How Can Society Secure the World-Sized Web?

TL;DR
Securing the world-sized web requires protecting the integrity and availability of connected systems, not only the confidentiality of their data. As sensors, cloud analytics, algorithms, and actuators gain control over vehicles and infrastructure, digital attacks can cause physical harm, while centralized platforms can magnify the power of governments and corporations.
Transcript
Distinguished guests, friends from the media, ladies and gentlemen, good afternoon and a warm welcome to day two of RSA Conference 2016, Asia Pacific and Japan. To start off Thursday's keynotes, please welcome to the stage Chief Technology Officer Resilient and IBM company, and security technologist, Mr. Bruce Schneier. Hello. Hello. All right. Now... Read More
Key Insights
- The Internet of Things consists of sensors that collect environmental data, computational systems that interpret it, and actuators that affect the physical world. These components function like the eyes, brain, hands, and feet of an internet that can sense, think, and act.
- The world-sized web is a convergence of mobile, cloud, and persistent computing with personal-data databases, cyber-physical systems, algorithms, autonomy, and artificial intelligence. Its capabilities arise from interconnection rather than from every individual component possessing sophisticated intelligence.
- Security failures in cyber-physical systems can threaten life and property because connected technologies act directly upon flesh, blood, steel, and concrete. The consequences therefore extend beyond unauthorized disclosure of information to manipulated behavior, interrupted operation, damaged infrastructure, and physical injury.
- Integrity and availability threats can become more serious than confidentiality threats when computers control physical systems. Vehicle ransomware illustrates an availability attack, while manipulating data so vehicles collide illustrates an integrity attack with consequences far beyond the compromise of stored information.
- A modern car is a distributed network of roughly 20 to 40 computers combined with wheels and an engine. Its navigation system, microphone, emissions controls, remote stopping capabilities, and traffic-management functions create competing demands involving privacy, safety, public authority, personal control, and resistance to hacking.
- Self-driving cars could address the 32,000 annual automobile deaths cited for the United States, but they also introduce privacy, tracking, hacking, denial-of-service, and data-integrity risks. Society must balance the anticipated safety benefit against the dangers of handing transportation control to automated algorithms.
- Security is an arms race because attackers and defenders repeatedly adapt to each other's techniques. Click fraud and detection, advertising blockers and countermeasures, credit-card fraud controls, and spam filtering demonstrate how technological advances continually shift which side temporarily holds an advantage.
- New technologies initially benefit quick and loosely organized groups because they can adopt tools rapidly, while governments and corporations possess more raw power to magnify after they adapt. Centralized infrastructure currently favors traditional institutions by enabling platform restrictions and making bulk surveillance easier.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is the world-sized web?
The world-sized web is an interconnected technological system that senses, thinks, and acts. It combines mobile computing, cloud computing, persistent computing, large databases of personal information, the Internet of Things, cyber-physical systems, algorithms, autonomy, and movement toward artificial intelligence. Its sensors observe the environment, its networked computation interprets data, and its actuators affect physical conditions.
Q: How does the Internet of Things sense, think, and act?
The Internet of Things uses three broad components. Sensors collect information about the environment, including smartphone locations and conditions detected by smart thermostats, light bulbs, streets, and highways. Processing systems, often located in the cloud, analyze that information through memory, data, algorithms, and analytics. Actuators then perform actions, such as adjusting temperatures, driving vehicles, or delivering packages.
Q: Why are integrity and availability critical for connected systems?
Integrity and availability are critical because connected systems can directly affect the physical world. An integrity attack can manipulate information and cause machines to behave dangerously, such as making vehicles drive into one another. An availability attack can prevent a system from working, as illustrated by ransomware disabling a car. Both can threaten life, property, and infrastructure.
Q: What security risks do modern connected cars create?
Modern cars create security risks because they are distributed networks containing roughly 20 to 40 computers. Attackers could exploit navigation data for road surveillance, use microphones for eavesdropping, bypass emissions requirements, remotely stop vehicles, deploy ransomware, or manipulate driving data. Capabilities intended for safety or traffic efficiency can also enable hacking or social control.
Q: What trade-offs arise from remotely stopping a car?
Remote stopping could allow police to end dangerous high-speed pursuits safely, creating a potential public-safety benefit. The same capability could also be exploited by a hacker to disable a vehicle. This illustrates a central security problem: a powerful function may support legitimate authority and safety while simultaneously creating an avenue for malicious control and availability attacks.
Q: How could self-driving cars improve safety while creating new risks?
Self-driving cars are presented as a way to eliminate almost all of the 32,000 annual automobile deaths cited for the United States. Achieving that benefit requires accepting new concerns involving privacy, tracking, malicious hacking, denial of service, and manipulated data. The challenge is transferring transportation control to automated algorithms without sacrificing safety or important freedoms.
Q: Why is cybersecurity described as an arms race?
Cybersecurity is described as an arms race because attackers and defenders continually respond to each other's innovations, with technology changing their relative advantage. Click fraud prompts better fraud detection, advertising blockers prompt blocker detection and countermeasures, and spam techniques prompt improved filters. The amount of visible spam can rise or fall depending on which side temporarily has the upper hand.
Q: How do internet technologies shift power between people and institutions?
Internet technologies initially favor quick, loosely organized actors such as dissidents, criminals, and affinity groups because they can rapidly use new tools for coordination, dissemination, organization, and action. Governments and corporations adopt more slowly, but they possess greater raw power to magnify. Centralized infrastructure can then favor them through platform restrictions, surveillance, and control over permitted activities.
Summary & Key Takeaways
-
The world-sized web emerges from mobile computing, cloud computing, persistent computing, personal-data databases, cyber-physical systems, algorithms, autonomy, and artificial intelligence. Together, these technologies create an internet that can sense conditions, interpret information, make decisions, and act directly upon the physical environment through increasingly interconnected devices and services.
-
Connected systems raise the consequences of security failures because compromised devices can affect life, property, transportation, and infrastructure. In this environment, integrity and availability become especially important. Manipulated information could cause vehicles to collide, while ransomware or denial-of-service attacks could prevent a vehicle or another essential system from operating.
-
Security remains an arms race in which technology changes the balance between attackers and defenders. New communications tools initially empower agile individuals, dissidents, criminals, and other unorganized groups. Once governments and large corporations adopt the same tools, their greater institutional power can be magnified through centralized platforms, surveillance capabilities, and design restrictions.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator