4. „Babylonian Confusion of Tongues“: Security between law and freedom – but without consensus

The surveyed opinion leaders have specific views of the Internet that are determined by their own goals, their potential for exerting influence and the current business climate, including the user requirements and concerns that go along with it. The sector-specific positioning depicted in the previous chapters revealed the broad range of ways in which the Internet has been integrated into techno- logical, economic, social and cultural contexts of interpretation and management processes.

These opinion leaders are clear that the Internet has come to represent an integral and indispensible component of private and public life. The magnitude of dependence on this infrastructure in their view raises not just opportunities, but also challenges as well. Regardless of whether the players here emphasized the potential or the risks of the Internet, the issue of security remains a central linch- pin in their consideration of the current situation, both in terms of its respective meaning as well as in terms of perceived conflicts of interest and solution approaches.

Almost all opinion leaders emphasize that security is an absolute precondition for all citizens (including the most undiscerning users!) to be able to place trust in the Internet as a medium and to use it safely and freely.

Security and trust are thus closely linked both from an associative and rhetorical standpoint. For many, security is a precondition for trust, although at the same time it is also possible to have trust without real security. To depict these interrelationships systematically, the focus will now turn initially to the grasp and the respective approaches towards security. The reference to the issue of trust will be established in the chapters that follow.

Comprehensive Internet security does not exist

In the view of the opinion leaders, there can be no 100 percent security on the Internet, no more than there can be in the real world. The goal is thus not to eliminate all dangers, but rather to achieve the best possible containment, estimation and calculation of an often diffuse spectrum of potential threats. The opinion leaders soberly acknowledge that most security holes only gain attention when somebody discovers them.

 „I’m of the firm opinion that there will never be 100 percent security. And naturally no 100 percent freedom for that matter. A total relinquishing of all freedoms won’t gain us more security either.“

„Everybody thinks that security involves adopting a Fort Knox strategy. They think that if they build a huge secure fortress it’ll be safe from attacks. The reality is that hackers get in everywhere and that entirely different strategies may be needed.“

„An admittedly somewhat dreadful example is the green traffic light that — quod erat demonstrandum — is anything but risk-free and which, tragically, teaches a few people the hard way each year that it is not risk-free. Nevertheless we all behave as if it were risk-free. It’s not. We establish conventions or define things and derive from the actuarial statistics that in a majority of cases it will be risk-free. Because we design it that way, knowing that there are absolutely no guarantees. I think that if you apply this perception to the digital world, then it shouldn’t mean that we can always expect security there — this isn’t a call for a nonchalant interaction with the risks, but rather a more realistic assessment of what can be achieved if you talk about freedom from risk.“

Security is thus defined as a generally accepted risk of danger — frequently described as the „limiting risk.“ From the perspective of the opinion leaders, in a best-case scenario security is established where systems are not being damaged by already known threats. Fulfillment of this condition can be referred to as „sufficient security.“

Security on the Internet as a challenge for business and politics

As shown in the first chapter, the opinion leaders see a large spectrum of risk on the Internet, and yet at the same time also presume that users are hardly aware of most security concerns. This is a dilemma insofar as they — particularly politicians and businesses — expect and even require security.

The real risks are thus, in the view of the opinion leaders, larger than people believe and are less effectively manageable than people seem to think. The problem is: this is difficult to convey without potentially disrupting the audience’s trust in one’s own offered services.

Communication about security must therefore put it into perspective to ensure that it is not misunderstood by the user as freedom from risks or damages.

 „But you have to choose the word security carefully and be very meticulous in not offering any room for subsequent attacks that claim you lied or that it’s not all true or blah blah blah. […] And you have to be very careful when using superlatives and that kind of thing. I think that a careful selection of words is crucially important especially in the area of trust and security, so that one doesn’t just simply call out your opponent […] or let’s say the guardians of the real term security and antagonize them.“

„The difficult thing is that the effort to communicate security measures in a purely positive manner based on best cases has never yet worked. That’s been our experience as well. Nor can we advocate, let’s say, simply washing and disinfecting your hands to prevent the spread of illnesses in some way without also pointing out that we’ve just suffered cases of it and just had EHEC and so on. And unfortunately security on the Internet is much the same way.“

The public discussion about security and trust — in relation to their own possibilities and expectations of the users — is decidedly rejected (particularly by various players, especially those in business) and for ideological reasons viewed as exaggerated.

 „I think that the topic of trust and security on the Internet is terribly overdone. And in particular through a tandem of media and politics, with a dash of that culturally ingrained German need for security. So, the topic of security and trust and threats and risks is part of our cultural identity. […] I believe that it’s a topic that is at least very strongly construed by the aforementioned tandem.“

Little common sense in the discourse about security on the Internet?

