Skip the navigation

DHS official fields hard questions at Black Hat

By Robert McMillan
July 28, 2010 03:18 PM ET

IDG News Service - The U.S. Department of Homeland Security sent its highest-ranking official ever to speak at the Black Hat conference this week, and its Deputy Secretary Jane Holl Lute ended up fielding a few tough questions from skeptical computer security professionals in attendance.

During a question-and-answer session at the end of her Wednesday keynote address, one attendee asked if we should expect the DHS to give cybersecurity the same kind of treatment it's given air travel with the Transportation Security Administration. "Why should we believe that DHS, going forward, is going to protect cyber in something other than the same way?" he asked, scoring the loudest applause of the session with the question. "Now as the TSA slows down the air travel, DHS will slow down the commerce."

The undersecretary disagreed with this characterization of the TSA, but conceded that there is a "tension" in the DHS' mission. "We want to keep out people who might be dangerous, but we want to expedite legitimate trade and travel."

"We happen to believe that we can achieve our security, we can protect our rights, we can protect commerce and lawful interchange," she said. "We can have all of these things, but we need to engage in a debate about how we will prioritize and how we will strike the balance."

Security experts such as Bruce Schneier have long slammed the TSA's procedures, saying that they are ineffective and poorly thought out. Schneier calls U.S. airport screenings "security theater."

Some have also criticized the DHS as slow in its response to cyber-incidents. As industrial systems were being targeted with the Stuxnet worm two weeks ago, it took DHS' Industrial Control Systems Computer Emergency Response Team five days to push out a public alert. Critics say that was too long.

Hitting on a theme of her keynote, Lute called for real dialogue between government and industry and said she hoped that her department could be a "portal for that debate."

"You know, societies used to have conversations with themselves through their governments. In that respect, we're not talking to each other any more," she said. "In many respects we're throwing assertions back and forth at each other and seeing who has the more clever report, who has thought of the newer idea."

Hitting on another theme that the government's response to cyberthreats has been more rhetorical than practical, another attendee asked if Lute thought the U.S. would be able to secure computer systems without first experiencing a cyberdisaster, equivalent to the Sept. 11 terrorist attacks. "In Homeland Security, at the water cooler, do your peers say, 'It's just a matter of time before something horrible happens and that's when we're going to need to do what we actually need to do, instead of just talking about what needs to be done?"

"I'm a person who believes that this country can protect itself," Lute said. "I don't know what's inevitable, and I think that anybody who lived through the events of 1989 [when the Berlin Wall fell] or who lived through the events of 2001 has lost the right to say that anything is impossible."

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is

Reprinted with permission from Story copyright 2014 International Data Group. All rights reserved.
Our Commenting Policies
Blog Spotlight

Staff member at a senior center calls this pilot fish, complaining that her printer won't work. And since she's the kind of user who thinks computers just get in the way of getting her job done, fish has his work cut out for him.