Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Researchers create humanitarian law digital emblem for the Red Cross (ethz.ch)
37 points by adrian_mrd on Dec 2, 2023 | hide | past | favorite | 48 comments


What’s interesting to me is that they are using the analogy with the actual red-cross like that automatically makes digital resources with the emblem entitled to protection in the same way that buildings and vehicles are. In other words, they want to suggest this is a simple extension of the meaning agreed to by States Parties to the Geneva Conventions of 1949. But it’s not a simple extension. Like, this is the sort of thing that you would need to include in an Additional Protocol in order for it to be binding, because it seems to me to represent a substantive extension of the original meaning and scope of the emblem affixed in meatspace.


Sure, crossing the Ts and dotting the Is are the job of diplomats. Hopefully it will happen. That doesn’t mean that a technical proposal must only be allowed once that is all squared away. In fact the existence of a widely deployed technical solution makes it easier to achieve consensus on the protocols.


Of course. I’d go further: it wouldn’t even make sense to try to achieve consensus until you have at least one functional technical solution. I just meant that this seems like the first step in that process. A couple of other comments seem to be suggesting this is a stupid thing because they were taking it as saying, “Problem solved!” This is a first step to open discussion on how IHL needs to be adapted to our present world, not bulletproof technical armor by itself.


Modern states are basically just feudal states with their private extensions, particularly on the international level and over the last 3 decades they chose over and over to let analogies hold from meat space because it maintains or expands their power relative to other elements of society.

The Red cross should not look for specific legislation so that any states that are foolish enough can argue their own assumed rights away and will have to take that risk if they want to take back the right the Red cross is taking by the same analogy.


I’m not sure I understand what you’re saying in that second paragraph. Can you expand a little bit? There is no “legislation” involved here at all. These are treaties. If there’s no treaty agreement, there’s no right period (setting aside customary international humanitarian law, which I think is obviously safe to do here, because, like, none of the elements required for something to be recognized as customary are present here).


A new convention functions as international legislation as far as I am concerned. The US for example did not ratify the newer convention on statelessness.

Take that scenerio with the Red Cross and a new convention to treat government sponsored criminals as not allowed to attack the Red Cross. It is far less risky to act like they already have that protection and every state should punish a State that violates their existing promises under existing convention than to navigate the situation where a superpower does not ratify the new convention and claims retaliations and shaming are technically violations of their sovereignty.

For a state in the current situation to deny such analogies seems paradoxical to me.. The Internet was not the wild west it was supposed to be for everyone when it comes to their own advantage, but still as dangerous as the wild west due in large part to criminals that are connected to sovereign States and largely shielded using rights to war logic.


Oh, I see now. I mean, I don’t disagree that the most aggressive way for the ICRC to handle it would be to claim it as some kind of emerging customary norm rather than trying to whet appetites for a new AP to address it. You can never be sure what the results of treaty negotiations will be. Failure to ratify an AP would be positive evidence that there is no such norm. So why risk it?

The problem is that it’s wildly implausible that there is such an emerging customary norm. And there really is no way to claim with a straight face that this sort of thing falls under the terms of the GCs. And the problem with making aggressive claims about customary norms is that IHL really only does work if people agree to make it work. The worst thing that could happen is to have countries not even pay IHL lip service.

But this all gets to the really, really hard but fundamental question of international law: enforcement. I was piqued by you originally using the term “legislation” just because the way we think about legislation, there is usually an executive to enforce it. That’s part of what makes it “law.” But there is no such thing in international law, and given how overwhelmingly powerful states continue to be, there won’t be in my lifetime. I love the idea of international law, but this is what makes it so slippery and difficult and frustrating.


This certainly would not "automatically make digital resources with the emblem entitled to protection". The criteria for the humanitarian emblem were very specific: a red cross/crescent/lion on a white background. Any other emblem (even a very similar emblem like the red star of David on a white background once used by Israel) doesn't qualify for protection.

But there is a legal mechanism for adding new emblems, which was used to add a "red crystal" in 2005 [1], and I imagine a similar mechanism could be used to add a digital emblem.

1: https://en.wikipedia.org/wiki/Protocol_III


Right, that’s why I said: “This is the sort of thing that you would need to include in an Additional Protocol.”

I think some people were confused why they were calling it an emblem. It’s an analogy to the protective emblems agreed in the GCs and APIII. But analogy alone won’t make this binding, and the ICRC knows that. This “technical solution” isn’t like a solution that solves the problem today. It’s the first step in showing that doing the work of another AP is possible and needed.


It can be an NFT that's technically a red cross/crescent/lion/crystal on a white background, and verifiably endorsed/minted by the Red Cross organization for that specific use. That way the existing treaty applies by extension.


