Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.
Speaker B: Hello and welcome to Password on Resonance 104.4 FM, the radio program that looks into the issues that technology raises in our technology-driven lives. I’m Peter Warren, and this month we’ll be looking into an issue that has begun to dominate the newspaper headlines since a poisoning in Salisbury with a nerve agent of Sergei Skripal, the Russian intelligence officer who was working as a spy for the UK, and his daughter Yulia. The prospect of a cyber war. In mid-March of this year, one national newspaper warned that the Russians were targeting the national grid with the aim of knocking out the UK’s electricity network. Well, in early April, the UK’s National Cyber Security Centre issued a warning that an ongoing attack against companies involved in the critical national infrastructure supply chain had been going on for over a year. This tense atmosphere has been further strained by calls from UK MPs for cyber reprisals against the Russians, along with the expulsions of diplomats that have already occurred. But what does that mean? And are the lights going to suddenly go out? Well, not according to Dr. Tim Stevens, a lecturer in global security at King’s College’s Department of War Studies and a specialist on cyber conflict.
Speaker C: I mean, let’s get one thing straight, which is that, as you well know, Russia and the UK are in each other’s networks all the time, mostly as a form of reconnaissance, of intelligence gathering, perhaps for prepositioning certain types of logical tools, shall we say. So neither is a stranger to each other’s networks. But my impression would be that were the UK to have embarked upon a new course of action, should we say, through cyber means, most of it would be invisible to the everyday observer in the sense that whatever it was we decided to do in Russian networks would be highly classified, not intended to be visible, but would be covert signaling to the Russians that we know where your assets are and we know how to play with your networks and so on. The likelihood of causing something more visible through those means, I would say, is extremely slim indeed. Because, you know, Stuxnet, for example, which we always talk about in these debates, was a covert operation that effectively became visible by accident. This would not be something that became visible by accident but was visible by design were the UK to embark upon a rather more overt course of action. And that is escalatory. It is also potentially illegal.. And one of the things the UK should be striving to do at the moment is to remain legally above board, demonstrate that it has moral authority, that it’s following the rule of international law. And I don’t think it would have been very wise on any level to embark upon cyber operations of the sort of offensive kind that was being mooted.
Speaker D: It was stated in an English paper very recently that the national grid is vulnerable to attack. From Russian hackers. If the national grid were attacked, surely under the NATO Convention that would be interpreted as— again, you would have to prove the responsibility— but under the NATO Convention that would be viewed as an act of war.
Speaker C: Probably, yes. Under Article 5, yes, it presumably would. The problem, of course, would be attributing it to a specific actor and— this is always the problem. In the public mind, there seems to be an understanding that intelligence assessments should meet the criterion that would pass in a court of law. That’s not how intelligence assessments are framed. Intelligence assessments are stated in language of what’s called estimative probability. So things are likely, highly likely, probable, possible, etc., etc. And that’s based on usually a high degree of internal intelligence assessment and analysis. Quite often, those would not pass muster in a court of law where it needs to be much more tightly considered. But it’s also not how international affairs worked anyway. So you have to put all the different types of evidence together, which includes the strategic context in which such an event might take place. If you’re already in a heightened state of hostility with another nation, that has to enter your strategic consideration of whether they are responsible or not. It doesn’t answer the question of 100% can you be sure that a Russian state actor was responsible for that particular incident. But of course that makes it a very difficult sell then to your public if you’re thinking about responding through international legal means or through the sort of collective security arrangements of something like NATO.. But if were it judged to be a very high level of probability that a Russian state actor was involved, for example, in an attack on the national grid, then there undoubtedly would be a meeting of the NATO Military Council. There would be other meetings with respect to Article 5. Does this raise to the level of an act of war, and what should our response be? Fortunately, we haven’t had to have those discussions. There were some very tentative discussions, as you know, around the Estonia 2007 attacks, which rejected— well, decided not to trigger Article 5. And it would be interesting to see what would happen this time round, given that actually the level of conflict between, at the moment, the UK and Russia is significantly higher than it was between Estonia and Russia 10 years ago.
Speaker D: If Russia were to attack the national grid, and if they were the people who were behind that attack, they would be giving away the fact that they were capable of doing that.
Speaker C: They would, yep. They would also almost certainly deny that it was them. But it would give National Grid at least the opportunity to patch those vulnerabilities. Of course, you don’t know whether there’s knowledge of other vulnerabilities existing within the Russian intelligence and military units. But yes, it would. And you wouldn’t want to do that unless you’re quite prepared to take it to the next level, which Russia full knows would be a discussion about Article 5. And I don’t— I see Russia as being provocative, as being destabilizing, but I don’t see it as warmongering. With respect to the UK, not least because of who our closest security ally is. And Putin, if he’s many things, which he is, he’s not a fool. And an out-and-out attack on UK infrastructure, which might be conceived of as a military act of war, I don’t think is currently on his main to-do list sitting on his desk in the Kremlin.
Speaker D: Do you think that a cyber response is one that we should be involved in? And also, do you think that we should really, rather than going for a cyber response, we should be trying to win the moral high ground, which is information?
Speaker C: I think there probably are forms of COVID cyber responses already going on. They will be signaling in covert fashion to the various units within the Russian military and intelligence apparatus that we know who they are, we know what they’re up to, and we know what is of value within your own networks. The response to information and cyber operations does not ever have to be cyber or information operations, although arguably any kind of political response is an information operation in the sense that it’s attempting to change someone’s behavior through psychological means. But what I mean is that a cyber or information operation can be responded to in another domain. So it can be responded to through economic sanctions, it can be responded to through pushing perhaps your troops further towards Russian borders, you know, little forms of signalling that don’t necessarily have to be a cyber attack or retaliation.
Speaker B: That was King’s College’s Dr Tim Stevens pointing out that there are very real problems in the new cyber realm in knowing who has done what and even when something has been done. This is the ultimate game of smoke and mirrors. Behind the scenes, virtually invisible. An issue that, as we have seen in the claims and counterclaims surrounding the Salisbury incident, is not confined to the technology world. But cyberwar is dangerous. Most conventional thinking about cyberwar is that it can quite easily lead to a real war. Commodore Patrick Tyrrell, a former military intelligence officer, does not think that this is at all likely, but he still believes Russia is thinking very hard about how it may use cyber weapons to make life uncomfortable for the UK. For Terrell, who was the first person in the UK to warn the MOD about the risks from cyber attack, the Russian strategy is an ongoing campaign of instability, a campaign that can be reinforced by using strategic cyber attacks.
Speaker E: To increase that uncertainty. The Russians have made extremely good use of these sort of black hacker groups which may or may not be actively directed by the Russian state.
Speaker D: And so when you say black hacker groups, what you mean is deniable hacker groups, i.e., criminal hacking groups? Yes.
Speaker E: And if you look at Russian activities over the last few years, they’re quite happy to deny things even when it’s extremely obvious that they were the people behind it. So there’s an awful lot of room for a clever and ruthless opposition to be able to make mayhem when it wants to.
Speaker D: But that’s the question, isn’t it? When it wants to. Because at the moment, there wouldn’t really be much point in entering into a cyber war, would there? According to the, what, the classical view of how you go about using cyber in a war, the Chinese, for example, in their war doctrine, they say that they would use cyber in the run-up to a physical war, that they would use it to destabilize a population and to create psychological issues?
Speaker E: Yes, I think that we’ve all, when studying the issue of cyber war, we’ve always looked at it as being used in the lead-up to a hot war. I think in reality it’ll get used at all points, both in the run-up to a hot war and during a hot war. Because I think that our ability to wage cyber war, and by that I mean not just the West but Russia and China’s ability to wage cyber war, is getting better and better every year. They exercise it more, they develop the doctrine more, they develop the tools and the software to be able to get these things to be more effective. Now, as to whether it’s in the Russians’ interests to perhaps attack the UK and damage our infrastructure in some way, well, you’d have to ask the Russians that. I think that they do like to discomfort Western powers and Europe in particular. They have certain things they want to obtain in Europe, not least of course the Baltic States. They don’t like the West getting too involved in the Ukraine, which they still see as a fundamental part of Russia. And, you know, they may decide it’s worth the candle, particularly if they’re working at arm’s length with these black groups that can wage information warfare on their behalf.
Speaker D: So what sort of things would those black groups do, Pat?
Speaker E: What are the tactics that you could expect to see those black groups engage in? Well, I think that as with all attacks, you will go for where you find vulnerabilities. So they found a vulnerability in the National Health Service. It caused mayhem. Whether people died as a result, I’m not sure that we know, but certainly it caused difficulties for the National Health Service for a reasonable amount of time. I’ve always maintained if they did an attack on the railway network, we probably wouldn’t notice the difference. You know, we’d blame it on the wrong type of rain or leaves on the track or signalling problems, but you could see that sort of thing happening. And we’ve got to be aware that these things can happen over a vast range of commercial and public systems. So you could have an attack aimed at the financial centres like the City of London. Which might cause— not saying it would, but it might cause problems with accessing cash from ATM machines. You know, all of these are possibilities, and at all times there are people out there who are looking at and probing our systems to see where there might be a vulnerability.
Speaker F: If I had to If I were to take a guess, I would say, you know, UK against Russia, Russia probably has significantly greater capability, and that’s historic. We’ve seen aggression out of them since around the turn of the century in hacking attacks, in cyber espionage, which is fairly well attributable. But the bigger question actually is, in terms of our capability, How many people in UK do we have that we can utilize that speak Russian to affect the Russian systems as opposed to the UK which the internet is primarily English, you know, English language. It’s still the predominant language on the internet and a lot more people are used to dealing in English and are much more effective in English than we have people people, I would guess, that we could mount who could be effective in Russian.
Speaker D: So what you’re saying is that if there is going to be a conflict, that this conflict would appear to be a propaganda conflict, an information war. Um, but an information war is a propaganda conflict plus, isn’t it?
Speaker F: I come back to, you know, the Russian perception and doctrine. Is very different. If you, you know, if you go back to 2008 and the Georgia conflict, out of that you got the— what clusters— the Gerasimov Doctrine. And it is about perception management. It is not about cyber specifically. It is about using whatever methods to affect the perception and the willpower. So this is why cyber response may not be the most appropriate, and our way of thinking, I think, needs to change, and we need to understand better what they’re trying to achieve using whichever tools are available.
