bk99.de entertain the web since 1997

To Protect and Infect: The militarisation of the internet

Summary

Claudio Guarnieri and Morgan Marquis-Boire show how states and commercial vendors use targeted malware for far-reaching surveillance. The talk covers a market for commercial surveillance technology worth billions. Offensive security markets turn vulnerabilities into assets that are kept secret for good.

Ideas

  • Besides mass collection, state surveillance increasingly relies on targeted device compromise.
  • Commercial vendors sell attack tools as regular security products.
  • Malware provides deeper access than merely intercepted network traffic.
  • Whistleblowers and seized documents make hidden markets open to investigation.
  • Technical indicators can link different campaigns and operators.
  • Legitimate customers do not guarantee proportionate or lawful use.

Insights

  • Offensive security markets turn vulnerabilities into assets that are kept secret for good.
  • Targeted surveillance shifts power directly onto the personal device.
  • Technical analysis creates accountability where state transparency is deliberately missing.

Quotes

  • 2013 will be remembered as the year that the Internet lost its innocence. – talk description

Habits

  • The researchers compare malware, infrastructure and published documents across several cases.

Facts

  • The talk covers a market for commercial surveillance technology worth billions.

References

  • CCC: To Protect And Infect
  • WikiLeaks SpyFiles: documented vendors and products.
  • 30C3: the event in the year of the Snowden revelations.

Critique

  • The cases visible at the time did not yet allow a complete overview of the market.
  • Technical similarities alone do not always prove who the customer was or who is legally responsible.

Remarks

  • A second part of the talk added further intelligence documents the following day.
  • Many of the methods described still shape modern state trojans.

Recommendations

  • Treat endpoint compromise as a risk of its own alongside network surveillance.
  • Share reliable malware indicators with trustworthy research partners.
  • Demand transparent rules for the procurement and use of state attack tools.

Watch the talk

Search the Web Archive