Google AI


Modern Australian

Leak of US military plans on Signal is a classic case of ‘shadow IT’. It shows why security systems need to be easy to use

  • Written by: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne
Hand holding a mobile phone displaying the blue and white logo for the Signal app.

Yesterday, The Atlantic magazine revealed an extraordinary national security blunder in the United States. Top US government officials had discussed plans for a bombing campaign in Yemen against Houthi rebels in a Signal group chat which inadvertently included The Atlantic’s editor in chief, Jeffrey Goldberg.

This is hardly the first time senior US government officials have used non-approved systems to handle classified information. In 2009, the then US Secretary of State Hilary Clinton fatefully decided to accept the risk of storing her emails on a server in her basement because she preferred the convenience of accessing them using her personal BlackBerry.

Much has been written about the unprecedented nature of this latest incident. Reporting has suggested the US officials involved may have also violated federal laws that require any communication, including text messages, about official acts to be properly preserved.

But what can we learn from it to help us better understand how to design secure systems?

A classic case of ‘shadow IT’

Signal is regarded by many cybersecurity experts as one of the world’s most secure messaging apps. It has become an established part of many workplaces, including government.

Even so, it should never be used to store and send classified information. Governments, including in the US, define strict rules for how national security classified information needs to be handled and secured. These rules prohibit the use of non-approved systems, including commercial messaging apps such as Signal plus cloud services such as Dropbox or OneDrive, for sending and storing classified data.

The sharing of military plans on Signal is a classic case of what IT professionals call “shadow IT”.

It refers to the all-too-common practice of employees setting up parallel IT infrastructure for business purposes without the approval of central IT administrators.

This incident highlights the potential for shadow IT to create security risks.

Government agencies and large organisations employ teams of cybersecurity professionals whose job it is to manage and secure the organisation’s IT infrastructure from cyber threats. At a minimum, these teams need to track what systems are being used to store sensitive information. Defending against sophisticated threats requires constant monitoring of IT systems.

In this sense, shadow IT creates security blind spots: systems that adversaries can breach while going undetected, not least because the IT security team doesn’t even know these systems exist.

It’s possible that part of the motivation for the US officials in question using shadow IT systems in this instance might have been avoiding the scrutiny and record-keeping requirements of the official channels. For example, some of the messages in the Signal group chat were set to disappear after one week, and some after four.

However, we have known for at least a decade that employees also build shadow IT systems not because they are trying to weaken their organisation’s cybersecurity. Instead, a common motivation is that by using shadow IT systems many employees can get their work done faster than when using official, approved systems.

Usability is key

The latest incident highlights an important but often overlooked lesson in cybersecurity: whether a security system is easy to use has an outsized impact on the degree to which it helps improve security.

To borrow from US Founding Father Benjamin Franklin, we might say that a system designer who prioritises security at the expense of usability will produce a system that is neither usable nor secure.

The belief that to make a system more secure requires making it harder to use is as widespread as it is wrong. The best systems are the ones that are both highly secure and highly usable.

The reason is simple: a system that is secure yet difficult to use securely will invariably be used insecurely, if at all. Anyone whose inbox auto-complete has caused them to send an email to the wrong person will understand this risk. It likely also explains how The Atlantic’s editor-in-chief might have been mistakenly added by US officials to the Signal group chat.

While we cannot know for certain, reporting suggests Signal displayed the name of Jeffrey Goldberg to the chat group only as “JG”. Signal doesn’t make it easy to confirm the identity of someone in a group chat, except by their phone number or contact name.

In this sense, Signal gives relatively few clues about the identities of people in chats. This makes it relatively easy to inadvertently add the wrong “JG” from one’s contact list to a group chat.

Hand holding a mobile phone displaying the blue and white logo for the Signal app.
Signal is one of the most secure messaging apps, but should never be used to store and send classified information. Ink Drop/Shutterstock

A highly secure – and highly usable – system

Fortunately, we can have our cake and eat it too. My own research shows how.

In collaboration with Australia’s Defence Science and Technology Group, I helped develop what’s known as the Cross Domain Desktop Compositor. This device allows secure access to classified information while being easier to use than traditional solutions.

It is easier to use because it allows users to connect to the internet. At the same time, it keeps sensitive data physically separate – and therefore secure – but allows it to be displayed alongside internet applications such as web browsers.

