Slashdot Mirror


FBI's Top Cyber-cop Says We're Losing the War Against Hackers

New submitter sienrak writes "Shawn Henry, who is preparing to leave the FBI after more than two decades with the bureau, said in an interview that the current public and private approach to fending off hackers is 'unsustainable.' 'I don't see how we ever come out of this without changes in technology or changes in behavior, because with the status quo, it's an unsustainable model. Unsustainable in that you never get ahead, never become secure, never have a reasonable expectation of privacy or security,' Mr. Henry said."

134 comments

  1. Yay by Anonymous Coward · · Score: 0, Offtopic

    Hack the planet....

    1. Re:Yay by Anonymous Coward · · Score: 0
      They're hacking Microsoft products, of course.

      For the good of humanity, the US DoJ needs to split Microsoft up, strip them of their patents and force them to abandon their proprietary formats and APIs. The world needs interoperability, not lock-in,

    2. Re:Yay by Anonymous Coward · · Score: 0

      People are allowed to run their business within the scope of the law. If you're going to split up Microsoft for bundling Apps with an OS then you're setting a very dangerous anti-business precedent. Might as well go after the shampoo companies for suggesting you use their conditioner for best results. You don't have to use their conditioner, but you don't have to use MS apps just because you're running Windows. In fact, you can write all your own drivers, services, APIs and applications and make your own secure version of Windows. It is possible to do all that, so there is no Anti-trust to speak of. You aren't forced into anything, you are just stupid. Evidence of your stupidity is the fact you want to enact policy to fix a problem that can't be solved through policy.

    3. Re:Yay by Anonymous Coward · · Score: 0

      Evidence of your stupidity is the fact you want to enact policy to fix a problem that can't be solved through policy.

      "The Bell System divestiture, or the breakup of AT&T, was initiated by the filing in 1974 by the U.S. Department of Justice of an antitrust lawsuit against AT&T."

    4. Re:Yay by Anonymous Coward · · Score: 0

      And yet, AT&T is still king of wireless in the US.
      Told you it couldn't be fixed with policy.

    5. Re:Yay by Anonymous Coward · · Score: 0

      They don't have control of personal telecommunication and have to compete in many areas. Problem solved.

    6. Re:Yay by Pubstar · · Score: 1

      Wasn't this the exact comment that was posted in the MacOS article?

  2. Given the previous FBI story... by 3seas · · Score: 5, Insightful

    Well of course they are losing the battle..... a house fighting against itself will fall.

    1. Re:Given the previous FBI story... by zero.kalvin · · Score: 4, Insightful

      It is in the nature of the fight itself. Anyone anywhere can come up with a way ( if smart and motivated enough) to hack anything anywhere, it is completely different from invading another country or defending your own. Individuals can't be suppressed the way you subdue hostile forces. The matter is unless you install a spy cam inside the brains of everyone I don't see how the hacking war can be won. ( and even in this case someone would hack it ! )

    2. Re:Given the previous FBI story... by poetmatt · · Score: 5, Insightful

      Nah, see it's just a word replaced incorrectly. they're losing the war against profit. "Cybercrime" is just the justification. They want people to spend more money under the guise of counter-terrorism.

    3. Re:Given the previous FBI story... by Jeremiah+Cornelius · · Score: 1

      Thank you. They don't seem to be worried about the threat to expectation of privacy from Facebook and Google... Let alone that from the FBI or NSA.

      You were born in sector X. Sector X has the dominion over you!

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    4. Re:Given the previous FBI story... by DCFusor · · Score: 3, Interesting

      They are losing the battle, but we're doing just fine, thanks. Their definition of the battle is that they effortlessly control everything and have "Total Information Awareness" which, of course, is not the battle we are in ourselves at all.

      --
      Why guess when you can know? Measure!
    5. Re:Given the previous FBI story... by Anthony+Mouse · · Score: 5, Interesting

      Anyone anywhere can come up with a way ( if smart and motivated enough) to hack anything anywhere, it is completely different from invading another country or defending your own.

      You're completely right. And the idea of having some incompetent bureaucracy with the power to spy on everyone and shut down the internet is is totally insane.

      But let's not just complain about it, shall we? Why don't we do one better?

      Making systems totally secure is a pipe dream, but we can certainly make them more secure. And entirely without a surveillance bureaucracy.

      The key is to understand that secure software is a market failure: Nobody wants to pay for security until after they get hacked, which means software developers have the wrong incentives. The one that goes out of their way to do security right end up going out of business because they get beat to market by the ones that ship the first code that compiles. But let's resist the knee jerk government reaction to this, which is to pass laws telling everybody what to do. That isn't what's needed here -- the result of any sanctions will be a "teaching to the test" problem where developers do the bare minimum to avoid liability while not actually making secure software, and meanwhile software development is made far more expensive due to regulatory compliance burdens. So forget about that.

      What would actually work? SE Linux. It was produced by the NSA, it's open source, and it makes things more secure. Why don't we spend the money on that sort of thing? Use the carrot, not the stick. Have the NSA provide free, voluntary security audits to major infrastructure providers. Have them produce more software in the nature of SE Linux -- things designed by all those genius cryptographers they already employ, which can subsequently be adopted by everyone everywhere and make things more secure. Fund more software like TOR which can protect privacy, to get such things to the point that they're fast and efficient enough for regular use by everyday people (and screw over enemy countries that censor and oppress in the process). Provide incentives for the more rapid adoption of technologies that increase security, like DNSSEC and IPv6.

      These are the things that have the potential to actually work. If they're actually serious about improving security, and Something Must Be Done, let it be that. Because the last thing we need is another hopeless regulatory bureaucracy.

    6. Re:Given the previous FBI story... by justforgetme · · Score: 2, Interesting

      Correct, the solution is not to battle the effects (hacking, hacktivism, organized digital crime) but the things that create the need for them (IP, DRM, Patents, Coprorational governance of the world wide market). Still hacking and hacktivism will continue to exists as long as there is a reason to tinker and protest.

      Hacking was never the bad guy, it is the establishment being afraid of change that instigates it.

      --
      -- no sig today
    7. Re:Given the previous FBI story... by justforgetme · · Score: 3, Insightful

      Of some concern may be the following:
      A "loosing the battle" statement, in modern history, is often precedent to a mass disruption of civil rights.

      So I would like to see what this one will conjure. OSs with required government back door? Ban on cryptography?

      --
      -- no sig today
  3. So trust us! by Anonymous Coward · · Score: 0

    so trust the government with our privacy and security they will say...

  4. Huh? by rossdee · · Score: 0, Redundant

    Who is this "we" ?

    Some of us aren't part of the Government...

    1. Re:Huh? by F69631 · · Score: 0

      You will be one day, so I recommend staying up to date on all the important issues.

