Live data from Hacker News

Obama expected to issue cybersecurity executive order

usatoday.com

1–10 of 63 posts

Re: Obama expected to issue cybersecurity executive order

#3
The order should be all critical computers like power-grid control should not be able to connect to the internet in any way or have usb ports or DVD drives.

I have this fear that somewhere an ICBM is on an internet router because some general wants to monitor it. Sounds insane right? Well why are power stations on the internet?

Re: Obama expected to issue cybersecurity executive order

#4
post #3

The order should be all critical computers like power-grid control should not be able to connect to the internet in any way or have usb ports or DVD drives. I have this fear that somewhere an ICBM is on an internet router because some general wants to monitor it. Sounds insane right? Well why are power stations on the internet?

You also need to monitor or update the software and machinery, so you'll probably want some kind of internal network. But can other things than the control systems connect to that network? Then you're screwed, unless you can absolutely guarantee that e.g. a laptop connected to the same network can't be compromised/transported out of the facility.

Iran's SCADA controllers were not connected to the Internet when they got owned by Stuxnet. They were just connected to a network with a laptop with a USB port.

Re: Obama expected to issue cybersecurity executive order

#5
The fundamental problem with this in my opinion starts with the executive order. As the article states: the executive's job is to enforce laws, not make them. EO's have stepped well beyond that in the last 20 years, with the executive branch becoming more sovereign in nature, which scares the hell out of me.

We do need a cyber security bill, but it should be passed by Congress, whose job it is to iron out all the competing needs, instead of passed by fiat by a wanna-be king[1] who "knows what's best for the country".

1. EO's aren't the exclusive domain of Obama by any stretch. Every president since HW Bush has used them in increasing number and, IMO, in increasing defiance to the separation of powers. Another 20 years and Congress will be nothing but a complete farce, much like other dictatorial "republics".

Re: Obama expected to issue cybersecurity executive order

#7

The fundamental problem with this in my opinion starts with the executive order. As the article states: the executive's job is to enforce laws, not make them. EO's have stepped well beyond that in the last 20 years, with the executive branch becoming more sovereign in nature, which scares the hell out of me. We do need a cyber security bill, but it should be passed by Congress, whose job it is to iron out all the com…

You're WAAAAAAY past the fundamental problem IMO. The problem is not the king, it's the entire court. The US now has a dysfunctional relationship with a federal government that continually grabs powers they don't have.

Re: Obama expected to issue cybersecurity executive order

#9
Have any of you actually read the executive order? If not, did you perhaps notice who the sources were for the stories being written about it today?

There was a cybersecurity order on the table last year (it wasn't enacted). HN got up in arms about it. Some of us read it. Guess what? It concerned itself almost entirely with the operational security of the federal government itself (which operates the world's largest IT departments). The places where it stepped past instructing DOE how to secure their networks were to create educational programs to get more people doing information security. It contained no provisions at all that would have given the government access to private entities networks.

I haven't read this executive order, but if I was going to place a bet about it, it would be that everyone hyperventilating about "king complexes" on HN is being played.

Re: Obama expected to issue cybersecurity executive order

#10
post #4
post #3

The order should be all critical computers like power-grid control should not be able to connect to the internet in any way or have usb ports or DVD drives. I have this fear that somewhere an ICBM is on an internet router because some general wants to monitor it. Sounds insane right? Well why are power stations on the internet?

You also need to monitor or update the software and machinery, so you'll probably want some kind of internal network. But can other things than the control systems connect to that network? Then you're screwed, unless you can absolutely guarantee that e.g. a laptop connected to the same network can't be compromised/transported out of the facility. Iran's SCADA controllers were not connected to the Internet when they g…

But Obama's problem seems to be with the Internet. So keep those off the Internet, and then pass whatever legislation and executive orders they want for those networks, and leave the Internet alone.

Of course the reality is this executive order is going to have many "gotchas" hidden in it, to give the executive more power over the Internet, and we probably won't learn about them until it's too late.

Post reply on HN