<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>W. Andrew Jones. 
Thoughts on politics. Contact me</description><title>“Look, the Horizon!”</title><generator>Tumblr (3.0; @wajones90)</generator><link>http://wajones90.tumblr.com/</link><item><title>"Cyber attacks", advocacy groups, and legitimacy</title><description>&lt;p&gt;&lt;p class="p1"&gt;Yesterday, &lt;a href="http://avaaz.org/" target="_blank"&gt;Avaaz&lt;/a&gt; posted a newsletter release stating that they were experiencing a &amp;#8220;massive&amp;#8221; cyber attack, sophisticated to the point that&lt;/p&gt;
&lt;blockquote&gt;
&lt;p class="p1"&gt;&amp;#8220;likely only a government or major corporation could launch an attack this large, with massive, simultaneous and sophisticated assaults from across the world to take down our site.&amp;#8221;&lt;/p&gt;
&lt;p class="p1"&gt;&lt;a href="https://secure.avaaz.org/en/massive_attack_on_avaaz_b/" target="_blank"&gt;https://secure.avaaz.org/en/massive_attack_on_avaaz_b/&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p class="p1"&gt;Their immediate followup, in the same newsletter, is to ask for donations on their website, to contribute to a &amp;#8220;defence fund&amp;#8221; to protect against future attacks.&lt;/p&gt;
&lt;p class="p2"&gt;This raises all kinds of alarm bells - not of the kind it is in Avaaz&amp;#8217;s interest to raise.&lt;/p&gt;
&lt;ul class="ul1"&gt;&lt;li class="li1"&gt;if their website is currently under attack, should supporters feel comfortable donating via their website? Wouldn&amp;#8217;t that actually put the supporters&amp;#8217; personal information or credit card details at risk?&lt;/li&gt;
&lt;li class="li1"&gt;how does &amp;#8220;donating now&amp;#8221; mitigate an ongoing attack?  Security investments that could come as a result would be implemented months down the road. If the website continued to function normally throughout that time, then the urgency or necessity of the &amp;#8220;security&amp;#8221; donations is strongly put into question.&lt;/li&gt;
&lt;li class="li1"&gt;what is the severity of the attack, and who is the expert who can corroborate that it is happening? Is there any third-party assessment, beyond Avaaz&amp;#8217;s own internal claims?&lt;/li&gt;
&lt;/ul&gt;&lt;p class="p1"&gt;The overall situation raises an important point - that, in the future, as online campaigns or online activities of advocacy groups play a more influential role, they will somehow be targeted by other actors (indeed, corporations, governments or organizations with a different political view) who are challenged by their activities. Without a doubt, at some point in the future this may become a very real concern for advocacy groups.&lt;/p&gt;
&lt;p class="p1"&gt;What isn&amp;#8217;t clear, in Avaaz&amp;#8217;s messaging, is if that is legitimately the case here. To - all at once - state that you are &amp;#8220;under attack&amp;#8221;, that you need urgent security investments, and to ask for donations, is a combination of messages that seems ill-advised (if not extremely questionable), especially without any sort of third-party confirmation. &lt;strong&gt;If you were &lt;em&gt;pretending&lt;/em&gt; to be under &amp;#8220;cyber attack&amp;#8221; and were hoping to solicit donations under those grounds, your message would look exactly the same.&lt;/strong&gt;&lt;/p&gt;
&lt;p class="p1"&gt;What makes things much more blurry is that &amp;#8220;cyber attack&amp;#8221; is a term that is almost impossible to define. Are they being spammed by some malicious server filling their petition forms with links to (of course) questionable pharmaceutical sites? If so, that&amp;#8217;s less a cyber attack, and more a regular fact of running a website on the internet, something dealt with (not always easily) with careful (but not expensive) network security setups. Perhaps the case here was spawned from a simple miscommunication between some computer consultant and Avaaz&amp;#8217;s campaign team: small-scale &amp;#8220;cyber attacks&amp;#8221; are entirely normal, for any website online. In most cases, finding out that they are occurring does not lead to a donation campaign reaching millions.&lt;/p&gt;
&lt;p class="p1"&gt;If Avaaz was the target of a carefully-designed, globe-spanning computer virus aimed exclusively at their systems (as was the case in the recent Iran incidents that Avaaz&amp;#8217;s situation is &lt;a href="http://www.techweekeurope.co.uk/news/human-rights-body-avaaz-under-massive-cyber-attack-76217" target="_blank"&gt;compared to here&lt;/a&gt;), then that would be a very different story - and a few thousand dollars in donations would not have any impact in preventing it.&lt;/p&gt;
&lt;p class="p1"&gt;&lt;strong&gt;This sets an extremely uncomfortable precedent for other non-profit organizations.&lt;/strong&gt; To pay for website upgrades or network security, should they also claim to be &amp;#8220;under attack&amp;#8221; by mysterious corporate cyber attackers? If they actually are &amp;#8220;under attack&amp;#8221;, should soliciting donations via their (still-under-attack) website really be the first action they take?&lt;/p&gt;
&lt;p class="p1"&gt;And finally: are the groups that are targeted most, really the most deserving recipients of your donation money? Should &lt;em&gt;that&lt;/em&gt; be your criteria for donating to an organization?&lt;/p&gt;
&lt;p class="p1"&gt;Donate to organizations that do good work. Full stop.&lt;/p&gt;
&lt;p class="p1"&gt;And to organizations like Avaaz: if your online sites are under attack, enlist some computer security firms perhaps on a pro bono basis to improve your network security. If those investments cost money, ask for it, months later, as part of your regular administrative costs - not as an urgent, &amp;#8220;only your donation can keep us online&amp;#8221; appeal that can only smell contrived (at best) or put donors at risk (at worst).&lt;/p&gt;&lt;/p&gt;</description><link>http://wajones90.tumblr.com/post/22326898619</link><guid>http://wajones90.tumblr.com/post/22326898619</guid><pubDate>Thu, 03 May 2012 13:20:00 -0400</pubDate></item></channel></rss>
