Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts
Sunday, January 19, 2020
India Global Business: India as a Digital Decider in 2020
"India as a Digital Decider in 2020"
Wilder Alejandro Sanchez
India Global Business
Opinion
January 10, 2020
Originally published: https://indiaincgroup.com/india-as-a-digital-decider-in-2020-india-global-business/
Today, India is one of the pillars of the global economy and an influential player in regional and global affairs. Similarly important are India’s contributions to information technology as Indian companies and experts are the forefront of new developments in IT, including artificial intelligence and cyber security.
Wilder Alejandro Sanchez is an international security analyst who focuses on geopolitics, military and cyber security issues.
Continue Reading...
Saturday, November 17, 2018
Presentation: Hudson Institute: Cybersecurity Threats in Latin America
"Cybersecurity Threats in Latin America"
Hudson Institute
12 November 2018
Originally published: https://www.hudson.org/events/1627-cybersecurity-threats-in-latin-america112018
On November 12, Hudson Institute hosted a panel to discuss cybersecurity concerns present in Latin America. Threats range from hacking, identity theft, and criminal dark web activities to the exploitation of online services by insurgent groups for propaganda purposes. These concerns have prompted a number of government initiatives to crack down on cybercrime including the creation of cyber-security agencies within police and armed forces and improved citizen awareness initiatives. However, more should be done in order to deter attackers and minimize consequences of these threats.
Panelists included Analyst and Jane’s Defence Weekly Contributor Wilder Alejandro Sanchez; author Richard Stiennon; and Organization of American States Cyber Security Programme Manager Belisario Contreras. The discussion was moderated by Hudson Senior Fellow Ambassador Jaime Daremblum.
Hudson Institute
12 November 2018
Originally published: https://www.hudson.org/events/1627-cybersecurity-threats-in-latin-america112018
On November 12, Hudson Institute hosted a panel to discuss cybersecurity concerns present in Latin America. Threats range from hacking, identity theft, and criminal dark web activities to the exploitation of online services by insurgent groups for propaganda purposes. These concerns have prompted a number of government initiatives to crack down on cybercrime including the creation of cyber-security agencies within police and armed forces and improved citizen awareness initiatives. However, more should be done in order to deter attackers and minimize consequences of these threats.
Panelists included Analyst and Jane’s Defence Weekly Contributor Wilder Alejandro Sanchez; author Richard Stiennon; and Organization of American States Cyber Security Programme Manager Belisario Contreras. The discussion was moderated by Hudson Senior Fellow Ambassador Jaime Daremblum.
Speakers
Belisario Contreras Speaker
Manager, Cyber Security Programme, Organization of American States (OAS)
Richard Stiennon Speaker
Author, There Will Be Cyberwar: How The
Move To Network-Centric War Fighting Has Set The Stage For Cyberwar
(IT-Harvest Press 2015)
Wilder Alejandro Sanchez Speaker
Analyst and Jane's Defence Weekly Contributor
Amb. Jaime Daremblum Speaker
Senior Fellow and Director, Center for Latin American Studies, Hudson Institute
Tuesday, August 18, 2015
Blouin Beat: Mr. Robot: A realistic hacker show?
"Mr. Robot: A Realistic Hacker Show?"
W. Alejandro Sanchez
Blouin Beat: Technology
August 18, 2015
Originally published: http://blogs.blouinnews.com/blouinbeattechnology/2015/08/18/mr-robot-a-realistic-hacker-show/
The USA television network will soon air the finale of the debut season of Mr. Robot, whose popularity has already secured it a second one. This attention-grabbing program revolves around the members of a hacking group called F Society who are trying to bring down a fictitious villain company, named E Corp (or Evil Corp, to its enemies).
