<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title></title>
	<atom:link href="http://t3chlaw.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://t3chlaw.wordpress.com</link>
	<description>discussions regarding technology &#38; law</description>
	<lastBuildDate>Thu, 09 Dec 2010 14:56:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='t3chlaw.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1489ab261e0c28339c85b5959ee82bdd?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title></title>
		<link>http://t3chlaw.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://t3chlaw.wordpress.com/osd.xml" title="" />
	<atom:link rel='hub' href='http://t3chlaw.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Notes from Digital Pearl Harbor Panel Discussion</title>
		<link>http://t3chlaw.wordpress.com/2010/12/09/notes-from-digital-pearl-harbor-panel-discussion/</link>
		<comments>http://t3chlaw.wordpress.com/2010/12/09/notes-from-digital-pearl-harbor-panel-discussion/#comments</comments>
		<pubDate>Thu, 09 Dec 2010 14:56:41 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[General Michael Hayden]]></category>
		<category><![CDATA[Jeff Carr]]></category>
		<category><![CDATA[Richard A. Clark]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=108</guid>
		<description><![CDATA[Yesterday I attended the Georgetown University sponsored discussion on Digital Pearl Harbor.  The speakers, Richard Clarke, Michael Hayden, and Jeff Carr, are well known in this area and speak from experience. The following are my notes from the event, sorted &#8230; <a href="http://t3chlaw.wordpress.com/2010/12/09/notes-from-digital-pearl-harbor-panel-discussion/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=108&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Yesterday I attended the <a href="http://lsgs.georgetown.edu/programs/CyberProject/DigitalAPearlHarbor/">Georgetown University sponsored discussion on Digital Pearl Harbor</a>.  The speakers, Richard Clarke, Michael Hayden, and Jeff Carr, are well known in this area and speak from experience.</p>
<p>The following are my notes from the event, sorted by each speaker:</p>
<p><span style="text-decoration:underline;">Richard Clark</span></p>
<p>Most companies that have any intellectual property (IP) of value have already been victims of cyber espionage and that their IP has been looted.  He referenced a report released by Verizon (which I can&#8217;t find anywhere) that supposedly discusses data theft.  Apparently Verizon approached a bunch of companies to inform them of malicious activity and over two-thirds of the companies that they approached didn&#8217;t know about the malicious activity.</p>
<p>The prospect of cyber war is remote.  Nations do not just attack because they have a new offensive weapon that they want to try out.</p>
<p>If there were an attack today, a sophisticated adversary could:</p>
<ul>
<li>derail trains;</li>
<li>blow up refineries;</li>
<li>blow up natural gas refineries; or</li>
<li>knock out air traffic control systems.</li>
</ul>
<p>Cyber war to him means a cyber attack that causes damage that a bomb would cause.</p>
<p>Russia &amp; China have no incentive to use cyber war against us unless they were going to attack anyway.</p>
<p>He worries about Government of Iran or North Korea because they are not as dependent on the world economy as most advanced countries.</p>
<p>Cyber security legislation is hopefully coming but that we need to overcome partisan politics and get something done.</p>
<p>We need to engage Internet Service Providers (ISP) and give them safe harbor to look for evidence of attacks and stop them.</p>
<p><span style="text-decoration:underline;">Michael Hayden</span></p>
<p>ARPANET was the bloodline for the Internet but it was built on trusted nodes.  Today&#8217;s Internet has many more nodes and most are not trusted.</p>
<p>We are moving in the right direction with the creation of US Cyber Command but we are unable to deploy our defenses because of a lack of policy and legal guidelines, so we pull our punches.</p>
<p>Bill Lynn wrote an article in Foreign Affairs about &#8220;cyber&#8221; being a domain which we must be prepared to defend.  It is a DoD concept.  Most commercial companies aren&#8217;t looking at cyber as a domain yet.</p>
<p>He went to a hacker conference and spoke and said that &#8220;cyber&#8221; is comparable to European man&#8217;s discovery of western hemisphere.  After his speech he was approached by someone who said that it is comparable to the human development of language.  He agreed with the person.  Cyber is changing human cognition.</p>
<p>Vocabulary is being used from other areas but it doesn&#8217;t translate over.</p>
<ul>
<li>Deterence &#8211; sounds nice but requires attribution.</li>
<li>Privacy &#8211; we don&#8217;t even have a concept for what constitutes legitimate privacy in cyber.</li>
</ul>
<p>We need to develop policy or our cyber capacity will be useless.</p>
<p>The private sector is not much better.  Often security is looked at as &#8220;additional&#8221; or something you bolt on.  It needs to be included as part of the process.</p>
<p><span style="text-decoration:underline;">Jeff Carr</span></p>
<p>Just returned from India where he met with Indian Government Officials who were worried about China and Pakistan.  Indian Government doesn&#8217;t trust private industry because of their motives.</p>
<p>The title cyber warfare was used on his book but he doesn&#8217;t like the term.</p>
<p>We need to rethink war.</p>
<p>China is engaged in ultimate war.  A war where they move forward and gather leverage on their foes without shedding a drop of bloodshed.  Cyber has given them this ability.</p>
<p>China is engaged in theft of intellectual property.</p>
<p>They encourage research and development companies to come to China and then require that communications be monitored and supervised.</p>
<p>In 2002 there were 100 R&amp;D labs.<br />
In 2007 there were 1200 R&amp;D labs.</p>
