<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Last Watchdog &#187; Obama watch</title>
	<atom:link href="http://lastwatchdog.com/category/obama-watch/feed/" rel="self" type="application/rss+xml" />
	<link>http://lastwatchdog.com</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Wed, 25 Apr 2012 20:37:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Will Congress make Obama&#8217;s Privacy Bill of Rights law?</title>
		<link>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/</link>
		<comments>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/#comments</comments>
		<pubDate>Thu, 23 Feb 2012 15:43:18 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[For technologists]]></category>
		<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12139</guid>
		<description><![CDATA[Getting a divided Congress to pass any hard-edged privacy legislation is the next big hurdle President Obama faces in getting his Consumer Privacy Bill of Rights made the law of the land. &#8220;We urge the Administration to ensure that it carries out this process in a fair and transparent manner, and that consumer voices are [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12140" href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/congress_interior175px/"><img class="alignleft size-full wp-image-12140" title="Congress_interior175px" src="http://lastwatchdog.com/wp/wp-content/uploads/Congress_interior175px.jpg" alt="" width="175" height="111" /></a>Getting a divided Congress to pass any hard-edged privacy legislation is the next big hurdle President Obama faces in getting his Consumer Privacy Bill of Rights made the <a href="http://content.usatoday.com/communities/technologylive/post/2012/02/will-obamas-privacy-bill-of-rights-become-law/1">law of the land</a>.</p>
<p>&#8220;We urge the Administration to ensure that it carries out this process in a fair and transparent manner, and that consumer voices are heard and acted on,&#8221; Susan Grant, Director of Consumer Protection at Consumer Federation of America, adds:</p>
<p>In an unusual move, the White House convened a press conference at 4:30 p.m. Eastern on Wednesday to<a href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/"> announce </a>the details, imposing an embargo – which all media outlets accepted without question – to midnight. Here are the seven rights:</p>
<ul>
<li><strong>Individual Control:</strong> Consumers have a right to exercise control over what personal data organizations collect from them and how they use it.</li>
<li><strong>Transparency:</strong> Consumers have a right to easily understandable information about privacy and security practices.</li>
<li><strong>Respect for Context: </strong>Consumers have a right to expect that organizations will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provide the data.</li>
<li><strong>Security:</strong> Consumers have a right to secure and responsible handling of personal data.</li>
<li><strong>Access and Accuracy:</strong> Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data are inaccurate.</li>
<li><strong>Focused Collection: </strong>Consumers have a right to reasonable limits on the personal data that companies collect and retain.</li>
<li><strong>Accountability:</strong> Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights.</li>
</ul>
<p><strong>Watering down</strong></p>
<div id="attachment_12141" class="wp-caption alignleft" style="width: 102px"><a rel="attachment wp-att-12141" href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/john-simpson92px/"><img class="size-full wp-image-12141" title="John SImpson92px" src="http://lastwatchdog.com/wp/wp-content/uploads/John-SImpson92px.jpg" alt="" width="92" height="134" /></a><p class="wp-caption-text">Simpson</p></div>
<p>&#8220;The real question is how much influence companies like Google, Microsoft, Yahoo and Facebook will have intheir inevitable attempt to water down the rules that are implemented and render them essentially meaningless,&#8221; says John Simpson, spokesman for Consumer Watchdog. &#8221; I am skeptical about the &#8216;multi-stakeholder process&#8217;, but am willing to make a good faith effort to try it.</p>
<p>Simpson and others remain concerned about the Commerce Department&#8217;s role in shaping consumer privacy protections. &#8221; Commerce&#8217;s job — quite correctly — is to promote the interests of business, not protect consumers,&#8221; he says. &#8220;If nothing else, the report demonstrates the growing concern about online privacy. Perhaps this is one of the few issues where true bipartisan action will be possible this year.&#8221;</p>
<p>As proposed by the White House, the bill of recognizes the need to for heightened protections for children and teens on the Internet.</p>
<p>&#8220;If we want to ensure that the Internet economy continues to be strong and vital, consumers need to be able to trust that the information collected about them will not be misused. This announcement sets the stage for that to begin to happen,&#8221; says Ellen Bloom, Senior Director of Federal Policy for Consumers Union, the policy and advocacy arm of Consumer Reports.</p>
<p><strong>Power moves</strong></p>
<p>The next steps will entail Washington D.C.-style power brokering, says Jeffrey Chester, executive director of the Center for Digital Democracy.</p>
<div id="attachment_11936" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-11936" href="http://lastwatchdog.com/google-execs-give-closed-door-briefing-ceo-stays/jeffrey_chester_90px-8/"><img class="size-full wp-image-11936" title="jeffrey_chester_90px" src="http://lastwatchdog.com/wp/wp-content/uploads/jeffrey_chester_90px7.jpg" alt="" width="90" height="122" /></a><p class="wp-caption-text">Chester</p></div>
<p>&#8220;The new framework largely depends on the development of voluntary codes of conduct, to be negotiated between consumer groups and companies like Google, Facebook, Microsoft, Yahoo and others, Chester says. &#8220;Consumers groups will engage in these negotiations in good faith.  But we cannot accept any &#8216;deal&#8217; that doesn’t really protect consumers, and merely allows the data-profiling status quo to remain.&#8221;</p>
<p>Another part of the White House privacy framework calls for the Digital Advertising Alliance to add to its efforts to self-police its members by improving  an existing Do Not Track mechanism many of its members already make available to consumers.</p>
<p>&#8221;   The plan by the DAA to add Do-Not-Track to its self-regulatory system could derail a promising privacy effort by the Worldwide Web Consortium standards group (W3C) that is being designed to give consumers greater control over data collection,&#8221; contends Chester. &#8220;The new DAA scheme will enable companies to continue to collect profiling data on users, and merely prevent the delivery of targeted ads. DAA members are terrified about the development of a DNT system with teeth, which would stop so much data collection, profiling and tracking.&#8221;</p>
<p><strong>California cracks down</strong></p>
<p>On a parallel track, the Associated Press <a href="http://www.usatoday.com/tech/news/story/2012-02-22/california-mobile-apps-privacy/53214500/1">reports</a> that  California is cracking down on invasive mobile apps.</p>
<p>California Attorney General Kamala Harris is calling for the tech giants vying in the mobile space &#8212; Apple, Google, Microsoft, Amazon Research In Motion and Hewlett-Packard  &#8212; as well as thousands of mobile app developers to give people advance warning before extracting and storing sensitive information from smartphones and tablet PCs.</p>
<p>Harris began discussing the need for better privacy protections with six powerful companies that have shaped the mobile computing market, spawning nearly 1 million applications over the past four years, the AP reports.</p>
<p>&#8220;We are assuming everyone is going to cooperate in good faith and not get cute,&#8221; Harris told AP reporter Mike Liedtke.</p>
<p>Harris , a Democrat, is taking her stand out west, at the same time fellow Californian, Mary Kay Bono, a Republican Congresswoman, and several other Republican lawmakers are clamoring for more details about Google and Facebook conduct online tracking. The tech giants put themselves in the spotlight by recently announcing new initiatives to extend how they index and cross-reference data about what consumer do on their PCs and mobile devices.</p>
<p>Google has begun rolling out a new user privacy policy that will make it easier for the search giant to correlate information about anyone who uses multiple Google services, such as Google search, plus Gmail, Google Apps, YouTube, Picasa or Google+.  Facebook is rolling out a new user interface &#8212; Timeline &#8212; that makes it easier to search and digest chronologically-assembled data about a person. Each is trying to out do each other in a race to sell more online advertising. Each insists  they  provide consumers with ample choice and control over such tracking data.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/" rel="bookmark" class="crp_title">Obama calls for a Consumer Privacy Bill of Rights</a></li><li><a href="http://lastwatchdog.com/white-house-issues-historic-call-u-s-privacy-bill/" rel="bookmark" class="crp_title">White House issues historic call for U.S. privacy bill of rights</a></li><li><a href="http://lastwatchdog.com/privacy-advocates-push-google-led-effort-kill-online/" rel="bookmark" class="crp_title">Privacy advocates push back against Google-led effort to kill online advertising rules</a></li><li><a href="http://lastwatchdog.com/google-execs-give-closed-door-briefing-ceo-stays/" rel="bookmark" class="crp_title">Google execs to give closed-door briefing, CEO stays home</a></li><li><a href="http://lastwatchdog.com/critics-house-do-not-track-hearing-skewed-consumers/" rel="bookmark" class="crp_title">Critics say House do-not-track hearing skewed against consumers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Obama calls for a Consumer Privacy Bill of Rights</title>
		<link>http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/</link>
		<comments>http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/#comments</comments>
		<pubDate>Thu, 23 Feb 2012 14:40:32 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[For technologists]]></category>
		<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12126</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 23FEB2012, P1B The White House on Wednesday unveiled a strongly worded “Consumer Privacy Bill of Rights’’ as the linchpin for a drive to get Congress to pass new laws protecting consumers privacy as they surf the Internet. The announcement came as Maryland Attorney General Douglas F. Gansler and attorneys general [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12127" href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/barack-obama150px/"><img class="alignleft size-full wp-image-12127" title="Barack Obama150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Barack-Obama150px.jpg" alt="" width="150" height="151" /></a>By Byron Acohido, USA TODAY, 23FEB2012, <a href="http://www.usatoday.com/tech/news/story/2012-02-23/ftc-consumer-internet-privacy/53213162/1">P1B</a></p>
<p>The White House on Wednesday unveiled a strongly worded “Consumer Privacy Bill of Rights’’ as the linchpin for a drive to get Congress to pass new laws protecting consumers privacy as they surf the Internet.</p>
<p>The announcement came as Maryland Attorney General Douglas F. Gansler and attorneys general from 35 other states sent a letter to Google complaining about a new privacy policy which will give the search giant greater latitude to track people using computers and mobile devices, with no way to opt out of being tracked.</p>
<p>One of the seven privacy rights, unveiled at a press conference by Commerce Secretary John Bryson guarantees consumers the “right to exercise control over what personal data organizations collect from them and how they use it.”</p>
<p>The Commerce Department will now commence a series of meetings inviting privacy advocates, consumer groups and key players in the tech and online advertising industries to hash out “enforceable privacy policies,” Bryson said.</p>
<p>In a statement, President Obama said, “American consumers can’t wait any longer for clear rules of the road that ensure their personal information is safe online. As the Internet evolves, consumer trust is essential for the continued growth of the digital economy. “</p>
<p>Meanwhile, the Digital Advertising Alliance an industry trade group, announced it has begun work on a more visible and effective Do Not Track mechanism to add to a self-policing system in effect for all of the consortium’s members. The Federal Trade Commission separately has backed a call for a Do Not Track system buttressed by new federal laws.</p>
<p>Daniel Weitzner, the White House deputy chief technical officer, said the Obama Administration’s goal is to get Congress to draft and pass new privacy laws using the privacy bill of rights as a framework.</p>
<p>“We now have a much more focused blueprint” Weitzner said. “We’ll use our bully pulpit to get legislation passed based on these principals.”</p>
<p>The push comes as Google, Facebook and Apple have come under fire from some members of Congress and the FTC for tracking consumers as they use their PCs and mobile devices on the Internet, often without asking permission.</p>
<p>The Attorney Generals are seeking a delay is implementation of Google&#8217;s new privacy policy &#8212; which is set to take full effect  on March 1. The AGs now join several members of Congress and numerous privacy advocates and consumer group in protesting the fact that anyone who uses multiple Google services can not opt out of the new policy, which makes it easier for Google to cross reference activities across its most popular services, including search, Gmail, Google Apps, YouTube, Picasa and Google+.</p>
<p>The Obama administration recognizes that “we need to make meaningful changes to preserve consumer trust and confidence,” says Craig Spiezle, executive director of the non-profit Online Trust Association. “At the same time, we need to preserve innovation. Balancing the two is a challenge.”</p>
<p>Getting a divided Congress to pass any hard-edged privacy legislation is another challenge.</p>
<p>&#8220;The real question is how much influence companies like Google, Microsoft, Yahoo and Facebook will have in their inevitable attempt to water down the rules that are implemented and render them essentially meaningless,&#8221; says John Simpson, spokesman for Consumer Watchdog. &#8221; I am skeptical about the &#8216;multi-stakeholder process&#8217;, but am willing to make a good faith effort to try it.</p>
<p>Simpson and others remain concerned about the Commerce Department&#8217;s role in shaping consumer privacy protections. &#8221; Commerce&#8217;s job &#8212; quite correctly &#8212; is to promote the interests of business, not protect consumers,&#8221; he says. &#8220;If nothing else, the report demonstrates the growing concern about online privacy.  Perhaps this is one of the few issues where true bipartisan action will be possible this year.&#8221;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/" rel="bookmark" class="crp_title">Will Congress make Obama&#8217;s Privacy Bill of Rights law?</a></li><li><a href="http://lastwatchdog.com/white-house-issues-historic-call-u-s-privacy-bill/" rel="bookmark" class="crp_title">White House issues historic call for U.S. privacy bill of rights</a></li><li><a href="http://lastwatchdog.com/privacy-advocates-push-google-led-effort-kill-online/" rel="bookmark" class="crp_title">Privacy advocates push back against Google-led effort to kill online advertising rules</a></li><li><a href="http://lastwatchdog.com/consumer-groups-herald-ftcs-call-do-track-mechanism/" rel="bookmark" class="crp_title">Consumer groups herald FTC&#8217;s call for a &#8220;Do Not Track&#8221; mechanism</a></li><li><a href="http://lastwatchdog.com/google-execs-lack-clarity-closed-door-briefing-congress/" rel="bookmark" class="crp_title">Google execs lack clarity in closed-door briefing of Congress</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DHS has slightly reduced role in Langevin’s cybersecurity bill</title>
		<link>http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/</link>
		<comments>http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 18:11:31 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=10537</guid>
		<description><![CDATA[A spokesman for Rep. Jim Langevin, D-R.I., has just contacted LastWatchdog to point out that Langevin&#8217;s cybersecurity bill, which is the major comprehensive one in the House, is not exactly the same as the White House proposal. The major difference is that Langevin&#8217;s bill calls for a  National Office for Cyberspace with the Office of [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_10539" class="wp-caption alignleft" style="width: 160px"><a rel="attachment wp-att-10539" href="http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/jim_langevin175px/"><img class="size-thumbnail wp-image-10539" title="Jim_Langevin175px" src="http://lastwatchdog.com/wp/wp-content/uploads/Jim_Langevin175px-150x150.jpg" alt="" width="150" height="150" /></a><p class="wp-caption-text">Langevin</p></div>
<p>A spokesman for Rep. Jim Langevin, D-R.I., has just contacted LastWatchdog to point out that Langevin&#8217;s cybersecurity bill, which is the major comprehensive one in the House, is not exactly the same as the White House proposal.</p>
<p>The major difference is that Langevin&#8217;s bill calls for a  National Office for Cyberspace with the Office of the President to oversee the security of agency information systems and infrastructure. While the Langevin bill entrusts the Department of Homeland Security with a  significant role, this is a bit different than the White House and Senate versions, which basically center everything in DHS.</p>
<p>Here is a  summary of Langevin&#8217;s proposed cybersecurity  legislation, much of which passed the House last year and was held up because the Senate was planning to cover even more ground in its own bill, but that never got done:</p>
<p><em><strong>Executive Cyberspace Coordination Act of 2011, sponsored by Rep. Jim Langevin, D-Rhode Island<br />
</strong></em></p>
<p><strong>Background</strong></p>
<p>In 2011, the CSIS Commission on Cybersecurity for the 44th Presidency released their second report with recommendations to increase the Federal government’s ability to protect itself and the American public from increasing cyber threats.  Similar to the first report released in 2008, the second edition continues to recommend that the White House take a leadership role and direct national strategy for cyberspace; the public sector enlist the help of the private sector in providing better quality software; and the American public be better engaged in what was previously a private discussion about the digital threats that could disrupt their everyday lives.  The second report notes that after two years, the only significant progress has been the extent to which the American public is discovering the profound effects of the internet on their daily lives, and the importance of government efforts to ensure the safety of our networks.</p>
<p>Many in both the government and private sector are frustrated with the pace of progress in cybersecurity.  Analysts and senior officials in Washington talk about a &#8220;cyber 9/11&#8243; scenario, reflecting a belief that as a nation, we will be unable or unwilling to take any meaningful action on cybersecurity until after a catastrophic event.  The Executive Cyberspace Coordination Act of 2011 will update our nation’s federal cyber policy and bring strong cyber protections to our nation’s power grid and other critical infrastructure.</p>
<p><strong> National Office for Cyberspace</strong></p>
<p>The bill establishes a National Office for Cyberspace (NOC) within the Executive Office of the President to coordinate and oversee the security of agency information systems and infrastructure.  This office will have strong budgetary oversight powers that are backed by financial pay-for-performance authorities, while remaining accountable to Congress. Federal agencies will be responsible for reporting on their information security threats, practices and history to the NOC before submission of their budgets to OMB.  The Director of the NOC would be appointed by the President, subject to Senate confirmation, and will also have a seat on the National Security Council.  This will allow the Director to review agency information security budgets and make recommendations back to the Agencies as well as the President.</p>
<p><strong> Increased coordination for Departments of Defense and Homeland Security</strong></p>
<p>Recognizing the need for closer cooperation between the Departments of Defense and Homeland Security, the bill brings both agency partners to the table to better coordinate their resources but under the appropriate authority of the Office of the President.</p>
<p><strong> Closing Gaps in Authority to Protect Critical Infrastructure</strong></p>
<p>Homeland Security Presidential Directive-7 provides authority to the Secretary of Homeland Security to coordinate the protection of critical infrastructure.  This bill clarifies this authority to include the creation, verification, and enforcement of measures with respect to the protection of the information systems that control critical infrastructure.  This does not give DHS control over private systems, but it allows them to establish risk-informed security practices and standards for critical infrastructure.</p>
<p><strong>Secure Federal Acquisition Policies</strong></p>
<p>The bill requires the development of secure acquisition policies to be used in the procurement of information technology products and services, including a vulnerability assessment for any major system and its significant items of supply prior to development.</p>
<p><strong> Establishing Cyber Challenge Programs for Students</strong></p>
<p>Given the great deficiency of advanced cybersecurity capabilities in today’s workforce, it is imperative that the government support educational programs designed to engage students in the skill sets that they will need to keep our country competitive and safe online into the future.</p>
<p><strong> Enhancing the Public Private Partnership for Critical Infrastructure</strong></p>
<p>The bill requires DHS to work with the Department of Defense and Commerce, the National Institute of Standards and Technology and the sector specific Federal regulatory agencies to establish standards to protect critical infrastructure.  These efforts will also be carried out with the consultation of appropriate private sector bodies, including private owners and operators of the infrastructure affected.  This will ensure that standards are based on the recommendations of cyber experts as well as those with first hand knowledge of the reality of the challenges facing each industry.</p>
<p><strong> Agency Annual Independent Audit</strong></p>
<p>The bill requires agencies to obtain an annual independent audit of their information security programs to determine their overall effectiveness and compliance with FISMA requirements.  Audits would also be required of contractors responsible for managing agency systems or programs on their behalf.</p>
<p><strong> Agency Automated and Continuous Monitoring</strong></p>
<p>This legislation sets forth requirements for agencies to undertake automated and continuous monitoring of their systems to ensure compliance and identify deficiencies and potential risks caused by cyber incidents or threats to an agency&#8217;s information technology assets. These activities are intended to move agencies away from current manually intensive, compliance focused, periodic assessments.</p>
<p><strong> Enhancing the Public Private Partnership for Critical Infrastructure</strong></p>
<p>The bill requires DHS to work with the Department of Defense and Commerce, the National Institute of Standards and Technology and the sector specific Federal regulatory agencies to establish standards to protect critical infrastructure.  These efforts will also be carried out with the consultation of appropriate private sector bodies, including private owners and operators of the infrastructure affected.  This will ensure that standards are based on the recommendations of cyber experts as well as those with first hand knowledge of the reality of the challenges facing each industry.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/us-cybersecurity-report-sats-leading-top-crucial/" rel="bookmark" class="crp_title">U.S. cybersecurity report: &#8216;Leading From The Top&#8217; is crucial</a></li><li><a href="http://lastwatchdog.com/congress-pass-lieberman-collins-cybersecurity-bill/" rel="bookmark" class="crp_title">What Congress must do to pass Lieberman-Collins cybersecurity bill</a></li><li><a href="http://lastwatchdog.com/kill-switch-quandry-president-power-turn-internet/" rel="bookmark" class="crp_title">Kill switch quandry: should president have power to turn off Internet</a></li><li><a href="http://lastwatchdog.com/senate-bill-mandates-strong-federal-role-internet/" rel="bookmark" class="crp_title">Senate bill mandates strong federal role to make Internet safer</a></li><li><a href="http://lastwatchdog.com/cyber-equivalent-monroe-doctrine-needed-repel/" rel="bookmark" class="crp_title">Cyber-equivalent of Monroe Doctrine needed to repel Internet attacks</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disclosure of IMF, Google hacks support cybersecurity legislation</title>
		<link>http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/</link>
		<comments>http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 15:27:23 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[USAToday stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=10512</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 15June2011, P1B The recent rash of disclosures about cyberspying &#8212; aimed at undermining the United States &#8212; comes as the White House is making its third attempt to push through a historic federal cybersecurity law. The timing is no coincidence, some cybersecurity analysts say. After two previous bills went nowhere, [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-10514" href="http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/dhs_270x269/"><img class="alignleft size-thumbnail wp-image-10514" title="dhs_270x269" src="http://lastwatchdog.com/wp/wp-content/uploads/dhs_270x269-150x150.png" alt="" width="150" height="150" /></a>By Byron Acohido, USA TODAY, 15June2011, P1B</p>
<p>The recent <a href="http://www.usatoday.com/tech/news/2011-06-01-gmail-under-attack-from-china_n.htm">rash of disclosures </a>about cyberspying &#8212; aimed at undermining the United States &#8212; comes as the White House is making its third attempt to push through a historic federal <a href="http://thehill.com/blogs/hillicon-valley/technology/150119-langevin-introduces-cybersecurity-bill">cybersecurity law.</a></p>
<p>The timing is no coincidence, some cybersecurity analysts say. After <a href="http://blogs.forbes.com/firewall/2010/06/28/five-critical-flaws-in-the-lieberman-collins-cybersecurity-bill/">two previous bills</a> went nowhere, the White House needs to garner public support for a new law that could equip America for cyberwarfare.</p>
<p><em><strong><a href="http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/">UPDATE -Click here:</a> DHS has slightly reduced role in Langevin bill vs. White House and Senate versions</strong></em></p>
<div id="attachment_10544" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-10544" href="http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/ed-adams_90px/"><img class="size-full wp-image-10544" title="ed adams_90px" src="http://lastwatchdog.com/wp/wp-content/uploads/ed-adams_90px.jpg" alt="" width="90" height="138" /></a><p class="wp-caption-text">Adams</p></div>
<p>&#8220;The best way to do that is to get folks worried that we&#8217;re under attack from some foreign state like China or North Korea,&#8221; says Ed Adams, CEO of <a href="http://www.securityinnovation.com/">Security Innovation,</a> which integrates security systems for government agencies. &#8220;Most people don&#8217;t realize how much of this is premeditated.&#8221;</p>
<p>Recent disclosures of cyberattacks against the International Monetary Fund, Google and several defense contractors coincided with an <a href="http://www.csmonitor.com/USA/Military/2011/0609/CIA-chief-Leon-Panetta-The-next-Pearl-Harbor-could-be-a-cyberattack">unprecedented pronouncement</a> last week by CIA Director Leon Panetta, who warned a U.S. Senate panel that the U.S. needs to take &#8220;defensive measures as well as aggressive measures&#8221; to win at cyberwarfare.</p>
<p>The bill is gaining bipartisan support in Congress. It would establish a framework for distributing billions of dollars for new cybersecurity systems, while placing responsibility for securing cyberspace with the Department of Homeland Security.</p>
<div id="attachment_10523" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-10523" href="http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/jim_langevin90px/"><img class="size-full wp-image-10523" title="Jim_Langevin90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Jim_Langevin90px.jpg" alt="" width="90" height="142" /></a><p class="wp-caption-text">Langevin</p></div>
<p>In an op-ed piece Tuesday in <em>The Hill,</em> Rep. Jim Langevin, D-R.I., the bill&#8217;s chief sponsor, underscored the need to engage Americans &#8220;in a continuous dialogue about threats we face and steps taken to protect them.&#8221;</p>
<p>In that vein, the FBI will help investigate what&#8217;s believed to be the theft of e-mails and other documents related to the IMF&#8217;s role in stabilizing currency exchange rates and keeping global trade in balance.</p>
<p>&#8220;This is part of a wave of economic espionage putting additional pressure on the U.S. economy,&#8221; says Alan Paller, research director at SANS Institute, a cybersecurity think tank.</p>
<p>Mike Baker, president and co-founder of consultancy Diligence, agrees that the threats are palpable. The data thieves&#8217;  agenda could involve terrorists or military goals, such as disrupting critical  infrastructure, or economic cheating to influence currency exchange rates.</p>
<p>&#8220;At the end of the day if I&#8217;ve got more information than you, then I&#8217;m going to win &#8212; however I define winning,&#8221; says Baker.</p>
<p>The recent breach disclosures, which include losses of strategically important data at EMC&#8217;s RSA security division, Lockheed Martin, L-3 Communications and Northrop Grumman,  help provide  supporting evidence for the importance of a strong cybersecurity bill, says Harry Sverdlove, chief technology officer at security firm Bit9.</p>
<div id="attachment_10528" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-10528" href="http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/harry-sverdlove90px-4/"><img class="size-full wp-image-10528" title="Harry Sverdlove90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Harry-Sverdlove90px3.jpg" alt="" width="90" height="122" /></a><p class="wp-caption-text">Sverdlove</p></div>
<p>&#8220;One of the provisions of the cybersecurity bill proposed by the White House is a federal data breach notification statute. Almost every state already has its own data breach notification law, but in today’s global economy, having a consistent set of guidelines that can be enforced across the nation is essential,&#8221; says Sverdlove.</p>
<p>Google recently voluntarily revealed that hackers pilfered information from the Gmail accounts of hundreds of high-profile individuals, including U.S. government officials. &#8220;The dialogue around cybersecurity has definitely become politicized and militarized,&#8221; says Dave Jevans, chairman of IronKey, which secures data and online access.</p>
<p>By pinpointing Jinan, China, as the origination point of the Gmail hack, Google &#8220;elevated the awareness of the enemy,&#8221; says  Sverdlove. &#8220;That could influence both the cybersecurity bill … (and) the rules of engagement for cyberwarfare being debated by the Pentagon,&#8221; says Sverdlove.</p>
<p>Sverdlove, for one, isn&#8217;t convinced that the traditionally tight-lipped  IMF was manipulated into making its disclosure to support the push for a new U.S. cybersecurity law.  Says Sverdlove:</p>
<blockquote><p>When Google announced that the Gmail accounts of specific and highly influential individuals had been hacked, I speculated that the timing was designed to influence public policy. Google made their disclosure in the midst of news on the recent breaches at defense contractors Lockheed Martin, L-3 Communications, and Northrop Grumman. In that case, while the cyber attacks on the defense contractors were described as sophisticated and, at least in the Lockheed Martin case, related to the data breach at RSA months earlier, no one was publicly identifying the source of the attacks.</p>
<p>In the IMF case, however, I don’t believe an international organization within the United Nations has such overt and nation specific motives. More likely, assuming the timing was a conscious decision, the disclosure was more about hiding amidst the noise; there have been so many high profile attacks recently that, while this one might be the most frightening from a global impact perspective, it also just becomes one in a long list of recent breaches (RSA, Lockheed Martin, Citigroup, Sony, PBS, Gmail, …).</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/google-pinpoints-china-orginating-point-successful/" rel="bookmark" class="crp_title">Google pinpoints China as point of origin of Gmail breach</a></li><li><a href="http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/" rel="bookmark" class="crp_title">DHS has slightly reduced role in Langevin’s cybersecurity bill</a></li><li><a href="http://lastwatchdog.com/congress-pass-lieberman-collins-cybersecurity-bill/" rel="bookmark" class="crp_title">What Congress must do to pass Lieberman-Collins cybersecurity bill</a></li><li><a href="http://lastwatchdog.com/us-cybersecurity-report-sats-leading-top-crucial/" rel="bookmark" class="crp_title">U.S. cybersecurity report: &#8216;Leading From The Top&#8217; is crucial</a></li><li><a href="http://lastwatchdog.com/booz-allen-sends-consultants-analysts-cybersecurity/" rel="bookmark" class="crp_title">Booz Allen sends consultants, analysts to cybersecurity school</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/disclosure-imf-google-hacks-support-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Coalition launches global online safety campaign: Stop. Think. Connect.</title>
		<link>http://lastwatchdog.com/coalition-launches-global-online-safety-campaign/</link>
		<comments>http://lastwatchdog.com/coalition-launches-global-online-safety-campaign/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 13:43:04 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=8347</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, Oct. 4, 2010, page 3B SEATTLE â€” Stop. Think. Connect. That&#8217;s what a high-powered coalition of federal agencies, tech companies, retailers and non-profit groups want you to do every time you use the Internet. Today, the group launched a milestone public awareness campaign. The goal: to engrain &#8220;stop-think-connect&#8221; as deeply [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-8355" href="http://lastwatchdog.com/coalition-launches-global-online-safety-campaign/stopthinkconnect_logo225px/"><img class="alignleft size-full wp-image-8355" title="StopThinkConnect_logo225px" src="http://lastwatchdog.com/wp/wp-content/uploads/StopThinkConnect_logo225px.jpg" alt="" width="225" height="56" /></a>By Byron Acohido, USA TODAY, Oct. 4, 2010,<a href="http://www.usatoday.com/tech/news/2010-10-04-cybersecurity04_ST_N.htm"> page 3B</a></p>
<p>SEATTLE â€” Stop. Think. Connect.</p>
<p>That&#8217;s what a high-powered coalition of federal agencies, tech companies, retailers and non-profit groups want you to do every time you use the Internet.</p>
<p>Today, the group launched a milestone public awareness campaign. The goal: to engrain &#8220;stop-think-connect&#8221; as deeply into culture as the seatbelt reminder &#8220;click-it-or-ticket&#8221; and Smokey Bear&#8217;s quote, &#8220;Only you can prevent forest fires.&#8221;</p>
<p>&#8220;Cybersecurity is a shared responsibility for all of us,&#8221; says Joe Sullivan, Facebook&#8217;s chief security officer. &#8220;People will have a better experience on the Internet if they do some basic things.&#8221;</p>
<p>The campaign stems directly from President Obama&#8217;s May 2009 pronouncement that the U.S. will assume a leadership role in making the Internet safer.</p>
<p>Overseen by the Department of Homeland Security, the coalition includes Microsoft, Facebook, Google, Intel, AT&amp;T, Visa, PayPal, Wal-Mart, Costco, the Department of Justice and the IRS among its 28 founding members.</p>
<p><strong>For the common good</strong></p>
<div id="attachment_8360" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-8360" href="http://lastwatchdog.com/coalition-launches-global-online-safety-campaign/michael-kaiser-90px/"><img class="size-full wp-image-8360" title="michael kaiser 90px" src="http://lastwatchdog.com/wp/wp-content/uploads/michael-kaiser-90px.jpg" alt="" width="90" height="118" /></a><p class="wp-caption-text">Kaiser</p></div>
<p>The members understand that each of their respective organizations stands to benefit from a unified effort to advance public awareness about Internet threats, says Michael Kaiser, executive director of the non-profit National Cyber Security Alliance. Each will incorporate the stop-think-connect slogan and theme into existing and new public education initiatives.</p>
<p>Facebook, for instance, is preparing a seven-question quiz, which it will make available sometime this month on its security issues page and home page. It will also donate 35 million ad impressions to promote the quiz, which espouses best practices for passwords and browser use.</p>
<p>This is all intended to slow down cybercriminals, who are having a field day. One estimate puts identity theft losses, much of it due to online scams, at $4.5 billion in the past two years, making it the fastest-growing crime in America, says Kaiser.</p>
<p>Online safety has yet to be elevated to a major public safety issue, akin to the way society views drunk driving, forest fires and seat belt usage, he says.</p>
<p>The coalition selected &#8220;stop-think-connect&#8221; after a year-long process of research, focus groups, polling and government-industry collaboration. That research confirmed that most folks view cybersecurity as a personal responsibility and that any public safety message must address the individual. The founding members voted to go with a message that could be used globally to effect a &#8220;big cultural change,&#8221; says Kaiser.</p>
<p>The group strove to &#8220;simplify the messaging and speak in one voice,&#8221; says Facebook&#8217;s Sullivan. &#8220;If we&#8217;re using the same terminology, it&#8217;s going to make the whole process much more effective.&#8221;</p>
<p><strong>Apple conspicuously absent</strong></p>
<p>One absence at launch: Apple, which has risen to become one the world&#8217;s most highly valued companies, measured by its stock price, on the strength of Internet-connected products such as the iPhone and iPad.</p>
<p>Company spokeswoman Natalie Kerris declined comment.</p>
<p>However, the door remains wide open for Apple and others to join the coalition, says Kaiser.</p>
<p>&#8220;It takes a group of leaders to start a movement,&#8221; says Kaiser. &#8220;I&#8217;m optimistic others will join the effort. We&#8217;re trying to solve the problem for the benefit of all concerned, not just for the benefit of any individual company.&#8221;</p>
<p>By Byron Acohido</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/instilling-proper-cyber-consciousness-in-school/" rel="bookmark" class="crp_title">Instilling proper cyber consciousness in school-aged children</a></li><li><a href="http://lastwatchdog.com/online-christmas-shoppers-spooked-cyberscams-identity/" rel="bookmark" class="crp_title">Online Christmas shoppers spooked by cyberscams and identity theft</a></li><li><a href="http://lastwatchdog.com/call-assume-digital-responsibilty/" rel="bookmark" class="crp_title">A call for each of us to assume digital responsibility</a></li><li><a href="http://lastwatchdog.com/collaboration-needed-slow-advance-cyberthreats/" rel="bookmark" class="crp_title">More collaboration needed to slow the advance of cyberthreats</a></li><li><a href="http://lastwatchdog.com/keeping-kids-safe-line-requires-collaborative-community/" rel="bookmark" class="crp_title">Keeping kids safe on line requires collaborative community efforts</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/coalition-launches-global-online-safety-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>President Obama launches tech contest for 5th-graders</title>
		<link>http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/</link>
		<comments>http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/#comments</comments>
		<pubDate>Fri, 17 Sep 2010 19:48:03 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=8029</guid>
		<description><![CDATA[Advanced Micro Devices and Microsoft were among the co-sponsors who showed up at the White House Thursday, 17 Sept. 2010,Â  to applaud President Obama as he launched the National STEM Video Game Challenge. Students grades 5 through 8 can compete for a cash prizes, as well tech gear from AMD and Microsoft.Â  Another competition is [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-8031" href="http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/amd_contest150px/"><img class="alignleft size-full wp-image-8031" title="AMD_contest150px" src="http://lastwatchdog.com/wp/wp-content/uploads/AMD_contest150px.jpg" alt="" width="150" height="107" /></a><em>Advanced Micro Devices and Microsoft were among the co-sponsors who showed up at the White House Thursday, 17 Sept. 2010,Â  to applaud President Obama as he launched the<a href="http://www.joanganzcooneycenter.org/Initiatives-31.html"> National STEM Video Game Challenge</a>.</em></p>
<p><em>Students grades 5 through 8 can compete for a cash prizes, as well tech gear from AMD and Microsoft.Â  Another competition is geared for college-age contestants; a top cash prize of $25,000 awaits the creator of the top technology with &#8220;high potential to reach underserved communities, such as games built for basic mobile phones that address urgent educational needs among at-risk youth.</em></p>
<p><em>This is another piece of the puzzle that should help shape a new generation of cybersecurity professionals highly trained and motivated to defend the Internet. This program joins the ongoing <a href="http://lastwatchdog.com/recruitment-drive-accelerates-find-young-cyberdefenders/">Collegiate Cyber Defense Competition</a> and The  University of Maryland University CollegeÂ   first-of-its kind cybersecurity bachelorâ€™s and masterâ€™s  academicÂ <a href="http://www.umuc.edu/spotlight/cybersecurity.shtml"> degree program</a> that&#8217;s just getting underway this month.</em></p>
<p><em>LastWatchdog caught up with Allyson Peerman, corporate vice president of AMD Public Affairs and president of the AMD Foundation, just after the President announced the competition.</em></p>
<p><strong><a rel="attachment wp-att-8036" href="http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/allyson_peerman175px/"><img class="alignleft size-full wp-image-8036" title="Allyson_Peerman175px" src="http://lastwatchdog.com/wp/wp-content/uploads/Allyson_Peerman175px.jpg" alt="" width="175" height="254" /></a>LW:</strong> So the concept here is to boost the cool factor of the sciences?</p>
<p><strong>Peerman: </strong>The concept is to make learning about science and math more appealing for students, and a very effective way to get kids excited is through video game development. If kids think the contest is cool, thatâ€™s an added bonus.</p>
<p><strong>LW:</strong> At the end of the day, how will you measure if these contests are a success?</p>
<p><strong>Peerman: </strong>I think the success of this contest will be measured by whether we excite kids about learning math and science. Long term, if some of the contestants opt to pursue higher education and careers in math, science and engineering, then thatâ€™s an even bigger win.</p>
<p><strong>LW:</strong> The U.S. leads the world in, well,  chip technology, among other things. Yet we lag in teaching the basic sciences to our youngsters. How do you explain that?</p>
<p><strong><a rel="attachment wp-att-8045" href="http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/print-4/"><img class="alignleft size-full wp-image-8045" title="Print" src="http://lastwatchdog.com/wp/wp-content/uploads/AMD_logo225px1.jpg" alt="" width="225" height="90" /></a>Peerman: </strong>Young people are craving relevance in their math and science education, and I think we need to find ways to do a better job of providing that relevance. Some of the best in-school and out-of-school programs are helping kids make that connection and helping make it fun. Thatâ€™s one of the reasons<a href="http://lastwatchdog.com/recruitment-drive-accelerates-find-young-cyberdefenders/"> AMD Changing the Game</a> has been so effective; the programs weâ€™ve supported and enabled are making math and science relevant and fun for kids.  Itâ€™s all about meeting young people where they are and inserting the learning on their own turf; in this case itâ€™s through video games.</p>
<p><strong>LW:</strong> Do most CEOs of the top tech companies get that this is important?</p>
<p><strong>Peerman:</strong> Absolutely. Tech industry CEOs know better than anyone how important it is to have a workforce thatâ€™s deeply steeped in math and science education. At AMD, for example, our success as a company directly depends on the strength of our engineering talent pool. AMDâ€™s primary co-sponsors for the National STEM Video Game Challenge are both tech companies, as well. And if you look at the roster of 100 member companies that joined Change the Equation, the tech industry is very well represented.</p>
<p><strong>LW:</strong> How important has it been to have the President get out in front of this?</p>
<p><strong>Peerman: </strong>Itâ€™s hugely important for the President to set the tone and raise the conversation to a level where itâ€™s getting a lot of focus.Â <strong></strong>People have been talking about improving STEM education in the United States for years, but we need concerted, cooperative efforts by enterprise, non-profits and public entities to move the needle. This is a national priority, itâ€™s a priority for corporations and itâ€™s a priority for students.</p>
<p>By Byron Acohido</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/booz-allen-sends-consultants-analysts-cybersecurity/" rel="bookmark" class="crp_title">Booz Allen sends consultants, analysts to cybersecurity school</a></li><li><a href="http://lastwatchdog.com/recruitment-drive-accelerates-find-young-cyberdefenders/" rel="bookmark" class="crp_title">Recruitment drive accelerates to find young cyberdefenders</a></li><li><a href="http://lastwatchdog.com/univ-marylands-cybersecurity-degrees-fill-work/" rel="bookmark" class="crp_title">New cybersecurity bachelor&#8217;s, master&#8217;s degrees designed to fill workforce need</a></li><li><a href="http://lastwatchdog.com/us-cybersecurity-report-sats-leading-top-crucial/" rel="bookmark" class="crp_title">U.S. cybersecurity report: &#8216;Leading From The Top&#8217; is crucial</a></li><li><a href="http://lastwatchdog.com/solera-networks-donation-train-next-gen-cyberdefenders/" rel="bookmark" class="crp_title">Solera Networks&#8217; donation will help train next-gen cyberdefenders</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/president-obama-launches-contest-5th-grade-developers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kill switch quandry: should president have power to turn off Internet</title>
		<link>http://lastwatchdog.com/kill-switch-quandry-president-power-turn-internet/</link>
		<comments>http://lastwatchdog.com/kill-switch-quandry-president-power-turn-internet/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 21:29:53 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Guest Blog Post]]></category>
		<category><![CDATA[Obama watch]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=6958</guid>
		<description><![CDATA[Last year Senators Jay Rockefeller and Olympia Snowe stirred up a bi-partisan ruckus by proposing to give the U.S. president the authority to shut down all or portions of the Internet in the event of an emergency. The so-called Internet &#8220;kill switch&#8221; may &#8212; or may not &#8212; be part of the currently proposed Lieberman-Collins [...]]]></description>
			<content:encoded><![CDATA[<p><em>Last year  Senators Jay Rockefeller and Olympia Snowe stirred up a bi-partisan ruckus by proposing to give the U.S. president the authority to shut down all or portions of the Internet in the event of an emergency. The so-called Internet <a href="http://www.schneier.com/blog/archives/2010/07/internet_kill_s.html">&#8220;kill switch&#8221; </a>may &#8212; or may not &#8212; be part of the <a href="http://www.engadget.com/2010/06/24/the-internet-kill-switch-and-other-lies-the-internet-told-you/">currently proposed </a>Lieberman-Collins Protecting Cyberspace as a National Asset Act, depending on who you talk to. In this guest LastWatchdog guest blog post, Patricia Titus, Chief Information Security Officer, Unisys Federal, sorts through this tempest in a teapot.</em></p>
<p><img class="alignnone" title="Patricia Titus_guest mug" src="http://lastwatchdog.com/wp/wp-content/uploads/patricia_titus12.jpg" alt="" width="133" height="118" />By Patricia Titus</p>
<p>The 2009 proposed bill, introduced by Sen. John Rockefeller (D-W. Va.) and Sen. Olympia Snowe (R-Maine), clearly called for a Presidential internet kill switch and spawned visuals of President Obama sitting in the Oval Office with his hand hovering over an â€œeasy button.â€</p>
<p>Several industry groups spent countless hours debating the language of that earlier bill and its implications, offering guidance to the members and staffers writing the legislation.  In response to this, Sen. Joseph Lieberman (ID-CT) softened the language in his bill and added good clarifying terms.  In my estimation, there is currently no language that would suggest an â€œinternet kill switchâ€ is being placed in the hands of the President.  Rather the language allows decision making within the executive branch to protect our national interests and critical infrastructure, and achieve this through consensus.</p>
<p>The Lieberman bill highlights the need for a public/private partnership to help set policy to define what constitutes a cyber attack.  This is where many of us are skeptical.  For years weâ€™ve been hearing the term â€œpublic/private partnershipâ€ or â€œP-cubed.â€  Weâ€™ve already seen several examples of failed P-cubed.  Without this critical governance partnership, the job of successfully negotiating these policies will surely fail. Lack of a cohesive plan could be catastrophic for the country.  Imagine if a portion of critical infrastructure were taken off the internet, resulting in an interruption of international trade communications.  Economic stability could be placed at risk, and the cascading effect could have far reaching implications for years to come.</p>
<p>Organizations that own our critical infrastructure must be held accountable to immediately determine which stakeholders from both the public and private sector need to participate in negotiations.  Representatives from every relevant sector of government and industry should participate in comprehensive discussions to determine appropriate actions to be taken by the President and to provide guidance.  Perhaps involvement from think tanks would add great value.</p>
<p>Also, we cannot allow the international community to be cut out of this discussion; there could be great implications for them as well.</p>
<p>As always, the devil is in the details. But without participation by both the government and the private sector, this legislation will surely fail.  We currently have a surfeit of cyber security legislation, yet we seem to lack the ability to make much of it stick.  With the pending recess and elections, itâ€™s possible all this work will lead to nothing.  Our country will remain at risk while our new legislators come up to speed.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/lame-duck-congress-pass-cybersecurity-legislation/" rel="bookmark" class="crp_title">Lame duck Congress unlikely to pass cybersecurity legislation</a></li><li><a href="http://lastwatchdog.com/senate-bill-mandates-strong-federal-role-internet/" rel="bookmark" class="crp_title">Senate bill mandates strong federal role to make Internet safer</a></li><li><a href="http://lastwatchdog.com/dhs-slightly-reduced-role-langevins-cybersecurity/" rel="bookmark" class="crp_title">DHS has slightly reduced role in Langevin’s cybersecurity bill</a></li><li><a href="http://lastwatchdog.com/federal-tax-incentives-stem-rampant-data-breaches/" rel="bookmark" class="crp_title">How federal tax incentives could help stem rampant data breaches</a></li><li><a href="http://lastwatchdog.com/congress-pass-lieberman-collins-cybersecurity-bill/" rel="bookmark" class="crp_title">What Congress must do to pass Lieberman-Collins cybersecurity bill</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/kill-switch-quandry-president-power-turn-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV vendor ESET lauded for fostering cybersecurity partnerships</title>
		<link>http://lastwatchdog.com/av-vendor-eset-lauded-fostering-cybersecurity-partnerships/</link>
		<comments>http://lastwatchdog.com/av-vendor-eset-lauded-fostering-cybersecurity-partnerships/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 17:42:21 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=6780</guid>
		<description><![CDATA[President Obama this week praised San Diego-based antivirus vendor ESETÂ  for itsÂ  Securing Our eCity program, citing it as an example ofÂ  how local-level partnerships between the private and public sectors can boost cybersecurity. ESET was awarded &#8220;Best Local/Community Plan&#8221; as part of the Department of Homeland Security&#8217;s National Cybersecurity Awareness Challenge. Speaking at the [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-6781" href="http://lastwatchdog.com/av-vendor-eset-lauded-fostering-cybersecurity-partnerships/eset_ecity150px/"><img class="alignleft size-full wp-image-6781" title="ESET_eCity150px" src="http://lastwatchdog.com/wp/wp-content/uploads/ESET_eCity150px.jpg" alt="" width="150" height="126" /></a>President Obama this week praised San Diego-based antivirus vendor ESETÂ  for itsÂ  <a href="http://securingourecity.org/">Securing Our eCity</a> program, citing it as an example ofÂ  how local-level partnerships between the private and public sectors can boost cybersecurity. ESET was <a href="http://www.securingourecity.org/blog/2010/07/14/soec-goes-to-the-white-house/">awarded </a> &#8220;Best Local/Community Plan&#8221; as part of the Department of Homeland Security&#8217;s National Cybersecurity Awareness Challenge.</p>
<p>Speaking at the award ceremony, Obama alluded to ESET as helpingÂ  toÂ  strengthen &#8221; public/private partnerships both cooperatively on the domestic as well as the international side.â€</p>
<p>DHS handed out seven awards to organizations, business and one individual. This is allÂ  part of DHS working toward crafting a comprehensive national cybersecurity plan, which it is slated to  officially unveiled in October as a part of <a href="http://www.dhs.gov/files/programs/gc_1158611596104.shtm">Cybersecurity Awareness Month.</a></p>
<p>Since 2008, ESET has been rallying San Diego-areaÂ  consumer advocates, business owners, law enforcement investigators, government regulators and elected officials to form partnerships to boost cybersecurity awareness and best practices.</p>
<p>&#8220;The journey to get to this point was beyond exciting,&#8221; says ESET&#8217;s Liz Fraumann, Director of Cybersecurity Awareness &amp; Education. &#8220;With 200 stakeholders representing all segments of the greater San Diego community we are well on our way to achieving our mission of &#8216;making San Diego a place where we can all live, work and play in a cybersecure city.&#8217; â€</p>
<p><em>By Byron Acohido</em></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/us-cybersecurity-report-sats-leading-top-crucial/" rel="bookmark" class="crp_title">U.S. cybersecurity report: &#8216;Leading From The Top&#8217; is crucial</a></li><li><a href="http://lastwatchdog.com/pressure-mounts-naming-white-house-cybersecurity-adviser/" rel="bookmark" class="crp_title">Pressure mounts for naming of a White House cybersecurity adviser with clout</a></li><li><a href="http://lastwatchdog.com/booz-allen-sends-consultants-analysts-cybersecurity/" rel="bookmark" class="crp_title">Booz Allen sends consultants, analysts to cybersecurity school</a></li><li><a href="http://lastwatchdog.com/us-cybersecurity-review-hearing-scheduled-march-10/" rel="bookmark" class="crp_title">U.S cybersecurity review 30-day update: hearing scheduled March 10</a></li><li><a href="http://lastwatchdog.com/global-leaders-meet-dallas-fight-cybercrime/" rel="bookmark" class="crp_title">Global leaders meet in Dallas to form partnerships to fight cybercrime</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/av-vendor-eset-lauded-fostering-cybersecurity-partnerships/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google-NSA collaboration draws alarm</title>
		<link>http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/</link>
		<comments>http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 15:41:39 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=4413</guid>
		<description><![CDATA[Wanted: Inside sales rep to hawk online services to U.S. spy agencies. Perks: Employer has search monopoly &#8212; and warm leads at top spy organizations. That&#8217;s one takeaway of reports that Google has asked the secretive National Security Agency to help track down the cyberattackers who recently breached its network. More on this below. Reporter [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a rel="attachment wp-att-4415" href="http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/nsa-logo/"><img class="alignleft size-full wp-image-4415" title="nsa logo" src="http://lastwatchdog.com/wp/wp-content/uploads/nsa-logo.jpg" alt="" width="121" height="121" /></a>Wanted: </strong>Inside sales rep to hawk  online services to U.S. spy agencies.</p>
<p><strong>Perks:</strong> Employer has search monopoly &#8212; and warm leads at top spy organizations.</p>
<p>That&#8217;s one takeaway of reports that Google has asked the secretive <a href="http://www.nsa.gov/">National Security Agency</a> to help track down the cyberattackers who recently breached its network. More on this below.</p>
<p>Reporter Ellen Nakashima&#8217;s front page <a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html?wpisrc=nl_tech">story</a> in the Washington Post yesterday, 04Feb2010, has rekindled simmering concerns about corporations collaborating in the shadows with the government&#8217;s top sleuth agency. Nakashima&#8217;s report used Deep Throat sources to flush out a substantive development in the finest tradition of Woodward and Bernstein.</p>
<p>You may recall how privacy and civil liberties activists raised a hew and cry  in 2006 after an<a href="http://www.usatoday.com/news/washington/2006-05-10-nsa_x.htm"> investigation,</a> by USA TODAY&#8217;S ace telecom reporter Leslie Cauley, revealed how the  NSA secretly analyzed phone records of tens of millions of Americans.</p>
<p><strong>High potential for abuse</strong></p>
<p>At the time, public <a href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy">backlash</a> was directed mainly at telecom giants AT&amp;T, Verizon and BellSouth for so readily giving up their customers&#8217; private phone records to a government agency.</p>
<p><a rel="attachment wp-att-4416" href="http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/amrit-williams90px/"><img class="alignleft size-full wp-image-4416" title="Amrit Williams90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Amrit-Williams90px.jpg" alt="" width="90" height="137" /></a>In a similar vein, Google, the world&#8217;s dominant search service, amasses data on the surfing habits of most Internet users, and stores vast amounts of sensitive data belonging to users of its popular Gmail and Google Apps online services, says Amrit Williams, CTO of security firm Big Fix.</p>
<p>Because the NSA is an &#8220;opaque intelligence organization . . .the potential for abuse of private information at the intelligence or government level is very high,&#8221; he says.</p>
