How Citizen Lab Investigates Digital Surveillance

856 views
•
March 8, 2019
by
RSAC Cybersecurity
YouTube video player
How Citizen Lab Investigates Digital Surveillance

TL;DR

Citizen Lab investigates targeted digital attacks against civil society groups that cannot pay for security investigations. Foundation funding, long-term relationships with high-risk communities, donated technical support, and academic independence enable its forensic and policy work, while growing mobile surveillance and the misuse of commercial security products create serious challenges for researchers, activists, journalists, and other high-risk users.

Transcript

Hi, I'm here with John Scott-Railton, who is a senior researcher at Citizen Lab. Hey, Bruce. Hey, so I'd love you to talk about Citizen Lab a- and the work you do. So we're like, um, this group based at the University of Toronto. We're academically independent, and we're interested in tracking targeted attacks against civil society. So this basical... Read More

Key Insights

  • Citizen Lab is an academically independent research group based at the University of Toronto that tracks targeted attacks against civil society. Its investigations provide security support for people and organizations that cannot pay, while revealing attacks associated with significant state interest.
  • Civil society groups are valuable sources of threat intelligence because they often attract sophisticated attacks while carrying a heavy burden of risk. Citizen Lab builds relationships with some high-risk groups for a decade or more, enabling researchers to observe threats across extended periods.
  • Citizen Lab is funded entirely by large public foundations, which provides independence from government funding. Its researchers also depend on donated tools and in-kind technical support because the organization cannot afford every capability available to commercial security teams.
  • Citizen Lab combines several forms of work, including close partnerships with high-risk communities, investigations prompted by incoming requests, policy engagement, censorship tracking, and deep technical forensics. Researchers examine compromised devices and analyze evidence to determine how targeted attacks operate.
  • Academic affiliation provides practical protection and credibility as Citizen Lab's work becomes more prominent and attracts threats, including physical threats. It also allows others to treat published findings as academic research and use them independently, rather than viewing them solely as advocacy material.
  • Student participation gives undergraduate and graduate researchers unusually hands-on exposure to important security investigations. Citizen Lab also serves a developmental role by showing future industry professionals why public-interest technical work matters and by maintaining relationships as participants move into other careers.
  • Mobile communication creates growing surveillance risks because phones function as persistent tracking and monitoring devices that emit extensive digital information. Mobile threats can be harder for researchers to track and analyze than computer malware, even when they expose targeted people to greater risks.
  • Technology products can be repurposed after release, regardless of the intentions that guided their development. Developers should consider misuse when commercializing tools, prepare to respond without defensiveness, and engage with civil society to reduce harm when unexpected applications appear.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What does Citizen Lab investigate?

Citizen Lab investigates targeted digital attacks against civil society groups, including attacks affecting high-risk individuals, nongovernmental organizations, and the press. Its work includes technical forensics on computers and other devices, long-term collaboration with frequently targeted communities, analysis of cases submitted by affected people, censorship tracking, policy engagement, and publication of reports that other researchers and organizations can use.

Q: How is Citizen Lab's research funded?

Citizen Lab receives its support entirely from large public foundations. Scott-Railton says this arrangement gives the group a degree of independence from government funding while allowing it to conduct security investigations for people who cannot pay. Because the organization also cannot afford every commercial security capability, donated tools and in-kind support are important parts of its technical work.

Q: How does Citizen Lab find and investigate targeted attacks?

Citizen Lab develops close relationships with high-risk groups, sometimes maintaining those connections for a decade or more. These groups frequently receive suspicious messages or other attacks, giving researchers opportunities to study threats. The lab also investigates cases from people who contact it directly. Researchers then use industry-style forensic methods to examine devices, analyze malicious activity, and determine what happened.

Q: Why are civil society groups important for security research?

Civil society groups often act as an early warning system because they attract substantial interest from states and other powerful actors. Their exposure produces evidence of sophisticated and consequential attacks that might otherwise remain hidden. At the same time, these groups carry a serious burden because they often lack the money, tools, and institutional support needed to investigate threats or protect themselves.

Q: How does academia support Citizen Lab's independence?

Operating in an academic setting gives Citizen Lab independence, credibility, and some protection as its investigations gain attention and generate threats, including physical threats. Academic affiliation also helps distinguish its findings from the work of an advocacy arm. Other organizations can therefore engage with the lab's reports as solid academic research and build their own analysis or action upon the published evidence.

Q: What role do students play at Citizen Lab?

Citizen Lab involves both undergraduate and graduate students in its research. Graduate students participate through the university and its faculty leadership, while interested undergraduates can receive surprisingly hands-on research experience. The lab hopes this early exposure influences people before they enter industry, teaches them the importance of public-interest security work, and creates professional relationships that may continue throughout their careers.

Q: Why are mobile devices a growing surveillance concern?

Mobile devices are a major concern because communication is increasingly moving to phones, which Scott-Railton describes as devices with tracking and monitoring built into their operation. They continually emit digital information that can expose users. Threats targeting mobile systems are also harder to identify and analyze than many computer-based attacks, yet they can create even greater risks for high-risk users.

Q: How should technology developers prepare for product misuse?

Developers should consider potential misuse when they begin commercializing a tool and evaluating its possible applications. They should not assume that their original intentions will remain embedded in the product after release, because tools can be adopted for very different purposes. If harmful uses emerge, developers should avoid defensiveness, engage with civil society, and think seriously about how the product can be improved.

Summary & Key Takeaways

  • Citizen Lab is an academically independent group at the University of Toronto that investigates targeted attacks against civil society. Its researchers work closely with high-risk groups, sometimes for a decade or more, examine cases submitted by affected people, publish reports, track censorship, and engage with policy questions arising from digital surveillance.

  • Large public foundations fund Citizen Lab, helping it remain independent from government funding while serving people who cannot pay for security investigations. Researchers use technical methods comparable to those employed in industry, but limited budgets make donated tools and in-kind support essential. Students and visiting industry professionals also contribute to its work.

  • Scott-Railton identifies mobile devices and major online platforms as growing areas of concern because they concentrate communication while exposing high-risk users to tracking and monitoring. He urges technology developers to anticipate misuse during commercialization, avoid assuming their original intentions will govern a product, and engage constructively with civil society when harms emerge.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