<p>There has been a 500% increase in Chinese patents in recent years.</p>
<p>Russia is now following the same tactic.  They are building an R&amp;D area supported by Intel and others to attract foreign companies to Russia.</p>
<p>In Russia, FSB has power to review source code or have source code added &#8211; all in the name of national security.</p>
<p>We don&#8217;t recognize these efforts by Russia and China as warfare but they are achieving a national political goal without bloodshed.</p>
<p>Remember the data breach relating to the F35 contractor.  Apparently now there are fewer orders for F35 because customers are saying that Chinese anti-aircraft technology has advanced so much that it isn&#8217;t worth the cost of the F35.</p>
<p>Russia is different from China in that Russia has used cyber along with kinetic force.  He mentioned:</p>
<ul>
<li>Chechnya</li>
<li>Kyrgistan</li>
<li>Estonia</li>
</ul>
<p>Russia works with organized crime to use their platforms to engage in cyber activities.</p>
<p>Russia is also playing hard in technology development and social networks.  DST (Russian investment firm with links to the Kremlin) now has a 10% share of Facebook.</p>
<p>DST has become the venture capitalist of choice in silicon valley due to their lenient lending.</p>
<p><em>END</em></p>
<p><em>The notes above are my attempt at paraphrasing what was actually said by the speakers.  The event was recorded so it should be available in its entirety through Georgetown&#8217;s web site.</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/108/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=108&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2010/12/09/notes-from-digital-pearl-harbor-panel-discussion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>Fake AV Fun</title>
		<link>http://t3chlaw.wordpress.com/2010/09/14/fakeav-fun/</link>
		<comments>http://t3chlaw.wordpress.com/2010/09/14/fakeav-fun/#comments</comments>
		<pubDate>Tue, 14 Sep 2010 12:42:49 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=94</guid>
		<description><![CDATA[The following file made its way onto the family PC yesterday so I took the opportunity to use my recent malware analysis training to see if I could do anything with it.  This is just basic behavioral analysis and the &#8230; <a href="http://t3chlaw.wordpress.com/2010/09/14/fakeav-fun/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=94&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The following file made its way onto the family PC yesterday so I took the opportunity to use my recent malware analysis training to see if I could do anything with it.  This is just basic behavioral analysis and the file isn&#8217;t too complex but it was fun anyway.</p>
<p>This is the first time that my collection of AV products (MalwareBytes, McAfee, and Microsoft Malicious Software Removal Tool) were not up to date on a threat so I was forced to deal with it myself.</p>
<p>See <a href="http://www.virustotal.com/file-scan/report.html?id=ed50737eeed3fb8c6f7126c5d055cd941087a4a2709e3289d98c9500cab96ea4-1284440336">VirusTotal</a> for my entry.</p>
<p>The file hijacks the user&#8217;s ability to get access to the Internet via browsers like Microsoft IE and Firefox.  I only have those two but I assume it stops others too.</p>
<p>It also blocks the ability to use utilities such as PING and CMD.exe but doesn&#8217;t work if you have rename the utilities.  I renamed my command prompt file to &#8220;special.exe&#8221; and was able to get command prompt access.</p>
<p>The file also uses a batch file to try to delete itself but it wasn&#8217;t too successful.</p>
<p>It start out trying to trick the user into thinking that Microsoft Security  Essentials is installed and has caught the file.</p>
<p><a href="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-00-53-am.png"><img class="alignnone size-medium wp-image-95" title="Screen shot 2010-09-14 at 8.00.53 AM" src="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-00-53-am.png?w=300&#038;h=160" alt="" width="300" height="160" /></a></p>
<p>If you select &#8220;clean computer&#8221; or &#8220;apply actions&#8221; you get the same result&#8230;</p>
<p><a href="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-10-57-am.png"><img class="size-medium wp-image-96 alignnone" title="Screen shot 2010-09-14 at 8.10.57 AM" src="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-10-57-am.png?w=300&#038;h=160" alt="" width="300" height="160" /></a></p>
<p>After you choose &#8220;Scan Online&#8221;, it goes through the motions of making you think that you are getting your file scanned but I did this in my VM on &#8220;host only&#8221; and got the same result.</p>
<p><a href="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-10-am.png"><img class="alignnone size-medium wp-image-97" title="Screen shot 2010-09-14 at 8.15.10 AM" src="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-10-am.png?w=300&#038;h=224" alt="" width="300" height="224" /></a></p>
<p>The result is what appears like a successful scan.  Of course only a few  AV vendors have discovered this variant and now offer you free access to their products.  At this point, you have the option of downloading their files for free and your system will reboot automatically.</p>
<p><a href="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-48-am.png"><img class="alignnone size-medium wp-image-98" title="Screen shot 2010-09-14 at 8.15.48 AM" src="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-48-am.png?w=300&#038;h=225" alt="" width="300" height="225" /></a></p>
<p>The file is packed with UPX but I was able to dump out the unpacked version of Ollydbg easily.</p>
<p>It also beacons out to <strong>www.stopbadware.org</strong> but didn&#8217;t issue a &#8220;GET&#8221; request.</p>
<p>The  company name shows as &#8220;Mouskit AG&#8221; which also shows up in other FAKEAV  files.</p>
