Connect with us

Published

on

the human factor — Is cybersecurity an unsolvable problem? Ars chats with law philosopher Scott Shapiro about his new book, Fancy Bear Goes Phishing.

Jennifer Ouellette – May 27, 2023 1:12 pm UTC EnlargeFarrar, Straus and Giroux reader comments 156 with

In November 1988, a graduate student at Cornell University named Robert Morris, Jr. inadvertently sparked a national crisis by unleashing a self-replicating computer worm on a VAX 11/750 computer in the Massachusetts Institute of Technology’s Artificial Intelligence Lab. Morris had no malicious intent; it was merely a scientific experiment to see how many computers he could infect. But he made a grievous error, setting his reinfection rate much too high. The worm spread so rapidly that it brought down the entire computer network at Cornell University, crippled those at several other universities, and even infiltrated the computers at Los Alamos and Livermore National Laboratories.

Making matters worse, his father was a computer scientist and cryptographer who was the chief scientist at the National Security Agency’s National Computer Security Center. Even though it was unintentional and witnesses testified that Morris didn’t have “a fraudulent or dishonest bone in his body,” he was convicted of felonious computer fraud. The judge was merciful during sentencing. Rather than 1520 years in prison, Morris got three years of probation with community service and had to pay a $10,000 fine. He went on to found Y Combinator with his longtime friendPaul Graham, among other accomplishments.

The “Morris Worm” is just one of five hacking cases that Scott Shapiro highlights in his new book, Fancy Bear Goes Phishing: The Dark History of the Information Age in Five Extraordinary Hacks. Shapiro is a legal philosopher at Yale University, but as a child, his mathematician fatherwho worked at Bell Labssparked an interest in computing by bringing home various components, like microchips, resistors, diodes, LEDs, and breadboards. Their father/son outings included annual attendance at the Institute of Electrical and Electronics Engineers convention in New York City. Then, a classmate in Shapiro’s high school biology class introduced him to programming on the school’s TRS-80, and Shapiro was hooked. He moved on to working on an Apple II and majored in computer science in college but lost interest afterward and went to law school instead.

With his Yale colleague Oona Hathaway, Shapiro co-authored a book called The Internationalists: How a Radical Plan to Outlaw War Remade the World, a sweeping historical analysis of the laws of war that spans from Hugo Grotius, the early 17th century father of international law, all the way to 2014. That experience raised numerous questions about the future of warfarenamely, cyberwar and whether the same “rules” would apply. The topic seemed like a natural choice for his next book, particularly given Shapiro’s background in computer science and coding. Advertisement

Despite that background, “I honestly had no idea what to say about it,” Shapiro told Ars. “I just found it all extremely confusing.” He was then asked to co-teach a special course, “The Law and Technology of Cyber Conflict,” with Hathaway and Yale’s computer science department. But the equal mix of law students and computer science students trying to learn about two very different highly technical fields proved to be a challenging combination. “It was the worst class I’ve ever taught in my career,” said Shapiro. “At any given time, half the class was bored and the other half was confused. I learned nothing from it, and nor did any of the students.”

That experience goaded Shapiro to spend the next few years trying to crack that particular nut. He brushed up on C, x86 assembly code, and Linux and immersed himself in the history of hacking, achieving his first hack at the age of 52. But he also approached the issue from his field of expertise. “I’m a philosopher, so I like to go to first principles,” he said. “But computer science is only a century old, and hacking, or cybersecurity, is maybe a few decades old. It’s a very young field, and part of the problem is that people haven’t thought it through from first principles.” The result was Fancy Bear Goes Phishing.

The book is a lively, engaging read filled with fascinating stories and colorful characters: the infamous Bulgarian hacker known as Dark Avenger, whose identity is still unknown; Cameron LaCroix, a 16-year-old from south Boston notorious for hacking into Paris Hilton’s Sidekick II in 2005; Paras Jha, a Rutgers student who designed the “Mirai botnet”apparently to get out of a calculus examand nearly destroyed the Internet in 2016 when he hacked Minecraft; and of course, the titular Fancy Bear hack by Russian military intelligence that was so central to the 2016 presidential election. (Fun fact: Shapiro notes that John von Neumann “built a self-reproducing automaton in 1949, decades before any other hacker… [and] he wrote it without a computer.”)

