Reports & Papers

36 Items

Paper

The Coming AI Hackers

| April 2021

Hacking is generally thought of as something done to computer systems, but this conceptualization can be extended to any system of rules. The tax code, financial markets, and any system of laws can be hacked. This essay considers a world where AIs can be hackers. This is a generalization of specification gaming, where vulnerabilities and exploits of our social, economic, and political systems are discovered and exploited at computer speeds and scale.

Donald Trump and Anthony Fauci

AP/Alex Brandon

Paper - Centre for International Governance Innovation

US Intelligence, the Coronavirus and the Age of Globalized Challenges

| Aug. 24, 2020

This essay makes three arguments. First, the US government will need to establish a coronavirus commission, similar to the 9/11 commission, to determine why, since April 2020, the United States has suffered more coronavirus fatalities than any other country in the world. Second, the COVID-19 pandemic represents a watershed for what will be a major national security theme this century: biological threats, both from naturally occurring pathogens and from synthesized biology. Third, intelligence about globalized challenges, such as pandemics, needs to be dramatically reconceptualized, stripping away outmoded levels of secrecy.

In this April 22, 2020 photo, Gerard Bakulikira, right, and captain Tim Daghelet, left, both wear a Romware COVID Radius digital bracelet, which flashes red when people are too close to each other and creates a log of contacts. 

AP Photo/Virginia Mayo

Paper

Considerations for Digital Contact Tracing Tools for COVID-19 Mitigation: Recommendations for Stakeholders and Policymakers

Many are looking to digital contact tracing to assist reopening efforts, especially in light of reports that the U.S. could expect as many as 100,000 more deaths due to the virus by this Fall. This report focuses on how the U.S. might consider various proposed solutions.

We believe there are real benefits, challenges, and even potential harms in using digital solutions in the fight against COVID-19, but we must also acknowledge that the promise of any technology and associated systems to assist manual contact tracing efforts is largely hypothetical in the United States. There is not one catch-all answer; the truth is that technology is not a panacea, but it may be able to assist official efforts at an unprecedented time. However, no technological solution can succeed without two specific factors: public trust and buy-in, and rapid, widespread testing for everyone living in the U.S. To achieve the first, a number of factors must be addressed by officials in the states looking to implement digital solutions, and by technology developers.
 

Advocacy groups display a thousand signs that read #GetUsPPE, along images of health care workers, in a call for personal protective equipment for frontline health workers during the coronavirus outbreak, on the West Lawn of the U.S. Capitol, Friday, April 17, 2020, in Washington.

AP Photo/Andrew Harnik

Paper

Coronavirus as a Strategic Challenge: Has Washington Misdiagnosed the Problem?

| April 2020

With reservations about venturing into territory outside our normal wheelhouse, and in full certainty that some of what we write here will in retrospect turn out to have been wrong, a team of researchers at the Belfer Center and I have been collecting all the data we have been able to find about coronavirus, analyzing it to the best of our ability, and debating competing answers to the fundamental questions about the challenge this novel virus poses to our nation.

What follows is our current first-approximation of a work in progress. We are posting at this point in the hope of stimulating a wider debate that will include a much larger number of analysts beyond public health professionals and epidemiologists—including in particular intelligence officers, financial wizards, historians, and others.

A representative image of a digital "map"

Adobe Stock

Report

Reconceptualizing Cyber Power

Our intention is to provide the best possible understanding of cyber power capabilities to inform public debate. The Belfer approach proposes eight objectives that countries pursue using cyber means; provides a list of capabilities required to achieve those objectives that demonstrates the breadth of sources of cyber power; and compares countries based on their capability to achieve those objectives. Our work builds on existing cyber indices such as the Economist Intelligence Unit and Booz Allen Hamilton’s 2011 Cyber Power Ranking, by, for example, including a policy dimension and recognizing that cyber capabilities enhance military strength.

PRC flag with digital overlay

Adobe Stock

Paper - Belfer Center for Science and International Affairs, Harvard Kennedy School

Governing Cyberspace: State Control vs. The Multistakeholder Model

| August 2019

This paper is part of a Track-II dialogue between the Belfer Center’s China Cyber Policy Initiative and the China Institute for International Strategic Studies (CIISS) to manage the risk of cyber conflict between the two countries through dialogue and concrete policy recommendations. The paper includes two parts: a cyber governance theory written by Chinese People’s Liberation Army Major General (ret.) Hao Yeli, a senior adviser to CIISS, and a response prepared by Belfer Center Co-Director Eric Rosenbach and Research Assistant Shu Min Chong.

Paper - Cyber Security Project, Belfer Center

Countering the Proliferation of Malware

| June 27, 2017

Malicious software is adapted, stolen, bought, and used everyday on a global scale. There are better ways to counter this proliferation than export controls. Policymakers should strengthen incentives for researchers and the private sector to rapidly identify software vulnerabilities, disclose them to developers, patch those vulnerabilities, and adopt those patches. Building on previous debates, this paper makes specific recommendations to shorten the lifecycle of vulnerabilities and improve the short term health of the software security ecosystem.