Showing posts with label Stuxnet. Show all posts
Showing posts with label Stuxnet. Show all posts

Monday, May 20, 2013

Book on ethical guidance for PICT on its way

Emerging Pervasive Information and Communication Technologies (PICT): Ethical Challenges, Opportunities and Safeguards 

Edited by Kenneth D. Pimple,  Ph.D.

To be published by Springer; expected publication date June 30, 2013.

Description


This book provides a wide and deep perspective on the ethical issues raised by pervasive information and communication technology (PICT) – small, powerful, and often inexpensive Internet-connected computing devices and systems. It describes complex and unfamiliar technologies and their implications, including the transformative potential of augmented reality, the power of location-linked information, and the uses of “big data,” and explains potential threats, including privacy invaded, security violated, and independence compromised, often through widespread and lucrative manipulation.

PICT is changing how we live, providing entertainment, useful tools, and life-saving systems. But the very smartphones that connect us to each other and to unlimited knowledge also provide a stream of data to systems that can be used for targeted advertising or police surveillance. Paradoxically, PICT expands our personal horizons while weaving a web that may ensnare whole communities.

Chapters describe particular cases of PICT gone wrong, but also highlight its general utility. Every chapter includes ethical analysis and guidance, both specific and general. Topics are as focused as the Stuxnet worm and as broad as the innumerable ways new technologies are transforming medical care.

Written for a broad audience and suitable for classes in emerging technologies, the book is an example of anticipatory ethics – “ethical analysis aimed at influencing the development of new technologies” (Deborah Johnson 2010).

The growth of PICT is outpacing the development of regulations and laws to protect individuals, organizations, and nations from unintended harm and malicious havoc. This book alerts users to some of the hazards of PICT; encourages designers, developers, and merchants of PICT to take seriously their ethical responsibilities – if only to “do no harm” – before their products go public; and introduces citizens and policy makers to challenges and opportunities that must not be ignored.

Monday, June 25, 2012

"A Weapon We Can’t Control"

I've written on Stuxnet five times and mentioned it once on this blog. I was appalled at the first news of Stuxnet I came across, not simply because of the virus' power, but because it appeared that Stuxnet was created by the United States or Israel or both. Most importantly, when a computer virus is let loose on the world, it becomes available to bad actors who can modify it for their own purposes. It's almost as if the bombing of Hiroshima and Nagasaki gave would-be bomb builders 98% of everything they needed to build their own a-bombs.

The author of this op-ed piece, Misha Glenny (New York Times, June 24, 2012), observes:
There is no international treaty or agreement restricting the use of cyberweapons, which can do anything from controlling an individual laptop to disrupting an entire country's critical telecommunications or banking infrastructure. It is in the United States' interest to push for one before the monster it has unleashed comes home to roost.        
We might be headed toward a new Cold War in which mutual destruction can be triggered by any one of thousands of sophisticated programmers. To me, this is just as scary as the previous cold war, in part because it's much more complicated. A treaty would not be a complete solution, but it would be a valuable tool.

Ken Pimple, PAIT Project Director

Friday, June 1, 2012

"Obama order sped up wave of cyberattacks against Iran"

An alarming article in the New York Times (Obama Order Sped Up Wave of Cyberattacks Against Iran, David E. Sanger, June 1, 2012) claims
From his first months in office, President Obama secretly ordered increasingly sophisticated attacks on the computer systems that run Iran’s main nuclear enrichment facilities, significantly expanding America’s first sustained use of cyberweapons, according to participants in the program.
The effort was begun in the Bush administration.

The article is
based on interviews over the past 18 months with current and former American, European and Israeli officials involved in the program, as well as a range of outside experts. None would allow their names to be used because the effort remains highly classified, and parts of it continue to this day.
It's a long, detailed, and sobering article. My basic reaction to this news isn't much changed from what I express in an earlier post.

Ken Pimple, PAIT Project Director

Wednesday, October 19, 2011

"Stuxnet Computer Worm’s Creators May Be Active Again"

John Markoff of the New York Times reports that the Stuxnet Computer Worm’s Creators May Be Active Again (October 18, 2011). Can anyone tell me what's more scary than Stuxnet?

Maybe I don't want to know.

Ken Pimple, PAIT Project Director

Monday, February 28, 2011

"Surrounded by Machines"

This article, published in the March 2011 edition of Communications of the ACM (pp. 29-31).

Although the article was authored by yours truly, it owes its title to Keith Miller and its publication to Rachelle Hollander, editor of CACM's ethics column, to both of whom my thanks. It briefly describes three of the presentations at the 2010 PAIT workshop.
The funding period for the project officially ends tomorrow (March 1, 2011).

