Elizabeth Van Wie Davis /author/elizabeth-van-wie-davis/ Fact-based, well-reasoned perspectives from around the world Mon, 19 Aug 2019 21:44:44 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.3 Can Technology Help China Rebuild Social Trust? /region/asia_pacific/china-social-credit-system-surveillance-technology-asia-pacific-news-32411/ Thu, 01 Aug 2019 12:14:03 +0000 /?p=79668 The world’s governments and peoples must decide how to address the increasing surveillance and data collection — and the resulting loss of privacy — that digital formats provide. In recent years, much of this attention has focused on the rapidly building surveillance and data aggregation in China in terms of the emerging social credit systems,… Continue reading Can Technology Help China Rebuild Social Trust?

The post Can Technology Help China Rebuild Social Trust? appeared first on 51Թ.

]]>
The world’s governments and peoples must decide how to address the increasing surveillance and data collection — and the resulting loss of privacy — that digital formats provide. In recent years, much of this attention has focused on the rapidly building surveillance and data aggregation in China in terms of the emerging social credit systems, which received strongly from the in the past two years. At issue is the to “comprehensively move social credit system construction forward” by 2020.

According to the systems’ founding document, the optimistic scheme should “the idea of a sincerity culture and carrying forward sincerity and traditional virtues.” So why is there such a strong difference between the optimistic Chinese and pessimistic Western perceptions of social credit systems?

Many reasons contribute to this chasm between the Chinese and Western perceptions. First, the outcry may relate to the erroneous idea that this information is consolidated into a single file on individuals, combining financial data, purchasing patterns, travel records and facial recognition. Second, the Western perceptions are influenced both by suspicions of the Chinese government and by a Western failure to come to grips with their own domestic electronic collection. Finally, and uniquely, the social credit network mimics some elements and repairs other consequences of the 1966-76 Cultural Revolution in China.

Good Standing

The Chinese government is proposing a social credit network as a desirable way to measure and enhance “trust” nationwide and to build a culture of “sincerity” in a society still suffering from the shattered trust of the Cultural Revolution. The policy : “It will forge a public opinion environment where keeping trust is glorious. It will strengthen sincerity in government affairs, commercial sincerity, social sincerity and the construction of judicial credibility.”

There is no single social credit system in China. There is a wide spectrum of pilot systems, some commercial and some run by local governments that measure different elements related to social trust. Eventually, however, the National Development and Reform Commission, a powerful central body, will have vast amounts of data available. Striving to of existing systems, “The government is responsible for formulating and implementing development plans, completing regulations and standards, fostering and supervising credit service markets. Focus on giving rein to the role of market mechanisms, coordinate and optimize resource allocation, encourage and muster social forces, broaden participation, move forward together, shape joint forces for social credit system construction.”

Specifically, the credit system wants to limit commercial swindles, sales of counterfeit products, tax evasion and fraudulent financial claims. Not only is there no overall system yet to monitor this fraud by commercial entities on citizens — or by citizens on other citizens — but also Chinese authorities are not creating a that will determine every aspect of every citizen’s life.

Although the West has sleep walked into the massive collection of data and loss of privacy, the Chinese electronic systems have leapt nearly fully formed into view.

Of the pilot systems, — 80% of respondents — approve of both the commercial and the government-run systems. In one commercial program, now ended, the government allowed private companies to pilot systems and algorithms for social credit scores, including : one by a partner of the social-network giant Tencent and developer of the messaging app WeChat, and another, by Sesame Credit, is run by the Ant Financial Services Group (AFSG), an affiliate company of Alibaba. These private systems appear to have ended in 2017.

Although the commercial pilot social credit programs have ended, commercial entities feature first and foremost in the systems of Chinese social credit. Commercial entities retain their good standing if they pay taxes on time and lose good standing for substandard or unsanitary products — a for people across China due to frequent scams and food safety scandals. Chinese citizens see social credit systems as a reliable source of information on the trustworthiness of commercial entities, social organizations and individual service providers to such an extent that 76% of people queried responded that a general is a problem.

Respondents see social credit as a helpful means of punishing polluters, reducing substandard products and otherwise disciplining negligent commercial entities in an era of rapid commercialization, economic growth and .

Signs of Abuse

In addition to monitoring the trustworthiness of commercial entities, the social credit network is meant to provide individual citizens with credit records. The more durable social credit pilots have been primarily piloted by local governments. In these local government schemes — there are approximately — negative criminal infractions lead to deductions from the overall individual credit score. The government asserts that social credit systems are also a positive way to bring in those people out of traditional credit systems, including low-income and rural households.

The negative and positive also extends to the overall systems, where the negative impacts of social distrust inculcated by the Cultural Revolution and adverse side effects of rapid economic expansion are intended to be balanced by the positive aspects of social credit systems that discourage scams and reward good citizenship.

These programs to monitor commercial entities and citizens — both civil servants and private citizens — are being developed simultaneously with video surveillance systems and rapidly developing facial recognition software. China is now rivaling the West and Japan in implementing a as well as becoming a major distributor of surveillance equipment. While there are justifiable concerns that these closed-circuit television (CCTV) cameras combined with facial recognition networks can be used for nefarious purposes in China and elsewhere, so far include boarding subways in Shanghai, catching shooters in the West, waking up drowsy workers in Japan, checking bus driver fitness in the UAE and finding elders with dementia in Singapore.

Again, it is vital to watch for signs of abuse from both governments and commercial entities in this rapidly expanding technology. Reported include Uighur Muslims in Western China, where victims relate stories of being tracked by cell phones, facial recognition software attached to either CCTV or drones, and DNA testing. According to , “The field of big data in cloud computing is slowly blossoming.” The surveillance of specific political or ethnic groups was designed, as the , to “apply the ideas of military cyber systems to civilian public security.” These cases — especially those targeting political opposition in , Rwanda and Zimbabwe — are at best.

