DOJ's charges against China reframe security, surveillance debate
The charges against five alleged members of the Chinese army refocus a debate dominated by NSA disclosures, some experts say
IDG News Service - The U.S. Department of Justice's decision to bring computer hacking and economic espionage charges against five alleged members of the Chinese army is an attempt by President Barack Obama's administration to redirect a global discussion about cyberhacking and surveillance, some cybersecurity experts said.
The charges, announced Monday, represent the first time the DOJ has filed computer fraud charges against state-sponsored hackers, and the indictments come after a yearlong debate about cybersurveillance at the U.S. National Security Agency, based on leaks by former NSA contractor Edward Snowden.
The chances of the five alleged members of the Chinese People's Liberation Army ending up in a U.S. court are "nil," but the charges point to an effort by the Obama administration to take back a narrative it was pushing with China before the Snowden leaks about the dangers of state-sponsored hacking, said David Fidler, a professor focused on cybersecurity issues at the Indiana University law school.
The underlying message of the DOJ charges to U.S. allies is that they should be more worried about Chinese hackers than the NSA, Fidler said. At the press conference announcing the indictments, U.S. Attorney General Eric Holder repeated the Obama administration assertion that the U.S. government doesn't engage in economic espionage, even though a representative of the Chinese government accused the U.S. of cyberattacks and surveillance on Chinese targets.
"The Chinese aren't just targeting U.S. companies," Fidler said. "The subtext of this is our allies ... know that the more serious threat to their national security and their companies comes from Beijing, not from the NSA."
The prosecution has some risks, including other countries bringing cyber-espionage charges against NSA employees and hackers in China retaliating with new attacks, he said. Even with those risks, the Obama administration seems to be trying to "get back to some core security interests that we have," he said.
The DOJ is signaling that "because of Snowden, we're not just going to sit here and let foreign hackers or foreign governments steal our trade secrets," Fidler added.
The DOJ prosecution could lead to indictments of U.S. government and contractor hackers, agreed Alan Pallar, research director of the SANS Institute, the security training organization. A second problem is "a possibility of the U.S. being seen as hypocritical wherever the line between military and economic espionage is not crystal clear," he added by email.
But Pallar also called the charges an "innovative approach" to putting pressure on computer hackers. "Standard diplomatic efforts have proven impotent in slowing economic crime," he said.
Nick Akerman, a lawyer focused on cybercrime at law firm Dorsey and Whitney, praised the DOJ's move, calling it a "significant prosecution" that points to longtime problems with international cyber-espionage.
- DOJ's charges against China reframe security, surveillance debate
- Hacker indictments against China's military unlikely to change anything
- U.S. to formally accuse Chinese military of hacking
- Cyberattacks could paralyze U.S., former defense chief warns
- The NSA blame game: Singling out RSA diverts attention from others
- Jury still out on FISA court
- Suspected China-based hackers 'Comment Crew' rises again
- Chinese hackers master the art of lying in wait
- Spy court OK'd all U.S. wiretap requests it received in 2012
- Groups denounce FBI plan to require Internet backdoors for wiretaps
- Using Cyber Insurance and Cybercrime Data to Limit Your Business Risk This paper examines the challenges of understanding cyber risks, the importance of having the right cyber risk intelligence, and how to use this...
- 5 Tips to Secure Small Business Backdoors in the Enterprise Supply Chain This paper examines the insecurity of the small businesses in the supply chain and offers tips to close those backdoors into the enterprise.
- Comprehensive Advanced Threat Defense The hot topic in the information security industry these days is "Advanced Threat Defense" (ATD). This paper describes a comprehensive, network-based approach to...
- Advanced Threat Defense: A Comprehensive Approach In this interview, Peter George, president, General Dynamics Fidelis Cybersecurity Solutions, explains why we need more than anti-malware, and what constitutes a comprehensive...
- Live Webcast Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- NSS Labs & Cisco Present: Evaluating Leading Breach Detection Systems Today's constantly evolving advanced malware and APTs can evade point-in-time defenses to penetrate networks. Security professionals must evolve their strategy in lockstep to... All Cybercrime and Hacking White Papers | Webcasts