SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> No Category

Cybersecurity czar gets tough on responsibility

Cybersecurity czar gets tough on responsibility

By:  Dan Verton  On: 31 Jul 2002 For: Computerworld Creator

President Bush's chief cybersecurity adviser yesterday expanded the administration's concept of corporate responsibility, warning the IT industry that it is no longer acceptable to sell glitch-riddled software, and urged users to stop buying software that they know isn't secure.

President Bush's chief cybersecurity adviser yesterday expanded the administration's concept of corporate responsibility, warning the IT industry that it is no longer acceptable to sell glitch-riddled software, and urged users to stop buying software that they know isn't secure.

"Every day in this country there are companies suffering from damages and losses" that are the result of poorly engineered software, said Richard Clarke, chairman of the President's Critical Infrastructure Protection Board. "The quality control obviously isn't there," he said, speaking at the annual Black Hat computer security conference.

Clarke's comments were met with thunderous applause from a crowd of more than 1,500 hackers and IT security experts attending this year's convention, the largest in its six-year history. As the country reels from a series of corporate corruption cases, Clarke called for the beginning of a new dialogue in the IT sector focused on corporate responsibility and transparency with respect to IT security.

Problems with software quality and security go beyond the failure of systems administrators to routinely update their systems with new patches, Clarke said. The patches themselves often have glitches that cause "unforeseen consequences" for companies when they install them, he said. As a result, many companies fall behind in patch deployment because they must first test the patches to see what additional problems they might cause.

"Rather than reject Bill Gates' statement that he's going to make security job No. 1, I welcome it," said Clarke. "And I'm going to hold him to it," he said, adding that other major software vendors should step forward with similar pledges.

Harris Miller, president of the Information Technology Association of America in Arlington, Va., said IT vendors have been moving aggressively on "baking in" rather than "painting on" security for a long time. However, "we are never going to have perfect software, any more than we have perfect buildings or perfect cars or perfect airplanes or any perfect products designed and built by humans," Miller said. "What is necessary is for consumers to understand that upgrades and patches will continue, just as cars get recalled to fix problems in the original vehicle."

But Clarke aimed his message at both sides of the supply and demand equation, particularly in the wireless access market. "Why is it that companies have sold [wireless] products that they know are not secure?" he said. "And why is it that companies have bought them? We all ought to shut them off until the technology gets better."

Although Clarke blamed the government to a certain extent for allowing security awareness to flounder, he also blamed telecommunications companies, Internet service providers and cable companies for offering broadband connections with little or no mention of the inherent security vulnerabilities in such connections.


Sign up for our Newsletters












Print |  Views: 363   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Dan Verton Dan Verton is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Canadian, American firms don't see employees as huge security threat
Canadian, American firms don't see employees as huge security threat Despite the media hype over internal security breaches, it seems Canadian as well as American firms trust their employees
Oracle no longer a bastion of security
Oracle no longer a bastion of securityGartner Inc. has warned that Oracle Corp. databases no longer deserve their reputation for security and advised systems administrators to do more to protect their systems.
Federal Government Secure Channel boondoggle finally being made visible
an article by kathryn may of the ottawa citizen exposes the "secure channel" boondoggle. this is the same project that was mentioned in the
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 
Dan Swanson: Security leaders
dan’s security resource educational column (#027) 

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.