Ethics Notes
Ethics Notes
.
Chapter 1
Morality, Ethics, Justice, Rights:
Morality: “the standards that an individual or a group has about what is right and wrong”
Ethics: examining moral standards and asking how these standards apply and whether these
standards are reasonable or unreasonable”
Ideally, justice is ethical, and one assumes that doing what is ethical is legal.
Justice cares about people’s rights, and righting wrongs when those rights are violated.
What are the differences between values, morals and ethics? They all provide behavioral rules,
after all. It may seem like splitting hairs, but the differences can be important when persuading
others.
Values
Values are the rules by which we make decisions about right and wrong, should and shouldn't,
good and bad. They also tell us which are more or less important, which is useful when we have
to trade off meeting one value over another.
[Link] defines values as: beliefs of a person or social group in which they have an
emotional investment (either for or against something); "he has very conservatives values"
Morals
Morals have a greater social element to values and tend to have a very broad acceptance. Morals
are far more about good and bad than other values. We thus judge others more strongly on
morals than values. A person can be described as immoral, yet there is no word for them not
following values.
[Link] defines morals as: motivation based on ideas of right and wrong
Ethics
You can have professional ethics, but you seldom hear about professional morals. Ethics tend to
be codified into a formal system or set of rules which are explicitly adopted by a group of
people. Ethics are thus internally defined and adopted, whilst morals tend to be externally
imposed on other people.
If you accuse someone of being unethical, it is equivalent of calling them unprofessional and
may well be taken as a significant insult and perceived more personally than if you called them
immoral (which of course they may also not like).
A theory or a system of moral values: The rules or standards governing the conduct of a person
or the members of a profession.
Ethics of principled conviction asserts that intent is the most important factor. If you have good
principles, then you will act ethically.
Ethics of responsibility challenges this, saying that you must understand the consequences of
your decisions and actions and answer to these, not just your high-minded principles.
The medical maxim 'do no harm', for example, is based in the outcome-oriented ethics of
responsibility.
There are four types of justice that people can seek when they have been wronged.
Distributive justice
Distributive justice, also known as economic justice, is about fairness in what people receive,
from goods to attention. Its roots are in social order and it is at the roots of socialism, where
equality is a fundamental principle.
If people do not think that they are getting their fair share of something, they will seek first to
gain what they believe they deserve. They may well also seek other forms of justice.
Procedural justice
The principle of fairness is also found in the idea of fair play (as opposed to the fair share of
distributive justice).
If people believe that a fair process was used in deciding what it to be distributed, then they may
well accept an imbalance in what they receive in comparison to others. If they see both
procedural and distributive injustice, they will likely seek restorative and/or retributive justice.
Restorative justice
Social And Professional Ethics in IT G4 IT(A&B)
The first thing that the betrayed person may seek from the betrayer is some form of restitution,
putting things back as they should be.
The simplest form of restitution is a straightforward apology. Restoration means putting things
back as they were, so it may include some act of contrition to demonstrate one is truly sorry. This
may include action and even extra payment to the offended party.
Retributive justice
Retributive justice works on the principle of punishment, although what constitutes fair and
proportional punishment is widely debated. While the intent may be to dissuade the perpetrator
or others from future wrong-doing, the re-offending rate of many criminals indicates the limited
success of this approach.
Punishment in practice is more about the satisfaction of victims and those who care about them.
This strays into the realm of revenge, which can be many times more severe than reparation as
the hurt party seeks to make the other person suffer in return. In such cases 'justice' is typically
defined emotionally rather that with intent for fairness or prevention.
So what?
If you have been wronged, consider carefully what kind of justice you are really seeking.
If you are the wrong-doer and others are seeking justice against you, seek first to ensure
distributive justice.
A question may be asked why people are put in prison. If it is to prevent them re-offending, then
it is restorative justice. If it is to punish them, then it is retributive justice. Sadly, this have proven
a poor method of prevention.
Definitions of Rights:
Rights are legal or moral recognition of choices or interests to which particular weight is
attached.
A person is faced with a number of alternatives or choices and he is to select one or two of them.
This freedom is the central idea of rights. The individual shall have the full freedom to select the
required number of alternatives. The system of rights therefore denotes “some sort of
distribution of freedom” (Oxford Concise Dictionary of Politics).
It is justified in the sense that when one claims rights there shall be sufficient justification behind
the claims and, at the same time, the claims should be recognised.
Thirdly, T. H. Green defines rights in the light of idealism since he was the doyen of English
idealist philosophy. He defines the concept of rights:
“The capacity on the part of the individual of conceiving a good as the same for himself and
others and of being determined to action by that conception is foundation of rights, and rights are
the condition of that capacity being realised. No right is justifiable or should be a right except on
the ground that directly or indirectly it serves this purpose”.
Andrew Heywood (Political Theory) calls rights as entitlements (emphasis added). Rights are
entitlements to act or be treated in a particular way. Modern political thinkers are accustomed to
treat rights mainly as entitlements. It is a type of entitlement in the sense that an individual has
rights means that he is entitled to have something.
In the present day situation rights have been regarded as rational claims. The environmentalists
have challenged the traditional concept of rights. They forcefully argue that every claim made by
Social And Professional Ethics in IT G4 IT(A&B)
the individuals must be based on rationality. Human beings cannot kill animals indiscriminately
or destroy forest for their own benefit.
These two acts may satisfy their needs but at the same time the killing of animals or destroying
forest shall cause an imbalance in nature and ultimately society and succeeding generations will
suffer. So the idea of entitlement shall be viewed from modern and wider perspective.
Nature of Rights:
(1) Norman Barry uses a new term which he calls claim-rights. Let us quote him: “In the more
usual sense of the word right it is understood as a type of claim. Claim-rights entitle their holder
to limit the liberty of another person.
A has a right against B, deriving either from moral or legal rule, which puts B under a duty. It is
not the moral quality of act that entitles A to limit B’s liberty but simply the fact that he
possesses the rights……… Claim-rights possessed by persons are quite different from favours or
concessions granted to individuals by authorities”.
The claim-rights do not depend upon the mercy of another person. For one reason or other
individuals claim rights which means that others will not create any obstructions on the way of
enjoying the claim-rights. The implication of this right is individuals claim-right on the ground
that the rights are indispensable for the development of personality and the authority is bound to
provide such right.
(2) Right is viewed in the sense of liberty, right is liberty. There is a general and popular view
that rights imply duties. A man cannot claim/demand rights if he does not perform duties. Rights,
in this sense, are correlative to duties or functions. But when rights are interpreted in the
background of liberty the doing of duty does not arise at all.
For example, an individual has right of the freedom of speech means that the individual has
liberty to open his mouth and mind and if he does so he will face no problem. When rights are
understood as liberties, the possession of rights by one person does not entail the restrictions on
Social And Professional Ethics in IT G4 IT(A&B)
liberty of another or in the sense of being under a correlative duty. This concept of right denies
the traditional relation between right and duty.
(3) Identification of rights as special claims is another characteristic feature of rights. In the
period of monarchical absolutism people claimed the right to freedom of speech because it was
drastically curtailed by the absolute kings. Not only freedom of speech, but also freedom of
thought and action were demanded by people.
In the middle Ages there were conflicts among the various religious groups and in that period
many people claimed the right to practise any religious belief and faith. In the nineteenth
century, individualism dominated the political scene and rights were viewed negatively. The
state interference with the individual’s affairs shall be minimum.
It was the negative approach to rights. In the modern age positive ideas cloaked the idea of
rights. It means that Individuals will enjoy rights but at the same time the state should do for
the realisation of welfare objectives. It was also felt that this could be done by both the state
and the general public. Both should act in tandem.
(4) Sometimes it has been found that there are rights for few and rights for many. For
example, the revolutionaries of American Revolution and French Revolution demanded that they
were fighting for the general rights of general public.
But after the revolutions it was found that only limited people were able to enjoy the rights. In all
class societies only handful of persons enjoys all sorts of rights and majority is deprived of basic
rights. In many states special rights are recognised for particular sections of people.
For example, in India the scheduled caste, scheduled tribes and other backward classes enjoy
special rights and Constitution recognises these special provisions. We may call this system as
special rights for special classes. Side by side there are general rights for general classes or all
persons of the state.
(5) Rights are very important no doubt, but individuals alone and without any help from the state
cannot enjoy rights. The state must create an atmosphere in which all the individuals will have
Social And Professional Ethics in IT G4 IT(A&B)
opportunities to enjoy rights. But the state can do this only on condition that the rights are
recognised by the state. Whether the state recognises or not rights are always rights. But this is
the conceptual sense of rights.
In reality, people will be in a position to enjoy rights if the state comes forward for their
realisation. No rights can exist beyond the jurisdiction of state. People of the state of nature had
natural rights, but all of them had not the opportunities to enjoy rights because the state of nature
had no enforcing organ.
(6) For the enforcement of rights law is essential. The state is the enforcing authority and law is
the mechanism or instrument. State takes precautionary measures with the help of law. This
rights, law and state are all interlinked. In respect of law and right-law performs a double
function. It protects the right of some and prevents others from interfering with the rights
enjoyed, by others.
Natural Rights:
“Rights which persons possess by nature that is without the intervention of the agreement, or in
the absence of political and legal institution” (Oxford Concise Dictionary of Politics).
Some thinkers believe that natural rights are some sort of moral rights in the sense that they
do not depend for their validity on the enforcement of a legal system. They are a special type of
moral rights. Any agreement or authority is not the source of natural rights. Again, such rights
need not be recognised by the state because they existed before the origin of state.
