New Chinese Cyberattacks: What’s to Be Done?
chinafile.com
chinafile.com
- Coldly, the US citizens and companies broadly views the internet as a way to make cash, and generally will pursue that.
- Free speech concerns and the decentralized power of the internet are of interest to "damn fool idealists", as Kenobi might say. Not your major business powers. Google's play is very revealing here...
- China is extremely interested in their own sovereignty and control of the China-sphere, with soft power exercised elsewhere.
The obvious easy way forward is for companies to capitulate to Beijing and let the cash flow. This is likely the most common occurrence today. Some companies will take the higher road, particularly the more idealistic ones with fat cash bags.
The argument that the State department should be involved is probably the correct one, but one wonders exactly what leverage can be applied, since China has spent decades building local apps and infrastructure.
I would be extremely interested in tokenadult's take on this, as he is very familiar with China.
Four things, each with their own time horizon and in parallel.
1. Norms for cyber warfare and international cyber activity to be developed. (The US may not be able to lead this post-Snowden, but they should try and should be involved.)
2. Cooperation on international standards, development and funding in cyberspace to improve and prove the security of networks, protocols, hardware and software.
3. Deescalation of cyber capabilities and activities. These exercises can be expressed in many ways such as 'cyber-free days' where nations show their good intentions by withholding operations in good faith.
4. International investment, development, data sharing and standardization of forensics capabilities to squeeze the attribution problem. This may be done in lockstep with protocol development.
But at its root there are three reasons nations hack one another: intelligence, intellectual property, sabotage.
Whatever deterrents and legal frameworks are in place will need to be as or more compelling than the motivations for cyberactivity. Whatever can be done to limit what can be gained by intelligence, sabotage and IP theft will in turn limit cyber activity. So a fifth item would be to reexamine and double down on the international peace keeping frameworks that discourage the listed above.
Or in this case to block their own citizens access to information that is available worldwide.
My argument above can be thought of a way to deal with the international problem of cybermilitary attacks. Diplomacy products are another, separate, issue.
Asking everyone to please stop exploiting vulnerabilities hasn't worked for non-state actors. What's different this time?
The internet community needs to adopt better protocols, hardware, and software. The development of attack capabilities force that to happen.
This won't in and of itself stop the activity - and it's not intended to. This is intended to foster cooperation and trust. Cooperation and trust are required for international norms development and cooperation on standards, and in addition lessen the incentive for nations to hack one another out of suspicion or hedging bets.
I'm not saying states should hack each others but complaining about China is a pretty spectacular "do as I say, not as I do".
This is a tragedy of the commons type situation. Nobody wants to disarm. However there is historical precedent for cooperation and disarmament under these conditions - even with nuclear arms races.
This is what I'm suggesting - what things do we need to do to deescalate an international cyber arms race.
It is no different than if the Google Analytics script got hijacked in the West.
Within China, China can weaponize Baidu, Google, or anything else they choose. That's the nature of their internet connectivity and their ownership of CNNIC, which recently issued certificates that can be used to impersonate Google, Facebook, etc.
But these systems deal with static content. Distributed hash tables are a well-studied solution. Providing the same advantages of magic, trust-free, peer-to-peer replication to a dynamic (interactive and frequently-modified) site like Github is a much cooler and harder problem, and I'm not aware of anyone trying to solve it. Intuitively it feels impossible to create such a site without a distinct set of trusted nodes doing the work.