Thank you so much, and it's really fortuitous that we had the DIAF presentation right before this, because I wouldn't be presenting on this panel if not for the award that I got from DIAF and all the very helpful mentorship, a lot of that being Elizabeth Garber, who helped me put together this presentation. I started speaking with Elizabeth about law, as I am a lawyer, and that's how I came into this space, and digital identity as a human right and what is being done right now.
Since 2013, digital identity has been referenced in cyberspace as international law has been declared by the UN to apply in cyberspace. In reality, there is not a very good one-to-one connection between international law and cyberspace, and so not a lot has been done in terms of enforcement in international law. This panel today really brings together a lot of perspectives on the other areas of enforcement and digital identity that you see in conflict.
With that, I'll have the panelists introduce themselves and start with the first question of, what do you see right now in this space as it relates to digital identity and defense? Good morning. Maybe good afternoon, just about. I'm Sanjay Dharwadkar. I'm the senior digital identity officer at the UN Refugee Office, UNHCR. We are in a lot of trouble because the US government has cut our funds. I'm not very sure whether I'll have my job tomorrow.
But today, as I'm still in the job, I'm here, and I'll try and speak on the topic, which is a very difficult topic, and wonderful guys here. Very quickly, do you want us to first introduce ourselves?
Yes, please. My name is Alex Weinert. I am recently, I guess, completed a 30-year tour with Microsoft, leaving a lot of the identity security space, including a lot of nation-state conflict that happened sort of in our systems as battleground. I recently joined St. Paris as the chief product officer. Good morning, everyone. I'm Adam Cooper. I'm an independent consultant, ex-UK government, but spend most of my time these days working with the World Bank.
I've done for quite a few years, which means I actually come into contact directly with many countries that are suffering conflict or are under attack from other countries in one way or another. So hopefully be able to talk about some of those today. But I think looking at some of the legal aspects would be very interesting as well, and what could or can and cannot be done there. Want me to go on with the question?
Sure, go ahead. Yes. So I think where we stand today is a very interesting situation in many countries. We have some international laws that cover some aspects of how we protect states that set guidelines for how states should interact with each other in a normal way, shall I say. Unfortunately, we're seeing more and more weaponization of digital in warfare, for example. It's not so much tanks that invade countries anymore, it's hackers. It's techniques that are often not seen, often are instigated by partners and clients and not directly the country you would normally see invading.
You will have seen many incidents highlighted in the news, sort of the high-profile ones, some of the things that happen maybe in Lebanon with attacks on pagers, telecom systems, even attacking banks. You get other countries as well where cyber attacks are not necessarily instigated directly by a country as a part of warfare, but are state-sponsored. So North Korea has been very good at weaponizing cyber security attacks over the years to attack countries and it's causing huge damage.
And sometimes it's just because these things are out there and they get used to attack countries and cause huge disruption. One example of that from about 12 months ago is the Indonesian immigration system was completely wiped out. When I was trying to cross the border, I had to provide emails from my own phone to prove that I actually had visas, for example, because that's how vulnerable national infrastructure can be now because it is digital. So there's inherent danger in what we do digitally.
I'll let the other panelists sort of kick into this now, but one of the concerns I have is that I don't see there being enough legal protection for countries in those situations because traceability of these events and attribution is very hard. Yeah, no, I think that's correct. I think attribution is challenging. And I think something that makes it interesting, if you think about the body of norms and laws that we have, for example, espionage or for sabotage, that sort of thing, if you go back over the time in which those norms were created, it was generally you had to be physically present.
Which gives you both a sense of attribution, the ability to do attribution, but also to bring people to justice under the laws of the nation in which the crimes were committed. Mostly with cyber, these attacks are happening very remotely and through a lot of obfuscation, so that attribution is extremely hard. But moreover, the person who's perpetuating the act of sabotage or espionage or attack is protected in their home country by their sponsoring forces, so that part is hard.
I also think it's kind of – I'd actually like to hear from you a little bit about this, but it seems like even where we have laws, which are mostly far behind the realities of technology that we're dealing with, increasingly laws are being ignored. And so we can add another layer of complexity. Thank you. I think our refugees agency comes in where we see the impact of war and impact of violence and the applicability of these laws on individuals. So what happens is that a war breaks out and millions of people come out and they need to be provided what we call international protection.
And as has already been said, many of the conventions or laws which govern all this, that how is a refugee to be received, how is he to be protected, were written post-Second World War. You know, our Refugees Convention is dated 1951. The Statelessness Convention is dated 1955. And the provisions look so archaic today.
