
City Data Breach
In July, the City of Columbus experienced a massive data breach, which officials at the time referred to as “some type of incident.” Months later, the scope, damage, and cost of the incident are still coming into focus. I sat down with Connor Goodwolf, a cybersecurity engineer, to discuss the data breach and his role in the ongoing efforts to understand what happened and how to recover from it. According to Goodwolf, despite his efforts to alert the city, he faced a restraining order and legal challenges. In our discussion, he emphasized the need for better cybersecurity measures and proactive communication from the city.
Shownotes
Read the transcript
Welcome to the Confluence Cast, presented by Columbus Underground. We are a weekly Columbus-centric podcast focusing on the civics, lifestyle, entertainment, and people of our city. I'm your host, Tim Fulton. This week: in July of this year, the city of Columbus experienced a massive data breach, what officials at the time referred to as "some type of incident." Months later, the scope, damage, and cost of the incident are still coming into focus. I sat down with Connor Goodwolf, a cybersecurity engineer, to discuss the data breach and his role in the ongoing efforts to understand what happened and how to recover from it. According to Goodwolf, despite his efforts to alert the city, he faced a restraining order and legal challenges. In our discussion, he emphasized the need for better cybersecurity measures and proactive communication from the city. You can get more information on what we discussed today in the show notes for this episode at theconfluencecast.com. Enjoy the interview. Sitting down here with Connor Goodwolf, cybersecurity engineer, on the occasion of the data breach that happened here at the City of Columbus. Before we get into what happened, Connor, can you tell us about yourself? Yeah, so I'm a multifaceted engineer, but for this, as I tell people, I'm big into cybersecurity, so just refer to me as a cybersecurity engineer. I do software, systems, hardware. I do CAD work, silicone implants for medical. I'm kind of all over the board. You've got all kinds of stuff. And you came into at least my purview as a result of this data breach that happened in Columbus. I'm probably going to get the timeline slightly off here, but in mid-July, it was identified that there was a data breach in Columbus. It was framed in a couple of different ways, and then multiple messages went out to the city that were maybe not completely untruthful, but possibly just unaware of the extent of this breach. And then you took it upon yourself, is that fair to say, to look into what is out there? Yeah. So I came across the breach. I monitor the dark web, different groups, everything from ransomware to trafficking, to rather dark places on the net. So I just saw the words "City of Columbus" come across my radar on some of the dark web tracking. I was like, oh, what's this? Reseda.
Not as a result—you didn't go seeking it. You basically were doing, I don't know, a daily perusal of what was out there, and what people were looking at or offering up for sale. Is that correct? Yeah. So I had seen the news, but I was like, okay, data breach, whatever. And then I saw the group responsible, and I was like, well, this is going to be good. So I just started looking through the file list. I was like, oh, the Matrix database. And what does that mean? So the Matrix database is a platform utilized by anything from law enforcement, attorneys, prosecutors, civil and criminal courts. This platform is sold—from what I've seen, there are quite a few municipalities across Ohio who utilize it. So that's why I'm aware of it. Again, I monitor certain groups and entities, so when something pops up, I've generally forwarded it on to law enforcement. So I've kind of already been in the know with some of the tech and software that's utilized. And I'm going to ask you about some things, and basically just say, is that a term of art? Is that something somebody who works in this space would be familiar with, what a Matrix database was? Matrix is just the platform. It's a web database platform, and some of the other offerings they have, like file upload—you deploy these different platforms usually on premise, because you want everything to be self-contained within each municipality or each data center. You don't want it all together.
So let's talk about your intent. First of all, you are not there to do crime. You are there to sort of—there's one, a little bit of interest, but two, it's like, oh, I could help stop this, or help make people aware of a problem or a breach. I think sometimes you may even reach out to an organization and say, it's apparent that you have a weak link here that you can fix. Is that fair? Yeah. And sometimes I've investigated some ransomware attacks where it's like, wow. And then I've reached out to organizations or other municipalities and been like, hey, do you guys need help? So is it a bit of business development for you? It can be. Sometimes I do just say, do you need help? I can help out if you want. Sometimes they take it, sometimes they don't, whatever. I do a load of consulting across the board, against different areas. And of course, I have my full-time job as well, doing engineering work. So I love just taking on additional tasks.
Got it. So when you discovered this set of data, both the Matrix database and other things there, what did that tell you? Like, this was pretty bad? Well, at first it's like, okay, let's download it and then see if it's actually intact, if it's actually there, instead of just making broad comments saying it's corrupted or encrypted, thus unusable— Which is what the city said at the time, correct? Correct. So I'm like, okay, let's just download one database, the one I'm familiar with. It was one of the Matrix prosecutor databases. I download it, it takes like eight hours, because Tor and the router is slow. So once I download it and restore it, it's like, oh.
There it is, everything here. Everything that was supposedly unusable or supposedly encrypted. And you weren't using some magic way to decipher it or come up with it. It was just there. Once you were able to open it, it was— Unencrypted. All I did was restore to SQL Server and started just browsing different tables. I was like, wow, everything from 2014 on. That's when the city purchased the platform to utilize. That's when they purchased it and deployed it, with the prosecutors, civil, law enforcement, and other departments. So then what did you do with that information, to start? Well, first I was actually making sure. So I was looking at my information on it, and others I knew were in there, and verifying. And then once Monday rolled around, I did start calling different numbers within the city. And even that weekend, I tried calling others before, but everything's closed on the weekends.
That's fair. And did you get any response from these folks? No, not from the city, no. And one with the prosecutor's office. I did call a couple of times, and I was like, do you realize that the database is out there, and it's more than just employees, current and former? And they were like, yes, we are aware. And everyone was basically given marching orders that the Department of Technology and the mayor's office is handling it and all aspects of it. So I'm like, okay. And, to be clear, did you reach out to the prosecutor's office or to the city attorney's office? I reached out to the prosecutor's office. And at no point during this conversation, and with any conversation I had, whether it was with the Columbus Police Department, people I was actually able to talk to there, or the prosecutor's office, or even City Council's number—they were all told to forward any questions or comments to the Department of Technology. At no point was I told to contact the city attorney.
Okay, got it. And then when you sort of weren't getting the response—sorry, what did you think of that response? I don't want to put words in your mouth. Did you think, oh, maybe they do have this handled? No, I was expecting someone to call me back. I did leave a voicemail on the HR individual who is responsible for the Department of Technology jobs, and that's what one of the channels had posted. But that one was from HR because—I'm pretty sure, because, like I mentioned, HR is there to protect the company and the department. But it's like, everyone just seems to be completely blacked out. No one was talking to anyone. No one was reaching out. And here I had the information that really needed to be public. The public needed to be aware of it. Okay. And we'll get into the "why" there. But your next step was, based on the stories you were seeing, the reporting on it, you knew that wasn't true—that the dissemination of that information was wider, or at least it was available. It was out there, someone with your skill set would have been able to steal it. And sometimes people with your skill set are bad actors. And so is that when you reached out to the media? Well, I reached out to the media—I believe I tried reaching out Monday evening. Then I tried reaching out Tuesday morning. When I wasn't getting a response, and I knew it was urgent, I started making my rounds to all the channels again. And that's when two of them had called me back, and I won an interview. And I did not know that morning, on Tuesday morning, that there was going to be a press conference with the mayor. They didn't tell me until, like, right before. The mayor sent out this fact sheet.
