Slashdot Mirror


Threat of Cyberwar Is Over-Hyped

nk497 writes "A new OECD report suggests the cyberwar threat is over-hyped. A pair of British researchers have said states are only likely to use cyberattacks against other states when already involved in military action against them, and that sub-state actors such as terrorists and individual hackers can't really do much damage. Dr. Ian Brown said, 'We think that describing things like online fraud and hacktivism as cyberwar is very misleading.'"

123 comments

  1. Well... by Monkeedude1212 · · Score: 3, Interesting

    Good thing the US isn't at involved in any military action with anyone.

    Oh wait. is that WoT thing still going?

    1. Re:Well... by jusdisgi · · Score: 4, Insightful

      A pair of British researchers have said states are only likely to use cyberattacks against other states when already involved in military action against them...

      Right. Tell that to the Iranians who just lost 984 uranium-enrichment centrifuges to a US/Israeli worm.

      --
      Given a choice between free speech and free beer, most people will take the beer.
    2. Re:Well... by cacba · · Score: 1

      Was stuxnet a one sided attack and therefore not a cyberwar?

    3. Re:Well... by blueg3 · · Score: 1

      And if the Stuxnet worm wasn't state-developed, then certainly sub-state actors are doing substantial damage.

    4. Re:Well... by scorp1us · · Score: 0

      Someone has to fire first, and I hope everyone remembers we did.

      While I don't want to over-generalize, Russian hackers are top-notch. We have may started a war we're going to lose. As more and more Russian systems go Linux, and we keep writing checks to Microsoft for shoddy code, I expect us to be at a full disadvantage.

      --
      Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
    5. Re:Well... by PolygamousRanchKid+ · · Score: 4, Funny

      Right. Tell that to the Iranians who just lost 984 uranium-enrichment centrifuges to a US/Israeli worm.

      The official explanation from the British Foreign Office stated that the centrifuges were not lost, but merely resting, after a long squawk, and were pining for the fjords.

      Norwegian centrifuges stun easily.

      --
      Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
    6. Re:Well... by trendzetter · · Score: 2

      It has never been proven that Iranian uranium-enrichment centrifuges where damaged by Stuxnet. The Iranians deny it. I wouldn't rely on the NYT for information about such topics. It might well be a propaganda spin.

    7. Re:Well... by icebike · · Score: 1

      Your point is well made.

      However, the question remains as to whether the US and Isreal, (not to mention the Saudis) were already engaged in military action (covertly), and about to be engaged overtly.

      Perhaps there was already military action, just short of lethal weaponry?

      The Guardian has a story that suggests there may have already been an attack on Iranian nuclear facilities by this time had it not been for the success of Stuxnet, as well as targeted assassinations of key scientists.

      Add to this the Iranian's claim to have shot down more than one US Navy UAV, and various reports (never proven) of special forces missions, and you might be on firm ground to suggest that there is already military involvement.

      So while in this case, as you point out, the British researchers' opinions look false on their face, perhaps they are simply working on a different definition of "Military Involvement".

      --
      Sig Battery depleted. Reverting to safe mode.
    8. Re:Well... by ColdWetDog · · Score: 1

      It has never been proven that Iranian uranium-enrichment centrifuges where damaged by Stuxnet. The Iranians deny it. I wouldn't rely on the NYT for information about such topics. It might well be a propaganda spin.

      Quite right. It's not like the Iranians wouldn't try to hide the fact they got taken for a ride. FWIW, it's been reported by numerous other journalistic outlets, the virus itself has infected countries other than Iran and has been subject to quite a bit of detailed scrutiny.

      But of course, it could all be a put on by Symantec.

      --
      Faster! Faster! Faster would be better!
    9. Re:Well... by Anonymous Coward · · Score: 0

      Tell that to the Iranians who just lost 984 uranium-enrichment centrifuges to a US/Israeli worm.

      Why would they use a PLC to control a centrifuge?
      Why was there no overspeed safety on the centrifuge?
      Is there proof that actually happened?

      This sounds more like bad design or BS.

    10. Re:Well... by Anonymous Coward · · Score: 0

      And the OECD are a bunch of clowns who can't be trusted to give you the truth anyways. Ever seen their press releases? Might as well be Fox News. Group these guys in with others who want to control what you think and do, such as the World Bank and IMF.

    11. Re:Well... by treeves · · Score: 1

      Yeah, they shoulda just used rheostats and some college interns to run around and set the centrifuge speeds manually.

      --
      ...the future crusty old bastards are already drinking the Kool-Aid.
    12. Re:Well... by plover · · Score: 1

      It has never been proven that Iranian uranium-enrichment centrifuges where damaged by Stuxnet. The Iranians deny it. I wouldn't rely on the NYT for information about such topics. It might well be a propaganda spin.

      That's funny, because the president of Iran admitted it. He said

      Ahmadinejad admitted the worm had affected Iran's uranium enrichment. "They succeeded in creating problems for a limited number of our centrifuges with the software they had installed in electronic parts," the president said. "They did a bad thing. Fortunately our experts discovered that, and today they are not able [to do that] anymore."

      That means very little, other than that you probably shouldn't rely on an Iranian news source for actual news about Iran.

      --
      John
    13. Re:Well... by LifesABeach · · Score: 1

      Who's to say it wasn't someone else? Iran does a lot of business with China, and the Middle Kingdom would more than enjoy helping by providing more hardware. I would find it hard to accept that the events in Iran were only limited to governments. There are far more inciteful and vicious businesses out there that could only profit by the events in the Farsi State.

      Just a thought, but considering these events, should underwear be Internet Enabled?

    14. Re:Well... by shoehornjob · · Score: 1

      My government (for better or worse) can't seem to function properly unless we're at war with something or someone. This sort of behaviour seems to be inexorably linked to profit taking by multinational corporations and defense contractors. Same old crap.

      --
      "We are just a war away from Amerikastan. When god vs god the undoing of man." Dave Mustaine
    15. Re:Well... by shoehornjob · · Score: 1

      Wish I hadn't posted since the above post re: the Iranian reactors lost to a worm is a perfect example of cyberwarfare.

      --
      "We are just a war away from Amerikastan. When god vs god the undoing of man." Dave Mustaine
    16. Re:Well... by w1z4rd · · Score: 1

      Exactly. Not to

    17. Re:Well... by SnowZero · · Score: 2

      I was curious about stuxnet so I read the various stories (though many have quite flimsy evidence), and read up on gas centrifuges as used in enrichment.

      Why would they use a PLC to control a centrifuge?

      These things operate pretty close to their mechanical limits, and exact speed control is apparently necessary to make sure the forces applied match the gas flow rates and thermal gradient used. Mess up any of those and you won't get good separation. Also, the controllers are designed to power quickly through speeds that are harmonic with the resonant frequency of centrifuge or its housing.

      Why was there no overspeed safety on the centrifuge?

      The worm caused the controller to lie to the process monitoring system, so those safety controls would not apply. As I mentioned earlier, the centrifuges don't appear to have a lot of margin between nominal operation and mechanical limits, so their may not be any fail-safe speed limits on the device itself (instead it would just be in the controller). Additionally in a radiation environment it probably makes sense to put all controls on the controller and make the centrifuge itself a "dumb" assemblage.

      This is just speculation on my part, but my guess is that instead of running the centrifuge at overspeed, the worm ran them at a resonant frequency, which would shake the centrifuge apart while staying within speed limits. Even if this is the case though, I doubt you'll see it in a news story since it is not something a typical journalist would understand, and if they did they might not want to explain it to their readers.

      Is there proof that actually happened? This sounds more like bad design or BS.

      The evidence right now is very circumstantial, but consistently points in the direction of a directed attack. Few parties have both the technical means and motive for an attack like this, so it seems likely to be a state-sponsored. It will be interesting to see if more information eventually comes to light.

    18. Re:Well... by L7_ · · Score: 1

      The iranians first causes millions of twitter users to turn their icons green. If that is not a first strike, I don't know what is.

    19. Re:Well... by thegarbz · · Score: 1

      Why resort to manual labour when they invented 3-15PSI pneumatic controllers for a reason :-)

    20. Re:Well... by cold+fjord · · Score: 1

      Stuxnet targeted Iran, not Russia.

      --
      much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
    21. Re:Well... by Anonymous Coward · · Score: 0

      The NYT is more likely to be spinning some propaganda than the Iranians? Excuse me, but your bias is showing.

    22. Re:Well... by RussellSHarris · · Score: 1

      Cyber-warfare will likely always be guerrilla warfare: one-sided surprise attacks.

    23. Re:Well... by tehcyder · · Score: 1

      Stuxnet targeted Iran, not Russia.

      And it is Israel and the US who want to prevent Iran's nuclear power/weapons program, not Russia.

      --
      To have a right to do a thing is not at all the same as to be right in doing it
    24. Re:Well... by scorp1us · · Score: 1

      Who has been helping Iran? Russia.

      --
      Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
    25. Re:Well... by ewanm89 · · Score: 1

      Just because a country doesn't mount a defense doesn't mean it's not an act of war to march troops into that country without an alliance treaty.

  2. Perhaps... by Pojut · · Score: 2, Insightful

    Perhaps the "movie science/actual science" effect is going on here...example: people see "Hackers", and think that's what "hacking" is. People then see either a script kiddy in their mom's basement or a government techie with sky-high stacks of paper on his desk (or working at a scarily-clean desk), and realize the actual act is pretty damn boring.

    1. Re:Perhaps... by snookerhog · · Score: 1

      this made me think of Cloak and Dagger for some reason.

    2. Re:Perhaps... by _Sprocket_ · · Score: 1

      Hacking (in all senses of the word) is not a spectator sport. You can't watch someone poking at code or discovering an exploit / compromising a system and understand the feeling of elation unless you, yourself, have felt that elation. The excitement is personal. Or at least, the excitement requires considerable background knowledge. Capturing that is a difficult challenge. As you noted, it tends to make a pretty poor movie scene.

    3. Re:Perhaps... by Cryacin · · Score: 1

      Have you ever seen a chess match?!?

      --
      Science advances one funeral at a time- Max Planck
    4. Re:Perhaps... by _Sprocket_ · · Score: 1

      Are you saying a chess match would make a good movie scene? And yes - seen a chess match. Not all that interesting unless you're in to the game. Which means you have personal experience and the considerable background knowledge the appreciate it.

    5. Re:Perhaps... by Nadaka · · Score: 1

      Have you seen the chess match between Kai and the prince of fire in LEXX?

    6. Re:Perhaps... by _Sprocket_ · · Score: 1

      No. But I have seen LEXX before. As far as I've been able to determine, it isn't a documentary and their take on chess might be somewhat removed from the experiences of the average player.

    7. Re:Perhaps... by Nadaka · · Score: 1

      It very much removed, but it was both entertaining and technically accurate.

    8. Re:Perhaps... by Noughmad · · Score: 1

      A chess match is usually much better understandable than program code to a general audience.

      --
      PlusFive Slashdot reader for Android. Can post comments.
    9. Re:Perhaps... by _Sprocket_ · · Score: 1

      It very much removed, but it was both entertaining and technically accurate.

      Alright - entertaining, yes. But not exactly educational or representing what chess is about. There's been movies done about hacking that are reasonably accurate and entertaining as well. But for the most part, the subject isn't handled well and I still maintain that is because the subject is difficult to handle in an entertaining way without presenting an entirely inaccurate portrayal.

  3. Yes and no by geekoid · · Score: 4, Insightful

    Yes, describing fraud and hackivism as cyber war is misleadg.

    No, it's not over-hyped.

    Cyber-war is cheap, the knowledge on how to do it is free, and it doesn't need to take much manpower, as compared to conventional war.

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    1. Re:Yes and no by Anonymous Coward · · Score: 0

      And there was just a news report on it recently... stuxnet anyone???

      http://www.nytimes.com/2010/11/19/world/middleeast/19stuxnet.html?_r=1

    2. Re:Yes and no by Anonymous Coward · · Score: 0

      Still doesn't beat good ole carpet bombing though.

    3. Re:Yes and no by marcosdumay · · Score: 1

      That depends. Do you wan't to do the bombing with drones?

    4. Re:Yes and no by Tablizer · · Score: 1

      So it's like terrorism: it may not necessarily take out a whole city, but it sure the hell can be annoying

  4. It's about control not reality by commodore64_love · · Score: 5, Insightful

    There's no real threat of cyberwar. And there's no real threat of me being blown by an airplane terrorist. But that's completely irrelevant for government leaders desiring to control everything within their sight.

    So enjoy your slef-portrait porn, scanner-induced skin cancer, your breast/penis fondling by the SA, and the eventual limitations placed upon the internet/free speech. It's inevitable.

    --
    "I disapprove of what you say, but I will defend to the death your right to say it." - historian Evelyn Beatrice Hall
    1. Re:It's about control not reality by fishexe · · Score: 4, Funny

      And there's no real threat of me being blown by an airplane terrorist.

      Well, no, I think nearly all airplane terrorists are men who don't swing that way. But it would be an interesting experience right before getting blown up.

      --
      "I don't care about the Constitution!" --Bill O'Reilly, November 17, 2009
    2. Re:It's about control not reality by Anonymous Coward · · Score: 0

      And there's no real threat of me being blown by an airplane terrorist.

