Axios Codebook

December 02, 2022
😎 TGIF, everyone. Welcome back to Codebook.
- The holidays can bring a spike in breach attempts. If you’re a network defender, I’d love to hear how you’re still trying to get into the holiday spirit with your teams this year.
- 📬 Have other thoughts, feedback or scoops to share? [email protected]
Today's newsletter is 1,466 words, a 5.5-minute read.
1 big thing: Averting quantum's encryption apocalypse
Illustration: Sarah Grillo/Axios
The U.S. is barreling toward a quantum computing future, but until it’s here, it's unknown if all the investments and time spent preparing the country’s cybersecurity will pay off.
The big picture: Experts have long feared quantum computing would allow foreign adversaries and hackers to crack the otherwise unbreakable encryption standards that protect most online data — leaving everything from online payment systems to government secrets vulnerable.
- Although a quantum computer isn't expected until 2030, at the earliest, updating current encryption standards will take just as long, creating a high-stakes race filled with unanswerable questions for national security and cybersecurity officials alike.
As scientists, academics and international policymakers attended the first-ever Quantum World Congress conference in Washington this week, alarmism around the future of secure data was undercut by foundational questions of what quantum computing will mean for the world.
- "We don't even know what we don't know about what quantum can do," said Michael Redding, chief technology officer at Quantropi, during a panel about cryptography at the Quantum World Congress.
Catch up quick: While classical computers rely on a binary of ones and zeros to run calculations, quantum computing harnesses the principles of quantum physics — which argues a particle can be in two places at once — to complete more complex calculations than a classical computer could ever do.
- Those calculations include cracking the equations that underpin the encryption standards that protect most online data today.
Threat level: Some governments are believed to have already started stealing enemies’ encrypted secrets now, so they can unlock them as soon as quantum computing is available.
- "It's the single-largest economic national-security issue we have ever faced as a Western society," said Denis Mandich, chief technology officer at Qrypt and a former U.S. intelligence official, at this week's conference. "We don't know what happens if they actually decrypt, operationalize and monetize all the data that they already have."
Between the lines: Whether the new post-quantum cybersecurity protocols governments and researchers are developing will be able to fend off quantum is tricky, if not impossible, to guarantee: It’s hard to prepare for a technology that still doesn’t exist.
- Current projects researching how to modernize encryption are based on insights into how adversaries have broken current encryption algorithms in past attacks and building on top of that.
The intrigue: That isn’t stopping the U.S. from investing even more resources into developing and protecting against quantum computing.
- President Joe Biden signed a national security memo in May ordering federal agencies to take inventory of all use cases for encryption in their systems. Congress has already poured at least $1.2 billion into quantum computing research and development.
- Cities and states are also stepping up: Chattanooga, Tennessee, on Wednesday became the first U.S. city to stand up a commercially available fiber optic network capable of handling quantum technologies.
Yes, but: A lot of post-quantum encryption research is happening in tandem with quantum development projects, so researchers have a more informed understanding of what they could be protecting against.
- "The way to do things efficiently is to do things in parallel and have the different components talking to each other and guiding each other," David Awschalom, director of the Chicago Quantum Exchange and senior scientist at the Argonne National Laboratory, tells Axios.
What’s next: All eyes are on the Commerce Department's National Institute of Standards and Technology as it prepares to release a second set of post-quantum encryption tools for security experts to test and analyze.
- Companies should also consider hiring quantum-specific security teams that can start modernizing their systems for a post-quantum world, Redding said.
2. DHS board investigates teen hacker group
Illustration: Aïda Amer/Axios
A group of federal cyber advisers is putting a suspected teen hacking group under the microscope in the second investigation ever conducted by the Cyber Safety Review Board.
Driving the news: The Department of Homeland Security review board — a group of 15 federal government and private-sector cyber experts — announced Friday morning that it will study and provide recommendations to fend off the hacking techniques behind the Lapsus$ data extortion group.
- The Cyber Safety Review Board first investigated and released a report with security recommendations in July about the Log4j open-source software vulnerability that affected millions of devices last year.
The big picture: Lapsus$, which has been outed as a teenage hacking group, is believed to be behind data breaches at Uber, Rockstar Games, Microsoft, Okta and other major companies earlier this year.
