Last weekend, while the sun was shining brightly, nature was flourishing in all its colours, flavours and scents and hundreds of birds were chirping their favourite tunes, I decided to go for a stroll with my dog. A nice two-hour walk in the vineyards around CERN, hiking up the Jura, enjoying the view and returning home full of energy. So nice and neat. Or not…
Under the supervision (or not) of my eldest daughter, I left my young son at home (as both were, as usual, not interested in a walk, and I was not interested in an argument about that). My daughter upstairs chatting with friends; my son downstairs in the living room where he is usually occupied with his building bricks.
But not this time. He found my smartphone and my computer. Both unlocked [1] (as they were sitting in my office). Both idly awaiting my return.
And my son figured out how to use them. With his rudimentary knowledge of using a keyboard, carelessly hitting random keys, clumsily moving the mouse pointer, frantically clicking the mouse button and swiping wildly across the screen, he wreaked havoc: not knowing what he was doing, he opened some files at random, changed some contents, deleted others. Hitting Ctrl-X worked its magic. He started some programs and I am still busy figuring out which documents were touched and, please God − no!, changed. At least I managed to trace the numerous emails full of gibberish he sent to some friends and colleagues (and I’ve apologised to them already). Fortunately, I was not connected to CERN (eduVPN, anyone?) at that time as I usually tend to be when working on the control system of my beamline. Just imagine what some unchecked manipulations by my son could have led to – destruction [2]? Or new physics results?!
If you have curious and creative kids, or if you have been a reckless, hyperactive kid yourself, you can understand my panic. Just imagine what my son, in his young naïve way, not yet fully grown into his own (or my parentally handed-down) values, still lacking a comprehensive understanding of technology and its consequences, without any constraints or ethics apart from his childish drive to try, test and play, without a full and conscious grasp of his actions and their consequences, just imagine what damage my son could have done to my data, files and work…
Only someone with full self-awareness, with a conscience, values and an understanding of the “right and correct” context should touch my IT stuff. An adult like me. ME! But maybe not a kid like my son (when not closely supervised). Actually, his name is Albert Ignatius, or “Al” for short.
P.S. This article is fictious. I don’t have a dog and two small kids, nor “Al” and, in any case, would never leave them unattended. Nor would I ever leave my computer or smartphone unlocked when not sitting in front of them. Nor would I have any other (agentic) AI performing random tasks without tight control over what it was doing. Check out our Bulletin article on “Agentic loss of control” and the pitfalls of using agentic AI tools. And, for the more technical among us, here are some good “Security Principles when using AI tools”.
[1] Yes, my bad! Smartphones and computers should ALWAYS be locked with a password or biometry if you are not sitting in front of them. Precisely to avoid any kind (of such) abuse… Sigh. I knew it.
[2] I hope none, as every control system should be fenced, guarded and protected by an encompassing safety system.
_________
Do you want to learn more about computer security incidents and issues at CERN? Follow our Monthly Report. For further information, questions or help, check our websiteor contact us at Computer.Security@cern.ch.