So, you know, we have to find some little interpretation which can help us survive in today's world. And one of the major, you know, kind of changes has been the whole warfare has moved into the cyberspace. And I heard Bill Gates talk about this 20 years back. That time it didn't seem, he says there'll be as much warfare in the cyberspace as anywhere else. And that is so today. And we see some very, you know, difficult situations. What is happening is that countries are realizing the importance of records.
So, for example, in some of the recent wars, the first thing some of the invading countries did was destroy the entire civil registries of the, you know, the countries they were invading. And suddenly you had no record of, you know, the individuals of that country, the citizens of that country. So it is this kind of a situation that, you know, we need to grapple with. We have to work, you know, kind of as innovatively as possible. And that is where we are. I can go on forever, but I think. And I think to highlight that this is such an issue that transcends boundaries.
You cannot limit it to one state. And so that's why international laws are so important in this space. Just as you see with climate change, those international standards, if you can create them, are so much more effective. And I want to dial back on attribution that you mentioned. This is something that we've discussed before as well. How do you attribute a cyber attack to a state? That's very difficult. And it's also very crucial in the legal realm. The remedies are vastly different for a non-state actor versus a state actor.
And trying to breach state sovereignty is another legal issue that comes into play. And I wanted to ask from the technical side, how do you approach attribution? And then maybe we can circle back to the implications on that.
Yeah, I can tackle that one. So these are things you can read about. I'm fortunate to have worked with some really brilliant people who track nation-state actors and advanced actors. And there's a set of things that are happening when we're tracking a body of actors that can range from the way they serve their VMs to the kinds of VPNs that they use to specifics around the IP address or times of day, activity times of day, that sort of thing. And then sometimes you get lucky and you get an intercept of email or one kind of well-known example I spoke about at RSA last year.
They popped up a server, but they forgot to secure it. So we actually were able to dump the server before they could shut it down. And at that point, we actually had source code and we could see hard evidence of who we were dealing with. So sometimes you get a break and you're able to do more attribution.
Now, in terms of enforceability, you still have to get a court to accept that attribution. As a large corporation, my previous employer, we were cautious about attribution because you don't want to make accusations you can't back up. And then very often now, for example, Iran has a good cyber training program. And a lot of people leave that program and go do independent work that if it is successful, the government will reward them for it. So they're not actually state actors. They're sort of contractors or vendors to the state. So this is all part of the complexity of it.
From a technical perspective, attribution is going to be a combination of, first of all, getting enough behavioral telemetry to sort of say we're dealing with the same group of people. And you might say, OK, here's a group of people that are operating. We can track them back to IPs in China or they're operating in, say, a Chinese time frame. That's not actually attribution. That's not enough. Because anybody can operate at any time of day and anybody can VPN to anywhere. Right. So you have to go a little bit farther.
And again, you have to get lucky enough to get those intercepts of communication. And with that obscurity, how do you see governments trying to handle that? I know you mentioned reliance on private as well.
Yeah, I mean, talking from my perspective of working in UK government for many years, it's every government suffers this kind of attack. So it's not just warfare. It's espionage as well. It's attempts to steal intellectual property quite often. That happens a lot. So these things are going on constantly. And the intelligence agencies play a huge part in this. Countries like my own, where previously I've worked with GCHQ, for example, that have the capability to deal with these kind of attacks. It's good. What we need, I think, more of is sharing in that intelligence community.
It happens in Five Eyes, for example, to a good extent, but it doesn't happen internationally. It's almost as if, and this is wrong, I think, for many of the Western countries that have this capability, that they aren't playing a big enough role in sharing that protection from knowledge and intelligence and real intel that they could. And I know they do some work like that, but they do some more. I think one of the things that makes it a little bit harder for us as professionals to guard against this is that we are driving forward constantly with new technologies.
And we're talking today even about gathering facial biometrics and biometric information for everyone. Yes, that's fantastic. All of a sudden you're creating really good target datasets. So it's a double-edged sword. So we have to always be mindful of, when we create these things, the impact they're going to have. I'll give you an example from Ukraine.
One of the things that the Russian state does is not just so much to attack the systems in Ukraine, but actually to utilize them by accessing them so that they can confirm, by looking at different datasets that the government holds, where airstrikes have been effective. Because you look at public data that's held by the government, administrative data that looks at, well, we need to repair roads and buildings and, oh, look, that maps nicely to the thing we attacked. So did we hit our target?
Oh, yeah, we did. We took that out. So it's just having that sort of appreciation that it's not just about stopping things working. Sometimes it's about that espionage element as well, which is really powerful when you're an invading nation. I'd only like to add here what happens at the UN is that, as the example of biometrics, okay, if you're using biometrics, have these additional guardrails in place, have these additional precautions that you must take.
