2 Do No Digital Harm: Mitigating Technology Risks …
21
frequently less willing to discuss sensitive issues over digital media, sometimes for
the fear of interception or spying. In Syria, for instance, it was impossible to record
GPS-stamps as armed groups would immediately suspect a connection to a foreign
military and worry that their armed bases could be revealed. In Somalia, al-Shabaab
banned aid actors with smartphones altogether and would threaten those who used
them. The negative stigma of digital devices could also affect the quality of survey
responses and information passed on via mobile phones. With regards to remote
sensing, some governments banned aid agencies from using aerial imagery, fearing
that the NGO could reveal data that could harm the government.
Challenge 4: Digital vulnerabilities and digital harm
Further, there are severe risks related to digital security that are far from addressed,
let alone known, by both the humanitarian and other sectors. Even though aid practitioners often were aware that digital data can be copied and intercepted without them
noticing and that online accounts can be compromised, mobile communications can
be tracked and anonymized datasets can be reidentified, many organizations fail to
prioritize digital security and even opt against using encryption to secure their data
or devices. ‘If militants knew how to intercept our communications,’ one respondent
said, ‘then they would build better bombs.’ And ‘we offer encryption, but aid organisations never want it,’ said two different service providers. Increasing digitization,
though, means increasing dependency on tools, which both reduce redundancy. Any
potential blackout or attack on digital databases or systems will likely become ever
more costly. At the same time, it makes attacks more rewarding for attackers as they
can get their hands on more information, which can be used against people or passed
on to third parties. The potential cost of digital attack was far from meeting with
adequate security precautions, typically for a simple reason: as long as no serious
incidents are known, aid actors have other worries.
Challenge 5: Privacy risks and irresponsible digital data
Notably, where multiple datasets exist that include information about the same group
or individual, for example, census data, food aid distribution charts, caller ID records
and online social media accounts, these could allow digital attacker to reidentify a
person. Comparing multiple datasets makes it possible to distil accurate revealing
information about people. Increasing amounts of digital data, that are increasingly
shared with digital communities around the world, for example, in order to ‘crowdsource’ the analysis of images, can unintentionally increase the risk of data abuse
and cross-referencing. All in all, humanitarians’ lack of interest in ‘cyber’ threats is
alarming. If aid actors digitize more of their data and communications, they urgently
need to increase their digital security efforts. Though some actors are developing
promising protective tools, aid organizations overall might be well advised to listen
to a quote from IT-security circles: ‘There are two types of organizations: those who
have been hacked, and those who will be.’
21
frequently less willing to discuss sensitive issues over digital media, sometimes for
the fear of interception or spying. In Syria, for instance, it was impossible to record
GPS-stamps as armed groups would immediately suspect a connection to a foreign
military and worry that their armed bases could be revealed. In Somalia, al-Shabaab
banned aid actors with smartphones altogether and would threaten those who used
them. The negative stigma of digital devices could also affect the quality of survey
responses and information passed on via mobile phones. With regards to remote
sensing, some governments banned aid agencies from using aerial imagery, fearing
that the NGO could reveal data that could harm the government.
Challenge 4: Digital vulnerabilities and digital harm
Further, there are severe risks related to digital security that are far from addressed,
let alone known, by both the humanitarian and other sectors. Even though aid practitioners often were aware that digital data can be copied and intercepted without them
noticing and that online accounts can be compromised, mobile communications can
be tracked and anonymized datasets can be reidentified, many organizations fail to
prioritize digital security and even opt against using encryption to secure their data
or devices. ‘If militants knew how to intercept our communications,’ one respondent
said, ‘then they would build better bombs.’ And ‘we offer encryption, but aid organisations never want it,’ said two different service providers. Increasing digitization,
though, means increasing dependency on tools, which both reduce redundancy. Any
potential blackout or attack on digital databases or systems will likely become ever
more costly. At the same time, it makes attacks more rewarding for attackers as they
can get their hands on more information, which can be used against people or passed
on to third parties. The potential cost of digital attack was far from meeting with
adequate security precautions, typically for a simple reason: as long as no serious
incidents are known, aid actors have other worries.
Challenge 5: Privacy risks and irresponsible digital data
Notably, where multiple datasets exist that include information about the same group
or individual, for example, census data, food aid distribution charts, caller ID records
and online social media accounts, these could allow digital attacker to reidentify a
person. Comparing multiple datasets makes it possible to distil accurate revealing
information about people. Increasing amounts of digital data, that are increasingly
shared with digital communities around the world, for example, in order to ‘crowdsource’ the analysis of images, can unintentionally increase the risk of data abuse
and cross-referencing. All in all, humanitarians’ lack of interest in ‘cyber’ threats is
alarming. If aid actors digitize more of their data and communications, they urgently
need to increase their digital security efforts. Though some actors are developing
promising protective tools, aid organizations overall might be well advised to listen
to a quote from IT-security circles: ‘There are two types of organizations: those who
have been hacked, and those who will be.’
