http://www.thehindubusinessline.com/ew/2009/12/28/stories/2009122849960200.htm
Shot in the arm for cyber security The US is sending the right signals? with the appointment of a Cyber Czar. R.K. Raghavan US President Barack Obama's bold move to appoint Howard Schmidt, formerly of Microsoft and eBay, to be the first US Cyber Czar could not have come at a more appropriate time. Actually, the decision to create this position in the White House was taken as early as May 2009, and an acting chief, Melissa Hathaway, was appointed then. She, however, quit in August, frustrated at her inability to implement the much needed changes in a country that has shown itself to be extremely vulnerable to cyber attacks. Schmidt comes to the job with forty years experience in government, business and law enforcement. While his role will evolve itself as he proceeds, it is generally believed that his major task will be one of integrating different agencies and organisations in the US so that cyber security received better attention. In this direction he may be expected to formulate a new strategy to obtain an organised response to cyber attacks that have become far too often for the President's comfort. Relevant here is that, in spite of all the bonhomie lately seen between the US and China, the latter has reportedly not shown itself not averse to supporting individuals solely on the job of breaking into Western systems. Russia and North Korea too have been suspected to share this propensity to pry into government systems. Schmidt could also be launching a major programme to educate organisations and individuals in the US so that they understand why it is necessary to secure cyber space. Schimdt's appointment is a bold and imaginative experiment. Upon its success will depend how well the country is able to protect its critical information, especially that which is stored in the Pentagon. My readers may recall how Gary MacKinnon, a 42-year-old Briton, was able to break into US defence computers a few years ago and caused immense damage. He claimed innocence and said that his intention was only to pick up information on UFOs that was available to the US government. He is now facing expatriation to the US. Whether Schmidt succeeds or not, even if he fails, the message will have been sent across the nation that cyber security is important enough to warrant the attention of the highest executive in the country. It has a significant lesson for Indian authorities also. They would do well to study what prompted President Obama to go this distance to create a cyber security position in the White House. It will not be totally inappropriate for Indian Government to copy the US example and establish an authority at the national level to take care of our systems, especially when the terrorist threat has not faded away. Significant is the Union Home Secretary's recent public comment that the IT industry was a definite terrorist target. We have, of course, agencies such as like the Computer Emergency Response Team (CERT) in the IT Ministry which perform this role, but these do more fire fighting than policy formulation. A highly empowered expert with a good track record in the area will be an important adjunct to the National Security Advisor. Worrisome security breaches Interestingly, Schmidt's appointment comes against the backdrop of several security breaches recently in the US, especially in the private sector. The Wall Street Journal reports a major hacker attack on the Citi Group Inc. systems which resulted in the theft of millions of dollars. While the Citi group does not acknowledge that such an incident had occurred, it is believed that the report is true and that the theft took place over a course of time and was detected only a few months ago. The crime was perpetrated by a Russian gang that had come to adverse notice for hacking and circulating malicious software, child pornography and spam. The FBI is investigating into the Citi group attack. The intruders are alleged to have used a program called Black Energy. This software was designed by a Russian hacker and can be used to a command a botnet or a large group of computers infected by a malware. The gang that which committed this crime was known to have also targeted a US government agency. General indifference and lack of preparedness to thwart cyber intrusions in the private sector is also evident from the breaches that were reported earlier this year from a top payments processor company called the Heartland Payment Systems (HPY). Investigations revealed that beginning May 2008, cyber criminals were able to break into Heartland's networks and steal voluminous information relating to the credit/debit card data belonging to consumers. The numbers involved are mind-boggling, namely, 100 million cards issued by more than 650 financial services companies. The culprits are yet to be caught. It is learned that Heartland hackers secured track data from a credit card's magnetic stripe, which usually contains the account number and often also the card holder's name. Heartland is now engaged in encrypting card data at the point it is swiped, so that such data does do not go through the networks unencrypted. President Obama's concern for strengthening cyber security percolates down to the level of school children. In a recent speech at Huntington he advised them to be careful about what they posted on Facebook. , and warned them that what they say on this social network could be used against them much later. Although some organisations in the country berated him for stepping into a territory that was not strictly his, Obama's word of caution as a parent could hardly be faulted. There is little disagreement over the fact that the users of Facebook and similar sites are over sharing their personal information carelessly, and this ack of carehas often led to violent crime. There is now a whole lot of literature on how to protect yourself while on Facebook and other sites, so that what should remain private does not become public. According to Sarah Peres of ReWriteWeb, children accessing Facebook will have to make at least three lists before using Facebook. These would include persons who come under the definition of `friends', and those whom the user regards as safe and `who can see what on your profile' and `who can see your address and phone number'. This seems a very sensible categorisation so that undesirables do not exploit the posted information. The point is, how many parents will take care to educate tell their children on these fundamental precautions. Their lack of seriousness in the matter is unpardonable if not wholly culpable, and is the chief cause of Internet crime against children. The writer is a former CBI Director who is currently Adviser (Security) to TCS Ltd.
