• Home
  • About
  • Blog
  • News
  • Events
  • Media
  • Video
  • Glossary
  • Contact
  • Download
  • RSS

Federalizing cybersecurity?

April 2nd, 2009  |  by jz  |  Published in Future of the Internet, cybersecurity  |  2 Comments

The Washington Post has reported that the U.S. Congress will shortly take up a bill to “empower the government to set and enforce security standards for private industry for the first time.”

Today’s conventional wisdom in cybersecurity circles is that:

  • we’re very much open to attack (defined lots of ways; often people mean: PCs attached to the Internet can be compromised by outsiders and then put to bad uses, turned into spies, or made to self-destruct).  Virtually no one takes cybersecurity as seriously as he or she should, in part because the costs of compromise are not always charged back to the person who should take measures.  (Many people don’t care if their PCs are sending spam in the background, so long as it doesn’t disrupt their Doom game.)
  • “perimeter defense,” the basic idea behind firewalls, doesn’t cut it.  If just one bad bit of code gets past the wall dividing a PC or a network from the rest of the world, it’s all over.  (This makes Senator Rockefeller’s soundbite a bit inapt: “You have to keep making higher walls.”)
  • for the first time, our defense establishment is genuinely not in a position to be able to “defend the homeland.”  That’s because much of the vulnerable infrastructure — PCs — is entirely in private hands and then connected to the world at large.  There’s no place for a fighter jet or Border Patrol agent to intercede.

Given these articles of faith, one can see how tempting it is — indeed, nicely bold — to propose a government official who can mandate certain security standards across the board.  But there are many potential problems with this approach.

First — could they realistically be made to apply to individuals?  What penalty should obtain if I fail to secure my computer?  Perhaps the thought is that operating system and software vendors could be regulated, the way that cars must have seat belts and air bags — precisely to deal with the problem of irresponsible individual drivers.  But that’s dicey: there are many clearly wrong ways to code operating systems, but that doesn’t mean there are obvious right ways to do it.  Many of the vulnerabilities we face come not from hidden exploits that take advantage of some literal bug in the way, say, Windows works, but from our own acquiscence in running new code.  We click “yes” to “are you sure you want to run this?” because we are impatient, and because so many times during the day we’re typically asked to make a snap decision like that.

Second — any standards process would quickly become the purview of security firms with something to sell.  Tens of millions of dollars or more could rise or fall on whether one’s security suite is made the obvious way to satisfy a particular regulatory requirement.  With no scale to determine how much security is enough — especially when risk aversion will vary so much from one firm or computer owner to the next — we run the risk of overregulation.  Too easily security standards will just amount to vendor selection.

So, what should we do?

Well, one fruitful point of dampening security problems is at the ISP level.  Computers that have fallen prey to an active worm or virus can frequently behave in predictable ways — sending out certain traffic patterns, or having vulnerabilities that can be detected at a distance.  ISPs know this, but are reluctant to tell their own subscriber that they have a problem, much less to quarantine them.  To do so means a customer service event — someone has to coach the user through fixing the machine.  But that incentive can be changed.  If ISPs were asked — well, required — to take more reasonable responsibility for zombie computers located on their networks, they could rise to the occasion.

Another underexplored strategy is to build our systems so that they can recover gracefully from problems.  Wikipedia isn’t designed to prevent all vandalism; instead it has technical tools that make it easy to revert a page to the state it was in before someone came along and vandalized it.  If the Wikipedia entry for Britney Spears is resilient to defacement, shouldn’t our valuable spreadsheets be the same way?  Imagine a history file automatically generated so we could see changes as they have happened and revert to an older version.  Then we need only deal with the problem of viruses that try to tamper with a document’s history — something that can be made very difficult to do.  Similarly, researchers like Butler Lampson have proposed PCs with “red” and “green” zones in them.  Stuff in the red zone can’t affect what’s going on in the green.  Trusted software ready for prime time goes in the green zone; experimental or new stuff goe sin the red.  If there’s a problem in the red zone, it’s at least confined.  None of these approaches is a cure-all, but they can help a lot.

Finally, we can work to build collective solutions, neighborhood watches in cyberspace.  Right now each PC has a metaphorically autistic experience: it surfs from one site to the next with no awareness of what other PCs are doing.  Imagine having a little software on your PC that reports its vital signs to other participating PCs.  Collectively we could generate a map of the health of cyberspace, an early warning system — and a means of answering some very useful questions.  Before running new code, you could say: How many machines in the herd are running it?  How many self-proclaimed experts run it, versus neophytes like me?  Is the code brand new, or has it been around for months or years?  These questions are not beyond the expertise of most PC users, and the answers can help them make much more informed decisions about what code to run.

