Risk
7/6/2010
01:36 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Senate Seeks White House Help On Cybersecurity Bill

In a letter to Obama, key senators have asked for administration support in crafting comprehensive cybersecurity legislation.

The Senate is continuing to push forward with plans to develop comprehensive cybersecurity legislation, with seven key senators last week writing a letter to President Obama seeking White House support in crafting a bill.

The Senate has recently begun ramping up efforts to combine its disparate cybersecurity legislative efforts into a single, comprehensive bill in an effort led by Senate majority leader Harry Reid, D-Nev., while the public profile of Senate efforts has also increased, sparked by concerns about privacy and the extent of Presidential power over the Internet.

"Executive branch leadership is key to the nation's cybersecurity and we are eager to hear your views on the optimal organizational structure, necessary updates and reforms to legislation and regulations governing communications networks and information systems, and additional authorities needed to facilitate effective government leadership and response to cyber threats and vulnerabilities," the letter said.

The letter's signatories themselves may indicate a bit about Sen. Reid's strategy for getting legislation passed, as the six other senators signing the letter are all chairmen of committees likely to have an interest in any cybersecurity legislation: Armed Services Committee chairman Carl Levin, D-Mich; Commerce, Science and Transportation Committee chairman Jay Rockefeller, D-W.Va.; Select Committee on Intelligence chairwoman Dianne Feinstein, D-Calif.; Judiciary Committee chairman Patrick Leahy, D-Vt.; Foreign Relations Chairman John Kerry, D-Mass.; and Homeland Security and Government Affairs chairman Joseph Lieberman, I-Conn.

The letter itself give any sense of timing for a comprehensive bill. However, Lieberman and Senate staffers have said that Reid wants a bill passed sometime this year.

While Reid has taken command of the issue in the Senate, the comprehensive strategy in the House of Representatives is less clear. The House has actually passed cybersecurity legislation this session, including some language in a military appropriations bill and a cybersecurity research and development bill, though senior lawmakers on the House Homeland Security Committee have expressed support for a Senate bill recently offered by Lieberman, Susan Collins, R-Maine, and Thomas Carper, D-Del.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3541
Published: 2014-07-29
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVE-2014-3542
Published: 2014-07-29
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...

Best of the Web
Dark Reading Radio