{"id":16143,"date":"2019-08-22T10:45:05","date_gmt":"2019-08-22T18:45:05","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/08\/22\/news-9886\/"},"modified":"2019-08-22T10:45:05","modified_gmt":"2019-08-22T18:45:05","slug":"news-9886","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/08\/22\/news-9886\/","title":{"rendered":"Shh! No Hacking the Census in the Library"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5d5c5fb4ec9a9600081deb44\/master\/pass\/OpEd-Library-Hack-612884930.jpg\"\/><\/p>\n<p><strong>Credit to Author: Leeza Garber| Date: Thu, 22 Aug 2019 13:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">The 2020 United <\/span>States Census will be the first to request a <a href=\"https:\/\/www.wired.com\/story\/us-census-2020-goes-digital\/\">majority of Americans to respond online<\/a>. The benefits are obvious. A digitized census is more efficient than the 230-year-old paper method, streamlining the processing of individual data for a population that has increased nearly a hundredfold since 1790, to 330 million. But connecting the country\u2019s biggest and most important questionnaire to the internet also creates vulnerabilities to hacks. And what could be the most popular census survey station is also an underfunded and maliciously targeted American institution: the public library (and its computers).<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\"><a href=\"https:\/\/twitter.com\/LeezaGarber?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor\" target=\"_blank\">Leeza Garber<\/a> is a cybersecurity and privacy attorney and Drexel University\u2019s Kline School of Law adjunct law professor specializing in information privacy.<\/p>\n<p class=\"paywall\">The Census Bureau is aware of digitization risks (and expenses, with cost projections upwards of $15 billion, including an IT budget). The bureau has responded to cybersecurity concerns with encryption, dual-factor authentication, use of the Department of Homeland Security\u2019s <a href=\"https:\/\/www.dhs.gov\/cisa\/einstein\" target=\"_blank\">EINSTEIN 3 Accelerated cybersecurity system<\/a>, and a <a href=\"https:\/\/www.census.gov\/library\/stories\/2019\/07\/hey-siri-why-is-2020-census-important.html\" target=\"_blank\">partnership with Microsoft<\/a> to leverage its expertise.<\/p>\n<p class=\"paywall\">Not only must census data be secured, kept private, and counted accurately, we must also feel safe providing data within an internet-connected system. When the census arrives, so will cyber scams: phishing emails from bad actors claiming to be bureau representatives, text messages with malicious links, and harassing phone calls demanding private information.<\/p>\n<p class=\"paywall\">Among the most widespread scams may be ransomware at public libraries, which could temporarily halt internet access. Twenty percent of Americans\u2014about 66 million people\u2014don\u2019t have home internet access, which is exactly why the bureau encourages going to public libraries to fill out the 2020 Census. Libraries will offer internet-connected desktops and designated census \u201ckiosks.\u201d Unfortunately, the Americans who rely on libraries for internet access may face greater cybersecurity risk. Cyberattacks on libraries continue to wreak havoc across the United States. In 2017, hackers locked access to 700 public computers at the St. Louis Public Library. In 2018, some 600 public library computers in Anne Arundel County, Maryland, <a href=\"https:\/\/www.govtech.com\/security\/Maryland-Library-Systems-Yet-to-Recover-Following-Hack.html\" target=\"_blank\">were infected<\/a> with a virus that took them offline for weeks, while 13 of the 23 servers within the Spartanburg, South Carolina, public library system <a href=\"https:\/\/www.goupstate.com\/news\/20180130\/spartanburg-public-library-computer-system-hit-by-ransomware\" target=\"_blank\">were compromised by ransomware<\/a>. Just last month, the Onondaga County, New York, library computer network <a href=\"https:\/\/www.syracuse.com\/news\/2019\/07\/grim-spider-strikes-same-ransomware-hit-onondaga-county-library-syracuse-schools.html\" target=\"_blank\">was attacked<\/a> by criminal Eastern European\u2013based ransomware. Moreover, public library internet users may be susceptible to more malware than the typical private computer user; they can&#x27;t control what protective software is in use, and more users on a single computer creates more opportunities for hackers to pass through. Malicious opportunists can attempt to steal users\u2019 information from public access computers with keystroke loggers or other data filching viruses.<\/p>\n<p class=\"paywall\">It\u2019s impossible to completely prevent malware, as attacks morph to catch victims off guard and capitalize on changing vulnerabilities. The Public Library Association <a href=\"http:\/\/publiclibrariesonline.org\/2018\/11\/ransomware-at-the-library-time-to-boost-your-cybersecurity\/\" target=\"_blank\">published<\/a> a robust malware overview, and the American Library Association has a <a href=\"http:\/\/www.ala.org\/advocacy\/privacy\" target=\"_blank\">dynamic privacy page<\/a>. The ALA also offers guidance for securing public access computers and networks, and the <a href=\"http:\/\/www.ala.org\/lita\/about\/igs\/public\/lit-Pp\" target=\"_blank\">Patron Privacy Technologies Interest Group<\/a> prioritizes data privacy.<\/p>\n<p class=\"paywall\">But is this enough for the 2020 Census? Not when library budgets are being slashed across the country. Last December, the New York Library Association issued a statement claiming the state was <a href=\"https:\/\/www.nyla.org\/max\/4DCGI\/cms\/review.html?Action=CMS_Document&amp;DocID=2725&amp;MenuKey=advocacy\" target=\"_blank\">\u201cunprepared for the 2020 Census,\u201d<\/a> and that a \u201clack of federal funding has caused the Bureau to cancel field tests, reduce hiring, and delay critical cybersecurity assessments.\u201d (<a href=\"https:\/\/www.nydailynews.com\/news\/politics\/ny-nyc-libraries-2020-census-count-20190801-mkwvycyijbgeldhvrqw7tw7axq-story.html\" target=\"_blank\">$1.4 million in city funding<\/a> was approved this August.) Other states are suffering from similar cuts. In Connecticut, <a href=\"https:\/\/www.nhregister.com\/news\/article\/Public-urged-to-pressure-West-Haven-officials-on-13836625.php\" target=\"_blank\">the West Haven Public Library executive director<\/a> is fighting against years of flat funding that has forced reduced hours of operation. Budget cuts in Louisville, Kentucky, <a href=\"https:\/\/www.wdrb.com\/news\/louisville-libraries-closing-saturday-as-latest-budget-casualties\/article_56615e28-8268-11e9-88fb-f3752da77842.html\" target=\"_blank\">required the closure<\/a> of two public libraries this year. Alaska state funding for broadband internet in its public libraries <a href=\"https:\/\/www.alaskapublic.org\/2019\/07\/11\/governors-vetoes-cancel-state-funding-for-library-broadband-program\/\" target=\"_blank\">was canceled<\/a> last month.<\/p>\n<p class=\"paywall\">While funds aren\u2019t being reduced across the board (cities like <a href=\"https:\/\/www.inquirer.com\/news\/stan-saylor-pennsylvania-public-library-funding-increase-20190711.html\" target=\"_blank\">Philadelphia<\/a> are celebrating recent wins), when budgeting is approved it is more often for construction, facade renovations, and other non-tech issues. At the federal level, the 2020 budget proposes <a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2019\/03\/msar-fy2020.pdf\" target=\"_blank\">eliminating<\/a> the Institute of Museum and Library Services (IMLS), the primary source of federal support for US libraries. This is the third year in a row that the White House has moved to eliminate the IMLS, but past congressional support pushed library funds through. The ALA <a href=\"http:\/\/www.ala.org\/news\/press-releases\/2019\/03\/ala-hopeful-bipartisan-support-116th-congress-despite-discouraging-white\" target=\"_blank\">responded<\/a> to this latest budget-cut threat by stating that \u201cdiscouraging as it is that the administration has again proposed eliminating the &#8230; IMLS, the bipartisan support in Congress over the past two years gives us reason to hope.\u201d<\/p>\n<p class=\"paywall\">To safeguard against cybersecurity threats to tens of millions, we need much more than hope. We need federal-, state-, and local-level recognition of the necessity of budgeting for technological updates for public libraries. The upcoming census will require public libraries to have solid and proactive cybersecurity training programs, system backups, and risk-management plans to meet our national needs, lest hackers make fools of us come April 1, 2020.<\/p>\n<p class=\"paywall\">WIRED Opinion <em>publishes pieces written by outside contributors and represents a wide range of viewpoints. Read more opinions <a href=\"https:\/\/www.wired.com\/opinion\">here<\/a>. Submit an op-ed at opinion@wired.com.<\/em><\/p>\n<p class=\"related-cne-video-component__dek\">In a discussion that covers ethics in technology, hacking humans, free will, and how to avoid potential dystopian scenarios, historian and philosopher Yuval Noah Harari speaks with Fei-Fei Li, renowned computer scientist and Co-Director of Stanford University&#39;s Human-Centered AI Institute &#8212; in a conversation moderated by Nicholas Thompson, WIRED&#39;s Editor-in-Chief.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/shh-no-hacking-the-census-in-the-library\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5d5c5fb4ec9a9600081deb44\/master\/pass\/OpEd-Library-Hack-612884930.jpg\"\/><\/p>\n<p><strong>Credit to Author: Leeza Garber| Date: Thu, 22 Aug 2019 13:00:00 +0000<\/strong><\/p>\n<p>Opinion: Millions of folks filling out the 2020 Census on public library computers also are putting themselves at risk.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[234,714,21358],"class_list":["post-16143","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-opinion","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16143"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16143\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}