Mr. Robot’s main character is a young man named Elliot, a brilliant hacker who has emotional issues as well as social interaction problems. He works for the fictitious Allsafe, a cybersecurity company who has E Corp as a client. As hackers attempt to bring down the all-mighty E Corp, they produce online videos to criticize the company, expose information to get the company’s leaders arrested, and even approach a shadowy group of Chinese hackers for support. (There are various other subplots.) From a real-world standpoint, Mr. Robot is worthy of praise, as it properly exemplifies the complex world of cybersecurity.
One issue that Mr. Robot accurately portrays is how members of FSociety are able to exploit the lack of proper cybersecurity by the general population. For example, in one memorable scene, a policeman picks up a USB from the ground and plugs it into his computer at work. The USB displays a screen for free music, while in reality it is downloading a Trojan.
Luring unsuspecting victims into downloading a file from a website, inserting a USB, or clicking on a link in an email (maybe from an acquaintance or someone offering a one-in-a-million business transaction) is a common practice for cybercriminals. One recent example: Romanian banks being hit by the Tinba Trojan as it expanded via a maltervising campaign. The situation will become more problematic as Trojans appear in mobile apps, which many smartphone users download daily.
Clearly, Mr. Robot is accurate in that it does not portray its characters as omnipotent hackers who can penetrate a law enforcement network with a few simple clicks; rather, they rely on the naiveté of unsuspecting individuals who will infect their computers themselves. (An IT expert interviewed for this commentary explained how, as in the show, real-world police networks are offline systems referred to as air-gapped, and it is popular at IT-security conferences to find ways to break into them.) In fact, the use of USB sticks in the show is probably a nod to Stuxnet, a computer worm that crippled Iran’s controversial nuclear program and was delivered via a thumb drive.
What’s more, F Society’s main objective, to bring down a multinational corporation such as a bank or industrial conglomerate, has appeared often enough in the real world to be the inspiration for any number of Hollywood productions. For example, in 2013 the hacking groupAnonymous published “the login and private information from over 4,000 American bank executive accounts in the name of its new Operation Last Resort campaign, demanding U.S. computer crime law reform.” In other areas of the world, such as Brazil, hackers have attacked government websites. Moreover, Anonymous hacked Stratfor, a renowned global intelligence and security consulting organization. The group retrieved millions of emails, dated between 2004-2011, from the company’s employees as well as intelligence data. The information was then uploaded to the whistle-blowing site Wikileaks.
When it comes to carrying out its operations against E Corp, the hackers of F Society upload videos showing an individual with a top hat and a mask who explains, in a distorted voice, the wickedness that is E Corp. Creative yes, but also relevant. The rise of social media has increased the amount of platforms that hackers can use in order to disseminate their messages to the global masses. Anonymous regularly uploads videos in preparation for, or to report on, some of its operations; for example, in a June 17 video, the group announced its operations against the Canadian government in retaliation for the controversial Anti-Terrorism Bill C-51.
Finally, one notable aspect about F Society is its composition – the group has around half a dozen members, including four men and two women, with ages varying between early 20s to mid 30s. Curious if such gender diversity is present in real-life hacking organization? Not yet. My own research at least seems to show that hackers are predominantly male. Nevertheless, if theInternational Women’s Hackathon is anything to go by, this gap may close in the near future. (Read “Mr. Robot, Ms. Robot” for a discussion on how the show approaches gender norms.)
Motivations are another key element of the show: a few of the hackers question whether they are driven by a need for fame, the desire to bring about an “economic revolution,” or merely to embody the American dream as they perceive it? In real life, hackers’ motivations have been extensively analyzed (with one study dividing them into four categories: old school hackers; cyberpunks; professional criminals; and coders). Mr. Robot takes these nuances into account, rendering its characters more multi-faceted than the stereotypical Hollywood-hacker or socially awkward anarchist with a god-complex. USA’s surprise hit should not be placed in the growing ocean of television shows in which IT-savvy characters are drawn from stereotypical hacker clichés. On the contrary, Mr. Robot succeeds at displaying the complexities of the programmers behind the screen. Moreover, the show correctly portrays several issues of real-world cybersecurity, such as hackers attacking multinational corporations and boldly bragging about it online. In this way, it highlights the ongoing concerns surrounding personal online security. Hopefully, Mr. Robot’s season two continues to portray the intricacies of the hacker world. I, for one, will stay tuned.
