3 ms·
The biggest problem with the NSA proposal was that it was dishonest. Industry has been asking them for threat alerts based on tier 1 network surveillance for so
by trotsky 14y ago
The biggest problem with the NSA proposal was that it was dishonest. Industry has been asking them for threat alerts based on tier 1 network surveillance for some time, but the NSA (dba Cyber Command) has continually questioned whether they were chartered to share that information. As a response they offered to share data only with organizations that would place NSA instrumentation inside their private networks, which is what raised the privacy concerns.
Simply put, defense is hard. That's the main reason you've seen all of the national intelligence organizations playing hot potato with the issue. Hopefully this will be changing a bit for the better based on the executive order Obama signed recently that directs DHS, NSA and the FBI to expand their programs that share active threat information with private companies.
- Nrsolis 14y agoI hear you and I don't want to underestimate or diminish the concerns that private companies have. That said, the threat vectors for APTs aren't always solely network-based. IIRC, the behavior of the APT that struck RSA was fairly targeted and changed behavior once inside the network. It isn't unreasonable to think that the NSA would want to talk about putting sensors inside a private network where they could detect "successful" penetrations. Again, we have every right to be wary of letting the (government) camel nose in the tent. I'm just saying that if you don't kinda sorta trust your government to help you fight a serious foreign power with nearly unlimited resources, you might need to reconsider your position. The threat from China is real and ongoing versus the theoretical threat from the US Government.
- joequant 14y agoOne problem is that multinational corporations are multinational with significant operations inside of China. I doubt that the NSA is going to be of much help in helping a US company secure its networks inside of China, and if that company has large numbers of Chinese employees in China, there are security issues with having US intelligence companies sharing sensitive US intelligence. For example, the NYTimes has a bureau in Shanghai, and if they use a private contractor to help strengthen their networks, then I don't think that the Chinese government would be cancelling visas. If the NYTimes brought in the NSA, then I give the Chinese government five minutes before all of the visa get cancelled and the journalists get expelled.
- greedo 14y agoDefense is hard; that doesn't mean measures shouldn't be taken to protect your assets. However, due to how western businesses operate, it's almost trivial to successfully attack them. The attack surface is just too large, and most businesses can't afford security measures and restrictions that would truly make them safe.