For more technical details, here is the actual spec: https://github.com/adem-wg/adem-spec

If you are a nation state hacker, you can also install the convenient chrome extension which will tell you if you are allowed to hack a website or not: https://chromewebstore.google.com/detail/adem-dns-checker/ik...


Yes, if I’m a nation state hacker I’m totally going to install a third party Chrome extension from the Chrome Web Store.


An alternative is to expose yourself to ICC and universal jurisdiction of War Crimes, I dunno, maybe you should. Or maybe not, so you can claim to be on the other side of carelessly/knowingly line.

The point of this is not to make ICRC unhackable, the point is to make sure that 1) you can see you are specifically hacking protected communication 2) it's possible to prove to third party that you still continued with your war crimes business, because you either don't know better or don't care.


> An alternative is to expose yourself to ICC

Unless you're American, since the US doesn't recognise the ICC.


Various states don't recognize the ICC, but that doesn't stop prosecution. What does stop prosecution is if no one transfers you to the ICC or you have a state that is willing to invade if the ICC prosecutes you. In theory, the US falls in the latter category, many others fall in the first. Nonetheless, people have been prosecuted even if their state of origin didn't recognize the ICC. Otherwise, it would be really easy for some crackpot dictator to just say his state didn't recognize the ICC under his dictatorship, so he cannot be prosecuted.


Or work for Tsahal. Those "universal" jurisdictions aren't are universal they pretend to be, it's just another way to enforce power for people or nations already powerful.


How many cybercriminals have been prosecuted (and punished) by the ICC again?


One of the major reasons humanitarian organisations are not attacked or even protected is because generally they provide benefits impartially, officially or otherwise. This makes attacking them "spitting into the well" and risk not only depriving yourself of the benefits but also earning yourself enemies from all sides.

I don't believe this dynamic exists online, for one, the belligerents are often in the shadows and don't depend or rely on any "community" or locality that might be benefiting from humanitarian work.

The only benefit this digital certificate might provide is prosecution grounds for harsher punishments, which isn't useless, but far from being a red cross or lion.


Another reason is that many humanitarian organisations get out of the conflict zone pretty fast once their handlers' real antagonists come to the fore, notice how's no Red Cross or any such presence in the Donbass, to say nothing of the many countries in the Sahel and in Central Africa which have switched sides to the Russians and the Chinese.

As to why the West chooses to instrumentalise humanitarian organisations, that's another discussion.


>notice how's no Red Cross or any such presence in the Donbass

"The Russian Red Cross (RKK), together with the Office of the United Nations High Commissioner for Refugees (UNHCR), will provide assistance to internally displaced persons in Donbass"

https://www.emergency-live.com/news/the-other-side-of-the-fi...

>to say nothing of the many countries in the Sahel

Red Cross in Mali: https://www.icrc.org/en/where-we-work/africa/mali

Red Cross in Niger: https://www.icrc.org/en/document/operational-update-niger-mo...

Could you explain further?


Didn’t see any Red Cross thingies close to the battle-fronts, as in, putting themselves in harms’ way in order to save lives. I’m talking about Ukraine/Russia, which is the conflict I’ve followed closer. I’m convinced the same holds true about Niger and Mali, where they most probably enjoy diplomatic neo-colonial status close to the capital.

In other words, show me the Red Cross people who have lost their lives close to the lines of battle in the last 5-10-15 years and I’ll change my opinion. Otherwise, stuff like this just denotes laziness when it comes to investing in real IT security.


https://www.nbcnews.com/id/wbna19173330 - Two Red Cross workers killed in Lebanon camp

https://www.npr.org/sections/goatsandsoda/2017/02/10/5145078... - six killed in Afghanistan

https://www.reuters.com/world/africa/two-red-cross-workers-k... - Two Red Cross workers killed in attack in western Mali

I think you might just not be well informed, combined with being too lazy to do a 2 minute web search "red cross workers killed".

I half expect you now to say "yeah, but it isn't that many people", which might be because it is a a WAR CRIME to kill Red Cross workers. Really, seriously smh.


I bet the same people behind this would take https://www.ietf.org/rfc/rfc3514.txt seriously.


My goodness, what a charade!

> In other words, hacker software needs to automatically load and read the emblem, so it can recognise that it is accessing a system belonging to an organisation that is protected by international humanitarian law. And that needs to happen during the software’s first reconnaissance, before it does any damage to the system.

Hackers are going to look up the emblem "protected by international humanitarian law".

> Another key requirement is for the digital emblem to be managed in a decentralised way rather than by a central authority. States that are committed to international humanitarian law should be able to verify that a certain digital infrastructure on their territory is entitled to protection and therefore bears an emblem.

And when they say decentralised, they mean centralised: states "should be able to verify that a certain digital infrastructure".

PS Felix Linker is defining a new protocol for hackers to anonymously check whether infrastructure can be attacked... The theatre of war!