Thursday, May 2, 2013
VOXXI:E-businesses in Latin America: The future is Ahora
E-Businesses in Latin America: The Future is Ahora
W. Alejandro Sanchez
VOXXI
May 1, 2013
Originally published: http://www.voxxi.com/e-businesses-in-latin-america-the-future-is-ahora/
The major economic growth that most Latin American nations currently enjoy has led to the emergence of what has been labeled as a “digital middle class.” Namely, more Latin American citizens are connecting to the virtual world thanks to increasingly cheaper internet-devices (computers, laptops, tablets and smartphones) as well as the spread of greater Wi-Fi access areas. One important result of this development is the rise of regional e-businesses by Latin American entrepreneurs. Even though these have not appeared as quickly as those in the “dotcom” boom in the U.S. in the late 1990s, they are certainly noteworthy.
Latin American e-businesses
Over the past years, e-stores and other types of e-businesses have appeared across Latin America, particularly in states such as Brazil, Chile, Mexico and Peru. There are several examples of successful e-businesses and retailers where users can buy merchandise such as clothes, alcohol, blenders and even vehicles. Examples of these e-stores are a Peruvian website called PlataTop and another one called Linio.com, which has subsidiaries in Colombia, Peru, Mexico and Venezuela. In addition, there is a website called Mercado Libre based in Colombia, Mexico and Venezuela, which is a Latin American version of eBay. Users can sell their personal goods, such as clothing or electronic devices to others via this website and Mercado Libre receives a commission per transaction. However, there is the concern that some of this merchandise may be of illegal origin.
Moreover, as proof that anything can be bought and sold online, there are websites aptly called YourCar and YourMotorcycle based in Colombia, Panama and Venezuela. Through these websites, users can post ads for the sale of vehicles and motorcycles. For wealthier individuals, there are websites where a user can advertise the sale of small airplanes (YourPlane) and others where users can browse houses for sale not only in Latin America but also in Florida (YourHouse).
As for Brazil, local startup e-businesses have appeared in the past couple of years, like for example Meliuz and Peixe Urbano. Meliuz is an interesting enterprise as it is essentially a “cashback” type of business in which users that join the site can have access to deals in a variety of major online retailers in Brazil, such as Sephora and Netshoes. In an email interview with the author of this commentary, a Meliuz spokeswoman stated that she thinks that online shopping will continue in the coming years. She explained that “Brazilians are getting used to shop[ing] online. That’s why Brazilian e-commerce is growing at an average of 20 percent each year. The biggest challenge for the online retailers, and also for web sites like Meliuz, is to keep in mind that the most important thing is the customer care, as this business is based on trust.”
Limits, limitations and leaping ahead too quickly
Nevertheless, there are still limitations to the growth of Latin American e-businesses. For example, Latin American governments will have to increase educational funding to promote computer literacy among their populations. Initiatives like providing free laptop computers to schoolchildren to help them become computer-literate, like Uruguay has done, are positive examples that other countries should follow. Nevertheless, in countries like Peru, a nation which has enjoyed propitious economic development, there are still communities with no access to water or electricity. These stark infrastructural deficits put Peruvian citizens at a disadvantage when it comes to entering the virtual job market and restricts their potential for creating independent online startups.
Moreover, recent rumors that Argentina may use the e-currency known as Bitcoin is interesting but potentially dangerous. The decision may arguably be based not so much on public interest in Bitcoin itself, but may rather be due to the country’s continuing economic struggles. This is a bad reason to turn to e-currencies, which are unpredictable. As a recent blog post in the Financial Times explains, “part of the rise in Bitcoin demand must be for saving, economists say, since Argentines lack instruments that can keep pace with inflation.” In an e-mail interview with the author, an IT expert that focuses on cyber security explained that Argentina should know more about Bitcoin using it. He explained that “this is part of the wider problem of people using the internet but not fully understanding it, they just click ‘OK’ on a box that appears without fully knowing the repercussions.” Computer and internet literacy goes hand in hand with internet security, and it will also be up to Latin American e-businesses, just like their e-customers, to make sure that cyber criminals do not exploit the still vulnerable market that is e-businesses in Latin America. For example, the aforementioned Meliuz spokesperson stressed how her company sees the protection of consumer data as vital, exemplified by the company’s “implementation of a method to encrypt personal user information data based on a random generated string only available on the server running the application.”
Furthermore, there are continuing limitations to scaling up e-business in Latin America, especially in terms of geographic access. E-stores like Peru’s PlazaTop work well for the bigger Peruvian cities such as Lima, but still do not have delivery options for smaller towns. Startup companies in the region cannot (yet) be compared to well-established e-businesses like Amazon, which has essentially worldwide delivery capacities.
The virtual world provides plenty of opportunities for commercial growth, as exemplified by the appearance of Latin America-based e-businesses such as PlazaTop, Meliuz and Mercado Libre. Nevertheless, there are still limitations such as geography, internet connectivity and computer literacy, as well as concerns over the e-security of users’ personal information. Given the potential perils of trying to take advantage of potential virtual profits (such as Bitcoin, which can be manipulated by hackers), perhaps the current slow pace is a good idea.
Read more: http://www.voxxi.com/e-businesses-in-latin-america-the-future-is-ahora/#ixzz2SBqVbRIS
Sunday, August 26, 2012
Quote: S. America cybersecurity spend set to grow
S. America cybersecurity spend set to grow
Security Industry
August 24, 2012
Originally published: http://bit.ly/PGNyAZ
Cybersecurity products and services are geared for a major growth in Latin America between now and next year, with a surge in spending already in evidence, current industry data indicated.
SANTIAGO, Chile, Aug. 24 (UPI) -- Cybersecurity products and services are geared for a major growth in Latin America over the next year, with a surge in spending already in evidence, current industry data indicated.
Regional interest in cybersecurity has increased with rising development expenditure and multibillion-dollar government and private sector investment in high-value projects in aviation, defense, oil and natural gas, hydroelectric power generation, transport and border security.
Demand for high-end information technology, defense and security hardware and software has drawn international manufacturers, suppliers and security experts to Latin America.
The market for purchases of information technology goods and services by business and government will go through two transitions during the period, the Global Tech Market Outlook For 2012 and 2013 report predicted.
The report by Andrew Bartels identified Latin America as a major growth area alongside the Asia Pacific region.
"Fast growth in emerging markets like Asia Pacific and Latin America has partially offset a struggling Europe," Bartels said in the report. "Vendors will focus more on the potential of emerging markets in 2012."
South American buyers and vendors showed up in significant numbers at England's Farnborough Air Show, which brought together not only aviation and defense experts but also security industry businesses.
Subsequent shows in Brazil and Chile and a forthcoming event in Puerto Rico reinforced business leaders' view that Latin America would see further cybersecurity growth in the coming months.
Analysts said the industry was also seeing a major shift from older technologies like servers, routers and desktop computers to mobile devices, analytics and advanced software.
Latin American companies, with cash infusions from governments, especially in Brazil and Chile, have turned attention to acquiring technological capacity they can turn around and exploit as new avenues for business activity and exports.
Niksun Inc., a major U.S. manufacturer and provider in real-time and forensics-based cybersecurity and network monitoring solutions, announced it is hosting a customer and partner event next week in Puerto Rico as part of its strategy to position itself in Latin America and the Caribbean.
"Entering the Caribbean and Latin America region is part of our strategy to continue that growth. After all, cyberwarfare has no borders," Niksun Chairman and Chief Executive Officer Parag Pruthi said.
