No Cyber Policy, Doctrine, Protection, Result of Senate Hearing

President Trump signed another executive order today. This one is on cyber security and protecting infrastructure. Read it here.

Image result for trump signs executive order BusinessInsider

No one wants to participate in the hard debate regarding cyber, where it is noted to be the highest threat for the homeland. At least the Trump White House is taking note, yet this executive order may not be enough or engage the private sector. It is gratifying however that some inside and outside experts are in fact having talks on an international basis with cyber experts. That is always a good thing.

At issue on this topic is the path forward and the estimated costs. Cyber is a battlespace where it should be noted it could cost what conventional military operations costs against adversaries and could take as long if not forever. All government infrastructure is dated, unprotected and there are no measures to correct in a priority ranking.

The other item of note, there is no legal or case law condition where the cyber attackers are prosecuted. Exactly why did Sony not sue North Korea? If there is no consequence, even ceremoniously, then expect more hacks. Of note, to sue and or sanction North Korea, China would have to be included, as the internet connectivity to North Korea is provided by China and further, China trained the hackers in North Korea….sheesh right?

Politico reports: The directive is Trump’s first major action on cyber policy and sets the stage for the administration’s efforts to secure porous federal networks that have been repeatedly infiltrated by digital pranksters, cyber thieves and government-backed hackers from China and Russia.

“The trend is going in the wrong direction in cyberspace, and it’s time to stop that trend and reverse it on behalf of the American people,” White House Homeland Security Adviser Tom Bossert told reporters during a Thursday afternoon briefing.

Cyber specialists say the order breaks little new ground but is vastly improved over early drafts, which omitted input from key government policy specialists. The final version, cyber watchers say, essentially reaffirms the gradually emerging cyber policy path of the past two administrations.

As part of the executive order’s IT upgrade initiative, administration officials will study the feasibility of transitioning to shared IT services and networks across the government. An estimated 80 percent of the $80 billion federal IT budget goes toward taking care of aging systems.

Senior Trump adviser Jared Kushner’s Office of American Innovation will play a significant role in the federal IT modernization effort, multiple people tracking the efforts have told POLITICO. Earlier this month, Trump signed an executive order creating the American Technology Council, with Kushner as director, to help coordinate that effort. More here.

*** Personally, it must be mentioned there is a problem with this operating out of the White House and certainly out of Jared Kushner’s office, he is way too tasked to be effective. Other professionals in the cyber realm agree, the matter of a ‘net’ command and operations that collaborate with the private sector should be it’s own command and separated from NSA.

There was a significant hearing today on The Hill while the FBI hearing was going on. Those on the witness panel included James Clapper, Jim Stavridis and Michael Hayden. The Senate Armed Services Committee hosted this session and it included high rate discussions including why there is no cyber doctrine, why there are no offensive measures and what the highest cyber threats are for the homeland.

Proposed Legislation on Citizen Feedback on Govt Services

So, do you think your voice regarding the federal government goes unheard? Actually it is heard and it is scored. At issue is whether any substantial corrections are made. This proposed legislation may help and it is a step at least in the right direction.

Most of us don’t bother to even voice or register complaints. Perhaps we should rethink that. Who even knew in the first place there was a tally operation on public comments and it is referred to as ‘customer service’? Hah…

Problem is there is not an agency does not have issues….okay then, let the games begin…read on.

Primer: OMB belongs to the White House:

The Office of Management and Budget (OMB) serves the President of the United States in overseeing the implementation of his vision across the Executive Branch. Specifically, OMB’s mission is to assist the President in meeting his policy, budget, management and regulatory objectives and to fulfill the agency’s statutory responsibilities.

OMB carries out its mission through five critical processes that are essential to the President’s ability to plan and implement his priorities across the Executive Branch:

  1. Budget development and execution.
  2. Management, including oversight of agency performance, human capital, Federal procurement, financial management, and information technology.
  3. Regulatory policy, including coordination and review of all significant Federal regulations by executive agencies.
  4. Legislative clearance and coordination.
  5. Executive Orders and Presidential Memoranda.

*** Image result for omb

Congress could be poised to take on the federal government’s customer service problems.

Sens. James Lankford, R-Okla., and Claire McCaskill, D-Mo., Wednesday introduced the Federal Agency Customer Experience Act, bipartisan legislation that would simplify the process agencies go through to gather public feedback about their customer service.

The bill would roll back requirements that force agencies to go through lengthy approval processes to gather voluntary feedback from citizens and customers, and further creates both legislative and executive oversight mechanisms to oversee how agencies deliver services.

“The bill also directs agencies to post the results to their websites and requires them to use the feedback they receive to improve government services,” Lankford said in a statement. “We must do more to increase federal customer service and remove unnecessary requirements that make basic services tedious and overly bureaucratic.”

The legislation mandates agency heads—or designated officials—collect voluntary feedback from customers “with respect to services of or transactions” made by the agency.

Feedback would be gathered across all channels based on both standardized questions created in tandem by the leaders of the Office of Management and Budget director and the General Services Administration, and agency-specific questions developed by senior officials. Those questions would revolve around customer satisfaction, such as the professionalism and timeliness of federal action and potentially other metrics.

Agencies would be required to submit customer service reports based on the feedback they collect to OMB and to post it on their websites. In addition, the legislation would create a centralized website that links to all agencies’ customer service reports.

“Most people think interacting with the federal government is unpleasant—but at the same time we’re making it difficult for agencies to ask the public how they can improve—it makes no sense,” McCaskill said. “This law will allow the federal government to better identify specific customer service issues and start to implement changes to make the government work better for the American people.”

Congress, too, would get regular updates on how agencies perform with regards to customer service.

The bill would require the U.S. comptroller general to deliver scorecard reports “assessing the quality of services provided to the public” of agencies to the Senate.

Fixing the government’s customer services woes—the government routinely ranks below industry—could unite Republicans and Democrats in much the same way the government’s IT issues have. The Obama administration elevated customer service as a major issue, yet agency progress was minimal.

Max Stier, CEO of the government-focused nonprofit Partnership for Public Service, said the Federal Agency Customer Experience Act will help agencies improve their service delivery.

“The important legislation introduced today by Sens. Lankford and McCaskill will allow agencies to continue to improve by helping them better understand the concerns of the public, continue to improve in the delivery of services and increase citizen satisfaction,” he said in a statement.

NSA Chief Testimony, Cyber Security Threats and Solutions

French presidential candidate Marcon was hacked on Friday before the Sunday voting. Per the NSA Chief, U.S. Tipped Off France on the Russia hacks. The U.S. tipped off France when it saw that Russians were carrying out cyberattacks targeting French President-elect Emmanuel Macron, NSA chief Adm. Mike Rogers told a Senate panel on Tuesday. Macron’s campaign revealed it was hacked just hours before a campaigning blackout in the country ahead of the presidential election on Sunday. Macron ended up handily defeating his rival, Putin-backed Marine Le Pen. “We had become aware of Russian activity. We had talked to our French counterparts and gave them a heads-up—‘Look, we’re watching the Russians. We’re seeing them penetrate some of your infrastructure. Here’s what we’ve seen. What can we do to try to assist?’” Rogers told the Senate Armed Services Committee.

*** Meanwhile….there is no strategy or policy position on U.S. cyber warfare. However…

Next Steps for U.S. Cybersecurity in the Trump Administration: Active Cyber Defense

The failure of the government to provide adequate protection has led many cybersecurity analysts, scholars, and policymakers to suggest that there is a need for private-sector self-help. If the government is unable or unwilling to take or threaten credible offensive actions to deter cyberattacks or to punish those who engage in them, it may be incumbent upon private-sector actors to take up an active defense. In other words, the private sector may wish to take actions that go beyond protective software, firewalls, and other passive screening methods—and instead actively deceive, identify, or retaliate against hackers to raise their costs for conducting cyberattacks. Taking into consideration U.S., foreign, and international law, the U.S. should expressly allow active defenses that annoy adversaries while allowing only certified actors to engage in attribution-level active defenses. More aggressive active defenses that could be considered counterattacks should be taken only by law enforcement or in close collaboration with them.

