Politic?

This is a blog dedicated to a personal interpretation of political news of the day. I attempt to be as knowledgeable as possible before commenting and committing my thoughts to a day's communication.

Friday, April 21, 2023

Chinese-Produced Security Gear -- Five Eyes Intelligence Group

"The Department of National Defence and the Canadian Armed Forces take physical and corporate security extremely seriously and ensures it has a robust and effective security program in place."
"This is accomplished through the development and maintenance of a comprehensive security policy, tailored to both DND/CAF departmental and operational requirements through which we continually assess the effectiveness of our security practices."
"Acquisitions are done in accordance with DND/CAF [Department of National Defence/Canadian Armed Forces] industrial security program protocols, which provides oversight of the risks associated with supply chain integrity commensurate with the intended final use of goods/services."
National Defence spokesperson Dan Le Bouthillier

"Both the human and technical reach of Chinese companies now give the intelligence services opportunities to gain direct access to many governments within the developing world as well as many Allied and European countries with inroads into other societies."
Canadian Security Intelligence Service

"[If Canadian communication passes through their equipment, the companies could be] compelled to comply with extrajudicial directions from foreign governments in ways that would conflict with Canadian laws or would be detrimental to Canadian interests."
Bill C-26, Cybersecurity Law
https://thelogic.co/wp-content/uploads/2020/02/GettyImages-1145557115.jpg
Getty Images
 
Bill C-26, a proposed cybersecurity law would allow the government to order private telecom networks to extract gear from China-based Huawei and ZTE should their equipment allow Canadian communication to pass through to a foreign government. Canada, as a member of the Five-Eyes intelligence security group, along with the United States, United Kingdom, Australia and New Zealand is now out of step with those other four nations in the laxity of the Liberal government's reaction to obvious breaches in national security posed by Chinese equipment.

This, despite the fact that the Canadian Security Intelligence Service has given due warning to the government that China's National Intelligence Law authorizes Beijing to compel Chinese companies' cooperation with intelligence-gathering. This is a law that not only pertains to companies operating within China, but those with branches and operations globally; all are expected to respond to the National Intelligence Law. This is a law that extends to expatriate Chinese with citizenship in other countries, as well.

DND spokesman Dan Le Bouthillier notes that all closed-circuit video gear comes courtesy of a list of vendors the government's procurement department maintains. Vendors who generally install and maintain equipment they purchase from manufacturers for the purpose of reselling them. The United States initiated a cull of Chinese-produced cameras out of its public security systems in 2019 -- products from Hytera, Hikvision and Dahua specifically targeted, as have other allies in the Five Eyes intelligence-sharing network.

The Department of National Defence in Canada explained it would not follow the U.S. ban of multiple models of security cameras manufactured in China, partly because there are 20,000 DND buildings, none of which properties are managed centrally. Moreover an inventory of where security gear emanates from has never been developed by DND. The United Kingdom and Australia share the U.S. concerns of devices manufactured in China having the potential to endanger national security.

The U.K. in 2022 ordered its government agencies that new Chinese cameras were not to be installed at sensitive sites; further that Chinese-made surveillance equipment from core networks be disconnected, and plans forwarded to remove such equipment altogether. The United States Federal Communications Commission moved to restrict sale of security equipment even to ordinary consumers, of several Chinese brands.

Many police departments in Britain use cameras from Chinese manufacturers, pointed out the British government surveillance watchdog, cautioning that software updates can create new backdoors in equipment following initial installation. Australia's defence minister committed to that country removing Chinese-made cameras from government buildings, while New Zealand this month saw a news probe discovering that Chinese surveillance technology permeates government buildings -- and calls are being made for an audit on the devices.

