The Impact
Losing Trust in the Glass
A false screen costs someone a decision first. It costs more later. Once people learn that a trusted screen showed them something false, they start doubting screens that are telling the truth.
Researchers have measured this loss of trust. People who watch an automated aid make a single mistake stop relying on it, even when it is still more accurate than they are. In an experiment with about two thousand adults, a fabricated video was more likely to leave viewers unsure what to believe than to fool them, and the people left unsure trusted news less afterward. Once fakes are known to exist, anyone caught by a true record can call it fake. Legal scholars have named this the liar's dividend: the more the public hears about convincing forgeries, the easier it becomes for a dishonest person to wave away genuine evidence.
A bank whose customers question their balances, a hospital whose staff second-guess the chart, a newsroom whose readers wonder whether the article they read is the one that was published: none of them needs a second attack. One well-publicized false screen is enough. People build trust in a screen slowly and drop it quickly, and the institutions that reach us through the Glass have no other way to reach most of us.
What Fails, and for Whom
A hospital, a trading floor, a newsroom, and a power substation all assemble their screens the same way. They differ in what sits behind the screen and who acts on what it shows.
News and media. A publisher's name is its most valuable asset, and an attacker reaches it directly. Readers can be shown an altered version of a story under the publisher's name and the reporter's byline, while the editors and fact-checkers see the correct one. The alteration can be as small as one number in a report on a company's earnings, one name in a story about a crime, or one quotation put into a politician's mouth. The false Associated Press message of 2013 moved the stock market in minutes, and that was a single sentence on one social media account. The publisher cannot retrieve what any individual reader was shown, because no copy exists anywhere the publisher controls, and so it cannot issue a correction to the people who need one.
Banking and payments. Criminals have used this method for a decade to steal card numbers from checkout pages. In the Ticketmaster case the attacker never touched the company itself. The break-in was at another firm whose chat window sat on the payment page, and a United Kingdom regulator recorded it in a penalty notice. The same method that copies a card number can change the account a payment is sent to, or the balance a customer sees. Fraud that works by changing the bank details on an invoice already costs businesses billions of dollars a year when it is done by email, where the victim at least has a suspicious message to look back at. Inside a bank, a trader or treasury officer who acts on a false summary of the firm's holdings is an authorized person taking an authorized action on information they had every reason to trust.
Healthcare. Medication charts, test results, appointment systems, and the displays on medical devices are all screens assembled in software, and patients now read their own on portals and phone apps. A nurse reading a value usually has nowhere else to check it. A decimal point moved one place in a dose, a blood type changed, an allergy warning that fails to appear: each is a small change on a screen and a large one for a patient. Often nobody reads the value at all. An automatic alert watches the number instead, and if the reading looks normal, it stays silent.
Power, water, and industry. Elsewhere an attacker changes what a person believes. Here an attacker can change what a machine does. An operator's control screen commands pumps, breakers, valves, and alarms, so interfering with what it does matters more than changing what it says. Timing matters too. A delay that would merely irritate someone shopping online can make a control command arrive too late to work. In December 2015, operators at three regional electricity distribution companies in Ukraine watched the pointers on their control screens move by themselves as remote attackers opened circuit breakers one after another, cutting power to about 225,000 customers in midwinter. That attack took over the operators' computers, which is a different method. It is a reminder that a control screen moves real equipment. Well-run plants restrict what reaches those screens, and many keep their control networks cut off from the internet altogether. That helps a great deal. It shortens the supply chain without ending it, because the software on an isolated network was still built from outside parts, by other companies, and is still updated from time to time.
Government and public services. Benefits, taxes, public health guidance, election information, and emergency alerts all reach citizens through the Glass. The Hawaii missile alert showed what one false official message does to a population in 38 minutes. Election results are an obvious target. During Ukraine's presidential vote in May 2014, attackers broke into the election commission's systems and prepared a fake results page showing a fringe candidate winning. Officials found and removed it less than an hour before it was due to appear, and a Russian state television channel reported the fake result that evening anyway. The officials who run public services also make their own decisions from screens assembled the same way, so the exposure runs in both directions.
Inside every organization. The people who administer an organization's technology work from screens too: the consoles that manage user accounts, databases, cloud storage, and the building of the organization's own software. Those consoles are assembled on the device from outside resources like any other modern screen. An altered shopping page can mislead a customer. An altered administrator's console can delete the accounts, the data, and the backups.
What Is Known
We separate what we can prove from what we reason, what we presume, and what nobody can measure.
The way screens are assembled is established, and anyone can confirm it. Incidents that used it are part of the public record, including the polyfill.io and Ticketmaster cases. The research on how people respond to what they see, and how far they trust an automated display, is established in its own fields.
