What Century is Lord Justice Leveson Living In?


On a day when world politics was rocked by the news that the Syrian government shut down the country's Internet in an ostensible attempt to stymie opposition groups, an English judge issued the much-anticipated findings of his eight-month inquiry into the culture, practice and ethics of the British press. The nearly 2,000-page report (a 48-page executive summary is available), spawned by an eight-year and increasingly explosive phone-hacking scandal by News International newspaper journalists, is a sprawling deep dive into the UK media landscape, press ethics and values in addition to a detailed analysis of the complex scandal itself.

The massive condensation of materials examined, interviews conducted and hearings held is a prosecuting jurist's dream and a media analyst's delight, featuring facts, analysis, history and wonderfully colorful condemnation of some of Britain's most powerful figures and institutions, primarily Rupert Murdoch's News International., which has dominated British press and politics for well over a quarter of a century.  I'll leave it to others to accurately and adequately summarize the Proustian report, except to say that Lord Justice Leveson, the judge who led the inquiry, concluded his work by recommending an intricate system of British press self-regulation back-stopped by legislation and public officials to "guard the guardians."

This prospect of further intrusion by the British government into the workings of the press is only now being digested by the press and politicians, although Conservative Party Prime Minister David Cameron immediately and summarily dismissed the report's call for statutory oversight of the press.  And by "press," Leveson does indeed mean only the traditional press, the kind that uses paper and ink.  

Any notion of regulating Internet-based journalism or publishing was roundly rejected by Leveson because, well, the Internet is not the press, in his eyes, because it is unregulated, does not operate according to ethical standards and in any event, web-based content such as blogs or tweets are barely ready by anyone and "rarely read as news or factual."  

Yes, that's what he said.

What follows are selected sections from the report where, in essence, Leveson says, unlike the Syrian government, that the Internet does not matter.  

Regarding blogs (and here Leveson even cites newspaper blogs, such as those maintained by the Guardian newspaper):
These vastly different sites are all offered to the public in the same way; they all have the same theoretical reach to the entire internet-connected population at the touch of a button (particularly when facilitated by search engines). They are also, with the regulatory exceptions set out above, entirely unregulated, though subject to civil and criminal law in appropriate jurisdictions. However, it is noteworthy that although the blogs cited here are read by very large numbers of people, it should not detract from the fact that most blogs are read by very few people. Indeed, most blogs are rarely read as news or factual, but as opinion and must be considered as such. [emphasis added]
How Twitter is not really that important a new source because so few tweets are read:
However, it is worthy of note that despite their extraordinary growth, as with most blogs, in the main few tweets or social network pages are read by very large numbers of people.
The Internet does not operate by ethical standards:
...the internet  does not claim to operate by any particular ethical standards, still less high ones. Some have called it a ‘wild west’ but I would prefer to use the term ‘ethical vacuum’. This is not to say  for one moment that everything on the internet is therefore unethical. That would be a gross  mischaracterisation of the work of very many bloggers and websites which should rightly and  fairly be characterised as valuable and professional. The point I am making is a more modest one, namely that the internet does not claim to operate by express ethical standards, so that  bloggers and others may, if they choose, act with impunity.
Because it does not operate according to ethical standards, the Internet is not really the press:
The press, on the other hand, does claim to operate by and adhere to an ethical code of  conduct. Publishers of newspapers will be (or, at least, are far more likely to be) far more  heavily resourced than most, if not all, bloggers and websites that report news (as opposed  to search engines that direct those on line to different sites). Newspapers, through whichever  medium they are delivered, purport to offer a quality product in all senses of that term.  Although in the light of the events leading to the setting up of this Inquiry and the evidence  I have heard, the public is entitled to be sceptical about the true quality of parts of that  product in certain sections of the press, the premise on which newspapers operate remains  constant: that the Code will be adhered to, that within the bounds of natural human error  printed facts whether in newsprint or online will be accurate, and that individual rights will  be respected. In contrast, the internet does not function on this basis at all. People will not  assume that what they read on the internet is trustworthy or that it carries any particular  assurance or accuracy; it need be no more than one person’s view. There is none of the notional imprimatur or kitemark which comes from being the publisher of a respected  broadsheet or, in its different style, an equally respected mass circulation tabloid.
So, in the end, Leveson is recommending government regulation (through the formation of a statutorily backed independent self-regulatory body) of only print products and, vaguely, for web-based news produced by traditional print media.  And the only entities subject to that regulation would be UK-based press outlets.

