Live data from Hacker News

Obama expected to issue cybersecurity executive order

usatoday.com

61–63 of 63 posts

Re: Obama expected to issue cybersecurity executive order

#61
post #21
post #9

Have any of you actually read the executive order? If not, did you perhaps notice who the sources were for the stories being written about it today? There was a cybersecurity order on the table last year (it wasn't enacted). HN got up in arms about it. Some of us read it. Guess what? It concerned itself almost entirely with the operational security of the federal government itself (which operates the world's largest…

Are you talking about this? http://www.lawfareblog.com/wp-content/uploads/2012/11/White-...

The "new" EO is virtually identical to that one, yes.

(I think I got "educational programs", which IIRC was from Rockefeller's draft bill, confused with "outside consultation" from this order.)

I did a clause-by-clause comparison (you're welcome! all part of the service I provide) and while there are minor deltas (like which sentence of a clause the Attorney General appears in, or whether deadlines are 90 days or 120 days) it's the same thing:

* Coordinate better in managing FedGov systems

* Figure out a way to relay threat info from FedGov to private sector

* Inventory the US for computer systems that if disabled could kill people

* Reach out to owners of those systems to help them not be owned up over old dialup modems everyone forgot about

Re: Obama expected to issue cybersecurity executive order

#62
post #28
post #23

Earlier quoted context omitted.

The problem is the bi-directional information sharing between private companies and the multiple levels of government -- it should be one-way (private companies -> government). There is a very large potential for abuse and we will have no recourse.

I don't want information sharing that way either. We have (sadly, increasingly circumvented or weakened) laws banning that for a reason.

I will not deny that it's unpleasant but it is a necessity, which is why subpoenas and warrants exist.

Unfortunately, law enforcement organizations are harrumphing and ruffling feathers so they're getting what they want -- ability to bypass the requirement for subpoenas and court-ordered warrants.

Re: Obama expected to issue cybersecurity executive order

#63
post #34
post #3

The order should be all critical computers like power-grid control should not be able to connect to the internet in any way or have usb ports or DVD drives. I have this fear that somewhere an ICBM is on an internet router because some general wants to monitor it. Sounds insane right? Well why are power stations on the internet?

As a former employee of one of the US's largest electric utilities, I can answer this question. The reason is quite simple. Most power plants are in the middle of nowhere and people with the capability to manage them don't want to live near them, not because of the plants themselves, but because they are in tiny rural towns, which most people understand and appreciate. To make good decisions, the experts, who prefer…

The great thing about remote management interfaces over the internet is that anyone can try to take control over the internet. Whether it's simply a video camera or a power station.

See that pesky internet part.

I really hope ICBMs don't have remote management interfaces over the internet for "convenience".

Post reply on HN