Surveillance cameras manufactured by Hangzhou Hikvision Digital Technology Co. are mounted on a post at a testing station near the company's headquarters in Hangzhou, China, on Tuesday, May 28, 2019. Hikvision, which is controlled by the Chinese government, is one of the leaders in the market for surveillance technology, with cameras that can produce sharp, full-color images in fog and near-total darkness. Photographer: Qilai Shen/Bloomberg
Surveillance cameras manufactured by Hangzhou Hikvision Digital Technology Co. are mounted on a post at a testing station near the company's headquarters in Hangzhou, China, on Tuesday, May 28, 2019. Hikvision, which is controlled by the Chinese government, is one of the leaders in the market for surveillance technology, with cameras that can produce sharp, full-color images in fog and near-total darkness. Photographer: Qilai Shen/Bloomberg , Bloomberg

Labels: , , ,

Sunday, March 26, 2023

Food Security as a Geopolitical Weapon

 

"They've just become so common. Every week, I would say, we are getting contacted by farmers or food companies. It's one of the soft bellies of our critical infrastructure."
"I think we are all waiting for disaster."
Ali Dahghantanha, Cyber Science Lab, University of Guelph, Ontario
"These are all systems that we explicitly depend on every single day, and they have become extremely vulnerable to manipulation of all sorts."
"They're vulnerable because we haven't thought carefully about the security of how we set these systems up."
"I mean, it's truly terrifying, to be honest."
Even Fraser, director, Arrell Food Institute, University of Guelph

"The interruption of the global food supply is not collateral damage from the war in Ukraine."
"It is a planned hybrid weapon to further massively destabilize the global economy and political order."
Yulia Klymenko, Ukrainian MP, first deputy chair, Transport and Infrastructure Committee, Ukraine

"There is a lot of innovation happening in agriculture in Canada."
"So we are at risk from foreign-backed espionage."
Mohamad Yaghi, Agriculture and Climate policy lead, Royal Bank of Canada
Hackers could be waiting to cause disruption, or simply just monitoring and collecting data on foreign agricultural methods.
Hackers could be waiting to cause disruption, or simply just monitoring and collecting data on foreign agricultural methods. Photo by Chung Sun-Jun/Getty Images
 
Last year Ali Dehghantanha's squad of engineers and computer scientists responded to dozens of reports from southwestern Ontario of hacks within farming and food production operations. Sometimes the incidents represent a bad link in an email with hackers demanding money to unlock a system or to return the farmer's data. In other instances hackers break into a farm system and threaten to kill livestock; chickens, cattle. 

In a third of the cases, investigators found evidence of state-sponsored hackers originating in
Russia, China, North Korea and Iran who have quietly gained access to control systems inside a farming operation. The University of Guelph is located close to Toronto in one of the province's most vital farming hubs. A group of specialists work out of the Cyber Science Lab, visiting banks, defence contractors, hospitals and farms. The lab received fifty calls from the food industry last year.

The realization dawned that the domestic food production system may be one of the most obvious cracks in Canada's national defences. Criminals or state-sponsored hackers breaking into systems to disrupt critical infrastructure like transportation or health care or food production only recently become plausible owing in part to Russia's invasion of Ukraine.
 
 Canada's Communications Security Establishment (CSE) the country's signals intelligence agency, warned that Russian-backed hackers are "exploring options for potential counterattacks" on critical infrastructure in Canada and other NATO allies supporting Ukraine.
 
A computer monitor is seen inside a tractor cab with a farm field in the background.
A computer monitor is seen inside a GPS-equipped John Deere tractor. As farm use of technology and smart devices grows, experts say more needs to be done to protect against cyberattacks that could threaten food security. (Seth Perlman/The Associated Press)
 
Farms have become complex technical operations using networks of remote monitors measuring soil moisture, or robotic milkers capable of detecting an infection in a single teat, or environmental control systems maintaining the precise indoor temperature and air filtration requirements of a poultry barn. All of which in theory could be commandeered and held for ransom by a hacker. The U.S. Department of Homeland Security identified several "hypothetical threat scenarios" in its 2018 report where hackers could compromise agricultural operations. 
 
One scenario had a terrorist lift data on the health of a large livestock herd. "They modify the data to look like the herds have foot and mouth disease, and dump the data on the internet". In such an instance it could take weeks for lab tests to confirm the outbreak was in fact false -- in the interim causing trade issues and shaking public trust in the food supply. Another scenario had hackers manipulate moisture sensors in a farmer's soil, triggering watering systems to flood the fields and destroy crops.
 
In its invasion of Ukraine an effective part of the Russian playbook has been attacking agricultural infrastructure. EU trade counsellor Maud Labat warned that Moscow strategized how to wield food as a "geopolitical weapon". Its attacks on transportation and grain storage infrastructure, its months-long blockade of ports on the Black Sea choked off access to one of the world's most important bread baskets, driving up global grain prices last spring. Food shortage concerns intensified in developing nations depending on the region for imports. 
 
National Cyber Threat Assessment's latest report stated state-sponsored hackers are not likely to disrupt or destroy critical infrastructure unless Canada enters into direct hostilioties, leaving  hackers more likely to break into Canadian systems to collect information or "pre-position" in the event of a future conflict. Released last fall, the CSE report stated adversaries could use cyberattacks as a form of "power projection and intimidation".
 
Farm worker in a red baseball hat working on a laptop as he watches a farm equipment operator working in a farm field
 
"In the absence of a significant escalation in international hostilities, we assess it is unlikely that state-sponsored actors will intentionally seek to disrupt Canadian critical infrastructure and cause major damage or loss of life", advised CSE spokesperson Kyla Borden. "This is organized crime. These folks have HR departments. They have employees of the month awards. This is big business", explained John Hewie, a national security officer at Microsoft Inc., referring to sophisticated networks focusing on "big-game hunting" -- attacks where a hacker takes control of a system or data from a major business and asks for a steep ransom.
 
In fact, the Canadian food industry alone experienced a series of high-profile incidents late last year, a "cybersecurity incident" at Maple Leaf Foods Inc., one of Canada's largest meat packers. Empire Co.Ltd., Canada's second-largest grocery chain experienced a "cybersecurity intrusion" that snarled operations, expected to cost the company $25 million. According to Janos Botschner, lead investigator of the Cyber Security Capacity in Canadian Agriculture, approximately four to 11 percent of Canada's farms have had a cyberattack attempt on their operations. "This is very much an estimate, but it's probably also an under-report", he clarified. 

A farmer in a chicken barn in Ontario.

Labels: , , , , ,

Thursday, March 23, 2023

Extreme Level of Cyber-Security Risk

"Given the extreme risk level associated with this vulnerability and the widespread usage of Outlook in the Government of Canada [GC], I am directing GC Chief Information Officers and Heads of IT to prioritize patching of this vulnerability within two days."
"Critical zero-day vulnerability [discovered Outlook Microsoft's email program could give hackers the opportunity to access and exfiltrate sensitive government data, requiring urgent address]." 
"This vulnerability has been exploited by nation-state actors targeting international government institutions to covertly obtain the password hash of targeted users in the past."
"I encourage you to make this a priority within your organization [Departments]."
Shirley Ivan, Chief Information Security and Technology Officer, Canada
 
"We're now in a year plus one in the Ukrainian conflict, and it has been seen in many Telegram channels that Russian-backed cyber criminal gangs will be enhancing, if not promulgating, such attacks against all types of governments that have been helping out Ukraine war efforts."
"The Cyber Centre has access to all the data. So, they knew in advance, and I don't know why they took their time to publish an advisory so late in the game."
"They should have been at the forefront of bringing on this alert one week ahead of Microsoft."
Steve Waterhouse, cybersecurity expert
The new Outlook vulnerability allows hackers to potentially extract an individual’s email account login information simply by sending a 'specially crafted email with a malicious payload.'

Russian-backed hackers have been taking advantage of Microsoft Outlook's newly identified cybersecurity vulnerability. Microsoft itself only days ago confirmed a "critical" zero-day vulnerability in their Outlook email product, its flagship email program. The issue was detected while it was already live and potentially exploitable, interpreted as "zero days" for the organization to find a solution, since "zero-day" designates the vulnerability as a real and current threat.
 
