Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « Firefighters to Fight Terrorism While Doing their Day Jobs | Main | Animal Rights Activists Forced to Hand Over Encryption Keys » November 28, 2007Cybercrime vs CyberterrorismI've been saying this for a while now: Since the outbreak of a cybercrime epidemic that has cost the American economy billions of dollars, the federal government has failed to respond with enough resources, attention and determination to combat the cyberthreat, a Mercury News investigation reveals. This is Part III of a good series on cybercrime. Here are Parts I and II. Posted on November 28, 2007 at 6:56 AM • 16 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. I like the way that you can mentally add even more "cyber-" prefixes as you're reading, in order to make the article sound even more cutting-edge: "The U.S. government has not devoted the cyberleadership and cyberenergy that this cyberissue needs", and "overlooking the international cybercriminals who are cyberstealing a fortune through the cyberInternet". Posted by: SteveJ at November 28, 2007 7:45 AM There's also the question: if you can't secure something against criminals, how can you secure it against enemy action or terrorists? They'll be able to do anything criminals can and more (since they have more resources or are less concerned about consequences). Once we've got a good basic level of security, we can decide whether additional resources are needed, and where to put them. Any situation where criminals can wage their own cyberwars with botnets, or gather large amounts of sensitive information, is secure neither against information war nor espionage. Posted by: David at November 28, 2007 7:56 AM I have reservations about discerning cybercrime from cyberterrorism. Terror being a subset of crime. By bringing the term "terrorism" to the level of "crime" or "warfare", it validates the argument we've been fed for many years now and impares our ability to address the issue for what it is. Posted by: Harry Tuttle at November 28, 2007 8:33 AM
"...if you can't secure something against criminals, how can you secure it against enemy action or terrorists?"
Nuff said. Posted by: reswob at November 28, 2007 8:45 AM Criminals have economic motivations, and have the problem of laundering their profits in order to do something with them. The fact that we (our governments) have not followed the money is very embarrassing. It's worse though --- those criminals that we aren't catching may well be for hire to the "enemy". Posted by: Michael Richardson at November 28, 2007 9:23 AM A quick scan of the link Bruce included did not show this bill that passed the House last month according to /. U.S. House Says the Internet is Terrorist Threat http://www.govtrack.us/congress/bill.xpd?... (caveat: Bruce may have covered this already) Posted by: reswob at November 28, 2007 10:22 AM @reswob, considering that the fundamental motivator for war is economic, the distinction between criminals and enemy action is rather specious. It's time we re-evaluated our paradigms around terrorists, criminals, and enemies of the state (as distinct from enemies of the people). The real problem is those who steal value without providing something of equal value in return. Those are the true enemies of the people, and include terrorists, criminals, and corrupt governments. Enemies of the state are those who threaten the government, and to corrupt governments that includes terrorists, criminals, and patriots. Elucidating the implications of distinguishing enemies of the state from enemies of the people is left as an exercise for the reader... Posted by: guvn'r at November 28, 2007 10:32 AM It occurs to me that cybercrime is not really a problem; if it were, the victims (i.e. banks, websites, etc...) would take stronger measures to combat it. Unlike crime in the physical world, where one only has to be in the wrong place at the wrong time, being a victim of cybercrime is largely a matter of one's own ignorance of computer system security. As long as it costs more to secure computer systems than the fraud perpetrated through them, we will have cybercrime. And it is not a problem so much as it is an economic choice that businesses make; as long as publicly-paid prosecutors are willing to prosecute computer criminals, businesses will shift the cost of computer security to the government. In fact, I believe many businesses believe that, since they pay taxes, they have a right to expect their lapses in computer security to be righted by law enforcement. Posted by: lucid at November 28, 2007 11:52 AM ' "Federal law enforcement needs more agents to deal with this," said Ron Plesco, executive director of the National Cyber-Forensics and Training Alliance, a government-funded non-profit that investigates cybercrime.' I submit that Federal Law Enforcement already has more agents than there are employees in "tiny startup Rock Phish". What Federal Law Enforcement really needs is agents who understand the problem, understand how to decide what action to take, and legally and ethically gain authorization to take that action. Posted by: sidelobe at November 28, 2007 11:55 AM @lucid Posted by: djunia at November 28, 2007 1:22 PM The siliconvalley.com link wants registration. Google's cache is much more convenient: http://64.233.169.104/search?... Finding parts I & II is left as an exercise for the reader. :-) Posted by: Terry Cloth at November 28, 2007 6:22 PM The paradigm of traditional law enforcement is that one criminal is perpetrating a crime against another person. Until law enforcement truly grasps that cyber crime breaks that paradigm by using computers to perpretrate crimes against others often via other computers, it will be an uphill struggle to thwart the billions of dollars that are lost each year to criminial activities. Felicia Donovan Posted by: Felicia Donovan at November 28, 2007 8:24 PM The price tag for recovering from a single security incident has jumped 30% over 2006. As if it were cheap before... Posted by: Pam Scott at November 28, 2007 10:00 PM Continuing with Comments on Bruce Schneier book Beyond Fear, ~~ Is anonymity a Good thing or a Bad Thing? For the Op Ed pages you post to your web site as text or HTML -- a pseudonym is fine. You can be anonymous because you can't hurt anything. But if you are writing executable code or eMail: NO: You cannot be anonymous. Bruce discusses the role of auditing, detection, and response mechanisms as a key part of good security in his book. And anonymity obstructs the functions of auditing and response. I have been following with great interest the FireFox/GnuPG project. The idea being to incorporate PGP authentication into the browser so as to require a PGP signature for every executable. The concept could be taken 1 step further by adding the restriction that every executable has to be registered and a copy of the program saved before execution can be authorized. This would facilitate auditing. The un-wanted programs could be cleared off the computer system as soon as an audit had been completed. Proper modifications to the browswers and/or related OS would be required but that is within our capability. I would note as well that he has a very interesting approach to risk analysis, evaluating threats, assets, and probabilities and working into cost trade-offs. One of the most important aspects of his approach is that the results will vary depending on the viewpoint. This is very important to our effort to STOP RATS and to make online commerce safer. If you are the credit card industry, a loss rate of 15 cents per $100 of business might be an acceptable risk, - and you just put that down to the "Cost of Doing Business." But from the stand point of the individual the risk is entirely different. While the bank is supposed to limit individual liability for fraud to $50 this may not actually happen. The bank might sue to collect a debt that was created by fraud. And the individual could face a nightmare trying to deal with a very unsympathetic bank fighting through endless phone menus -- only to end up talking to a help desk agent who just reads information off a computer screen and claims infallibility. A credit card fraud incident can turn into a nightmare. It is my opinion that if online commerce is to continue to grow the RATS which are fast becoming a sophisticated and pervasive problem online -- must be EXTERMINATED. If RATS are allowed to continue to fester the future of online commerce and of MS/Windows itself will have been wagerd and placed at risk. NO SIGNATURE? NO EXECUTE. Posted by: Mike Acker at November 29, 2007 12:53 PM More clues that cybercrime has many forms ... some more obvious than others, and some less technical than others. When breaking through network security seems like too much of a bother, the easy solution appears to be cutting a hole in the wall and grabbing data the old fashion way. There is nothing new here with the method or the crime. Or in this case, both. Is this a case where paying insurance is cheaper than thicker walls? Posted by: sreacnudroimty at November 29, 2007 10:33 PM Like Paul Kurtz, I live in the Washington, DC area and work on information security issues. I agree with him that the federal government hasn't invested enough resources to tackle the cyber-crime issue effectively. That is starting to change but more must be done. Part of the challenge is getting key decision makers -- whether in Congress or the Administration -- to understand how the threats and technology constantly evolve. Posted by: SLK at December 4, 2007 5:23 PM Post a comment
Powered by Movable Type. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments