{"id":1328,"date":"2014-06-08T04:20:07","date_gmt":"2014-06-08T04:20:07","guid":{"rendered":"http:\/\/www.chinesepen.org\/english\/?p=1328"},"modified":"2014-06-08T04:20:07","modified_gmt":"2014-06-08T04:20:07","slug":"the-online-threat-should-we-be-worried-about-a-cyber-war","status":"publish","type":"post","link":"https:\/\/www.chinesepen.org\/english\/the-online-threat-should-we-be-worried-about-a-cyber-war","title":{"rendered":"THE ONLINE THREAT Should we be worried about a cyber war?"},"content":{"rendered":"<p><span style=\"color: #444444;line-height: 1.7\">BY SEYMOUR M. HERSH<\/span><\/p>\n<p>NOVEMBER 1, 2010<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" alt=\"\" src=\"http:\/\/www.newyorker.com\/images\/2010\/11\/01\/p233\/101101_r20106_p233.jpg\" width=\"233\" height=\"316\" \/><br \/>\nSome experts say that the real danger lies in confusing cyber espionage with cyber war.Some experts say that the real danger lies in confusing cyber espionage with cyber war.<!--more--><\/p>\n<p>&nbsp;<\/p>\n<p>On April 1, 2001, an American EP-3E Aries II reconnaissance plane on an eavesdropping mission collided with a Chinese interceptor jet over the South China Sea, triggering the first international crisis of George W. Bush\u2019s Administration. The Chinese jet crashed, and its pilot was killed, but the pilot of the American aircraft, Navy Lieutenant Shane Osborn, managed to make an emergency landing at a Chinese F-8 fighter base on Hainan Island, fifteen miles from the mainland. Osborn later published a memoir, in which he described the \u201cincessant jackhammer vibration\u201d as the plane fell eight thousand feet in thirty seconds, before he regained control.<\/p>\n<p>The plane carried twenty-four officers and enlisted men and women attached to the Naval Security Group Command, a field component of the National Security Agency. They were repatriated after eleven days; the plane stayed behind. The Pentagon told the press that the crew had followed its protocol, which called for the use of a fire axe, and even hot coffee, to disable the plane\u2019s equipment and software. These included an operating system created and controlled by the N.S.A., and the drivers needed to monitor encrypted Chinese radar, voice, and electronic communications. It was more than two years before the Navy acknowledged that things had not gone so well. \u201cCompromise by the People\u2019s Republic of China of undestroyed classified material . . . is highly probable and cannot be ruled out,\u201d a Navy report issued in September, 2003, said.<\/p>\n<p>The loss was even more devastating than the 2003 report suggested, and its dimensions have still not been fully revealed. Retired Rear Admiral Eric McVadon, who flew patrols off the coast of Russia and served as a defense attach\u00e9 in Beijing, told me that the radio reports from the aircraft indicated that essential electronic gear had been dealt with. He said that the crew of the EP-3E managed to erase the hard drive\u2014\u201czeroed it out\u201d\u2014but did not destroy the hardware, which left data retrievable: \u201cNo one took a hammer.\u201d Worse, the electronics had recently been upgraded. \u201cSome might think it would not turn out as badly as it did, but I sat in some meetings about the intelligence cost,\u201d McVadon said. \u201cIt was grim.\u201d<\/p>\n<p>The Navy\u2019s experts didn\u2019t believe that China was capable of reverse-engineering the plane\u2019s N.S.A.-supplied operating system, estimated at between thirty and fifty million lines of computer code, according to a former senior intelligence official. Mastering it would give China a road map for decrypting the Navy\u2019s classified intelligence and operational data. \u201cIf the operating system was controlling what you\u2019d expect on an intelligence aircraft, it would have a bunch of drivers to capture radar and telemetry,\u201d Whitfield Diffie, a pioneer in the field of encryption, said. \u201cThe plane was configured for what it wants to snoop, and the Chinese would want to know what we wanted to know about them\u2014what we could intercept and they could not.\u201d And over the next few years the U.S. intelligence community began to \u201cread the tells\u201d that China had access to sensitive traffic.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" alt=\"\" src=\"http:\/\/randomcartoon.s3.amazonaws.com\/44495.JPG\" width=\"300\" height=\"254\" \/><br \/>\nFROM THE ISSUEBUY AS A PRINTE-MAIL THIS<\/p>\n<p>The U.S. realized the extent of its exposure only in late 2008. A few weeks after Barack Obama\u2019s election, the Chinese began flooding a group of communications links known to be monitored by the N.S.A. with a barrage of intercepts, two Bush Administration national-security officials and the former senior intelligence official told me. The intercepts included details of planned American naval movements. The Chinese were apparently showing the U.S. their hand. (\u201cThe N.S.A. would ask, \u2018Can the Chinese be that good?\u2019 \u201d the former official told me. \u201cMy response was that they only invented gunpowder in the tenth century and built the bomb in 1965. I\u2019d say, \u2018Can you read Chinese?\u2019 We don\u2019t even know the Chinese pictograph for \u2018Happy hour.\u2019 \u201d)<\/p>\n<p>Why would the Chinese reveal that they had access to American communications? One of the Bush national-security officials told me that some of the aides then working for Vice-President Dick Cheney believed\u2014or wanted to believe\u2014that the barrage was meant as a welcome to President Obama. It is also possible that the Chinese simply made a mistake, given the difficulty of operating surgically in the cyber world.