      Well, no, I think nearly all airplane terrorists are men who don't swing that way. But it would be an interesting experience right before getting blown up.

      Actually, the local nationals I worked with in the U.S. Army while stationed in Iraq had a saying: "Women are for babies, men are for fun."

      So... You just need to ask in a different way. I'm sure they swing "that" way.

    3. Re:It's about control not reality by Anonymous Coward · · Score: 0

      You're right. There is no threat. Not right now, because the internet doesn't belong to anyone, hurting people on the internet would serve no military goal, bring down no installations or cause nuclear wars. But the moment, the internet becomes, state property or state regulated, like what the US is trying to do, then you get a whole slew of opportunities to explore.

      People keep bringing up that Iran bit and their centrifuges, my question is this, why do they have an internet connection? Were their plans for nuclear bombs downloaded from the internet?

      Do other countries do that? Does the US connect it's F-16s and drones to the internet, and send hourly tweets? Even if they need to communicate from one end of the country to another, wouldn't any military use it's own communications network?

      If they don't, well, gamers have an expression for this: EPIC FAIL!

    4. Re:It's about control not reality by Anonymous Coward · · Score: 0

      Well, what better way to keep the passengers from becoming unruly than by... relaxing them? A happy ending for a passenger gives the terrorists time for their own happy ending.

    5. Re:It's about control not reality by rickb928 · · Score: 1

      "There's no real threat of cyberwar."

      Um, citations, please.

      And there's no real threat of me being blown by an airplane terrorist."

      Same for me, but that's because I rarely fly nowadays.

      "But that's completely irrelevant for government leaders desiring to control everything within their sight."

      Their reactions would be the same if they were instead desiring to not to be in office when an attack was successful. Bonus points for thwarting attacks in a way that can be disclosed. More points if any of various terrorist groups claim to be planning attacks and nothing happens...

      "So enjoy your slef-portrait porn, scanner-induced skin cancer, your breast/penis fondling by the SA, and the eventual limitations placed upon the internet/free speech. It's inevitable."

      Yes, indeed. Many excuses available for the powers to do these things. We must be vigilant.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    6. Re:It's about control not reality by Nadaka · · Score: 1

      You're right. There is no threat. Not right now, because the internet doesn't belong to anyone, hurting people on the internet would serve no military goal, bring down no installations or cause nuclear wars. But the moment, the internet becomes, state property or state regulated, like what the US is trying to do, then you get a whole slew of opportunities to explore.

      People keep bringing up that Iran bit and their centrifuges, my question is this, why do they have an internet connection?

      They were not connected to the internet, they were infected by USB drives.

      Were their plans for nuclear bombs downloaded from the internet?

      Do other countries do that? Does the US connect it's F-16s and drones to the internet, and send hourly tweets?

      South Korea has semi autonomous internet enabled gun turrets in select banks to replace on site guards. Is that close enough?

      Even if they need to communicate from one end of the country to another, wouldn't any military use it's own communications network?

      If they don't, well, gamers have an expression for this: EPIC FAIL!

    7. Re:It's about control not reality by khallow · · Score: 1

      People keep bringing up that Iran bit and their centrifuges, my question is this, why do they have an internet connection?

      Why do people still think that Stuxnet came in on an internet connection? There's been plenty of talk about this. Stuxnet is known to be able to infect UBS sticks. It's also possible that someone inserted it deliberately into some of the internal systems. Sure, we don't know details of Iran's IT infrastructure for its nuclear program, but given that a direct connection from your internal, "secure" industrial site to the whole outside world is colossally stupid and the worm had other ways to get in, why assume that Iran is colossally stupid?

    8. Re:It's about control not reality by commodore64_love · · Score: 1

      -1 Flamebait

      Really? Which part?

      --
      "I disapprove of what you say, but I will defend to the death your right to say it." - historian Evelyn Beatrice Hall
  5. Historical Contradiction by royallthefourth · · Score: 3, Informative

    Perhaps they are unaware that the US and Israel have just recently made a computer attack against Iran, where there is no actual military confrontation.

  6. Does targetted malware count? by ballsbot · · Score: 3, Informative

    I guess they didn't read yesterday's new york times: http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html

    1. Re:Does targetted malware count? by trendzetter · · Score: 0

      It has never been proven that Iranian uranium-enrichment centrifuges where damaged by Stuxnet. The Iranians deny it. I wouldn't rely on the NYT for information about such topics. It might well be a propaganda spin.

  7. News media touts sensationalist trash! by Anonymous Coward · · Score: 0

    Story at 11!

  8. "can't really do much damge"? by v1 · · Score: 1

    sub-state actors such as terrorists and individual hackers can't really do much damage.

    Considering the presence of many brands of botnets for hire, I'd strongly disagree with that. Anyone with the cash can launch a cyber-attack.

    Or look at what "Anonymous" has been doing lately. Or are they a state now?

    --
    I work for the Department of Redundancy Department.
    1. Re:"can't really do much damge"? by Anonymous Coward · · Score: 0

      Anonymous hasn't been doing much at all lately except getting undeserved media attention. The attacks against PayPal, Amazon, MasterCard, etc. haven't done anything except make a small group of people stroke their e-peen.

      Posted Anonymously for humor.

    2. Re:"can't really do much damge"? by Anonymous Coward · · Score: 0

      >stroke their e-peen.

      Mission objectives accomplished.

    3. Re:"can't really do much damge"? by krou · · Score: 4, Insightful

      I recently submitted a story to /. that is related to this very topic. Chief of defence staff in the UK, General Sir David Richards, argued a little while ago that the UK should have a cyber command, and that the UK faces what he called a 'horse verses tank moment' in coping with modern warfare, saying the the rules of war had changed as a result of the success of insurgents in Iraq/Afghanistan, and the threat of non-state actors. In particular, he said that 'We must learn to defend, delay, attack and manoeuvre in cyberspace, just as we might on the land, sea or air and all together at the same time. Future war will always include a cyber dimension and it could become the dominant form. At the moment we don't have a cyber command and I'm very keen we have one. Whether we like it or not, cyber is going to be part of future warfare, just as tanks and aircraft are today. It's a cultural change. In the future I don't think state-to-state warfare will start in the way it did even 10 years ago. It will be cyber or banking attacks — that's how I'd conduct a war if I was running a belligerent state or a rebel movement. It's semi-anonymous, cheap and doesn't risk people.'"

      --
      'If Christ had tweeted the sermon on the mount, it might have lasted until nightfall.' - John Perry Barlow
    4. Re:"can't really do much damge"? by M.+Baranczak · · Score: 2

      Or look at what "Anonymous" has been doing lately.

      Yes, let's look at that. What did Anonymous accomplish? They brought down a few websites for a couple of hours.

