- ‘Gay Jeans’ that fade into rainbow-colored denim created
- Divided court strikes down big porn award
- Jimmy Carter: Don’t hurt Russian people with sanctions
- Oldest ex-MLB player dies in Cuba, 2 days shy of 103rd birthday
- ‘Top Gun’ for drones: Squadrons of carrier-based killers have Navy’s approval
- Bill Clinton to endorse Charlie Rangel for re-election
- Pfc. Bradley Manning is now Pfc. Chelsea Manning: Court says so
- Secret base U.S. special forces used to train Libyans now under terrorist control: report
- 9th suspect in N.C. kidnapping turns self in to FBI
- L.A. sheriff admits to testing flyover spy program without notifying residents
Civilian ‘hacktivists’ could be lethal targets in cyberwar, NATO study says
Politically motivated civilian hackers, or “hacktivists,” who conduct online attacks as part of a nation’s cyberwar efforts could lawfully be targeted with deadly force, according to a new study commissioned by NATO’s cyberwarfare center.
“An act of direct participation in hostilities by civilians renders them liable to be attacked, by cyber or other legal means,” reads the study, “The Tallinn Manual on the International Law Applicable to Cyber Warfare.”
An international group of experts in the laws of warfare wrote the manual, at the invitation of NATO’s Cooperative Cyber Defense Center of Excellence in Tallinn, Estonia. It is not a statement of official policy by NATO or any of its member governments, but it reflects a consensus view of a large group of legal scholars and practitioners, including several senior military lawyers from NATO countries.
The manual is being launched next week in Washington, and the issue it raises, of hacktivists who join hostilities online, is far from merely hypothetical.
In August 2008, the Republic of Georgia and the Russian Federation went to war in the disputed border province of South Ossetia. But the shooting war was accompanied by cyberattacks that knocked offline much of the Georgian government, including the Foreign Affairs Ministry. At a crucial moment for their nation’s history, Georgian diplomats were reduced to using a publicly hosted Google Blogspot page to post their public statements.
Georgian websites were attacked using a technique known as distributed denial of service, or DDoS, in which networks of personal computers, infected and enslaved unbeknown to their innocent owners, are used to bombard the target’s web servers so that real users cannot get through.
The manual says that joining a DDoS attack against a military network counts as “direct participation,” but the manual does not squarely address the issue of such an attack against civilian or government computers.
But the manual is clear that civilian infrastructure, including computers and computer networks, that is used for a “military purpose” — for instance, to carry military communications traffic — can lawfully be targeted, providing that any damage is “proportional” to the value of the military objective.
“The analogy is to a road network used by civilian and military vehicles,” the manual states. “There is no reason to treat a computer network differently.”
The DDoS attacks on Georgia were led by loosely-knit groups of ultranationalist Russian hackers who coordinated the timing and targeting of their attacks and distributed software that could be downloaded by volunteer users so their computers could join the assault.
The hackers who wrote such malicious software and made it “openly available online” would not be legally targetable even if the malware was used in cyberwarfare, according to the manual. But a hacker who supplied a similar cyberweapon specifically designed for use in an online assault that rose to the level of international hostilities could be treated as a legitimate military target.
Former senior U.S. intelligence officials have said that private sector or freelance contractors write much of the malicious computer code used by the Chinese military in its cyberespionage operations.
Moreover, since they are not members of their countries’ military, the manual says, hacktivists taking part in a cyberwar should be considered “unprivileged belligerents” — the status the Bush administration accorded to al Qaeda fighters captured on the battlefield in Afghanistan. Unprivileged belligerents are not entitled to prisoner of war status under the Geneva Conventions, and they can be prosecuted for their actions — even if those actions would have been legal under the laws of war if carried out by military personnel.
© Copyright 2014 The Washington Times, LLC. Click here for reprint permission.
About the Author
Shaun Waterman is an award-winning reporter for The Washington Times, covering foreign affairs, defense and cybersecurity. He was a senior editor and correspondent for United Press International for nearly a decade, and has covered the Department of Homeland Security since 2003. His reporting on the Sept. 11 Commission and the tortuous process by which some of its recommendations finally became ...
- Senator's memo shows Iran links in Homeland Security's troubled immigration program
- Help wanted: Homeland Security plagued by vacancies at the top
- Dems back bill to fix problems in investor visa program
- Democrats proceed with Mayorkas vote despite pending investigation
- Game players don't think peace has a chance in Syria
Latest Blog Entries
TWT Video Picks
By Andrew P. Napolitano
Obama's veil of secrecy is pierced
- Pentagon plans to replace flight crews with 'full-time' robots
- 'Top Gun' for drones: Squadrons of carrier-based killers have Navy's approval
- Kansas will nullify local regulation of guns
- Nevada rancher Cliven Bundy hailed as patriot, ripped as lawless deadbeat
- CARSON: When government looks more like foe than friend
- America is an oligarchy, not a democracy or republic, university study finds
- Washington Redskins' 2014 schedule opens with Texans
- Texas is next! AG warns BLM wants 90,000 acres after Bundy ranch standoff
- Georgia governor signs bill expanding gun rights
- Opposition rising to Colorado gun control laws
Top 10 handguns in the U.S.
Celebrity deaths in 2014