Not Breaking: Keith Alexander to Be Allowed to Retire Unscathed; Breaking: NSA

We’ve actually known for some time that Keith Alexander was retiring shortly. So Reuters’ headline reporting it (and the departure of Alexander’s Deputy John Inglis) is not news.

Screen shot 2013-10-16 at 5.38.14 PM

But mega kudos to the person who dubbed Alexander the “eavesdropping agency chief.”

One important implication of this headline though is,

Alexander will not be fired, much less criminally charged, for serial lies to Congress

Not to mention the fact that James Clapper will, as far as we know, remain employed and free.

All that said, the overall point of Reuters’ story is important. This presents Obama with an opportunity to set a new direction for NSA.

While both men are leaving voluntarily, the dual vacancies give Obama an opportunity both to install new leadership following Snowden’s revelations and to decide whether the NSA and Cyber Command should have separate leaders.

Cyber Command, which has grown significantly in recent years, has the authority to engage in both defensive and offensive operations in cyberspace. Many NSA veterans argue that having the same person lead the spy agency and Cyber Command diminishes the emphasis on the NSA’s work and its unique capabilities.

I say go even bigger than this: break up this Frankenstein contraption and split NSA’s defensive function from its offensive ones entirely. And while we’re at it, let’s move it out of DOD.

Noah Shachtman wrote a piece describing how to do this so long ago he actually referred to “the agency that tapped AT&T switching stations (OK, OK, allegedly)” instead of “the agency FISC deemed in violation of the Fourth Amendment for collecting US person data at AT&T’s switches.”

NSA headquarters — the “Puzzle Palace” — in Fort Meade, Maryland, is actually home to two different agencies under one roof. There’s the signals-intelligence directorate, the Big Brothers who, it is said, can tap into any electronic communication. And there’s the information-assurance directorate, the cybersecurity nerds who make sure our government’s computers and telecommunications systems are hacker- and eavesdropper-free. In other words, there’s a locked-down spy division and a relatively open geek division. The problem is, their goals are often in opposition. One team wants to exploit software holes; the other wants to repair them.

[snip]

A broken-out bureau — call it the Cyber Security Agency, or CSA — that didn’t include the spooks would obviate this conflict. “A separate information-assurance agency,” says Michael Tanji, a 21-year veteran of intelligence services, including the NSA, “will have a greater level of acceptance across the government and the private sector.”

[snip]

An independent CSA would be trusted more widely than Fort Meade, improving collaboration among cybersecurity geniuses. It was private researchers and academics who led the effort to corral the ultrasophisticated Conficker worm. And the National Institute of Standards and Technology worked on federal desktop security. A well-run, independent CSA would be able to coordinate better with these outside entities.

The problem — both of NSA’s conflicting missions and of the lack of trust in it — has gotten far worse since Shachtman wrote this piece. The NYT reported that the NSA has been ensuring it has back doors in far more places than originally thought. In addition there are the concerns about its use of NIST to weaken encryption standards.

And we now know that NSA is keeping encrypted communications — including that of the white hats you need to cooperate on the cyberdefense project — indefinitely. That is, it is treating necessary partners are criminals.

Right now, the NSA wants to be able to copy and scan all the traffic in the US to be able to search for malware and other malicious code. Yet it has already been caught spying on Americans even while just (allegedly) hunting for terrorists. And it refuses to count how many Americans it has spied on in this way. This is not a trustworthy agency to conduct out whatever sorting that needs to be done (not to mention the fact it can’t be trusted to keep this goal separate from its offensive ones).

Even NSA’s apologists should embrace such a suggestion. Without it, their claims to want the best defense against cyberthreats ring hollow, because the existing NSA is one of the biggest cyberdangers out there.

Tweet about this on Twitter0Share on Reddit0Share on Facebook0Google+0Email to someone

14 Responses to Not Breaking: Keith Alexander to Be Allowed to Retire Unscathed; Breaking: NSA

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
Emptywheel Twitterverse
bmaz @erinscafe The furry picture should lead all reports though.
3mreplyretweetfavorite
bmaz @billmon1 @TheBradBlog Ooof. Hope you have enough coffee and/or bourbon.
5mreplyretweetfavorite
bmaz @billmon1 @TheBradBlog Sure. But that is exactly why the patina of "legality" is so illusory in this discussion.
10mreplyretweetfavorite
bmaz @billmon1 @TheBradBlog And that applies to torture, extrajudicial killing, banksters, illegal surveillance, and a whole host of issues.
13mreplyretweetfavorite
bmaz @billmon1 @TheBradBlog The problem, as with so much is the political acts that beget such use/nonuse of discretion.
14mreplyretweetfavorite
bmaz @billmon1 @TheBradBlog Right. Failure to prosecute/hold accountable for Senate incursion is technically legal as prosecutorial discretion.
15mreplyretweetfavorite
bmaz RT @WSJ: At 79, Jerry Lee Lewis just released his 41st studio album. Listen here: http://t.co/rAJMtCwvpX http://t.co/IVJYFJ10VM
23mreplyretweetfavorite
bmaz RT @AntonioFrench: Bob McCulloch and Attorney General Holder should be launching investigations into who is leaking this info. Police? Atto…
38mreplyretweetfavorite
bmaz @mtracey @billmon1 As SSCI Chair, it was her duty to make the case, and she did, lack of vocal support from others, and non-SSCI depressing
49mreplyretweetfavorite
bmaz @billmon1 Even assuming you get past that as to DOD action, which is dubious, there is still issue of §1117+§1119 liability for civilians
54mreplyretweetfavorite
bmaz @billmon1 I agree as to seriousness. But disagree that characterization as combatants is legally correct without a battlefield+imminence.
57mreplyretweetfavorite
bmaz @shenebraskan @billmon1 Yeah, sorry about that. But even in a constant sea of depressing, certain things just stand out.
1hreplyretweetfavorite
October 2013
S M T W T F S
« Sep   Nov »
 12345
6789101112
13141516171819
20212223242526
2728293031