<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: What would you ask the Department of Homeland Security Secretary?</title>
	<atom:link href="http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention.  The views expressed on this blog do not reflect the views of my employer or anyone other than myself.</description>
	<lastBuildDate>Thu, 02 Feb 2012 21:45:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Martin</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3757</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 11 Nov 2008 15:14:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3757</guid>
		<description>Here are some more responses this morning from Twitter.

rybolov @mckeay Just ask about information sharing--how do security professionals get more than just the friendly face of US-CERT?
rybolov @mckeay infosharing is the important thing.  DHS has many enemies in teh blagosphere, how can DHS make friends with them?

amrittsering @mckeay Ask him to expose any aspect of the $17b cyber security initiative
amrittsering @mckeay Ask him about the backdoor wiretapping into several major telecom carriers, and then ask him about the constitution
amrittsering @mckeay Ask if there is a conflict of interest for folks like Karen Evans to mandate the use of specific security software (cont)
amrittsering @mckeay made by companies she has discussed joining the board of (rumors, only rumors)
amrittsering @mckeay Ask if it is in the best interest of the DoD to make public which security software they do use
amrittsering @mckeay You can throw him some softballs so he will let you ask more - like what did you learn from Cyber Storm II?
amrittsering @mckeay Ask what changes have been implemented to deal with &quot;Katrina II - the reckoning&quot; especially in terms of 1st response &amp; cross org com
amrittsering @mckeay 1 more - when and how will private co&#039;s have the opportunity to tell DHS and CNCI, generally, how their technologies can help CIP?

jeremiahg @mckeay perhaps ask why the cyber security initiatives, identical to Obama&#039;s, never got any traction... http://doiop.com/n825qw</description>
		<content:encoded><![CDATA[<p>Here are some more responses this morning from Twitter.</p>
<p>rybolov @mckeay Just ask about information sharing&#8211;how do security professionals get more than just the friendly face of US-CERT?<br />
rybolov @mckeay infosharing is the important thing.  DHS has many enemies in teh blagosphere, how can DHS make friends with them?</p>
<p>amrittsering @mckeay Ask him to expose any aspect of the $17b cyber security initiative<br />
amrittsering @mckeay Ask him about the backdoor wiretapping into several major telecom carriers, and then ask him about the constitution<br />
amrittsering @mckeay Ask if there is a conflict of interest for folks like Karen Evans to mandate the use of specific security software (cont)<br />
amrittsering @mckeay made by companies she has discussed joining the board of (rumors, only rumors)<br />
amrittsering @mckeay Ask if it is in the best interest of the DoD to make public which security software they do use<br />
amrittsering @mckeay You can throw him some softballs so he will let you ask more &#8211; like what did you learn from Cyber Storm II?<br />
amrittsering @mckeay Ask what changes have been implemented to deal with &#8220;Katrina II &#8211; the reckoning&#8221; especially in terms of 1st response &amp; cross org com<br />
amrittsering @mckeay 1 more &#8211; when and how will private co&#8217;s have the opportunity to tell DHS and CNCI, generally, how their technologies can help CIP?</p>
<p>jeremiahg @mckeay perhaps ask why the cyber security initiatives, identical to Obama&#8217;s, never got any traction&#8230; <a href="http://doiop.com/n825qw" rel="nofollow">http://doiop.com/n825qw</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3756</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 11 Nov 2008 14:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3756</guid>
		<description>Here are some of the responses I got from Twitter last night concerning Secretary Chertoff.  I am not responsible for the content, don&#039;t send the black helicopters to my house.

davehull @mckeay Ask him if he knows what security theater is

catalyst @mckeay I&#039;d ask two questions: (1) what is the biggest lesson learned in working to combine DHS into a singular agency, and
catalyst @mckeay (2) what is the largest challenge facing the next administration

Beaker @mckeay I can&#039;t answer your question without knowing why Chertoff is hosting a blogger roundtable...Is this really his highest priority!?
Beaker RT from myself: WTH is Chertoff hosting a security bloggers roundtable?  Is this REALLY his highest priority these days?
Beaker Maybe Chertoff could hold a Katrina survivors roundtable?  An Iraq or Afghanistan wounded veteran roundtable?  A Pissing Me Off Roundtable?
Beaker Oh, and another thing, he&#039;s hosting a security bloggers roundtable on VETERAN&#039;S DAY!?  REALLY!?  Veterans day!?  WTF.
Beaker Hello friendly DHS data mining bots...please send the water board team in the black helis on the weekend as I have the kids tomorrow, kthxby

johndoe678 @mckeay How many terrorists have been caught due to ID checks at airports since 9/11?  How many extra hours have people sat around?</description>
		<content:encoded><![CDATA[<p>Here are some of the responses I got from Twitter last night concerning Secretary Chertoff.  I am not responsible for the content, don&#8217;t send the black helicopters to my house.</p>
<p>davehull @mckeay Ask him if he knows what security theater is</p>
<p>catalyst @mckeay I&#8217;d ask two questions: (1) what is the biggest lesson learned in working to combine DHS into a singular agency, and<br />
catalyst @mckeay (2) what is the largest challenge facing the next administration</p>
<p>Beaker @mckeay I can&#8217;t answer your question without knowing why Chertoff is hosting a blogger roundtable&#8230;Is this really his highest priority!?<br />
Beaker RT from myself: WTH is Chertoff hosting a security bloggers roundtable?  Is this REALLY his highest priority these days?<br />
Beaker Maybe Chertoff could hold a Katrina survivors roundtable?  An Iraq or Afghanistan wounded veteran roundtable?  A Pissing Me Off Roundtable?<br />
Beaker Oh, and another thing, he&#8217;s hosting a security bloggers roundtable on VETERAN&#8217;S DAY!?  REALLY!?  Veterans day!?  WTF.<br />
Beaker Hello friendly DHS data mining bots&#8230;please send the water board team in the black helis on the weekend as I have the kids tomorrow, kthxby</p>
<p>johndoe678 @mckeay How many terrorists have been caught due to ID checks at airports since 9/11?  How many extra hours have people sat around?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3752</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 11 Nov 2008 06:45:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3752</guid>
		<description>Folks, I have comment moderation turned.  Akismet catches 95% of the comment spam, but it also flags any comment it can&#039;t determine, leaving it up to me to review.  Sorry, I was away from my computer for most of the evening.

I see a number of very good questions.  And a couple by Rocky that I&#039;ll need to expand my own vocabulary before I can fully understand them.  I&#039;ve never heard of the first two programs he mentions.  I&#039;ll hand those over to George Ou.  

Keep them coming if you&#039;ve got them.  I don&#039;t know how many questions we&#039;ll get to ask.  I don&#039;t know if they&#039;ll allow twitter during his talk, but I&#039;ll try.

Martin</description>
		<content:encoded><![CDATA[<p>Folks, I have comment moderation turned.  Akismet catches 95% of the comment spam, but it also flags any comment it can&#8217;t determine, leaving it up to me to review.  Sorry, I was away from my computer for most of the evening.</p>
<p>I see a number of very good questions.  And a couple by Rocky that I&#8217;ll need to expand my own vocabulary before I can fully understand them.  I&#8217;ve never heard of the first two programs he mentions.  I&#8217;ll hand those over to George Ou.  </p>
<p>Keep them coming if you&#8217;ve got them.  I don&#8217;t know how many questions we&#8217;ll get to ask.  I don&#8217;t know if they&#8217;ll allow twitter during his talk, but I&#8217;ll try.</p>
<p>Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rocky DeStefano</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3750</link>
		<dc:creator>Rocky DeStefano</dc:creator>
		<pubDate>Tue, 11 Nov 2008 04:15:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3750</guid>
		<description>Martin,
I got tired of my reply timing out - so I posted my response to my blog....

http://blog.decurity.com/index.php/dec_template/more/dhs_blog_round_table/

Enjoy the session!

Rocky</description>
		<content:encoded><![CDATA[<p>Martin,<br />
I got tired of my reply timing out &#8211; so I posted my response to my blog&#8230;.</p>
<p><a href="http://blog.decurity.com/index.php/dec_template/more/dhs_blog_round_table/" rel="nofollow">http://blog.decurity.com/index.php/dec_template/more/dhs_blog_round_table/</a></p>
<p>Enjoy the session!</p>
<p>Rocky</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rocky</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3749</link>
		<dc:creator>Rocky</dc:creator>
		<pubDate>Tue, 11 Nov 2008 03:24:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3749</guid>
		<description>I would ask about a couple of programs and have the plans articulated a bit more robustly.

1. Einstein v1 is essentially netflow and log management at a very basic level providing session data across departments.  It is valueable but only to a very limited extent.  According to press reports Einstein v2 adds basic (and limited scale) IDS functionality, but what is the end goal for the program?  Why not go for full packet reconstruction on a more aggressive timescale?  

