
Ads by Google
2Expand
How Active is Twitter Now? Tweespeed
Tags: social media surveillance, crowd mining on 2009-06-28 and saved by 3 people -All Annotations (2) -About
more fromradar.oreilly.com
-

-
As of Friday, June 26th, 2009 at 1:10PM PST Twitter is pumping out 13,574 tweets per minute. I know from TweeSpeed, The Twitter Instant Speed Meter. The auto-refreshing application averages the last five minutes of Twitter's public timeline to get its figure.
7Expand
DOD creates Cyber Command as U.S. Strategic Command subunit
-
Defense Secretary Robert Gates issued a much-anticipated order June 23 establishing the U.S. Cyber Command, which will assume responsibility for the defense of the military’s portion of cyberspace.
The new Cybercom will be a subunit of the U.S. Strategic Command and will be commanded by the director of the National Security Agency. It is expected to be headquartered with NSA at Fort Meade, Md., and to reach initial operating capacity in October, with full operating capacity coming in October 2010.
-
The order is recognition that cyberspace is a distinct military domain, along with land, sea and air, and the Defense Department must be prepared to defend and conduct offensive operations in it.
“Cyberspace and its associated technologies offer unprecedented opportunities to the United States and are vital to our nation’s security and, by extension, to all aspects of military operations,” Gates wrote in his order. “Yet our increasing dependency on cyberspace, alongside a growing array of cyber threats and vulnerabilities, adds a new element of risk to our national security. To address this risk effectively and to secure freedom of action in cyberspace, the Department of Defense requires a command that possesses the required technical capability and remains focused on the integration of cyberspace operations.”
-
Alan Paller, director of research at the SANS Institute, called the command a "spectacular idea" because it allows defense to be informed by offensive capabilities and offers the potential for increased interoperability, information sharing and visibility. It also could provide enhanced career paths for cybersecurity professionals.Add Sticky Note
- Cynical translation: "Yay! More jobs and money for us!"posted by TransTracker on 2009-06-26
-
Add Sticky Note
In remarks made last week, Deputy Defense Secretary William Lynn III said the new command does not represent an expansion of DOD’s mission in cyberspace. “On the contrary, it is keeping with our defined and historic mission, to protect and defend our national security and to protect the lives of our men and women in uniform,” he said.
He also stressed that “such a command would not represent the militarization of cyberspace. It would in no way be about the Defense Department trying to take over the government’s cybersecurity efforts. On the contrary, such a command would not be responsible for the security of civilian computer networks outside the Defense Department.”
- Cynical translation: "Move along! Nothing to see here! No militarization here...no how, no way! Move along!"posted by TransTracker on 2009-06-26
-
NSA’s director will be the Cybercom commander and carry the grade of general or admiral. The deputy commander positions at NSA and Cybercom would be separate.
1Expand
Maltego and Twitter!
Tags: social media surveillance, social_networking, crowd mining on 2009-06-25 -All Annotations (1) -About
more fromwww.paterva.com
2Expand
Seeing green - Iran on Twitter
Tags: iran, social media surveillance, cyberwar, crowd mining, social_networking on 2009-06-25 -All Annotations (3) -About
more fromwww.paterva.com
-
With many people setting their Twitter icon to green and Maltego’s ability to show icons in the graph we thought it would be interesting to visualize it! The graph below is the senders and receivers of Tweets that mentioned the word “Iran”. Click on the image for the full size screenshot.
-

2Expand
Twitter and disinformation in Iran
Very interesting application of an open source intelligence/social network analysis application to mapping Twitter conversations/communities.
Tags: cyberwar, social media surveillance, social_networking, crowd mining on 2009-06-25 -All Annotations (2) -About
more frompatronusanalytical.com
-
Over the past week there has been a lot of media coverage of the relationship between Twitter, the hybrid online/mobile communication service, and its impact on post election events in Iran. The argument that Twitter service in Iran is a critical opposition activist tool is already over-hyped so I won’t rehash them here. Rather, I think its worth shedding some light on how Twitter is being used to spread disinformation and who is doing it.
Twitspam has a continually updated list of suspected fake accounts that may have connections with Iranian security. I used some of these account names as a starting point for a quick and dirty analysis of their networks. -

9Expand
Cyber-Scare: The Exaggerate Fears over Digital Warfare
Tags: cyberwar on 2009-06-22 and saved by 2 people -All Annotations (9) -About
more fromwww.bostonreview.net
-
It is alarming that so many people have accepted the White House’s assertions about cyber-security as a key national security problem without demanding further evidence. Have we learned nothing from the WMD debacle? The administration’s claims could lead to policies with serious, long-term, troubling consequences for network openness and personal privacy.
-
There are certainly genuine security concerns associated with the Internet. But before accepting the demands of government agencies for new and increased powers to fight threats in cyberspace and prepare for cyber-warfare, we should look more closely at well-defined dangers and ask just where existing technological means and legal norms fall short.
-
In fact, what may be most remarkable about GhostNet is what did not happen. No computers belonging to the U.S. or U.K. governments—both deeply concerned about cyber-security—were affected; one NATO computer was affected, but had no classified information on it. It might be unnerving that the computers in the foreign ministries of Brunei, Barbados, and Bhutan were compromised, but the cyber-security standards and procedures of those countries probably are not at the global cutting edge. With some assistance on upgrades, they could be made much more secure.
-
So why is there so much concern about “cyber-terrorism”? Answering a question with a question: who frames the debate? Much of the data are gathered by ultra-secretive government agencies—which need to justify their own existence—and cyber-security companies—which derive commercial benefits from popular anxiety. Journalists do not help. Gloomy scenarios and speculations about cyber-Armaggedon draw attention, even if they are relatively short on facts.
Politicians, too, deserve some blame, as they are usually quick to draw parallels between cyber-terrorism and conventional terrorism—often for geopolitical convenience—while glossing over the vast differences that make military metaphors inappropriate.
-
Some might still argue that state sponsorship (or mere toleration) of cyber-terrorism could be treated as casus belli, but we are yet to see a significant instance of cyber-terrorists colluding with governments. All of this makes talk of large-scale retaliation impractical, if not irresponsible, but also understandable if one is trying to attract attention.
-
Much of the cyber-security problem, then, seems to be exaggerated: the economy is not about to be brought down, data and networks can be secured, and terrorists do not have the upper hand.
-
The militarization of cyberspace that inevitably comes with any talk of war is disturbing, for there is no evidence yet to link the current generation of cyber-attacks to warfare, at least not in the legal sense of the term.
-
it is important to bear in mind that the cyber-attacks on Estonia and especially Georgia did little damage, particularly when compared to the physical destruction caused by angry mobs in the former and troops in the latter. One argument about the Georgian case is that cyber-attacks played a strategic role by thwarting Georgia’s ability to communicate with the rest of the world and present its case to the international community. This argument both overestimates the Georgian government’s reliance on the Internet and underestimates how much international PR—particularly during wartime—is done by lobbyists and publicity firms based in Washington, Brussels, and London. There is, probably, an argument to be made about the vast psychological effects of cyber-attacks—particularly those that disrupt ordinary economic life. But there is a line between causing inconvenience and causing human suffering, and cyber-attacks have not crossed it yet.
-
In the meantime, those truly concerned about the future of the Internet, global security, and e-Katrinas would be advised to watch a recent South Park episode, in which the Internet suddenly disappears and hordes of obsessed families head to the Internet Refugee Camp in California, where they are allowed to browse their favorite Web sites for 40 seconds a day, while the military fights the no-longer-blinking giant Internet router. Finally, a nine-year-old boy plugs the router back in, and its magic green light returns. This would make a sensible strategy for many governments, which are all-too eager to adopt militaristic postures instead of focusing on making their own Internet infrastructures more robust.
1Expand
Update on Iran-Twitter-US cyber war
Tags: cyberwar, social media surveillance, crowd mining on 2009-06-17 -All Annotations (1) -About
more fromthreatchaos.com
-
Twitter has an issue ahead of them. After this experience the general populace has learned how to participate in cyber civil unrest. Twitter will be used in the future for hacking attacks and the targets of attacks may find legal cause to complain.
The State Department has created a huge issue by supporting Twitter. I hope they know what they are doing.
2Expand
Obama's Pentagon Budget: Not Enough for Defense
Tags: procurement, F-22, F-35, fcs on 2009-06-10 -All Annotations (2) -About
more fromwww.washingtonpost.com
-
Add Sticky Note
Procurement and research and development are the chief areas in which Defense Secretary Robert Gates has sought savings in the proposals he announced in April. He has proposed cuts to programs including the F-22 fighter, the DDG-1000 destroyer, the Army's Future Combat System, the presidential helicopter fleet, the transformational communications satellite, aircraft carrier production runs, the airborne laser missile defense program and the next-generation bomber. These are solid proposals; he could make additional cuts to the V-22 Osprey and the F-35 Joint Strike Fighter programs, as well as existing nuclear weapons platforms.
It is important to note, though, that these aren't cuts in current costs; they are cuts in plans. When you eliminate a defense program, you still typically must buy something to replace aging equipment, even if the alternative is less expensive. Moreover, a lot of equipment (much of it purchased under Ronald Reagan and the first President Bush) is wearing out, and we need to replace it soon.- Or....here's a radical idea. Maybe it would be cheaper to buy the shit we've already paid to develop! Ya know, instead of paying for it, then shit canning it, and then paying AGAIN to develop other stuff!! The problem with these kinds of "analyses" is that they never take into account the money we have already spent. They only consider from today forward. Long term responsibility with our defense dollars means not making decisions now that, in effect, wastes all the money we have already spent. But alas, politicians don't think that way.posted by TransTracker on 2009-06-10
3Expand
Henry A. Kissinger - North Korea's Nuclear Program Cannot Be Stopped by America Alone
Tags: WMD, nukes, proliferation on 2009-06-09 -All Annotations (3) -About
more fromwww.washingtonpost.com
-
De facto acquiescence in a North Korean nuclear program would require a reconsideration of U.S. strategic planning. More emphasis would need to be given to missile defense. It would be essential to redesign the American deterrent strategy in a world of multiple nuclear powers -- a challenge unprecedented in our experience. The enhanced role of non-state actors with respect to terrorism would have to be addressed. The concepts of deterrence against state actors are familiar, though not in a world of multiple nuclear powers. They have little or no relevance to non-state actors operating by stealth.
-
De facto acquiescence in a North Korean nuclear program would require a reconsideration of U.S. strategic planning. More emphasis would need to be given to missile defense. It would be essential to redesign the American deterrent strategy in a world of multiple nuclear powers -- a challenge unprecedented in our experience. The enhanced role of non-state actors with respect to terrorism would have to be addressed. The concepts of deterrence against state actors are familiar, though not in a world of multiple nuclear powers. They have little or no relevance to non-state actors operating by stealth.Add Sticky Note
- Unfortunately, it appears that we lack the resolve to do anything other than acquiesce. At the same time, Gates has cancelled missile defense and all major weapon modernization efforts (e.g. FCS, F-22, strategic bomber, etc.) under the assumption that state-level warfare is a thing of the past. The international threat environment and our force planning seem to be diverging rapidly, with threats heading in a direction that would suggest the possibility of state-level conflict while we build forces to optimized to re-fight the Iraqi and Afghan insurgencies.posted by TransTracker on 2009-06-09
9Expand
Computers and the Internet
-
ANYONE who follows technology or military affairs has heard the predictions for more than a decade. Cyberwar is coming. Although the long-announced, long-awaited computer-based conflict has yet to occur, the forecast grows more ominous with every telling: an onslaught is brought by a warring nation, backed by its brains and computing resources; banks and other businesses in the enemy states are destroyed; governments grind to a halt; telephones disconnect; the microchip-controlled Tickle Me Elmos will be transformed into unstoppable killing machines.
-
But how bad would a cyberwar really be — especially when compared with the blood-and-guts genuine article? And is there really a chance it would happen at all?
Whatever the answer, governments are readying themselves for the Big One.
-
Whatever form cyberwar might take, most experts have concluded that what happened in Estonia earlier this month was not an example.
-
Still, many in the security community and the news media initially treated the digital attacks against Estonia’s computer networks as the coming of a long-anticipated new chapter in the history of conflict — when, in fact, the technologies and techniques used in the attacks were hardly new, nor were they the kind of thing that only a powerful government would have in its digital armamentarium.
-
James Andrew Lewis, director of the Technology and Public Policy Program at the Center for Strategic and International Studies.
-
Add Sticky Note
Mr. Lewis stressed. “The idea that Estonia was brought to its knees — that’s when we have to stop sniffing glue,” he said.
In fact, an attack would have borne real risks for Russia, or any aggressor nation, said Ross Stapleton-Gray, a security consultant in Berkeley, Calif. “The downside consequence of getting caught doing something more could well be a military escalation,” he said.
That’s too great a risk for a government to want to engage in what amounts to high-tech harassment, Mr. Lewis said. “The Russians are not dumb,” he said.
- And yet, in early 2009, CSIS jumped on the cyber-hysteria bandwagon, with a report that cites the Estonia example in a document meant for the President that seems to imply that simple DDoS and/or cyber-espionage should be considered acts of war!posted by TransTracker on 2009-06-05
-
Add Sticky Note
Down on earth, by comparison, this correspondent found himself near the Kennedy Space Center in a convenience store without cash and with the credit card network unavailable. “The satellite’s down,” the clerk said. “It’s the rain.” And so the purchase of jerky and soda had to wait. At the center’s visitor complex, a sales clerk dealt with the same problem by pulling out paper sales slips.
People, after all, are not computers. When something goes wrong, we do not crash. Instead, we find another way: we improvise; we fix. We pull out the slips.
- Excellent point. Cyber-doom scenarios assume that people will respond to a massive attack with complete, paralyzing panic. But that didn't even happen during the massive strategic bombing campaigns of WWII. Instead, Londoners, for example, not only improvised, but they got pissed off...and more determined than ever to defeat their German attackers.posted by TransTracker on 2009-06-05
8Expand
‘Cyberwar’ and Estonia’s Panic Attack
-
We see, for example, that Estonia’s computer emergency response team responded to the junk packets with technical aplomb and coolheaded professionalism, while Estonia’s leadership … well, didn’t. Faced with DDoS and nationalistic, cross-border hacktivism — nuisances that have plagued the rest of the wired world for the better part of a decade — Estonia’s leaders lost perspective.
Here’s the best quote, from the speaker of the Estonian parliament, Ene Ergma: "When I look at a nuclear explosion, and the explosion that happened in our country in May, I see the same thing." -
Cyberwars were supposed to target critical infrastructures beyond the internet, like the SCADA systems that control elements of the power grid; air traffic control networks; nuclear power plant safety systems. In other words, real cyberwarriors aren’t interested in clogging the public internet like spammers; they use the internet as a path to sensitive, private networks where sabotage has some hope of causing physical, real-world mayhem that outlasts the attack. (DDoS barely rated a walk-on role in DHS’s comprehensive Cyber Storm exercise last year.)
-
I’m skeptical that real cyberwar, or cyberterrorism, will ever take place. But what is certain is that the Estonia DDoS does nothing to illuminate our risk of it. No new attack techniques surfaced; the level of traffic was not surprising; the mitigation tactics were tried and true and, of course, successful. That Estonia’s public internet is small and easily overrun doesn’t change anything for the U.S.
-
While cyberhawks fancy themselves Cassandras preaching to an oblivious world, dire predictions of a Red cyberdawn were widely accepted in the halls of power for years. Condaleeza Rice voiced concerns in March 2001; six months later, September 11 provided a grim reminder that America’s enemies prefer shedding blood over bytes.
-
Add Sticky Note

- AWESOME!!posted by TransTracker on 2009-06-04
-
Add Sticky Note
If we cast computer attacks in military terms, we invite military thinking where defensive technical solutions are needed. You can see the outline of where this is headed in the magazine. Peters, a former Army intelligence officer, writes not a word in support of the many serious efforts to close vulnerabilities in civilian and military networks. But he laments that in an age of cyberwar, America is burdened by "our own insistence of confining all forms of warfare within antiquated laws."
We see it in Estonia too. While cooler heads were combating the first wave of Estonia’s DDoS attacks with packet filters, we learn, the country’s defense minister was contemplating invoking NATO Article 5, which considers an "armed attack" against any NATO country to be an attack against all. That might have obliged the U.S. and other signatories to go to war with Russia, if anyone was silly enough to take it seriously.- Exactly! Framing "cyberwar" as "war" makes it a military issue, leading to military ways of thinking and military forms of response. This, in turn, increases the risk of needless conflict escalation. Hawks like Peters (and many, many others) seek to define cyberwar as entirely new, with all existing laws governing the use of force as "antiquated." The risk of escalation is real because hawks are working hard to toss existing laws and norms in an attempt to define acts that would not traditionally be considered "use of force" or "acts of war" as precisely that, thus providing justification for launching physical military responses to DDoS attacks.posted by TransTracker on 2009-06-05
3Expand
When Bots Attack
Tags: cyberwar on 2009-06-04 and saved by 7 people -All Annotations (3) -About
more fromwww.wired.com
-
In this hypothetical scenario, a single attack launched by China against the US lasts only a few hours, but a full-scale assault lasting days or weeks could bring an entire modern information economy to its knees.
-
Add Sticky Note

- Classic! A bot net "attack" portrayed in the manner of a Cold War-era ICBM attack!posted by TransTracker on 2009-06-04
2Expand
NSA Must Examine All Internet Traffic to Prevent Cyber Nine-Eleven, Top Spy Says
-
The nation’s top spy, Michael McConnell, thinks the threat of cyberarmageddon! is so great that the U.S. government should have unfettered and warrantless access to U.S. citizens’ Google search histories, private e-mails and file transfers, in order to spot the cyberterrorists in our midst.
That’s according to a sprawling 18-page story on the Director of
National Intelligence by Lawrence Wright in the January 21 edition of the New Yorker. (The story is not online).In the piece, McConnell returns, in flamboyant style, to his exaggerating ways, hyping threats and statistics to further his bureaucratic aims. For example, McConnell regurgitates the hoary myth that computer crime costs America $100 billion a year. THREAT LEVEL traced down the source of that fake-factoid in September to a former privacy officer for the state of Colorado.
