Showing posts with label Computer Virus. Show all posts
Showing posts with label Computer Virus. Show all posts

Sunday, August 11, 2013

Beware The ‘Sons Of Stuxnet’

Map of countries affected by the Red October malware. (Screenshot Courtesy Kaspersky Lab)

The Virus That Compromised Iran’s Nuclear Infrastructure Is A Model Of Things To Come, and Israel Is Not Immune

By DAVID SHAMAH

Stuxnet was, according to many security analysts, a major success. The virus that targeted Iranian infrastructure servers significantly delayed the progress of that country’s nuclear program, most experts agree.


That is the kind of success that inspires copycats and leads hackers to develop “offspring” building on the sophistication and reach of the original, said Sergey Novikov, deputy director, global research & analysis team at Kaspersky Lab.


Novikov was in Israel recently to introduce Kaspersky’s new security product, Endpoint Security for Business. As part of the introduction, he gave a general presentation on the computer security situation in general as well as in Israel.

With all the publicity surrounding Stuxnet and Flame (which Kaspersky Lab head Eugene Kaspersky last year called “the beginning of the end of the world as we know it“), one would expect that awareness of the security risks in unprotected surfing would be high and that companies would be taking every possible precaution.

But there is still a long way to go. During the first five months of 2013, a new virus, Trojan or other piece of malware was being discovered at a rate twice as fast as the same period in 2012. This year it’s about one every half-second, which is equivalent to an astounding 200,000 per day.

Nevertheless, some three-quarters of the IT decision makers and managers in large enterprise companies are convinced either that they are ready for the onslaught — even though, a Kaspersky Lab poll showed, most had no idea of the extent and power of today’s malware — or that “it won’t happen to us.”

Another one-quarter of top computer system managers in these companies were aware of the dangers, but said that they could not justify to their bosses the cost of the major security overhaul that was necessary. Meanwhile, that same poll showed that 91% of the IT managers themselves had, in the past year, been the victim of a serious attack.

If those managers are heading up security at the electric, gas, water, or other infrastructure company, said Novikov, “then we all have a lot to worry about,” because those systems are becoming popular targets for hackers. But the newest trend in hacking is in state- or organization-sponsored hacking.

Much like Stuxnet, which, according to most analysts, was put together by a highly professional team of state-sponsored hackers — both Israel and the US are suspected — the more recent Red October attack was also said to have been launched by a state or state-sponsored group. The attack, which targeted computers in diplomatic missions and embassies, science labs, and government offices around the world — was found to contain malware that had been transmitting information to unknown parties (China is considered a prime suspect).

To get to those sites, hackers presumably had to work around numerous layers of protection. And it’s just a matter of time, said Novikov, before these groups begin targeting infrastructure in enemy countries, either to extort concessions from their victims, or as an act of terror or war.

“At this point, we should expect such infrastructure attacks anytime and anywhere,” Novikov told The Times of Israel. “It’s just a matter of time before someone pulls one off, and it will have a huge impact.”

Israel is in no way immune to such attacks, warned the Kaspersky deputy director. “Israel is in better security shape than many countries in places like Eastern Europe and the former Soviet Union countries, but many EU countries are more cyber-secure than Israel.”

Then there are the threats from the cloud — “Why spend time attacking individual computers for information when you can attack a database in the cloud and get a lot of information for the same effort?” Novikov asked rhetorically — as well as the threats from unsecured mobile devices (the vast majority do not even have basic anti-virus protection, he added).

And there are the enhanced “social engineering” techniques users face today, which tries to convince users users to click on links that secretly install malware that will enslave their machines or devices to one of the fast-growing “botnets” that cause all sorts of online trouble. 

“We are going to be seeing many ‘sons of Stuxnet,’ much more sophisticated malware in terms of its reach and capabilities,” Novikov added. “We, indeed, do live in interesting times.”

