Obama Will Veto CISPA Unless Changes Are Made
livewire.talkingpointsmemo.com
livewire.talkingpointsmemo.com
Instead, what's happening is that policy people in the Administration believe we need extensive further legislation and rulemaking to ensure that computer systems which are in any way "vital to the national interest" are kept "secure", where a final definition of "security" is sure to rest on "XXX hours of $400/person/hour time from a Raytheon or Lockheed subcontractor".
Restated†:
The GOP:
* Wants Government to keep its hands off private networks
* Does not currently see "cybersecurity" as a subject worth increasing Executive power over (possibly a side effect of who controls the Executive)
* Is, true to form, pursuing a policy of finding minimalistic ways of allowing private industry to self-regulate the problem away
* Is marginally more likely than the Democratic Administration to want to concede privacy concerns to private industry and away from end-users in the service of this goal
The Democratic Administration:
* Generally believes itself to be at (undeclared, cold) war with China over information systems
* Believes Government intervention is going to be required to protect utilities, communications, military, and trading exchange networks
* Is marginally more likely than the GOP to want to enact rules regarding information privacy that protect end-users from private industry --- but not from the Government.
The animating concern regarding CISPA to HN readers is privacy. You should be aware that privacy is a third- or fourth- tier concern of both factions in this policy debate. The real concern is: does private industry tackle the "China hacker problem" itself, or does the Government step in?
Excepting that the only mechanism the government has to add security to any network (private, public, or military) is to purchase blocks of Raytheon hours, I don't even disagree with Obama: the security of many networks that are prima facie vital to the public interest are not only a shambles, but continue to degrade in quality as rounds of purchasing and infrastructure upgrades continue to execute without any serious attention given to software security quality. Look at the "Smart Grid" for the most obvious example, but there are more, such as SCADA networks that are "modernizing" into web-based systems with circa-2005 levels of application security. The Administration is not wrong that CISPA doesn't go far enough --- and again: that is the central conflict here, that CISPA does.not.go.far.enough --- but they have no effective mechanisms to bring to bear to improve the situation either. Their vantage point implies a bonanza for giant government contractors like Lockheed and SAIC.
Be careful what you wish for, especially if all your opinions about CISPA came from EFF. For the first time, my perception is that the EFF is running with this CISPA issue not out of genuine concern over policy, but because it's a vehicle for fundraising off Internet rage. And look at the result: stories where the Democratic Administration looks like a white knight. Wow, is that ever the opposite of what's actually happening.
† (and please note I'm a dollars-donating supporter of the Democratic party; I support public schools and believe in single-payer health care --- but party identification is unavoidable here and vital to understanding what is happening)
Primarily - make anyone receiving federal funding meet a certain standard of security that is tested through periodic auditing.
And, I agree that this is a policy vector that is in the discussion mix. In fact, I think it's much of what the Administration has in mind.
But I strongly oppose this policy, because companies like mine almost certainly wouldn't end up doing the audit work.
Mandated scheduled audit is a race to the bottom. Look no further than PCI-DSS to see the end result of audit done for audit's sake: the winners are the ones who can deliver the most audits with the best cost structure, and once they gain a foothold, the winners can roll their previous success like a snowball to capture more market share regardless of the quality of the end result. The major credit card breaches of the last few years were all audited by reputable PCI-DSS audit firms.
In the Government, the problem is even worse. Government contracting is procedurally tricky. Most companies that do significant government contracting have entire GSA and DoD business units to handle the sales cycle. When it comes to "security" x "services", the overwhelming majority of the dollars go to a few giant companies (Raytheon, Lockheed, SAIC). These companies aren't winning business because they deliver results; whether any of them ever do or don't, you can look at the security of government networks today to see that mandated audit- for- audits- sake isn't working.
What's needed is liability, or at least toothsome penalties.
People respond to incentives. The problem we have today is cleanly illustrating by looking at the incentive structure, which overwhelmingly favors getting ambitious systems fielded as fast as possible, offseted poorly (if at all) by post-deployment risk of any sort. From a careerist perspective: it is much better to get something deployed --- especially if it will appear to work long enough to soak up credit --- than it is to delay deployment for ambiguous "security" objectives. It's so much better that it's still better to get something deployed even if 2 years from now it's going to cough up 20 million credit card numbers.
But CISPA, is just a way to funnel data about every person in the world into a giant government database in secret. It dwarfs the NSA wiretapping scandal and it allows companies to violate their own privacy policies and shelter them from justified lawsuits.
(I don't support CISPA, but not for this bullshit tinfoil hat reason).
The amount of misinformation circulating around CISPA is very dispiriting. People are being deluded into thinking there's some giant conspiracy, and the only reason that's happening is so that unscrupulous interest groups can fundraise or drive ad revenue from rageviews.
Thanks
Before you comment on CISPA, though, be sure to read the entirety of the Electronic Communications Privacy Act of 1986.
Yesterday I was sent the testing methodology requirements document for a specific agency that was littered with footnotes pointing mostly to TAOSSA. That was good to see, at least.
tooth·some/ˈto͞oTHsəm/ Adjective: (of food) Temptingly tasty: "a toothsome morsel". (of a person) Good-looking; attractive.
Good post, though. You seem credible on this issue. I'm one of the uninformed.
The stigma to holding the title "CTO" in any Government is way, way worse.
At any rate, whichever private sector notable is promoted to whatever vanity "technology" role in the government is of little impact to the security of SCADA networks, which are virtually all operated by private companies. The Secretary of Energy had more impact on utility security than any other person in government, and that impact was (from what I can tell) largely negative.††
† Again: I'm sure Tom can commit to whatever branch he wants.
†† I'm not myopic or tunnel-focused on my own field; the social value of getting responsive billing and utilization deployed may end up dwarfing the cost of widespread utility vulnerabilities or breaches. Steven Chu is probably an excellent Secretary of Energy.
Without a doubt no organization in the world knows as much about cybersecurity as the United States government, and up until now all of that knowledge has been held from the private sector behind many layers of classification. Don't you feel that it could be beneficial for the public to have a path for the two groups to work together?
"Without a doubt no organization in the world knows as much about cybersecurity as the United States government"... I've been a practitioner in this field since the early '90s; I know not one other practitioner who shares that opinion.
I think he has proven that statements beginning with the words "I will" must be taken with a large grain of salt. In fact, with CSIPA you can already see it happening -- the weasel words to note are "in its current form".
How can you believe his progressive-leaning statements any longer without being completely naive?
Tone, I'd take it. The same reason you are being downvoted.
As for your "in their current form" innuendo: that would be clever, except that the Administration has for several years communicated loud and clear what their agenda is on this subject. That it is surely something you will not approve of (likelihood that random sampling of HN readers will go apeshit over what the Obama Administration wants to do vis a vis cyberspace: 99.999%) doesn't make it "weaselly". They've been anything but weaselly on this topic.