<p>I was able to run Process Explorer and kill it outright.   It didn&#8217;t come back and didn&#8217;t seem to have persistence.  Also, it only  resides in user profile so I was able to use other profiles on my PC to  get files I needed to get rid of it.</p>
<p>When I first submitted it,  only two AV had seen it so I pushed it to McAfee via email.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=94&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2010/09/14/fakeav-fun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>

		<media:content url="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-00-53-am.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-09-14 at 8.00.53 AM</media:title>
		</media:content>

		<media:content url="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-10-57-am.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-09-14 at 8.10.57 AM</media:title>
		</media:content>

		<media:content url="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-10-am.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-09-14 at 8.15.10 AM</media:title>
		</media:content>

		<media:content url="http://t3chlaw.files.wordpress.com/2010/09/screen-shot-2010-09-14-at-8-15-48-am.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-09-14 at 8.15.48 AM</media:title>
		</media:content>
	</item>
		<item>
		<title>State Secrets Privilege Panel Discussion</title>
		<link>http://t3chlaw.wordpress.com/2009/11/19/state-secrets-privilege-panel-discussion/</link>
		<comments>http://t3chlaw.wordpress.com/2009/11/19/state-secrets-privilege-panel-discussion/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 00:24:14 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[National Security Law]]></category>
		<category><![CDATA[state secrets privilege]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=86</guid>
		<description><![CDATA[Today I attended a panel discussion on &#8220;The State of the State Secrets Privilege&#8221;.  The panel discussion took place at American University Washington College of Law (WCL) and was presented by WCL&#8217;s Collaboration on Government Secrecy (CGS) It is my &#8230; <a href="http://t3chlaw.wordpress.com/2009/11/19/state-secrets-privilege-panel-discussion/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=86&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today I attended a panel discussion on &#8220;The State of the State Secrets Privilege&#8221;.  The panel discussion took place at American University Washington College of Law (WCL) and was presented by WCL&#8217;s Collaboration on Government Secrecy (CGS)</p>
<p>It is my understanding that the entirety of this program was captured on video and will be available for review.  Select <a href="http://www.wcl.american.edu/lawandgov/cgs/documents/20091118_cgs_sssp_agenda.pdf?rd=1">here </a>for a copy of the agenda.</p>
<p>Congressman Nadler gave the opening keynote and spoke of his bill HR 984 which he hopes will reform the use of the state secrets privilege.</p>
<p>This was a very enlightening discussion.  I recommend taking the time to watch the video of the panels.</p>
<p>The following were note worthy (to me):</p>
<ul>
<li>Laura Donoghue (from Georgetown) is writing a book on history of the use of state secrets privilege;</li>
<li>Obama administration has new procedures for deciding when to invoke the state secrets privilege.  They ran their process against cases in the system now and all of them would have passed under their new procedures.  To me this says that the Bush administration use of the state secrets privilege was probably legitimate (contrary to popular opinion of many);</li>
<li>According to one panelist, the US didn&#8217;t assert state secrets privilege on NSA Terrorist Surveillance Program (TSP) cases;</li>
<li>Oral argument on <a href="http://www.ca9.uscourts.gov/datastore/uploads/enbanc/08-15693pfr.pdf">Jeppesen </a>to be heard by 9th Circuit on 15 December 2009; and</li>
<li><a href="http://judiciary.house.gov/hearings/pdf/IGTSPReport090710.pdf">IG report</a> on TSP was released in July 2009.</li>
</ul>
<p>Overall, (I believe) all that attended agree on the following:</p>
<ul>
<li>The state secrets privilege is a legitimate and necessary tool to keep classified information from getting into the public record;</li>
<li>There is a need for more standards and/or guidance for courts to handle the privilege in a consistent way;</li>
<li>Need to consider alternatives to just dismissing cases that can&#8217;t sustain state secrets privilege invocation; and</li>
<li>We need to be careful how we reform SSP since it could lead to an appearance that we are telling the courts how to run or even that there is a hit on executive power.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/86/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=86&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/11/19/state-secrets-privilege-panel-discussion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>ABA 19th Annual Review of the Field of National Security Law Conference</title>
		<link>http://t3chlaw.wordpress.com/2009/11/18/aba-19th-annual-review-of-the-field-of-national-security-law-conference/</link>
		<comments>http://t3chlaw.wordpress.com/2009/11/18/aba-19th-annual-review-of-the-field-of-national-security-law-conference/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 23:48:23 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Cyber War]]></category>
		<category><![CDATA[Modern Piracy]]></category>
		<category><![CDATA[National Security Law]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=67</guid>
		<description><![CDATA[On November 12-13, 2009, I attended the 19th Annual Review of the Field of National Security Law Conference presented by the American Bar Association (ABA) Standing Committee on Law and National Security.  Select here for latest copy of program agenda. &#8230; <a href="http://t3chlaw.wordpress.com/2009/11/18/aba-19th-annual-review-of-the-field-of-national-security-law-conference/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=67&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>On November 12-13, 2009, I attended the 19th Annual Review of the Field of National Security Law Conference presented by the American Bar Association (ABA) Standing Committee on Law and National Security.  Select <a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/program.shtml">here</a> for latest copy of program agenda.</p>