It’s merely meant to be a digital equivalent of a physical red cross/crescent on a battlefield. So if the “hackers” are members of the armed forces of a State Party to the Geneva Conventions of 1949, then… yes, they had better look up the emblem, if they don’t want to be seen as war criminals. That’s the idea at least. although, as I’ve said elsewhere in my comments on this, I think they’re going to need to propose an AP for it to have any actual legal effect.


This is aimed at nation state hackers. E.g. those who work with bosses and budgets and accountability.


I should probably read the article but it sounds like a great way of announcing the that you are attacking a server.


The conference paper is the best read for details: https://dl.acm.org/doi/pdf/10.1145/3576915.3616578 - the security properties of the scheme are 1) supports covert inspection, 2) emblems are verifiably authentic and 3) provides accountability - identification of parties that issued fraudulent emblems.

The covert inspection part is primarily through broadcast of the emblem through multiple channels (so it will go to many people interacting with the systems who didn't ask) so that the attacker will see the emblem passively without having to make a request for it that only attackers would make.


The whole thing feels dreamt up by AI.


The nature of criminal hackers is not to care about this. If it has value (financial or ideological) they will target it. Often the point is to send a message. I’m not sure they care not to attack the red cross. Also, cybercrime is one way countries try to act in the shadows. The point is to not be discovered so they can do things that are not allowed by international law. Why could they respect this if people can only accuse them and not prove it? Even when there are mountains of evidence, they still say it wasn’t us…or simply remain quiet. Did any country come forward on the pipeline attack?


Because when you actually read the linked article, you will see that it usually contrasts cybercrime with the use of cyberattacks during a time of armed conflict. In other words, this isn’t about cybercrime. This is clearly targeting states parties to the Geneva Conventions. So, if we (US) go to war with China, the idea would be this would serve to validate that some digital resource or system is entitled to protection from attacks by either side in the same way that ambulances are supposed to be. Attacks on ambulances are no less war crimes just because no one wants to admit publicly they were the attacker.


Wonder if the real goal is that when these people are caught you go after them for crimes against humanity and not just hacking.


I presume you're correct. They're trying to create a digital equivalent of the red cross emblem and encourage others to make it the norm. It sounds unbelievable that it would be effective, but so does a white paint job and a red sticker on a vehicle.


Yes, but as I said in a separate comment elsewhere on this story, the sort of interesting question is, how do they extend the legal protection to this digital emblem? I smell a draft additional protocol in the pipeline.


A cynical person might even suggest that the mere existence of such emblems, which are actually ineffective at increasing digital security but rather only provide a legal framework for prosecution, would encourage false flag operations.


With that argument you could say that the red cross in the non-digital world encourages false flag operations.


I think it’s still much easier to attribute a physical attack than a digital one.


     << Digital Ambulance -- plz do not hack!!1 >>


Afaik that organization is very protective of its brands and symbols. Are these researchers authorized to use that name?


If you read the article there are quotes from an ICRC representative.


They discovered public key certificate infrastructure and are calling it an "Emblem"


From the technical point of view is like a signed robots.txt , to avoid idiots publishing a "life hack" to protect your machine from virus. (Or antivirus adding it by default to every machine.)

A nice name makes it easier to explain to laymen. This idea can not work unles they convince a lot of diplomatics to sign all the paperwork.

But as the sibling comment said, I also was looking for an image until I understood the implementation.


Thank you — was looking for a visual


I wasn't aware there was international law pertaining to not hacking medical facilities in the same way there is law pertaining to not bombing them.


It seems completely obvious that humanitarian law also covers cyber attacks.

Rule 15. In the conduct of military operations, constant care must be taken to spare the civilian population, civilians and civilian objects. All feasible precautions must be taken to avoid, and in any event to minimize, incidental loss of civilian life, injury to civilians and damage to civilian objects.

Disabling a hospital by attacking its IT obviously will lead to loss of life of injury and is thus, other factors notwithstanding, not permissible. If you attack power infrastructure (using bombs or by hacking, doesn't matter), that's probably also a war crime because it's indiscriminate and, among other things, affects hospital and other civilian infrastructure.

https://ihl-databases.icrc.org/en/customary-ihl/v1/rule15

https://ihl-databases.icrc.org/en/customary-ihl/v1


It should be, but I'm not sure it is, considering the use of dedicated weapons like graphite bombs to disable 85% of the grid in the Gulf War.

But maybe you have to ratify Protocol I of the Geneva Conventions for that to apply.

And we'll see how well they're enforced after a ratifying country has been hammering civilian infrastructure in Ukraine.


Nothing is illegal until someone is punished for doing it.


There isn’t, of course, but they are clearly laying the groundwork to extend IHL that direction. Which, as I said in a different comment, seems to me like it would require an Additional Protocol to the GCs, because it surely isn’t and won’t be customary IHL.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: