Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>One of the most vocal of those critics is Chris Soghoian, a privacy activist with the Open Society Foundations, who has described the firms and individuals who sell software exploits as “the modern-day merchants of death” selling “the bullets of cyberwar.”

Are there any documented cases of malware killing someone? All this cyberwarfare stuff seems a little overblown.



Syrian activists are being killed right now and identified, amongst other means, through smartphone spywares.

In Myanmar, this kind of thing has circulated : http://www.crime-research.org/news/05.10.2007/2928/

Another virus, sent to the Dalai Lama's office, was used to track Tibetan sympathizers, probably by the Chinese government.

There are REAL cases where REAL people's life is put in danger. Everyone uses email know and usually do that on insecure platforms.

I almost support the person in this article, but I wished he would sell only to Europe and USA out of ethical concerns instead of simple profit optimization, because otherwise, he would have the same responsibility as an arms dealer selling weapons to Syria.


How much more ethical are Europe and the US?


It may make you laugh and there are serious offenses (cough wikileaks cough) but freedom of speech and of political opinion IS taken seriously, opponents are not "disappeared" on a regular basis in EU and US and they do not outlaw means to circumvent surveillance.


We tend not to bomb our own cities.


I dont think that by itself is enough to claim that one state is more or less ethical than another.

Another metic you could use is who causes the most deaths, in which case the US is pretty high up on the unethical list.


With flame and stuxnet in picture, cyber warfare looks a lot more real and physical. From disabling production of nuclear weapons to extremes of (highly unlikely) blowing up of reactors. That's a little more than a bullet.


I'd still call it less than a bullet. You can also potentially use a wrench to blow up a reactor, but ultimately I wouldn't call a wrench a powerful weapon. (That distinction goes to the reactor.)


I would say the "blame" is transferable indefinitely. The reactor is not responsible either, the enriched uranium is responsible instead, for the damage. But then uranium is not responsible either, the atoms are, that fuse (or fission), or the momentum (of atoms) can also be at blame. There has to be a line that needs to be drawn here.

Wrench can explode a reactor, but it is not made specifically to blow up a reactor. Stuxnet, on the other hand was specifically made to do the damage to fuel cells. Hence it's a weapon and wrench is not.


A wrench is a weapon in the war against loose bolts. However, most people would probably call it a weapon only when wielded with the intention of hitting another person.

I don't think it's fair to characterize the intention of stuxnet as blowing up reactors. From what I've read, the purposeful damage it was designed to inflict was to disable uranium-enriching equipment. I don't recall reading anything about purposeful attempts to use the software to kill or wound.

That's where I'd draw the line: purposeful killing. So I'd describe this as a case of cyber-sabatoge -- not a case of cyber-war.


Here's an attempt at an outline of an argument that Stuxnet was used to kill or wound. Note that I don't necessarily hold this as my belief.

1. Stuxnet was designed to slow Iran's progress toward developing their own nuclear power (and weapons).

2. Nuclear power is a cleaner alternative to burning fossil fuels.

3. Fossil fuels are the cause of many deaths through pollution, mining accidents, and wars over oilfields.

4. Therefore, by delaying Iran's use of nuclear power, Stuxnet resulted in an increase in killing or wounding, via wars over oil and pollution.

That's where I'd draw the line: purposeful killing. So I'd describe this as a case of cyber-sabatoge -- not a case of cyber-war.

Sabotage can be a tactic used in an ongoing war.


Read Richard Clarke's _Cyberwarfare_. There are some tech errata, but it's still a good introduction to the subject.


Depending on your view, Chris Soghoian is a transparency activist fighting for the rights of others, or a bit of a troll who doesn't know what he's talking about. I err towards the latter rather than the former, but YMMV.


Yea, there's far more people working on software actually meant to kill people, like weapon systems.

I think the exploits are probably most useful for spying.


the fact that is hasn't killed anyone is what makes it so effective. if US or Isreal had bombed iranian nuclear facilities it would have likely resulted in many deaths, but stuxnet was effective in setting back the iranian nuclear program without any deaths, and less threat of war.


A good point. If the nytimes article is to be believed, stuxnet was actually used to talk Israel out of performing more physical attacks.

I don't know about anyone else, but I'll take an infected computer over gunfire any day.


The chief Iranian computer scientist in charge of managing Stuxnet was killed by a magnet car bomb attached by a motorcyclist.

http://www.usatoday.com/news/world/story/2012-01-11/iran-nuc...

No exploit > No Stuxnet > No Death


While I think there are clearly cases to be made linking cyber attacks to physical violence and harm, I'm not sure this is one of them. This was a chemist, not a computer scientist, and it's plausible that Stuxnet slowed more violent/coercive efforts against Iranian scientists.


That article mentions Stuxnet once and draws no relationship between the killing and the virus.


Nation States that employ offensive cyber operations will NOT stop at only targeting computer infrastructure. Many technologists/hackers naturaly like to separate the world into two spheres (the so called "real world" and the "online" world), somehow thinking that they are above the physical fray. The truth is that hackers and security professionals on all sides will increasingly expose themselves to physical attacks like this. Any militarily sound employment of cyber warfare will include a physical attack component, whether covert or overt, depending on the current stage of the conflict.


That still sounds like someone using a conventional weapon to kill someone, it's a pretty big stretch to compare malware to a bullet.


Intelligence is a major part of warfare. It's a lot easier to assassinate people if you have good means of finding the people you want dead.


Well, I have no problem with calling it cyberintelligence, or even cyberespionage, but just because espionage is part of warfare doesn't make it warfare.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: