Security

FSI scholars produce research aimed at creating a safer world and examing the consequences of security policies on institutions and society. They look at longstanding issues including nuclear nonproliferation and the conflicts between countries like North and South Korea. But their research also examines new and emerging areas that transcend traditional borders – the drug war in Mexico and expanding terrorism networks. FSI researchers look at the changing methods of warfare with a focus on biosecurity and nuclear risk. They tackle cybersecurity with an eye toward privacy concerns and explore the implications of new actors like hackers.

Along with the changing face of conflict, terrorism and crime, FSI researchers study food security. They tackle the global problems of hunger, poverty and environmental degradation by generating knowledge and policy-relevant solutions. 

News Type
Q&As
Date
Paragraphs

This interview with CISAC Affiliate Christopher Painter was originally produced by Jen Kirby. The complete article is available at Vox.

The frequency, scope and scale of ransomware attacks against public and private systems is accelerating. In the latest incident, the ransomware group REvil has demanded $70 million to unlock the systems of the software company Kaseya, an attack that affects not only Kaseya, but simultaneously exploits all of the company’s clients.

The REvil, JBS meatpacking and Colonial Pipeline attacks have abruptly raised the profile of ransomware from a malicious strand of criminality to a national security priority. These are issues that Christopher Painter, an affiliate at the Center for International Security and Cooperation (CISAC), has worked on at length during his tenures as a senior official at the Department of Justice, the FBI, the National Security Council and as the world's first top cyber diplomat at the State Department.

Jen Kirby, a reporter for Vox, interviewed Painter to discuss how cybercrimes are evolving and what governments should do to keep ransomware attacks from escalating geopolitical tensions online and off.



Jen Kirby:
I think a good place to start would be: What are “ransomware attacks”?

Christopher Painter:
It is largely criminal groups who are getting into computers through any number of potential vulnerabilities, and then they essentially lock the systems — they encrypt the data in a way that makes it impossible for you to see your files. And they demand ransom, they demand payment. In exchange for that payment, they will give you — or they claim, they don’t always do it — they claim they’ll give you the decryption keys, or the codes, that allow you to unlock your own files and have access to them again.

That is what traditionally we say is “ransomware.” That’s been going on for some time, but it’s gotten much more acute recently.

There is another half of that, which is that groups don’t just hold your files for ransom, they either leak or threaten to leak or expose your files and your information — your secrets and your emails, whatever you have — publicly, either in an attempt to embarrass you or to extort more money out of you, because you don’t want those things to happen. So it’s split now into two tracks, but they’re a combined method of getting money.

Jen Kirby:
We’ve recently had some high-profile ransomware attacks, including this recent REvil incident. Is it that we’re seeing a lot more of them, or they’re just bigger and bolder? How do you assess that ransomware attacks are becoming more acute?

Christopher Painter:
We’ve seen this going on for some time. I was one of the co-chairs of this Ransomware Task Force that issued a report recently. One of the reasons we did this report was we’re trying to call greater attention to this issue. Although governments and law enforcement were taking it seriously, it wasn’t being given the kind of national-level priority it deserved.

It was being treated as more of an ordinary cybercrime issue. Most governments’ attention is focused on big nation-state activity — like the SolarWinds hack [where suspected Russian government hackers breached US government departments], which are important, and we need to care about those. But we’re very worried about this, too.

It’s especially become more of an issue during the pandemic, when some of the ransomware actors were going after health care systems and health care providers.That combined with these big infrastructure attacks — the Colonial Pipeline clearly was one of them. Another one was the meat processing plants. Another one was hospital systems in Ireland. You also had the DC Police Department being victimized by ransomware. These things are very high-profile. When you’re lining up for gas because of a ransomware attack, and you can’t get your food because of a ransomware attack, that brings it home as a priority. And then, of course, you have what happened this past weekend. So ransomware has not abated, and it continues to get more serious and hit more organizations.

painter

Christopher Painter

Affiliate at the Center for Internatial Security and Cooperation (CISAC)
Full Profile

Read More

Hero Image
Ransomware locks up digital data until a fee is paid to the hackers. Getty Images
All News button
1
Subtitle

Christopher Painter explains why the emerging pattern of ransomware attacks needs to be addressed at a political level – both domestically and internationally – and not be treated solely as a criminal issue.

Paragraphs

The first COVID-19-related death in the United States was announced on February 29, 2020, the day of the South Carolina primary. International news about the early spread of the coronavirus and the initial reaction from American public health professionals to its quick spread in this country made it clear that the presidential election was facing an existential threat. Election officials who held primaries in early- and mid-March found themselves increasingly making public health decisions to guard both their voters and their staff. The larger societal challenges quickly overwhelmed the ability of states to hold primaries at all, leading to hastily canceled and postponed elections. The one early primary that was not postponed, Wisconsin, provided cautionary tales in the form of closed polling places, poll worker shortages, and massive transitions to mail balloting.

