{"id":5299,"date":"2016-07-05T11:31:12","date_gmt":"2016-07-05T15:31:12","guid":{"rendered":"https:\/\/www.bu.edu\/federal\/?p=5299"},"modified":"2016-07-05T11:40:33","modified_gmt":"2016-07-05T15:40:33","slug":"cybersecurity-experts-go-to-washington","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/federal\/2016\/07\/05\/cybersecurity-experts-go-to-washington\/","title":{"rendered":"Cybersecurity Experts Go to Washington"},"content":{"rendered":"<h2>Sharon Goldberg briefs Congressional staffers on internet insecurities<\/h2>\n<p class=\"p2\"><span class=\"s1\"><a href=\"\/federal\/files\/2016\/07\/h_butoday_AOB_0065.jpg\"><img loading=\"lazy\" src=\"\/federal\/files\/2016\/07\/h_butoday_AOB_0065.jpg\" alt=\"h_butoday_AOB_0065\" width=\"525\" height=\"350\" class=\"alignleft  wp-image-5300\" \/><\/a><em>Expert panelists at a recent Capitol Hill cybersecurity briefing sponsored by BU and the Congressional Cybersecurity Caucus: FTC Office of Technology, Research, and Investigation research director Joseph Calandrino (from left), Center for Democracy &amp; Technology chief technologist Joseph Lorenzo Hall, and Sharon Goldberg, a CAS associate professor of computer science. Photos by AOB Photo.<\/em><\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Officially, it was a cybersecurity briefing on Capitol Hill hosted by Jean Morrison, Boston University provost, and the <a href=\"http:\/\/cybercaucus.langevin.house.gov\/\"><span class=\"s2\">Congressional Cybersecurity Caucus<\/span><\/a>, but it felt a little like a college freshman-level computer science seminar. Sharon Goldberg, a College of Arts &amp; Sciences associate professor of computer science, was explaining some of the deep insecurities built into the internet, and why they matter. Her students were a group of Congressional aides and interns and other Hill staffers. They had crowded into a room in the Cannon House Office Building recently on their lunch hour and were taking copious notes so they could better inform policymakers, who are scrambling these days to catch up with technical reality.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">\u201cThe internet was designed several decades ago as a network for universities, for graduate students to send each other emails, to do scientific computing\u2014not for what it\u2019s doing today,\u201d said Goldberg, one of three cybersecurity experts who addressed the briefing. It was a time, she added, \u201cwhen basically everyone on the internet believed they could all trust each other because they were all graduate students playing with computers.\u201d<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Therein lies the problem. Many of the internet\u2019s protocols and algorithms, which were created during an era that has long since vanished, \u201care baked into the architecture, and it\u2019s very, very hard to change them,\u201d Goldberg said. The result, she said, is a system vulnerable to attackers. Not only can attackers eavesdrop undetected, but they can also intercept, manipulate, and change internet traffic\u2014the flow of email messages, calls, texts, internet searches\u2014unbeknownst to users. The risk is not just to something as simple as buying a book on Amazon, said Goldberg, who is also a <a href=\"http:\/\/www.bu.edu\/hic\/\"><span class=\"s2\">Rafik B. Hariri Institute for Computing and Computational Science &amp; Engineering<\/span><\/a>\u00a0faculty fellow, but to vital global systems such as air traffic control or the running of trains.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">\u201cAnything that runs on the internet is subject to all these attacks,\u201d she said. \u201cIt\u2019s not just about interception and eavesdropping. It\u2019s about tampering, changing the traffic.\u201d<\/span><\/p>\n<p class=\"p2\"><em><span class=\"s1\"><a href=\"\/federal\/files\/2016\/07\/v_butoday_AOB_0036-Sharon-Goldberg.jpg\"><img loading=\"lazy\" src=\"\/federal\/files\/2016\/07\/v_butoday_AOB_0036-Sharon-Goldberg.jpg\" alt=\"v_butoday_AOB_0036 (Sharon Goldberg)\" width=\"300\" height=\"450\" class=\"alignright  wp-image-5303\" \/><\/a>Sharon Goldberg, a Rafik B. Hariri Institute for Computing and Computer Science &amp; Engineering faculty fellow and a national expert on cybersecurity, described some of the deep insecurities built into the internet (photo to the right).<\/span><\/em><\/p>\n<p class=\"p3\"><span class=\"s1\">For some three quarters of an hour, Goldberg and the other two speakers, Joseph Lorenzo Hall, the chief technologist for the <a href=\"https:\/\/cdt.org\/\"><span class=\"s2\">Center for Democracy &amp; Technology<\/span><\/a>, and Joseph Calandrino, research director for the Federal Trade Commission (FTC) <a href=\"https:\/\/www.ftc.gov\/about-ftc\/bureaus-offices\/bureau-consumer-protection\/office-technology-research-investigation\"><span class=\"s3\">Office of Technology Research and Investigation<\/span><\/a>, talked about security risks, and what can and cannot be done to fix them\u2014from BGP (Border Gateway Protocol), the glue that holds the internet together, to IP addresses to the Internet of things (IoT).<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">These kinds of discussions are long overdue in Washington, Hall said after the briefing. He recalled a moment, made famous on YouTube, from a Congressional debate five years ago about a bill that was ostensibly designed to thwart online piracy. After dressing down his colleagues for \u201ctrying to do surgery on the internet\u201d without bringing in a \u201cdoctor to tell us how the organs fit together,\u201d Congressman Jason Chaffetz (R-Utah) declared: \u201cWe need to bring some nerds in.