Showing posts with label dhs. Show all posts
Showing posts with label dhs. Show all posts

Saturday, July 9, 2011

US suspects some foreign-made components threaten cybersecurity

US suspects some foreign-made components threaten cybersecurity
from abcnews: Some foreign-made computer components are being manufactured to make it easier to launch cyber attacks on U.S. companies and consumers, a security official at the the Department of Homeland Security said. "I am aware of instances where that has happened," said Greg Schaffer, who is the Acting Deputy Undersecretary National Protection and Programs Director at the DHS. Schaffer did not say where specifically these components are coming from or elaborate on how they could be manufactured in such a way as to facilitate a cyber attack. But Schaffer's comment confirms that the U.S. government believes some electronics manufacturers have included parts in products that could make U.S. consumers and corporations more vulnerable to targeted cyber attacks. A device tampered with prior to distribution or sale could act as a "Trojan horse" in the opening wave of an international cyberwar. Contaminated products could be used to jeopardize the entire network. The admission by Schaffer came out Thursday after repeated questioning from Rep. Jason Chaffetz, R-Utah, at a House Oversight and Government Reform Committee hearing on cyber threats. ABC News previously reported that the FBI was investigating a case in which counterfeit Cisco routers were being sold to various government agencies but this is the first time that a government official has confirmed that the threat is real.

Wednesday, May 25, 2011

dhs to gain 'autonomy' under obama cybersecurity plan

dhs merges with dod/nsa under obama's cyber threat plan
dhs merges with dod/nsa under obama's cyber threat planfrom kurt nimmo: Obama has proposed legislation that will give the Department of Homeland Security more “autonomy” in its effort to protect civilian computer networks from ostensible cyber attack, according to Information Week. White House officials testified Monday before the Senate Committee on Homeland Security and Governmental Affairs about the comprehensive plan presented by the administration two weeks ago to create legislation to protect critical infrastructure and networks. It will merge operations with the Pentagon.

“One key aspect of the plan is to put the DHS’s mission to protect U.S. federal civilian networks on par with the DOD’s mission to protect U.S. military networks, giving the DHS more autonomy to act against cyberthreats on behalf of the government than before,” writes Elizabeth Montalbano for the technology publication.

DHS has also sought to merge the effort with the NSA and various civilian operations.

Last October, the Obama administration adopted new procedures for using the Defense Department’s vast array of cyberwarfare capabilities in case of an attack on vital computer networks inside the United States, “delicately navigating historic rules that restrict military action on American soil,” according to the New York Times.

According to the Times, a team of military networking experts would be assigned to the operations center at the Homeland Security Department. The new approach will begin with a Department of Homeland Security team deploying to Fort Meade, Maryland, home to both the National Security Agency, which specializes in electronic espionage, and the military’s new Cyber Command.

At the time, government officials said the new rules contain “a rapid response to a cyberthreat while balancing concerns that civil liberties might be at risk should the military take over such domestic operations,” in other words the government announced effort to protect against the hyped threat of cyber terrorism would require a sacrifice of liberty.

The DHS plan announced on Monday will give “the DHS – recognizing our similar role to DOD with regard to federal civilian networks – similar authority with regard to personnel so we can bring them on board rapidly,” Philip R. Reitinger, deputy undersecretary for the DHS National Protection and Programs Directorate, told Congress.

The plan also gives DHS “much clearer authority and responsibility to work in a voluntary way” with the private sector, something it already has been doing, Reitinger added.

In 2009, Pentagon spokesman Bryan Whitman sidestepped answering if the Pentagon’s cyber command would be capable of offensive operations as well as protecting the Department of Defense. “This command is going to focus on the protection and operation of DoD’s networks,” he said. “This command is going to do what is necessary to be able to do that.”

