Conference attendees support partnerships between the feds and hackers, and even U.S. Cybercommand head General Keith Alexander shook hands with 11-year-old hacker CyFi.
At last year’s GFIRST summit in Nashville, I participated in a panel discussion on the role of threats to federal information systems. All of us on the panel held differing views regarding individual types of threats; sometimes the audience gave our responses a polite round of applause, and other times, mild groans and the occasional hiss were heard when a panelist said something particularly controversial.
However, there was one moment from that panel discussion that particularly stands out in my mind: during a discussion of public-private partnership, my fellow panelist and author Winn Schwartau suggested that, if the federal government wants to get serious about security, it needs to embrace – and hire – members of the private hacker community. Before he even finished that statement, half of the room was applauding, and the other half was in the process of standing to provide him with an ovation. Mind you, GFIRST is a federal conference, sponsored by the Department of Homeland Security. These were not sleeve-tattooed, black-clad, wearing-Ray-Ban-Aviators-indoors people who were providing the applause (not, as they say, that there’s anything wrong with that): they were federal employees, contractors and vendors, all professionals in the federal information assurance arena.
For years, the federal government – or, more accurately, federal agency heads and their lieutenants – have held a very dim view of the entire hacker community (or at least, the ones they can’t recruit to work directly for the government). In the scope of the federal government’s view, anyone who knows more than they do about security intentionally tries to discover vulnerabilities (regardless of their motivation) or even views security in a different way than they do has perpetually been perceived as a threat, regardless of the shade of their hat. While there has been no written policy for this, we all know it’s been the de facto standard for decades.
This all changed at this year’s Defcon, when none other than Gen. Keith Alexander – who heads both the NSA and U.S. Cybercommand – shook the hand of 11-year old (and absolutely brilliant) hacker CyFi, and delivered a contrite speech in which he stated that partnerships between the feds and the hacking community is the only way that we’re going to really solve security problems.
And, of course, he was right.
The federal government has a great handle on “macro”-level information security tasks that private entities do not: they have facilities in place for reporting and incident response (both in federal agencies and private industry), they have the ability to monitor global cybersecurity threats on a level that individuals and most corporations do not, and they have established legal mechanisms for security enforcement (some might also say illegal methods, but that’s for another post). The hacker community, on the other hand, has locked-up “micro”-level security at a level the feds simply have not. It takes a certain type of personality – not to mention a big, giant brain – to use black box methods to discover new vulnerabilities within not only operating systems and applications, but critical infrastructure components such as ATMs and public utility “smart” meters…hacks for both of which have been demonstrated in recent years at Black Hat and Defcon.
Put these two groups together – a global federal government cybersecurity detection and response capability, and a community of smart, curious and highly motivated hackers who can discover the vulnerabilities within the critical infrastructure that the federal government seeks to protect through policies and laws – and you have a formidable force that can more effectively address the entire stack of information security.
Here’s hoping that this year’s Defcon was more than just rhetoric, and actually signals better relations between these two communities in the future.