One key to making this work was employing mathematical reasoning to prove the device’s software provided rock-solid security guarantees. This allowed us to marry the flexibility of software with the strong hardware-enforced security, without introducing additional vulnerability.

Where to from here?

Avoiding security incidents such as this one requires people following the rules to keep everyone secure. This is especially true when handling classified information, even if doing so requires more work than setting up shadow IT workarounds.

In the meantime, we can avoid the need for people to work around the rules by focusing more research on how to make systems both secure and usable.

Authors: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne

Read more https://theconversation.com/leak-of-us-military-plans-on-signal-is-a-classic-case-of-shadow-it-it-shows-why-security-systems-need-to-be-easy-to-use-253036

Pool and Deck Design: How to Plan the Perfect Outdoor Living Space for Your Sydney Home

For many Australians, the backyard is where life happens. Summer barbecues, weekend swims and long evenings outdoors are all part of the lifestyle, ...

Is Solar Pool Heating Worth It? What Sydney Homeowners Should Know

There's nothing quite like a backyard pool on a hot Sydney day. But once autumn rolls in, many pools sit unused for months because the water is simp...

Planning a Luxury House Move: A Week-by-Week Timeline for Prestige Sydney Homes

Selling or buying a prestige home is a major milestone. Whether it's a waterfront residence in Birchgrove, a grand Federation home in Haberfield or ...

Downsizing or Upgrading Your Caravan? Here's How to Sell It Without the Hassle

Selling a caravan can feel like a major task, especially when you are unsure about its value, paperwork, or how to find a buyer. Whether you are dow...

The Best Overseas Adventure Holidays for Australians Who Love the Outdoors

Australia offers no shortage of incredible outdoor experiences, but sometimes the best way to satisfy your sense of adventure is to head overseas. A...

Cape Town Wine Shuttle: Winelands Tasting & Tours

Embark on an unforgettable journey through the picturesque Cape Winelands, where world-class wines and breathtaking scenery await. Our Cape Town Win...

Metal Fabrication: Choosing Metal Fabrication Melbourne Services for Custom Projects

What Modern Metal Fabrication Involves From individual components to complete structures, metal fabrication brings together processes such as desig...

Why Giant Rats Tail Grass Keeps Coming Back After Spraying

Giant Rats Tail Grass (GRT) is one of the most frustrating pasture weeds for farmers and lifestyle property owners. You spray an infested area, see th...

When Custom Cardboard Boxes Make Sense for Your Business

Custom cardboard boxes can be useful when a standard carton does not fit a product, packing method or presentation requirement particularly well. A ...

Bottle Label Printing: Key Factors for a Professional Finish

Why the Printing Method Matters When businesses need packaging or printed containers developed for a particular application, the right supplier can m...

Virtual Livestock Fencing and GPS Tracking: Improving Visibility Across Cattle Properties

What Virtual Livestock Fencing Means for Modern Cattle Management Managing cattle across extensive properties requires more than knowing where anim...

Sydney Pawnbrokers Explained: How Hocking Your Car Actually Works

Sometimes you need cash, and you need it soon. If you own a car, you may already have a way to get it. That's what people mean when they say they've...

Moving Interstate from the Gold Coast to Brisbane (or Back)? What Removalists Wish You Knew First

Have you talked to anyone who’s done the move? They say the same thing: the drive up the M1 is the easy part. It's everything around it that catches...

Why the Spring School Holidays Are a Great Time to Visit Coffs Harbour

The spring school holidays are a good time to spend a few days on the Coffs Coast. The weather is starting to warm up, there is plenty to do outdoor...

What to Do When an Older Car Is No Longer Worth Keeping in Melbourne

Ever looked at another repair quote and wondered whether your old car is still worth the trouble? It is a common turning point for Melbourne motoris...

Your Baby's First Year: A Local Guide to Feeding, Sleep, and When to Get Extra Support

Ask ten parents in a Brisbane mothers' group how their baby is feeding or sleeping, and expect ten different answers.  Someone's baby sleeps throug...

Kitchen and Laundry Makeover Ideas That Don't Require a Full Renovation

Full kitchen renos are expensive — and most people don't actually need one.  They need the kitchen to stop looking like it's stuck in 2009, or they...

How Technology Is Reshaping the Modern Australian Commercial Kitchen

The commercial kitchen has always been shaped by technology. Refrigeration changed how ingredients could be stored, modern ventilation transformed k...