Tuesday, June 5, 2012

Obama ordered Stuxnet

According to an upcoming book by New York Times chief Washington correspondent, David Sanger, it was Obama who ordered the Stuxnet attack against Iran's nuclear program.

This isn't really a surprise, since most people believed the US to be behind the attack, but it does continue Obama's M.O. of preferring special forces over direct and prolonged engagements.

If true, the real motivation for the attack was to prevent further escalation of a conflict.  Had the virus not been discovered, perhaps the belief was that Iran would have assumed that the failures were accidental or that the virus wasn't targeted.  After all, the world had never seen such a directed cyber attack before.

Tuesday, May 8, 2012

Interesting article on NPR about whether businesses should foot the bill for a Cyber War.

The Lieberman-Collins bill before congress would help pay to secure the nation's critical infrastructure like the power grid, water treatment plants, and the financial system.  Does the government have a duty to protect the rest of the country?

I think it's a great question.  One reason, the first sentance of this blog post - it's not "A" cyber war that we're talking about here...we can't talk about it like it isn't already happening.  It's the current cyber war.  If a city was hit by a tornado or hurricane, there is always disaster assistance that is available.  It's important to a country, especially during a war to help rebuild so that the country can keep on functioning.

Another reason - can a small business really protect itself from a cyber attack from a government?

On the flip side of the issue of course, is risk tolerance.  Businesses don't take security seriously largely because they don't need to.  The only reason some companies have security programs is so they can comply with the Payment Card Industry Data Security Standards (PCI-DSS), and even then it is largely ignored (as we saw was the case with Sony last year).  People are excellent judges of risk.  As identity theft grows, they will tend to get better at creating passwords.  Businesses, too, need to learn from these issues.  But until the WAll Street Journal is covering a story about how a fortune 500 company closed it's doors because of a security breach, businesses won't invest what they need to to protect themselves.  Despite Sony's breach last year, they are still in business and their stock seems to have been barely effected.

If the government steps in, then, and prevents businesses from having to deal with the ramifications of a security threat, then businesses never will treat the issue seriously.

Monday, April 30, 2012

Facebook "Likes" Not Protected Speech?

ArsTechnica has a great summary of the case of Bland v. Roberts, which has ruled that Facebook "Likes" are not protected speech under the 1st Amendment.  The case was decided in the Eastern District Court of Virginia, so it could be appealed a couple of times before hitting the Supreme Court...  There have been lots of other cases where something didn't have to actually constitute speech to be protected under the 1st Amendment, so it isn't clear if this case would stand if appealed.

CISPA Defections Begin

An update on my last post, CISPA - The Government's consolation prize for not passing SOPA, it looks like the measure has already lost some of its original supporters.  According to a story on TheHill.com, seven of the original cosponsors of the Cyber Information Sharing and Protection Act (CISPA) abandoned ship and voted "No" on the bill. 

http://thehill.com/blogs/hillicon-valley/technology/224339-six-cosponsors-of-cispa-cybersecurity-bill-voted-against-it


Friday, April 27, 2012

CISPA - The Government's consolation prize for not passing SOPA

Yesterday, the U.S. House of Representatives passed the Cyber Intelligence Sharing and Protection Act (CISPA).  While the bill was introduced with bibartisan sponsors, the bill passed the house on mostly party lines...Republican "yes" votes were 206 and Democrat "No" votes were 140.  Both sponsors were the ranking members of the House Intelligence Committee.  42 democrats supported the bill while 28 republicans were against it, including Republican U.S. representative and presidential candidate Ron Paul who called it "Big Brother writ large".  President Obama has threatened to veto the legislation if it remains in its current form, but Obama waffled on his support of SOPA, so who know what could happen in an election year.

Some questions:

Why would this bill be fast-tracked while other data security bills or data privacy bills have been stymied for years?

Does this bill simply legalize the warrantless wiretapping that is already being done throughout the country?

Rather than being an attack on the first amendment like SOPA, CISPA attacks the fourth amendment to the constitution. The Fourth Amendment of the Constitution says:

The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

A good question to ask might be what is an unreasonable search?  For Law Enforcement, if you see someone in public committing a crime, they can act.  Why is there an expectation of privacy for communications over Facebook?  Over email?  It is probably very reasonable to expect that Law Enforcement can look at all publicly available information on Facebook.  Is it reasonable to let them look at information that a user has expressly defined as private?  Keep in mind that no one is saying that Law Enforcement can't get a warrant to access the information.

Of course, none of these questions are posed in the bill. Instead, CISPA purports to create a more secure Internet.  How does it attempt to do this?  One blogger site took Representatives Rogers and Ruppersberger to task over their own lack of security on their congressional web pages, including broken certificates, lack of HTTPS and broken links. 

CNET has a great breakdown of how CISPA would impact an individual citizen.

When asked about whether the government could use this private information to spy on its own citizens, one Representative, Dan Boren (D-Oklahoma) said: "The government is not the enemy."  I don't think this would be comforting to most Americans, given the low approval rating of Congress right now.

So why isn't there greater oposition from all the same organizations that were against SOPA?  One answer might be that SOPA requred a lot of intervention on the part of search engines or payment processors (think Google, Yahoo, PayPal, etc.)  They would have had to have dedicated people to respond to requests and to develop technology to help respond.  CISPA would mostly impact ISPs, who in large part support the legislation.

Monday, March 19, 2012

McCain vs. Lieberman - SecureIT vs. Cybersecurity Act of 2012

Senator John McCain along with 5 other Republican senators released their counterproposal to the Lieberman-Collins Cybersecurity Act of 2012 released last month. The bill is called the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information and Technology (Secure IT) Act. Let me start by saying that when I see a bill that cleverly named so as to have an acronym that is readable, I immediately wonder how serious the authors of a bill are about its passage. I can't think of any bills off the top of my head that have actually passed that have been so named. HIPAA? Sarbanes Oxley? Digital Millenium Copyright Act?

I'm not sure how long it took McCain and the other Senators to write their counterproposal bill. It isn't clear whether the bill was already in progress or whether they started last month after hearing about the competing legislation. In any event, McCain’s bill was introduced only a week after the Lieberman bill. The Lieberman purports to have been the result of 3 years of negotiation and research. Mostly, the McCain bill appears to be a hodgepodge of the Cybersecurty Act of 2012 and other preexisting bills, with a ton of deletions and insertions of partisan elements.

Let’s look at the similarities and differences between the two bills:

Both bills have some provision for a Federal Cyber Scholarship-for-service program. The McCain bill copies word for word the first paragraph of the Lieberman bill. Where the Lieberman bill has provisions for how many scholarships are to be given (1,000) and provides for full tuition, the McCain bill provides no guidance on how many scholarships will be given, and only provides for tuition for 2 years of study. The Lieberman bill requires students to enter into a commitment for the same amount of time they spent in school, while the McCain bill requires one and a half times.

If I were a student, I’m not sure I’d be interested in the McCain offer. Less money for longer indentured servitude? Unfortunately, not many students would be able to sign up for the McCain proposal, since the McCain bill specifies that no additional funding will be allocated for Cybersecurity. This means that any money for scholarships would have to be carved out of departments individual budgets…presumably why the McCain bill doesn’t specify a specific number of scholarships. Presumably that number would be close to 0.

No new funding is problematic where issues of national security and defense come into play. If the national air traffic control network, for example, needs to be completely scrapped and a new secure network needs to be deployed, how could that be accomplished under the McCain bill? The FAA would have to carve that out of its budget, and small upgrades would have to happen over a long period of time. This is perhaps why Lieberman and Rockefeller have been so outspoken in their criticism of the McCain bill since the counterproposal.

The Lieberman bill has several sections that the McCain bill is missing entirely:


  • Information Sharing

  • Public Awareness Reports

  • International Cooperation
The Lieberman bill creates affirmative authorities to monitor and defend against cybersecurity threats and allows for coordination of cyber issues within the US government. It addresses FISMA and attempts to address Federal agency purchasing and planning for Information Security, and explicitly discusses savings. It has considerations of international coordination. Finally, it creates the notion of Federal and non-Federal Cybersecurity Exchanges which would allow for the sharing of both classified and non-classified information. The Lieberman bill seems to be attempting to address the issue with Federal agencies claims that they were not allowed to share information prior to September 11th, 2001, one of the main drivers behind the Patriot Act and the creation of the Department of Homeland Security.

The McCain bill has several sections that the Lieberman bill is missing:


  • High Performance Computing

  • Criminal Penalties

The Lieberman bill only mentions High Performance Computing once to make one small amendment while the McCain bill focuses on it for several pages. My only thought here is why? McCain’s changes to the High Performance Computing act of 1991 don’t even really have anything to do with security. The changes mostly read as funding modifications, which make me think this whole bill is about pork, and not security.

The Criminal Penalties section amends the Computer Fraud and Abuse Act, but mostly focuses on stiffening penalties and forfeiture of property directly or indirectly gained by said fraud and abuse. While these are okay goals of the act and could potentially be added to the Lieberman bill, the miss the point of the reality of hacking today. The most successful hackers operate internationally and are very difficult to capture. The McCain bill does nothing to address this new reality.