Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One particular issue that makes this difficult to enforce is the nature of nation-state cyber weapons. Unlike physical weapons, which can be regulated by tracking their location or use, cyber weapons are undetectable by design. Less advanced cyber weapons from weaker programs like North Korea's or Iran's teams can be found but the capabilities of major players like the USA, China, or European countries likely extends far beyond what a company would be able to detect.

The technology that advanced nation-states are using to do attacks is highly classified and most likely farther reaching than most people realize. The documentary Zero Days gives a pretty good overview of how nation-state cyber attacks have transferred into physical attacks (e.g. taking large power grids offline, derailing trains, subverting anything that has a PLC, etc.). This technology has been around for almost a decade. Without knowledge of what kind of weapons they have, we won't be able to detect them. If these capabilities fell into the hands of non-nation state actors (terrorists) the damage they could do could be analogous to a nuclear weapon.

Even if we do discover an attack, it's even harder to attribute a piece of software to a country. Do you think an advanced nation would leave marks saying "foobar virus copyright X team 2017"? There's plausible deniability as well because one country could frame the other to make it look credible and we'd have no way to know what the truth was.

This program may work well for normal hacking attacks by people or lesser nation-states but it will not affect the missions for more advanced countries. Maybe it's worthwhile for stopping some attacks and setting a precedent but it won't be a silver bullet. I agree with the sentiment though, innocent civilians and companies should be left out of the crosshairs. It would be good if major software companies could work together to mitigate damage from attacks.



Nation states have gravitated to cyber because it carries less risk than espionage in the field, and because of the difficulty of attribution. Despite a mountain of evidence, Russia denies the DNC hack. The US pretends Stuxnet didn't happen. And N. Korea obviously is not owning up to Sony.

This puts tech companies in a bind. They want to innovate on society changing ideas like autonomous vehicles, but with nation to nation cyber attacks, they are potentially putting civilian lives at risk by doing so.

Will nation states play nice? No one expected direct attacks on private companies -- then Sony happened. No one expected attacks on a US election. And no one expected an attack on the grid without declaration of war -- but then Ukraine. Without defined international norms, anything is on the table -- even in peacetime.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: