Connect with us

Published

on

the human factor — Is cybersecurity an unsolvable problem? Ars chats with law philosopher Scott Shapiro about his new book, Fancy Bear Goes Phishing.

Jennifer Ouellette – May 27, 2023 1:12 pm UTC EnlargeFarrar, Straus and Giroux reader comments 156 with

In November 1988, a graduate student at Cornell University named Robert Morris, Jr. inadvertently sparked a national crisis by unleashing a self-replicating computer worm on a VAX 11/750 computer in the Massachusetts Institute of Technology’s Artificial Intelligence Lab. Morris had no malicious intent; it was merely a scientific experiment to see how many computers he could infect. But he made a grievous error, setting his reinfection rate much too high. The worm spread so rapidly that it brought down the entire computer network at Cornell University, crippled those at several other universities, and even infiltrated the computers at Los Alamos and Livermore National Laboratories.

Making matters worse, his father was a computer scientist and cryptographer who was the chief scientist at the National Security Agency’s National Computer Security Center. Even though it was unintentional and witnesses testified that Morris didn’t have “a fraudulent or dishonest bone in his body,” he was convicted of felonious computer fraud. The judge was merciful during sentencing. Rather than 1520 years in prison, Morris got three years of probation with community service and had to pay a $10,000 fine. He went on to found Y Combinator with his longtime friendPaul Graham, among other accomplishments.

The “Morris Worm” is just one of five hacking cases that Scott Shapiro highlights in his new book, Fancy Bear Goes Phishing: The Dark History of the Information Age in Five Extraordinary Hacks. Shapiro is a legal philosopher at Yale University, but as a child, his mathematician fatherwho worked at Bell Labssparked an interest in computing by bringing home various components, like microchips, resistors, diodes, LEDs, and breadboards. Their father/son outings included annual attendance at the Institute of Electrical and Electronics Engineers convention in New York City. Then, a classmate in Shapiro’s high school biology class introduced him to programming on the school’s TRS-80, and Shapiro was hooked. He moved on to working on an Apple II and majored in computer science in college but lost interest afterward and went to law school instead.

With his Yale colleague Oona Hathaway, Shapiro co-authored a book called The Internationalists: How a Radical Plan to Outlaw War Remade the World, a sweeping historical analysis of the laws of war that spans from Hugo Grotius, the early 17th century father of international law, all the way to 2014. That experience raised numerous questions about the future of warfarenamely, cyberwar and whether the same “rules” would apply. The topic seemed like a natural choice for his next book, particularly given Shapiro’s background in computer science and coding. Advertisement

Despite that background, “I honestly had no idea what to say about it,” Shapiro told Ars. “I just found it all extremely confusing.” He was then asked to co-teach a special course, “The Law and Technology of Cyber Conflict,” with Hathaway and Yale’s computer science department. But the equal mix of law students and computer science students trying to learn about two very different highly technical fields proved to be a challenging combination. “It was the worst class I’ve ever taught in my career,” said Shapiro. “At any given time, half the class was bored and the other half was confused. I learned nothing from it, and nor did any of the students.”

That experience goaded Shapiro to spend the next few years trying to crack that particular nut. He brushed up on C, x86 assembly code, and Linux and immersed himself in the history of hacking, achieving his first hack at the age of 52. But he also approached the issue from his field of expertise. “I’m a philosopher, so I like to go to first principles,” he said. “But computer science is only a century old, and hacking, or cybersecurity, is maybe a few decades old. It’s a very young field, and part of the problem is that people haven’t thought it through from first principles.” The result was Fancy Bear Goes Phishing.

The book is a lively, engaging read filled with fascinating stories and colorful characters: the infamous Bulgarian hacker known as Dark Avenger, whose identity is still unknown; Cameron LaCroix, a 16-year-old from south Boston notorious for hacking into Paris Hilton’s Sidekick II in 2005; Paras Jha, a Rutgers student who designed the “Mirai botnet”apparently to get out of a calculus examand nearly destroyed the Internet in 2016 when he hacked Minecraft; and of course, the titular Fancy Bear hack by Russian military intelligence that was so central to the 2016 presidential election. (Fun fact: Shapiro notes that John von Neumann “built a self-reproducing automaton in 1949, decades before any other hacker… [and] he wrote it without a computer.”)

But Shapiro also brings some penetrating insight into why the Internet remains so insecure decades after its invention, as well as how and why hackers do what they do. And his conclusion about what can be done about it might prove a bit controversial: there is no permanent solution to the cybersecurity problem. “Cybersecurity is not a primarily technological problem that requires a primarily engineering solution,” Shapiro writes. “It is a human problem that requires an understanding of human behavior.” That’s his mantra throughout the book: “Hacking is about humans.” And it portends, for Shapiro, “the death of ‘solutionism.'”

