http://www.thehindubusinessline.com/ew/2009/12/28/stories/2009122849960200.htm

Shot in the arm for cyber security

The US is sending the right signals? with the appointment of a Cyber Czar.


R.K. Raghavan

US President Barack Obama's bold move to appoint Howard Schmidt,
formerly of Microsoft and eBay, to be the first US Cyber Czar could
not have come at a more appropriate time. Actually, the decision to
create this position in the White House was taken as early as May
2009, and an acting chief, Melissa Hathaway, was appointed then. She,
however, quit in August, frustrated at her inability to implement the
much needed changes in a country that has shown itself to be extremely
vulnerable to cyber attacks.

Schmidt comes to the job with forty years experience in government,
business and law enforcement. While his role will evolve itself as he
proceeds, it is generally believed that his major task will be one of
integrating different agencies and organisations in the US so that
cyber security received better attention. In this direction he may be
expected to formulate a new strategy to obtain an organised response
to cyber attacks that have become far too often for the President's
comfort.

Relevant here is that, in spite of all the bonhomie lately seen
between the US and China, the latter has reportedly not shown itself
not averse to supporting individuals solely on the job of breaking
into Western systems. Russia and North Korea too have been suspected
to share this propensity to pry into government systems. Schmidt could
also be launching a major programme to educate organisations and
individuals in the US so that they understand why it is necessary to
secure cyber space.

Schimdt's appointment is a bold and imaginative experiment. Upon its
success will depend how well the country is able to protect its
critical information, especially that which is stored in the Pentagon.
My readers may recall how Gary MacKinnon, a 42-year-old Briton, was
able to break into US defence computers a few years ago and caused
immense damage. He claimed innocence and said that his intention was
only to pick up information on UFOs that was available to the US
government. He is now facing expatriation to the US.

Whether Schmidt succeeds or not, even if he fails, the message will
have been sent across the nation that cyber security is important
enough to warrant the attention of the highest executive in the
country. It has a significant lesson for Indian authorities also. They
would do well to study what prompted President Obama to go this
distance to create a cyber security position in the White House. It
will not be totally inappropriate for Indian Government to copy the US
example and establish an authority at the national level to take care
of our systems, especially when the terrorist threat has not faded
away.

Significant is the Union Home Secretary's recent public comment that
the IT industry was a definite terrorist target. We have, of course,
agencies such as like the Computer Emergency Response Team (CERT) in
the IT Ministry which perform this role, but these do more fire
fighting than policy formulation. A highly empowered expert with a
good track record in the area will be an important adjunct to the
National Security Advisor.

Worrisome security breaches

Interestingly, Schmidt's appointment comes against the backdrop of
several security breaches recently in the US, especially in the
private sector. The Wall Street Journal reports a major hacker attack
on the Citi Group Inc. systems which resulted in the theft of millions
of dollars. While the Citi group does not acknowledge that such an
incident had occurred, it is believed that the report is true and that
the theft took place over a course of time and was detected only a few
months ago. The crime was perpetrated by a Russian gang that had come
to adverse notice for hacking and circulating malicious software,
child pornography and spam.

The FBI is investigating into the Citi group attack. The intruders are
alleged to have used a program called Black Energy. This software was
designed by a Russian hacker and can be used to a command a botnet or
a large group of computers infected by a malware. The gang that which
committed this crime was known to have also targeted a US government
agency.

General indifference and lack of preparedness to thwart cyber
intrusions in the private sector is also evident from the breaches
that were reported earlier this year from a top payments processor
company called the Heartland Payment Systems (HPY). Investigations
revealed that beginning May 2008, cyber criminals were able to break
into Heartland's networks and steal voluminous information relating to
the credit/debit card data belonging to consumers.

The numbers involved are mind-boggling, namely, 100 million cards
issued by more than 650 financial services companies. The culprits are
yet to be caught. It is learned that Heartland hackers secured track
data from a credit card's magnetic stripe, which usually contains the
account number and often also the card holder's name. Heartland is now
engaged in encrypting card data at the point it is swiped, so that
such data does do not go through the networks unencrypted.

President Obama's concern for strengthening cyber security percolates
down to the level of school children. In a recent speech at Huntington
he advised them to be careful about what they posted on Facebook. ,
and warned them that what they say on this social network could be
used against them much later.

Although some organisations in the country berated him for stepping
into a territory that was not strictly his, Obama's word of caution as
a parent could hardly be faulted. There is little disagreement over
the fact that the users of Facebook and similar sites are over sharing
their personal information carelessly, and this ack of carehas often
led to violent crime. There is now a whole lot of literature on how to
protect yourself while on Facebook and other sites, so that what
should remain private does not become public.

According to Sarah Peres of ReWriteWeb, children accessing Facebook
will have to make at least three lists before using Facebook.

These would include persons who come under the definition of
`friends', and those whom the user regards as safe and `who can see
what on your profile' and `who can see your address and phone number'.
This seems a very sensible categorisation so that undesirables do not
exploit the posted information.

The point is, how many parents will take care to educate tell their
children on these fundamental precautions. Their lack of seriousness
in the matter is unpardonable if not wholly culpable, and is the chief
cause of Internet crime against children.

The writer is a former CBI Director who is currently Adviser
(Security) to TCS Ltd.

Reply via email to