<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Global-Praxis &#187; Catch All</title>
	<atom:link href="http://www.global-praxis.com/category/catchall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.global-praxis.com</link>
	<description>Information and analysis on US global affairs and their domestic counterpart</description>
	<lastBuildDate>Thu, 06 Aug 2009 08:01:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Three Reasons Why U.S. Cyber Security Sucks</title>
		<link>http://www.global-praxis.com/2009/07/three-reasons-why-u-s-cyber-security-sucks/</link>
		<comments>http://www.global-praxis.com/2009/07/three-reasons-why-u-s-cyber-security-sucks/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 12:44:30 +0000</pubDate>
		<dc:creator>Michael Tanji</dc:creator>
				<category><![CDATA[Catch All]]></category>

		<guid isPermaLink="false">http://www.wired.com/dangerroom/?p=14717</guid>
		<description><![CDATA[
Good news, cyber security nerds: You ain&#8217;t running out of work, any time soon. As last week&#8217;s cyber panic about North Korea showed, when there isn&#8217;t a teenager-simple denial-of-service attack that delays your access to a government web site, there is a voracious hype machine that feeds on the tiniest slivers of data – both [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.wired.com/images_blogs/dangerroom/2009/07/080416-f-5297k-101.jpg"><img class="aligncenter size-full wp-image-14730" title="080416-f-5297k-101" src="http://www.wired.com/images_blogs/dangerroom/2009/07/080416-f-5297k-101.jpg" alt="080416-f-5297k-101" width="660" height="352" /></a></p>
<p>Good news, cyber security nerds: You ain&#8217;t running out of work, any time soon. As last week&#8217;s cyber panic about North Korea showed, when there isn&#8217;t a teenager-simple denial-of-service attack that <a href="http://online.wsj.com/article/SB124701806176209691.html" >delays your access to a government web site</a>, there is a voracious hype machine that feeds on the tiniest slivers of data – both significant and trivial – and <a href="http://neteffect.foreignpolicy.com/posts/2009/07/08/south_koreans_test_the_first_law_of_cyberwarfare" >expels massive quantities of fear and misinformation</a>. And where there&#8217;s cyber fear, there&#8217;s cyber security work to be done.</p>
<p>It&#8217;s sad that this sham is allowed to continue unabated. But worse still, it&#8217;s dangerous. Despite the expenditure of tens of billions of dollars and <a href="http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf" >countless</a> <a href="http://www.ieee-security.org/Cipher/Newsbriefs/1997/971124.PCCIP.html" >studies</a> on what needs to happen (not to mention all the offices, centers and <a href="http://www.wired.com/dangerroom/2009/06/foggy-future-for-militarys-new-cyber-command/" >commands</a>, that are supposed to implement those reports), we&#8217;re still largely screwed when it comes to threats of the online variety.</p>
<p>The problem is multi-faceted, but can be broken down into three meta-categories:</p>
<ol>
<li>Bullshit. It’s the North Koreans! It&#8217;s the Chinese! It&#8217;s the Ruskies out to steal our essence! The one thing you can be sure of is that very few people know who is behind any cyber attack. Code analysis helps to a degree (&#8221;Hey, there are some Chinese characters in here!&#8221;) but code-reuse is not exactly an unknown phenomenon online. There is no serious attribution methodology, <a href="http://www.msnbc.msn.com/id/31866018/ns/world_news-asiapacific/" >so to some extent everyone is guessing</a>.</li>
<li>Ineptitude. There are a lot of people working cyber security issues, a lot of people &#8220;managing&#8221; these issues, but not a lot of people leading on these issues. Cyber security doesn&#8217;t lack for brainpower; <a href="http://www.wired.com/dangerroom/2009/06/foggy-future-for-militarys-new-cyber-command/" >it lacks vision, the juice and the intestinal fortitude to realize the vision</a>. When your focus is billets and resources and dollars and org charts (read: management) it&#8217;s easy to see why cyber security fails. Why? Cyber doesn&#8217;t kill, it doesn&#8217;t maim, it rarely has negative impact on any scale and when it does it is almost always a readily recoverable event. Managers don&#8217;t deal with the nebulous, intangible and anything that involves &#8220;maybe&#8221; very well.</li>
<li>Complexity. The people at Verizon look on bemused when the military talks of achieving information-space dominance, when with the flick of a switch technician in overalls and a tool belt can render inert our digital military might. Attack and defense tools are built for computer-based warfare, but planet-wide more people access the &#8216;Net via phones than desktops. There has yet to be a study that has looked at these problems in a truly comprehensive manner (read: not dominated by geezers who have other people read and respond to their e-mail). Mostly they&#8217;re <a href="http://threatswatch.org/commentary/2009/03/legacy-futures-in-cyberspace/" >focused on legacy-futures</a>, which is cool if you&#8217;re not interested in forward progress.</li>
</ol>
<p>Cyber security is a real problem. It has been <a href="http://www.amazon.com/Computer-Capers-Electronic-Thievery-Embezzlement/dp/069001743X" >since computers were invented and connected to one another</a> but we&#8217;re no better off today than we were then. It is not as if we don&#8217;t have any <a href="http://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/1416507787/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1247500762&amp;sr=1-1" >lessons-</a><a href="http://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/1416507787/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1247500762&amp;sr=1-1" >learned to draw from</a>. We are in fact worse off because of the extent of our inter-connectedness, and that says a lot more about those who purport to be about enhancing cyber security than it does those who are out to subvert it.</p>
<p><em>[Photo: USAF]</em></p>
<p><span id="more-14717"></span></p>
<p><strong>ALSO:</strong></p>
<ul>
<li><a href="http://www.wired.com/dangerroom/2009/06/foggy-future-for-militarys-new-cyber-command/">U.S. Cyber Command: 404 Error, Mission Not (Yet) Found</a></li>
<li><a href="http://www.wired.com/threatlevel/2009/07/mydoom/">Lazy Hacker and Little Worm Set Off Cyberwar Frenzy</a></li>
<li><a href="http://www.wired.com/threatlevel/2009/07/show-of-force/">Lawmaker Wants &#8216;Show of Force&#8217; Against North Korea for Website &#8230;</a></li>
<li><a href="http://www.wired.com/dangerroom/2008/06/marlborough-mas/">Air Force Wobbles on Plan for Cyber &#8216;Dominance&#8217;</a></li>
<li><a href="http://www.wired.com/dangerroom/2008/10/air-force-will/">Air Force Will Fight Online, Without Cyber Command</a></li>
<li><a href="http://www.wired.com/dangerroom/2008/01/the-fbi-would-l/">Ex-Spook Blasts New Net-Spying Plan</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.global-praxis.com/2009/07/three-reasons-why-u-s-cyber-security-sucks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.238 seconds -->