The company cited a Forrester Research study that said, "Fast growth in emerging markets like Asia Pacific and Latin America has partially offset a struggling Europe," and vendors would likely focus more on the potential of emerging markets in 2012.
A World Wide Security and Mobility Conference July 9-11 in Princeton, N.J., highlighted recent high profile cyberattacks that have cost industry and governments billions of dollars.
"The amount of money costing companies and governments from even a minor data breach is staggering," Pruthi said at the conference.
A report by the Council on Hemispheric Affairs, which has headquarters in Washington, noted Latin American awareness of cybersecurity risks is growing.
"While demonstrably the expansion of Internet usage (in Latin America) has not rivaled that of the United States, Europe, or some Asian states like South Korea and Japan, the growth of the Internet in the region continues at a steady tempo," said the report by W. Alex Sanchez, a research fellow at the council.
"Additionally, we are witnessing a rise in the importance of cybersecurity as cases of hacking and other cybercrimes proliferate," Sanchez added.
Regional interest in cybersecurity has increased with rising development expenditure and multibillion-dollar government and private sector investment in high-value projects in aviation, defense, oil and natural gas, hydroelectric power generation, transport and border security.
Demand for high-end information technology, defense and security hardware and software has drawn international manufacturers, suppliers and security experts to Latin America.
The market for purchases of information technology goods and services by business and government will go through two transitions during the period, the Global Tech Market Outlook For 2012 and 2013 report predicted.
The report by Andrew Bartels identified Latin America as a major growth area alongside the Asia Pacific region.
"Fast growth in emerging markets like Asia Pacific and Latin America has partially offset a struggling Europe," Bartels said in the report. "Vendors will focus more on the potential of emerging markets in 2012."
South American buyers and vendors showed up in significant numbers at England's Farnborough Air Show, which brought together not only aviation and defense experts but also security industry businesses.
Subsequent shows in Brazil and Chile and a forthcoming event in Puerto Rico reinforced business leaders' view that Latin America would see further cybersecurity growth in the coming months.
Analysts said the industry was also seeing a major shift from older technologies like servers, routers and desktop computers to mobile devices, analytics and advanced software.
Latin American companies, with cash infusions from governments, especially in Brazil and Chile, have turned attention to acquiring technological capacity they can turn around and exploit as new avenues for business activity and exports.
Niksun Inc., a major U.S. manufacturer and provider in real-time and forensics-based cybersecurity and network monitoring solutions, announced it is hosting a customer and partner event next week in Puerto Rico as part of its strategy to position itself in Latin America and the Caribbean.
"Entering the Caribbean and Latin America region is part of our strategy to continue that growth. After all, cyberwarfare has no borders," Niksun Chairman and Chief Executive Officer Parag Pruthi said.
The company cited a Forrester Research study that said, "Fast growth in emerging markets like Asia Pacific and Latin America has partially offset a struggling Europe," and vendors would likely focus more on the potential of emerging markets in 2012.
A World Wide Security and Mobility Conference July 9-11 in Princeton, N.J., highlighted recent high profile cyberattacks that have cost industry and governments billions of dollars.
"The amount of money costing companies and governments from even a minor data breach is staggering," Pruthi said at the conference.
A report by the Council on Hemispheric Affairs, which has headquarters in Washington, noted Latin American awareness of cybersecurity risks is growing.
"While demonstrably the expansion of Internet usage (in Latin America) has not rivaled that of the United States, Europe, or some Asian states like South Korea and Japan, the growth of the Internet in the region continues at a steady tempo," said the report by W. Alex Sanchez, a research fellow at the council.
"Additionally, we are witnessing a rise in the importance of cybersecurity as cases of hacking and other cybercrimes proliferate," Sanchez added.
Read more: http://www.upi.com/Business_News/Security-Industry/2012/08/24/S-America-cybersecurity-spend-set-to-grow/UPI-47501345836220/#ixzz24f62amCQ
Tuesday, August 7, 2012
Hacking freedom of speech in Chavez’s Venezuela and Latin America
Hacking freedom of speech in Chavez’s Venezuela and Latin America
W. Alejandro Sanchez
Research Fellow
Council on Hemispheric Affairs
VoXXI
August 7, 2012
Available: http://bit.ly/Mi3Tvy
Numerous cyber attacks and hacking incidents invade privacy and freedom of speech for in Venezuela and Latin America.
The latest internet-related scandal to hit Latin America involves revelations that the Hugo Chavez government hired an Argentine hacker, working in Spain, to install a communications network to monitor opposition leaders, journalists and individuals who may “pose a threat to the Bolivarian revolution.”
While concerning, it is important to mention that freedom of expression and other online privacy issues have become a major issue in Latin American, not just Venezuela but also in countries like Colombia and Mexico. Until some kind of multinational treaty establishes legal standards for the transfer of cyber technology, the future of e-privacy in Latin America looks grim.
The facts behind the Venezuelan hacking scandal
In late July, Spanish security forces carried Operation Pitiusa, a raid in which 135 individuals were arrested. The goal of the operation was to crack down on individuals illegally collecting the personal data of Spanish citizens and then selling it.
What brought international attention to this situation was that the director of CF Labs, Matias Belivacqua, one of the individuals arrested, was allegedly employed by the Venezuelan government. Investigations carried out by the daily El Nuevo Herald showed that thousands of emails were intercepted by the Venezuelan intelligence agencies, as well as passwords and other personal information. Some of the alleged targets include Venezuelan opposition leaders like Antonio Ledezma, Osvaldo Alvarez Paz and Maria Corina Machado.
After the revelations came to light, a Venezuelan news website, LaPatilla.com, declared that it too suffered from cyber-attacks. The site’s editor, David Moran, stated that “the attacks occur when we cover incidents that are not favorable to the government, like during the recent incident at the prison in La Planta [in May].”
Caracas has come out to defend its relationship with Belivacqua and CF Labs. According to a report by the Spanish daily ABC, the Venezuelan government hired the Argentine citizen to build laboratories and provide technology to the Sistema Nacional de Gestion de Incidentes Telematicos VenCERT. According to its website, VenCERT’s objective is to detect and prevent cyber related crimes against government websites.
Hacking, cyber attacks and other incidents
This is not the first internet-related incident in which the Chavez government is accused of utilizing the internet to violate privacy and access the personal data of anti-government individuals. In September 2011, a hacker group known as N#33 allegedly interfered with the Twitter and e-mail accounts of several prominent anti-Chavez figures.
According to Univision: “In the most remarkable case so far, N33 took control of the personal twitter account of journalist Berenice Gomez, known as the “La Bicha”. Her account, @Labichaoficial [suspended], had more than 190,000 followers. After stealing her email account, the hacker called, threatening to publish the entire contents of her account, including confidential sources and information.”
Another individual who was apparently attacked by the group was military analyst Rocio San Miguel, president of Control Ciudadano, a non-governmental organization that monitors defense and security issues in Venezuela. “The hacking is a plan of state terrorism,” she said in an interview.
N#33 declared that, while it took responsibility for the cyber-attacks, the operation was carried out on its own accord and not ordered by the Venezuelan government. To justify its operation, the group argued that it was to halt the “unnecessary [indebido]” use of Twitter by individuals who are against the government under the pretext of freedom of expression.
Cyber attacks, hacking limits e-freedom in Latin America in 2012
Whether the Chavez regime has violated the e-privacy of its citizens or not, it is important to highlight that other regional countries have been accused of similar incidents or of trying to pass legislation that could potentially restrict the online freedom of their citizens.
