Follow Us

This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Sunday, 2 November 2014

Apple Pay Rival and Walmart-backed MCX Hacked, User Emails Snatched

Apple Pay Rival and Walmart-backed MCX Hacked, User Emails Snatched

 

 

Merchant Customer Exchange (MCX), a partnership between retailers including Rite Aid RAD +1.35%, Sears and Walmart that’s building an Apple AAPL +0.95% Pay competitor, notified customers on Wednesday that it had been hacked.
MCX, which describes itself as “the only merchant-owned mobile commerce network built to streamline the customer shopping experience,” told users that unknown individuals had gained access to customer email addresses and that it had learned of the breach in the last 36 hours. The Needham, Mass.-based company is currently beta testing its main product, CurrentC, an app that will allow users to pay at physical retail stores with their phones.
“Within the last 36 hours, we learned that unauthorized third parties obtained the e-mail addresses of some of our CurrentC pilot program participants and individuals who had expressed interest in the app,” said MCX spokesperson Linda Walsh in a statement. “Many of these email addresses are dummy accounts used for testing purposes only.”
MCX also noted that the CurrentC app was not affected and that it had individually contacted users whose emails had been stolen. It is unclear how many emails were taken in the breach.
“MCX is continuing to investigate this situation and will provide updates as necessary,” read part of company’s email to customers. “We take the security of your information extremely seriously, apologize for any inconvenience and thank you for your support of CurrentC.”
MCX is comprised of more than 50 businesses which include some of the nation’s largest retailers and restaurants like Lowe’s and Olive Garden. Collectively those companies operate more than 110,000 locations and process more than $1 trillion in payments annually. MCX’s CurrentC was expected to be in a private pilot through the end of the year, with national rollouts expected in 2015.
Unlike Apple Pay, which allows the company’s new smartphones and hardware to communicate with point-of-sale systems through Near Field Communication (NFC) technology, CurrentC noted its software would not require merchants to employ new or additional hardware and instead relied on QR codes scanned from phones. On Monday, CVS and Rite Aid, both MCX partners, said that they were disabling NFC capabilities on point-of-sale systems like cash registers in an effort to curb the use of Apple Pay.
“It’s a skirmish,” said Apple AAPL +0.95% CEO Tim Cook, when asked at the Wall Street Journal Digital Live conference why Rite Aid and CVS had pulled the plug on integrating NFC technology. “Merchants have different objectives sometimes. But in the long arc of time, you only are relevant as a retailer or merchant if your customers love you.”
There doesn’t seem to be much love for the CurrentC app in Apple’s App Store where it is free to download. Currently, more than 2,000 people have rated the app, which has received an average rating of one star out of a possible five. Most of those rating CurrentC, however, seem to be using the system to provide a personal message to the retailers involved with MCX.
“The retailers who are supporting this payment system should be told emphatically that to require this form of payment over another acceptable form of payment is not tolerated,” wrote one frustrated consumer. “If these merchants want to continue with their own mobile payment system, there is nothing wrong with that… as long as they allow a choice.”
In a blog post to his company’s website on Wednesday, MCX CEO Dekkers Davidson said that the group’s participating retailers chose to work with MCX exclusively in implementing mobile payments systems. While earlier reports suggested that there would be fines for MCX retailers that accepted Apple Pay and stepped away from the MCX system, Davidson said that was not the case.
“MCX merchants make their own decisions about what solutions they want to bring to their customers; the choice is theirs,” he wrote. “When merchants choose to work with MCX, they choose to do so exclusively and we’re proud of the long list of merchants who have partnered with us. Importantly, if a merchant decides to stop working with MCX, there are no fines.”

America's Hackable Backbone

America's Hackable Backbone

 

 

The first time Scott Lunsford offered to hack into a nuclear power station, he was told it would be impossible. There was no way, the plant’s owners claimed, that their critical components could be accessed from the Internet. Lunsford, a researcher for IBM ‘s Internet Security Systems, found otherwise.
“It turned out to be one of the easiest penetration tests I’d ever done,” he says. “By the first day, we had penetrated the network. Within a week, we were controlling a nuclear power plant. I thought, ‘Gosh. This is a big problem.’”
In retrospect, Lunsford says–and the Nuclear Regulatory Commission agrees–that government-mandated safeguards would have prevented him from triggering a nuclear meltdown. But he’s fairly certain that by accessing controls through the company’s network, he could have sabotaged the power supply to a large portion of the state. “It would have been as simple as closing a valve,” he says.

