Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 


advertise-here4


Slip Opinions


Most under-appreciated thing about Warren Buffett: he built Berkshire to last well beyond him.  (LAC, at BRK annual meeting via Motley Fool, here.)

University governance as a new topic of public discussion.

An unusual profile of Mary Anne Franks (kw)

Aggressive copyright litigation run amok. (fp)

USA Today's Matt Krantz quoting me on Warren Buffett joining Twitter.  (LAC)

Private prisons? Why, sure! What could possibly go wrong? (kw)

TNR profiles Susan Crawford (kw)

Berkshire Hathaway is bigger than Warren Buffett.  Manual of Ideas (LAC).

Guns don't shoot people, kitchen appliances shoot people (kw)

Via Glom, Sat Eve Post review of The Essays of Warren Buffett.


Our Podcast

Subscribe to Law Talk


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments


    • Orin Kerr on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • David Schwartz on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • Matt on Is Berkshire Hathaway Really a Psychology Experiment?

    • Orin Kerr on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • Guy Spier on Is Berkshire Hathaway Really a Psychology Experiment?

    • Griff on The Varying Use of Legal Scholarship by the U.S. Supreme Court across Issues

    • John Mihaljevic on Warren Buffett: Practical Philosopher of Capitalism

    • Patrick S. O'Donnell on Warren Buffett: Practical Philosopher of Capitalism

    • Arthur Clarke on Mr. Buffett Joins a Board

    • Patrick S. O'Donnell on Warren Buffett: Practical Philosopher of Capitalism

    • Matt on Warren Buffett: Practical Philosopher of Capitalism

    • Larry Sheldon on Warren Buffett: Practical Philosopher of Capitalism

    • Personal Injury Lawyer on Privacy Self-Management and the Consent Dilemma

    • Lawrence Cunningham on Mr. Buffett Joins a Board

    • Guy Spier on Mr. Buffett Joins a Board
  •  

    Site Meter

    About the Blog

    Concurring Opinions is a multiple authored, general interest legal blog.

    (Image: Wikicommons)

Sending Out an e-SOS

posted by Dave Hoffman

My colleague Duncan Hollis has a new article up on SSRN, An e-SOS for Cyberspace. In the article, Duncan argues that the “conventional response” to cyberthreats (e.g., hacking, e-espionage, cyberwar, and hacktivistism) isn’t working. Though “cybercrime laws proscribe individuals from engaging in unwanted cyberactivities[, such laws fail because] anonymity is built into the very structure of the Internet. As a result, existing rules on cybercrime and cyberwar do little to deter. They may even create new problems, when attackers and victims assume different rules apply to the same conduct.”  Instead of traditional proscriptive approaches, Duncan proposes that “states adopt a duty to assist victims of the most severe cyberthreats. A duty to assist works by giving victims assistance to avoid or mitigate serious harms. At sea, anyone who hears a victim’s SOS must offer whatever assistance they reasonably can. An e-SOS would work in a similar way. It would require assistance for cyberthreat victims without requiring them to know who, if anyone, was threatening them.”

I read e-SOS in draft and found it fascinating, even though I have little intrinsic interest in international law or cybersecurity issues.  Duncan does a terrific job of storytelling – did you know that the CIA allegedly tampered with the computer control system of a Soviet gas pipeline in 1982, causing the largest non-nuclear explosion in history?  Or that the United States recently rescued North Korean sailors from pirates on receipt of an SOS?  The article is full of such nuggets. And I think the proposal is pretty clever, and borderline workable.  That’s high praise for a law review article.

Anyway, I advise that you download it before some cyberbully manages to hack SSRN and replace it with a trojan horse.  And then come back here, follow me after the jump, and enjoy a classic Police video.



 September 3, 2010 at 8:16 pm   Posted in: Cyberlaw, International & Comparative Law, Privacy (National Security), Web 2.0   Print This Post Print This Post

Responses (9)

  1. Matt Bodie - September 5, 2010 at 9:25 am

    Are you using the video to make a larger meta-point? I like the a-ha homage, but this is the classic video I remember:
    http://www.youtube.com/watch?v=vLFF2P8fInI

  2. dave hoffman - September 5, 2010 at 11:37 am

    No larger point. Just idiocy by me in not checking what I was linking to.