Saturday, July 13, 2013

Obama Orders List For Overseas Cyber-Attacks



By Glenn Greenwald and Ewen MacAskill

Barack Obama has ordered his senior national security and intelligence officials to draw up a list of potential overseas targets for US cyber-attacks, a top secret presidential directive obtained by the Guardian reveals.
The 18-page Presidential Policy Directive 20, issued in October last year but never published, states that what it calls Offensive Cyber Effects Operations (OCEO) "can offer unique and unconventional capabilities to advance US national objectives around the world with little or no warning to the adversary or target and with potential effects ranging from subtle to severely damaging".
It says the government will "identify potential targets of national importance where OCEO can offer a favorable balance of effectiveness and risk as compared with other instruments of national power".
The directive also contemplates the possible use of cyber actions inside the US, though it specifies that no such domestic operations can be conducted without the prior order of the president, except in cases of emergency. 
The aim of the document was "to put in place tools and a framework to enable government to make decisions" on cyber actions, a senior administration official told the Guardian.
The administration published some declassified talking points from the directive in January 2013, but those did not mention the stepping up of America's offensive capability and the drawing up of a target list.
Obama's move to establish a potentially aggressive cyber warfare doctrine will heighten fears over the increasing militarization of the internet.
The directive's publication comes as the president plans to confront his Chinese counterpart Xi Jinping at a summit in California on Friday over alleged Chinese attacks on western targets.
Even before the publication of the directive, Beijing had hit back against US criticism, with a senior official claiming to have "mountains of data" on American cyber-attacks he claimed were every bit as serious as thoseChina was accused of having carried out against the US.
Presidential Policy Directive 20 defines OCEO as "operations and related programs or activities … conducted by or on behalf of the United States Government, in or through cyberspace, that are intended to enable or produce cyber effects outside United States government networks."
Asked about the stepping up of US offensive capabilities outlined in the directive, a senior administration official said: "Once humans develop the capacity to build boats, we build navies. Once you build airplanes, we build air forces."
The official added: "As a citizen, you expect your government to plan for scenarios. We're very interested in having a discussion with our international partners about what the appropriate boundaries are."
The document includes caveats and precautions stating that all US cyber operations should conform to US and international law, and that any operations "reasonably likely to result in significant consequences require specific presidential approval".
The document says that agencies should consider the consequences of any cyber-action. They include the impact on intelligence-gathering; the risk of retaliation; the impact on the stability and security of the internet itself; the balance of political risks versus gains; and the establishment of unwelcome norms of international behaviour.
Among the possible "significant consequences" are loss of life; responsive actions against the US; damage to property; serious adverse foreign policy or economic impacts.
The US is understood to have already participated in at least one major cyber attack, the use of the Stuxnet computer worm targeted on Iranian uranium enrichment centrifuges, the legality of which has been the subject of controversy. US reports citing high-level sources within the intelligence services said the US and Israel were responsible for the worm.
In the presidential directive, the criteria for offensive cyber operations in the directive is not limited to retaliatory action but vaguely framed as advancing "US national objectives around the world".
The revelation that the US is preparing a specific target list for offensive cyber-action is likely to reignite previously raised concerns of security researchers and academics, several of whom have warned that large-scale cyber operations could easily escalate into full-scale military conflict.
Sean Lawson, assistant professor in the department of communication at the University of Utah, argues: "When militarist cyber rhetoric results in use of offensive cyber attack it is likely that those attacks will escalate into physical, kinetic uses of force."
An intelligence source with extensive knowledge of the National Security Agency's systems told the Guardian the US complaints again China were hypocritical, because America had participated in offensive cyber operations and widespread hacking – breaking into foreign computer systems to mine information.
Provided anonymity to speak critically about classified practices, the source said: "We hack everyone everywhere. We like to make a distinction between us and the others. But we are in almost every country in the world."
The US likes to haul China before the international court of public opinion for "doing what we do every day", the source added.
One of the unclassified points released by the administration in January stated: "It is our policy that we shall undertake the least action necessary to mitigate threats and that we will prioritize network defense and law enforcement as preferred courses of action."
The full classified directive repeatedly emphasizes that all cyber-operations must be conducted in accordance with US law and only as a complement to diplomatic and military options. But it also makes clear how both offensive and defensive cyber operations are central to US strategy.
Under the heading "Policy Reviews and Preparation", a section marked "TS/NF" - top secret/no foreign - states: "The secretary of defense, the DNI [Director of National Intelligence], and the director of the CIA … shall prepare for approval by the president through the National Security Advisor a plan that identifies potential systems, processes and infrastructure against which the United States should establish and maintain OCEO capabilities…" The deadline for the plan is six months after the approval of the directive.
The directive provides that any cyber-operations "intended or likely to produce cyber effects within the United States" require the approval of the president, except in the case of an "emergency cyber action". When such an emergency arises, several departments, including the department of defense, are authorized to conduct such domestic operations without presidential approval.
Obama further authorized the use of offensive cyber attacks in foreign nations without their government's consent whenever "US national interests and equities" require such nonconsensual attacks. It expressly reserves the right to use cyber tactics as part of what it calls "anticipatory action taken against imminent threats".
The directive makes multiple references to the use of offensive cyber attacks by the US military. It states several times that cyber operations are to be used only in conjunction with other national tools and within the confines of law.
When the directive was first reported, lawyers with the Electronic PrivacyInformation Center filed a Freedom of Information Act request for it to be made public. The NSA, in a statement, refused to disclose the directive on the ground that it was classified.
In January, the Pentagon announced a major expansion of its Cyber Command Unit, under the command of General Keith Alexander, who is also the director of the NSA. That unit is responsible for executing both offensive and defensive cyber operations.
Earlier this year, the Pentagon publicly accused China for the first time of being behind attacks on the US. The Washington Post reported last month that Chinese hackers had gained access to the Pentagon's most advanced military programs.
The director of national intelligence, James Clapper, identified cyber threats in general as the top national security threat.
Obama officials have repeatedly cited the threat of cyber-attacks to advocate new legislation that would vest the US government with greater powers to monitor and control the internet as a means of guarding against such threats.
One such bill currently pending in Congress, the Cyber Intelligence Sharing and Protection Act (Cispa), has prompted serious concerns from privacy groups, who say that it would further erode online privacy while doing little to enhance cyber security.
In a statement, Caitlin Hayden, national security council spokeswoman, said: "We have not seen the document the Guardian has obtained, as they did not share it with us. However, as we have already publicly acknowledged, last year the president signed a classified presidential directive relating to cyber operations, updating a similar directive dating back to 2004. This step is part of the administration's focus on cybersecurity as a top priority. The cyber threat has evolved, and we have new experiences to take into account.
"This directive establishes principles and processes for the use of cyber operations so that cyber tools are integrated with the full array of national security tools we have at our disposal. It provides a whole-of-government approach consistent with the values that we promote domestically and internationally as we have previously articulated in the International Strategy for Cyberspace.
"This directive will establish principles and processes that can enable more effective planning, development, and use of our capabilities. It enables us to be flexible, while also exercising restraint in dealing with the threats we face. It continues to be our policy that we shall undertake the least action necessary to mitigate threats and that we will prioritize network defense and law enforcement as the preferred courses of action. The procedures outlined in this directive are consistent with the US Constitution, including the president's role as commander in chief, and other applicable law and policies."

Friday, March 22, 2013

Computer Fights Hacker Attack



"Born To Be Viral" is our new weekly slot for incredible videos that we think deserve to go wild across the web


Ever wondered what it looks like when a hacker attacks a computer and tries to break into someone's account?
Now Ben Reardon of Dataviz Australia has created a stunning visualisation that shows a single attack on a voice-over-IP (VOIP) server, similar to those used for Skype. Hacked VOIP servers are often used for black-market communications and cheap calling-card scams.
In the video above, the server is shown on the left, where the accounts of the people signed up to make calls are represented by blue bubbles. A hacker's attack comes from the right, launching small white and red bubbles that represent scans from a malicious computer program. The battle that plays out is slowed down by 25 per cent.
If the hacker's scans connect with the blue bubbles, they may be able to compromise the server, gathering the passwords of account holders and ultimately letting the hacker control other people's phone activity.
To protect itself against the attack, the server releases green honeypots: disguised data released to trap the intruding scans. But the hacker then increases the number of scans in an attempt to overwhelm the honeypots. In the end, the server wins the battle.
According to Reardon, countless attacks like this one occur every second. "The volume of data from this one attack is really a drop in the ocean in terms of the wider internet," he says.
Source: New Scientist

Sunday, February 03, 2013

The Year 2038 Problem



The year 2038 problem may cause some computer software to fail at some point near the year 2038. The problem affects all software and systems that both store system time as a signed 32-bit integer, and interpret this number as the number of seconds since 00:00:00 UTC on Thursday, 1 January 1970. The furthest time that can be represented this way is 03:14:07 UTC on Tuesday, 19 January 2038. Times beyond this moment will "wrap around" and be stored internally as a negative number, which these systems will interpret as a date in 1901 rather than 2038. This is caused by integer overflow. The counter "runs out" of usable digits, "increments" the sign bit instead, and reports a maximally negative number (continuing to count up, toward zero). This is likely to cause problems for users of these systems due to erroneous calculations.

Further, while most programs will only be affected in or very close to 2038, programs that work with future dates will begin to run into problems much sooner. For example, a program that works with dates 20 years in the future will have to be fixed no later than 2018.

Because most 32-bit Unix-like systems store and manipulate time in this format, it is usually called Unix time, and so the year 2038 problem is often referred to as the Unix Millennium Bug, or s2G.

In May 2006, reports surfaced of an early manifestation of the Y2038 problem in the AOLserver software. The software was designed with a kludge to handle a database request that should "never" time out. Rather than specifically handling this special case, the initial design simply specified an arbitrary time-out date in the future. The default configuration for the server specified that the request should time out after one billion seconds. One billion seconds (approximately thirty-two years) after 9:27.28 pm on 12 May 2006 is beyond the 2038 cutoff date. Thus, after this time, the time-out calculation overflowed and returned a date that was actually in the past, causing the software to crash. When the problem was discovered, AOL server managers had to edit the configuration file and set the time-out to a lower value.

Vulnerable Systems:
Embedded systems that use dates for either computation or diagnostic logging are most likely to be affected by the 2038 bug. Telecommunication systems and transportation systems from flight to automobiles increasingly use embedded systems. Automobiles, electric vehicles, and hybrid vehicles are increasingly using embedded systems to maximize efficiency and reduce pollution. Other automotive safety systems include anti-lock braking system (ABS), electronic stability control (ESC/ESP), traction control (TCS) and automatic four-wheel drive. New aircraft contain advanced avionics such as inertial guidance systems and GPS receivers that also have considerable safety requirements. Another major use of embedded systems is in communications devices, including cell phones and Internet appliances (routers, wireless access points, etc.) which rely on storing an accurate time and date and are increasingly based on UNIX-like operating systems. For example, the bug makes some Android devices crash and not restart when the time is changed to that date.

As of 2012, most embedded systems use 8-bit or 16-bit microprocessors, even as desktop systems are transitioning to 64-bit systems. Despite the modern 18–24-month generational update in computer systems technology, embedded systems are designed to last the lifetime of the machine in which they are a component. It is conceivable that some of these systems may still be in use in 2038. It may be impractical or, in some cases, impossible to upgrade the software running these systems, ultimately requiring replacement if 32-bit time_t limitations are to be corrected.

The use of 32-bit time_t has also been encoded into some file formats,[citation needed] which means it can live on well beyond the life of the machines on which such file formats were originally supported.

MySQL database's inbuilt functions like UNIX_TIMESTAMP() will return 0 after 03:14:07 UTC on 19 January 2038. The limit reached will vary in time, based on the time zones as in the following table:
Auckland19 January 2038, 16:14:07 NZDT (UTC+13:00)
Sydney19 January 2038, 14:14:07 AEDT (UTC+11:00)
Tokyo19 January 2038, 12:14:07 JST (UTC+09:00)
Beijing19 January 2038, 11:14:07 CST (UTC+08:00)
Mumbai19 January 2038, 08:44:07 IST (UTC+05:30)
Dubai19 January 2038, 07:14:07 GST (UTC+04:00)
Nairobi19 January 2038, 06:14:07 EAT (UTC+03:00)
Cairo19 January 2038, 05:14:07 EET (UTC+02:00)
Paris19 January 2038, 04:14:07 CET (UTC+01:00)
London19 January 2038, 03:14:07 GMT (UTC±00:00)
Brasília19 January 2038, 01:14:07 BRST (UTC−02:00)
Atlantic Time18 January 2038, 23:14:07 AST (UTC−04:00)
Eastern Time18 January 2038, 22:14:07 EST (UTC−05:00)
Central Time18 January 2038, 21:14:07 CST (UTC−06:00)
Mountain Time18 January 2038, 20:14:07 MST (UTC−07:00)
Pacific Time18 January 2038, 19:14:07 PST (UTC−08:00)
HawaiÊ»i18 January 2038, 17:14:07 HST (UTC−10:00)
Data Structures With Time Problems:


Many data structures in use today have 32-bit time representations embedded into their structure. A full list of these data structures is virtually impossible to derive but there are well-known data structures that have the Unix time problem.

  • file systems (many filesystems use only 32 bits to represent times in inode)
  • binary file formats (that use 32-bit time fields)
  • databases (that have 32-bit time fields)
  • COBOL systems from the 1970s, 1980s and 1990s that have not been replaced by 2038-compliant systems
  • embedded factory, refinery control and monitoring subsystems
  • assorted medical devices
  • assorted military devices
Each one of these places where data structures using 32-bit time are in place has its own risks related to failure of the product to perform as designed.

Solutions:
There is no universal solution for the Year 2038 problem. Any change to the definition of the time_t data type would result in code compatibility problems in any application in which date and time representations are dependent on the nature of the signed 32-bit time_t integer. For example, changing time_t to an unsigned 32-bit integer, which would extend the range to the year 2106, would adversely affect programs that store, retrieve, or manipulate dates prior to 1970, as such dates are represented by negative numbers.

Most operating systems designed to run on 64-bit hardware already use signed 64-bit time_t integers, effectively eliminating the Year 2038 problem in any software that has been developed to use the extended format. Using a signed 64-bit value introduces a new wraparound date that is over twenty times greater than the estimated age of the universe: approximately 292 billion years from now, at 15:30:08 on Sunday, 4 December 292,277,026,596. The ability to make computations on dates is limited by the fact that tm_year uses a signed 32 bit int value starting at 1900 for the year. This limits the year to a maximum of 2,147,485,547 (2,147,483,647 + 1900).[7] While this solves the problem for executing programs, it does not, however, solve the problem of storing date values within binary data files, many of which employ rigid storage formats.

Starting with NetBSD version 6.0 (released in October 2012), the NetBSD operating system uses a 64-bit time_t for both 32-bit and 64-bit architectures. Applications that were compiled for an older NetBSD release with 32-bit time_t are supported via a binary compatibility layer, but such older applications will still suffer from the Year 2038 problem.

Alternative proposals have been made (some of which are in use), such as storing either milliseconds or microseconds since an epoch (typically either 1 January 1970 or 1 January 2000) in a signed 64-bit integer, providing a minimum of 300,000 years range.[8][9] Other proposals for new time representations provide different precisions, ranges, and sizes (almost always wider than 32 bits), as well as solving other related problems, such as the handling of leap seconds. In particular, TAI64[10] is an implementation of the Temps Atomique International standard, the current international real-time standard for defining a second and frame of reference.

Wednesday, December 26, 2012

NSA Targets Domestic Computer System / Infrastructure



Revealed: National Security Agency's Perfect Citizen Program Hunts For Vulnerabilities In "Large-Scale" Utilities, Including Power Grid and Gas Pipeline Controllers, Newly Released Documents Show.

By Declan McCullagh
Source: C|net
Courtesy Of "Signs Of The Times"

Newly released files show a secret National Security Agency program is targeting the computerized systems that control utilities to discover security vulnerabilities, which can be used to defend the United States or disrupt the infrastructure of other nations. 

The NSA's so-called Perfect Citizen program conducts "vulnerability exploration and research" against the computerized controllers that control "large-scale" utilities including power grids and natural gas pipelines, the documents show. The program is scheduled to continue through at least September 2014. 

The Perfect Citizen files obtained by the Electronic Privacy Information Center and provided to CNET shed more light on how the agency aims to defend -- and attack -- embedded controllers. The NSA is reported to have developed Stuxnet, which President Obama secretly ordered to be used against Iran's nuclear program, with the help of Israel. 

U.S. officials have warned for years, privately and publicly, about the vulnerability of the electrical grid to cyberattacks. Gen. Martin Dempsey, the chairman of the Joint Chiefs of Staff, told a congressional committee in February: "I know what we [the U.S.] can do and therefore I am extraordinarily concerned about the cyber capabilities of other nations." If a nation gave such software to a fringe group, Dempsey said, "the next thing you know could be into our electrical grid." 

Discussions about offensive weapons in the U.S. government's electronic arsenal have gradually become more public. One NSAemployment posting for a Control System Network Vulnerability Analyst says the job involves "building proof-of concept exploits," and an Air Force announcement in August called for papers discussing "Cyberspace Warfare Attack" capabilities. The Washington Post reported last month that Obama secretly signed a directive in October outlining the rules for offensive "cyber-operations." 

"Sabotage or disruption of these industries can have wide-ranging negative effects including loss of life, economic damage, property destruction, or environmental pollution," the NSA concluded in a public report (PDF) discussing industrial control systems and their vulnerabilities. 

The 190 pages of the NSA's Perfect Citizen files, which EPIC obtained through the Freedom of Information Act last week, are heavily redacted. At least 98 pages were completely deleted for a number of reasons, including that portions are "classified top secret," and could "cause exceptionally grave damage to the national security" if released, according to an accompanying letter from Pamela Phillips, chief of the NSA's FOIA office. 

But the portions that were released show that Raytheon received a contract worth up to $91 million to establish Perfect Citizen, which "enables the government to protect the systems," especially "large-scale distributed utilities," operated by the private sector. 

The focus is "sensitive control systems," or SCS, which "provide automation of infrastructure processes." Raytheon is allowed to hire up to 28 hardware and software engineers who are supposed to "investigate and document the results of vulnerability exploration and research against specific SCS and devices." 

One job description, for a senior penetration tester, says the position will "identify and demonstrate vulnerabilities," and requires experience using security-related utilities such as Nmap, Tenable's NessusLibnet, and Netcat. Raytheon is required not to disclose that this work is being done for the NSA. 

The Wall Street Journal disclosed the existence of Perfect Citizen in a 2010 article, which reported the NSA's "surveillance" of such systems relies "on a set of sensors deployed in computer networks for critical infrastructure that would be triggered by unusual activity suggesting an impending cyber attack." 

An NSA spokeswoman responded to CNET at the time by saying that Perfect Citizen is "purely a vulnerabilities assessment and capabilities development contract" that "does not involve the monitoring of communications or the placement of sensors on utility company systems." 

Marc Rotenberg, EPIC's executive director, said that the newly declassified documents "may help disprove" the NSA's argument that Perfect Citizen doesn't involve monitoring private networks. 

The FOIA'd documents say that because the U.S. government relies on commercial utilities for electricity, telecommunications, and other infrastructure requirements, "understanding the technologies utilized in the infrastructure nodes to interoperate on the commercial backbone enables the government to protect the systems." 

Neither the NSA nor Raytheon immediately responded to requests to comment from CNET this morning. We'll update this story if we receive a response.

