- The Strategist - https://www.aspistrategist.org.au -

Cyber wrap

Posted By on August 31, 2016 @ 12:30

Image courtesy of Flickr user Jeso Carneiro.

Kicking off this week, China has invited [1] foreign tech corporations to join its government’s central technical committee. Technical Committee 260, which reports to the Cyberspace Administration of China, is responsible [2] for establishing China’s cyber security standards and will now feature Cisco, IBM, Intel and Microsoft as members. The move comes after intense criticism [3] of China’s cyber regulations for being tough on international business interests, and has been interpreted as an attempt to placate those concerns. Ostensibly, these companies will now play a role in drafting China’s cyber security legislation; however the extent of their influence is still an unknown.

Cyber cooperation isn’t all Beijing has on its mind however. Kaspersky stats show Chinese hacking of the defense, aviation and nuclear industries in Russia has almost tripled [4] since the beginning of the year. The clear focus on cyber espionage targeting critical national interests, rather than financial cybercrime on corporations, suggests these activities were either approved or undertaken by official Chinese representatives. This uptick of Russia’s cyber suffering at the hands of the Chinese has interestingly coincided with a recent drop [5] in Chinese targeting of the US in cyberspace. Russia and China have historically demonstrated a fair degree of cooperation on cyber security, creating [6] and updating [7] a code of conduct for information security through the Shanghai Cooperation Organisation in 2011 and 2015, signing a bilateral ‘non-aggression pact [8]’ in May last year and releasing a joint statement [9] in June this year. However, these recent hacking trends may have confirmed suspicions [10] that such public comradeship may only be surface deep.

Privacy feathers have been ruffled this week, with WhatsApp announcing [11] a new information sharing deal with Facebook. WhatsApp will now [12] disclose phone numbers and user activity analytics to its parent company in order to facilitate more targeted advertising and friend suggestions on Facebook, as well as fight spam. The new policy has raised eyebrows [13] across the world, representing WhatsApp’s first diversion from its famous privacy vow [14] and Facebook’s first steps to monetise the platform since purchasing it for US$22 billion in 2014. The good news is that users have the choice to opt-out [15] of this new policy change—but you’d better move fast because the window to do so is only open for 30 days. WhatsApp has provided a slightly awkward ‘how-to’ guide here [16].

The privacy battle between government and civil society continues in America. Last week, tech giants vocally rejected [17] the Obama administration’s proposal to request the social media accounts of foreign visitors in an attempt to identify terrorist threats. The proposed change [18] would create a field stating ‘please enter information associated with your online presence’ on the US’s ESTA and I-94W arrival/departure forms. The companies, including Google, Facebook and Twitter, warn [19] that the proposed measure will ‘have a chilling effect on the use of social media networks, online sharing and, ultimately, free speech online’. Civil liberties advocacy groups have also argued [20] in an open letter that beyond invading individuals’ personal privacy, this measure will be ‘ineffective and prohibitively expensive to implement and maintain’.

Across the Atlantic, France and Germany are pushing [21] for a European crackdown on encryption technology in response to the recent wave of terrorist attacks in Europe. The German Interior Minister, Thomas De Maizière, and his French counterpart, Bernard Cazeneuve, put forward a joint proposal [22] calling on the European Commission to draft a law obliging [23] online messaging services to monitor content and assist law enforcement with decryption efforts when required. As expected, the move sparked opposition [24] from European industry groups who argue that enforcing such backdoors ‘ultimately leaves online systems more vulnerable’. It seems Europe is following in the footsteps of the privacy–security debate that has unfolded in the US over the last year.

Debate continues over the identity, capability and credibility of the Shadow Broker hackers who several weeks ago [25] hosted on online auction of programs apparently nabbed from the NSA. Importantly, this content was stolen from another hacking team [26], Equation Group, and is actually fairly old, containing no programs more recent than October 2013. The indirect leak supposedly reveals some of the top secret cyber tools used by the spy agency to surveil American security companies such as Cisco and Fortinet. However, recent realisations [27] that these tools contain the ability to compromise the firewalls of Chinese tech manufacturer Huawei have given even deeper insight into the scope of NSA operations. The contents of the Shadow Brokers dump have seemingly been confirmed as authentic [28] by correlations with previously unreleased Snowden documents. Learn more about the speculated ‘who and how’ of the hack with this Engadget article [29] and read this Lawfare piece [30] for a low down of the questions that should be asked of the NSA in response.

And finally, check out Monday night’s episode of Four Corners, boldly titled ‘Cyber War [31]’. While it won’t teach well-informed cyber nerds anything new, it’s a welcome fourth estate attempt to raise public awareness of cyber security. You can read commentary on the episode here [32] and here [33].



