third-generation controls, during the time of the Olympics, when thousands of
Chinese bloggers posted aggressively to counter what they perceived as anti-Chinese
propaganda. 33 Whether the volunteer posts were managed or encouraged by the state,
or simply benefited the state coincidentally, or some combination, is a vexing question
nearly impossible to untangle. Such attribution problems are, in fact, one of the key
characteristics of second- and third-generation controls and one of their greatest challenges for research projects like the ONI.
Outside of authoritarian contexts and among democratic countries, it is now common to hear of legal and market pressures being invoked to remove content from
Web hosting and social networking platforms, and there is also a very noticeable trend
to offload policing activities to ISPs, particularly in the areas of content controls around
pornography, hate speech, and copyright violations. In fact, most industrialized democratic countries have passed far-reaching surveillance measures that enable widespread
eavesdropping on e-mail, cellular phone, and other communications activities by
requiring ISPs to retain and, when required, turn over such information to legal
authorities.
Perhaps the strongest impetus toward second- and third-generation controls has
emerged from a growing emphasis on cyber security and the recognition of cyberspace
as a domain of military action. Military actors have come to understand cyberspace as a
domain equal in importance to land, air, sea, and space, requiring a full spectrum of
capabilities. This has meant developing weapons and tactics designed to disrupt, destroy, and confuse potential adversaries. For the most part, these capabilities have
been kept quiet and under classification, but they are similar in intent and execution
to the network attacks characteristic of second-generation information controls. Russia,
China, and the United States have all developed doctrines and capabilities for operations in cyberspace that include computer network attacks, as well as psychological
operations designed to shape the domain through selective filtering, denial of access
to information, and information engagement. The intent and effect of these emerging
doctrines is the same as those we have documented in second- and third-generation
controls in the CIS—to silence information that is strategically threatening and sow
confusion and doubt among opponents dependent on cyberspace for information
and organization.
Overall, the lexicon of cyber security is shifting norms around acceptable behavior
for intervention into cyberspace and generating new incentives for technological development. Pervasive surveillance, including deep packet inspection, is now an acceptable part of compliance with good security practices, despite the impacts on privacy
protections. Similarly, the political rush to secure cyberspace is generating economic
opportunities not seen since the Internet boom of the 1990s. However, unlike the
1990s when the rush was led by companies seeking to open up cyberspace, the current
momentum is in the other direction. The fact that defense contractors are now lining up to compete in this domain only raises the troubling concerns that some of the
Control and Subversion in Russian Cyberspace
31
Chinese bloggers posted aggressively to counter what they perceived as anti-Chinese
propaganda. 33 Whether the volunteer posts were managed or encouraged by the state,
or simply benefited the state coincidentally, or some combination, is a vexing question
nearly impossible to untangle. Such attribution problems are, in fact, one of the key
characteristics of second- and third-generation controls and one of their greatest challenges for research projects like the ONI.
Outside of authoritarian contexts and among democratic countries, it is now common to hear of legal and market pressures being invoked to remove content from
Web hosting and social networking platforms, and there is also a very noticeable trend
to offload policing activities to ISPs, particularly in the areas of content controls around
pornography, hate speech, and copyright violations. In fact, most industrialized democratic countries have passed far-reaching surveillance measures that enable widespread
eavesdropping on e-mail, cellular phone, and other communications activities by
requiring ISPs to retain and, when required, turn over such information to legal
authorities.
Perhaps the strongest impetus toward second- and third-generation controls has
emerged from a growing emphasis on cyber security and the recognition of cyberspace
as a domain of military action. Military actors have come to understand cyberspace as a
domain equal in importance to land, air, sea, and space, requiring a full spectrum of
capabilities. This has meant developing weapons and tactics designed to disrupt, destroy, and confuse potential adversaries. For the most part, these capabilities have
been kept quiet and under classification, but they are similar in intent and execution
to the network attacks characteristic of second-generation information controls. Russia,
China, and the United States have all developed doctrines and capabilities for operations in cyberspace that include computer network attacks, as well as psychological
operations designed to shape the domain through selective filtering, denial of access
to information, and information engagement. The intent and effect of these emerging
doctrines is the same as those we have documented in second- and third-generation
controls in the CIS—to silence information that is strategically threatening and sow
confusion and doubt among opponents dependent on cyberspace for information
and organization.
Overall, the lexicon of cyber security is shifting norms around acceptable behavior
for intervention into cyberspace and generating new incentives for technological development. Pervasive surveillance, including deep packet inspection, is now an acceptable part of compliance with good security practices, despite the impacts on privacy
protections. Similarly, the political rush to secure cyberspace is generating economic
opportunities not seen since the Internet boom of the 1990s. However, unlike the
1990s when the rush was led by companies seeking to open up cyberspace, the current
momentum is in the other direction. The fact that defense contractors are now lining up to compete in this domain only raises the troubling concerns that some of the
Control and Subversion in Russian Cyberspace
31