<p>Google CEO Eric Schmidt did little  to allay the fears of privacy and civil liberty advocates in this <a href="http://www.youtube.com/watch?v=A6e7wfDHzew">interview</a> last December with CNBC financial reporter Maria Bartiromo. Schmidt says on camera:</p>
<blockquote><p>The reality is that search engines, including Google, do retain this information for some time and it&#8217;s important, for example, that we are all subject in the United States to the Patriot Act and it is possible that all that information could be made available to the authorities.</p></blockquote>
<p>It&#8217;s understandable the Google and other corporations might covet the NSA&#8217;s expertise at quelling cyber attacks; the agency possess unsurpassed intelligence gathering technologies and know how, says Jody Westby, CEO of consulting firm Global Cyber Risk and a distinguished fellow at the Carnegie Mellon CyLab think tank.</p>
<p><strong>Mysterious agenda</strong></p>
<p>Yet the cyber attackers who <a href="http://lastwatchdog.com/googles-china-threat-ignite-cyber-cold-war/">breached</a> Google&#8217;s network and some 30 other tech, financial and media corporations in late December and early January used <a href="http://lastwatchdog.com/servers-used-in-google-attacks/">conventional</a> messaging trickery and infection methods. So much so that security firm McAfee with in a couple of days of Google&#8217;s crying foul went public with extensive analysis of the distinctiveÂ  attacks, dubbed<a href="http://www.mcafee.com/us/threat_center/operation_aurora.html"> &#8220;Operation Aurora.&#8221;</a></p>
<p><a rel="attachment wp-att-4423" href="http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/jody-westby90px-2/"><img class="alignleft size-full wp-image-4423" title="JODY WESTBY90px" src="http://lastwatchdog.com/wp/wp-content/uploads/JODY-WESTBY90px1.jpg" alt="" width="90" height="122" /></a>So why tap the NSA when top-notch forensics is readily available from dozens of tech security firms?</p>
<p>&#8220;Company&#8217;s don&#8217;t usually run and ask the government to get involve in their business,&#8221; says Westby. &#8220;The attacks may be more sophisticated than we think. I think they (Google) is really trying to preserve their brand.&#8221;</p>
<p>Gunter Ollman, head of research at security firm Damballa, says there is a &#8220;a high probability&#8221; that Chinese nationals were involved. Whether anyone can prove the Chinese government was behind the attacks is another matter. Attacks that trace back to China are &#8220;state sponsored, endorsed or, at the very least, ignored by the Chinese government,&#8221; observes Ollman.</p>
<p>Given that long-held conventional wisdom, Jeff Chester, executive director of the Center for Digital Democracy, wonders what a search company that collects and distributes public and private data for commercial reasons might gain by turning to a U.S. spy agency for help.</p>
<p><strong>Selling to spy agencies</strong></p>
<p>He points out that Google is actively <a href="http://www.google.com/support/jobs/bin/answer.py?answer=158685">seeking </a>an experienced sales rep at its Washington D.C. offices whose job will be to sell to the intelligence community. According to Google&#8217;s job description, whoever gets the job selling its wares to spy agencies must:</p>
<ul>
<li>Be responsible for the entire sales process from Prospecting to Close.</li>
<li> Lead Generation/outbound calling and warm lead follow up.</li>
<li>Understand Customer Needs and requirements.</li>
<li> Present and articulate advanced product features and benefits of Google Enterprise solutions.</li>
<li> Provide on-line demonstrations.</li>
<li> Close Sales and achieve sales quotas. Be able to sell and differentiate in a competitive environment.</li>
</ul>
<p>&#8220;Another real problem is that Google is working to curry favor with the NSA, CIA, DoD and others in order to sell its services and make greater profits,&#8221; says Chester.</p>
<p>Big Fix CTO Williams offers this takeaway:</p>
<blockquote><p>The NSA is also one of the nations most secretive and opaque intelligence organizations and creating a balance between the information and enablement they can provide to private sector companies, such as Google, and the impact this may have on personal privacy is the major concern. The potential for abuse of private information at the intelligence or government level is very high. Some may argue that national security is more important than personal privacy and that if you have nothing to hide you have nothing to fear, but imagine the impact on one&#8217;s willingness to speak frankly about life threatening medical or legal issues if one felt that the privacy, that we as US citizens are guaranteed and hold so dear, will be compromised for the sake of security.</p>
<p>The United States has always struggled with finding a balance between national security and civil liberties, the question that we need to pose today is are we ready to compromise our liberty for the perception of short-term safety, especially knowing that this relationship sets a very dangerous precedent for the future involvement of Government within evolving commercial technologies of the tomorrow?</p></blockquote>
<p>A Google spokesperson pointed out the company&#8217;s Jan. 12 public <a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">statement</a> about cyberattacks and censorhips in China and declined further comment.</p>
<p><em>By Byron Acohido</em></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/google-vs-china-timeline-search-giant-communist/" rel="bookmark" class="crp_title">Google vs. China timeline: can search giant thwart communist superpower?</a></li><li><a href="http://lastwatchdog.com/advocacy-calls-congressional-hearings-google-spying/" rel="bookmark" class="crp_title">Advocacy group calls for Congressional hearings on Google spying</a></li><li><a href="http://lastwatchdog.com/servers-used-in-google-attacks/" rel="bookmark" class="crp_title">Servers used in Google attacks tied to Peng Yong, Dyn Inc.</a></li><li><a href="http://lastwatchdog.com/pros-report-83-big-organizations-breached/" rel="bookmark" class="crp_title">IT pros: most senior execs are ignorant about cyberattacks</a></li><li><a href="http://lastwatchdog.com/chinese-hackers-seek-us-access/" rel="bookmark" class="crp_title">Chinese hackers seek U.S. access</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/google-nsa-collaboration-draws-alarm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>China&#8217;s cyberspies aren&#8217;t the only ones prowling Internet</title>
		<link>http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/</link>
		<comments>http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 22:33:31 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Obama watch]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=4073</guid>
		<description><![CDATA[Google&#8217;s taking umbrage over Chinese cyberattacks has security experts talking about just how vast and rich the world of cyber espionage has quietly become. &#8220;It isn&#8217;t just China,&#8221; says Matt Moynahan CEO of applications security firm Veracode. &#8220;They are the most aggressive. But all large governments are doing this, as are organized non-government actors.&#8221; Indeed, [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-4090" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/google_chinacampus275px-2/"><img class="alignleft size-full wp-image-4090" title="Google_chinaCampus275px" src="http://lastwatchdog.com/wp/wp-content/uploads/Google_chinaCampus275px1.jpg" alt="" width="275" height="125" /></a>Google&#8217;s taking <a href="http://www.usatoday.com/tech/news/2010-01-14-google-china_N.htm">umbrage</a> over Chinese cyberattacks has security experts talking about  just how vast and rich the world of cyber espionage has quietly become.</p>
<p>&#8220;It isn&#8217;t just China,&#8221; says Matt Moynahan CEO of applications security firm Veracode. &#8220;They are the most aggressive. But all large governments are doing this,  as are organized non-government actors.&#8221;</p>
<p>Indeed, China, Russia, North Korea, Iran, Israel, France, the United States and the United Kingdom are widely known to possess state-of-the-art cyber espionage know-how which is put to use gatheringÂ  economic and military intelligence. Details of covert cyber-ops get discussed at numerous conferences attended by military brass, federal regulators, law enforcement officials, privacy advocates and tech security analysts.</p>
<p><a rel="attachment wp-att-4091" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/jody_westby167px-2/"><img class="alignleft size-full wp-image-4091" title="jody_westby167px" src="http://lastwatchdog.com/wp/wp-content/uploads/jody_westby167px1.jpg" alt="" width="167" height="171" /></a>&#8220;The consensus discussion is that everybody is busy spying on everybody else,&#8221; says <a href="http://www.cylab.cmu.edu/about/bio-westby.html">Jody Westby</a>, CEO of consulting firm Global Cyber Risk and a distinguished fellow at the Carnegie Mellon CyLab think tank.Â  &#8220;These countries are doing it to us, but we&#8217;re also doing it to them.&#8221;</p>
<p>With little fanfare, Secretary of Defense Robert Gates, underscored as much on 24Jun2009. Gates <a href="http://www.defense.gov/news/newsarticle.aspx?id=54890">stood up </a>a new Department of Defense subcommand focused on cybersecurity under the U.S. Strategic Command.</p>
<p>&#8220;This is about trying to figure out how we, within this department, within the United States military, can better coordinate the day-to-day defense, protection and operation of the department&#8217;s computer networks,&#8221; Pentagon Press Secretary Geoff Morrell told reporters at the time.</p>
<p><a rel="attachment wp-att-4107" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/schmidt_obama200px/"><img class="alignleft size-full wp-image-4107" title="schmidt_obama200px" src="http://lastwatchdog.com/wp/wp-content/uploads/schmidt_obama200px.jpg" alt="" width="200" height="229" /></a>And last month, on 22Dec2009, when many of us were doing last minute gift shopping, President Obama named <a href="http://">Howard Schmidt</a> to the newly created post of White House cybersecurity adviser. Schmidt&#8217;s assignment: coordinate economic and military cybersecurity policy.</p>