<p>The following podcast links are from the ABA Standing Committee on Law and National Security web site.  I highly recommend watching the panel on &#8220;Modern Piracy&#8221;.<strong> </strong></p>
<p>Podcasts</p>
<ul>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30233.mp3">Opening Remarks</a> &#8211; Carolyn Lamm<br />
<a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30233.mp3">Panel I &#8211; Executive  Update on Developments                      in National Security Law</a></li>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30233-2.mp3">Panel II &#8211;  Legislative  Update on Developments in National Security Law and Keynote Address</a> &#8211; Hon. James B. Steinberg</li>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30234.mp3">Panel III &#8211; Emerging Issues in National Security Law: Narco-Violence Along the  Border</a></li>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30236.mp3">Friday Opening Remarks</a> &#8211; Professor John Norton Moore<br />
<a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30236.mp3">Panel IV &#8211; Modern Piracy: Legal and Policy Options</a></li>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30237.mp3">Panel V &#8211; Military Commissions</a></li>
<li><a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30240.mp3">Panel VI -</a> <a href="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30240.mp3">Cyber Security and Cyber Warfare</a></li>
</ul>
<p>Over the course of two days, I noted the following which I found interesting enough to mention here:</p>
<ul>
<li>General Counsel for DHS was the only one in the first panel discussion one to mention cyber security as a top issue.</li>
<li>When topic of interaction between Title 10 &amp; Title 50 came up during the first discussion, many of the panelists had very little to say (as if they were avoiding it).</li>
<li>According to Martin Murphy, modern piracy should be viewed as an organized crime problem.</li>
<li>Based on the comments by the shipping industry representative, shipping companies do not consider piracy an issue because they can just avoid the area or pay the ransom and there is very little impact on cost.  Mostly a personal safety issue of employees.</li>
<li>There are forty threshold legal issues associated with cyber strategy.</li>
<li>According to FBI rep at the cyber panel, hackers are targeting law firms and public relations firms.  Since this conference there have been a number of stories that have come out about this statement.</li>
<li>Someone in the crowd stood up and said that Raytheon had been penetrated by known foreign power.  I can&#8217;t find anything in open press to support this statement.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/67/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=67&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/11/18/aba-19th-annual-review-of-the-field-of-national-security-law-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30233.mp3" length="15616322" type="audio/mpeg" />
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30233-2.mp3" length="16466210" type="audio/mpeg" />
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30234.mp3" length="12298736" type="audio/mpeg" />
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30236.mp3" length="14052266" type="audio/mpeg" />
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30237.mp3" length="11941082" type="audio/mpeg" />
<enclosure url="http://www.abanet.org/natsecurity/events/conference/2009%20Annual%20Review/WS_30240.mp3" length="21672992" type="audio/mpeg" />
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>To Tweet or Not to Tweet &#8211; Do Twitter&#8217;s Terms of Service Need a Revision?</title>
		<link>http://t3chlaw.wordpress.com/2009/10/09/to-tweet-or-not-to-tweet-do-twitters-terms-of-service-need-a-revision/</link>
		<comments>http://t3chlaw.wordpress.com/2009/10/09/to-tweet-or-not-to-tweet-do-twitters-terms-of-service-need-a-revision/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:55:44 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Mikko Hypponen]]></category>
		<category><![CDATA[Social Networking Sites]]></category>
		<category><![CDATA[Terms of Service Agreement]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=56</guid>
		<description><![CDATA[Twitter&#8217;s recent banning of F-Secure Chief Research Officer, Mikko H. Hypponen, calls into question their terms of service and whether they actually practice what they preach and also whether they feel they are protected by it. According to Mikko Hypponen,  &#8230; <a href="http://t3chlaw.wordpress.com/2009/10/09/to-tweet-or-not-to-tweet-do-twitters-terms-of-service-need-a-revision/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=56&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Twitter&#8217;s recent banning of F-Secure Chief Research Officer, <a href="http://mikko.hypponen.com/bio.htm">Mikko H. Hypponen</a>, calls into question their <a href="http://twitter.com/tos">terms of service</a> and whether they actually practice what they preach and also whether they feel they are protected by it.</p>
<p>According to Mikko Hypponen,  Twitter suspended his account (<a href="http://twitter.com/MikkoHypponen">@mikkohypponen</a>) and removed all his tweets without notice or explanation.  After a short period of time, Twitter finally reactivated his account with the following <a href="http://www.f-secure.com/weblog/archives/00001789.html">accompanying statement</a>.<strong><em> </em></strong></p>
<p><strong><em>&#8220;</em></strong><strong><em> I&#8217;ve unsuspended your acct.<br />
You were suspended for using the malware URL rnyspeceDOTcom in DMs.<br />
Be careful!<br />
We scan evrythng for malware.</em></strong><strong><em>&#8220;</em></strong></p>
<p>Based on this statement, it appears to me that Twitter believes Mikko was distributing a malicious link and Twitter must have felt that they would be at least partially on the hook for his actions.</p>
<p>This seems directly in contrast to what they state in their terms of service.</p>
<p>Under the heading &#8220;Basic Terms&#8221;, it clearly is speaking to users who post content when it states the following:</p>
<ul> &#8220;<strong>You are responsible for your use of the Services, for any content you post to the Services, and for any consequences thereof</strong>. The Content you submit, post, or display will be able to be viewed by other users of the Services and through third party services and websites (go to the Account Settings page to control who sees your Content). <strong>You should only provide Content that you are comfortable sharing with others under these Terms</strong>.&#8221;</ul>
<p>The portion about being comfortable sharing is a little wiggly since it is rather subjective (apparently Mikko felt comfortable sending it out) but the rest of it seems pretty straight forward and clear (at least to me).  They are stating in pretty direct terms that they are not responsible.</p>
<p>Under the heading &#8220;Content on the Services&#8221;, it states:</p>
<ul> &#8220;All Content, whether publicly posted or privately transmitted, is the sole responsibility of the person who originated such Content. We may not monitor or control the Content posted via the Services and, we cannot take responsibility for such Content. Any use or reliance on any Content or materials posted via the Services or obtained by you through the Services is at your own risk.</p>
<p>We do not endorse, support, represent or guarantee the completeness, truthfulness, accuracy, or reliability of any Content or communications posted via the Services or endorse any opinions expressed via the Services. You understand that by using the Services, you may be exposed to Content that might be offensive, harmful, inaccurate or otherwise inappropriate, or in some cases, postings that have been mislabeled or are otherwise deceptive. Under no circumstances will Twitter be liable in any way for any Content, including, but not limited to, any errors or omissions in any Content, or any loss or damage of any kind incurred as a result of the use of any Content posted, emailed, transmitted or otherwise made available via the Services or broadcast elsewhere.&#8221;</ul>
<p>This throws me for a loop, when they say &#8220;We may not monitor or control the Content posted via the Services and, we cannot take responsibility for such Content&#8221;.  Based on the response to Mikko regarding why his account was suspended, they do appear to be monitoring or they would not have suspended Mikko&#8217;s account based on a scan of the link.</p>
<p>Under the heading &#8220;Restrictions on Content and Use of the Services&#8221;, it states:</p>
<ul> We reserve the right at all times (but will not have an obligation) to remove or refuse to distribute any Content on the Services and to terminate users or reclaim usernames.   Please review the <a href="http://help.twitter.com/forums/26257/entries/18311">Twitter Rules</a> (which are part of these Terms) to better understand what is prohibited on the Service.&#8221;</ul>
<p>Based on &#8220;<a href="http://help.twitter.com/forums/26257/entries/18311">Twitter Rules</a>&#8220;, under the heading of <span style="font-weight:bold;">Malware/Phishing</span>, &#8220;You may not publish or link to malicious content intended to damage or disrupt another user’s browser or computer or to compromise a user’s privacy.&#8221;</p>
<p>Based on my review of the tweet that got Mikko into trouble with Twitter, he did not provide a functional link but rather a domain name reference.  To further show that he attempted to dissuade casual visitors from going to that site, he included a warning to not visit the site.</p>
<p>With all this mess, it makes me wonder if Twitter will issue some revisions to its policy and rules.</p>
<p>I guess this throws a wrinkle into the<a href="http://www.abajournal.com/news/possible_defense_to_twitter_suits_tweets_arent_taken_seriously/"> argument that nobody takes Tweets seriously</a>, at least Twitter does.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=56&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/10/09/to-tweet-or-not-to-tweet-do-twitters-terms-of-service-need-a-revision/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>Chilling of Security Researchers (Again) &#8211; Let&#8217;s Fix It!</title>
		<link>http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/</link>
		<comments>http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 02:17:03 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Chilling Effect]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Moxie Marlinspike]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=39</guid>
		<description><![CDATA[Today it was reported that security researcher Moxie Marlinspike was &#8220;banished from PayPal&#8221;.  According to The Register, he received an email which seemed to indicate he violated the acceptable use policy.  It further explained that he should remove PayPal logos &#8230; <a href="http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=39&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today it was reported that security researcher <a href="http://www.thoughtcrime.org/about.html">Moxie Marlinspike</a> was &#8220;banished from PayPal&#8221;.  <a href="http://www.theregister.co.uk/2009/10/06/paypal_banishes_ssl_hacker/">According to The Register</a>, he received an email which seemed to indicate he violated the acceptable use policy.  It further explained that he should remove PayPal logos from his site and submit and affidavit acknowledging that it has been done.</p>