-
Presumably using unsupported stats like that, in May 2007 McConnell convinced President Bush that a massive cyber-attack on a single U.S. bank would be worse for the economy than than the deadly terrorist attacks of September 11, the article reports. In response, the NSA developed a mind-boggling, but still incomplete, plan to eavesdrop on the internet in order to protect it.
In order for cyberspace to be policed, Internet activity will have to be closely monitored. Ed Giorgio, who is working with McConnell on the plan, said that would mean giving the government the authority to examine the content of any e-mail, file transfer, or Web search. "Google has records that could help in a cyber-investigation," he said. Giorgio warned me, "We have a saying in this business: ‘Privacy and security are a zero-sum game.’"
It says something ominous about McConnell’s priorities if he believes a DDOS attack on Bank of America, or even a computer intrusion that wiped out its database (and magically purged its backup tapes), would be worse than an attack that killed 3,000 Americans.
Still, it’s hardly a surprising plan — given that McConnell was one of the main backers of the Clipper Chip, the government’s failed, early 1990’s proposal to put a backdoor in every encryption product.
6Expand
Fake Factoid Virus: ‘Cybercrime More Lucrative Than Drug Trade’
-
If you’ve been reading Slashdot, you’re probably stunned to learn that cybercrime has just now ballooned into a $105 billion industry, making it more lucrative than the global trade in illegal drugs. This from David DeWalt, CEO of anti-virus vendor McAfee, who dropped the billion-dollar bombshell at a conference in Tucson, where it was uncritically reported by InformationWeek.
-
The $105 billion figure has been bouncing around the media like a bad check for two years, being quietly debunked by security experts and the tech press (including InformationWeek, in 2005), even as the more mainstream media nurture and love it.
-
It all started with a quote in a Reuters story from technology consultant Valerie McNevin the former privacy officer for the state of Colorado
-
There’s no evidence that McNevin offered anything to back up her claim (and the $105 billion figure for drug profits is flat-out wrong).
-
Confused? No longer! Here’s THREAT LEVEL’s flowchart of how this fake news has gotten around, and occasionally encountered resistance.
-

4Expand
Did Hackers Cause the 2003 Northeast Blackout? Umm, No
-
Chinese hackers may have been responsible for the recent power outage in Florida, and the widespread blackout that struck the northeastern U.S. in 2003, according to a new report in the National Journal that shows the intelligence community taking cyberwar hysteria to new and dizzying heights.
The story, citing computer security professionals, who in turn cite unnamed U.S. intelligence officials, says that China’s People’s Liberation Army may have cracked the computers controlling the U.S. power grid to trigger the cascading 2003 blackout that cut off electricity to 50 million people in eight states and a Canadian province. -
It’s official: Cyberterror is the new yellowcake uranium.
Ever since intelligence chief Michael McConnell decided on cyberterrorism as the latest raison d’etre for warrantless NSA surveillance, we’ve seen increasingly brazen falsehoods and unverifiable cyberattack stories coming from him and his subordinates, from McConnell’s bogus claim that cyberattacks cost the U.S. economy $100 billion a year, to one intelligence official’s vague assertion that hackers have caused electrical blackouts in unnamed countries overseas.This time, though, they’ve attached their tale to the most thoroughly investigated power incident in U.S. history.
-
The detailed 228-page final NERC report found a complex confluence of events responsible, but not a single hacker. It traced the root cause of the outage to the utility company FirstEnergy’s failure to trim back trees encroaching on high-voltage power lines in Ohio. When the power lines were ensnared by the trees, they tripped.
-
Or maybe I’m being naive. Maybe there were no trees. Implicit in this new cyberterror tale is the suggestion that everybody who investigated the 2003 blackout, including FirstEnergy, the Department of Energy, the Federal Energy Regulatory Commission, and the civilian North American Electric Reliability Council, were part of a massive conspiracy to conceal a (pointless) Chinese hack attack from the American people.
Now that we’re seeing "overgrown trees" between the same scare quotes conspiracy theorists bracket around "lone gunman" and "moon landing," the cybarmageddon hawks have squarely set foot in the realm of 9/11 truthers. I’m waiting for them to blame Chinese hackers for "Hurricane" Katrina.
14Expand
Is the Hacking Threat to National Security Overblown?
-
Is hacking a real threat to the United States or is it just the latest overblown threat to national security, whose magnitude is being exaggerated to expand government budgets and power?
-
Add Sticky Note
Amit Yoran, a former Bush Administration cybersecurity czar, argues the answer is easy.