\u201d<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Five years later, said Hall, Washington is bringing in the nerds. \u201cMembers of Congress and Congressional staffers recognize that they need to know their way around these concepts\u2014network security, internet routing, cryptography, and simply how software works on computing devices,\u201d he said. \u201cIncreasingly, to make decisions they have to have technical advice they can trust. There are plenty of people who can give partisan or biased technical advice that might skew decisions you make one way or the other, and government agencies and policymakers recognize the value of cutting through the hype with their own technical staff.\u201d<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Nick Leiserson, a staff member for Congressman Jim Langevin (D-R.I.), the cochair of the Congressional Cybersecurity Caucus, said there is now a recognition among policymakers and staff \u201cthat any talk of security, whether it\u2019s economic or national security, needs to have a cybersecurity component to it.\u201d With a dearth of staffers on the Hill who have technical backgrounds, Leiserson said, there is a need for experts, like Goldberg, Hall, and Calandrino, \u201cwho can translate technology in ways policymakers can understand.\u201d<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">\u201cWe\u2019re all grappling with this,\u201d said Morrison, in opening the briefing. \u201cThe internet now plays a dominant role in everyone\u2019s life. With all the capabilities it affords, it also creates a lot of opportunities for data theft and manipulation, and while there\u2019s a general awareness of the hazards of the internet, the true scope of concerns and threats is not widely appreciated.\u201d<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Hall told the audience that technologists know how to \u201cpatch up and fix\u201d some aspects of internet infrastructure and that overcoming these existing barriers involves collective action\u2014getting everyone to switch to the secure versions of these technologies. However, citing Goldberg\u2019s work on a technology called <a href=\"http:\/\/queue.acm.org\/detail.cfm?id=2668966\"><span class=\"s2\">BGPSEC<\/span><\/a>, he explained how in other areas it\u2019s unclear if switching to a secure version would cause more trouble than it would fix.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">He gave a quick primer on what he called \u201cone of the dirtiest secrets of the internet\u2014the domain system.\u201d Hall described how the domain name system (DNS) translates internet domains such as www.bu.edu to internet addresses like 128.197.26.3. He characterized the current system as insecure, meaning that unlike in web browsers, where you can trust the little lock icon to indicate that you\u2019re talking to your bank and not a cybercriminal, it\u2019s relatively easy for malicious attackers to forge DNS responses, meaning you could be talking to, say, 6.6.6.6 (a potential criminal) instead of 128.197.26.3 when you want to visit www.bu.edu.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">During the question-and-answer period, Leiserson, who has a bachelor\u2019s in computer science from Brown University, asked about what he called that \u201cgreat buzzword\u201d in Washington\u2014\u201dthe Internet of things.\u201d He wanted to know whether the same sort of infrastructure mistakes that had been baked into the internet would end up being repeated with the IoT.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">Calandrino said the FTC has been making an effort to encourage IoT product developers to consider security. \u201cWe reach out to developers\u2014we say, \u2018Here\u2019s what you need to think about,\u2019\u201d he said.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">\u201cThat\u2019s truly the $60,000 question,\u201d Hall said in response to the IoT question. \u201cThere are some really new, really sexy Band-Aids we\u2019ve put in place to patch things over.\u201d There are plenty of potential problems, he said. \u201cYou have people who have a Kickstarter idea. They get the cheapest bidder to build the board, the electronics software, they put it out in the world. They haven\u2019t thought about all the vulnerabilities.<\/span><\/p>\n<p class=\"p3\"><span class=\"s1\">\u201cBand-Aids and forethought are about as good as we can do.\u201d<\/span><\/p>\n<p class=\"p3\"><a href=\"https:\/\/www.bu.edu\/federal\/cyberbriefing\/\" title=\"Click here to find out more about this event.\" target=\"_blank\">Click here to find out more about this event<\/a><\/p>\n<p class=\"p3\"><em><span class=\"s1\">Author,\u00a0<em>Sara Rimer can be reached at\u00a0<a href=\"mailto:srimer@bu.edu\">srimer@bu.edu<\/a>.<\/em><\/span><\/em><\/p>\n<p class=\"p1\"><em><span class=\"s1\">Photographer, Allison O&#8217;Brien can be reached at <a href=\"http:\/\/www.aobphoto.com\/\" title=\"AOB Photo\" target=\"_blank\">AOB Photo<\/a>.<\/span><\/em><\/p>\n<p class=\"p1\">\n","protected":false},"excerpt":{"rendered":"<p>Sharon Goldberg briefs Congressional staffers on internet insecurities Expert panelists at a recent Capitol Hill cybersecurity briefing sponsored by BU and the Congressional Cybersecurity Caucus: FTC Office of Technology, Research, and Investigation research director Joseph Calandrino (from left), Center for Democracy &amp; Technology chief technologist Joseph Lorenzo Hall, and Sharon Goldberg, a CAS associate professor [&hellip;]<\/p>\n","protected":false},"author":7048,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[8],"tags":[256,34,108,26,88,143,224,257,63,13,93,65,66],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/5299"}],"collection":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/users\/7048"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/comments?post=5299"}],"version-history":[{"count":7,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/5299\/revisions"}],"predecessor-version":[{"id":5308,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/5299\/revisions\/5308"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/media?parent=5299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/categories?post=5299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/tags?post=5299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}