In the same issue, "Catch me if you can" by Gregory Benford (pp. 112-111)1 traces the evolution of computer viruses and other malware, including Stuxnet. Benford claims that he wrote the first virus. I thank him for the article, but not for his invention.


Ken Pimple, PAIT Project Director

1This isn't a typo; the article begins on page 112 and ends on 111.

Monday, February 14, 2011

"Malware Aimed at Iran Hit Five Sites, Report Says"

This article from the New York Times by John Markoff (February 11, 2011) summarizes a report from computer security software firm Symantec analyzing the Stuxnet worm. They found that there were "three waves of attacks."
Liam O Murchu, a security researcher at the firm, said his team was able to chart the path of the infection because of an unusual feature of the malware: Stuxnet recorded information on the location and type of each computer it infected.
Symantec analyzed samples of the worm from "various" computers and "determined that 12,000 infections could be traced back to just five initial infection points."

The tracking information was apparently intended to allow the attackers to learn whether the target computers became infected.

Sophisticated malware meets sophisticated analysis.

Ken Pimple, PAIT Project Director

Thursday, January 27, 2011

More on Stuxnet

In an earlier post, I wrote about the theory that Stuxnet was created and deployed by the U.S. and Israel. I deplored the deed because it also unleashed a powerful and - to my knowledge - unprecedented form of malicious software that will certainly be copied and re-used for all sorts of mischief.

The January 26, 2010, edition of the New York Times includes two op-ed pieces on Stuxnet. In "25 Years of Vandalism," William Gibson (author of Neuromancer and coiner of the word "cyberspace") traces the history of hacking to 1986. He also claims that it is less likely that Stuxnet is "a cyberweapon purpose-built by one state actor to strategically interfere with the business of another" than "a piece of hobbyist 'street' technology." If he's right, this is probably even worse news than I thought. It seems likely that hobbyist crackers - who are probably more numerous and even less discerning than governments - can adapt each others' code more readily than the kind of sophisticated worm Stuxnet has been described as elsewhere.

Indeed, the other op-ed, "From Bullets to Megabytes" by Richard A. Falkenrath, former "deputy homeland security adviser to President George W. Bush," describes Stuxnet as a "sophisticated half-megabyte of computer code." Falkenrath's analysis of the fallout from Stuxnet is also more sophisticated on mine, touching on the likely effect on relationships between governments and the global information technology industry as well as raising questions about the legality of the authorization of the use of such malware by the U.S. President.

It's a scary place out there.

Ken Pimple, PAIT Project Director

Friday, January 21, 2011

"Israel Tests on Worm Called Crucial in Iran Nuclear Delay"

This article, published January 15, 2011, in the New York Times, lays out a case to show that the United States and Israel created and used the Stuxnet computer worm to delay Iran's nuclear program.
By the accounts of a number of computer scientists, nuclear enrichment experts and former officials, the covert race to create Stuxnet was a joint project between the Americans and the Israelis, with some help, knowing or unknowing, from the Germans and the British.
Stuxnet does its damage by taking over a specific controller, the Siemens P.C.S.-7, which is used to run all kinds of industrial machinery. In particular, Stuxnet targeted the controllers of the centrifuges used by Iran to enrich uranium into a form that can be used to fuel a power plant or create a nuclear weapon. The P.C.S.-7 is widely used, and it seems likely that Stuxnet could be adapted to attack other nuclear refineries or even other kinds of plants - water treatment facilities, power plants, and so forth.

It seems to be widely agreed that Stuxnet is too sophisticated to have been created by your run-of-the-mill, or even stand-out, cracker, meaning that it was most likely created by one or more governments or corporations. The claim that it was crafted by the United States with Israeli help strikes me as credible, and I am glad that Iran's nuclear ambitions have been delayed.

However, the origin and results of this (apparently) first use of Stuxnet are not my concern here. To me, the biggest issue is that this sophisticated software is out there, available for study. I find this to be the most disturbing paragraph in the article:
“It’s like a playbook,” said Ralph Langner, an independent computer security expert in Hamburg, Germany, who was among the first to decode Stuxnet. “Anyone who looks at it carefully can build something like it.” Mr. Langner is among the experts who expressed fear that the attack had legitimized a new form of industrial warfare, one to which the United States is also highly vulnerable.
Someone, whether the U.S. or someone else, carefully crafted a genie, and then let it out of the bottle. The world may be a bit more safe from Iran's nuclear program for the moment, but I can't help wondering whether it's a net gain in security.


Ken Pimple, PAIT Project Director