At first blush, while Leveson may have noble intentions to elevate the British press to a more sacred purveyor of only ethical news that serves the public interest, his garbled grasp of how the Internet works might only serve to weaken the very institution he seeks to strengthen.  By burdening the already beleaguered print media with the prospect of a new regulatory body, given the force of law by the government (the prospective weakening of the "free" press that would occur from this move will likely and should receive more analysis), Leveson's recommendations, if carried out, could be yet another nail in the old media's coffin, at least in the UK.

Here Comes the Cybersecurity Executive Order with Its Insane Deadlines


In a move engineered by Majority Leader Harry Reid (D-NV), the Senate shot down two days ago the prospect of comprehensive cybersecurity legislation during the lame duck Congress, ratcheting up the prospects that President Obama will make good on his threats to sign an executive order that achieves what Congress has so far failed to accomplish.  Proponents for a cybersecurity bill lost 51 to 47 and some of the smarter (and perhaps more cynical)  thinkers on the cybersecurity tussle believe that the fast post-election effort to give Congress another run at the goal line was nothing more than a hail Mary maneuver to give Obama political cover to issue the order.

Whatever the case may be, all signs point to Obama issuing that order any day now.  Amid all the political wrangling, little attention has been paid to the actual substance of the order itself.  Although little more than a dozen pages long, the order is a vast, gnarly beast that will put into motion massive activity throughout the federal government, involving virtually every agency, administrative office, military branch and, of course, hundreds of thousands of businesses, non-profit organizations, public agencies and state and local governments.

Not only is the scope of the order vast, but also the deadlines specified in the latest version of the "public" draft order are insanely ambitious for such a complex undertaking.  I've mapped out the key deadlines in the table below.

Assuming that Obama signs the order before Thanksgiving (as is widely believed), and assuming the final order resembles the current draft, the complex apparatus needed to fulfill the order's directives must swing into gear to accomplish a host of intricate things in extremely short time frames.  For example,
  • via a consultative process throughout the federal government (and relying on an existing and controversial database involving hundreds of thousands of entities), the Department of Homeland Security has to identify all critical infrastructure assets covered under the order by mid-April.  
  • The National Institute of Standards and Technology has to develop a framework for identifying and managing cyber risks across a host of diverse critical infrastructure sectors by mid-May.  
  • Also by mid-May DHS has to implement guidance on how critical infrastructure owners can voluntarily share cybersecurity information, 
  • and on and on.
Each of the deadlined tasks spelled out in the order will require fast, nimble and extraordinarily skilled bureaucratic scrambling throughout the government and heretofore unseen policy, technical and administrative process expertise by the critical infrastructure owners.  Then there's the matter of the all-important privacy-related items, which appear to have no deadline affixed to them, as of the latest public draft.

Quite a few people, it seems, will be toiling away during the holiday season..and for years afterward.

 

It’s the Back-Up Power, Stupid: Communications, Electricity and Service Restoration Following Hurricane Sandy


Hurricane Sandy, like Hurricane Katrina before it, highlights a little-examined but perennial riddle:  what comes first in restoring life to normal after a major crisis, electricity or communications?  Without electricity, there can be no form of electronic communications but without the ability to communicate, power providers are ill-equipped to restore electricity in anything but a haphazard manner.

In the wake of Sandy’s damage, both critical infrastructure providers, telecommunications and electricity, were hard hit with outages due to downed lines and damaged, flooded hardware.  But as the days wore on, a crucial distinction emerged between the two providers:  with no electricity and back-up fuel in extremely short supply, communications providers simply had no power to operate their networks, particularly their wireless networks.  Last Friday, the FCC commented on the situation, acknowledging that “replenishing fuel supplies for generators that are enabling communications networks to continue operating is a particularly critical challenge.”

This assessment echoes the conclusions of an FCC panel asked to address how well communications networks fared in the aftermath of Hurricane Katrina.  That panel found that among the chief causes of communications failure after Katrina were faulty batteries used by the telcos combined with lack of power given that utilities had been knocked out too.  The panel also found that communications networks owned and operated by utilities fared fairly well because they were designed to remain intact to aid restoration of service following a significant event. 

The importance of maintaining robust communications in a crisis situation is one of the top reasons why utilities tenaciously argue they need to maintain their own communications networks, such as private land mobile radio communications and fiber and microwave-based systems that allow system-wide communications, independent of and apart from the so-called “public carrier” networks.   Since the dawn of both industries, which occurred at roughly the same time period -- Alexander Graham Bell and Thomas Edison were both pushing wires to homes and businesses simultaneously -- utilities have been fighting with telecom providers to maintain their own communications networks while telecom providers have been arguing that this duplication of infrastructure is a waste of society’s resources and ignores the highly specialized and valuable expertise that telecom companies bring to the table. 

And both industries are correct.  Utilities are rarely on the cutting-edge of technology innovation, a handicap that is becoming clear, for example, in the cybersecurity arena, where communications providers must develop razor sharp protection schemes or else lose out to smarter, more technologically savvy rivals, while utilities have no economic incentive – and indeed are often discouraged by regulators – to spend more money or time on maintaining digital security.  And yet, when it comes to crisis situations, it all comes down to back-up power.

To keep their communications networks running, most utilities use interim battery and long-term generator back-up which is usually indefinite – practically unlimited storage of diesel, gas or other fuel sources is one of the perks of being a power company.   No other industry, including telecom providers, can keep back-up power going for more than a day or two.  A study I conducted in 2010 found that one of the top reasons utilities are reluctant to rely on communications providers is "insufficient levels of power back-up."  Another top reason that utilities are reluctant to rely on phone company networks for their mission critical functions, according to the study’s findings, are "concerns over disaster preparedness" on the part of telecom providers.

While telecom companies have made great strides since Katrina in ensuring better power back-up during crisis situations, Hurricane Sandy answers, for now, the riddle of what comes first in restoring life to normal, electricity or communications.  The answer, of course, is that they both come first.

(With full disclosure, I spent three-and-a-half years studying what most people, prior to the advent of the “smart grid,” used to consider the arcane niche of “utility communications” on behalf of the utility industry.  But I also spent years many more years before that conducting analyses on behalf of a host of traditional communications providers so I’d like to think I’m coming at this fully informed by the cultures and arguments of both industries.)

Image source:  Power outage screen capture from Google Maps.

Lieberman Aide: Cybersecurity Executive Order Will Move Forward No Matter What


A top aide to cybersecurity legislation proponent Senator Joseph Lieberman (I-CT) said today that the administration will move forward on a cybersecurity executive order no matter what happens in the presidential election next Tuesday.  Speaking at a cybersecurity summit hosted by the Washington Post, Jeff Ratner, Counsel and Senior Advisor for Cybersecurity, Senate Homeland Security & Government Affairs Committee said "regardless of what happens on Tuesday, the executive order will move forward" because the Obama administration does not view cybersecurity as a political issue as much as it does a vital issue of national security.

What then will the Congress do given that Senator Majority Leader Harry Reid (D-NV) has announced his intention to bring up a cybersecurity bill during the upcoming lame duck Congressional session?  Ratner indicated that any cybersecurity bill that follows the executive order will likely fill in the gaps that the executive order cannot legally address, such as offering liability protection to critical infrastructure industries covered by the bill.  This protection offers affected companies some insulation from civil or criminal prosecution for activities carried out under the bill (such as information sharing) if conducted in good faith.  (A lot of debate has cropped up regarding what constitutes good faith under earlier legislative language and how effective the liability protection provisions are).

"Much of what we did in our new bill in Title I can be done via executive order," Ratner said.  "What can’t be done is the incentives.  You can’t offer [via executive order] incentives like liability protections, which the Congress can."

Kicking off the event, Department of Homeland Security Secretary (DHS) Janet Napolitano likened the effect of a cyberattack to Frankenstorm Sandy, and likened DHS to FEMA, the Federal Emergency Management Agency.  "We look and act like a cyber-FEMA," she said.

Whether DHS should have that kind of power, as is likely under the Executive Order and as was specified in cybersecurity legislation, has been subject to heated debate.  "People don't think DHS should be given more authority," Jim Lewis, Senior Fellow and Program Director at CSIS said.  But then the problem becomes:  which arm of the federal government should be given authority?

One other logical government agency that could be assigned cybersecurity responsibility is the National Security Agency (NSA). "When you say to people that you want to put NSA in charge of public information, it doesn’t bring screams of joy," Lewis joked.  How about the FBI, the other government arm arguably qualified to do the job?  Affected industries are bound to ask "am I going to want the FBI crawling over our networks?" Lewis said.  By default, for now, the DHS seems the best, if not optimal, government agency to take on the task.