    2. Re:Huh? by Iniamyen · · Score: 1

      Sorry, I don't understand the joke. Can you enlighten me? Thanks in advance.

    3. Re:Huh? by meow27 · · Score: 1

      he is basically calling the parent poster a minor, since in the united states, it is illegal [AFAIK even for the government] to distribute the identity of minors

    4. Re:Huh? by F69631 · · Score: 3, Insightful

      The OP lives in USA which is - last time I checked - a representative democracy. It might be imperfect one (=difficult to break the two-party system) but it's still a democracy... which means that The Government is just the set of institutions that The Population has built. Saying that you aren't part of the government in such a state is saying that you can't influence the decision making process, which probably means that you are too young to vote.

      It doesn't help if you say "I'm a LIBERTARIAN. I want the fed abolished...". Even ignoring all arguments about how you can't exclude yourself from a group just because you don't believe in everything it has democratically decided... This is FBI we are talking about. Even the most idealistic libertarians would say "The government has only one job: Keep us safe from the bad guys" (i.e. power to use violence is the only true natural monopoly) so this is perhaps the one institution that libertarians would retain.

    5. Re:Huh? by Pubstar · · Score: 1

      If by 'The Population' you mean 'large corporations' then yes, you are correct.

  5. Slashdot, non-news for nerds. by Anonymous Coward · · Score: 0

    Not news in anyway shape or form, unless, of course, for some reason you thought the Feds had a handle on things. BAHAHAHA.

  6. Of course he would by Hatta · · Score: 4, Insightful

    Economic espionage is an excellent excuse for implementing centralized control of the internet.

    --
    Give me Classic Slashdot or give me death!
    1. Re:Of course he would by Glarimore · · Score: 3, Insightful

      Economic espionage is an excellent excuse for implementing centralized control of the internet.

      And as long as corporations are not controlled by the government, their security is their responsibility. Let them handle it.

    2. Re:Of course he would by Hatta · · Score: 2

      This is America. Here it's the corporations who control the government.

      --
      Give me Classic Slashdot or give me death!
    3. Re:Of course he would by rrohbeck · · Score: 1

      Obligatory:
      In Soviet Russia, politicians control corporations!

    4. Re:Of course he would by Anonymous Coward · · Score: 0

      In Soviet Russia, they kill people who steal there memes.

    5. Re:Of course he would by Nimey · · Score: 1

      In Nazi Germany, they kill people who use poor grammar.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    6. Re:Of course he would by Boronx · · Score: 1

      Spelling grammer correctly is known to cause cancer in California.

    7. Re:Of course he would by Anomalyst · · Score: 1

      Spelling grammer correctly is known to cause cancer in California.

      It seems to be metastasizing from Cupertino.

      --
      There is no right to feel safe thru security vaudeville at the expense of everyone's freedom, privacy and tax money.
  7. The new "Think of the Children" by Anonymous Coward · · Score: 5, Insightful

    "Privacy and Security". Watch those words, folks. In the name of privacy and security we have already given up bits of both. This yahoo wants us to give up even more. Fear the person who says he can guarantee your privacy and security because first you need to give those up to him.

    1. Re:The new "Think of the Children" by Anonymous Coward · · Score: 0

      Pitt responded that: "Necessity was the plea for every infringement of human freedom.
        It was the argument of tyrants; it was the creed of slaves.

  8. The Propaganda war has begun by realmolo · · Score: 5, Insightful

    Can you feel it? The government wants to get control of the internet, and computers, and all communications devices in general.

    They're going to pretend it's for our safety. They just want to protect us from hackers, after all.

    I'm not a "government is evil" guy, but this is the kind of thing governments typically want to do. And it has to be prevented. Call your congressman.

    1. Re:The Propaganda war has begun by Ihmhi · · Score: 1

      Honestly, the worst firewalls in the world are in places like Iran and China. People in those countries manage to circumvent them just fine, and so will we if it comes down to it.

      And if not, there's always sneakernet.

    2. Re:The Propaganda war has begun by Anonymous Coward · · Score: 2, Insightful

      Yep.

      Even on /. there was at least half a dozen stories matching the "$insider says $hackers have already compromised >90% of computers in ($line_of_business|$federal_department|...)"

      Feels like someone's preparing the ground to bring out some new legislation.

    3. Re:The Propaganda war has begun by Anonymous Coward · · Score: 0

      I don't think that's what he's saying. (It should go without saying that government control of the internet will not make it more secure.)

      The internet is full of technologies built before anyone thought security was a concern and others that were built without thinking about security because there's no money in it. A lot of computer technologies need to be rethought from the ground up if we want any hope of having them be secure, and that's not cheap or worthwhile in the eyes of most people. Remote logins should use (hopefully physical) cryptographically secure tokens, not passwords. Any program dealing with data from a remote server or client should be written to be provably free of buffer overflows and other known categories of security bugs (the simplest way to do that is to not use C, but I'll leave it open to the possibility that that is not an option, perhaps for performance reasons).

    4. Re:The Propaganda war has begun by Anonymous Coward · · Score: 0

      Who takes the product of your labor by threat of force and gives it to plutocrats? The government - not illegal aliens.

      Who kidnaps and tortures people? The government - not kids that download MP3s.

      Who murders civilians with drones? The government - not pot smokers.

      Yes, the occupational government is evil and should be treated as such.

      Can you name a single police state in all of human history that didn't end up evil?

    5. Re:The Propaganda war has begun by Anonymous Coward · · Score: 0

      Government is made of people just like you and me. Government only goes so far as we let it. If it runs amok and hurts us, it is as if we hurt ourselves. What are you prepared to do to stop this insanity?

    6. Re:The Propaganda war has begun by Anonymous Coward · · Score: 1

      Many will do anything due to greed.

      We're fucked.

    7. Re:The Propaganda war has begun by rtb61 · · Score: 1

      Which is the underlying reality of internet security. If it absolutely doesn't need to be connected to the internet than don't bloody connect it to the internet. If it is going to save a thousand dollars a year to connect to the internet but cost ten thousand dollars to 'maybe' secure it, then don't connect it to the internet.

      When it comes to security, the internet should not be any different than reality. What would you do to secure your actual physical computer system, would you require every person on the planet continuously (incorporate an auto-taze neck collar to disable them of they do anything suspicious) because of that one person who grabs a brick throws it through you office window and yanks your file server right off your desk.

      --
      Chaos - everything, everywhere, everywhen
    8. Re:The Propaganda war has begun by SpaceLifeForm · · Score: 1

      Notice he does not mention the M word.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
  9. Refreshingly, he does NOT call for new laws by TheEmperorOfSlashdot · · Score: 5, Informative
    He places the blame right where it belongs, on those corporations and government agencies that are too incompetent to design secure computer systems or hire those who can:

    Mr. Henry, who is leaving government to take a cybersecurity job with an undisclosed firm in Washington, said companies need to make major changes in the way they use computer networks to avoid further damage to national security and the economy. Too many companies, from major multinationals to small start-ups, fail to recognize the financial and legal risks they are taking—or the costs they may have already suffered unknowingly—by operating vulnerable networks, he said.