The new Outlook vulnerability gives hackers the opportunity potentially to extract an individual's email account login information through the simple medium of sending a "specially crafted email with a malicious payload", one that does not depend on it being opened to be effective, notes the Canadian Centre for Cyber Security. "Sophisticated actors", confirmed the Cyber Centre in an advisory, had already exploited the vulnerability with success. 
 
Ms. Ivan stated that the Cyber Centre would be committing to placing further measures to "mitigate the threat" of password data being lifted by hackers via the Outlook vulnerability, along with addressing the "long-standing risk of exfiltration" of government data. First detected by Ukraine's Computer Emergency Response Team (CERT) in conjunction with Microsoft researchers in February, Microsoft confirmed its existence a full month later. 

The vulnerability is notoriously exploited by Russian-backed hackers, used against Ukrainian adversaries forming part of their full-scale invasion. Pro-Russia channels on social media have been promoting the use of that Outlook vulnerability against Ukrainian allies, such as Canada, explained cybersecurity expert Steve Waterhouse. The urgency spelled out in Ms. Ivan's memo to federal government department heads reveals the critical nature of the security issue.

According to Mr. Waterhouse, it seemed "weird" that no one in government moved earlier, particularly the Cyber Centre which should have been aware of the issue when Ukraine first signalled it in late February. He described it as a "cover-your-ass approach", that the Cyber Centre waited until Microsoft published its alert. It was on February 24, a full year after the Russian invasion of Ukraine that the Cyber Centre published its advisory warning all Canadians to be aware and "prepared for potential malicious cyber activity following the one-year mark of Russia's war on Ukraine".

A screenshot of the  Microsoft instructions for updating your Office applications.
  
"The Cyber Centre would like to specifically warn Canadian organizations and critical lnfrastructure operators to be prepared for the possible disruption, defacement, and attempted exploitation of Canadian network assets by cyber threat actors aligned with Russian interests."
Canadian Centre for Cyber Security Advisory

Labels: , , , , ,

Sunday, August 01, 2021

The Canada/China Contortion Conundrum

"We are in a uniquely complicated spot."
"We are being borne along a current with very few options. So the idea that we can craft a way forward easily is wrong."
"They don't see it in Chinese thinking as an oppressive thing, they just see themselves in more benign terms as the leading civilization in the world, and that they ought to have an important say in the affairs of the world and even a dominant position."
"But it's not a Nazi-like military conquest of the world."
Gordon Houlden, director, China Institute, University of Alberta 

"It's been said that China doesn't have allies, it has markets."
"I attribute the Cold War spirit and the Cold War stresses, in largest part to China's actions, as well as the tone of their 'wolf warrior diplomacy', which isn't very diplomatic."
Margaret McCuiag-Johnston senior fellow, University of Ottawa, former member, Canada-China Joint Committee on Science and Technology

"It will require much more thought, it will require much more management of foreign policy."
"That will be difficult for everybody. It'll be particularly difficult for Canada because we haven't put much thought into our foreign policy for a long time, and we're going to pay a price in terms of the learning curve that we have to go up."
"That's the first step [Beijing releasing detained Canadians Michael Kovrig and Michael Spavor] when I talked about China's assault on our sovereignty and our autonomy."
"It's sapping the will, it causes countries to feel that it's just impossible, it's too much work. And that was never Canada's approach in the past, but I worry that we've succumbed to that to a certain extent."
David Mulroney former Canadian ambassador to China 2009-2012
The U.S. Senate passed a bill aimed at competing with China on economic and other fronts. It wants clarity on U.S. strategy for working with allies. (Jason Lee/Reuters illustration)
 
U.S. legislation titled the Innovation and Competition Act, a 1,445-page bill is set to lay the groundwork for broad strategy on the part of America to enfeeble Beijing's plan to raise the country globally as a colossus of commerce, a guide to the world's perplexed over China's increasingly aggressive stance as the ultimate world-leading power. The Act identifies strategic industries where the recommendation is for the U.S. to ramp public support for quantum computing, advanced semiconductors and pharmaceuticals to continue to reflect America's preeminent global role.

It also proposes more substantial protections for America's share of critical minerals, expansion of research spending with an aim to strengthen cyber defence capabilities as primary objectives, among others. That same act places Canada in a role in sections of legislation; plans deeply consequential that will rework and reshape Canadian foreign policy for some time to come. This, as American officials spur forward on a protracted conflict with China for global supremacy; an issue observers refer to as the new Cold War.

That Cold War is in active engagement between the two giants on a number of fronts including cyber warfare, military expansionism, technological research, culture, infrastructure, and intellectual property. All areas incidentally, which in one way or another Beijing has stealthily intruded upon in the process enriching itself with the results of its cyber-scrutiny otherwise known as stealth-theft. There is little question that Canada's traditional neighbourly ties with the United States will inform its inclusion in the U.S.-led agenda dividing China and the U.S. where trade and national security are issues of huge importance./China impedes both at will; one as punishment the other as threat.

The links between Canada and the U.S. are historically strong and steadfast, culturally and politically. with the U.S. Canada's largest trading partner. An agreement between the two neighbours was signed to establish new supply chains for critical minerals and rare earths as defence against China's zeal in gaining rights and overwhelming ownership to both. Canada has been lax in deciding whether, like all other members of the Five Eyes intelligence group, it will shut Huawei out of its 5G upgrade.

On the surface the U.S. legislation is clear enough with its plans to uphold a "shared vision of democracy", maintaining the "rules based international order established after WWII", which China flouts with impunity. The loosening of export regimes between the two neighbours, protecting "critical defence-related technology", establishing open and transparent planning on infrastructure, co-operating on Arctic defence and energy connectivity, combating "industrial espionage" and deepening intelligence sharing "particularly in 5G telecommunications technology", all favour more secure ties.

And all specifically point at China's infamously notorious penchant for surveillance, espionage and hunger to acquire by foul means the intelligence and secrets of other countries. "We are in the midst of a fundamental debate about the future and direction of our world", stated U.S.President Biden in a public statement earlier in the year in response to a more bellicose, authoritarian China guided by President Xi Jinping who seized the temptation to step in where the influence of the United States has waned as it withdrew from various stations of U.S.-guided support across the world.

The Communist Party of China is invested in aggressively redressing its "century of humiliation" when the Western world advanced far beyond the capabilities that China brought to bear from the mid-1800s to mid-1900, a situation humiliating to a once-powerful nation. It focuses on a goal of re-asserting its proper place in the world as a leading nation whose influence and power can be challenged by no others, even as it challenges with the assurance of entitlement the lone global super-power as a has-been entity.

Implacably, President Xi awaits each opportunity with the patience of an ancient cultural tradition of self-assurance renewed. His mantra of "socialism with Chinese characteristics" has served him and his country well in a few short decades that has literally pulled the country from its bootstraps up, in economic advantage leading to its ambitious Belt and Road initiative expanding travel, trade and telecommunications links with Europe and Asia.

While bidding for economic supremacy since it joined the World Trade Organization, China has undermined multilateral institutions and the international rule of law. At one time President Xi in conversation with then-President Obama assured there was no intention to militarize the disputed islands he had built in the South China Sea that he had illegally preempted as China's sovereign right. They were soon enough militarized, the purpose for which they had been established. 
 
Multilateral institutions have been slowly succumbing to Chinese power plans where international settlements and diplomatic and industrial guidelines are set. Chinese nationals occupy leadership positions in some 40 United Nations institutions for engineering, maritime law, health, finance, atomic energy and dozens of other areas. A situation that would make even a cynic cringe over future implications where Chinese positions at the International Telecommunications Union, UN Industrial Development Organization, Food and Agriculture Association renders massive leverage to China.
 
 

Labels: , , , , , , , ,

() Follow @rheytah Tweet