14
Ronald Deibert, John Palfrey, Rafal Rohozinski, and Jonathan Zittrain
group known as the Iranian Cyber Army compromised Twitter and some key opposition
Web sites, defacing the home pages with their own messages.
17 Although no formal
connection to the Iranian authorities has been established, the groups responsible for
the attacks posted proregime messages on the hacked Web sites and services.
Accessing sensitive information about adversaries is one of the most important
tools for shaping political outcomes, so it should come as no surprise that great effort
has been devoted to targeted espionage. In 2008 the Information Warfare Monitor
discovered that TOM-Skype (the Chinese version of Skype) was actively collecting the
logs and records of any text and voice calls placed to users, including full-text chat
logs that contained politically sensitive keywords.
18 The TOM-Skype example is only
one of many such next-generation methods now becoming common in the cyber
ecosystem. Infi ltration of adversarial networks through targeted “ social malware ”
(software designed to infi ltrate an unsuspecting user ’ s computer) and “ drive-by ” Web
exploits (Web sites infected with viruses that target insecure browsers) is exploding
along the dark underbelly of the Internet. Among the most prominent examples of
this type of infi ltration was a targeted espionage attack on Google ’ s infrastructure,
which the company made public in January 2010.
19
The OpenNet Initiative ’ s experiences in this third phase have proven to be challenging on a number of levels. Our methods were calibrated to check for basic Internet
fi ltering as the primary mechanism of information shaping and denial. However, the
hallmark of the access-controlled phase is the use of nontechnological methods of
shaping cyberspace in combination with selective fi ltering. Many of these methods
are based on social, as opposed to technical, means and do not lend themselves well
to technical fi ngerprinting in ways that were more obvious in the access-denied phase,
when our methods were born. In addition, some of the controls are applied selectively
at key moments, when our testing regime may not be present, thus escaping our notice
entirely. For the ONI to remain relevant, it must adapt to the exigencies of the new
modes of cyberspace controls.
Phase 4: Access Contested (2010 and Beyond)
Today we are headed into a fourth phase that we call “ access contested. ” Although
the central characteristics of the previous phases remain relevant, the key notion of
this phase, as outlined by Ronald Deibert and Rafal Rohozinski in chapter 2 of this
volume, is that the contest over access has burst into the open, both among advocates
for an open Internet and those, mostly governments but also corporations, who feel
it is now legitimate for them to exercise power openly in this domain. There is, and
will be more, pushback against some of these controls from civil society, supported in
many instances by the resources of major governments, like the United States and the
European Union. But that pushback is met by a more vigorous commitment by many
Ronald Deibert, John Palfrey, Rafal Rohozinski, and Jonathan Zittrain
group known as the Iranian Cyber Army compromised Twitter and some key opposition
Web sites, defacing the home pages with their own messages.
17 Although no formal
connection to the Iranian authorities has been established, the groups responsible for
the attacks posted proregime messages on the hacked Web sites and services.
Accessing sensitive information about adversaries is one of the most important
tools for shaping political outcomes, so it should come as no surprise that great effort
has been devoted to targeted espionage. In 2008 the Information Warfare Monitor
discovered that TOM-Skype (the Chinese version of Skype) was actively collecting the
logs and records of any text and voice calls placed to users, including full-text chat
logs that contained politically sensitive keywords.
18 The TOM-Skype example is only
one of many such next-generation methods now becoming common in the cyber
ecosystem. Infi ltration of adversarial networks through targeted “ social malware ”
(software designed to infi ltrate an unsuspecting user ’ s computer) and “ drive-by ” Web
exploits (Web sites infected with viruses that target insecure browsers) is exploding
along the dark underbelly of the Internet. Among the most prominent examples of
this type of infi ltration was a targeted espionage attack on Google ’ s infrastructure,
which the company made public in January 2010.
19
The OpenNet Initiative ’ s experiences in this third phase have proven to be challenging on a number of levels. Our methods were calibrated to check for basic Internet
fi ltering as the primary mechanism of information shaping and denial. However, the
hallmark of the access-controlled phase is the use of nontechnological methods of
shaping cyberspace in combination with selective fi ltering. Many of these methods
are based on social, as opposed to technical, means and do not lend themselves well
to technical fi ngerprinting in ways that were more obvious in the access-denied phase,
when our methods were born. In addition, some of the controls are applied selectively
at key moments, when our testing regime may not be present, thus escaping our notice
entirely. For the ONI to remain relevant, it must adapt to the exigencies of the new
modes of cyberspace controls.
Phase 4: Access Contested (2010 and Beyond)
Today we are headed into a fourth phase that we call “ access contested. ” Although
the central characteristics of the previous phases remain relevant, the key notion of
this phase, as outlined by Ronald Deibert and Rafal Rohozinski in chapter 2 of this
volume, is that the contest over access has burst into the open, both among advocates
for an open Internet and those, mostly governments but also corporations, who feel
it is now legitimate for them to exercise power openly in this domain. There is, and
will be more, pushback against some of these controls from civil society, supported in
many instances by the resources of major governments, like the United States and the
European Union. But that pushback is met by a more vigorous commitment by many
