Showing posts with label Export Controls. Show all posts
Showing posts with label Export Controls. Show all posts

16 February 2025

Export Controls

'The spoilers from within: Allies and export controls' by Eliza Gheorghe in (2025) Journal of Strategic Studies comments 

Do alliances help or hinder non-proliferation efforts? Existing theories of nuclear non-proliferation have looked at the direct effects of having allies on the spread of nuclear weapons, i.e., whether protégés are more or less likely to obtain atomic arsenals. However, there is value in examining the indirect impact of alliances on non-proliferation, namely how allies make it easier or harder for third parties to acquire nuclear weapons. In this article, I argue that transfers from suppliers allied with enforcers spoil the non-proliferation regime more than assistance from other suppliers, which underlines the difficulties enforcers face when combatting proliferation. ...

Alliances also play an indirect role in the spread of nuclear weapons, especially through the influence enforcers’ allies can have on the non-proliferation regime. ... The literature on sanctions highlights that allies pose a significant challenge for sanctioning states because they can ‘exploit the political cover provided by their alliances’ to engage in sanctions busting. Given the close relationship between sanctions and export controls, the question arises: do allies help or hinder the enforcement of export controls? 

Allies can support non-proliferation efforts by aiding enforcers in cracking down on proliferants through unilateral, bilateral, or multilateral action. However, when states are both enforcers’ allies and suppliers of nuclear technology, they can undermine the non-proliferation regime by transferring nuclear technology to proliferants. Existing quantitative studies have shown that both civilian and sensitive nuclear assistance catalyze proliferation, but they have not examined whether, on average, nuclear technology transfers from spoilers are more damaging than those from other suppliers. This article offers the first comparison of these two types of nuclear assistance to highlight the challenge spoilers pose to enforcers’ non-proliferation efforts. I find that technology transfers from enforcers’ allies accelerate nuclear weapons programs, demonstrating how the non-proliferation regime can be undermined from within. 

The following analysis is organized into five sections that aim to show how allies complicate export controls. The first section looks at the literature on the role of allies in creating and enforcing cartels, lays out a theory of non-proliferation spoiling, and specifies its key predictions. The second part discusses the methodology and the data I draw on. The third section presents the results of the quantitative analysis and shows that allied suppliers spoil the enforcers’ efforts to stem the spread of nuclear weapons more than other nuclear technology providers. I find that spoilers have contributed to the acceleration of nuclear weapons programs via nuclear trade after the creation of the Nuclear Suppliers Group (NSG). The fourth part provides a case study of Italy as a non-proliferation spoiler. The fifth and concluding section offers a summary of the findings, discusses implications for emerging technologies, and proposes avenues for future research.

'From nonproliferation to strategic competition: US export controls and China' by Mathilde Velliet in (2025) International Politics comments 

Technological competition is at the heart of the renewed great-power competition that has characterized relations between the USA and China since the 2010s. The role of technological innovation in the evolution of power relations is already recognized in the literature of international relations. However, developments in US technology policy under the last two administrations raise the reverse question: how does the perception of changing power relations (in this case, Chinese technological catch-up perceived as a threat to US leadership) transform policies granting or denying access to technological innovation? This study sheds light on the transformation in the American conception of export controls: mainly conceived in the post-Cold War era as a law enforcement and nonproliferation tool, it has become a strategic instrument to restrict technology transfers to the People’s Republic of China. Using a Foreign Policy Analysis approach based on the analysis of legal texts, speeches, and interviews with the political actors involved, this article examines the policy process, leading to this fundamental change in US export control policy. As this study demonstrates, this change reflects a new interpretation of the link between economic and security interests, as well as the expansion of the perimeter of American national security.

'The trojan submarine: AUKUS, Pillar II, and the U.S. ITAR' by Paul Esau in (2024) 2 Journal of Strategic Trade Control comments 

Since the announcement of the AUKUS trilateral security partnership in September 2021, critics have attacked the U.S. International Traffic in Arms Regulations (ITAR) as a key obstacle to its success. Echoing long-standing frustrations over the regulatory burden of the ITAR, these critics manufactured an “AUKUS-ITAR dilemma” which seemed to require a general ITAR exemption for military trade between the three partner countries. This dilemma minimized critical disparities between the Australian, U.K., and U.S. military export control regimes and exaggerated the impact of ITAR reform on the success of AUKUS, especially on the emerging technology collaboration envisioned in the second pillar of the partnership. Yet recent U.S. legislation and regulatory reform indicate that rather than eliminating U.S. military export controls, the AUKUS-ITAR dilemma has resulted in a more robust, ITAR-based plurilateral export control regime dominated by U.S. interests and primed for further expansion. 