And so then your interview is basically going through and saying, here's this fact sheet, and based on what I know, here are the aspects of it that are either incorrect or maybe misleading. Let's step way, way back. What does a normal attack like this look like? What are the things that happen? Because I would like to think that there's nuggets of truth in what was put out there, but maybe just the full story wasn't put out there. So my understanding: some bad actor gets access to something. They then have a couple of different steps. One is locking down the system that previously was there, making it unusable. And then second, taking the data that was there and holding it hostage, holding it for ransom. So what aspects of that—did all of that successfully happen here? So the data was exfiltrated. And generally in ransomware attacks, or severe breaches, you're right, one or both of those things generally happen. So in this case with the city, six terabytes of data was exfiltrated, removed, sent somewhere else. That was out of the control of the city. Now, generally, right afterwards, these groups will deploy tools on every resource, every machine, workstation, and then hit a button that says "encrypt everything." And that's where you've maybe seen on TV, your common ransomware attack will pop up with a message: pay this amount of Bitcoin or whatever, or we won't restore your systems. And that is what the city successfully stopped. Okay. So, and is it fair to say they may not have been aware that the data was taken? They more than likely, in the beginning—yeah, in the beginning, because right now, they don't know the timeline, whether they're in there for days or weeks or even months. Because, again, generally you get a foothold in a company or their infrastructure, and the more damage that you can do, the more likely they'll—
The more they are, right. And so it's possible that these bad actors—what's the name of the group, Reseda?—was in there long before the breach actually happened. It's possible. And probably they were looking to see how everything was architected, looking to see the best way to disable these systems. But they did have the data. So is it fair to say that they may not have known that the data was gone? Well, the City of Columbus detected suspicious activity. Just looking from the file list, all of the SQL or database backups happened around the same time. So more than likely what happened was they had console access, administrator access, to all these database servers, and started initiating backups and then exfiltrating the data right there. Because that's what it looks like. That was probably the red flag. I do know that in one of the screenshots that were posted by Reseda, there was a screenshot of an admin account that was posted in the SQL Management Console. So more than likely that was one of the accounts utilized to infiltrate the network. Got it. And so you talk to the media, you go through and you say, this is the kind of thing I'm seeing. I am here because I believe it's important for the public to be aware of it. The city's response to that was basically, yeah, we know—oh, turns out it is out there. They start offering more identity protection, which I will link in the show notes. The city is offering credit protection to any city resident and anybody that was at, I believe, City Hall. But again, there'll be a link in the show notes. What was the city's response then to you? I do have to clarify with the credit monitoring, please. That credit monitoring is for anyone, whether you're interacting with the city directly or not. Anyone is technically able to sign up for it. Obviously, due to the cost, please sign up only if you have reason to. Because literally anyone from California to New Jersey can sign up. But there is also credit monitoring for minors on that page. Minors are victims of identity theft as well, believe it or not, so this does happen. Now, I tell people, even if you've paid your water bill, if you've filed your taxes directly with the city, if you've done any sort of payroll or done business with the city—because the general ledger was posted as well, the databases, basically the database that contained all the statements of everything. So if you've interacted with the city in any way, please sign up for the credit monitoring. What I personally do is I rotate my bank accounts every so often. And that's because if they do have all the information—and maybe you've looked at the second lawsuit, where officers' accounts were being drained—if you have the bank account, the routing account info and the proper info, and you sign up for some app like Cash App or Venmo, whatever, and you get all the information correctly, you can actually connect to someone's bank account.
Okay. Proactive things that folks should do? For me, I'm going to be rotating my bank accounts out, opening another one where I currently bank, moving everything over. So I have to redo everything for my credit card payments. And of course, if you utilize your debit card anywhere online—you shouldn't. You should pipe that through a credit card and pay it off at the end of the month. Okay, so what was the city's response then to your basically going to the media? So at first they were hesitant, and then sometime later, they had come out and said, okay, it's more than just employees, current and former.
But then also they got a temporary restraining order against you as well. Yeah, on the 28th. I was going to the media on, I believe, the 13th. So they only took offense when I started talking about the law enforcement database—not the prosecutors', but the crime Matrix database. But everything else was okay. So is that why they reacted, that you started talking about a set of data that they didn't want out there, that could have the awareness of out there— That could have potentially contained extremely sensitive materials relating to undercover officers and confidential informants.
Okay. And so then you were served. And what were the terms of the restraining order they got against you? So the terms of the original restraining order were rather obtuse. They're basically telling me I cannot do what I love doing. I can't do my job. The work I do is more than just a hobby. It is work. It's learning. It's cybersecurity engineering. For a lot of us, it is ingrained in us. Well, it's exploration. It's poking things. It's knowledge. The judge had basically granted this motion saying I cannot be myself.
Okay. Well, let's be explicit about that, though. Basically you were not allowed to be in possession of, disseminate, or discuss—accessing— Downloading, disseminating. And there was another— Any data, or just this data? Any data related to the City of Columbus breach.
And so, based on how you work and what you do, you may not have even been able to prevent yourself from having some access. Or is that fair to say? Yeah. Well, when it comes to the cybersecurity engineering research, there are some cybersecurity engineers who take the path of just don't download the data. That's up to them. But when it comes down to it, when you're developing machine learning or AI models, and when you're being able to develop technology and software in order to help people post-breach, that's literally telling me I can't do my job. Okay. But, to be clear and fair, you were not contracted to do any correction here, right? No, no. This is all just, oh, you know, I was just curious. I do a lot of OCR machine learning work. This is like, okay, I can actually branch off on this. This is, like, a few months ago, and work on developing technology to do post-breach work, like e-discovery and whatnot. Because again, if you look at the statistics, there is an increase in these breaches and attacks. But for the City of Columbus, it's like, okay, it's just going to be extra data. I wasn't expecting this amount of data or the impact. Generally, with breaches, it's like the Social Security number breach from NPD. It's not, generally, multiple databases, every single thing for the past 20 years, with—
Records intertwined with each other. Oh, mind-blowing. And so the current status of things is that that restraining order is much more limited now. Like, you wouldn't have been able to have this conversation with me if that original order was standing. It would be limited in conversation.
We could talk about a myriad of things, but not this. Yeah. Well, the way they word it—the word "disseminating," in legal, is still kind of gray. I looked it up, because I do a lot of work on the side for criminal investigations. I'm just an independent investigator. But "disseminating" is kind of gray in the legal space. It can be interpreted a few different ways. Are you disseminating by talking about it or saying what's in there? Or are you disseminating by taking the actual data and, here's what the contents are, here you go? And so how are you limited now? Right now, you can't show anybody anything? Basically. I cannot sit there, open up the database on my laptop, and say, look at this.
And so—but there is still a case pending. You are still technically being sued. Is that correct? That is correct. Are you being sued for damages, or just for limiting your behavior? So as it stands, the original suit has not been modified. Damages greater than $25,000, for a variety of reasons: invasion of privacy, causing panic. And how am I causing panic? The breach already happened. Making people aware that their data is out there on the dark web—is that me causing panic? Excuse me.
So my question is, how do you think the city should have handled it? Well, let me just put it this way. That morning the TRO was being filed, an officer who was affiliated with an Ohio law enforcement department actually reached out to me through an acquaintance. That was the appropriate step they should have taken, was to reach out and say, what's going on? Could you tell us more about what it is you found? Because they never did that. Your first proper contact with the city was—other than casual, you reach out and you said, hey, I found this stuff, what should I do, and that was very like, hey, this is all being referred to this department. The first real interaction, could it be said, was that temporary restraining order? Unfortunately. And that was the most inappropriate action they could have taken. I don't know if you know who Barbra Streisand is.
I am familiar. Are you aware of the Streisand effect? This is the photo that she took—or she sued somebody for taking a photo of her house— Of her mansion, on the cliffside. So, general gist. Streisand—so then what's the effect? This person took a photo of her mansion on the cliffside. She didn't want it on the net, and she sued the person to have it removed. Well, everybody saw this on the net and decided to repost that photo everywhere. Therefore, since then, it's called the Streisand effect.
Okay, so basically you're pursuing against the one actor. It's not a takedown notice, because that one actor doesn't even have control at this point over the dissemination of that information. So, setting you aside, what do you think the city should have done? Do you think that the messaging that they put out could have been more thorough? Do you think that they should have been more proactive about saying, we are investigating, we do not know what we do not know? What do you think would have been a better course of action? They should have hired people who browse the dark web, who understand the dark web and Tor, the onion router. My observation is Ginther was told information that was incorrect. Again, you cannot expect a CEO or mayor or whatever to be a tech person. So he was given incorrect information, and then he decided to run with it. He could have waited, but he was excited, I get that, and he wanted to get something out there. But someone along the line messed up. Is it possible—this is devil's advocate, or maybe angel's advocate, I don't know how you would say it—is it possible that the folks that were giving him information either didn't know, or were making assumptions, and in either of those cases they weren't telling him what they knew to be untrue? Or is it your opinion it was just a CYA? Oh, no. I had actually sat down with an officer who was asking me questions about Tor and whatnot, and the data. And I've been using Tor for so long, I do actions that are just second nature to me now, like using command-line tools. And when it comes to large files, I never use the browser. So it didn't dawn on me that someone may actually try to download a 200-gigabyte file with the Tor browser. So the officer asked me, I tried downloading this file and it completed, but it was corrupted. And I just slapped my face right there. I was like, oh my God.
Now, I don't know what analogy they'll use here, but it is sort of like—they could have used the Tor browser to download that data, of course it's going to be corrupted. It's not meant to be downloaded in that way. And maybe they did it twice. What generally happens is the download will stop. Again, Tor is a loose set of servers, computers that are all set up across the world in order to anonymize someone. So sometimes those larger downloads, they stop midway. You can resume, but that's where sometimes the corruption happens. So it didn't dawn on me. The officer wasn't the one who told Ginther anything, but it made me realize, oh, someone working in that space, someone along the line, did the same thing and then told Ginther it's corrupted. And so do you think the decision to present the temporary restraining order is simply shortsighted? The motion itself was full of falsehoods and lies. So the website, for example—if you've read the restraining order, there were several falsehoods in there. I don't know who gave them the false information, but it's almost like the same person who went to Ginther and reported the falsehoods to him. But the website that I'm creating, it's about doing, like, Have I Been Pwned, a check to whether or not your information is in there—not to make the information searchable.
Is that your intent? Is that what you were planning on doing at the time? I am doing it. But I will be reaching out to people within the city this time. Now I have communication and contacts. The intention is to sit people in a room, explain what it does, and even get additional input. And I guess I would hope maybe bring in somebody else that's up to your level, and say, you should show them that it can't be accessed. Because that's the fear, right? So is that maybe where—sorry, I didn't know this part of it, and I didn't want to read the restraining order. An outsider's perspective would be, well, if you're creating something that is at all searchable, then there's got to be some access to that data on the back end, or somebody could find it. And they feared that you would create something that would potentially easily disseminate that information? Yeah. So all the data would be taken from the breach, and just very specific snippets of data would be hashed. Whether it's the full name and date of birth, in one table, and it'd be mathematically hashed. It's what's called a one-way hash. It's not encryption, so you can't decode it.
Got it. And so that action, or statement of that and the intent of that action, may be what scared them? Yeah. The TRO motion makes it look as if they had feared that I was going to just basically take the data and say, here you go, here's all the data that was there. That's how it reads, at least to me and others. And then, the invasion of privacy and the creation of fear or whatnot. I'm just like, the data's out there, and you're not telling anyone. From the very start, my intention was to make sure people are aware, so they could take steps and precautions, because credit monitoring only goes so far. And like I said, personally, I'm going to be rotating all my bank accounts, because I can't take the risk that my account and routing info is attached to something within the city at this point. And so what do you think now that things are settled, basically? Do you think that the city is taking the necessary action? Do you think that there are still more unanswered questions about what's happening? Where do we stand now? Right now, we need answers. What happened within the Department of Technology?
So, to be clear, we are talking on Monday, September 16, before the city council meeting tonight. The head of—sorry, what's the office, the Department of Technology—their head spoke last week at a council meeting. It was not a proper investigation at that point. It was just answering some questions. But they are going to start, we believe this evening, investigating basically every week until it all comes out. There will be, from what they stated last time, a series of just statements about the ongoing investigation, without divulging any pertinent information. Now, right afterwards, there will be a series of hearings performed by the city council, an actual investigatory hearing. But I do not know when that's going to occur. Okay, got it. It'll probably occur after the investigation is complete.
Is there more that the city—be that council, be that mayor—that should be doing at this point? Or is there more they can do? I don't think there's anything more that they can do at this point. The data is gone. It's out there. Yeah, it's out there on the dark web. And right now, according to the Department of Technology, they are still working on restoring the rest of the systems.
So, I guess here's kind of a big question. The group that hacked the city came back and asked for roughly $1.9 million in Bitcoin. I can only put it this simply: given everything that's happened, given the amount that we, the city, are now paying for credit monitoring for folks—should we have paid it? And I'm asking you this as a professional in the space. Like, sometimes you just gotta clean up the mess. Or would that just have invited other bad actors? That is an ethical question. So there are some who feel like, yes, sometimes you should pay it, especially since the city does not have cybersecurity insurance—which, maybe that would have been a good idea to have before this hack. Now, according to the FBI, some organizations have paid the ransom, and law enforcement has been able to claw some of the funds back, and this usually occurs after they catch up with specific bad actors in the group. Like you may have seen in the news, some ransom group, those members have been arrested and charged. So sometimes that does happen, sometimes victims are able to get their money back. But seeing as how it was, whatever, $2 million—that's a drop in the bucket compared to what's happening now, the lawsuits, plus anything else. But these sorts of groups, they act like a professional organization. That was my follow-up: are you incentivizing them to continue acting that way, to continue to try and breach again? And frankly, from an insurance perspective, it's probably pretty hard to get cybersecurity insurance for the city at this moment. So it is a moral, legal, and ethical conundrum of what should we have done when this happened. Anything else? Should we just have been more thorough in terms of investigating what actually happened here? Well, we're talking post-breach. Honestly, there could have been more that should have been done pre-breach. When I'm working with companies, a part of what I do is go in, get a list of systems, services, work on what's called SOC Type 2 compliance, or ISO compliance. It's basically a full audit. For me, I get together all this information—systems, services, how they're secured—even do the work of locking down systems and services, and adding in the software or policies to enhance the security, even limiting access that employees have, even admin access. I don't have the keys to the kingdom. I split the responsibility up to others, that way, if one person is hacked—
No single point of failure. Exactly. So the work I do, and a lot of people like me do, is do all that, take the documentation, give it to a CPA, and then they work on getting the company the approval to be certified. A version of that report they put together. The question is, does the city do this yearly? I do not know. There's no mandate. In the State of Ohio, there is a federal mandate, but only for federal organizations, like when it comes to STIG guidelines—the Standard Technical Implementation Guidelines—and the FISMA certification processes. The feds have it, they know how to do this. We need something that says—for example, I don't expect your township of 300 people to implement this, but for a city like Columbus or Cincinnati or Cleveland, we should have some state laws passed where we say, okay, you need to follow this standard.
Okay. And so you think this is both a city issue and a state issue, to help get things in line? There's no guidelines to it. There's no law, there's no guidelines of how you should secure a city. It's just, here you go, do whatever. Well, and it's not sexy, right? The city is not going to proactively do it to the extent that it needs to be done and then get any sort of pat on the back. It's just like, oh, maybe their insurance is cheaper. People have actually asked me, why don't I work for the city? You don't work for the city for money. If you're someone like me, you're not working for a municipality. It's not about the money, though. People who work for the city, sure, they do go in for a paycheck, but they may even enjoy their job. But people like me do tend to work for larger organizations like Google, Amazon, or companies, banks, etc., who are looking to secure their infrastructure.
Absolutely. And so do you feel, at this point—do you feel vindicated to an extent? Because at one point you were telling the press, oh, I'm going to reach out to the ACLU, I apparently need to go and get counsel. So where does that stand? Do you still feel maligned, I guess is the question, or do you feel vindicated a bit? I do have a lawyer on standby, should I need them. The EFF is actually seen, in tech, as the tech version of the ACLU. Covers this. The Electronic Frontier Foundation, for those that are familiar. So the EFF, they cover a wide range of topics. Generally, privacy is a big one, and it's relatable because we're talking about people's data and security. The work they do is incredibly important, from pushing new laws into place to proposals to help people understand their online privacy. They're one of the organizations who endorsed Tor, the onion router, which even has been brought up by others who have made incorrect statements that imply that Tor is only utilized by criminals. But just to clarify, when it comes to Tor and the dark web, it's used by journalists, whistleblowers, privacy advocates. Sure, there's always going to be a criminal element to, well, anything, even the internet, not just Tor. That's just the nature of the beast. But the intent for Tor is not to hide the criminal element.
Okay. So, we've talked a little bit about some of the things that the city could have done to rectify the situation, but where do you think—either you personally, or the city in general—where do we go from here? So, quite honestly, I know there is a lack of resources, and this is really any municipality when it comes to cyber. Again, you're not working for the government for money. But pulling in some of those individuals, and some of the resources from the city or other departments of law enforcement or whatever, helping create these cyber units within the city or law enforcement, pulling them in so they can help secure the infrastructure of our local municipalities. It's like the National Guard Cyber unit, for instance. I remember hearing about them some years ago, I think it was 2019 they were created, and I completely forgot. It's like, man, that would have actually been cool to even just join in, because I technically could now. That is actually a good idea, to help educate a lot of these individuals who work for the government, whether the tech departments or whatever—just have seminars and educate, and really just pull people into cyber, because that's what we are going to be needing. This onslaught, this increase of attacks. And the majority of attacks do happen in the US, from actors abroad. I end every interview with the same two questions. What do you think Columbus is doing well? And what do you think Columbus is not doing so well? I don't know what they're doing well.
I mean, it can be even just community-related, like, I love the food scene, the art, anything. I'll tell you why I live in Columbus. I live in Columbus for the green spaces, the festivals, the people. That's why I live in Columbus, and that's what they're doing well. That's what Columbus is fantastic for. I'm a nature person. And I disliked my time in Pittsburgh. It was a concrete city that did not have the amount of community and green spaces that Columbus has. And it's so attractive. Being a nature person, also a hunter, it kind of has this mishmash of different attractions for people like me. And what do you think Columbus is not doing so well? Right now, at least to me, I think they need to do better on notifying people who are potentially at risk. Sure, they did comply with the Ohio law by posting the breach notification on their website, and that was an alternative notification. However, I think we can do a little bit better. I want to work with them on the website, and also potentially follow up via contacting individuals who are more at risk, at least giving the persons a heads up, whether it's by email, call, or sending a letter.
Okay. Connor, thanks for your time. All right. Thanks so much. Thank you for listening to the Confluence Cast, presented by Columbus Underground. Again, you can get more information on what we discussed today in the show notes for this episode at theconfluencecast.com. Please rate, subscribe, share this episode of the Confluence Cast with your friends, family, contacts, enemies, your favorite cybersecurity engineer. If you're interested in sponsoring the Confluence Cast, get in touch with us. We can be reached by email at info@theconfluencecast.com. Our theme music was composed by Benji Robinson. Our producer is Philip Cogley. I'm your host, Tim Fulton. Have a great week.
Transcript6,308 words
Tim Fulton Welcome to the Confluence Cast, presented by Columbus Underground. We are a weekly Columbus-centric podcast focusing on the civics, lifestyle, entertainment, and people of our city. I'm your host, Tim Fulton. This week: in July of this year, the city of Columbus experienced a massive data breach, what officials at the time referred to as "some type of incident." Months later, the scope, damage, and cost of the incident are still coming into focus. I sat down with Connor Goodwolf, a cybersecurity engineer, to discuss the data breach and his role in the ongoing efforts to understand what happened and how to recover from it. According to Goodwolf, despite his efforts to alert the city, he faced a restraining order and legal challenges. In our discussion, he emphasized the need for better cybersecurity measures and proactive communication from the city. You can get more information on what we discussed today in the show notes for this episode at theconfluencecast.com. Enjoy the interview. Sitting down here with Connor Goodwolf, cybersecurity engineer, on the occasion of the data breach that happened here at the City of Columbus. Before we get into what happened, Connor, can you tell us about yourself?