Key Takeaways

If the government is unable or unwilling to deter cyberattacks, it may be incumbent upon private-sector actors to take up an active defense.

Before the U.S. authorizes private hack back, it must consider not only U.S. laws, but also foreign and international laws governing cyberspace.

Congress should establish a new active cyber defense system that enables the private sector to identify and respond to hackers more effectively.

***

Heritage: Americans want their cyber data to be safe from prying eyes. They also want the government to be able to catch criminals. Can they have both?

It’s an especially pertinent question to ask at a time when concerns over Russian hacking are prevalent. Can we expose lawbreakers without also putting law-abiders at greater risk? After all, the same iPhone that makes life easier for ordinary Americans also makes life easier for criminals.

Manhattan District Attorney Cyrus Vance Jr. has described the operating system of the iPhone as “warrant-proof,” saying criminals are using the devices – encrypted by default – to their advantage. In one instance, he quoted an inmate who, ironically, called the iPhone a “gift from God.”

Divine involvement is a matter of debate, but there’s no question that when it comes to the choice of breaking the cybersecurity of criminals without also endangering the personal data of ordinary Americans, well, the devil is in the details.

This is especially true given the evolving nature of the threat. Even if we wanted to give the government access to all the metadata it wants (when, where, and who called), technology is moving away from phone calls to text messages and other non-telephony applications. Traditional metadata will be of limited use to law enforcement in pursuit of the savvy criminal of the future. Law enforcement needs to develop new strategies and investigative techniques without making us all prey.

It’s nearly impossible to assess the total monetary value for all successfully prosecuted cybercrimes in the U.S., let alone estimate the number of criminal cases that would have fallen apart without access to a smartphone’s data. The Department of Justice doesn’t publish such data. But, according to the 2014 Center for Strategic and International Studies report “Net Losses: Estimating the Global Cost of Cybercrime,” global cybercriminal activity is valued at $400 billion a year. Cybercrime damages trade, reduces competitiveness, and limits innovation and global growth.

The fundamental problem is that no one in the government is responsible for securing the internet for all of us. The Department of Homeland Security is responsible for safeguarding our nation’s critical infrastructure, yet the insecure internet presents cyberthreats to non-enterprise users affect individual security, safety and economic prosperity. Who is responsible for their security?

Some elements of the federal government are so focused on hunting down information against a few horrendous criminals that they don’t seem to realize they’re doing it at the expense of our right to privacy and online protection. We can appreciate their dedication in these noble causes, but the fact remains that the internet has become a host to more and more personal information ever since Steve Jobs introduced the first iPhone.

Since then, the smartphone has evolved to have much more control over our lives, homes and vehicles. There is no sign of less data being held in the cyberspace.

In attempting to square this cyber-circle, the government would be wise to take a cue from the medical profession, which uses the Hippocratic oath to dictate an underlying requirement to refrain from causing harm to patients.

There is no such oath for members of the Department of Justice. They simply affirm that they will faithfully execute their duties without affirming that they will do so without harming the citizenry as a whole.

DOJ lawyers focus on individual prosecutions. That is too narrow of a definition of success. It forces them to use all means they can muster to make their prosecutions successful with little or no consideration of the larger harm their efforts may cause to the population in general.

That is a problem today and will only be magnified in the coming years as technology advances and the gap between those advances and the DOJ’s understanding of them widens. Within this environment, where insecurity breed’s criminality and stopping individual high-value criminals can motivate the DOJ to undermine security, one can only wonder, who is responsible for our security?

The world has changed. A new paradigm is needed to ensure the safety and security of all American’s data predicated on applying airtight security to our data. There is no return to the past. Perhaps the Trump administration will make this need for security a priority in a manner the previous administration did not.

Trump, Peace Deal with Palestinians, Easy

So far there has been no read out if Trump asked or rather demanded that the Palestinian authority to stop paying families of terrorists.

The PA, which receives millions in funding from U.S. taxpayers, spends roughly 8 percent of its annual budget, some $300 million a year, on salaries for terrorists who are imprisoned in Israel as well as the families of terrorists who attacked the Jewish state.

Mahmood Abbas, the head of the Palestinian Authority met with President Trump at the White House. Abbas brought the following people with him:

So who are these people?

Well Usama Qawasmeh in April of last year said that the West sponsors Islamic extremism and that 9/11 was no coincidence.

Saeb Erikat was one of the negotiators of the Oslo Accords and said there will never be peace if Trump moves the embassy to Jerusalem.

Ziad Abu Amr is an author, negotiator and foreign minister in charge of economics for Gaza. By the way, he was educated at Georgetown.

Hosso Zomlot is the Palestinian ambassador to the United States and continues to broadcast Israel as an occupier while declaring a two state solution is an international responsibility.

Ahmad Assaf, in 2011 said: ‘if armed resistance can accomplish the goals of the Palestinian people, we will not hesitate even for a second.’

***

So there was a working lunch at the Trump White House.

Working lunch with discussions of economic and trade opportunities?

“I’m committed to working with Israel and the Palestinians to reach an agreement,” Trump said. “I will do whatever is necessary to facilitate the agreement.”

Acknowledging an Israeli-Palestinian accord is seen as the “toughest deal to make,” Trump told Abbas, “Perhaps we can prove them wrong” – before heading into a meeting with the Palestinian Authority president.

Abbas told Trump moments earlier, “Mr. President, with you we have hope.”

The peace process has been stalled since 2014 when former Secretary of State John Kerry’s effort to lead the sides into peace talks collapsed. Since then, there have been no serious attempts to get negotiations restarted. The Obama administration spent its last months in office attempting to preserve conditions for an eventual resumption.

“We hope this will be a new beginning,” Abbas told Palestinians at a meeting in Washington on the eve of the talks.

During remarks alongside Trump at the White House, Abbas – through a translator – stressed that his people want a Palestinian state with the capital of East Jerusalem and borders along the pre-1967 lines.

Israel rejects the 1967 lines as a possible border, saying it would impose grave security risks.

Trump stressed that there can be no lasting peace unless Palestinian leaders speak in a unified voice against “incitement … to violence and hate.”

He also was expected to press Abbas to end payments to families of Palestinians killed or held in Israeli jails, which critics decry as payments for terrorism. Republicans lawmakers have urged a halt to such payments.

While Abbas will be challenged on the payments, officials said Trump will reiterate his belief that Israeli settlement construction on land claimed by the Palestinians does not advance peace prospects.

In his Wednesday comments, Abbas also criticized ideas for a “one state” peace agreement, saying it could mean “racial discrimination” or an apartheid-like system.

In a February news conference with Israeli Prime Minister Benjamin Netanyahu, Trump broke with longtime U.S. policy by raising the one-state idea and withholding clear support for an independent Palestine, though officials quickly stressed he would support any arrangement agreed by the two sides.

Another contentious issue: Trump’s campaign promise to move the U.S. Embassy in Israel from Tel Aviv to Jerusalem. The symbolic relocation would essentially recognize Jerusalem as Israel’s capital. Abbas and other Arab leaders have said doing so would inflame already simmering tensions.

Since taking office, Trump has backed away from the pledge while saying he’s still discussing it. On Tuesday, Vice President Mike Pence said the White House was giving “serious consideration” to the idea. More here.

Rep. Steny Hoyer, Million Dollar Porker

CAGW Names Rep. Steny Hoyer April 2017 Porker of the Month  

Citizens Against Government Waste (CAGW) named House Minority Whip Steny Hoyer (D-Md.) its April 2017 Porker of the Month for his ridiculous attack on the most pro-taxpayer budget proposal in decades.