    1. Re:Refreshingly, he does NOT call for new laws by DigiShaman · · Score: 2

      No, but he sure as hell left the door wide open for a politician to create new ones. The other politicians salivate at the prospect of attaching riders to it too.

      It was bound to happen sooner or later. He just kicked the pace up a notch, that's all.

      --
      Life is not for the lazy.
    2. Re:Refreshingly, he does NOT call for new laws by Red+Flayer · · Score: 2
      Sure, but that doesn't stop others from hopping on that train:

      Matthew Eggers, a senior director at the Chamber, said the group "is urging policy makers to change the 'status quo' by rallying our efforts around a targeted and effective information-sharing bill that would get the support of multiple stakeholders and come equipped with ample protections for the business community."

      Message: Further blur the lines between various enforcement agencies, possibly including military, for the benefit of corporations.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    3. Re:Refreshingly, he does NOT call for new laws by Glarimore · · Score: 1

      The problem is that even if you're tech team is the most savvy in the world, you've still left yourself wide open to attack via social hacking. In terms of security, humans are and will always be the weakest link in a computer network.

      Good luck keeping the CFO from being phished.

  10. Security is by Crash+McBang · · Score: 0

    a journey, not a destination.

    Thus saith Steve Jobs.

    Or maybe it's that perfection is a journey, not a destination.

    Meh. Probably both...

    --
    To put a witty saying into 120 characters, jst rmv ll th vwls.
    1. Re:Security is by dido · · Score: 3, Insightful

      I think the quote you're looking for is "Security is a process, not a product." --Bruce Schneier.

      --
      Qu'on me donne six lignes écrites de la main du plus honnête homme, j'y trouverai de quoi le faire pendre.
  11. Obvious by Anonymous Coward · · Score: 0

    If he says FBI is winning there's no reason for asking more budget.

  12. I fully agree by hjf · · Score: 1, Insightful

    I fully agree. We need a change in legislation.

    And I propose the following: make every technician in charge of systems security liable for hacks to their network. And systems manufcaturers too. Make security a a requirement, and not a suggestion.

    You know, cause some people might interpret "change in legislation" as "we want to spy on all citizens". Which is useless.

    1. Re:I fully agree by Glarimore · · Score: 2

      You can legislate only to a certain degree. That is, make companies responsible for the security of the information related to their CLIENTS. I personally don't care if a company loses their trade secrets to hackers, but I do care if they lose my personal information, credit card numbers, etc.

    2. Re:I fully agree by es330td · · Score: 2

      make every technician in charge of systems security liable for hacks to their network

      Okay, so technicians will require hack insurance, because nobody will risk the financial penalty of taking said job with unlimited financial liability. This means that network technicians will have to be licensed to be insurable, which will cost money. Now only large firms will be able to afford the cost of these technicians. It is almost certain that the government will step in an license operators, just as they do doctors, accountants and other professionals. This is all certain to do wonders for the "anyone can do it" nature of computing.

    3. Re:I fully agree by hjf · · Score: 1, Interesting

      I don't see any problem with that. I don't want an idiot with a pirated Windows Server 2008 to be in charge of my medical records, for example. And a lot of times that's exactly what you get.

      "Anyone can do it" doesn't mean they SHOULD. Doctors, architects, engineers, and everyone in charge of infrastructure or other critical projects or things that could cost your life are required a license. Why aren't "IT managers" required the same? IT now IS infrastructure, and a lot of times the sysadmin is just a guy who installed a server. IT systems run traffic lights. I'm sure the engineer that designed and placed the lights was licensed, but the guy in charge of the two computers that run the system isn't.

      And as a bonus, since IT managers now need to be licensed, their rates would go higher. We'd get rid of the boss' nephew installed warez windows and undercutting a tech that actually knows what he's doing.

    4. Re:I fully agree by PeterM+from+Berkeley · · Score: 1

      Hold the technician liable? How completely unfair.

      What if your OS is insecure and leads to you getting hacked? Did the Technician write the OS? Did the technician get dictatorial control of what OS was used?

      No. In this case, the technician is a mere scapegoat.

      What if your network hardware had a backdoor installed in it by a 'counterfeit' or malicious 'legitimate' manufacturer? Can one reasonably expect a security technician to audit every piece of hardware and software?

      No. In this case, the technician is a mere scapegoat.

      Can the technician dictate exactly how systems are to be used and who can use them?

      No, in the case of an insider hack, the technician is a mere scapegoat.

      Can the technician dictate the physical security of all his hardware?

      No, in the case of a physical compromise, the technician is a mere scapegoat.

      About the only thing the technician can control are some weak-ish security policies and how quickly patches get installed.

      Security is a tough problem, and I'm telling you, the fix for it is NOT scapegoating the technician.

      --PM

    5. Re:I fully agree by Anonymous Coward · · Score: 0

      Many extremely talented individuals have six or seven figure incomes and no high school diploma let alone any college!

      They are hired by skill and skill alone.

      I raked in 80,000 before turning 20 myself. Dropped out of school and all that. Showed my skills off at a convention and was hired immediately by a fellow attendee who happened to like my talent.

      That's how the big boys play. I can destroy your scope-lacking context-unaware college wannabe. I was writing code before I turned 10 and knew from a very young age that computers were my life. I have an autistic-like draw to computers and know them inside and out. I'd never pass your certification yet here I am racking in big money. That tells me your certification is wrong and short sighted. Another attempt to squish true professionals out of the field. Pathetic this war is on intelligence.

      I never let my schooling get in the way of my education.
      -Mark Twain.

    6. Re:I fully agree by hjf · · Score: 1

      No, that tells me you're special. You're an exception. And if you knew as much as you say, you'd ace any certification tests.

      This is from someone like you, who flunked college, but aced all stupid certs and how I not only have the knowledge, but also the papers to prove it.

    7. Re:I fully agree by hjf · · Score: 0

      Hold the technician liable? How completely unfair.

      The technician has no responsibility if data is stolen or loss? How completely unfair. If a security guard is on the night shift and someone robs your place, guess who's liable?

      What if your OS is insecure and leads to you getting hacked? Did the Technician write the OS? Did the technician get dictatorial control of what OS was used?

      If the technician is a CIO, yes, he gets dictatorial control. And if the OS is insecured and it got hacked, the OS vendor can be liable.

      What if your network hardware had a backdoor installed in it by a 'counterfeit' or malicious 'legitimate' manufacturer? Can one reasonably expect a security technician to audit every piece of hardware and software?

      Yes. It is reasonable to expect hardware and software to be audited. It should be MANDATORY. If you have a credit card module on your sales system, you can expect Visa to audit it. If your software does taxes, you can expect the IRS to audit it.

