Bruce Gain is an Automotive News Europe correspondent in France.
Volkswagen recently won a court case that stopped computer
scientists from publishing an academic paper revealing the secret codes
used to start luxury cars including Porsches, Audis, Bentleys and
Lamborghinis.
The victory, however, will make carmakers more
vulnerable to hackers because company engineers will have less
information available to help them design more secure in-car systems.
The
academics wanted to add to a collective pool of knowledge that
engineers could use to make systems more secure from attack. By having
as much information as possible about security flaws, engineers are less
prone to make design errors.
The researchers are "white hats,"
meaning that they create hacks to discover how things work, and
ultimately, how to remove security flaws in computer code.
The
"black hats," those who sell hacks on the black market, and their
customers who use the information to steal and defraud their victims,
are probably happy that Volkswagen won its lawsuit. Now the black hats
can sell their hacking tools for even more money.
When a hack that
can be used to exploit a system is not publicly available black hats
usually must pay for it. If it is in the public domain, it is not worth
as much.
Ross Anderson, a security researcher at the University of
Cambridge's computer laboratory department, thinks that VW's court
victory to stop one security flaw from being published won't stop the
bad guys from doing what they are already doing.
In the end, the court case is bad public relations for VW, Anderson wrote in an e-mail reply to questions.
"Now
the world and his dog know not just that their engineering skills are
less than perfect, but that the company is unpleasant and unreasonable
to boot," Anderson wrote. "If they had kept quiet, then [the research
paper VW stopped from being published] would have been one out of
several dozen ... and would probably have got only a few column inches
in obscure specialist publications."
Instead, the case was reported by the Guardian newspaper, the BBC, and other media outlets including Automotive News Europe(for the original story, click here). You can reach Bruce Gain at bgain@crain.com.
Voila ce qui ce passe quand des "journalistes" ne font pas leur boulot et ne respectent pas l'éthique de base du métier. C'est-à-dire que chaque
rumeur doit être vérifiée. Au lieu de voler des « faits » aux autres
journalistes, la source doit être
citée. Ces journalistes n’ont pas respecté ce principe dans ce cas. Les
jeunes dans ces quartiers défavorisés ont assez des problèmes déjà, mais
cette fausse information fait encore plus de dégât.
Ce qui est
encore plus choquant est qu’aucun de ces charlatans ne va être licencié
pour cela. Un support media sérieux les virerait sur le coup. Qu’est ce
que TF1, FranceTVInfo, et Europe1.fr vont faire ?
Voila le lien pour trouver l'article dans Le Nouvel Observateur: http://leplus.nouvelobs.com/contribution/907153-bretigny-sur-orge-comment-les-rumeurs-de-pillages-se-sont-propagees-sur-la-toile.html
Pillages à Brétigny ? D'Europe 1 à la fachosphère, comment la fausse rumeur s'est propagée
LE PLUS. Les victimes de l'accident de train de Brétigny-sur-Orge ont-elles été dépouillées
? Depuis hier, les réseaux sociaux ne parlent que de ça : des jeunes
auraient profité du drame pour agresser et voler des personnes sur
place. Comment ces rumeurs ont-elles pris autant d'ampleur ? Décryptage
de Mathieu Géniole.
Les secours et les personnels de sécurité se rendent en gare de Brétigny-sur-Orge suite à l'accident de 12/07/13 (M.EULER/SIPA)
C'était donc faux : ce matin, la préfecture de l'Essonne a démenti à Metronewsdes rumeurs qui circulaient depuis hier sur les réseaux sociaux.
Non, les forces de l'ordre n'ont pas été caillassées après le
déraillement du train. Non, les victimes (et notamment les cadavres)
n'ont pas été pillées. Il n'y a eu, selon la préfecture, qu'un acte de
vol isolé et une ambiance "rude".
Cette version a depuis été confirmée par les sauveteurs dépêchés sur place. Mais alors comment se sont propagées ces rumeurs plus sordides les unes que les autres ?
Quand deux informations "exagérées" se croisent
Il y a deux informations démenties ce matin par la préfecture. Hier,
peu après le déraillement du train, "Le Parisien" rapportait un vol de
portable sur des membres du SAMU et un caillassage des pompiers. L'information apparaît dans le live consacré à l'accident aux alentours de 19h30, y restera, mais ne fera pas l'objet de développements complémentaires.
C'est cette information qui est considérée comme "exagérée" par la
préfecture : elle a été massivement reprise hier soir par d'autres sites
d'informations, comme TF1 et FranceTVInfo (ce dernier article a été modifié).