      And most of their targets didn't actually need their websites to conduct business, so it barely affected them (PayPal was the big exception).

    5. Re:"can't really do much damge"? by Anonymous Coward · · Score: 0

      They accomplished a lot of publicity.

    6. Re:"can't really do much damge"? by internettoughguy · · Score: 1

      I recently submitted a story to /. that is related to this very topic. Chief of defence staff in the UK, General Sir David Richards, argued a little while ago that the UK should have a cyber command, and that the UK faces what he called a 'horse verses tank moment' in coping with modern warfare, saying the the rules of war had changed as a result of the success of insurgents in Iraq/Afghanistan, and the threat of non-state actors. In particular, he said that 'We must learn to defend, delay, attack and manoeuvre in cyberspace, just as we might on the land, sea or air and all together at the same time. Future war will always include a cyber dimension and it could become the dominant form. At the moment we don't have a cyber command and I'm very keen we have one. Whether we like it or not, cyber is going to be part of future warfare, just as tanks and aircraft are today. It's a cultural change. In the future I don't think state-to-state warfare will start in the way it did even 10 years ago. It will be cyber or banking attacks — that's how I'd conduct a war if I was running a belligerent state or a rebel movement. It's semi-anonymous, cheap and doesn't risk people.'"

      I for one welcome our new bloodless cyber-war overlords. I think StarCraft 5 should be the medium mandated by the Seoul Conventions of 2025 and 2032.

    7. Re:"can't really do much damge"? by Anonymous Coward · · Score: 0

      2025? More like Starcraft 3.

  9. The real problem... by fuzzyfuzzyfungus · · Score: 4, Insightful

    Is that the term "cyberwar" is pretty stupid. In fact, it isn't just stupid, it is so misleading(intentionally or otherwise) that letting it slip into your lexicon makes you dumber.

    "war" carries with it a strong series of historical associations, lessons learned, rules of thumb, rules, likelihoods, etc. Virtually none of them really map all that well into the area of computer security. If you use the term "cyberwar", though, you are implicitly trying to mash those (comfortingly familiar) concepts into a badly-fitting new environment. In a much less serious vein, this is why most movies that feature a "hacking" sequence usually make hacking look like beating a video game- because video games are "computery"; but they work very hard to simulate familiar rules.

    Electronic attacks are a costly problem and, if some idiot connects the wrong control systems to the internet, or a laptop to the wrong control systems, potentially a dangerous one; but trying to map them into the historical concepts of "war" just doesn't work very well.

    1. Re:The real problem... by cacba · · Score: 1

      I disagree, viruses infiltrating enemy electronics can have a very similar affect to human infiltrating enemy structures. A few similar capabilities are sabotaging production and leaking information. They are also similar in that it is difficult to prove who controls them. Cyberwar may be a silly name but it is correct in the characterization. It is a new domain and because it hasnt seen many important attacks is struggling to be separated from its lone hacker past.

    2. Re:The real problem... by jfengel · · Score: 3, Insightful

      It's really computer espionage and/or sabotage. Those have been parts of warfare for as long as there has been war.

      Since the Internet lets you engage in espionage and sabotage with zero risk of being physically caught, it changes the dynamic to something we haven't seen before. But it's not completely unrelated to warfare as it's always been done. The real constant about it is the lack of constants, as the level of technology constantly increases and presents new opportunities to thwart or take advantage.

    3. Re:The real problem... by Anonymous Coward · · Score: 0

      As an addendum to my above comment; what would you call the taliban using off-the-shelf software to monitor the unencrypted UAV feeds? If that doesn't fit everyones definition for electronic warfare deployed by a non-state actor against a state-actor, I don't know what will.

    4. Re:The real problem... by Anonymous Coward · · Score: 0

      Perhaps the issue is you're only looking at "cyberwar" as defensive.

    5. Re:The real problem... by marcosdumay · · Score: 1

      Spionage isn't war. The name is dumb.

      You can use spionage in a war. But it is not the same as murdering lots of people.

    6. Re:The real problem... by fuzzyfuzzyfungus · · Score: 1

      Did anything about my comment suggest that either espionage or sabotage would not see updates to electronic means? Historically, those two have always closely followed the material culture of their targets, and I see no reason why this will be any different. If anything, that is more or less why "cyberwar" is such a gapingly stupid analogy: "cyber" activity is, to the degree it resembles any prior activity, espionage and sabotage much more than warfare.

    7. Re:The real problem... by AlienIntelligence · · Score: 1

      Is that the term "cyberwar" is pretty stupid. In fact, it isn't just stupid, it is so misleading(intentionally or otherwise) that letting it slip into your lexicon makes you dumber.

      "war" carries with it a strong series of historical associations, lessons learned, rules of thumb, rules, likelihoods, etc.

      Electronic attacks are a costly problem and, if some idiot connects the wrong control systems to the internet, or a laptop to the wrong control systems, potentially a dangerous one; but trying to map them into the historical concepts of "war" just doesn't work very well.

      Ahh, I see. And by your determination, the bit of electronics I have in my pocket that
      I make "telephone calls" with is thus, not a telephone because it doesn't have the
      strong historical associations with MaBell's horkin large plastic behemoth that has
      been hanging from my mom's kitchen wall for the past 40 years.

      Got it!

      -AI

      --
      For me, it is far better to grasp the Universe as it really is than to persist in delusion
    8. Re:The real problem... by Anonymous Coward · · Score: 0

      Oh I see, so to match your definition, you just redefined war so that it didn't include espionage, sabotage and other related war-time activities.

      In that case, youre correct!

      So if you had to track down the origin of the word, I'm pretty sure you'd find that cyberwar was some GS15s term because he realized that information assurance was not what we were really talking about anymore. Dismissing it because you don't like the word is just, well silly.

    9. Re:The real problem... by fuzzyfuzzyfungus · · Score: 3, Insightful

      Your proposed reductio ad absurdem is actually a pretty decent example: The two are not fundamentally and utterly different, both cellphones and landlines are capable of making voice calls, just as both "cyberwar" and conventional war are ways of applying pressure to foreigners you don't like; but the broad similarities obscure a vast number of salient differences:

      Your old-school landline was associated with a place, in that its area code probably actually meant something, it was physically terminated in a given building(which, if a residence, quite likely had more occupants than phone lines). Also, billing may well have drawn a distinction between "local" and "long distance". It was further localized in that, unless specifically unlisted, it would be printed in the local telephone directory.

      Your cellphone, by contrast, is more typically connected with a person. Odds are that its area code is nearly arbitrary, it is listed in no phone books, and its billing is flat at least within an entire country, if not more broadly. It is not at all uncommon for a household to have a cell per person, and, since there is no physical hookup, even people without addresses commonly have them.