Wednesday, December 19, 2012

The Cyber Threat To American Rights and Liberties



By Karen J. Greenberg,


Cyber is “a new terrain for warfare,” Panetta tells us, a “battlefield of the future.” So perhaps it’s time to ask two questions: In a world of cyber fear, what has the war on terror taught us about protecting ourselves from the excesses of government? What do policymakers, citizens, and civil libertarians need to think about when it comes to rights that would potentially be threatened in the wake of, or even in anticipation of, a cyber attack?
Here, then, are several potential threats to constitutional liberties, democratic decision-making processes, and the rule of law to watch out for in this new cyber war era:
The Threat to Privacy: In the war on terror, the government — thanks to the Patriot Act and the warrantless surveillance program, among other efforts — expanded its ability to collect information on individuals suspected of terrorism. It became a net that could snag all sorts of Americans in all sorts of ways. In cyber space, of course, the potential for collecting, sharing, and archiving data on individuals, often without a warrant, increases exponentially, especially when potential attacks may target information itself.
A recent FBI investigation illustrates the point. The Coreflood Botnet utilized viruses to steal personal and financial information from millions of Internet users, including hospitals, banks, universities, and police stations. The focus of the Coreflood threat — which also means its interface with the government — was private information. The FBI got warrants to seize the command-and-control servers that acted as an intermediary for the stolen information. At that point, the government was potentially in possession of vast amounts of private information on individual American citizens. The FBI then offered assurances that it would not access or make use of any of the personal information held on those servers.
But in an age that has become increasingly tolerant of — or perhaps resigned to — the government’s pursuit of information in violation of privacy rights, the prospects for future cyber-security policy are worrisome. After all, much of the information that might be at risk in so many potential cyber attacks — let’s say on banks — would fall into the private sphere. Yet the government, citing national security, could persuade companies to turn over that that data, store it, and use it in various ways, all the while claiming that its acts are “preventive” in nature and so not open to debate or challenge. And as in so many post-9/11 cases, the courts might back such claims up.
Once the information has been shared within the government, who’s to say how long it will be held and how it will be used in the future? Or what agency guidelines exist, if any, to ensure that it won’t be warehoused for future uses of quite a different sort? As former Department of Homeland Security head Michael Chertoff put it, “You need to have a certain amount of accountability so government doesn’t run roughshod [over people’s right to privacy] and that’s been a hard thing to architect.”
Enemy Creep: If you think it’s been difficult to reliably distinguish enemies from the rest of us in the war on terror (as in the 600 Guantanamo detainees that the Bush administration finally declared “no longer enemy combatants” and sent home), try figuring it out in cyber space. Sorting out just who launched an attack and in whose name can be excruciatingly difficult. Even if, for example, you locate the server that introduced the virus, how do you determine on whose behalf such an attack was launched? Was it a state or non-state actor? Was it a proxy or an original attack?
The crisis of how to determine the enemy in virtual space opens up a host of disturbing possibilities, not just for mistakes, but for convenient blaming. After all, George W. Bush’s top officials went to war in Iraq labeling Saddam Hussein an ally of al-Qaeda, even when they knew it wasn’t true. Who is to say that a president won’t use the very difficulty of naming an online enemy as an excuse to blame a more convenient target?
War or Crime?: And what if that enemy is domestic rather than international? Will its followers be deemed “enemy combatants” or “lawbreakers”? If this doesn’t already sound chillingly familiar to you, it should. It was an early theme of the war on terror where, beginning with its very name, “war” won out over crime.
Cyber attacks will raise similar questions, but the stakes will be even higher. Is a hacker attempting to steal money working on his own or for a terrorist group, or is he essentially a front for an enemy state eager to take down the U.S.? As Kelly Jackson Higgins, senior editor at the information security blog Dark Reading, reminds us, “Hackers posing as other hackers can basically encourage conflict among other nations or organizations, experts say, and sit back and watch.”
Expanding Presidential Fiat: National security professionals like Defense Secretary Panetta are already encouraging another cyber development that will mimic the war on terror. Crucial decisions, they argue, should be the president’s alone, leaving Congress and the American people out in the cold. President Bush, of course, reserved the right to determine who was an enemy combatant. President Obama has reserved the right to choose individuals for drone assassination on his own.
Now, an ever less checked-and-balanced executive is going to be given war powers in cyber space. In fact, we know that this is already the case, that the last two administrations have launched the first state cyber war in history — against Iran and its nuclear program. Going forward, the White House is likely to be left with the power of deciding who is a cyber attacker, and when and how such enemies should be attacked. In Panetta’s words, “If we detect an imminent threat of attack that will cause significant, physical destruction in the United States or kill American citizens, we need to have the option to take action against those who would attack us to defend this nation when directed by the president.”
Given the complex and secretive world of cyber attacks and cyber war, who is going to cry foul when the president alone makes such a decision? Who will even know?
Secrecy Creep: While government officials are out in full force warning of the incipient cyber threat to our way of life, it’s becoming ever clearer that the relationship between classified information, covert activities, and what the public can know is being further challenged by the new cyber world. In the war on terror years, a cult of government secrecy has spread, while Obama administration attacks on government leakers have reached new heights. On the other hand, Julian Assange and WikiLeaks made the ability to access previously classified information a household premise.
So the attempt to create an aura of secrecy around governmental acts is on the rise and yet government secrets seem ever more at risk. For example, the U.S. intended to keep the Stuxnet virus, launched anonymously against Iranian nuclear facilities, a secret. Not only did the attacks themselves become public knowledge, but eventually the American-Israeli ownership of the attack leaked out as well. The old adage “the truth will out” certainly seems alive today and yet the governmental urge for secrecy still remains ascendant.
The question is: Will there be a heightened call — however futile — for increased secrecy and the ever more draconian punishment of leakers, as has been the case in the war on terror? Will the strong arm of government threaten, in an ever more draconian manner, the media, leakers, and those demanding transparency in the name of exposing lawless policies — as has happened with CIA leaker John Kiriakou, New York Times reporter James Risen, and others?