E-stonia: Antithesis of Russia

President Toomas Hendrik Ilves (pictured) says Estonia does have a national database of data on its citizens, but that individuals have to be notified if their information is accessed. 

It’s not often that a European head of state uses the “radical postmodernist philosophy” of Jacques Derrida and Jean Baudrillard to bash a hostile superpower. But then Toomas Hendrik Ilves, Estonia’s defiantly erudite president of nearly 10 years, is no ordinary head of state.

Ilves is trying to reinvent Estonia as the brightly lit antithesis of Russia, and in today’s confessional age of Edward Snowden, WikiLeaks and the Panama Papers, claims he is baking transparency and accountability into a new kind of digital civic operating system.

Ilves is known for his controversial opinions on everything from Snowden and Internet privacy to cyberwarfare and Vladimir Putin’s postmodernist state, which have apparently, transformed the 63-year-old into a “regional sex symbol”.

The problem with Putin’s Russia, Ilves insists, is that the truth has been entirely devalued. Quoting from Peter Pomerantsov’s 2015 Nothing Is True and Everything Is Possible, the Estonian president says that “all truths have become equivalent” in contemporary Russia. 

With his nearly 70,000 Twitter followers, Ilves has become a kind of global village elder

Ilves came up with this grand idea a quarter of a century ago. When Gorbachev pulled the Soviets out of Estonia in 1991, Ilves asked himself a simple question about the future of a country that had been brutally occupied by its eastern neighbor for a half-century.

 “What do we have?” Ilves asked himself about a country not much larger than Israel with a population less than half that of Silicon Valley.

His answer was equally simple. What the 1.3 million Estonians had, Ilves concluded in 1991, was technology. He recognized that the Soviets, despite their appropriation of most of Estonia’s wealth, had bequeathed a decent educational legacy, especially in mathematics. Estonia’s future, Ilves thus imagined a quarter of a century ago, was hi-tech, especially personal computers and the Internet.

Ilves – a trained psychologist with degrees from Columbia and the University of Pennsylvania – is also self-schooled in computer science. He proudly recalls learning to program as a 13-year-old schoolboy in New Jersey and being among the first geeks to own Apple’s iconic 2E personal computer. By 1993, he was already arguing that Estonia “should computerize all schools” and by 1997 had championed putting all Estonian schools online and establishing publicly funded Internet centers around the country.

Yet despite its multibillion-dollar success stories – including Skype, Playtech and more startups per person than anywhere else in the world – Estonia isn’t just “E-Stonia”, some Baltic version of Silicon Valley or Israel. The little Baltic republic – with the counterintuitive Ilves at its helm – is actually building something more ambitious than just another tightly knit ecosystem of entrepreneurs, investors and technologists.

Estonia is pioneering a model for a democratically transparent 21st-century networked society – the opposite of Putin’s opaque virtual reality show – by giving everyone a digital license plate. “Our goal is to make it impossible to do bad things,” he explains. “Six billion lanes, and nobody has a license plate except the Estonians.”

Is Estonia becoming a 21st-century panopticon?

That is Ilves’ grand – one might even say baroque – idea. Under his presidency over the past 10 years, Estonia has pioneered a series of technological reforms to not only bring everyone online but also to create a national database. The system is built around the online ID card, introduced in 2002, in which its citizens’ information – from healthcare records to tax filings to educational qualifications to real estate documents – is stored in a seamlessly integrated national database.

But what about privacy in this database of its citizens’ intentions?

“Our obsession with privacy is misguided,” Ilves – who is, of course, anything but indifferent to 20th-century Big Brother surveillance regimes – insists. The Estonian system, he explains, is based on “trust”. While the national database can be accessed by the authorities, he stresses, the citizen has to be notified when their records are observed. So if the system hasn’t been built on Blockchain technology, it nonetheless operates on Blockchain-like principles – creating a data system that can’t be altered with notifying both the authorities and citizens.

