People and the Glass

This is about deception. It is about how people can be tricked, manipulated, and misled by the screens they trust most: the phone in their hand, the laptop on their desk, the display they work from every day. It is about a cybersecurity vulnerability that gives an attacker control over what your screen shows and what it does. The attacker can change the information in front of you. The attacker can add things that were never there. The attacker can take away what you needed to see: the warning, the fee, the alternative, the button that would have let you say no. A great many of the decisions we make each day rest on information shown to us on a screen, and the same screen often captures the decision and sets the action in motion: the payment is sent, the order is placed, the valve is opened. Whoever controls the screen can influence what people believe, the opinions they form, the decisions they make, and the actions they take. This is disinformation in its most direct form: a false experience, on a screen you had every reason to believe.

We call this cybersecurity vulnerability Attack the Glass (ATG). It exploits a weakness in our existing cybersecurity architecture through a supply chain injection on client-side rendering. Most of the screens around us are dynamic, created in the instant before they are shown to you. What appears is often shaped by who you are, where you are, what you are doing, why and when you are doing it, and even how you are interacting with the system. That real-time assembly of the user interface is accomplished using client-side rendering. The various companies and individuals that provide the data, media, components, code, and other assets are part of the vast, global internet supply chain. Anyone who controls one of those assets can quietly change what your screen shows and what it does, and every security tool in use today will report that all is well. An attacker can aim the change at everyone, at one group, or at one person, which makes the deception more persuasive and leaves almost nobody in a position to notice. Artificial intelligence can now write a different deception for every one of those people, in seconds, at almost no cost. The change happens in the memory of the device and is gone when the screen goes dark, so an attack that could not be detected while it ran cannot be proven afterward.

Truth Is a Decision

People act on what they believe to be true at the moment they act. A nurse gives a dose because she believes the chart. A trader sells because he believes the price. A customer pays, a driver brakes, an operator opens a valve, each acting on a picture of the world they did not build themselves and have no time to verify.

Nobody checks most of what they believe. Nobody could. A person cannot test the water before every glass, audit the bank before every deposit, or confirm each headline with a second source. People do something else. They decide whom and what to trust, and then they take its word. These choices of who we trust anchor nearly everything a person holds to be true.

Truth, as people live it, is a decision. It is made quickly, many times a day, usually without noticing, and it is made about the source far more often than about the claim. My bank says this is my balance. The clinic says the appointment is Tuesday. The news says the bridge is closed. The person has verified none of it and acts on all of it, because of who said it.

How the Brain Automates Trust

Trust is one of the most common decisions a person makes, and the brain does with it what it does with anything repeated often enough: it turns the decision into a habit. The first time you used your bank's app, you may have looked it over with some care. By the hundredth time you were checking a balance while crossing the street. Psychologists call these mental shortcuts heuristics. They are rules the brain applies automatically so that it can save its attention for whatever is new. "This is my bank's app, and it has always been right" is a heuristic. So is "this newspaper checks its facts," and so is "this is the screen I use at work every day."

Shortcuts make daily life possible. Nobody could get through a morning while weighing every source from scratch. They also carry a cost. Once trust has become automatic, the brain stops inspecting. It ties the trust to something familiar, a name, a logo, a face, the look of a page, and it lets whatever arrives under that sign pass without a second look. Small things that are out of place go unseen, because nothing is looking for them.

Ordinary life is full of examples. Hardly anyone examines a twenty-dollar bill, which is the only reason counterfeit money works. A stranger in a high-visibility vest carrying a ladder walks past most front desks unchallenged, because the vest answers the question before anyone asks it. An email that appears to come from the chief executive, asking the finance team for an urgent wire transfer, succeeds often enough that the FBI counts the losses from that one trick in billions of dollars a year. In each case the victim checked the sign, a banknote's look, a uniform, a sender's name, and the sign was all the deceiver needed to supply.

Every con artist, forger, and propagandist in history has worked in that gap. The reliable way to deceive someone is to borrow a source they already trust and speak in its voice.

With My Own Eyes

Before we trust any person or any institution, we trust our own senses. "I saw it with my own eyes" is the strongest claim most people know how to make, and courts, newsrooms, and families all treat it that way.

Human beings take in the world through five senses, and vision dominates the other four. When sight and another sense disagree, the brain sides with sight, and it does so before we know there was a disagreement. In a classic experiment, people were shown a light and played a tone at the same instant. They responded to the light almost every time, and on a third of those trials they never noticed the tone at all. None of this is a choice. Nobody decides to weight their eyes over their ears, and nobody can decide to stop.