<\/p>\n<p>Admiral Timothy J. Keating, who was then the head of the Pacific Command, convened a series of frantic meetings in Hawaii, according to a former C.I.A. official. In early 2009, Keating brought the issue to the new Obama Administration. If China had reverse-engineered the EP-3E\u2019s operating system, all such systems in the Navy would have to be replaced, at a cost of hundreds of millions of dollars. After much discussion, several current and former officials said, this was done. (The Navy did not respond to a request for comment on the incident.)<\/p>\n<p>Admiral McVadon said that the loss prompted some black humor, with one Navy program officer quoted as saying, \u201cThis is one hell of a way to go about getting a new operating system.\u201d<\/p>\n<p>The EP-3E debacle fuelled a longstanding debate within the military and in the Obama Administration. Many military leaders view the Chinese penetration as a warning about present and future vulnerabilities\u2014about the possibility that China, or some other nation, could use its expanding cyber skills to attack America\u2019s civilian infrastructure and military complex. On the other side are those who argue for a civilian response to the threat, focussed on a wider use of encryption. They fear that an overreliance on the military will have adverse consequences for privacy and civil liberties.<\/p>\n<p>In May, after years of planning, the U.S. Cyber Command was officially activated, and took operational control of disparate cyber-security and attack units that had been scattered among the four military services. Its commander, Army General Keith Alexander, a career intelligence officer, has made it clear that he wants more access to e-mail, social networks, and the Internet to protect America and fight in what he sees as a new warfare domain\u2014cyberspace. In the next few months, President Obama, who has publicly pledged that his Administration will protect openness and privacy on the Internet, will have to make choices that will have enormous consequences for the future of an ever-growing maze of new communication techniques: Will America\u2019s networks be entrusted to civilians or to the military? Will cyber security be treated as a kind of war?<\/p>\n<p>Even as the full story of China\u2019s EP-3E coup remained hidden, \u201ccyber war\u201d was emerging as one of the nation\u2019s most widely publicized national-security concerns. Early this year, Richard Clarke, a former White House national-security aide who warned about the threat from Al Qaeda before the September 11th attacks, published \u201cCyber War,\u201d an edgy account of America\u2019s vulnerability to hackers, both state-sponsored and individual, especially from China. \u201cSince the late 1990s, China has systematically done all the things a nation would do if it contemplated having an offensive cyber war capability,\u201d Clarke wrote. He forecast a world in which China might unleash havoc:<br \/>\nWithin a quarter of an hour, 157 major metropolitan areas have been thrown into knots by a nationwide power blackout hitting during rush hour. Poison gas clouds are wafting toward Wilmington and Houston. Refineries are burning up oil supplies in several cities. Subways have crashed in New York, Oakland, Washington, and Los Angeles. . . . Aircraft are literally falling out of the sky as a result of midair collisions across the country. . . . Several thousand Americans have already died.<br \/>\nRetired Vice-Admiral J. Michael McConnell, Bush\u2019s second director of National Intelligence, has issued similar warnings. \u201cThe United States is fighting a cyber war today, and we are losing,\u201d McConnell wrote earlier this year in the Washington Post. \u201cOur cyber-defenses are woefully lacking.\u201d In February, in testimony before the Senate Commerce, Science, and Transportation Committee, he said, \u201cAs a consequence of not mitigating the risk, we\u2019re going to have a catastrophic event.\u201d<\/p>\n<p>A great deal of money is at stake. Cyber security is a major growth industry, and warnings from Clarke, McConnell, and others have helped to create what has become a military-cyber complex. The federal government currently spends between six and seven billion dollars annually for unclassified cyber-security work, and, it is estimated, an equal amount on the classified portion. In July, the Washington Post published a critical assessment of the unchecked growth of government intelligence agencies and private contractors. Benjamin Powell, who served as general counsel for three directors of the Office of National Intelligence, was quoted as saying of the cyber-security sector, \u201cSometimes there was an unfortunate attitude of bring your knives, your guns, your fists, and be fully prepared to defend your turf. . . . Because it\u2019s funded, it\u2019s hot and it\u2019s sexy.\u201d<\/p>\n<p>Clarke is the chairman of Good Harbor Consulting, a strategic-planning firm that advises governments and companies on cyber security and other issues. (He says that more than ninety per cent of his company\u2019s revenue comes from non-cyber-related work.) McConnell is now an executive vice-president of Booz Allen Hamilton, a major defense contractor. Two months after McConnell testified before the Senate, Booz Allen Hamilton landed a thirty-four-million-dollar cyber contract. It included fourteen million dollars to build a bunker for the Pentagon\u2019s new Cyber Command.