<p>This action comes one day after someone <a href="http://www.theregister.co.uk/2009/10/05/fraudulent_paypay_certificate_published/">posted </a>a null-prefix certificate on the full-disclosure mailing list.  The <a href="http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike">concept of this hack</a> was introduced by Moxie Marlinspike this summer in Las   Vegas during Black Hat and then again at Defcon 17.  I happened to have attended his brief at Black Hat and remember the buzz that resulted from his presentation.  The effect of the disclosure seemingly lost some of the shock factor after Dan Kaminsky <a href="https://media.blackhat.com/bh-usa-09/video/KAMINSKY/BHUSA09-Kaminsky-BlackOpsPKI-VIDEO.mov">gave a presentation</a> where he discussed this same vulnerability.  Mr.  Kaminsky commented that he had reached out to certificate authentication authorities.  So why does this problem still exist and more importantly why is a chilling action being taken against a security researcher, again?</p>
<p>This seemingly retaliatory action against a security researcher is not the first of its kind.  In 2008, three students at the Massachusetts Institute of Technology (MIT) were put under a gag order after it was discovered they were going to give a <a href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Anderson">talk at DEFCON 16</a> that would reveal vulnerabilities in Boston&#8217;s transit fare payment system.</p>
<p>Electronic Frontier Foundation (EFF), who defended the MIT students, were able to get a positive result for the three students but the problem of chilling researchers still exists.  EFF&#8217;s <a href="http://www.eff.org/issues/coders">Coder&#8217;s Rights Project</a> was established to defend researchers during these types of situations.  While they do great work, it is not a long-term solution.  We need something more concrete that can scale and be available to all researchers.</p>
<p>I propose creation of a safe harbor system where security researchers can reveal their findings to an objective third party (possibly US-CERT) prior (maybe 30 days) to publishing them to the public and in exchange receive some benefits and legal protections.</p>
<p>Without such a protection mechanism, security researchers will continue to be threatened by potential chilling effects that come with revealing vulnerabilities to the public.  In an age when cyber security is making the nightly news and is widely considered one of our greatest national security problem sets, we have a system that provides an obstacle to security research.</p>
<p>I am looking forward to discussion of this proposal and moving forward with trying to establish protections for security researchers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=39&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/10/07/chilling-of-security-researchers-again-lets-fix-it/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>Notes from Panel Discussion on &#8220;Integrating Disciplines: Cyber Security, Law &amp; Policy&#8221;</title>
		<link>http://t3chlaw.wordpress.com/2009/10/01/note-from-panel-discussion-on/</link>
		<comments>http://t3chlaw.wordpress.com/2009/10/01/note-from-panel-discussion-on/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 19:55:43 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[computer network defense]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=26</guid>
		<description><![CDATA[The following comments are based on my notes from the panel discussion &#8220;Integrating Disciplines: Cyber Security, Law &#38; Policy&#8221; which took place on 1 October 2009 at Georgetown University &#8211; ironically the same day that the newly created U.S. Cyber &#8230; <a href="http://t3chlaw.wordpress.com/2009/10/01/note-from-panel-discussion-on/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=26&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The following comments are based on my notes from the panel discussion &#8220;Integrating Disciplines: Cyber Security, Law &amp; Policy&#8221; which took place on 1 October 2009 at Georgetown University &#8211; ironically the same day that the newly created U.S. Cyber Command goes online.</p>
<p>Because I was hand writing my notes, I didn&#8217;t get a chance to get full quotes so much of this is paraphrased&#8230; so please do not take any of this as scripture.  I just wrote down the comments that caught my attention.</p>
<p>The speakers on the panel were as follows:</p>
<p>Gen. (Ret.) Michael Hayden<br />
Former Director, National Security Agency and Central Intelligence Agency</p>
<p>Dr. James Lewis<br />
Senior Fellow, Center for Strategic and International Studies</p>
<p>Ms. Suzanne Spaulding<br />
Principal, Bingham McCutchen Consulting Group</p>
<p>Ms. Siobhan Gorman<br />
National Security Correspondent, The Wall Street Journal</p>
<p>Mr. Amit Yoran<br />
CEO, Netwitness; Former Director, U.S. Computer Emergency Readiness Team</p>
<p>Mr. Wes Spain<br />
Program Director for Intelligence, Lawrence Livermore National Laboratory</p>
<p>The panel discussion started with each speaker having a few minutes to give their remarks. After the entire panel spoke, the crowd was permitted to ask questions.  I didn&#8217;t type out the questions and responses so you will have to <a href="http://explore.georgetown.edu/news/?id=45081">watch the video</a> for those.</p>
<p><strong>Michael Hayden</strong> began the discussion stating that the problems of cyber are &#8220;really hard&#8221; and challenging.  He began thinking about cyber while leading another command prior to NSA.  He mentions the law of the seas and how it took the world almost a decade to get that right and there were years of experience and history from which to draw.</p>
<p>We currently have a lack of adequate laws and policies and consequently our practices are outstripping policy and actions are almost legitimized as we go along.</p>
<p>Regarding cyber policy, it has been tried before (even before George Bush started it).  During the last days of the Clinton campaign, Dick Clark, released a policy and it was dead in 36 hours.</p>
<p>NSA is the center of expertise for this area but because of previous negatively perceived incidents involving NSA many are nervous about their involvement.</p>
<p><strong>James Lewis</strong> spoke second.  He started off by stating how he believed that Gen. Hayden was the greatest NSA Director.</p>
<p>He does not believe that the problem of cyber is a technology problem but a law and policy problem.  Due to our history as a nation, we have legal and political impediments that other nations do not have.  We care about freedom of speech and privacy where other countries have them lower on their list of concerns.</p>
<p>Nation states active in malicious cyber activity are conducting what is called a hybrid war (where you avoid direct military confrontation with US).  Many are staying just below the threshold.  He believes this has been going on for a while and references how in 1984 the then KGB hired German hackers.  I believe this is a reference to &#8220;<a title="The Cuckoo's Egg" href="http://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book)">The Cuckoo&#8217;s Egg</a>&#8221; written by Clifford Stoll.</p>
<p>These types of attacks can get adversary&#8217;s the kind of information they desire and they are hard to attribute to the offending nation or actor.</p>
<p>He also believes that there are two ideological tides that push against progress.  One is the thought that the market will solve everything.  Those people don&#8217;t want the U.S. Government to be involved in cyber security.  The second is the thought that the Internet is some clean beautiful place and having U.S. Government involvement will only mess it up.</p>
<p>He believes a cyber September 11th scenario would get the kind of political will it takes to get moving at the right speed.</p>
<p><strong>Suzanne Spaulding</strong> began by stating that she believes there is a &#8220;who goes first&#8221; problem occuring.  Lawyers want to know the goals and policymakers are asking the lawyers for what they can do.  She believes the biggest challenges relate to secrecy.  Democracy doesn&#8217;t function well with secrecy.  It is not just the U.S. Government that is being secretive, U.S. companies are also playing that game.  She would like to have an open discussion where we can make an informed decision.</p>
<p><strong>Siobhan Gorman</strong> (formerly of the Baltimore Sun) is concerned about transparency.  She stated that it is easier to get details about a terror cell than to get details from officials about cyber security.  This is a problem when the average person doesn&#8217;t feel that it has an impact on them.  The closest the general public gets to the problem is identity theft.  Despite the lack of awareness, the problems are there.  According to her, GSA has a report out that states that 20 of 24 agencies have problems securing information.  DHS system called Einstein will not be online fully for another year and a half.</p>
<p>Impact of companies not reporting security breaches is also contributing to a lack of information and understanding of breadth of problems that are out there.</p>
<p><strong>Amit Yoran</strong>, who is part of the commercial sector, believes that the nuances of cyber are phenomenally complex and that law and policy are having problems keeping up.</p>
<p>He believes that the future of the national defense posture is going to be the ability to be offensive in cyberspace.  He sees the cyberspace problem as more of an economic issue than a national security issue.  He concurs with the sentiment about transparency and argues that the reason the commercial industry has not solved the problems is because of the lack of transparency into the activities of national security related breaches.  He mentioned two FBI statements relating to cyber.  The first is that more money is being made by cyber criminals than drug traffickers.  Compromised systems become a commodity on the cyber market.  The second statement relates to the fact that some 100 nations now have offensive cyber operations.</p>
<p><strong>Wes Spain</strong> believes it is a significant threat and is concerned with lack of U.S. Government leadership.  He believes it is a problem of predictable surprise.  Leadership is aware of the problem (and it is only getting worse) but not enough is being done.  He believes that it is a technological and law/policy problem.  He also concurs with Mr. Lewis that we will need a significant catalyst.  It is a risk management issue.  We need to get cyber security on the same plain with physical security.  Nobody argues about having physical security because they understand there is a threat.  When you walk in a tough neighborhood, you understand where you are and that you may have physical security concerns but when you get on the Internet, there is no sense of a threat.</p>
<p>The following are the what I took from the discussion:</p>
<ul>
<li>Need more transparency (from U.S. Gov and U.S. businesses);</li>
<li>Need to get public awareness of the threat &#8211; don&#8217;t wait until it is too late.  There are already some good examples that could do the trick (<a title="GhostNet" href="http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network">GhostNet</a> &amp; <a title="SCADA" href="http://www.wired.com/epicenter/2009/04/china-and-russi/">SCADA</a>);</li>
<li>DHS has the authority and NSA has the know-how &#8211; need to get them working together better (FAA &amp; NORAD work together fine for air traffic control issues &#8211; why can&#8217;t it be done with DHS-NSA for cyber security);</li>
<li>Need broad law and policies because law &amp; policy are not as reactive as technology;</li>
<li>There is a current active conflict taking place in cyberspace where nation state actors are acting just below the threshold;</li>
<li>Need to make a value proposition for market place to take part and be willing;</li>