On March 16, 2017, President Donald Trump released his first budget proposal, which recommends the elimination of dozens of wasteful, duplicative, and failing federal programs that CAGW has long felt should be jettisoned.

The same day, Rep. Steny Hoyer appeared on CNBC and uncorked a hefty load of hyperbole and a number of questionable claims about the budget.  He called it “the most irresponsible budget that I’ve seen and the most unrealistic budget that I’ve seen.”  He labeled the budget a “hatchet job” with “irrational” cuts.

By rejecting the budget in such a reckless and melodramatic manner, Rep. Hoyer takes ownership of the wasteful spending he defends, including billions of dollars’ worth of federal programs that have been identified by CAGW in Prime Cuts, the Congressional Pig Book, the Government Accountability Office (GAO), the Congressional Budget Office, and many other sources as not worthy of taxpayer funding.  The following programs are a tiny fraction of those that the Trump budget consolidates or eliminates, and Rep. Hoyer harbors:

  • $3 billion for Community Development Block Grants, where “outcomes [are] difficult to measure and evaluate,” according to the Obama White House.
  • $293 million for the Economic Development Administration, which the GAO found has no effect on employment.
  • $150 million for the Essential Air Service, which subsidizes often empty flights from remote airports.
  • $16.7 million for the East-West Center, which the State Department has tried to eliminate for decades.
  • $10 million for the Denali Commission, which even former President Obama wanted to terminate.

CAGW President Tom Schatz said, “When it comes to spending the taxpayers’ money, Rep. Hoyer has never seen a government program that he wanted to terminate, even if it means squandering billions of dollars.  Defenders of wasteful spending like Rep. Hoyer will exaggerate and muddy the waters, but he cannot obscure the hard truth that hundreds of federal programs simply do not deserve to be funded by taxpayers.”

For his baseless attack on the most pro-taxpayer budget in decades, CAGW names House Minority Whip Steny Hoyer its April 2017 Porker of the Month.

****

Image result for steny hoyer HuffPo

(He is 77 years old….sheesh…go Steny go)

PBS: Trump, who made improving veterans’ care a prominent issue as he campaigned for office, was to issue the order while visiting the VA. It will create a new Office of Accountability and Whistleblower Protection within the department. The eventual head of the office will report directly to VA Secretary David Shulkin.

The office is a byproduct of a 2014 scandal in which as many as 40 veterans died while waiting months for appointments at the VA medical center in Phoenix.

The House has passed a bill to make it easier for the VA to fire, suspend or demote employees for poor performance or bad conduct, and the Senate continues to work on its version of the measure. Shulkin said Trump’s decision to create the office before Congress sends him a bill speaks to his commitment to accountability at the VA.

As President Trump signed an executive order establishing a VA Accountability Office to protect whistleblowers, back in 2014, Steny Hoyer had a disgusting position with regard to Republicans and the VA.

The House‘s No. 2 Democrat accused Republicans of exploiting the scandal that has enveloped the Veterans Affairs Department for political gain and said he is worried that civil servants could be swept up unfairly in a witch hunt.

“I don’t think there’s any doubt about it … that is essentially the tactic that Republicans are trying to employ,” Minority Whip Steny Hoyer of Maryland told reporters.

Hoyer said that while any wrong-doers within the VA must be held accountable, it’s imperative that accused employees be given due process and that innocent federal workers aren’t needlessly punished as a knee-jerk reaction.

“I don’t think that serving veterans is antithetical to making sure that employees of the federal government have the civil service protections that were adopted as long ago as the Pendleton [Civil Service Reform] Act in the 19th Century,” said Hoyer, whose district includes a large number of federal workers.

“Our civil service system is designed not to be a system where people serve at the will of those who win elections. It’s a professional civil service [that is] protected.” More here.