There’s a lot of work to be done to secure cyberspace — work that goes beyond any one set of regulatory “best practices” that we know won’t be uniformly implemented.

Responses

Feed
  1. Bertil Hatt says:

    April 2nd, 2009 at 3:02 pm (#)

    Many important truth in that post — but an important element is missing: most hacks still go through traditional channel (human engineering, physical access). Recent failures (droping USB keys on NSA parking lot, loosing laptops) plead for more central control too.

  2. Seth Finkelstein says:

    April 2nd, 2009 at 11:00 pm (#)

    I find this post a bit confusing, since it lumps so much together as “security” – I kept thinking, but what is it that the bill was talking about in the first place? (in terms of “security standards”) And how does that relate to the items discussed?

Blog

  • FOI Topics and Links of the Week
  • The Extraordinaries Haiti Earthquake Support Center. A followup post on the Extraordinaries’ efforts to use ubiquitous human computing to help find missing people after the Haiti earthquake — a positive vision inspired by JZ’s nightmare scenario of crowdsourced secret police work. Did they succeed? “Yes and no”—but, as they detail, there’s obvious potential for future disaster relief.

    Amazon Cracks Open the Kindle. Amazon is opening the Kindle to outside developers who can market their products in what sounds exactly like an App Store, down to the 70-30 revenue split and and light policing of apps. (One difference is that developers have to pay for wireless delivery.) It’s seeming like this is *the* model for the next few years. Speaking of which…

    Computers Should Be More Like Toasters. The sale of the Apple Tablet could mark an important moment for generativity. Computers have been shrinking and phones have been growing—but the critical difference has been that anyone could still code for a computer, until now. The Tablet looks more like a computer than a phone, but will Apple will prescreen apps they way it does for the iPhone? Farhad Manjoo thinks that would be a good thing, but there are clear generativity costs.

    The Splinternet means the end of the Web’s golden age. Josh Bernoff points out that, as we switch to appliancized computers and smart devices instead of PCs, the web becomes a “splinternet.” Websites show up and operate differently on each device. He thinks about how to handle this from a business and marketing perspective, advising: “Here’s what not to do: panic and try to unify things again. The shattering cannot be undone.”

    Technology Changes “Outstrip” Netbooks. Meanwhile, the BBC considers the convergence among netbooks, smartphones, and tablet notebooks, and who the short- and long-term winners are likely to be.

    Apple censors Dalai Lama iPhone Apps in China. An interesting look at how censorship works on iPhones in China. (The story was written pre-Google announcement, so some portions are out of date.) Apple, complying with local law, appears to be removing apps related to the Dalai Lama in the Chinese App Store, and a search for Falun Gong apps freezes the search page. On the other hand, it’s possible to access YouTube through an iPhone app, which isn’t always possible on a PC.

    And in the crystal ball dep’t — from JZ’s book:

    Imagine entering a café in Paris with one’s personal digital assistant or mobile phone, and being able to query: “Is there anyone on my buddy list within 100 yards? Are any of the ten closest friends of my ten closest friends within 100 yards?” Although this may sound fanciful, it could quickly become mainstream. With reputation systems already advising us on what to buy, why not have them also help us make the first cut on whom to meet, to date, to befriend? These are not difficult services to offer, and there are precursors today.

    As usual, there’s an app for that… the “datecheck” app allows you to enter a name, phone number, or email address, and get information on your date. The categories are “sleaze detector” (check of criminal convictions & sex offenses), “$$$” (home ownership, etc), “interests” (gleaned from social networks), “living situation” (who they live with), and “compatibility”—although unfortunately, the “compatibility” check is still just a check of astrological signs. Now all they need is friends’ feedback rankings.

    —By Elisabeth Oppenheimer

  • Life in a clickshop
  • In talks about ubicomp, JZ gives an example of a worst-case scenario involving ubicomp platforms. He imagines that the Iranian government could use Amazon Mechanical Turk to identify dissidents, simply by posting pictures of protestors and ID-card pictures of the adults in the country, then asking Turkers to match protestor pictures to ID-card pictures. Voila—and the Turkers wouldn’t necessarily have to know what they were doing. In the department of amazingly cool ideas, though, the folks at the Extraordinaries reflected on the Iran example and then turned it around. After the earthquake in Haiti, they posted news wire pictures of people in Haiti (with crowdsourced help), asked others to post pictures of missing relatives, and finally asked volunteers to try to match the two up. This is v 1.0 of what could be a terrific and widely-used technology after natural disasters, allowing people at home to do more than just donate money.