In 2006, a Pentagon document entitled the Information Operation Roadmap was released to the public after a Freedom of Information Request by the National Security Archive at George Washington University. It states that the Pentagon has developed a “robust offensive suite of capabilities to include full-range electronic and computer network attack… We Must Fight the Net.”


related updates:
facebook & google join forces to oppose privacy bill*
18 places censored by google maps:
from aberdeen proving grounds in maryland to... north korea
*
nsa collects as much data as is stored in the entire library of congress every 6hrs?*
video: nsa whistleblower tom drake talks espionage act, 9/11 & intel with '60 minutes'*

Tuesday, May 24, 2011

dhs/ice start another round of 'pirate' domain seizures

dhs/ice start another round of 'pirate' domain seizuresfrom torrent freak: US authorities have resumed “Operation In Our Sites” and have seized several domain names associated with copyright infringement or counterfeit related crimes. Among the new targets are two sites that linked to copyrighted films hosted on third party streaming sites such as megavideo.com and veoh.com. Homeland Security’s Immigration and Customs Enforcement (ICE) has yet to officially announce the new operation.

Over the past several months a series of domain name seizures by the Department of Justice (DOJ) and Immigration and Customs Enforcement (ICE) made headlines across the Internet.

Under the flag of “Operation In Our Sites” the authorities shut down a dozen file-sharing and streaming sites and many more accused of selling counterfeit goods.

Today ICE continued the operation with a 4th round, and the first one since February this year. Although the authorities are yet to give an official comment on the new seizures, TorrentFreak was able to confirm the following targets:

* Re1ease.net
* Watchnewfilms.com
* Dvdcollectionsale.com
* Dvdscollection.com
* Dvdsetsonline.com
* Newstylerolex.com

The first two domains are accused of copyright-related offenses, but did not host any copyrighted films themselves. Both Re1ease.net and Watchnewfilms.com linked to popular movie streaming sites such as Veoh.com and Megavideo.com. The rest of the domains appear to be connected to sales of counterfeit goods.

The new targets were most likely put forward to ICE by movie industry groups. In April of this year ICE director John Morton admitted that his organization was acting based on “tips from industry representatives,” among others.

The authorities are also aware of the fact that the domain seizures themselves are not really an effective tool. As pointed out before, more than half of the piracy-related domains that were seized by Operation In Our Sites simply continued under a different name.

Morton replied to this critique by emphasizing that the seizures also act as “public education about pirating.”

To quash allegedly copyright infringing sites more effectively U.S. lawmakers introduced the PROTECT IP Act last week. Aside from domain seizures, the new bill will also make it possible to block sites on an ISP level, to censor search engines, and to cut funding of allegedly copyright-infringing websites.


flashbacks: government seizes domains alleged to infringe copyright & dhs seizes more domains; this time for linking to copyrighted material

Wednesday, March 16, 2011

white house wants new copyright law crackdown

white house wants new copyright law crackdownfrom cnet: The White House today proposed sweeping revisions to U.S. copyright law, including making "illegal streaming" of audio or video a federal felony and allowing FBI agents to wiretap suspected infringers. In a 20-page white paper (PDF), the Obama administration called on the U.S. Congress to fix "deficiencies that could hinder enforcement" of intellectual property laws... In October 2008, President Bush signed into law the so-called Pro IP ACT, which created Espinel's position and increased penalties for infringement, after expressing its opposition to an earlier version. Unless legislative proposals--like one nearly a decade ago implanting strict copy controls in digital devices--go too far, digital copyright tends not to be a particularly partisan topic. The Digital Millennium Copyright Act, near-universally disliked by programmers and engineers for its anti-circumvention section, was approved unanimously in the U.S. Senate. At the same time, Democratic politicians tend to be a bit more enthusiastic about the topic. Biden was a close Senate allypicked top copyright industry lawyers for Justice Department posts of copyright holders, and President Obama. Last year, Biden warned that "piracy is theft." No less than 78 percent of political contributions from Hollywood went to Democrats in 2008, which is broadly consistent with the trend for the last two decades, according to OpenSecrets.org.

