Hacker-Hit Tibetan Monks 'Detach From Attachments'

Advertisement
By Associated Press | Updated: 11 November 2014 19:50 IST
Hacker-Hit Tibetan Monks 'Detach From Attachments'
Buffeted by persistent cyber-attacks, Tibetan monks are giving new meaning to their ancient creed: Detach from attachments.

"Attachment can lead you to all sort of trouble and we Buddhists believe that non-attachment alone can lead you to happiness," 30-year-old monk Jamyang Palden told The Associated Press at a cafe in the Indian hill town of Dharamsala, before giving the philosophy its Information Age twist: "We have to learn to be suspicious of email attachments."

The Internet safety slogan, one of several messages championed by digital security group Tibet Action Institute, is an example of how human rights defenders are seeking creative ways to protect activists from electronic espionage.

"It's cheesy, but it's memorable," said Freya Putt, a Vancouver-based activist.

There's little doubt that groups like Tibet Action need protection. A major study published Tuesday by Internet watchdog Citizen Lab shows that it and other civil society organizations have been penetrated by cyber-spies, many of them linked to China. And the report says that those behind the compromises are the same hackers responsible for high-profile attacks on major multinationals and Western governments.

Advertisement

(Also See: Notorious Hacktivist Shares Methods, Motives)

"They're using the same weaponry, the same arsenal - indiscriminately," said Citizen Lab director Ronald Deibert.

Advertisement

Deibert's study draws on four years of research with Tibet Action and nine other cooperating civil society groups. Eight are China or Tibet-focused; two are large international human rights organizations.

Altogether the groups forwarded more than 800 suspicious emails to Citizen Lab, an interdisciplinary laboratory based at the University of Toronto's Munk School of Global Affairs. Experts there scanned the emails for malicious software, checked several organizations' networks for intruders, interviewed campaigners and, in the case of one particularly hard-hit human rights organization, combed through half a dozen hard drives.

Advertisement

All 10 groups were compromised at some point during the study, many of them through emails carrying booby-trapped attachments.

In a 2012 attack email shared with the AP, Tibet Action's director Lhadon Tethong was approached by a hacker impersonating a well-known China scholar, asking whether she would proof-read a list of Tibetans who have set themselves on fire in protest against the government in Beijing.

"Would you please have a look and make necessary corrections?" the email asks.

That attack failed - Tethong sensed a trap when she noticed the email did not come from the scholar's professional address - but others succeeded. Deibert said one rights group had its network compromised by "APT1" - a prolific hacking crew whose activities have been tied to the China's People's Liberation Army - for 20 months.

(Also See: US Postal Service Hacked; Employee Information Potentially Breached)

The Chinese Embassy in London did not immediately respond to a message seeking comment on the report. Beijing is often accused of masterminding electronic attacks against an array of targets, including human rights groups. It's a charge it regularly denies.

Most targets of the attacks studied by Citizen Lab are anonymous, something Deibert says is in part because security holes identified by his colleagues remain unpatched. That means the organizations could be at greater risk if their names got out.

Others may simply fear losing face.

"There's still a stigma in some circles around computer breaches of any sort," Deibert said.

That isn't an issue for Tibet Action, whose work is centered on raising awareness about online threats.

The efforts involve comic strips which portray Tibetans being spied through their webcams or their smartphones by glowering Chinese officers with 1950s-style headsets, and a video skit in which "Attachment" - played by a grinning Tibetan amateur - sneaks into a man's home and steals his wallet.

It may be corny but trainer Lobsang Gyatso Sither says the humor works. Sither shows the film and repeats the 'Detach from Attachments' mantra at digital security classes he teaches in classes in Dharamsala and elsewhere.

Palden, the monk, appears to have gotten the point. He tapes over his Mac's webcam, takes the battery out of his Nokia handset when he doesn't want to be tracked and avoids popular Chinese chat program QQ. And he has absorbed the main message: "I do not open attachments from sources I do not trust," he said.

(Also See: US Government Struggling Against Cyber-Attacks)

Deibert says the plight of people like Palden is often lost amid a cyber-security debate which focuses on attacks against Fortune 500 companies and high-powered defense contractors.

"Ironically we are spotlighting the organizations that are the most equipped, that have the most resources and capacity to throw at the problem while leaving aside the organizations that could use the most help," Deibert said.

He said one solution might be for human rights organizations - and their funders - to follow Tibetan Action's example in opening up about the threats they face.

"I'm not a Buddhist," Deibert said, "but groups around the world could learn a lot from the Tibetans."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week: Truth or Trouble, Motorheads, and More
  2. Xiaomi 15s Pro Design, Camera Details Teased Ahead of Launch Today
  3. Motorola Razr 60 Will Launch in India on This Date
  4. Sam Altman Reportedly Drops Clues About 'Secret' AI Device With Jony Ive
  5. Tecno Pova Curve 5G India Launch Date Announced
  6. LinkedIn Is Now Letting Users Search for Ideal Jobs Using GenAI
  7. Mistral's Coding Agent Devstral Outperforms OpenAI's GPT-4.1 Mini
  8. Realme Neo 7 Turbo Launch Date Confirmed; Teased to Run on This New Chipset
  1. SpaceX Successfully Launches 23 Starlink Satellites on Brand-New Falcon 9 Rocket
  2. Polaris Wasn’t Always the North Star: How Earth’s Wobble Shifts the Celestial Pole
  3. Scientists Warn of Inadequate Solar Storm Forecasting: What You Need to Know
  4. NASA’s Perseverance Explores Mars' Oldest Rocks in Krokodillen Region
  5. New Study Uses AI to Reveal Dry Origins of Mars’ Mysterious Slope Streaks
  6. Ancient 14,000-Year-Old Solar Storm Revealed as Strongest Ever Recorded in Earth’s History
  7. New Study Confirms TeV Halos Are Common in Middle-Aged Pulsars
  8. Capuchin Monkeys Abduct Baby Howler Monkeys on Panama’s Jicarón Island, New Study Reveals
  9. Sneaky Links: Dating After Dark Now Streaming on Netflix: What You Need to Know
  10. Devika & Danny OTT Release Date Revealed: When and Where to Watch It Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.