Sight and sound together are stronger still. When what we see and what we hear arrive at the same moment and agree, the brain fuses them into a single experience that is easier to understand, easier to remember, and harder to doubt than either one alone. Anyone who has sat in a cinema has felt it. The speakers are on the walls, and every voice seems to come from the mouth of the actor on the screen. The brain moves the sound to where the eyes say it belongs, and knowing how the effect works does nothing to stop it. A screen that delivers matched picture and sound is using the richest channel there is into the human brain.

People also learn by watching. We see something done and know how to do it. We watch something happen to another person and feel it ourselves. Human beings have handed down knowledge and experience this way since long before writing, and it has never required being in the room. Children who watch an adult on film imitate what they saw as readily as those who were there in person. Adults who watch a video of a stranger receiving electric shocks at the sight of a colored square display the physical signs of fear when it later appears in front of them, though nothing has ever happened to them. The brain files what it watches alongside what it lives through.

What we see shapes what we judge to be true. People rate the same statement as more likely to be true when it is printed in type that is easier to read. They find a claim more believable when an unrelated photograph sits beside it. They rate a statement as more accurate the second time they see it, even when they know it is false. None of these changes what is said. Each changes only how it appears, or how often. Each effect is small, and each can be repeated without limit.

What we see can also replace what we remember. People shown a doctored photograph of a public event come to remember the event the way the image shows it. When the truth arrives later, it does not fully undo the damage: people go on reasoning from the first version they saw.

For nearly all of human history, everything a person saw or heard was physically present: a face, a fire, an animal, a voice across a room. Our senses, and the trust we place in them, were formed in that world over hundreds of thousands of years. Screens have existed for about a century, and the ones we carry for less than twenty years. The eyes and ears have made no adjustment. Light from a screen enters the same eye and is handled by the same machinery as light from a face, and the brain has no separate, more skeptical channel for things that are digital. We experience what is on a screen with senses that were built for what is physically there.

The gap between ancient senses and digital screens is about to be tested harder. Artificial intelligence can now produce a face, a voice, a document, or a video of something that never happened, and the number of screens around us grows every year. Some countries have started treating the public's ability to resist deception as a matter of national defense. Sweden set up its Psychological Defence Agency in 2022 to help a whole society detect and resist attempts to manipulate what it believes. A defense of that kind starts with knowing how deception reaches us, and today most of it arrives through a screen.

The Glass

Look around the room you are in and count the screens. A phone, almost certainly, within reach. A laptop or a monitor. A television. A watch. Beyond the room there is the dashboard of the car, the display on the thermostat and the refrigerator, the kiosk where you check in for a flight or order lunch, the card terminal at the counter, the pump at the gas station, the departure board, the menu above the register, the screen in the back of the seat in front of you. On the job there may be a point-of-sale system, a patient chart, a trading terminal, a dispatch board, or the control panel for a production line, a water plant, or a power grid.

There are billions of these surfaces, backlit and connected, and nearly all of them arrived within a single lifetime. Most arrived in the last twenty years. People spend a large part of their waking lives looking at them, and the screens call for attention when we look away, with alerts, notifications, vibrations, and chimes. Nearly every one of them can deliver picture and sound together.

We call all of them, together, the Glass. The Glass is any digital surface where a computer puts something in front of a human being to see, usually with sound to match. A browser window on a laptop is only the most familiar example. A phone app, a television menu, a vehicle display, an appliance panel, and an operator's console in a control room are the same thing under different housings, and they are built the same way.

Nothing in human history, or in the long evolution of the brain before it, resembles this. Never have so many eyes rested on so few kinds of surface for so many hours. Never has so much human attention been reachable so quickly, in every country at once, across every language and every culture. A story, an image, or an instruction can be in front of a billion people within minutes. The Glass is a direct channel, through sight and sound, to the place where people decide what is true.

The Glass matters for a second reason, which is where it sits. It is the last step in every digital system. Whatever happened upstream, in the data centers, the databases, the networks, and the security tools, the final act is always the same: an interface is put together on a pane of glass in front of a person, with its information, its choices, and its buttons, and they read it and act. It is the point where data stops being data and becomes what someone believes, and then what they do. A bank runs its systems so that a customer can see a balance and move money. A hospital runs its systems so that a nurse can see a dose and give it. A utility runs its systems so that an operator can see the state of the grid and act on it. Years of engineering sit behind each of those screens, and all of it exists to produce the few square inches a person looks at.