But it's only now that some effort is being put in to have something like, you know, have a war criminal kind of attribute given to something happening in cyberspace. There's nothing today, you know, so people can get away with impunity. And talking of Ukraine, sorry, I'm almost digressing a bit, because that was our new operation, and we were receiving the Ukrainian refugees at seven country borders, you know, Poland and Czech Republic and Moldova. And I think on a single day at the Polish border, we had 150,000 refugees turned up.
So just capture of that data and, you know, knowing where they are going, we had to be extremely innovative and wish we had many more of you digital identity experts to, you know, find solutions for us. Yeah, I do think that, you know, we do have norms and conventions around not, for example, not targeting civilian populations. But to your point, like the infrastructure, you know, in fact, tracks a lot. There's a lot of data that's stored. And we've talked about identity systems, especially to serve at risk communities, and the importance of protecting the data there from hostile governments.
If you can, you know, figure out who's moving and delete those documents, these are forms of targeting when you're taking out a power grid or you're turning off a hospital people buy. And that is targeting civilian populations, but we don't, we're not mapping it in our heads to the conventions we already have. I think you raise a great point there about targeting populations, Alex. And that's not just conflict between one nation and another that quite often happens within a single nation.
If you think about the Rohingya, for example, they were forced to be enrolled into the national verification card system, basically an ID card. Why? Because the government wanted to identify them as foreigners so they could be persecuted. So that's when a digital identity system can be used very powerfully to actually harm people. It wasn't a digital ID system, but in 1994 in Rwanda, identifying people by their ethnicity, which was recorded on national ID cards, caused a large part of the genocide.
So you have to be careful about when one of the things in the World Bank that we do is we make sure that the legal ecosystem is in place in any country we engage in to make sure that those kind of things don't happen, so that you're not recording information that can be used to persecute your own citizens. Because the government today might be completely benign, but six months from now, who knows? One weakness I see globally is that as World Bank, we will intervene in many countries, but we're not intervening in Europe. We're not intervening in continental USA.
Who's setting the parameters for how our governments collect and manage our data? I think that's still an open question. As a final takeaway, we've noted that the laws as they currently exist don't map well into the cyberspace, and there's a lot of gaps. What is one solution or improvement in terms of standards or protocols that you'd want to enforce?
Well, in the last couple of refugee situations, we found against a lot of advice and against a lot of general directions that storing data in the cloud is dangerous. But we had certain compulsions why we had to put our data into the cloud, and that has more than once now saved us because the data is always available somewhere. Countries dissolve.
You know, we've seen like in Yugoslavia, entire countries dissolved, but the data was still there somewhere in the cloud. And that is something which always helped both organizations as well as individuals. I think from the perspective of having worked on one of the big identity platforms, something that's actually effective is when you set up norms and say to do business here, these protections must be in place, like the GDPR, the UDB, data locality rules. Those things actually can create meaningful protections.
If we were to include the possibility of, especially I think for our industry, the identity-specific targeting that we were talking about, these were great examples of, hey, if you're providing an identity system, providing in a way that the data is protected in these cases, and I'm not sure what the right answers are all the way, you know, it's an area of interest, but I think that this is a place where local rules, because even if it's a relatively local rule, there are big businesses that operate in those localities, and we want that business.
And so then we'll comply to more conflict-resilient systems. I think there's just two brief things I'd like to say about all of this. Sanjay talking about the cloud is very pertinent.
I mean, just to give another example from Ukraine, one of the first things that happened when Russia started the recent amount of attacks is a missile hit the primary data center for the Ukrainian digital systems. Luckily, they backed it up to the cloud, and that was a recent thing. Many countries are concerned about data sovereignty and cloud, and it prevents them from doing that. I know many countries who are under similar threats to Ukraine who are not doing this, but it's an incredibly powerful thing.
It enabled the Ukrainian digital systems, the BIA and all of those, to keep going, and that's served the people very strongly. The other thing is resilience in a day-to-day sense, and decentralizing government systems is very important. Anywhere where there's centralization is a point of attack. So decentralizing how these systems work is also a very powerful protection. And I think as one final note on the legal side, there is a lot of work being done right now to match international law to cybersecurity standards.
One example of that is the Talon Manual and the Talon Manual 2.0, which traces the black letter law and applies it. And if governments can start to adopt that, that has a lot of implications for stopping cyber attacks. Thank you so much. Unfortunately, we don't have time for the questions, but please feel free to catch up with our panelists in our networking rooms or in the open space you have. Thank you so much again.