    As we keep thinking about ubicomp and the potential upsides and downsides, it’ll be important to keep in mind that it’s a tool—a largely undeveloped one as yet—with much room to develop in both directions. In that spirit, I wanted to comment on this piece from Technology Review that casts a skeptical eye on Prof. Zittrain’s recent column in Newsweek on cloud labor (also known as ubiquitous human computing). The Newsweek editors gave the piece the ominous headline “Work the New Digital Sweatshops,” and Tech Review bloggers question whether that’s really a fair description of the Mechanical Turk platform. I’m not sure there’s a real disagreement here—the Newsweek headline overstated the content of the piece. Much of the point, as I read it, was just that cloudwork practices are so new, dynamic, and varied that it’s hard to know what the good and bad effects will turn out to be. As they point out, this could be a boon for workers here in the US who want flexibility and autonomy, as well as creating new kinds of opportunities for workers abroad. A few specific points are worth thinking about, though.

    They quote John Horton, at Harvard, who put out a HIT (“human intelligence task”) on Amazon Mechanical Turk asking about working conditions, and found that a small majority think AMT requestors treat workers better than most real-world employers. That surprised me—maybe I spend too much time reading Turker messageboards, where the theme is often discontent. I wonder, though, whether many responders use AMT for fun or small income supplements, rather than to earn a living wage, which changes the complexion of the situation. Even if Horton is wholly correct, though, it doesn’t mean requestors can’t improve. For a project I’m doing for JZ’s winter cyberlaw class, we’ve put up some AMT HITs asking about worker satisfaction. We’ve found that people do not like doing search engine optimization or creating spam, and a majority (though not an overwhelming one) likes knowing what the project is for. Disclosure of the company’s identity or the project purpose could become a much stronger norm on AMT, which would help fend off the problems of work alienation and unwittingly doing bad things with the platform, but wouldn’t detract from any of the benefits TR bloggers praise.

    The other major point they make is that this type of work can be good for workers in developing countries. That’s definitely true in some cases (see, for instance, previous blogging about CrowdFlower’s GiveWork program). I certainly don’t have enough background in international development to make an unambiguous statement either way. But surely it’s worrisome that children can be made to do the work as well as adults—there’s just no way of knowing who’s at the other end of the system. Overall, for better or for worse, we live in a society where we’ve decided that paternalistic labor laws play some valuable role. Some of them can be imported into an AMT context—but maybe not internationally—and the technology means that some can’t, even if, like child labor, there’s widespread condemnation. I would agree, and I think JZ would too, that we don’t want regulators charging in with too heavy a hand. But we should be alert to what’s happening on these platforms.

    —By Elisabeth Oppenheimer

  • A quick cosmology question
  • The amazing Hubble telescope has now shown us images of galaxies from 13.2 billion years ago.  That’s because the light comes from 13.2 billion light years away, and took (by definition) that much time to get here:

    “The deeper Hubble looks into space, the farther back in time it looks, because light takes billions of years to cross the observable universe,” the Space Telescope Science Institute said in a statement released Tuesday.

    So that makes sense on one level.  But here’s what I don’t get: the light only took that long to get here if the starting point for it was in fact 13.2 billion light years away.  Since the universe is expanding, if one rewinds time, it shrinks.  Indeed, I thought the Big Bang to mean that at one point the Universe was a singularity, both meaning in a condition for which our laws of physics can’t say anything, and that it was essentially compressed into a single point.

    But if it was compressed into a single point — apparently about 5-600 million years further back from the 13.2 billion we’re now seeing — that means that 14 billion years ago everything was, well, extremely close to everything else.  So unless the universe is expanding faster than the speed of light, how could anything be 13.2 billion light years away from us, 13.2 billion years ago?  Maybe something is that far now, but if so its light would only just be starting its journey to us.  The whole light year calculation presumes that something was that far away from us then – a time when the whole universe was much, much smaller in diameter.  Maybe it has something to do with the universe’s expansion as a matter of dark energy, e.g., the fabric of the universe itself expanding, vs. the expansion found as all the galaxies speed away from one another (countered by the actions of gravity)?  Something to do with the “inflationary period” catapulting everything really far away from everything else in one swoop?

    I’m sure I’m missing something here.  What is it?

  • Google takes on China
  • Google announced today that it would cease (well, phase out) censoring the results in google.cn, the Chinese-language version of its famed search engine.  It’s a pretty stunning move, both in its fact and in its execution.  First, the announcement of “A new approach to China” may appear to have buried the lede.  The lion’s share of the post is devoted to describing a series of coordinated attacks on the accounts of human rights activists, including those who use Google.  It includes a link to the amazing story of GhostNet, discovered by fellow ONI researchers when the Dalai Lama gave them his oddly-acting laptop to examine.

