{"id":131806,"date":"2015-07-11T16:00:47","date_gmt":"2015-07-11T14:00:47","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=131806"},"modified":"2015-07-10T17:56:10","modified_gmt":"2015-07-10T15:56:10","slug":"can-we-trust-hackers-with-our-security","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/131806-can-we-trust-hackers-with-our-security.html","title":{"rendered":"Can we trust hackers with our security?"},"content":{"rendered":"<blockquote><p>To think that men are so foolish that they take care to avoid what mischiefs may be done them by polecats or foxes, but are content, nay, think it safety, to be devoured by lions.<\/p><\/blockquote>\n<p>English philosopher John Locke\u2019s <a href=\"http:\/\/press-pubs.uchicago.edu\/founders\/documents\/v1ch17s5.html\">words from 1689<\/a> describe the way in which fear for their own security may irrationally drive citizens to accept the absolute authority of the state.<\/p>\n<p>His words may bring to mind the <a href=\"http:\/\/www.theverge.com\/2013\/7\/17\/4517480\/nsa-spying-prism-surveillance-cheat-sheet\">NSA surveillance scandal<\/a>, or more recently the <a href=\"http:\/\/www.theguardian.com\/technology\/2015\/jul\/06\/hacking-team-hacked-firm-sold-spying-tools-to-repressive-regimes-documents-claim\">devastating hack<\/a> of cybersecurity firm Hacking Team.<\/p>\n<p>The controversial \u201csecurity\u201d firm \u2013 parlance for hackers for hire \u2013 had its servers compromised, company files stolen and social media and email accounts hijacked.<\/p>\n<p>Some attribute the attack to activists aiming to expose the firm\u2019s dealings with authoritarian regimes \u2013 the 400Gb file the attackers posted online <a href=\"https:\/\/firstlook.org\/theintercept\/2015\/07\/08\/hacking-team-emails-exposed-death-squad-uk-spying\/\">contains details<\/a> that apparently support the concerns of <a href=\"http:\/\/surveillance.rsf.org\/en\/\">Reporters Without Borders<\/a> and the University of Toronto\u2019s <a href=\"https:\/\/citizenlab.org\/tag\/hacking-team\">CitizenLab<\/a>.<\/p>\n<p>Other believe the attack originates from a competing firm. In any case, what it demonstrates is that hackers today \u2013 as much as the well-funded government intelligence agencies \u2013 can affect national and international politics, to foster or to disregard human rights and ultimately to shape the development of democracy.<\/p>\n<h3 class=\"my-4\">Striking the balance<\/h3>\n<p>Communication technology has become both a valuable asset needing protection <a href=\"http:\/\/www.theatlantic.com\/technology\/archive\/2012\/03\/cyber-and-drone-attacks-may-change-warfare-more-than-the-machine-gun\/254540\/\">and the means of attack<\/a>.<\/p>\n<p>A balance must be struck between the rights of citizens \u2013 privacy, freedom of speech and information \u2013 and the requirements of the state to keep them safe and to secure itself against outside and inside threats.<\/p>\n<p>The <a href=\"https:\/\/theconversation.com\/better-locks-to-secure-our-data-are-the-inevitable-result-of-too-many-prying-eyes-33790\">debate over the use of encryption<\/a> is a case in point: on one hand encryption shields its users from intrusive surveillance, protecting their privacy. On the other, by thwarting the surveillance of law enforcement, encryption limits the state\u2019s ability to protect its citizens.<\/p>\n<p>Striking a balance between individual rights and security is not a simple matter \u2013 Hobbes and Locke debated the problem centuries ago and it has been debated ever since. But the attack on Hacking Team reveals something more.<\/p>\n<h3 class=\"my-4\">The new lords of the internet wild west<\/h3>\n<p>The term \u201chacker\u201d, aside from suggesting a high level of technical expertise, fails to take into account the wide range of aims and motivations moving these experts, for example hacktivism, crime, or terrorism. Hackers are not just tech-savvy experts \u2013 they are the new makers, capable of shaping debate and consequently the path societies take.<\/p>\n<p>Look at their role in the events of the <a href=\"http:\/\/www.bbc.co.uk\/news\/blogs-news-from-elsewhere-23356422\">Arab Spring<\/a>, those <a href=\"http:\/\/www.aaronsw.com\">fighting regulation of intellectual property and copyright<\/a>, and groups like the <a href=\"https:\/\/theconversation.com\/the-syrian-electronic-army-is-rewriting-the-rules-of-war-17618\">Syrian Electronic Army<\/a> (or Hacking Team) that support governments\u2019 intelligence activities.<\/p>\n<div id=\"attachment_131808\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Hard-drive-warriors.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-131808\" class=\"wp-image-131808 size-full\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Hard-drive-warriors.jpg\" alt=\"Hard drive\" width=\"630\" height=\"419\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Hard-drive-warriors.jpg 630w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Hard-drive-warriors-601x400.jpg 601w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Hard-drive-warriors-250x166.jpg 250w\" sizes=\"(max-width: 630px) 100vw, 630px\" \/><\/a><p id=\"caption-attachment-131808\" class=\"wp-caption-text\">Hard drive<\/p><\/div>\n<p>More worryingly this hack, like the many others before it, reveals the unregulated grey area in which hackers operate. Hacking Team, based in Italy, has always denied accusations that it works with authoritarian governments, including those for which European Union member states are <a href=\"http:\/\/www.csoonline.com\/article\/2944333\/data-breach\/hacking-team-responds-to-data-breach-issues-public-threats-and-denials.html\">under arms embargos<\/a>, such as Sudan.