 

Nate Persily

Nathaniel Persily

James B. McClatchy Professor of Law at Stanford Law School | Senior Fellow, Freeman Spogli Institute | Professor, by courtesy, Political Science | Professor, by courtesy, Communication | Co-director, Cyber Policy Center
FULL BIO
All Publications button
1
Publication Type
Working Papers
Publication Date
Subtitle
A Compendium of Research from the Stanford-MIT Healthy Elections Project
Authors
Authors
News Type
News
Date
Paragraphs

Today, the Healthy Elections Project, a joint effort of Stanford and MIT, released a new 800 page report based on their research and findings on the administration of the 2020 election. The Stanford-MIT Healthy Elections Project was developed to ensure that the 2020 election could proceed with integrity, safety, and equal access. The Project aimed to do this by bringing together academics, civic organizations, election administrators, and election administration experts to assess and promote best practices. 

The first COVID-19-related death in the United States was announced on February 29, 2020, the day of the South Carolina primary. International news about the early spread of the coronavirus and the initial reaction from American public health professionals to its quick spread in this country made it clear that the presidential election was facing an existential threat. Election officials who held primaries in early- and mid-March found themselves increasingly making public health decisions to guard both their voters and their staff. The larger societal challenges quickly overwhelmed the ability of states to hold primaries at all, leading to hastily canceled and postponed elections. The one early primary that was not postponed, Wisconsin, provided cautionary tales in the form of closed polling places, poll worker shortages, and massive transitions to mail balloting.

Nate Persily

Nathaniel Persily

James B. McClatchy Professor of Law at Stanford Law School | Senior Fellow, Freeman Spogli Institute | Professor, by courtesy, Political Science | Professor, by courtesy, Communication | Co-director, Cyber Policy Center
FULL BIO
Hero Image
virus and the vote
All News button
1
Subtitle

A Compendium of Research from the Stanford-MIT Healthy Elections Project

Paragraphs

Whether the targets are local governmentshospital systems, or gas pipelines, ransomware attacks in which hackers lock down a computer network and demand money are a growing threat to critical infrastructure. The attack on Colonial Pipeline, a major supplier of fuel on the East Coast of the United States, is just one of the latest examples—there will likely be many more. Yet the federal government has so far failed to protect these organizations from the cyberattacks, and even its actions since May, when Colonial Pipeline was attacked, fall short of what’s necessary.

Read more 

All Publications button
1
Publication Type
Commentary
Publication Date
Subtitle
Op-ed in Bulletin of the Atomic Scientists, by Gregory Falco and Sejal Jhawer
Authors
-

Image
German Consulate logo and Stanford Logo

Technological cooperation is one of the key topics of the transatlantic agenda. The capacity of nations to innovate and to regulate will define impact their future relevancy. Beyond setting incentives to enhance innovation, Regulation and setting standards is at the forefront of the geopolitical dimension of tech policy.
 
On June 24 from 12:00 to 1:00 pm Pacific Time, Germany’s Ambassador to the United States, Dr. Emily Haber, International Policy Director at Stanford University’s Cyber Policy Center, Marietje Schaake, and Chris Riley, Senior Fellow for Internet Governance at the R Street Institute, will discuss the opportunities and challenges of the digital transformation for the US and the EU with respect to strategies to strengthen democratic public spheres, restore digital trust and promote liberal liberal-democratic values through a global digital order. Nathanial Persily, co-director of the Stanford Cyber Policy Center, will introduce and moderate the event.
 
This event is part of the series “Meeting America,” virtual talks with the German Ambassador and American stakeholders across the United States.
 
This event is co-sponsored by the German Consulate General San Francisco and the American Council on Germany.

REGISTER

 

About the Speakers

 

Dr. Emily Margarethe Haber has been German Ambassador to the United States since June 2018.   Prior to her transfer to Washington, DC, she served in various leadership functions at the Foreign Office in Berlin. In 2009, she was appointed Political Director and, in 2011, State Secretary, the first woman to hold either post. Thereafter, she was deployed to the Federal Ministry of the Interior, serving as State Secretary in charge of homeland security and migration policy from 2014 until 2018.   Emily Haber has many years of experience with Russia and the former Soviet Union. She held various posts at the German Embassy in Moscow, including Head of the Political Department. At the Foreign Office in Berlin, she served as Head of the OSCE Division and as Deputy Director-General for the Western Balkans, among other positions.   Emily Haber holds a PhD in history and is married to former diplomat Hansjörg Haber. The couple has two sons.

Chris Riley is R Street’s senior fellow of Internet Governance. He will be leading the Knight Foundation-funded project on content moderation, running convenings of a broad range of stakeholders to develop a framework for platforms managing user-generated content. Chris will also be doing policy analysis around content regulatory issues related to that project, including work on Section 230 in the United States and the Digital Services Act in the European Union.

Prior to joining R Street, Chris led global public policy work for the Mozilla Corporation, managing their work on the ground in Washington, D.C., Brussels, Delhi and Nairobi from Mozilla’s San Francisco office, and worked with government policymakers, stakeholders in industry and civil society, and internal teams at Mozilla to advance their mission. Prior to that, he worked in the U.S. Department of State to help manage the Internet Freedom grants portfolio designated by Congress to support technology development, digital safety training, research and related work as a part of advancing the expression of human rights online in internet-repressive countries.

Chris received his bachelor’s in computer science from Wheeling Jesuit University, his PhD in computer science from Johns Hopkins University and his JD from Yale Law School.

Nathaniel Persily is the James B. McClatchy Professor of Law at Stanford Law School, with appointments in the departments of Political Science, Communication, and FSI.

Marietje Schaake is the International Policy Director at Stanford University’s Cyber Policy Center and international policy fellow at Stanford’s Institute for Human-Centered Artificial Intelligence. 

 

0
marietje.schaake

Marietje Schaake is a non-resident Fellow at Stanford’s Cyber Policy Center and at the Institute for Human-Centered AI. She is a columnist for the Financial Times and serves on a number of not-for-profit Boards as well as the UN's High Level Advisory Body on AI. Between 2009-2019 she served as a Member of European Parliament where she worked on trade-, foreign- and tech policy. She is the author of The Tech Coup.


 

Non-Resident Fellow, Cyber Policy Center
Fellow, Institute for Human-Centered Artificial Intelligence
Date Label
Emily Margarethe Haber
Chris Riley
-

Image
the trump takedown

The Facebook Oversight Board will release its decision concerning the takedown of President Donald Trump's account this Wednesday. On Thursday, May 6, from 2:00 to 3:15 PM Pacific, members of the Oversight Board will be joined by the leaders of the Stanford Cyber Policy Center to discuss the Board's decision. Two members of the Oversight Board, Michael McConnell and Julie Owono, will be joined by Nate Persily, Renee DiResta, Daphne Keller, Marietje Schaake and Alex Stamos to discuss the decision and its implications for Facebook's handling of similar controversies around the world.

-

Image
this is how they tell me the world ends event at cyber policy center

On Wednesday, May 26 at 10 am pacific time, please join Andrew Grotto, Director of Stanford’s Program on Geopolitics, Technology and Governance, for a conversation with Nicole Perlroth, New York Times Cybersecurity Reporter, about the underground market for cyber-attack capabilities.

In her book This Is How They Tell Me the World Ends: The Cyberweapons Arms Race,” Perlroth argues that the United States government became the world's dominant hoarder of one of the most coveted tools in a spy's arsenal, the zero-day vulnerability. After briefly cornering the market, in her account, the United States then lost control of its hoard and the market.

Perlroth and Grotto, a former Senior Director for Cybersecurity Policy at the White House in both the Obama and Trump Administrations, will talk about the development and evolution of this market, and what it portends about the future of conflict in cyberspace and beyond.

This event is co-sponsored by the Freeman Spogli Institute for International Studies and the Cyber Policy Center.

Praise for “This Is How They Tell Me the World Ends”: “Perlroth's terrifying revelation of how vulnerable American institutions and individuals are to clandestine cyberattacks by malicious hackers is possibly the most important book of the year . . . Perlroth's precise, lucid, and compelling presentation of mind-blowing disclosures about the underground arms race a must-read exposé.” —Booklist, starred review

Nicole Perlroth
-

A new administration and Congress provide a key opportunity to improve US cybersecurity and the governance of digital technologies. Yet the challenges appear daunting: viral disinformation, widespread privacy violations, algorithms biased by race, class and gender, ransomware running rampant, and unprecedented tech company scale and market dominance. Additionally, the US faces a persistent deficit in skilled cybersecurity workers, a lack of diversity in the field, and a public with wildly unequal broadband internet access.  Meanwhile, competition among governance regimes, specifically between the United States, Europe and China, has raised the stakes over whether democracies or authoritarian governments will set the rules for the internet. The policy choices made by the new administration will play a pivotal role in shaping our global future. On February 24 at 10am PST, join Kelly Born and Marietje Schaake of Stanford’s Cyber Policy Center, Michael Daniel of the Aspen Institute’s Cyber Group, and Karen Kornbluh for the German Marshall Fund to discuss cyber policy priorities for the new administration.

