I think everyone agrees that hacking is not inhumane...
I think everyone agrees that hacking is not inhumane...
By "the actual Geneva Convention" do you mean one of the four Geneva Conventions of 1949, or do you mean one of three previous Geneva Conventions that were predecessors of the First through Third of the 1949 Conventions?
> The Geneva Convention doesn't ask for "no fighting", but rather gives boundaries to keep fighting within "human-ish" levels.
As the article indicates, the new convention would parallel the protection of civilians in the Fourth Geneva Convention of 1949 by protecting civilians from being targets of nation-state cyberattacks, not prohibiting cyberattacks generally.
Though I think a better model would be the protection of civilians in Additional Protocol I (1977) to the Geneva Conventions of 1949.
Out of their six points four simply make cyber attacks harder or nearly impossible, one exempts civilian targets from attacks, and one guarantees government help in defense and cleanup.
I struggle to see much more here than an attempt from tech companies to prevent cyber war, and have them as untargatable combatants if cyber war st still occurs.
1. Self driving cars getting hacked (and killing passengers?) 2. Stock market being hacked or retirement accounts getting hacked and losing data (we don't know how much money you had) 3. Election fraud
We're building a public infrastructure that is highly susceptible to security threats, meanwhile governments around the world only intensify their capacity to do inhumane things to this infrastructure (rather than building up the defenses).
While details of the context will matter, an attack on such a plant would potentially implicate any or all of Arts. 51-56 (exc. 53) of Protocol I to the 1949 Conventions (the US is not a party to Protocol I but had traditionally viewed it's terms as declarative of and redundant with pre-existing customary international law.)
Furthermore, this would be a perfect example where a "digital Geneva convention" would not be needed; you'd want a treaty expressing mutual agreement that everyone understands that destruction of such facilities is not in anyone's best interest, and everyone agrees not to do it in principle - without any reference to specific means of destruction; the same principles should apply for digital attacks as for bombing or insider sabotage.
The Geneva convention Protocol I states that facilities like nuclear reactors "may be attacked but only in ways that do not threaten to release the dangerous forces", and that seems a perfectly valid description - there is no blanket prohibition to attack them, you are explicitly allowed to bomb or sabotage the nuclear plant in a way that disables it but not in a way that causes a meltdown; so you'd be also allowed to hack it in a way that disables it but not in a way that causes a meltdown.
As it generally wouldn't be a violation to bomb that power plant from a plane or sabotage it via infiltrated spies, sabotage by hacking shouldn't have special treatment. Doing so should be just as [il]legal according to the exact same criteria that determines if it'd be allowed or not by conventional means.
I do like the idea of a digital weapons non-proliferation agreement, but I suspect that it would be even less enforceable than the nuclear version.
Let's say 'within profitable levels'.
Not all weapons are that good for enabling an army to advance, even if lots of people are killed, e.g. poison gas. Civilians get instantly killed by the stuff but armies are tooled up to survive it, or can be. With not much profit in poison gas compared to a cruise missile laced with depleted uranium it makes sense to ban the poison gas that anyone with a degree in chemistry can make in their front room rather than the missile.
Instead of cyber war being the threat those conventional and nuclear weapons are the threat, although hard to imagine if living in Kansas.
What we need are some jolly clever OSS licenses that have clauses in them 'not for military use'. Microsoft could put that in their license today and go heavy on the enforcement - 'sorry Lockheed Martin you can't be using Excel to design 'echelon 2 as that is in violation of the EULA, here is the cease and desist...'.
In this way we can make the military contractors fall out of the loop and be as IT savvy as North Korea.
'Don't be evil' is something we forgot about, however, again, if Google just 404'd on the military due to some EULA then that we wouldn't have so much evil in the world.
Seems that 'cyber terror' is the new al-qaeda, i.e. make believe.
That may be 'open source,' for some definition of the term, but it wouldn't be free software.
Nor would it be right: it is the right of any people to band together in their own self defence, and munitions are part of that. The rights to own a gun, encrypt a file and operate a computer are one and the same.
People have committed suicide for leaked information.