This is what Ilves calls a “Lockean contract” between digital citizen and the government. The 21st-century networked sovereign, he says, is the guarantor of what he calls “data integrity”. While the government can’t access our data without our knowledge, the citizen no longer has any anonymity in this system.

Rather than privacy from the state, the real concern, Ilves insists, is the integrity of data. Instead of worrying about somebody else knowing our blood type, we should be worried when they start “fiddling” with that data to change our blood type.

Snowden ‘harmed the EU privacy debate’

This focus on data integrity is why Ilves is much less concerned with Snowden’s NSA revelations than either last year’s Office of Personnel Management (OPM) hack in which the data of 21 million people was stolen, or with the ongoing fight between Apple and the FBI over a back door to the iPhone’s data.

Ilves believes that paranoia over the Snowden revelations “harmed the debate” about privacy in the EU. The NSA, he quipped, wasn’t “mining the deep packets of Bohemian poets sending emails to their girlfriends”. In contrast, the OPM and Apple cases are both about trust. Giving the authorities a blanket and unverifiable back door on the iPhone, for example, means that citizens can no longer trust either their government or Apple.

The Estonian model of digital development is “scalable”, Ilves says, although he acknowledges that its political side is much easier to build in a small country like Estonia. But, in light of the revelations from Snowden and other whistleblowers, can we ever really trust the system – even in a tiny country like Estonia?

Guardian

« US Spies Want A Laser Gun Bomb Detector
One Massive Hack Last Year - Nobody Noticed! »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Rollbar

Rollbar

Rollbar is a full-stack error monitoring platform for web and mobile applications. We help developers find and fix bugs fast. Built by developers for developers.

CyberSource

CyberSource

CyberSource provides online payment and fraud management services for medium and large-sized merchants.

ContentKeeper

ContentKeeper

ContentKeeper provides Web Threat Protection solutions to secure today’s Web 2.0 and mobile centric business environments.

ODVA

ODVA

ODVA is a global trade and standards development organization whose members comprise the world’s leading industrial automation companies.

Identillect Technologies

Identillect Technologies

Identillect Technologies provide a user-friendly secure email solution to protect critical information, with an emphasis on simplicity.

Ingenio Global

Ingenio Global

Ingenio is a specialist recruitment business for SaaS companies. Our purpose is to source exceptional talent in areas including cyber security for leading SaaS companies in the UK and Ireland.

Incopro

Incopro

Incopro is an online IP and brand protection software provider that arms brand owners with actionable intelligence to combat online and offline intellectual property and copyright infringements.

GoSecure

GoSecure

GoSecure Managed Detection and Response helps all organizations reduce dwell time by preventing breaches before they happen.

Thoma Bravo

Thoma Bravo

Thoma Bravo is a leading private equity firm with a 40+ year history and a focus on investing in software and technology companies.

Innovex Global

Innovex Global

Innovex is a full-service executive search and advisory business that engages with early-stage startups, scale-ups, and established businesses in the Fintech, Cybersecurity and Technology industries.

Open Data Security (ODS)

Open Data Security (ODS)

Open Data Security is a market leader in the information security sector, offering services to companies, governments and individuals, helping them shield from hackers and cyber attacks.

Spyderbat

Spyderbat

Spyderbat ATI closes the manual investigation gap between detection and response by instantly presenting causally connected threat activity to security analysts at the onset of an investigation.

Approov

Approov

Approov provides a comprehensive runtime security solution for mobile apps and their APIs, unified across iOS and Android.

Stacklok

Stacklok

Stacklok are an Open Source first security company enabling safe Open Source Software consumption.

Nyx Security Solutions

Nyx Security Solutions

Nyx is committed to excellence in embedded cybersecurity, delivering top-tier secure design, development, and penetration testing services that meet and exceed industry standards.

Scytale

Scytale

Scytale is the global leader in security compliance automation, helping companies get compliant and stay compliant.