Ars spoke with Shapiro to learn more. Page: 1 2 3 4 Next → reader comments 156 with Jennifer Ouellette Jennifer is a senior reporter at Ars Technica with a particular focus on where science meets culture, covering everything from physics and related interdisciplinary topics to her favorite films and TV series. Jennifer lives in Baltimore with her spouse, physicist Sean M. Carroll, and their two cats, Ariel and Caliban. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

UK

Fireball at Southend Airport after small plane crashes

Published

on

By

Fireball at Southend Airport after small plane crashes

A small plane has crashed at Southend Airport in Essex.

Essex Police said it was at the scene of a “serious incident”.

Images posted online showed huge flames and a large cloud of black smoke, with one witness saying they saw a “fireball”.

A police statement said: “We were alerted shortly before 4pm to reports of a collision involving one 12-metre plane.

“We are working with all emergency services at the scene now and that work will be ongoing for several hours.

“We would please ask the public to avoid this area where possible while this work continues.”

Fireball after plane crash at Southend Airport. Pic: Ben G
Image:
A huge fireball near the airport. Pic: Ben G

It has been reported that the plane involved in the incident is a Beech B200 Super King Air.

According to flight-tracking service Flightradar, it took off at 3.48pm and was bound for Lelystad, a city in the Netherlands.

One man, who was at Southend Airport with his family around the time of the incident, said the aircraft “crashed headfirst into the ground”.

John Johnson said: “About three or four seconds after taking off, it started to bank heavily to its left, and then within a few seconds of that happening, it more or less inverted and crashed.

“There was a big fireball. Obviously, everybody was in shock in terms of witnessing it. All the kids saw it and the families saw it.”

Mr Johnson added that he phoned 999 to report the crash.

Southend Airport said the incident involved “a general aviation aircraft”.

Four flights scheduled to take off from Southend this afternoon were cancelled, according to its website.

Flightradar data shows two planes that had been due to land at Southend were diverted to nearby airports London Gatwick and London Stansted.

Smoke rising near Southend airport. Pic: UKNIP
Image:
Plumes of black smoke. Pic: UKNIP

Essex County Fire and Rescue Service said four crews, along with off-road vehicles, have attended the scene.

Four ambulances and four hazardous area response team vehicles are also at the airport, as well as an air ambulance, the East of England Ambulance Service said.

Its statement described the incident as “still developing”.

Fire engines at the scene at Southend Airport
Image:
Fire engines at the airport

David Burton-Sampson, the MP for Southend West and Leigh, posted on social media: “I am aware of an incident at Southend Airport. Please keep away and allow the emergency services to do their work.

“My thoughts are with everyone involved.”

Local councillor Matt Dent said on X: “At present all I know is that a small plane has crashed at the airport. My thoughts are with all those involved, and with the emergency services currently responding to the incident.”

This breaking news story is being updated and more details will be published shortly.

Please refresh the page for the latest version.

You can receive breaking news alerts on a smartphone or tablet via the Sky News app. You can also follow us on WhatsApp and subscribe to our YouTube channel to keep up with the latest news.

Continue Reading

World

Meredith Kercher’s killer faces new trial over sexual assault allegations

Published

on

By

Meredith Kercher's killer faces new trial over sexual assault allegations

The man convicted of the murder of British student Meredith Kercher has been charged with sexual assault against an ex-girlfriend.

Rudy Guede, 38, was the only person who was definitively convicted of the murder of 21-year-old Ms Kercher in Perugia, Italy, back in 2007.

He will be standing trial again in November after an ex-girlfriend filed a police report in the summer of 2023 accusing Guede of mistreatment, personal injury and sexual violence.

Guede, from the Ivory Coast, was released from prison for the murder of Leeds University student Ms Kercher in 2021, after having served about 13 years of a 16-year sentence.

Follow The World
Follow The World

Listen to The World with Richard Engel and Yalda Hakim every Wednesday

Tap to follow

Since last year – when this investigation was still ongoing – Guede has been under a “special surveillance” regime, Sky News understands, meaning he was banned from having any contact with the woman behind the sexual assault allegations, including via social media, and had to inform police any time he left his city of residence, Viterbo, as ruled by a Rome court.

Guede has been serving a restraining order and fitted with an electronic ankle tag.

The Kercher murder case, in the university city of Perugia, was the subject of international attention.

Ms Kercher, a 21-year-old British exchange student, was found murdered in the flat she shared with her American roommate, Amanda Knox.

The Briton’s throat had been cut and she had been stabbed 47 times.

(L-R) Raffaele Sollecito, Meredith Kercher and Amanda Knox. Pic: AP
Image:
(L-R) Raffaele Sollecito, Meredith Kercher and Amanda Knox. File pic: AP

Ms Knox and her then-boyfriend, Raffaele Sollecito, were placed under suspicion.

Both were initially convicted of murder, but Italy’s highest court overturned their convictions, acquitting them in 2015.

Continue Reading

Politics

RWAs build mirrors where they need building blocks

Published

on

By

RWAs build mirrors where they need building blocks

RWAs build mirrors where they need building blocks

Most RWAs remain isolated and underutilized instead of composable, DeFi-ready building blocks. It’s time to change that.

Continue Reading

Trending