“Is hacking a national security threat?” Yoran said. “The one word answer is ‘Yes.’”
As proof, Yoran pointed to stories about the denial-of-service attacks in Estonia, attacks on government contractor Booz Allen Hamilton and the recently reported breach of defense contractor computers that let hackers get at information on the Joint Strike Fighter.
“Cyber 9-11 has happened over the last 10 years, but it’s happened slowly so we don’t see it,” Yoran said.
- Cyber 9-11 in slow motion! Nice! This is the first time I've heard this rationale. All those cyber-doom scenarios we've heard for almost 20 years now have yet to come close to being realized. So, take the cyber 9-11, cyber Katrina, cyber Pearl Harbor, etc. and turn them into long, slow events. But, by definition, a long slow 9-11 is NOT 9-11 anymore!posted by TransTracker on 2009-06-04
-
Poulsen called the threat of cyber-terrorism “preposterous,” citing the long-standing warnings that hackers would attack the power grid — despite the fact that it has never happened. And he argued that calling such intrusions national security threats means information about attacks gets classified unnecessarily.
-
Dr. Herb Lin, a cyberattack expert at the National Research Council, called the scoffing naive, saying he could imagine hackers getting into classified command-and-control systems, for one.Add Sticky Note
- Yes, so can I. I can IMAGINE all sorts of crazy shit! So can lots of other people. (Authors of sci-fi novels and movies have been making boat loads of money based on this capability for years.) But just because you can imagine it does not mean it is a real threat! So far, cyberwar discourse is long on imagined cyber-doom scenarios and short of real, empirical evidence.posted by TransTracker on 2009-06-04
-
But he lamented that much of the current dialogue is about about cyberwar and cyber-terror, when the largest threat is in cyber-espionage — which is not considered an act of war.Add Sticky Note
- So, is he suggesting that espionage, when conducted via cyberspace, should now be considered an "act of war?" If so, that's complete bullshit.posted by TransTracker on 2009-06-04
-
Add Sticky Note
Yoran did admit that cyber-terrorism was improbable, but stuck to his point that there are significant national security threats from hackers.
Lin says the government needs to think about getting its own cyberattack capability.
- Translation: "We admit that a large part of what we tried to use to scare you in the past has turned out to be a bunch of BS, but believe us about the new scenarios we're trying to use to scare you, and then give us lots of money so that we can learn to attack people ourselves."posted by TransTracker on 2009-06-04
-
Add Sticky Note
Lin was dumbstruck by Poulsen’s dismissal of the examples that the government, including President Obama, have used as evidence that there is a massive cybersecurity threat — specifically Obama’s recent description of a November USB thumb-drive virus attack as one of the biggest cyberattacks against the U.S. military.
“Why is something that is an obvious threat not considered a threat to national security?” Lin asked.
“The point is that the way you frame these issues matters,” Schneier explained.
- Classic use of the realist style by Lin. Act as though all of this is just "obvious"; anyone who doesn't see it that way is just "naive." And yet, if it really were obvious, he and Yoran, and others, wouldn't have to work so hard to scare folks with IMAGINED cyber-doom scenarios that never seem to come close to be realized in REALITY. Indeed, Schneier is correct, the "framing" of all of this is important; the process of "securitization" taking place is really the interesting part.posted by TransTracker on 2009-06-04
-
In fact, they do matter — since now the government is pouring billions of dollars into cybersecurity for its own networks, and possibly the general public’s net — a far change from the government’s relative indifference to such issues until about two years ago.Add Sticky Note
- Exactly! It matters because if we're going to spend billions of dollars on to combat a threat, that threat needs to be based on something more than an "expert" saying "trust me, it's real because I can imagine it!"posted by TransTracker on 2009-06-04
6Expand
Fending Off Attacks in Cyberspace
Tags: cyberwar on 2009-05-30 and saved by 2 people -All Annotations (6) -About
more fromroomfordebate.blogs.nytimes.com
-
Overseeing the Cybermonitor

James Bamford is a writer and documentary producer specializing in intelligence and national security issues. His most recent book, his third on the National Security Agency, is “The Shadow Factory: The Ultra-Secret NSA, From 9/11 to the Eavesdropping on America.”
-
Because the new cyber czar will have neither a checkbook nor direct access to President Obama, the role will be more analogous to a traffic cop than a czar.
-
The person who does have both the president’s ear and an enormous war chest is Secretary of Defense Gates. While today’s spotlight is on the civilian side of cyberdefense, the real battle for control over cyberspace is taking place behind cipher-locked doors at the Pentagon.