With a 2020 goal to get systems in place — although the goal seems to be less a deadline and more the end of a — the social credit network appears to be an ecosystem made up of various stratagems that are all run in different ways by cities, government ministries, online payment providers, neighborhoods, libraries and businesses, Chinese researchers who are designing the national scheme. Although many of these subsystems may be interconnected by a network of information, it will not be a unified platform where one can type in one’s ID and get a single score that will determine a citizen’s life.

This caricature of a unified system that doles out unique scores to 1.4 billion people — with around 46,000 born and some 19,000 dying each day — would come with nearly insurmountable . Politically, the Chinese government is not only trying to build trust for and within commercial entities and individual citizens, but also runs a terrible risk if it loses this same trust from those same commercial entities and citizens, as it has during the Cultural Revolution.

Western Perceptions

Western perceptions of Chinese social credit systems are pessimistic. This negative perception has at least two major parts. The first part is the horror of seeing a complex electronic network implemented over a few years with its resultant loss of privacy and inevitable errors. Although the developing social credit systems are similar to the systems in the West, these Western systems emerged bit by bit and are rarely considered as a whole. The second part of negative perception is the fear that the Chinese government is not to be trusted with such data, especially given the history of that government with similar data during eras like the Cultural Revolution.

Westerners are often appalled by the Chinese social credit systems for many reasons, not the least of which is seeing the systems that have slowly accumulated in the West appear fully formed in China. Westerners have become accustomed to losing privacy in small bits — by private commercial entities like Amazon, Google and Experian — and have eagerly participated in rating other private entities based on their experiences, such as doctors, realtors and restaurants. With Uber and Lyft, riders rate the drivers, and the drivers rate the riders.

Entire podcasts exist just to rate movies, books and television series. Facebook automatically identifies people in photographs with facial recognition software and chooses advertisements based on . These rating systems that developed over decades become truly shocking when Westerners see it developed in a single leap, much as it is in China.

Governments in the West increasingly monitor their citizens with the resultant loss of privacy. The US National Security Agency (NSA) monitors phone calls, emails and locations, then uses that information to try to identify potential wrongdoers. The UK intelligence agency, GHCQ, with collaboration from the NSA, has been from guiltless Yahoo users. GCHQ files between 2008-12 state that a surveillance program, Optic Nerve, collected still images of Yahoo webcam chats in bulk and saved them to agency databases, regardless of whether individual users were an intelligence target or not. The was used to experiment with facial recognition, to monitor existing targets and discover fresh ones.

The electronic systems in the West, and the loss of privacy, reached a tipping point over a decade ago. Richard James Thomas, who served as the UK information commissioner from 2002-09, says more and more personal data is being collected and stored, both by Western governments and commercial entities. He back in 2006 that “we are in fact waking up to a surveillance society that is already all around us.”

Moreover, Western electronic surveillance has a few known flaws. On the one hand, there is always the potential for false positives with algorithms. For instance, think of irrelevant advertisements popping up online based on some algorithm one’s interests. In another instance, false information is almost impossible to remove from based on similar names or some other error.

On the other hand, the databases are being stretched. Alec Jeffreys, a pioneer of , said fingerprint, DNA and facial recognition databases originally created from criminal arrests or investigations are now running biometric network searches against massive state driver’s license data bases that are primarily made up of . The UK’s , from the Surveillance Studies Network, says that “The surveillance society has come about almost without us realizing.” Although the West has sleep walked into the massive collection of data and loss of privacy, the Chinese electronic systems have leapt nearly fully formed into view.

Suspicions of the Chinese government

So, although the technologies and methodologies of electronic surveillance are similar in the West and in China, one big difference is that the Chinese government is viewed suspiciously. For instance, there is an outcry that China issues national ID cards at age 16; however, the is also issued at 16. There is outrage at the Chinese use of facial recognition software, similar to the systems set up by the and used extensively in . There is unhappiness concerning the Chinese government’s emails, texts and social media, which is done throughout the West, especially in the context of terrorism or to aid law enforcement or for visas, or even “inadvertently.”

Complaints highlight the Chinese use of credit scores, like the US FICO score, and CCTV, which is used intensively in the UK. Especially ironic is the emphasis on China’s viewing of shopping habits, which are so notoriously scrutinized in the US that knew women were pregnant based on what they purchased before their families did.

One basis of these concerns seems to be Western commentators’ worries that this information will allow the Chinese government to target citizens’ behavior and political beliefs. Of course targeting Western citizens’ beliefs is rampant in the West in an age where the disclosure of — a database that government voter rolls with social media data such as lists of people who liked certain Facebook posts, commercial data from grocery chains and religious leanings based on church membership rolls — caused popular distress and government hearings.

Google street views can determine whether voters on that street are conservative or liberal based on the number of parked pickup trucks or Toyota Priuses. Moreover, most , including every registered voter, along with their name, addresses, party registration, voting frequency history, employer and job title.

The social credit systems, a major policy initiative, is clearly identified with Xi Jinping. While he is powerful and the pilots are popular, the social credit network is secure. 

Clearly, most Westerners give their governments the benefit of the doubt that this data will only be collected under specific constraints and for trustworthy purposes. The same benefit of the doubt is not conferred on the Chinese authorities. While the Chinese government may be seeking to develop domestic trust with the collection of data, internationally the trust seems to be waning rather than waxing. Some Western suspicions are likely based on the former Chinese dangan and hukou systems that kept public records and encouraged neighbors and co-workers to check on each other.

These systems played an important role in the Cultural Revolution, and fears are that an electronic version is being created in an era of massive urbanization, where people have left their home villages to work in the cities and live side by side with people they do not know well.

Chinese citizens, however, do give their government the benefit of the doubt both that this data will be used responsibly and that the social credit system will help alleviate the massive lack of trust in Chinese society. Much of this lack of trust stems not only from the rapid industrialization and modernization, but also from the long-lasting and unprocessed effects of the Cultural Revolution. It is not a coincidence that both China’s first leader to grow up during the Cultural Revolution and the renewed assertion that local officials implement a “” — that is, go among the people, talk to everyone and collect and distinguish correct and incorrect ideas — are occurring simultaneously with the creation of social credit systems. The social credit systems mimic some elements and repairs other consequences of China’s Cultural Revolution.

The Cultural Revolution’s massive discord saw citizens turn on citizens and destroy social trust, which is the main area that the social credit systems try to repair. An important shows that the Cultural Revolution, in which have lost their lives, affected everyone in society. It affected not only citizens who were mistreated during the revolution, but also those who witnessed the untrustworthy behavior of their neighbors and friends even when these behaviors were not directed at them. Another study also shows the continuing as a result of the culture of spying and snitching that the Chinese Communist Party fostered among the population. It is this loss of social trust that the social credit systems attempt to address.

Children of the Revolution

The Cultural Revolution was a formative time for Chinese President Xi Jinping and for his generation. The president’s father, once a high-ranking official, was purged in the early days of the , and Xi Jinping — thus considered a “princeling” — was among millions of urban youth sent to rural areas to be reeducated by farmers and laborers. Some of that his experiences during the Cultural Revolution support his authoritarian approach; that is, instead of turning against the party, government or leader, he revered strict order and abhorred challenges to hierarchy.

As the Cultural Revolution cooled, one of Xi Jinping’s friends saw him choose to become “” — red symbolizing the Communist Party’s ideology — to survive. If any of these observations are true, they certainly lend credence to a reliance on a government-run social credit network.

Xi Jinping, the leader creating and implementing the social credit score, took the trauma of the Cultural Revolution to move back into and up through the ranks of the Chinese government and party, but never throwing off its impact. In 1975, the 22-year-old Xi Jinping attended the esteemed Tsinghua University to study chemical engineering. By the time Xi graduated in 1979, he as secretary to the then-secretary general of the Central Military Commission, Geng Biao, until 1982. Twenty years later, Xi Jinping came last in the rankings of alternate members of the 15th Central Committee of the Communist Party in 1997.

Working his way up the party ranks, Xi served in several provinces, ending with a brief but prestigious in Shanghai, to be unexpectedly promoted in 2007 directly to the Standing Committee of the Politburo — China’s most elite political body. His just months later, in March 2008, as vice president signaled his rise to president and party general secretary in 2012.

Xi Jinping is a powerful leader, but it is an error to assume that the party is a monolithic structure or that the success of policies like the social credit systems do not matter or that popular support for social credit networks do not matter. Xi’s strength is clear: Not only was his political ideology written into the Chinese Constitution, but also a constitutional amendment was passed on March 11, 2018, after his first five-year term, that removed the country’s 10-year presidential term limits.

In addition to his strength, however, Xi Jinping has many enemies and a formidable . Since Xi’s removal of the two-term limit, murmurs of have risen among academics, businesspeople and former officials despite censorship and the security police. So far, that discontent has not visibly extended to the creation of the social credit network.

So, while the party holds a monopoly on power, the party leadership is . The current leadership and its programs not only reflect the trauma of the Cultural Revolution, but also must survive the political mechanisms. The political mechanisms center on two main political coalitions within the party that are often in tension with each other and promote different policy agendas. These coalitions have become dangerously antagonistic. The success and popularity of the social credit systems may be hostage to these political tensions.

21st-Century Mao Zedong

On one side is the elitist coalition, now led by Xi Jinping. Its supporters come from the families of the old-guard revolutionaries who held top posts upon the founding of the People’s Republic of China in 1949. Those revolutionaries mostly lived and worked together, coalescing into a tight social group, until the Cultural Revolution dispersed them. Officials with a direct lineage to those founders, who claim to be the republic’s rightful heirs, have experienced a resurgence under Xi Jinping. The wants the party and the state to have more control in markets and corporations, and have an expansionist and nationalist position in international trade and politics. They are the primary advocates of the social credit systems.

On the other side is the populist coalition headed first by the previous president, Hu Jintao, and now by China’s premier, Li Keqiang. They drew their power base in part from the Communist Youth League, a gateway for young Chinese to achieve party membership that is often identified with populist positions. Populist coalition supporters are often without significant pre-1949 revolutionary credentials or family lineage. The policies are more pro-market, perhaps because they consolidated power in the new socialist market economy and take a more subtle approach to international politics. They tend to represent the more disadvantaged groups in the rapidly modernizing society. The Communist Youth League has been attacked vigorously by Xi Jinping and his faction within the elitist coalition. The populist coalition’s stance on the social credit systems is less clear.

The Xi Jinping faction — mainly Xi’s subordinates when he served in the provinces and Shanghai, his home province of Shaanxi and graduates of Xi’s alma mater Tsinghua University — initially targeted another faction within the elitist coalition, and then the populist coalition, with his anti-corruption campaign. It directed the campaign against the former president Jiang Zemin’s business faction within the elitist coalition, destroying families and wealth and networks of many powerful people. The faction simultaneously consolidated power by filling top regional posts and the top leadership positions in most of China’s 31 major administrative districts.

Will you support FO’s journalism?

We rely on your support for our independence, diversity and quality.

Donation Cycle

Donation Amount

The IRS recognizes 51Թ as a section 501(c)(3) registered public charity (EIN: 46-4070943), enabling you to claim a tax deduction.

The Xi faction within the elitist coalition is strong, but , at around 40,000 people, and he certainly has his domestic detractors. His admirers, reflecting back in part to the Cultural Revolution, like to Xi Jinping “the Mao Zedong of the 21st Century.” The opposition, however, is not hesitant in calling for Xi to .

The social credit systems, a major policy initiative, is clearly identified with Xi Jinping. While he is powerful and the pilots are popular, the social credit network is secure. However, if the citizens find the social credit systems to be unduly burdensome or too reminiscent of the negative aspects of the Cultural Revolution, there are plenty of powerful people in China — both within the elitist coalition and in the rival populist coalition — willing to find Xi Jinping responsible and .

While the Western fears of an all-pervasive, socially stifling social credit system are not impossible, Chinese domestic politics do provide something of a counterweight. Chinese citizens want to take the best from a social credit network: rebuild the trust destroyed by the Cultural Revolution and prevent the food scandals and general scams.

The development of Chinese social credit systems does provide an important opportunity for all countries using electronic surveillance to make important judgments regarding the boundaries of this new massive era of data collection. It is not very realistic to ask China to take the lead on this, especially given the wider Western experience, but China certainly should be part of emerging global standards on what is an acceptable loss of privacy by both governments and commercial entities.

The views expressed in this article are the author’s own and do not necessarily reflect 51Թ’s editorial policy.

The post Can Technology Help China Rebuild Social Trust? appeared first on 51Թ.

]]>
Don’t Underestimate North Korea’s Cyber Efforts /region/asia_pacific/north-korea-cyberattacks-cybersecurity-asia-pacific-news-analysis-15400/ Wed, 21 Mar 2018 15:29:08 +0000 http://www.fairobserver.com/?p=69444 Cyber operations in North Korea are becoming increasingly sophisticated. Cyber operations in North Korea (DPRK) are more diverse, aggressive and capable than often realized. According to the cyber security firm FireEye, “There is no question that DPRK has become increasingly aggressive with their use of cyber capabilities. They are not just focused on espionage —… Continue reading Don’t Underestimate North Korea’s Cyber Efforts

The post Don’t Underestimate North Korea’s Cyber Efforts appeared first on 51Թ.

]]>
Cyber operations in North Korea are becoming increasingly sophisticated.

Cyber operations in North Korea (DPRK) are more diverse, aggressive and capable than often realized. According to the cyber security firm , “There is no question that DPRK has become increasingly aggressive with their use of cyber capabilities. They are not just focused on espionage — we’ve seen them use it for attack, we’ve seen them use it for crime. …They are showing up in places outside South Korea [and] continuing to expand capabilities.” DPRK cyber warriors regularly exploit so-called zero-day vulnerabilities — undiscovered flaws in operating systems that allow a breach of defenses.

Moreover, cyber experts in DPRK are now capable of from vital computer networks isolated from the internet — air-gapped — such as military servers and power plant control systems. Now even air-gapped networks can be infiltrated, because even computers not connected to the internet still leak electromagnetic radiation during operation. By measuring those emanations, a cyber warrior can “extract the whole secret key by monitoring the target’s electromagnetic field for just a few seconds,” according to a recently published .

The DPRK cyber warfare program has clearly advanced over the past few decades. In the early 1990s, when computer networks were beginning to reach a level of maturity, a group of North Korean computer scientists proposed using the internet to spy on and attack enemies. These computer scientists were introduced to cyber military purposes by observing other countries’ uses of the internet as they traveled abroad. The DPRK program began by identifying promising young students for training in China’s top computer science programs.

By the late 1990s, the FBI noticed that DPRK officials assigned to work at the United Nations in New York were also enrolling in university computer programming courses there. The DPRK’s cyberwarfare program continued to gain in priority after the 2003 US invasion of Iraq. After watching the American “shock and awe” campaign, Kim Jong-un’s father, , “If warfare was about bullets and oil until now, warfare in the 21st century is about information.” Pushing the DPRK’s cyber units to dramatically level up in capability again and building on his father’s observation, allegedly said, “Cyber warfare, along with nuclear weapons and missiles, is an ‘all-purpose sword’ that guarantees our military’s capability to strike relentlessly.”

Institutions and Individuals

North Korea’s cyber operations are run by the clandestine Reconnaissance General Bureau (RGB) and by the military’s General Staff Department (GSD). The RGB is the center of the DPRK cyber activity as well as more traditional subversive and clandestine activity. Formed in 2009 from various intelligence and special operations units — tasked with unconventional and political warfare, subversion, propaganda, kidnappings and assassinations, intelligence and special operations — the RGB combined these units into one organization. General was the founding director of the RGB from 2009 to 2016. The Japanese press speculates that the of the RGB could be an official named Jang Kil-su, while others speculate that the new director could be General No Kwang-chol.

Regardless of its de jure reporting status, the RGB de facto answers directly to the National Defense Commission and Kim Jong-un in his role as supreme commander of the military. Notable examples associated with the RGB, and the offices that were combined to create it, are subversive provocations short of armed conflict, such as the 2010 sinking of the South Korean Cheonan naval vessel, as well as its extensive cyber activities.

The GSD, the military wing of cyber operations and broadly comparable to the US Joint Chiefs of Staff, oversees operational aspects of the entire DPRK military as well as having authority over numerous operational cyber units. GSD units are tasked with political subversion, cyber warfare and operations such as network defense. So far the DPRK does not seem to have these units into an overarching cyber command. Specifically, the GSD’s Operations Bureau has been attributed with conducting cyber operations and perhaps propaganda/psychological warfare using cyberspace as a medium, but information about the nature of these operations, as well as the subordinate unit conducting them, has been sparse.

The DPRK’s cyberattacks often emanate from third party countries and use hijacked computers. Those ordering and controlling the attacks communicate to cyber warriors and hijacked computers from within North Korea. In an attempt to interfere with the connection between the internal commands and external attack sites, the carried out denial of service (DoS) attacks against the DPRK in an attempt to limit their access to the internet.

In part as a response to DoS attacks and attempts to shut down its main international internet access, the DPRK has moved to increase its capability to conduct cyberattacks by diversifying its access to the internet. Initially, the DPRK’s internet traffic was handled via China Unicom under a 2010 deal. The DPRK opened a second internet connection with the outside world in October 2017, this time via Russia. Dyn Research, which monitors international internet traffic flows, saw the Russian telecommunications company Trans Telecom routing the DPRK traffic. The Russian internet provider now appears to be handling roughly 60% of the DPRK internet traffic, while the Chinese internet provider transmits the remaining 40%. “This will improve the resiliency of their network and increase their ability to conduct command and control over those activities,” a Dyn Researcher executive .

Cyber Strategy

Emerging as a significant cyber warrior with both its clandestine and military organizations exercising substantial capability to conduct cyber operations, the emphasizes asymmetric and irregular operations in its state of constant military preparedness in both low-intensity conflict and high-intensity conflict to counter adversaries’ military strength. The DPRK’s low-intensity conflict strategy is to launch unconventional operations to disrupt the status quo without escalating the situation to a level the DPRK cannot control or win. However, if high-intensity kinetic war breaks out, the “quick war, quick end” strategy is to launch extensive irregular operations, which include cyberwarfare, to exploit the adversary’s vulnerabilities and target command, control, communications, computers, intelligence, surveillance and reconnaissance (C4ISR) in a military blitzkrieg.

In support of its cyber strategy, the DPRK maintains an information technology base that serves as a general research and developmental foundation for computer technology and programming. The existence of a software and computer industry means that the DPRK’s cyber industries are increasingly advanced. This research and development means the DPRK is capable of sophisticated cyber operations in conjunction with psychological operations, military exercises and missile tests.

While other countries, like New Zealand, Singapore and Canada, have complained about cyberattacks from the DPRK, most of North Korea’s cyber focus is on South Korea and the US. The DPRK’s most famous strike was an unconventional attack in 2014, against , to block the release of a political farce movie, The Interview, which satirized an attempt to “kill” DPRK leader Kim Jong-un. What has been less publicized is that the DPRK also unconventionally attacked a British television network a few weeks earlier in 2014 to stop the broadcast of a drama about a nuclear scientist kidnapped in Pyongyang. This type of unconventional cyberattack is different than most countries’ cyber strategy, but similar to cyberattacks on South Korea’s television station in 2013.

The DPRK has also conducted a serious of cybercrimes to both disrupt the international system and to gain much needed foreign currencies. US intelligence officials the DPRK to the WannaCry ransomware attack in May 2017. The WannaCry attack involved an outbreak of malware that infected more than 230,000 computers in over 150 countries.

Although the have not been independently verified, researchers in South Korea say attacks in 2017 on virtual currency exchanges have the digital fingerprints of the DPRK cyber forces. South Korea is home to some of the world’s largest virtual currency exchanges and accounts for 15% to 25% of world bitcoin trading. On December 18 and 19, 2017, a virtual currency company, Youbit, suffered two cyberattacks that cost it 17% of its assets, forcing the exchange to halt operations and file for bankruptcy. Similarities between the December cyberattacks and an April 2017 cyberattack included the use of malicious code previously used by the DPRK.

Hidden Cobra

Even more seriously, a South Korean lawmaker revealed in 2017 that the DPRK had successfully broken into the South’s to steal war plans, including for the “decapitation” of the DPRK leadership in the opening hours of a theoretical war on the Korean peninsula. There is also evidence the DPRK planted so-called digital sleeper cells in South Korea’s critical infrastructure that could be activated to paralyze power supplies and military command and control networks. Additionally, the DPRK stole F-15 fighter jet wings’ blueprints from its neighbors computers.

The DPRK’s program was created to deploy cyberattacks against enemy states. Since 2009, the DPRK has conducted cyberattacks and infiltrated US aerospace, telecommunications, financial industries and critical infrastructure sectors in both the US and around the world. Hidden Cobra includes Volgmer and FALLCHILL. US Homeland Security and the FBI released technical details of the DPRK cyberattacks in alerts containing IP addresses associated with Volgmer, one of the backdoor Trojans the DPRK has used for years.

They similarly released information on a DPRK malware titled FALLCHILL. FALLCHILL gains entry into a computer when a user unwittingly downloads it from an infected website or as a secondary payload from another malware that had infected the system. FALLCHILL can retrieve information as well as execute, terminate and move processes and files; it is hard to detect because it can also clean up after itself. Hidden Cobra is the same program that claimed responsibility for the Sony Pictures cyberattack in 2014.

Cyber operations in the DPRK are becoming quite sophisticated. In designing these cyberattacks, DPRK strategy emphasizes asymmetric and irregular operations in both peacetime and wartime to counter adversaries’ military strength. Peacetime strategy is to launch low-intensity unconventional operations like cyberattacks and wartime strategy is to use cyber capabilities in hybrid blitzkrieg operations.

While keeping abreast of international cyber capabilities, the DPRK maintains a national information technology base that conducts and creates the national research and developmental necessary for its cyber operations. This should leave the international community in no doubt that not only is the DPRK a significant actor in cyberwarfare, but also that the North Korean leadership is committed to further development of their operations and capabilities.

The views expressed in this article are the author’s own and do not necessarily reflect 51Թ’s editorial policy.

Photo Credit:/

The post Don’t Underestimate North Korea’s Cyber Efforts appeared first on 51Թ.

]]>
China’s Cyberwarfare Finds New Targets /region/asia_pacific/china-cyberwarfare-cybersecurity-asia-pacific-news-analysis-04253/ Fri, 27 Oct 2017 15:50:14 +0000 http://www.fairobserver.com/?p=67345 Is China a leader in cyberwarfare? China answers yes. With the massive media coverage of Russian cyber interference in recent Western elections, the time is ripe to examine the issue of cyberwarfare in China. China discusses its own emphasis on cyberwar capabilities in several official documents, including the 2015China’s Military Strategy white paper: “Cyberspace has… Continue reading China’s Cyberwarfare Finds New Targets

The post China’s Cyberwarfare Finds New Targets appeared first on 51Թ.

]]>
Is China a leader in cyberwarfare? China answers yes.

With the massive media coverage of Russian cyber interference in recent Western elections, the time is ripe to examine the issue of cyberwarfare in China. China discusses its own emphasis on cyberwar capabilities in several official documents, including the 2015 white paper:

“Cyberspace has become a new pillar of economic and social development, and a new domain of national security. … As cyberspace weighs more in military security, China will expedite the development of a cyber force, and enhance its capabilities of cyberspace situation awareness, cyber defense, support for the country’s endeavors in cyberspace and participation in international cyber cooperation, so as to stem major cyber crises, ensure national network and information security, and maintain national security and social stability.”

Moreover, in the wake of the massive worldwide , China was hit hard. The malicious backdoor software that hackers relied on to develop the ransomware attack was created by the US National Security Agency (NSA) and later stolen by a secretive group known as the ; NSA whistleblower Edward Snowden wrote that the “circumstantial evidence and conventional wisdom” suggested . With the , surpassing 649 million users, China is more openly declaring its place as a cyber power among the US, Russia, Israel and North Korea — the “cyber five.” The question is whether China will fully assume a leadership role.

The iSight intelligence unit of FireEye — a company that manages large network breaches — conducted a study that came to the conclusion that. China picks targets more carefully and covers tracks more expertly. Unit 61398 — the notorious military-run cyber center — appears to be largely out of business, with its hackers dispersed to other military, private and intelligence units. The Chinese cyberattacks have focused on the US, Russia, South Korea and Vietnam and have sometimes aimed at the South China Sea disputes. The report states that the change is part of Chinese President Xi Jinping’s broad effort to bring the Chinese military, which is one of the , further under his control.

A Revolution in Cyber Affairs

The Chinese approach has clearly shifted in the past three years. For instance, The Science of Military Strategy — a study of the , published by China’s Academy of Military Sciences — released in 2015,both acknowledges for the first time that China has built up network attack forces and divides them into specialized military network warfare forces, teams of network warfare specialists in government civilian organizations and entities outside of the government that engage in network attack and defense, including its civilian IT industry. Similarly, the 2015 China’s Military Strategy asserts that “China will devote more efforts to science and technology in national defense mobilization, be more readily prepared for the requisition of information resources, and build specialized support forces. China aims to build a national defense mobilization system that can meet the requirements of winning informationized wars and responding to both emergencies and wars.” This new openness about the need for strong cyber forces and the integration of civilian specialties into national defense is a definite shift.

The previous two decades were a steady buildup to this perspective. Beginning as early as 2000, China’s Central Military Commission called for a study of people’s war under conditions of “informationalization.” The Chinese strategy called Integrated Network Electronic Warfare consolidated the offensive mission for both computer network attack and electronic warfare under the PLA’s General Staff Department. The originator of the strategy, now retired Major General Dai Qingmin, a prolific and outspoken supporter of modernizing the PLA’s information warfare capabilities, first described the combined use of network and electronic warfare as early as 1999 in articles and a book entitled An Introduction to Information Warfare, written while on faculty at the military’s Electronic Engineering Academy. General Dai was promoted in 2000 to lead the General Staff’s 4th Department.

China’s National Defense in 2004 white paper stated that “informationalization has become the key factor in enhancing the warfighting capability of the armed forces” and that the military takes informationalization “as its orientation and strategic focus.” advocates a combination of cyber and electronic warfare capabilities in the early stages of conflict. Both the 2004 white paper and the noted expert on the PLA, , identify the PLA Air Force as responsible for information operations and information countermeasures. Other lie with the PLA General Staff’s 4thand 3rdDepartments that conduct advanced research on information security. The 4thDepartment oversees electronic counter-measures and research institutes developing information warfare technologies. The 3rdDepartment is responsible for signals intelligence and focuses on collection, analysis and exploitation of electronic information. The military also maintains ties with research universities and the .

The Chinese military maintains a network of universities and research institutes that support information warfare-related education either in advanced degree granting programs or specialized courses. Military universities supporting this approach include the National University of Defense Technology, the PLA Science and Engineering University and the PLA Information Engineering University.

China, like many countries, initially turned to its civilian computer programmer subculture and information technology workforce, but this strategy too has modified as Chinese cyberwarfare strategy matures. In the early days of 1999 to 2004, China’s civilian computer programmer subculture gained notoriety for its willingness to engage in large-scale politically motivated denial of service attacks, data destruction and defacements of foreign networks. While initially encouraged, this sentiment changed and sources published editorials suggesting that civilian computer attack activities would not be tolerated.

Nonetheless, the traditional computer programmer subculture may still offer unique skill sets and may have a niche role for military or state intelligence collection. Some evidence suggests a relationship exists between Chinese malicious civilian computer programmer subculture and Chinese government operators responsible for network intrusions, and there has been limited recruiting from this community, similar to what occurs in the US and Russia.

Informationization

How is China integrating the military strategy for cyberwarfare into overall planning efforts and implementing it? The FireEye study concluded that as early as 2014, around the time of the indictment of the PLA’s officers and hackers in the US for economic cyber theft, the . Central to this new posture is the previous decade’s scheme of informationization. The guiding doctrine, Local War Under Informationized Conditions, outlines the effort to develop a fully networked architecture capable of coordinating military operations on land, in air, at sea, in space and in cyber realms. The goal is to establish control of a rival’s information flow and maintain dominance in the early stages of a conflict.

Chinese military strategists early on viewed information dominance as a key goal at the strategic and campaign level, according to The Science of Military Strategy in 2005 and in 2006. The strategy relies on applying electronic warfare and computer network operations against an adversary’s command, control, communications, computers, intelligence, surveillance and reconnaissance (C4ISR) networks and other essential information systems. The strategy requires that these cyber tools should be widely employed in the earliest phases of a conflict and possibly preemptively against an adversary’s information systems and C4ISR systems. Additional to the core military objective, other goals have emerged.

The is to deny an enemy access to information essential for continued combat operations, ideally before other forces engage in combat. A secondary objective is to attack people’s perception and belief systems through information deception and psychological attack. A third objective is strategic deterrence, which some Chinese military strategists see as comparable to nuclear weapons but possessing greater precision, leaving far fewer casualties and possessing longer range as most other weapons.

Another early objective of cyber strategy in China, a strategy that has been greatly modified since the 2014 shift, was cyberespionage. Most countries engage in some sort of espionage of each other’s governments. However, in the initial stages from 2006 to 2014, China was very active in cyberespionage of commercial interests as opposed to government secrets; some scholars argue that . A massive commercial cyberespionage campaign was conducted by APT1, a single organization of operators. Since 2006, Mandiant — another FireEye company — observed APT1 compromised 141 companies spanning 20 major industries, a long-running and extensive cyberespionage campaign made possible, in large part, through direct government support it received from the military’s Unit 61398. As late as 2011, at least 17 new victims operating in 10 different industries. However, by 2017, , as Chinese cyber strategy completes its shift from volume to sophistication and its shift from commercial to government objectives.

One of the major concerns of cyberespionage, besides loss of government and commercial secrets, is that it can be a frontrunner for cyberattacks. According to , “What most worries American investigators is that the latest set of attacks believed coming from Unit 61398 focus not just on stealing information, but obtaining the ability to manipulate American critical infrastructure: the power grids and other utilities.”

Then-US President Obama discussed this point in this 2013 . “We know foreign countries and companies swipe our corporate secrets,” he said. “Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions, our air-traffic control systems. We cannot look back years from now and wonder why we did nothing.” From 2006 to 2014, the theft of intellectual property resulted in the loss of billions of dollars of revenue. But clearly the strategy and objectives have changed.

Controlling Cyberspace

Another thing that has changed is the belief in the ability to control cyberspace. , much like they do any other domain or territory or cyber-sovereignty, while for an “open, interoperable, secure, and reliable information and communications infrastructure.” Chinese leaders believe that cyberspace is largely controllable. Around the time of the Google pullout, China’s State Council Information Office delivered an exultant report on its work to regulate online traffic, according to a crucial Chinese contact cited by the State Department in a cable in early 2010 and later quoted in . The source claimed that “in the past, a lot of officials worried that the Web could not be controlled. But through the Google incident and other increased controls and surveillance, like real-name registration, they reached a conclusion: the Web is fundamentally controllable.”

In an attempt to control its own cyberspace, China adopted a cybersecurity law to address growing threats of cyberattacks in addition to the Golden Shield Project, a major part of which is the notorious Great Firewall of China. The new cyber legislation took effect in June 2017 and is labeled an “objective need” of , a parliament official said. The law might shut foreign technology companies out of various sectors deemed “critical” and include requirements for security reviews and for data to be stored on servers in China. In 2016, Beijing adopted a sweeping national security law that aimed to make all key network infrastructure and information systems secure and controllable. “China’s government has come to recognize that cyberspace immediately and profoundly impacts on many if not all aspects of national security,” said , a Sinologist at Leiden University. “It is a national space, it is a space for military action, for important economic action, for criminal action and for espionage.”

So is China a leader in cyberwarfare? China answers yes. Yang Heqing, an official on the National People’s Congress standing committee, said : “China is an internet power, and as one of the countries that faces the greatest internet security risks, urgently needs to establish and perfect network security legal systems.” The Chinese cyber approach has clearly shifted in the past three years with expanding goals and increased sophistication in strategy and targets. It has also shifted from predominantly economic cyber targets to predominantly governmental and infrastructure targets. China has taken a leadership role among the top five cyber powers, now openly declaring its place with the US, Russia, Israel and North Korea.

The views expressed in this article are the author’s own and do not necessarily reflect 51Թ’s editorial policy.

Photo Credit:/

The post China’s Cyberwarfare Finds New Targets appeared first on 51Թ.

]]>
Moderating Political Islam in Central Asia /region/central_south_asia/moderating-political-islam-central-asia/ /region/central_south_asia/moderating-political-islam-central-asia/#respond Sun, 22 Jul 2012 23:08:57 +0000 The failure of Central Asian states to engage political Islam within a religious and political framework perpetuates the threat of Islamic extremism. Religious pluralism may offer the antidote.

The post Moderating Political Islam in Central Asia appeared first on 51Թ.

]]>
The failure of Central Asian states to engage political Islam within a religious and political framework perpetuates the threat of Islamic extremism. Religious pluralism may offer the antidote.

Islamic society and the state have a long history of active engagement in Central Asia, but the 20th century introduced external agents that disrupted Islam’s place in the civic system. Two disruptive agents include state-imposed secularism, and the simultaneous shift towards pan-Islamic political activism within intra-Islamic dialogue. These phenomena coalesced into a mode of religious governance that disengaged Islam in the state sphere and silenced moderation within the religious sphere. And now, Central Asia collectively faces the challenge of maneuvering religious and political revival within the unholy triangle of governance, security and sustainable economic development.

Soviet Secularism

Central Asia underwent a significant shift in governance and religious activity throughout the 20th century. Soviet imposition of strict secularism created a vacuum of “truth” discussion that facilitated the rise of Islamic extremism, expressed through the medium of political Islam. Additionally, heightened international integration offered access to contemporary Islamic debate fueled by Sayyid Abul A’la Maududi and Sayyid Qutb, which altered the intra-religious dialogue about the purpose of Islam and government.

The breakup of the Soviet Union and the ensuing power stabilization efforts within the region temporarily enabled a revival of Islamic culture. However, the War on Terror created a cover of legitimacy for state crackdowns on Islamic organizations. As a consequence of crackdowns and unchecked intra-Islam developments, political Islam and Islamic extremism evolved into a largely homogenous agent. Current Islamic activism in Central Asia, with the notable exception of the Islamic Renaissance Party of Tajikistan (IRPT), is defined largely by radical organizations such as the Islamic Movement of Uzbekistan (IMU), the international Hizb ut-Tahrir Islamiyya (HT) and Salafi movements.

Recapturing the proactive state-religious dialogue of the 19th and early 20th centuries remains a challenge for governments and Islamic organizations alike. The lack of a religious pluralism framework widens the gap between state and religion, further complicating the state’s security and governance challenges.

Contemporary State-Islam Relations

The 21st century requires states to be flexible in order to develop while balancing increasingly informed and active populations. However, most Central Asian states continue to regulate the political and religious activism spaces without adapting to technological advances. Uzbekistan, Kazakhstan and Kyrgyzstan maintain strict policies concerning Islamic organizations and activism. The governments boast similar extremism laws that provide broad interpretive powers regarding the activities of religious organizations. While some organizations may legitimately warrant state intervention, regulating the religious sphere forces extremist views out of the public space where dialogue and public opinion can correct against, and minimize the effectiveness of such views.

Tajikistan once represented an exception to the state-religion status quo, but the country’s leadership now appears to be revising its strategy of engaging political Islam through the IRPT. President Emomali Rahmon’s administration recently supported the closing of the Muhammadiya Mosque, a popular mosque run by Haji Akbar Turajonzoda’s family (the former deputy prime minister, and an Islamic activist).

In addition to the mosque closing, the Tajikistani government has pursued a general policy of marginalizing the IRPT specifically, and political Islam in general. In June, the parliament passed a law that restricts domestic access to foreign faith groups in an attempt to reduce foreign influence, especially from the IMU. These developments in Tajikistan, a country once used by academics and policymakers as a model of state-religion engagement in Central Asia, signify a discouraging turn in favor of an outdated secularism that ignores the global wave of populism.

Among leading Islamic organizations in Central Asia, the response to increasing pressures against ‘Islamic extremism’ varies little from past operations. Hizb ut-Tahrir Islamiyya maintains its relatively passive support of violent jihad against Western powers and other non-Islamic governments, using propaganda and networking to influence Central Asian populations, while the IMU continues small-scale attacks throughout Central Asia.

However, as NATO prepares to leave the region, stability in Afghanistan and Pakistan may diminish further. The potential power vacuum offers an opportunity for Central Asian Islamic organizations to expand their radius of influence and operations. The IMU has already been active in Afghanistan, having semi-officially joined forces with al-Qaeda. Moreover, while HT is banned in Pakistan, an active underground network exists as allegations against British Conservative Party Chairwoman Baroness Warsi show. An investigation into Baroness Warsi’s ties to the HT in Pakistan reveals active networking between the underground British HT and Pakistani HT.

The Future of Political Islam in Central Asia

Central Asia’s maintenance of a pre-Cold War governance mentality has done it much harm. Until recently, Central Asian governments manipulated an already apathetic society into rejecting any political or religious activism that was not rooted in state authority. Recently, things have changed. Governance and security have globally become entangled with technology and social media. Furthermore, new political and religious movements are reshaping populations’ perceptions of authority and activism.

The governance hurdle of the 21st century is a state’s ability to balance authority and individual autonomy. This autonomy allows an individual to pursue a political or religious identity. The ability of the state to provide security is no longer defined by its skill in handling international relations alone. Today, states must also navigate populations awakening to new ideas about politics, economics and society. Some new ideas are propagated by radical religious forces and religious pluralism is the best way to counter them and prevent them from taking over the apparatus of the state or exploit its security vulnerabilities.

Religious pluralism is no cure for the disintegrating ties between Central Asian states and regional Islamic organizations. Nonetheless, it does create transparency and tolerance among religions through dialogue that reveals and corrects against extremist ideologies. Extremism thrives on ‘underground’ energy, and strict secularism provides a framework for this. State-sanctioned crackdowns in order to contain extremist ideologies are only catalysts, as increased activity in Pakistan and Afghanistan shows.

State-protected religious pluralism, alternatively, institutionalizes a self-correcting mechanism through freedom of speech and demonstration. It reveals the true faces of extremism and moderation. Should states choose to engage political Islam through religious pluralism, they would reduce the ability of Islamic extremism to manipulate governance, security, and development threats within the region.

The views expressed in this article are the author’s own and do not necessarily reflect 51Թ’s editorial policy.

The post Moderating Political Islam in Central Asia appeared first on 51Թ.

]]>
/region/central_south_asia/moderating-political-islam-central-asia/feed/ 0