Author Archive | Stewart Baker

Testifying on cybersecurity before the Senate Judiciary Committee

I’ll be testifying this morning before the Senate Judiciary Committee’s subcommittee on crime and terrorism. My testimony will touch on the Attribution Revolution in cybersecurity, the need to move from attribution to creative forms of retribution, and the need to give victims more leeway to investigate the hackers who attack them. Here are some excerpts: That […]

Continue Reading 0

Of course, that explains everything …

Most people know that China’s largest telecommunications supplier, Huawei, has been largely excluded from the US market because of official allegations that it will enable Chinese cyberespionage and wiretapping. What none of us realized, apparently, is the real reason that Huawei’s been forced out. Luckily, the company’s head of Cyber Security, John Suffolk, is happy […]

Continue Reading 0

Privacy surprises … that somehow aren’t

If you’re looking for laws of unintended consequences, you can’t do better than privacy.  Take two examples plucked from last week’s front pages: Here’s the New York Times reporting on massive fraud in the billion-dollar settlement of claims that the Agriculture Department discriminated against black, Hispanic, and female farmers: “It was the craziest thing I […]

Continue Reading 0

Why wasn’t Tsarnaev searched at the border?

There’s been considerable speculation about how the government handled Tamerlan Tsarnaev’s return from Russia. Before Tsarnaev’s return, both the FBI and the CIA had suggested that Tsarnaev belonged in the government’s classified terrorist database, and according to some reports an alert for Tsarnaev was entered into the DHS border system. Yet according to Secretary Napolitano […]

Continue Reading 0

George Gershwin, CISPA, and the President’s Veto Threat

This White House sure knows how to snatch defeat from the jaws of victory. The President’s threat to veto CISPA (Download Cyber – S A P ) will likely kill cybersecurity legislation for the year. Here’s the sentence that I believe will eat away at support for the legislation among its last defenders in Silicon […]

Continue Reading 0

Luxembourg: The Steve McQueen of Cybersecurity

Here’s the scant good news on cybersecurity It’s getting harder for attackers to hide.  The same security weaknesses that bedevil our networks can be found on the systems used by our attackers. A shorter version is something I call Baker’s Law: “Our security sucks.  But so does theirs.” That’s good news because, with a little gumption, […]

Continue Reading 0

Will CISPA amendments hurt cybersecurity?

The House intel committee is amending CISPA to address privacy criticisms.  Politico’s Tony Romm reports on some of the likely amendments: Still another amendment specifies clearly that CISPA won’t allow companies to “hack back” their hackers in pursuit of stolen trade secrets … Really?  A government that can’t protect us is debating new measures to make […]

Continue Reading 0

Cybersecurity Meets the WTO

The continuing resolution that I wrote about yesterday could have a big impact on the federal government’s procurement of IT equipment from Chinese companies. As described in an earlier post, the resolution includes a provision that bars purchases of an “information technology system” that was “produced, manufactured or assembled” by entities “owned, directed, or subsidized by the People’s […]

Continue Reading 0

Congress Bulls into China’s Shop

Anger over Chinese cyberespionage continues to mount in Congress, and it’s beginning to show in legislation. Not just the bills Congressmen introduce, the ones Congress passes.  Demonstrating remarkable bipartisan angst about Chinese hacking and the risks in Chinese high tech equipment, Congress has added tough sanctions to the continuing resolution that funds the federal government […]

Continue Reading 0

How’s that “law of cyberwar” thing working out for you?

Can cyberwar be limited by international law and diplomacy?  Those who believe in international “norms” for cyberwar usually argue that cyberattacks on financial institutions are beyond the pale. For example, Harold Koh has declared the State Department’s view that cyberwarriors “must distinguish military objectives … from civilian objects, which under international law are generally protected from […]

Continue Reading 0

A Real Life Prison Break for Ugly Gorilla?

I’ve never thought there was much romance in cracking the networks of American companies and agencies, but a recent LA Times article underlines just how dreary it can be. The piece is based on a blog diary kept by Wang Dong, identified in recent reports as the notorious Ugly Gorilla, whose code has been found in […]

Continue Reading 0

Hollywood discovers hacking

That might sound like breaking news from 1983, but this time we’re not talking movie plots, we’re talking business.  Specifically how Chinese cyberespionage could affect Hollywood’s bottom line.  The Hollywood Reporter asked me to talk about that impact in a guest column, out this week.  Here’s some of what I said: Hollywood might be blinded by […]

Continue Reading 0

Hackback Debates — The Rematch

Last fall, Orin Kerr and I engaged in an online debate over the Computer Fraud and Abuse Act — specifically whether it is lawful for the victim of computer crime to follow his stolen data into networks controlled by the thief. The debate spread across several posts and into the comments, but it’s been pulled […]

Continue Reading 0

Attribution? Check. Retribution? Coming up.

Anyone who’s followed my recent posts on state-sponsored hacking knows that I’ve been preaching the importance of attribution.  (See here, here, and here.) Well, I have to say that attribution is coming along pretty well, as witness the devastating Mandiant report and the risible Chinese response. (My personal favorite: “A spokesman for China’s Ministry of […]

Continue Reading 0

Powered by WordPress. Designed by Woo Themes