I am going to shift gears here with Baby Got Bactria for a moment and take a look at what is going on in Central Eurasia today. One need not search for very long to find news of new laws limiting journalistic powers, penalizing certain forms of free speech, and the blacklisting certain websites in the former Soviet satellite states. This is also seen in Iran and over and down into the Middle East states. Yet even with this suspicion of the internet and its influence, there are also examples of Central Eurasian countries benefiting from its use. For example, there is a project in Kyrgyzstan to collect a photo archive, accessible to everyone, so people may learn about Kyrgyzstan's history. There is also the matter of e-commerce in Kazakhstan, an area of potentially incredible growth in the Kazakh economy, yet Kazakhstan cannot seem to keep itself from regulating and restricting information on the internet.
With these juxtaposing interests of freedom and authority active in the region, I have asked Dr. Joshua I. James of University College Dublin, Ireland and the website Cybercrime Technologies to share his thoughts on the issues facing Central Eurasia in Cyberspace.
BGB: I've read recently that Azerbaijan is considering a new law implementing stiff penalties for profanity and libel on the internet. Such legislation is being decried as a way to curb government critics. While attempts to legislate the internet seem to be in vogue right now, do you find these to be ultimately useless laws, or do you find them to be power-grabs by governments?
JJ: "I think Azerbaijan, like many other countries, are currently going through a period of realization that they don’t understand what this “Internet” thing actually is in terms of the role their government(s) will play in the future. Their natural reaction, as we have seen, is to attempt to impose a local law to something that is really much bigger than themselves. In most cases I don’t think they really care what the law is, as long as they look like they are doing something about the “problem” (locally). Because of the nature of the Internet, a lack of understanding, and a lack of willingness to do research, the majority of laws that are being passed right now are much, much too general, allowing many opportunities for abuse. We’ve seen abuses because of the general scope of laws like the U.S. Computer Fraud and Abuse Act, and the laws that (arguably) less developed democracies are proposing are normally much more general than that – very old - law.
I don’t believe every horrible law that is proposed is meant to be malicious, but is just the product of a person who is ignorant of the area trying to do something good without actually understanding the problem. That being said, with the Internet playing a key role in the Arab Spring, I think that was somewhat a wake-up call to some governments, or organizations within governments. I think many politicians saw a chance to sell cybersecurity as a National Security issue (which security experts have been yelling for years), and gain political power in doing so.
I believe cyber law is mostly, as you say, a power-grab right now. My primary reason for believing this is because countries that are extremely concerned with online profanity are rarely willing to work on the problem at a global level. They want to keep control, or even further oppress, their physical space in digital reality, not actually contribute to fighting a real problem. This tells me that they might actually be concerned with profanity, but they are also looking to abuse the power overly general laws will afford them. Do I think these laws are useless? No... I think they’re terrifying.
However, from what I’ve seen around the world, the people in most countries don’t really care what laws are passed, as long as 1) they don’t have to pay more for the Internet and 2) they think they are not being watched/filtered (I’m over-generalizing). Basically, trying to get people to pay attention to what is happening is impossible until it is far too late. With an attitude like that, power-grabs based around national cyber security are actually pretty effective."
BGB: Also, in relation to the previous question, do you think that hacktivism has become something of a great equalizer, pitting the "little guy" against "big governments"? Or do you feel that this hacktivism is fueling the fires of government calls for restriction of online freedoms and even access?
JJ: "I am quite mixed about hacktivism (again how, exactly, do we define hacktivism). I’m very much an advocate of openness, but not maliciousness. I find some ‘attacks’ where I might agree with the attacker’s sentiment, but completely disagree with the attack they used, or how data or information was used afterwards. In an article about legal protest and distributed denial of service, I tried to make an argument FOR legal civil protest using DDoS, but ultimately couldn’t find a way to justify it. Right now hacktivism, to me, seems more like bullying than communication. However, the bigger problem is that in most cases it is impossible to tell if something is hacktivism or malicious exploitation by criminals. For example, if a bank looses the personal records of 1,000,000 people, it is very hard to say in one case “ah, well they are just standing up for what they believe in – they will delete the data”, and in another “they stole the records to sell on the black market”. One, I can probably agree with, the other should probably be a crime. However, all we know is that the records were stolen, and not how the records will be used. And since hacktivists are usually relatively anonymous, should we actually trust they are using stolen data as they claim? If stolen data negatively affects the people AND the corporations, I don’t think I can agree with it. During protests we should be fighting to make things better for the people. If the people become collateral damage, then the protest is not worth it.
But in those cases, I am referring towards civil complains, not complains against the government. In civil cases, there should be some way to legally protest online. This means that the techniques that are used should be able to be differentiated from malicious hackers. Extreme force is not always necessary to get your point across.
In the case of hacktivism against governments, I think online attacks are becoming somewhat an equalizer. But I also think it is being abused. It is very easy to launch online attacks, and everyone has something to complain about. If hacktivism is always rather extreme, and is used whether it is an amendment violation or a parking violation, then the overall impact will be lessened. This reminds me of physical protests in Korea. Groups here protest different causes literally every day. The result of protesting every day is that the average person becomes desensitized, and quits caring about your cause. This makes groups more radical to get their point across, then people start hating these groups for being insane.
I think in terms of government activism there should be some sort of legalized channel of anonymous online protest, and when that fails, then other – potentially illegal – measures may be necessary in extreme cases. The problem now is that if everyone can launch an online protest, again, how do you differentiate protest from malicious attack when you cant identify the person attacking you. Keep in mind that governments and businesses are pretty much constantly under malicious attack. It would be best if there was a way to organize and control the use of extreme protest methods online, but centralized management is impossible. And you will always have a crazy person that wants to protest pickles on his hamburger by taking down a government website. To these organizations, hacktivism looks just like another malicious attack coming in.
I think in both cases the problem is attribution. Hacktivists would need to differentiate themselves from malicious hackers with some form of identification, and since hacktivsts use illegal methods to get their point across, they don’t want to identify themselves. The result, then, is that organizations can’t tell the difference, so they call for more online restrictions. Again, communication is key, and most hacktivist methods I have seen so far are not really about communication, but showing that they are stronger. And I think intimidation methods hurt everyone in the long run."
Dr. Joshua I. James is a research fellow at UCD Ireland. He is currently in South Korea working with the South Korean police on cybercrime and investigative methods in digital forensic research.
No comments:
Post a Comment