Bill of Rights:
It states: “No free man shall be taken or imprisoned or dispossessed or outlawed or banished or
in any way destroyed, nor will we go upon him, nor send upon him except by the legal judgment
of his peers or by the law of the land”.
Social And Professional Ethics in IT G4 IT(A&B)
Fundamental Rights:
Almost all the constitutions (which have adopted rights as part of the constitution) call
fundamental rights. The same rights are called fundamental in the sense that these rights are
inviolable or cannot be violated simply to satisfy the needs or whims of a section of government
or population.
The idea of fundamental, inviolable rights is rooted in the Magna Carta. Bill of Rights passed by
the British Parliament and the declaration of Rights of Man. From the progress of society and
course of history it became crystal clear that certain rights are indeed fundamental or
indispensable for the development of personality and inherent qualities of man.
The purpose of incorporating these rights into the constitution is that rights need to be protected
by the state and if these rights are not made parts of the constitution their proper protection will
not be ensured. There is a subtle difference between rights in general sense and the fundamental
rights.
All sorts of rights are not included into the fundamental rights. Fundamental rights are also called
basic rights. Citizens also came to know what are their rights. The term fundamental is not rigid
at all. A right is fundamental in one state and the same right is not fundamental in another state.
For example, right to work is a fundamental right in a socialist state but not in a capitalist state.
Human Rights:
Besides fundamental rights, natural rights and bill of rights there is another right which is called
human rights. Human rights are not, so to speak, basically different from general category of
rights. While analysing the nature of rights we had the opportunity to throw light on the idea that
rights can practically come to be meaningless if they are not recognised and state authority does
not take any step for their protection.
Social And Professional Ethics in IT G4 IT(A&B)
Naturally the intervention of state appears to be inevitable for the realisation of rights, but this
need not be the case. Any human being as a part of humanity is entitled to have certain rights and
the state must take necessary steps for their protection. From this idea emanates the concept of
human rights.
We here quote Heywood’s definition of human rights: “Human rights are rights to which
people are entitled by virtue of being human. They are, therefore, universal rights in the sense
that they belong to all human beings rather than to members of any particular nation, race,
religion, gender, social class or whatever”.
In a slightly different way Oxford Concise Dictionary of Politics has defined it:
Human rights are a special sort of moral entitlement. They attach to all men equally simply by
virtue of their humanity irrespective of race, nationality or membership of particular social
group. They specify the minimum conditions for human dignity and a tolerable life.
1. Human rights are called moral entitlements. As a part of the whole humanity every human
being is entitled to certain rights and no authority under the sun can deprive him of these basic
rights. Naturally, any attempt to deprive man of his share to rights is immoral.
Though the two words human rights are comparatively of recent origin the rights included under
this head are not of recent origin. Even the rights contemplated by Locke or Jefferson have found
place in human rights.
For example, Locke’s right to life, liberty and property or Jefferson’s life, liberty and pursuit of
happiness are treated as parts of human rights. So originally civil rights such as life, liberty and
freedom from torture were human rights.
Social And Professional Ethics in IT G4 IT(A&B)
Derivative Rights
Derivative rights are rights which are designed to further the interests of persons other than
those to whom the rights are granted. Thus, utility rights are at least partly derivative, because
they are designed to increase social utility, rather than the utility of the bearers of those rights.
In a free society, the "rights" of any group are derived from the rights of its members through
their voluntary, individual choice and contractual agreement, and are merely the application of
these individual rights to a specific undertaking.26
"that these rights are not suddenly forfeited when a business grows beyond some arbitrarily
defined size ...". if a corporation's "right to exist were limited, then to that extent the rights of
individuals to property, association and contract would also be limited."
A critical analysis is different from a summary. It may include a summary, but should go beyond
this. You are providing an informed critique of the material. Remember that the purpose of a
critical analysis is to evaluate.
Articulate connections.
3. What exactly is meant by . . .?
Define terms.
Social And Professional Ethics in IT G4 IT(A&B)
Theory of Justice is a work of political philosophy and ethics by John Rawls, in which Rawls
attempts to solve the problem of distributive justice (the socially just distribution of goods in a
society) by utilising a variant of the familiar device of the social contract. The resultant theory is
known as "Justice as Fairness", from which Rawls derives his two principles of justice: the
liberty principle and the difference principle.
Rawls belongs to the social contract tradition, although he takes a different view from that of
previous thinkers. Specifically, Rawls develops what he claims are principles of justice through
the use of an artificial device he calls the Original position in which everyone decides
principles of justice from behind a veil of ignorance. This "veil" is one that essentially blinds
people to all facts about themselves so they cannot tailor principles to their own advantage:
"...no one knows his place in society, his class position or social status, nor does anyone
know his fortune in the distribution of natural assets and abilities, his intelligence,
strength, and the like. I shall even assume that the parties do not know their conceptions
of the good or their special psychological propensities. The principles of justice are
chosen behind a veil of ignorance."
According to Rawls, ignorance of these details about oneself will lead to principles that are fair
to all. If an individual does not know how he will end up in his own conceived society, he is
likely not going to privilege any one class of people, but rather develop a scheme of justice that
treats all fairly. In particular, Rawls claims that those in the Original Position would all adopt a
maximin strategy which would maximise the prospects of the least well-off.
These principles are lexically ordered, and Rawls emphasizes the priority of liberty.
The basic liberties of citizens are the political liberty to vote and run for office, freedom of
speech and assembly, liberty of conscience, freedom of personal property and freedom from
arbitrary arrest.
(a) they are to be of the greatest benefit to the least-advantaged members of society,
consistent with the just savings principle. (the difference principle)
(b) offices and positions must be open to everyone under conditions of fair equality of
opportunity
Rawls' claim in (a) is that departures from equality of a list of what he calls primary goods
—"things which a rational man wants whatever else he wants" [Rawls, 1971, pg. 92]—are
justified only to the extent that they improve the lot of those who are worst-off under that
distribution in comparison with the previous, equal, distribution. His position is at least in some
sense egalitarian, with a provision that inequalities are allowed when they benefit the least
advantaged. An important consequence of Rawls' view is that inequalities can actually be
just, as long as they are to the benefit of the least well off. His argument for this position rests
heavily on the claim that morally arbitrary factors (for example, the family one is born into)
shouldn't determine one's life chances or opportunities. Rawls is also keying on an intuition that
a person does not morally deserve their inborn talents; thus that one is not entitled to all the
benefits they could possibly receive from them; hence, at least one of the criteria which could
provide an alternative to equality in assessing the justice of distributions is eliminated.
The stipulation in (b) is lexically prior to that in (a). Fair equality of opportunity requires not
merely that offices and positions are distributed on the basis of merit, but that all have reasonable
opportunity to acquire the skills on the basis of which merit is assessed. It may be thought that
this stipulation, and even the first principle of justice, may require greater equality than the
difference principle, because large social and economic inequalities, even when they are to the
advantage of the worst-off, will tend to seriously undermine the value of the political liberties
and any measures towards fair equality of opportunity.
Ethical formalism is a type of ethical theory which defines moral judgments in terms of their
logical form (e.g., as "laws" or "universal prescriptions") rather than their content (e.g., as
judgments about what actions will best promote human well-being). The term also often carries
critical connotations. Kant, for example, has been criticized for defining morality in terms of the
Social And Professional Ethics in IT G4 IT(A&B)
formal feature of being a "universal law", and then attempting to derive from this formal feature
various concrete moral duties.
Kantian Ethics
Deontological (or duty-oriented) theories of ethics (e.g., divine- command theory, Kantian
formalism) assume that the first task of ethics is to determine what we are obligated to do. By
doing our duty, we do what is valuable (not the other way around).
Divine-command theory says that something is good for no other reason than that God
commands it.
Kant's ethics is called formalism because it focuses on the form or structure of a moral judgment
(the fact that all moral directives have the form "you ought to do X").
The fundamental aim of Kant's ethical theory is to determine how a command can be a moral
command with a particularly obligating character.
Kant's Ethics
o According to the consequentialist, no act (no matter how evil or cruel) is right or
wrong in itself
o If we are already inclined to do an act because we naturally seek to produce good
consequences (e.g., pleasure, happiness), then we are not acting freely and
therefore not morally responsibly
o Because of differences in their experiences and backgrounds, people differ as to
what are good consequences; therefore, we can never achieve agreement on the
end of moral behavior or on an ulitmate criterion for making such decisions
o The consequences of our actions are often out of our control, so we cannot be held
responsible for those consequences or have our actions judged based on them
Social And Professional Ethics in IT G4 IT(A&B)
Morality is not based on hypothetical imperatives (if you want X--where X is, for
example, happiness--then do Y) but rather on a categorical imperative (you must do X,
regardless). If morality were hypothetical and people differed in their social and personal
goals (as they do), then their means for attaining those goals (e.g., morality) would differ
as well. But morality should be the kind of thing which does not vary from individual to
individual, because otherwise there would be no point in providing a reason for behavior
other than that it is simply what one wants to do. In other words, it would be to
acknowledge that there is no reason for acting one way rather than another. But because
we are rational beings, we can give reasons for what we do, and we can act based on
those reasons rather than acting simply because we want to.