Connor Goodwolf Yeah, so I'm a multifaceted engineer, but for this, as I tell people, I'm big into cybersecurity, so just refer to me as a cybersecurity engineer. I do software, systems, hardware. I do CAD work, silicone implants for medical. I'm kind of all over the board.
Tim Fulton You've got all kinds of stuff. And you came into at least my purview as a result of this data breach that happened in Columbus. I'm probably going to get the timeline slightly off here, but in mid-July, it was identified that there was a data breach in Columbus. It was framed in a couple of different ways, and then multiple messages went out to the city that were maybe not completely untruthful, but possibly just unaware of the extent of this breach. And then you took it upon yourself, is that fair to say, to look into what is out there?
Connor Goodwolf Yeah. So I came across the breach. I monitor the dark web, different groups, everything from ransomware to trafficking, to rather dark places on the net. So I just saw the words "City of Columbus" come across my radar on some of the dark web tracking. I was like, oh, what's this? Reseda.
Tim Fulton Not as a result—you didn't go seeking it. You basically were doing, I don't know, a daily perusal of what was out there, and what people were looking at or offering up for sale. Is that correct?
Connor Goodwolf Yeah. So I had seen the news, but I was like, okay, data breach, whatever. And then I saw the group responsible, and I was like, well, this is going to be good. So I just started looking through the file list. I was like, oh, the Matrix database. And what does that mean? So the Matrix database is a platform utilized by anything from law enforcement, attorneys, prosecutors, civil and criminal courts. This platform is sold—from what I've seen, there are quite a few municipalities across Ohio who utilize it. So that's why I'm aware of it. Again, I monitor certain groups and entities, so when something pops up, I've generally forwarded it on to law enforcement. So I've kind of already been in the know with some of the tech and software that's utilized.
Tim Fulton And I'm going to ask you about some things, and basically just say, is that a term of art? Is that something somebody who works in this space would be familiar with, what a Matrix database was?
Connor Goodwolf Matrix is just the platform. It's a web database platform, and some of the other offerings they have, like file upload—you deploy these different platforms usually on premise, because you want everything to be self-contained within each municipality or each data center. You don't want it all together.
Tim Fulton So let's talk about your intent. First of all, you are not there to do crime. You are there to sort of—there's one, a little bit of interest, but two, it's like, oh, I could help stop this, or help make people aware of a problem or a breach. I think sometimes you may even reach out to an organization and say, it's apparent that you have a weak link here that you can fix. Is that fair?
Connor Goodwolf Yeah. And sometimes I've investigated some ransomware attacks where it's like, wow. And then I've reached out to organizations or other municipalities and been like, hey, do you guys need help?
Tim Fulton So is it a bit of business development for you?
Connor Goodwolf It can be. Sometimes I do just say, do you need help? I can help out if you want. Sometimes they take it, sometimes they don't, whatever. I do a load of consulting across the board, against different areas. And of course, I have my full-time job as well, doing engineering work. So I love just taking on additional tasks.
Tim Fulton Got it. So when you discovered this set of data, both the Matrix database and other things there, what did that tell you? Like, this was pretty bad?
Connor Goodwolf Well, at first it's like, okay, let's download it and then see if it's actually intact, if it's actually there, instead of just making broad comments saying it's corrupted or encrypted, thus unusable—
Tim Fulton Which is what the city said at the time, correct?
Connor Goodwolf Correct. So I'm like, okay, let's just download one database, the one I'm familiar with. It was one of the Matrix prosecutor databases. I download it, it takes like eight hours, because Tor and the router is slow. So once I download it and restore it, it's like, oh.
Tim Fulton There it is, everything here. Everything that was supposedly unusable or supposedly encrypted. And you weren't using some magic way to decipher it or come up with it. It was just there. Once you were able to open it, it was—
Connor Goodwolf Unencrypted. All I did was restore to SQL Server and started just browsing different tables. I was like, wow, everything from 2014 on. That's when the city purchased the platform to utilize. That's when they purchased it and deployed it, with the prosecutors, civil, law enforcement, and other departments.
Tim Fulton So then what did you do with that information, to start?
Connor Goodwolf Well, first I was actually making sure. So I was looking at my information on it, and others I knew were in there, and verifying. And then once Monday rolled around, I did start calling different numbers within the city. And even that weekend, I tried calling others before, but everything's closed on the weekends.
Tim Fulton That's fair. And did you get any response from these folks?
Connor Goodwolf No, not from the city, no. And one with the prosecutor's office. I did call a couple of times, and I was like, do you realize that the database is out there, and it's more than just employees, current and former? And they were like, yes, we are aware. And everyone was basically given marching orders that the Department of Technology and the mayor's office is handling it and all aspects of it. So I'm like, okay.
Tim Fulton And, to be clear, did you reach out to the prosecutor's office or to the city attorney's office?
Connor Goodwolf I reached out to the prosecutor's office. And at no point during this conversation, and with any conversation I had, whether it was with the Columbus Police Department, people I was actually able to talk to there, or the prosecutor's office, or even City Council's number—they were all told to forward any questions or comments to the Department of Technology. At no point was I told to contact the city attorney.
Tim Fulton Okay, got it. And then when you sort of weren't getting the response—sorry, what did you think of that response? I don't want to put words in your mouth. Did you think, oh, maybe they do have this handled?
Connor Goodwolf No, I was expecting someone to call me back. I did leave a voicemail on the HR individual who is responsible for the Department of Technology jobs, and that's what one of the channels had posted. But that one was from HR because—I'm pretty sure, because, like I mentioned, HR is there to protect the company and the department. But it's like, everyone just seems to be completely blacked out. No one was talking to anyone. No one was reaching out. And here I had the information that really needed to be public. The public needed to be aware of it.
Tim Fulton Okay. And we'll get into the "why" there. But your next step was, based on the stories you were seeing, the reporting on it, you knew that wasn't true—that the dissemination of that information was wider, or at least it was available. It was out there, someone with your skill set would have been able to steal it. And sometimes people with your skill set are bad actors. And so is that when you reached out to the media?
Connor Goodwolf Well, I reached out to the media—I believe I tried reaching out Monday evening. Then I tried reaching out Tuesday morning. When I wasn't getting a response, and I knew it was urgent, I started making my rounds to all the channels again. And that's when two of them had called me back, and I won an interview. And I did not know that morning, on Tuesday morning, that there was going to be a press conference with the mayor. They didn't tell me until, like, right before. The mayor sent out this fact sheet.
Tim Fulton And so then your interview is basically going through and saying, here's this fact sheet, and based on what I know, here are the aspects of it that are either incorrect or maybe misleading. Let's step way, way back. What does a normal attack like this look like? What are the things that happen? Because I would like to think that there's nuggets of truth in what was put out there, but maybe just the full story wasn't put out there. So my understanding: some bad actor gets access to something. They then have a couple of different steps. One is locking down the system that previously was there, making it unusable. And then second, taking the data that was there and holding it hostage, holding it for ransom. So what aspects of that—did all of that successfully happen here?