related: dem rep intros bill to give dhs larger cybersecurity role

Monday, February 7, 2011

dhs seizes more domains; this time for linking to copyrighted material

dhs seizes more domains; this time for linking to copyrighted materialfrom eric blair: Apparently the Department of Homeland Security is now authorized to rewrite and enforce copyright infringement laws. In a stunning precedent, the recent round of domain seizures to shut down websites that allowed illegal streaming of the Super Bowl, also included a few other websites that were seized simply for linking to infringing content. Mike Masnick of TechDirt, who received and published a DHS seizure affidavit, had this to say in a must-read article:
...the affidavit itself is chock full of legal and technical errors, compounded by assertions-as-facts that seem to have little basis in reality... The biggest problem is that Homeland Security seems to suggest — without a hint of doubt — that merely linking to infringing content is criminal copyright infringement.
Additionally, this type of precedent would seem to massively change the Internet as we know it. What’s next, seizing websites that link to those affiliate sites, like Facebook, Google, or Twitter? Well, that’s the exact question Masnick investigated in his follow-up article, "Homeland Security Tries & Fails To Explain Why Seized Domains Are Different From Google"...

Despite the DHS’s obvious distortion of the law, we are rapidly approaching a day where information can no longer flow freely on the Internet. We better wake up and share these stories with everyone we know, because tyranny is fast approaching. These words written above belong to nobody but the open-source, free Internet. Share and re-post at will.


flashback: govt seizes domains alleged to infringe copyright

Monday, January 31, 2011

killswitch: obama admin fears egypt-style revolt in US

killswitch: obama admin fears egypt-style revolt in USfrom paul joseph watson: The Obama administration is busy attempting to pass legislation that would give the President a kill switch for the Internet in the United States while at the same time decrying Egyptian authorities for shutting down the Internet in a bid to deflate the unfolding revolution against Hosni Mubarak. The reason is simple – the government fears an Egypt-style revolt occurring in the U.S. and wants to block access to the world wide web if and when it happens... While Obama criticizes Egyptian authorities for shutting down web access to disrupt protesters, his own administration prepares to launch a fresh attempt at instituting the exact same powers in America, which as recent history clearly demonstrates, represent tools for tyrannical regimes who wish to silence legitimate political opposition.

related: dhs' new terror alert system to use facebook, twitter

Saturday, December 18, 2010

son of stuxnet?

Senate Committee on Homeland Security and Governmental Affairs was advised, last week, variant of Stuxnet poses threat to critical infrastructure, reports Christian Science Monitor. Cybersecurity experts believe modified Son of Stuxnet" could target wider range of control systems. Many facilities use a combination of Windows operating & Siemens control systems like Iran's nuclear facilities, attacked by the computer worm this past summer. "The concern for the future of Stuxnet is that the underlying code could be adapted to target a broader range of control systems in any number of critical infrastructure sectors," said Sean McGurk, acting director of the National Cybersecurity and Communications Integration Center at the US Department of Homeland Security.

Wednesday, December 1, 2010

government seizes domains alleged to infringe copyright

bittorrent based dns to counter US domain seizures
government seizes domains alleged to infringe copyrightfrom pcmag: The U.S. government has shut down several sites apparently suspected of either linking to or providing access to copyrighted materials. Visitors to Torrent-Finder.com and other sites were met with a notice that the site's domain name had been shut down by the Immigration and Customs Enforcement - Homeland Security Investigations department, pursuant to a seizure warrant that would apparently be issued by a judge in the future.

It was unclear how many sites the ICE took down or otherwise took over, with TorrentFreak publishing a list of sites that had been taken down. If that list is accurate, only a few apparently disseminated links to BitTorrent trackers, the master index for distributing a given file across the Internet through the BitTorrent network. Such sites included Torrent-Finder.com, but also mydreamwatches.com and nfljerseysupply.com, among others. Others apparently distributed rap music.

"ICE office of Homeland Security Investigations executed court-ordered seizure warrants against a number of domain names," ICE said in a written statement to the UPI. "As this is an ongoing investigation, there are no additional details available at this time."