<\/p>\n<p>But will the details now revealed lead to any action against the firm? Were its actions illegal under national or international law? It\u2019s just not clear.<\/p>\n<p>What is clear is the regulatory vacuum and lack of any effective restraints on the activities of hackers and cybersecurity firms, and the inability to distinguish legitimate from illegitimate uses of hacking expertise.<\/p>\n<p>Indeed, many working in the field cross from being \u201cblackhat\u201d (illegal) to \u201cwhitehat\u201d (legal) operators. The distance between the two is often paper thin.<\/p>\n<h3 class=\"my-4\">Bringing light to the shadows<\/h3>\n<p>Hackers prefer acting in the shadows, affording them anonymity and room for manoeuvre. Governments and intelligence services may favour a similar approach, allowing them to operate outside various constraints. But in the long run, information societies \u2013 especially democratic ones \u2013 cannot afford the risks of allowing this activity to remain in the shadows.<\/p>\n<p>As Locke pointed out, left to their own devices, the apparent saviour has the potential to become the next lion.<\/p>\n<p>There have been attempts to regulate cybersecurity firms: the <a href=\"http:\/\/www.wassenaar.org\/introduction\/index.html\">Wassenaar Arrangement<\/a>, for example, defines rules controlling the export of surveillance software to specific countries. Very recently, the US Bureau of Industry and Security recently <a href=\"http:\/\/www.bis.doc.gov\/index.php\/regulations\/federal-register-notices#FR28853\">defined new rules<\/a> based on the Wassenaar Arrangement.<\/p>\n<p>Although this showed a few significant drawbacks, the new rules are so broad that while forbidding collaboration with blacklisted counties they could restrict the legitimate use of tools used to improve <a href=\"http:\/\/www.wired.com\/2015\/06\/arms-control-pact-security-experts-arms\/\">computer security<\/a>.<\/p>\n<p>Such shortcomings are common when lawmakers attempt to regulate areas with which they are unfamiliar, overlooking their novelties and peculiarities. This has exacerbated the policy vacuum. The same can be seen in the application of the right to be forgotten in Europe, and the regulation of cyber-warfare.<\/p>\n<p>The internet is the new realm with vital importance for all of us \u2013 and hackers are the masters of it, with the potential to bring about radical change, reshape the political status quo and redefine our understanding of political power.<\/p>\n<p>Until this is understood in the context of the current information revolution, any attempt to legislate and regulate the role of the hacker is doomed to failure.<\/p>\n<p><a href=\"http:\/\/theconversation.com\/profiles\/mariarosaria-taddeo-160655\">Mariarosaria Taddeo<\/a> is Researcher in Information and Computer Ethics at <a href=\"http:\/\/theconversation.com\/institutions\/university-of-oxford\">University of Oxford<\/a>.<\/p>\n<p>This article was originally published on <a href=\"http:\/\/theconversation.com\">The Conversation<\/a>.\u00a0Read the <a href=\"http:\/\/theconversation.com\/trusting-hackers-with-your-security-youd-better-be-able-to-sort-the-whitehats-from-the-blackhats-44477\">original article<\/a>.<\/p>\n<h3 class=\"my-4\">More on hackers<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/127776-how-hackers-steal-your-private-information-on-wi-fi.html\">How hackers steal your private information on Wi-Fi<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/131780-here-are-the-leaked-e-mails-from-sars-spy-unit-to-hacking-team.html\">Here are the leaked e-mails from SARS spy unit to Hacking Team<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/129364-not-even-secret-government-talks-are-safe-from-hacking.html\">Not even secret government talks are safe from hacking<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>English philosopher John Locke\u2019s words from 1689 describe the way in which fear for their own security may irrationally drive citizens to accept the absolute authority of the state.<\/p>\n","protected":false},"author":340972,"featured_media":85485,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[199,35],"class_list":["post-131806","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-hackers","tag-headline"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/131806"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/340972"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=131806"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/131806\/revisions"}],"predecessor-version":[{"id":131810,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/131806\/revisions\/131810"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/85485"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=131806"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=131806"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=131806"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}