Hackers are the new lawyers
calebmadrigal.com
calebmadrigal.com
lol indeed
One of the major benefits of society is to remove the need for individuals to keep their own firepower. You're allowed to defend yourself, but the goal is to make it so you can feel safe in a city of 8 million people with no more than a heavy bag, cell phone, or can of mace.
In the digital world, you still need self-defense (network protections, strong passwords, small attack surface), but hopefully not everybody has to hire cyber-thugs to defend their turf. If another cyber-thug attacks you, you figure out who they are, call your lawyer, and let the state deal with it.
It's not perfect, but I'd think lawyers will learn unmasking techniques before corporations hire body-guard divisions full of black-hat crypto types. And international conflict is always messier...
I think the article addresses this in both suggesting these attacks are more common in China (where lawyers from other countries tend to be notoriously ineffective) and in the hypothetical scenario that corporations grow in power to be above the law.
It's really two-sided coin. On the other hand, average person don't have to to learn about technical stuff. On the other, there is also weird stuff like illegal numbers, battles on encryption, censorship, restrictions on reverse engineering and learning, all the copyright/DRM weirdness, and, on more common level, also a lot of uncertainity about if something's legal or not[1] (because, duh, engineering and lawmaking are completely different worlds and they mismatch heavily).
____
[1] You encounter a computer system. You just can't tell if it's legal to access it or not. And a smart lawyers can make it look both ways - it's not tech (where things are straightforward but harsh), just humans persuading other humans.
I find this point of view fascinating. Walking down the street, do you have any trouble telling which buildings are legal to access and which are not?
I would posit that there is nothing unclear about the law here. In meat-space, the social norm is clear: you go into other peoples' property only if you have business there, you go in through the front door, and once there, you do only what the owner would want you to do. Otherwise, your entry is illegal. Nobody complains that you can't tell just by looking at a building whether going inside is legal or not.
Some people resist this clear social norm in cyber-space. They want to posit a "right to tinker" or a "right to explore." It is that resistance that creates uncertainty, not the law.
I think it is only clear most of the time.
There are plenty of odd situations.
I might ask where the restroom is in a retail store and learn I need to walk through a back storage room to get there.
What if I walk into a business an it appears empty, as if the sole proprietor just walked out and forgot to lock it.
Where exactly is the dividing line between the park or field and the similar looking lawn.
If I am hiking in the woods and I come upon the back of a sign I will walk around to the front. If it says "Tresspassers will be shot" I really start to worry what I just walked through.
Cyberspace hasn't had time to work out good samaritan laws or castle doctrine and the only property are purely technical in nature. I mean, do I own the VM on a VPS host or does the VPS host, certainly I own the software on it I wrote and they own the host OS but where is that line? Then IP laws come into play...
I think it's only us nerds with our low social sensitivity and literal minded-ness would think otherwise.
Do you expect the same response to hacking your local computer club as hacking the IRS?
There are more than one set of social norms on the internet.
The "I know it when I see it" test is useless because it does nothing in the cases where you actually need the test to decide anything. There was never any question what happens to someone who hacks the DoD and sells secrets to the Russians -- you don't need any kind of computer-specific laws for that because it's illegal regardless of how you do it.
The problem cases are the ones where the argument is over whether permission was implicit vs. absent vs. not required. For example, should it be illegal for a journalist to access internal documents a company published on their website but probably didn't intend to? What if the journalist has to guess the URL? And those seem to be exactly the sort of cases that can be charged only under the CFAA and not any other law.
> Some people resist this clear social norm in cyber-space. They want to posit a "right to tinker" or a "right to explore." It is that resistance that creates uncertainty, not the law.
A law the relies on social norms adopts the uncertainty inherent in the social norms. In the context of the internet where all cultures are together in the same "space" this gives the law more than the usual amount of uncertainty.
Which makes the problem one that is much easier to solve technically than legally. If you in fact prevent unauthorized access using technical means then there is no occasion to resort to legal process or contend with the uncertainty of differing social norms, which is already inherently necessary for extrajurisdictional attackers who aren't subject to legal process regardless.
And if the problem can (and for foreign attackers must) be addressed mainly through technical means then the justification for uncertain laws with harsh penalties is significantly eroded, while the cost in terms of chilling effects and potential for abuse is not reduced at all.
Local social norm, in your meat-space neighborhood, sure. Also, norms from the other places, if you've did the research, or if their norms are close enough to what you're used to so your behavior is compliant or at least tolerable (for a foreigner).
