Schneier Says We Don't Need a Cybersecurity Czar
Trailrunner7 writes "Threatpost.com reports that security guru Bruce Schneier says not only should the NSA not run cybersecurity for the federal government, no one should. 'Really what I think is it shouldn't be anybody. We do better without a top-down hierarchy. Our economic and political systems work best when there isn't a dictator in charge, when there isn't one organization in charge. My feeling is there shouldn't be one organization in charge. Not only shouldn't it be the NSA, it shouldn't be anybody,' Schneier said."
He won't make any friends with the government research grant people with that attitude, though. Seriously, if you only occasionally read what Schneier has to say, and follow his advice and guidelines, you'll be more "secure" than 99% of everyone else. That's because 99% of the people (and companies) don't follow his advice, which is often simple and just requires a little effort and awareness. It's the "effort and awareness" thing that most people find challenging.
I, for one, would be happy with an oversight committee that does its job.
The cybersecurity czar would more likely than not be mostly responsible for making sure that the public perceives that the feds are doing actually something while actually accomplishing very little other than to direct a few contracts to vendors who donated the right amount of money and/or were buddies of his while he was in school
Fixed that for you. Given the track record of the other "czar's" appointed by the Federal Government, you'll forgive me for my skepticism.
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
The problem isn't the basic idea of having a 'czar', which is a good idea. The issue is that we have too many czars appointed, so it has become difficult to keep track of them all and coordinate their efforts. What we need is a single individual given the executive power to oversee all of these czars, and appoint them, discipline them, and fire them at will, so as to centralize control of the czars. That person will be the Czar Czar.
At the Department of the Interior, "Alan Balaran, a court-appointed special master, soon confirmed that a team of hackers could break into the trust accounting system with relative ease and then write checks on the trust funds". Those trust funds were held for the benefit of Native American nations, who filed a multi-billion dollar lawsuit over the security problems.
There are sensitive systems all over.
The second they use the term "Czar", to describe a person in administrative capacity over a regulatory body, they betray the authoritarian and anti-democratic ideology with which they conspire against representative government and individual rights and liberties.
Czar is the Slavic rendering of Caesar. Why anybody sees this as an expediency worthy of trade-off for democratic involvement and oversight is a question I leave you, the dear reader to resolve.
"Speaking the Truth in times of universal deceit is a revolutionary act." -- George Orwell