Iran's moral agency
My video for SouthFront….
Yes, the pressure is relentlless.
CyberWar Part 2
My last post on the vulnerability of US infrastructure to cyberattacks was long and complicated and you may have missed some points which I did not articulate clearly enough. . My bad!
Iran certainly has the ability to hack digital systems and US infrastructure is very vulnerable.
The last article was based on US sources, which — as I wrote — naturally has a certain bias which we need to parse
Western governments (primarily U.S. agencies including CISA, FBI, NSA, DOJ, and Treasury), allied intelligence services, and private cybersecurity firms name groups such as MuddyWater (Seedworm), CyberAv3ngers (Shahid Kaveh Group), Charming Kitten (APT35), APT33, APT34 (OilRig),and APT42, all alleged to be Iranian“state actors” and accused of all sorts of malfeasance such as bank DDoS campaigns in the 2010s , the Bowman Dam intrusion, and, of course, doing naughty things to American elections.
Iran, however, says the country “never had on its agenda any dangerous measures in cyberspace and does not support such moves.” It has demanded documentary evidence from the US.–and, of course, received none
Because?
It’s classified? That’s bureaucratese for “fuck you”. And generally means there is NO evidence, just conjecture and speculation with ill intent.
Now ask yourself, US sources admit that its infrastructure is at risk, unprotected and if the Iranians did mount a full-scale attack, the country will fall apart, yet nothing is being done to reduce the risk.
While Iran denies it has a cyberwar agenda, it also says it reserves the right to proportional self-defense if attacked ,which it has not so far exercised despite being the victim of considerable American/ Israeli cyber aggression. For them, this is a matter of moral distinctions, which the US, having no moral core, does not make.
Iran, has some of the best digital engineers in the world , And it has independent hacktivist groups, who could very well be positioning themselves. There are also Zionists to consider, always ready for a False Flag.
MuddyWater (Seedworm), CyberAv3ngers (Shahid Kaveh Group), Charming Kitten (APT35), APT33, APT34 (OilRig),and APT42 ? Who are they? Nobody quite knows.
“Hacktivism, ” the kind of Activism that uses hacking as a way to promote social change, is significant in this cyber age. Anonymously entering into the groups and doing high-profile operations are well-known hacktivism activities. Hacktivists carry out these activities anonymously because they have no fear of retribution, social norms, or hierarchies. Most of the hackers have a shared sense of identity and purpose.
Motivations and behaviors of hacktivists can be understood by the “Social Identity Model of Collective Action”. According to the framework, various factors, including morality, social identity, injustice in society, and perceived efficacy, are the motivators behind hacktivism.
People with moral conviction take actions against injustice in society by joining anonymous groups where they have strong feelings about certain issues, such as corrupt government, abuse of human rights, anti-authoritarianism, and a desire for transparency and accountability. Iran is a society where morality matters
The upshot of all this is that we know:
that the US is vulnerable to cyberattack
Iran could devastate it
Moral issues are important.
We don’t know under what circumstances Iranian cyberwarfare would take place. The consensus of Sharia scholars is that such an attack would have be:
defensive
not excessive
not intended to cause suffering of the innocent
The greater the “collateral damage”, the stricter the requirement for justification.
Yet, the US and Israel seem intent on offering Iran moal justification.
Is that possible.
Yes. A good example would be Ukrainian terrorism which allows Russian attacks on Ukrainian military targets hidden in civilian warehouses, residential complexes, and the like. Modern infrastructure is to a greater or lesser extent multiple-use.
For a moral actor, the keys are restraint and deterrence rather than open-ended retaliation or revenge.
So, certain multiple-use civilian infrastructures — power supplies, communications, water , logistics and the like would be legitimate targets but hospitals and schools not.
The Ukrainians, Americans and Israelis are not moral actors obviously. Their goal is simply mass destruction.
The threat of Iranian cyberattacks on highly vulnerable American infrastructure is just another excuse for total war .
But as with Kiev and its terrorist attacks on Russia, the US may come to regret this strategy
Support New Forensics
Chappy and Ichi know I love them. I can’t help it.
Please donate to support Chappy and Ichi and their cuddle buddy Julian, by clicking on the graphic or the url below.
I would really like to get to 5000 subscribers. If you like my work, share the urls on other blogs and sites and in comments on podcasts.
Show us you care by buying us coffee at https://buymeacoffee.com/julicow




Between about 1988 and 1993 (when I left DEC) I did a good deal of lecturing and consulting about software security. Also hardware and human security, as security is seamless and cannot be divided up without leaving gaping holes.
One thing that I always warned my audiences and clients about was that, given the state of security in general and the capabilities available to attackers, the most remarkable fact was that so little damage was being done. Even in 1985, anyone with the inclination and a little knowledge could have cut a swathe of destruction through any country's computing infrastructure. Government and military installations were no exception - indeed, some of them were exceptionally vulnerable. (Like the US government VAX computers whose "system" (root) credentials had been left for years as account "System" and password "Manager". (Should have been changed the moment the computer was powered up for the first time)).
Software has not become noticeably more secure since then, but it has become enormously more complicated. That suggests more attack possibilities. Hardware, which used to be considered pretty safe, has developed alarming vulnerabilities such as Spectre and Meltdown. There have even been reports that manufacturers like Intel have put undetectable hardware features into all their processors that could be used to break security.
It is a well-known rule that complexity always militates against security. Early experiments like the MULTICS operating system held out some hopes of establishing a relatively secure baseline, but all such ideas have now gone with the wind. Low cost and high performance have won the day; even when hiring programmers cheapness is a powerful consideration.
Since 1985 or earlier, the whole computing world has been building on sand. Virtually any software can be snatched away without warning, causing untold harm. Iranian officials say they would not stoop to such sabotage, and they may well be telling the truth. But they have the capability.
As I wrote yesterday, given the US, Israel, and the EU/NATO via Ukraine were the aggressors, I would be hard pressed to fault the Iranians or Russians for taking the shot at vulnerabilities Western “leaders” knowingly left open before starting this rodeo. Expecting the Iranians and Russians to not take their shots or feigning outrage when they do exposes the naked calculation that the population of the Western countries could be used as human shields, or, worst yet, bait.