Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Saturday, June 20, 2009

DHS centralizes cybersecurity programs (FCW)

DHS centralizes cybersecurity programs

Homeland Security Secretary Janet Napolitano explained how DHS is coordinating cybersecurity programs across the department

By Ben Bain
Jun 19, 2009
http://fcw.com/articles/2009/06/19/web-napolitano-leadership-journal.aspx

The Homeland Security Department has centralized its cybersecurity programs under the department's deputy undersecretary for the National Protection and Programs Directorate (NPPD), Homeland Security Secretary Janet Napolitano recently wrote in a message posted on DHS' Web site.

DHS announced June 1 that as part of his role as NPPD undersecretary. Philip Reitinger would also lead DHS' National Cybersecurity Center (NCSC) – an organization designed to improve cybersecurity coordination across the government's civilian, military and intelligence cyber domains. In her blog post, Napolitano also said Reitinger would coordinate cybersecurity efforts across the department, including the NCSC and the U.S. Computer Emergency Readiness Team.

The Bush administration gave DHS a major role in federal cybersecurity efforts, putting the department in charge of protecting the government's .gov domain and working with the private sector to secure the country's communication's infrastructure.

Some observers have criticizd the department's performance thus far, but President Barack Obama and appropriators in the House and Senate haveindicated they plan for DHS to continue those programs.

The Obama administration requested $400.7 million for DHS' cybersecurity programs in fiscal 2010, compared with the $313.5 million DHS got this year. Meanwhile, the House Appropriations Committee approved $382 million for fiscal 2010, and the Senate Appropriations Committee on June 18 approved a bill that would give DHS $398.7 million for the programs.

"Of all the threats America faces, the integrity of our cyber infrastructure demands special attention. These are no longer emerging threats. They are with us now, and are happening every day," Napolitano wrote June 18 in DHS' "Leadership Journal."

Tuesday, June 16, 2009

Lawmakers fear White House cybersecurity czar would undercut DHS role (Computerworld)

Lawmakers fear White House cybersecurity czar would undercut DHS role

June 15, 2009 12:01 AM ET

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=340091&intsrc=news_ts_head


Computerworld - Some lawmakers are questioning President Barack Obama's plan to appoint a White House cybersecurity coordinator, fearing that the new post will dilute the role of the U.S. Department of Homeland Security.

The misgivings were expressed during a U.S. Senate confirmation hearing held earlier this month for Rand Beers, the president's nominee for the post of undersecretary of the DHS's National Protection and Programs Directorate, just days after the Obama announcement.

Sen. Joseph Lieberman (I-Conn.), who chairs the Senate Committee on Homeland Security and Governmental Affairs, said he fears that a new cybersecurity czar will "undercut the role of the DHS."

"To me, it's not just turf. It's a very critical element of homeland security," Lieberman said.

Sen. Susan Collins (R-Maine), a ranking member of the committee, added that concentrating power in the White House could make oversight more difficult -- because DHS officials are more likely to appear before the committee when asked.

"[I have a] lot of reservations about the establishment of a White House cybersecurity czar," she said.

Obama told reporters at a press conference announcing the move that the as-yet-unnamed coordinator will be responsible for "orchestrating and integrating" all cybersecurity policies for the government.

In his testimony before the committee, Beers said the White House position will have no operational authority and will serve a purely coordinating function. There will be "no realignment of roles and mission for the [DHS]," and the department's operational role will not be undercut, he added.

Sunday, June 7, 2009

Hacker ‘Dark Tangent’ Joins DHS Advisory Council (Threat Level)

Hacker 'Dark Tangent' Joins DHS Advisory Council

By Kim Zetter
June 5, 2009
10:07 pm

 

jeff-moss7

Forget the new cyber security czar position that President Barack Obama announced last week.

The real sign that the White House might be finally taking cyber security seriously came in an announcement on Friday that Jeff Moss, aka "Dark Tangent" and the former hacker behind the annual DefCon hacker confab in Las Vegas, has been appointed to the Department of Homeland Security's Advisory Council (HSAC).

He was among 16 people (.pdf) sworn in to the council by Homeland Security Secretary Janet Napolitano. Former CIA Director WIlliam Webster and former FBI Director Louis Freeh are also on the council, which provides advice and recommendations to the secretary. Webster is the council chair.

Moss, who lives in Seattle, says he was really surprised when he got a call about three weeks ago inviting him to join.

"I always figured that because of my associations in the past that I would be kind of out of the running for anything like this," he told Threat Level. "DefCon started as a hacking conference . . . and I just figured that that past, in a nontraditional beginning, people wouldn't know how to relate to that. To me it shows that they're really looking for fresh perspectives."

Moss, who's 39, was a phreaker in high school — someone who cracks into phone systems to make calls on the telecom's dime.

I asked him in a 2001 interview how he got into hacking.

"I didn't know there was really a scene until probably about my junior year in high school," he said. "Somebody called me up one day from the other side of the country. I was asking him how he could afford the call, and he just laughed and said, 'You're joking, right?' And he started to explain how phone systems work and how you can phone for free. That was the peeling back of the veneer."

He stopped hacking when people around him started getting arrested.

"You can only stand by and watch so many people you know get busted," he said. "Sooner or later you catch on that … there's a limited life span to doing this kind of stuff. So before I got out of high school that was pretty much it."

He studied law for a while before switching to computer science. He launched DefCon in 1993 on a lark to bring hacker friends from around the country to the desert to party and trade skills.