-
In addition, we are seeing the start of the usual hype attacks — dire warnings by anomalous government officials — that always accompany the creation of a new euphemistic “war,” such as the “war” on drugs and the “war” on terrorism. Cyberwar is a real threat and it need not be hyped
-
Arms Control in Cyberspace

Ron Deibert is the director of the Citizen Lab at the Munk Centre for International Studies at the University of Toronto. He is the co-founder of the Information Warfare Monitor report, and one of the principal investigators and a co-author of the GhostNet study investigating alleged Chinese cyberespionage.
-
The president acknowledges the globally interconnected character of cyberspace in detail. But curiously there is not even a strategic vision, much less a blueprint, for how the United States will work to protect global networks as part of its own security.
Indeed, the biggest black hole — likely to remain as such — concerns U.S. offensive operations in cyberspace, which presumably include everything from denial of service attacks to targeted malware to Web 2.0 psychological operations.
I rather naively hoped today would have been President Obama’s Eisenhower moment, an opportunity to lay out a grand strategic vision for “Bits for Peace” (or maybe an “Open Net Initiative”?) and take leadership in swiftly controlling weapons in cyberspace worldwide. Instead, it is almost certain (and it is among the worst kept secrets) that a stamp of approval is forthcoming for the Pentagon’s plans to fight and win wars in cyberspace.
Undoubtedly the move will trigger an escalation of attack strategies and incidences from adversaries, including Russia and China, who will see the U.S. policy as a ratcheting of threats and a legitimization of such tactics. And we can expect more debilitating attacks on Websites and services, contracted out to third parties to muddy attribution issues and allow for plausible deniability.
Today’s announcement does nothing to explain how to secure against the chaos unleashed by that threat. Ultimately the assurance of security for every nation’s critical infrastructure must include an international dimension that preserves the openness of global cyberspace.
13Expand
Pentagon Plans New Arm to Wage Cyberspace Wars
-
The Pentagon plans to create a new military command for cyberspace, administration officials said Thursday, stepping up preparations by the armed forces to conduct both offensive and defensive computer warfare.
The military command would complement a civilian effort to be announced by President Obama on Friday that would overhaul the way the United States safeguards its computer networks.
-
Add Sticky Note
White House officials say Mr. Obama has not yet been formally presented with the Pentagon plan. They said he would not discuss it Friday when he announced the creation of a White House office responsible for coordinating private-sector and government defenses against the thousands of cyberattacks mounted against the United States — largely by hackers but sometimes by foreign governments — every day.
But he is expected to sign a classified order in coming weeks that will create the military cybercommand, officials said. It is a recognition that the United States already has a growing number of computer weapons in its arsenal and must prepare strategies for their use — as a deterrent or alongside conventional weapons — in a wide variety of possible future conflicts.
- Indeed, announcements of impending secret plans to authorize the offensive use of cyber-weapons were not forthcoming in today's press conference.posted by TransTracker on 2009-05-29
-
Officials said that in addition to the unclassified strategy paper to be released by Mr. Obama on Friday, a classified set of presidential directives is expected to lay out the military’s new responsibilities and how it coordinates its mission with that of the N.S.A., where most of the expertise on digital warfare resides today.Add Sticky Note
- So much for openness and transparency, at least on the scariest and most important part of all of this!posted by TransTracker on 2009-05-29
-
The decision to create a cybercommand is a major step beyond the actions taken by the Bush administration, which authorized several computer-based attacks but never resolved the question of how the government would prepare for a new era of warfare fought over digital networks.Add Sticky Note
- Mr. President 2.0 going further than anyone in terms of militarizing cyberspace. But it's OK, because he uses a Blackberry and is on Twitter!posted by TransTracker on 2009-05-29
-
It is still unclear whether the military’s new command or the N.S.A. — or both — will actually conduct this new kind of offensive cyberoperations.Add Sticky Note
- They've made it absolutely clear that they would very much like to use offensive cyber-weapons. If allowed to have them and given a whole separate command, that definitely ups the chances, no?posted by TransTracker on 2009-05-29
-
The White House has never said whether Mr. Obama embraces the idea that the United States should use cyberweapons, and the public announcement on Friday is expected to focus solely on defensive steps and the government’s acknowledgment that it needs to be better organized to face the threat from foes attacking military, government and commercial online systems.
Defense Secretary Robert M. Gates has pushed for the Pentagon to become better organized to address the security threat.
-
Officials declined to describe potential offensive operations, but said they now viewed cyberspace as comparable to more traditional battlefields.
“We are not comfortable discussing the question of offensive cyberoperations, but we consider cyberspace a war-fighting domain,“ said Bryan Whitman, a Pentagon spokesman. “We need to be able to operate within that domain just like on any battlefield, which includes protecting our freedom of movement and preserving our capability to perform in that environment.”