 

0
marietje.schaake

Marietje Schaake is a non-resident Fellow at Stanford’s Cyber Policy Center and at the Institute for Human-Centered AI. She is a columnist for the Financial Times and serves on a number of not-for-profit Boards as well as the UN's High Level Advisory Body on AI. Between 2009-2019 she served as a Member of European Parliament where she worked on trade-, foreign- and tech policy. She is the author of The Tech Coup.


 

Non-Resident Fellow, Cyber Policy Center
Fellow, Institute for Human-Centered Artificial Intelligence
Date Label
Karen Kornbluh
Michael Daniel
Seminars
0
Matt Masterson

Matt Masterson is a former non-resident policy fellow with the Stanford Internet Observatory. He served as Senior Cybersecurity Advisor at the Department of Homeland Security, where he focused on election security issues. He previously served as a Commissioner at the Election Assistance Commission from December 2014 until March 2018, including serving as the Commission’s Chairman in 2017-2018. Prior to that, he held staff positions with the Ohio Secretary of State’s office, where he oversaw voting-system certification efforts and helped develop an online voter registration system. Matt holds a law degree from the University of Dayton School of Law and BS and BA degrees from Miami University in Oxford, Ohio.

As part of his Stanford Internet Observatory fellowship, Matt compiled and published an oral history of the 2020 election, "The Guardians of Democracy."

Former Non-Resident Fellow, Stanford Internet Observatory
-

What rules for the web? That question has been given new urgency on January 6th. The European Union, at the end of 2020, proposed the Digital Services Act (DSA). This new legislation aims at creating clarity about the responsibility of tech platforms and intermediaries. European rules, just as the General Data Protection Regulation (GDPR) did, will likely have ripple effects worldwide. Is there room for transatlantic alignment? How do values translate into enforceable rules? Can fundamental rights and economic growth go hand in hand? And who keep the gatekeepers in check? We will dive into the proposed Digital Services Act with leading European experts.

Join Stanford Cyber Policy Center's Marietje Schaake, International Policy Director and former Member of European Parliament in conversation with the CPC’s Daphne Keller, Director of the Center for Internet and Society, Guillermo Beltrà Navarro, European Union’s Digital Policy Lead, Eliška Pírková, Access Now’s Europe Policy Analyst and Joris van Hoboken, Professor of Law at the Vrije Universiteit Brussels.

 

0
top_pick_rsd25_070_0254a.jpg

Daphne Keller is the Director of Platform Regulation at the Stanford Program in Law, Science, & Technology. Her academic, policy, and popular press writing focuses on platform regulation and Internet users'; rights in the U.S., EU, and around the world. Her recent work has focused on platform transparency, data collection for artificial intelligence, interoperability models, and “must-carry” obligations. She has testified before legislatures, courts, and regulatory bodies around the world on topics ranging from the practical realities of content moderation to copyright and data protection. She was previously Associate General Counsel for Google, where she had responsibility for the company’s web search products. She is a graduate of Yale Law School, Brown University, and Head Start.

SHORT PIECES

 

ACADEMIC PUBLICATIONS

 

POLICY PUBLICATIONS

 

FILINGS

  • U.S. Supreme Court amicus brief on behalf of Francis Fukuyama, NetChoice v. Moody (2024)
  • U.S. Supreme Court amicus brief with ACLU, Gonzalez v. Google (2023)
  • Comment to European Commission on data access under EU Digital Services Act
  • U.S. Senate testimony on platform transparency

 

PUBLICATIONS LIST

Director of Platform Regulation, Stanford Program in Law, Science & Technology (LST)
Social Science Research Scholar
Date Label
0
marietje.schaake

Marietje Schaake is a non-resident Fellow at Stanford’s Cyber Policy Center and at the Institute for Human-Centered AI. She is a columnist for the Financial Times and serves on a number of not-for-profit Boards as well as the UN's High Level Advisory Body on AI. Between 2009-2019 she served as a Member of European Parliament where she worked on trade-, foreign- and tech policy. She is the author of The Tech Coup.


 

Non-Resident Fellow, Cyber Policy Center
Fellow, Institute for Human-Centered Artificial Intelligence
Date Label
Guillermo Beltrà Navarro
Joris van Hoboken
Eliška Pírková
Subscribe to Security