
Keren Elazari speaks at TED2014. The day she gave her talk, we spoke to her about the shutdown of Twitter in Turkey. Photo: James Duncan Davidson
Two weeks ago, hours after Turkish prime minister Recep Tayyip Erdoğan vowed to “wipe out” Twitter, his government blocked access to the platform across the country. It was just weeks before a hotly contended election, and Erdoğan was upset about tweets accusing him of corruption. A judicial ruling in Turkey called for Twitter to take down the offending links, but when Twitter did not comply, the Turkish government opted to block the site. (Since then, the courts have deemed the ban illegal, but the government has yet to lift it — and instead banned access to YouTube as well, reportedly due to a security leak.)
Other governments have also tried to block access to parts or all of the Internet in the past, including Egypt’s Internet shutdown in January 2011 and Syria’s in May 2013. As it happened, cybersecurity expert Keren Elazari was talking at TED2014 about the effects of the Egyptian shutdown and others like it around the same time as news of the Turkish Twitter ban was starting to trend on Twitter.
In her talk, Elazari said that hackers play an essential role in giving power, or free access to information, back to the people when governments try to take it away. We were curious to hear her take on the situation in Turkey, so we sat down with her to discuss the ban and the uneasy relationship between tech companies, like Facebook or Twitter, and governments. An edited version of our conversation follows:
So what’s really going on in Turkey?
While Egypt had Tahrir Square and other places around the world had other social uprisings and revolutions, in Istanbul it happened in Taksim Gezi Park. This is because of some controversial decisions and acts by the current Prime Minister of Turkey, Tayyip Erdoğan [NB: Erdoğan’s party, the Justice and Development Party, won a victory in the nationwide local elections 10 days after this interview took place, a show of support from voters despite stronger-than-usual opposition]. We don’t think of Turkey as a dictatorship, right? It’s fairly modernized. In fact, it’s one of the most modernized and democratized countries in the Muslim world.
But in the last few years there have been a lot of struggles. There have been a lot of questions with regard to the elections that they had, and with regard to democracy, and with regard to the separation of Islam as a religion from state affairs and from military affairs.
This was a huge deal, by the way, for Turkey, when it became a modern nation. Ataturk, the founder of the Turkish modern nation, really had this ideology of separating religious affairs from secular affairs and military and state affairs. And that has been slowly changing, even reverting back to more traditional, less liberal values, in the past couple years, and this is the reason that there are a lot of uprisings and revolts and conflicts within Turkey. This has to do with some traditional or religious values coming into sharp conflict and contrast with a more modernized world that wants free access to all kinds of information and freedom from oppression.
It seems like social media is playing a really critical role in bringing stories to light. Del Harvey, head of safety at Twitter, addressed this in her talk. One of her team’s roles is to make sure that Twitter is not inadvertently blocking things like a citizen journalist sharing a really important video. It seems like this is a critical role of social media and governments are scared, so they’re trying to shut it down. That seems unsustainable, no?
But they’re still trying. They’re still freaking out. Because governments used to have control over the propaganda channels, the communication channels, the printing presses, the radio stations… When you would take over a country, you would take over these things and indoctrinate the population and use propaganda. Now, anyone has a printing press, and they can put out revolutionary pamphlets.
So because they are freaking out, they are overreacting. So not only is it unsustainable, it’s also causing this overreaction. We see this again and again. In Egypt, when Mubarak tried to shut down the Internet in order to stop the revolution, not only did it not stop the revolution, perhaps it even propelled it even more.
It seems like it incites the rest of the world to care.
Not just the rest of the world, even people there. Even people in Cairo who maybe didn’t know what was going on found out from the Internet and Facebook. They didn’t get the reports from the TV channel or the government radio. And when the internet was shut down, then they had to go out to the streets to see what was going on, and to be part of it.
People talk about the social network revolution. It’s obvious that Twitter and Facebook do not cause a revolution, and they don’t overthrow governments. Years of dictatorship, years of overreach and years of abuse cause people to want to overthrow governments. Social media and the web — open access to information — are tools and the scaffolding that allows this to happen, and allows the world to know. We can sit right here now in Vancouver, and we can know about what is happening in Caracas, what is happening in Turkey, what is happening in Egypt, in Tunisia.
There’s a lot of responsibility on the companies that run these services — on Facebook and Twitter and on the foundations of the Internet. And a lot of that responsibility lies with American companies. And here, here’s the rub — all this power, all these companies, are based in the US, and the US government, the most powerful Western democracy in the world, has been trying to manipulate and control the web. It makes other governments feel like maybe it’s okay to do this sort of thing. If the Americans don’t make a fuss about it, why should anyone else? That erodes the sense of democracy.
You mean that America tries to champion freedom, and yet we’re not actually embodying it?
A lot of this complexity rises from the relationship between corporations and governments. You have to kind of hope that multinational corporations have the responsibility, they have the right morals and the values. But they’re not democratic government. They’re businesses that make money. Their ethos is usually the bottom line, the shareholder value. All though they try to “do no evil” – is that really possible?
