In Cyber-Attacks Such as Sony Hack, Obama Turns to 'Name and Shame'

Advertisement
By Reuters | Updated: 15 January 2015 16:00 IST
The unusually destructive cyber-attack on Sony Pictures Entertainment is providing an early test of a new Obama administration policy to reveal more of what it knows or suspects about hacking campaigns.

President Barack Obama's decision last month to blame North Korea for the breach capped a year that saw the U.S. Justice Department file indictments against alleged Russian cybercriminals, as well as accuse five Chinese army officers of stealing trade secrets.

The increased finger pointing is part of a broad new U.S. plan for responding to cyber-attacks, setting the stage for retaliation such as sanctions or trade complaints, according to current and former government officials.

"We need to improve our defenses, but we also need to make clear the consequences," John Carlin, who heads the Justice Department's national security division, told Reuters.

Advertisement

Carlin, 41 but often mistaken for younger, has been at the center of the policy shift. He worked at the Federal Bureau of Investigation as the agency created a new cyber-investigative task force, rising to be chief of staff to FBI Director Robert Mueller. Carlin was appointed assistant attorney general for national security last year, and has put cyber-threats at the top of his agenda.

Advertisement

The decision to blame North Korea was made easier by Pyongyang's pariah status and the seriousness of the attack - data was destroyed, not just stolen. Eight weeks after the breach, Sony Pictures' computer network still has not been fully restored.

Carlin said U.S. prosecutors are considering whether they can bring indictments related to the Sony attack. North Korea has denied orchestrating the breach.

Advertisement

Former FBI cybercrime chief Shawn Henry said the recent comments by Obama and other U.S. officials on Sony are an attempt to define the "red lines" in cyberspace.

"The destruction of physical property is not acceptable, and the U.S. can take steps to demonstrate what the response is going to be," said Henry, now an executive at private security firm CrowdStrike.

Advertisement

Critics of the new tack
The U.S. government used to remain officially silent over similar cyber-attacks, including one in August 2012 that damaged 30,000 computers at Saudi Arabia's national oil company and was widely believed to have been orchestrated by Iran.

U.S. officials say they have changed tack because of continuing, serious intrusions; improved ability to pinpoint those responsible; and a desire to educate the public and companies about the problem's seriousness.

The strategy is not without critics. Some security experts who looked at the evidence the FBI made public about the Sony hack said none of it proved North Korean involvement, prompting FBI Director James Comey last week to provide a forceful defense and supply new data pointing to Pyongyang.

Even if the claim turns out to be correct, the effects of the "name and shame" campaign remain unclear. Obama's public response so far has been to slap sanctions on North Korea that appear unlikely to have much effect on the insular country.

The U.S. strategy could also prompt other states to point the finger at Washington for hacks in their own countries.

"Doing indictments once a year - I don't see the point," said Jason Healey of the Atlantic Council, a former White House director of infrastructure protection. "Naming and shaming might work, but not as a one-off. We need a campaign."

The new policy has meant wresting some control of the issue from U.S. intelligence agencies, which are traditionally wary of revealing much about what they know or how they know it.

Intelligence officers initially wanted more proof of North Korea's involvement before going public, according to one person briefed on the matter. A step that helped build consensus was the creation of a team dedicated to pursuing rival theories - none of which panned out.

Steel foundation
Joel Brenner, a former head of U.S. counterintelligence and then a top lawyer at the National Security Agency, said there is a growing view that cyber-attacks should be prosecuted like any other type of crime. "We're putting less emphasis on the cyber characteristic and more emphasis on the fact that they are just criminal and that they shouldn't be treated differently."

Among the first people to recognize this trend was David Hickton, who became the top U.S. prosecutor in Pittsburgh in 2010 and set up a new cyber-national security unit. Other prosecutors questioned whether the group would have any cases, but a breakfast meeting with the heads of U.S. Steel Corp and the United Steelworkers in 2010 provided an unexpected tip.

Complaints that information stolen through cyber-attacks could prove deeply harmful spurred an investigation that led to the May 2014 indictment of five Chinese army officers, who were accused of spying on U.S. Steel, the union, and others.

"We were really interested in doing more than just monitoring hacking, we were interested in preventing it, which might include prosecuting it," Hickton said.

It is unclear what the indictment accomplished, however. The Chinese officers are beyond the reach of U.S. law, and security companies say they have seen no reduction in Chinese hacking. Beijing withdrew from Sino-American talks on cyber-security to protest the U.S. charges.

Still, the previous cases laid the foundation for the response to the Sony breach. In 2012, the Justice Department started training prosecutors in technology issues, and the FBI began giving them more in-depth information about cyber-attacks.

Weeks before the Sony attack, Carlin restructured his division to create a top position specifically focused on cyber-security, a change he said was critical in the Sony response.

Carlin said the new policy has sparked more conversations with companies about hacking incidents. He met last week in New York with security officers and lawyers from six banks and a hedge fund to discuss cyber-security risks and defenses, following a similar gathering with general counsels from Fortune 100 companies.

"We need to do something to make it stop," Carlin said.

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 15T Arrives on Geekbench With 12GB of RAM and This MediaTek SoC
  2. Realme 15T 5G India Launch Today: All You Need to Know
  3. Oppo Enco Buds 3 Pro Available for Purchase in India: See Price, Offers
  4. Apple Marks iPhone 8 Plus as Vintage Alongside These MacBook Models
  5. Samsung Galaxy Z TriFold Could Launch Alongside XR Headset on This Date
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.