A maxim such as "lie when you can get away with it" cannot be universalized
consistently (i.e., without contradiction) because, if people lied when they thought they
could get away with it, you would never know when anyone was telling you the truth; in
such a world, there would be no way to tell the truth from a lie, so its universalization
would generate a contradiction. Another example of this same point: the universalization
of "steal when you can" would create a world in which no one's property would any
longer truly be rightfully his or hers; but if there is no private property any more, there
can be no stealing either, since stealing means taking someone's private property.
everyone, and the fact that it does not have universal acceptability makes it a maxim on
which no moral action can be based.
Being rational means being able to act based on motives that are universally defensible.
Thus to act as a human being is not to act as a slave to one's instincts or passions or as a
result of social causes but as ends-in- themselves. Human beings can act out of respect
for doing something because it is the rational thing to do, and when they do this they are
acting for the sake of doing their duty; and this is what being moral means, acting on the
basis of a "good will." In this way, they are authors of their actions (autonomous) and are
morally responsible for their intentions, not the consequences of actions.
A. Free Speech
Suppressed opinions are always suppressed on the grounds that they are false
But to suppress (censor) an opinion is more than to believe that we are right – it implies
that we could not be wrong
Suppression presumes certainty to be equivalent to absolute certainty
But everyone knows that we can be mistaken
o People have been mistaken
o Ages have been mistaken
o Great thinkers have been mistaken
Socrates & Athens, Christianity & Marcus Aurelius
The most open-minded and educated people can be wrong!
We have no reason to believe that today’s certainties will not be found false tomorrow
o We used to be “certain” that the earth was flat
C. It Could Be True
The opinion that is suppressed could very well be true, and if we squash it, we’ve missed
out on the truth
And if you believe that the truth always shines, you’re mistaken
o If not entirely lost it can be lost for centuries, e.g. Aristarchus and the solar system
The only way to insure that we are as close to truth as possible is to allow for divergent
opinions
Experience is not enough, we need discussion – the free exchange of ideas
This is evidenced by the fact that the greatest advances in knowledge have always taken
place in ages of extreme toleration, e.g. German Enlightenment
D. The Balance Theory of Truth
In dealing with questions concerning matters of fact, the only way we can come close to
truth is by subjecting our belief to the rigors of debate
o Recall that reason alone won’t do it
All ideas must be tested through discussion:
Social And Professional Ethics in IT G4 IT(A&B)
both sides
Reply Objection 2
Reply
Truth
We need completely free discussion because that’s the only way we can compensate for
our fallibility
It’s the only way to be assured that our mistakes can be rectified
It’s the only way to avoid stagnation and decadence of thought
Just as no one thinks they are mistaken about any of their beliefs, no one takes
themselves to be intolerant
The tendency is to limit the class of things we could be mistaken about or intolerant of
o I know I’m not right about everything, but I am right about this!
o It’s good to be tolerant – of all good people, e.g. all Christians, all theists, all non-
communists
Such an attitude, says Mill, is self-deception at best
There is no such thing as limited toleration, or limited fallibilism
Social And Professional Ethics in IT G4 IT(A&B)
It is often claimed that the only people who defend deviant beliefs & practices are
deviants.
o Only atheists defend the right to express atheistic practices?
o Only Nazi’s defend the right to publish Nazi literature?
o Only perverts defend the right to publish pornography?
This attitude is mistaken, says Mill
The people we protect in defending these rights are not the perverts, Nazi’s and heretics,
but all of society
o Unless we defend everyone’s rights, there’ll be no guarantee that ours will not be
the next one to be infringed upon
G. What If It Is False?
Of course it is sometimes the case that the received view is the best and the deviant view
is false
o Why not suppress deviance in this circumstance?
First of all, we really can’t be certain that our view is true or will continue to be true
Secondly, even if we know for sure that the deviant view is mistaken, we should still
allow its expression
o There are two main reasons for this:
1. Without opposition, a true belief will be nothing more than a prejudice
(preference) (Irrational Belief)
2. Without opposition, true belief will lose its meaning (Unfelt belief)
H. Prejudicial Beliefs
Social And Professional Ethics in IT G4 IT(A&B)
I. Meaningless Beliefs
A belief that is nothing more than a prejudice one that does not come from rational
reflection – is a dead belief
The truth of it is not something you feel, but something you repeat like a parrot
o cf Aristotle on akrasia (Nicomachean Ethics, Bk VII)
If the belief is to be meaningful, you must understand why it is true
o Why is stealing wrong?
o Why is infidelity a bad idea?
o Why should we be polite to our neighbors?
To fully understand why it’s true, we must have arguments for our views
To prevent these arguments from being more than associated words, we must test them
by debate
Just as finding the truth in all questions concerning matters of fact requires a dialectical
exchange, true beliefs must be subjected to the same dialogue to retain their meaning
A free discussion of the pro’s & con’s of any idea both verifies (or falsifies) it, and it
keeps the idea lively and forceful:
Social And Professional Ethics in IT G4 IT(A&B)
Pro Con
Pro Con
Justified Truth
And so, even if the deviant opinion is false, we must allow its expression that our view
will not be reduced to empty words
o Comment on Christianity of his day (p. 39, Hackett ed.)
K. Partial Truths
The last possibility concerning the truth of a deviant opinion is the most common one
Most doctrines are neither absolutely true, nor absolutely false; they are partly true &
partly false
In these cases, suppressing the opinion – squashing discussion – makes us incapable of
finding the whole truth
It is through dialogue that we can amend and revise our views to conform to the truth;
hence the need for free discussion
The Balance Theory of Inquiry
told Mom
L. Recapitulation
Liberty-Limiting Principles
This principle is most widely accepted. John Stuart Mill holds that only the harm principle
can justify the limitation of liberty.
The principle of legal paternalism--Individual liberty is justifiably limited to prevent harm
to self.
J. S. Mill clearly rejects this principle as a basis for limiting liberty.
The principle of legal moralism--Individual liberty is justifiably limited to prevent immoral
behavior.
Legal moralism is usually invoked only what would be prohibited is so-called victimless
crimes. (If there were victims, the harm or legal paternalist principles might apply.)
The older arguments for censorship of pornography on the basis of "obscenity" seem to rest
upon the legal moralism and offense principles.
Social And Professional Ethics in IT G4 IT(A&B)
Chapter 2:
2.7. "Goofing off": who owns the "Easter eggs"? Why are they tolerated?
Intellectual Property Rights in Software: What They Are and How the Law Protects Them
Social And Professional Ethics in IT G4 IT(A&B)
People talk a lot in the information technology business about "intellectual property rights." But
what are they? How do they apply to software technology? Why should you protect them? How
do you protect them?
Intellectual property rights are at the foundation of the software industry. The term refers to a
range of intangible rights of ownership in an asset such as a software program. Each intellectual
property "right" is itself an asset, a slice of the overall ownership pie. The law provides different
methods for protecting these rights of ownership based on their type.
There are essentially four types of intellectual property rights relevant to software: patents,
copyrights, trade secrets and trademarks. Each affords a different type of legal protection.
Patents, copyrights and trade secrets can be used to protect the technology itself. Trademarks do
not protect technology, but the names or symbols used to distinguish a product in the
marketplace.
Patents
A patent is a twenty year exclusive monopoly on the right to make, use and sell a qualifying
invention. This legal monopoly is considered a reward for the time and effort expended in
creating the invention. In return, the invention must be described in detail to the Patent Office,
which publishes the information, thus increasing the amount of technological knowledge
available to the public.
To obtain a U.S. patent, an inventor must apply to the Patent Office and demonstrate that the
invention is new (as compared to prior technology), useful, and "nonobvious." An invention is
nonobvious if it is more than a trivial, obvious next step in the advance of the technology.
Software patents can be extremely powerful economic tools. They can protect features of a
program that cannot be protected under copyright or trade secret law. For example, patents can
be obtained for ideas, systems, methods, algorithms, and functions embodied in a software
product: editing functions, user-interface features, compiling techniques, operating system
techniques, program algorithms, menu arrangements, display presentations or arrangements, and
program language translation methods.
Social And Professional Ethics in IT G4 IT(A&B)
Since patent rights are exclusive, anyone making, using or selling the patented invention without
the patent owner's authorization is guilty of infringement. Penalties are stiff and include triple
damages. Once a patent for an invention is granted, subsequent "independent" (i.e., without
access to the patented technology) development of the invention by another inventor is still
considered infringement.
Copyrights
While a patent can protect the novel ideas embodied in a software program, a copyright cannot.
Copyright protection extends to the particular form in which an idea is expressed. In the case of
software, copyright law would protect the source and object code, as well as certain unique
original elements of the user interface.
The owner of a copyrighted software program has certain exclusive rights (with some
exceptions): the right to copy the software, create derivative or modified versions of it, and
distribute copies to the public by license, sale or otherwise. Anyone exercising any of these
exclusive rights without permission of the copyright owner is an infringer and subject to liability
for damages or statutory fines.
As with patents, the exclusive rights afforded under copyright law are intended to reward the
creative and inventive efforts of the "author" of the copyrighted work. The exclusive right to
control duplication protects the owner of copyrighted software against the competition that
would result from verbatim copying of the program's code. Copyright law also protects against
indirect copying, such as unauthorized translation of the code into a different programming
language.
Copyright protection arises automatically upon the creation of an original work of authorship.
There is no need to "apply" for a copyright or register the copyrighted work in order for
protection to exist. Generally, the duration of a copyright is the author's life plus fifty years. In
the case of software created by an employee in the course of his or her employment, the resulting
"work made for hire" would be protected by copyright law for seventy-five years from
publication.