None of the parts is new, and we do not claim to have discovered an unprecedented trick. Security teams already worry about the risk from outside scripts. Web skimming has stolen from checkout pages for a decade. Cloaking is a documented practice. Polyfill.io happened in public. What has been missing is one account of the weakness underneath all of them: modern screens are assembled at the last moment from resources trusted by their address and never checked for their content, the change can be made after every security check has passed, and nothing records it. We also follow that weakness beyond the web browser, where almost all of the existing attention has gone, to the apps, vehicles, appliances, medical devices, and control rooms that are built the same way.
This also explains why Attack the Glass has no entry in the public catalog of software vulnerabilities, known as CVE. That catalog lists specific flaws in specific products, each of which a vendor can fix. Attack the Glass is a property of how thousands of products are assembled. There is no single product to list and no single fix to ship.
We evaluated 50 kinds of device and platform that build screens this way, in 10 categories from web browsers and phones to vehicles, medical devices, and industrial control systems. All 50 are exposed, and we rated 46 of them Critical or High. Protection runs opposite to consequence. The web browser, which has the most safeguards, is where people read the news. The operator's station, the medical display, and the command screen, where the gravest decisions are made, have almost none of the browser's safeguards.
The Risks It Implies
Some conclusions are reasoned from how these systems are built, since no public case yet documents them in every field. The damage an attack can do grows with what sits behind the screen and with the authority of the person reading it. A false screen, once publicized, weakens trust in true ones, which follows from research on automated aids and fabricated video. That generative AI can produce tailored content for any number of individual readers is established, and anyone can test it. That it multiplies the reach of an Attack the Glass operation is reasoned from how the two fit together.
One conclusion we presume. Capable actors already hold the positions an operation would need. Our threat-intelligence work places them there, but those findings sit in restricted channels a reader cannot check, which is why we mark the conclusion as presumed and rest no other claim on it.
What Nobody Can See
Nobody can establish how much this is being used today, because the instruments that would measure it do not exist. We cannot tell you an operation is running against you, and no tool in standard use can tell you one is not. Absence of evidence is not evidence of absence, and here the absence is a property of the attack rather than a sign of safety. That is the finding, and it is why awareness is the defense available now.
What We Need to Do Now
Awareness comes first. A person who knows that a trusted screen can be altered treats a surprising one differently: they stop, and they check.
For anything consequential and hard to reverse, a payment, a change of bank details, a password reset, a command to a physical system, verify through a second channel before acting on a screen alone. The second channel has to be one the screen did not supply: a phone number you already had, or a person you can ask directly. A telephone number shown on the same screen is part of what could have been altered. Banks and companies that handle large payments have long used a version of this rule, calling back on a known number before changing where money is sent, and the rule protects against this attack just as it does against a forged email.
When a screen surprises you, with an unexpected demand, a missing option, a number that seems wrong, treat the surprise as information. Look at the same thing on another device or network if you can, or ask someone else what they see. If the two differ, keep a record of both. It may be the only evidence that ever exists.
Organizations can do a good deal more, and none of it waits on new technology. They can write down the list that does not exist, every outside company whose resources load on their screens, including the suppliers of their suppliers. They can remove the ones they do not need, keep their own copies of the ones they do instead of fetching them from someone else's address, and switch on the protections that are already available, Content Security Policy and Subresource Integrity among them, and then confirm that those are truly in force. They can ask the same questions of the vendors whose consoles their own staff sign in to every day. The Remediation Playbook sets it out in three horizons, beginning with what an engineering team can change in the first ninety days.
The Work Still to Be Done
Awareness and good housekeeping reduce the risk. They do not remove it, because the weakness is built into how screens are assembled on nearly every platform, and no single company can fix that alone. We do not have a solution for Attack the Glass, and we are not selling one.
Several things do not exist yet and need to. Devices need a way to confirm, while a screen is running, that what they assembled is what the publisher intended, which requires a trusted record of that intention to compare against. Engineers call the general idea runtime monitoring: watching how a screen behaves as it is drawn, where today's checks inspect resources only before they arrive. It would also take measurement across many users at once, because comparing what one person was served with what everyone else received is the only way a change aimed at a few can be noticed at all. Deception written by AI for a single reader defeats even that comparison, so detection will also have to work without a second copy to compare against, by recognizing that a screen is behaving in a way its publisher never intended. None of this ships as a standard part of any browser, phone, or device today. That is an engineering problem, and those get solved when someone pays for the work.
Someone needs to be able to establish afterward what a screen showed a given person at a given time. The ownership of the companies and addresses that deliver resources to billions of screens needs to be visible, and changes of control need to be disclosed, as they are in other industries the public depends on. And people need better preparation for a world in which a trusted screen can be wrong on purpose, which is work for educators, psychologists, and institutions as much as for engineers.
The standards that organizations are audited against, and the questions buyers ask their suppliers before signing a contract, need to reach this layer too. At present none of them asks what a product loads onto the customer's screen while it runs, or who controls it.
None of that is the work of one company or one country. The builders of browsers, phones, and other platforms, the industries that depend on them, researchers, and governments each hold a piece. It starts with enough people understanding the problem to insist that it be solved.
The engineering behind everything said here is in the Technical Primer and the Technical Whitepaper.