Risk
8/1/2007
04:58 PM
50%
50%

What Richard Clarke Was Really Saying At Black Hat

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.Clarke, chief counterterrorism adviser on the U.S. National Security Council during portions of the Bill Clinton and George W. Bush administrations and currently chairman of Good Harbor Consulting, has been known to wear his politics on his sleeve. Although he served during both the Clinton and Bush administrations, let's just say he's not been impressed with the latter. He even suggested that the Bush Administration's lack of funding for important technology developments will create serious impediments for the U.S.

Clarke criticized the current Bush Administration's policies against stem-cell research and its opposition to the development of human-machine interface technologies. The question is, "are humans beginning to take control of their own evolution and is that a good thing or a bad thing?" he asked the crowd Wednesday at the Black Hat USA 2007 conference in Las Vegas. "We need to start thinking about it now."

Clarke operated at the highest level of the federal government, and he's no novice when it comes to IT security or to Black Hat. Clarke keynoted Black Hat during President Bush's first term. "When I got back to the White House, I got a lot of" insert expletive "for it," he said. "They didn't get it. The real reason I took" insert same expletive "is because I encourage you all to continue to hack … Apparently, someone from Redmond called the White House," and complained.

The key to progress is avoiding politics when it comes to technological advancements. "At the center of all these advances is computing," he said. The human genome couldn't have been decoded without superior computer processing power. Yet, there are still enormous security problems that plague computer software and systems.

Of course, Clarke is also hawking his new book, Breakpoint, which, as I understand it, addresses the impact of technology on humanity, with IT security playing a crucial role. Clarke said that his new book paints a scenario in the future where soldiers wear intelligent exoskeletons to protect them in combat, an advance that reminded me of a similar technology portrayed in Alan Dean Foster's Sentenced To Prism, which I read as a teenager. Foster's book is a few decades old, however, and didn't address what Clarke views as the biggest threat to such battlefield armor: a computer virus that freezes up the systems that allow the soldier to control the exoskeleton.

Near-term science-fiction aside, Clarke is a big believer that net-centric warfare is on the way. Its combatants will be on the battlefield and in front of the computer, as each soldier will have multiple IP addresses that tie his equipment to a larger network. IPv6's ability to accommodate this is one of the reasons the Pentagon is pushing the adoption of this protocol.

Today's networks can't differentiate Web traffic, can't tell the difference between downloading a relative's vacation photos and an emergency responder using the network to get through in an emergency. "IPv6 would let you do that," which is why it needs to be adopted more rapidly, Clarke said. One of the problems, he noted, is that insufficient funding is being provided to secure cyberspace.

So it comes down to politics again. Regardless of whether you agree with his political slant, it's hard to argue against Clarke when he's talking about IT security. He knows his insert expletive.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9209
Published: 2015-03-30
Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.