Risk

2/25/2014
02:06 PM
50%
50%

NSA Spying Scandal Darkens Cloud Discussions At RSA

From Europe's efforts to create regulations for data localization to worries over the security of the cloud, the leaks of the past eight months have cast a shadow over cloud providers

RSA CONFERENCE -- San Francisco -- Last summer's revelations of the extent to which the U.S. National Security Agency (NSA) collected data on American and foreign targets has caused rifts between global businesses that are hindering efforts to secure the cloud, said Richard Clarke, CEO of Good Harbor and a former U.S. cyberczar, at the Cloud Security Alliance (CSA) Summit on Monday.

RSA Conference 2014
Click here for more articles about the RSA Conference.

The steady leak of documents during the past eight months detailing the operations of the NSA intelligence collection activities has damaged both U.S. policy efforts abroad and the business of a variety of multinational companies, especially cloud providers. Efforts to implement strong security guidelines for the cloud will have to overcome efforts by other nations to implement data residency restrictions to hinder competition, Clarke said.

"Non-U.S. companies are using the NSA revelations as a marketing tool," he said. "There is a great deal of hypocrisy in all of this. People are suddenly amazed that intelligence agencies were collecting intelligence."

Requirements to force cloud providers to keep data in the country of origin and not allow data to transit through the U.S. amount to technological nationalism and, worse, do not make the data any appreciably safer, Clarke said. Data hosting in Europe will be just as easy to get access to as data hosted in the U.S. or another country, Clarke said.

"I'm not revealing away any secrets here if I say that the NSA, and any other world-class intelligence agency, can hack into databases, even if they are not in the United States," he said. "If you think that by passing a law making data localization a requirement for databases in the EU or Argentina or Venezuela or wherever stops the NSA from getting into those databases, think again."

Yet Europe's own technical guru, Udo Heimbrecht, executive director of the European Union Agency for Network and Information Security (ENISA), an EU agency that works to enhance information security, argued that data that travels through the U.S. is at greater risk of interception.

"If you are sending an e-mail from Germany to Estonia, why should it go through the U.S.?" he said. "And that is the idea that we keep our data in Europe."

[Companies need cloud providers to delineate responsibilities for the security of data, provide better security information, and encrypt data everywhere. See 5 Ways Cloud Services Can Soothe Security Fears In 2014.]

Clarke served on President Obama's Review Group on Intelligence and Communications Technologies, the five-member group that issued a 308-page report on the U.S.'s intelligence-gathering efforts. The report underscored that the competing goals of the U.S. intelligence community -- protecting liberty and the right to privacy while at the same time rooting out and combatting terrorism -- could not always be met simultaneously.

Clarke voiced support for the NSA's mission, but underscored that there was a disconnect between policy makers and the intelligence collectors. While legislators gave the NSA powers to accomplish certain goals and missions, the intelligence collectors sought all manner of information that would help them achieve those goals. The technological infrastructure, however, could be used for laudable aims as well as nefarious, he said.

"We may have created, along with the CIA and FBI and other intelligence agencies, and with all these technologies ... the potential -- the potential -- for a police surveillance state," Clarke said. "We are not there yet, but the technology is."

For most companies that put their data into cloud services, there are more practical concerns of data security. Questions of security boil down to questions of trust, said David Miller, chief security officer at Covisint, a cloud identity provider.

"Do I trust the cloud? That's a little bit of a broad statement," Miller said. "I trust some vendors on the cloud; I don't trust other vendors in the cloud. I do know that we are at a point where we are going to have to use it."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Robert Lemos is a veteran technology journalist of more than 16 years and a former research engineer, writing articles that have appeared in Business Week, CIO Magazine, CNET News.com, Computing Japan, CSO Magazine, Dark Reading, eWEEK, InfoWorld, MIT's Technology Review, ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17283
PUBLISHED: 2018-09-21
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Inject...
CVE-2018-17282
PUBLISHED: 2018-09-20
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
CVE-2018-14592
PUBLISHED: 2018-09-20
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
CVE-2018-15832
PUBLISHED: 2018-09-20
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI ha...
CVE-2018-16282
PUBLISHED: 2018-09-20
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.