What responsibility do you think these companies have?
What’s interesting is that this is not Turkey vs the US government; it’s Turkey vs Twitter, headquartered in San Francisco. Or in the case of the Great Firewall of China, it’s not China vs the US government; it’s China vs a corporation, Google.
These are very different types of relationships, and I think both sides of those relationships are still figuring it all out. The web giants hold the world in their hands. What will they do? How will they react? Will they make business decisions or will this be about values? It’s very unclear, and we’re in the first skirmishes of the future of this world. To me it is very clear that the power of multinational conglomerates is extremely important. It’s not just what the NSA or the US government or even the Turkish government does. There are a lot of moral decisions on the shoulders of CEOs.
What should those CEOs be thinking about as they face those kinds of moral challenges?
This is very complicated, but ultimately, can we afford these to be the decisions of boards of directors who are concerned with the bottom line? This is why the nature of the Internet originated as decentralized, but in essence we’re losing that aspect of it. Because it’s not so decentralized any more. It’s almost feudal. There is a small group of landowners, and we live on their land.
It’s very complicated to ask a business owner or a company to think about how their decisions affect policies and people and revolutions. They’re having a coffee on Market Street in San Francisco, but their decision affects what happens in Rezi Park, in Tahrir Square, in Caracas… we can only hope they do take these things into account.
How do you think hackers help to balance that power, and help to make it so that it’s maybe not quite so dependent on those people?
Hackers make connections happen. It’s very clear, if Anonymous cares about what’s happening in Venezuela, I should care about what’s happening in Venezuela. They actually connect people, they don’t only break stuff. I saw images from the protests in Caracas because the Anonymous Twitter account was posting them. That’s how I learned what was happening there – not from CNN.
It’s also important to have those, yes, chaotic elements. It’s really important for companies and governments to know that if they overreach, if they do uncool stuff, there is someone that can react. There is someone out there, maybe lots of people out there, who chaotically, and in a disorderly and sometimes illegal fashion, can intuitively self-organize to react and respond and get important information out there, or even expose overreach and corruption.
Hackers have evolved as the web has evolved. They’re an integral part of it. And they’re a vital role in it. It’s not organized, it’s not orderly, a lot of them do bad stuff. But overall, I’m hopeful about it. Because for me, it means that this world we live in, which is more and more reliant on digital services, which are run by money-driven corporations, also has someone that can be the counterbalance. They alert our attention to what is happening and to the threats (technical and social). I think that’s important.
What do you think that governments are failing to understand as they continue to try these often fairly misguided efforts to shut something down entirely?
They’re applying 20th century thinking to a 21st century world. There’s this line from a Israeli song, “I’m an analog guy in a digital world.” Lots of governments are analog guys in a digital world, and they think they’ll just shut it down. You can’t. It just doesn’t work that way. But secondly, they’re also positioning themselves as an “us vs them.” They think they can cordon themselves off or build a secure environment. Hackers gonna hack. They’re going to take down those walls. So there is no such thing as unhackable. And even if we could design an unhackable world, I don’t know if I’d want to live there. That sounds kind of like The Matrix. It’s totally controlled and organized by the AI. That’s kind of creepy.
In your talk you said that “access to information is a critical currency of power.” I loved that, and it’s so true. It really seems like shutting down parts of the Internet is removing power from the people in your country. It’s sort of cutting them off at the knees.
Definitely. The Internet is a basic human right. And our world is changing. Really, we are moving towards that Matrix kind of reality where our lives, our brains, will be backed up to the cloud. And who controls that cloud? Who says what’s okay and not okay to go on the cloud, or on the Internet of things? We have these technologies, but we haven’t thought about these implications. The technology’s out faster than we know what to do with it. Policy is way behind, politics is way behind, governments are way behind. Even the corporations that are building it, companies like Amazon, Google, they’re building AIs and drones — are they thinking about the meaning of it? These technologies can quickly become our new overlords, while national governments are still stuck in 20th century reforms.
]]>

Keren Elazari. Photo: James Duncan Davidson
In 2010, the late security researcher — or as cybersecurity expert Keren Elazari would like you to call him, the late hacker — Barnaby Jack found a security flaw in two different models of automated teller machines (ATMs). Onstage at a tech security conference, he publicly demonstrated his ability to make these machines spit out paper money, Elazari says at TED2014. “Barnaby Jack could have easily turned to a career criminal,” she says, “but he chose to show the world his research instead. Sometimes you have to demo a threat to spark a solution.”
How we think about people like Jack is immensely complicated, Elazari says. Hackers scare us and fascinate us at once, and our reasons for these feelings are valid, she says, but we shouldn’t let fear get the best of us. “They scare us, but the choices they make have dramatic outcomes that influence us all,” Elazari says.
