iPhone app iPad app Android phone app Android tablet app More

Richard A. Clarke

Richard A. Clarke

Posted: May 8, 2009 10:29 AM

Obama's Challenge in Cyberspace


In the next few days President Obama will decide whether he will live up to his campaign promises about dealing seriously with the challenge of cyber security by creating a White House office to direct government activity and coordinate with the private sector. None of the options being served up to him will create the stand alone White House office that is needed to provide the leadership on this issue.

The reasons that this decision is important have been spread across the media this last month. Among the facts revealed are that foreign intelligence services have penetrated the control systems of the US electric power grid and have left behind "logic bombs" and "trap doors;" data about America's latest fighter aircraft, the F-35 Lightning II, has been copied off the networks of defense contractors and sent overseas; the Pentagon plans to appoint a new four star general to run a new Cyber Command based on the National Security Agency (NSA); and a National Academy of Sciences blue ribbon panel has urged caution about the US engaging in offensive cyber war.

Blue ribbon panels have been strongly recommending the creation of a coordinated government response to cyber security since the Marsh Commission reported to President Clinton in 1997. As a service to the new president, the Center for Strategic and International Studies (CSIS) empaneled members of Congress and other experts last year to review how a new administration should deal with the issue. Their unanimous recommendation was the establishment of a White House Office of Cyber Security to energize and rationalize the myriad, ineffective government programs to secure cyberspace. Senator Rockefeller (D-WV) and other Members have legislation pending to do just that.

It's not just the plans for the F-35 that have been stolen. Information technology experts in and out of government believe that American corporations are regularly losing to foreign cyber espionage (most likely China's) what gives the US firms their competitive edge: the results of expense R&D, engineering plans, chemical and biological formulas, complex software, even customer lists and pricing data. No company, no matter how large, can defend itself effectively against the techniques of sophisticated foreign cyber war organizations and intelligence services. They must rely on the government to so do. Yet the government is in disarray, like a Crew team without a cocksen, making little forward progress, despite massive expenditures of effort.

Obama is now being told by economic advisor Larry Summers that those advocating greater coordination of efforts on cyber security are misguided, that they seek to impose intrusive and costly regulation on industry, and would stifle innovation. Summer's solution is that someone in his office, which is busy with other things, should have equal responsibility to deal with this set of cyber challenges with another official buried somewhere on the National Security Council staff. What the CSIS Commission and Congressional hearings have shown is that many industry leaders disagree with Summers; they want a single, senior official to deal with on protecting America's cyberspace. What Summer's wants would mean no one official was accountable or responsible to the President and the Congress on this issue. We have seen what such a lack of leadership has produced thus far, unaddressed and escalating cyber threats to both our national security and national economy. The Economic Advisor should have a role in reviewing any proposal that would regulate industry, but he should not have the power to prevent the US government from establishing a new office to deal with a serious new challenge.

President Obama has been presented with more complex and important issues than any American leader in my lifetime. One of the difficulties any executive has in such a circumstance is spotting the crucial decisions that he must make now on what are comparatively quiet issues, decisions that will have significant future consequences. If Obama reneges on his campaign pledge to create a White House Office on Cyber Security to lead US government efforts, one day he or some future President may wish he had done otherwise, as the noise from the White House's back up electric generator fills the Oval Office and the President looks out on a city darkened by cyber attack.

In the next few days President Obama will decide whether he will live up to his campaign promises about dealing seriously with the challenge of cyber security by creating a White House office to direc...
In the next few days President Obama will decide whether he will live up to his campaign promises about dealing seriously with the challenge of cyber security by creating a White House office to direc...
 
 
  • Comments
  • 127
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2 3 4  Next ›  Last »  (4 total)
10:05 AM on 05/12/2009
I guess we need other people to be afraid so that we don't have to. Is there ANY substantive proof that there are ANY vulnerabilities in our infrastructure or is this another case where hair gel and nail clippers are dangerous to everyone? My understanding of the networks you are describing is that they are intranets not directly connected to the general internet backbone (regardless of what the almost-always-wrong television media says). There are all kinds of ways that individuals are scammed and stolen from online, but taking out the power grid is an entirely other concept. I also understand from what I have read elsewhere that the vast majority of the thefts you are describing took place the old fashioned way; they walked in with a portable storage device, took the information and walked out of the building - hardly cyber-theft. Isn't it possible that rather than yet another expansion of government in this case , what we actually need is a consolidation and focus of the justice department into a more credible agency capable of taking on more appropriate and important issues? We have yet to see a full recovery from the recent illegal politicization of the department - that seems more important right now in any case than chasing after the cyber-boogyman.
01:20 PM on 05/11/2009
My Gawd! What in the heck was the Bush Administration during those 8 years? Why is that everything is a dayum crisis when President Obama takes office? It just gets worsts everyday. I don't know how we are still on the planet with all the potential thre.ats this country has. Seems like the Bush Administration's solution to keeping America safe was to infringe on our rights instead of correcting the problems which were making us unsafe. When we hear Cheney and the rest of the Republican leadership speak today it is telling as to what was going on during those 8 years...NOTHING. At the same time a lot of short cuts were being taken to fix problems temporarily.
photo
HUFFPOST SUPER USER
Rimser
01:10 PM on 05/11/2009
With the increasing reliance by everyone on the internet and internal networking systems, this should be a cabinet level position. It's too important an issue to have it subsumed into another department.
12:40 PM on 05/11/2009
Dear MoveOn member,
Yesterday, Dick Cheney said he has "no regrets" for the Bush-era torture program1—which we now know authorized waterboarding, forced nudity, and other gruesome acts of torture2—and rebuffed calls for accountability, saying the torture program was "the right thing to do."3

He's wrong—and we need to push back. We put together a powerful new video reminding people why we can't trust Cheney's judgment, and calling for an honest investigation into the Bush torture program.