Hurricane Sandy’s Crucial Technology Chain


Hurricane Sandy, with its wide swath of destruction and long duration, served as a case study of how important technology, particularly communications technology, has become during a crisis situation.  Most of us in Sandy’s path spent at least some time glued to our big and small screens over the past few days, but it’s interesting to take a step back and look at the very complex chain of technology that made surviving the storm easier. 

The following are just some of the crucial links in the technology chain surrounding the big storm.
  • Weather Satellites:  Most of the intelligence and analysis that gave us all uncannily accurate and advance warning of the hybrid conditions that would foster this superstorm came from satellites that fly pole-to-pole, taking snapshots and measurements of the entire earth’s conditions and producing data that make weather prediction a far more exact science than in decades past.    These satellites, however, are aging and bad planning by the Department of Commerce’s National Oceanic and Atmosphere Agency threatens to soon leave the U.S. with a potential three-year gap before replacement satellite capability can resume the data gathering capabilities.  Launching one of these birds takes a lot of advanced work and money (“it’s not simply like replacing a burned-out light bulb,” American Meteorological Society President-Elect J. Marshall Shepard said) and so far no good solution to the impending weather satellite intelligence drought has emerged. 
  • A Smarter Energy Grid:  The most fundamental technology that maintains acceptable quality of life during and after a weather emergency is electric power.  Although millions of homes are still without power in the Northeast, the situation could have been a lot worse, particularly in the DC and mid-Atlantic regions served by Pepco, which left hundreds of thousands of homes sweltering in triple-digit misery after the big derecho storm in July.  This go-around Pepco fared far better in maintaining and restoring power, with comparatively few homes in its service territory suffering lengthy outages.  Part of Pepco’s turn-around is no doubt a result of political heat placed on the utility by powerful people, including Democratic Maryland Governor Martin O’Malley, one of the party’s rising stars.  But part of the utility’s improved performance might be traced back to its ramped-up deployment of smart grid technology, two key benefits of which are improved resiliency and reduced power restoration time.  “Smarter” grid improvements by hard-hit New York area utilities and pre-emptive shut downs by ConEd may also be making the electricity down times shorter even though that region is still suffering widespread outages.
  • Smart Phones:  Not only were smart phones the top choice for connecting to the Internet during power outages, but they also served as Internet hot spots for some users.  And crucial services, including utilities and emergency responders, devised mobile apps for communications or urged affected citizens to stay in touch via handheld devices.    Flooding and power outages disrupted mobile  and other forms of communications throughout the storm-hit areas, but thousands of tweets and Facebook posts attest to the popularity of smart phones as a critical means of staying connected during the deluge.
  • Twitter:  Without a doubt, Twitter was a prime, if not the prime, news source for timely information during Sandy, serving as a real-time newswire that proved more informative than most newspapers and news channels.  In fact, the most useful information on most traditional newspaper websites came from curated tweets, with the “real” news articles often dated and inaccurate by the time they were posted.  Government officials and politicians (including heavily damaged Newark’s mayor Cory Booker) used Twitter as a primary mode of communications throughout the crisis.
  • Big Data:  Big data played a very useful role during the storm, helping to map everything from transportation problems to school closing to power outages.  The granddaddy of big data analytics, Google, created a SuperStorm Sandy mapping tool that detailed everything from power outages to emergency shelter locations to evacuation routes to live webcams.
  • Emergency Response Communications:  Although it’s too soon to say how well the first-responder community fared across the multiple states where Sandy hit, the storm does serve as an object lesson regarding why the upcoming First Responder Network, authorized under the Middle Class Tax Relief and Job Creation Act of 2012, is needed .  FirstNet will be a nationwide interoperable broadband communications network that allow emergency responders, including police, firefighters and emergency medical personnel, to have access to a common network dedicated to public safety purposes.
Update:  Right after posting this piece, I read Josh Smith's piece about how both TV broadcasters and wireless carriers are making their arguments for more spectrum on the basis of the vital information roles they played during Sandy.  I realize, dumbfounded, I left out television and radio out altogether in the crucial technology chain.  I suppose that most people do indeed watch broadcast stations during storms these days, but as Mathew Ingram noted, much of the TV reports "amounted to reading reports from Twitter, and interviewing their own news reporters standing hip-deep in the water in places like Atlantic City or Battery Park."  Radio is, of course, different and important.  But the fact that I genuinely "forgot" about TV and radio speaks volumes, whether it's about my skills as a media analyst or about the fading away of traditional broadcasting as an important communications tool in the U.S., I'm not sure.

Panetta Issues Cybersecurity Clarion Call...But Why?


The big cybersecurity news of the week is Defense Secretary Leon Panetta's high-profile clarion call for the Congress to pass a cybersecurity bill because the U.S.otherwise faces a possible "cyber-Pearl Harbor."  During his speech at an award dinner hosted by a group of security-focused business executives, Panetta also hinted that the government's interest isn't merely in defending against critical cyber threats but could extend to something more proactive.  "If we detect an imminent threat of attack that will cause significant physical destruction in the United States or kill American citizens, we need to have the option to take action against those who would attack us, to defend this nation when directed by the president," Panetta said. 

The speech is notable for three things. First, it's the most comprehensive statement by the Defense Secretary on the issue.  Secondly, it's clearly timed to either push the Congress into immediate action on passing a cybersecurity bill during the lame duck Congress or provide the President with enough rhetorical cover if he does issue an executive order on cybersecurity.  Finally, although the spin by administration flacks was that Panetta was disclosing new previously classified threats in his speech, the examples he offered -- DDoS attacks on U.S. financial institutions and the Shamoon malware that plagued Aramco and RasGas late this summer -- are all old news in cybersecurity terms, as Wired's Noah Schachtman points out. 

But why amp up the rhetoric regarding threats that are, by now, extensively known?  And for that matter, why is the Administration turning up the heat on the issue in general?  There is no question that cyberthreats are the 21st century version of nuclear warfare and should be much feared.  But, Republicans and business lobbies oppose anything beyond simple information sharing, and the relatively arcane issue of cybersecurity won't interest or sway many voters, so the Obama Administration stands to gain very little politically by continuing to push the issue. 

The clues to the puzzle of why Obama is pressing cybersecurity so hard are shrouded by the nature of the subject matter itself.  If there were a new threat on the horizon that could derail trains or "contaminate the water supply in major cities, or shut down the power grid across large parts of the country," as Panetta said in his speech, only a handful of people are allowed to know that, just as only a handful of people are allowed to know the launch codes for nuclear weapons. Panetta isn't going to trot out the latest intelligence on a potentially catastrophic cyber weapon during a black tie dinner and we are likely never going to hear what's really going on, or at least not for years.

It's also possible that the Administration plans to ramp up its own military capabilities in the cyber realm and the strong language used by Panetta (and others) helps to provide cover for stepped-up military action.  The U.S., after all, is the creator of the most potent cyber weapon the world has known so far (Stuxnet) and the Administration could be beefing up its military muscles not necessarily to defend against threats but to take the offense against enemies.

Whatever the case may be, the Administration is getting more serious every day about cybersecurity.  And we may never know why.

Shamoon image via SecureList

Rogers: White House “Irresponsible” for Failing to Consult on Cyber Executive Order


House Intelligence Committee Chairman Mike Rogers (R-MI) said today “it’s irresponsible” that the Obama administration failed to consult with the committee while drafting the impending executive order on cybersecurity.  Speaking at a U.S. Chamber of Commerce Cybersecurity Summit, Rogers said “we have been consulted as much as you have been consulted, which is a huge problem. “

“I don’t get it. I don’t understand it. I think it’s irresponsible.  We’re equally as frustrated as you are.” Rogers told the mostly pro-business audience.  The U.S. Chamber of Commerce opposes the President’s cybersecurity order, which mirrors to a large degree Senate cybersecurity legislation that failed to pass in August.  The Chamber also opposed that Democractic-backed bill, arguing that it creates an unnecessary regulatory structure.

Rogers said that the White House has also failed to seek private sector input when drafting the order.  “It’s just odd you would do it this way.  Why you wouldn’t want input from the outside is beyond me and that tells me what kind of product you’re going to get too.”

Cyber security legislation, along the lines of the Cyber Intelligence Sharing and Protection Act (CISPA), still stands a chance of passage during the upcoming lame duck session of Congress, Rogers said.  Rogers was a co-sponsor and proponent of that legislation, which established a voluntary cyber threat information sharing framework.  

Boosting the bill’s chance are recent classified briefings some members of Congress have received on “what appears to be a new level of threat from an unusual source that has some very real consequences,” Rogers said.  When pressed on the nature of this new threat, Rogers was vague – “I look really bad in orange,” he quipped.  But he seemed to indicate that perhaps a new nation-state has emerged as a cyber enemy.  “Our concern is nation-states that are gaining capabilities,” was the closest he came to an explanation of the new threat.

Twitter Delicious Facebook Digg Stumbleupon Favorites More