Read the Trump administration's draft of the executive order on cybersecurity
apps.washingtonpost.com
apps.washingtonpost.com
https://obamawhitehouse.archives.gov/the-press-office/2013/0...
https://obamawhitehouse.archives.gov/the-press-office/2015/0...
https://obamawhitehouse.archives.gov/the-press-office/2016/0...
This could potentially mean allowing NSA expanded capabilities. Not necessarily, though, I guess.
Obviously I don't think that is actually going to happen either, but, nor do I think this means the NSA would be expanded here.
/pedantry
The problem: could Trump do this legally, and legally force Google not to disclose it? What can Trump do with the NSA data? I haven't seen any stories addressing this, beyond vague "concerns".
Furthermore, it misses the larger point that all of their data is readily and easily collected by the NSA already.
Such assertions are counterproductive. They ignore actual statements by google regarding their efforts to improve security against US agency snooping, or Apple's somewhat valiant if ultimately fruitless attempts to defend the iPhone's security against national security interests.
We need to specifically call out bad actors and actions, such as Yahoo's eagerness to CC the NSA on all our emails. We also need to reward positive action with praise. Both are methods to provide the incentives for companies to act in our interests: the companies can point to praise to argue that their principled stand makes financial sense, and the employees deserve the recognition by their peer group.
The wider public is completely ignorant about this, and this should be written up and publicized more.
The term ?critical infrastructure? means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.
The term national security system means any telecommunications or information system Operated by the Federal Government or any contractor on its behalf, the function, operation, or use of which?
involves intelligence activities;"
So it seems to not imply private systems.
As a result of these changes, cyberSpace has emerged
as a new domain of engagement, comparable in
signi?cance to land, sea, air, and space, and its
signi?cance will increase in the years ahead.
This raises the possibility of hacking being treated as an act of war, and the resulting actions. I'm not sure if that's the current status quo – I know there was discussion about it a few months ago. The term ?critical infrastructure? means
systems and assets, whether physical or virtual,
so vital to the United States that the incapacity
or destruction of such systems would have a
debilitating impact on security, national economic
security, national public health or safety, or
any combination of those matters.
This does notably seem to exclude anything related to elections. The term ?national security system? means any
telecommunications or information system
Operated by the Federal Government or any contractor
on its behalf, the function, operation, or use of which:
[...]
is critical to the direct fulfillment of military or intelligence
missions (but does not include a system used for routine
administrative and business applications, including payroll, finance,
logistics, and personnel management applications).
This seems to go out of its way to exclude "personnel management applications", which is curious considering exactly such a system was at center of the second-largest hacking scandal involving the government last year. Review Participants. The Secretary of Defense
shall co?chair the Vulnerabilities Review with
the Secretary of Homeland Security, the Director of
National Intelligence, the Assistant to the
President for National Security Affairs, and the
Assistant to the President for Homeland Security
and Counterterrorism.
The last three are Dan Coats, Michael Flynn, and Tom Bossert, respectively. It's a bit heavy on the military brass and leans towards the political side to the exclusion of anybody with technical credentials (I'd think someone from the NSA or even the private sector could possibly be useful). But I've always been critical when, for example, judges have been accused to be inadequate to adjudicate technical issue – smart people can and will get the information they need to make right decisions. So let's give them the benefit of the doubt.Possibly relevant: it's two cabinet members vs three people reporting directly to the president. I don't know if these committees ever vote on anything, but that could be intentional to allow the President to keep full control over the direction of the investigation (Cabinet Secretaries being traditionally more independent than anyone in the West Wing)
[..]the Secretary of Defense and Secretary
of Homeland Security shall
also gather and review information from the
Department of Education regarding computer
science, mathematics, and cyber security
education from primary through higher education
to understand the ?ll] scope of US. efforts to
educate and train the workforce of the future. Th
Secretary of Defense shall make recommendations
as he sees ?t in order to best position the US.
educational system to maintain its competitive
advantage into the future.
I feel a bit uneasy about Secretary of Defense being authorized to change the primary school curriculum, especially considering the basically limitless scope of "maintain[ing] its competitive advantage into the future". It sounds like they want more math in school. But what if he concludes that the US has plenty of hackers, but they're just not patriotic enough and rather work for Apple (which is actually somewhat true)? [A review shall find ways to incentivice
private enterprises to] invest in cyber
enterprise risk management tools and services; and
adopt best practices with respect to processes and
technologies necessary for the increased
sharing of and response to real-time
cyber threat information.
This is once again pretty broad, but I thought it warrants inclusion because any sharing of data collected by private entities with government agencies has the potential to violate individuals' privacy.Overall this isn't really specific enough to scare me, yet. The bit about education is what most effectively raises my blood pressure, while the focus on military systems at the exclusion of anything election-related is somewhat curious.
Any deficit could be compensated by increasing quotas for people from alternate countries, India, Russia, China all which produce great numbers of people in technical fields and who don't always get choice work in their home countries.
Trump's EO sent a message, and it was the wrong message. People are listening.
This is going to have potentially decades-long ramifications for STEM, tech, and cybersecurity in the US, among other things.
I'd bet, even the people affected directly by the ban, if given the chance would accept, despite your assertion.
When I go to work or live in a diff country, the thought about immigration policies do not enter my mind aside from, can I get the visa.
Once upon a time, I wanted to immigrate to the US but the immigration laws convinced me otherwise. I'm interested in cutting edge things but I found that I could easily work on them without being in the country.
This is just anecdotal and I don't know how many are like me but I do have quite a few friends in Europe who have the impression that the immigration process to the US is over complicated and reject trying to go there out of hand.
[1]: https://en.wikipedia.org/wiki/Immigration_Act_of_1965 [2]: https://en.wikipedia.org/wiki/Historical_racial_and_ethnic_d...
This EO is ordering a review and report, while the immigration EO is ordering actions to address a perceived immediate need. Note also that they are only in effect for 60 and 90 days respectively - this administration is in the "organization" phase still.
"China bad. Big internet computer need antivirus."
The Department of Commerce is rightfully responsible for the creation of the private sector report, because NIST is part of the DoC and NIST is where all of the best security guidance is coming from these days (the DoD adopted NIST's security standards, for example).
HUMINT vs SIGINT. NSA confidence was moderate as they weight SIGINT-based evidence more heavily. The biggest bits of evidence came from human intelligence sources in Russian government (I believe some were arrested for treason due to this).
This is a call for reports to be rewritten by staff sympathetic to the current president's cause. That's the first step to "securing our cyber borders" via VPNs, proxies, vetting of internet companies, etc.
If he asks what "VPN" means, you then say "Virtual Private Network" ... which he still doesn't know and must ask again, making him feel doubly stupid. So when presenting to such people you absolutely must start with baby talk. Instead of VPN start with "tunnels through the internet protected by encryption". If he recognizes this as a VPN he will interrupt you, making him feel smart. And don't mention servers. Say "computers". "Servers" will make him picture waitresses.
Not kidding. This speaking-to-the-idiot-bossman is a skill, especially in politics or military areas where bossman is appointed for reasons divorced from knowledge or background.
And "man" because I've never seen this behavior in a female leader. This is a macho male thing imho rooted in instinct and genetics.