Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

10/31/2018
10:50 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

UC Berkeley Launches Cybersecurity "Citizen Clinic"

New program will train students to provide sustainable cybersecurity assistance to politically vulnerable organizations

BERKELEY, CALIFORNIA — The University of California, Berkeley's Center for Long-Term Cybersecurity (CLTC) has launched a new public interest cybersecurity clinic dedicated to providing services to politically vulnerable organizations—including media outlets, human rights groups, and non-government organizations—that are at risk of cyberattacks.

Similar to public-interest clinics in law and medicine, the "Citizen Clinic" will train teams of students to provide assistance to organizations that face online threats from governments, hate groups, and other politically motivated adversaries. Citizen Clinic's interdisciplinary teams will assess threats to targeted organizations, recommend risk-appropriate mitigations, and work collaboratively with clients to implement new policies and technical controls to enhance their long-term cybersecurity needs. The initiative builds off a recent report published by CLTC that exposed the lack of resources available to build capacity in civil society organizations, which often face significant cybersecurity threats but have limited resources to protect themselves.

"Citizen Clinic is helping address an urgent challenge, as many civil society organizations are highly vulnerable to spyware, surveillance, troll campaigns, censorship, and other online threats," said Steve Weber, Faculty Director of CLTC. "Many of the other resources available to civil society are focused on responding to cyber emergencies, as opposed to prevention and baseline security. Citizen Clinic represents an important new model for helping these organizations develop long-term resilience in the face of an evolving threat landscape."

In addition to supporting client organizations, Citizen Clinic provides UC Berkeley students with a unique experiential learning opportunity. By working with civil society organizations as clients, students are learning how to assess vulnerabilities, and how to develop, recommend, and perform mitigating controls for security risks in a manner tailored to the resource-constrained environments of clients. Following a successful pilot in spring 2018, Citizen Clinic is now offered as a course in the UC Berkeley School of Information; participating students currently come from the fields of law, computer science, public policy, information management, and others.

"Citizen Clinic is helping build a pipeline of public-interest technologists who know how to help under-resourced organizations operating in complex political, sociological, and legal contexts," said Sean Brooks, Director of Citizen Clinic. "We hope to expand our staff and capabilities in the coming months and years, and we are interested in meeting with potential partners and supporters, as well as with prospective client organizations."

Citizen Clinic is directed by a team that includes experienced cybersecurity experts—including Bill Marczak, who gained recognition for identifying spyware on the phones of journalists in Mexico and Bahrain. The program also has an advisory board that will provide support with development and outreach efforts. Advisory board members include:

  • Ron Deibert, Director, The Citizen Lab
  • Eva Galperin, Director of Cybersecurity, Electronic Frontier Foundation
  • Lobsang Gyatso Sither, Digital Security Program Director, Tibet Action Institute
  • Matt Mitchell, Director of Digital Safety & Privacy, Tactical Technology Collective
  • Eleni Gessiou, Security Engineering Manager, Facebook

"I am excited to see the launch of Citizen Clinic, and look forward to developing a strong collaborative engagement between our respective organizations," said Ron Deibert, professor of political science and director of Citizen Lab, Munk School of Global Affairs and Public Policy, University of Toronto. "For the past decade, we have documented a growing epidemic of targeted digital attacks against vulnerable populations online. We desperately need innovation around how to mitigate this emerging and very harmful problem. Citizen Clinic promises to be one such innovation."

Learn more at https://cltc.berkeley.edu.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3697
PUBLISHED: 2020-01-24
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.
CVE-2019-3694
PUBLISHED: 2020-01-24
A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin version 2.0.40-lp151.1.1 a...
CVE-2019-3693
PUBLISHED: 2020-01-24
A symlink following vulnerability in the packaging of mailman in SUSE SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. Th...
CVE-2019-3687
PUBLISHED: 2020-01-24
The permission package in SUSE SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 t...
CVE-2019-3692
PUBLISHED: 2020-01-24
The packaging of inn on SUSE SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn versi...