<\/p>\n<p>American intelligence and security officials for the most part agree that the Chinese military, or, for that matter, an independent hacker, is theoretically capable of creating a degree of chaos inside America. But I was told by military, technical, and intelligence experts that these fears have been exaggerated, and are based on a fundamental confusion between cyber espionage and cyber war. Cyber espionage is the science of covertly capturing e-mail traffic, text messages, other electronic communications, and corporate data for the purpose of gathering national-security or commercial intelligence. Cyber war involves the penetration of foreign networks for the purpose of disrupting or dismantling those networks, and making them inoperable. (Some of those I spoke to made the point that China had demonstrated its mastery of cyber espionage in the EP-3E incident, but it did not make overt use of it to wage cyber war.) Blurring the distinction between cyber war and cyber espionage has been profitable for defense contractors\u2014and dispiriting for privacy advocates.<\/p>\n<p>Clarke\u2019s book, with its alarming vignettes, was praised by many reviewers. But it received much harsher treatment from writers in the technical press, who pointed out factual errors and faulty assumptions. For example, Clarke attributed a severe power outage in Brazil to a hacker; the evidence pointed to sooty insulators.<\/p>\n<p>The most common cyber-war scare scenarios involve America\u2019s electrical grid. Even the most vigorous privacy advocate would not dispute the need to improve the safety of the power infrastructure, but there is no documented case of an electrical shutdown forced by a cyber attack. And the cartoonish view that a hacker pressing a button could cause the lights to go out across the country is simply wrong. There is no national power grid in the United States. There are more than a hundred publicly and privately owned power companies that operate their own lines, with separate computer systems and separate security arrangements. The companies have formed many regional grids, which means that an electrical supplier that found itself under cyber attack would be able to avail itself of power from nearby systems. Decentralization, which alarms security experts like Clarke and many in the military, can also protect networks.<\/p>\n<p>In July, there were reports that a computer worm, known as Stuxnet, had infected thousands of computers worldwide. Victims, most of whom were unharmed, were able to overcome the attacks, although it sometimes took hours or days to even notice them. Some of the computers were inside the Bushehr nuclear-energy plant, in Iran, and this led to speculation that Israel or the United States might have developed the virus. A Pentagon adviser on information warfare told me that it could have been an attempted \u201csemantic attack,\u201d in which the virus or worm is designed to fool its victim into thinking that its computer systems are functioning properly, when in fact they are not, and may not have been for some time. (This month, Microsoft, whose Windows operating systems were the main target of Stuxnet, completed a lengthy security fix, or patch.)<\/p>\n<p>If Stuxnet was aimed specifically at Bushehr, it exhibited one of the weaknesses of cyber attacks: they are difficult to target and also to contain. India and China were both hit harder than Iran, and the virus could easily have spread in a different direction, and hit Israel itself. Again, the very openness of the Internet serves as a deterrent against the use of cyber weapons.<\/p>\n<p>Bruce Schneier, a computer scientist who publishes a widely read blog on cyber security, told me that he didn\u2019t know whether Stuxnet posed a new threat. \u201cThere\u2019s certainly no actual evidence that the worm is targeted against Iran or anybody,\u201d he said in an e-mail. \u201cOn the other hand, it\u2019s very well designed and well written.\u201d The real hazard of Stuxnet, he added, might be that it was \u201cgreat for those who want to believe cyber war is here. It is going to be harder than ever to hold off the military.\u201d<\/p>\n<p>A defense contractor who is regarded as one of America\u2019s most knowledgeable experts on Chinese military and cyber capabilities took exception to the phrase \u201ccyber war.\u201d \u201cYes, the Chinese would love to stick it to us,\u201d the contractor told me. \u201cThey would love to transfer economic and business innovation from West to East. But cyber espionage is not cyber war.\u201d He added, \u201cPeople have been sloppy in their language. McConnell and Clarke have been pushing cyber war, but their evidentiary basis is weak.\u201d<\/p>\n<p>James Lewis, a senior fellow at the Center for Strategic and International Studies, who worked for the Departments of State and Commerce in the Clinton Administration, has written extensively on the huge economic costs due to cyber espionage from China and other countries, like Russia, whose hackers are closely linked to organized crime. Lewis, too, made a distinction between this and cyber war: \u201cCurrent Chinese officials have told me that we\u2019re not going to attack Wall Street, because we basically own it\u201d\u2014a reference to China\u2019s holdings of nearly a trillion dollars in American securities\u2014\u201cand a cyber-war attack would do as much economic harm to us as to you.