NIST has revised the draft cybersecurity framework that it released in August. What it published today is a “preliminary cybersecurity framework.” After comments, a final framework will be released in February. I’ve been very critical of the draft released in August. NIST clearly worked to address the criticisms. The result is a mixed bag, but […]
Author Archive | Stewart Baker
Not all big federal IT deployments are disasters
There’s a lot of talk in the press these days about how hard it is for the federal government to do IT right and how the blame for the failures of the healthcare.gov website should fall on the federal procurement system, not the federal managers. As someone who advocated enthusiastically for federal use of relatively […]
Dubious news hook lets me confirm and blog my pre-existing views
I’m a much bigger fan of Girl Talk, whom I’ve blogged about before, than of current copyright law, so it’s hard to resist a chance to talk about both. Girl Talk (actually a fellow named Greg Gillis) produces delightful mashups of hip-hop and classic rock that shed new light on both. Since Girl Talk relies […]
European webmail privacy: Even worse than I thought
I’ve been critical of the claim that European privacy law offers more protection against government surveillance than American law. Apparently not critical enough. An Ars Technica reporter with a pro-privacy inclination decided to seriously investigate using a German email system to get the benefits of European privacy law. His tale of disillusionment revealed three privacy deficits […]
Judges as Bureaucrats
I’d like to offer readers a short quiz on judicial independence. Imagine a field where liability is common but damages vary widely — patent law, perhaps, or disability claims. In this field, there is a specialized court that has attracted Congressional and press criticism because it rules for the plaintiff 99% of the time. Stung by relentless […]
If he does for NSA what he’s done for Obamacare, this could turn out pretty well
From Foreign Policy: Recently, Heritage refused to publish two papers about the National Security Agency’s surveillance programs written by a prominent conservative attorney. Why? Because he concluded that the programs were legal and constitutional, according to sources familiar with the matter. It was a surprising move for a think tank that has supported extension of the Patriot […]
At last, something good comes from the Snowden leaks
It turns out that at least one Washington mugger is a little too well informed about current affairs: An attempted mugging on Capitol Hill was thwarted Monday night by a quick-thinking victim — one who apparently keeps an eye on national security news. The victim, who weighs a petite 95 pounds, explained to the assailant […]
Europe, the Cloud, and the New York Times
The New York The New York Times recently ran a story arguing that, after the Snowden revelations, Europe would have to build its own cloud computing industry to protect European privacy. I was moved to send the Times a letter in response. The Times edits such letters pretty heavily, so I’m sharing it here: You […]
How the NIST Cybersecurity Framework Could Reduce Cybersecurity
In my first post about NIST’s draft cybersecurity framework I explained its basic problem as a spur to better security: It doesn’t actually require companies to do much to improve their network security. My second post argued that the framework’s privacy appendix, under the guise of protecting cybersecurity, actually creates a tough new privacy requirement for industry by smuggling the […]
Is NIST turning weak cybersecurity standards into aggressive new privacy regulation?
Following up on my earlier NIST post, it’s fair to ask why I think the NIST Cybersecurity Framework will be a regulatory disaster. After all, as I acknowledged in that post, NIST’s standards for cybersecurity are looking far less prescriptive than business feared. There’s not a “shall” or “should” to be found in NIST’s August […]
Who’s Afraid of the NIST Cybersecurity Framework?
Business and conservatives have been worried all year about the cybersecurity standards framework that NIST (the National Institute of Standards and Technology) is drafting. An executive order issued early this year, after cybersecurity legislation stalled on the Hill, told NIST to assemble a set of standards to address cyber risks. Once they’re adopted, the order says, other agencies will encourage private […]
Hmmm…
Two straws in the wind for the Snowden flap: 1. When Silicon Valley corporate leaders are grilled over their view NSA by an outraged Michael Arrington, he uncovers a remarkably diverse set of views and ends up complaining, ”I’m not getting anyone to care so far on stage.” 2. When Joseph Menn of Reuters does a […]
Surprise! Tor Privacy Technology Mainly Helps Botnets
According to the MIT Technology Review, a short-lived security flaw in the anonymousTor network allowed researchers to analyze and categorize the traffic that Tor was protecting. The results weren’t pretty: The Tor network is an online service that allows users to surf the web anonymously. Its main benefit is to reduce the chances of network surveillance […]
Video of Stewart Baker’s Recent Cyberespionage Speeches
I’ve been giving speeches lately on cyberespionage, the attribution revolution, and how it helps corporate boards and general counsels to think about the cybersecurity problem without trying to do the Chief Information Security Officer’s job. Video of a recent speech is embedded below: Another version of this speech can be found here. And a somewhat […]
FISA — The Uncanny Valley of Article III
I’m still working my way through all the FISA court material that was declassified today, and acquiring a new appreciation for how hard a journalist’s job can be. But I’ve gotten far enough to start worrying, seriously, about the role we’ve given to the FISA court and what it does to the court and NSA. […]