Bush Names New Cyber Security Czar
goombah99 writes "The Washington Post reports that Cybersecurity "czar" Richard Clarke has confirmed widespread reports that he is leaving the White House, to be replaced by former microsoft security chief Howard Schmidt. He was also part of the Air Force's 'Computer Crime and Information Warfare division'. In related news, the National Strategy to Secure Cyberspace has received Bush's signature and will be released to the public in the next few weeks. Clark's blunt staements on the to the need to avoid erosion of privacy rights is rumored to have rubbed the administration the wrong way, prompting his exit. Anyone know how Schmitt will view the relative security of closed versus open source?"
Nothing says "Security" better to me than "Former Microsoft Security Chief".
What you are not look at is this. This person had the same chance to make good security decisions with Microsoft and HE DIDN'T. Thats the point. Taxpayers should have to spend money on something that Microsoft should be paying for. It is their responsibility to make their product secure, why should tax payers pay for that?
According to his biography here. From his bio, it doesn't sound like he's a dyed in the wool microsoftie.
Instead of making jokes or clamoring about how this is a bad (or good) thing, let's try to figure out what this guy is about.
Any signal out there?
My father is a blogger.
Here are a few legitimate concerns in order of importance (in my mind of course).
1. Blackmail: If this security chief assisted in any of Microsoft's prior bad acts (DR-DOS episode is just one example) and is vulnerable to a criminal charge, he's vulnerable to blackmail. That makes him singularly inappropriate to head a sensitive position such as this one.
2. Incompetence: He's a former head of MS security. His performance is part of the reason that MS had the trusted computing initiative after he left because security was so screwed up.
3. Unwillingness to choose honest dealing with the public over self-interest: He never blew the whistle on MS even though security people generally know where all the bodies are buried. A lot of insecure systems are out there on the Internet in part because he didn't want to make waves. That is not necessarily what you want in a govt. job.
Second, if he was ever head of MS security, he is used to dealing with extremely difficult situations and has handled his share of disasters. Overall, that job would provide great experiance understanding the tradeoffs made between functionality, ease of use and security. Also, a good understanding of how some software companies resolve security issues and how to lead an effort to address security flaws in software. Probably an ideal background overall.
When I hear about a the "Drug Czar" I am reminded about the "war on drugs" that has already cost us plenty of civil liberties and caused a violent and expensive black market for drugs.
The idea of a "Cyber Security Czar" frightens me even more, especially given the fact that the Bush Administration doesn't seem to care jack squat for the rights and privacy of American citizens.
The fact that it seems they dismissed the old Cyber Security Czar because he was actually sticking up for the privacy of citizens (and thus not working towards Bush's vision of a facist-style government in which citizens are reduced to flag-waving serfs with no actual rights) scares me quite a bit.
"You spoony bard!" -Tellah