The move appears to be completely independent of COICA, the Combating Online Infringement and Counterfeits Act making its way through the U.S. Senate.


related: in the wake of 'cablegate' -
why hasn't the govt seized the domain name wikileaks.org?*

uk police to get major new powers to seize domains*

update: dhs seizes more domains; this time for linking to copyrighted material

Saturday, October 23, 2010

dod leads cyber defense

Pentagon's Cyber Policy chief Robert Butler announces new relationships, "...in a break with previous policy, the military now is prepared to provide cyber expertise to other government agencies and to certain private companies to counter attacks on their computer networks...". Defense News article, "DoD Expanding Domestic Cyber Role" emphasizes utilizing cyber capabilities of the Pentagon.  Butler, who is a deputy assistant defense secretary, said "while the Department of Homeland Security officially remains the lead government agency on cyber defense, the new agreement 'sets up an opportunity for DHS to take advantage of the expertise' in the Pentagon, and particularly the secretive electronic spying agency, the National Security Agency." Is the Defense Department just helping out or is the military taking over?

related: booz allen hamilton staffers go to cybersecurity school

Tuesday, September 28, 2010

'cyber storm iii' tests US on cyber attack

stuxnet & cyberstorm3 are unrelated, nothing to see here...
'cyber storm iii' tests US on cyber attackfrom defencetalk: US keyboard warriors were doing battle Tuesday with a simulated cyberattack on government and private computer networks that undermines basic trust in the Internet. The "Cyber Storm III" exercise involves participants from seven US government departments, including the Pentagon, 11 US states, 60 private companies and 12 international partners.

The biennial exercise is being staged by the Department of Homeland Security and is the first test of the new National Cybersecurity and Communications Integration Center based in an office building in this Washington suburb. The NCCIC booted up in October 2009 to serve as the coordinating center for US cybersecurity operations and houses US government computer experts and their private sector counterparts under one roof.

Briefing reporters ahead of "Cyber Storm III," Brett Lambo, the director of DHS's Cyber Exercise Program, stressed that the exercise, which is expected to last three days, is "completely simulated... We're not attacking any real networks," Lambo said. "We're not taking down a network. We're not injecting any real malware."

The thousands of participants in the exercise will receive more than 1,500 "injects" of simulated events that they will have to react to as unknown adversaries seek to exploit known vulnerabilities in cyber infrastructure...

The international partners taking part in the exercise are from Australia, Britain, Canada, France, Germany, Hungary, Japan, Italy, the Netherlands, New Zealand, Sweden and Switzerland.


update: millions of comps hit by virus across china*
'cyber storm iii' simulates large-scale cyberattack*
dhs tests cyber response plan in global drill*
cyber attack on iranian industry appears well-funded*
iran says no virus hit nuclear systems*
in a computer worm, a possible biblical clue*

Wednesday, June 23, 2010

napolitano: US must balance liberties & cybersecurity

"those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety."
napolitano: US must balance liberties & cybersecurityfrom ap: Fighting homegrown terrorism by monitoring Internet communications is a civil liberties trade-off the U.S. government must make to beef up national security, the nation's homeland security chief said Friday.

As terrorists increasingly recruit U.S. citizens, the government needs to constantly balance Americans' civil rights and privacy with the need to keep people safe, said Homeland Security Secretary Janet Napolitano.

But finding that balance has become more complex as homegrown terrorists have used the Internet to reach out to extremists abroad for inspiration and training. Those contacts have spurred a recent rash of U.S.-based terror plots and incidents.

"The First Amendment protects radical opinions, but we need the legal tools to do things like monitor the recruitment of terrorists via the Internet," Napolitano told a gathering of the American Constitution Society for Law and Policy.

Napolitano's comments suggest an effort by the Obama administration to reach out to its more liberal, Democratic constituencies to assuage fears that terrorist worries will lead to the erosion of civil rights.

The administration has faced a number of civil liberties and privacy challenges in recent months as it has tried to increase airport security by adding full-body scanners, or track suspected terrorists traveling into the United States from other countries.