\u201d<\/p>\n<p>Nonetheless, China \u201cis in full economic attack\u201d inside the United States, Lewis says. \u201cSome of it is economic espionage that we know and understand. Some of it is like the Wild West. Everybody is pirating from everybody else. The U.S.\u2019s problem is what to do about it. I believe we have to begin by thinking about it\u201d\u2014the Chinese cyber threat\u2014\u201cas a trade issue that we have not dealt with.\u201d<\/p>\n<p>The bureaucratic battle between the military and civilian agencies over cyber security\u2014and the budget that comes with it\u2014has made threat assessments more problematic. General Alexander, the head of Cyber Command, is also the director of the N.S.A., a double role that has caused some apprehension, particularly on the part of privacy advocates and civil libertarians. (The N.S.A. is formally part of the Department of Defense.) One of Alexander\u2019s first goals was to make sure that the military would take the lead role in cyber security and in determining the future shape of computer networks. (A Department of Defense spokesman, in response to a request to comment on this story, said that the department \u201ccontinues to adhere to all laws, policies, directives, or regulations regarding cyberspace. The Department of Defense maintains strong commitments to protecting civil liberties and privacy.\u201d)<\/p>\n<p>The Department of Homeland Security has nominal responsibility for the safety of America\u2019s civilian and private infrastructure, but the military leadership believes that the D.H.S. does not have the resources to protect the electrical grids and other networks. (The department intends to hire a thousand more cyber-security staff members over the next three years.) This dispute became public when, in March, 2009, Rodney Beckstrom, the director of the D.H.S.\u2019s National Cybersecurity Center, abruptly resigned. In a letter to Secretary Janet Napolitano, Beckstrom warned that the N.S.A. was effectively controlling her department\u2019s cyber operations: \u201cWhile acknowledging the critical importance of N.S.A. to our intelligence efforts . . . the threats to our democratic processes are significant if all top level government network security and monitoring are handled by any one organization.\u201d Beckstrom added that he had argued for civilian control of cyber security, \u201cwhich interfaces with, but is not controlled by, the N.S.A.\u201d<\/p>\n<p>General Alexander has done little to reassure critics about the N.S.A.\u2019s growing role. In the public portion of his confirmation hearing, in April, before the Senate Armed Services Committee, he complained of a \u201cmismatch between our technical capabilities to conduct operations and the governing laws and policies.\u201d<\/p>\n<p>Alexander later addressed a controversial area: when to use conventional armed forces to respond to, or even pre\u00ebmpt, a network attack. He told the senators that one problem for Cyber Command would be to formulate a response based on nothing more than a rough judgment about a hacker\u2019s intent. \u201cWhat\u2019s his game plan? Does he have one?\u201d he said. \u201cThese are tough issues, especially when attribution and neutrality are brought in, and when trying to figure out what\u2019s come in.\u201d At this point, he said, he did not have \u201cthe authority . . . to reach out into a neutral country and do an attack. And therein lies the complication. . . . What do you do to take that second step?\u201d<\/p>\n<p>Making the same argument, William J. Lynn III, the Deputy Secretary of Defense, published an essay this fall in Foreign Affairs in which he wrote of applying the N.S.A.\u2019s \u201cdefense capabilities beyond the \u2018.gov\u2019 domain,\u201d and asserted, \u201cAs a doctrinal matter, the Pentagon has formally recognized cyberspace as a new domain of warfare.\u201d This definition raises questions about where the battlefield begins and where it ends. If the military is operating in \u201ccyberspace,\u201d does that include civilian computers in American homes?<\/p>\n<p>Lynn also alluded to a previously classified incident, in 2008, in which some N.S.A. unit commanders, facing penetration of their bases\u2019 secure networks, concluded that the break-in was caused by a disabling thumb drive; Lynn said that it had been corrupted by \u201ca foreign intelligence agency.\u201d (According to press reports, the program was just as likely to be the product of hackers as that of a government.) Lynn termed it a \u201cwakeup call\u201d and a \u201cturning point in U.S. cyber defense strategy.\u201d He compared the present moment to the day in 1939 when President Franklin D. Roosevelt got a letter from Albert Einstein about the possibility of atomic warfare.<\/p>\n<p>But Lynn didn\u2019t mention one key element in the commanders\u2019 response: they ordered all ports on the computers on their bases to be sealed with liquid cement. Such a demand would be a tough sell in the civilian realm. (And a Pentagon adviser suggested that many military computer operators had simply ignored the order.)<\/p>\n<p>A senior official in the Department of Homeland Security told me, \u201cEvery time the N.S.A. gets involved in domestic security, there\u2019s a hue and cry from people in the privacy world.\u201d He said, though, that co\u00f6peration between the military and civilians had increased. (The Department of Homeland Security recently signed a memorandum with the Pentagon that gives the military authority to operate inside the United States in case of cyber attack.) \u201cWe need the N.S.A., but the question we have is how to work with them and still say and demonstrate that we are in charge in the areas for which we are responsible.\u201d<\/p>\n<p>This official, like many I spoke to, portrayed the talk about cyber war as a bureaucratic effort \u201cto raise the alarm\u201d and garner support for an increased Defense Department role in the protection of private infrastructure. He said, \u201cYou hear about cyber war all over town. This\u201d\u2014he mentioned statements by Clarke and others\u2014\u201cis being done to mobilize a political effort. We always turn to war analogies to mobilize the people.\u201d<\/p>\n<p>In theory, the fight over whether the Pentagon or civilian agencies should be in charge of cyber security should be mediated by President Obama\u2019s co\u00f6rdinator for cyber security, Howard Schmidt\u2014the cyber czar. But Schmidt has done little to assert his authority. He has no independent budget control and in a crisis would be at the mercy of those with more assets, such as General Alexander. He was not the Administration\u2019s first choice for the cyber-czar job\u2014reportedly, several people turned it down. The Pentagon adviser on information warfare, in an e-mail that described the lack of an over-all policy and the \u201ccyber-pillage\u201d of intellectual property, added the sort of dismissive comment that I heard from others: \u201cIt\u2019s ironic that all this goes on under the nose of our first cyber President. . . . Maybe he should have picked a cyber czar with more than a mail-order degree.\u201d (Schmidt\u2019s bachelor\u2019s and master\u2019s degrees are from the University of Phoenix, though from one of their \u201cground\u201d campuses.)<\/p>\n<p>Howard Schmidt doesn\u2019t like the term \u201ccyber war.\u201d \u201cThe key point is that cyber war benefits no one,\u201d Schmidt told me in an interview at the Old Executive Office Building. \u201cWe need to focus on that fact. When people tell me that these guys or this government is going to take down the U.S. military with information warfare I say that, if you look at the history of conflicts, there\u2019s always been the goal of intercepting the communications of combatants\u2014whether it\u2019s cutting down telephone poles or intercepting Morse-code signalling. We have people now who have found that warning about \u2018cyber war\u2019 has become an unlikely career path\u201d\u2014an obvious reference to McConnell and Clarke. \u201cAll of a sudden, they have become experts, and they get a lot of attention. \u2018War\u2019 is a big word, and the media is responsible for pushing this, too. Economic espionage on the Internet has been mischaracterized by people as cyber war.\u201d<\/p>\n<p>Schmidt served in Vietnam, worked as a police officer for several years on a swat team in Arizona, and then specialized in computer-related crimes at the F.B.I. and in the Air Force\u2019s investigative division. In 1997, he joined Microsoft, where he became chief of security, leaving after the 9\/11 attacks to serve in the Bush Administration as a special adviser for cyber security. When Obama hired him, he was working as the head of security for eBay. When I asked him about the ongoing military-civilian dispute, Schmidt said, \u201cThe middle way is not to give too much authority to one group or another and to make sure that we share information with each other.\u201d<\/p>\n<p>Schmidt continued, \u201cWe have to protect our infrastructure and our way of life, for sure. We do have vulnerabilities, and we do talk about worst-case scenarios\u201d with the Pentagon and the Department of Homeland Security. \u201cYou don\u2019t see a looming war and just wait for it to come.\u201d But, at the same time, \u201cwe have to keep our shipping lanes open, to continue to do commerce, and to freely use the Internet.\u201d<\/p>\n<p>How should the power grid be protected? It does remain far too easy for a sophisticated hacker to break into American networks. In 2008, the computers of both the Obama and the McCain campaigns were hacked. Suspicion fell on Chinese hackers. People routinely open e-mails with infected attachments, allowing hackers to \u201censlave\u201d their computers. Such machines, known as zombies, can be linked to create a \u201cbotnet,\u201d which can flood and effectively shut down a major system. Hackers are also capable of penetrating a major server, like Gmail. Guesses about the cost of cyber crime vary widely, but one survey, cited by President Obama in a speech in May, 2009, put the price at more than eight billion dollars in 2007 and 2008 combined. Obama added, referring to corporate cyber espionage, \u201cIt\u2019s been estimated that last year alone cyber criminals stole intellectual property from businesses worldwide worth up to one trillion dollars.\u201d<\/p>\n<p>One solution is mandated encryption: the government would compel both corporations and individuals to install the most up-to-date protection tools. This option, in some form, has broad support in the technology community and among privacy advocates. In contrast, military and intelligence eavesdroppers have resisted nationwide encryption since 1976, when the Diffie-Hellman key exchange (an encryption tool co-developed by Whitfield Diffie) was invented, for the most obvious of reasons: it would hinder their ability to intercept signals. In this sense, the N.S.A.\u2019s interests align with those of the hackers.<\/p>\n<p>John Arquilla, who has taught since 1993 at the U.S. Naval Postgraduate School in Monterey, California, writes in his book \u201cWorst Enemies,\u201d \u201cWe would all be far better off if virtually all civil, commercial, governmental, and military internet and web traffic were strongly encrypted.