Cybersecurity as Public Interest Technology
I’m going to begin with a controversial statement:
Over the last 12 months, I have witnessed a decline in cybersecurity.
Yes, we have never had as many security products on the market as today. But I'm not referring here to advanced software techniques that use machine learning to ward off attacks, I’m not referring to the state-of-the-art hardware, network security or anything “security vendor”- produced.
I am referring here about the jostling between large organisations in the Internet space, that scrounge and scrape more and more information on data from ordinary citizens each day:
their identity,
location,
condition,
and more;
and government agencies, including federal law enforcement agencies, that seek to exercise greater and greater powers of surveillance that are deliberately imposing their power on private corporations, particularly those who use encryption or other forms of security protections.
*
For the first time in the history of computing we now have overt data requests, written into the law, to conduct what is generally known as technical capability requests, on privacy branded products and services. The claim goes something like this:
We are the government, we have the power to demand that you help us create a mechanism by which to penetrate your systems and if you don’t comply, we’ll fine you.
On the one hand, this is a demand to create a systemic weakness in the creative and robust advanced design of cybersecurity in all its forms, and on the other hand, one can argue this is a legitimate right of governments who seek social securitization, or if you look at it another way, a government who seeks to erode the freedom and human rights of its people in the event these people can't be trusted or because we need the people’s votes and we will get them one way or another.
And yes, it all comes down to trust. And it is no wonder that at this time of the greatest forging forward in cybersecurity, the paradox, is that we have never felt so insecure.
*
One might ask, what this has to do with public interest technology, and public interest technology education?
Ladies and gentlemen, it has everything to do with PIT. As commercial products on the market, enter our homes, and our pockets, even our psyches, there has never been a greater need for a job description that reads — public interest technologist.
It is a skill set that is required in a translational capacity between technology and policy related jobs, but not only translational but operational and tactical and strategic. We are speaking of a new generation and a new breed of policy, law and regulation analysts, who are technically endowed with the skills to make judgments which make sense.
And technologists who can implement policies and regulations based on extrapolating processes using formal methods and approaches. These are not technologists who are waiting for laws like the General Data Protection Regulation to implement certain principles into their software processes, but proactively, follow their instincts to protect their customers and not to blatantly abuse them, just because they can and the chances are that no one would ever find out.
We are referring to individuals who are not tempted by big data potentials, and prefer to use their big judgement to create a safer online world for open exchange without discriminating against people of:
race,
ethnicity,
gender
health or
religion.
*
As technology and its pace of change introduces an elevated pacing problem to policy regulation and the law, we seek to develop individuals who are able to not simply point the finger at one another and claim that this is their problem that’s why that went wrong, but we seek individuals who are intrinsically both technologists working in the public interest, and policymakers that get technology.
Today, subject to the pacing problem where our laws move ever so slowly to keep pace with rapid technological change, we place our faith in soft laws, which act as legally non-binding instruments utilised for a variety of reasons primarily to strengthen member commitments to agreements and reaffirm international norms. In essence, what is the right thing to do? Some of our corporations are bigger than countries. They know no geographic bounds.
No longer do we want court room judges who don't understand how AI-driven sentencing works, nor do we wish for prosecutors who don't understand how GPS coordinates can be incorrectly recorded or might be used to stalk someone, or that DNA evidence requires ongoing consent for storage.
Nor do we want inept policymakers in positions of power who believe they are acting on behalf of the common good and introducing as a result draconian measures for the populace.
Nor do we wish for a police force that relies on so-called just-in-time intelligence, built on facial recognition systems that do not work. Whether it is a social credit or trust system we are introducing in classrooms or in societies at large, we have to be mindful of the impact of these mass scale, imposed technical systems, that are never “just technical”, they have societal impacts.
We need to be introducing electronic health records with cybersecurity, privacy and data rights at front and centre, not as bolt on, or “nice to have if time permits” and the budget stretches out- because the reality is that it will NEVER stretch out unless it is embedded in all the systems we build from the very beginning.
*
We need students in computing, information technology, and software engineering to be taking security seriously in the creation of their algorithms and executable code.
We need to ensure they are asking WHY are we building this or that,
and for WHOM,
and what PURPOSE will it serve,
and WHICH stakeholders have been consulted?