The Glass is also where trust now arrives. Trust starts small, with family, friends, a teacher, a doctor. It scales up to institutions we will never meet in person: a bank, a newspaper, a hospital, an employer, a brand we have bought for twenty years. Nobody audits their bank before checking a balance. They trust the name, and the name has usually earned it. Until recently that trust was carried by things you could hold and people you could see: a printed statement, a signed letter, a teller behind a counter. Nearly all of it now arrives through the Glass. For practical purposes, your bank is the screen that says it is your bank.

The Glass is three things at once. It is the surface our senses trust most. It is the channel through which the institutions we rely on reach us. And it is the place where we decide: to pay, to treat, to buy, to sell, to open the valve.

Anything that carries this much of what people believe ought to be among the most carefully secured things ever built. Today, at the moment a screen is put together in front of a person, almost nothing protects it.

Deception Works on Shortcuts

People hold true what trusted sources tell them. The brain has automated that trust and tied it to familiar signs. It believes its eyes above all else, and almost everything it now sees arrives on the Glass.

The best-known deception on a screen is phishing: an email or a text message leads to a fake website dressed up as a real one, and the victim types a password or a card number into it. People have been taught a few checks against it, and the careful ones use them. Look at the address. Look for the padlock. Make sure the logo and the page look right. Be suspicious of the email with the odd spelling and the link that goes somewhere strange. Those checks are shortcuts too, and they all ask one question: is this really my bank, my newspaper, my employer?

Phishing fails those checks when people remember to make them, because the fake site has to live at a fake address. Attack the Glass passes them, because the answer is yes. The site is genuine. The address is correct, the padlock is showing, the logo is real, and the person signed in the way they always do. The change is made to what that genuine site shows, after every one of those checks has passed. The altered paragraph arrives under the newspaper's masthead and the reporter's byline. The false notice arrives inside the credit union's own site, after sign-in. The attacker borrows all of the trust the institution spent decades earning, and the person's own shortcuts wave the deception through.

The Glass as an Attack Surface

Security professionals talk about an attack surface: every place where an attacker can get at something. A house has doors and windows. A company has its network, its email, and its staff.

For thirty years, security has meant protecting what computers hold. Keep strangers out of the network. Keep the data from being stolen or changed. Keep the systems running. Enormous effort has gone into that work, and much of it has succeeded. Almost none has gone into the last few inches, the point where a finished screen meets a person's eyes, because it was assumed to be a plain display of what the protected systems already held.

That assumption no longer holds. The screen has become a place where things are assembled, and anything assembled can be tampered with during assembly. Every organization now reaches people through the Glass. Customers, citizens, clinicians, traders, and operators make decisions based on what those screens show them. The organization is accountable for what appears there, and believes it controls it.

The profession has a shorthand for its goals, often called the CIA triad: confidentiality, integrity, and availability. Confidentiality means secrets stay secret. Availability means systems stay up. Integrity means information is not altered by anyone who should not alter it. In practice integrity has been defended where data is stored and while it travels across networks. Attack the Glass is an attack on integrity at a place those defenses were never extended to: the point of display.

An attacker who can change what appears on the Glass has no need to break into the bank. The bank's records stay correct. The customer sees something else, acts on it, and the bank faithfully carries out the request. A network can be secure, its data can be intact, and the people making decisions on its screens can still be acting on a lie.

Automation Bias

It is tempting to believe that professionals are different, and that a trained operator watching a familiar display would catch what an ordinary person would miss. The evidence runs the other way.

In June 1995 the cruise ship Royal Majesty left Bermuda for Boston with more than 1,500 people aboard. Less than an hour out, the cable to its GPS antenna came loose. The navigation system switched, without any alarm the crew noticed, to estimating the ship's position from its speed and heading, and it went on drawing the vessel neatly on its planned track. For more than thirty hours, experienced officers stood their watches in front of a display that said everything was fine. One of them sighted a buoy in the wrong place and took it for the one he expected, because the screen agreed. Lookouts reported lights and breaking water that should not have been there. The ship ran aground off Nantucket, seventeen miles from where its screen placed it. Investigators put the grounding down to the officers' overreliance on the automated system. Years of accurate readings had taught them to stop questioning it.