-
The creation of the cyberczar’s office inside the White House appears to be part of a significant expansion of the role of the national security apparatus there. A separate group overseeing domestic security, created by President George W. Bush after the Sept. 11 attacks, now resides within the National Security Council. A senior White House official responsible for countering the proliferation of nuclear and unconventional weapons has been given broader authority. Now, cybersecurity will also rank as one of the key threats that Mr. Obama is seeking to coordinate from the White House.Add Sticky Note
- All of this represents not only a broadening of the NSC's role, but also a broadening of what is considered a "national security issue." That category now includes theft of intellectual property--i.e. illegal movie and music downloading.posted by TransTracker on 2009-05-29
1Expand
Starlight Demo - Text and UAV Video Analysis
Video demo of a software package developed at PNNL for doing visual analysis of mass amounts of qualitative data.
Tags: intelligence on 2009-05-28 -All Annotations (1) -About
more fromwww.youtube.com
1Expand
Israeli soldiers preach Facebook vigilantism
From the man who started the panic over Twitter supposedly causing panic, more panic over Facebook supposedly empowering holocaust deniers and causing terrorism.
Tags: social_networking, Military, terrorism, social_media on 2009-05-23 -All Annotations (1) -About
more fromneteffect.foreignpolicy.com
-
Now, there is one more reason for Israel to hate Facebook: not only does it empower Holocaust deniers, it also helps to promote terrorism...
Notation: * = Private bookmark and comment|… = Clipping [?] | … = Public highlight [?]
Recent Tags (36)
- 57cyberwar,
- 23social media surveillance,
- 23crowd mining,
- 13science2.0,
- 12social_media,
- 12microblogging,
- 9kylin,
- 6social_networking,
- 5scholarship2.0,
- 5military,
- 5intelligence,
- 3complexity,
- 3new_media,
- 3cyber command,
- 2visualization,
- 2blogosphere analysis,
- 2milblogging,
- 2military theory,
- 2fcs,
- 2procurement,
- 2iran,
- 2wmd,
- 2proliferation,
- 2information sharing,
- 1blogging,
- 1israel,
- 1army,
- 1open source,
- 1coin,
- 1web2.0,
- 1collaboration,
- 1argumentation_debate,
- 1terrorism,
- 1nukes,
- 1f-35,
- 1f-22
Public Tags (103)
- 84GW,
- 5Academic,
- 14airpower,
- 27air_force,
- 1al-jazeera,
- 8Arab-Israeli Conflict,
- 1argumentation_debate,
- 3army,
- 1Barnett,
- 1biometrics,
- 6blogging,
- 6blogosphere analysis,
- 2boyd,
- 1C4ISR,
- 1cameras,
- 1cebrowski,
- 1Citizen,
- 1cloud computing,
- 22coin,
- 13collaboration,
- 5complexity,
- 23crowd mining,
- 8cyber command,
- 3cyber-vigilantism,
- 105cyberwar,
- 11dod_blogger_outreach,
- 2e-gov,
- 4evernote,
- 7F-22,
- 4F-35,
- 4f2c2,
- 1facebook,
- 24fcs,
- 2Flexibility,
- 2foreign policy,
- 11future war,
- 6Futuring,
- 2gadgets,
- 4Gaming_Simulation,
- 12General,
- 4Global,
- 1gps,
- 17GWOT,
- 28Info,
- 10information sharing,
- 1information society,
- 72InfoWar,
- 30intelligence,
- 2Interpretive,
- 7iran,
- 25Iraq,
- 4israel,
- 3it,
- 9kylin,
- 1LCS,
- 4mashup,
- 13microblogging,
- 47MilBlogging,
- 48Military,
- 8military theory,
- 5military_reform,
- 6Movement,
- 1Navy,
- 10ncw,
- 1network society,
- 34Network-Centric,
- 23new_media,
- 3nonlinear_science,
- 5nukes,
- 2OODA,
- 18Open,
- 2open source,
- 15opsec,
- 1oral history,
- 4perception management,
- 11petraeus,
- 12procurement,
- 10proliferation,
- 1RefManExport,
- 6Reform,
- 1rss,
- 8scholarship2.0,
- 15science2.0,
- 1Security,
- 28Sharing,
- 23social media surveillance,
- 41social_media,
- 13social_networking,
- 18Source,
- 4Strike,
- 2STS,
- 1systems science,
- 10TechNews,
- 5technology,
- 14terrorism,
- 43Transformation,
- 82TransTracker,
- 1UAVs,
- 10videogames,
- 5visualization,
- 34Warfare,
- 5web2.0,
- 10WMD



