Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint //

Privacy

4/4/2014
07:00 AM
Ira Winkler
Ira Winkler
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

NSAs Big Surprise: Govt Agency Is Actually Doing Its Job

When people claimed after 9/11 that the NSA was ill equipped to deal with a changing world, I wonder what they expected to happen.

As I read all of the stories about the NSA, they come across as if this is somehow surprising. You can search back to the early 2000s and find stories that state how the NSA was behind the technology curve, and was woefully unprepared to deal with the ever-growing Internet and new technologies.

The Sept. 11 attacks seemed to further highlight how the NSA was unable to do its job, because it was focused on Cold War enemies and ill equipped to handle the new terrorist threat.

Well, it now appears that the NSA has made up for lost time.

People want to portray it as an ominous entity that operates independently from all control, but the fact is that the NSA only does what it has been asked to do. It takes direction from the executive branch of the government. Requirements for NSA operations come through the director of national intelligence. All programs are funded through Congress, despite the selective amnesia of many prominent senators and congressmen. Despite any disdain people may have for the FISA court, programs go through that court when required. The NSA is not a rogue agency that operates without oversight.

NSA Director Keith Alexander.
NSA Director Keith Alexander.

The leaks resulting from Edward Snowden's treason demonstrate that the NSA is making inroads where everyone previously doubted its capability and said it was failing at its mission. When people claimed that it was ill equipped to deal with a changing world, I wonder what they expected to happen. Did they expect Congress to just dissolve the NSA? Did they expect it just to accept its current technology capability? No, the NSA found a smart group of people and started using its money to work on its supposed shortcomings.

If you don't like what it is doing, you can't really protest the NSA itself. It just found a way to do what people said it couldn't do but was supposed to do. It is only doing exactly what it has been tasked to do.

Easy target? Talk to Congress
Yes, people like to have something to embody their frustration (and the NSA makes an easy target). But if you have a complaint, talk to your representatives in Congress. The NSA director, and actually the incredibly small number of staff members who work on the programs in question, are doing what they believe to be in the best interests of the country, as well as what is morally and legally right. If you think otherwise, then find the people who allocate the funding for the NSA, and deal with them.

As for the protesters who focus their attention on the NSA, they ignore the people who are actively harming hundreds of millions of people. When they criticize the NSA, they ignore the fact that Snowden first ran to China, which has hundreds of political dissidents in jail. China is monitoring its citizens on a scale well beyond anything the NSA is accused of doing -- and that isn't even up for debate. Likewise, they ignore China's supposed wide-scale hacking of the accounts of US citizens and companies.

I actually don't begrudge China for doing what it is doing in theory. The people doing the work are only doing what they believe is in the best interests of their country. The only difference that people should consider is that, at least in the US, there is a public conversation about it. Nor does there seem to be any public outrage toward the criminals who stole the credit cards from Target or who committed similar thefts of personal information or caused financial loss to hundreds of millions of people.

I guess that people just like to go after an entity that appears to actually care about what they think, despite the actual damage caused.

Ira Winkler is president of Secure Mentem and author of Advanced Persistent Security. View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
tjensen846
50%
50%
tjensen846,
User Rank: Apprentice
4/4/2014 | 11:14:27 AM
George III
No doubt there were colonists who believed that King George III was "doing what [he] believed to be in the best interests of the country, as well as what is morally and legally right." 

But they were wrong too.
DOUG01
0%
100%
DOUG01,
User Rank: Apprentice
4/4/2014 | 10:23:09 AM
Missing the obvious
In addition to the excellent points already posted, you've overlooked the obvious.  People who are upset with Target have protested by not buying from Target.  Target revenue is down some 40% since the credit card theft.  When people vote with their money, the effect is immediate.  People cannot quit buying from NSA, so there is no alternative but to protest and contact their government representatives as the author suggests.  When people vote at the polling place, or contact their senator/representative, they do not get immediate action, partly because they don't have enough money individually to influence congress. Their influence is very small unless the congressman is flooded with millions of phone calls and emails.  This requires massive organization, which most individuals do not have time for.  Even with a massive campaign that influenced members of congress, change would take months or years.  The only group who could have an immediate effect on congress is the large corporations who donate huge sums of money to finance congressional election campaigns.  If  big business was really upset, they could easlily and rapidly initiate change in NSA policy by threatening to withhold election campaign funds or threaten to suppport another candidate.
GeoffreyL842
100%
0%
GeoffreyL842,
User Rank: Apprentice
4/4/2014 | 10:03:38 AM
False dichotomy
>Nor does there seem to be any public outrage toward the criminals

>who stole the credit cards from Target or who committed similar thefts...

This is an example of several logical fallacies.  The first is FALSE DICHOTOMY-- what you are presenting is not an either/or choice.  The worse one, though, "ARGUMENT BY IRRELEVANCY" (commonly known as "Red Herring").  Basically, you're trying to distract people from their quite reasonable objections to the NSA by bringing up a completely different subject.  Your argument boils down to "look, here's something else!  Squirrel!"

A third, somewhat more subtle logic flaw here is categorization error (commonly called "apples and oranges.")  The Target Hackers don't claim to be working for the government that (in principle) I elected, nor do they claim to be doing their bad things with a claim that they are benefitting me, nor are they subject to public pressure.  They are criminals. Are you are putting forth the premise the NSA are criminals, and thus the NSA and the Target Hackers are in a common category, but the Target Hackers are WORSE criminals? 
geriatric
100%
0%
geriatric,
User Rank: Moderator
4/4/2014 | 8:26:14 AM
Not Doing the Job You Think
Your argument falls flat when one looks at the Boston Marathon bombing. There was an abundance of evidence to raise enough red flags on the perps. The NSA didn't see them for one simple reason - that's not who they're looking for.
<<   <   Page 2 / 2
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11529
PUBLISHED: 2020-04-04
Common/Grav.php in Grav before 1.6.23 has an Open Redirect.
CVE-2020-11527
PUBLISHED: 2020-04-04
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
CVE-2020-11528
PUBLISHED: 2020-04-04
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
CVE-2020-11518
PUBLISHED: 2020-04-04
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
CVE-2020-5347
PUBLISHED: 2020-04-04
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.