Still, nerd social awkwardness issues aside, I tend to believe there there are quite different social norms in drastically different meatspace areas.
On the Internet it's only worse. You can't even tell which country/jurisdiction the site you plan to visit belongs to (no, addresses from whois may be a continent away from the legal system site ToS mentions). I neither think there are universal laws regarding this (to best of my knowledge, there aren't), nor that you can always know whenever it's legal to click that link you saw someone had posted on IRC or not, or read that link's contents, or save it.
(Ever thought that "liking" a post on a social network can be a criminal offense punishable with a few years in jail? In some countries it could be.)
That doesn't actually work here. If someone attacks you from Russia or China or Nigeria, there are no lawyers that can help you.
The reason hack back is unwise and unnecessary is that you don't need deterrence to prevent cyber attacks. In meatspace anybody with a rock and two hands can steal your television and the defenses necessary to prevent that are significantly more expensive than relying on the state to use prison as a deterrent.
But it's a lot more practical to maintain a secure digital system than a secure physical system, because digital systems fail closed rather than fail open. If you can't pick a physical lock you can still break a window or bust down the door, but the equivalent brute force against digital systems yields only denial of service rather than unauthorized access.
That doesn't mean you can't screw it up. Possible to succeed is not the same as impossible to fail. But it means it's possible to have a good enough defense that you require no offense.
This statement is all shades of Wrong. In Nigeria at least, I know you can easily report to the Country's Economic and Financial Crimes Commission (EFCC), which is currently doing a very good job of getting back foreign stolen money through internet scams.
But let's suppose all of that is true. If someone in Nigeria steals your money, you pick up the phone and in five minutes they're in jail and your money is returned. Then you're doing this:
http://slatestarcodex.com/2014/05/12/weak-men-are-superweapo...
Because there are still many places where no such process is available. Many of the attacks from China are state-sponsored. Many of the attacks from Russia are from organized crime who have law enforcement on payroll. ISIS. You haven't done anything to refute the point, you're just arguing about which examples I should be using this year.
Most economic value is due to labor and tangible products, and cyber attacks can only indirectly touch those. Cyber attacks are unfortunate, sure, but they're hardly all that damaging to the core operations of the organizations they affect, unless, of course, it's something like Stuxnet, where physical damage is done.
Neither is lawyering, that's his point. Lawyers do not (usually) create value, they protect it, same as the hackers he is talking about.
>Cyber attacks are unfortunate, sure, but they're hardly all that damaging to the core operations of the organizations they affect, unless, of course, it's something like Stuxnet, where physical damage is done.
The Sony hack: http://www.vanityfair.com/hollywood/2015/02/sony-hacking-set...
Bangladesh Bank hack: https://en.wikipedia.org/wiki/2016_Bangladesh_Bank_heist
On HN? Inconceivable.
It would be a very bad idea for a US company to start a renegade hacking team that broke into other companies and stole their documents. That would get you thrown in jail, no matter who you were.
It would be an even worse if you started counter-hacking random ips that attacked your machines, because you'd end up with soccer moms crying to politicians on national television about what you did to their kids.
This is something we as a community should probably have a conversation about. Too many people went to law school, and now they can't find jobs. Meanwhile, the "tech" (read: software) zeitgeist has enthusiastically taken up the mantle by proclaiming that everyone should learn to code and start making $100k. We're only devaluing our own work and setting unrealistic expectations by doing this.
Finding business strategy is one thing. "Let's run through their service, deconstruct it, and see how we can make ours better than theirs." That's above board."Find a hole, pivot, take what you can." Pump the brakes there, sweetie.
Or maybe I'm just interpreting this wrong.
I can't help but wonder if the competitors of Theranos understand this idea (use tech to influence media to influence regulators)and used it as a weapon that Theranos has not done a good job of defending against.
It would be fun to run an analysis of all news articles mentioning Theranos and see historically the sentiment analysis of each one, and at what average sentiment point the regulators got involved.
You could extrapolate and see if there is an average media sentiment that can predict when regulators will get involved. Could be a great "weapon" to use.
A company who don't spend their effort on R&D and just cloning competitors technologies cannot dominate the market. A company which doesn't seriously concerns security deserve to die.
No worries at all.
Also this article is super-naive. If a country were not the USA and caught hacking a bunch of western businesses then the US political and military machine would start up. Look at what we pressured others to do about the pirate bay and megaupload.