<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; homeland security</title>
	<atom:link href="http://praetorianprefect.com/archives/category/homeland-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 29 Jul 2010 16:38:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Was the Austin Plane Crash Domestic Terrorism?</title>
		<link>http://praetorianprefect.com/archives/2010/02/was-the-austin-plane-crash-domestic-terrorism/</link>
		<comments>http://praetorianprefect.com/archives/2010/02/was-the-austin-plane-crash-domestic-terrorism/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 19:24:27 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[homeland security]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[terrorism]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3346</guid>
		<description><![CDATA[In what could be the first act of domestic terrorism since Timothy McVeigh, a small plane (Piper) that set out from Georgetown Municipal Airport hit a federal office building housing the Internal Revenue Service (IRS) at 11:36 AM in Austin, Texas. A software developer, Joseph Andrew Stack, who had previously set his house on fire, was the pilot who suicidally flew his plane Kamikaze style into the building in an apparent act of revenge against the IRS as detailed in a 3,202 word suicide note on his web site: <a href="http://embeddedart.com">http://embeddedart.com</a>.]]></description>
			<content:encoded><![CDATA[<p><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/plane_crash_.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/plane_crash_-150x150.jpg" alt="plane_crash_" title="plane_crash_" width="150" height="150" class="alignleft size-thumbnail wp-image-3347" /></a></p>

<p>In what could be the first act of domestic terrorism since Timothy McVeigh, a small plane (Piper) that set out from Georgetown Municipal Airport hit a federal office building housing the Internal Revenue Service (IRS) at 11:36 AM in Austin, Texas. A software developer, Joseph Andrew Stack, who had previously set his house on fire, was the pilot who suicidally flew his plane Kamikaze style into the building in an apparent act of revenge against the IRS as detailed in a 3,202 word suicide note on his web site: http://embeddedart.com. The web site is reporting a last update of Thursday, February 18, 2010 10:12:53 AM.</p>

<p>Note that the following message now appears on embeddedart.com: <i>This website has been taken offline due to the sensitive nature of the events that transpired in Texas this morning and in compliance with a request from the FBI. If you want to see the original letter, please see the archived version at thesmokinggun.com. Regards, T35 Hosting <a href="http://www.t35.com/">http://www.t35.com/</a></i></p>

<p>The suicide note on embeddedart.com downloaded as a pdf:
<a href='http://praetorianprefect.com/wp-content/uploads/2010/02/Well-Mr.-Big-Brother-IRS-man...-take-my-pound-of-flesh-and-sleep-well..pdf'>Well Mr. Big Brother IRS man&#8230; take my pound of flesh and sleep well.</a></p>

<div id="attachment_3374" class="wp-caption alignnone" style="width: 760px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/suicide_note.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/suicide_note.jpg" alt="The suicide note as it originally appeared." title="suicide_note" width="750" height="501" class="size-full wp-image-3374" /></a><p class="wp-caption-text">The suicide note as it originally appeared.</p></div>
<br /></p>

<p>The FBI and CIA also have offices in the same building complex. This particular IRS office is home to a group called the EP Team Audit Program, which examines employee benefit plans with 2,500 or more participants.</p>

<h3>Terrorism?</h3>

<p><div id="attachment_3388" class="wp-caption alignleft" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/officebuilding.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/officebuilding-300x259.jpg" alt="The Echelon Building Burning." title="officebuilding" width="300" height="259" class="size-medium wp-image-3388" /></a><p class="wp-caption-text">The Echelon Building Burning.</p></div>

<p>Well certainly not the kind that one would think of with regards to foreign religious ideological based groups, such as Al Qaeda, but let&#8217;s take a closer look at what the definition of terrorism really is:</p>

<p><i>(the calculated use of violence (or the threat of violence) against civilians in order to attain goals that are political or religious or ideological in nature; this is done through intimidation or coercion or instilling fear)</i> -Princeton.edu</p>

<p>Well, one could make argument that this was a decision to commit suicide in a very public way (crashing planes into buildings is certainly an attention getter), to further his views as outlined in the manifesto he wrote, or that this was an attempt to incite some sort of movement by his actions. Regardless, there was an attempt to incite fear. The deliberate use of an airplane as the method of attack, along with the parallels it invokes, are no accident. These characteristics place this as, albeit minor given the no reported deaths, an act of domestic terrorism.</p>

<blockquote>
  <p>“I am finally ready to stop this insanity.  Well, Mr. Big Brother IRS man, let&#8217;s try something different; take my pound of flesh and sleep well.” <br />- Joseph Stack</p>
</blockquote>