Yes, there are hackers doing things like stealing identities, leaking false information, and taking money that is not theirs, she says, but there are also hackers like Jack pointing out vulnerabilities in the devices we use to live, and doing things like fighting against government corruption and advocating for equal rights to privacy, security, and information. If we see hackers as only the bad guys, we are doing our society a disservice: risking ostracizing all those doing great things in the world, working to help us
Growing up idolizing hackers, with a special affinity for Angelina Jolie as Acid Burn in the movie Hackers, as a teenager Elazari ached to execute her own hacks. After her first break-in to a password-protected website, she felt a rush of power, she says, “like I had discovered limitless potential in my fingertips.” And that potential is the great and terrifying thing about hackers — their power for good or bad: “It’s geeks just like me discovering that they have access to a superpower, one that requires the skill and tenacity of their intellect.”
Like superheroes or supervillains, Elazari says, with hackers’ great power comes great responsibility (though not necessarily radioactive spiders.) “We all like to think that if we had such powers we’d only use them for good,” she says, “[but] what if you could read your ex’s emails, or add a couple of zeros to your bank account?” she asks. Would you do it? Hackers have to face that choice every day, and though several of them choose to do malicious things with their power, many instead work to do hard things that benefit the greater good.
One such hacker is Kyle Lovett — who in June 2013 discovered “a gaping vulnerability in wireless routers you might have in your home or office,” Elazari says, a vulnerability that allowed hackers to easily access users’ files and passwords. Choosing not to use this leak for his own advantage, Lovett reported the vulnerability to the manufacturer. Eight months later, the manufacturer still had not repaired the bug, so Lovett used the leaky routers to send a message directly to their users, letting them know just how vulnerable they are to hacks, and encouraging them to ask the manufacturer to fix the flaw.
Another hacker — Khalil Shreateh — found a security bug in Facebook’s system that allowed him to post on any users’ wall, despite whether or not he was the user’s “friend,” Elazari says. Shreateh reported this bug to Facebook via their bug bounty program, an initiative that invites hackers to report all vulnerabilities in exchange for a “bounty” that starts at $500 USD. When Facebook mishandled Shreateh’s report, he used the vulnerability to post on founder Mark Zuckerberg’s personal Facebook wall, Elazari says. He was denied the bounty because he hadn’t reported through proper channels — so hackers all around the world came together to raise over $10,000 USD as a reward.
This shows that — whether we want them to or not — hackers will discover the things that are broken in our world, Elazari says, and either report them or exploit them. If companies as progressive as Facebook — companies “founded by hackers,” Elazari says — still have a complicated relationship with hackers, how will more conservative organizations fare when dealing with hacker culture? This is something we need to address, Elazari asserts, because — more and more — in a changing world, with a growing dependence on technology, hackers are key players. “It’s worth the effort,” she says, “because the alternative, to blindly fight all hackers, is to go against a power you can’t control.”
The power of a creative, intelligent, engaged and curious hacker is immense, Elazari says, and not just regulated to Facebook accounts or local ATMs. “Hackers can do a lot more than break things,” she says. Hackers were key players in the Egyptian revolution, she explains, noting how the group Telecomix worked to provide Egyptians with dial-up access to the Internet — asking two European ISPs to switch old phone-line modems back on — after Mubarak shut down all Egyptian ISPs, “This worked so well one guy used it to download an episode of How I Met Your Mother,” she laughs, “… and when the same thing happened in Syria, Telecomix were ready.”
But there are two sides to every issue, Elazari says, noting: “One man’s hero can be another villain.” Not all people will agree with Telecomix’s actions, or the actions of many other big hacker groups, like the Syrian Electronic Army, who in the same country “have taken down multiple high-profile targets over the years, including the Associated Press’s Twitter account.”
The power hackers yield is great and is one of information, Elazari says, and right now, in the digital age, “access to information is a critical currency of power.” Hackers are shaping our future whether we like it or not, Elazari explains, and it’s up to us whether we want to help them make it better … or believe they will make it worse.
But the most fundamental characteristic of a hacker, according to Elazari? “They can’t just see something broken in the world and leave it be.” So, she says, “I think we need them to do just that, for after all, it’s not just information that wants to be free. It’s us.”
]]>
Catherine Bracy works at Code for America, where civic hackers help their cities. Here, she points out historical figures who fit the definition of “civic hacker.” Photo: Ryan Lash
Hacking has always been an important component of healthy democracies. Despite the bad connotation the word often has these days — indicating rogue criminals breaking into computer systems, stealing identities, spying or worse — hacking is really just any amateur innovation on an existing system. And that “system” doesn’t have to be a technical one. Civic hacking, then, is when citizens see something in the public realm they think can work better and decide to take it upon themselves to push for change. It’s about creating something bigger than the sum of its parts. (You can read about the supposed origin of the word here.)
Catherine Bracy: Why good hackers make good citizens
In the talk I gave at TEDCity2.0, I called Benjamin Franklin possibly the greatest American civic hacker of all time — not just because he was a prolific inventor, but also because he took his curiosity for innovation into the public realm. He created the first volunteer firefighting brigade, in Philadelphia, because he saw that the city was ill-equipped to tackle its many fires on its own.
Though Franklin may be the greatest American civic hacker he’s certainly not the only one. Here are a few other citizens who saw a system in need of fixing and decided to make it better for everyone’s good:
Those are just a few of many Americans who saw a way their communities and their country could be better and decided to hack the system to make it better. At Code for America, we’re trying to inspire the next generation of civic hackers by adding technology to our toolbelt. We hope you’ll come join us.
Catherine Bracy is the director of community organizing at Code for America. Read much more about the organization, including how to get involved »
]]>
The Pudong business district of Shanghai is famed (and often reviled) for its efflorescence of gaudy skyscrapers. Photograph: Lawrence Wang. See also Wang’s photoessay of must-see Shanghai places.
In 2005, at the start of my first visit to Shanghai, the city clothed itself in a growling thunderstorm. When dusk fell and neon began to score the sky, the city was more Blade Runner-y than I thought a real place possible to be. I remember diving into a luxe spa for a post-train massage, slipping, mildly terrified, into an urgent slumber, if that’s not a contradiction, as rain clattered the roof.
Shanghai will do that to you: the intensity, the thrill, the—um—overwriting. It’s a sensation David Li knows well. He was born in Taiwan, studied computer science at USC, and worked as a programmer in Los Angeles during what he remembers as “the good old fun days” before the dotcom bubble burst. In 2003, after 13 years in the US, he headed to Shanghai. More than anywhere else he’d found, the city “captured the energy of the dotcom era,” that sense that “everything is possible.”
Back then, he says, the city shape-shifted month after month. “Everything was changing, everything was moving,” he says. “The city was physically like that.” New skyscrapers charged up around him, especially in the Pudong business district. In the early years of the new millennium there was one of those casual “facts” going around, even at water coolers in London or New York: half, or a third, or most of the world’s construction cranes were operating in Shanghai (the same was said about Dubai, as I remember). True or not, Shanghai seemed to be a new global center of gravity.
Now, says Li, things are a little different. Just as he’s shifted gears (he’s now in his early 40s), so has the city. The changes are subtle, more a matter of attitude. For a start, “people from outside hold Shanghai in much higher regard” than residents do: speed is impressive and, compared to Shanghai, the rest of the world is slow. But speed is “a fact of life” here, so locals—some 23 million of them—fixate on the more quotidian aspects of life: the penetrating humidity clogging up your throat whatever the weather, and the traffic snarls that wrap up every megacity in love with the automobile, which is to say all of them, and especially Shanghai.
The grand ambitions of real estate developers steal the headlines. But Li sees an appetite for innovation among regular city dwellers, too. He sees it up close at the hackerspace XinCheJian, a community space for tech experimentation he founded in 2010. XinCheJian provides lab space, tools, and workshops on programming and open source hardware such as the Arduino microprocessor. About 150 people visit each week to tinker, hack, program, and collaborate. XinCheJian is supported by membership dues and workshop fees, but it’s more about recreation than business. In fact, says Li: “It’s an escape from a city where every meeting is about how to make money.”
Shanghai is a kind of hackerspace itself: it’s been made and remade by waves of immigrants and colonizers down the years. It is, Li reminded me, the Chinese city most influenced by, and attuned to, the rest of the world. In the 19th century Europeans and Americans governed and occupied key locations in China through a system of forced “concessions.” Shanghai, and its strategically powerful port, was particularly valuable; the British and Americans combined to form an International Settlement (its waning days memorably evoked by J. G. Ballard), while the French Concession stood alone.

A back street in the French Concession. Photograph: Lawrence Wang. See also Wang’s photoessay of must-see Shanghai places.
Neither exist formally today, though the French Concession remains a key district in the city, characterized by creative businesses, global cuisine and backstreet coffee shops. “What’s fashionable around the world gets to Shanghai pretty easily,” Li says. (There is, much to his dismay, little in the way of street food, here or elsewhere in the city. In an attempt to “keep up appearances” for the outside world, the city began requiring street food vendors to be licensed in 2011, and there is a history of tension and violence between authorities and unlicensed cart operators. Li says the air used to be filled with the spicy, smoky flavors of Xinjiang barbecue, but no longer.)
The French Concession is also the most walkable district of the city, a kind of “Shanghai bubble” of pretty, tree-lined streets. If you’re based there or thereabouts, as XinCheJian is, the city is pleasant and manageable. Li himself lives about 15 minutes away by car, in a densely populated central district called Jing’an. Li, his wife and 8-year-old daughter live in an apartment, which they own.
Living centrally makes things relatively easy. If you happen to be based further away from the heart of Shanghai, good luck. Yes, there’s an extensive public transportation system — buses, a subway — and cabs are relatively inexpensive in the center of town (about $4/journey). But it’s slow, says Li. Many people choose to ride bikes, even along major roads and in everything but the most brutal temperatures. At least the city’s almost uniformly flat.
Riding a bike is, of course, the cheap way to get around. Now Li says bicycles are “getting trendy,” appealing to the moneyed middle class. When Brompton, the British folding bike company, sought a location for its first showroom in China, it chose Shanghai. But bike lanes, you ask? Forget it. Shanghai drivers often park their cars on sidewalks. “That will be the first thing to solve,” says Li.
