National Post (National Edition)

Staying afloat in a leaky cyberworld

- HEATHER M. ROFF Halifax Papers Heather M. Roff is a senior research fellow at the University of Oxford, a research scientist at Arizona State University, and a fellow at New America.

The annual Halifax Internatio­nal Security Forum will convene on Nov. 18, bringing together some of the finest military and strategic thinkers in the Western world for a three-day conference. In the run-up to the event, the National Post is presenting some of the essays from the conference, which describe the challenges, and opportunit­ies, facing the West today.

In 1985, Aldrich “Rick” Ames began his infamous career as a mole for the Soviet Union’s KGB. Ames, with 20 years of service in the Central Intelligen­ce Agency, flipped to the other side. He claimed that his primary motivation was money, and in an interview in the mid-1990s, soon after being caught, he surmised that he was operative for so long because he kept things “small.”

In other words, when there are big bureaucrac­ies at play with lots of informatio­n, it is easy to slip under the radar if you keep your ambitions in check.

Today, we would do well to remind ourselves of Ames and the role that informatio­n has always played. Informatio­n is the most valued currency, and being able to manipulate beliefs about informatio­n is equally as powerful. This is where our present-day struggle to protect informatio­n begins to feel somehow new or different.

The huge “hacks” that dump zettabytes of informatio­n into the hands of nefarious actors, the ease with which they seem to do it, and the inability to do much about it, make it feel as if we have collective­ly failed in keeping our most prized digital possession­s secure.

There is some truth here, but I would not say that we have entered a completely new age and are struggling with never- before-seen problems. Rather, the newness is just that adversarie­s have never before had so many open targets. Ames had to give up names of fellow spies, and he had to be paid for his risk, but now, nefarious adversarie­s do not have to undertake risk, and they can pull all this informatio­n from outside the territory in which they are living.

The volume of informatio­n is now astounding. If Ames handed over the or are short-sighted.

Adding all these things together with the reality that we have 3.4 billion Internet users today — with an estimated 1.4 billion more in the next 10 years — connected to 24 billion devices worldwide, the potential attack space appears to present an insurmount­able challenge.

However, we ought not to take the present and coming difficulti­es of data protection as evidence that nothing that is digital is secure. Going back to a pencil and paper is no guarantee of data security either, as Ames proves. Rather, we must think transparen­t to us as possible. We ought not be afraid that using digital informatio­n is an invitation for exploitati­on. But, we need to think critically about how to design these systems for human users. If we fail to understand the informatio­n presented, in our algorithmi­cally determined world, then we cannot know if it is biased, true, or false. This is as dangerous for security experts as it is for the average citizen.

Ultimately, there is a level of risk acceptance in the digital domain. This risk acceptance, however, is not an acceptance that all informatio­n is insecure, but that perfect security is an illusion. The technologi­es we develop to enhance our informatio­n security, as well as the strategies for their use, must depend on a delicate balance of “technologi­cal realism” and social science. That is, rather than thinking there is an easy technologi­cal fix, or that technology saves, we ought to admit its limits. For these limits are uniquely and inherently intertwine­d with human behaviour and beliefs. The human factor can never be over looked or under-estimated. This means that informatio­n “leakage” is always a possibilit­y (and perhaps inevitable), as no one can anticipate the moles or the whistleblo­wers. Protecting informatio­n means being better aware of how we protect ourselves in this new age, and rememberin­g that because we live amid huge data, big bureaucrac­ies, and big business, we are all comparativ­ely “small.”

Newspapers in English

Newspapers from Canada