We need students from interdisciplinary backgrounds to join together to work in cross-disciplinary project teams to consider the potential scenarios, for example, for autonomous vehicles, and 5G connected cars. Soon we won't be talking about white hat hackers or black hats or grey hats but predatory hackers whose main aim is to maim and kill, what Joseph Carvalko calls ‘death by Internet’.
Biomedical devices will soon be Internet of things enabled, and NIST has long been speaking of a multiplicity of operational scenarios of the future:
not just the things that we lug around,
not just the things that we wear,
but ultimately those things that each of us will bear.
We are talking about what my husband and colleague MG Michael coined as:
uberveillance back in 2006. Embedded surveillance devices for care, convenience and ultimately, control.
If we do not get our act together, with the burgeoning Internet of Things (IOT) market which is estimated at 20 billion devices in 2020, how will we address the new horizon scenarios of “in body” technologies not just “on body” or “external to the body”.
The case here is really about how we educate our next generation to intimately understand the challenges that they will be faced with, within public agencies, private organisations, not for profits and non-government organisations. We are talking about establishing the need to take cyber security seriously in all its forms and all its life worlds, not just within governments and big corporations, but raising awareness in civil society.
We have on our hands what seems to be an insurmountable task. But it does begin with education, and the movement has already long begun, and led by such public interest advocates as security expert Bruce Schneier, and privacy expert Ann Cavoukian. These are the role models that we hope inspire the younger generation to think about cybersecurity and privacy by design. It is not an old meme that says privacy versus security, but a new meme that emphasizes privacy AND security.
MG Michael in 2010 also spoke of an emerging concept that he labelled the “axis of access”. Michael goes beyond access control matrices and questions who has the right to oversight? Michael refers to:
the axis of access as the second lung of uberveillance and so the higher up the axis we go we get a clearer picture of the current and future dangers ahead of us.
-
Who has the right to penetrate systems? Who has the right to ultimate transparency? Do citizens have access to their own data “on demand”?
-
Can hackers increasingly, motivated by money and the art of hacking, penetrate systems that should otherwise be impenetrable?
-
Does law-enforcement always have the last say propelled by governments in five eyes nations, to breach systems they should otherwise leave alone?
-
Do governments and corporations have the right to increasingly encroach on citizenry and their unique characteristics, behavioural traits, and other sensitive information that is often transactional?
In other words, who will guard the guards?
Especially when we are talking about the bulk collection of DNA, facial images, and increasingly voice prints and heart rates and brain waves?
Ultimately the trajectory points to a complex system of systems accessible only to an asymmetric very few; and on the axis we have to ask, which agents rank above governments.
Is it the Google's Facebook's and Amazon's of our time who have more data than governments could ever dream of?
*
Systems of all types are penetrable. It is fallacious, to claim that a system can never be breached, even if some make these inferences regarding cryptobionics. This raises questions of where artificial intelligence will go and how we can incorporate risk into cybersecurity studies.
How do we prepare the next generation, for the next generation of applications and services which presently look as if they are the stuff of science fiction?
-
How do we have sober responses to the outlandish capacities of some private enterprises?
-
How do we measure risk when we are considering dabbling with the body’s most vital organ, the brain, through brain to computer, or brain to brain interfaces?
*
At ASU we pride ourselves on the entrepreneurial mindset. We don't stop progress, and innovation is intrinsic to making the world a better place for all.
In our forthcoming Masters of Science in Public Interest Technology, we call on international participants to become involved in international student instruction.
We wish to acknowledge the role of NGOs and not-for-profits, provide these organisations with a platform by which they can be heard using innovative technologies.
To openly discuss values and care and empathy in the design of new systems.
At the same time we seek to educate managers and senior employees in organisations in the public and private sectors to be among the first to be informed and impart matters integral to the creation of next-generation services that won't be subject to frequent data breaches, nor of malpractice in organisations, with a view to creating distributive leaders who will take responsibility for their actions.
*
I am speaking here about the importance of detecting:
fake news,
fake services,
fake products,
fake companies,
fake ventures.
When we defined uberveillance back in 2006 before the ridesharing app Uber was released in 2009, we wrote about the problems related to these “always on”, allegedly “real-time” devices that would stream data. They would inevitably propagate three things:
misinformation
misinterpretation
information manipulation.
