The use of computers and the Internet in conducting warfare in cyberspace.
Cybersecurity and Cyberwarfare
Privacy Conversation at 2017 TPI Aspen Forum
Rep Darrell Issa (R-CA) wants us to get real about how much faith we should put in encryption. Rep Issa argued on an Internet of Things panel that it’s high time for a straight-talk discussion about how secure popular encryption protocols actually are. ‘The former FBI director [James] Comey came before Congress and swore under oath that he had no ability to get what he needed from the San Bernardino bomber [sic] except by forcing Apple to create an active remote backdoor into the problem,’ Issa said. ‘Now a matter of weeks later, an Israeli company for a million dollars gave him the data he wanted.’ And, Issa pointed out, a few weeks after that, a University of Cambridge professor appeared to crack it again. Said Issa, ‘We have to have a real debate about whether encryptions and protections are real and unbreakable.’
President Donald Trump on the Elevation of Cyber Command
I have directed that United States Cyber Command be elevated to the status of a Unified Combatant Command focused on cyberspace operations. This new Unified Combatant Command will strengthen our cyberspace operations and create more opportunities to improve our Nation’s defense. The elevation of United States Cyber Command demonstrates our increased resolve against cyberspace threats and will help reassure our allies and partners and deter our adversaries. United States Cyber Command’s elevation will also help streamline command and control of time-sensitive cyberspace operations by consolidating them under a single commander with authorities commensurate with the importance of such operations. Elevation will also ensure that critical cyberspace operations are adequately funded. In connection with this elevation, the Secretary of Defense is examining the possibility of separating United States Cyber Command from the National Security Agency. He will announce recommendations on this matter at a later date.
FCC Pledges Openness – Just Don’t Ask to See Complaints
Shortly after Ajit Pai was named chair of the Federal Communications Commission in February, he said he wanted the agency to be “as open and accessible as possible to the American people." Six months on, the agency is falling short of Pai’s lofty goal in some key areas.
Critics are especially concerned about the FCC’s handling of complaints from the public about internet providers and the causes of a May 7 outage of the public-comments section of the agency’s website. "Chairman Pai promised to make the FCC more transparent, but the early returns aren't looking good," said Sen Ron Wyden (D-OR). "The FCC seems more concerned with helping Big Cable than living up to his promise." Many complaints about a lack of transparency at the FCC relate to the commission’s plan to reverse some of its net-neutrality rules, which prohibit internet providers from favoring some forms of traffic over others. The FCC’s proceeding failed to mention that the agency has received more than 47,000 informal complaints about alleged net-neutrality violations since the rules took effect in 2015.
Democratic Lawmakers call for independent investigation into FCC's cyberattack response
Democratic lawmakers are calling for an independent investigation into how the Federal Communications Commission responded to a reported cyberattack in May that crippled the agency’s comment filing system. Sen Brian Schatz (D-HI) and House Commerce Committee Ranking Member Frank Pallone Jr. (D-NJ) sent a letter to the Government Accountability Office (GAO) that cast doubt on the FCC’s version of the incident. “While the FCC and the FBI have responded to Congressional inquiries into these [distributed denial of service] attacks, they have not released any records or documentation that would allow for confirmation that an attack occurred, that it was effectively dealt with, and that the FCC has begun to institute measures to thwart future attacks and ensure the security of its systems,” the letter reads. "As a result, questions remain about the attack itself and more generally about the state of cybersecurity at the FCC — questions that warrant an independent review.”
FCC’s claim that it was hit by DDoS should be investigated, lawmakers say
Sen Brian Schatz (D-Hawaii) and Rep Frank Pallone (D-NJ) called for an independent investigation into the Federal Communications Commission's claim that it suffered DDoS attacks on May 8, when the net neutrality public comments system went offline. "While the FCC and the FBI have responded to Congressional inquiries into these DDoS attacks, they have not released any records or documentation that would allow for confirmation that an attack occurred, that it was effectively dealt with, and that the FCC has begun to institute measures to thwart future attacks and ensure the security of its systems," the lawmakers wrote in a letter to the US Government Accountability Office. "As a result, questions remain about the attack itself and more generally about the state of cybersecurity at the FCC—questions that warrant an independent review."