In Pictures: America’s Hackable Backbone

The disturbingly vulnerable system that Lunsford hijacked is powered by Supervisory Control and Data Acquisition software, or SCADA, a type of software made by companies including Siemens , ABB , Rockwell Automation and Emerson.
SCADA systems are used around the country to control infrastructure like water filtration and distribution, trains and subways, natural gas and oil pipelines, and practically every kind of industrial manufacturing. And as some security professionals are pointing out, those weaknesses are increasingly connected to the Internet, leaving large parts of America’s critical infrastructure exposed to anyone with moderate information technology training and a laptop.
At the DefCon hacker conference earlier this month, security researcher Ganesh Devarajan gave a presentation detailing how researchers can find flaws in SCADA systems using “fuzzing,” a technique that floods software with data and tracks which input causes a crash, allowing hackers to inject their own commands.
“These are simple bugs, but very dangerous ones,” says Devarajan, associate security analyst at 3Com-owned security firm TippingPoint. He says he’s alerted SCADA software vendors to all the flaws he’s found, but he nonetheless imagines a scenario in which someone plants a contaminant in a water reservoir and hacks into water-quality sensor systems to prevent detection. “If someone can provide false data,” he says, “They own the system.”
To be sure, the threat of attacks on major SCADA systems isn’t entirely new, and the wave of cyberterrorism predictions that followed Sept. 11, 2001, have largely been dismissed as hype and paranoia. But given SCADA systems’ vulnerability, many experts wonder why those attacks haven’t yet materialized.
One answer may be the sheer complexity of major infrastructure systems: Though SCADA computers have weak external security, controlling them takes engineering expertise. Most hackers could only gain enough control to create the fear that they’re capable of something worse, says Alan Paller, director of the SANS Institute.
That means that even if outright attacks aren’t increasing, there’s a growing threat of extortion, says Paller. In fact, the SANS Institute hosts a crisis response center for cyberattacks, and Paller says he’s learned of multiple threats within the last year and a half from hackers claiming to have infiltrated SCADA systems and demanding ransom. Other shakedowns have likely gone unreported.
Paller predicts that those incidents will increase. “There’s been very active and sophisticated chatter in the hacker community, trading exploits on how to break through capabilities on these systems,” he says. “That kind of chatter usually precedes bad things happening.”
Extortion is more than an economic problem; racketeers could easily trigger an accident while trying to demonstrate control over a facility, says Marcus Ranum, chief security officer for Tenable Security. “To spin a pump or move a valve, you don’t have to be a petroleum engineer,” he says. “Then again, you could spin the wrong pump and blow something up.”
Not every SCADA sabotage scenario is so hypothetical. In 2000, Vitek Boden, a 48-year-old man fired from his job at a sewage-treatment plant in Australia, remotely accessed his former workplace’s computers and poured toxic sludge into parks and rivers; he hoped the plant would re-hire him to solve the leakage problem.
In January 2003, computers infected with the Slammer worm shut down safety display systems at the Davis-Besse power plant in Ohio, though the plant was already shut down at the time. Seven months later, another computer virus was widely suspected by security researchers of leading to a power loss at a plant providing electricity to parts of New York State, despite the Nuclear Regulatory Commission’s argument that no evidence of virus-involvement was found.
SCADA systems’ lack of security features is a symptom of their age; most were developed at a time when critical infrastructure systems weren’t connected to the Internet and needed no intrusion prevention. Some have a 20-year life span, making them obsolete for years after they’re installed. And many of the companies that develop SCADA software make installing security patches difficult or, fearing that patches will hamper the software’s operation, don’t offer customer support for patched systems.
All of which still leaves U.S. infrastructure open to crippling attacks by criminal hackers or cyberterrorists, says Jim Christy, director of future exploration at the Department of Defense’s Cyber Crime Center. “This is an Achille’s heel for several of our critical systems,” Christy says. “Nation-states and terrorist organizations are definitely looking at this as an option, a weapon of mass disruption.”
That kind of risk means major security changes are necessary, says Christy. But because SCADA systems are largely owned by the private sector, critical infrastructure like power plants and water systems may remain vulnerable until the problem affects profits–or leads to disaster. Christy argues that we can’t wait that long: His unofficial opinion is that SCADA needs government regulation.
“The government mandates fire sprinklers. Those cost builders money, but they save property and lives,” he says. “If critical infrastructure is important to our national security, shouldn’t there be minimum standards it has to meet?”

