>One of the most vocal of those critics is Chris Soghoian, a privacy activist with the Open Society Foundations, who has described the firms and individuals who sell software exploits as “the modern-day merchants of death” selling “the bullets of cyberwar.”
Are there any documented cases of malware killing someone? All this cyberwarfare stuff seems a little overblown.
Another virus, sent to the Dalai Lama's office, was used to track Tibetan sympathizers, probably by the Chinese government.
There are REAL cases where REAL people's life is put in danger. Everyone uses email know and usually do that on insecure platforms.
I almost support the person in this article, but I wished he would sell only to Europe and USA out of ethical concerns instead of simple profit optimization, because otherwise, he would have the same responsibility as an arms dealer selling weapons to Syria.
It may make you laugh and there are serious offenses (cough wikileaks cough) but freedom of speech and of political opinion IS taken seriously, opponents are not "disappeared" on a regular basis in EU and US and they do not outlaw means to circumvent surveillance.
With flame and stuxnet in picture, cyber warfare looks a lot more real and physical. From disabling production of nuclear weapons to extremes of (highly unlikely) blowing up of reactors. That's a little more than a bullet.
I'd still call it less than a bullet. You can also potentially use a wrench to blow up a reactor, but ultimately I wouldn't call a wrench a powerful weapon. (That distinction goes to the reactor.)
I would say the "blame" is transferable indefinitely. The reactor is not responsible either, the enriched uranium is responsible instead, for the damage. But then uranium is not responsible either, the atoms are, that fuse (or fission), or the momentum (of atoms) can also be at blame. There has to be a line that needs to be drawn here.
Wrench can explode a reactor, but it is not made specifically to blow up a reactor. Stuxnet, on the other hand was specifically made to do the damage to fuel cells. Hence it's a weapon and wrench is not.
A wrench is a weapon in the war against loose bolts. However, most people would probably call it a weapon only when wielded with the intention of hitting another person.
I don't think it's fair to characterize the intention of stuxnet as blowing up reactors. From what I've read, the purposeful damage it was designed to inflict was to disable uranium-enriching equipment. I don't recall reading anything about purposeful attempts to use the software to kill or wound.
That's where I'd draw the line: purposeful killing. So I'd describe this as a case of cyber-sabatoge -- not a case of cyber-war.
Depending on your view, Chris Soghoian is a transparency activist fighting for the rights of others, or a bit of a troll who doesn't know what he's talking about. I err towards the latter rather than the former, but YMMV.
the fact that is hasn't killed anyone is what makes it so effective. if US or Isreal had bombed iranian nuclear facilities it would have likely resulted in many deaths, but stuxnet was effective in setting back the iranian nuclear program without any deaths, and less threat of war.
While I think there are clearly cases to be made linking cyber attacks to physical violence and harm, I'm not sure this is one of them. This was a chemist, not a computer scientist, and it's plausible that Stuxnet slowed more violent/coercive efforts against Iranian scientists.
Nation States that employ offensive cyber operations will NOT stop at only targeting computer infrastructure. Many technologists/hackers naturaly like to separate the world into two spheres (the so called "real world" and the "online" world), somehow thinking that they are above the physical fray. The truth is that hackers and security professionals on all sides will increasingly expose themselves to physical attacks like this. Any militarily sound employment of cyber warfare will include a physical attack component, whether covert or overt, depending on the current stage of the conflict.
Well, I have no problem with calling it cyberintelligence, or even cyberespionage, but just because espionage is part of warfare doesn't make it warfare.
Are there any documented cases of malware killing someone? All this cyberwarfare stuff seems a little overblown.