Introduction
Information Technology and Communication Infrastructures – commonly referred to as the Cyberspace – have been in the focus of military institutions and secret services from the beginning. Not only was the Internet originally introduced by U.S. military institutions – it emerged from the Arpanet, named after the Advanced Research Project Agency (ARPA) of the U.S. Department of Defense – it also serves as an infrastructure for military action today, being under surveillance by secret services and military agencies to gather information for cyber- and conventional military means and used for cyber attacks in order to compromise the infrastructure of the percepted enemy.
FIfF has launched the Cyberpeace campaign [1] to address the threats emerging from cyber warfare policies and to push back the colonization of the communication infrastructure by the military and surveillance of the entire population, which, in addition, sets everyone under suspicion. Our goals are non-violent conflict resolution, arms control of cyber weapons and surveillance technology, dismissal of development and use of cyber weapons, the obligation to make IT vulnerabilities public and the promotion of communication infrastructure, which is, by law, secure against surveillance. We want the Internet and all infrastructure to be used in a peaceful fashion and to be protected against military misuse. We want that secure communication be ensured while preserving and promoting human and civil rights.
In order to achieve these goals, we focus on four issues we elaborate on in the following chapters:
This is our framework for the claims we require in our Cyberpeace campaign for a peaceful use of the Internet and all information and communication infrastructures.
Rebuild trust
Our society is based on trust – this is what sociologist Niklas Luhmann pointed out in his book Vertrauen („Trust“) in 1968 [4] – long before the Internet arised to influence our entire life. Luhmann points out, that trust ist essential to reduce the social complexity of our societal environment. This is necessary to enable us to take all the decisions which everyday life requests us to. With a lack of trust, the number of decisions to take would become overwhelming; we would not be able to cope with everyday life. Security expert Bruce Schneier [5] illustrates this convincingly:
„Just today, a stranger came to my door claiming he was here to unclog a bathroom drain. I let him into my house without verifying his identity, and not only did he repair the drain, he also took off his shoes so he wouldn't track mud on my floors. When he was done, I gave him a piece of paper that asked my bank to give him some money. He accepted it without a second glance. At no point did he attempt to take my possessions, and at no point did I attempt the same of him. In fact, neither of us worried that the other would. My wife was also home, but it never occurred to me that he was a sexual rival and I should therefore kill him.“
Using Internet services also requires trust – and we are commonly willing to provide this trust, e.g. by calling web sites, often without double-checking their trustworthiness. We often simply rely on our intuition. We call web sites without encryption, trusting, that nobody would eavesdrop on our communication. Also, we do not encrypt our e-mail – nobody would read along and if so, what could possibly happen?
The recent disclosures should have changed our minds. Edward Snowden provided us with the consciousness of world-wide surveillance of the entire communication by secret services [3]. Authors like Josef Foschepoth [2], Professor of history from the University of Freiburg, made clear that modern mail and communication surveillance started from the end of World War II – not only in the eastern states, but also in the Federal Republic of Germany. Currently, an inquiry committee investigates unconstitutional surveillance by the German federal intelligence service (Bundesnachrichtendienst). Austria, as an example, just filed a case due to punishable espionage – formally against the unknown; actually it clearly affects german authorities.
Trust cannot be enforced by political claims – it grows (and vanishes) due to actual action. Nevertheless, political action is necessary to restore trust and to enforce the demands we derive from the second and third issue mentioned above.
Condemn offensive action and promote non-violent conflict resolution
Real peace is only possible, if all parties abstain from armament and from attacking each other. Since unilateral measures of disarmament lead to the risk of insufficient defense capacities, bilateral or multilateral agreements must be concluded. These agreements should aim at structural inability to attack and the limitation of military capacity to defense. Strict rules must be agreed upon to protect people, if in spite of focusing military strategies on defense, a conflict might arise. In detail, from our point of view the following demands must be requested [1]:
Secure vital infrastructure
Although we prefer all parties in a conflict to abstain from using military force and employ non-violent means of conflict resolution, we must be aware, that defensive military capacity has to be built up to intervene in cases, when short-term non-violent conflict resolution is not possible and a military cyber attack takes place. Additionally, cyber attacks from non-military origins have to be considered, such as cyber crime and cyber terrorism – a threat strongly expanding. Public authorities and business companies will have to meet sufficient security measures, and constantly update them with regard to the evolution of capacity on the attackers' side. The range spans from script-kiddies, hackers, criminals to secret services with virtually unlimited capacity to set up attacks.
The following demands, from out point of view, are preconditions to make secure system operation possible – they do not guarantee it [1].
Preserve democratic political control
The demands mentioned before need sufficient attention on the political level. Organisational and legislative measures must be taken to promote confidentiality, integrity and availability, bring forward democratic control and civil rights such as free speech, and, last but not least, take care of appropriate political language [1].
We consider these four fields – trust, non-violent conflict resolution, securing vital infrastructure and democratic political control – an appropriate framework to achieve cyberpeace. We are convinced, that this framework and the demands will help us to take the political decisions to reject the military colonization, promote peace and human and civil rights in cyberspace.
Acknowledgments
The framework and the claims cited in this paper are a result of collaborative work in the Cyberpeace campaign team.
References and Notes