https://www.eff.org/deeplinks/2022/03/anti-war-hacktivism-leading-digital-xenophobia-and-more-hostile-internet Skip to main content * About + Contact + Press + People + Opportunities * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers + Podcast * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] --------------------------------------------------------------------- Email updates on news, actions, and events in your area. Join EFF Lists * Copyright (CC BY) * Trademark * Privacy Policy * Thanks Electronic Frontier Foundation Donate [podcast-si]Podcast Episode: Hack to the Future [podcast-si] Electronic Frontier Foundation * About + Contact + Press + People + Opportunities * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers + Podcast * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] Anti-War Hacktivism is Leading to Digital Xenophobia and a More Hostile Internet DEEPLINKS BLOG By Cooper Quintin March 21, 2022 [og-governm] Anti-War Hacktivism is Leading to Digital Xenophobia and a More Hostile Internet Share It Share on Twitter Share on Facebook Copy link [og-governmenthacking_0] The horrific Russian military invasion of Ukraine has understandably led to a backlash against Russia. The temptation is to label anything Russian, from state media and students to cats, as bad and block it to signal outrage and ostracization. This type of thinking has infected the open source and internet security communities as well--a terrible idea with potentially harmful consequences. Recently the maintainer of a popular open source Node JS package "node-ipc" released a new plugin called "peacenotwar." A Node JS package is publicly-available JavaScript code used by developers to add functionality to applications. According to the maintainer, this plugin would display a message of peace on users' desktops, serving "as a non-violent protest against Russia's aggression." Some versions of the node-ipc package, a networking tool that has been downloaded millions of times, will automatically run this protest-ware. Then a post on Github claimed that some versions of the node-ipc package were deleting and overwriting all files with the heart emoji if the package was installed on a computer with a Russian or Belarusian IP address. If the accusations are true, this is a terrible idea which could result in all sorts of horrible and unintended outcomes. What if a Russian human rights or anti-war organization, or a Russian hospital, was using this particular software package? This action--although conceived of as a simple nonviolent protest by the package creator--could result in the loss of important footage of protests or war crimes, loss of medical records, or even the deaths of innocent people. The trend of half-baked hacktivism involving everyday internet users is now growing into sites and games that encourage users to become part of DDoS (Distributed Denial of Service) attacks against some Russian digital assets. For the same reasons mentioned above, randomly sending attacks without thinking through the consequences and potential collateral damage are feel-good actions that amount to shooting in the dark. Also unknown are the consequences for users that were part of this campaign. Are users aware that they could have their IPs logged by a potentially aggressive and vindictive target? It's an incredibly irresponsible action that gives tools to ordinary users without the due diligence it deserves, putting innocent lives at risk on all sides. Targeting every computer with a Russian or Belarusian IP address with this sort of hacktivism as a means of protest against the actions of a government is patently absurd and harmful. Developers living in countries that commit war crimes, including the US, might want to consider how they would feel if the tables were turned. This sort of digital xenophobia didn't start with the Russian military invasion of Ukraine, however. For many years the common network defender orthodoxy has been to block certain countries deemed disreputable from your network, effectively creating no-fly lists for IP addresses. Most traffic coming from Russia or China is malicious, the thinking goes, so why not block all traffic coming from Russian or Chinese IP addresses? Putting aside for a moment the question of whether Russian and Chinese hackers have heard of VPNs, this bit of network security theater ensures that entire countries are thrown under the bus, many of whom might find your service useful, because of a few bad actors. 1 Calls are mounting to disconnect Russia from the internet since the Russian invasion of Ukraine. This is an awful idea and it once again treats Russia as a monolith, punishing the Russian people because of the actions of their authoritarian leaders. Russians who might be looking up information about a protest or trying to find news about those killed in the war will be blocked. Someone living in Ukraine in an area bordering Russia or Belarus could have their IP address incorrectly categorized as Russian or Belarusian. Their communications and ability to access websites about relief or evacuation efforts could be blocked. We have warned that remaking fundamental internet infrastructure protocols--like disconnecting Russia from the internet by revoking its top level domain names or revoking IP addresses--to protest a war will likely lead to a host of dangerous and long-lasting consequences. It will deprive people of a powerful tool for sharing information when they need it the most, compromise security and privacy, and undermine trust in the global communications infrastructures we all rely on. Treating the population of a country as a monolith risks alienating and denying services to people who would agree with you, people who are your allies, and people who desperately need sources of information and help. It makes the internet less open and more hostile for all involved. Equating people with their authoritarian governments in your performative activism is never a good idea. * 1. Of course if you are running a network that is only meant for a few specific people to access, you might feel justified in engaging in this bit of security theater. If that is the case then you should ask yourself why you are not banning all outside traffic except for a dedicated VPN? After all, malicious traffic can come from a country you trust just as much as a country that you don't. Related Issues International Tags threat lab Share It Share on Twitter Share on Facebook Copy link Join EFF Lists Join Our Newsletter! Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Related Updates brazil fake news bill Deeplinks Blog by Cory Doctorow, Veridiana Alimonti | March 21, 2022 Brazil's "Remuneration Right" Strengthens Big Tech and Big Media, At the Cost of Free Expression and a Free Press Brazil's "Fake News Bill" (PL 2630/2020) is the latest salvo in the global battle between Big Tech companies and the media industry--which is itself highly concentrated, controlled by a handful of dominant firms. The remuneration rule in the "Fake News Bill" is a made-in-Brazil installment that is poised to... International issues banner, a colorful graphic of a globe Deeplinks Blog by Shirin Mori | March 16, 2022 Letter to Iran, Regarding the Regulatory System for Cyberspace Services Bill Today, EFF joins Article 19 and more than 50 organizations in urging the Iranian government to rescind a bill with severe implications for the privacy, security and freedom of expression of Internet users in Iran. The text of our letter is below.Iran: Human rights groups sound alarm against draconian... [malware-shark] Deeplinks Blog by Alexis Hancock | March 15, 2022 You Should Not Trust Russia's New "Trusted Root CA" Last week, Russian citizens began receiving instructions to either download a government-approved web browser, or change their basic browser settings, according to instructions issued by their government's Ministry of Digital Development and Communications. On the one hand, these changes may be necessary for Russians to access... multi-colored hands with circuit patterns reach to the sky Deeplinks Blog by Katitza Rodriguez, Karen Gullo | March 3, 2022 Negotiations Over UN Cybercrime Treaty Under Way in New York, With EFF and Partners Urging Focus on Human Rights While tensions run high across the globe over the invasion of Ukraine, the world's governments are meeting at the UN this week and next to find common ground on a proposed treaty to facilitate international cooperation and coordination in computer crime investigations. The treaty, if approved, may reshape criminal laws... A person holding a megaphone that another person speaks through Deeplinks Blog by Corynne McSherry, Konstantinos Komaitis | March 3, 2022 Wartime Is a Bad Time To Mess With the Internet Like most people, we at EFF are horrified by Russia's invasion of Ukraine. Also like most people, we are not experts on military strategy or international diplomacy. But we do have some expertise with the internet and civil liberties, which is why we are deeply concerned that governments around the... [eff-pr-og] Press Release | March 3, 2022 Cybersecurity Experts Urge EU Lawmakers to Fix Website Authentication Proposal That Puts Internet Users' Security and Privacy at Risk SAN FRANCISCO--Electronic Frontier Foundation (EFF) technologists, along with 36 of the world's top cybersecurity experts, today urged European lawmakers to reject proposed changes to European Union (EU) regulations for securing electronic payments and other online transactions that will dramatically weaken web security and expose internet users to increased risk of... surveillance camera, purple background Deeplinks Blog by Konstantinos Komaitis, Katitza Rodriguez, Christoph Schmon | February 18, 2022 Enforcement Overreach Could Turn Out To Be A Real Problem in the EU's Digital Services Act Democracies are in many ways like the internet. In both cases, it may take a thousand cuts to demolish their foundation, yet each cut contributes significantly to their erosion. One such cut exists in the Digital Services Act (DSA) in the form of drastic and overbroad government enforcement powers. But... [eff-pr-og] Press Release | January 27, 2022 EFF Launches Tracking Global Online Censorship Project to Shine Light on How Content Moderation Affects Freedom of Expression Around the World San Francisco--The Electronic Frontier Foundation (EFF) today launched Tracking Global Online Censorship, a website project that provides comprehensive, in-depth information about how and why social media platforms remove users' posts, how users can appeal these take down decisions, and how the practice affects freedom of expression across the globe.Tracking... EU-flag-circuits Deeplinks Blog by Christoph Schmon | January 20, 2022 DSA: EU Parliament Vote Ensures a Free Internet, But a Final Regulation Must Add Stronger Privacy Protections The European Parliament had an important decision to make this week about the Digital Services Act (DSA). After months of considering amendments, members oscillated between several policy options on how to regulate online platforms, including the dystopian idea of mandating dominant platforms act as internet police, monitoring content on behalf... Egyptian blogger Alaa Abd El Fattah Deeplinks Blog by Karen Gullo | January 4, 2022 EFF Condemns the Unjust Conviction and Sentencing of Activist and Friend Alaa Abd El Fattah EFF is deeply saddened and angered by the news that our friend, Egyptian blogger, coder, and free speech activist Alaa Abd El Fattah, long a target of oppression by Egypt's successive authoritarian regimes, was sentenced to five years in prison by an emergency state security court just before the... Join Our Newsletter! Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Share It Share on Twitter Share on Facebook Copy link Related Issues International Related Tags threat lab Back to top EFF Home Follow EFF: * twitter * facebook * instagram * youtube * flicker * rss Contact * General * Legal * Security * Membership * Press About * Calendar * Volunteer * Victories * History * Internships * Jobs * Staff * Diversity & Inclusion Issues * Free Speech * Privacy * Creativity & Innovation * Transparency * International * Security Updates * Blog * Press Releases * Events * Legal Cases * Whitepapers * EFFector Newsletter Press * Press Contact Donate * Join or Renew Membership Online * One-Time Donation Online * Shop * Other Ways to Give * Copyright (CC BY) * Trademark * Privacy Policy * Thanks JavaScript license information *