Risk
8/1/2007
04:58 PM
Connect Directly
RSS
E-Mail
50%
50%

What Richard Clarke Was Really Saying At Black Hat

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.

Don't let politics get in the way of progress. That was one of the key messages former U.S. counterterrorism advisor Richard Clarke delivered during his Black Hat keynote. Of course, Clarke has a colorful way of putting things.Clarke, chief counterterrorism adviser on the U.S. National Security Council during portions of the Bill Clinton and George W. Bush administrations and currently chairman of Good Harbor Consulting, has been known to wear his politics on his sleeve. Although he served during both the Clinton and Bush administrations, let's just say he's not been impressed with the latter. He even suggested that the Bush Administration's lack of funding for important technology developments will create serious impediments for the U.S.

Clarke criticized the current Bush Administration's policies against stem-cell research and its opposition to the development of human-machine interface technologies. The question is, "are humans beginning to take control of their own evolution and is that a good thing or a bad thing?" he asked the crowd Wednesday at the Black Hat USA 2007 conference in Las Vegas. "We need to start thinking about it now."

Clarke operated at the highest level of the federal government, and he's no novice when it comes to IT security or to Black Hat. Clarke keynoted Black Hat during President Bush's first term. "When I got back to the White House, I got a lot of" insert expletive "for it," he said. "They didn't get it. The real reason I took" insert same expletive "is because I encourage you all to continue to hack … Apparently, someone from Redmond called the White House," and complained.

The key to progress is avoiding politics when it comes to technological advancements. "At the center of all these advances is computing," he said. The human genome couldn't have been decoded without superior computer processing power. Yet, there are still enormous security problems that plague computer software and systems.

Of course, Clarke is also hawking his new book, Breakpoint, which, as I understand it, addresses the impact of technology on humanity, with IT security playing a crucial role. Clarke said that his new book paints a scenario in the future where soldiers wear intelligent exoskeletons to protect them in combat, an advance that reminded me of a similar technology portrayed in Alan Dean Foster's Sentenced To Prism, which I read as a teenager. Foster's book is a few decades old, however, and didn't address what Clarke views as the biggest threat to such battlefield armor: a computer virus that freezes up the systems that allow the soldier to control the exoskeleton.

Near-term science-fiction aside, Clarke is a big believer that net-centric warfare is on the way. Its combatants will be on the battlefield and in front of the computer, as each soldier will have multiple IP addresses that tie his equipment to a larger network. IPv6's ability to accommodate this is one of the reasons the Pentagon is pushing the adoption of this protocol.

Today's networks can't differentiate Web traffic, can't tell the difference between downloading a relative's vacation photos and an emergency responder using the network to get through in an emergency. "IPv6 would let you do that," which is why it needs to be adopted more rapidly, Clarke said. One of the problems, he noted, is that insufficient funding is being provided to secure cyberspace.

So it comes down to politics again. Regardless of whether you agree with his political slant, it's hard to argue against Clarke when he's talking about IT security. He knows his insert expletive.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.