Policy Matters: Innovation, Balkanization and the Government’s Role Privacy Symposium, Harvard 23 August 2007 Adam Golodner, Director Global Security & Technology Policy Cisco Systems, Inc.
Your Privacy Is my Security WTO Accession – encryption (and my flavor) Authentication//Anonymous Techno regulatory arbitrage afoot… Dare we look back?
Nothing New Under the Sun: Same Crimes, New Names Offline Online Commercial Security Commercial Security Vandalism, Graffiti, Worms, Viruses Theft, Fraud, Deceptive Trade Hacking, Spam, Phishing, Spyware Extortion, Piracy, Organized Crime DDoS, Intercept, ID Theft, Bots - CIP- Terrorism, Espionage Physical Attack, Insider, etc. National Security National Security Techniques Related—But Different Motivations, Legal Principles, Government Roles
A Three-Part Test for Policy Making 1. Innovation—Trust 2. Balkanization Innovation Balkanization Proper Role of Government Let’s look at each of these … 3. Proper Role of Government 4 4
The Impact on Innovation Public choice theory FCC to FTC? Breach notification And public choice theory & real harm FCC to FTC? (or EC, China, etc Breach Notification
The Balkanization of Technology and Business Use my flavor WAPI Data flow My values Balkanization Use my flavor Standards, data transfer, WTO sec. exception
Proper Role of Government Which aspect of “security” or “privacy”? What are the costs and benefits of intervention? Proper Role of Government What kind of ‘security’ or ‘privacy’? Costs, benefits, incentives and consequences
Policy Truism: Policy = Architecture = Innovation Impact Network-based security and privacy From passive to active Self-defending Interactive Interconnected Managed IP networks Global Policies must reflect: Security and privacy moves fast Unintended consequences Protecting innovation Don’t specify technologies Or pre-judge biz models Tying-up innovation makes us less, not more secure Virtualization Identity+Trust Web Filtering SMTP HTTP Port 80 Worm Mitigation Content Inspection Anti Spam Secure IP
We Must Do Something—Anything! It’s a Tragedy of the Commons! Fact or Fiction? We Must Do Something—Anything! It’s a Tragedy of the Commons!
How Do we Create a Global Framework? What historic precedents can we call on? Emerging frameworks London Action Plan for consumer protection MLATs Council of Europe Treaty on Cyber Crime OECD Privacy and Culture of Security ICN—International Competition Network model What are we missing? Historical precedents Nation states with different laws, values Shared basic principles – like crime Some differences real, at least for the mid-term Emerging frameworks London Action Plan for consumer protection MLATs Council of Europe Treaty on Cyber Crime OECD Privacy & consumer dispute resolution ICN – International Competition Network model ? Principles for off-line and on-line the same What precedent are we missing?
Build Upon Enduring Principles Perform Surgery as Needed What We Must Do Build Upon Enduring Principles Continue to Innovate Perform Surgery as Needed Do No Harm