Risk
3/9/2009
06:29 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

U.S. Cybersecurity Director Resigns, Blames NSA

Rod Beckstrom criticizes the NSA's dominance of most of the nation's cybersecurity initiatives.

The government's director of cybersecurity resigned Thursday, warning that the National Security Agency's control of national cybersecurity efforts poses a potential threat to U.S. democratic processes.

Rod Beckstrom, a former Silicon Valley entrepreneur, was appointed in March 2008 to run the National Cybersecurity Center, a group created to oversee government cybersecurity efforts.

In his March 5 resignation letter, a copy of which was published by The Wall Street Journal, Beckstrom criticized the NSA's dominance of most of the nation's cybersecurity initiatives.

"While acknowledging the critical important of the NSA to our intelligence efforts, I believe this is a bad strategy on multiple grounds," he wrote. "The intelligence culture is very different than a network operations or security culture. In addition, the threats to our democratic processes are significant if all top-level government network security and monitoring are handled by one organization (either directly or indirectly)."

Beckstrom said he supports a model that allows for a civilian government cybersecurity capability operating in partnership with the NSA, but not controlled by it. He also made it clear that he was unhappy with the lack of funding at the NCSC, noting that the organization "received only five weeks of funding, due to various roadblocks engineered with the [Department of Homeland Security] and by the Office of Management and Budget."

U.S. Rep. Yvette Clarke, D-NY, who chairs the House Subcommittee on Emerging Threats, Cybersecurity, Science, and Technology, expressed regret over Beckstrom's departure and blamed the Bush administration for hobbling Beckstrom's efforts by withholding funds.

"Mr. Beckstrom's departure is a huge loss for the department," Clarke said in an e-mailed statement. "If the last administration had provided him with the appropriate resources and staffing, he would have been extremely effective."

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4497
Published: 2015-08-29
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token...

CVE-2015-4498
Published: 2015-08-29
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point i...

CVE-2014-9651
Published: 2015-08-28
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."

CVE-2015-1171
Published: 2015-08-28
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.

CVE-2015-2987
Published: 2015-08-28
Type74 ED before 4.0 misuses 128-bit ECB encryption for small files, which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smaller than 128 bits.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.