  3. Orin Kerr - September 6, 2010 at 2:04 am

    Thanks for the tip, Dave. I don’t think this approach to deterring computer crimes works, as it seems to be based on assumptions about the physical world that don’t translate to the Internet. I wrote about this approach and its challenges in this short essay, Orin Kerr “Virtual Crime, Virtual Deterrence: A Skeptical View of Self-Help, Architecture, and Civil Liability.” 1 Journal of Law, Economics & Policy 197-214 (2005).

    http://papers.ssrn.com/sol3/papers.cfm?abstract_id=605964

  4. Duncan Hollis - September 6, 2010 at 8:54 am

    As the author, I obviously DO think the idea might work. That said, I do not think any of the assumptions about the physical world that Orin critiqued in his 2005 paper are implicated by the e-SOS idea that I am advocating. On the contrary, my paper is a response to one of those very assumptions (the ability to attribute responsibility) which make it difficult for cybercrime (or self-help or civil liability) to regulate and deter the most severe cyberthreats. An e-SOS, in contrast, works without the victim having to know who attacked them (or even if they were attacked at all); the idea is that when really bad things happen due to a computer error/attack/exploitation, victims can call for help, and get it, whether it’s added bandwidth, blocking traffic, or patching code. Existing cyberthreats are at such a level that cybercrime and security are plainly inadequate. My e-SOS idea offers a general idea that CAN be tailored to cyberspace to supplement these existing responses to an increasingly hostile environment.

  5. dave hoffman - September 6, 2010 at 11:27 am

    Orin,
    Can you say a bit more about how the e-SOS assumes or incorporates notions of physical closeness?

    There is sort of an interesting question about the psychology of the SOS (generally). I bet that some of the reason that the physical SOS works is that the legal duty puts pressure on the bystander effect. Each listener is specifically charged with the responsibility of aiding the victim. The diffusion of responsibility problem is likely to be orders-of-magnitude more severe online. Unlike sailors, surfers on the web don’t really think of themselves as a part of a particular community. So compliance with an e-SOS regime is a difficult problem. Is that what you meant?

  6. Orin Kerr - September 6, 2010 at 1:38 pm

    To explain a bit about what I mean, the argument seems to rest on an analogy between a rescue in cyberspace and a rescue on the high seas — specifically, the case of helping a boat in distress that calls on people nearby to help.

    In that traditional case, the characteristics of the physical world define the duty and tell us whether it is desirable. The issues of who needs to help, and in what cases, and what they have to do, are relatively straightforward. The physical environment provides the answers: It tells us who needs to help (people physically nearby); in what cases (when the threat is serious, which physical clues tell us); and what they have to do (measured based on reasonableness in a physical setting, in which notions of reasonableness are well settled). The physical understandings give us an idea of what the duty is and whether it is desirable and in what circumstances.

    These same questions tend to break down — or at least become extremely complicated — in the digital environment. Take the question of what is a “severe” computer crime. How do you measure that? In the physical world, we know what is a major threat in many cases because we have clear warning signs of cause and effect. That’s particularly true in the traditional “duty to assist” cases. If a boat with 100 people aboard is sinking, we know the severity of the event: 100 lives could be lost if the boat sinks and the people drown. But computer crimes usually don’t give us those sorts of clues. For example, imagine I have a hacker in my network. Is that a severe problem? It’s hard to know. The hacker could be harmless or harmful, and I don’t know his intent unless I know who he is. But I normally won’t know who he is. How do you measure the severity of the event?

    The same goes for who is supposed to help. In the physical world, like the case of a disabled or sinking boat, the answer is whoever is nearby. Physical proximity is key. But physical proximity is no longer a reliable guide to who can help in the case of a computer crime. Network crimes can be from anywhere and to anywhere — they can involve traffic going through dozens of countries at once. The paper suggests that the duty could be limited to those in “the territorial jurisdiction(s) within which the threat lies.” But what is the territorial jurisdiction in which the threat lies? Is that where the known victim is? Is that the jurisdiction in which the IP address of the attacks seem to be originating? What to do if the question of who can realistically help as a technological matter is no longer necessarily connected to who is physically nearby?

  7. Duncan Hollis - September 7, 2010 at 4:18 pm

    I’ve posted some comments in reaction to Orin and Dave’s questions over at Opinio Juris — see http://opiniojuris.org/2010/09/07/an-e-sos-for-cyberspace/

  8. AnonSecurityGuy - September 9, 2010 at 7:36 pm

    I couldn’t download it from SSRN; SSRN doesn’t work for me, for some reason. (Maybe too much fancy Javascript technology.)

    I’m trying to imagine how this could work. How does this scale? If one victim sends out an eSOS, do all 4 billion people in the world have to help out that victim? If not, how do we tell who is obligated to help? What help are they obligated to provide, and what are the limits on the extent of the help their obligations? How does it scale when there are hundreds of millions of victims? Keep in mind that some people estimate that ~ 30% of PCs are infected with malware, spyware, or other unwanted software, at any given time. That’s an awful lot of victims.

    As Orin says, there is no clear notion of proximity for electronic crime, so it’s not clear how the “SOS on the high seas” analogy transfers to electronic crime.

