Internet kill switch
An Internet kill switch is the cybercrime and countermeasures concept of activating a single shut off mechanism for all Internet traffic. The theory behind a kill switch is creation of a single point of control for one authority or another to control in order to shut down the Internet to protect it from unspecified assailants; however, groups such as the American Civil Liberties Union and the Nominet Trust have criticized the proposals for implementation made so far.
United States
History
The prospect of cyberwarfare over the 2000s has prompted the drafting of legislation by US officials, but worldwide the implications of actually "killing" the Internet has prompted criticism of the idea in the United States. During the Arab Spring in Tunisia, Egypt, and Libya access to the Internet was denied[1] in an effort to limit peer networking to facilitate organization. While the effects of shutting off information access are controversial, the topic of a kill switch does remain a topic that remains to be resolved.
Communications Act of 1934
The Communications Act of 1934 established the United States' Federal regulation of electronic communications by the Federal Communications Commission (FCC). This act, created by the Franklin D. Roosevelt Administration, gave the president powers of control over the media under certain circumstances. This act was the basis of regulatory power for the executive branch of the government to control electronic communications in the United States.
Telecommunications Act of 1996
Presidential Decision Directive 63 (PDD-63), signed in May 1998, established a structure under White House leadership to coordinate the activities of designated lead departments and agencies, in partnership with their counterparts from the private sector, to “eliminate any significant vulnerability to both physical and cyber attacks on our critical infrastructures, including especially our cyber systems.” [2]
Proposed Protecting Cyberspace as a National Asset Act of 2010
On June 19, 2010, Senator Joe Lieberman (I-CT) introduced the Protecting Cyberspace as a National Asset Act,[3] which he co-wrote with Senator Susan Collins (R-ME) and Senator Thomas Carper (D-DE). If signed into law, this controversial bill, which the American media dubbed the kill switch bill, would have granted the President emergency powers over the Internet. Other parts of the bill focused on the establishment of an Office of Cyberspace Policy and on its missions, as well as on the coordination of cyberspace policy at the federal level.
If national security were to be severely threatened by a cyber attack, broadband providers, search engines, software firms and other major players in the Telecommunications/Computer/Internet industry could have been be required to immediately comply and implement any emergency measure taken;[4] for most of the month of June, media coverage of the bill insisted on this so-called 'kill switch' provision, said to be included in the bill.[5]
Section 249 of the bill states that "the President may issue a declaration of a national cyber emergency to covered critical infrastructure," in which case a response plan is implemented.[6] This plan shall consist of "measures or actions necessary to preserve the reliable operation, and mitigate or remediate the consequences of the potential disruption, of covered critical infrastructure". Said measures should "represent the least disruptive means feasible to the operations of the covered critical infrastructure" and "shall cease to have effect not later than 30 days after the date on which the President issued the declaration of a national cyber emergency" unless the President seeks to extend them, with the approval of the Director of the Office of Cyberspace Policy established by the bill.
Criticisms of the Lieberman bill
Interviewed by Candy Crowley on CNN's State of the Union, Lieberman claimed "it is a fact cyber war is going in some sense right now", "a cyber attack on America [could] do as much or more damage [...] by incapacitating our banks, our communications, our finance, our transportation, as a conventional war attack".
"Right now, China, the government, can disconnect parts of its Internet in a case of war. We need to have that here, too," Senator Joe Lieberman, sponsor of the bill, said on Candy Crowley's State of the Union on CNN.[7]
Following this remark, Comedy Central's Jon Stewart made fun of Senator Lieberman for bringing up the example of censorship in China on his satirical program The Daily Show with Jon Stewart.[8]
The American Civil Liberties Union (ACLU) criticized the scope of the legislation in a letter to Senator Lieberman signed by several other civil liberty groups.[9] Particularly, they asked how the authorities would classify what is critical communications infrastructure (CCI) and what is not, and how the government would preserve the right of free speech in cybersecurity emergencies. An automatic renewal provision within the proposed legislation would keep it going beyond thirty days. The group recommended that the legislation follows a strict First Amendment scrutiny test:
- (i) the action must further a compelling governmental interest;
- (ii) it must be narrowly tailored to advance that interest; and
- (iii) it must be the least restrictive means of achieving that interest.
Outcome
All three co-authors of the bill subsequently issued a statement claiming that the bill "[narrowed] existing broad Presidential authority to take over telecommunications networks",[10] and Senator Lieberman contended that the bill did not seek to make a 'kill switch' option available ("the President will never take over -- the government should never take over the Internet"),[10] but instead insisted that serious steps had to be taken in order to counter a potential mass scale cyber attack.
The Protecting Cyberspace as a National Asset Act of 2010 expired at the end of the 2009–2010 Congress without receiving a vote from either chamber.[11]
Implementation issues
There are several issues that may prevent a system to be established in the United States. The Telecommunications Act of 1996 deregulated the telecommunications market and allowed for the growth of data carrier services. Since the Federal Communications Commission (FCC) does not require registration of a company as an Internet Service Provider (ISP), there are only estimates available. As of April 2011, there are over 7,800 ISPs estimated to be operating in the United States. This makes implementation of a kill switch that much more difficult: each company would have to voluntarily comply. There is no law that gives the United States authority over an ISP without a court order.
A court order is not necessarily the solution either. Even if an ISP is forced by court order, the attack may have already taken place and the prophylactic methods too late in implementing. There are thousands of ISPs and since they don’t have to register, there is no known way of contacting them in time and forcing the ISP to comply.
The regulations that the United States uses to regulate the information and data industry may have inadvertently made a true “Internet kill switch” impossible. The deregulation allowed for building of a patch-work system (ISPs, Internet Backbone) that is extremely complex and not fully known.
In the United States, there are strong citizen and business protection systems. There is redress of grievances allowed to the courts or administrative authority. There is also the need for a court order for the government to shut off services. In addition to these fairly large roadblocks, there are human rights groups such as the ACLU, Amnesty International, and others. All of these reasons make implementing the Internet kill switch difficult.
Policy issues
The key policy issue is whether or not the United States has the right constitutionally to restrict or cut off access to the Internet. The powers granted to the presidency starting with the Communications Act of 1934 seem to be adequate in dealing with this threat, and is one of the major criticisms of legislation determined to regulate this question. The next most important question is whether or not the United States even need this legislation or it would chip away at individual liberties. The trade offs are apparent - if the government can control information online then it can limit access to information online. One of the biggest problems with the theory is what to classify as critical communications infrastructure and what to leave out.
Policy makers have to take into account the cost of shutting down the Internet, if it is even possible. The loss of the network for even a day could cost billions of dollars in lost revenue. The National Cybersecurity Center was set up to deal with these questions, to research threats and design and recommend prophylactic methods.
In many ways, the integration of networked computer-mediated communication systems into our business and personal lives means that the potential threat is increasing along with the potential problem of protecting a wide class of products. Utility systems can be monitored and controlled remotely, whereas it used to be a physical person. So the issue of what an Internet kill switch could affect is growing exponentially.
The 2009 White House Assessment stated that there needed to be more work done on this issue and the National Cybersecurity Center was created to handle security issues.[2] It is not known at this point if the Center has a policy regarding asserting control of the national networks.
United Kingdom
In the United Kingdom, the Communications Act 2003 and the Civil Contingencies Act 2004 allow the Secretary of State for Culture, Media and Sport to suspend Internet services, either by ordering Internet service providers to shut down operations or by closing Internet exchange points.[12] A representative of the Department for Culture, Media and Sport said in 2011 that:
"It would have to be a very serious threat for these powers to be used, something like a major cyber attack. The powers are subject to review and if it was used inappropriately there could be an appeal to the competitions appeal tribunal. Any decision to use them would have to comply with public law and the Human Rights Act."[12]
Dr. Peter Gradwell, a trustee of the Nominet Trust, criticized the provisions in the Communications Act:
"The legislation also includes the requirement to make compensatory payments for loss or damage. Would the Government want to foot the bill for switching off a multi- billion-pound industry? If a notice is served on an ISP and ignored, the penalty is only a fine. If the public were massing on the streets of London, I believe that many internet providers would be happy to argue the legitimacy of such a penalty in court.[12]
Egypt
On January 27, 2011, during the Egyptian Revolution of 2011, the government of President Hosni Mubarak cut off access to the Internet by all four national ISPs, and all mobile phone networks.[13][12] This version of a kill switch was effected by a government-ordered shutdown of the Egyptian-run portion of the Domain Name System, and Border Gateway Protocol (BGP), making transmission of Internet traffic impossible for Egyptian ISPs. All network traffic ceased within two hours, according to Arbor Networks.[13]
See also
References
- ↑ Dainotti et al., Analysis of Country-wide Internet Outages Caused by Censorship, ACM, 2011
- 1 2 "Cyberspace Policy Review" (PDF). USA Government. 2009.
- ↑ "Protecting Cyberspace as a National Asset Act of 2010". U.S. Congress.
- ↑ Senator Lieberman Proposes Cyber Security Act. Archived June 22, 2010, at the Wayback Machine.
- ↑ McCullagh, Declan (10 June 2010). "Senators propose granting president emergency Internet power". CNet.
- ↑ Proposed Response Plan Archived April 17, 2011, at the Wayback Machine.
- ↑ "Transcripts of CNN's State of the Union with Sen. Joe Lieberman". CNN. 20 June 2010.
- ↑ "John Steward looks at Kids' Junk". The Daily Show. 21 June 2010.
- ↑ American Civil Liberties Union (23 June 2010). "Civil Liberties Issues in Cybersecurity Bill" (PDF).
- 1 2 Hoover, J. Nicholas (24 June 2010). "Senators Say Cybersecurity Bill Has No 'Kill Switch'". informationweek.com. Retrieved 25 June 2010.
- ↑ Status of S.3480, 111th Congress, Status of H.R.5548, 111th Congress
- 1 2 3 4 "Could the UK Government shut down the web?". The Independent. March 8, 2011.
- 1 2 "Egyptian Revolt Unquelled By Total Comms Blackout". TechWeek (magazine). January 28, 2011.