\u201d Instead, many of those charged with security have adopted the view that \u201ccyberspace can be defended with virtual fortifications\u2014basically the \u2018firewalls\u2019 that everyone knows about. . . . A kind of Maginot Line mentality prevails.\u201d<\/p>\n<p>Arquilla added that America\u2019s intelligence agencies and law-enforcement officials have consistently resisted encryption because of fears that a serious, widespread effort to secure data would interfere with their ability to electronically monitor and track would-be criminals or international terrorists. This hasn\u2019t stopped sophisticated wrongdoers from, say, hiring hackers or encrypting files; it just leaves the public exposed, Arquilla writes. \u201cToday drug lords still enjoy secure internet and web communications, as do many in terror networks, while most Americans don\u2019t.\u201d<\/p>\n<p>Schmidt told me that he supports mandated encryption for the nation\u2019s power and electrical infrastructure, though not beyond that. But, early last year, President Obama declined to support such a mandate, in part, Schmidt said, because of the costs it would entail for corporations. In addition to the setup expenses, sophisticated encryption systems involve a reliance on security cards and on constantly changing passwords, along with increased demands on employees and a ceding of control by executives to their security teams.<\/p>\n<p>General Alexander, meanwhile, has continued to press for more authority, and even for a separate Internet domain\u2014another Maginot Line, perhaps. One morning in September, he told a group of journalists that the Cyber Command needed what he called \u201ca secure zone,\u201d a separate space within the Internet to shelter the military and essential industries from cyber attacks. The secure zone would be kept under tight government control. He also assured the journalists, according to the Times, that \u201cwe can protect civil liberties, privacy, and still do our mission.\u201d The General was more skeptical about his ability to please privacy advocates when he testified, a few hours later, before the House Armed Services Committee: \u201cA lot of people bring up privacy and civil liberties. And then you say, \u2018Well, what specifically are you concerned about?\u2019 And they say, \u2018Well, privacy and civil liberties.\u2019 . . . Are you concerned that the anti-virus program that McAfee runs invades your privacy or civil liberties?\u2019 And the answer is \u2018No, no, no\u2014but I\u2019m worried that you would.\u2019 \u201d<\/p>\n<p>This summer, the Wall Street Journal reported that the N.S.A. had begun financing a secret surveillance program called Perfect Citizen to monitor attempted intrusions into the computer networks of private power companies. The program calls for the installation of government sensors in those networks to watch for unusual activity. The Journal noted that some companies expressed concerns about privacy, and said that what they needed instead was better guidance on what to do in case of a major cyber attack. The N.S.A. issued a rare public response, insisting that there was no \u201cmonitoring activity\u201d involved: \u201cWe strictly adhere to both the spirit and the letter of U.S. laws and regulations.\u201d<\/p>\n<p>A former N.S.A. operative I spoke to said, of Perfect Citizen, \u201cThis would put the N.S.A. into the job of being able to watch over our national communications grid. If it was all dot-gov, I would have no problem with the sensors, but what if the private companies rely on Gmail or att.net to communicate? This could put the N.S.A. into every service provider in the country.\u201d<\/p>\n<p>The N.S.A. has its own hackers. Many of them are based at a secret annex near Thurgood Marshall International Airport, outside Baltimore. (The airport used to be called Friendship Airport, and the annex is known to insiders as the fanx, for \u201cFriendship annex.\u201d) There teams of attackers seek to penetrate the communications of both friendly and unfriendly governments, and teams of defenders monitor penetrations and attempted penetrations of U.S. systems. The former N.S.A. operative, who served as a senior watch officer at a major covert installation, told me that the N.S.A. obtained invaluable on-the-job training in cyber espionage during the attack on Iraq in 1991. Its techniques were perfected during the struggle in Kosovo in 1999 and, later, against Al Qaeda in Iraq. \u201cWhatever the Chinese can do to us, we can do better,\u201d the technician said. \u201cOur offensive cyber capabilities are far more advanced.\u201d<\/p>\n<p>Nonetheless, Marc Rotenberg, the president of the Electronic Privacy Information Center and a leading privacy advocate, argues that the N.S.A. is simply not competent enough to take a leadership role in cyber security. \u201cLet\u2019s put the issue of privacy of communications aside,\u201d Rotenberg, a former Senate aide who has testified often before Congress on encryption policy and consumer protection, said. \u201cThe question is: Do you want an agency that spies with mixed success to be responsible for securing the nation\u2019s security? If you do, that\u2019s crazy.