      Can the technician dictate exactly how systems are to be used and who can use them?

      Yes. That's his fucking JOB.

      Can the technician dictate the physical security of all his hardware?

      Yes, he can, and should.

      About the only thing the technician can control are some weak-ish security policies and how quickly patches get installed.

      Then you're exactly the problem with IT: expecting your vendor to provide all sort of fixes and support. Do not think, don't do anything. If the system fails, call vendor support to cover your ass, instead of actually fixing the problem that's causing you downtime.

      Security is a tough problem, and I'm telling you, the fix for it is NOT scapegoating the technician.

      Something tells me you don't have real work experience. You're just a code monkey (no offense) somewhere, and there is an idiot above you who dictates the rules. What I mean is that THIS guy is the one who's liable. That's what he's paid for.

      If a pipe is leaking and it ruins your wall, do you call the individual plumber who installed that? Or do you call your contractor, i.e. the guy you PAID to do the job?

    8. Re:I fully agree by indymike · · Score: 1

      Outawing stupidity has never worked. Nor has legislating that pi=3.15.

      --
      -- Mike
    9. Re:I fully agree by hjf · · Score: 1

      Except this doesn't outlaw stupidity. This just makes sure stupid ones aren't in charge. And if they are, and do stupid things, they go to jail.

    10. Re:I fully agree by Anonymous Coward · · Score: 0

      make every technician in charge of systems security liable for hacks to their network

      Yea that will end well. CEOs and upper management fuck things up by accepting fancy cruises in exchange for the use of insecure software by those who bribe most and technicians will be liable for that. Right.

      CEOs rake in more than dozens of technicians. They fuck over whole companies, political systems and populations. Yet they are liable for nothing. The best course of action would of course be to start with putting the blame on technicians. It's only fair.

  13. pot and kettle? by v1 · · Score: 4, Insightful

    Anyone else find it ironic that the FBI, of all organizations, (perhaps besides the NSA) is whining about losing to people hacking into our privacy? Isn't that what they do for a living? Not just to "the other people", but to our own citizens all the same nowadays?

    They're grousing over a problem that they're part of...

    --
    I work for the Department of Redundancy Department.
  14. Don't aim to outrun the bear... by wanderfowl · · Score: 5, Insightful

    There are hackers, phishers, spammers, and other untrustworthy people on the internet. The FBI seems to have just realized that they can't prevent them from existing, and now tells us that we'll "never be secure", and people react. But this has always been the case offline as well. There are thieves, murderers, and con-artists, and we can never make them go away either, and as such, here too, we will never be secure.

    That said, if you use common sense, encrypt your important data, don't click links in unsolicited emails, and use a password better than "12345", you'll already be enough of a pain to most "hackers" that they'll not bother, because next door, there's a guy who's got a plaintext full of banking passwords on his desktop with file sharing on.

    There's a saying that if attacked by a hungry bear, you don't need to outrun the bear, just the other people at the campground. Same goes here.

    1. Re:Don't aim to outrun the bear... by mlts · · Score: 5, Insightful

      The FBI is also dealing with a lot of businesses who have existed for years with at best paying lip service to computer security.

      I remember a few years back so many PHBs saying, "security has no ROI" like it was a mantra for magic success. Of course when I asked the person about what they do if they do get breached, the answer was invariably, "Call Geek Squad, and they will fix it."

      The sad thing is that there is no real drive for private businesses to focus on actual security. A breach happens, and usually it won't be reported, and if it is, it is because there are thousands of people who got nailed and have hard evidence finding who did it upstream. Even though there are laws to disclose breaches with private info lost, it isn't hard to ignore them -- the company top brass will find a fall guy, and the domain admin password will continue to remain "swordfish". Even if the firm goes bankrupt, it doesn't really matter, because the top brass just finds a niche somewhere else.

      There is also the belief that intruders won't do much damage. A wiped box? Stick in a backup tape. Lost customer info? Not our problem if customers get identity theft issues. Lost source code? The H-1Bs end up copying it to their home soil anyway.

      Until the attitude that security is a cost center with nothing to gain back goes away, it is no wonder that criminal organizations and foreign intel departments are having a field day.

      Ironically, where I see actual improvement in security is in government. The main reason is that government departments (and this applies not just to the US but any country out there) have a lot to lose, especially around election years. Companies can fold and the CEO just moves to a new venture, but a government department that is weak on security will face the wrath of the voters, as well as any elected official that is looking to keep their jobs. In countries that are not democracies, it can mean loss of face for leadership which will be swiftly dealt with.

    2. Re:Don't aim to outrun the bear... by elucido · · Score: 1

      There are hackers, phishers, spammers, and other untrustworthy people on the internet. The FBI seems to have just realized that they can't prevent them from existing, and now tells us that we'll "never be secure", and people react. But this has always been the case offline as well. There are thieves, murderers, and con-artists, and we can never make them go away either, and as such, here too, we will never be secure.

      That said, if you use common sense, encrypt your important data, don't click links in unsolicited emails, and use a password better than "12345", you'll already be enough of a pain to most "hackers" that they'll not bother, because next door, there's a guy who's got a plaintext full of banking passwords on his desktop with file sharing on.

      There's a saying that if attacked by a hungry bear, you don't need to outrun the bear, just the other people at the campground. Same goes here.

      But most hackers aren't the ones who the US government would have to use war powers against. The US government would have to use war powers to stop state sponsored hackers.

  15. I can see it now by Anonymous Coward · · Score: 0

    I can see it now. Due to rampant hacking we are enacting new laws requiring everyone to have an FBI secured internet box to protect your privacy. Followed by a clause in tiny letters "The FBI will have have access to all your data. But it's OK because we're the good guys".

  16. How quaint by Anonymous Coward · · Score: 1

    "...never have a reasonable expectation of privacy or security."

    Yet the same government will step aside when the corporates want to nullify privacy, which means the question is really "from whom" and "for how much money".

  17. losing a war? by Anonymous Coward · · Score: 0

    a war? against cooperation, the US government needs to protect? against cooperation who can't afford to properly secure their OWN SERVERS!?!?
    there is a war going on, smart vs retarded government agencies who work for big cooperation and who can't secure their servers...

    it's time to pull the plug on the US governments protection of stupid...

  18. Only a partial quote by mr1911 · · Score: 1

    "We're losing the war against hackers" is the public version.
    "We're losing the war against hackers unless my budget is tripled" is what he tells Congress.

    --
    This post comes with a double-your-money-back guarantee!
    Any offense taken to this post is at your sole discretion.
    1. Re:Only a partial quote by Anonymous Coward · · Score: 0

      I wish he was just after money, but most of the time you hear this kind of story from the FBI what they want from congress isn't money, but more power over people.

    2. Re:Only a partial quote by mr1911 · · Score: 1

      I agree with your sentiment, except power isn't something they ask Congress for. They just do it and say they won't do it again if/when they get caught. Or they will do illegal and immoral things to gain new powers through FUD legislation. Google "fast and furious gunwalker" if you would like an example of the ATF and DOJ at work.

      --
      This post comes with a double-your-money-back guarantee!
      Any offense taken to this post is at your sole discretion.
  19. Security is swimming upriver by definition. by El+Jynx · · Score: 3, Informative

    Information sharing is built into the universe, and so is copying of patterns. Atoms and molecules share electrons in predictable ways, cells communicate with each other, living entities communicate and share in incredibly diverse and complex ways; and once "the cat is out of the bag" it's almost impossible to get it back in. Streisand effects ad nauseum. The war living things wage against each other on so many levels - for example, viruses versus our immune systems - are also a facet of this interaction. We exist in an environment where sharing and communication is fundamental and everything influences everything else in myriad, complex ways. Making something totally secure - in other words, preventing it from interacting with its environment - hence is utterly impossible, or at the very least the amount of energy required to secure something is immense and the result is always imperfect.

    Goes for plagiairism as well. DNA copies itself, kids copy their parents, we copy habits and patterns from each other hundreds of times every day. It's part of our processes for optimalisation and they're also intrinsic to the universe. Thus, things like copyright are also doomed to fail. Here, too, the amount of energy required is huge.

    --
    A positive attitude may not solve all your problems, but it will annoy enough people to make it well worth the effort.
    1. Re:Security is swimming upriver by definition. by micahraleigh · · Score: 1

      A very bland world you live in there. If people do not have individuality (everything is shared with everyone) there is no freedom or responsibility and life is dull and hardly seems worth living. This is why socialist countries on the whole have higher suicide rates. The solution is a meritocracy where the individuals who can succeed do and the government still collects taxes, but not as a punishment and it earns what little money it is permitted to collect.

  20. Dr. Strangelove by Nimey · · Score: 3, Insightful

    "Mr. President, we must not allow... a hacker gap!"

    Standard tactic for getting the government to spend money on a military-industrial complex project.

    --
    Hail Eris, full of mischief...

    E pluribus sanguinem
  21. Doomed to fail by jd2112 · · Score: 3, Insightful

    Any "war" where there isn't a party who can negotiate terms of surrender is doomed to failure.

    --
    Any insufficiently advanced magic is indistinguishable from technology.
    1. Re:Doomed to fail by regdul · · Score: 1

      A war where there is no clear enemy can never be won but that's the whole point. If the war will never and you don't ave to take back the restrictions and laws you passed and you don't have to release prisoners of war (doesn't apply to "cyberwars" yet, but see the war on terror). And as a bonus it can't be "lost" either since there's nobody to whom you can surrender.

    2. Re:Doomed to fail by scarboni888 · · Score: 1

      The war on polio went pretty well and I don't remember the disease doing any negotiating on that one.

  22. That's funny, I am consistently winning... by Anonymous Coward · · Score: 0

    The first time I ever hooked up a computer to the Internet it was cracked and owned within two weeks. It took me half a day to remove the trojan, install a firewall, and discard all the "helpful security advice" from Microsoft and the antivirus industry. In the 15 years since, no computer under my control has had a security incident worse than a browser hijacker, with the impact confined to the settings in the browser itself.

    The problems are twofold: 1) Microsoft makes tons of money from replacement sales to computer illiterate lusers who believe their compromised machine is "broken" and purchase a replacement. 2) A whole industry of useless "certified IT professionals" has been raised up to exploit Microsoft's deliberately broken security model, that makes them "indispensable" and "knights in shining armour" in a world filled with (non-existent) Super Hackers.

    People who know how to secure a computer and a network are a very small minority, in terms of both numbers and dollars. Our voices are actively suppressed at every turn, because when people listen to us, Microsoft and their army of outside sales reps a.k.a. A+ and MCSE Certified technicians lose money and power. At least we have this: Ours are always the last systems standing.

  23. Just like terrorism by honestmonkey · · Score: 3, Interesting

    You can't really fight terrorism with bullets and bombs, just like you can't fight hackers with some "new" anti-virus program or whatever (at least not for long). But nobody wants to think like that. "If we kill enough of them, they'll stop" doesn't work with terrorists - they're roaches in the walls and you can't get them all without collateral damage or creating yet a different kind of roach. However, all we have are bullets and bombs. "If we build a good enough firewall, it'll stop them" is just a challenge to hackers. Nobody wants to hear "You must completely change how your computers work to have even a ghost of a chance." Instead, it's "How do I fix what I have now?" The answer "You can't" doesn't let you keep your job or make anyone any money.

    --
    Everything you know is wrong, Just forget the words and sing along.
    1. Re:Just like terrorism by elucido · · Score: 1

      You can't really fight terrorism with bullets and bombs, just like you can't fight hackers with some "new" anti-virus program or whatever (at least not for long). But nobody wants to think like that. "If we kill enough of them, they'll stop" doesn't work with terrorists - they're roaches in the walls and you can't get them all without collateral damage or creating yet a different kind of roach. However, all we have are bullets and bombs. "If we build a good enough firewall, it'll stop them" is just a challenge to hackers. Nobody wants to hear "You must completely change how your computers work to have even a ghost of a chance." Instead, it's "How do I fix what I have now?" The answer "You can't" doesn't let you keep your job or make anyone any money.

      The way to stop hackers is to create jobs. When there's fewer jobs there tends to be more hackers just like any other type of crime.

      If we are talking about cyber warriors then we are talking about state sponsored hackers and this is actually a war effort because these state sponsored hackers aren't civilians.

  24. Businesses need to invest in IT from day 1 by undeadbill · · Score: 5, Insightful

    At least, that is what I got out of the warnings in the article. It wasn't about the FBI needing more money, so much as his discussion of the absolutely deplorable state of most business networks. Most businesses, even IT managers within businesses, seem to think that best security practice means sending someone to a Cisco firewall class, putting an ASA into an external facing connection, and passing a security scan as all they need to stop the bad guys. They never really consider what it means to really monitor the health of a network, or have an understanding of how their internal applications operate across their machines, nor are they willing to really invest in the kind of staffing and knowledge needed to make sure their data is actually secure. In the end, they are better off with making that early investment, because that knowledge also translates into fewer expenditures on gimmicky appliances, and a better focus on having things run right. It is a shame that mostly these businesses are blithely whistling past the graveyard.

    Most businesses seem to miss from the day they replaced their file drawers with a file server, they went from a "widget" company to an IT company that does widgets. It is a subtle but definitive change in how businesses need to focus investments in resources. Unfortunately, most businesses just don't get it. They think because some snake oil dealer slapped "security" on the side of the box that the word means anything.

    What I'd like to see is ACM, the ISC, ISC2 (no relation), and other organizations start pushing for more stringent best practices written into regulation (not law). Basically, if a business doesn't take the effort to invest in their own security, then they should be held liable if they get broken into. Don't expect insurance to pay out. Don't expect to be personally shielded by corporate liability if your client data goes into the wild. On the other hand, if businesses DO meet those standards, then they likewise shouldn't be held liable. I would really like to see the above organizations testifying on the Hill about what that would mean.

    1. Re:Businesses need to invest in IT from day 1 by Ocker3 · · Score: 1

      Wait, so you're Not going make a post about the Government's War on Privacy and put up actual facts and try for a reasonable analysis? Fool, this is Slashdot, expect to be modded -1 Troll. *sigh*

  25. The obvious problem, the unspoken answers by idontgno · · Score: 0

    "I don't see how we ever come out of this without changes in technology

    I.e., treacherous computing, where the computer actually serves the powers-that-be and not you

    or changes in behavior,

    Um.... I got nothing here. People are douchebags. Period. People have been defrauding, trolling, lying, and generally hating since before recorded history, and nothing the government can do the change the basic core of human behavior. Embedding monitoring and control logic into each computing and communications node would be far easier, and profitable for those contracted to accomplish it.

    --
    Welcome to the Panopticon. Used to be a prison, now it's your home.
  26. The goal presented is absurd. by Anonymous Coward · · Score: 0

    The common term "vulnerable network" has incorrect implications. It suggests that the current type of network would be "invulnerable", which is unreasonable. Applying that to the physical world demonstrates the absurdity of that goal. Something like 90%+ of US houses can be broken into with trivial effort (e.g. bump keys) if the burglar even bothers to acknowledge the lock - 99%+ if the burglar decides to just smash a window instead. And yet we don't get continual stories about how we're losing the war on burglaries.

  27. Amazing... by sirroc · · Score: 1

    Its only taken them a "few" years to realize this... Yet, the war on drugs is 35(?) years strong now. When will they admit they can't win that one too?

    1. Re:Amazing... by Anonymous Coward · · Score: 0

      Its only taken them a "few" years to realize this... Yet, the war on drugs is 35(?) years strong now. When will they admit they can't win that one too?

      +5, Insightful

  28. I say we ... by PPH · · Score: 2

    ... take off and nuke them from orbit. Its the only way to be sure.

    --
    Have gnu, will travel.
    1. Re:I say we ... by Anomalyst · · Score: 1

      ... take off and nuke them from orbit. Its the only way to be sure.

      Are you talking about the congressticks or the FBI?

      --
      There is no right to feel safe thru security vaudeville at the expense of everyone's freedom, privacy and tax money.
  29. Changes in Technology by Anonymous Coward · · Score: 3, Insightful

    The technology is fine, the problem is the user-centric security that everything employs. There's an alternative called the principle of least privilege, which we use all the time in other aspects of life, just not with computers.

    You might be tempted to think you know of a system that actually uses this, but you're wrong. The term capability has a lot of uses, and the application of it in Posix or Symbian systems isn't the same thing.

    Only when we stop assuming that a program should be able to have free run of everything will we be able to fix this problem.

    It's almost like there's an active conspiracy to keep this idea in obscurity..... but probably not.

  30. It dosnt have to be "hackers" by bobjr94 · · Score: 1

    An employee, who is allowed access to files/info, that they then are then copying/sharing/selling... Users who don't log out of their computers, or administrator who give users to much access to things they dont need to see. Is it hacking then the person has a sticky note with this months password on their monitor, or on their pull out keyboard if they think they are being sneaky.

    1. Re:It dosnt have to be "hackers" by elucido · · Score: 1

      An employee, who is allowed access to files/info, that they then are then copying/sharing/selling...
      Users who don't log out of their computers, or administrator who give users to much access to things they dont need to see.
      Is it hacking then the person has a sticky note with this months password on their monitor, or on their pull out keyboard if they think they are being sneaky.

      Espionage yes but that still involves hackers usually.

  31. "war?" by JustAnotherIdiot · · Score: 1

    This is as much a "war" as kids playing with squirt guns in the backyard.

    --
    What do I know, I'm just an idiot, right?
  32. In related "news" by Anonymous Coward · · Score: 0

    They are also losing the War on Drugs, the War on Terror, the War on Gambling, the War on Crime, the War on Prostitution, and the War on Thirst. There are some things that you just can't beat. Kill them all, and they will rise up again from an unrelated source.

  33. hold on by Anonymous Coward · · Score: 0

    Are they talking about real hackers that do shit of their own volition? Or about hackers who are talked into doing shit by the FBI and then arrested by the FBI, like the terrorists?

  34. Not the government's business by Hentes · · Score: 1

    If corporations don't care about their own security why is it so important to the US government?

    1. Re:Not the government's business by jc42 · · Score: 1

      If corporations don't care about their own security why is it so important to the US government?

      Perhaps because the US government makes a pretense of representing us, the citizens. And poor corporate computer security threatens us, especially since it makes our bank accounts vulnerable to criminals who can exploit the poor security. So it's not surprising that our representatives in Congress might be starting to get the message that there's a problem that's threatening their voters. And, being Congress, they do what the Constitution says is their role: They declare war.

      Yes, this makes no sense at all. But nobody ever accused the US Congress of being full of people with sense.

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    2. Re:Not the government's business by elucido · · Score: 1

      If corporations don't care about their own security why is it so important to the US government?

      Our lives are at stake if some dumb corporation doesn't care about security. Some corporations are critical.

    3. Re:Not the government's business by Hentes · · Score: 1

      One solution could be to make corporations liable for loss of user data. I'm pretty sure that they would secure their systems surpisingly quickly if they are the ones who have to pay for a breach. That still wouldn't help against industrial espionage though.

  35. Define "We" .... by sammcj · · Score: 2

    Over the years I've been subjected to less and less personal data attacks to the point where I can't remember the last time I got a virus. Back in the day I used to be constantly battling with them.

  36. Are we? by Entropius · · Score: 2

    I'm able to do my job (high-performance computational simulations in physics) just fine without worrying about "hackers".

    I buy shit off the internet, pay my bills, have cybersex with my girlfriend, play online games, and read the news -- no problems.

    How are we "losing the war on hackers" if I can basically do all sorts of useful crap on the internet without having to greatly alter my patterns of behavior because of hackers?

    I definitely am more worried about non-computer theft (which I've been the victim of quite a few times) than ONOZ HACKERS. Yes, there is computer crime, but it is really not that big of a deal.

    1. Re:Are we? by Skapare · · Score: 1

      Just wait until your research grant funding account gets drained and sent to Nigeria so they can buy shit off the internet, pay their bills, have cybersex with their girlfriends, play online games (they hacked in to), and read the news about research grants being lost due to hacker breakins.