Social And Professional Ethics in IT G4 IT(A&B)
Trade Secrets
A trade secret is any formula, pattern, compound, device, process, tool, or mechanism that is not
generally known or discoverable by others, is maintained in secrecy by its owner, and gives its
owner a competitive advantage because it is kept secret. The classic example of a trade secret is
the formula to Coca-Cola.
A trade secret can theoretically last forever -- for as long as its owner uses reasonable efforts to
keep it secret and someone else doesn't independently create or "discover" it.
Many features of software, such as code and the ideas and concepts reflected in it, can be
protected as trade secrets. This protection lasts as long as the protected element retains its trade
secret status. Unlike patents, trade secret protection will not extend to elements of software that
are readily ascertainable by lawful means, such as reverse engineering or independent
development.
Trade secrets are not subject to being "infringed," as with patents and copyrights, but are subject
to theft. Their legal status as a protectable intellectual property right will be upheld if the owner
can prove the trade secret was not generally known and reasonable steps were taken to preserve
its secrecy.
Maximizing the economic value of a software asset critically depends on understanding the
nature of the intellectual property rights involved and how best to use the available forms of legal
protection to protect those rights.
Five Things Every Software Developer Should Know About Intellectual Property
Social And Professional Ethics in IT G4 IT(A&B)
It is essential for every Software Developer to have a firm grasp of intellectual property rights
and how they apply to the Software Industry. Intellectual property is an umbrella term for
various types of rights individuals or businesses can have in their names, creative works,
and inventions. Software developers need a solid understanding of their rights to develop and
protect a brand, ensure exclusive ownership of their creations, and keep their work confidential
to create and maintain an advantage in this competitive market.
Software as Patents
A patent entitles an inventor to exclude others from making, using or selling the claimed
invention for a period of 20 years. A Software Developer can get a patent on software inventions
much like a Mechanical Engineer can get a patent on a new machine or device. To obtain a
patent, your software or algorithm must have a very high level of originality and you must
disclose the “recipe” for your invention to the public.
With the rapid growth of the technology industry, software patents have become more common.
Some examples of software patents include [Link]’s “one-click buy” patent (US Patent
No. 5960411) and the popular MP3 audio format (US Patent No. 5579430). Software developers
who create unique and novel software should consider obtaining patent protection, especially if
they wish to market and sell their software to others.
Copyrighting Software
Regardless of whether or not a Developer can get a patent, copyright protection is available for
the software. A copyright is a set of exclusive rights given to an individual or business that
has created a literary or artistic work (including computer software). A copyright gives the
owner the exclusive right to make copies of the work, distribute copies of the work to the
public, and create derivative works based on the software.
The key difference between a patent and a copyright is that while a patent can protect you from
people who try to imitate your software, software copyrights have a narrower scope and will only
protect you if someone copies actual executable or source code or graphics from your software.
Copyright protection also lasts much longer than patent protection. However, you must keep in
mind that to invoke these protections, your must file for and receive a copyright registration.
Social And Professional Ethics in IT G4 IT(A&B)
It is important that both Software Developers and Software Companies 1) understand at the
beginning who will own any copyrights that result from the work, and 2) create the necessary
contracts to ensure that ownership ends up where it was intended.
Protecting your brand is especially important if your software is not entitled to other forms of
protection. For example, an Internet browser may not be patentable, but a trademarked brand
name can help ensure that the public perceives the browser as unique product associated solely
with your company. Protecting your brand names can also help prevent others from interfering
with your company’s Internet presence through cybersquatting.
trade secret. Trade secrets provide another way to protect material that could otherwise be
copyrighted or patented. While copyrights and patents are made public and limited in duration,
trade secrets are private and can last indefinitely – so long as you actually keep them secret and
use reasonable measures to protect their secrecy. Trade secrets also can extend to things, such as
customer lists, that are not easily protected by copyrights or patents.
Imagine a clever software developer who writes a program that predicts the Stock Market with
99% accuracy. If he patents his software, in 20 years, everyone can create, use, and sell similar
software. However, if he keeps the software a trade secret, he can control the source code
indefinitely and no one will ever know how he achieved such accuracy.
However, it is essential that you take sufficient steps to develop a Trade Secret Protection
Program for your software. A Software Developer must maintain the confidentiality of the
source code to ensure trade secret protection. A proper Protection Program will include steps like
requiring confidentially agreements, ensuring limited access to source code, having password
protections, and limiting the number of people with access to sensitive information. If you take
appropriate steps and your software qualifies for trade secret protection, you can prevent others
from taking or using the source code, development processes, and algorithms without your
permission.
Conclusion
By understanding of the different types of intellectual property and issues related to software
development, you will be better equipped to protect the rights in your software. If you encounter
any of the issues discussed above, you should consult an attorney to make sure you are fully
protecting your intellectual property rights..
Usually, ownership of an idea or invention is determined by whom, where and in what context
the creation of the idea took place.
Usually, ownership of an idea or invention is determined by whom, where and in what context
the creation of the idea took place. However, the question of ownership of an invention is
sometimes a difficult one. Often this question becomes contentious many years after the
invention was devised and a patent application lodged. The contention may arise because of
circumstances in which the invention was developed or because of economic merits of the
invention which is often not apparent at an early stage.
In order to establish the ownership of an invention it is necessary first of all to establish who an
inventor is and then establish whether or not an inventor, or some other person or company, is
entitled to the ownership of an invention.
Article 7 of the Patent Law provides that, the right to the invention shall devolve to the inventor
or his legal successor, and in case two or more persons collaborate in completing an invention,
rights shall devolve to them or their legal successors jointly. However, such right shall not
extend to those whose efforts were limited only to assistance in the completion of an invention
without any creative contribution.
It should be noted that the Patent Law requires an inventor to lodge a patent or Utility Certificate
application with the Department of Industrial Property at the Ministry of Economy in order to
confirm or to claim the ownership of an invention. The Patent Law confirms that the person who
lodges an application for a Patent or Utility Certificate before others; or claims priority for the
same invention before others, shall be entitled to the ownership of the invention as well as to the
right to the Patent or Utility Certificate. So if two people create an invention, the ownership and
the right to the Patent and/or Utility Certificate shall be granted to the first person who lodges an
application for a Patent or Utility Certificate.
We learnt that the general principal is he who invents owns the invention and the rights to it.
Social And Professional Ethics in IT G4 IT(A&B)
This general rule applies if the inventor is a self employed individual/s who works for himself.
However, this general rule may be put to question when an invention is not created by a self
employed individual but rather by an individual who works for another person or company. The
Patent Law has dealt with this matter and provided two scenarios for this situation as follows:
Employees are required by law to assign their inventions to their employers so long as their
employment or contracts states so. Like any contract, an employment agreement may be written
in any manner agreed upon by both the employer and the employee. The key elements are that
the agreement must be in writing and signed by both parties.
Article 9, subsections 1& 2 of the Patent Law has clearly stated that if an invention is completed
through an engagement contract or employment contract, the right thereto shall devolve to the
employer, unless otherwise stipulated in the contract.
The Patent Law has succeeded in minimizing future disputes that may arise between the
employer and the employee regarding the economic merits of an invention in subsection 2 of
Article 9 by allowing the parties to agree in the employment contract or a later agreement on a
certain sum of money to be allocated to the inventor from the proceeds of the invention. In the
absence of such agreement, the competent court will have the power to determine such
consideration to the inventor.|
To remedy the uncertainty that arises when determining ownership of patentable invention in the
absence of a written employment or contract, the Patent Law has provided three criteria in
determining the ownership of an employer of the invention created by his employee during his
employment; these criteria are:
The invention comes out of tasks and assignments that are part of the employee's job
responsibilities; and finally,
The invention was created using any of the company's resources (time, materials, space, know
how etc).
The law has further placed a duty on the employee to notify the employer immediately of his
invention by a written report. The date of this report is essential in deciding the owner of an
invention.
It is worth mentioning that the above criteria does not automatically grant an employer the right
to the ownership of an invention; the employer has to express his interest in acquiring the rights
to the invention created by one of his employees. The Patent Law has set some limitations on the
period within which an employer has to express his interest on an invention and that the
employer has to express his interest in the invention within four (4) months from the date of the
submission of the report by his employee. This limitation period is intended by the legislator to
be mandatory and any departure from this requirement will deprive the employer of any rights to
an invention created by his employee.
Interestingly, in balancing the rights of employers and employees, the Patent Law states in article
10 that the name of the actual inventor (who is an employee in this case) has to be written in the
application for Patent or Utility Certificate which is usually submitted by an employer unless the
inventor declares, in writing, otherwise.
The above two situations (written employment contract and no written employment contract)
allow an employer to become the owner of the invention and its patent rights. The employer will
have the right to exploit the invention to his benefit which is known in some jurisdictions as
Shop Rights. The only difference is that under the UAE Patent Law an employer retains both the
ownership as well as the Patent Rights. The Duration of the Patent right is 20 years and the
Utility Certificate is 10 years starting from the date of filing application thereof.
Social And Professional Ethics in IT G4 IT(A&B)
1.1. Risk
Risk is a measure of future uncertainties in achieving program performance goals and objectives
within defined cost, schedule and performance constraints. Risk can be associated with all
aspects of a program (e.g., threat, technology maturity, supplier capability, design maturation,
performance against plan,) as these aspects relate across the Work Breakdown Structure (WBS)
and Integrated Master Schedule (IMS). Risk addresses the potential variation in the planned
approach and its expected outcome. While such variation could include positive as well as
negative effects, this guide will only address negative future effects since programs have
typically experienced difficulty in this area during the acquisition process.