Ce qui va vraiment mettre le feu aux poudres est en fait un article
d'Europe1.fr : ce papier reprend le témoignage d'une membre d'Alliance,
un syndicat policier classé à droite, qui intervenait dans le cadre de
l'édition spéciale de la radio sur le déraillement de Brétigny. La
syndicaliste décrit les scènes de pillage et y va de son commentaire
personnel :
Ce témoignage va être repris in extenso par le site d'Europe 1 qui va
transformer un témoignage qu'on peut qualifier d'engagé en information :
le site titre "Des policiers caillassés" et passe l'article sur sa
home, en dessous de l'accident en lui-même .
Non seulement ce papier ne remet pas en cause la parole de la
syndicaliste (en interrogeant par exemple un autre syndicat), mais en
plus le témoignage est agrémenté d'un tweet d'un militant FN pour une
raison totalement incompréhensible (ce tweet a depuis été supprimé de
l'article) :
L'article d'Europe 1 est rapidement repris par des comptes de
journalistes de la radio qui ajoutent un commentaire personnel : "à
vomir!!" dénonce ainsi une journaliste de la station, permettant une
propagation rapide de ce témoignage.
Aucun autre site d'information ne mentionnera de pillage hier soir.
De l'influence de la fachosphère
L'article d'Europe 1 est repris très rapidement par le blog
d'extrême-droite Fdesouche : à 22 heures, de nombreux utilisateurs de
Twitter proches de la fachosphère et de la Manif pour tous relaient le
témoignage d'Alliance.
Scène surréaliste à minuit : le hashtag "Bretigny" ne parle plus du
tout de la catastrophe ferroviaire mais uniquement de l'affaire des
pillages. Un mélange de tweets improbable fait se cotoyer des militants
d'extrême-droite dénonçant l'immigration et des jeunes de issus de
toutes les couches de la société qui cherchent les mots pour dénoncer
cette rumeur épouvantable.
Pas un tweet – pas un – ne prend l'affaire des pillages à la rigolade
ou n'en fait un évènement à célébrer : Brétigny fait alors l'objet de
50 récurrences par minute.
Il faut également souligner que de nombreux tweets s'insurgent contre
le peu de visibilité que les médias consacrent à cette affaire :
beaucoup d'utilisateurs du réseau se demandent pourquoi BFM et iTélé, en
direct depuis des heures, n'abordent même pas cette histoire.
On peut saluer aujourd'hui le travail de ces deux chaînes qui ne sont
pas tombées dans le piège de la rumeur en fin de soirée : il faut
d'ailleurs se souvenir que les multiples témoignages entendus après le
drame, souvent diffusés en direct et en longueur, ne faisaient jamais
état d'incidents ou de violences sur les victimes après la catastrophe.
Je n'écris pas cet article pour donner des leçons et je précise qu'on
parle ici de médias que j'apprécie et que je consomme quotidiennement.
Simplement, je trouve que cette histoire méritait d'être rapportée :
s'il on estime que la version donnée par la Préfecture correspond
effectivement à la réalité, on peut réfléchir à la façon dont un
déraillement de train a permis d'alimenter l'extrême-droite en aussi peu
de temps et de façon aussi massive par des médias traditionnels.
Vers minuit hier soir, j’avais besoin de conduire. C’était particulièrement
agréable hier soir car la lune était pleine. J’habite dans la campagne un peu
aussi et je ne voyais pas beaucoup de voitures le long de la côte. Avant de
quitter la côte, je voyais le phare du Cap Fréhel. Et pendant que je conduisais,
j’ai découvert cette chanson…
On a eu un peu de tout dimanche,
à 3-4 miles nautiques du bouée sud-est des Minquiers en allant vers jersey
dimanche matin :on etait deux à
bord. On faisait du près, vent nord-est entre 23-30 nœuds, houles long
avec une mélange des vagues arrachées ici et une courant à travers de 2 nœuds…j’ai
même couché le bateau une fois…
We had a little bit of everything Sunday,
about three to four nautical miles from the south-east tip of the Minquiers
rocks between St. Malo and Jersey. We were
beating up into the wind of 23_30 knots, le swell period was big but it was all
mixed with confused waves from the wind and a 2 knot cross current. I confess
that I broached once…
The
US government is ratcheting up its rhetoric against China, claiming
that state-sponsored Chinese hackers are involved in massive-scale
campaigns to steal trade secrets over the Internet. The Chinese
government denies this, of course, while claiming that it has discovered
numerous attacks against its networks and infrastructure originating
from the United States.
The allegations fired back and forth between the world's two largest
economic powers are largely true, of course. As we have reported,
network spying has been taking place for years. (See: America's Declared (& Undeclared) Cyberwar.)
It is also a modern extension of classic cross-border espionage and
spying, which is considered to be the second-oldest profession. But
recently, cyberattacks by foreign governments, especially from China,
seem to have emerged as an unprecedented threat, according to vocal
outcries by US officials and a surge in media coverage about the "China
hacking menace."
Sticky fingers
In the worst possible outcome, the war of rhetoric could lead to an all-out cyber war that ends the relative freedoms of data exchange.
(Source: George Thomas, Flickr)
Pointing fingers
Without condoning trade secret theft by China or any other country, I
feel the agendas of those responsible for inciting a call to arms in
United States to combat China's covert cyberwar against US intellectual
property interests need to be carefully scrutinized. Lobbying groups and
elected officials representing those hurt by the flow of technology and
jobs from the United States to other countries, especially to China,
certainly have a stake in playing up fears about purported cyberthreats.
However, something to watch out for is when politicians start to use
false or dubious allegations to play on the fears of the populace as an
excuse to restrict or more tightly control cross-border exchanges of
data with China or any other country.
One worrisome example of a largely unfounded allegation against China
is the publication of a report from US-based security firm Mandiant
about alleged Internet attacks by the Chinese army. While Mandiant's
allegations are worrisome on the surface, they are not completely
grounded in fact, according to South Africa-based security firm Thinkst. (See: Cyberwarfare & the Battle to Protect Supply Chain Data.)
According to Mandiant, a China-based army unit of hackers is behind
the so-called "APT1" attacks, which it says have involved over 1,900
assaults targeting mainly US and Canadian networks. Over 97 percent of
the attacks originated from IP addresses in the Shanghai region, where
Mandiant estimates there are possibly hundreds of hacker operatives
involved. Faulty facts?
But according to Thinkst, Mandiant's metrics are at fault. The main
issue is that Mandiant failed to conclusively demonstrate that the IP
addresses corresponded to a single organization, which has set a
dangerous precedent. Thinkst writes:
We are not saying the Chinese government does not hack the US.
Our concern is with this specific report; it is the first concrete
public attribution of ongoing espionage against the US, and, if the
report sets the standard for attribution, future events will be highly
muddled as competing hypotheses all meet the low standard set out in
Mandiant's APT1 report. Unfortunately it seems that contrary opinions
are being subjected to a level of diatribe usually reserved for
arguments of faith, not facts.
Following the publication of Mandiant's report in February, the US State Department published "Administration’s Strategy on Mitigating the Theft of U.S. Trade Secrets,"
which outlines policy measures and proposals to help organizations
protect their data from foreign attacks. Both reports were released just
a few days after The New York Times reported that a group of hackers
originating from China had penetrated its networks.
The US government outlines voluntary and seemingly benign
best-practices to help organizations protect their sensitive data in
"Theft of U.S. Trade Secrets." But what happens when the elected
officials decide to take the next step and force organizations to follow
certain procedures? Chilling effects
The risk is when lobbyists convince Congress to create mandates that
require organizations to spend a lot of money on software or hardware
they do not want or need in the name of security. They might also
mandate that companies with supply chain partners in China comply with
unreasonable and expensive compliance procedures beyond the alphabet
soups of regulatory compliance protocols that organizations must already
follow when exchanging and storing data abroad.
Heavy-handed laws and regulations put in place under the guise of
blocking Chinese hackers from stealing trade secrets would have obvious
implications for supply chains that rely on cross-border data exchange
over the Internet. And they would almost certainly prompt Beijing to
retaliate, prompting it at a minimum to more heavily regulate and
censure data communications than it already does.
In the worst possible outcome, the war of rhetoric and empty
allegations could lead to an all-out cyberwar levied multilaterally,
while ending the relatively freedom of data exchange that we have come
to expect from the Internet.
Organizations are rightfully concerned about losing their competitive
edge when hackers steal data over the Internet and obviously hope the
government has a plan in place to head off these kinds of thefts in an
appropriate way. But forcing organizations to comply with stricter and
obtrusive laws and regulations that do not help much, based on
irrational fear mongering, is not a viable solution.
Hopefully, Washington will taper off its war of words and learn how
to better nab and shutdown black hat hacker networks that operate from
China or anywhere else, in a way that remains transparent and
unobtrusive to the non-combatants. Related posts:
Bruce, this is a fantastic piece and
good tough love for companies in North America. It reminds me of all the
post-911 security changes we've adopted in America.
Have they stopped additional terrorist attacks? Perhaps. Have they
fundamentally changed our culture for the worse? Yes, indeed.
Bruce is a writer based in France and in the United States. His adventures include starting and promptly dropping out of La Sorbonne Law School in Paris and chatting with arms salesmen in Tunisia. If you want to read his published articles, Bruce's Website address is www.brucegain.com.