Showing posts with label system. Show all posts
Showing posts with label system. Show all posts

Tuesday, June 25, 2013

N.S.A. Leak Puts Focus on System Administrators

As the N.S.A., some companies and the city of San Francisco have learned, information technology administrators, who are vital to keeping the system running and often have access to everything, are in the perfect position if they want to leak sensitive information or blackmail higher-level officials.

“The difficulty comes in an environment where computer networks need to work all the time,” said Christopher P. Simkins, a former Justice Department lawyer whose firm advises companies, including military contractors, on insider threats.

The director of the N.S.A., Gen. Keith B. Alexander, acknowledged the problem in a television interview on Sunday and said his agency would institute “a two-man rule” that would limit the ability of each of its 1,000 system administrators to gain unfettered access to the entire system. The rule, which would require a second check on each attempt to access sensitive information, is already in place in some intelligence agencies. It is a concept borrowed from the field of cryptography, where, in effect, two sets of keys are required to unlock a safe.

From government agencies to corporate America, there is a renewed emphasis on thwarting the rogue I.T. employee. Such in-house breaches are relatively rare, but the N.S.A. leaks have prompted assessments of the best precautions businesses and government can take, from added checks and balances to increased scrutiny during hiring.

“The scariest threat is the systems administrator,” said Eric Chiu, president of Hytrust, a computer security company. “The system administrator has godlike access to systems they manage.”

Asked Sunday about General Alexander’s two-man rule, Dale W. Meyerrose, a former chief information officer for the director of national intelligence, said, “I think what he’s doing is reasonable.”

“There are all kinds of things in life that have two-man rules,” added Mr. Meyerrose, who now runs a business consulting firm. “We’ve had a two-man rule ever since we had nuclear weapons. And when somebody repairs an airplane, an engineer has to check it.”

John R. Schindler, a former N.S.A. counterintelligence officer who now teaches at the Naval War College, agreed that the “buddy system” would help. “But I just don’t see it as a particularly good long-term solution,” he said.

“Wouldn’t it be easier to scrub all your I.T.’s for security issues,” he asked, “and see if there is another Snowden?”

The two-man rule “has existed in other areas of the intelligence community for certain exceptionally sensitive programs where high risk was involved,” he said, “but it’s not a standard procedure.”

Mr. Meyerrose and Mr. Schindler both said that software monitoring systems can also help, though they can be evaded by a knowledgeable systems administrator. The biggest issue for government and industry, they said, is to vet the I.T. candidates more carefully and to watch for any signs of disillusionment after they are hired.

“It’s really a personal reliability issue,” Mr. Meyerrose said.

Insiders of all types going rogue have become a problem for the government and industry over the last decade. One of the most prominent is Pfc. Bradley Manning, who downloaded a vast archive of American military and diplomatic materials from his post in Iraq and gave it to WikiLeaks. But there have been others, including scientists and software developers who stole secrets from American companies where they worked and provided them to China.

Now the spotlight is on the system administrators, who are often the technology workers with the most intimate knowledge of what is moving through their employers’ computer networks.

Monday, May 6, 2013

Letters: A Simpler Bank System

The Rope Wrangler, Ideas Unfurling Striking a Pose Above the Clouds A co-creator of “Game of Thrones” on Caesar, songs about killers and compost cookies.

Stand Up, Cast Off, Reel In Leonhardt: The Idled Young Americans New Faces Coming Sharply Into Focus Malaysian voters have a historic opportunity to throw out the long-ruling National Front.

Wednesday, February 27, 2013

Media Decoder Blog: Online Piracy Alert System to Begin This Week

The Copyright Alert System, a program of escalating warnings and prods against people suspected of online copyright infringement, is finally going into effect this week, more than a year and a half after the plan was announced as part of an agreement between the entertainment industry and five major Internet service providers.

The Center for Copyright Information, the organization created to administer the system, announced on Monday that the Internet providers would begin putting it in place “over the course of the next several days,” though it gave no specifics. The Internet companies are AT&T, Cablevision, Comcast, Verizon and Time Warner Cable.

In the alert system, media companies monitor online traffic through a third party and can complain to Internet providers if a file is downloaded illegally. The suspected violator is then given the first of six warnings, some of which carry “educational” messages and must be acknowledged. After the fifth and sixth warnings, the customer’s Internet speed can be slowed to a crawl.

The Center for Copyright Information says it will not ask for repeat offenders’ Internet access to be blocked, but most service providers have the right to do that if a customer violates its terms of service. The findings can be contested for a $35 fee, to be refunded if an appeal is successful.

The introduction of the alert system has been notably slow. Nearly a year passed before the group had a leader in place, and its own prediction failed when it said in October that the system would be coming in two months. Part of the reason for that might be the relationships between media companies and Internet service providers, which in the past have often been adversarial over issues of piracy and control.

So-called graduated response programs like the Copyright Alert System have been tried in other countries, with mixed results. France’s Hadopi law, passed in 2009, set up a system of three “strikes,” culminating in a fine. More than a million warnings have been issued through that plan, but a recent government report said that its effects were “hard to evaluate precisely.”

Sunday, October 14, 2012

Court won't hear challenge to Iowa judicial system

WASHINGTON (AP) - The Supreme Court won't hear an appeal challenging the makeup of an Iowa commission that nominates the state's Supreme Court and Court of Appeals members.