Book 1: On the Nature of War, Chapter 1: What is War? (page 264 if you’re in the same edition I am).
The root of Clausewitz’s definition of war, which we will spend the rest of the chapter tearing to shreds, is “War is thus an act of force to compel our adversary to do our will.” Clearly, this is entirely too simplistic, as there are many means of compelling our adversary.
“It is accompanied by insignificant restrictions, hardly worth mentioning, which it imposes on itself under the name of international law and usage, but which do not really weaken its power.” There is a lot going on in this one sentence.
- “…but which do not really weaken its power.” In short: just because one shouldn’t, doesn’t mean one can’t. We see this frequently in the kinetic warfare realm, where just because there is an international law against <insert atrocity here>, it doesn’t prevent those atrocities. Given the general problems regarding enforcement of international law generally, this isn’t really all that shocking, but it is still a point of frustration.
- When it comes to the non-kinetic side of warfare, those international laws are truly “hardly worth mentioning.” There’s definitely been a lot of work in this area (see Tallinn Manual) but making enforceable laws on local levels has proven difficult enough, so getting useful laws at the international level that cover something as rapidly changing as computer use/misuse may not be tenable.
- We can’t even reach consensus among the InfoSec community itself as to whether trying to sort out international law is worth it. See: @tarah’s article and @marasawr’s response. Clausewitz would seem to think that international law has such a small impact as to not be bothered with, but we’ll see if that gets more nuanced with further reading.
“To achieve this object with certainty we must disarm the enemy, and this disarming is by definition the proper aim of military action.” In kinetic warfare, the concept of disarming is pretty simple and straightforward – many weapons don’t have legitimate civilian uses. This is particularly true of modern weaponry (missiles, assault rifles…) but for those things that do have legitimate civilian use, we have the Wassenaar Arrangement.
- The concept of totally disarming is problematic when “weapons” are everyday items – the same computer I use to write this blog post could, theoretically, be used to take down a power plant. Does that make my computer a “weapon”? One could argue it is all about the code on the computer, so we need to control code. Well, in a world with public GitHub repos, and pastebin, how do you control who access what code?
- With this in mind, trying to disarm a person of all possible “cyber weapons” would be not unlike banning all automobiles because a few people turn them into VBIEDs. We need vehicles, so we need mechanisms for identifying whether they are malicious or benign.
- Going back to the Wassenaar Arrangement, and the concept of dual-use goods, people like @k8em0 have been working to get exemptions for security researchers into it so that legit researchers are less likely to get rolled up. IMHO whether some of these things end up being futile for some use cases, it is really important to have a solid legal framework in place.
Paraphrase: Because humans have gotten better at weapons, we have more effective means of applying force than burning entire countries to the ground. I wonder if Clausewitz would be thrilled at, or horrified of, some of the advances in munitions since his time. We are better able to completely burn entire countries to the ground (see: nuclear weaponry), but we also have much better precision munitions that can reduce collateral damage. I suspect he would appreciate the latter as “more effective ways of applying force”. And then there are the non-kinetic effects that “cyber” can provide – deny access to information, manipulate that information changing how people make decisions – in addition to its kinetic effects.
“…we must either actually disarm him or put him in such a condition that he is threatened with the probability of our doing so.” Given the problem that is digital attribution, threatening to disarm your enemy is… interesting… when it comes to computers. SONY Pictures is a worthwhile case study in attribution, but also shows just how hard a problem it is (and the relative futility of even conducting attribution, from a deterrent/punishment standpoint). There’s definitely lots of ways to harass people using computer-based attacks, but few examples of really threatening an organization/nation with “disarming”.
“Now war is not the action of a live force upon a dead mass… I must fear that he may overthrow me.” This is an interesting piece of theory, because it gets into how we define active resistance (and does it really matter from a “warfare” standpoint?). Is pillaging a wide-open environment, even if it belongs to an adversary’s government, warfare? Is finding the few gaps in a well-defended environment, but still managing to sneak in and out unseen warfare? Is it only warfare if you are caught in the act, and the adversary at least tries to kick you out of their network? Or is it warfare if they don’t catch you in the act, but still see the effects of your actions after you leave?
The power of the opponent’s resistance is expressed as “the extent of the means at his disposal and the strength of his will.” Firstly, this sounds an awful lot like risk assessment math (you’re going to see this comment come up quite a bit). Secondly, the “strength of his will” bit reminds me of the fact that power is only power when one shows the will to use it. This is currently easily demonstrated by looking at how Russia and the US currently approach the use of the information at their disposal.
Speaking in really generalistic terms, Russia has been much more willing than the US to use the information at its disposal. They not only cultivate contacts and accesses, but turn around and use that information in their propaganda and disinformation campaigns. They are also not generally terribly bothered when they get called out because they’re not trying to save face. In contrast, the US’s intel machine is highly silo’d, and loves having information, but doesn’t want to generate those contacts and accesses again, so it is much more hesitant to actually use that information in a manner that would make it clear they had that information in the first place (when you see things about “sources and methods”). Thus, one could argue that both countries have equal means at their disposal, but one shows greater strength of will to use those means.
“An effort of will would be required disproportionate to the object in view.” More risk assessment math! This is a pretty common one for defenders: don’t invest more in protecting a thing than the thing is worth to you. The trick is that it is possible that its worth to the adversary may have nothing to do with its worth to you – something that is of trivial value to you may be of very high value to your adversary, so be sure that you understand your threat model when doing your own risk calculations.
Really important note: all of the above is essentially theory. Unfortunately, humans are messy, illogical creatures, so all of this needs to be modified to fit the real world. This will be addressed later on in the chapter, and in a separate blog post.
2018-09-21: Edited to fix Katie Moussouris’s Twitter handle, and to properly link all the Twitter handles, not just their work.