The underlying attitudes and approaches to the topic of security among the players can be differentiated based on their self-image and sphere of activity. As already sketched out in Chapter 3

  • the opinion makers in government are primarily interested in Internet safety as a part of the critical infrastructure. They link the security question closely to the question of a (fundamental) regulation of the Net, but warn against a limited ability of business to compete due to overly strong regulation.
  • the opinion leaders in business thematize security in equal measure as a business model and as a deterrent to innovation and cost factor. The opinion leaders from business want to handle security issues through voluntary commitments rather than through regulation.
  • the opinion leaders in civil society warn most clearly that security on the Internet comes at the price of liberty.
  • the opinion leaders in the area of media and academics are acting as a flanking pair of impulse generators whose observations on this issue are given little heed.

This means that the term is being laden with various associations and corresponding valuations, which in turn produces various formulations of intended behavior.

In politics, Internet security is a topic that demands action, yet one whose pace is not set by the politicians themselves and where they know that whatever demarcation they make of the scope of security requirements, those thresholds will inherently face opposition from business and digital natives. The security question is a delicate one for politicians, since it frequently must be defined as defensive („as something forced“) and where contrary security needs must be balanced out. Security inherently involves dilemmas, since security can have a price in freedom and purportedly can slow down economic development. The players in this sector are — depending on their nature of their protective duties — „risk-avoiders“, with skepticism about the ability to cope being characteristic of the security discourse in the public sector, not least because they admit to being dependent on external experts.

Discourse on security among opinion leaders in politics and the public sector

Discourse on security among opinion leaders in politics and the public sector

The business side sees itself more as „risk-takers“, drivers and impulse generators for innovations. Despite the perception that 100 percent security is an illusion, the security discourse among decision makers on the industry side tends to feature a greater optimism/realism about the ability to manage the issue. There is a stronger focus on the opportunities brought by a desire for security than is observed among politicians and administrators. There is a feeling that regulation limited to the national level is pointless and that any efforts in this direction deserve sharp criticism.

Discourse on security among opinion leaders in business

Discourse on security among opinion leaders in business

Representatives of civil society primarily get involved in the debate on Internet security when it affects aspects such as education, equal participation and democratic structures. They view security both as a threat and as a precondition for the freedom of the user, and thus desire balance, not ill-considered procedures in areas like regulatory questions — and above all else, an initial discourse between all players on equal footing.

Discourse on security among opinion leaders in civil society

Discourse on security among opinion leaders in civil society

As such it is difficult to talk about Internet security and make decisions on the basis of a shared basic understanding.

Representatives of civil society and academia in particular have committed to examining the complexity of the term in more details. They are most likely to think in terms of a security architecture in which various levels are kept separate and attempt to understand their respective relationships.

„It’s really a quite difficult field and for that reason I also say at the start I don’t hold much of talking about the security of the Internet, but rather you really need to break it down into the individual services. E-mail is really different from this kind of online shopping — and even there you have to differentiate once again between the purchase of larger goods, as they have other security concerns.“

„Security is generally speaking a gradual process. All security experts know, I’ll start just as an example with the physical aspects, so, how can I enter into a building at all, what is the potential for accessing IT systems, how are these correspondingly protected, how is the network then protected, which operating system is being used, meaning the host itself, how are the applications protected and how is the data in and of itself protected. We’ve established corresponding protective measures on each of these levels.“

Security as a „hot potato“

That security is understood in different ways and to some extent has highly fluid boundaries isn’t just a factor of sector-specific fields of responsibility and personal competencies, but also with intentional caution. Why is this the case?

The conversations showed that security is a sensitive topic. How someone understands security and the concepts and solution approaches that are adopted based on that understanding are clearly taken by other opinion leaders — at least in terms of Internet politics — as indicators of an underlying attitude toward the Internet and society.

Those who accord the topic of security less importance are seen as negligent, irresponsible and self-centered by others. Those who strive for „a lot of security“ are accused by others of being controlling, domineering and regulation-obsessed.

In many cases fundamental ideological discourses are being broached.

 „I’m no communist, but I do think it’s a problem that everything always has to be dedicated to making money.“

„We live in an anti-business climate where one has to justify earning money.“

It only takes one more logical step to come to the associated question of who then can and should assume responsibility for the presumed challenges on the Internet.

Passing the buck on responsibility

Responsibility isn’t a term used actively by the opinion leaders. There is notably a problem-oriented treatment being promoted here, i.e. hardly any positive vision of responsibility for Internet security can be observed, and responsibility for security on the Net isn’t a virtue to be publicly touted. Responsibility instead seems to be more a matter of passing the buck, because it’s clearly primarily linked with dealing with problems, and in particularly with the elimination of damages and bearing of costs.

Each party’s own areas of responsibility are thus sketched as narrowly as possible and concentrated on fields that promise a burnishing of reputation (be it in relationship to voter opinions or business success). That said, there are also some first players (primarily in industry) who are starting to integrate the topic of responsibility into their business strategy.

„Media literacy is really the job of the state, but if they’re not doing it, then we’ll develop materials and distribute them in schools.“

How responsibility is really being distributed and the solutions proposed by decision makers are shown in the following chapters.