A future root cause (yet to happen), which, if eliminated or corrected, would prevent a
potential consequence from occurring,
A probability (or likelihood) assessed at the present time of that future root cause
occurring, and
The consequence (or effect) of that future occurrence.
A future root cause is the most basic reason for the presence of a risk. Accordingly, risks should
be tied to future root causes and their effects.
Risk management is the overarching process that encompasses identification, analysis, mitigation
planning, mitigation plan implementation, and tracking. Risk management should begin at the
earliest stages of program planning and continue throughout the total life-cycle of the program.
Additionally, risk management is most effective if it is fully integrated with the program's
systems engineering and program management processes—as a driver and a dependency on
those processes for root cause and consequence management. A common misconception, and
program office practice, concerning risk management is to identify and track issues (vice risks),
and then manage the consequences (vice the root causes). This practice tends to mask true risks,
and it serves to track rather than resolve or mitigate risks. This guide focuses on risk mitigation
planning and implementation rather on risk avoidance, transfer or assumption.
Social And Professional Ethics in IT G4 IT(A&B)
Note: Risks should not be confused with issues. If a root cause is described in the past tense, the
root cause has already occurred, and hence, it is an issue that needs to be resolved, but it is not a
risk. While issue management is one of the main functions of PMs, an important difference
between issue management and risk management is that issue management applies resources to
address and resolve current issues or problems, while risk management applies resources to
mitigate future potential root causes and their consequences.
2.8. "Goofing off": who owns the "Easter eggs"? Why are
they tolerated?
Goofing off is a slang term in the United States for engaging in recreation or an idle
pastime while obligations of work or society are neglected.
Chaper 3
According to Donna Batten, "computer crime is the use of a computer to take or alter data or to
gain unlawful use of computers or services" ("Computer Crime"). With the increasing
prevalence of the computer and other technological devices, the amount of computer crimes has
skyrocketed.
Prior to 2000
The very first legislation on a federal level regarding computer crime was the Counterfeit Access
Device and Computer Fraud and Abuse Act in 1984.
This Act made obtaining financial or credit information through a computer a misdemeanor.
Before this Act was put in place, there was not much that could be done for computer fraud. Not
only did this Act help fight against computer fraud, but it also acted against the use of computers
as a means of inflicting damage on other computing systems.
Note that this was a Federal Act, and about half of the states passed similar statutes for greater
enforcement. It was around this time in 1984 that there was an organized effort to try to define
what exactly constitutes "computer crime" ("Computer Crime").
Despite the new laws, in 1987, a report by Ernst and Whinney found that approximately $3-5
billion is lost each year due to computer crime ("Computer Crime"). The increased money loss
can be attributed to the growing accessibility of the Internet, for Internet service providers were
starting to develop large customer bases.
Social And Professional Ethics in IT G4 IT(A&B)
To help combat the exploding amount of computer crimes, a new team was formed under the
FBI--the National Computer Crime Squad. This team worked exclusively on cases involving
computer crime, and between 1991 and 1997, it investigated over two hundred individual cases
("Computer Crime").
Early 2000s
One of the most prominent events in the history of computer crime was the terrorist attack of
September 11, 2001. Though this attack was not directly related to computer crime, it led to the
creation of the Uniting and Strengthening America by Providing Appropriate Tools Required to
Intercept and Obstruct Terrorism Act--the USA PATRIOT Act ("Computer Crime"). This Act
gave government agencies an increased ability to crack down on computer crime in the name of
intercepting and obstructing terrorism.
In 2002, a survey by the Computer Security Institute found that over 90% of large corporations,
including government agencies, reported having security breaches. This data alone demonstrates
just how commonplace and effective computer crimes were becoming. The survey also found
that in 2002 alone, there was a loss of $455 million attributed to computer crime ("Computer
Crime").
By 2012, a large computer security company, Symantec, found that computer crime was costing
companies $114 billion per year, a significant increase from that of $455 million from ten years
prior. In addition, $274 billion was wasted in lost time due to interferences caused by computer
crime (Smith).
With the astonishing amount of money going down the drain, a Bloomberg Government study
was performed to figure out how much money would be needed to prevent the cyber security
attacks. The study found that big organizations would have to increase the money allotted for
computer security from $5.3 billion to $46.6 billion per year. Even then, only 95% of the attacks
would be prevented, leaving 5% of attacks entirely unavoidable (Smith). Because of the daunting
Social And Professional Ethics in IT G4 IT(A&B)
amount of money required, many companies simply turn a blind eye on investing more in
security.
Your corporate assets are at risk and every day that you avoid taking action shortens the time
until your IP will be leaked. Here are six steps toward better data security.
The security world is awash with various malware-centric cyber kill chain models and advanced
styles of threat defense that focus on network traffic, payload, and endpoint analyses. But if you
step back and look at what most security tools and frameworks are trying to accomplish at a very
high level, it boils down to:
Detecting and/or blocking adversaries as they try to get inside your organization to steal
your valuable data and intellectual property (IP)
Detecting and/or blocking adversaries as they try to exfiltrate that IP and data to use for
their own purposes.
With absolute intrusion prevention no longer possible and the new security mantra of fast
detection and response, one could argue that disproportionate time and effort are spent watching
the perimeter doors and too little time is spent guarding the internal resource vault that holds the
company’s most sensitive IP. Privileged insiders who already have the keys to the kingdom may
pose an immediate threat.
More recently, Wall Street traders from Goldman Sachs and Flow Traders BV were accused of
taking proprietary computer source code used to make high-speed stock and commodity trades
that earn millions of dollars in profits each year.
In 2013, the IP Commission Report put the costs of intellectual property theft in excess of $300
billion in the United States alone.
To understand how best to protect such critical assets, it’s important to consider where they are
stored.
For companies that build commercial software products or implement internal software apps and
platforms, their IP consists of source code and related assets stored in version control/source
control management (SCM) systems.
These systems not only store the assets, but also facilitate the collaboration across all the product
contributors, who access the SCM system to update their work and share it with others.
While some security tools focus on monitoring and correlating network log data or endpoint data
(watching the perimeter doors) to spot anomalous behavior, this approach may require time-
consuming manual rules and threshold setting, and often results in security teams being
inundated with false positive alerts.
Some tools may lack context-specific information (e.g., who, when, how and where) that typifies
the behavior of a data thief and don’t compare his or her actions to a baseline of “normal
Social And Professional Ethics in IT G4 IT(A&B)
behavior.” Many tools just give a simple count of how many files were downloaded but don’t
specify exactly which files were downloaded or which critical projects were affected.
For example, a worker who takes small amounts of software code (or other assets) every week
won’t necessarily be detected if a threshold has been set to trigger an alert at an arbitrary fixed
value. But if the worker’s access patterns were compared in a cluster map to a baseline of peers
who don’t steal assets, this slow data leak could be detected.
When a bad guy starts exploring the corporate IP vault, you’d be well served to detect unusual
high-risk behavior and provide actionable insights to your security teams. Certainly, this
approach is preferable to watching the doors for everything and drowning in the security alert
noise.
SCM tools manage those complex development workflows by meticulously tracking all access to
project repositories and files. This means they can generate detailed audit logs. A month of log
data from an SCM system might yield millions of different interactions with files and projects;
for the purpose of detecting anomalies, the more granular the log data, the better.
The focus of security teams is quickly moving toward where the data and critical IP reside. A
new class of security tools uses machine learning and applies behavioral analytics models to
detailed audit logs and other data sources to identify and prioritize threats. These tools enable
organizations to take necessary actions to prevent data exfiltration by individuals who have
gained access to the source of mission-critical IP.
Your corporate assets are at risk, and every day that you avoid taking action shortens the time
until your IP will be leaked. Here are six steps toward better data security:
Social And Professional Ethics in IT G4 IT(A&B)
1. Identify the most important IP in your organization and choose which groups and/or
individuals should have access.
2. Use multi-factor and/or continuous authentication and fine-grained access control. And
enforce strong passwords and different levels of security controls based on asset type.
3. Provide the ability to encrypt data at rest and in transit.
4. Continuously monitor data access and make sure that detailed audit logs are implemented
in a secure SCM repository.
5. Implement a security platform that can apply behavioral analytics models to audit logs
and quickly identify high-risk anomalous data access.
6. Integrate your SIEM and other log data with a flexible security platform that can provide
detailed context-rich actionable data to identify high-risk threats to your most important
projects and files.
It is vital that you acknowledge any information source you use. If you do not cite the source of
your information (from a book, article, website), then you may be accused of plagiarism.
Being party to someone else's plagiarism (by allowing them to copy your work or by otherwise
helping them plagiarise work for an assessment) is also dishonest practice.
Many people think of plagiarism as copying another's work or borrowing someone else's original
ideas. But terms like "copying" and "borrowing" can disguise the seriousness of the offense:
Social And Professional Ethics in IT G4 IT(A&B)
to steal and pass off (the ideas or words of another) as one's own
to use (another's production) without crediting the source
to commit literary theft
to present as new and original an idea or product derived from an existing source
In other words, plagiarism is an act of fraud. It involves both stealing someone else's work and
lying about it afterward.
According to U.S. law, the answer is yes. The expression of original ideas is considered
intellectual property and is protected by copyright laws, just like original inventions. Almost all
forms of expression fall under copyright protection as long as they are recorded in some way
(such as a book or a computer file).
