Security professionals probably spend too much time and money securing their systems and too little checking to see whether their security measures have failed. After putting a new security solution in place at great cost, it’s only natural to think that you’ve, well, solved your security problems. But the history of computer security, not to […]
Author Archive | Stewart Baker
More on Attribution and Retribution: Si Chuan University and Tencent
A few posts back, I told the story of how Trend Micro identified “Luckycat,” a Chinese hacker who had attacked the Dalai Lama, aerospace firms, and other targets. Based on what we know so far, it looks likely that the hacker is Gu Kaiyuan, formerly a student at Si Chuan University’s Information Security Institute and […]
Sex Secrets of the Security Line
“I … watch him working at the stove. His easy concentration, economical movements, setting up in me a procession of sparks and chills.” — Alice Munro, Dear Life Three pages after this passage, Alice Munro’s virginal young narrator goes to bed with the man at the stove. That will come as no surprise to most […]
The Right To Be … Oh, Forget It
The harshest blow yet has been struck against the European Commission‘s wacky “right to be forgotten.” What’s worse, the blow came from another European Union agency, the European Network and Information Security Agency, or ENISA. And, worst of all, ENISA trashed the right to be forgotten in the most innocent and most devastating way possible: […]
Attribution and Retribution: The Anvisoft Case
Attribution of cyberattacks is getting easier, but we’re still bad at the next step: retribution. A case in point is Brian Krebs’s clever investigation of a new antivirus company, Anvisoft. He offers compelling reasons to believe that Anvisoft is run by a notorious Chinese hacker who helped attack a DoD contractor and others several years […]
Cyberwar and Industrial Controls: A conversation with Ralph Langner
I got a call the other day from Ralph Langner, the man who reverse-engineered Stuxnet. He wanted to compare views on cyberweapons and industrial control systems. These systems have now been installed in most of the infrastructure that supports civilian life. But Stuxnet showed how vulnerable such systems can be to cyberattack. I fear that […]
The Hackback Debates — Together at Last
In recent years, Orin Kerr has debated hacking law with two of his cobloggers, Stewart Baker and Eugene Volokh. The issue: whether federal law prevents network owners from hacking those who are hacking them. Spread over several years and multiple posts and comments, the debates have been hard to find and harder to read. No […]
Republicans Briefly Repudiate 40 Years of Tougher Copyright Laws
As the fight over SOPA wound down, I predicted that SOPA might be turn out to be a watershed, permanently turning Tea Party Republicans into copyright skeptics: For Republicans, opposition to new intellectual property enforcement is starting to look like a political winner. It pleases conservative bloggers, appeals to young swing voters, stokes the culture […]
When Should Government Suppress the Truth About Powerful Men?
That’s a trick question. Government is always tempted to punish those who reveal unwelcome truths, just as it’s always tempted to protect the rich and powerful by selective enforcement of vague laws. But even good liberals and libertarians seem to have trouble seeing the problem when suppression of truth and protection of the powerful is […]
The Latest Victim of European Privacy Law? Privacy Itself
Transcending parody, the European Union has proposed a privacy regulation that will inevitably deprive many people of their privacy. The regulation, now working its way through the tortuous Brussels process, includes a “right to data portability.” This is typically oversexed Commission-speak for a regulatory requirement that information services must hand over all of a subscriber’s […]
Georgia pwn my mind: the face of a Russian cyberspy?
I’ve been beating the drums for the value of tracking down the cyberspies who are attacking US government agencies and private companies alike. Somebody seems to be listening. Counterhackers have already unmasked a Chinese cyberspy. And now the government of Georgia has landed an even bigger fish, seizing control of a cyberspy’s computer and taking screen […]
The Legality of Counterhacking: Baker’s Last Post
Now the debate with Orin is actually getting somewhere. Sort of. Here’s a scorecard: 1. Does authorization depend exclusively on ownership? Orin’s latest post does a good job of showing that the CFAA often draws a coherent distinction between rights in data and rights in a computer, and that rights in the computer are the statute’s […]
The Legality of Counterhacking: Baker Replies to Kerr
Orin Kerr and I agree that “authorization” is the central, and undefined, key to criminal liability under the CFAA. In Orin’s view, “authorization” can be determined by asking two questions: First, does the CFAA protect computers or data? And, second, who controls a computer, the data owner or the computer owner? It seems to me […]
RATs and Poison II — The Legal Case for Counterhacking
In an earlier post, I made the policy case for counterhacking, and specifically for exploiting security weaknesses in the Remote Access Tools, or RATs, that hackers use to exploit computer networks. Poisoning an attacker’s RAT is a good idea for at least three reasons. First, we can make sure the RAT doesn’t work or that […]
RATs and Poison: Can Cyberespionage Victims Counterhack?
More good news for network security: It turns out that the tools attackers use to control compromised computers are themselves full of security holes. A couple of undergrads interning for Matasano Security have reverse-engineered the Remote Access Tools (RATs) that attackers use to gain control of compromised machines. According to Dark Reading, Jesse Hertz and Shawn […]