      There are also the broader social changes: social event organization certainly isn't the same if you can only call somebody when you are both in a building with a phone. Just ask an old person about the rise of the spontaneous "eh, we'll figure it out as we go and text you" model of social planning. That simply didn't work with the old material culture. Never mind the(less notable in the wealthy west; but dramatic among the poor here and abroad) change from "you basically can't get a line run and provisioned for less than $$ a month; but the calls cost essentially nothing" to "calls cost $/minute; but you can literally get a phone and some starter minutes at any corner store for 15-20bucks".

      Also, of course, we have the fact that landline phones work very well as dumb extensions of the network. The older ones are even powered by it. Thus, the landline world has seen an almost complete dichotomy: phones, which have remained dumb as bricks, with the exception of message machines, and modem-connected computers, which are wholly free of telco control and treat the network as a dumb pipe. Cellphones, on the other hand, have to be pretty sophisticated devices just to work, so they started sprouting additional features early; but were always much more creatures of the carriers. Hence the continuing differences between the evolution of the "smartphone" and the evolution of internet-connected devices with their heritage in modem-linked PCs.

      I don't wish to claim that yours is precisely analogous to "war" vs. "cyberwar"; but I would very much claim that it does demonstrate the sort of important changes that an apparently simple switch can hide. My contention would be that somebody trying to approach a "cyberwar" based on the "war" part would be roughly like somebody trying to use a bleeding-edge smartphone by looking things up in the phone book and attempting to rotary dial the touch screen.

  10. There's an elephant in the living room. by russotto · · Score: 4, Insightful

    The cyberwar is already ON between state actors. Stuxnet, for instance. Certainly targeted at Iran, almost certainly developed by the US, Israel, or both. There's the attack on Google and other non-Chinese companies from China in 2009 as well.

    IMO, now that Stuxnet has paved the way, we WILL see cyberterrorism directed at other SCADA systems.

    1. Re:There's an elephant in the living room. by Anonymous Coward · · Score: 1

      The cyberwar is already ON between state actors.

      Has been for years, amazing how many people have seen the NSA portrayed in TV and films but have not heard of INFOSEC.

    2. Re:There's an elephant in the living room. by _Sprocket_ · · Score: 1, Insightful

      And that elephant is named "espionage." The only difference today is that the systems are more complex and interconnected. Otherwise, "cyber-war" is no different than the ongoing spying and sabotage that's been practiced for decades. Espionage was never it's own entity which is why "cyber-war" is misleading.

    3. Re:There's an elephant in the living room. by amicusNYCL · · Score: 1

      There's the attack on Google and other non-Chinese companies from China in 2009 as well.

      Not to mention Titan Rain, from 2003.

      --
      "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
  11. In a Perfect World by jasnw · · Score: 4, Insightful

    Granted that Cyberwar (sound of clashing cymbols) is overhyped, but a key assumption in this article is that governments and key private organizations (power grid operators, network operators, etc) are doing everything they can to protect their systems. I find this assumption to be laughably naive. The point to be made here is that cyberwar is often used as a bludgeon to obtain resources, or persue hackers in court (Wikileaks, anyone?), and is a bit over-hyped. There are, however, clear dangers in this area which can be avoided if prudent steps are taken (not putting power-grid controlling on the Internet, for example). Given the US's penchant for letting private industry do what it wants, and given that private industry only cares about this-quarter bottom-line earnings, I still see even the "small fry" identified in this article as being capable of some nasty mischief.

  12. its probably safe to ignore... by Anonymous Coward · · Score: 1

    I mean their example of what they consider cyberwar is the estonia thing, which pretty much means they couldn't have done much research considering the US and China have been battling it out for well over 10 years.

    But beyond that, they're economics professors! Why do educated people try to convey messages about stuff they're not educated in? Isn't that how the whole 'thermite did 9/11' thing started? By not realizing that thermite is more or less a fancy word for 'finely crushed aluminum', sorta like what you would expect to find at a plane crash !

    even more absurd is that they wont end up eating the words that non-nation-states couldn't be effective in this arena. I think they think it requires multi-billion dollar rocket research or something.

  13. Only likely when already involved ? HA! by i_want_you_to_throw_ · · Score: 3, Interesting

    states are only likely to use cyberattacks against other states when already involved in military action against them

    Ho, that's rich! There is speculation that the U.S. and Israel are behind Stuxnet which is dedicated to screwing up Iran. And why not? Why wait until military action? In fact in this case if you can screw the Iran infrastructure up enough, you may not even need to have a military action against them.

    Also a lot of this depends on your definition of cyberwar.

    China is doing the smart thing right now by backing cyber attacks against the US infrastructure. Before engaging an opponent, it's good to know their weaknesses. The US government uses a lot of Microsoft products as does China now. (China bought shared source years ago). If I were the Chinese I would be setting up servers and hacking them down just to record things like recovery time, etc.

    This ain't your daddy's cyberwar. It's all about probing and sizing up an opponent these days.

  14. Almost everything in the News is "over-hyped" by mschaffer · · Score: 3, Insightful

    Since the news media likes to repeat the same thing over, and over, and over, just about anything that hits the national press is either over-hyped or about to be over-hyped. That's just the way it is. Cyberwar is no different.

  15. Opiate by tanujt · · Score: 2

    Oh come now, we need all the hype to keep our unsatisfactory, unhappy, dull and routine days mildly entertaining. Media sensationalism is the new opiate of the masses. How dare a research study take that away from us, by blatantly stating facts?!

  16. No. by Anonymous Coward · · Score: 1

    I guess they didn't read yesterday's new york times:
    http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html

    No.
    So, who was actually hurt? Were there any casualties?

    No one was hurt. Most Persian civilians went about their business. The Government had one of their projects set back. BFD.

    Comparing that to war just dilutes what war really means just as much as the "War on Drugs", "War on Terrorism", and every other hyperbolic statement made by media, government and anyone else who has an agenda - like computer security people selling their services and wares.

    1. Re:No. by AlienIntelligence · · Score: 1

      No.
      So, who was actually hurt? Were there any casualties?

      No one was hurt. Most Persian civilians went about their business. The Government had one of their projects set back. BFD.

      Comparing that to war just dilutes what war really means just as much as the "War on Drugs", "War on Terrorism", and every other hyperbolic statement made by media, government and anyone else who has an agenda - like computer security people selling their services and wares.

      Are you requiring casualties and injuries in order to make the determination of war??

      In fact, I think a clearer representation of what fuels the undertakings of war was
      your one line:
      "The Government had one of their projects set back."

      Uh-huh... I think THAT is the purpose of war.