In September 2021, the United States, Australia, and the United Kingdom jointly announced a trilateral security partnership to address evolving threats in the Indo-Pacific region—AUKUS. Described as “the most significant security arrangement among the three countries in a generation,” this partnership was initially perceived as a vehicle for the transfer of nuclear propulsion technology to Australia for use in conventionally-armed, nuclear-powered submarines. External analysis, especially in the U.S., focused on the controversial export of nuclear technology and reactions from the impetus for the new partnership: China. While the second-last paragraph of the official joint statement also promised new collaboration in “cyber capabilities, artificial intelligence, quantum technologies, and additional undersea capabilities,” this second pillar of AUKUS seemed like an ambiguous afterthought. Submarines, not science fiction, were the core deliverable of the partnership. 

Yet as the timeline for the submarine sales (Pillar I) lengthened, Pillar II emerged as not only central but also essential to the AUKUS partnership. In the words of one former U.S. official and industry analyst in March 2023, “If Pillar Two fails, AUKUS will be a failure. Plain and simple.” Industry representatives and several former U.S. ambassadors to Australia positioned U.S. military export controls, specifically the U.S. International Traffic in Arms Regulations (ITAR) as obsolete Cold War-era relics and impediments to collaboration among the three AUKUS partners, creating an “AUKUS-ITAR dilemma.” The ITAR was called a “unique threat” to U.S. national security, and the “most significant obstacle” to winning a strategic competition with China. These arguments echoed long-standing frustrations over the regulatory burden of the ITAR in all three countries, and inspired a series of radical proposals from hawkish members of Congress to implement a blanket ITAR exemption for AUKUS partners. 

However, the passage of the 2024 National Defense Authorization Act (NDAA) in December 2023 revealed that these arguments had not been as persuasive as advocates had originally hoped. Instead, the U.S. Congress pursued a more moderate version of ITAR reform predicated on ensuring comparability between that the U.S., Australian and U.K. export control regimes, with implementation entrusted to conservative elements within the U.S. Department of State. In May 2024, the State Department released a proposed rule outlining a limited ITAR exemption that was finalized in August and implemented on September 1. Instead of receiving the crown jewels without caveat, Australia and the U.K. were forced to adopt ITAR-like regimes of their own. 

Does this result mean Congress missed a “generational opportunity” to implement AUKUS and ensure a new era of allied collaboration and innovation? Not quite. This article argues that Congress has evaded an attempt to use the AUKUS/ITAR dilemma as a “trojan horse” for long- standing commercial frustrations with the ITAR. This attempt built on previous initiatives to exempt Australian and British entities from ITAR licensing requirements and minimized critical disparities between the Australian, U.K., and U.S. military export control regimes. It also misaligned the goals of Pillar II and the probable outcomes of blanket ITAR exemptions, exaggerating the impact of the ITAR on military trade between the three countries – especially exports of critical and emerging technologies. As shown by the existing Canadian ITAR exemption, licensing relief has limited potential to realize the sort of seamless military integration and research collaboration envisioned under Pillar II. Ultimately, rather than eliminating U.S. military export controls, the AUKUS/ITAR dilemma has created a more robust ITAR-based regime dominated by U.S. interests and primed for further expansion. This article begins by describing the re-emergence of export controls amidst increasing competition between the U.S. and China. After introducing the ITAR and contrasting it with the Australian and U.K. military export control regimes, it summarizes a series of recent attempts to reducing export licensing requirements among the three AUKUS partners and highlights the key obstacles to greater collaboration. Finally, it contextualizes three major arguments used to criticize the ITAR prior to the passage of the 2024 NDAA and explores the possibility that AUKUS constitutes not only a security partnership but also lays the groundwork for a new plurilateral military export control regime.

22 January 2025

Export Controls

'US Export Controls and the Restructuring of Global Values Chains: An analysis of Japanese multinationals'exits from China' by I Deseatnicov and F Kyoji comments 

The increased export controls on advanced technologies like semiconductors imposed by the U.S. and aligned countries targeting primarily China are accelerating technological decoupling. What are consequences of this process on global value chains (GVCs) dominated by the activities of multinational enterprises (MNEs)? To answer this question, we use Japanese microdata for the period 2017–2021. We find an increase in the exit of Japanese MNEs from China. Building on this observation, we hypothesize that this increase in exits may have been triggered by an increase in production costs brought about by a decline in the variety of imported intermediate inputs as a direct consequence of the increased export controls. We offer a simple theoretical framework to rationalize this mechanism, which guided us in creating an export controls index using a detailed review of U.S. Federal Register documents and input-output tables. Our empirical analysis of the probability of exit confirms that the reduction in imported intermediate inputs plays an important role in the behavior of Japanese MNEs.

26 August 2023

Export Controls

Catching up with the 'Export Controls and Human Rights Initiative Code of Conduct' released at the Summit for Democracy in March this year. 

The US State Department comments

 The United States continues to put human rights at the center of our foreign policy. The Export Controls and Human Rights Initiative – launched at the first Summit for Democracy as part of the Presidential Initiative for Democratic Renewal – is a multilateral effort intended to counter state and non-state actors’ misuse of goods and technology that violate human rights. During the Year of Action following the first Summit, the United States led an effort to establish a voluntary, nonbinding written code of conduct outlining political commitments by Subscribing States to apply export control tools to prevent the proliferation of goods, software, and technologies that enable serious human rights abuses. Written with the input of partner countries, the Code of Conduct complements existing multilateral commitments and will contribute to regional and international security and stability. 

In addition to the United States, the governments that have endorsed the voluntary Code of Conduct are: Albania, Australia, Bulgaria, Canada, Costa Rica, Croatia, Czechia, Denmark, Ecuador, Estonia, Finland, France, Germany, Japan, Kosovo, Latvia, The Netherlands, New Zealand, North Macedonia, Norway, Republic of Korea, Slovakia, Spain, and the United Kingdom. The Code of Conduct is open for all Summit for Democracy participants to join.

Indeed, Bulgaria and Albania 

The Code of Conduct calls for Subscribing States to:

  • Take human rights into account when reviewing potential exports of dual-use goods, software, or technologies that could be misused for the purposes of serious violations or abuses of human rights. 

  • Consult with the private sector, academia, and civil society representatives on human rights concerns and effective implementation of export control measures. 

  • Share information with each other on emerging threats and risks associated with the trade of goods, software, and technologies that pose human rights concerns. 

  • Share best practices in developing and implementing export controls of dual-use goods and technologies that could be misused, reexported, or transferred in a manner that could result in serious violations or abuses of human rights. 

  • Encourage their respective private sectors to conduct due diligence in line with national law and the UN Guiding Principles on Business and Human Rights or other complementing international instruments, while enabling non-subscribing states to do the same. 

  • Aim to improve the capacity of States that have not subscribed to the Code of Conduct to do the same in accordance with national programs and procedures.

22 November 2018

FTAs and Export Controls

'How Trade Deals Extend the Frontiers of International Patent Law' (CIGI Papers No. 199 — November 2018) by Jean-Frédéric Morin and Dimitri Thériault for the Centre for International Governance Innovation comments 
Bilateral and regional trade deals frequently include patent provisions that go beyond the minimum requirement of the multilateral Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS). They extend the scope of patentability and provide additional rights to patent holders. This paper systematically maps these “TRIPS-plus” agreements. Exploiting a new data set, 52 TRIPS-plus agreements are found to have been concluded between 1990 and 2017. The major proponents of these TRIPS-plus agreements on patents are the United States, followed by the European Union and the European Free Trade Association. Other technology-rich countries, such as Japan and Korea, have surprisingly few TRIPSplus provisions on patent protection in their trade agreements. Few South-South trade agreements include TRIPS-plus provisions, but some include TRIPS-extra provisions on genetic resources and traditional knowledge. Having a clear picture of these TRIPS-plus agreements is essential as they can have important social and economic consequences, including for the development of innovations and access to technologies.
The authors note
This paper is one of the first attempts to systematically map key patent provisions in bilateral and regional preferential trade agreements (PTAs). Some of these provisions have important policy implications, including for the development of innovations and access to technologies. This paper shows their historical evolution and their geographical distribution. 
The available literature has already reported that some PTAs offer a level of patent protection that goes beyond the minimum requirements of TRIPS. However, several questions still need more research and analysis. In particular, the number and scope of TRIPS-plus agreements are uncertain. It is also unclear if their conclusion is more frequent today than it was a decade ago. As well, the practices of several countries remain undocumented, beyond some well-known advocates and opponents of TRIPS-plus agreements. 
This paper fills these gaps by relying on a recent data set of TRIPS-plus agreements (the T+TPA data set) introduced by Jean-Frédéric Morin and Jenny Surbeck. This data set is based on an exhaustive collection of more than 600 PTAs concluded between 1947 and 2017. Among these PTAs, Morin and Surbeck identified 52 PTAs with significant TRIPS-plus provisions on patents. 
The rest of this paper is divided into seven short sections. The first section describes the current state of multilateral negotiations over patent law. The second section describes eight categories of TRIPS-plus provisions on patents, while the third section presents their development over time. The next section identifies the key role played by the United States and by European countries in promoting TRIPS-plus agreements. The fifth section assesses the PTAs involving other technology-rich countries. The sixth section considers developing countries and their role in the diffusion of TRIPSplus provisions on patents. The last section focuses on provisions that are of particular interest for developing countries. The conclusion identifies directions for future policy-oriented research.
They conclude
The proliferation of TRIPS-plus and TRIPS-extra provisions in PTAs requires further research. At least three main areas of research would have clear added value for policy making. The first involves exploring the domestic consequences of TRIPS-plus provisions on patent protection. As yet, it is unclear how far these commitments reflect pre-existing legal standards or whether they require domestic reforms. In the latter case, it would be interesting to study if and how the reforms are being implemented. Developing countries that are compelled to implement TRIPS-plus obligations might take advantage of these legal reforms to include new exceptions and exclusions in their domestic legislation. Case studies might also be useful for investigating the social and economic consequences of implementing TRIPS-plus provisions. 
A second stream of research concerns the global and strategic consequences of TRIPS-plus provisions. These consequences would include processes such as regulatory competition across countries with different standards, norm diffusion driven by the desire to level the playing field and the reverberation from bilateral initiative to multilateral negotiations. The existing literature also tends to portray developed and developing countries as antagonistic actors in international patent law making. It is time to debunk this apparent oversimplification. The pro-patent posture of some developing countries, the nuanced policy of some high-income countries and the rise of emerging countries raise new questions that should be explored. 
A third avenue for future research concerns the potential alternative to existing TRIPS-plus provisions on patents. The current debate on international patent protection has focused on the flexibilities already provided in the TRIPS Agreement and on TRIPS-plus provisions. However, the example of TRIPS-extra provisions on TK and GRs shows that trade negotiators have the capacity to be creative and think outside the TRIPS box. Nothing precludes trade negotiators from addressing issues such as licensing pools, open science and scientific collaboration in their future PTAs. Provisions on these issues might actually do more for technological innovation than TRIPS-plus provisions on patents.

'Strategic Export Controls: A Case Study of Regulation of Executive Power and Parliamentary Accountability in the United Kingdom' by John F McEldowney in Daniel Joyner (ed), Non-Proliferation Export Controls Origins, Challenges, and Proposals for Strengthening (Routledge, 2006) comments 

Export controls received concentrated media attention during the Arms to Iraq saga played out in all its detail before the Scott Inquiry in 1996. The inquiry revealed a complex and detailed regulatory structure overseeing exports that lacked transparency, was of dubious legality and was subject to only weak parliamentary accountability. The focus of this chapter is on the command and control system of regulation over export control within the United Kingdom post the Scott Inquiry and the enactment of the Export Control Act 2002 which came into force on 1 May 2004. In the last annual Report on Strategic Export Controls (United Kingdom 2005; see also Taylor 2003), it was estimated for the year ended 2003, the value of exports of strategically controlled goods was £992.4 million. These exports make a significant contribution to the defence and security of the United Kingdom, as well as contributing to the multi-various international obligations to be met by the armed forces. In considering the regulation of strategic exports, an historical approach is adopted in drawing out the tensions between executive discretion and parliamentary controls. The main question addressed is how accountable is the new regulatory system? The main thesis advanced is that the system of export control is linked to the policy of the government of the day. In its early legal construct, it reflected the legal culture of the UK. Formally legalistic and highly structured in form, the actualité is of a pragmatic system that also reflects many of the strengths and weaknesses of a parliamentary system of ad hoc accountability. Thus the system of control is strongly driven by the government of the day, sustainable through political oversight and pragmatic decision-making subject to market forces. Party political decisionmaking is often interspersed with balancing different shades of multi-nationalism, especially in terms of the influences of the United States and Europe.

19 August 2013

CoE Declaration

The Council of Europe (CoE) Committee of Ministers has released a 'Declaration' on 'Risks to Fundamental Rights stemming from Digital Tracking and other Surveillance Technologies'.

The Declaration states that
1. The propensity to interfere with the right to private life has significantly increased as a result of rapid technological development and of legal frameworks which are slow to adapt. 
2. Data processing in the information society which is carried out without the necessary safeguards and security can raise major human rights related concerns. Legislation allowing broad surveillance of citizens can be found contrary to the right to respect of private life. These capabilities and practices can have a chilling effect on citizen participation in social, cultural and political life and, in the longer term, could have damaging effects on democracy. They can also undermine the confidentiality rights associated to certain professions, such as the protection of journalists’ sources, and even threaten the safety of the persons concerned. More generally, they can endanger the exercise of freedom of expression and the right to receive and impart information protected under Article 10 of the European Convention on Human Rights. 
3. In this connection, it is recalled that, in accordance with Article 8 of the European Convention on Human Rights, Council of Europe member States have undertaken to secure to everyone within their jurisdiction the right to respect of private and family life, home and correspondence. Restrictions to this right can only be justified when it is necessary in a democratic society, in accordance with the law and for one of the limited purposes set out in Article 8, paragraph 2, of the Convention.
4. As a corollary to the Convention and relevant case law of the European Court of Human Rights, member States have negative obligations, that is, to refrain from interference with fundamental rights, and positive obligations, that is, to actively protect these rights. This includes the protection of individuals from action by non-state actors. 
5. People nowadays rely on a growing range of both fixed-location and mobile electronic devices which enhance their possibilities to communicate, participate and manage their everyday lives. However, a growing number of these devices are equipped with software that are capable of collecting and storing data, including personal data (e.g. keystrokes that reveal passwords) and private information such as user generated content, websites visited, and geographical locations that potentially allow tracking and surveillance of people. This data can reveal delicate and/or sensitive personal information (such as financial, health, political, religious preferences, sexual habits) which can be aggregated to provide detailed and intimate profiles of them. 
6. Tracking and surveillance technologies can be used in the pursuit of legitimate interests, for example to develop new services, improve user experience or facilitate network management, as well as law enforcement. On the other hand, they may also be used for unlawful purposes that lead to illegal access, data interception or interference, system surveillance, and misuse of devices or other forms of malpractice; for example, geo-location tracking could be used to stalk women and make them more vulnerable to gender-related abuse and violence. 
7. In all cases, the modalities for processing personal data should comply with relevant Council of Europe standards. This implies ensuring that law enforcement’s own tracking and surveillance measures respect the applicable human rights safeguards, which should provide for the adequate protection of human rights and liberties, including rights arising pursuant to obligations undertaken under the 1950 Council of Europe Convention for the Protection of Human Rights and Fundamental Freedoms, the 1966 United Nations International Covenant on Civil and Political Rights, and other applicable international human rights instruments, and which should incorporate the principle of proportionality. It also concerns strict respect for the limits, requirements and safeguards set out in the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and in its Additional Protocol as well as regard for other instruments such as Recommendation CM/Rec(2010)13 on the protection of personal data in the context of profiling. 
The Committee of Ministers accordingly [at 8] -
  • alerts member States to the risks of digital tracking and other surveillance technologies for human rights, democracy and the rule of law and recalls the need to guarantee their legitimate use which benefits individuals, the economy, society at large, and the needs of law enforcement;
  • encourages member States to bear these risks in mind in their bilateral discussions with third countries, and, where necessary, consider the introduction of suitable export controls to prevent the misuse of technology to undermine those standards;
  • welcomes steps taken by data protection authorities in some member States to raise awareness of the implications of tracking and surveillance technologies and to investigate these practices to ensure compliance with the provisions of Convention No. 108 and their national legislations;
  • draws attention to the criminal law implications of unlawful surveillance and tracking activities in cyberspace and the relevance of the Budapest Convention in combating cybercrime;
  • welcomes measures taken by both State and non-State actors to raise awareness among users, and, a fortiori, within the private sector and among technology developers about the potential impact of the use of such technologies on human rights and the steps which can be taken at the design stage to minimise the risks of interferences with these rights and freedoms (e.g. “privacy by design” and “privacy by default”);
  • recalls the Council of Europe Internet Governance Strategy 2012-2015 which includes a number of action lines relevant to the challenges identified in this Declaration and looks forward to the concrete results of the work of the competent Council of Europe bodies.

14 June 2013

CoE response to PRISM

The Council of Europe (CoE) - the international entity that has driven Australian proposals for mandatory electronic data retention through the global Cybercrime Convention - has responded to the furore over PRISM.

Its media release states that the Council
today alerted its 47 member states to the risks of digital tracking and other surveillance technologies for human rights, the rule of law and democracy, and recalled the need to ensure their legitimate use. 
In a Declaration issued to governments, the Committee of Ministers say that legislation allowing for overly broad surveillance of citizens can challenge their privacy and have a chilling effect on their freedom of expression and the freedom of the media.
The Committee recall that tracking and surveillance measures by law enforcement authorities should comply with the Council of Europe’s human rights standards set out in the European Convention on Human Rights. Such measures should also strictly respect the limits, requirements and safeguards set out in the Data Protection Convention 108.
The Declaration also draws attention to the criminal law implications of unlawful surveillance and tracking and to the relevance of the Budapest convention on Cybercrime to address this challenge.
Finally, the Committee also encourages states to introduce suitable export controls to prevent the misuse of technology to undermine human rights standards.
The Declaration, which must have been fun to write, is as follows
1. The propensity to interfere with the right to private life has significantly increased as a result of rapid technological development and of legal frameworks which are slow to adapt. 
2. Data processing in the information society which is carried out without the necessary safeguards and security can raise major human rights related concerns. Legislation allowing broad surveillance of citizens can be found contrary to the right to respect of private life. These capabilities and practices can have a chilling effect on citizen participation in social, cultural and political life and, in the longer term, could have damaging effects on democracy. They can also undermine the confidentiality rights associated to certain professions, such as the protection of journalists’ sources, and even threaten the safety of the persons concerned. More generally, they can endanger the exercise of freedom of expression and the right to receive and impart information protected under Article 10 of the European Convention on Human Rights. 
3. In this connection, it is recalled that, in accordance with Article 8 of the European Convention on Human Rights, Council of Europe member States have undertaken to secure to everyone within their jurisdiction the right to respect of private and family life, home and correspondence. Restrictions to this right can only be justified when it is necessary in a democratic society, in accordance with the law and for one of the limited purposes set out in Article 8, paragraph 2, of the Convention. 
4. As a corollary to the Convention and relevant case law of the European Court of Human Rights, member States have negative obligations, that is, to refrain from interference with fundamental rights, and positive obligations, that is, to actively protect these rights. This includes the protection of individuals from action by non-state actors. 
5. People nowadays rely on a growing range of both fixed-location and mobile electronic devices which enhance their possibilities to communicate, participate and manage their everyday lives. However, a growing number of these devices are equipped with software that are capable of collecting and storing data, including personal data (e.g. keystrokes that reveal passwords) and private information such as user generated content, websites visited, and geographical locations that potentially allow tracking and surveillance of people. This data can reveal delicate and/or sensitive personal information (such as financial, health, political, religious preferences, sexual habits) which can be aggregated to provide detailed and intimate profiles of them. 
6. Tracking and surveillance technologies can be used in the pursuit of legitimate interests, for example to develop new services, improve user experience or facilitate network management, as well as law enforcement. On the other hand, they may also be used for unlawful purposes that lead to illegal access, data interception or interference, system surveillance, and misuse of devices or other forms of malpractice; for example, geo-location tracking could be used to stalk women and make them more vulnerable to gender-related abuse and violence. 
7. In all cases, the modalities for processing personal data should comply with relevant Council of Europe standards. This implies ensuring that law enforcement’s own tracking and surveillance measures respect the applicable human rights safeguards, which should provide for the adequate protection of human rights and liberties, including rights arising pursuant to obligations undertaken under the 1950 Council of Europe Convention for the Protection of Human Rights and Fundamental Freedoms, the 1966 United Nations International Covenant on Civil and Political Rights, and other applicable international human rights instruments, and which should incorporate the principle of proportionality. It also concerns strict respect for the limits, requirements and safeguards set out in the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and in its Additional Protocol as well as regard for other instruments such as Recommendation CM/Rec(2010)13 on the protection of personal data in the context of profiling. 
8. Against this background, the Committee of Ministers:
  • - alerts member States to the risks of digital tracking and other surveillance technologies for human rights, democracy and the rule of law and recalls the need to guarantee their legitimate use which benefits individuals, the economy, society at large, and the needs of law enforcement; 
  • - encourages member States to bear these risks in mind in their bilateral discussions with third countries, and, where necessary, consider the introduction of suitable export controls to prevent the misuse of technology to undermine those standards; 
  • - welcomes steps taken by data protection authorities in some member States to raise awareness of the implications of tracking and surveillance technologies and to investigate these practices to ensure compliance with the provisions of Convention No. 108 and their national legislations; 
  • - draws attention to the criminal law implications of unlawful surveillance and tracking activities in cyberspace and the relevance of the Budapest Convention in combating cybercrime; 
  • - welcomes measures taken by both State and non-State actors to raise awareness among users, and, a fortiori, within the private sector and among technology developers about the potential impact of the use of such technologies on human rights and the steps which can be taken at the design stage to minimise the risks of interferences with these rights and freedoms (e.g. “privacy by design” and “privacy by default”); 
  • - recalls the Council of Europe Internet Governance Strategy 2012-2015 which includes a number of action lines relevant to the challenges identified in this Declaration and looks forward to the concrete results of the work of the competent Council of Europe bodies.

15 April 2013

CyberAttacks and Neurotech Ethics

'Ghost in the Network' by Derek Bambauer - forthcoming in (2014) 162 University of Pennsylvania Law Review indicates that
Cyberattacks are inevitable and widespread. Existing scholarship on cyberespionage and cyberwar is undermined by its futile obsession with preventing attacks. This Article draws on research in normal accident theory and complex system design to argue that successful attacks are unavoidable. Cybersecurity must focus on mitigating breaches rather than preventing them.
First, the Article analyzes cybersecurity’s market failures and information asymmetries. It argues that these economic and structural factors necessitate greater regulation, particularly given the abject failures of alternative approaches. Second, the Article divides cyber-threats into two categories: known and unknown. To reduce the impact of known threats with identified fixes, the federal government should combine funding and legal mandates to push firms to redesign their computer systems. Redesign should follow two principles: disaggregation, dispersing data across many locations; and heterogeneity, running those disaggregated components on variegated software and hardware. For unknown threats -- “zero-day” attacks -- regulation should seek to increase the government’s access to markets for these exploits. Regulation cannot exorcise the ghost in the network, but it can contain the damage it causes.
Bambauer argues that
While a complete defense to zero-day attacks is impossible, policymakers can improve cybersecurity with three regulatory moves: mandatory access to public zero-day markets for the federal government, required confidential reporting on transactions by firms in those markets, and a reward system for researchers who share vulnerabilities with the government. Congress should pass legislation implementing these measures. America should try to convert unknown unknowns to known unknowns. First, firms that transact in software security vulnerabilities should be required to permit the federal government to participate in any offerings or services they provide, on non-discriminatory terms. If Vupen, for example, sought to sell zero-day exploits to France’s security services, but not to America’s National Security Agency, that would be problematic. American law should make paid access by the U.S. government a condition of legal operation for software security firms. This enables the government to develop and deploy countermeasures to at least some zero-day attacks.
Congress has taken analogous measures for other potential risks to national security. For example, one cannot obtain a patent for inventions in nuclear materials or weapons. Such inventions are eligible for a governmental reward scheme, but not for patents. And, the statute transfers rights to the invention from the inventor to the federal government. Similarly, export controls restrict private firms’ ability to engage in transactions with foreign countries. One may not transfer software utilizing encryption to countries such as Iran or North Korea, and one may not sell certain supercomputers to countries such as China or Russia. These rules apply to all firms within U.S. jurisdiction. Thus, Congress has either mandated or forbidden certain transactions based on national security concerns, and could mount a similar effort for zero-day sales.
Not all zero-day merchants fall under American jurisdiction, or enforcement. However, even those operating abroad likely have contacts with the United States. Vupen’s employees visit the United States. Many, if not all, such firms use financial or payment processing companies that are subject to U.S. regulation. These links provide potential leverage. Congress could attach provisions to this legislation that would allow the executive branch to designate firms that do not provide access to the government, and to require banks and payment processors to forgo transactions with them. Analogous measures have been implemented to interdict financing for terrorist groups489, and have been proposed to deal with sites offering prescription drugs or copyrighted works illegally.
Second, Congress should mandate a transaction-reporting system for firms trading in vulnerabilities. These companies should have to report, on a confidential basis, the purchaser’s identity in all transactions of zero-day exploits to the National Security Agency (NSA). This data would remain confidential, and should be designated as statutorily immune from discovery or other use unless the NSA expressly chooses to share it. The statute should enable auditing of firms’ records by the NSA if the agency is able to demonstrate an objectively reasonable basis to suspect inaccuracies or falsification. To make this provision less objectionable for the vulnerability merchants, Congress should include payments to firms that report. While additional spending is politically difficult, this expenditure would be a small but worthwhile investment in security.
Similar reporting systems are widely used to mitigate risk. The National Aeronautics and Space Administration encourages confidential reporting of “near miss” incidents – those that nearly resulted in aviation mishaps – to improve safety procedures and detect product defects. Insurers offering policies for medical malpractice liability must report judgments and settlements to the National Health Practitioner Data Bank. This malpractice information is available for use by state medical licensing boards and federal agencies, but is otherwise confidential. The Federal Railroad Administration is testing a Close Calls Demonstration Project to identify risks in rail operations via confidential reporting of near-miss incidents. The Department of Veterans Affairs has a similar system for patient safety, as does the Federal Communications Commission for network outages.
A zero-day reporting system has several benefits. It would enable the government to detect problematic sales, particularly to unfriendly states and to insecure parties. It would increase the effectiveness of countermeasures that mitigate zero-day exploits by providing a rough guide to how widely distributed a particular attack tool is. It would allow the government to identify whether firms follow their stated criteria for sales (such as Vupen’s self-imposed limit to NATO countries and clients), and to scrutinize suspect firms more closely. Lastly, it would provide a crude estimate of the ebb and flow of the zero-day threat, and to the platforms and applications viewed by the merchant as worthy of attention (and payment).
Finally, Congress should authorize a “bug bounty” program. Its goal would be to collect zero-day exploits, and to encourage researchers to sell their findings to the U.S. government rather than to private firms or other nation-states. A government agency, such as the NSA or the U.S. Computer Emergency Readiness Team, should be provided funds to buy zero-day vulnerability information. The entity selling the exploit, such as a security research firm, would have to certify under penalty of perjury that it had not previously shared the vulnerability information with others, and would have to agree contractually not to do so in the future. Congress should consider backing these requirements with substantial criminal penalties. Arms dealers who sell to both sides are held in low esteem.
Similar private bounty programs, such as by Google and Mozilla, have had considerable success in identifying and remediating bugs. The funding, and amount paid per bug, should be generous: removing zero-days from the Internet ecosystem is highly worthwhile. Moreover, generous payments will have two further beneficial effects. First, it will spur researchers to search for additional bugs. These bugs are like latent defects in a product – they lurk, creating risk, until discovered. Second, paying above-market rates makes it more difficult for others to purchase zero-days. Pushing others out of the zero-day market is useful both offensively and defensively. Offensively, accumulating zero-days provides the U.S. with the building blocks for future Stuxnets. Defensively, it reduces the likelihood that American firms or government entities will fall vulnerable to attacks.
The bug bounty program will create several challenges. First, price: more competition for zero-day exploits will drive up their cost. This increase will burden the public fisc slightly, but helpfully generates added incentives for research into bugs. Second, the government will need to decide how to use exploit information. Congress could establish rules for what NSA may do with the data, or it could defer to the agency (and, by extension, the executive branch) to make that decision. If the NSA uses the exploits to build cyberweapons, such as Stuxnet, or to enable others to do so, it is likely to share vulnerability information less widely than it would without a vision of offensive use. If the agency enables other government entities or private firms to take precautions against the zero-days, it risks having those patches shared, including with potential targets. And, there is an ironic feedback effect: the more important the vulnerability, the greater the temptation to weaponize it, and thus to withhold it from other affected parties.
The hardest decision regarding sharing is determining whether to notify the affected vendor. This Article argues that telling the vendor about the vulnerable code should be the default practice, with two caveats. First, the NSA should work with the vendor to ensure the patch for the vulnerability is maximally effective and minimally visible. If the company draws attention to the patch’s criticality, it may signal to anyone who has independently discovered it that the window of vulnerability is closing – which could draw attacks. Second, NSA should work with the vendor to include detection code in patches. This would help the agency estimate how often vulnerabilities are discovered independently, and perhaps to detect double-dealing by researchers participating in the bug bounty system.
This Article’s solutions for the zero-day problem – the unknown unknowns – differ in character from those for vulnerabilities with existing solutions (the known unknowns) in that they have a greater focus on prevention. Mitigation is still invaluable: disaggregation and heterogeneity are just as helpful for zero-days as for known bugs. However, preventive steps are more important for zero-day exploits. With known vulnerabilities, defenses are possible, though logistically constrained by externalities, information costs, and system complexity. With zero-days, defenses are impossible. Defenders must rely solely on mitigation and recovery. And while prevention tends to be overrated in cybersecurity literature, it remains useful. In particular, even if complete prevention is impossible, defenders may be able to reduce an exploit’s effects – for example, by allowing a server to terminate an affected program, rather than having it cause the server to crash. This is similar to a public health approach: even if one cannot prevent people from contracting a virus, we may be able to make it less lethal. Thus, the three-part agenda above seeks to increase America’s access to information about zero-days, thereby enabling precautions and improving mitigation.

'The Representations of Novel Neurotechnologies in Social Media: Five Case Studies' by Allyson Purcell-Davis in (2013) 19(1) The New Bioethics 30 comments 

The aim of this study was to conduct an analysis of how certain novel neurotechnologies are represented and communicated within social media. The research was conducted as part of a report called Novel Neurotechnologies: Intervening in the Brain and was initially commissioned by the Nuffield Council on Bioethics. Before producing the final report, a working party examined the ethical, social and legal issues surrounding the use of novel neurotechnologies in both therapeutic and non-clinical settings, with the objective of providing an ethical framework to guide those practices. This ethical framework includes the desire to see responsible communication of novel neurotechnologies within the media. 

Chapter 9 of the report, ‘Communication of Research and the Media,’ examines issues raised in the reporting of research into, and the development of, the uses of novel neurotechnologies. As part of the findings contained within this chapter, research was undertaken to provide a ‘snapshot’ of the kinds of representations found within social media: the nature of the connections between users; the kinds of messages that are uploaded; how media content is used; and the kinds of representations of user groups found within posts. This ‘snapshot’ is presented using five case studies