Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint //

Privacy

Richard Clarke: Foreign Governments Not So Surprised by US Snooping

50%
50%

Former White House cybersecurity advisor Richard Clarke thinks foreign governments' outrage about American cyber-snooping is largely an act being put on for the benefit of political and economic agendas.

Comment  | 
Print  | 
Comments
Threaded  |  Newest First  |  Oldest First
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
3/27/2014 | 10:33:14 AM
Why is the NSA's activity such a surprise to anyone?
I'm amazed at the strong reaction to the NSA's surveillance activity, which has always been vast and deep. The NSA has been doing deep surveillance for many years. In fact, it used to be that all telecom carriers were required to have a presence in Jessup, Md. -- providing an easy location for the NSA to listen in.
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
3/27/2014 | 2:52:02 PM
Re: Why is the NSA's activity such a surprise to anyone?
Well Tim we must distinguish two aspect:

I agree with Richard Clarke, foreign governments are not surprised by US snooping because almost every state is developing its surveillance programme, more or less efficient. China, Russia and many other countries are investing to improve cyber capabilities on both defensive and offensive perspective. Suverillance and monitoring are common practices, they are the essential part of every cyber strategy, necessary to protect homeland security.

The extension of NSA activity, despite US isn't the unique government with a so aggressive cyber espionage programme, is embarrassing. US Governments has spied also on allies and it has arranged hacking campaigns (see FoxACID and TURBINE) to hack foreign enterprises like Huawei and Siemens. 

Frankly, it is gone too far ... it's policy will damage US IT industry

 
tmccreight
50%
50%
tmccreight,
User Rank: Apprentice
3/27/2014 | 10:43:48 PM
Why is the NSA's activity such a surprise to anyone?
I agree with Richard's comments and his insight into the drivers behind some of the comments from foreign states.

I remember working on CALEA projects (there's an oldie for you) back in the 90's that caused concern wtih so many people, yet proved invaluable when we provided assistance to intelligence agencies in North America.  I understand and appreciate the difficult position Western nations are in - they don't want to let potential intelligence go undetected, but must also face harsh criticisms when they 'invade' the personal electronic space of citizens (both foreign and domestic).  I don't envy the daily decisions these folks make, but I can say I've seen the benefits of that information.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/10/2020
Zscaler to Buy Cloudneeti
Dark Reading Staff 4/9/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Yes, I do have virus protection on my system, now what?
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18375
PUBLISHED: 2020-04-10
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
CVE-2019-18376
PUBLISHED: 2020-04-10
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.
CVE-2019-7305
PUBLISHED: 2020-04-10
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information di...
CVE-2020-8832
PUBLISHED: 2020-04-10
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacke...
CVE-2020-1633
PUBLISHED: 2020-04-09
Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, lea...