Over the years, the attendance grew and the attendees' hi-jinks — cement poured into a hotel toilet, fire alarm systems and ATMs hacked — gave way to serious talks, and the conference soon became the premier "haxor" event for learning about computer security vulnerabilities and ways to exploit them. It also quickly drew the attention of undercover feds, who came to spy on hackers and recruit them. The tension between hackers and feds at the conference has loosened over the years, with help from the annual Spot-the-Fed contest.

In 1996, Moss launched Black Hat, a complementary conference to DefCon that caters more to the computer professional crowd, many of them former hackers who doffed their Goth clothes, mohawks and body piercings for khaki pants, white socks and corporate jobs. Black Hat runs in Vegas the week before DefCon, as well as in Washington, DC, Europe and Japan at other times of the year.

Moss says he didn't have a clue what the Advisory Council was when he got the call to join. But he was told that DHS was looking for outside perspectives to rejuvenate the council, which had been neglected under former Secretary Michael Chertoff. The position is voluntary and runs for a term of three years.

He was told he might have to attend quarterly meetings and occasional teleconferences but other than this, it wouldn't be a lot of work.

"I thought okay, that's fine," he says. "And then the next day all the e-mails arrived with all the financial disclosure forms and security clearances. I spent the rest of the week filling out forms like mad."

Hacker named to Homeland Security Advisory Council (CNet News)

June 5, 2009 5:27 PM PDT

Hacker named to Homeland Security Advisory Council

Defcon founder Jeff Moss, aka Dark Tangent, is one of the newest members of the Homeland Security Advisory Council.

(Credit: Defcon)

Jeff Moss, founder of the Black Hat and Defcon hacker and security conferences, was among 16 people sworn in on Friday to the Homeland Security Advisory Council.

The HSAC members will provide recommendations and advice directly to Secretary of Homeland Security Janet Napolitano.

Moss' background as a computer hacker (aka "Dark Tangent") and role as a luminary among young hackers who flock to Defcon in Las Vegas every summer might seem to make him an odd choice to swear allegiance to the government. (Although before running his computer conferences, Moss also worked in the information system security division at Ernst & Young.)

I'd like to hear some of the banter as he rubs elbows with the likes of former CIA (Bill Webster) and FBI directors (Louis Freeh), Los Angeles County sheriff, Miami mayor, New York police commissioner, governors of Maryland and Georgia, former Colorado Sen. Gary Hart, and the president of the Navajo Nation.

In an interview late on Friday, Moss, who is 39, said he was surprised when he got the call and was asked to join the group.

"I know there is a newfound emphasis on cybersecurity and they're looking to diversify the members and to have alternative viewpoints," he said. "I think they needed a skeptical outsider's view because that has been missing."

Asked if there was anything in particular he would advocate, Moss said: "There will be more cyber announcements in coming weeks and once that happens my role will become more clear. This meeting was focused on Southwest border protection... With things like Fastpass and Safe Flight, everything they are doing has some kind of technology component."

Moss, who is genuinely humble, said he was "fantastically honored and excited to contribute" to the HSAC and not concerned with losing any street cred among what some would call his fan base. He did concede that his new position would give him an unfair advantage in Defcon's "Spot The Fed" contest in which people win prizes for successfully outing undercover government agents.

Security consultant Kevin Mitnick, who spent five years in prison on computer-related charges and was on the FBI's most wanted list, praised Moss' diplomacy, but said: "I'm surprised to see Jeff on the list. I would have expected (crypto/security guru and author) Bruce Schneier to be on the council."

Moss "is a great crowd pleaser" and "he's just bad enough for them to say 'we're crossing the ranks,'" said journalist and threat analyst Adrian Lamo, who served two years of probation for breaking into computer networks. "But the reality is he's as corporate as hiring someone out of Microsoft."

Homeland Security Keeping Central Cybersecurity Role (Information Week)

Homeland Security Keeping Central Cybersecurity Role

The department's operational responsibility won't be undercut by the cybersecurity coordinator, a DHS undersecretary nominee says.

By J. Nicholas Hoover,
June 3, 2009 
http://www.informationweek.com/news/government/policy/showArticle.jhtml?articleID=217701655

The White House has made it clear that the Department of Homeland Security will continue to have a central operational role in federal cybersecurity despite the looming appointment of a cybersecurity coordinator, a nominee for a top post at the department told Congress Tuesday.

Rand Beers, nominee for undersecretary of the Department of Homeland Security for the National Protection and Programs Directorate, which among its roles plays a hand in federal cybersecurity, said that deputy national security adviser John Brennan told him as recently as Tuesday morning -- as others had before that -- that Homeland Security's operational responsibility will not be undercut by the cybersecurity coordinator.

"There was no realignment of roles and missions in the department, and it is the view in the White House that the Department of Homeland Security will continue to play a central role in the protection of America's cyber infrastructure," Beers said.

According to Beers, the White House will play a bit of the peacemaker role. "I'm sorry to say we need help from the White House for people to play in the same sandbox," he said.

While it's clear that the Department of Homeland Security believes it will retain its responsibility for cybersecurity, what's less certain is whether the White House will shift any of that responsibility, or exactly how the White House will step in to broker peace in turf wars like the one between DHS and the National Security Agency earlier this year that sent then-director of the National Cyber Security Center at DHS packing, resignation letter in hand.

"DHS has a major role both in the civilian side of the U.S. government and in the private sector for drawing together the best defensive measures and the best partnership for making this nation's cyber infrastructure secure," Beers said in his testimony. "I believe DHS is the logical place for that responsibility to reside."

While Beers would focus much of his attention on cybersecurity in his new role, he would also be responsible for other technology-related programs like the U.S. Visitor and Immigrant Status Indicator Technology (US-Visit) program, which will eventually scan foreign visitors' biometrics when they enter the country, as well as DHS's risk management and analysis office.