Speaker D: So what are they trying to achieve then?
Speaker F: They’re trying to reduce the threat to themselves, in their view, and they do that by the whole range of tools, disinformation, etc., etc. Perception management is the way of their thinking, trying to affect the people, the decision makers, to spread disaffection amongst other things.
Speaker D: Do you want to give me some examples of that disaffection that they’re spreading?
Speaker F: Well, I guess if you want to look at it, you know, tampering with elections, whether it’s in America, Europe, you know, Germany or Italy, UK, trying to reduce people’s trust so that there’s not the strength of support for potential action.
Speaker D: What you do is you weaken people’s belief in the reasons that their politicians are giving for doing something so that people don’t actually feel that they want to support that.
Speaker F: Yeah, and you weaken the trust in those politicians and those leaders themselves. And you also affect the decision makers and their trust in the information they’re using. Are they convinced that what they’ve been told is correct? And without picking specifically on the Americans, but you know, you look at the friction between the president and the agencies in the States. I’m not attributing that to Russia, but I’m saying that, you know, if they had wanted to do it, that would be a pretty good outcome for them.
Speaker D: Okay, so essentially we do seem to be looking at— I mean, some people are calling this a cyber cool war, but it seems to be a bit of a cyber Cold War, doesn’t it? We seem to be in this situation where we’re all feeling a little tense and we’re seeing what we perceive of as lots of Russian victories. They’re getting away with doing things and we don’t seem to be able to respond. We seem to be losing elections or seeing elections being influenced, and we’re not really quite sure how that’s happening. Is that what you’re saying their strategy is, or is it that this is our perception of their strategy?
Speaker F: How do we know the difference? If that’s our perception, then maybe it has been managed. But I’m not in government and I’m not in the classified arena, so, you know, all I can what we can look at is the classified material that’s available, and we’re not doing very well. How do we respond? I honestly don’t know. What I do think is that we certainly need to look at our approach. You can’t— we might end up fighting the wrong war.
Speaker B: Its lack of understanding of Russian tactics, and indeed of Russia itself, is something that Professor Mark Gagliotti is an expert on. Gagliotti is the coordinator of the Institute of International Relations and the author of The Vory, a forthcoming book on the Russian supermafia. Professor Gagliotti sees Russia as a gangster state that uses criminals who have a frightening familiarity with technology and are intimately welded into the Russian state.
Speaker G: Well, I suspect there are several processes that are going on at once which put together makes it look more alarming than it really is. First of all, there’s the activities of the Russian so-called patriotic hackers. These are just ordinary people who, remember, are being fed this line that Russia is currently in a desperate existential struggle for its own cultural and political survival. And it’s clear that they get a kick out of attacking Western targets, as hackers do. These are not people who we could consider to be Kremlin agents. They’re sometimes mobilized for a particular attack, but basically this is just individual stuff. Secondly, yes, of course, there is also a low-level element of pressure and penetration by Russian cyber intelligence agencies. In part, it’s about building up positions, trying to find backdoor, build backdoors and so forth if it ever did come to a conflict. And the third element is that sometimes this is used as signaling. Sometimes this is a way in which Moscow tries to intimidate. In some ways, it’s a cyber equivalent of those times when it sends bomber patrols close to NATO members’ airspaces or buzzes ships with its own jets. It’s just a way of saying, “Oi, back off.” They clearly turn to criminals from time to time, and that could be, as we’ve seen, assassinating Chechen rebel fundraisers in Turkey, raising funds to support populist movements in Europe, or indeed also in the cyber realm. We see them also hiring hackers, sometimes actually recruiting hackers. So that is the case. On one level, that’s no big deal. Exactly, it’s not much more than this, the outsourcing of statecraft that we we’ve seen in the past. Where it is a big deal is, first of all, that it actually creates a very hazy line between what is state and private and criminal interests in Russian policy. And if you look at some areas, it’s sometimes hard to know if this is really the Kremlin using gangsters and oligarchs and so forth, or how far they’re using the Kremlin. But the second element is that it creates an element of uncontrollability. You cannot control these kind of outsourced instruments with the same degree of finesse that you can if they’re your own card-carrying spooks. So that is my concern. I can understand why the Russians do it, but on the other hand, they’re trading control for additional capacity.
Speaker B: I mean, that is the big issue, isn’t it? Because what you’re doing is you’re undercutting the moral integrity of a state or of states, aren’t you? That, that’s the big issue, because that means that, for instance, if we want to try to get a grip on crime, which— and, and now lots and lots of organized criminals are using cybercrime as just one bit of their portfolio— if we want to try to get a grip on that, then it’s very difficult if states are saying to a criminal element, no, you go off and be criminal, but we want to use you when we need you.
Speaker G: Yeah, absolutely. I think this is, this is one of the problems. Unfortunately, law enforcement cooperation across the board has always been one of the first victims of worsening relations. We saw that obviously after Litvinenko, for example, in Anglo-Russian cooperation. And now it’s even more the case. I think, again, the fact that absolutely now with cybercrime you have criminality that can be carried out by people who never even have to come into your jurisdiction. That, you know, 5 people sitting in Russia can carry out a cyber attack, criminal attack in the UK, not leave the country, and actually under Russian constitution cannot even be extradited. Russian citizens cannot be extradited from Russia. So that always creates one initial sort of problem. When you add in the fact that at present not only do the Russians have no desire to help us out, but also may well want to use these people as assets, it really creates a serious problem, which is not just in terms of we can’t get the Russians to cooperate and give us information, but how far are the Russians also, for example, looking at requests that get put into Interpol, not from the point of view of how can we help our fellow law enforcers, but how can We warn our own gangsters that someone’s on to them.