More than a decade ago our loosely formed cyberethics/security team made up of Roba Abbas, Anas Aloudat, Christine Perakslis, Jeremy Pitt and many more, noted the fallout of uberveillance which we described as the assault on privacy. We were 13 years ahead of the fall out.
*
So let’s peer into the future-- a world that has gone crazy in the adoption of body worn cameras, for not only policing but also wildlife rescue, and even visiting your mental health professional, and even tracking on school grounds and day cares, and shopping malls.
Let’s say we all adopt these tiny devices and place them above our clavicles. Imagine, like the 50,000 wearable cameras on law enforcement officers in the USA, that we stream real-time feeds. Are these supposed to give us greater visibility? These technologies are supposed to make us safer and more secure but again I go back to the paradox of insecurity, and having a “false sense of security”.
-
How do we change the mindset of the field at large and concentrate again on producing better people and technologies, not just merely MORE technologies?
We need:
practitioners that understand the challenges of social justice,
practitioners that understand technology assessment,
practitioners that can speak about the tangible and intangible environmental impacts.
And here, I am not merely speaking about endangered species but endangered practices.
I am also talking about a just cause, and an equal footing at the stakeholder table that is inclusive of minority groups and representation and not exclusive:
women,
black, yellow, and white people,
native people,
the dis/abled,
the homeless
those that cannot afford medical insurance.
Practitioners who seek to innovate responsibly and who don't wish to cut corners simply to be 1st to market.
We have a lot of work to do. The wonderful thing is that this generation is ready to take up the challenge, that our generation abandoned.
The next generation:
is privacy conscious,
does understand disinformation,
is aware that they are entering a world where deep fakes are part and parcel of a future evidence based society.
That visual recordings must first be ascertained as authentic before making claims about their message or implication. We will need to create audit systems that ensure visual alibis have not been fabricated.
*
Finally in closing, I want to share with you several personal exchanges that I have had with current Masters and PhD students at ASU who have a variety of background in criminology, international affairs, and the law.
-
In the case of the criminologist who is passionately wishing to take up the role in cybersecurity of medical devices, he asks “Katina will I have to know how to code to be a part of this biomedical ecosystem”?
-
In the case of the international affairs student has completed their Masters of Science and Technology Policy, and frustrated with the limited possibilities of entering a public interest technology role not because they don't exist but because corporations don't wish to invest in them, she asks me
“when are these companies going to wake up and hire me. I am ready to go, I have something to offer. The Facebook vacancy, Katina, that has been advertised for a data abuse and misuse analyst has still not been filled 9 months on! Why?”
3. And the lawyer who is struggling to get his Masters of Computing, is stupefied by the resistance within the field of computing to hire a lawyer who will only be considered as a pizza box cookie-cutter.
Ladies and gentleman, he doesn't want to be a programmer, he wants to be a part of the bigger solution but we are still suffering from myopia! We still want traditional siloed careers and look for those people in siloed disciplines. We want one-dimensional teams but they won’t be effective in 2020.
We must begin to give these public interest technologists a chance to practice their craft. And yes initially we have to take a chance, but I am of the opinion that the E in ebusiness or the “I”, in iSchool, has now lost its glory.
Our hope in the School for the Future of Innovation in Society, is to reach across disciplines, whether it be in law, communications, psychology, humanities, the social sciences or beyond. The hope is to inject the public interest technology philosophy across technical and non-technical fields, giving birth to:
the thinking technologist,
the philosophical engineer,
the technologist who can be reflexive
of which if we are to be true to ourselves, should be every single one of us in the cyber-physical world we live in.
*
Finally, as we look to a future which is hyper connected, and integrated in systems of systems, we must find a way to interweave cyberethics with cybersecurity. This is not just a skill for techies, because in the future we live in, we all have to get with tech and at all levels.
The current contexts, the converging veillances of:
surveillance,
dataveillance,
sousveillance,
and uberveillance,
set up for us risks like we’ve never known before:
personally,
in the business/financial world,
the environmental and,
global world.
The question now is:
what are we going to do about it?
Source: Katina Michael, November 20, 2019, “Cybersecurity as Public Interest Technology”, National Initiative for Cybersecurity Education (NICE), a program of the National Institute of Standards and Technology in the U.S. Department of Commerce, under NIST Financial Assistance, https://niceconference.org/, Sheraton Grand Hotel, Phoenix, Arizona.