2. Trusted Internet Connection (TIC):  What is the end goal of TIC?  Is the goal to create a NIPR or SIPR-like environment for Federal / Civilian Agencies where data is &quot;classified&quot;, or is it simply a plan for a more robust, sustainable government network in case of civilian Internet outages?  

3.  Government/Commercial cooperation - on the civilian side we need better protection provided by the government - how can we help the government deliver those services?  Current day Information sharing is not completely useless but it is certainly delayed, insufficient and no where near the level of robustness that those who aim to attack our networks enjoy.  What other plans are there from a DHS perspective to enable the civilian sector (or to better align and communicate with them in a collaborative manner)?</description>
		<content:encoded><![CDATA[<p>I would ask about a couple of programs and have the plans articulated a bit more robustly.</p>
<p>1. Einstein v1 is essentially netflow and log management at a very basic level providing session data across departments.  It is valueable but only to a very limited extent.  According to press reports Einstein v2 adds basic (and limited scale) IDS functionality, but what is the end goal for the program?  Why not go for full packet reconstruction on a more aggressive timescale?  </p>
<p>2. Trusted Internet Connection (TIC):  What is the end goal of TIC?  Is the goal to create a NIPR or SIPR-like environment for Federal / Civilian Agencies where data is &#8220;classified&#8221;, or is it simply a plan for a more robust, sustainable government network in case of civilian Internet outages?  </p>
<p>3.  Government/Commercial cooperation &#8211; on the civilian side we need better protection provided by the government &#8211; how can we help the government deliver those services?  Current day Information sharing is not completely useless but it is certainly delayed, insufficient and no where near the level of robustness that those who aim to attack our networks enjoy.  What other plans are there from a DHS perspective to enable the civilian sector (or to better align and communicate with them in a collaborative manner)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chaitanya Sagar</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3748</link>
		<dc:creator>Chaitanya Sagar</dc:creator>
		<pubDate>Tue, 11 Nov 2008 03:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3748</guid>
		<description>My question would be: How do you use the new age media to enhance security? Can  you give specific examples?

You could also suggest using blogs to get tip offs about security issues.

Chaitanya
CEO, http://www.p2w2.com</description>
		<content:encoded><![CDATA[<p>My question would be: How do you use the new age media to enhance security? Can  you give specific examples?</p>
<p>You could also suggest using blogs to get tip offs about security issues.</p>
<p>Chaitanya<br />
CEO, <a href="http://www.p2w2.com" rel="nofollow">http://www.p2w2.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3747</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Tue, 11 Nov 2008 03:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3747</guid>
		<description>Oh, one more thing...he&#039;s hosting a security bloggers roundtable on Veteran&#039;s Day!? 

Wow.</description>
		<content:encoded><![CDATA[<p>Oh, one more thing&#8230;he&#8217;s hosting a security bloggers roundtable on Veteran&#8217;s Day!? </p>
<p>Wow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3746</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Tue, 11 Nov 2008 03:01:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3746</guid>
		<description>{copied from my Twitter response to you}

My question would be: given all of the high profile security issues we have, the fact that the leadership in our country is in transition, the economy is in shambles inviting all sorts of additional pressures on our strapped resources and our military/homeland security are fighting two wars, is a blogger roundtable REALLY the best thing you can be spending tax payer money on!?

Really?

Good luck with that one, Martin... ;)

/Hoff</description>
		<content:encoded><![CDATA[<p>{copied from my Twitter response to you}</p>
<p>My question would be: given all of the high profile security issues we have, the fact that the leadership in our country is in transition, the economy is in shambles inviting all sorts of additional pressures on our strapped resources and our military/homeland security are fighting two wars, is a blogger roundtable REALLY the best thing you can be spending tax payer money on!?</p>
<p>Really?</p>
<p>Good luck with that one, Martin&#8230; <img src='http://mckeay.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>/Hoff</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard E. Baker</title>
		<link>http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/comment-page-1/#comment-3745</link>
		<dc:creator>Richard E. Baker</dc:creator>
		<pubDate>Tue, 11 Nov 2008 02:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/11/10/what-would-you-ask-the-department-of-homeland-security-secretary/#comment-3745</guid>
		<description>How does any one get into jobs that require security clearances... if there are no jobs that will sponsor security clearances...</description>
		<content:encoded><![CDATA[<p>How does any one get into jobs that require security clearances&#8230; if there are no jobs that will sponsor security clearances&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

