The effort to pass cybersecurity legislation in the Senate is looking more and more like a wreck. Claims that it will create an Internet “kill switch” still poison the air. The Chamber of Commerce is being especially hard to please, rejecting not just Collins-Lieberman but also a Kyl-Whitehouse compromise. Maybe it’s time for Sen. Collins […]
Author Archive | Stewart Baker
Is network offense the best network defense?
Joseph Menn has a good Reuters article on a growing sentiment within network security circles: Frustrated by their inability to stop sophisticated hacking attacks or use the law to punish their assailants, an increasing number of U.S. companies are taking retaliatory action. Known in the cyber security industry as “active defense” or “strike-back” technology, the […]
House Intelligence Committee investigates Chinese telecom firms
The House Intelligence Committee is conducting a remarkably detailed and bipartisan investigation of ties between the Chinese government and two Chinese telecom equipment giants, Huawei and ZTE. These companies have been the objects of widespread security fears that their equipment would enable Chinese interception of US telephone calls, expanding American cybervulnerabilities from computer networks to all communications. […]
UK bill hits both libel tourism and anonymous abuse
GOOD NEWS: Great Britain appears ready to end libel tourism: The overall aim of the Defamation Bill is to end ‘libel tourism’ and protect free speech. In recent years London has become the libel capital of the world. Critics say this is because regulations favour claimants and that the very high costs involved in defending […]
Privacy law rots from the head
Privacy kills. Fish, this time. The main difference between US and European data protection law is this: in the United States, laws are usually written to solve a particular privacy problem, whereas in Europe all personal data is broadly protected by a set of grand principles. Both privacy regimes produce plenty of unanticipated consequences and […]
Google outs state-sponsored cyberespionage (again)
Google has begun notifying individual Gmail account-holders that they may be the targets of “state-sponsored” attacks: Google doesn’t say how it knows that particular accounts have been targeted, or even which “state” is sponsoring the attacks. But here’s my guess. Computer security experts have learned a lot from analyzing the most pervasive attacks. The attackers […]
How Antivirus Software Fails
Mikko Hypponen of F-Secure, an antivirus company, has a revealing post on the limits of antivirus software. He notes that Flame, Stuxnet, and Duqu were all reported to antivirus firms months or years before they were flagged as malware. He blames the failure of his company and other antivirus firms on the sophistication of Western intelligence agencies: “As far […]
“Confront and Conceal”: New Stuxnet Revelations
Despite serious concerns about the damage that these leaks will do to national security, I confess to being fascinated by the New York Times’s compelling and highly plausible account of the Stuxnet worm’s origins. Drawn from a book due to come out next week, the article says that Stuxnet originated in the Bush Administration, was […]
White House announces private sector botnet initiative
Showing the power of the bully pulpit, the White House today announced a pilot program in which ISPs will share data about botnets with financial institutions. ISPs also announced a set of principles for fighting botnets. This is a good thing. If your computer belongs to a botnet, you shouldn’t be engaged in online banking. […]
Going through high school shorter than Mitt Romney
Browsing my high school yearbook for a family celebration this weekend, I discovered that I may have actual information about a burning issue in the Presidential campaign — namely, whether Mitt Romney was once a high school bully. That’s because I went to high school, or at least grades 7 through 10, with him. We […]
NPR Discovers Privacy Victims, Buries Lead
NPR aired what it must have seen as a heart-warming story about how social media is making it possible to do medical research on people with rare conditions, such as Katherine Leon, who at the age of 38 suddenly suffered a severe heart attack caused by spontaneous coronary artery dissection, or SCAD. It is heart-warming, but […]
Well, that’s a relief
It turns out that the backdoor found in Chinese-made US military chips by Cambridge researchers might not be evidence of a planned cyberattack. The backdoor is probably there, all right, say other researchers, but that’s because backdoors are built into many field-programmable chips for debugging purposes. Once installed, they can’t be easily removed. Instead, manufacturers try to […]
EU competition bureau creating yet another intellectual property regime?
I was struck by the EU competition bureau’s recent threat to punish Google because of “the way Google copies content from competing vertical search services and uses it in its own offerings.” (Vertical search services are specialized search engines like Yelp and Kayak that help people find local restaurants or cheap flights and rental cars.) […]
Big Data and Network Security
As far as I can tell, one of the few network security tools getting better at the speed of Moore’s Law is network monitoring and audit. Modern networks throw off vast amounts of data as users go about their daily business. It is often possible to find the telltale signs of network intrusion by watching […]
3D printing is cool — but not yet sexy
The promise of perfectly personalized products manufactured by 3D printers is on the horizon, but this 3D-printed bikini — supposedly the “world’s first ready-to-wear, completely 3D-printed article of clothing” — looks surprisingly uncomfortable and badly fitted to me. And believe me, I looked closely. I take seriously my responsibilities as a technology commentator. And in that […]