elsehow

Share this post

Wednesday briefing

www.else.how

Wednesday briefing

Emails hacked & porn blocked

Nick Merrill
Mar 10, 2021
1
Share this post

Wednesday briefing

www.else.how

I’m trying something new: sharing news stories I’m tracking.

Some truly massive espionage

The biggest news this week: people—probably China, and maybe others

1
—compromised potentially every Microsoft Exchange Server in the US.
2

It's hard to overstate the magnitude of this attack. Imagine collecting every email from every company, government, and state agency in the US—and having the AI capacity (think Baidu) to make sense of it all. CISA is posting about it,

3
the National Security Advisor to POTUS is tweeting about it… This is as large as it gets.

We'll learn much more about the scope and impact of this compromise in the coming days and weeks. Until then, my two cents: the thing about self-hosted solutions (e.g., a company running its own Exchange Server) is that this compromise can happen in 300,000 places at once. When a vulnerability emerges, everyone needs to upgrade. In contrast, Gmail can pour all of its resources into protecting one thing. The downside is their monopoly power. If only Gmail had more government oversight—or were just owned by the government like a Canadian Crown corporation...

Some of the more modern blockchain networks (like Oasis) provide a compromise between centralization and monopoly: they distribute the physical infrastructure (helping to prevent monopolies) while “centralizing” the code into something auditable (helping to surface bugs and centralize patches). There are other problems with on-chain applications,

4
but they do offer an in-between here.

Utah demands phones block porn by default

A new law in Utah...

5

...requires a tablet or a smart phone (a device) sold in the state [...] to, when activated in the state, automatically enable a filter capable of blocking material that is harmful to minors (via utah.gov)

On the one hand, this law could be like California passing car tailpipe emissions laws in the 1970s—effectively forcing the world to follow suit. Like California setting the conversation for what counts as emissions, Utah is attempting to set the conversation about what counts as “material that is harmful to minors.” That would affect defaults worldwide.

On the other hand, this law could make certain content inaccessible (by default) in Utah or, perhaps, in the US—effectively causing more Internet fragmentation.

You might be thinking, “Come on, this is no big deal—people can just disable the filter.” But, to quote the ISchool Pledge, “beware the power of defaults.”

6
Remember, all content blocking is, in a sense, “by default:” user action can almost always circumvent it (VPNs, Shadowsocks, etc.). All to say: don't underestimate the impact of this law on Internet fragmentation—assuming the law stands up to legal scrutiny and has teeth.

1
Twitter avatar for @likethecoins
Katie Nickels @likethecoins
Reminder: Microsoft named HAFNIUM. They define what it is. Just because an adversary exploited one of the recent Exchange vulns doesn't mean it was HAFNIUM. To even hypothesize that activity may be HAFNIUM, as an analyst, I'd want multiple specific overlaps with the MS post.
12:17 AM ∙ Mar 6, 2021
195Likes33Retweets
2

https://krebsonsecurity.com/2021/03/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software/

3

https://cyber.dhs.gov/ed/21-02/

Twitter avatar for @JakeSullivan46
Jake Sullivan @JakeSullivan46
We are closely tracking Microsoft’s emergency patch for previously unknown vulnerabilities in Exchange Server software and reports of potential compromises of U.S. think tanks and defense industrial base entities. We encourage network owners to patch ASAP:
msrc-blog.microsoft.comMultiple Security Updates Released for Exchange Server – updated March 8, 2021 – Microsoft Security Response Center
2:17 AM ∙ Mar 5, 2021
3,319Likes1,507Retweets
4

No, not environmental challenges. Oasis is a proof-of-stake chain, and the environmental stuff you hear about is about proof-of-work chains. The problems I’m talking about are much more about the social infrastructures that make chain-based assets meaningful or valuable. More about that in a future post.

5

https://www.xbiz.com/news/257750/utah-mandatory-porn-filter-bill-passes-senate-awaits-governors-signature

6

https://en.wikipedia.org/wiki/Default_effect

Share this post

Wednesday briefing

www.else.how
Comments
TopNewCommunity

No posts

Ready for more?

© 2023 Nick Merrill
Privacy ∙ Terms ∙ Collection notice
Start WritingGet the app
Substack is the home for great writing