Sen Schatz and Rep Pallone, the ranking members of the Senate and House Commerce Committees, also said the FCC has not acted to prevent or mitigate the problem of fake comments flooding the net neutrality docket. "[T]aken together, these situations raise serious questions about how the public makes its thoughts known to the FCC and how the FCC develops the record it uses to justify decisions reached by the agency," they wrote to the GAO.
Network Neutrality Fake Out
As the number of online comments in the Federal Communications Commission's network neutrality proceeding soars to record highs, groups on both sides of the debate are calling on Congress to investigate mounting allegations of fake public input. The latest allegations come from the conservative-leaning National Legal and Policy Center (NLPC), which said a whopping 5.8 million pro-net neutrality comments submitted between July 17 and Aug. 4 using the same one sentence appear to be fake. The docket has been plagued for months by charges that many of the comments are duplicates, filed under fake names or submitted without the permission of the people who supposedly signed them. The growing controversy is raising questions about how the comments will be used when the FCC mulls a final order. "It's almost unimaginable how anybody thinks this could do any good," NLPC President Peter Flaherty said.
The Fate of Online Trust in the Next Decade
Many experts say lack of trust will not be a barrier to increased public reliance on the internet. Those who are hopeful that trust will grow expect technical and regulatory change will combat users’ concerns about security and privacy. Those who have doubts about progress say people are inured to risk, addicted to convenience and will not be offered alternatives to online interaction. Some expect the very nature of trust will change.
A Future Ruled by the "Botnet of Things"?
In October 2016, botnets (an interconnected group of electronic devices under the control of a botmaster, or botherder, who can then use the bot army to steal information or carry out scams on a massive scale) made headlines as the instrument behind a distributed denial of service (DDoS) attack against domain name system (DNS) provider Dyn that took dozens of websites, including Amazon, Netflix, Spotify, Twitter, and even the Swedish government, offline for hours. In response to a Request for Comment from the National Telecommunications and Information Administration (NTIA), OTI offered seven recommendations for addressing the threats posed by botnets:
1. Use bug bounty programs to reduce vulnerabilities in IoT products
2. Design devices such that they can be patched and updated
3. Ship items with unique, random credentials, and let users customize login information
4. Establish clear support windows and end-of-life procedures
5. Let users know which security features are available to them on a device—and which are not
6. Connect consciously
7. Support the products that implement best practices
FBI tracked Election Day social media for fake news from Russia
The FBI monitored social media accounts on Election Day 2016 to track Russian efforts to spread damaging false information about candidates. Dozens of agents scanned Twitter and Facebook, where stories promoting conspiracy theories and false claims against Democratic nominee Hillary Clinton had gained traction before the vote. Apparently, agents and security analysts spent the day at the FBI headquarters in Washington watching for security threats they believed were originating from Russia. Another group of FBI analysts and investigators found overseas-based social media accounts linked to the viral stories, which they suspected to be a part of a Russian disinformation operation, apparently.
Information Security: OPM Has Improved Controls, but Further Efforts Are Needed
The Office of Personnel Management (OPM) collects and maintains personal data on millions of individuals, including data related to security clearance investigations. In 2015, OPM reported significant breaches of personal information that affected 21.5 million individuals. The Senate report accompanying the Financial Services and General Government Appropriations Act, 2016 included a provision for GAO to review information security at OPM. GAO evaluated OPM's (1) actions since the 2015 reported data breaches to prevent, mitigate, and respond to data breaches involving sensitive personnel records and information; (2) information security policies and practices for implementing selected government-wide initiatives and requirements; and (3) procedures for overseeing the security of OPM information maintained by contractors providing IT services. To do so, GAO examined policies, plans, and procedures and other documents; tested controls for selected systems; and interviewed officials. This is a public version of a sensitive report being issued concurrently. GAO omitted certain specific examples due to the sensitive nature of the information.
GAO is making five recommendations to improve OPM's security. OPM concurred with four of these and partially concurred with the one on validating its corrective actions. GAO continues to believe that implementation of this recommendation is warranted. In GAO's limited distribution report, GAO made nine additional recommendations.