      --
      now we need to go OSS in diesel cars
  37. cuttin' in on their action! by v1 · · Score: 1

    They're just grumpy because others are cutting in on their action. If anyone's going to be violating your right to privacy, it's going to be them!

    --
    I work for the Department of Redundancy Department.
  38. Re:Suck my dick. by Chas · · Score: 0

    Dude, if you're cruising for a piece of guy-ass, we don't need to know about it.

    Seriously.

    --


    Chas - The one, the only.
    THANK GOD!!!
  39. War? hackers? by jc42 · · Score: 4, Insightful

    Solving the problem might require abandoning the "war" metaphor. Declaring this a "war" is a way of allowing the authorities to ignore insignificant (to them) things like legality and morality. The inevitable result, which we're already seeing, is offending a lot of the population by the overreaction and "scorched earth" tactics. Taking down sites without any semblance of due process is guaranteed to hurt a lot of innocent bystanders, and as with real wars, this just turns the population against you.

    This is much like the "war on drugs". Even those of us who don't abuse (or even use) illegal drugs are still very likely to be offended by the atrocities committed by the warriors. Taking people's cars, homes, and sometimes lives without any sort of trial is both wrong and counterproductive, but it's what the "war" metaphor leads to.

    There's also a major problem with the media's expropriation of the term "hacker", which was originally a term of high praise for a technical expert, retargetting (;-) it as a term for an anti-social criminal. This tends to get the message across that people with technical expertise in software security are considered suspect by the media and the general population. You want these people on your side. Characterizing them as criminals isn't the best way to make this happen.

    As long as we have a "war against hackers", I'd expect the problems to get worse. That phrase itself is pretty much a guarantee that the problems won't be approached in a reasonable fashion. It also guarantees that lots of innocent bystanders will be hit by the warlike measures. Even worse, people who could have helped you will be classified as hackers and, uh, "discouraged" from helping find the solutions.

    I'm reminded of the time, back in the 1960s, when a "War on Poverty" was declared here in the US. That one ended rather quickly, as lots of poor people started publicly asking where they could go to surrender. But it's not obvious that the large population of software "hackers" will take this approach. If I happened to be a software expert with some expertise in computer security, where would I go to surrender?

    --
    Those who do study history are doomed to stand helplessly by while everyone else repeats it.
  40. Who has what role? by Anonymous Coward · · Score: 0

    Perhaps because the FBI doesn't have a clearly defined role, or at least not one that they willingly define to the public. They're all over the place. What the hell is the FBI, an domestic investigative body, doing in every country we have an embassy? Oh, right. Providing investigative administrative assistance.

    Perhaps it's my fault to think they should only be operating within US borders. That said, let's look at the argument here. Losing to Hackers. Would that be domestic hackers, or foreign hackers? Can the FBI even tell the difference? I doubt it. Especially when it's been stated before Congress that the entire military and corporate network landscape has been compromised by China!

    I digress though, since ICE is clearly handling those nasty trademark cases by shutting down product infringement websites both here in the US and overseas, where presumably, their only way in is if the TLD goes back to Verisign ownership. Good use of enforcement money and protection against industry products who can be easily replicated at 1/3 the price. To hell with International law, trade agreements, and treaties, right?

    Then you have US-CERT, which I presume should be the one handling actual network security and response, seem to be doing a bang up job at the moment. Remember again how our entire military and corporate network environment has been infiltrated by foreign entities? Are they asleep at the switch or they just lacking the funding to implement effective policies.

    Then we have the NSA, which I'd argue is in the best position to inform us of who is doing what to whom on the networks, and how we can better stopgap that, but that would mean admitting that they are actually vaccumming up every bit that travels more than a meter domestically.

    And all that goes back to proper administration personnel, right? I mean, it's the arm-chair admins who are the last line of defense here isn't it? They're the ones securiing the networks, servers, web portals, access-rights, and so on, and so on ......

    But we don't punish admins or contractors who lapse at their job, do we? Well, if they do, I haven't heard of too many other than those who were commiting fraud or vising questionably legal content on the web from work, instead of rolling out patches from earlier this week. I mean, we're still going after Gary McKinnon for 'logging in' to unsecured windows boxes at NASA. At least he brought awareness to the fact that some public facing machines were vulnerable. I'd say give him a $1000 cashiers check and be on about it. Oh, and fire the admins or permanently ban the Government contractors who were supposed to be doing the job they were hired for.

    My point? It's spaghettification. Creating the DHS did nothing for any of this, even if that wasn't part of its intent. And I can bet you several things will happen in response to this giant gaping cluster-f#&k of a situation. Which will likely occur after another year or two, when more retiring long-serving members of the Gov, testify before Congressional posturing sessions. The result will be more money will be thrown at it, more completely misdirected legislation will be passed to combat it, usually pinpointed to restricting US citizens rights online, and more infiltration by foreign entities will ultimately ensue. All the while, from a legal perspective of the 'save your own ass clause', it's better for such compromises to exist in the first place lest the blame can't be held to the military or corporation, but to an untouchable 3rd party OUT of every US citizens jurisdiction.

    Cynical? There isn't a word for how I feel about all this.

    /rant

  41. First of all... by Anonymous Coward · · Score: 0

    the correct term is cracker. A hacker is a good thing.

  42. Isn't this obvious? by spynode · · Score: 1

    US Firewall, here we come!

  43. damn those hackers!!111 by Anonymous Coward · · Score: 0

    they keep writing free software faster than we can use it!!111 halp!

    1. Re:damn those hackers!!111 by Daniel+Phillips · · Score: 1

      they keep writing free software faster than we can use it!!111 halp!

      Now that's scary.

      --
      Have you got your LWN subscription yet?
  44. Yeah, and he's so qualified to judge this.. by guisar · · Score: 1

    Mr. Henry has earned a Bachelor of Business Administration from Hofstra University in New York, and a Master of Science in Criminal Justice Administration from Virginia Commonwealth University. He's a "bureau"crat saying what he's saying for political reasons and/or personal gain rather than any insight or competency. Not that academic credentials are the be all and end all but there's no indication either in his experience or training that would give me any confidence in his independent judgement or understanding of what others are telling him- other than that he's a politician....

    http://www.fbi.gov/news/pressrel/press-releases/shawn-henry-named-executive-assistant-director-of-the-criminal-cyber-response-and-services-branch

    1. Re:Yeah, and he's so qualified to judge this.. by Daniel+Phillips · · Score: 2

      And I would be far from surprised to learn he is an inveterate Windows user.

      --
      Have you got your LWN subscription yet?
    2. Re:Yeah, and he's so qualified to judge this.. by Anomalyst · · Score: 1

      And I would be far from surprised to learn he is an inveterate Windows user.

      He definitely appears to lack a spine.

      --
      There is no right to feel safe thru security vaudeville at the expense of everyone's freedom, privacy and tax money.
  45. *facepalm* by lightknight · · Score: 1

    What do you call a one-sided war, where the opposing side does not even register that you are fighting them, let alone why?

    And this kills me. They want money for a 'war' that doesn't even exist, to produce armaments to fight enemies that do not wear uniforms and rarely act as groups, and to acquire powers which are so completely antithetical to this nation's foundation (super 4th Amendment violation) that merely suggesting the need for them guarantees an involuntary laugh from anyone with some learning in the field. It's such a power-grab, of such a large magnitude and breadth, using nothing but fear coupled with lies (of them being able to actually protect anyone, let alone themselves), that it is comparable to asking a King if you could have a night with the Queen, and oh, if you could, leave some condoms and lube on the night table near the bed.

    Never mind the part where they will, in time, ask to install electronic agents on people's computers. I would be mindful to point at that that action will violate the 3rd Amendment: "No soldier shall, in time of peace be quartered in any house, without the consent of the owner, nor in time of war, but in a manner to be prescribed by law." In so far as they have labeled this a 'war,' by their very own language, and will, no doubt, ask to sequester electronic 'soldiers' on people's machines, in their homes, they will be in supreme violation of the law of the land.

    But I digress. It's highly unlikely that the Supreme Court Justices, whose understanding of technology, I imagine, is eclipsed by their understanding of trainspotting, will lift a finger to stop that from happening.

    --
    I am John Hurt.
    1. Re:*facepalm* by Anonymous Coward · · Score: 0

      ... to sequester electronic 'soldiers' ...

      A soldier, as referenced by the US constitution, is a government employee, with a weapon and willingness to kill people.

      Will your electronic soldier do that? Then the 3rd amendment isn't relevant.

      What is relevant are the concepts, of taxes (money or time), freedoms (travel, thought, recreation) and searches (person, car, house).

  46. Job creators. by Anonymous Coward · · Score: 0

    How else would we employ all the cyber police.

  47. Easy by Daniel+Phillips · · Score: 1

    Introduce an "intenet repair tax" that applies for Windows users. And they can just go on being lazy and fearful of changing to something better designed, but at least they will contribute towards paying for the damage.

    --
    Have you got your LWN subscription yet?
  48. There is never perfect security by elucido · · Score: 1

    It's always an epic battle. That is why it creates jobs because there a problems to be solved which aren't easy.

  49. Re:War? hackers? by elucido · · Score: 1

    It's a war in the sense that hackers can put lives at stake and get people killed. Yes it's accurate to describe it as a war.

    But I don't think teenage script kiddies are "cyber warriors".

  50. The Answer by Ukab+the+Great · · Score: 1

    "I don't see how we ever come out of this without changes in technology or changes in behavior"

    ding, ding, ding, ding

  51. What War? by Doctor_Jest · · Score: 1

    Sounds like a "dire prediction" land-grab for an outgoing lunatic who needed to retire MANY years sooner....

    --
    It's the Stay-Puft Marshmallow Man.
  52. Eastasia by Anonymous Coward · · Score: 1

    Remember that one of the pillars of fascism and other totalitarian societies is the great enemy, which must simultaneously be too strong to defeat and too weak to be defeated by, allowing for a constant state of panic to get people to surrender their rights for.

    For Nazi Germany, it was the Jewish Bolshevist communists who were always about to take over. Obviously in 1984 it was Eastasia. In modern America it's Islamic Terrorism and Hackers.

    I don't want to compare the US to Nazi Germany, we haven't gotten there yet, but we are definitely moving in that direction at an alarming rate.

  53. Are we? by Anonymous Coward · · Score: 0

    ... take off and nuke them from orbit. Its the only way to be sure. TechSandy

  54. A fix already exists. by Anonymous Coward · · Score: 0

    The technology to build secure systems already exists, and ironically its creation was spearheaded by the US DOD. i.e. http://www.adacore.com

    1. Re:A fix already exists. by Skapare · · Score: 1

      That does not make systems secure. It makes them less buggy. Not all security breaches are due to silly things like buffer overflows. Higher level issues like properly managing who has access to what are involved, too. Things like lost laptops that don't have everything (and I mean EVERYTHING), encrypted, are part of the problem. Security is not about just bug free code ... it's the process of how you do everything.

      Now if only they could do that with a programming language that doesn't suck.

      --
      now we need to go OSS in diesel cars
  55. What behaviour by Anonymous Coward · · Score: 0

    ... changes in behavior ...

    What changes are required to save us? Look at some other changes:

    The changes that made chemistry so dangerous, because it teaches explosives?
    The changes that made pocket knives so dangerous, because knives can kill?
    The changes that made the internet so dangerous because, child-porn and rock music can be duplicated at zero cost?
    The changes that made e-business so dangerous because people don't recognize a trojan applet/web-page/e-mail?

    And of course there is the increasing encroachment on our freedoms of travel, association, thought, possession by law enforcement and corporations.

  56. It's 4 AM by Skapare · · Score: 1

    Do you know where your data is?

    --
    now we need to go OSS in diesel cars
  57. Mod parent up! by Anonymous Coward · · Score: 0

    A "loosing the battle" statement, in modern history, is often precedent to a mass disruption of civil rights.

    +1 Insightful

  58. who gave him the steer? by Anonymous Coward · · Score: 0

    First make sure no one could break into my house, or kill me or pickpocket me in the street, then talk about "sustainable computer security".

    Its the humans to blame, and not the tools.

  59. Re:War? hackers? by Anonymous Coward · · Score: 0

    It's a war in the sense that hackers can put lives at stake and get people killed. Yes it's accurate to describe it as a war.

    Then the mining industry is at war with miners, fertilizer factories provide material support for terrorists and a guy in an automobile is America's primary warfighter.

    We have always been at war. What use is metaphor, when people willingly believe things literally when it serves a purpose?

  60. Job security? by jduhls · · Score: 1

    I don't see how we ever come out of this without changes in technology or changes in behavior, because with the status quo, it's an unsustainable model.

    Sounds like this dude just acknowledged incompetence and volunteered to resign.

  61. roaches they're not by steve.cri · · Score: 1

    Thinking of your enemies as roaches is a serious misconception which will cause flawed decisions. Unless they are actual roaches and you work in pest control. However wicked and crazy they might be, terrorists and even hackers are human beings and you better keep that in mind if you don't want them to catch you pants down, just because you underestimated them to be some kind of dumb animal.

  62. "Changes in behavior" by SCHecklerX · · Score: 1

    That's the most important. I currently work for a government agency. Yeah, we're doomed. The private sector doesn't do nearly as bad, especially smaller companies (1000 or so employeees) who are smart enough to hire bright, security-minded admins.

  63. "security has no ROI" by Anonymous Coward · · Score: 0

    Security yield's better ROI than paying out losing lawsuits for negligence though...

    APK