President-elect Donald Trump at a news conference, Jan. 11, 2017. It was his first as President-elect.

President-elect Donald Trump at a news conference, Jan. 11, 2017. It was his first as President-elect. Seth Wenig/AP

Trump’s Cyber-Appeasement Policy Might Encourage More Hacks

Casting doubt on security experts’ ability to identify the culprits behind cyberattacks could make it hard to deter the next one.

Since well before he was elected president, Donald Trump has been casting doubt on the accuracy and integrity of investigations that assign blame for cyberattacks. His statements have created an atmosphere of mistrust around forensic analyses, like the one focused on Russia that three top spy agencies briefed him on last week.

This confusion benefits Trump by deflecting uncomfortable questions about Russia’s role in shifting public opinion about him and his opponent in the election, Hillary Clinton. But it’s also a boon to state-sponsored hackers, for whom uncertainty is the ideal camouflage.

That’s why the Obama administration made a habit of publicly attributing cyberattacks, like North Korea’s attack on Sony Pictures Entertainment, or, less formally, China’s theft of sensitive records from the Office of Personnel Management. For the past several years, the Justice Department also has brought charges against a bevy of state-sponsored hackers from places like China, Iran, and Syria, in a name-and-shame campaign aimed at outing the perpetrators of smaller hacks.

Related: Here's Why Trump's Intel Bashing Matters

In an article published last year in the Harvard National Security Journal, John Carlin—then the head of the Justice Department’s national security division—argued that disrupting cyberattacks and deterring future intrusions both hinge on placing public blame. “To do either, we must first strip hackers of their real or perceived cloak of anonymity through public attribution, because if a hacker is invisible, his actions are cost-free,” Carlin wrote. “Attribution is the lynchpin of our success.”

The erosion of public confidence in analysts’ ability to identify hackers is dangerous.

Trump appears to put far less stock in public attribution. He’s repeatedly called into question the possibility that digital investigators—whether from intelligence agencies or private companies—could piece together a cyberattack after it’s over with enough accuracy to know where it came from, despite the fact that experts regularly track down attackers by gathering digital evidence.

This attitude has trickled down to the general public. Over the weekend, two reporters for The New York Times asked Trump supporters in Louisiana and Indiana for their reactions on the intelligence community’s hacking report. Their responses ranged from skepticism (“It seems silly”) to total rejection (“I don’t believe it”).

This erosion of public confidence in analysts’ ability to identify hackers is dangerous. “Mistrust of attribution would make hacking easier, since it means retribution is harder: You need to have attribution for retribution, both to know that you are retaliating against the right actor and to convince the public you are justified in doing so if it is a public retaliation,” wrote Nicholas Weaver, a professor and security researcher at the University of California, Berkeley, in an email. “The former is unaffected, but the latter is compromised by needless mistrust.”

That mistrust spread quickly. Two years ago, the only people who concerned themselves with fact-checking cyberattack attributions were top security experts like Bruce Schneier, who wrote an article in The Atlantic arguing that the government didn’t have enough evidence to connect the Sony hack to the North Korean government. (He was convinced later that month, when the Times reported that U.S. intelligence agencies were also relying on secret evidence from the NSA and from sources inside North Korea to back up its claims.) Now, Trump’s public disavowals of hacking analyses have made it popular to question Russia’s involvement.

Healthy skepticism has turned to toxic, blanket cynicism.

The increase in public mistrust in cyber-attribution mirrors the way that the language of doubt has taken hold around climate science and the trustworthiness of mainstream news reports. Fewer than half of Americans believe that climate change is the result of human activity—the conclusion of the overwhelming majority of scientists—and just below a third say they have “a great deal” or “a fair amount” of trust in the news media. A third is about the same proportion of Americans who say they believe Russia influenced the 2016 election.

Last week, danah boyd, a scholar of online communications and the founder of Data & Society, wrote that a generation of media-literacy teachings encouraging Americans to question sources and do their own research may have backfired. “Doubt,” boyd says, “has become [a] tool.”

She argues for the necessity of relying on trusted sources of information:

I believe that information intermediaries are important, that honed expertise matters, and that no one can ever be fully informed. As a result, I have long believed that we have to outsource certain matters and to trust others to do right by us as individuals and society as a whole. This is what it means to live in a democracy, but, more importantly, it’s what it means to live in a society.

But people who don’t have the tools to separate bad information sources from good ones may choose unreliable sources, or might be inclined to doubt them all. And when people in power reinforce the notion that experts can’t be trusted—whether it’s climate scientists, journalists for major publications, or medical researchers with advanced degrees—confusion only spreads further. Healthy skepticism turns to toxic, blanket cynicism.

Without a shared basis of facts, climate-change denial and suspicion toward modern medicine flourish. Thorough, fact-based news reporting gets slandered as “fake news” and discounted by large portions of the population. And now, legitimate attributions of blame for cyberattacks are brushed aside as half-baked, untrustworthy, and politically motivated.

These are ideal conditions for malicious hackers looking to strike out at the United States. Foreign businesses can conduct corporate espionage, individuals can dox Americans against whom they hold grudges, and state-sponsored hackers can invade critical infrastructure, all with little worry of retribution. Because even if a cybersecurity company or the U.S. intelligence community finds out what the intruders did, and points fingers publicly—who’s going to believe them?

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.