Connor Goodwolf So the data was exfiltrated. And generally in ransomware attacks, or severe breaches, you're right, one or both of those things generally happen. So in this case with the city, six terabytes of data was exfiltrated, removed, sent somewhere else. That was out of the control of the city. Now, generally, right afterwards, these groups will deploy tools on every resource, every machine, workstation, and then hit a button that says "encrypt everything." And that's where you've maybe seen on TV, your common ransomware attack will pop up with a message: pay this amount of Bitcoin or whatever, or we won't restore your systems. And that is what the city successfully stopped.
Tim Fulton Okay. So, and is it fair to say they may not have been aware that the data was taken?
Connor Goodwolf They more than likely, in the beginning—yeah, in the beginning, because right now, they don't know the timeline, whether they're in there for days or weeks or even months. Because, again, generally you get a foothold in a company or their infrastructure, and the more damage that you can do, the more likely they'll—
Tim Fulton The more they are, right. And so it's possible that these bad actors—what's the name of the group, Reseda?—was in there long before the breach actually happened. It's possible. And probably they were looking to see how everything was architected, looking to see the best way to disable these systems. But they did have the data. So is it fair to say that they may not have known that the data was gone?
Connor Goodwolf Well, the City of Columbus detected suspicious activity. Just looking from the file list, all of the SQL or database backups happened around the same time. So more than likely what happened was they had console access, administrator access, to all these database servers, and started initiating backups and then exfiltrating the data right there. Because that's what it looks like. That was probably the red flag. I do know that in one of the screenshots that were posted by Reseda, there was a screenshot of an admin account that was posted in the SQL Management Console. So more than likely that was one of the accounts utilized to infiltrate the network.
Tim Fulton Got it. And so you talk to the media, you go through and you say, this is the kind of thing I'm seeing. I am here because I believe it's important for the public to be aware of it. The city's response to that was basically, yeah, we know—oh, turns out it is out there. They start offering more identity protection, which I will link in the show notes. The city is offering credit protection to any city resident and anybody that was at, I believe, City Hall. But again, there'll be a link in the show notes. What was the city's response then to you?
Connor Goodwolf I do have to clarify with the credit monitoring, please. That credit monitoring is for anyone, whether you're interacting with the city directly or not. Anyone is technically able to sign up for it. Obviously, due to the cost, please sign up only if you have reason to. Because literally anyone from California to New Jersey can sign up. But there is also credit monitoring for minors on that page. Minors are victims of identity theft as well, believe it or not, so this does happen. Now, I tell people, even if you've paid your water bill, if you've filed your taxes directly with the city, if you've done any sort of payroll or done business with the city—because the general ledger was posted as well, the databases, basically the database that contained all the statements of everything. So if you've interacted with the city in any way, please sign up for the credit monitoring. What I personally do is I rotate my bank accounts every so often. And that's because if they do have all the information—and maybe you've looked at the second lawsuit, where officers' accounts were being drained—if you have the bank account, the routing account info and the proper info, and you sign up for some app like Cash App or Venmo, whatever, and you get all the information correctly, you can actually connect to someone's bank account.
Tim Fulton Okay. Proactive things that folks should do?
Connor Goodwolf For me, I'm going to be rotating my bank accounts out, opening another one where I currently bank, moving everything over. So I have to redo everything for my credit card payments. And of course, if you utilize your debit card anywhere online—you shouldn't. You should pipe that through a credit card and pay it off at the end of the month.
Tim Fulton Okay, so what was the city's response then to your basically going to the media?
Connor Goodwolf So at first they were hesitant, and then sometime later, they had come out and said, okay, it's more than just employees, current and former.
Tim Fulton But then also they got a temporary restraining order against you as well.
Connor Goodwolf Yeah, on the 28th. I was going to the media on, I believe, the 13th. So they only took offense when I started talking about the law enforcement database—not the prosecutors', but the crime Matrix database. But everything else was okay.
Tim Fulton So is that why they reacted, that you started talking about a set of data that they didn't want out there, that could have the awareness of out there—
Connor Goodwolf That could have potentially contained extremely sensitive materials relating to undercover officers and confidential informants.
Tim Fulton Okay. And so then you were served. And what were the terms of the restraining order they got against you?
Connor Goodwolf So the terms of the original restraining order were rather obtuse. They're basically telling me I cannot do what I love doing. I can't do my job. The work I do is more than just a hobby. It is work. It's learning. It's cybersecurity engineering. For a lot of us, it is ingrained in us.
Tim Fulton Well, it's exploration. It's poking things.
Connor Goodwolf It's knowledge. The judge had basically granted this motion saying I cannot be myself.
Tim Fulton Okay. Well, let's be explicit about that, though. Basically you were not allowed to be in possession of, disseminate, or discuss—accessing—
Connor Goodwolf Downloading, disseminating. And there was another—
Tim Fulton Any data, or just this data?
Connor Goodwolf Any data related to the City of Columbus breach.
Tim Fulton And so, based on how you work and what you do, you may not have even been able to prevent yourself from having some access. Or is that fair to say?
Connor Goodwolf Yeah. Well, when it comes to the cybersecurity engineering research, there are some cybersecurity engineers who take the path of just don't download the data. That's up to them. But when it comes down to it, when you're developing machine learning or AI models, and when you're being able to develop technology and software in order to help people post-breach, that's literally telling me I can't do my job.
Tim Fulton Okay. But, to be clear and fair, you were not contracted to do any correction here, right?
Connor Goodwolf No, no. This is all just, oh, you know, I was just curious. I do a lot of OCR machine learning work. This is like, okay, I can actually branch off on this. This is, like, a few months ago, and work on developing technology to do post-breach work, like e-discovery and whatnot. Because again, if you look at the statistics, there is an increase in these breaches and attacks. But for the City of Columbus, it's like, okay, it's just going to be extra data. I wasn't expecting this amount of data or the impact. Generally, with breaches, it's like the Social Security number breach from NPD. It's not, generally, multiple databases, every single thing for the past 20 years, with—
Tim Fulton Records intertwined with each other.
Connor Goodwolf Oh, mind-blowing.
Tim Fulton And so the current status of things is that that restraining order is much more limited now. Like, you wouldn't have been able to have this conversation with me if that original order was standing.
Connor Goodwolf It would be limited in conversation.
Tim Fulton We could talk about a myriad of things, but not this.
Connor Goodwolf Yeah. Well, the way they word it—the word "disseminating," in legal, is still kind of gray. I looked it up, because I do a lot of work on the side for criminal investigations. I'm just an independent investigator. But "disseminating" is kind of gray in the legal space. It can be interpreted a few different ways. Are you disseminating by talking about it or saying what's in there? Or are you disseminating by taking the actual data and, here's what the contents are, here you go?
Tim Fulton And so how are you limited now? Right now, you can't show anybody anything?
Connor Goodwolf Basically. I cannot sit there, open up the database on my laptop, and say, look at this.
Tim Fulton And so—but there is still a case pending. You are still technically being sued. Is that correct?
Connor Goodwolf That is correct.
Tim Fulton Are you being sued for damages, or just for limiting your behavior?