See Brompton Junction’s showroom in the photoessay of must-see Shanghai places by Lawrence Wang »
David Li’s passion is XinCheJian. To earn a living, he works as a freelance consultant to internet and mobile companies. That doesn’t leave much time for anything else, although as much as he can, he tries to keep tabs on the city’s cultural offerings. For all of Shanghai’s 21st-century architecture, he says the city has yet to develop much of an appetite for contemporary art. The Shanghai Museum, which showcases classical Chinese culture, draws larger crowds than the Museum of Contemporary Art Shanghai. Both museums are in People’s Park, just west of Shanghai’s famous stretch of riverside, The Bund, where tourists fill up on Art Deco and knick knacks.
The Bund is full of historical buildings, but this is a city that’s always directed at its future. Li estimates that, over the last decade, one new museum building has opened in Shanghai every year. He says the city does things in reverse order. The buildings arrive first, often at the direction of the government. Decisions about what to put in them come second. And audiences follow, or don’t. Right now that means Shanghai is a wonderful place to see art in peace and quiet. Go after lunch on a weekday, as Li does from time to time, and you can have the run of giant spaces such as the new Power Station of Art, housed in a former thermal power plant. Take that, Tate Modern.
Li gives one instruction to every first-time visitor: pay a visit to Shanghai’s trendy, affluent Xintiandi district, just south of People’s Park. The business district’s media office describes it as where “yesterday meets tomorrow in Shanghai today,” which at one and the same time confuses and yet tells you everything you need to know. Xintiandi is dotted with shiny shops and sleek, upscale restaurants, many of them operating out of renovated traditional Shikumen homes (literally “stone warehouse gate”). Here, in a state of pedestrianized calm, you may top up on as many of the trappings of the global urban elite as you choose. Then, once you’re dressed in the expensive drapings of the tony brand, Shanghai Tang, and hydrated by, um, Starbucks, Li suggests you go get “one of the most amazing experiences you can get in Shanghai,” a dose of anti-capitalist, anti-foreigner propaganda at the Museum of the First National Congress of the Chinese Communist Party (held on this site in 1921). Those two Shanghai experiences, opposites in harmony, will give any visitor a good sense of the current Chinese moment. “It gives you a perspective on what this country looks like right now.”
When he really wants to get away from it all, Li leaves Shanghai entirely, to head to one of the smaller cities nearby, such as Suzhou, Wuxi, or Hangzhou. The latter, about 100 miles away, features Xī Hú, one of China’s urban glories (literally, the “West Lake”). You can rent a bike, ride up into the hills and stop for green tea on the way back down.
In Shanghai itself, authorities are developing a “recreational area” southwest of the city center, a glorified park-on-a-hill called She Shan. There’s a golf course and a small forest. But since it’s so difficult and so maddening to wade through Shanghai, Li much prefers to take the fast train all the way to the West Lake. “It’s actually easier to get there,” he says.
To see some of David Li’s favorite places in Shanghai, see this gallery of photographs, photographed by Lawrence Wang »
Or, check out this annotated map (click the pins to view details of his chosen spots):
To see other profiles in this series, including a profile of New York City’s trash anthropologist and an amateur signmaker in Lahore, Pakistan, check out TED’s Cities topic page »
Alex Gallafent is a contributing correspondent for PRI’s The World and a former BBC radio producer. He’s also a freelance experience designer, currently with ESI Design, and a composer and sound designer for theater and film.
]]>
This week’s TED Radio Hour examines the hacker, a term often associated with computer crime. But, as host Guy Raz tells us, “All of our TED speakers today are hacking for good — hacking into our brains, into the environment, even into the DNA of extinct animals — hackers trying to save the world.”
First up, Mikko Hypponen, the programmer who visited the creators of The_Brain, the very first computer virus that plagued the technology world in 1986. In his talk from 2011, Hypponen tells the story of how his investigation of the virus led him to an address in Pakistan. Embedded in the code of an infected floppy disk, Hypponen found English text that said, “Welcome to the dungeon 1986. Beware of this virus. Contact us for vaccination.” Following their instructions, Hypponen found himself face to face with the people who had made history. The reason they did it: to prove that the new PC computers were insecure. it’s evidence that the first hackers were actually good hackers.
The next TED speaker in the episode is a completely different kind of hacker. Stewart Brand is using DNA from fossils and preserved specimens to bring a species back from extinction. In his talk from TED2013, he tells the story of Martha, the last living passenger pigeon who died on September 1, 1914. Brand and his colleagues are engaged in “resurrection biology,” also known as “de-extinction.” The idea is to insert genes from an extinct species into a closely related living species. Brand says he is using hacking to organize the past. “Sorrow, anger, mourning?” he says. “Don’t mourn; organize.”