How To Hijack 'Every iPhone In The World'

How To Hijack 'Every iPhone In The World'

 

 

If you receive a text message on your iPhone any time after Thursday afternoon containing only a single square character, Charlie Miller would suggest you turn the device off. Quickly.
That small cipher will likely be your only warning that someone has taken advantage of a bug that Miller and his fellow cybersecurity researcher Collin Mulliner plan to publicize Thursday at the Black Hat cybersecurity conference in Las Vegas. Using a flaw they’ve found in the iPhone’s handling of text messages, the researchers say they’ll demonstrate how to send a series of mostly invisible SMS bursts that can give a hacker complete power over any of the smart phone’s functions. That includes dialing the phone, visiting Web sites, turning on the device’s camera and microphone and, most importantly, sending more text messages to further propagate a mass-gadget hijacking.
“This is serious. The only thing you can do to prevent it is turn off your phone,” Miller told Forbes. “Someone could pretty quickly take over every iPhone in the world with this.”
Though Miller and Mulliner say they notified Apple about the vulnerability more than a month ago, the company hasn’t released a patch, and it didn’t respond to Forbes’ repeated calls seeking comment.
The iPhone SMS bug is just one of a series that the researchers plan to reveal in their talk. They say they’ve also found a similar texting bug in Windows Mobile that allows complete remote control of Microsoft -based devices. Another pair of SMS bugs in the iPhone and Google’s Android phones would purportedly allow a hacker to knock a phone off its wireless network for about 10 seconds with a series of text messages. The trick could be repeated again and again to keep the user offline, Miller says. Though Google has patched the Android flaw, this second iPhone bug also remains unpatched, he adds.
The new round of bugs aren’t the first that Miller has dug up in the iPhone’s code. In 2007, he became the first to remotely hijack the iPhone using a flaw in its browser. But while that vulnerability gave the attacker a similar power over the phone’s functions, it required tricking the user into visiting an infected Web site to invisibly download a piece of malicious software. When Miller alerted Apple in July of that year, the company patched the vulnerability before Miller publicized the bug at the Black Hat conference the following month. (“See: Hacking the iPhone.”)
The new attacks, by contrast, can strike a phone without any action on the part of the user and are virtually unpreventable while the phone is powered on, according to Miller and Mulliner’s research. And unlike the earlier exploits, Apple has inexplicably left them unpatched, Miller says. “I’ve given them more time to patch this than I’ve ever given a company to patch a bug,” he says.
The Windows bug he and Mulliner plan to reveal hasn’t been patched either, says Miller, though he admits that he and Mulliner discovered the Windows flaw on Monday and hadn’t yet alerted Microsoft to its existence.
The attack developed by Miller and Mulliner works by exploiting a missing safeguard in the phones’ text messaging software that prevents code in the messages’ text from overflowing into other parts of the device’s memory where it can run as an executable program. The two researchers plan to demonstrate how a series of 512 SMS messages can exploit the bug, with only one of those messages actually appearing on the phone, showing a small square. (Someone could easily design the attack to show a different message or without any visible messages, Miller cautions.) The entire process of infecting an iPhone and then using the device to infect another phone on the user’s contact list would take only a few minutes, Miller says.
The vulnerability of SMS to that sort of attack will likely be a hot topic at this year’s Black Hat and Defcon cybersecurity confabs. Two other researchers, Zane Lackey and Luis Miras, say they plan to present other vulnerabilities in major vendors’ SMS applications, though they declined to discuss which vendors or the specifics of the vulnerabilities before the companies had issued patches.
Lackey and Miras argue that SMS demands far more attention from the cybersecurity community and device vendors. “Like a lot of mobile phone software, it’s been relatively unexplored in the past,” Lackey told Forbes. “Only recently has there been proper debugging and development tools available. SMS exemplifies a common trend: once it was a simple technology. Now it’s being used in devices far beyond its original purposes, and security is still playing catch up.”
The researchers’ concerns aren’t merely theoretical. Finnish security firm F-Secure says it’s found nearly 500 different variants of mobile phone malicious software since 2004, mostly using Bluetooth to hop between phones in close proximity. But in the last 18 months, cybercriminals have begun using text messages to send links to malicious Web sites that infect the phone with malware, says Mikko Hyppönen, an F-Secure researcher.
One seemingly-Chinese variant, known as “Sexy View” and currently targeting the Symbian operating system, is far more threatening than an iPhone attack, given that around 50% of cellphones use Symbian, Hyppönen says. “After years of the security industry wondering why we aren’t seeing text message worms, it’s starting to happen now,” he says.
While many of those ongoing attacks are merely hacker experiments, some have used phones to text premium numbers that generate revenue for cybercriminals. “Mostly it’s still about curiosity and fun, but eventually the criminal guys move in,” says Hyppönen. “We’re probably on the verge of that right now.”
As dangerous as his iPhone attack sounds, Miller argues that it’s important to expose flaws in SMS software before they can be exploited by more malicious actors. Texting applications’ insecurity isn’t due to the software’s complexity so much as the security community’s inattention and the expense of sending thousands of text messages to test a phone’s security, Miller says.
“The bad news is that SMS is the perfect attack vector, but the good news is that it’s probably possible to build it securely,” he says. “As a researcher, I can only show [Apple] the bugs. It’s up to them to fix them.”
See Also:
Your Spying iPhone
Apple’s Security Paradox
Hacking The iPhone

Data Breach Bulletin: Gmail, Central Utah Clinic, JP Morgan, George Mason University

Data Breach Bulletin: Gmail, Central Utah Clinic, JP Morgan, George Mason University

 

 

Here’s a roundup of this week’s data breaches:
Gmail – Last week, nearly five million Gmail addresses and passwords were found on a Russian security site in addition to 123,000 yandex.ru addresses. This leak closely followed two other dumps of Russian email and password combinations last week–1.26 million Yandex accounts were leaked on Monday and 4.66 million Mail.ru accounts were leaked on Tuesday. Google GOOGL +1.33% says it has not been breached and that less than 2% of the leaked usernames and passwords were current. Security researchers speculate that the emails and passwords were likely aggregated from a number of previous breaches.  Moral of this breach (and most breaches): change your passwords, make passwords unique across different accounts, and set up two-factor authentication whenever possible.
Central Utah Clinic – More than 31,000 patients at Central Utah Clinic may have had their personal information accessed in a data breach. While the hospital says it successfully defends against many cyber attackers every month, the hospital’s IT professionals discovered on June 9 that an attacker had compromised one of the hospital’s servers that contained radiology reporters dating back from 2010. The server also contained some names, dates of birth, Social Security numbers, addresses and phone numbers. There is no evidence that information was viewed or copied during the breach. “These attacks are an unfortunate aspect of information technology and modern healthcare is not immune from this,” said Central Utah Clinic CEO Scott Barlow.
JP Morgan – Ever since the FBI announced it was investigating a potential breach at JP Morgan Chase at the end of August, information about the breach has trickled out partially through anonymous sources. This week, sources close to the investigation told the New York Times that the investigation has revealed that hackers had infiltrated as many as 90 bank servers over the course of two months. In doing this, the hackers gained access to a million customer accounts as well as a list of the bank’s installed software. Another anonymous source said that hackers were not able to access Social Security numbers or financial information. Until the investigation is complete, we won’t know the full details—including if other banks were also breached and if this was a state-sponsored attack out of Russia.
George Mason University – Approximately 4,400 individuals may have had their personal information breached in a malware attack against George Mason University. The university says it discovered the malware on July 16 on a server hosting the Travel Request Service, which is used to help university members book subsidized travel. The University’s Vice President for IT, Marilyn Smith, told SC Magazine that while the server held names and Social Security numbers, the school doesn’t believe that any sensitive data was accessed.
Tampa General Hospital – Nearly 700 Tampa General Hospital patients have been notified that their personal and medical information was accessed by a former hospital employee. This information included Social Security numbers, names, addresses, dates of birth, diagnoses, and insurance information. The breach was discovered when police notified TGH that hospital documents had been discovered in a car during a traffic stop and arrest. The arrested individual didn’t work at the hospital, but the documents were traced back to a hospital staffer who was then fired. The hospital told Fox News that the employee had been at TGH since 2009 in a non-clinical role. The hospital says it is implementing blocks around who can access patients’ Social Security numbers and is increasing employee training.
Napa Health & Human Services Agency – Personal data was an unforeseen casualty in the earthquake that hit California last month, according to the Napa County In Home Supportive Services (IHSS) program.  On August 27—three days after the earthquake—the Comprehensive Services for Other Adults Division of Health and Human Services discovered that a thumb drive was missing from a locked office that had been damaged during the earthquake. While the thumb drive did not contain Social Security numbers, it did have clients’ names, addresses, phone numbers, and other limited information about care received.
Yandy.com – If you recently bought lingerie and costumes from online retailer Yandy.com, it might be smart to check your credit report. On August 18th, 2014, Yandy.com discovered that an “unauthorized, external cyber-attack” had hit its website, exposing customer payment card data. Yandy reported the breach and says it cannot determine if data was exposed during the breach. While it’s pretty typical for data breach notification letters to include an offer of a year of free credit monitoring, Yandy is offering no such service to their customers.

