Risk
8/1/2007
04:58 PM
50%
50%

What Richard Clarke Was Really Saying At Black Hat

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.Clarke, chief counterterrorism adviser on the U.S. National Security Council during portions of the Bill Clinton and George W. Bush administrations and currently chairman of Good Harbor Consulting, has been known to wear his politics on his sleeve. Although he served during both the Clinton and Bush administrations, let's just say he's not been impressed with the latter. He even suggested that the Bush Administration's lack of funding for important technology developments will create serious impediments for the U.S.

Clarke criticized the current Bush Administration's policies against stem-cell research and its opposition to the development of human-machine interface technologies. The question is, "are humans beginning to take control of their own evolution and is that a good thing or a bad thing?" he asked the crowd Wednesday at the Black Hat USA 2007 conference in Las Vegas. "We need to start thinking about it now."

Clarke operated at the highest level of the federal government, and he's no novice when it comes to IT security or to Black Hat. Clarke keynoted Black Hat during President Bush's first term. "When I got back to the White House, I got a lot of" insert expletive "for it," he said. "They didn't get it. The real reason I took" insert same expletive "is because I encourage you all to continue to hack … Apparently, someone from Redmond called the White House," and complained.

The key to progress is avoiding politics when it comes to technological advancements. "At the center of all these advances is computing," he said. The human genome couldn't have been decoded without superior computer processing power. Yet, there are still enormous security problems that plague computer software and systems.

Of course, Clarke is also hawking his new book, Breakpoint, which, as I understand it, addresses the impact of technology on humanity, with IT security playing a crucial role. Clarke said that his new book paints a scenario in the future where soldiers wear intelligent exoskeletons to protect them in combat, an advance that reminded me of a similar technology portrayed in Alan Dean Foster's Sentenced To Prism, which I read as a teenager. Foster's book is a few decades old, however, and didn't address what Clarke views as the biggest threat to such battlefield armor: a computer virus that freezes up the systems that allow the soldier to control the exoskeleton.

Near-term science-fiction aside, Clarke is a big believer that net-centric warfare is on the way. Its combatants will be on the battlefield and in front of the computer, as each soldier will have multiple IP addresses that tie his equipment to a larger network. IPv6's ability to accommodate this is one of the reasons the Pentagon is pushing the adoption of this protocol.

Today's networks can't differentiate Web traffic, can't tell the difference between downloading a relative's vacation photos and an emergency responder using the network to get through in an emergency. "IPv6 would let you do that," which is why it needs to be adopted more rapidly, Clarke said. One of the problems, he noted, is that insufficient funding is being provided to secure cyberspace.

So it comes down to politics again. Regardless of whether you agree with his political slant, it's hard to argue against Clarke when he's talking about IT security. He knows his insert expletive.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.