<h3>Is the Letter a Hoax?</h3>

<p>We do not think so. Let&#8217;s explore this a little, first looking at the whois results for this http://embeddedart.com/ web site. The person listed as the administrative contact is the same person being identified as the pilot, Joseph Stack. Further the web site was not registered recently, its been around for seven years. Finally, while we&#8217;ve been impressed with the complexity of Internet hoaxes in the past, its not easy to write a well thought out essay of 3,202 words in less than two hours.</p>

<pre><code>Administrative Contact:
Stack, Joe dns.5.sgmail@dfgh.net
925 E Hwy 80
287
San Marcos, TX 78666
US
1.3215649879
Technical Contact:
Stack, Joe dns.5.sgmail@dfgh.net
925 E Hwy 80
287 San Marcos, TX 78666
US
1.3215649879

Registrar of Record: TUCOWS, INC.
Record last updated on 16-Sep-2006.
Record expires on 05-Jun-2010.
Record created on 05-Jun-2003.
</code></pre>

<p>So this does appear to be as it outwardly appears: the last essay of an American suicide bomber with a serious beef against the IRS.</p>

<h3>A Software Engineer</h3>

<p>Looking at the previous form of Stack&#8217;s web site, before it hosted an anti-tax manifesto, it advertised his software contracting services:</p>

<p><div id="attachment_3368" class="wp-caption alignnone" style="width: 760px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/website_1.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/website_1.jpg" alt="Joseph Stack Web Site" title="website_1" width="750" height="598" class="size-full wp-image-3368" /></a><p class="wp-caption-text">Joseph Stack Web Site</p></div>
<br /></p>

<h4>Company Mission</h4>

<pre><code>To advance the art of programming, one project at a time; by achieving an optimum balance between
 cost, schedule, functionality, reliability, and maintainability. 
</code></pre>

<h4>Resume</h4>

<p>Stack&#8217;s software experience (resume): <a href='http://praetorianprefect.com/wp-content/uploads/2010/02/Embedded-Art-Key-Environment-Components.pdf'>Embedded Art &#8211; Key Environment Components</a>.</p>

<h4>Software Projects</h4>

<p><div id="attachment_3369" class="wp-caption alignnone" style="width: 760px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/website_projects.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/website_projects.jpg" alt="Listed customer projects from Joseph Stack&#039;s web site." title="website_projects" width="750" height="598" class="size-full wp-image-3369" /></a><p class="wp-caption-text">Listed customer projects from Joseph Stack's web site.</p></div>
<br /></p>

<h3>Stack&#8217;s Home Location</h3>

<p>According to his web site, his address appears to be a condominium unit:</p>

<pre><code>6001 W. Parmer Ln., #370-167
Austin, TX 78727
</code></pre>

<p><div id="attachment_3370" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/condo.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/condo-300x218.jpg" alt="Condo address listed on Stack&#039;s web site." title="condo" width="300" height="218" class="size-medium wp-image-3370" /></a><p class="wp-caption-text">Condo address listed on Stack's web site.</p></div>
<br /></p>

<p>However this may be old, as another web site is reporting the address to be: 1827 Dapplegray Lane. This makes more sense when combined with the house burning video below (there is a fence/wall in both).</p>

<p><div id="attachment_3371" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/dapplegray.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/dapplegray-300x204.jpg" alt="The address listed as Stack&#039;s on media web sites." title="dapplegray" width="300" height="204" class="size-medium wp-image-3371" /></a><p class="wp-caption-text">The address listed as Stack's on media web sites.</p></div>
<br /></p>

<p>If this is really his house, its a nice place for a guy with tax problems:
<div id="attachment_3384" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2010/02/Screen-shot-2010-02-18-at-3.49.12-PM.png"><img src="http://praetorianprefect.com/wp-content/uploads/2010/02/Screen-shot-2010-02-18-at-3.49.12-PM-300x216.png" alt="House listed on media outlets as Joseph Stack&#039;s." title="Screen shot 2010-02-18 at 3.49.12 PM" width="300" height="216" class="size-medium wp-image-3384" /></a><p class="wp-caption-text">House listed on media outlets as Joseph Stack's.</p></div>
<br /></p>

<p>Either way, this was what the house looked like this morning:</p>

<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/ojoWY_Fy6Bk&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en_US&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/ojoWY_Fy6Bk&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en_US&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="425" height="344"></embed></object>
<br /></p>