Connor Goodwolf So as it stands, the original suit has not been modified. Damages greater than $25,000, for a variety of reasons: invasion of privacy, causing panic. And how am I causing panic? The breach already happened. Making people aware that their data is out there on the dark web—is that me causing panic? Excuse me.
Tim Fulton So my question is, how do you think the city should have handled it?
Connor Goodwolf Well, let me just put it this way. That morning the TRO was being filed, an officer who was affiliated with an Ohio law enforcement department actually reached out to me through an acquaintance. That was the appropriate step they should have taken, was to reach out and say, what's going on?
Tim Fulton Could you tell us more about what it is you found? Because they never did that. Your first proper contact with the city was—other than casual, you reach out and you said, hey, I found this stuff, what should I do, and that was very like, hey, this is all being referred to this department. The first real interaction, could it be said, was that temporary restraining order?
Connor Goodwolf Unfortunately. And that was the most inappropriate action they could have taken. I don't know if you know who Barbra Streisand is.
Tim Fulton I am familiar.
Connor Goodwolf Are you aware of the Streisand effect?
Tim Fulton This is the photo that she took—or she sued somebody for taking a photo of her house—
Connor Goodwolf Of her mansion, on the cliffside. So, general gist. Streisand—so then what's the effect? This person took a photo of her mansion on the cliffside. She didn't want it on the net, and she sued the person to have it removed. Well, everybody saw this on the net and decided to repost that photo everywhere. Therefore, since then, it's called the Streisand effect.
Tim Fulton Okay, so basically you're pursuing against the one actor. It's not a takedown notice, because that one actor doesn't even have control at this point over the dissemination of that information. So, setting you aside, what do you think the city should have done? Do you think that the messaging that they put out could have been more thorough? Do you think that they should have been more proactive about saying, we are investigating, we do not know what we do not know? What do you think would have been a better course of action?
Connor Goodwolf They should have hired people who browse the dark web, who understand the dark web and Tor, the onion router. My observation is Ginther was told information that was incorrect. Again, you cannot expect a CEO or mayor or whatever to be a tech person. So he was given incorrect information, and then he decided to run with it. He could have waited, but he was excited, I get that, and he wanted to get something out there. But someone along the line messed up.
Tim Fulton Is it possible—this is devil's advocate, or maybe angel's advocate, I don't know how you would say it—is it possible that the folks that were giving him information either didn't know, or were making assumptions, and in either of those cases they weren't telling him what they knew to be untrue? Or is it your opinion it was just a CYA?
Connor Goodwolf Oh, no. I had actually sat down with an officer who was asking me questions about Tor and whatnot, and the data. And I've been using Tor for so long, I do actions that are just second nature to me now, like using command-line tools. And when it comes to large files, I never use the browser. So it didn't dawn on me that someone may actually try to download a 200-gigabyte file with the Tor browser. So the officer asked me, I tried downloading this file and it completed, but it was corrupted. And I just slapped my face right there. I was like, oh my God.
Tim Fulton Now, I don't know what analogy they'll use here, but it is sort of like—they could have used the Tor browser to download that data, of course it's going to be corrupted. It's not meant to be downloaded in that way. And maybe they did it twice.
Connor Goodwolf What generally happens is the download will stop. Again, Tor is a loose set of servers, computers that are all set up across the world in order to anonymize someone. So sometimes those larger downloads, they stop midway. You can resume, but that's where sometimes the corruption happens. So it didn't dawn on me. The officer wasn't the one who told Ginther anything, but it made me realize, oh, someone working in that space, someone along the line, did the same thing and then told Ginther it's corrupted.
Tim Fulton And so do you think the decision to present the temporary restraining order is simply shortsighted?
Connor Goodwolf The motion itself was full of falsehoods and lies. So the website, for example—if you've read the restraining order, there were several falsehoods in there. I don't know who gave them the false information, but it's almost like the same person who went to Ginther and reported the falsehoods to him. But the website that I'm creating, it's about doing, like, Have I Been Pwned, a check to whether or not your information is in there—not to make the information searchable.
Tim Fulton Is that your intent? Is that what you were planning on doing at the time?
Connor Goodwolf I am doing it. But I will be reaching out to people within the city this time. Now I have communication and contacts. The intention is to sit people in a room, explain what it does, and even get additional input.
Tim Fulton And I guess I would hope maybe bring in somebody else that's up to your level, and say, you should show them that it can't be accessed. Because that's the fear, right? So is that maybe where—sorry, I didn't know this part of it, and I didn't want to read the restraining order. An outsider's perspective would be, well, if you're creating something that is at all searchable, then there's got to be some access to that data on the back end, or somebody could find it. And they feared that you would create something that would potentially easily disseminate that information?
Connor Goodwolf Yeah. So all the data would be taken from the breach, and just very specific snippets of data would be hashed. Whether it's the full name and date of birth, in one table, and it'd be mathematically hashed. It's what's called a one-way hash. It's not encryption, so you can't decode it.
Tim Fulton Got it. And so that action, or statement of that and the intent of that action, may be what scared them?
Connor Goodwolf Yeah. The TRO motion makes it look as if they had feared that I was going to just basically take the data and say, here you go, here's all the data that was there. That's how it reads, at least to me and others. And then, the invasion of privacy and the creation of fear or whatnot. I'm just like, the data's out there, and you're not telling anyone. From the very start, my intention was to make sure people are aware, so they could take steps and precautions, because credit monitoring only goes so far. And like I said, personally, I'm going to be rotating all my bank accounts, because I can't take the risk that my account and routing info is attached to something within the city at this point.
Tim Fulton And so what do you think now that things are settled, basically? Do you think that the city is taking the necessary action? Do you think that there are still more unanswered questions about what's happening? Where do we stand now?
Connor Goodwolf Right now, we need answers. What happened within the Department of Technology?
Tim Fulton So, to be clear, we are talking on Monday, September 16, before the city council meeting tonight. The head of—sorry, what's the office, the Department of Technology—their head spoke last week at a council meeting. It was not a proper investigation at that point. It was just answering some questions. But they are going to start, we believe this evening, investigating basically every week until it all comes out.
Connor Goodwolf There will be, from what they stated last time, a series of just statements about the ongoing investigation, without divulging any pertinent information. Now, right afterwards, there will be a series of hearings performed by the city council, an actual investigatory hearing. But I do not know when that's going to occur.
Tim Fulton Okay, got it.
Connor Goodwolf It'll probably occur after the investigation is complete.
Tim Fulton Is there more that the city—be that council, be that mayor—that should be doing at this point? Or is there more they can do?
Connor Goodwolf I don't think there's anything more that they can do at this point. The data is gone.
Tim Fulton It's out there.
Connor Goodwolf Yeah, it's out there on the dark web. And right now, according to the Department of Technology, they are still working on restoring the rest of the systems.
Tim Fulton So, I guess here's kind of a big question. The group that hacked the city came back and asked for roughly $1.9 million in Bitcoin. I can only put it this simply: given everything that's happened, given the amount that we, the city, are now paying for credit monitoring for folks—should we have paid it? And I'm asking you this as a professional in the space. Like, sometimes you just gotta clean up the mess. Or would that just have invited other bad actors?
Connor Goodwolf That is an ethical question. So there are some who feel like, yes, sometimes you should pay it, especially since the city does not have cybersecurity insurance—which, maybe that would have been a good idea to have before this hack. Now, according to the FBI, some organizations have paid the ransom, and law enforcement has been able to claw some of the funds back, and this usually occurs after they catch up with specific bad actors in the group. Like you may have seen in the news, some ransom group, those members have been arrested and charged. So sometimes that does happen, sometimes victims are able to get their money back. But seeing as how it was, whatever, $2 million—that's a drop in the bucket compared to what's happening now, the lawsuits, plus anything else. But these sorts of groups, they act like a professional organization.
Tim Fulton That was my follow-up: are you incentivizing them to continue acting that way, to continue to try and breach again? And frankly, from an insurance perspective, it's probably pretty hard to get cybersecurity insurance for the city at this moment. So it is a moral, legal, and ethical conundrum of what should we have done when this happened. Anything else? Should we just have been more thorough in terms of investigating what actually happened here?
Connor Goodwolf Well, we're talking post-breach. Honestly, there could have been more that should have been done pre-breach. When I'm working with companies, a part of what I do is go in, get a list of systems, services, work on what's called SOC Type 2 compliance, or ISO compliance. It's basically a full audit. For me, I get together all this information—systems, services, how they're secured—even do the work of locking down systems and services, and adding in the software or policies to enhance the security, even limiting access that employees have, even admin access. I don't have the keys to the kingdom. I split the responsibility up to others, that way, if one person is hacked—
Tim Fulton No single point of failure.
Connor Goodwolf Exactly. So the work I do, and a lot of people like me do, is do all that, take the documentation, give it to a CPA, and then they work on getting the company the approval to be certified.
Tim Fulton A version of that report they put together.
Connor Goodwolf The question is, does the city do this yearly? I do not know. There's no mandate. In the State of Ohio, there is a federal mandate, but only for federal organizations, like when it comes to STIG guidelines—the Standard Technical Implementation Guidelines—and the FISMA certification processes. The feds have it, they know how to do this. We need something that says—for example, I don't expect your township of 300 people to implement this, but for a city like Columbus or Cincinnati or Cleveland, we should have some state laws passed where we say, okay, you need to follow this standard.
Tim Fulton Okay. And so you think this is both a city issue and a state issue, to help get things in line?
Connor Goodwolf There's no guidelines to it. There's no law, there's no guidelines of how you should secure a city. It's just, here you go, do whatever.
Tim Fulton Well, and it's not sexy, right? The city is not going to proactively do it to the extent that it needs to be done and then get any sort of pat on the back. It's just like, oh, maybe their insurance is cheaper.
Connor Goodwolf People have actually asked me, why don't I work for the city? You don't work for the city for money. If you're someone like me, you're not working for a municipality. It's not about the money, though. People who work for the city, sure, they do go in for a paycheck, but they may even enjoy their job. But people like me do tend to work for larger organizations like Google, Amazon, or companies, banks, etc., who are looking to secure their infrastructure.
Tim Fulton Absolutely. And so do you feel, at this point—do you feel vindicated to an extent? Because at one point you were telling the press, oh, I'm going to reach out to the ACLU, I apparently need to go and get counsel. So where does that stand? Do you still feel maligned, I guess is the question, or do you feel vindicated a bit?
Connor Goodwolf I do have a lawyer on standby, should I need them. The EFF is actually seen, in tech, as the tech version of the ACLU.
Tim Fulton Covers this. The Electronic Frontier Foundation, for those that are familiar.
Connor Goodwolf So the EFF, they cover a wide range of topics. Generally, privacy is a big one, and it's relatable because we're talking about people's data and security. The work they do is incredibly important, from pushing new laws into place to proposals to help people understand their online privacy. They're one of the organizations who endorsed Tor, the onion router, which even has been brought up by others who have made incorrect statements that imply that Tor is only utilized by criminals. But just to clarify, when it comes to Tor and the dark web, it's used by journalists, whistleblowers, privacy advocates. Sure, there's always going to be a criminal element to, well, anything, even the internet, not just Tor. That's just the nature of the beast. But the intent for Tor is not to hide the criminal element.
Tim Fulton Okay. So, we've talked a little bit about some of the things that the city could have done to rectify the situation, but where do you think—either you personally, or the city in general—where do we go from here?
Connor Goodwolf So, quite honestly, I know there is a lack of resources, and this is really any municipality when it comes to cyber. Again, you're not working for the government for money. But pulling in some of those individuals, and some of the resources from the city or other departments of law enforcement or whatever, helping create these cyber units within the city or law enforcement, pulling them in so they can help secure the infrastructure of our local municipalities. It's like the National Guard Cyber unit, for instance. I remember hearing about them some years ago, I think it was 2019 they were created, and I completely forgot. It's like, man, that would have actually been cool to even just join in, because I technically could now. That is actually a good idea, to help educate a lot of these individuals who work for the government, whether the tech departments or whatever—just have seminars and educate, and really just pull people into cyber, because that's what we are going to be needing. This onslaught, this increase of attacks. And the majority of attacks do happen in the US, from actors abroad.
Tim Fulton I end every interview with the same two questions. What do you think Columbus is doing well? And what do you think Columbus is not doing so well?
Connor Goodwolf I don't know what they're doing well.
Tim Fulton I mean, it can be even just community-related, like, I love the food scene, the art, anything.
Connor Goodwolf I'll tell you why I live in Columbus. I live in Columbus for the green spaces, the festivals, the people. That's why I live in Columbus, and that's what they're doing well. That's what Columbus is fantastic for. I'm a nature person. And I disliked my time in Pittsburgh. It was a concrete city that did not have the amount of community and green spaces that Columbus has. And it's so attractive. Being a nature person, also a hunter, it kind of has this mishmash of different attractions for people like me.
Tim Fulton And what do you think Columbus is not doing so well?
Connor Goodwolf Right now, at least to me, I think they need to do better on notifying people who are potentially at risk. Sure, they did comply with the Ohio law by posting the breach notification on their website, and that was an alternative notification. However, I think we can do a little bit better. I want to work with them on the website, and also potentially follow up via contacting individuals who are more at risk, at least giving the persons a heads up, whether it's by email, call, or sending a letter.
Tim Fulton Okay. Connor, thanks for your time.
Connor Goodwolf All right. Thanks so much.
Tim Fulton Thank you for listening to the Confluence Cast, presented by Columbus Underground. Again, you can get more information on what we discussed today in the show notes for this episode at theconfluencecast.com. Please rate, subscribe, share this episode of the Confluence Cast with your friends, family, contacts, enemies, your favorite cybersecurity engineer. If you're interested in sponsoring the Confluence Cast, get in touch with us. We can be reached by email at info@theconfluencecast.com. Our theme music was composed by Benji Robinson. Our producer is Philip Cogley. I'm your host, Tim Fulton. Have a great week.