Most cases of plagiarism can be avoided, however, by citing sources. Simply acknowledging that
certain material has been borrowed and providing your audience with the information necessary
to find that source is usually enough to prevent plagiarism.
Software Licensure Agreement When installing software via Internet or CD-ROM, users
agree to a licensure agreement before they are able to test out the software. If this agreement is
broken or violated, then the user is guilty of software piracy. The software licensure agreement is
a contract between the software user and the software developer. Usually, this agreement has
certain terms and conditions the software user must follow. When the user doesn't follow the
rules and regulations, they are guilty of software piracy. Some of these terms and conditions
prohibit:
1. Using multiple copies of a single software package on several computers
2. Passing out copies of software to others without the proper documentation (Not having a
multiple site license for more than one computer)
3. Downloading or uploading pieces of software via bulletin boards for others to copy
4. Downloading and installing shareware without pay-ing for it Unless otherwise stated, most
software licensure agreements allow you to place one copy on a single computer and make a
second copy for backup purposes.
Software piracy comes in many different forms. The three most common type are
End-User Piracy,
Internet Piracy and
Reseller Piracy.
End-User Piracy
With the advancement of technological tools software piracy has increased worldwide. You may
be thinking, what does this have to do with me?
Unfortunately, software piracy affects all of us in more ways than one. For instance, software
piracy hurts the economy because revenue is lost.
Second, the software industry is affected because limited numbers of jobs are available. Lastly,
consumers end up paying higher prices for software programs. Not being educated about
software piracy will not exempt you of civil and/or criminal penalties if found guilty. Fines could
include up to $250,000 and/or 5 years in jail.
The Business Software Alliance (BSA) has stated the following...
♦
One in every four software programs in use in the United States is illegally copied
♦
In the United States, nearly 25 percent of all business software is obtained illegally
♦
In 1999, the United States suffered a staggering 107,000 job losses, $5.3 billion in lost wages and
$1.8 million in lost tax revenue due to pirated software
♦
Software makers lost nearly $3.2 billion to piracy in 1999
♦
In 1998, piracy cost 109,000 jobs, $4.5 billion in lost wages and almost $1 billion in tax revenue.
The software user also runs a higher risk of viruses and fatal system crashes because of corrupted
diskettes or defective software. Consumers also lose because they don't enjoy the full benefits of
technical support, warranty protection, or product upgrade information.
piracy also deals with individuals swapping copies of software programs with friends or family
members.
Internet Piracy
Internet piracy is rapidly becoming the fastest and easiest way to receive pirated software. Many
companies allow consumers to download software from the Internet. This eliminates the need to
make several trips to the store or sending out copies of software on CD-ROM or floppy disk.
However, these simple and time saving techniques have also increased Internet piracy.
Social And Professional Ethics in IT G4 IT(A&B)
Internet piracy can occur in many different forms such as downloading or uploading software
from/to a bulletin board, attaching a copy of software via email and/or transmitting software
programs via file transfer protocol (FTP).
Reseller Piracy
Reseller piracy, also known as counterfeiting and hard disk loading, happens when a legal copy
of software is duplicated and distributed on a massive amount of personal computers and/or to
consumers as a legal software application. This type of piracy can be very difficult to identify
due to the very sophisticated manner in which the software is duplicated and presented to the
individual and/or organization.
What Can You Do?
If you are aware of an individual and/or organization who is using pirated software you can...
♦
Confidentially report suspected piracy use by contacting Business Software Alliance (BSA) via
phone (888) NOPIRACY, online at [Link] or email software@[Link]
♦
Implement some type of software management tool. The BSA offers a free publication entitled
“The Guide to Software Management,” which can assist you and/or the organization in
establishing guidelines for proper software installation in your environment. This guide can be
ordered or downloaded via Internet at [Link]
♦
Download a free copy of the BSA software management tool titled SoftScan and MacScan
available at [Link]. The software program can help businesses/organizations to detect
licensed and unlicensed software applications on their machines.
♦
Contact The Software & Information Industry Association (SIIA) to report violations via phone
(800)388-7478 or via e-mail piracy@[Link] or online via their online piracy intake report
located at [Link]
♦
Download a free software management tool provided by SIIA. SIIA provides a self-audit kit that
deals with appropriate procedures to assist an organization/business with software issues. SIIA
Social And Professional Ethics in IT G4 IT(A&B)
has a self-audit kit for Windows and Macintosh users. The Windows program is WRQ Express
Meter;
KeyAudit is for Macintosh users.
♦
Be careful when purchasing software via Internet auction sites. According to a recent study
conducted by the BSA, most of the business software available on many Internet auction sites is
counterfeit.
♦
When in doubt, contact the software publisher/manufacturer. They will be able to tell you the
proper documentation and price range for that particular software.
♦
Download freeware and/or shareware applications from the Internet. Freeware applications are
software programs that are free, uncopyrighted programs that are considered to be in
the public domain. Shareware applications are software programs that are available online
for a certain number of days on a trial basis. Days vary on the developer of the software.
After the trial period, the user is supposed to send in the amount asked by the developer.
Sometimes after the trial period, some of the options will be revoked or automatically
disabled. Some common shareware application prices range from $10 to $35 dollars or higher.
Freeware and shareware applications are available at [Link] and www.
[Link].
♦
Stay away from “warez” sites. [Link] defines warez “as a term used by software ‘pirates’ to
describe software that has been stripped of its copy-protection and made available on the Internet
for downloading.”
♦
Avoid purchasing software that is loose (no shrink-wrap) and has hand labeled disks. Make sure
you receive the proper documentation and license information.
♦
Last but not least — remember, if it sounds too good to be true, it probably is! The BSA states,
“It is much safer to purchase software from known, reliable, authorized sellers, either online or in
retail settings.”
Social And Professional Ethics in IT G4 IT(A&B)
Hackers use DoS attacks to prevent legitimate uses of computer network resources.
Those on the receiving end of a DoS attack my lose valuable resources, such as their e-mail
services, Internet access or their Web server. Some DoS attacks may eat up all your bandwidth or
even use up all of a system resource, such as server memory, for example. Some of the worst-
case scenarios seen over the past couple years is a Web site, used by millions of people being
forced to cease operation because of a successful DoS attack.
A DoS attack may very well appear to be legitimate traffic on the system or network, but differs
in that the volume and frequency of the traffic will increase to unmanageable levels. An attack
on a Web server, for example, would not be normal spurts of visitors, but rather a large barrage
of hits in close proximity so the server cannot keep up with the sheer volume of page requests.
On a mail server, hundreds of thousands of messages can be sent to the server in a short period of
time where the server would normally only handle under a thousand messages in that same time
period. The targeted server would most likely be brought to a halt from a DoS attack because it
runs out of swap space, process space or network connections.
Social And Professional Ethics in IT G4 IT(A&B)
While DoS attacks do not usually result in information theft or any security loss for a company,
they can cost an organization both time and money while their network services are down.
Buffer Overflow
The condition wherein the data transferred to a buffer exceeds the storage capacity of the buffer
and some of the data .overflows. into another buffer, one that the data was not intended to go
into. Since buffers can only hold a specific amount of data, when that capacity has been reached
the data has to flow somewhere else, typically into another buffer, which can corrupt data that is
already contained in that buffer. Malicious hackers can launch buffer overflow attacks wherein
data with instructions to corrupt a system are purposely written into a file in full knowledge that
the data will overflow a buffer and release the instructions into the computer.s instructions.
Ping of Death
A type of DoS attack in which the attacker sends a ping request that is larger than 65,536 bytes,
which is the maximum size that IP allows. While a ping larger than 65,536 bytes is too large to
fit in one packet that can be transmitted, TCP/IP allows a packet to be fragmented, essentially
splitting the packet into smaller segments that are eventually reassembled. Attacks took
advantage of this flaw by fragmenting packets that when received would total more than the
allowed number of bytes and would effectively cause a buffer overload on the operating system
at the receiving end, crashing the system.
Smurf Attack
A type of network security breach in which a network connected to the Internet is swamped with
replies to ICMP echo (PING) requests. A smurf attacker sends PING requests to an Internet
broadcast address. These are special addresses that broadcast all received messages to the hosts
connected to the subnet. Each broadcast address can support up to 255 hosts, so a single PING
request can be multiplied 255 times. The return address of the request itself is spoofed to be the
address of the attacker's victim. All the hosts receiving the PING request reply to this victim's
Social And Professional Ethics in IT G4 IT(A&B)
address instead of the real sender's address. A single attacker sending hundreds or thousands of
these PING messages per second can fill the victim's T-1 (or even T-3) line with ping replies,
bring the entire Internet service to its knees.
In a SYN attack, a sender transmits a volume of connections that cannot be completed. This
causes the connection queues to fill up, thereby denying service to legitimate TCP users.
Teardrop
A Teardrop is a type of DoS attack where fragmented packets are forged to overlap each other
when the receiving host tries to reassemble them.
Distributed denial of service (DDoS) attacks are a growing concern with far-reaching effects for
businesses and organizations of all sizes. DDoS attacks are used by criminal enterprises,
politically-motivated cyber terrorists, and hackers hoping to bring websites down for fun or
profit.
Now, more than ever, it is crucial for organizations and online retailers to measure their risk of
attack and create a DDoS attack protection plan in advance in order to mitigate risk and enable a
fast recovery.
But DDoS attacks are not all the same. On a very high level, a DDoS attack can be first divided
into the following two categories:
Secondly, a DDoS attack can fall into the following three broad categories, depending on the
area of the network infrastructure on which the attack is focused:
Social And Professional Ethics in IT G4 IT(A&B)
Also known as “floods,” the goal of this type of attack is to cause congestion and send so much
traffic that it overwhelms the bandwidth of the site. Attacks are typically executed using botnets,
an army of computers infected with malicious software and controlled as a group by the hacker.
This type of attack focuses on actual web servers, firewalls and load balancers to disrupt
connections, resulting in exhausting their finite number of concurrent connections the device can
support.
This type of attack, also known as Layer 7 attacks, specifically targets weaknesses in an
application or server with the goal of establishing a connection and exhausting it by
monopolizing processes and transactions. These sophisticated threats are harder to detect because
not many machines are required to attack, generating a low traffic rate that appears to be
legitimate.
Additionally, an attack can also be a combination of the three types listed above, which makes it
even more challenging for organizations to combat.
Here are some common forms of DDoS attacks (both past and present):
UDP Flood
User Datagram Protocol is a sessionless networking protocol. One common DDoS attack method
is referred to as a UDP flood. Random ports on the target machine are flooded with packets that
cause it to listen for applications on that those ports and report back with a ICMP packet.
SYN Flood
A “three-way handshake”, which is a reference to how TCP connections work, are the basis for
this form of attack. The SYN-ACK communication process works like this:
Social And Professional Ethics in IT G4 IT(A&B)
First, a “synchronize”, or SYN message, is sent to the host machine to start the
conversation.
Next, the request is “acknowledged” by the server. It sends an ACK flag to the machine
that started the “handshake” process and awaits for the connection to be closed.
The connection is completed when the requesting machine closes the connection.
A SYN flood attack will send repeated spoofed requests from a variety of sources at a target
server. The server will respond with an ACK packet to complete the TCP connection, but instead
of closing the connection the connection is allowed to timeout. Eventually, and with a strong
enough attack, the host resources will be exhausted and the server will go offline.
Ping of Death
Ping of death (”POD”) is a denial of service attack that manipulates IP protocol by sending
packets larger than the maximum byte allowance, which under IPv4 is 65,535 bytes. Large
packets are divided across multiple IP packets – called fragments – and once reassembled create
a packet larger than 65,535 bytes. The resulting behemoth packet causes servers to reboot or
crash.
Note: This was a real problem in early years (think 1996), but doesn’t have the same effect these
days. Most ISPs block ICMP or “ping” messages at the firewall. However, there are many
others forms of this attack that target unique hardware or applications. Some other names are
“Teardrop”, “Bonk”, and “Boink”.
Reflected Attack
A reflected attack is where an attacker creates forged packets that will be sent out to as many
computers as possible. When these computers receive the packets they will reply, but the reply
will be a spoofed address that actually routes to the target. All of the computers will attempt to
communicate at once and this will cause the site to be bogged down with requests until the server
resources are exhausted.
Social And Professional Ethics in IT G4 IT(A&B)
Peer-to-Peer Attacks
Peer-to-Peer servers present an opportunity for attackers. What happens is instead of using a
botnet to siphon traffic towards the target, a peer-to-peer server is exploited to route traffic to the
target website. When done successfully, people using the file-sharing hub are instead sent to the
target website until the website is overwhelmed and sent offline.
Nuke
Corrupt and fragmented ICMP packets are sent via a modified ping utility to keep the malicious
packets to be delivered to the target. Eventually, the target machine goes offline. This attack
focuses on comprising computer networks and is an old distributed denial of service attack.
Slowloris
This type of distributed denial of service attack can be especially difficult to mitigate. It’s most
notable use was in the 2009 Iranian Presidential election. Slowloris is a tool that allows an
attacker to use fewer resources during an attack. During the attack connections to the target
machine will be opened with partial requests and allowed to stay open for the maximum time
possible. It will also send HTTP headers at certain intervals. This adds to the requests, but never
completes them – keeping more connections open longer until the target website is no longer
able to stay online.
The purpose of this attack is to slow server response times. A DDoS attack seeks to take a
website or server offline. That is not the case in a degradation of service attack. The goal here is
to slow response time to a level that essentially makes the website unusable for most people.
Zombie computers are leveraged to flood a target machine with malicious traffic that will cause
performance and page-loading issues. These types of attacks can be difficult to detect because
the goal is not to take the website offline, but to degrade performance. They are often confused
with simply an increase in website traffic.
Social And Professional Ethics in IT G4 IT(A&B)
Unintentional DDoS
Unintended distributed denial of service happens when a spike in web traffic causes a server to
not be able to handle all of the incoming requests. The more traffic that occurs, the more
resources are used. This causes pages to timeout when loading and eventually the server will fail
to respond and go offline.
Application level attacks target areas that have more vulnerabilities. Rather than attempt to
overwhelm the entire server, an attacker will focus their attack on one – or a few – applications.
Web-based email apps, WordPress, Joomla, and forum software are good examples of
application specific targets.
Multi-Vector Attacks
Multi-vector attacks are the most complex forms of distributed denial of service (DDoS) attack.
Instead of utilizing a single method, a combination of tools and strategies are used to overwhelm
the target and take it offline. Often times, multi-vector attacks will target specific applications on
the target server, as well as, flood the target with a large volume of malicious traffic. These types
of DDoS attacks are the most difficult to mitigate because the attack come in different forms and
target different resources simultaneously.
A “Zero Day” based attack is simply an attack method that to date has no patches. This is a
general term used to describe new vulnerabilities and exploits that are still new.
These attacks occur when an actor exploits a zero-day vulnerability to carry out a DDoS attack.
A zero-day vulnerability is a system or application flaw previously unknown to the vendor, and
has not been fixed or patched. It is called a “zero-day” because once a flaw is discovered the
vendor has zero days (before disclosure) to fix it.
Social And Professional Ethics in IT G4 IT(A&B)
Zero-day DDoS attacks are particularly difficult to protect against as they originate from an
unknown threat. The adoption of bug bounty programs by software vendors and other companies
are becoming increasingly popular to incentivize security researchers to report possible
vulnerabilities.1
As you can see, the types of DDoS attacks vary, but all can affect your website’s performance.
There’s no question about the global impact the Internet has played on economic growth and
prosperity, and how it’s changed the way we work, play, connect and share. While living in
today’s Internet-reliant world has brought unprecedented benefits to businesses and consumers
alike, the underlying threat of distributed denial-of-service (DDoS) attacks cannot be ignored.
This may not be surprising to hear - recent headlines about security breaches with major retailers
and financial institutions seem to be a reoccurring theme in the news.
Simply put, a DDoS attack is a malicious attempt to bring down networks, Web-based
applications, and/or services by overwhelming these resources with too much data or impairing
them in some other way. Unlike a denial-of-service (DoS) attack where the source is just a
singular computer and connection, a DDoS attack is from multiple sources, and is capable of
causing great consequences to a company’s brand, reputation and bottom line.
DDoS attacks are designed to target any aspect of a business and its resources, and can easily:
Here’s the good news: Despite the fact that DDoS attacks have become more pervasive than
ever before, businesses can help mitigate against these threats by utilizing a cloud-based DDoS
protection service that offers a more holistic, proactive approach.
Social And Professional Ethics in IT G4 IT(A&B)
Verisign’s DDoS Protection Services provide the highest level of infrastructure protection and
availability and use proactive monitoring, advance warning systems and proprietary mitigation
technology to prevent DDoS attacks from ever reaching the organization.
Preventative Measures
To prevent your system and network from becoming a victim of DoS attacks, CERT/CC offers
many preventative solutions (3) which include:
Implement router filters. This will lessen your exposure to certain denial-of-service
attacks.
If they are available for your system, install patches to guard against TCP SYN flooding.
Disable any unused or unneeded network services. This can limit the ability of an
intruder to take advantage of those services to execute a denial-of-service attack.
Enable quota systems on your operating system if they are available.
Observe your system performance and establish baselines for ordinary activity. Use the
baseline to gauge unusual levels of disk activity, CPU usage, or network traffic.
Routinely examine your physical security with respect to your current needs.
Use Tripwire or a similar tool to detect changes in configuration information or other
files.
Invest in and maintain "hot spares" - machines that can be placed into service quickly in
the event that a similar machine is disabled.
Invest in redundant and fault-tolerant network configurations.
Establish and maintain regular backup schedules and policies, particularly for important
configuration information.
Establish and maintain appropriate password policies, especially access to highly privileged accounts
such as UNIX root or Microsoft Windows NT Administrator.
DoS attack
Social And Professional Ethics in IT G4 IT(A&B)
Short for denial-of-service attack, a type of attack on a network that is designed to bring the network to
its knees by flooding it with useless traffic.
DDoS attack
Short for Distributed Denial of Service, it is an attack where multiple compromised systems (which are
usually infected with a Trojan) are used to target a single system causing a Denial of Service (DoS)
attack.
Script kiddie
A person, normally someone who is not technologically sophisticated, who randomly seeks out a
specific weakness over the Internet...
network meltdown
A state in which a network grinds to a halt due to excessive traffic.
Cyber terrorism
As stated above, cyber terrorism is a form of political attack in which fear or havoc is
instilled in a victim by means of a computer. This differs from traditional terrorism, which does
not have to specifically include the use of computer technology. At their core, both forms of
terrorism are inspired by something political, are against unarmed people, and are attempting to
raise fear in order to reach an intended outcome (Taylor). In today's world, cyber terrorism is
growing in popularity, and most terrorist attacks are either an example of cyber terrorism or a
blend between traditional terrorism and cyber terrorism.
Anonymity
Social And Professional Ethics in IT G4 IT(A&B)
The Internet is a chamber of secrets. It is a place where people can pose as whoever they
want and take part in a plethora of online activities. Though there are ways to track someone's
online activity, Internet surveillance is not heavily enforced (Curran, Concannon, and
McKeever). There is much debate as to what the balance between surveillance and anonymity
online should be.
Convenience
Terrorists can utilize the Internet to organize and launch attacks in other countries
without leaving the comfort of their home. From his living room, a terrorist can drop a bomb in a
foreign city, for example; the possibilities are endless.
The Internet is also a goldmine of information. No longer must people search book after
book to find the piece of information they are looking for; nearly any topic is now accessible
with the click of a mouse. Books are available on the Internet that detail instructions on how to
create bombs from scratch, as well as guides on how to be a terrorist (Curran, Concannon, and
McKeever). Because of the convenience of this information, even someone's next-door neighbor
Social And Professional Ethics in IT G4 IT(A&B)
can become a terrorist. The Internet allows an individual to participate in terrorist activities with
little effort.
Due to the anonymity of the Internet and vagueness of digital crime laws, cyber terrorism
can be difficult to trace and take action on. There have been cases in the past where the term
"computer" was not defined clearly in a law or policy, preventing the necessary legal action from
being taken. Because of cyber terrorism, some people support the idea of "total surveillance",
where the government has the ability to monitor cyber resources for terroristic activity, while
others view this as an invasion of privacy (Taylor).
History
The first known cyber terrorist attack occurred in 1998 and targeted Sri Lankan
embassies. The attack was based on spam, of which 800 emails were sent to Sri Lankan
embassies daily for two straight weeks. The spam message read "We are the Internet Black
Tigers and we're doing this to interrupt your communications" (Curran, Concannon, and
McKeever).
Though this first attack was not necessarily dangerous, it managed to invoke fear into its
victims. Before this attack, the world had not been fully introduced to cyber terrorism, and this
incident helped raise government awareness. It became apparent to others that cyber terrorism
could be used to allow people to protest and disrupt organizations or ideas they are against.
The terrorist attack of September 11, 2001, can also be related to cyber terrorism.
Terrorist groups, "including Hezbollah, HAMAS, the Abu Nidal organization, and Bin Laden's al
Qa'ida organization were using computerized files, e-mail, and encryption to support their
operations", George Tenet, the Director of Central Intelligence, has said (Curran, Concannon,
and McKeever).
Responses
Because of cyber terrorism, countries like the United States and Australia have
recommended that a cyber space network operations center be formed. Such an operations center
Social And Professional Ethics in IT G4 IT(A&B)
could include representatives from Internet service providers, hardware companies, and software
companies (Curran, Concannon, and McKeever).
Together, the representatives of a cyber space network operations center could work on
developing secure technologies by developing systems development life cycles (SDLCs). An
SDLC is a guideline that is followed when creating a new technology for the duration of the
product's development as well as for support after the release. By having a cyber space network
operations center, organizations would be involved in a more assertive approach to security.
In recent years, countries have created new policies regarding cyber terrorism and
governmental right of response. Figure 6 identifies a few examples of what some countries have
implemented.
figure6
Notice in Figure 6 that the United Kingdom's policy to allow a greater level of
government involvement with communications was merely an attempt and fell through. This is
because people tend to be uncomfortable with the idea of total surveillance. Many people are
worried about the misuse of information or the government gathering more information than
Social And Professional Ethics in IT G4 IT(A&B)
figure5
Luckily, a new act, known as the Cybersecurity Act of 2012, has been proposed. This Act would
allow the Homeland Security Department to work with organizations to develop security
standards. Some companies, however, are demanding that Congress give out rewards and
incentives in exchange for increasing security. Other companies do not want any government
departments obtaining authority over them (Smith).
Another Act has been proposed, the Secure IT Act, which is very similar to the Cybersecurity
Act of 2012. This Act varies in that it does not give Homeland Security any extra authority over
the security practices of companies. Instead, the companies would be able to spend money the
way they want to for the security practices that work best for them (Smith).
Types of Attacks
Social And Professional Ethics in IT G4 IT(A&B)
Because technology has no set form, there are many different avenues of attack that a victim can
fall susceptible to. The types of attacks listed below are just a short sampling of the threats that
exist. Though a simple computer virus may hold the record for the most commonplace attack,
new attacks are bursting at the seams with creativity, keeping information security professionals
on their toes.
Figure 1 portrays data found in the CSI/FBI 2005 Computer Crime and Security Survey in
regards to the types of cyber attacks causing the greatest amount of losses. According to the
survey, viruses are the number one attack to cause the most damage.
figure1
Malware
Social And Professional Ethics in IT G4 IT(A&B)
Simply defined, malware is any computer code that has a malicious intent. Malware is often used
to destroy something on a computer or to steal private information. Odds are, nearly everyone
with a computer has fallen victim to some form of malware in their time.
Viruses
As the name implies, viruses make a computer "sick". They infect a computer, just like a real
virus that infects a person, and then they hide inside the depths of the computer. Viruses replicate
themselves, and they survive by attaching to other programs or files. Though viruses are one of
the oldest types of cyber attacks, they can be some of the craftiest. The capability of viruses has
evolved, and they are often hard to spot and remove from a computer ("Current Cyber").
Spyware
Spyware is a form of malware that monitors or spies on its victims. It usually remains in hiding,
but even so, it can log the various activities performed by a user. Spyware is capable of recording
keystrokes (what a user types on the keyboard), which means that the attacker can view
passwords that the victim enters into the computer. Spyware is also used to steal confidential
information (Konklin 418).
Worms
Similar to viruses, worms replicate themselves many times to fulfill a nefarious purpose.
However, worms differ from viruses in that they do not need to attach themselves to other files
or programs. Worms are capable of surviving all by themselves, and not only do they replicate
on a single computer host, but they can also replicate across an entire network of computers
("Current Cyber"). It is these features that can make a worm significantly more dangerous than a
virus.
Social And Professional Ethics in IT G4 IT(A&B)
Password Attacks
These attacks are focused on cracking a victim's password so that the attacker may obtain access
to a secured system. A username/password combination is typically the standard form of
authentication on most systems. Though this type of account security is not necessarily weak by
default, a user must follow good password procedures in order to stand a chance against a
password attack (Konklin 412).
Brute-Force Attack
This type of attack is typically used as an end-all method to crack a difficult password. A brute-
force attack is executed when an attacker tries to use all possible combinations of letters,
numbers, and symbols to enter a correct password. Programs exist that help a hacker achieve
this, such as Zip Password Cracker Pro, as seen in Figure 2. Any password can be cracked using
the brute-force method, but it can take a very long time to finish. The longer and more intricate a
password is, the longer it will take a computer to try all of the possible combinations (Konklin
413).
Social And Professional Ethics in IT G4 IT(A&B)
figure2
Dictionary Attack
A dictionary attack takes place when an attacker utilizes a dictionary in an attempt to crack a
password. Essentially, words from the dictionary are inputted into the password field to try to
guess the password. Programs and tools exist that allow hackers to easily try various
combinations of words in the dictionary against a user's password (Konklin 412). Because of the
dictionary attack, it is recommended to use passwords that do not contain simple words that can
be found in a dictionary.
Denial-of-Service Attacks
A denial-of-service (DoS) attack is a special form of cyber attack that focuses on the interruption
of a network service. This is achieved when an attacker sends high volumes of traffic or data
through the target network until the network becomes overloaded ("Denial-of-Service"). Think
of a man juggling; he may be able to juggle quite well when using three or four balls, but if
Social And Professional Ethics in IT G4 IT(A&B)
someone throws more balls into the fray and he tries to continue juggling with an increasing
amount of balls, he may lose control and drop them all. This is essentially what happens when a
network becomes overloaded.
Execution Methods
Typically, a DoS attack is carried out by one computer or one central location of computers. A
popular sub-category of DoS attacks is distributed denial-of-service (DDoS) attacks. A DDoS
attack varies from a regular DoS attack in that there are multiple computers involved. The
computers all work together by means of the Internet to send traffic to the target network
("Denial-of-Service"). Figure 3 shows the basic construction of a DDoS attack, with a primary
attacker accompanied by hijacked computers.
figure3
Another term commonly associated with DoS attacks is "botnet". A botnet is a group of
computers that an attacker has taken control of for nefarious purposes. Often, the true owner of a
Social And Professional Ethics in IT G4 IT(A&B)
computer does not even realize that his/her computer has been compromised. The compromised
computers can be referred to as "bots" or "zombies" because they are under an influence other
than their own ("Denial-of-Service"). Using a botnet, an attacker has the computing power
necessary to launch a DDoS attack, making it easier to overpower a target network.
There are multiple ways to execute a DoS attack. Some of the different forms of execution
include:
The Physical execution method is important to take notice to because it can often be overlooked.
An attacker does not necessarily have to use a computer to launch a DoS attack. A DoS attack
can occur simply by cutting a physical cable at a network site ("Denial-of-Service"). That is why
it is important to consider both physical security and cyber security.
It must also be accepted that a DoS attack can happen accidentally, perhaps by someone
internally who was modifying the network configuration. As long as a network goes down, it is a
form of denial-of-service.
Social And Professional Ethics in IT G4 IT(A&B)
figure4