Check out the video, and send it to your friends. If we want real accountability, we need to counter Cheney and get the message out that Americans demand answers on the Bush torture program.


Watch the video: http://www.moveon.org/r?r=51411&id=16109-9193653-dDV5QEx&t=2

Thanks for all you do.

–Nita, Kat, Ilyse, Justin and the rest of the team

Sources:

1. "Face the Nation," May 10, 2009.
http://www.cbsnews.com/video/watch/?id=5004452n

2. "Bush-era interrogations: From waterboarding to forced nudity," McClatchy Newspapers, April 16, 2009.
http://www.mcclatchydc.com/251/story/66339.html

3. "Face the Nation," May 10, 2009.
http://www.cbsnews.com/video/watch/?id=5004452n
12:38 PM on 05/11/2009
Larry Summers irks the hell out of me.
photo
HUFFPOST SUPER USER
AKaurora
Alaskan Dem
12:00 PM on 05/11/2009
Let's hope that Clarke takes to the talk circuit to push this issue.
11:47 AM on 05/11/2009
I have a hard time Richard Clarke wrote this. Others have pointed out the 'cocksen/coxswain' spelling; I'll add 'expense R & D' instead of 'expensive', and the misspelling of Summers's last name when using the possessive. But above all that is this gem: 'No company, no matter how large, can defend itself effectively against the techniques of sophisticated foreign cyber war organizations and intelligence services. They must rely on the government to so do.'

Really? I doubt that someone of Clarke's expertise and experience would have written such a grade-school absolutist statement without qualifying or explaining it to some extent. It's a rhetorical trick - a childish one - to make your point seem reasonable. I'm not sure how this piece came to bear his name, but I doubt he did it; it's too careless for someone of his rank.
11:46 AM on 05/11/2009
Larry Summers endangers everything he touches. Pack him up and send him to China, it will set them back 50 years.
DoTheMath
We're outspent, but they're outnumbered
11:42 AM on 05/11/2009
Clarke is right to suggest that the president needs to make one person ultimately accountable for cyber security. Accountability is not the sort of thing that can be spread out or shared effectively; if everyone thinks someone else is minding the store, no one is really minding it.

However, I understand Summers' concern about coordination, and I suspect he has a valid point. I have worked in an organization where a technical branch, isolated from the rest of our departments, made decisions based on security alone that prevented the organization from using its resources effectively to carry out its core mission. There is almost always a trade-off between security measures and the ability to use technical resources. When technical staff is required to work cooperatively with the people whose businesses they support, they can generally find ways to mitigate risks and strike an appropriate balance between business goals and security considerations. Left purely to their own devices, technical staff is more likely to build a culture of "You can't do this. You can't do that."
10:24 AM on 05/12/2009
That is not a common problem with technical staff, that is an extremely common problem with SECURITY staff. There are security specialists in the technology field that are very good at what they do. I very seriously doubt that the organization you are referencing paid an outside technology security firm to secure their computer network. I am quite sure that they did what every other company has been doing for years; they paid their own internal general IT department to secure their own network. You get what you pay for and when you ask individuals with very little understanding of security to secure a computer network, they will inevitably secure what is important to them and care very little about the ramifications of that. The fact is that there are extremely excellent tools available to create wonderfully usable networks that are safe and secure; you just have to pay for them.
11:38 AM on 05/11/2009
Summers ,Geithner,Bernanake,the 3 stooges,is it any wonder why America is in a economic freefall into the abyss!
11:49 AM on 05/11/2009
2 of the 3 have only been on the job for 4 months, and the free fall has morphed into a state of being suspended in midair at worst and may be bouncing back. Calling them stooges is way off the mark.
photo
HUFFPOST SUPER USER
lesterbud
Facts ARE Liberty
11:29 AM on 05/11/2009
Seems like if we are willing to pump a $trillion into new technology development over the next 4 years, we should be willing to put a few bucks into protecting that investment.

I am tired of giving the Russians, and now the Chinese products they had no hand in developing. Leaches can get very creative, but are themselves not very energetic - just opportunist. If we remove the opportunity, the Chinese will have to go back to buying our cars, computers, planes and ships.
11:29 AM on 05/11/2009
cyber is worst then nucler...can shut us all done...
11:23 AM on 05/11/2009
"Cypersecurity". Somebody forgot to run spell check on the headline page ;)
photo
HUFFPOST SUPER USER
knosiswar
Major General Smedley Butler - get to know him
11:16 AM on 05/11/2009
Rather, what is Cypersecurity?
11:23 AM on 05/11/2009
The endangerment of cypress trees. I always knew this president was weak on horticulture.
11:07 AM on 05/11/2009
I am a great fan of Obama, but I find it very hard to trust this Summers character. Too buddy-buddy with the banks and too secretive.

I say he should be replaced by Paul Krugman.