Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, June 1, 2008

How the Army found middle ground to embrace the internet

"This winter, the Air Force, as the Pentagon’s point agency for Internet operations –“cyberwarfare,” in military jargon – banned access from official networks to many blogs, declaring that they weren’t “established, reputable media.” The Air Force didn’t seem concerned that America’s greatest enemies, international jihadists, had long ago latched onto websites as cheap, effective tools for sharing ideas."

David Axe looks at The Military's Internet 'Civil War' in The Washington Independent. This is the first of three parts.

Source: As cited
Photo: U.S. Army

Monday, May 19, 2008

Getting caught up

Here are some items of general interest that we have found or have had brought to our attention by readers. Thank you!
  • What do the NSA and You Tube have in common? The Register

  • Nuclear Missile Deployment Area Discovered in Central China FAS
  • Booz Allen business sale to the Carlyle Group for $2.54 billion Press release
Sources: As linked

Friday, May 16, 2008

National cyber security initiative

After years of silence on the issue of cyber security Washington's recent flurry of activity is quite astounding and far reaching. The state of affairs has gone literally from silence to the proposition that government become America's firewall.

How is this to be done? Who is going to do it? How will it be monitored? These questions currently are not clearly addressed or fall under the umbrella label of secrecy.

"A chief concern is that virtually everything about the initiative is highly classified, and most of the information that is not classified is categorized as `For Official Use Only.' These restrictions preclude public education, awareness, and debate about the policy and legal issues, real or imagined, that the initiative poses in the areas of privacy and civil liberties. Without such debate and awareness in such important and sensitive areas, it is likely that the initiative will make slow or modest progress. ... "

"The committee also shares the view of the Senate Select Committee on Intelligence that major elements of the cyber initiative request should be scaled back because policy and legal reviews are not complete, and because the technology is not mature. ..."

"The committee also concludes that some major elements of the cyber initiative are not solely or even primarily intended to support the cyber security mission. Instead, it would be more accurate to say that some of the projects support foreign intelligence collection and analysis generally rather than the cyber security mission particularly. ... That is not to say that the proposed projects are not worthwhile, but rather that what will be achieved for the more than $17.0 billion planned by the administration to secure the government's networks is less than what might be expected."

From: Senate Armed Services Committee, Report 110-335, National Defense Authorization Act for Fiscal Year 2009

Tuesday, May 13, 2008

Cyberspace carpet bomb?

"The world has abandoned a fortress mentality in the real world, and we need to move beyond it in cyberspace. America needs a network that can project power by building an af.mil robot network (botnet) that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic. America needs the ability to carpet bomb in cyberspace to create the deterrent we lack." So writes Col. Charles Williamson III in Armed Forces Journal.

The Colonel's enthusiasm may be admirable but he may also be opening up a huge can of worms that will just lead to escalating botnet activity. Where does that leave everyone else? It's nice to have an attitude that if you're not part of the solution you're part of the problem. The implications for relations with allies, business, and the public are huge.

Source: AFJ

Thursday, March 20, 2008

File this under "bizarre"

Picture this.

Very public and very vocal critics of the Canadian defence policy just happen to have blueprints to a new, "secret ", military installation.

The documents were found on top of garbage.

The "critics" don't know what they have and it all just happens to come up in a conversation with a reporter.

It's bizarre even in these days where laptops with sensitive information seem to regularly go missing. David Pugliese's story is "How did counter terrorism blueprints end up on an Ottawa street?

Sources: As cited
Image: Generic, not secret, blueprint

Wednesday, March 19, 2008

Windows Mobile gets security certifications

"Microsoft Federal has announced the addition of two critical security certifications to its Windows Mobile operating system. Windows Mobile 5.0 with Messaging and Security Feature Pack, and Windows Mobile 6 operating systems were awarded Common Criteria Evaluation Assurance Level 2+ (EAL2+).

The U.S. Defense Information Systems Agency (DISA) announced it has approved Windows Mobile® for secure wireless e-mail throughout the Department of Defense (DoD). These milestones offer independent validation of Microsoft's commitment to assist governments and enterprises in meeting the ever-increasing security demands for mobile devices accessing sensitive data on information networks.

