Surveillance and servility: is the AV industry a puppet of statecraft?

2013-12-02

Samir Mody

K7 Computing, India
Editor: Helen Martin

Abstract

‘Surveillance has been an instrument of statecraft for millennia.' Samir Mody, K7 Computing


Table of contents

(The views expressed herein are the author’s own. They do not reflect the policies or opinions of the author’s current employer or any other party.)

In a paper I submitted for the 2011 AVAR conference I stated the following: ‘There can be little doubt that the military and intelligence establishments of various nations have wings dedicated to cyber warfare ... Given the enormous resources involved and the high-profile, targeted nature of cyber attacks, it is difficult to predict the security responses of commercial anti-virus companies and the general public at large. It is likely that standard civilian bodies would largely be bystanders in these events.’ [1]

My opinion, forged on the anvil of revelations surrounding Stuxnet, Flame, Duqu and their ilk, has not changed over the past couple of years, notwithstanding an article [2] which landed in my inbox recently. The article refers to an open letter to the AV industry, which seeks clarification on the possible tacit collusion of the industry within the ambit of global statecraft, whether ratified in a partisan manner or not. I agree with Kurt Wismer, who points out that resourceful intelligence agencies ought to be at least as proficient as the common, albeit professional, cybercriminal in routinely bypassing modern security software, thus obviating the need to recruit AV industry partners. No strings being pulled here.

What about the concept of surveillance in the era of cyber warriorism? Surveillance has been an instrument of statecraft for millennia. 2,300 years ago, in his magnum opus Arthashastra, the Indian philosopher and statesman Kautilya described and, in fact, prescribed spying as an essential aspect of government policy in maintaining the security of the realm. In a democracy, it is the extent to and premise on which the denuded citizen is subjected to government voyeurism that raises concerns and generates heated debate.

Interestingly, survey findings revealed during Andrew Lee’s keynote address at this year’s VB Conference [3] suggest that a majority of the US public would support, or at any rate be indifferent to government surveillance if it were done in a transparent manner for the public good. The respondents’ views must reflect their threat perception and trust in governance at any given point in time. Therefore, the geographical location of the respondent, influenced by the narratives of history, is very important.

Let’s look at a brief case study. In August 2012, a mass exodus of Indian citizens of north-eastern origin (from various other parts of the country) was orchestrated via crude but effective misinformation propaganda, involving doctored visuals and threatening messages disseminated via various forms of social media. The context of ethnic skirmishes immediately preceding these events meant that the attack was sufficiently potent to effect a mass movement of people who believed themselves to be vulnerable. It took several days for the former status quo to prevail, providing a stark demonstration of the threat potential inherent in social networking. Perhaps a timely intervention by a vigilant agency could have nipped this attack in the bud. Indeed, in the context of national security, section 69(1 and A1) of the Indian IT Act authorizes designated government agencies to ‘intercept, monitor, decrypt…’ and ‘block for access…’ any computer-related data. If nothing else, at least the intent has been communicated transparently in the public domain. (Certain intrusive activities require a court warrant.) Nevertheless, concerns about the security of the collected data and its potential abuse are justified. (IT-related legislation across many democracies probably contains similar provisions in relation to national security.)

The Act, perforce, makes no mention of clandestine monitoring activity, or the need for private entities to enter into an insidious partnership with intelligence agencies. Let us not be naïve, however. Should these agencies wish to snoop, they don’t require the cooperation of AV vendors.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest articles:

VB2018 paper: Tracking Mirai variants

Mirai, the infamous DDoS botnet family known for its great destructive power, was made open source soon after being found by MalwareMustDie in August 2016, which led to a proliferation of Mirai variant botnets. This paper presents a set of Mirai…

VB2018 paper: Hide’n’Seek: an adaptive peer-to-peer IoT botnet

This paper presents a thorough analysis of the inner workings of Hide’n’Seek, a peer-to-peer IoT botnet discovered in January 2018. With an exploit table that can be updated in memory and modular in its approach, Hide’n’Seek gives us a glimpse of…

Botception: botnet distributes script with bot capabilities

Researchers Jan Sirmer and Adolf Streda describe the branch of the Necurs botnet that they have been monitoring, the changes it has undergone in the course of a year, and present an analysis of the next stage of the attack: Flawed Ammy.

VB2018 paper: Since the hacking of Sony Pictures

Minseok (Jacky) Cha describes various attacks in Korea which occurred after the Sony Pictures hacking incident and which are suspected to be the work of the same group, the Lazarus Group.

VB2018 paper: Uncovering the wholesale industry of social media fraud: from botnets to bulk reseller panels

In this paper GoSecure researchers Masarah Paquet-Clouston and Olivier Bilodeau explore an undocumented segment of the social media fraud (SMF) industry: wholesaling, from botnet supply operations to bulk reselling.


Bulletin Archive

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.