Comments
NSA's Rogers: No White House Request for Action Against Russian Hacking
Newest First  |  Oldest First  |  Threaded View
jbconner
50%
50%
jbconner,
User Rank: Apprentice
2/28/2018 | 1:01:38 PM
SO he's admitting that he is not doing his job?
"his agency has not been asked to do anything about Russian hackers targeting the US election system. Rogers told the committee that he doesn't "have the day-to-day authority" to authorize activity to counter the attacks"

"He also confirmed that he has shared with individuals in the Trump administration his opinion on the attacks and what might be done to stop them."

"But Rogers said he has neither asked for, nor volunteered, a formal plan in writing."

Isn't it his job to develop a formal plan of exactly what his agency would do to combat this threat and then formally submit that in writing to the White House for approval? Does he sit around always waiting for someone to request that he do his job, and doesn't do anything until then? Shouldn't the heads of all the intelligence agencies be constantly developing plans to deal with not only this threat, but all other threats to national security? And if they don't have the authority to implement those plans, then submit those plans to the commander-in-chief and the White House for approval? And not just tell a few people about their opinions?

If they did that and the request was turned down by the White House, then this would be a different story. But as is, it is partisan BS being pushed by media bias.

If someone asked me what I was doing to prevent a breach into my organization, and I said that I haven't had any request from my executive officers for any action to prevent a breach, so I'm not developing a plan to submit to them for approval, I would be justifiably FIRED for not doing my job.


Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20173
PUBLISHED: 2018-12-17
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2017-18352
PUBLISHED: 2018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVE-2017-18353
PUBLISHED: 2018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
CVE-2017-18354
PUBLISHED: 2018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
CVE-2017-18355
PUBLISHED: 2018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.