David Keith imagines hacking the planet — the idea that we could correct climate change by manipulating the stratosphere. As he explains in his TED Talk, the addition of sulfuric acid droplets to the stratosphere could create small wisps of cloud that can deflect some of the sun’s rays. Adding one pollutant to another could cool the global temperature back down again. But the unintended consequences could be dire. Just as people drive faster when they have an airbag in their car, would such scientific manipulation keep us from truly solving the problems with our environment? Keith concludes, “The understanding of nature gives us power to do great harm as well as, potentially, power to do good..”
Jay Silver is the most literal hacker on the show, and he gives us an interesting way to think about the job. “A hacker is someone who doesn’t ask how something works, they just see what works,” he says. He compares his work to a kid who tries something over and over again in order to explore the different possibilities. The creator of the Makey-Makey, Silver suggests that almost everything is hackable: “Humans, plants, kitty cats, grandmas, water, graphite.” For Silver, hacking has made the very landscape of life a form of expression.
Closing out the episode this week is Andres Lozano, the renowned neurosurgeon who is hacking into the human brain. Lozano explains how it is possible to adjust the circuits of the human brain using electricity, turning up or down areas of activity using something similar to a remote control. In his TED Talk, Lozano shows a video of a woman with Parkinson’s disease and demonstrates his technique by alleviating her tremor almost entirely.
Having conquered the control of movement, Lozano suggests, could we also use this technique to clear the dark cloud of depression? In the episode, he broaches the controversial subject of what he calls “cosmetic brain surgery.” He says that the possibility of altering cognitive personality is within reach and describes it as “mapping an unexplored galaxy, an unexplored universe.” But like David Keith’s issues with manipulating the atmosphere, the celebration of human ingenuity is not the only consideration here. Lozano asks the important questions: should we be messing with intrinsic personality? And is it fair that only the rich will have this expensive opportunity?
All these speakers prove that humans have developed incredible ways to manipulate the universe — but just because we can, doesn’t mean we should. The question, then: Who should be making the decisions?
Check out your local NPR schedule to find out when TED Radio Hour’s “The Hackers” airs or listen to via the NPR website »
You can also head to iTunes, where the podcast is available now »
]]>
Photos: James Duncan Davidson
Cybersecurity specialist James Lyne takes the TED2013 stage to show us some of the newest and nastiest creations that cybercriminals have designed to steal data, make off with billions of dollars, watch people through their webcams and target power and utility companies. Every day, he says, about 250,000 new pieces of malware are created and 30,000 websites infected.
“People think that, if you get a computer virus, you’ve been on a porn site,” says Lyne, of the security firm Sophos. “Actually, statistically speaking, if you only visit porn sites you’re safer.” Shockingly, 80% of infecting sites are actually small businesses or other legitimate enterprises that have themselves been infected.
The world of malware is becoming commercialized. Cybercriminals now advertise online, offering their services for $10 to $50 per hour. Lyne shows this video as an example.
There are sites where you can test a virus to make sure it works before unleashing on the world, and sophisticated services for tracking your malware. Some of these services even offer customer support.
So what are some ways to infect a computer with malware? In addition to the old “Hello, I’m a Nigerian banker,” you could, perhaps, walk into a corporate lobby with a copy of your resume soaked in coffee, and make a sad face and ask the receptionist to plug in a USB key and print you a new copy. Or perhaps you can target a website that has an insecure comments section; anyone who visits the page will then be infected. And there’s a new tactic that Lyne has noticed — creating a virus that pops open a fake anti-virus protection software window on a person’s screen. By clicking the button, not only does a person give a hacker access to their computer, but might even pay for the privilege.
So many stories about cybercrime are terrifying. But Lyne has a success story to share — a time he was able to track the group of cybercriminals behind the Koobface malware. This group didn’t protect their malicious code, which was written to send each of them a text message daily to show them how much money they’d accumulated. In other words, Lyne’s team had their phone numbers. From there, he could tell they were located in Russia.
Because many smartphones embed GPS data about where photo is taken, Lyne was able to find the hackers’ exact location through photos they uploaded to Flickr. From there, Lyne’s team generated a 27-page report filled with information about this group — including an ad one of them had posted for the sale of kittens, shots from a fishing trip, a photo of their office on the third floor of a building and images from the office Christmas party. He eventually even found their bank accounts.
Sadly, Lyne reveals that this report wasn’t enough to bring these hackers to justice. Most laws pertaining to cybercrime are national, and because there is no common definition between countries, this group is still at large.
Lyne stresses that, for the time being, the onus is on individuals to protect themselves by creating different passwords for different websites and using basic internet safety protocols. For example, don’t upload smartphone photos to an online dating site — Lyne has found that 60% of photos there contain location data. But vulnerabilites can be even more subtle than that. As you move through the world, using your phone to connect to wireless networks Lyne warns that you are “beaming a list of the wireless networks you’ve previously connected to.”

“As we play with these shiny new toys, how much are we trading off convenience over privacy and security?” asks Lyne. “The internet is a fantastic resource for business, art and learning. Help me and the security community make life much more difficult for cybercriminals.”
James Lyne’s talk is now available for viewing. Watch it on TED.com »
]]>
By Shyam Sankar and Gabe Rosen
The Internet is the new Wild West, a frontier big enough for every pioneer and outlaw to roam free. Today, The New York Times revealed that hackers in China had spent the last four months infiltrating its computer systems and pilfering employee passwords. As in the old West, it’s not a question of if you’ll be hit — but when and how. Online, primitive DDOS attacks rain down like arrows, while artful hackers can steal the data equivalent of 5,000 head of cattle before any breach is detected. There’s no choice but to defend the homestead as best you can – and retreating to civilization is no longer an option.
According to Mandiant, the infosec firm that conducted the investigation, the Times was first compromised on September 13. The attackers established at least three backdoors and installed 45 pieces of malware, only one of which was detected by Symantec security software. After two weeks, the attackers found the domain controller that contained all staff passwords. Times executive editor Jill Abramson maintains there is “no evidence that sensitive emails or files” were accessed, yet the investigation found that the attackers “created custom software that allowed them to search for and grab [Times journalists] Mr. Barboza’s and Mr. Yardley’s e-mails and documents.”
As the TED Blog recently recounted, we know a bit about this sort of thing at Palantir. Our platform was used to investigate “GhostNet”, a Chinese cyber espionage network. In 2008, an unnamed country received an email from China warning them not to host the Dalai Lama for a scheduled visit. The email was startling because this visit was not public knowledge. The country sought to find out how this sensitive information had been leaked. Not only the Dalai Lama’s personal computer been hacked, but 1,300 computers across the globe had been infected in the same way. This network had been operating for two years without notice.
Naturally, when we heard about The New York Times hack today, we looked for parallels. The Dalai Lama’s office was infiltrated by “spear phishing” — where hackers research a person and create an email, with an attachment, that looks like it came from a confidant. Spear phishing is suspected, though not confirmed, in the Times attack. Like GhostNet, the Times attackers covered their tracks through intermediaries in numerous countries, and employed remote access tools (RATs) and malware. The attacks also appear related to Chinese political sensitivities, though the exact loyalties in play are murky.
While it’s important to resist easy conclusions, Occam’s razor and common sense shouldn’t be ignored. The difficulty is that positive attribution is rare in cyber warfare, so when something looks like the work of someone who was never actually identified, it may not be exceptionally meaningful. As open-source sleuth Jeff Carr points out, there are several doubts. Beijing’s time zone includes numerous other cities. The attacks were ultimately traced to Chinese IPs, though their geo-locations encompass millions of people. The attackers used RATs, but these are widely available and hardly confined to China. According to Richard Bejtlich, Mandiant’s chief security officer, “When you see the same group steal data on Chinese dissidents and Tibetan activists, then attack an aerospace company, it starts to push you in the right direction.” Given the vast spectrum of potentially interested parties, it’s a very general direction – but it’s a start nonetheless.
The lack of clear answers notwithstanding, Mr. Bejtlich is certainly correct that cyber defense “requires an internal vigilance model.” You have to sleep with one eye open, and preoccupation with one mode of attack leaves you vulnerable to others. As in the old West, it’s essential to make common cause with your neighbors, however distant. During the recent spate of suspected Iranian DDOS attacks, two global Top 20 banks shared threat data in real time with each other as well as US law enforcement, and collaboration across public/private lines is essential to countering the matrix of state and non-state combatants.
Above all, we need to adopt a Wild West approach of our own. The sheriff’s only hope is to become as swift, resourceful, and adaptive as the outlaws.
Shyam Sankar is the Director at Palantir Technologies. He gave the TED Talk “The rise of human-computer collaboration” at TEDGlobal 2012, as well as the talk embedded above at TED2010. Gabe Rosen works in Business Development at Palantir.
]]>Below, in a TED Blog exclusive recorded at TED2010, Sankar explains how his company, Palantir Technologies, helped create software to solve a mystery: Who hacked the Dalai Lama’s email?
Here is the story.
In 2008, an unnamed country received an email from China warning them not to host the Dalai Lama for a scheduled visit. The email was startling for a single reason: The upcoming visit was not public knowledge yet. And so the country brought in a team of data experts to find out where the message had come from and how this sensitive info had been leaked. The team used Palantir’s data analysis tools to help crack the case.
As it turns out, the Dalai Lama’s email had been targeted by spies using a practice known as “spear-fishing” — in which hackers do research on a specific person to create an email that looks like it came from someone they know well. The email includes an attachment that, if opened, gives hackers access to the target’s computer without their knowledge. As Sankar explains, hackers can not only read your email, export documents and send emails as you — they can even turn on your webcam and hear every word you say.
In this case, the hackers had downloaded negotiation documents off the Dalai Lama’s computer.
“These guys literally took the goods while sitting at home in their pajamas,” says Sankar in the talk.
But in the hands of a team of human data experts, Palantir’s technology helped showed something even more sinister at work. About 1,300 computers in 103 countries had been infected in the same way. The computers belonged to both individuals and companies with interests in Southeast Asia. And this network had existed for a shocking two years before it was made visible.
It’s a story that should warn us all to be very careful when it comes to opening attachments.
]]>
Anthropologist and academic Gabriella Coleman starts her talk with a simple-sounding question: “Who is Anonymous?” She promptly confesses that even after “exhilarating and extremely frustrating” years of studying the group, she still finds this question difficult to answer.
First of all, it’s not an organization with one or even a few leaders at the helm. It’s a name adopted by various unrelated groups of hackers and technologists to describe a whole range of actions, from hacks against security firms to technical support for occupiers to those involved in national revolutions. Subgroups such as Antisec, meanwhile, scour servers to look for sensitive national, military or political information they can leak to the world. What links the groups is a spirit of irreverence and disdain for the law as it stands.
It all starts with Internet trolling, a long-established habit in Internet circles. “Generally this contains a combination of four things: pranking, trickery, deceit and defilement,” says Coleman. Essentially a way to harm someone’s reputation, it often included the release of personal information, even the assault of an individual or company with unpaid-for pizzas. What’s the point? The laughs, or as Anonymous might put it, the “lulz.”
Declared the Internet Hate Machine by Fox News, a name Anonymous entirely embraced, the group has become more serious in recent years. What inspired them? Oddly, the church of Scientology. When they demanded that a leaked recruitment video be taken down, Anonymous got mad — and bombarded Scientology churches with free pizzas (and many other things besides). As an Anonymous member who taught Coleman’s class described it, it was “ultra coordinated motherfuckary.”
And it was at this point that a serious discussion began within Anonymous. Soon enough, it was clear that a political movement had been born. “Participants now saw themselves as bona fide activists–with an admittedly transgressive twist,” she says.
Not all geeks are members of Anonymous, or even agree with the group’s tactics. Yet together they have been an explosive force, and she has four ways to describe more about who they might be:
1. Anonymous scales and is participatory; it is not just hackers. 2011 was the “summer of endless hacks,” she acknowledges. The CIA website was taken down (again). PBS was defaced after an interview with Bradley Manning. “But the hacking is only one weapon among many,” says Coleman. Anonymous does many other things too, including distributing press releases, creating videos, designing propaganda posters.
And while technical elites certainly have authority within Anonymous, there are no barriers for participation. “All it takes is to self-identify as Anonymous,” says Coleman, saying that we could all declare ourselves right now (the audience doesn’t seem so tempted). But the scale and reach is not limited to any kind of hierarchy.
2. Anonymous may seem chaotic, but most targets are not random. Anonymous has names and reasons. “They may not be good reasons, but they exist,” says Coleman. Their most infamous operation humiliated HBGary CEO Aaron Barr, after Barr had boasted that he had infiltrated Anonymous and was ready to hand over names to the FBI. Anonymous instead gutted HBGary’s servers of 70,000 corporate emails. Operation BART happened after the transport agency blocked cell phone reception to block a planned protest. “Just yesterday, there was an operation in Japan after the country passed anti-piracy laws,” Coleman says. “Anonymous is not proactive, it is reactive, event-driven. It rises up most forcefully when internet freedom is in jeopardy.”
3. They put on a good performance, obvious even to their detractors. The political art of Anonymous is spectacle, says Coleman. The group has a formidable PR machine, which becomes a PR nightmare for others. Yet here’s the thing: Spectacle alone won’t engender political change. Perhaps the greatest accomplishment of all the spectacle, Coleman posits, is that “they dramatize the importance of anonymity and privacy in an era when both are rapidly eroding. Given that vast databases track us, given the vast explosion of surveillance, there’s something enchanting, mesmerizing and at a minimum thought-provoking about Anonymous’ interventions.”
4. They are visible and invisible. Unlike criminal groups that stay hidden at all costs, Anonymous allegedly announces itself loud and proud. It has received enormous attention, fear and admiration — it won the People’s Choice award on Time magazine’s online poll and was voted the top cybersecurity threat by IT professionals. Yet they’re also evasive and shifty. “It is hard to know how many people are involved,” says Coleman, thanks in part to an internal culture of avoiding personal fame at all costs. Hackers who have risen in visibility are chastised, marginalized, even banned. It’s difficult to know who did what when or how. What’s clear is that even though Anonymous members are so paradoxical and contradictory, “they have tapped into a deep disenchantment with the status quo as concerns censorship privacy and surveillance.”
This is why it doesn’t really matter whether Anonymous as it exists even lasts. Roiled by arrests and paranoia, the group may well implode. But, says Coleman firmly, “irreverent dissent on the internet is not going to go away with Anonymous.” Many geeks and hackers care about protecting the Internet, and they both invent and manage these resources, so it’s not surprising that this movement is under way. It might be difficult to come up with a blanket moral assessment of Anonymous’ influence, but it’s clear that this is just one moment. And, concludes Coleman, “if you try to hurt what’s so valuable about the internet, be careful — because the internet may very well hurt you back.”
Photos: James Duncan Davidson
]]>