Showing posts with label CISA. Show all posts
Showing posts with label CISA. Show all posts

Saturday, May 10, 2025

They can't win if they don't cheat

 And Trump doesn't plan on losing.

From the Democracy Docket newsletter...

The Trump administration introduced a new budget proposal calling for a near $500 million cut to the Cybersecurity and Infrastructure Security Agency, the nation’s top federal entity responsible for protecting elections from hacking. 

Tuesday, February 11, 2025

Trump 2.0 - No more "free and fair" elections

Employees tasked with helping to secure elections from foreign threats and disinformation within the Cybersecurity and Infrastructure Security Agency (CISA) have been placed on administrative leave. The move puts the security and integrity of elections in the U.S. — especially at the state level, where local election officials rely on CISA resources to securely run elections — at risk.

According to multiple reports, at least 17 employees of CISA, which is housed within the U.S. Department of Homeland Security, were recently put on leave. The employees, according to the Associated Press, worked specifically within CISA’s election efforts, helping state and local election officials secure their elections from cyber attacks and handle foreign and domestic-based disinformation and influence campaigns.

  Democracy Docket


Sunday, December 13, 2020

Hmmmmm

Hackers backed by a foreign government have been monitoring internal email traffic at the US treasury department and an agency that decides internet and telecommunications policy.

[...]

There is concern within the US intelligence community that the hackers who targeted the treasury department and the commerce department’s national telecommunications and information administration used a similar tool to break into other government agencies, according to three people briefed on the matter. The people did not say which other agencies.

The hack is so serious it led to a national security council meeting at the White House on Saturday.

[...]

Staff emails at the agency were monitored by the hackers for months, sources said.

[...]

“This is a nation state,” said a different person briefed on the matter. “We just don’t know which one yet.“

[...]

The investigation is still in its early stages and involves a range of federal agencies, including the FBI.

  Guardian
Hmmmmm.

From The Washington Post.
The Russian government hackers who breached a top cybersecurity firm are behind a global espionage campaign that also compromised the Treasury and Commerce departments and other U.S. government agencies, according to people familiar with the matter.

  WaPo
The agency within the Commerce Department that was hacked was said to be the National Telecommunications and Information Administration, which is in charge of advising the president on telecommunications issues. According to Reuters, those briefed on the matter fear that other government agencies could have been hacked as well.

  Daily Beast
The government's Cybersecurity and Infrastructure Security Agency said it has been working with other agencies “regarding recently discovered activity on government networks. CISA is providing technical assistance to affected entities as they work to identify and mitigate any potential compromises.”

President Donald Trump last month fired the director of CISA, Chris Krebs, after Krebs vouched for the integrity of the presidential election and disputed Trump’s claims of widespread electoral fraud.

[...]

Last Tuesday, prominent U.S. cybersecurity firm FireEye said that foreign government hackers with “world-class capabilities” broke into its network and stole offensive tools it uses to probe the defenses of its thousands of customers. Those customers include federal, state and local governments and top global corporations.

The hackers “primarily sought information related to certain government customers,” FireEye CEO Kevin Mandia said in a statement, without naming them.

  Boston 25
...but hey, do what you want...you will anyway.

Update:


Remember when Trump said he and Putin were going to have a joint cyber program?

Thursday, November 12, 2020

Another somebody's gonna get fired

This just posted on the US government website for the Cybersecurity and Infrastructure Security Agency.
The November 3rd election was the most secure in American history.

[...]

All of the states with close results in the 2020presidential race have paper records of each vote, allowing the ability to go back and count each ballot if necessary. This is an added benefit for security and resilience. [...] This process allows for the identification and correction of any mistakes or errors. There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised.

[...]

"While we know there are many unfounded claims and opportunities for misinformation about the process of our elections, we can assure you we have the utmost confidence in the security and integrity of our elections, and you should too. When you have questions, turn to elections officials as trusted voices as they administer elections.”

  CISA.gov
(Emphasis original)
UPDATE: He's expecting it.
Top U.S. cybersecurity official Christopher Krebs, who worked on protecting the election from hackers but drew the ire of the Trump White House over efforts to debunk disinformation, has told associates he expects to be fired.

[...]

Krebs, who heads the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), did not return messages seeking comment.

[...]

Separately, Bryan Ware, assistant director for cybersecurity at CISA, confirmed to Reuters that he had handed in his resignation on Thursday.

[...]

Krebs has drawn praise from both Democrats and Republicans for his handling of the election, which generally ran smoothly despite persistent fears that foreign hackers might try to undermine the vote.

But he drew the ire of the Trump White House over a website run by CISA dubbed “Rumor Control” which debunks misinformation about the election.

[...]

White House officials have asked for content to be edited or removed which pushed back against numerous false claims about the election, including that Democrats are behind a mass election fraud scheme. CISA officials have chosen not to delete accurate information.

In particular, one person said, the White House was angry about a CISA post rejecting a conspiracy theory that falsely claims an intelligence agency supercomputer and program, purportedly named Hammer and Scorecard, could have flipped votes nationally. No such system exists, according to Krebs, election security experts and former U.S. officials.

  Reuters
Probably votes Democrat.
On Twitter, U.S. Senator Mark Warner, a Democrat, wrote: “Chris Krebs has done a great job protecting our elections. He is one of the few people in this Administration respected by everyone on both sides of the aisle."
Not after the orange devil gets finished with him.

Update 11/16: Oopsie.

The mutiny is underway.
anyway.

Update 11/17: 







Saturday, December 19, 2015

Wednesday, October 28, 2015

CISA Follow Up

Roll Call Votes

The US Senate overwhelmingly passed a controversial cybersecurity bill critics say will allow the government to collect sensitive personal data unchecked, over the objections of civil liberties groups and many of the biggest names in the tech sector.

[...]

The data in question would come from private industry, which mines everything from credit card statements to prescription drug purchase records to target advertising and tweak product lines. Indeed, much of it is detailed financial and health information the government has never had access to in any form.

[...]

Cisa would create a program at the Department of Homeland Security (DHS) through which corporations could share user data in bulk with several US government agencies. In exchange for participating, the companies would receive complete immunity from Freedom of Information Act requests and regulatory action relating to the data they share. DHS would then share the information throughout the government.

[...]

The vote on Tuesday was 74 to 21 in support of the legislation. Democratic presidential contender Bernie Sanders voted against the bill. None of the Republican presidential candidates (except Lindsey Graham, who voted in favor) were present to cast a vote, including Rand Paul, who has made privacy from surveillance a major plank of his campaign platform.

[...]

[T]he Princeton Center for Information Technology Policy, sent an open letter to the Senate, urging them not to pass the bill. The bill, they wrote, would fatally undermine the Freedom of Information Act (Foia).

[...]

Cisa would “allow ‘voluntary’ sharing of heretofore private information with the government, allowing secret and ad hoc privacy intrusions in place of meaningful consideration of the privacy concerns of all Americans,” the professors wrote.

“The Freedom of Information Act would be neutralized, while a cornucopia of federal agencies could have access to the public’s heretofore private-held information with little fear that such sharing would ever be known to those whose information was shared.”

[...]

The American Banking Association and the Telecommunications Industry Association (TIA) applauded the passage of the bill. “The legislation passed by the Senate today bolsters our cyber defenses by providing the liability protections needed to encourage the voluntary sharing of cyber threat information,” the TIA said in a statement. “We applaud the Senate for moving this important bill and urge Congressional leaders to act quickly to send this bill to the president’s desk.”

  Guardian
Government of the people by the people for the people.
Cisa was negotiated and marked up in secret.
That, too.
The bill must next pass the House of Representatives, a procedure that will likely be much quicker and smoother than the opposition it faced in the Senate from Oregon senator Ron Wyden, among others. Then it must be negotiated by the House and the Senate and then likely passed in a package with two others.
Packaged for your protection.
Robyn Greene of the New America Foundation characterized the legislation as a “do-something” bill. “The Sony hack really changed the conversation,” Greene said. “You can see that in the way the administration approached cybersecurity – they stopped saying ‘This is is something that has to get done right’ and started saying ‘This is something that has to get done now.’”
Not to mention the corporatocratic advantages (dare I say 'fascist'*?) of the bill, it's easier for the government to pass restrictive legislation than it is to fix its fractured, outdated and vulnerable IT systems.