Speaker B: What is alarming, according to Gagliotti, is that in Russia crime is not only a business, it has become the preserve of businessmen.
Speaker G: Well, I think what’s interesting and depressing is that since the collapse of the Soviet Union in particular, we’ve seen Russian organized crime evolve quite strikingly and rapidly from precisely the kind of tattooed thugs that we know and love from film and TV into a whole new generation. This— we tend to not even use the word vóóó. They’re more likely to be known as athoritieti, authorities, who are basically criminal businessmen. They are engaged in whatever will make them, you know, get the money and power, and they don’t really care what it is. It could be entirely legitimate business, it could be gray business at the interface, or it could be outright criminality. And they will essentially have portfolios of interests that stretch across this whole range of activities. And in that context, I mean, technology is obviously crucial in several different ways. Most of the Russian cybercriminals are not members of existing gangs and networks. They are basically freelancers or involved in small circles. They are basically criminal service providers to the gangsters rather than actually members of the gangs. But the point is, it’s not just about the cybercrimes they commit. They’re also central to a lot of the money laundering scams and circuits that are created, because nowadays money is, after all, not a thing but a binary concept zooming around the world. And so they are often involved in that. They are also involved increasingly in what we might think of as criminal counterintelligence, is that if you are worried that hackers, whether they’re police hackers or just hackers working for another gang, might be trying to break into your computer or your phone, then you are also more likely to hire hackers, both to carry out the same attacks on others but also to protect you. So bit by bit, I think we have seen the Russians, more so than most organized crime fraternities, have embraced technology. They are probably the first truly post-industrial, postmodern mafia, and they are absolutely a creature of the internet and the cell phone, more so than their Sicilian or Latin American or New York counterparts.
Speaker B: Both Gagliotti and Dr. Stevens see this meshing of crime and state as having implications for the world because of the need for institutions in Russia to turn a blind eye to criminal acts.
Speaker C: Turning a blind eye to, or facilitating in some fashion, whether with a nod and a wink or through economic means, these groups to perform certain actions If they’re, you know, the general idea in this accusation that has been made of China, of course, is that, you know, if those groups and set motives and intentions are aligned with the national interest, as the government of the day sees it, then it’s A-okay and it’s open season. So go for it. I’m not sure how the British or European government would view that if it was their citizens performing those same functions.
Speaker D: Because we did see some examples of this by Russian hacking groups who showed themselves to be very patriotic and very loyal, uh, in the tension that developed between Russia and Estonia over the treatment of Russian nationals in Estonia. Websites were being attacked by Russian hacking groups who were putting Russian flags on them, things like that. That though is, again, it’s a strange area, isn’t it?
Speaker C: It is, it’s very murky, and, and I think a lot of it is done on modern wink. In the case of Estonia, I think one Russian was eventually prosecuted, and he was a member of one of the youth wings of Kremlin-affiliated party, perhaps even Putin’s party itself, I forget. But it’s kind of, you guys can go off and do this if it accords with what we think is our national interest, then we’re not going to worry too much about it, particularly if it’s happening within our territorial borders, because we’re not going to respect any kind of extradition requests or anything like that. But yeah, you’re absolutely You’re absolutely right. These patriotic hackers who pop up, and it’s not just in respect to Russia and Estonia or Russia and anywhere else. Of course, it happens an awful lot in the Middle East, whether it’s Iran, Syria, Palestine, Israel, probably many other parts of the world beside Taiwan, for example, and China. When groups think, well, what can we do? Well, we know how to code, we know how the networks work, we’re internet savvy, let’s get out there and do something. Even if it’s something as simple as denial of service attacks, website defacements, and so on.
Speaker D: But this, of course, goes to making the internet such a questionable place, making all of this so difficult. Because if you have states taking part in or turning a blind eye to this particular sort of behavior, then it allows the criminality to actually continue, doesn’t it?
Speaker C: It does. And this is part of the whole problem. It seems like an eternal question almost, you know, how do we govern the internet? And it’s very difficult if states see rather more utility in not abiding by those types of norms rather than trying to inculcate new norms that might, for example, control non-state behavior on the internet. So it’s— I’ve noticed this week that the Wild West metaphor has come up again in political conversations about the internet. Net. And what that’s saying essentially is that you can go out there and do anything you want effectively, which is a red rag to all sorts of not only just hacker groups but also to cyber criminals and to states, particularly those emerging and middle powers that have developing capabilities in this space and might be looking for ways to flex their muscles a little bit.
Speaker D: And this then actually does produce some pretty significant problems. I can remember members of the former National High Tech Crime Unit, saying that they were very frustrated because they would be pursuing people who they knew were criminals or had been responsible for criminal acts in the UK. They would go to a Russian counterpart, ask to have that individual arrested and interviewed, and they would subsequently be told, no, he’s one of ours.