      -AI

      --
      For me, it is far better to grasp the Universe as it really is than to persist in delusion
  17. *cough* Stuxnet *cough* by nweaver · · Score: 1

    Sorry, we already have a counterexample in Stuxnet: a highly enginnered, highly malicious 'cyber-warface' class attack, launched outside of open hostilities with the intended aim of destroying portions of the target's infrastructure.

    Stuxnet has now said 'if you don't get caught, its open season'.

    --
    Test your net with Netalyzr
  18. This is new. by jimmerz28 · · Score: 1

    Wait...are they saying that the media over-hyping something so that people constantly feel that there is/are imminent threat(s)? Sounds totally different than the war on drugs/terror/immigration/[insertscarythinghere]!

  19. Anonymous Coward by Anonymous Coward · · Score: 0

    "Hey, look at us, we have a report."

  20. There's a lot of money to be made in security... by interfecio · · Score: 1

    The cost of securing is much greater than the losses will ever be. There's good money to be made and jobs to be created on both sides.

  21. Why the hell would states restrict usage? by fishexe · · Score: 4, Insightful

    Why the hell would states restrict usage to conflicts that they're already prepared to engage in with conventional militaries? Dr. Brown himself admits that it's hard to tell the source of an attack, which creates plausible deniability for a state actor to engage in all sorts of conduct they otherwise might not get away with, including (potentially) both of the attacks Brown mentions which might have involved Russia, and all of the Chinese attacks against the US for the past 2 or 3 years, and of course Stuxnet. Why would countries turn down an opportunity to use these types of attacks on their enemies? Just because they're not officially fighting? Yeah, right. Granted cyber-warfare is much more likely to be used for black ops than for a full-scale long-term attack on another country's infrastructure, but that's warfare too. It's "unconventional warfare", but warfare nonetheless.

    --
    "I don't care about the Constitution!" --Bill O'Reilly, November 17, 2009
  22. So what happens...? by itamblyn · · Score: 1

    So what happens 20 Years from now when we all have robots connected to the internet living in our offices and houses?

    1. Re:So what happens...? by Anonymous Coward · · Score: 1

      new rule to add onto asimov's

      Never connect a robot to the internet.

    2. Re:So what happens...? by Isaac+Remuant · · Score: 1

      Some Robots already were connected to multivac. The difference probably relies on the fact that Multivac was run by the government.

      If we could actually apply Asimov's 3 rules to computers and robots we'd probably be on the right track. :P

      --
      "Science can amuse and fascinate us all, but it is engineering that changes the world. " - Asimov.
  23. Cyber espionage by He+who+knows · · Score: 3, Insightful

    Would be a much better name for it. Infact I would go as far as to call it espionage.

    1. Re:Cyber espionage by Anonymous Coward · · Score: 0

      I'd leave the "cyber" out of the name altogether. Just typing that word makes me feel about five points dumber.

  24. Translation... by GodfatherofSoul · · Score: 2

    Nothing to see here, move along, your unsecured networks are perfectly safe as they stand.

    --
    I swear to God...I swear to God! That is NOT how you treat your human!
  25. NSAs cant do much damage? by Nidi62 · · Score: 4, Insightful

    Do they mean like when, during the incident in Georgia, Russian hackers brought down the primary bank used by most Georgians for about a week? Look at what happened at 9/11. In physical terms, the damage was slight. A couple planes, a few buildings, and several thousand people gone. The actual act didn't really affect anything. It was the response generated by the attack-the fear, the anger-that prompted the stock market to drop, and the US to invade 2 countries. Terrorists do not care about physical damage, they go after symbolic targets that will create the most psychological damage. Say al-Qaeda brought down Bank of America's online systems for a few days. Economically it would not have much of an impact overall. However, it would shake people's confidence in the system, cause huge overreactions, and the damage would come not from the attack but from the response.

    Consider this example: you want to attack the population of a walled city, and you have something that will make a water supply useless. What is going to have the bigger impact, poisoning the stream that runs by the walls, or poisoning the well in the middle of the town? With cyber attacks, a terrorist can essentially do this without ever having to set foot inside the walls. You want to really cause problems in the US and the rest of the West? You don't attack an embassy, or a military convoy. You don't even have to directly, physically attack the civilian populace. You simply attack their wallets. Make people worried that they can't get to their money, and you will have caused real problems.

    --
    The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    1. Re:NSAs cant do much damage? by AlienIntelligence · · Score: 1

      Say al-Qaeda brought down Bank of America's online systems for a few days. Economically it would not have much of an impact overall.

      It would not have much of an impact overall??? I guess that
      means you bank with Well's Fargo or some other bank?

      Cause, if B of A was down for a few days, I would be so
      fucked it would be stupid.

      I'm one of these that bought into the, don't carry cash anymore.

      So, yeah, I don't. And if BofA went offline let's say yesterday
      morning cause I did my shopping, got gas, etc in the evening...
      I would be so completely fucked. I wouldn't have money in my
      pockets, I wouldn't have food for me to eat or for my poor dog

      If BofA went offline for a few days, that means no gas for me to
      go to work, no food for me or my dog. Couldn't necessarily bum
      some money from someone else for the same reasons... they're
      not carrying any, or they're banking with BofA, etc. And I live way
      out in BFE, no carpooling.

      So, maybe you're leading a life more off-grid than I, but I do
      enjoy 'electronic conveniences' and would see a CyberWarfare
      Attack on our banking infrastructure as a break-out-the-stealth-
      fighters-and-bombers-and-pound-them actionable offense.

      I guess the fallacy there would be 'to whom do we do the pounding'
      without a propensity of evidence pointing to them as culprits.

      Wait a minute, I live in the US... we don't need evidence!

      -AI

      --
      For me, it is far better to grasp the Universe as it really is than to persist in delusion
  26. Be careful with that word - War by Anonymous Coward · · Score: 0

    If "Cyberwar" is war, then we should bomb China?

    Or Iran has justification to bomb Israel and the US?

  27. Anyone by SnarfQuest · · Score: 2

    Anyone who leaves their machines open to invasion deserve what they get. My machines are well protected and will never be &*^#&%^#&

    Buy our H3RB4L V14GR4. Is the bestest availleable.

    --
    Who would win this election: Andrew Weiner vs Andrew Weiner's weiner.
  28. I've been saying this for years by PingXao · · Score: 1

    Where's my check?

  29. do not underestimate by Anonymous Coward · · Score: 0

    it's not overhyphed

    I'm glad someone's already mentioned the Georgian incident

    it seems how little of an idea people have how much countries depend on electronic means to communicate

    you nuke a country's comms in some shape or form, you can march right in and start to claim while they can't even holler for backup

  30. No one cares what cyberwar means exactly. by jfz · · Score: 0

    And this is why it is still in use. It's about TV specials, movies, and instilling enough fear to protect government IT sector jobs -and thus necessitating the lumping of enough bad guys together to justify contractor expenditures.