\u201d<\/p>\n<p>Nearly two decades ago, the Clinton Administration, under pressure from the N.S.A., said that it would permit encryption-equipped computers to be exported only if their American manufacturers agreed to install a government-approved chip, known as the Clipper Chip, in each one. It was subsequently revealed that the Clipper Chip would enable law-enforcement officials to have access to data in the computers. The ensuing privacy row embarrassed Clinton, and the encryption-equipped computers were permitted to be exported without the chip, in what amounted to a rebuke to the N.S.A.<\/p>\n<p>That history may be repeating itself. The Obama Administration is now planning to seek broad new legislation that would enable national-security and law-enforcement officials to police online communications. The legislation, similar to that sought two decades ago in the Clipper Chip debate, would require manufacturers of equipment such as the BlackBerry, and all domestic and foreign purveyors of communications, such as Skype, to develop technology that would allow the federal government to intercept and decode traffic.<\/p>\n<p>\u201cThe lesson of Clipper is that the N.S.A. is really not good at what it does, and its desire to eavesdrop overwhelms its ability to protect, and puts at risk U.S. security,\u201d Rotenberg said. \u201cThe N.S.A. wants security, sure, but it also wants to get to capture as much as it can. Its view is you can get great security as long as you listen in.\u201d Rotenberg added, \u201cGeneral Alexander is not interested in communication privacy. He\u2019s not pushing for encryption. He wants to learn more about people who are on the Internet\u201d\u2014to get access to the original internal protocol, or I.P., addresses identifying the computers sending e-mail messages. \u201cAlexander wants user I.D. He wants to know who you are talking to.\u201d<\/p>\n<p>Rotenberg concedes that the government has a role to play in the cyber world. \u201cWe privacy guys want strong encryption for the security of America\u2019s infrastructure,\u201d he said. He also supports Howard Schmidt in his willingness to mandate encryption for the few industries whose disruption could lead to chaos. \u201cHoward is trying to provide a reasoned debate on an important issue.\u201d<\/p>\n<p>Whitfield Diffie, the encryption pioneer, offered a different note of skepticism in an e-mail to me: \u201cIt would be easy to write a rule mandating encryption but hard to do it in such a way as to get good results. To make encryption effective, someone has to manage and maintain the systems (the way N.S.A. does for D.O.D. and, to a lesser extent, other parts of government). I think that what is needed is more by way of standards, guidance, etc., that would make it easier for industry to implement encryption without making more trouble for itself than it saves.\u201d<\/p>\n<p>More broadly, Diffie wrote, \u201cI am not convinced that lack of encryption is the primary problem. The problem with the Internet is that it is meant for communications among non-friends.\u201d<\/p>\n<p>What about China? Does it pose such a threat that, on its own, it justifies putting cyber security on a war footing? The U.S. has long viewed China as a strategic military threat, and as a potential adversary in the sixty-year dispute over Taiwan. Contingency plans dating back to the Cold War include calls for an American military response, led by a Navy carrier group, if a Chinese fleet sails into the Taiwan Strait. \u201cThey\u2019ll want to stop our carriers from coming, and they will throw whatever they have in cyber war\u2014everything but the kitchen sink\u2014to blind us, or slow our fleet down,\u201d Admiral McVadon, the retired defense attach\u00e9, said. \u201cOur fear is that the Chinese may think that cyber war will work, but it may not. And that\u2019s a danger because it\u201d\u2014a test of cyber warfare\u2014\u201ccould lead to a bigger war.\u201d<\/p>\n<p>However, the prospect of a naval battle for Taiwan and its escalation into a cyber attack on America\u2019s domestic infrastructure is remote. Jonathan Pollack, an expert on the Chinese military who teaches at the Naval War College in Newport, Rhode Island, said, \u201cThe fact is that the Chinese are remarkably risk-averse.\u201d He went on, \u201cYes, there have been dustups, and the United States collects intelligence around China\u2019s border, but there is an accommodation process under way today between China and Taiwan.\u201d In June, Taiwan approved a trade agreement with China that had, as its ultimate goal, a political rapprochement. \u201cThe movement there is palpable, and, given that, somebody\u2019s got to tell me how we are going to find ourselves in a war with China,\u201d Pollack said.<\/p>\n<p>Many long-standing allies of the United States have been deeply engaged in cyber espionage for decades. A retired four-star Navy admiral, who spent much of his career in signals intelligence, said that Russia, France, Israel, and Taiwan conduct the most cyber espionage against the U.S. \u201cI\u2019ve looked at the extraordinary amount of Russian and Chinese cyber activity,\u201d he told me, \u201cand I am hard put to it to sort out how much is planning for warfare and how much is for economic purposes.\u201d<\/p>\n<p>The admiral said that the U.S. Navy, worried about budget cuts, \u201cneeds an enemy, and it\u2019s settled on China,\u201d and that \u201cusing what your enemy is building to justify your budget is not a new game.\u201d<\/p>\n<p>There is surprising unanimity among cyber-security experts on one issue: that the immediate cyber threat does not come from traditional terrorist groups like Al Qaeda, at least, not for the moment. \u201cTerrorist groups are not particularly good now in attacking our computer system,\u201d John Arquilla told me. \u201cThey\u2019re not that interested in it\u2014yet. The question is: Do vulnerabilities exist inside America? And, if they do, the terrorists eventually will exploit them.\u201d Arquilla added a disturbing thought: \u201cThe terrorists of today rely on cyberspace, and they have to be good at cyber security to protect their operations.\u201d As terrorist groups get better at defense, they may eventually turn to offense.<\/p>\n<p>Jeffrey Carr, a Seattle-based consultant on cyber issues, looked into state and non-state cyber espionage throughout the recent conflicts in Estonia and Georgia. Carr, too, said he was skeptical that China or Russia would mount a cyber-war attack against the United States. \u201cIt\u2019s not in their interest to hurt the country that is feeding them money,\u201d he said. \u201cOn the other hand, it does make sense for lawless groups.\u201d He envisaged \u201cfive- or six-year-old kids in the Middle East who are working on the Internet,\u201d and who would \u201cbecome radicalized fifteen- or sixteen-year-old hackers.\u201d Carr is an advocate of making all Internet service providers require their customers to use verifiable registration information, as a means of helping authorities reduce cyber espionage.<\/p>\n<p>Earlier this year, Carr published \u201cInside Cyber Warfare,\u201d an account, in part, of his research into cyber activity around the world. But he added, \u201cI hate the term \u2018cyber war.\u2019 \u201d Asked why he used \u201ccyber warfare\u201d in the title of his book, he responded, \u201cI don\u2019t like hype, but hype sells.\u201d<\/p>\n<p>Why not ignore the privacy community and put cyber security on a war footing? Granting the military more access to private Internet communications, and to the Internet itself, may seem prudent to many in these days of international terrorism and growing American tensions with the Muslim world. But there are always unintended consequences of military activity\u2014some that may take years to unravel. Ironically, the story of the EP-3E aircraft that was downed off the coast of China provides an example. The account, as relayed to me by a fully informed retired American diplomat, begins with the contested Presidential election between Vice-President Al Gore and George W. Bush the previous November. That fall, a routine military review concluded that certain reconnaissance flights off the eastern coast of the former Soviet Union\u2014daily Air Force and Navy sorties flying out of bases in the Aleutian Islands\u2014were redundant, and recommended that they be cut back.<\/p>\n<p>\u201cFinally, on the eve of the 2000 election, the flights were released,\u201d the former diplomat related. \u201cBut there was nobody around with any authority to make changes, and everyone was looking for a job.\u201d The reality is that no military commander would unilaterally give up any mission. \u201cSo the system defaulted to the next target, which was China, and the surveillance flights there went from one every two weeks or so to something like one a day,\u201d the former diplomat continued. By early December, \u201cthe Chinese were acting aggressively toward our now increased reconnaissance flights, and we complained to our military about their complaints. But there was no one with political authority in Washington to respond, or explain.\u201d The Chinese would not have been told that the increase in American reconnaissance had little to do with anything other than the fact that inertia was driving day-to-day policy. There was no leadership in the Defense Department, as both Democrats and Republicans waited for the Supreme Court to decide the fate of the Presidency.<\/p>\n<p>The predictable result was an increase in provocative behavior by Chinese fighter pilots who were assigned to monitor and shadow the reconnaissance flights. This evolved into a pattern of harassment in which a Chinese jet would maneuver a few dozen yards in front of the slow, plodding EP-3E, and suddenly blast on its afterburners, soaring away and leaving behind a shock wave that severely rocked the American aircraft. On April 1, 2001, the Chinese pilot miscalculated the distance between his plane and the American aircraft. It was a mistake with consequences for the American debate on cyber security that have yet to be fully reckoned. \u2666<\/p>\n<p>From:http:\/\/www.newyorker.com\/reporting\/2010\/11\/01\/101101fa_fact_hersh?currentPage=all&amp;mobify=0?mbid=social_retweet<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BY SEYMOUR M. HERSH NOVEMBER 1, 2010 Som &hellip; <a href=\"https:\/\/www.chinesepen.org\/english\/the-online-threat-should-we-be-worried-about-a-cyber-war\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[232],"tags":[329,328],"views":1495,"_links":{"self":[{"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/posts\/1328"}],"collection":[{"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/comments?post=1328"}],"version-history":[{"count":1,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/posts\/1328\/revisions"}],"predecessor-version":[{"id":1329,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/posts\/1328\/revisions\/1329"}],"wp:attachment":[{"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/media?parent=1328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/categories?post=1328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.chinesepen.org\/english\/wp-json\/wp\/v2\/tags?post=1328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}