<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How Government Can Improve Cyber-Security</title>
	<atom:link href="http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jean Camp</title>
		<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/comment-page-1#comment-4157</link>
		<dc:creator>Jean Camp</dc:creator>
		<pubDate>Thu, 15 Nov 2007 21:06:42 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2555#comment-4157</guid>
		<description>Adam has an excellent point. In health and environmental risks we have standards for acceptable or hazardous risk. There are accepted methods for measuring risk. In finance there are also operational measures of risk.
I think if I hired two consultants and asked them to evaluate a small business network I would get not just two approaches but also two units of measure. It is like I ask someone &quot;How big is it?&quot; and the result came in weight and volume  with no understanding of how one might relate these with density. Security sometimes seems more like alchemy than chemistry.
We are in sad need of measures and metrics. Having some basic data would be a good start.
</description>
		<content:encoded><![CDATA[<p>Adam has an excellent point. In health and environmental risks we have standards for acceptable or hazardous risk. There are accepted methods for measuring risk. In finance there are also operational measures of risk.<br />
I think if I hired two consultants and asked them to evaluate a small business network I would get not just two approaches but also two units of measure. It is like I ask someone &#8220;How big is it?&#8221; and the result came in weight and volume  with no understanding of how one might relate these with density. Security sometimes seems more like alchemy than chemistry.<br />
We are in sad need of measures and metrics. Having some basic data would be a good start.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PHB</title>
		<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/comment-page-1#comment-4156</link>
		<dc:creator>PHB</dc:creator>
		<pubDate>Tue, 13 Nov 2007 20:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2555#comment-4156</guid>
		<description>Adam, I agree that government spending on research is good (my work was funded by five governments over the years), but suggesting this as THE way government needs to help frames the problem as a research problem.
I think we know what needs to be done, the big question is how to do it. How do we get from A to B?
</description>
		<content:encoded><![CDATA[<p>Adam, I agree that government spending on research is good (my work was funded by five governments over the years), but suggesting this as THE way government needs to help frames the problem as a research problem.<br />
I think we know what needs to be done, the big question is how to do it. How do we get from A to B?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/comment-page-1#comment-4155</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 13 Nov 2007 15:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2555#comment-4155</guid>
		<description>PHB,
I think there is a component of government action that could be very helpful.  Chris Walsh&#039;s work in getting reports from New York State online has been expensive in his time and money, and has exposed issues with the Attrition and PrivacyRights data sets.  New Hampshire putting their reports online allows people to do less work gathering data, and more work analyzing it.
I think it&#039;s a reasonable function of government to collect and distribute data, and one which could enable a tremendous amount of valuable research.
</description>
		<content:encoded><![CDATA[<p>PHB,<br />
I think there is a component of government action that could be very helpful.  Chris Walsh&#8217;s work in getting reports from New York State online has been expensive in his time and money, and has exposed issues with the Attrition and PrivacyRights data sets.  New Hampshire putting their reports online allows people to do less work gathering data, and more work analyzing it.<br />
I think it&#8217;s a reasonable function of government to collect and distribute data, and one which could enable a tremendous amount of valuable research.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PHB</title>
		<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/comment-page-1#comment-4154</link>
		<dc:creator>PHB</dc:creator>
		<pubDate>Tue, 13 Nov 2007 13:12:11 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2555#comment-4154</guid>
		<description>Without trying to be contrarian, I think that Adam described how the research community can improve computer security. That is not the same thing as how government can help.
More research is certainly good but I am strongly of the opinion that our Internet security problem is not a lack of tools. Instead the problem is how to put the tools to use. After three decades of PK and Fifteen years of the Web we have three cryptographic security infrastructures that are deployed and used at approaching Internet scale (hundreds of millions to billions of users). One of these is SSL, another is Chip and PIN, the other is DVD-CSS. Only two of those systems actually work. WiFi security, WPA and WEP is currently a runner up.
One observation to make is that most &#039;Internet&#039; crime isn&#039;t. Phishing is not an Internet crime, its bank fraud. Deploy strong authentication in the credit card infrastructure and we take a big bite out of phishing fraud.
The question that only government can address is why Chip and PIN is deployed in Europe but not the US?
The answer the bankers give is that the economics of the credit card industry are very different, lots of issuers, few acquirers. That makes it hard to deploy a security measure where costs fall on the acquirer but the benefit goes to the issuer. Particularly when anti-trust laws make renegotiation of settlement fees impractical.
What government can do and no other party can do is to align responsibility to act with ability to act through regulation.
That said, I do have some questions about the composition of this group. Despite the title it is clearly not a body appointed by the 44th President since we don&#039;t know who she is yet. What is the scope of the body? Is it only US nationals or is it looking to experiences in other countries. This is very important in my view because Internet crime has very different patterns in different countries across the world and many of the differences are due to the impact of regulation.
At the very least governments must become aware of the cyber-security implications of new regulations they make. The license plate story elsewhere on this blog illustrates how government actions can have unforseen but entirely forseable impact.
</description>
		<content:encoded><![CDATA[<p>Without trying to be contrarian, I think that Adam described how the research community can improve computer security. That is not the same thing as how government can help.<br />
More research is certainly good but I am strongly of the opinion that our Internet security problem is not a lack of tools. Instead the problem is how to put the tools to use. After three decades of PK and Fifteen years of the Web we have three cryptographic security infrastructures that are deployed and used at approaching Internet scale (hundreds of millions to billions of users). One of these is SSL, another is Chip and PIN, the other is DVD-CSS. Only two of those systems actually work. WiFi security, WPA and WEP is currently a runner up.<br />
One observation to make is that most &#8216;Internet&#8217; crime isn&#8217;t. Phishing is not an Internet crime, its bank fraud. Deploy strong authentication in the credit card infrastructure and we take a big bite out of phishing fraud.<br />
The question that only government can address is why Chip and PIN is deployed in Europe but not the US?<br />
The answer the bankers give is that the economics of the credit card industry are very different, lots of issuers, few acquirers. That makes it hard to deploy a security measure where costs fall on the acquirer but the benefit goes to the issuer. Particularly when anti-trust laws make renegotiation of settlement fees impractical.<br />
What government can do and no other party can do is to align responsibility to act with ability to act through regulation.<br />
That said, I do have some questions about the composition of this group. Despite the title it is clearly not a body appointed by the 44th President since we don&#8217;t know who she is yet. What is the scope of the body? Is it only US nationals or is it looking to experiences in other countries. This is very important in my view because Internet crime has very different patterns in different countries across the world and many of the differences are due to the impact of regulation.<br />
At the very least governments must become aware of the cyber-security implications of new regulations they make. The license plate story elsewhere on this blog illustrates how government actions can have unforseen but entirely forseable impact.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Felten</title>
		<link>http://emergentchaos.com/archives/2007/11/how-government-can-improve-cyber-security.html/comment-page-1#comment-4153</link>
		<dc:creator>Ed Felten</dc:creator>
		<pubDate>Mon, 12 Nov 2007 13:45:52 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2555#comment-4153</guid>
		<description>Thanks for a great suggestion, Adam.  I&#039;ll keep it in mind as the commission discusses what to recommend.
</description>
		<content:encoded><![CDATA[<p>Thanks for a great suggestion, Adam.  I&#8217;ll keep it in mind as the commission discusses what to recommend.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