  31. CyberWar CyberEspionage by fluffy99 · · Score: 3, Insightful

    states are only likely to use cyberattacks against other states when already involved in military action against them

    Well Stuxnet has already blown that theory. Network intrusions and system compromises are only part of the equation. Cyber espionage is alive and well and extremely prevalent. The only difference between a cyber-attack and cyber-espionage is whether you're just stealing valuable info or actively damaging things. China is only interested in acquiring technical knowledge at this point. Also by quietly exfiltrating data as they are, it makes it much harder to find out just how deep they are. If they start breaking things, their methods and access gets discovered. Better to be quiet and maintain access in case they want to turn malicious and actively disrupt things..

  32. Want to really mess things up? by Anonymous Coward · · Score: 0

    I wish the Chinese or some other capable country for that matter, would hack into the credit card companies and wipe away people's debt. That would sure cause serious trouble -- not to mention dancing in the streets -- because the companies weren't paid real money.

  33. A line from Cory Doctorow's Little Brother may ... by D4C5CE · · Score: 1

    The high school kids who broke it were Brazilian Linux hackers who lived in a favela - a kind of squatter's slum.
    Never underestimate the determination of a kid who is time-rich and cash-poor.

    ...also apply to what the authors discard as "less capable states and sub-state actors".

  34. A couple of points by rickb928 · · Score: 2

    First, there are plenty of non-states that would like to, and indeed are this moment planning to, cause harm to the United States, its people, and other nations that are generally considered our allies. Even some that are not. This motivation has, in the past, been expressed by actions that are not those of a conventional military, nor of even fairly unconventional war. Trying to dismiss 'cyberwar' as something that is not likely because it would not be termed 'war' misses the point and wastes my time.

    War by technical manipulation of the Internet, etc., would be damaging, and it is not inconceivable that it could cost lives directly and indirectly. This meets any definition of war that I'm interested in working with. Parsing the words will not change the outcomes, so let's stop that, ok?

    And it should be obvious that adversaries that are not 'states' will certainly not be less motivated to do us harm by 'cyberwar' means just because such means don't involve massive visible, physical damage and attendant casualties. Indeed, many will see this as a method that can yield them substantial gains for what is limited exposure to retaliation.

    I'm left thinking that not only do many Slashdotters buy into this 'no cyberwar threat' campaign, but that our leaders may. Discounting a new weapon is not a good military strategy. Perhaps we won't be using guns and bullets to fight this fight, but actually a well-placed explosive could isolate any number of cyberwar forces if they are limiting themselves to their home states. Needless to say, these combatants will be dispersing themselves to avoid being cut off, literally, from their battlefield. Finding them will be the challenge. Deflecting and mitigating the attacks will be needed, but finding the actual perpetrators will be a challenge. The question will be if this is necessary.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
    1. Re:A couple of points by AlienIntelligence · · Score: 1

      I'm left thinking that not only do many Slashdotters buy into this 'no cyberwar threat' campaign, but that our leaders may

      Really? Last place in the world I would expect people to "not get it"
      would be here. Maybe I see my fellow /.'rs as a different animal,
      but I'd expect a full 90% here to be the rallying cry for "watch out".

      And I'm just allowing 10% for the typical populous of naysayers.

      -AI

      --
      For me, it is far better to grasp the Universe as it really is than to persist in delusion
    2. Re:A couple of points by rickb928 · · Score: 1

      Many here try to minimize the threat. I understand, but of course, there's the delusion thing...

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    3. Re:A couple of points by Anonymous Coward · · Score: 0

      First, America would like to, and indeed are this moment planning to, cause harm to the Other Nations, and its people that are generally considered our allies. Even some that are not. This motivation has, in the past, been expressed by actions that are not those of a conventional military, nor of even fairly unconventional war. Trying to dismiss 'cyberwar' as something that is not likely because it would not be termed 'war' misses the point and wastes my time. (If you're so busy then why are you spending time here?)

      War by technical manipulation of the Internet, etc., would be damaging, and it is not inconceivable that it could cost lives directly and indirectly. ( Citation Needed) This meets any definition of war that I'm interested in working with. ( Dictionaries be damned!, my definition is all that matters!) Parsing the words will not change the outcomes, so let's stop that, ok?(Do not debate this, it could mess up my point, okay?)

      And it should be obvious that adversaries that are not 'states' will certainly not be less motivated to do us harm by 'cyberwar' means just because such means don't involve massive visible, physical damage and attendant casualties. Indeed, many will see this as a method that can yield them substantial gains for what is limited exposure to retaliation.

      I'm left thinking that not only do many Slashdotters ( I'm not a 'slashdotter' but I will appeal to you) buy into this 'no cyberwar threat' campaign, but that our leaders may. (ignoring that "our leaders" are the ones pushing this direction) Discounting a new weapon is not a good military strategy. Perhaps we won't be using guns and bullets to fight this fight, but actually a well-placed explosive (what does explosives have to do with cyber warfare?, please stay on topic. "Smart Bombs" have already proven themselves to be anything but "Smart") could isolate any number of cyberwar forces if they are limiting themselves to their home states.(Why would they? You can pivot attacks easily today, even skiddies can now thanks to metasploit) Needless to say, these combatants (they aren't people, they are "enemy combatants", fuck human rights and the rule of law. Excellent choice of words here) will be dispersing themselves to avoid being cut off, literally, from their battlefield. Finding them will be the challenge. Deflecting and mitigating the attacks will be needed, but finding the actual perpetrators will be a challenge. The question will be if this is necessary.

      (I can only hope you are being paid for this because "Why would anyone shill for anyone else in the "western hemisphere" if they aren't being financially compensated for doing so?)

    4. Re:A couple of points by rickb928 · · Score: 1

      What?

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    5. Re:A couple of points by rickb928 · · Score: 1

      It took two cups of coffee (one half-caffeinated) to get this.

      First, you're here, your a Slashdotter, even if you're an AC.

      I spend time here for the same reason you do - the discussion. Even busy people do things, my friend, but wasting my time is the same whether I'm busy or not. The ad hominem attack has set the stage. Already you dislike me as much as you dislike my opinions. Nice.

      Citations for damages and casualties from 'war by technical maipulation of the Internet' are plentiful, so long as we limit ourselves to physical damage. Most recently, the Stuxnet worm is credited with damage to Iran's nuclear processing facilities. I use the phrase 'war by technical maipulation of the Internet' badly, I admit, because the sensitivity to the use of 'cyber' anything is great. I wonder if there were any injuries in Iran as a result of the problems with centrifuges? I don't take any pleasure in that thought, but if it did, then you have an example of casualties.