The Windows Mobile DISA STIG complements other mission-critical work Microsoft is working on across the federal government. Systems integrator partners such as General Dynamics Corp. and L3 Communications Corp. have selected Microsoft to develop an NSA-approved Secure Mobile Environment Portable Electronic Device (SME PED). The SME PED is capable of secure wireless access to the SIPRNET and NIPRNET and supports DoD 8100.2 requirements.

Common Criteria is a globally recognized standard for secure IT products. By meeting the security criteria for EAL2+, Windows Mobile is accepted under the Common Criteria Recognition Arrangement (CCRA) worldwide by 24 member countries. This means that U.S. government agencies with disparate, worldwide operations can use Windows Mobile with the assurance that they have adopted a technology platform that is universally recognized as tested to exacting security standards.

Both accreditations will help mobile U.S. government personnel become more productive and effective while accessing mission-critical data, including for example, Common Operational Picture software for combat and reconnaissance missions; Battlefield Medical Triage; Logistics and supply chain support, and more."

Source and Photo: Microsoft

Friday, March 14, 2008

Major RFID hack appears

You may use an RFID pass to get on the subway or access your building.

The Netherlands' NXP Semiconductor is one of the world's leading suppliers of RFID systems. Researchers at Radboud University (Nijmegen) have become the second group to hack their MIFARE system. Literally billions of chips are out there from The Netherlands to the London Underground to Boston Transit to, perhaps, the building you enter every day.

The proprietary chip carries 48bit encryption and a replacement 128bit chip (Mifare Plus) is available, presumably at a higher cost.

How can the information be gathered? Why there's a convenient video on YouTube ...

Sources: As cited and PC World

Wednesday, January 2, 2008

BAE starts 2008 on a roll ...

It may be a quiet period for some but there's no moss growing on BAE. They have recently announced two acquisitions.

Petards Group has sold BAE its U.K. software business, including the Universal Video Management System (UVMS). Petards will continue to provide UVMS in North America through a licensing agreement. Wile this is a relatively small purchase for BAE it may point to a consolidation trend in the industry in light of last year's Bosch purchase of Extreme.

The bigger news on the financial scale ($450 million) is BAE's purchase of Dayton Ohio's MTC Technologies. This move certainly increases BAE's U.S. footprint. Founded in 1984 by Rajesh and Indu Soin, MTC has been involved with: avionics and control system mechanisms for the C-130 and attack helicopters; future soldier equipment integration; intelligence planning; and professional services.

For perspective, here are some BAE facts: 3rd largest global defence company; 6th largest US defence company; 96,000 employees; and annual sales exceed £15 billion.


Sources: Various
Image: BAE

Saturday, December 8, 2007

US espionage enters the 'un-Rumsfeld' era

"As the George W Bush administration winds up nearly seven years of intelligence fiascoes, a quiet revolution has been going on at the Pentagon, which controls more than 80% of America's US$60 billion intelligence budget. Since taking over from Donald Rumsfeld as secretary of defense in the winter of 2006, Robert Gates has greatly scaled down the Pentagon's footprint on national security policy and intelligence."
Tim Shorrock writes this in a very interesting article in the Asia Times. Check it out.

Source: Asia Times

Thursday, December 6, 2007

General Dynamics makes a big VOIP step.

VOIP is everywhere. A huge concern is security.

General Dynamics' vIPer phone has been certified by the National Security Agency. It complies with: the government's
Secure Communications Interoperability Protocol (SCIP); other compliant phones; Cisco Systems' Skinny Client Control Protocol and Sectera terminals.

General Dynamics will now develop it to
support Session Initiation Protocol (SIP). Both SIP and SCIP are required for government and military secure communications from top-secret level down.

Thursday, November 29, 2007

Reported malfunction in PayPal Security Key

"When eBay rolled out the PayPal Security Key earlier this year, its executives hailed it as an important measure that would make users more secure. And it was. By generating a random, six-digit number every 30 seconds that users needed to authenticate themselves online, the small electronic token provided an additional layer of protection against phishers and other online criminals."

Source: The Register

Wednesday, November 28, 2007

OMB consolidating agency Internet connectivity

" The Office of Management and Budget is calling on agencies to reconfigure their connection points to the Internet, in hopes of reducing the federal government's exposure to malicious hackers accessing agency networks.

OMB's newly announced Trusted Internet Connections requires agencies to develop a plan of action and a set of milestones by Jan. 8 on how they will reduce the number of connection points they maintain to the Internet."