- Data extortion groups break into a company's systems, steal prized information like source codes, and then demand a payment from the company to stop them from leaking the stolen information.
- Specifically, Lapsus$ targets companies through MFA fatigue, where they use stolen login credentials to log in to a network and then spam account owners with two-factor authentication requests on their phones until they accept one.
- Suspected members of the gang are believed to be based in the U.K. and have been arrested several times throughout the year.
Catch up quick: DHS created the Cyber Safety Review Board in February to study and provide insights into some of the country's most formative and widespread cyberattacks and data breaches.
Between the lines: The board does not have any regulatory powers, cannot compel companies to cooperate, and only provides recommendations and lessons learned from the incidents it studies.
- As part of the review, the board will reach out to affected companies, but it's unclear who will cooperate at this time, board chair and DHS official Rob Silvers told reporters.
What they're saying: "The ongoing Lapsus$ hacks represent just the type of activity that merits a fulsome review," said DHS Secretary Alejandro Mayorkas during a press call.
What's next: Silvers said the board is in the early days of its review, and it's still determining its timeline for completing the Lapsus$ investigation.
3. Google extends Ukraine cyber support
Illustration: Maura Losch/Axios
Google is giving the Ukrainian government 50,000 free, one-year licenses to its Workspace tools as the country continues to fend off cyber assaults nearly one year into the war with Russia, the company announced Thursday.
Why it matters: Google Workspace gives Ukraine access to the company's email spam filters and phishing monitoring tools, which will help Ukrainians fend off the swarm of phishing and malware attacks they've encountered in their email inboxes.
- Google Cloud CISO Phil Venables tells Axios that before, Ukraine was using Gmail and other Workspace tools in an "ad hoc" way.
Driving the news: Google made the announcement the same day Ukrainian Vice Prime Minister Mykhailo Fedorov visited the company's Washington office.
The big picture: The expansion of Workspace in Ukraine adds to a growing list of investments Google has made in the country since the war broke out.
- Shortly after Russia invaded Ukraine in February, Google gave the Ukrainian government access to its free tools for at-risk groups, known as Project Shield, that help block distributed denial-of-service attacks.
- Google-owned threat intelligence firm Mandiant has also been providing direct assistance to the Ukrainian government throughout the war.
What they're saying: "If they need extra services, extra capacity, we're going to look to deliver," Venables tells Axios.
- "The situation continues to evolve, and we evolve in our ability to help Ukraine."
Between the lines: Ukraine is bracing for a possible influx of Russian cyberattacks on its critical infrastructure during the winter, making any additional cyber tools all the more important.
- So far, while the country has fended off at least one known cyberattack on its energy infrastructure, it has mostly faced a series of less sophisticated attacks.
4. Catch up quick
@ D.C.
🚂 The Transportation Security Administration is looking to rely on third-party certifiers to conduct cybersecurity audits of pipeline and rail companies, citing budget constraints. (Nextgov)
📡 The Federal Communications Commission's ban on new telecom equipment imports from Huawei, ZTE and others won't be enough to rid U.S. networks of Chinese telecom tools. (CyberScoop)
@ Industry
📰 A group of journalists are suing NSO Group after a client used the spyware makers’ tools to target them. (New Yorker)
📉 Cybersecurity firm CrowdStrike projected fourth-quarter sales of as much as $628.2 million, missing analysts' estimated $634.8 million. (Bloomberg)
🐦 Twitter alternative Hive shut down its servers to address critical security flaws. (TechCrunch)
@ Hackers and hacks
🔍 Google security researchers identified a suspected new spyware vendor: Spanish IT firm Variston IT. (Google)
👾 Security firm Tenable warns that as of Oct. 1, 72% of organizations remained vulnerable to the Log4j open-source software vulnerability. (Tenable)
💰 The FBI estimates the "Cuba ransomware gang" (which is not affiliated with the Cuban government) had received a total of $60 million in ransom payments from more than 100 victims as of August. (BleepingComputer)
5. 1 fun thing
Lola the cat preparing for the year-end holidays in a festive napping spot. Courtesy of Sam Sabin
Happy holiday season! Hopefully you and your loved ones are finding time to get into the festive spirit in between all of the year-end meetings and reports. One of my cats sure is trying 🥰 🎄.
☀️ See y'all on Tuesday!
Thanks to Peter Allen Clark for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.



