Friday, February 08, 2008

Bush Admin Plans to Install Black Box Sensors on Private Computer Networks


Posted by Peter Swire, Think Progress at 11:38 AM on February 5, 2008.


This proposal repeats the mistakes of the Federal Intrusion Detection Network, which proposed similar monitoring of private systems in 1999.
fsia

Share and save this post:
Digg iconDelicious iconReddit iconFark iconYahoo! iconNewsvine! iconFacebook iconNewsTrust icon

Got a tip for a post?:
Email us | Anonymous form

Get PEEK in your
mailbox!


The Bush administration wants to place more black boxes on private-sector computer networks. We've already learned a lot about the NSA wiretap program and its Narus STA 6400 splitter -- that's the black box that AT&T whistleblower Mark Klein reported the NSA placed at a major node for voice and Internet communications (inside this secret room).

The president's budget wants to go much further. It moves beyond telcos and allocates $6 billion for a secretive system that is designed to protect government and private computer systems from attack. According to the Wall Street Journal, the White House proposal "would likely require the government to install sensors on private, company networks."

This proposal repeats the mistakes of the Federal Intrusion Detection Network, which proposed similar monitoring of private computer systems when it was proposed in 1999. That aspect of FIDNet was quickly withdrawn, for at least three good reasons:

1. Private companies are understandably reluctant to permit the government to attach unknown hardware or software to their corporate systems. The risks of security breach and operational problems are too high, especially given the long history of computer security failures by the federal agencies themselves.

2. Direct federal intervention in private computer systems raises innumerable legal and policy issues about privacy, the Fourth Amendment, and the scope of government surveillance.
3. The new proposal ignores the sensible principles for cybersecurity that were adopted in the wake of the FIDNet fiasco and built into the Federal Computer Incident Response Center. Quite simply, the federal government should adopt best security practices that apply to private systems.
Under the better approach, the federal government should adopt state-of-the-art intrusion detection software and other measures for its own systems to combat intrusions into federal systems. The federal government should not, however, try to install its equipment into private systems.

Digg!

Tagged as: technology, computers, bush administration, wiretapping

Peter Swire, is a senior fellow at the Center for American Progress and served as the Clinton Administration’s Chief Counselor for Privacy.

No comments: