Cry ‘Havoc!’, and let slip the dogs of lulz

Comment

Image Credits:

Well, why not? I mean, you know, what the hell. Dave Aitel’s proposal over at The Hill for “a cyber investigatory setup funded by private industry” to react to hacks into the American government may not be a good idea, per se, but who can afford that kind of cost-benefit analysis when we’re already in the throes of de-facto high-seas Internet warfare? Let’s just issue some letters of cybermarque and see what happens!

Back in the days of fighting sail, letters of marque authorized private vessels known as privateers to attack, seize, and profit from ships designated as targets. These were distinct from private vessels known as pirates, who attacked, seized, and profited from any ships they decided were targets. That historical distinction is pretty blurred today, one king’s pirate was another’s privateer, but the fundamental problem / opportunity was that vulnerable stores of highly concentrated wealth could be plundered while beyond the effective reach of traditional law. The consequences were more or less inevitable, given human nature. Don’t hate the pirate, hate the game.

Much the same applies today. Our world is largely built atop a foundation of software built in haste, by sloppy engineers using memory-unsafe languages, and then pressed into service for newly emergent purposes by people who had neither the talent nor the time to understand the niceties of the process and/or the consequences of their actions. Are we really so surprised that hackers and nation-states alike are taking advantage of the resulting birds-nest of gaping security holes?

(One exception: Apple. Philosophically, I don’t like their hegemonic approach to software, but the stark absence of any major iOS malware outbreaks over the first ten years of the iPhone deserves some sustained and standing applause. They’re not perfect, but they’re a long sight better than most — and they indicate that increased cyberinsecurity is not an inevitable result of our world’s increased complexity. We could write safe, or at least vastly safer, software. Apple and some enterprise providers like Cisco show as much. We just can’t be bothered, because of legacy commitments, and carrier fragmentation, and the rush to ship code that sort of mostly works if you reboot it often enough, and because, I mean, really, who has the time?)

And so we get insecure networks, and insecure crypto libraries, and insecure operating systems, and servers so insecure that they bleed someone else’s confidential data. We get worms that can spread across entire cities via light bulbs. We get megabotnets. We get the NSA accidentally leaving their toolkit in staging areas, like burglars leaving lockpicks in a stolen car, and that toolkit being used for the recent tsunamis of ransomware and wiperware.

And above all, we get phishing, because people will click on attachments you send them, and somehow, in 2017, we still have so much pervasive insecurity at both the network and the operating-system level that all too often “clicking on a file” — or, marginally more interestingly, “clicking on an OAuth button,” which even mighty Google was hit hard by just two months ago — basically equates to “handing over most of the keys to your kingdom.”

Sure, you could use two-factor authentication, but guess what, if you’re getting validation codes texted to your phone, that’s insecure too! I mean, you should still sign up for it. It’s better than not getting validation codes texted to your phone. But it’s not as good as using, say, Google Authenticator. Kudos to companies like Coinbase, who (wisely, given the current crypto bubble’s eyepopping valuations) are now requiring their users to switch to Authenticator.

But the fundamental problems remain. Decades of terrible security decisions are coming home to roost like a scene from The Birds. The state of information security has been so dire for so long that learned helplessness has caused many people to conclude, nihilistically and wrongly, that it’s not even possible. Attribution — i.e. deciding beyond a reasonable doubt, with more than circumstantial evidence, who was beyond any given hack — is extremely difficult unless the attackers were dumb enough to leave identifying fingerprints. So is retaliation, which is of course the whole point of asymmetrical warfare.

So: issue those letters of cybermarque, hack back against the hackers, and send our own privateers steaming across the dark web armed with cutlasses and cannons? What the hell, why not? It probably won’t accomplish anything; it probably will just escalate an arms race that makes things worse for everyone; but it might make people feel a little better, and if there’s anything that the last few decades of software development have taught us, it’s that people, companies, and governments are way more into building a feelgood façade of security than the hard work and endless slog of building our edifices atop any kind of solid foundation.

More TechCrunch

When it comes to the world of venture-backed startups, some issues are universal, and some are very dependent on where the startups and its backers are located. It’s something we…

The ups and downs of investing in Europe, with VCs Saul Klein and Raluca Ragab

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. OpenAI announced this week that…

Scarlett Johansson brought receipts to the OpenAI controversy

Accurate weather forecasts are critical to industries like agriculture, and they’re also important to help prevent and mitigate harm from inclement weather events or natural disasters. But getting forecasts right…

Deal Dive: Can blockchain make weather forecasts better? WeatherXM thinks so

pcTattletale’s website was briefly defaced and contained links containing files from the spyware maker’s servers, before going offline.

Spyware app pcTattletale was hacked and its website defaced

Featured Article

Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Synapse’s bankruptcy shows just how treacherous things are for the often-interdependent fintech world when one key player hits trouble. 

13 hours ago
Synapse, backed by a16z, has collapsed, and 10 million consumers could be hurt

Sarah Myers West, profiled as part of TechCrunch’s Women in AI series, is managing director at the AI Now institute.

Women in AI: Sarah Myers West says we should ask, ‘Why build AI at all?’

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI and publishers are partners of convenience

Evan, a high school sophomore from Houston, was stuck on a calculus problem. He pulled up Answer AI on his iPhone, snapped a photo of the problem from his Advanced…

AI tutors are quietly changing how kids in the US study, and the leading apps are from China

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Well,…

Startups Weekly: Drama at Techstars. Drama in AI. Drama everywhere.

Last year’s investor dreams of a strong 2024 IPO pipeline have faded, if not fully disappeared, as we approach the halfway point of the year. 2024 delivered four venture-backed tech…

From Plaid to Figma, here are the startups that are likely — or definitely — not having IPOs this year

Federal safety regulators have discovered nine more incidents that raise questions about the safety of Waymo’s self-driving vehicles operating in Phoenix and San Francisco.  The National Highway Traffic Safety Administration…

Feds add nine more incidents to Waymo robotaxi investigation

Terra One’s pitch deck has a few wins, but also a few misses. Here’s how to fix that.

Pitch Deck Teardown: Terra One’s $7.5M Seed deck

Chinasa T. Okolo researches AI policy and governance in the Global South.

Women in AI: Chinasa T. Okolo researches AI’s impact on the Global South

TechCrunch Disrupt takes place on October 28–30 in San Francisco. While the event is a few months away, the deadline to secure your early-bird tickets and save up to $800…

Disrupt 2024 early-bird tickets fly away next Friday

Another week, and another round of crazy cash injections and valuations emerged from the AI realm. DeepL, an AI language translation startup, raised $300 million on a $2 billion valuation;…

Big tech companies are plowing money into AI startups, which could help them dodge antitrust concerns

If raised, this new fund, the firm’s third, would be its largest to date.

Harlem Capital is raising a $150 million fund

About half a million patients have been notified so far, but the number of affected individuals is likely far higher.

US pharma giant Cencora says Americans’ health information stolen in data breach

Attention, tech enthusiasts and startup supporters! The final countdown is here: Today is the last day to cast your vote for the TechCrunch Disrupt 2024 Audience Choice program. Voting closes…

Last day to vote for TC Disrupt 2024 Audience Choice program

Featured Article

Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Among other things, Whittaker is concerned about the concentration of power in the five main social media platforms.

2 days ago
Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Lucid Motors is laying off about 400 employees, or roughly 6% of its workforce, as part of a restructuring ahead of the launch of its first electric SUV later this…

Lucid Motors slashes 400 jobs ahead of crucial SUV launch

Google is investing nearly $350 million in Flipkart, becoming the latest high-profile name to back the Walmart-owned Indian e-commerce startup. The Android-maker will also provide Flipkart with cloud offerings as…

Google invests $350 million in Indian e-commerce giant Flipkart

A Jio Financial unit plans to purchase customer premises equipment and telecom gear worth $4.32 billion from Reliance Retail.

Jio Financial unit to buy $4.32B of telecom gear from Reliance Retail

Foursquare, the location-focused outfit that in 2020 merged with Factual, another location-focused outfit, is joining the parade of companies to make cuts to one of its biggest cost centers –…

Foursquare just laid off 105 employees

“Running with scissors is a cardio exercise that can increase your heart rate and require concentration and focus,” says Google’s new AI search feature. “Some say it can also improve…

Using memes, social media users have become red teams for half-baked AI features

The European Space Agency selected two companies on Wednesday to advance designs of a cargo spacecraft that could establish the continent’s first sovereign access to space.  The two awardees, major…

ESA prepares for the post-ISS era, selects The Exploration Company, Thales Alenia to develop cargo spacecraft

Expressable is a platform that offers one-on-one virtual sessions with speech language pathologists.

Expressable brings speech therapy into the home

The French Secretary of State for the Digital Economy as of this year, Marina Ferrari, revealed this year’s laureates during VivaTech week in Paris. According to its promoters, this fifth…

The biggest French startups in 2024 according to the French government

Spotify is notifying customers who purchased its Car Thing product that the devices will stop working after December 9, 2024. The company discontinued the device back in July 2022, but…

Spotify to shut off Car Thing for good, leading users to demand refunds

Elon Musk’s X is preparing to make “likes” private on the social network, in a change that could potentially confuse users over the difference between something they’ve favorited and something…

X should bring back stars, not hide ‘likes’

The FCC has proposed a $6 million fine for the scammer who used voice-cloning tech to impersonate President Biden in a series of illegal robocalls during a New Hampshire primary…

$6M fine for robocaller who used AI to clone Biden’s voice