But Shapiro also brings some penetrating insight into why the Internet remains so insecure decades after its invention, as well as how and why hackers do what they do. And his conclusion about what can be done about it might prove a bit controversial: there is no permanent solution to the cybersecurity problem. “Cybersecurity is not a primarily technological problem that requires a primarily engineering solution,” Shapiro writes. “It is a human problem that requires an understanding of human behavior.” That’s his mantra throughout the book: “Hacking is about humans.” And it portends, for Shapiro, “the death of ‘solutionism.'”

Ars spoke with Shapiro to learn more. Page: 1 2 3 4 Next → reader comments 156 with Jennifer Ouellette Jennifer is a senior reporter at Ars Technica with a particular focus on where science meets culture, covering everything from physics and related interdisciplinary topics to her favorite films and TV series. Jennifer lives in Baltimore with her spouse, physicist Sean M. Carroll, and their two cats, Ariel and Caliban. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

UK

Police appeal to trace further 18 people linked to disorder at Unite the Kingdom march

Published

on

By

Police appeal to trace further 18 people linked to disorder at Unite the Kingdom march

Police have appealed for help to identify an additional 18 people suspected of public order offences and assaults on emergency workers on the day of the Unite the Kingdom march.

Between 110,000 and 150,000 people attended the rally in central London on 13 September, the Metropolitan Police estimates.

Protesters heard a number of speeches, including from far-right activist Tommy Robinson, who organised the rally and called it the “biggest freedom of speech” event in British history.

Pics: Met Police
Image:
Pics: Met Police

An anti-racism counter-protest, attended by about 5,000 campaigners, also took place, with the two groups clashing on Whitehall and Trafalgar Square, separated by lines of police.

Police previously said 24 people were arrested at the protests, 23 of whom are believed to have been involved in the Unite the Kingdom rally, while one was believed to be involved in the counter-protest.

The force launched an appeal to identify 11 people last week, one of whom was identified.

Officers now want to speak to a further 18 people “in connection with a range of public order offences and assaults on emergency workers” and have released 16 new images.

Pics: Met Police
Image:
Pics: Met Police

The Met previously said 26 officers were assaulted with kicks and punches, adding: “Bottles, flares and other projectiles were also thrown and concerted attempts were made to get past barriers.”

“Our post-event investigation continues and officers have looked through hundreds of hours of CCTV footage to review evidence to help with further inquiries,” said Detective Chief Inspector Natalie Norris.

“We have 28 people we want to speak to in connection with a range of offences – and we are again appealing for the public’s help to track them down.”

Read more from Sky News:
UK to push peace plan at UN summit
Gatwick second runway given green light

People may have travelled from outside London, so she said she was asking people “across the country” to look at a number of pictures that have been released and to get in touch if they recognise anyone.

Continue Reading

Business

Trump reveals Rupert and Lachlan Murdoch could be involved in TikTok deal

Published

on

By

Trump reveals Rupert and Lachlan Murdoch could be involved in TikTok deal

Donald Trump has revealed that media mogul Rupert Murdoch and his son Lachlan could be part of a deal in which TikTok in the United States will come under American control.

The US president also namedropped Michael Dell, the founder and CEO of Dell Technologies, as a possible participant in the deal during an interview with Fox News, which is owned by the Murdochs.

“I think they’re going to be in the group. A couple of others. Really great people, very prominent people,” Mr Trump said. “And they’re also American patriots, you know, they love this country. I think they’re going to do a really good job.”

Mr Trump said that Larry Ellison, founder and CEO of software firm Oracle, was part of the same group. His involvement in the potential TikTok deal had previously been revealed.

President Donald Trump speaking to reporters outside the White House. Pic: AP/Mark Schiefelbein
Image:
President Donald Trump speaking to reporters outside the White House. Pic: AP/Mark Schiefelbein

White House press secretary Karoline Leavitt said on Saturday that Oracle would be responsible for the app’s data and security, with Americans set to control six of the seven seats for a planned TikTok board.

This comes after Mr Trump said he and China’s Xi Jinping held a “very productive call” on Friday, discussing the final approval for the TikTok deal, much of which is still unknown.

Once confirmed, the deal should stop TikTok from being banned in the US after lawmakers decided it posed a security risk to citizens’ data.

More on Tiktok

Officials warned that the algorithm TikTok uses is vulnerable to manipulation by Chinese authorities, who can use it to push specific content on the social media platform in a way that is difficult to detect.

Congress had ordered the app shut down for American users by January 2025 if its Chinese owner ByteDance didn’t sell its assets in the country – but the ban has been delayed four times by President Trump.

Read more from Sky News:
Trump delivers speech at Charlie Kirk’s memorial
Pentagon orders journalists to agree to reporting rules

Mr Trump said on Sunday that he might be “a little prejudiced” about TikTok, after telling reporters on Friday: “I wasn’t a fan of TikTok and then I got to use it and then I became a fan and it helped me win an election in a landslide.”

After the call with Mr Xi, Mr Trump said in a Truth Social post: “We made progress on many very important issues, including Trade, Fentanyl, the need to bring the War between Russia and Ukraine to an end, and the approval of the TikTok Deal.”

Mr Trump later told reporters at the White House that Xi had approved the deal, but said it still needed to be signed.

Representatives for the Murdochs, Mr Dell and Mr Ellison have not yet commented on a potential TikTok deal.

Continue Reading

Business

Gatwick second runway given green light by government

Published

on

By

Gatwick second runway given green light by government

Gatwick’s second runway has been given the go-ahead by the government.

The northern runway already exists parallel to Gatwick‘s main one, but cannot be used at the same time, as it is too close.

It is currently limited to being a taxiway and is only used for take-offs and landings if the main one has to shut.

The £2.2bn expansion project will see it move 12 metres north so both can operate simultaneously, facilitating 100,000 extra flights a year, 14,000 jobs, and £1bn a year for the economy.

It would also mean the airport could process 75 million passengers a year by the late 2030s.

Gatwick is already the second busiest airport in the UK, and the busiest single runway airport in Europe.

No public money is being used for the expansion plan, which airport bosses say could see the new runway operational by 2029.

Read more from Sky News
Minister defends France migrant returns deal
Lib Dems pledge windfall tax on banks

The expansion was initially rejected by the Planning Inspectorate over concerns about its provisions for noise prevention and public transport connections.

Campaigners also argued the additional air traffic will be catastrophic for the environment and the local community.

A revised plan was published by the planning authority earlier this year, which it said could be approved by the government if all conditions were met.

The government says it is now satisfied this is the case, with additions made including Gatwick being able to set its own target for passengers who travel to the airport by public transport – instead of a statutory one.

Nearby residents affected by noise will also be able to charge the airport for the cost of triple-glazed windows.

And people who live directly under the flight path who choose to sell their homes could have their stamp duty and estate agent fees paid for up to 1% of the purchase price.

CAGNE, an aviation and environmental group in Sussex, Surrey, and Kent, says it still has concerns about noise, housing provision, and wastewaster treatment.

The group says it will lodge a judicial review, which will be funded by local residents and environmental organisations.

‘Disaster for the climate crisis’

Green Party leader Zack Polanski criticised the second runway decision, posting on X: “Aviation expansion is a disaster for the climate crisis.

“Anyone who’s been paying any attention to this shambles of a Labour Govenrment (sic) knows they don’t care about people in poverty, don’t care about nature nor for the planet. Just big business & their own interests.”

Friends of the Earth claimed the economic case for the airport expansion has been “massively overstated”.

Head of campaigns Rosie Downes warned: “If we’re to meet our legally-binding climate targets, today’s decision also makes it much harder for the government to approve expansion at Heathrow.”

Shadow transport secretary Richard Holden welcomed the decision but said it “should have been made months ago”, claiming Labour have “dithered and delayed at every turn”.

“Now that Gatwick’s second runway has been approved, it’s crucial Labour ensures this infrastructure helps drive the economic growth our country needs,” he said.

A government source told Sky News the second runway is a “no-brainer for growth”.

“The transport secretary has cleared Gatwick expansion for take-off,” they said. “It is possible that planes could be taking off from a new full runway at Gatwick before the next general election.

“Any airport expansion must be delivered in line with our legally binding climate change commitments and meet strict environmental requirements.”

Continue Reading

Trending