Researchers call this automation bias: people who work with an automated display accept what it tells them over evidence that contradicts it, and stop looking for any. It has been reproduced under controlled conditions many times. In a flight simulation, every airline pilot tested shut down an engine because an automated warning reported a fire that no other instrument showed. Afterward, two thirds of them remembered seeing other indications of fire. There were none. The false display drove the decision, and then it wrote the memory that justified it. In hospitals, physicians reading heart tracings have been pulled toward a computer's interpretation when the computer was wrong, and specialists examining mammograms have missed cancers that the detection software failed to mark.

Automation bias fails in two directions. People act on what the display wrongly shows, and they miss what it leaves out. It appears in experts as much as in novices. Neither an instruction to double-check nor a second person in the room removes it. It grows with reliability, which means the best-run systems produce the most trusting operators. After ten thousand correct readings, nobody checks the display.

All of those displays were wrong by accident. Attack the Glass describes one that is wrong on purpose, at a chosen moment, for a chosen person. The usual advice, to check against a second source, runs into a problem of its own: on a modern screen the second source is often another panel on the same Glass, put together the same way.

Decisions Have Consequences

A false screen does its damage through what a person then does. The harm lands in the world: money sent to the wrong account, a drug given at the wrong dose, a valve opened, a vote cast on a false story, a family that stays home because the evacuation notice never appeared.

Two well-known incidents show how fast a false message on a trusted channel turns into action. On April 23, 2013, hackers took over the Twitter account of the Associated Press and posted that explosions at the White House had injured the president. The message was false and was corrected within minutes. In those minutes the Dow Jones Industrial Average fell more than 140 points and roughly 136 billion dollars of stock market value vanished, because traders and automated trading programs acted on a trusted name before anyone could check. The market recovered. The lesson stayed: one false sentence from a trusted source briefly erased more value than any bank robbery in history has taken.

On January 13, 2018, phones across Hawaii displayed an official emergency alert: a ballistic missile was inbound, seek immediate shelter, this is not a drill. It was a mistake made by a state employee during a routine exercise, and it took 38 minutes to send a correction. In that time parents lowered children into storm drains, drivers abandoned cars on the highway, and people called their families to say goodbye. Nobody who received that alert did anything foolish. They believed an official message on their own screen, and they acted on it.

Neither incident was an Attack the Glass operation. One was a stolen password and the other was human error. Both show what the target of such an operation would be: the short distance between what a trusted screen says and what people do.

How much damage depends on who is looking. A forged memo handed to a receptionist cannot move money, because nobody at the front desk has authority over the accounts. The same memo handed to the treasurer can. The forgery is identical in both cases. What differs is the authority of the person who believes it.

Screens work the same way. Someone reading a news page can only read, so an attacker who alters that page misleads a reader and goes no further. A bank customer can move their own money, so an altered payment screen can send one person's savings to the wrong place. A payments clerk can move an employer's funds. A nurse can give a drug. A plant operator can open a valve. An IT administrator can delete every account the organization has. In each case the attacker never breaks into anything. The attacker changes what an authorized person sees, or acts through the access already granted, and that individual's own authority does the rest.

The most powerful screens are also the ones fewest people use and the hardest to reach. An attacker who goes after an administrator's console takes on a smaller, better-defended target in exchange for a larger result. An attacker who goes after a news page takes on an easy target and reaches millions of readers, each of whom can only be misled. Organizations usually protect the first kind of screen far more carefully than the second, and neither kind is protected against a change that arrives from a source the organization chose to trust.

Some of the damage is physical and immediate. Some of it is social. A rumor that a bank is failing can start a run on it, and screens have made runs faster than any in history: when doubts about Silicon Valley Bank spread through social media and group chats in March 2023, customers used their phones to pull 42 billion dollars out in a single day, and the bank was closed the next morning. False stories shown to one community about another can end in violence. In India in 2017 and 2018, rumors about child kidnappers passed from phone to phone on WhatsApp, and mobs killed about thirty innocent people, many of them strangers passing through a village. And a public that has been fooled once believes less of what it is told afterward, including what is true.

The Decision Is the Target

Most cyberattacks go after what a computer holds. They steal data, lock it up for ransom, or shut a system down. Attack the Glass goes after what a person decides. It is a technical vulnerability, and its target is human: the moment when someone reads a screen, believes it, and acts. It reaches that moment through the two things people trust most, the institutions they have chosen to rely on and the evidence of their own eyes.

Security professionals have a name for attacks that work on a person instead of a machine: social engineering. The con artist on the phone who claims to be from the bank is a social engineer, and so is the author of a phishing email. Attack the Glass is social engineering carried out by technical means, with one difference that matters a great deal. There is no stranger in the conversation for the victim to be suspicious of. The message comes from the institution's own screen.