<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Business-Technology Weave &#187; security defeats</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/business-technology/tag/security-defeats/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/business-technology</link>
	<description>Closing divides, directing purpose, and achieving results.</description>
	<lastBuildDate>Mon, 17 Jun 2013 19:25:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Pre-Infected Components and Software Entering the U.S.?</title>
		<link>http://itknowledgeexchange.techtarget.com/business-technology/pre-infected-components-and-software-entering-the-us/</link>
		<comments>http://itknowledgeexchange.techtarget.com/business-technology/pre-infected-components-and-software-entering-the-us/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 18:32:59 +0000</pubDate>
		<dc:creator>David Scott</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[computer inspection]]></category>
		<category><![CDATA[computer survey]]></category>
		<category><![CDATA[computer virus]]></category>
		<category><![CDATA[intellectual property]]></category>
		<category><![CDATA[keystroke logging]]></category>
		<category><![CDATA[keystroke monitoring]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pre-infected components]]></category>
		<category><![CDATA[security defeats]]></category>
		<category><![CDATA[software import]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/business-technology/pre-infected-components-and-software-entering-the-us/</guid>
		<description><![CDATA[  According to a top Homeland Security official, testifying before a hearing of the House Oversight and Government Reform Committee, computer software and hardware is being imported to the United States pre-loaded with security-defeats and spyware.   Greg Schaffer is Acting Deputy Undersecretary for National Protection and Programs at the Department of Homeland Security (at [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">According to a top Homeland Security official, testifying before a hearing of the House Oversight and Government Reform Committee, computer software and hardware is being imported to the United States pre-loaded with security-defeats and spyware.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri"><span style="font-size: small">Greg Schaffer is Acting Deputy Undersecretary for National Protection and Programs at the Department of Homeland Security (at least he’s not the <em>temporary</em> acting deputy under… there are those too).<span>  </span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Schaffer made a disturbing statement in response to a query by Rep. Jason Chaffetz, R-Utah, who first took care to state “the issue of software infrastructure (and) hardware built overseas with items embedded in them already by the time they get to the United States &#8230; poses, obviously, security and intellectual property risks.&#8221;</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Rep. Chaffetz then asked, “A)<span>  </span>Is this happening, Mr. Schaffer?<span>  </span>And, B)<span>  </span>What are we going to do to fight back against this?”</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&amp;quot"><span style="font-size: small">After a moment’s obfuscation on the part of Schaffer, the representative sharpened his query, “Are you aware of <em><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&amp;quot">any component software (or) hardware</span></em> coming to the United States of America that already have security risks embedded into those components?&#8221;</span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Schaffer:<span>  </span>&#8220;I am aware that there have been instances where that has happened.&#8221;</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri">The panel is considering a government proposal to tighten controls on imported computer equipment for use by critical government and communications infrastructure.<strong>*</strong><span>  </span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">It would seem to me that that area <em>would</em> <em>already</em> have the highest possible standards.<span>  </span>How many times have we stated here that protections must <em>lead</em> threats, not lag, and that a proactive, provocative security awareness is necessary?</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">The hearing didn’t tease out whether imported equipment included consumer-grade technical components and software like retail media, laptops, desktops, consoles, etc.<span>  </span>However, if it’s determined that there’s a necessity to survey those imports, watch for consumer-grade items to jump in price, as cost of inspection and survey gets added to the bill.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri"><strong>*</strong> Meantime, the government isn’t doing everything possible to inspect and screen their own components?<span>  </span>In the age of botnets, key-logging software, password discovery mechanisms,  encryption-busting and other software that defeats and disables existing security programs, there’s no excuse.<span>  </span>The missing existence of a progressive, matching, security posture and aggressive monitoring and survey/scrub for malfeasance is unaffordable. </span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Further, when an aggressive program <span style="text-decoration: underline">is</span> in place, that program is affordable because there is no cold-start mount in the face of extreme security perils:<span>  </span>It’s kinda like riding a bike uphill; you get a good start on the stretch, and are then able to pedal into the hill… eventually, you get back on level ground and your effort eases – but you don’t relax &#8211; you’re readying for the next hill.<span>  </span>However, if you <em>start</em> on the hill, it’s tough to get going.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">What has the government been doing if it is just now acknowledging import of infected components?<span>  </span>And… further, it is just <em>now</em> considering more stringent controls?<span>  </span>It’s past time to pedal faster.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">For your environment:<span>  </span>True security demands an aggressive posture.<span>  </span>Be certain to have the right mind-set in your organization.<span>  </span>Review the security-themed posts here as necessary.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><em><span style="text-decoration: underline"><span style="font-size: small"><span style="font-family: Calibri">Keep pedaling.</span></span></span></em></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><em></em></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"> </p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Calibri"><strong>On this day</strong>:<span>  </span>July 11<sup>th</sup>, 1798 Congress creates the Marine Corps.</span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/business-technology/pre-infected-components-and-software-entering-the-us/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