Speaker C: That’s the issue. How infuriating, I’m sure, for those law enforcement officers. You know, one of the things that has happened, of course, is the Budapest Convention on Cybercrime since the 2000s, which has harmonized legislation in this space, including on transnational investigation and information assistance and so on. And of course, some of that may lead to extradition, but it’s not going to lead to extradition for countries like Russia who put sovereignty above and beyond everything else, which of course is one reason why they haven’t signed the Budapest Convention. Even though it’s open for them to sign and ratify, because they see the potential for that kind of transnational law enforcement rather more as a threat to their national sovereignty rather than as an opportunity to prosecute people who are operating transnationally, even if it’s against their national interest. So it’s a case where geopolitics and sovereignty get in the way of what we might consider common sense.
Speaker B: As a result, according to Gagliotti, Russia’s patriotic black cyber gangs have become involved in politics on behalf of President Putin?
Speaker G: Yeah, I mean, this seems to be— so-called Internet Research Agency, which has since been renamed and moved, definitely seems to have been one of the sort of particular focuses for this activity. Though again, as you said beforehand, it was actually being used for Russian domestic politics and is also used for purely commercial purposes. People can actually hire trolls to big up their products or whatever. But although that very much gets the focus of Western attention, we should stress that this is not something that is unique to that.
Speaker B: There are other troll farms in Russia. Saint Petersburg seems to be very important in all of this, though, doesn’t it? We had the Russian Business Network that emerged out of Saint Petersburg. There are large technical universities around Saint Petersburg. That seem to supply hackers, as we’ve just been talking about. There’s an internet research center in Saint Petersburg. Why is Saint Petersburg so important?
Speaker G: There’s two reasons why Saint Petersburg is such a hub. First of all, back in Soviet times when everything was all about the planned economy, as was then, Leningrad was picked as one of the high-tech hubs for both university and through technical development. And what that meant, particularly in the 1990s, is you had a load of highly trained individuals in cybernetics and computers, or even just in terms of raw mathematics, who were products of a Soviet system that actually was a pretty good educational system in that respect, but now had no work, no opportunities, no hope. This was before the days of Kaspersky Labs, let alone the possibility of being able to sort and make it across to Silicon Valley. And a certain proportion of them drifted into hacking for social and also for economic reasons. And very much, I think, what that earlier generation did was kind of create a social milieu in which hacking is cool and in which, you know, you can find mentors and sort of physical hubs where you can meet as well as virtual ones and so forth. So it is is still one of the hubs of both criminal and also legal computer activity in Russia today. The second thing, and this is where the Putin factor comes in, is also, I mean, it was the hub for one of the particular powerful organized crime groupings that emerged with the collapse of the Soviet Union, the so-called Tambovskaya network. And this was a group that when Vladimir Putin, who was briefly the deputy mayor of St. It was one of the groups with which he was essentially liaising. I mean, his job was to keep the city working by dealing with whoever needed to be dealt with, whether that was an oligarch or whether that was a criminal gang. And in fact, the head of Tambovskaya ended up being known as the night governor. The idea was that kind of the legal authorities controlled the city during the day, but Tambovskaya controlled it at night. Although actually that particular individual, a chap by the name of Barsukov, who was to change names, also known as Kumarin, was in due course arrested in 2009, nonetheless Tamburskaya for a long time seemed to be operating under a degree of protection, which— and I could not possibly comment, but some have absolutely suggested— was actually Putin’s protection. The combination of a relatively entrepreneurial, relatively economic economy-minded criminal grouping with a large proportion of local cybercriminals clearly sort of, I think, was a match made if not in heaven, but at least in virtual space that definitely has made the city quite a hub for these kind of activities.
Speaker B: That’s one of the interesting points, isn’t it? One observer once said to me that at the same time as the Americans were making Silicon Valley, the Russians Russians were building Silicon Hell.
Speaker G: Is that fair? Yeah, I mean, I don’t think the Russians were building it. I think, again, Russians have, because of their own historical experiences, a phenomenal talent for making do in what are often awful situations. And the 1990s was, for 99.999 recurring percentage of Russians, an awful decade. And therefore people had to look to basically marketize whatever talent they had. And in this case, absolutely, this is what emerged. No one intended it, but by goodness, people nowadays are exploiting it.
Speaker B: These are tactics that, according to Gagliotti, may have even allowed the Russians to shape the UK’s destiny.
Speaker G: There is a certain amount of evidence that the Russians were very keen to push Brexit. It fits into their agenda of basically trying to divide and distract the West. They don’t really care about a lot of the individual sort of cases, whether it’s pushing Catalan independence or Scottish independence or Brexit or whatever. They just like the chaos that is created. And some of this was, was fairly obvious through the kind of one-sided representations that we saw in the RT television network and on their Sputnik news site and so forth. There is also the suggestion that they may well have actually moved money or done other more covert, more subversive things to try and push Brexit. Now, that said, I would very much doubt that it had a decisive impact. The evidence we have is actually that the impact of Russian political maneuvers tends to be pretty limited, even in the American election. The thrust of my article was more that that would certainly give an excuse to a British political elite as they see the chasm getting closer and closer, if they wanted an excuse to be able to say, oh no, we need to rethink this, without just simply saying we were stupid or we think that 52% of the British public are wrong, to actually say there has clearly been some level of Russian interference, we don’t know quite how important that was, however, for the moment we need to stop the process.
Speaker B: Just how they achieved this was relatively simple according to John Pike, the highly respected director of the website Global Security, because he claims the same process was used in the US.
Speaker H: Well, it’s obviously true. I think the main intervention was in the form of manipulation of social media advertising, very micro-targeted advertising in social media using Facebook that’s gotten a lot of publicity, but undoubtedly also in other networks like Google.
Speaker D: So what, you pick on individuals and you try to get them to sort of distort their view of the world?
Speaker H: Do you need many people for that? You needed at least 70,000 because that was the number of voters by which Donald Trump got elected president. So out of a third of a billion people in the country. So you don’t need a lot of people. You just need the right people in the right location.
Speaker D: Right, so you hone in on people, and what do you do with those particular individuals?
Speaker H: Well, you know, as they say in Star Wars, the Force has a strong effect on weak minds. You know, you basically are able to identify people who are vulnerable to distorted messages, people who are susceptible to highly polarized messages. You basically develop a campaign plan to turn people around to your point of view.— to what? You know— It’s interesting that if you look at Russian online news websites, yeah, they have some high-quality journalism over there, but they also tend to specialize in news of the weird. You know, they tend to attract people who are captivated by news that might be true, or strange and improbable news, and those are the people who are susceptible to manipulation. Their media preferentially attracts people who can be persuaded of untrue things.
Speaker D: But does this then mean that we’re in a new world? I mean, people say that we’re in the information age.
Speaker H: This is— this is completely different, okay? Because back in the old days, okay, back during the Cold War, you know, Moscow Center was certainly actively trying to intervene in the Western political process. But, you know, they were basically doing it through the Communist Party in that country. And, yeah, it was— the Communists in many countries were completely discredited. You know, they had various propaganda broadcasts on the radio, but their ability to reach people, you know, it was quite limited compared to what they have today, because they are basically operating like any other political campaign. Except that they have relatively unlimited— the unlimited resources of the Russian government. And the propaganda that they put out through Facebook and Google and other such channels doesn’t necessarily look like propaganda. And through a sustained campaign, they’re basically able to find constituencies that are susceptible to their message and gradually wean them off of the mainstream consensus reality and place them in a position where they’re receptive to the channels of information that Moscow Center’s trying to put out.
Speaker D: And it got Donald Trump elected. So is this new though? Because in a sense, what you’re saying is that Russia used to look to get its political message across in various different countries.
Speaker E: Sure.
Speaker D: Encourage and support, say, the Communist Party of the United Kingdom. And so what you’re saying is that the internet has given them this greater facility to get that message out?
Speaker H: Orders of magnitude. It’s opened up bright new vistas that, uh, even 20 years ago really didn’t exist.
Speaker B: That was John Pike. You’re listening to Password on Resonance FM. Following this program is DJ Ritu and A World in London. On Password, we’re looking into a worrying phenomenon known as information warfare, which states have been developing since 1996 and the emergence of social media has made significantly more potent. For Global Security’s John Pike, the issue is that the internet, and particularly social media, has allowed the micro-targeting of vulnerable individuals on an unprecedented unprecedented scale. For the first time, organizations and individuals can reach directly into people’s prejudices and affect the results of elections.
Speaker H: Pike says this needs to be changed. Western political systems are open to clandestine manipulation by big money. The American political system has been designed so that large piles of money can surreptitiously influence the election. But in making the American political system, and political systems in other countries, in making the American political system susceptible to influence by dark money, we’ve opened up a channel by which the Moscow Center is also going to be able to play this game. They’re, you know, they’re simply another super PAC. They’re playing the way, you know, the Mercers are playing and the Koch brothers are playing and others, other billionaires are playing, except that they’ve got an awful lot more money than any of these other billionaires. And the only way that we’re going to get Putin out of American politics is to get all these billionaires out of American politics and render the American political system immune to influence by large piles of money. That’s going to be really hard to do. And so I think that you’ve got these Vichy Republicans now who would rather rule in a country that is subordinated to Putin than to participate in an independent political system that is not subordinated to Moscow.
Speaker D: You say that that’s one solution, one of the things that NATO is doing is it’s opened up a fake news center. Can we do that? Can you counter fake news?
Speaker H: And any—
Speaker A: how?
Speaker H: Well, that’s certainly, you know, that’s certainly one thing that you can do. But as long as the billionaires can put in all the money they want, and as long as Putin can spend as much money as he wants, you know, these efforts to counter fake news are really not going to make much difference.
Speaker D: So you’re saying that that’s the issue, that because somebody can put money behind it and say, no, actually I’m true, this is true,— then that’s it as far as those people who listen to weird news, as you called it.
Speaker H: As far as they’re concerned, that’s it then. Yeah, as long as the American political system allows unlimited political expenditure, Moscow is going to be able to outspend any domestic political actor.
Speaker B: The vulnerability to technology is due to a fundamental flaw in human nature, says Angela Sasse. Professor of Human-Centered Technology in the Department of Computer Science at University College London. She led a research project for the British spy centre GCHQ into the reasons why most people struggle to properly protect themselves and their computers.