Article printed from The Strategist: https://www.aspistrategist.org.au

URL to article: https://www.aspistrategist.org.au/cyber-wrap-134/

URLs in this post:

[1] invited: http://www.wsj.com/articles/china-moves-to-ease-foreign-concerns-on-cybersecurity-controls-1472132575

[2] responsible: http://www.cbronline.com/news/cybersecurity/business/microsoft-and-cisco-join-chinese-cyber-security-programme-4990378

[3] criticism: http://www.reuters.com/article/us-cyber-china-business-idUSKCN10S0DG?il=0

[4] almost tripled: http://www.bloomberg.com/news/articles/2016-08-25/russia-more-prey-than-predator-to-cyber-firm-wary-of-china

[5] drop: https://www.fireeye.com/blog/threat-research/2016/06/red-line-drawn-china-espionage.html

[6] creating: https://ccdcoe.org/sites/default/files/documents/UN-110912-CodeOfConduct_0.pdf

[7] updating: https://ccdcoe.org/sites/default/files/documents/UN-150113-CodeOfConduct.pdf

[8] non-aggression pact: http://blogs.wsj.com/digits/2015/05/08/russia-china-pledge-to-not-hack-each-other/

[9] joint statement: http://www.chinadaily.com.cn/china/2016-06/26/content_25856778.htm

[10] suspicions: http://blogs.cfr.org/cyber/2016/06/30/despite-cyber-agreements-russia-and-china-are-not-as-close-as-you-think/

[11] announcing: https://www.whatsapp.com/faq/en/general/28030012

[12] will now: http://www.nytimes.com/2016/08/26/technology/relaxing-privacy-vow-whatsapp-to-share-some-data-with-facebook.html?_r=1

[13] raised eyebrows: http://www.bloomberg.com/news/articles/2016-08-29/whatsapp-privacy-changes-raise-eu-concern-over-user-data-control

[14] famous privacy vow: https://blog.whatsapp.com/529/Setting-the-record-straight

[15] choice to opt-out: http://www.wired.com/2016/08/how-to-stop-whatsapp-from-sharing-your-phone-number-with-facebook/

[16] here: https://www.whatsapp.com/faq/general/26000016

[17] vocally rejected: http://www.politico.com/story/2016/06/social-media-screening-homeland-security-224786

[18] proposed change: https://www.federalregister.gov/articles/2016/06/23/2016-14848/agency-information-collection-activities-arrival-and-departure-record-forms-i-94-and-i-94w-and#p-16

[19] warn: http://www.politico.com/story/2016/08/social-media-screening-privacy-227287

[20] also argued: https://cdt.org/insight/coalition-letter-opposing-dhs-social-media-collection-proposal/

[21] pushing: http://www.reuters.com/article/us-europe-attacks-france-germany-idUSKCN10Y174

[22] joint proposal: http://www.interieur.gouv.fr/Le-ministre/Interventions-du-ministre/Initiative-franco-allemande-sur-la-securite-interieure-en-Europe

[23] obliging: http://www.theverge.com/2016/8/24/12621834/france-germany-encryption-terorrism-eu-telegram

[24] opposition: http://www.ccianet.org/2016/08/tech-industry-warns-against-french-german-plans-to-weaken-encryption/

[25] several weeks ago: http://www.aspistrategist.org.au/cyber-wrap-132/

[26] another hacking team: http://www.wired.co.uk/article/nsa-hacking-tools-stolen-hackers

[27] recent realisations: https://motherboard.vice.com/read/nsa-huawei-firewalls-shadow-brokers-leak

[28] confirmed as authentic: https://theintercept.com/2016/08/19/the-nsa-was-hacked-snowden-documents-confirm/

[29] Engadget article: https://www.engadget.com/2016/08/26/untangling-the-nsas-latest-alleged-embarrassment/

[30] Lawfare piece: https://www.lawfareblog.com/nick-asks-nsa-shadow-brokers-and-leaking-ship

[31] Cyber War: http://www.abc.net.au/4corners/stories/2016/08/29/4526527.htm

[32] here: http://www.news.com.au/technology/online/hacking/australian-cyber-crime-threats-four-corners-investigates-how-hackers-are-hacking-into-our-information/news-story/71a30e2f53f8b530a08dbd2c3dd4996a

[33] here: https://theconversation.com/are-things-really-as-bad-as-the-abc-four-corners-cyber-war-documentary-makes-out-64572

Copyright © 2016 The Strategist. All rights reserved.