Risk
3/9/2009
06:29 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

U.S. Cybersecurity Director Resigns, Blames NSA

Rod Beckstrom criticizes the NSA's dominance of most of the nation's cybersecurity initiatives.

The government's director of cybersecurity resigned Thursday, warning that the National Security Agency's control of national cybersecurity efforts poses a potential threat to U.S. democratic processes.

Rod Beckstrom, a former Silicon Valley entrepreneur, was appointed in March 2008 to run the National Cybersecurity Center, a group created to oversee government cybersecurity efforts.

In his March 5 resignation letter, a copy of which was published by The Wall Street Journal, Beckstrom criticized the NSA's dominance of most of the nation's cybersecurity initiatives.

"While acknowledging the critical important of the NSA to our intelligence efforts, I believe this is a bad strategy on multiple grounds," he wrote. "The intelligence culture is very different than a network operations or security culture. In addition, the threats to our democratic processes are significant if all top-level government network security and monitoring are handled by one organization (either directly or indirectly)."

Beckstrom said he supports a model that allows for a civilian government cybersecurity capability operating in partnership with the NSA, but not controlled by it. He also made it clear that he was unhappy with the lack of funding at the NCSC, noting that the organization "received only five weeks of funding, due to various roadblocks engineered with the [Department of Homeland Security] and by the Office of Management and Budget."

U.S. Rep. Yvette Clarke, D-NY, who chairs the House Subcommittee on Emerging Threats, Cybersecurity, Science, and Technology, expressed regret over Beckstrom's departure and blamed the Bush administration for hobbling Beckstrom's efforts by withholding funds.

"Mr. Beckstrom's departure is a huge loss for the department," Clarke said in an e-mailed statement. "If the last administration had provided him with the appropriate resources and staffing, he would have been extremely effective."

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3861
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

CVE-2014-3862
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

CVE-2014-5076
Published: 2014-09-02
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVE-2014-5452
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.

CVE-2014-6041
Published: 2014-09-02
The Android Browser application 4.2.1 on Android allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.