    Companies rarely share information about the cyberattacks they experience — conventional wisdom has it that it makes the company appear vulnerable, and drives customers away.  Here Google is open about the attacks, while of course assuring readers that it had tightened security as a result.  Google then links these attacks to a lessening of enthusiasm for doing business in China.  Eliminating censorship in google.cn is only mentioned after that.

    Suppose the Chinese government acts as expected and tells Google that it may no longer operate in China.  Google.cn might vanish as a domain name, since it’s hosted under the Chinese country-code TLD of .cn, ultimately controllable by the Chinese government.  But the search engine found there could of course keep operating from a different location, like cn.google.com.  Suppose then that China attempts to filter out traffic to and from that new location — and to and from google.com for good measure, as it has done from time to time, especially before the advent of google.cn and its agreement to censor.  (We’ll be watching for such moves at herdict.org, a site where users can report Web blockages.)

    What next?  My hope, and expectation, is that Google engineers who might have been a bit halfhearted about implementing censorship mandates in google.cn could be full-throttle in coming up with ways for Google to be viewed despite any network interruptions between site and user.  There are lots of unexplored options here.  They’re unexplored not because they’re infeasible, but because most sites would rather not provoke a government that filters.  So they don’t undertake to get information out in ways that might evade blockages.  Here, Google would have nothing more to lose, so could pioneer some new approaches.  Circumvention of filtering (or other blockages, for that matter) tends to happen on the user side of things, seeking out proxies like the Tor network, or anonymizer.com.

    To be sure, many of the larger benefits of operating in China originally cited by Google four years ago — exposing the citizenry to services beyond those locally grown and monitored; engaging them beyond the “China Wide Web” to which some government officials aspire to limit them; and gaining market share that can create momentum and support for later loosening of restrictions — may attenuate.  Google.cn is less known and used than, say, the local Baidu search engine, which boasts about 60% market share.  That share is about to get even bigger.

    But drawing a line is both the right move and a brilliant one.  It helps realign Google’s business with its ethos, and masterfully recasts the firm in a place it will feel more comfortable: supporting the free and open dissemination of information rather than metering it out according to undesirable (and capricious) government standards.

  • Malicious Apps in the Android Market
  • As we knew would happen sooner or later, a dangerous malicious app has apparently made its way into Android’s Market. The app is said to “create[] a shell of mobile banking apps” and collect users’ personal information. It’s been removed; no word on how many users, if any, were actually affected.

    Offhand, I can’t think of an app with comparable problems that has gotten into iPhone’s app store. What will be really interesting about this incident, and the similar ones that are sure to follow, is how users and vendors react. I can imagine this creating hysterical urging for Google to pre-screen all Android apps the way Apple does, but I think that would be premature. Yes, an open Market(s) is going to have more questionable apps, but there are many solutions other than lockdown—a strong user ranking for apps (which already exists), a way to alert people who have already downloaded the app, sandboxing (which admittedly wouldn’t have mattered here), or a quick way to freeze the app while complaints are investigating. They’re only partial solutions, but lockdown is only partial, too.

    Now that the Android OS is really starting to take off, this story is going to be repeated, and we’ll get to see how strongly committed Google is to the principles it built the OS on — and whether there are models out there for vetting third party code that do better than those of the generative PC, but aren’t as restrictive as that of the iPhone.

    —By Elisabeth Oppenheimer

    Update: eWeek reports that Google has removed a number of suspicious apps from its marketplace.  Of course, the more generative structure of the Android market means that “banned” apps can be obtained elsewhere — unlike the iPhone app monopoly enjoyed by Apple, where the iPhone App store is the only point of distribution.  –JZ

About Jonathan Zittrain

jonathan zittrain

Jonathan Zittrain is Professor of Law at Harvard Law School and co-founder of the Berkman Center for Internet and Society at Harvard Law School

RSS Tweets from Z

  • Hosting Cliff Stoll at the Berkman Center tonight http://cyber.law.harvard.edu/events/2010/02/stoll
  • Iranian internet+sms "conveniently" slowing down b4 planned protests: http://bit.ly/9YzC3m
  • RT @ruskin147: http://bit.ly/aLmScH New blog post - Apple - an open and shut case. Linking to the Zittrain piece in FT - and starting in ...
  • iPad: a fight over freedom at Apple's core http://bit.ly/bglwoG

Blog Archives



Creative Commons BY-NC-SA Jonathan Zittrain unless otherwise noted.
Powered by WordPress using Gridline Lite.