<li>If you involve companies, make sure you have the political will power to sustain your position (don&#8217;t let them get exposed to market penalties because the will to support them has changed).  I am guessing this is a reference to the telecom immunity and how now there is a movement to repeal the immunity; and</li>
<li>We need a forum to discuss cyber problems.  China suggested the G20.  Need to have a place to do it.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=26&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/10/01/note-from-panel-discussion-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>Indicator of Court&#8217;s Stance Regarding Accountability of High Government Officials?</title>
		<link>http://t3chlaw.wordpress.com/2009/05/20/indicator-of-courts-stance-regarding-accountability-of-high-government-officials/</link>
		<comments>http://t3chlaw.wordpress.com/2009/05/20/indicator-of-courts-stance-regarding-accountability-of-high-government-officials/#comments</comments>
		<pubDate>Wed, 20 May 2009 03:52:01 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Law]]></category>
		<category><![CDATA[Ashcroft v. Iqbal]]></category>
		<category><![CDATA[Supreme Court]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=12</guid>
		<description><![CDATA[Based on a post found on the SCOTUSblog, I decided to read the Court&#8217;s opinion in Ashcroft v. Iqbal.  This is a pretty interesting read. The Court takes an opportunity to avoid the issue by relying on perceived problems in &#8230; <a href="http://t3chlaw.wordpress.com/2009/05/20/indicator-of-courts-stance-regarding-accountability-of-high-government-officials/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=12&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Based on a post found on the <a href="http://www.scotusblog.com/wp/analysis-a-pass-for-high-officials/" target="_blank">SCOTUSblog</a>, I decided to read the Court&#8217;s opinion in <em><a href="http://www.supremecourtus.gov/opinions/08pdf/07-1015.pdf" target="_blank">Ashcroft v. Iqbal</a>.  This is a pretty interesting read.</em></p>
<p>The Court takes an opportunity to avoid the issue by relying on perceived problems in the pleadings.</p>
<p>The dissent by Justice Souter is a good read and really does a good job of highlighting the problems in the Majority opinion.  I particularly like how they key in on the fact that Ashcroft and Mueller conceded in their petition for certiorari that they would be liable if they had &#8220;actual knowledge&#8221; of discrimination by their subordinates and exhibited &#8220;deliberate indifference&#8221; to that discrimination.</p>
<p>There is a strange reference made by the Majority when they seemingly try to justify the &#8220;disparate, incidental impact&#8221; on Arab Muslims by saying &#8220;the September 11 attacks were perpetrated by 19 Arab Muslim hijackers who counted themselves members in good standing of al Qaeda, an Islamic fundamentalist group.  Al Qaeda was headed by another Arab Muslim &#8211; Osama bin Laden &#8211; and composed in large part of his Arab Muslim disciples.&#8221;</p>
<p>I agree that most of the attackers were Arabs but from <a href="https://www.cia.gov/news-information/speeches-testimony/2002/DCI_18_June_testimony_new.pdf">what I found</a>, not all of them were Arabs.  It is  probably an oversight but could be perceived the wrong way.</p>
<p>This case will certainly be discussed if we ever see any litigation involving CIA (allegations of torture) or NSA (allegations involving surveillance).</p>
<p><em></em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=12&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/05/20/indicator-of-courts-stance-regarding-accountability-of-high-government-officials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
		<item>
		<title>NV Encryption Law</title>
		<link>http://t3chlaw.wordpress.com/2009/05/16/5/</link>
		<comments>http://t3chlaw.wordpress.com/2009/05/16/5/#comments</comments>
		<pubDate>Sat, 16 May 2009 18:34:10 +0000</pubDate>
		<dc:creator>t3chlaw</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[identity theft]]></category>

		<guid isPermaLink="false">http://t3chlaw.wordpress.com/?p=5</guid>
		<description><![CDATA[Interesting NV law regarding use of encryption. Seems like a tough burden for small businesses. http://tinyurl.com/rxh3dk (via @PrivacyProf) I am very surprised that this has not taken off in other states&#8230; considering all the identify theft that occurs with banks &#8230; <a href="http://t3chlaw.wordpress.com/2009/05/16/5/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=5&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span class="status-body"><span class="entry-content">Interesting NV law regarding use of encryption.   Seems like a tough burden for small businesses. </span></span></p>
<p><span class="status-body"><span class="entry-content"><a rel="nofollow" href="http://tinyurl.com/rxh3dk" target="_blank">http://tinyurl.com/rxh3dk</a> (via @PrivacyProf)</span></span></p>
<p><span class="status-body"><span class="entry-content">I am very surprised that this has not taken off in other states&#8230; considering all the identify theft that occurs with banks &amp; credit card companies getting hacked.</span></span></p>
<p><span class="status-body"><span class="entry-content"><br />
</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/t3chlaw.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/t3chlaw.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/t3chlaw.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=t3chlaw.wordpress.com&amp;blog=7775323&amp;post=5&amp;subd=t3chlaw&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://t3chlaw.wordpress.com/2009/05/16/5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4ff1d88dee9619d3fcb059c219559bd?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">t3chlaw</media:title>
		</media:content>
	</item>
	</channel>
</rss>