<h3>A Wrong Reaction</h3>

<p>So other than being a homeland security issue, why would a humble information security blog find this interesting? Well it is always interesting to us how people handle incident response.</p>

<p>The DHS Journal reported the following via Twitter: &#8220;Small plane crash into private office bldg in Austin, TX. Cause unknown, but no known link to terrorism.&#8221;</p>

<p>White House spokesman Robert Gibbs also weighed in, saying it was not an attack.</p>

<p><strong>Related Posts:</strong></p>
<ul>
<li><a href="http://praetorianprefect.com/archives/2009/10/dhs-responds-to-us/">DHS Responds to Us</a></li>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2010/02/was-the-austin-plane-crash-domestic-terrorism/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>DHS Responds to Us</title>
		<link>http://praetorianprefect.com/archives/2009/10/dhs-responds-to-us/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/dhs-responds-to-us/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 20:55:04 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[homeland security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[leadership]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1106</guid>
		<description><![CDATA[This morning at 11am Homeland Security Secretary Janet Napolitano addressed the nation as part of the ongoing activities around <a href="http://www.dhs.gov/files/programs/gc_1158611596104.shtm">National Cybersecurity Awareness Month</a>. This is the sixth year of this program, sponsored by the National Cyber Security Division (NCSD) of the Department of Homeland Security, in which the department advises the American people on staying safe online. This year's theme is "Our Shared Responsibility", reinforcing the idea that all computer users have a responsibility for protecting themselves online. The address this morning featured the ability to ask questions of the Secretary, we sent one in, and Secretary Napolitano answered it.]]></description>
			<content:encoded><![CDATA[<p><a href="http://praetorianprefect.com/wp-content/uploads/2009/10/napolitano.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2009/10/napolitano-150x150.jpg" alt="napolitano" title="napolitano" width="150" height="150" class="alignleft size-thumbnail wp-image-1107" /></a></p>

<p>This morning at 11am Homeland Security Secretary Janet Napolitano addressed the nation as part of the ongoing activities around <a href="http://www.dhs.gov/files/programs/gc_1158611596104.shtm">National Cybersecurity Awareness Month</a>. This is the sixth year of this program, sponsored by the National Cyber Security Division (NCSD) of the Department of Homeland Security, in which the department advises the American people on staying safe online. This year&#8217;s theme is &#8220;Our Shared Responsibility&#8221;, reinforcing the idea that all computer users have a responsibility for protecting themselves online. The address this morning featured the ability to ask questions of the Secretary: we sent one in and Secretary Napolitano answered it.</p>

<p>The overall talk was very accessible, speaking directly to people on the threats faced online and the precautions people can take to protect themselves. The Secretary referenced President Obama&#8217;s remarks a few months ago including his assertion that the status quo is insufficient. She noted the DHS role in securing civilian government networks referred to by her as the &#8220;.Gov world&#8221;. She also mentioned a few DHS initiatives, including: the consolidation of external connections at federal agencies and the use of the DHS intrusion detection system referred to as EINSTEIN.</p>

<blockquote>
  <p>&#8220;the President challenged the nation to “seize the promise” and also “confront the perils” that technology brings.&#8221;<br /></p>
  
  <p><code>Janet Napolitano</code></p>
</blockquote>

<p>After her talk, she accepted submitted questions. I will admit that I typed up a question quickly on Monday, only half thinking it would actually get answered (I apologize for my lack of faith). I probably would have thought about it a little more had I known it would be answered. That said, I tried to ask a question where the answer could provide a gauge of the Secretary&#8217;s view of how federal information security should be organized, and who should lead it. We&#8217;ve all been listening to the talk about a Cybersecurity Czar, so understanding the Secretary&#8217;s point of view on this issue would be timely.</p>

<p>Without further ado, here&#8217;s the question:
<br /><br /><br /></p>

<div class="wp-caption" style="display: block;text-align: left;margin: 5px;margin-left: 10px;">
Question 2: Daniel from New York &#8211; <br />We have cabinet level positions for labor, agriculture, energy, transportation, and yet none for technology/security which, as an industry, has a size commensurate with the others represented. Do you think a cabinet position to represent technology and its related effects &#8211; such as cybersecurity &#8211; is necessary?
</div>

<p><br /></p>

<p>How serious was I about a cabinet level position? Well if you think about the primary role of the cabinet, before running large bureaucracies, it is to provide advisory to the President. Same role as a czar, an adviser to the President, except where czar&#8217;s usually hang out in pre-1900 Russia, cabinet positions have been a standard in the U.S. for about 200 years. So if Benjiman Rush, a founding father, can propose a Peace Department, I can propose the Information Assurance Department.</p>

<p>If I can&#8217;t get a cabinet position, I&#8217;ll settle for a single, empowered official that can lay out a strong, reasoned strategy on information assurance and the protection of critical assets (or infrastructure) for the nation. We, on the national level, at this time, appear to have some serious risks to deal with and a disjointed legislative and strategic response. This requires step 1 in every strategic plan: put someone in charge. You&#8217;re oversimplifying you might counter. All strategic plans that have a chance of working put someone in charge, someone to be accountable for moving from the &#8216;as is&#8217; state that is the status quo to the &#8216;to be&#8217; state that leader outlines as required. Someone with a real understanding of the threats faced in cyberspace. Ideally someone who knows what he or she is doing would be great, but we won&#8217;t get greedy.</p>

<p>Here is what Secretary Napolitano had to say:</p>

<div class="wp-caption" style="display: block;text-align: left;margin: 5px;margin-left: 10px;">
Answer: &#8220;Daniel, I’m not sure that I think that a cabinet level position is necessary. And the reason is that cyber runs through everything that we do as a government. So, it’s really hard to segregate it out. In fact, I think one of the things we’re learning as we enter this new cyber arena is that segregating it into an IT or IT function no longer is adequate. Again, as my remarks suggested, cyber is part of everything we do, from the most basic transaction to complicated security protections of our country. So what we need to do is make sure that cyber is part of our thinking in all departments. But added to that now, the president has included a chief technology officer, a chief information officer, in the White House, and he will be appointing a coordinator for cyber within the White House to help make sure that cyber is part of all that we do throughout the vast array of the federal government as we move forward.&#8221;
</div>

<p><br />
A fair answer, and it &#8216;got me&#8217; on confusing information technology with information security. I should have been more clear with that in the question I asked, security is not exclusively a technology problem, and in this case I definitely don&#8217;t think the security official should report through the government&#8217;s CIO (chief information officer), Vivek Kundra or any other technology department. Like any other organization, sometimes it works to have a chief information security officer (CISO) report to the CIO and sometimes the CISO should report to someone else. I don&#8217;t think reporting to the CIO would work in this case. The CIO position is below that of chairman of the Office of Management and Budget (OMB) which does not provide the direct high level access required. Further the OMB does not have the historical role with cybersecurity that DHS and other entities have had. Finally the Federal Chief Information Officer role is best served being countered by a strong security representative, such that the transparency and related initiatives underway are properly vetted.</p>

<p>I was willing to combine security with technology if it got that cabinet position created.  If not, forget it. :)</p>

<p>The answer gets a little confused in the middle. The Secretary starts by stating that information security runs through everything in government, therefore it can not be siloed out and every department must have &#8220;cyber&#8221; in their thinking or planning. But then she points out that the President has appointed central leaders for technology and looks to appoint one for &#8220;cyber&#8221; (assumed to be information security).</p>

<p>The use of technology does permeate every department. Understanding information security and taking safeguards to protect critical assets is the responsibility of every department. But overall strategic direction, standardization, central monitoring, organized procurement, and many other aspects of information security management will not happen without centralized leadership. Accountability is lost without an empowered national leader for information assurance.</p>

<p>The Secretary seems to acknowledge this dichotomy in her response. I encourage you to review the full speech:</p>

<ul>
<li>Full transcript of the Secretary&#8217;s remarks: <a href="http://www.dhs.gov/ynews/gc_1256070988236.shtm">Transcript</a></li>
<li>The video of the remarks: <a href="http://www.dhs.gov/journal/leadership/2009/10/securing-america-against-threat-of.html">Securing America Against the Threat of Cyber Attack</a></li>
</ul>

<p>Also, who else is ready to retire the term &#8220;cybersecurity&#8221; in favor of something else (information assurance maybe)?</p>

<h3>Update</h3>

<p>Dark Reading posted an interesting synopsis of the response to my question: <a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=220700409">DHS Secretary Says Cabinet-Level IT Position Unnecessary</a></p>

<p><strong>Related Posts:</strong></p>
<ul>
<li><a href="http://praetorianprefect.com/archives/2010/02/was-the-austin-plane-crash-domestic-terrorism/">Was the Austin Plane Crash Domestic Terrorism?</a></li>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/dhs-responds-to-us/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
