RSA Conference 2014 in San Francisco felt to me like everyone rushed to the back corner of the playground after school, to see the fight that had been brewing for several weeks between the big bully (the US government) and the nerdy kid (the information security industry) – but then the fight didn’t happen.
Tensions between the bully and the nerdy kid have existed for many years, but have recently been escalating – here are just a few examples:
- In March 2012, we learned about the NSA’s US$2B investment in a massive datacenter in Utah, designed to store and analyze – and decrypt, when needed – enormous volumes of private communications and transactions of American citizens
- Throughout 2013, we debated the status of the peripatetic Edward Snowden as patriot or traitor, based on his leaking of thousands of classified documents
- In June 2013, documents leaked by Snowden brought to light details of the NSA’s PRISM program, which involves very broad surveillance of data flowing through service providers such as Facebook, Google, Microsoft, Apple, Yahoo, AOL, Skype, and YouTube
- Similarly, we learned in mid-2013 of the NSA capturing phone record metadata for millions of Verizon subscribers
- In December 2013, we found out about a flawed random number generator established as the default in the widely-used RSA BSAFE cryptographic libraries, under a commercial contract with the NSA going back to 2004 – a topic that I blogged about in RSA and NSA: Say It Isn’t So, Joe (30 December 2013)
Fifteen or so years ago, the RSA Conference was where the nerdy security industry kid stood up to the big government bully on issues such as key escrow, the Clipper chip, and classification of encryption as a munitions item to impose tighter export controls. So it looked like this year’s RSA Conference was going to be – as Yogi Berra famously said – déjà vu all over again.
But this year, the nerdy kid just kind of stared down at his shoes.
Among the dozen keynotes at RSA Conference 2014, for example, just four even mentioned the tension between the role of surveillance in the government’s mission to defend us, and its mission to protect our privacy and civil liberties – and one of them was from the government:
- RSA’s Art Coviello called on industry to help governments to establish societal norms to guide us, including the need to balance collective security and individual privacy
- Microsoft’s Scott Charney noted that industry can’t wait for societal norms to develop, and reviewed the principles that have been established to guide Microsoft’s activities – ensure the security of data; only provide data to lawful and specific requests; fight government access to bulk data; and be increasingly sensitive to the location of data
- Nawarf Bital from Juniper Networks made a passionate case for adding information to the list of things that we truly care about, along with family and money – and to treat it as such
- FBI Director James Comey disagreed that privacy and protection are even at odds, asserting that surveillance is required not only to prevent bad things from happening to our own people, but also to protect the privacy of our own people
Other than this, the other keynote speakers were strikingly silent on one of the most important issues of our time.
To me, Nawarf Bital was the only speaker with the courage to really stand up to the bully – it’s worth watching the full video of his talk, but here of some of his especially inspired comments:
I don’t think we give a damn. I’m fed up with talking about outrage. Liking a cause on Facebook is not outrage. Re-Tweeting a link is not outrage. Posting a bad review is not outrage. Not showing up at a Conference is not outrage. These are all examples of a new American disease: first-world outrage. We should be truly outraged, not first-world outraged.
The most dangerous plague of all is apathy … what’s really changing?
We in the US are not alone in this. For example, Yvette Cooper, the Shadow Home Secretary in the UK, is calling for major reforms to oversight over British intelligence agencies, and “a thorough review of the legal framework [under which they operate] to keep up with changing technology.”
A long time ago, on my high school baseball team, our crafty left-handed pitcher threw too close to the head of an opposing batter, who took a couple of threatening steps towards the mound. I vividly remember our teammate looking over at our bench for support – but the rest of us were just sitting there, caught up in watching what was happening. The lesson I took from that day: if there’s going to be a bench-clearing brawl, you have to clear the bench and get everyone out on the field.
Give a damn, get up, get off the bench, get onto the field – even if you just mill about, you have a part to play in deciding what happens, as opposed to merely waiting to see what happens to us all.