large data leaks. All right, folks, you heard in here data leaks are coming, they're gonna be embarrassing and it might be something of a train wreck, but hey, at the very least, we'll learn some valuable lessons.
Hey David, thanks for being on the show. Thanks. All right, I'm back to you guys in the studio.