  9. Duncan Hollis - September 12, 2010 at 1:25 pm

    Obviously, there’s a scaling issue; my paper thus specifically talks about the need to limit
    1) which threats would qualify for an e-SOS (i.e., those that are severe in terms of timing, scale, and indirect effects),
    2) who can invoke the e-SOS (i.e., whether to limit it to certain targets–like hydorelectric dams or hospitals; or to certain actors like nation states; or whether to allow some broader set of victims to appeal for help);
    3) who will bear the duty (i.e., just nation states, or private actors too; and the additional need to limit the set of duty-bearers in relation to victims, whether by jurisdictional ties; what I call technical proximity; or even tiering assistance in terms of defining first responders, second responders, etc.);
    4) how to call for help; and
    5) what assistance has to be provided (i.e., whether to require assistance in terms of effort, or result; whether to mandate precise technological help or to provide a more general standard, etc.).
    For my further reactions to the physical proximity issue, see my post at Opinio Juris — http://opiniojuris.org/2010/09/07/an-e-sos-for-cyberspace/.

Leave a Reply

Spam protection by WP Captcha-Free


  • « Previous post
  • Next post »

Authors

Daniel J. Solove
Kaimipono Wenger
Dave Hoffman
Frank Pasquale
Deven Desai
Danielle Citron
Lawrence Cunningham
Sarah Waldeck
Jaya Ramji-Nogales
Solangel Maldonado
Gerard Magliocca

Guests

Kelli A. Alces
Taunya Lovell Banks
Ryan Calo
Claire Hill
Jay Kesten
William McGeveran
Meredith Render
Aaron Saiger
David L. Schwartz
Olivier Sylvain
Charles K. Whitehead
Aaron Zelinsky


















Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Marvin Ammori
Michelle Anderson
Laura Appleman
Derek Bambauer
Taunya Lovell Banks
Ann Bartow
Steven Bellovin
Adam Benforado
Gaia Bernstein
Francesca Bignami
Josh Blackman
Joseph Blocher
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Khiara Bridges
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Ryan Calo
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Glenn Cohen
Gabriella Coleman
Jennifer Collins
Caroline Mala Corbin
Thomas Crocker
andré douglas pond cummings
Allison Danner
Laura DeNardis
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
Maxine Eichner
Jessica Erickson
David Fagundes
Lisa Fairfax
Joshua Fairfield
Christine Haight Farley
Kim Ferzan
Dan Filler
Mary Anne Franks
Susan Freiwald
Michael Froomkin
Amanda Frost
Brian Frye
Timothy Glynn
Rachel Godsil
Eric Goldman
Kyle Graham
David Gray
Craig Green
Tristin Green
Jonathan Hafetz
Vivian E. Hamilton
Meredith Harbach
Michelle Harner
Angela Harris
Jeffrey Harrison
Hosea Harvey
Erica Hashimoto
Jennifer Hendricks
Carissa Hessick
Laura Heymann
Robert Hillman
Gilbert A. Holmes
Nicole Huberfeld
Christine Hurt
Darian Ibrahim
Sherrilyn Ifill
John Ip
Shavar Jeffries
Kevin Johnson
Kristin Johnson
Jeff Jonas
Courtney Joslin
Dan Kahan
Jeffrey Kahn
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Alicia Kelly
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Alex Kreit
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Youngjae Lee
Margaret Lewis
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Matthew Lister
Joseph Liu
Michael Madison
Tayyab Mahmud
Kevin Noble Maillard
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Viva Moffat
Scott Moss
Eric Muller
Janai Nelson
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Angela Onwuachi-Willing
David Opderback
David Orentlicher
Michael O'Shea
Kristen Osenga
Mary-Rose Papandrea
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
Michael J. Pitts
Marc Poirier
David Post
Amanda Pustilnik
Shruti Rana
Geoffrey Rapp
William Reynolds
Neil Richards
Lori Ringhand
Alice Ristroph
Marc Roark
Brishen Rogers
Sasha Romanosky
Tuan Samahon
Susan Scafidi
David Schleicher
David Schraub
Paul Secunda
Lea Shaver
Jonathan Siegel
Jessica Silbey
Peter Smith
Judd Sneirson
Adam Steinman
Charles Sullivan
Rick Swedloff
Peter Swire
Olivier Sylvain
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Joseph Turow
Steve Vladeck
Ari Waldman
Spencer Weber Waller
Howard Wasserman
Melissa Waters
Elizabeth A. Wilson
Frank Wu
Alfred Yen
Corey Yung
David Zaring
Timothy Zick
Michael Zimmer
Jonathan Zittrain

Ownership

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Blogroll

Above the Law
Access to Justice
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Derechoalderecho
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Just Books
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
Privacy and Security Training
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
TeachPrivacy Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress