Read The Times Australia

Daily Bulletin

China data thefts expose murky world of hidden motives, tricky responses when nations hack

  • Written by: The Conversation
image"Unit 61398," a secretive Chinese military unit believed to be behind many hacking attacks, sits on the outskirts of Shanghai.Reuters

Recent reports that hackers were able to penetrate a variety of US databases – especially at the Office of Personnel Management and at insurers Anthem and Premera Blue Cross, where the personal information of many government employees was stolen – is unsettling for many reasons.

Usually, breaches like these are carried out by hackers and criminals for monetary gains. The economic incentives are clearly defined. Hackers seek to make some money by selling stolen credit cards or fake identifies or commit internet fraud.

The incentives of the company whose customer data is breached are also well-defined. The company protects the data as well as it can, but the cost of stolen consumer information eventually falls on consumers themselves. So the company’s incentives are not always that well-aligned with consumers.

This potential “externality” – the breach’s impact on consumers who have no role in preventing it – has led to a variety of regulations that force firms to increase their investments in data protection and be more careful in storing and handling personal information.

However, in this recent case, the breach is suspected to have been perpetrated by the government of another nation state, namely China. There does not seem to be any immediate economic motive, and the data may be used in the future for as yet unknown reasons.

This, in turn, raises profound questions of how we can protect US cyberspace and intellectual property while keeping the process transparent to citizens.

Challenges when a nation is the hacker

Both China and Russia have been suspected of carrying out many breaches on government and private companies in the US. Interestingly, they recently signed a pact not to hack each other. Some of the attacks seem to be for the purpose of stealing intellectual property; others have murkier motives. These nations, in turn, have accused the US of carrying out similar attacks.

When nation states enter cyberspace to undermine one another, the economic and legal frameworks become distorted.

How, for example, should we encourage private firms like Anthem and Premera Blue Cross and individual federal agencies to protect data and thwart such attacks?

As long as the market and regulations create the right incentives for companies to protect this data, they will continue to invest in their security policy, technology and organizational training.

Unfortunately, however, expecting private businesses to keep up with state actors like China with their often limitless resources might be asking a lot. A profit-making company or a budget-starved government agency is unlikely to have the sophistication, capital and patience to fight such attacks.

This is especially true for small- to mid-sized entities. Even if they had the resources, it is not clear that extra heightened data protection would be the most efficient allocation of resources.

imageThe NSA reportedly has been trying to find hackers for the past several years.Reuters

Enter the spies

This leads to an even more challenging problem: what role should our government play in protecting our cyberspace and private businesses?

Beyond diplomatic efforts, agencies like the National Security Agency may potentially act proactively by tracing, nabbing and punishing attackers – as a New York Times report this month suggests is already happening in a significant way.

While the effectiveness of these efforts, due to lack of transparency, is unknown, the rationale for these actions is not hard to comprehend. Our intelligence agencies may be in a better position than private companies alone to thwart such attacks. Active efforts might not only deter other nation states, they might also lead to quick detection and remediation.

But these efforts require surveillance, are done in secrecy, and could cause potential violations of our rights that have significant negative consequences. Many private businesses would be reluctant to even cooperate with government agencies because of potential suspicion that information would be used against them in future.

Secrecy, obfuscation and ‘zero days’

The use of cyberspace by nation states to attack other countries is, it’s fair to say, one of the most unfortunate and challenging developments of the last few years. It can only lead to more secrecy, more obfuscation and even less trust.

One example of such actions is vividly on display in the domain of software vulnerabilities.

Many of the sophisticated attacks and data breaches highlighted above exploit so-called zero-day vulnerabilities.

Zero-day vulnerabilities are flaws in the software products that millions of us use every day that are not widely known, but are being sold by hackers for thousands of dollars or much, much more, depending on their rarity.

All of our popular software has flaws, and most of these flaws are found, reported to software vendors and fixed on a routine basis without causing any significant disruptions.

But many governments, including the US, have started to explicitly pay researchers and hackers for vulnerability information rather than report them to the vendors.

These nations, in turn, use these “unknown” flaws for potential exploitation like the data breaches we see now. The more critical the flaw, the greater the chance that it will never be known until it is exploited in future.

Just the beginning

What was once a transparent and well-understood process has now become secretive and uncertain. And it is easy to see that as long as nations see cyberspace as a way to gain the upper hand, there is no easy way to reverse it. If anything, we can expect more of this in the coming years.

As cybersecurity efforts start overlapping with national security efforts, the private and public efforts to protect data will increasingly blur. And as nations increasingly play offense, we will need stronger efforts to find a balance where intelligence agencies can play an active but transparent role in protecting cyberspace.

Most importantly, we will need to clearly define a framework and parameters under which intelligence agencies can function in cyberspace so that they have our trust.

This is not going to be easy, both given our political environment and the fundamental complexity of this problem. Even if we were to find a balance, it must not be forgotten that as nations increasingly insert themselves into cyberspace, they increase the cost of business for everyone.

Firms have to invest more, and so do the intelligence agencies chasing down unproductive leads. Customers are the ones paying for it either way.

Rahul Telang receives or has received research funding from National Science Foundation (NSF), NSA, Sloan Foundation, MPAA (Motion Picture Association of America), Google Research

Authors: The Conversation

Read more http://theconversation.com/china-data-thefts-expose-murky-world-of-hidden-motives-tricky-responses-when-nations-hack-42938

Business News

Reducing Sales Friction Through Centralized Content Delivery

Sales friction appears whenever buyers or sales teams face unnecessary obstacles in the buying journey. It can happen when information is hard to find, when messaging feels inconsistent, when product ...

Daily Bulletin - avatar Daily Bulletin

Why Choosing the Right Bollard Supplier Matters for Australian Businesses and Public Spaces

From busy CBD streetscapes to sprawling warehouse loading docks, bollards have become one of the most essential safety and security fixtures across Australia. Whether protecting pedestrians from veh...

Daily Bulletin - avatar Daily Bulletin

Why Modular Content Is Transforming Modern Marketing Teams

Modern marketing teams are expected to produce more content than ever before. They need to support websites, landing pages, email campaigns, social channels, product pages, sales enablement material...

Daily Bulletin - avatar Daily Bulletin

Everything You Need to Know About Getting Support from Optus

Whether you've been an Optus customer for years or you've just switched over, at some point you'll probably need to contact their support team. Maybe your bill looks different from what you expected. ...

Daily Bulletin - avatar Daily Bulletin

The Marketing Strategy That’s Quietly Draining Sydney Business Owners’ Bank Accounts

Sydney businesses are investing more in digital marketing than ever before. The intention is clear. More visibility should mean more leads, more customers, and steady growth. However, many business ...

Daily Bulletin - avatar Daily Bulletin

Why Mining Hose Solutions Are Essential For High-Performance Industrial Operations

In environments where the ground itself is constantly shifting, breaking, and being reshaped, every component must be built to endure. Mining operations are among the most demanding in the industria...

Daily Bulletin - avatar Daily Bulletin

The Reason Talented Teams Underperform

If you’re in business, you might have seen it before. A team of capable and smart people just suddenly slows down, and things start spiraling out of control. On paper, everything looks perfect, but ...

Daily Bulletin - avatar Daily Bulletin

Why More Aussie Tradies Are Moving Away From Paid Ads

Across Australia, a lot of tradies are busy. There’s no shortage of demand in industries like plumbing, electrical, landscaping, and building. But being busy doesn’t always mean running a smooth or...

Daily Bulletin - avatar Daily Bulletin

Why Careers In The Defence Industry Are Growing Rapidly

The defence sector has evolved far beyond traditional roles, opening doors to a wide range of opportunities across technology, engineering, intelligence, and operations. This is where defense industry...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...

5 Signs Your Car Needs Immediate Attention Before It Breaks Down

Car problems rarely appear without warning. In most cases, your vehicle gives clear signals before...

Ensuring Safety and Efficiency with Professional Electrical Solutions

For businesses in Newcastle, a safe and fully functioning workplace remains a key part of day-to-d...

Choosing The Right Bin Hire Solution For Hassle-Free Waste Management

When it comes to managing waste efficiently, finding the right solution can save both time and eff...

Why Cleanliness Is Critical In Childcare Environments

Children explore the world with curiosity, often touching surfaces, sharing toys, and interacting ...

What to Look for in a Reliable Australian Engineering Partner

Choosing an engineering partner is rarely just about technical capability. Most businesses can fin...

How to Choose a Funeral Home That Supports Families with Care

Choosing a funeral home is rarely something families do under ideal circumstances. It often happen...

Why Premium Coffee Matters in Modern Hospitality Venues

In hospitality, details shape perception long before a guest consciously evaluates them.  Lightin...