Results 1 to 10 of 10

Thread: Congress: P2P Networks Harm National Security

  1. #1
    WASHINGTON--Politicians charged on Tuesday that peer-to-peer networks can pose a "national security threat" because they enable federal employees to share sensitive or classified documents accidentally from their computers.

    At a hearing on the topic, Government Reform Committee Chairman Henry Waxman (D-Calif.) said, without offering details, that he is considering new laws aimed at addressing the problem. He said he was troubled by the possibility that foreign governments, terrorists or organized crime could gain access to documents that reveal national secrets.

    Also at the hearing, Mark Gorton, the chairman of Lime Wire, which makes the peer-to-peer software LimeWire, was assailed for allegedly harming national security through offering his product.

    The documents at risk of exposure supposedly include classified government military orders, confidential corporate-accounting documents, localized terrorist threat assessments, as well as personal information such as federal workers' credit card numbers, bank statements, tax returns and medical records, according to recent studies by the U.S. House of Representatives Committee on Oversight and Government Reform, the U.S. Patent and Trademark Office, and private researchers.

    Evidence that sensitive information is accessible through peer-to-peer networks illustrates "the importance of strengthening the laws and rules protecting personal information held by federal agencies" and other organizations, said Rep. Tom Davis (R-Va.), the committee's ranking member, who has sponsored a bill that would impose new requirements on government agencies that discover security breaches. "We need to do this quickly."

    The politicians present Tuesday generally said they believe that there are benefits to peer-to-peer technology but that it will imperil national security, intrude on personal privacy and violate copyright law, if not properly restricted. Both Waxman and Rep. Paul Hodes (D-N.H.) dubbed P2P networks ongoing national security threats.

    Congressional gripes about P2P networks are hardly new, and in the past, they have reinforced concerns raised by the Motion Picture Association of America and the Recording Industry Association of America. Four years ago, the same committee held a pair of hearings that condemned pornography sharing on P2P networks and also explored leaks of sensitive information. And throughout 2004, Congress considered multiple proposals that would have restricted--or effectively banned--many popular file-swapping networks. Waxman noted that he was not seeking to ban peer-to-peer networks this time around but rather to "achieve a balance that protects sensitive government, personal and corporate information and copyright laws."

    To be sure, the kind of information leaks that alarmed politicians at Tuesday's hearing are most likely already against the law or federal policy. It is illegal for government employees to leak certain types of classified documents without approval, either electronically or through traditional paper means.

    Mary Koelbel Engle, the associate director for advertising practices in the Federal Trade Commission's Bureau of Consumer Protection, said her agency has found in its studies of peer-to-peer network use that risks to sensitive information "stem largely from how individuals use the technology rather than being inherent in the technology itself."

    Some politicians nonetheless lashed out at the sole representative from a peer-to-peer software company at Tuesday's hearing: Lime Wire's Gorton, who is also CEO of parent company Lime Group.

    The most scathing criticism came from Rep. Jim Cooper (D-Tenn.), who launched into a lengthy monologue in which he deemed Gorton "one of the most naive chairmen and CEOs I've ever run across," and accused his company of making the "skeleton keys" that grant access to material harmful to U.S. national security.

    "I'd feel more than a shade of guilt at this point, having made the laptop a dangerous weapon against the security of the United States," Cooper said. "Mr. Gorton, you seem to lack imagination about how your product can be deliberately misused by evildoers against this country." (Cooper also, at one point, claimed that Gorton's own home computer was probably leaking sensitive documents.)

    Rep. Darrell Issa (R-Calif.) warned Gorton that Lime Wire's practices may open the company up to serious legal liability.

    "Would it surprise you if you have a string of lawsuits for inherent defect in your product if people like Charlie Mueller of Missouri finds out he's lost his IRS filings and feels he's been damaged?" Issa asked.

    Gorton repeatedly defended his company's practices and said he wasn't aware of the extent to which national security information was being accessed through his network.

    Lime Wire strives to make its product easier to understand and is working on a new version even more tailored to the "neophyte" user, Gorton said.

    The software incorporates a number of warnings intended to stave off inadvertent file sharing, he added. For instance, pop-up messages appear when users attempt to share folders, such as the all-encompassing "My Documents" folder and the root directory, which are considered likely to contain sensitive information.

    "A lot of the information that gets out there now is because people accidentally share directories that they wouldn't mean to share clearly," Gorton said. "Those warnings are not enough, at least in a handful of cases."

    That assertion drew sharp disagreement from Thomas Sydnor, an attorney-advisor in the Patent Office's copyright group. He said peer-to-peer users are being tricked into sharing files they don't intend to make public and claimed that LimeWire's warnings to that effect don't always appear as they should.

    In research for a report released in March, the Patent Office found it "stunning to see features that are incredibly easy to misuse," Sydnor said. "You can go to an interface in these programs that looks like you're doing nothing except choosing a place to store files, and you end up sharing recursively all the folders on your computer. It's very easy to make a catastrophic mistake."

    Earlier this year, the Department of Transportation experienced an incident in which an employee's daughter installed LimeWire on the home computer that her mother occasionally uses for telework--and misconfigured it in such a way that documents from the department and the National Archives were open to others using the network--including a Fox News reporter. Forensic analysis determined that some of those documents were already publicly accessible and that none of the DOT documents contained sensitive personally identifiable information about anyone other than the employee herself.

    The agency's chief information officer, Daniel Mintz, told the committee that his agency already has sufficient authority to combat "inadvertent" file sharing and that it already is required to take such activity into account in its annual information security reports to Congress.

    The key to preventing additional incidents like that one, Mintz told the politicians, is for his agency to step up oversight and "to make sure we're really pushing the policy," which requires written authorization for installation of P2P programs on government machines. That also means beefing up training for its employees and making sure that they're aware of what the limits are, he added.

    General Wesley Clark, who now serves on the board of a small company called Tiversa that makes applications designed to monitor peer-to-peer file-sharing activity, called for "some pretty hard-nosed policies by business and government contractors that prevent people from doing government work on computers that have anything to do with the peer-to-peer networks."

    "Even when people...are sophisticated with computers, they can still make a mistake, and all that material can be gone in an instant," the former Democratic presidential candidate told the committee.

    zdnet: http://news.zdnet.com/2100-1009_22-6198585.html
    C|Net: Can't believe Congress blames P2P for security problems? Neither can tech bloggers
    Neowin.Net: P2P Slammed as "New National Security Risk"
    Last edited by Hairbautt; 08-02-2007 at 01:33 AM. Reason: Updated.

  2. News (Archive)   -   #2
    4play's Avatar knob jockey
    Join Date
    Jan 2003
    Location
    London
    Age
    41
    Posts
    3,824
    why not just enforce sensible procedures like banning p2p clients on government computers. I would be amazed if installing p2p software on work computers is not already grounds for dismissal in any government job that deals with sensitive information. hell admins should be firewalling the computers so p2p software does not work anyway.

    lets just add Henry Waxman to the list of people bribed by the riaa/mpaa and anything he says should be forever treated with a pinch of salt.

  3. News (Archive)   -   #3
    Hairbautt's Avatar *haircut
    Join Date
    Jul 2004
    Location
    Florida
    Age
    20
    Posts
    7,244
    Yea, read the first of the comments
    Quote Originally Posted by rvolkman
    Why are government employees within secure facilities (or any workplace) running Limewire clients?


    We all like music...
    _________________________________________________________________________________________
    Last edited by Alien5; Jun 6th, 2006 at
    06:36 PM..

  4. News (Archive)   -   #4
    TheFoX's Avatar www.arsebook.com
    Join Date
    Jan 2007
    Posts
    1,567
    Where I work, all the computers are completely insulated from the Internet. They use dedicated ISDN lines. There are only two portals that allow traffic to flow to and from the internet. Ports are limited to POP and HTTP (no FTP or any other mechanism allowed). Each PC has been set up by the IT department. If you want any program installed, only they can do it with administrator access.

    Talk about high security.

    What does the company I work for do. They distribute foodstuff to retailers.

    If a distribution company can employ a strict discipline regarding the use of it's PCs, then you'd think the Government of the most powerful nation on Earth would go that one step further.

    It just goes to show that the US government wants confidential data to leak out, so that they can pass some more draconian rules that will allow them to control the populace to an even greater extent.

    Give or take a few more years, and the US of A will be able to add another feather to their cap. They will be able to brag that they are also the largest prison in the world.

  5. News (Archive)   -   #5
    This is retarded. They will say and do anything no matter how silly. You can't blame Limewire because retarded government employees use the software and leak documents. They need to crack down on employees and make sure only allowed software is on their pc. Do a daily check of what's installed on their pc if you have to. Anybody can abuse ANYTHING. Is that the fault of whatever they use to abuse stuff? no!!! Some kid can draw graffiti on a sidewalk. Is it the fault of the city for putting down sidewalks?

  6. News (Archive)   -   #6
    Shadowfire's Avatar catch-22 BT Rep: +19BT Rep +19BT Rep +19BT Rep +19
    Join Date
    Oct 2006
    Posts
    1,207
    What, is one of the Congressmen accidentally going to install Limewire and accidentally allow it access through his firewall to send out critical data?

    Or maybe the Congressman is downloading porn to his shared folder, which happens to be the one that contains Iraq data.

    People like this might be called stupid.

  7. News (Archive)   -   #7
    Hairbautt's Avatar *haircut
    Join Date
    Jul 2004
    Location
    Florida
    Age
    20
    Posts
    7,244
    Just added a related link from Cnet.

    http://news.com.com/8301-10784_3-975...g=2547-1_3-0-5

    _________________________________________________________________________________________
    Last edited by Alien5; Jun 6th, 2006 at
    06:36 PM..

  8. News (Archive)   -   #8
    its the beginning of the end ...
    C2D 6600+tuniq tower 120+SAPPHIRE X2600XT 256MB DDR4 PCI
    p5w deluxe wifi+WD 250maxtor300 all sat2 with16m
    team elite 5300 2x1gb+1GB=3GB
    tv lcd grundig Amira 26 HD

  9. News (Archive)   -   #9
    Poster BT Rep: +2
    Join Date
    Jun 2007
    Posts
    52
    So that's why everyone wants to get on Uk-T! That's where the government must do all their classified document torrenting!

  10. News (Archive)   -   #10
    Member
    Join Date
    Apr 2007
    Posts
    21
    no wonder nearly the entire nation considers these yahoo's incompetent.--this is a weak and baseless argument. Guess what we aren't all simple.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •