The Pegasus case shows that government-linked hacking has become a general, and perhaps permanent, a feature of the global order.
On Monday, the world woke up to a kind of revelation that has become a baffling routine.
El Times A weekly selection of stories in Spanish that you won’t find anywhere else, with eñes and accents. Get it sent to your inbox.
For years, Chinese hackers mounted a campaign to steal scientific research from governments and universities, according to a complaint by the US Department of Justice.
On the other hand, several governments, including the government of Joe Biden, accused Beijing of hiring groups of cyber attackers to infiltrate the world’s largest companies and governments in exchange for economic benefits.
Just hours earlier, a consortium of news agencies reported that governments around the world had used spyware sold to them by an Israeli company to monitor foreign journalists, human rights defenders, opposition politicians and heads of state.
The spate of accusations represents the new normal of ongoing government-linked hacks that could now be a permanent feature of the world order, according to cybersecurity and foreign policy experts.
Governments have become more cunning in exploiting the connectivity of the digital age to further their interests and weaken their enemies, as are independent hackers who often sell their services to states, blurring the line between an international cyber conflict and a daily crime.
Hacking has become a widely used tool for political manipulation, oppression, and sheer economic gain. It’s a cheap, powerful, easy-to-outsource, and hard-to-track strategy. Anyone with a computer or smartphone is vulnerable.
And hacking shares a common trait with most of history’s destabilizing weapons, from medieval siege devices to nuclear weapons: it is far more effective for offensive than defensive use.
However, after a decade in which military strategists worried that a cyber conflict could have a real consequence, the emerging dangers of this new era are somewhat different than we ever imagined.
Rather than resembling a new kind of warfare, the role of hacking in the 21st century is very similar to that of espionage in the 20th, according to analysts and former officials. It is a never-ending game of cat and mouse played by small states and great powers alike. Conflictive, even hostile, but tolerated within limits. Sometimes it is punished or prevented, but it is assumed to be a constant.
However, according to experts, there is an important difference. Spy tools are mostly used by governments against other governments. The quasi-democratic nature of hacking – cheaper than creating an intelligence agency – means that private individuals can get involved as well, further muddying the digital waters. Also, because it can scale easily, almost no target is too small, which is why almost everyone is exposed.
Competition within limits
Image
President Obama spoke about Russian cyberattacks during the December 2016 US elections.
President Obama spoke about Russian cyberattacks during the December 2016 US elections. Credit …Al Drago / The New York Times
Since the first international cyberattacks in the 1990s, lawmakers have been concerned that one government may go too far in attacking another’s systems and that there is a risk that the escalation will turn into a war.
By 2010, Washington had institutionalized its vision of cyberspace as a “war field” – along with land, sea, air, and space – that would be dominated by a new military team called Cyber command. Hacking was seen as a new kind of war to be discouraged and, if necessary, won.
But many attacks have been more espionage than war.
Operators in China stole commercial and military patents. Russia broke into the US government mails and later released some for political impact. The Americans monitored international authorities and leaked viruses into hostile government systems.
Governments began treating foreign hackers more like foreign spies. They interrupted a conspiracy, directly accused and sanctioned the person responsible, and rebuked or punished the government that supported him.
In 2015, after a series of incidents, Washington reached an agreement with Beijing to limit the hacking. Chinese attacks on American targets fell immediately, some cybersecurity groups concluded. Again increase in 2018, amid increased tensions during the government of President Donald Trump, which was seen as a sign of a new rule in which digital attacks increase or down according to diplomatic relations.
While governments essentially abandoned military-style deterrence, they have come to punish particularly severe attacks. North Korea suffered nationwide internet outages shortly after Barack Obama declared that Washington was going to retaliate for a North Korean cyberattack. Obama considered similar options against Russia for its attacks during the 2016 elections.
“Our goal remains to send a clear message to Russia and other countries not to do this to us because we can harm them,” he said shortly before leaving office. “Sometimes we will make it public. Sometimes we will do it in such a way that they will know it, but not everyone. “
A new gray area
A power plant in Moscow, Russia. American hackers infiltrated Russia’s power grid in retaliation for the country’s meddling in the American elections.Credit …Maxim Shemetov / Reuters
By the end of the decade, many military and intelligence coordinators had been swayed by an idea expressed by Joshua Rovner, a resident academic at the National Security Agency and the U.S. Cyber Command until 2019.
