‘Click Here to Kill Everybody’
Click Here to Kill Everybody’ is the latest book by internationally renowned security technologist Bruce Schneier in which he warns about rapidly evolving one big connected system of devices. While expressing serious concern about these Internet+ system and devices, he says, unless governments across the world come out with ‘smart regulations’, data privacy and security of humankind will always susceptible to dangers, including physical harm. 
 
Mr Schneier, who is called a ‘security guru’ by The Economist, is a fellow at the Berkman Klein Center for Internet & Society at Harvard University; a lecturer in public policy at the Harvard Kennedy School; a board member of the Electronic Frontier Foundation, AccessNow, and the Tor Project; an advisory board member of the Electronic Privacy Information Center and VerifiedVoting.org; and a special advisor to IBM Security and the chief technology officer at IBM Resilient. 
 
Mr Schneier gave an email interview to Moneylife. Here are excerpts from the interview…
 
1. Normally, we use 'click' to connect. However, the title of your new book says, ‘Click Here to Kill Everybody’. Are you sharing a concern or warning people about the dangers of connected world?
 
Bruce Schneier (BS): I am trying to do both. The Internet is wonderful and powerful, but it is also dangerous. My book tries to lay out the dangers: where they come from, what the risks are, and how to secure ourselves. My goal is not to scare people; it is more of a road map of how to achieve all of that wonder and power without the danger. If the title is a slightly exaggerated wake-up call, the book is a more measured warning.
 
2. You have always raised concerns on rapidly growing IoT (Internet of Things) devices. However, this time, you are using a news phrase, ‘Internet+’. Is it just a new word or you are trying to convey something bigger than just IoT?
 
BS: I did not want to create a new term, but there was not anything available. The ‘Internet of Things’ refers to the new breed of consumer devices that are being connected to the Internet, everything from cars to toys to appliances to disposable objects. I am talking about that, but I am also talking about our phones and computers, the networks themselves, the large tech companies and their databases of personal information, the cloud providers that store our data for us, the critical infrastructure systems like power plants, and the networks themselves. It's all one big connected system, and the vulnerabilities transcend the individual parts. Internet+ is the best way to convey that.
 
3. Can you elaborate on dangers that these Internet+ devices are posing to humankind? Where this will take us to? Can it harm people physically as well?
 
BS: One important difference between the Intenet we are used to and the Internet of the future is that computers can now directly affect the physical world. They help us drive our cars. They are embedded in our bodies in the form of heart monitors and defibrillators. They turn our heating and air-conditioning on. They fly drones and control power plants. Today, we can be physically harmed by computers in ways that just were not possible before. And that threat will increase as even more computers get physical capabilities.
 
4. India is a mobile phones addicted country and not many are using IoT devices. Apart from health issues, what are the risks and dangers, Indians would be facing from this 24x7 connectivity?
 
BS: IoT devices are coming to India, just as they are coming to the rest of the world. It is all about price, and the tiny computers in many IoT devices are becoming cheaper every year. India might be a few years behind other countries, but it is not immune. I worry less about 24x7 connectivity—that has been true for years—and more about the changing nature of what computers can do.
 
5. Last year, while writing on the gadget addiction, I had suggested readers to 'switch off', at least for some time. Do you think this will help in Internet+ environment or will we really be able to switch off all gadgets?
 
BS: Switching off is a nice solution when the problem is constant attention, and works with email, texting, for Facebook. It works when computers have screens that we stare at and which distract us. These embedded computers of the future will not work that way. We cannot just ‘switch off’ our refrigerators or thermostats for a block of time. We cannot shut down our power plants our  airplanes. When computers do not have screens and are just ‘there,’ switching them off will make less sense.
 
6. The world over records of various governments, especially when it comes to protecting data privacy and security of citizens, is not that good. Yet, in your book, you expect the same governments to come out with ‘smart regulations’. How it can be achieved, especially, where vested interests may be playing their part in helping governments prepare such regulations?
 
BS: This is a hard question, and one that I devote most of the book for answering. Suffice it to say that there is no single answer, and that governments have been struggling with this question in other areas of society for centuries. In my book, I talk about regulations and standards, about courts and liabilities, about international trade agreements and treaties, and about changing social norms. It is only when everything is working together will we get security.
 
7. Coming to Aadhaar, the ID system in India, earlier (22 June 2010) you told me that the authorities would not be able to address privacy and security concerns. Looking at the increasing number of data breaches in Aadhaar system, do you think India should still have such ID system that endangers lives of everyone? (Mera Aadhaar Meri Pehchan: But Leaked All Over the Internet! & Aadhaar: Patch Selling for Rs2,500 Allows Record Manipulation and Generation of UID at Will, Says Report)
 
BS: I do not know if it endangers lives, but it certainly endangers privacy. This is a tough balance. Governments need to be able to identify their citizens, and a single identity system is the most cost-effective way to do that. But it is also the most risky, and it is unclear to me whether the Aadhaar designers have spent enough time thinking about, and mitigating, the risks.
 
8. The Indian government itself has been enforcing Aadhaar through coercive methods on citizens and asking them to link it with everything from bank accounts to mobile and even pension. In such a case, how citizens should protect their private data and privacy? Is there any way? (So far, we have resisted and have not obtained an Aadhaar ID. Also the Supreme Court is about to announce a decision on Aadhaar.)
 
BS: So much of our data is in other peoples' hands. It is not just government systems like Aadhaar; much of our data is being stored by companies like Google and Facebook. When we give our data to others, we have to trust that they will protect our privacy. So while there are some actions individuals can take to better protect their privacy, the best thing we can all do is agitate for better legal privacy protections.
 
9. A few days back, participating in a conference in India through video, Edward Snowden has called Aadhaar “as mass surveillance tool created by Unique Identification Authority of India (UIDAI) and supported by those in power for political benefits. He also suggested criminal penalty on those seeking Aadhaar number for providing any service. Do you think this will deter the government and other players with vested interest to let go such a massive database of Aadhaar holders? (Aadhaar Is a Mass Surveillance Tool and There Should Be Criminal Penalty for Its Misuse, Says Edward Snowden)
 
BS: I think systems like Aadhaar are here to stay. As much as I see risks, governments only see benefits. For a country with a massive population like India, there is no going back.
Comments
Free Helpline
Legal Credit
Feedback