Tuesday, 28 October 2014

Credit Cards Compromised In Month-Long Kmart Data Breach

Credit Cards Compromised In Month-Long Kmart Data Breach

 

 

Kmart revealed that an undisclosed number of credit card numbers were stolen in a month-long data breach which began in early September, according to an SEC filing on Friday. A subsidiary of Sears Holding Corporation, Kmart is the latest in a long string of retailers to suffer a credit card breach this year.
According to the filing, the breach was discovered by Kmart’s IT team on Thursday, October 9, and has likely been going on since early September. Security experts believe that Kmart’s payment data systems were hit with malware that was “undetectable by current anti-virus systems.” Kmart says it has now removed the malware from its system.
Based on the investigation, Kmart believes that credit and debit card numbers were compromised in the breach, but is not commenting on the scope of the breach. The retailer does not believe that any social security numbers, personal information, email addresses, or debit card PIN numbers were stolen. Additionally, kmart.com customers were not impacted, according to Kmart’s release.
Kmart is working with law enforcement, banks, and security firms to investigate the breach, according to the filing. Additionally, the retailer says it is working to improve its security systems.
Kmart is not alone in being hit with a credit card breach this year. On Thursday, Dairy Queen announced that 395 store locations had been compromised by Backoff malware. Last month, Home Depot HD +0.51% announced that 56 million cards had been compromised in a data breach that lasted five months. Earlier in September, Goodwill revealed that 868,000 cards had been compromised in a point-of-sale attack. Other breaches this year included PF Chang’s, Michaels, and Neiman Marcus. In December, 40 million cards at Target TGT -0.02% were compromised in what was the biggest retail data breach until Home Depot.
According to its website, Kmart had 1,221 Kmart stores, 25 of which were Super Centers, as of February 2013. In a statement, Kmart’s President Alasdair James apologized “for any inconvenience this may cause our members and customers.” Like most companies suffering a credit card breach, Kmart is assuring customers that “privacy and security of our customers’ information is of utmost importance,” and is offering free credit monitoring to anyone who shopped at Kmart in the last month.

World's Top Privacy Experts Worry About Internet Of Things

World's Top Privacy Experts Worry About Internet Of Things

 

 

Meeting in one of the world’s most remote and private locations – the island of Mauritius off the coast of Africa – top global privacy regulators could have focused on any number of issues. But they were especially concerned that the Internet of things, everything from health sensors to monitors in a car, depends on connectivity which could expose users to significant privacy and security risks.
Data privacy commissioners from countries as different as Albania and Uruguay, Japan and Ghana last week discussed a wide range of developments related to personal data and security, but gave special attention to the growing array of networked devices that surround us at every turn of life.
“These devices can make our lives much easier,” the data and privacy commissioners said in a declaration. “The internet of things however, can also reveal intimate details about the doings and goings of their owners through the sensors they contain.”
“Personal development should not be defined by what business and government know about you. The proliferation of the internet of things increases the risk that this will happen.”
Data privacy commissioners watch a dance performance at their annual conference, held this year in Mauritius (Photo by Adam Tanner)
Data privacy commissioners watch a dance performance at their annual conference, held this year in Mauritius (Photo by Adam Tanner)
Although we buy these devices to gain data about ourselves or our surroundings – such as to monitor how many steps we take in a day or whether food is running low in the kitchen – the information could also prove valuable to manufacturers as they can sell it to others. In a recent article I profiled a medical device entrepreneur struggling with the fact that he would have to forgo income by not selling information users produce on his device.
Many companies say they only sell aggregated anonymized data – details about you and many others like you gathered into one large pile. But the data privacy commissioners worry that outsiders will still be able to identify you. That may not seem to matter much if all the data suggests is you need a new gallon of milk, but might be more sensitive if it showed your vital statistics were looking weaker month after month.
Come to think about it, even milk could reflect details about our lifestyles paired with other information, for it could show whether we prefer whole fat or fat free.
Or even more obviously, consider the announced but as of yet unavailable Sexfit penis ring by British company Bondara which transmits sex data. And as my colleague Kashmir Hill wrote in 2011, some Fitbit users in the past have found statistics about their sexual activity posted online.
“Internet of things’ sensor data is high in quantity, quality and sensitivity. This means the inferences that can be drawn are much bigger and more sensitive, and identifiability becomes more likely than not,” the Mauritius declaration said.

The seriousness of the Mauritius meeting, also attended by officials from Facebook, Microsoft MSFT -0.48%, Google GOOGL +0.17% and other companies, certainly felt far removed from the setting of their conference. The doors from the conference hall opened onto a tropical beach where well-heeled tourists come to escape from the ever on technological world (yes, I had the pleasure of attending the conference to deliver a keynote speech). But even here, video camera surveillance, tracking of customer data and other signs of the modern business of personal information have expanded in recent years.
Data privacy commissioners pose for a group photo at their annual conference in Mauritius (Photo by Adam Tanner)
Data privacy commissioners pose for a group photo at their annual conference in Mauritius (Photo by Adam Tanner)
So when it comes to the interconnected devices known as the Internet of things, private officials say companies should not surreptitiously collect data, if anonymously.
“Transparency is key: those who offer internet of things devices should be clear about what data they collect, for what purposes and how long this data is retained,” the privacy commissioners agreed. “They should eliminate the out-of context surprises for customers. When purchasing an internet of things device or application, proper, sufficient and understandable information should be provided.
France’s privacy commissioner Isabelle Falque-Pierrotin put it simply: “The Internet of things should stay under the control of the user.”
And a 5,000 word privacy policy that nobody reads does not provide true control. “Consent on the basis of such policies can hardly be considered to be informed consent,” the commissioners said in their statement. “Companies need a mind shift to ensure privacy policies are no longer primarily about protecting them from litigation.”
Yes, it is easy to make fun of government bureaucrats who fly to a paradise island to formulate policies (and it is not always the case: last year they met in Warsaw, next conference will be in Amsterdam). But they have provided some important insights to consider as gadgets surrounding our lives become ever smarter and linked to the world beyond.

Can China's New Internet Conference Compete with the West in Defining Norms of Cyberspace?

Can China's New Internet Conference Compete with the West in Defining Norms of Cyberspace?

 

 

Not wanting to be left out, after the United KingdomHungary, and South Korea (PDF) all held conferences on cyberspace governance, China has announced that it will be hosting the World Internet Conference from November 19 to 21.  The  conference, planned by the Cyberspace Administration of China (formerly named the State Internet Information Office), has the stated mission to promote the “development of [the] Internet to be the global shared resources for human solidarity and economic progress.”
The conference seems somewhat hastily planned; invitations went out last week and the first I heard of it was a month ago. Perhaps Beijing wanted the get the conference out the door before the next conference meets in 2015 in the Netherlands (the UK, Hungary, South Korea, and the Netherlands are all part of a series that began in London). The agenda, covering global Internet governance, cybersecurity, the role of the Internet in promotion of economic and social development, and technological innovation, is very similar to the topics covered in the UK (2011), Hungary (2012), and South Korea (2013). There is, of course, no explicit reference to human rights, but it could be discussed under “social development.” In process, it will probably be most like South Korea, where there was criticism that the conference showed a low degree of inclusiveness to civil society groups.
The conference promises to have high-level political support within China. There have been a number of articles in the Chinese press over the last year arguing that Beijing needs to be more assertive about defining the agenda for Internet governance. According to Wang Yukai, an academic and advisor to the government, one of the things required to help make China a “strong cyber power” (网络强国) is a “ clear international strategy that lays out priorities and defends China’s right to have a voice on cyber issues.”
As with the previous conferences, we shouldn’t expect much in outcomes. The Seoul Conference, for example, issued a “Framework for and Commitment to Open and Secure Cyberspace” and announced the follow-up conference at the Hague. For China, just having the conference is probably enough, signaling that it intends to take more of a role in shaping the rules of the road for cyberspace.