In an essay for the War on the Rocks site, Rovner wrote that, in almost all cases, the hacking had not turned into some kind of war, but into “open competition between rival states” that resembles espionage and, often, it is an extension of that.
This new interpretation “puts the competition in cyberspace in perspective, but it requires a willingness to live in ambiguity,” he added.
Espionage disputes are never won. There are victories and defeats everywhere and they operate in what military theorists define as a “gray zone” that is neither war nor peace.
As governments have learned what kind of response an operation will provoke, the world has gradually converged on unwritten rules for cyber competition.
Scholars Michael P. Fischerkeller and Richard J. Harknett have described the result as “a competitive interaction within those limits, rather than spiraling to new levels of conflict.”
It is not that governments promise that they will never cross those boundaries. Rather, they understand that doing so will bring certain punishments that they may not want to endure.
Academics say these standards are “still in the making,” waiting to be imposed by governments that test the tolerance of others and the consequences of exceeding them. But they’ve been used long enough that some patterns are starting to emerge.
Obama’s reference to secret and public retaliation was a hint of something that has since become standard procedure. Routine hacks can provoke secret retaliation: for example, dismantling the systems of the government responsible for the incident, to impose punishment without risking escalation or a further diplomatic breakdown.
However, governments can respond to serious hacks with a public counterattack, by reporting the target and warning other governments that the incident went too far. For example, the United States made it known that its hackers infiltrated Russia’s power grid, an escalation calibrated to convince Moscow that meddling in the elections was not worth it.
Russia’s conduct in 2016 also prompted authorities to seek “deterrence by denial” – methods to reduce the chances of success of similar attacks. The goal was to increase the cost of those actions while reducing the benefits.
By calling on the world’s governments to condemn this week’s Chinese cyber theft, President Joe Biden is trying to impose a diplomatic cost that could hit Beijing more than Moscow. It’s a tactic that apparently worked with Obama. However, with the sensitivity of the relationships, Beijing may feel it has less to lose.
Image
Students during a cyber security class at a New York City school. Experts say influence peddling and espionage will be the new normal in the next era of cyber conflict.
Students during a cyber security class at a New York City school. Experts say influence peddling and espionage will be the new normal in the next era of cyber conflict. Credit …Chang W. Lee / The New York Times
In reality, little can be done to prevent governments from deciding to accept the risks involved in launching a cyberattack. Furthermore, because offensive cyber technology has so consistently outpaced defensive measures, it is inevitable that some of those hacks will be successful.
That dynamic is only accelerating, as governments are hiring more private firms or criminals directly to carry out their attacks. Moscow was one of the first innovators, hiring independent hackers abroad, including a 20-year-old Canadian, to infiltrate US government accounts.
The hidden industry of hiring hackers has exploded in recent years. Security researchers have identified highly capable groups targeting governments, financial and legal firms, real estate developers, Middle Eastern energy companies, and the World Health Organization.
Most are believed to be hired through darknet platforms that offer anonymity for both parties. Although their jobs appear to benefit certain governments or corporations, it is often impossible to identify their employers, thus reducing the risk of retaliation.
Globalization and advances in consumer technology have allowed the emergence of an almost infinite number of hackers. Many are believed to be young people from troubled countries where legitimate work is scarce, especially during the pandemic. Commercial piracy software and the expansion of broadband allow almost anyone to participate in these operations.
Some groups operate openly. An Indian company offered to help its clients spy on rivals and business partners. The Pegasus software, located in the center of recent allegations of attacks on journalists and dissidents worldwide, is sold by NSO Group, an Israeli company.
The changing landscape is an indication of the gap between what the legislators of the cyber-conflict era expect and what it really is. Large-scale attacks like Washington’s against Iran or Russia during the 2016 elections occur less frequently.
Rather, the new normal is small but constant hacks: criminals backed by China loot dozens of companies over the years, paranoid authorities spying on local journalists, rival politicians … or even nutrition advocates wanting a soda tax. All of this increasingly falls into the hands of third parties or private software that are perhaps less sophisticated but are easier to spread and deny.
None of those hacks will drastically change the international order. Taken together, however, they suggest that we are entering an era of the pervasiveness of digital theft, influence selling, and snooping. And it could be an era where, as many of the Pegasus victims learned this week, hardly anyone is too ordinary to be a target.