In mid-July, the Mexican government signed the controversial internet bill known as ACTA, which theoretically is supposed to fight online piracy and protect copyright material, but has been widely critiqued as a curtain for allowing government-sponsored online censorship. Colombia has also debated such polemic laws; in late 2011, Colombian legislators drafted a law called Ley Lleras, which also corresponds with anti-piracy and copyright issues. But the Colombian government bit more than it could chew as the international hacking group known as Anonymous hacked the website of the Colombian ministry of interior in protest, among other official websites, in April 2011.
Without a doubt, the debate over online freedom of expression will continue and we can expect more attempts at passing controversial laws like ACTA and Ley Lleras by certain states. But even more worrisome is that governments around the world today have access to high-tech spyware software to spy on its citizens. For instance, the controversial spyware known as FinFisher, produced by the UK-based Gamma group, has been utilized by the government of Bahrain to help crack down on protesters in that Arab state. Could software like this find its way to Latin America?
Whether it is governments utilizing spyware on their citizens or resorting to approving controversial laws that could promote online censorship, the lack of international treaties regulating the internet leaves too much open room for corrupt governments and officials, at any level, to abuse their power and crack down on free e-speech.
Read more: http://www.voxxi.com/hacking-freedom-speech-venezuela-chavez/#ixzz22tZ0Vmyz
Friday, August 3, 2012
Cyber Arms Deals And Latin America In The Post-Stuxnet World
W. Alex Sanchez
Research Fellow, Council on Hemispheric Affairs
August 3, 2012
Forbes.com
Available: http://onforb.es/M8P7Hf
Guest Blogger, W. Alex Sanchez, Research Fellow at the Council on Hemispheric Affairs, and participant in the International Cybersecurity Dialogue, introduces the issues surrounding cyber arms dealing, especially as they relate to Latin America.
In a way, the Stuxnet virus is not that surprising. Washington and Tel Aviv, just like Washington and London, have a historical “special relationship;” hence it is not astounding at all that binational operations include defense-related initiatives, such as dealing with a common foe (in this case, Iran). But what kind of precedent has been set by this inter-state cyber initiative? And what can we expect in the future? Malware can be acquired online fairly easily as many websites allow hackers to upload basic malware programs for download. Usually these viruses target basic software like chat programs, cracking product keys for professional software like Windows or Adobe Suite, and Trojans that can be sent to infect other computers. There are also IP addresses where, for the right price, more sophisticated malware programs can be quickly acquired. But these exist in the (borderline) illegal part of the internet and several governments are already formulating laws to catch up to the ever changing virus technology. But what about the future of legal cyber weapons trade?
The trade of conventional weapons between nations is a multi-billion dollar industry that circles the entire globe because trading such expensive weapons as warships, battle tanks and missiles can be a lucrative economic activity. States like the U.S., Russia, China and Israel are major conventional weapons suppliers, but even states not usually known for their strong militaries make a generous profit from weapons manufacturing. For example, Sweden’s SAAB produces high quality missile systems, such as AT4 anti tank weapons. But even when it comes to conventional weapons trade, there are limits of how far countries are willing to sell others regarding destructive weapons and state-of-the-art technology. For example, for several years Russia has delayed the delivery of its modern S-300 defense system to Iran (though, the Israeli government argues the contrary). There are also several treaties, ratified by a plethora of states, that impose limits to the type of weaponry they will sell each other; although, unfortunately, some of them are not always upheld.
But when it comes to cyber weapons, the developed cyber nations have yet to adopt rules and place limits on what kind of software can be exchanged or sold either between nations or a private company and governments. For example, much has been written lately of the controversial spyware known as FinFisher, produced by the UK-based Gamma group, and how it may have been used by the government of Bahrain to help crack down on protesters in that Arab state.
As an international security analyst for the Council on Hemispheric Affairs, my focus centers on defense issues that relate to Latin America and the Caribbean. Hence, it is part of my job to see how the development of cyber security affairs in the Global North (which I regard as the U.S., Europe, Israel, Russia and China), will affect Latin America in the coming years. This becomes even more important when we take into account that Latin America continues to be a region that is plagued with inter-state tensions that, in a worst-case scenario, could end in inter-state warfare (though it is worthy to highlight that this has been thankfully scarce in the past decades). For example, there is an ongoing maritime border dispute between Peru and Chile (the two countries have been at odds with each other since a 19th century war), and occasional flares between Colombia and Venezuela (like after an incident in 2008 that included a Colombian military raid in Ecuador to attack a guerrilla base there, subsequently Caracas almost declared war against Bogota to protect Quito’s sovereignty). The point here is, while Latin America has been slow to come around to the cyber world, this is rapidly changing, and cyber security is catching on. For example, Brazil’s army recently created a center for cyber defense. If we also take into account that a number of countries, besides Brazil, have experienced major economic growth in recent years, similar to Mexico and Peru, then the question becomes a matter of when, not if, cyber weapons will become a factor in Latin American military affairs.
Therefore, it becomes a necessity to begin some kind of international regulatory system for cyber weapons. In a few years, Stuxnet-like operations may not come just from some of the world’s most developed states, but regional powerhouses with more localized domestic national security interests. What should the role of the cyber powers be at that point? Could the government in Lima, a historical U.S. ally in Latin America (though of course not at the same level of Tel Aviv or London), approach Washington and ask to purchase cyber weapons capable of knocking out Chile’s electric grid as a mean to use as a dissuasive weapon to deter any possible conventional military threat from Santiago (another U.S. ally)? Or how about if Bogota, another close US ally, asks for spyware or more offensive software, should tensions flare up once again with Venezuela (repeatedly accused by the U.S. of being lax, at best, on fighting drug trafficking and for President Hugo Chavez’s friendship with the Iranian government). Finally, should London place limits on Gamma if it plans to sell its spyware to a Latin American state which is known for its crackdown on human rights?
While drafting this commentary I consulted a number of IT programmers, much more versed in coding and malware than myself. The obvious consensus was that, just like with conventional weapons, cyber weapons have to be custom made. A government cannot simply buy a virus and expect it to automatically adapt itself to the desired target; it must be formatted accordingly. Hence, the future of cyber arms trades, just like with conventional weapons, will rely not only on the sale of the software but also on educating the cyber-experts of the recipient government by supplying governments or companies. As one software programmer explained to me, “I wonder about the extent to which it’s possible for a cyber-weapons trade to exist—unless we think of the programmers (not their programs) as the weapons. Engineering competence isn’t easily transferred.”
My far-smarter-than-me colleague also mused how
“if your first [offensive] attempt is only half-successful and detected, it could give the opponent a chance to improve their defenses before any real damage is done. So if you’re the attacker, I would guess that a mere support contract isn’t going to suffice; you’ll want to have the programmers in house, and you want to have regular meetings with them, see their testing environment, and generally try to improve confidence that the attack is actually going to work on the first try. Any program of sufficient complexity, no matter how competent the programmer, is going to fail in various ways at first.”In other words, what limits should be placed on not only technology but also the human component when it comes to manufacturing and trading cyber weaponry?
Finally, should there be limits regarding the type of cyber weapons that can be sold? Such software can range from defensive programs (i.e. state-of-the-art firewalls) to more offensive ones like spyware (which raises the question whether this can constitute a declaration of war if detected by the targeted nation), or others I consider “cyber weapons of mass destruction” (capable of bringing down a city or nation’s electric or communication grids). Such issues and questions are problematic enough today when we see only a handful of cyber-developed nations who happen to be close allies with each other (i.e. U.S. and the UK or U.S. and Israel). Reaching consensus on cyber weapons’ transfers will only become more problematic in the near future when other developing states (i.e Brazil, Mexico and Peru, to name a few, in Latin America), turn more of their resources to cyber weaponry to protect national interests.
Subscribe to:
Posts (Atom)


