
Hosted by The Federmann Cyber Security Center – Cyber Law Program · EN

The two active shooter terrorist attack in San Bernardino became into a high-tech case when the phone of one of the shooters was obtained by police, which couldn’t open it because of encryption. This turned into a legal battle between the state and Apple, the creator of the phone, who were asked - and refused - to give access to the phone and to the information on it. This has inspired a lot of research and discussion of what rights we have as users for encryption for password protection, and should it be circumvented in the case of criminal offenses, and how. We talk about this and more in this episode of Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Research Center’s podcast, with Jennifer Daskal, Professor of Law, American University Washington College of Law; Stewart Baker, a lawyer with Steptoe & Johnson in Washington, D.C., and host of the Steptoe Cyberlaw Podcast; Amos Eytan, an attorney with the Israeli State Attorney’s Cybercrime Department; and Lex Cybernetica’s host, Ido Kenan.

Freedom of speech is almost a sacred thing in the US and revered in many democratic countries. But in recent years, there is talk of its abuse to propagate hate speech online, and the need to limit it as a result. What is hate speech (or dangerous speech), what’s unique about it online, what are its real dangers, how should it be dealt with, and at what cost? All this in this episode of the Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Research Center’s podcast, with Susan Benesch, Executive Director of The Dangerous Speech Project, Faculty Associate of the Berkman Klein Center for Internet and Society at Harvard University; Omri Abend, Hebrew University faculty member, researching NLP; Rotem Medzini, Research Fellow at the Federmann Cyber Security Research Center; and Lex Cybernetica’s host, Ido Kenan.

Legal accountability means that an unlawful act does not go with impunity. When a state carries out a cyber operation against another state, it’s accountable under international law towards the international community. However, international law doesn’t always have teeth to hold the rogue actor accountable. Additional challenges include attributing the act to a state, which might be using proxy groups and technology to conceal its identity and the actions themselves; and even the mere definition of a rogue act in cyberspace, using tools from the kinetic world. We discuss all that in this episode of Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Research Center’s podcast, with Yaël Ronen, Professor of International Law and a research associate at the Federmann Cyber Security Research Center; Isabella Brunner, researcher and lecturer in Public International Law at Bundeswehr University Munich; Rogier Bartels, an international criminal lawyer and a research fellow at Federmann Cyber Security Research Center ; and Lex Cybernetica’s host, Ido Kenan.

Can we trust decisions made by algorithms? Those are utilized by managers to choose employees, judges to give verdicts, and much more. While algorithms are often considered unbiased, or at least less biased than humans, they are in truth as biased as the data-sets that they were trained on, and as they were programmed to be - by oversight or design. The problems with AI decision making, and the right to have a human decision maker in the loop, are the subject of this episode of Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Center’s podcast, with Prof. Helmut Aust, Senior Fellow at the Freie Universität Berlin, Germany; Dafna Dror, legal counsel at the Office of the Deputy Attorney General, International Law Division, Human Rights Department And The Federmann Cyber Security Research Center Fellow; Prof. Alon Harel of the Hebrew University; and Lex Cybernetica’s host, Ido Kenan.

No description available

While cyber threats have been around for decades, cyber insurance is still a fledgling, mainly American, $4-6 bn industry, that's estimated to grow to $20 bn by 2025. In Israel, only 13% of local companies have cyber insurance, according to a June 2019 survey of executives, decision makers and insurance companies by the Israel National Cyber Directorate (Hebrew press release). The main reasons for not having such insurance are lack of awareness to cyber threats and a lack of financial viability. Many executives in the industry, agriculture, construction and retail said they didn’t know cyber insurance even existed. What exactly is cyber insurance, what cyber attacks does it cover, and how is it affecting global cyber security? In this episode of the Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Center’s podcast, we talk cyber insurance with Ariel Levite from the Cyber Policy Program at the Carnegie Endowment for Peace; Sharon Shaham, Betach Toren Insurance Agency CEO; and Asaf Lubin, an affiliate at the Berkman Klein Center for Internet and Society at Harvard University and a Visiting Scholar at the Federmann Center; and Lex Cybernetica’s host, Ido Kenan.

Who would you prefer tell you when your loved one is going to die? Annalisia Wilharm had a telerobodoctor on wheels deliver the sad news of her grandfather Ernest Quintana’s terminality. Two days later he died of lung failure, at 79. “This secure video technology is a live conversation with a physician using tele-video technology, and always with a nurse or other physician in the room to explain the purpose and function of the technology,” Michelle Gaskill-Hames, SVP and area manager for Kaiser Permanente Greater Southern Alameda County, told the Mercury News. “It does not, and did not, replace ongoing in-person evaluations and conversations with a patient and family members.” Technology is affecting not only our health, but our health services, the way we get diagnosed and treated, as well as how we preempt disease by changing our daily lives. And as with any new technology, things can, and will, go wrong. In this episode of the Lex Cybernetica, the Hebrew University of Jerusalem Cyber Security Research Center’s podcast, we will discuss this with Ron Shamir, a Federmann Cyber Security Center researcher and co-founder and CEO of the helath-tech startup Phonetica; Danit Leybovich-Shati, the leader of the Israeli National Cyber Directorate MediSec project; and Dr. Rachele Hendricks-Sturrup, Health Policy Fellow at FPF; and Lex Cybernetica’s host, Ido Kenan.

On average, 3,287 people are killed every day in car accidents, according to the World Health Organization (WHO). Elaine Herzberg was one of them, when, on the evening of March 18, 2018, as she was pushing her bicycle across the road outside the crosswalk in Tempe, Arizona, a car fatally hit her. Herzberg had the dubious honor of being the first pedestrian ever to be killed by an autonomous car. Autonomous cars are supposed to be safer than human drivers, but we still worry about them more. That’s not merely a tech or security issue, but a psychological one. We need to know someone is responsible; we need to understand how the autonomous-insurance works, we want to have clear and reasonable regulation. We have to feel safe. One of the promised advantages of autonomous cars is that they're better drivers than humans, but that's not enough. "We will be comfortable with machines making mistakes if the probability of mistakes is much, much smaller than the probability of mistakes of a human driver", says Shai Shalev Shwartz, a professor at the School of Computer Science and Engineering at the Hebrew University of Jerusalem and the CTO of Mobileye. "But if it will be just slightly better than a human driver, then we will have a problem. We are getting close to the statistics of a human driver, but we strive to be a thousand times better than a human driver". To regulating driverless cars, we first have to demystify them. "It's not regulating the end product, the car, this magic carpet. It's not magical at all. It's regulating technologies, and it's nothing new", explains Gadi Perl, research fellow at the Federmann Cyber Security Center. Autonomously driven cars which make less accidents mean a sea change for the car insurance companies. For example, truly autonomous cars make decisions in a black box environment, which could lead to a situation where there's a car accident but we can't determine whose fault it is. "I think that's the Armageddon scenario that everyone is scare of", says Anat Lior, who explores autonomous vehicles challenges facing the insurance industry. In this episode of the Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Center’s podcast, we will talk autonomous cars with Anat Lior, Gadi Perl and Shai Shalev Shwartz, with Lex Cybernetica’s host, Ido Kenan.

Hacker Kevin Mitnick’s infamous social engineering escapades, where he’d call up companies and convince employees to surrender information he would later use to hack their systems, took advantage of people’s, rather than computer systems’, weaknesses. Cybersecurity is not a purely technical issue, but also, and arguably, mostly, a social one. One of the missions cyber criminologists have is to understand why some people become hacking victims while others don’t, and why hackers hack. Take, for example, the rudimentary system of password protection. If a service provides an initial default password and doesn’t require changing it, many people will just settle for it, making it vulnerable to hackers who are aware of default passwords, which are easily searchable on the web. When required to choose a password, most people will resort to a common word or phrase, a phone number, or a birthdate, which are easy to remember but also easy to illegitimately obtain through dictionary attacks, if not mere guessing. People tend to stick to their beloved password, and re-use it for different services, meaning that if one service leaks the password, all that person’s services’ defenses topple down like dominoes. On the other hand, prompting frequent password changes causes people to worry they might forget the new password, so they write it down in a text document or email it to themselves, putting it at risk. Much like password protection, security systems need to be built with humans in mind. On the other side are the hackers – also humans. Situational crime prevention can be used to prevent them from committing cybercrimes, or, if unsuccessful, convincing them to discontinue their journey through your systems. In this episode of the Lex Cybernetica, the Hebrew University of Jerusalem Federmann Cyber Security Center’s podcast, we will talk about the human factor of hacking with our guests Prof. Benoît Dupont, Professor of Criminology at the Université de Montréal and the Scientific Director of SERENE-RISC; Dr. Rutger Leukfeldt, Senior Researcher Cybercrime at NSCR and Director Cybersecurity & SMEs at The Hague University of Applied Sciences; and Prof. David Maimon, Associate Professor in the department of Criminology and Criminal Justice at the Georgia State University and research associate at the Federmann Cyber Security Center; with Lex Cybernetica’s host, Ido Kenan.

A healthy innovation ecosystem is crucial for states to handle cybersecurity threats. Traditional methods and procedures simply will not do. “After a couple of years, if you're successful, you'll have a solution, for example the Iron Dome”, explains Dr. Amit Sheniak of the Federmann Cyber Security Center, the Truman Institute, and the Davis Institute. “Until you did that long process, went through all the bureaucracy – the change already evolved, moved on, inflicted harm, and you couldn't mitigate it. Hence, governments understand today that the way to tackle those threats in terms of research and development is to create some kind of outsourcing scheme”. What does it look like from the state’s point of view? “We have part of the resources, but know that we don't know anything - we know only part of the way to do something”, says Adv. Eynan Lichterman of the Israel National Cyber Directorate. “There's a lot of knowledge in the academia, there's a lot of knowledge in the industry, in the NGOs, and so on. We have to work together in order to make something bigger than any one of us”. An often unspoken yet crucial actor in the cybersecurity ecosystem is the law, says Adv. Deborah Housen-Couriel, a member of the advisory board of the Federmann Cyber Security Center, and an attorney with a practice in the Israeli and global commercial cyber sector. According to Housen-Couriel, “I would start out with looking at the basic underpinnings that a legal system gives to the incentives for setting up a cyber hub or other kinds of cyber ecosystems. Then there's a second piece, which is I think is often overlooked, but really key and also developing, and that's the issue of data protection”. Join us in this episode of Lex Cybernetica with our host Ido Kenan.