<p>Schmidt, former Microsoft exec and Bush Administration appointee, is the cyber czar Obama said he would name in a watershed 29May2009<a href="http://lastwatchdog.com/obama-inserts-white-house-leadership-role-secure-internet/"> speech</a>. He is the linchpin personnel piece to Obama&#8217;s plan for taking a leadership role in making the Internet safer.</p>
<p><strong>Cyber black-ops</strong></p>
<p>The cyber-espionage slice of the Internet underground traces its beginnings back to 1993 when the Russians first began developing black-ops teams to concentrate on intelligence gathering using the Internet, says Alan Paller, managing director of The Sans Institute think tank.</p>
<p>China was fully into cyber-spying by 2003 when a Chinese black-ops team, designated<a href="http://lastwatchdog.com/obama-inserts-white-house-leadership-role-secure-internet/"> Titan Rain, </a>roamed deep inside U.S. Department of Defense networks. By 2006, corporations in the U.S. and Europe were  heavily infiltrated by China and other nation-states, says Paller.</p>
<p><a rel="attachment wp-att-4118" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/jonathanevans90px/"><img class="alignleft size-full wp-image-4118" title="JonathanEvans90px" src="http://lastwatchdog.com/wp/wp-content/uploads/JonathanEvans90px.jpg" alt="" width="90" height="108" /></a> A watershed warning came in December 2007.  Jonathan Evans, Britain&#8217;s Director-General of MI5, <a href="http://business.timesonline.co.uk/tol/business/industry_sectors/technology/article2980250.ece">cautioned </a>300 senior execs to guard against Internet assaults from &#8220;Chinese state organizations.&#8221;  Such attacks, Evans warned, are designed to &#8220;defeat best-practice IT security systems.&#8221;</p>
<p>Evans said at the time &#8221;  &#8216;If you&#8217;re doing business in China, your company&#8217;s network and your company&#8217;s lawyer&#8217;s network are very likely being penetrated,&#8217; &#8221; says Paller.</p>
<p>Cyber-intruders today routinely go after corporations, their law firms &#8212; and even their public relations firms, according to an Evans-like <a href="http://business.timesonline.co.uk/tol/business/industry_sectors/technology/article2980250.ece">warning</a> issued by the FBI  last November.  &#8220;They&#8217;re after the corporate playbook,&#8221; says Paller.</p>
<p><strong>Google&#8217;s patience runs out in 4 years<br />
</strong></p>
<p>It took Google this week threatening to pull the plug on its China operations, to shed a brightÂ  light on the rising collateral damage caused by unchecked cyber espionage &#8211;Â  forÂ  economic and military strategic gain. Since agreeing to submit to China&#8217;s censors in exchange for opening a beachhead office in Beijing in January 2006,Â  Google CEO Eric Schmidt has stated on numerous occasions, as recently as October, 2009:Â  &#8220;China has 5,000 years of history, Google has 5,000 years of patience.&#8221;</p>
<p>In Chinese culture, the numbers five, eight and nine are auspicious. The number four is associated with death and considered extremely unlucky. On Tuesday, 12Jan2010,Â  after just four years in Beijing,Â  Google&#8217;s patience died.Â  Citing irritation over cyberattacks it loosely linked to censorship dictates, the search giant said it will no longer adhere to censorship rules as they stood.</p>
<p>Google chief legal counsel David Drummond issued a press release withÂ  details about how Google got hacked and why its patience had run out:</p>
<ul>
<li><em> In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident&#8211;albeit a significant one&#8211;was something quite different.Â  First, this attack was not just on Google. As part of our investigation we have discovered that at least twenty other large companies from a wide range of businesses . . .Â Â  Second, we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists&#8230;</em></li>
<li><em>&#8230; These attacks and the surveillance they have uncovered&#8211;combined with the attempts over the past year to further limit free speech on the web&#8211;have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results&#8230; over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.</em></li>
</ul>
<p><strong>The power of &#8216;no mas&#8217;</strong></p>
<p><a rel="attachment wp-att-4164" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/duran-leonard2_270px/"><img class="alignleft size-full wp-image-4164" title="duran-leonard2_270px" src="http://lastwatchdog.com/wp/wp-content/uploads/duran-leonard2_270px.jpg" alt="" width="270" height="208" /></a>Google had steppedÂ  forward and madeÂ  the same choice boxer<a href="http://www.youtube.com/watch?v=HPoWrWwwi8M"> Roberto Duran</a> made, when Duran could tolerate no more elusive footwork and peppering blows from Sugar Ray Leonard. ThisÂ  seemed to give permission for other Western companies to speak up. Subsequently, Adobe, Northrup and Juniper <a href="http://www.thebigmoney.com/blogs/feeling-lucky/2010/01/15/juniper-northrop-adobe-also-attacked-china">came forward</a> to disclose that they, too, were similarly targeted and breached by presumed Chinese attackers.</p>
<p>Then on Thursday, 14Jan2010, security firm McAfee contacted LastWatchdog with information that several of its customers had been likewiseÂ  hit. McAfee CTO George Kurtz told me hisÂ  researchers had isolated a sample of the attack sequence and malicious codes used.</p>
<p><a rel="attachment wp-att-4167" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/george_kurtz90px/"><img class="alignleft size-full wp-image-4167" title="george_kurtz90px" src="http://lastwatchdog.com/wp/wp-content/uploads/george_kurtz90px.jpg" alt="" width="90" height="127" /></a>According to Kurtz, the attackers began by sending emails and instant messages personally addressed to senior technical managers, enticing them to click on a corrupted Web page link. Clicking on the link activated a freshly-discovered security hole in Internet Explorer web browser, which Microsoft embeds on all Windows PCs. Through this hole the attackers installed a program that allowed them toÂ  take control of the PC.</p>
<p>They thenÂ  &#8220;began probing the network for high value intellectual property,&#8221; says Kurtz. Extracted data was sent to servers hosted by Rackspace, a San Antonio, Tex, web hosting company, and then transferred again to other servers.</p>
<p>This type of hybrid attack wasn&#8217;t at all innovative, nor was the attackers&#8217; use of a security hole that exists in all versions of Microsoft&#8217;s Internet Explorer Web browser. This is referred to as a zero-day vulnerability. Microsoft has patched hundreds of zero-day vulnerabilities since 2004. The software giant said Thursday it has begun work on a patch for the latest zero-day &#8212; the one intruders used to extract data from Google.</p>
<p>There&#8217;s a constant flow of fresh zero-days because computer code is complex. Researchers, known as Whitehats, continually flush them out so they can be patched. Meanwhile, bad guy programmers, called Blackhats, do the same to sell them to cyber-intruders &#8212; for up to $100,000, according to Moynahan &#8212; who use them to steal data before any patches exist.</p>
<p>While their methodology was ordinary, the tools and techniques used by the cyberspies who breached its customers&#8217; networksÂ  were no amateurs. &#8220;It wasn&#8217;t a 13-year-old king who pounded out a quick Trojan,&#8221; says Kurtz. &#8220;There were no corners cut in targeting these specific companies and in escaping detection as long as possible.</p>
<p><strong> CYBERsitter&#8217;s intellectual property stolen, its law firm targeted</strong></p>
<p>At roughly the same timeÂ  McAfee&#8217;s researchers were reverse engineering the Google attack, a live case of Chinese hackers going after a law firms unfolded in Los Angeles.</p>
<p><a rel="attachment wp-att-4157" href="http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/gregory-fayer90px_edited-1/"><img class="alignleft size-full wp-image-4157" title="Gregory Fayer90px_edited-1" src="http://lastwatchdog.com/wp/wp-content/uploads/Gregory-Fayer90px_edited-1.jpg" alt="" width="90" height="133" /></a>Gregory Fayer,Â  a lawyer at L.A. firm Gipson Hoffman &amp; Pancione received an obviously faked email purporting to come from his managing partner. Fayer told LastWatchdog thatÂ  more than a dozen employees at the firm had received similar faked e-mail messages on Monday, 11Jan2010.</p>
<p>A week earlier, Fayer had filed a $2.2 billion lawsuit against China on behalf of Santa Barbara-based CYBERsitter, maker of a Web browser filter parents buy to keep their kids off porn sites. The lawsuit accused China of copying CYBERsitter&#8217;s proprietary program and using it lock, stock and barrell in a misguidedÂ  state-sponsored child-protection censorship service, called Green Dam.</p>
<p>&#8220;The Trojan emails were located within China &#8212; the ISP routing shows there was a Chinese source, &#8221; says Fayer. &#8221; I&#8217;m not sure I can say a lot beyond that. We feel reasonably confident at this point that there was a connection with China.&#8221;</p>
<p><em>By Byron Acohido</em></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/wikileaks-cables-ties-chinas-politburo-operation/" rel="bookmark" class="crp_title">WikiLeaks cables ties China&#8217;s Politburo to Operation Aurora</a></li><li><a href="http://lastwatchdog.com/chinese-hackers-seek-us-access/" rel="bookmark" class="crp_title">Chinese hackers seek U.S. access</a></li><li><a href="http://lastwatchdog.com/google-pinpoints-china-orginating-point-successful/" rel="bookmark" class="crp_title">Google pinpoints China as point of origin of Gmail breach</a></li><li><a href="http://lastwatchdog.com/google-china-coverage-wins-journalism-award/" rel="bookmark" class="crp_title">Google vs. China analysis wins journalism award</a></li><li><a href="http://lastwatchdog.com/google-vs-china-timeline-search-giant-communist/" rel="bookmark" class="crp_title">Google vs. China timeline: can search giant thwart communist superpower?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/chinas-cyberspies-arent-prowling-internet/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

