Watch For A New Set Of CyberSecurity Laws
SuperDuG writes "According to a story on PCWorld.com the Congressional subcommittee dealing with cybersecurity will be researching and legislating new cybersecurity laws. The Chair, Adam Putnam says 'We want to put something out there that makes sense, that's balanced, that accomplishes the same goals, without it being this headlong rush to prove that we're doing something for our constituents because we were asleep at the switch when there was this digital Pearl Harbor.' Perhaps it wouldn't hurt if we all took a part and Contacted Representative Putnam about how well thought out other cybersecurity laws like the DMCA have 'helped out' and were 'thought out.' At least they're actually thinking before they legislate, and it seems they're open for suggestions."
An interesting idea in theory, but delivering *100%* secure software -- at least on the grand scale of operating systems -- is a practical impossibility. Even OpenBSD, arguably the most secure operating system out there, has had at least one large remote hole in the last few years. A law like this would have the effect of practically halting software advances in this country, unfortunately.
Politicans already overuse Pearl Harbor in situations where it is actually relevant, such as national defence. It's used for a catch phrase to mean if we let down our guard, we will be overwhelmed at any moment. It's a way to not explain exactly what they mean, which serves them well because the situation in intelligence gathering and warfare now is so different than it was in 1941.
So even using it in that context is a bit of a "Bavarian Fire Drill". Using the threat of a hacking attack and associating it with Pearl Harbor is even sillier. If this country faces a bad hacking attack, or major attempt on our internet infrastructure, what will it mean? I'll have to sklp read people's Live Journals for a few days? Some web pages will get defaces? Some banks records will get broken into? e-Mail will get choked with wormed messages? None of these things are very pleasent, but I don't think we will see a cyber attack that leaves thousands dead and billions of property smoking and burnt. In fact, I think comparing the effects of some "lost productivity" to an event like Pearl Harbor is somewhat tasteless.
Hopefully I didn't put any [] around my words.
we were asleep at the switch when there was this digital Pearl Harbor
Riiight, and passing a law through congress that made it illegal for Japan to attack the US would have stopped Japan how exactly?
New laws are not required, everything that should be illegal is under current law. Laws do not stop terrorists or foreign governments from attacking. It won't even stop ordinary people from attacking.
-- iCEBaLM
How can they compare the attacking of some computer systems to an attack that left 2,300 people dead?
Karma: Can only be portioned out by the Cosmos.
Once upon a time a messenger service discovered that by having all their messengers wear rocket powered roller skates they could deliver things in record time, beating their competitors into the dust. Soon every messenger service relied on rocket powered roller skates, the original company went broke and a few larger companies dominated the delivery business. People hardly shopped or went to the bank any more. Everything was handled by messengers wearing rocket powered roller skates. Commerce doubled and the economy briefly soared.
Then some asshole discovered that by dropping pencils on the sidewalk you could cause spectacular crashes. Packages were lost, messengers and pedstrians were killed, and commerce was interrupted. All manner of security precautions were invented. Radar-equipped skates appeared. The sidewalk hackers used hair-fine tripwires. Police and private guards patrolled the streets. The hackers went through the sewer system.
Congress passed some laws making it a crime to possess anything that could be placed on a sidewalk to trip up a rocket powered roller skater. Civil libertarians were outraged, but what else could be done?
Doing away with rocket powered roller skates was unthinkable, because everything would go back to being unbearably slow. Banning non-messengers from the sidewalk was similarly unthinkable. Building special secure sidewalks just for rocket powered roller skaters would be too expensive. The whole beauty of rocket powered roller skates was that they could use existing sidewalks.
The real problem was that the messenger companies had all jumped into relying on rocket powered roller skates without anticipating their weaknesses. They never really came up with a solution, just ways to stay one step behind the problem. But who could blame them? They had to stay competetive. It was always the hackers' fault. Maybe if enough of them got thrown into prison they would learn their lesson. If ordinary people had to live their lives differently, well... they were the ones who insisted on fast deliveries weren't they? The industry was just responding to demand.
Eventually ordinary people just didn't use the sidewalk anymore. It would expose them to too much danger and litigation. For all their communications and physical needs they relied exclusively on messengers on rocket powered roller skates, never leaving their homes. And they lived happily ever after.
I've put some thought into that statement "digital pearl harbor". Most people equate "cyberterror" with the idea that a terrorist might shut down a power grid, phone system, etc.
But we've had examples in the past of the power grid going down on a large scale (most of the northeastern US, including NYC, something like 30 years ago) and significant problems with the phone system (AT&T Long Distance outage). Both were thought to be malicious acts (the Russians and "the bomb" were initially accused of the power problems, hackers the AT&T outage) at first. But both were actually caused by bugs/glitches in the systems themselves, and were resolved shortly thereafter.
These two examples seem consistent with Bruce Schneir's explanation of how such outages are only temporary, and how its much easier for a terrorist to bomb a power plant or phone switching station rather than hack into it.
The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
Who cares? We're both screwed anyway. In Canada, you'd better be mortally threatened if you want treatment today. In America, you'd better have insurance or we're going to ship you down to the county hospital and hope you don't die en route.
Why did Kevorkian go to jail for euthanasia? Our HMO's have been letting people die for decades.