...but hey, do what you want...you will anyway.

* "Fascism operated from a Social Darwinist view of human relations. The aim was to promote superior individuals and weed out the weak.[6] In terms of economic practice, this meant promoting the interests of successful businessmen while destroying trade unions and other organizations of the working class.[7] Fascist governments encouraged the pursuit of private profit and offered many benefits to large businesses, but they demanded in return that all economic activity should serve the national interest.[8] Historian Gaetano Salvemini argued in 1936 that fascism makes taxpayers responsible to private enterprise, because "the State pays for the blunders of private enterprise... Profit is private and individual. Loss is public and social."[9]" - Wikipedia.org: Economics of Fascism

UPDATE: 12/19/15 - CISA passed handily.

Tuesday, October 27, 2015

CISA Update







...but hey, do what you want...you will anyway.

UPDATE: 12/19/15 - CISA passed handily.

Surprise! Senate Vote Today

Because your government does not have enough control over you:
The Senate Intelligence Committee advanced a terrible cybersecurity bill called the Cybersecurity Information Sharing Act of 2015 (CISA) to the Senate floor last week. The new chair (and huge fan of transparency) Senator Richard Burr may have set a record as he kept the bill secret until Tuesday night.

[...]

This fatally flawed bill must be stopped. It's not a cybersecurity, but a surveillance bill.

[...]

CISA marks the fifth time in as many years that Congress has tried to pass "cybersecurity" legislation.

[...]

Last year, President Obama signed Executive Order 13636 (EO 13636) directing the Department of Homeland Security (DHS) to expand current information sharing programs. In February, he signed another Executive Order encouraging regional cybersecurity information sharing and creating yet another Cyber Threat Center.

[...]

Aside from its redundancy, the Senate Intelligence bill grants two new authorities to companies. First, the bill authorizes companies to launch countermeasures (now called "defensive measures" in the bill) for a "cybersecurity purpose" against a "cybersecurity threat." "Cybersecurity purpose" is so broadly defined that it means almost anything related to protecting (including physically protecting) an information system, which can be a computer or software. The same goes for a "cybersecurity threat," which includes anything that "may result" in an unauthorized effort to impact the availability of the information system.

[...]

Second, the bill adds a new authority for companies to monitor information systems to protect an entity's hardware or software. Here again, the broad definitions could be used in conjunction with the monitoring clause to spy on users engaged in potentially innocuous activity. Once collected, companies can then share the information, which is also called “cyber threat indicators,” freely with government agencies like the NSA.

[...]

Its new role in the bill mandates DHS send information to agencies—like the NSA—"in real-time." The bill also allows companies to bypass DHS and share the information immediately with other agencies, like the intelligence agencies, which ensures that DHS's current privacy protections won’t be applied to the information.

[...]

Once the information is sent to any government agency (including local law enforcement), it can use the information for reasons other than for cybersecurity purposes.

  EFF
They wouldn't do that, would they?

I suspect this is one of those times when they need to make a law to cover something they're already doing. And I don't understand why they're so secretive about it. The majority of US citizens would surely scrap the constitution in order to give law enforcement agencies any powers they say they need to catch terrorists AND criminals. Well, certain KINDS of criminals.
The bill also retains near-blanket immunity for companies to monitor information systems and to share the information as long as it's conducted according to the act. Again, "cybersecurity purpose" rears its overly broad head since a wide range of actions conducted for a cybersecurity purpose are allowed by the bill. [...] It remains to be seen why such immunity is needed when just a few months ago, the FTC and DOJ noted they would not prosecute companies for sharing such information.
And with TPP, corporations would essentially be the supreme law.  All they need then is to have their own armies. Hmmm....come to think of it, during the Occupy protests, I do believe there were army-geared police standing guard in front of a bank or three.

Mission accomplished.

...but hey, do what you want...you will anyway.

 UPDATE  6:00pm:

UPDATE: 12/19/15 - CISA passed the House handily.