Speaker I: The insidious thing is that if you were exposed to certain posts or ads, you don’t think that you’ve— most, the vast majority of, you know, it’s like 80% of people think they are better than average driver. And in the same way, 80% of people think that they are not influenced by advertising. And I think most people wouldn’t admit or concede to themselves that their decision, you know, their votes were influenced by what they were exposed to. On the internet. What we between us would say is they kid themselves that this is a decision they came to entirely rationally and, you know, for very good reasons that have nothing to do with what they were exposed to on the internet. Nobody really likes to think they’re being manipulated or steered in a certain way, and people don’t like to admit that to themselves. For that reason, I think it’s only, you know, the people who are aggrieved about the outcome, you know, that the outcome, with the outcome, that would see this as a problem.
Speaker B: The people who voted for Brexit or voted for Trump aren’t going to see it that way. This lack of awareness of technology is something that Jamie Bartlett, Director for the Centre for the Analysis of Social Media says now lies at the heart of our society. In his book, “The People vs. Tech: How the Internet Is Killing Democracy and How We Can Save It,” Bartlett points out that the attack is now two-pronged. Not only are our hearts and minds coming under attack from unscrupulous nations like Russia, but also from billionaires. Bartlett points out that the use of internet and Facebook data by Cambridge Analytica has had a massive impact on recent politics. Cambridge Analytica is a UK-based data analysis and political consultancy company which had Stephen Bannon, founder of the right-wing website Breitbart and Donald Trump’s first national security adviser, on its board and serving as its vice president. The company is now mired in controversy following revelations that that it acquired 57 million Facebook records from the US, the UK, and other countries and used them to psychologically profile individuals and target them with political messages. It is claimed that this allowed them to influence political votes in the UK and the US in favor of both Trump and Brexit, and has uncanny echoes of the Russian interference talked about by John Pike.
Speaker A: Our system of, broadly speaking, representative democracy, a couple of hundred years old obviously, although mass parties and mass suffrage layered on top of that, it relies on a certain set of institutions, I think, to actually work. A very informed citizenry, a fair and free press that’s very healthy and vibrant, a relatively large and stable middle class a police or criminal justice system that actually works and can deliver what people want of it. And then digital technology, which of course, as you know, is based on often quite decentralized technologies. It tends to be relatively borderless, at least in certain aspects of it. It has dramatic exponential growth patterns and tendencies towards monopolization. And so to me, it’s partly the fault of representative democracies having not really changed much for such a really long time as everything around it has. So in the book, I sketch out how each of these pillars of modern representative democracy are threatened by digital technology. And I’m not saying it’s all bad. Obviously, there’s loads of ways that digital technology helps democracy immensely, but in very important ways, these sort of key pillars are being undermined. And then I’ll make a few suggestions about— 20 suggestions in fact— about how we kind of might turn it around. Although I’ve got to be honest with you, I’m not massively optimistic. The logical threat that you’re seeing? Yes, a good example. So one very simple way of looking at Cambridge Analytica, before we maybe get into the detail of the specifics of what they’ve done, is that we have laws that are in place about ensuring elect sort of campaigning information is is relatively accurate, so it can be monitored by regulators to make sure people are receiving accurate information, and it’s sort of broadly public, so everyone else gets to see what other people are seeing. And with the techniques of highly targeted microtargeting and very, very detailed emotional profiling of people, it’s very difficult to ensure that that information is accurate or that regulators can see it. So it’s a— to me, it’s a sort of classic case of how you suddenly have a brand new system of doing politics, and the current rules that we have aren’t really easily workable in, in that new world. I think the Cambridge Analytica story and microtargeting more generally also presents a bigger risk, which is political parties have always been based on these what some people call broad programmatic offers, you know, large-scale political parties that are based on big promises promises that everybody or large groups of people can get behind. And microtargeting works to a quite different logic. It’s really about identifying the one or two things that people care about and then just hammering them over and over again with that message. And to me, that makes politics even more polarised. And so I think there’s sort of longer-term threats that come from this type of new electioneering, and that we know that it’s just going to carry on getting more and more advanced. What is microtargeting? Microtargeting is a— it’s really an advertising technique, but so much of politics is advertising after all, which is essentially based on trying to build up very detailed profiles of individual people or small clusters of people based on offline data like records of census and address and that kind of thing, but also increasingly online behaviour. So the things that you’ve bought online, your credit records, your web browsing behaviour, And the idea is that with more and more of that kind of fine-grained information that we’re all producing all the time about ourselves, you can then tailor messages that you can reach people through platforms like Facebook that are incredibly personalized to the things that they care about. So rather than a big advert that’s trying to get everybody rallied around, you know, we’re going to lower taxes for the middle class, you could find somebody that cares about a very, very a particular niche thing, and you understand their concerns and fears and their hopes and aspirations and have a message that is just for that one person, that works for them. That’s microtargeting, and that’s the direction politics has been going in for some years. But the more data we produce and the more time we spend online, the more accurate that becomes.
Speaker B: For Bartlett, there is a desperate need to combat this world of disinformation that is proving as dangerous as any cyberweapon.
Speaker A: All of your behavior, increasingly now it’s digitized and is amenable to collection and analysis, says something about you. It says something about whether it’s your position in a network, what you care about, demographic or psychological information about you. And I think why this is so worrying is that we are— we don’t know that, we don’t understand that, we’re not aware of that. That. We struggle to— we do all these things that are constantly collected and we’re endlessly now researched and what, you know, thousands of companies taking our data, putting them into complex models to make sense of us. And we have no idea what we’re giving away about ourselves, not just the data itself, but the analysis that can be done on us. And, you know, it’s a I think a lot of people would be very surprised to learn about the things that can be discerned from them as a result of the careless clicks or purchases that they’ve made. And the more they know, the more I think they’ll worry about it because they’ll think, well, who’s got the data and how, you know, how’s it going to be used? Am I going to be targeted by a Jacob Rees-Mogg advert in 2020 because I filled in one of those BuzzFeed quizzes about what EastEnders character I am? My goodness me, what’s going on? And so, yeah, I think people— there is some— there are some regulations coming in in the next few weeks from the European Union that might, might help a bit on that. It’s called the GDPR, makes data sharing between companies a little harder. So that’s a start as well. But I think that people are going to be— people are going to be like— the Cambridge Analytica story, I think, is going to stimulate a a lot of similar stories like the one you’ve just said to do with pint-buying orders, and people are going to realize there’s lots and lots of stories like this coming out, and there’s going to be more of them.
Speaker B: As Professor Gagliotti points out, Russia may have a relatively small economy, but perception management gives it a position on the world stage that it should not occupy.
Speaker G: Yeah, I mean, I wouldn’t want to make it sound as if it’s too coordinated, Absolutely. Look, all politics is about perception management, both national and international. Even if you’re sending an army into another country, you are actually also involved in an information perceptual conflict. And I think this is it. That’s something that the Russians have understood, that basically it’s all about politics. And secondly, that they are essentially pretty weak. They have an economy, as I said, about the size of Spain’s. They have a military that has been partially modernized but is still nothing like the old Red Army. They lack for soft power. They have one key advantage in this respect, which is actually that they don’t have that much to lose. And what they have done— I sometimes kind of, okay, rather caricaturing it, but think of one of these sort of smallish rodentine animals that when when faced with a larger predator, sort of bears its teeth and puffs itself up and tries to look as big and as vicious as possible on the principle that says, well, okay, you may be bigger than me, but I’m that much nastier. And even if you win, you’re gonna know you’ve been in a fight. That’s been very much kind of Russia’s approach. And I know it is a ridiculous caricature, but I think it’s a useful one. So in this respect, yes, they are often looking for ways in which they can make Russia look more formidable credible, more dangerous than it really is, because from their point of view, that dissuades a lot of people from challenging Russia and presents this notion of, look, we are a country that you had better make a deal with. It’s much more important to cut a deal than to actually try and take us on. So whether we’re talking about military exercises, whether we’re talking about Putin’s often ridiculously macho rhetoric, or whether we’re talking about more unpleasant covert operations, it is exactly often direct, or at least in part directed towards perception management, giving a sense of Russia as being the kind of country you don’t want to mess with.
Speaker B: In a world of disinformation, as Bartlett says, we now have a duty to become better informed.
Speaker A: The single thing when it comes to elections I think is the best we can do is to have Every single advert that a political party puts out, who they’ve targeted, the nature of the targeting, the data they’ve got on those people, and the advert they’ve placed in front of them, all of that should be made public. So yeah, it’s going to be the world’s longest and most tedious Excel spreadsheet, but it’s going to be something that journalists and regulators will be able to look at and check and understand. The public can understand and try and make some sense of through the journalists and the experts who could take a look at it. And I think hopefully that would do something to at least keep a bit of a check on some of the more sinister techniques that will be possible in the years ahead. So that to me is an example of how you’d bring up some old rules, bring up old rules up to speed with sort of digital campaigning. Personally, I think we’re gonna, you know, bots and trolls are not going to go away. We’re never going to be able to get rid of them. So we’re probably going to to have some kind of more money for academic departments or somewhere to sort of at the very least do more work to uncover who they are and what they’re pushing out. But a government doing that is probably not a good idea because no one would trust them either. So there are a couple of things that we can do, but yeah, I mean, I imagine that we the people will wise up a little bit to some of the techniques. I feel like we have already as a result of all the Cambridge Analytica stuff, but it would be helped a lot by bringing those election commission rules up to speed as well.
Speaker B: Bartlett also recommends that you fight distraction, that you don’t get sucked down the wormholes of the internet, that there’s a need for digital ethics, more tolerance in our society so that we listen to other people’s opinions. Most importantly, that you own your own opinion. Make sure that the information that you have is yours. He also suggests critical thinking, thinking about what it is that you’re being told, and policing the algorithm. But whether those of us who are addicted to what John Pike describes as weird news will be prepared to do that is another matter, and one that may need some direct and well-considered government action. This program was presented by Peter Warren and produced by Blue Buffery. The script was edited by Jane Wyatt. Password is a Future Intelligence production. If you’d like to know more about the way that technology affects our lives and what we might have to do to make sure that it works for us, go to our website, futureintelligence.co.uk.
Speaker A: Goodbye. This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.