      My topic is not limited to electronic warfare, but encompasses retaliation by whatever means. Certainly you can understand that if you send someone sitting next to you an insulting text message, you risk a response. Even a verbal response could be seen as an escalation. Me? I might just get up and move away, depending on the nature of the insult. But if we knew where a camp of programmers were working to do damage to U.S. utilities, for instance, at the least we might drop a 'not so smart' bomb on their Internet connection. There are exceptions, and this might not be the response in all circumstances. If you're knowledgable in this realm, you might have some better ideas,but I make a hypothetical case that does not match reality much at all. There will be no camps of programmers. They will be dispersed. Bombs won't be much use at all.

      And certainly, you're wiser than to pretend that war, in and of itself, is an affront to human rights and the rule of law. You sound as if you think boxing, for example, should somehow prevent each participant from actually hurting the other. No, that isn't boxing. And there is no such thing as a 'polite' war. Yes, there is such a thing as egregious violations of human rights in war, but you'll prefer to focus on the conduct of others, I suspect.

      Alas, though, now I'm disappointed, You wrote, in part;

      "Why would anyone shill for anyone else in the "western hemisphere"

      I get it. You got a problem with the Western Hemisphere? I understand. Yes, I really do.

      --
      deleting the extra space after periods so i can stay relevant, yeah.
  35. Like riding a moped by mevets · · Score: 1

    you don't want your friends to see you on one...

    Who would admit to Windows on industrial controllers? It is embarrassing, to say the least.

  36. My vision of Cyber War by drunken-yeti · · Score: 1

    emacs -batch -l CYBERWAR #You have joined WAR WITH CHIRAN >Attack Router You find yourself in a very cold room with lots of wires there is an Ogar guarding the door >Attack Servers You begin to attack servers, and notice a Firwall intrusion alert. As you try to block it, you are logged out of the remote host. You are dead. You have scored 0 out of a possible 90 points.

  37. Cyberwut? by Anonymous Coward · · Score: 0

    I've always thought, wrongly perhaps, that 'Cyberwar' which supposedly only includes actions that take place on the internet, is actually something that's been done for a while. It was/is known as 'Electronic warfare'.

    Jamming transmissions of various sorts while maintaining your own working network for battlefield communications, among other things.

    The two things seem to go hand in hand to me as being high tech, spooky type stuff. Maybe I've been watching too many movies, and playing too many video games. lol.

    BUT...if the US was to attack a nation of significant technical prowess, you can bet your ass there will be some 'cyber-E-war' involved. Whatever it takes basically. This also works in reverse...

    Maybe someone just needs to come up with a less cheesy term for it? The word Cyber is thrown around way too much. Cybersex and Cyberwar are just too close for comfort IMHO.

  38. A generalization... by 200_success · · Score: 1

    The threat of "cyber-" anything is overhyped.

  39. Straighten up! by U8MyData · · Score: 1

    Ya think!? Seriously, the thing that concerns me the most is very caustic blend between any give management team and IT. I've been around a long time and have seen way too many occurances of exceptions in Infosec that are just unbelievable. I just recently had to make a payment on something and asked the bank how I could contact someone to arrange the details. I got a nice little e-mail from someone in management that I could call anyone with the payment details or I could just "e-mail" my name cc#, cvc, and exp date of my card. What? Are you kidding? A financial institution and a management person committing the cardinal sin of the banking business? I am still highly PO'd and still wondering what the F to do with that. I'd like to make an example out of all of this, but I fear I am much to small to have a big enough voice. However, if the very people we expect to maintain our financial information can't; how are we to expect anything more from anyone else unless there is a price to pay for such lunacy. Back on track, the reason we are so hackable; there is no accountability except for those poor folks in the basement trying to secure things. The public side doesn't give a sh*t, management doesn't until they are embarrased, and the guy in the basement turning the gears loses his/her job. The American way, no?

  40. Maybe by b4upoo · · Score: 1

    Online fraud is not usually terroristic. I have no issue at all with that. But when the combined effect of online fraud is considered it places a huge economic burden on some nations. Sex sites are similar. By themselves those sites are harmless. But the combined effect is eating half of the net alive. The power use for sex sites alone is a burden on society. So to what degree do we know that foreign powers are involved in promoting such things with war like intentions?

  41. Re:CyberWar CyberEspionage by Anonymous Coward · · Score: 0

    StuxNet is only a glimpse of the big picture. There are others used at defense & aerospace systems. See Slide #37:
    http://events.ccc.de/congress/2010/Fahrplan/attachments/1767_SAP_SECURITY-Ertunga_Arsal-Rootkits_and_Trojans-SLIDES.pdf

  42. WoT? by Anonymous Coward · · Score: 0

    > Oh wait. is that WoT thing still going?

    Yeah, I think they are still making Wheel of Time books, but what's that got to do with anything?

  43. When already involved in military action... by AlienIntelligence · · Score: 2

    "A pair of British researchers have said states are only likely to use cyberattacks against other states when already involved in military action against them"

    That is a ridiculously stupid assertion.

    IANAG, and...

    I haven't studied every war in history but I'm pretty sure they all
    started when "another state" instigated military action. Now the
    journalistic view of a war starting is a jet taking off or a tank rolling
    into town. But it can just as easily be started by someone hitting the
    ENTER key.

    Best thing you could do for your war is to do some meat tenderizing
    on every computer system you can gain access to, immediately
    preceding a military movement into another territory. Keep them
    imbalanced and busy. Potentially blind. If you knock their internet
    off, no tweeting/email/FB about the insurgency, etc. Keep the civis
    in the dark.

    I have no reason to believe that "CyberWarfare" won't be just as
    an effective tool in the WarToolChest as any other society disrupting
    attacks.

    -AI

    --
    For me, it is far better to grasp the Universe as it really is than to persist in delusion
    1. Re:When already involved in military action... by GrpA · · Score: 2

      Absolutely correct. Consider that one state wants resources that another state also desires and both are negotiating with a third state to secure them.

      Now imagine that one of the states has the information and capability to disrupt the resources of both the supplier and it's competing state. It will gain a serious competative advantage in doing do right?

      Warfare isn't just about shooting at people. Gains to the state can be made through many means. Through the barrel of a gun is just one of them. Electronic attacks and disruptions are another. Equating that both must be present to indicate warfare is naive.

      Those on the frontlines see the attacks and observe the intent. Perhaps it's best described as a Cyber-Cold War, because no one is admitting hostilities. But it is happening.

      Though some people say that war is only real to those who are exposed directly to it. Clearly, the authors involved are not.

      GrpA

      --
      Enjoy science fiction? "Turing Evolved" - AI, Mecha, Androids and rail-gun battles. What more could you want?
  44. The cyberwar will not be televised by Nyder · · Score: 1

    Instead, you can catch it on alt.com

    --
    Be seeing you...