News: 1713987808

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Shouldn't Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking

(2024/04/24)


Collaboration software used by federal government agencies — this includes apps from Microsoft, Zoom, Slack, and Google — will be required to work together and be securely end-to-end encrypted, if legislation proposed by US Senator Ron Wyden (D-OR) passes.

That's a big if. Without a lot of bipartisan momentum behind it, his proposal isn't expected to make into law during this election year.

Wyden proposed the legislation, the Secure and Interoperable Government Collaboration Technology Act

[1]PDF

, on Tuesday. It intends to make products from competing vendors, such as Teams and Zoom, for example, talk to each other more securely.

[2]

Specifically, it would require the US government's General Services Administration (GSA) to create a list of collaboration technology features used by the federal government. Then the National Institute of Standards and Technology (NIST) would need to identify a set of interoperable standards and requirements for each of these.

[3]

[4]

The legislation would also require that, "to the extent practicable," end-to-end encryption and other technologies to protect government communications from foreign surveillance would have to be built in. These collaboration technologies must also comply with federal record-keeping requirements.

Four years after NIST selects the standards, all collaboration technology purchased by the federal government would be required to communicate using the identified standards, thus ensuring they are interoperable with other products used by federal agencies.

[5]

And finally, the legislation would require Homeland Security to review these products, and every other year a GSA and Office of Management and Budget working group would review the products in use and suggest updates to the standards.

"My bill will secure the US government's communications from foreign hackers, while protecting taxpayer wallets. Vendor lock-in, bundling, and other anticompetitive practices result in the government spending vast sums of money on insecure software," Wyden said in a [6]statement .

"It's time to break the chokehold of big tech companies like Microsoft on government software, set high cybersecurity standards and reap the many benefits of a competitive market," he added.

[7]Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

[8]US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

[9]Microsoft cannot keep its own security in order, so what hope for its add-ons customers?

[10]Microsoft is a national security threat, says ex-White House cyber policy director

Stunningly, the bill identifies collaboration systems that would not be subject to the interoperability and security requirements. These include email, voice services, and national security systems.

So despite the proposal's attempt at landing a blow on [11]Microsoft's mafia-like hold on government-procured tech, the latest [12]Redmond email security breaches by [13]Chinese and [14]Russian cyberspies probably would have happened even with the Wyden-backed security standards being in place.

[15]

While those standards would likely face opposition from Big Tech, some digital rights and privacy organizations including Accountable Tech, Demand Progress, Fight for the Future, Proton, Nym, and the Matrix.org Foundation have already endorsed the draft legislation.

Author and activist Cory Doctorow has also thrown his support behind the proposal.

"Interoperability — the ability to plug something new into a technology, with or without permission from the manufacturer — is the key to defeating Big Tech," he said.

"This bill will require public funds to be spent on technology that anyone can fix, extend, or improve, preventing tech companies from locking in and ripping off the US government," Doctorow added. "The most amazing part is that this isn't already the way it's done." ®

Get our [16]Tech Resources



[1] https://www.wyden.senate.gov/imo/media/doc/secure_and_interoperable_government_collaboration_technology_act_full_text.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZimA@fEvKKVVUBRiiCY1vwAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZimA@fEvKKVVUBRiiCY1vwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZimA@fEvKKVVUBRiiCY1vwAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZimA@fEvKKVVUBRiiCY1vwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.wyden.senate.gov/news/press-releases/wyden-releases-draft-legislation-to-end-federal-dependence-on-insecure-proprietary-software-in-response-to-repeated-damaging-breaches-of-government-systems

[7] https://www.theregister.com/2024/04/03/cisa_microsoft_exchange_online_china_report/

[8] https://www.theregister.com/2024/04/05/microsoft_government_contracts/

[9] https://www.theregister.com/2024/04/24/microsoft_security_addons/

[10] https://www.theregister.com/2024/04/21/microsoft_national_security_risk/

[11] https://www.theregister.com/2024/04/05/microsoft_government_contracts/

[12] https://www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/

[13] https://www.theregister.com/2023/09/28/chinese_hackers_stole_60000_state/

[14] https://www.theregister.com/2024/04/12/microsoft_cisa_order/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZimA@fEvKKVVUBRiiCY1vwAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



Doctor Syntax

Given that email already has long established standards, mostly being followed, there are only a couple of changes, neither very radical that need to be made. One is to ban the use of any that don't follow the standard - I wonder who that would be - and the other is to roll PGP into the standard. In regard to the last PGP itself has been available in email clients for years, nothing new there.

Public key distribution would appear to be the main issue. It's not as if serving small text files is a massive technological leap. The only problem is telling the punter where to find the server. There are a few possible alternatives. One is to add a new type of record alongside the MX record to point to the key server. Another is to extend SMTP to allow the mail server to query the location of the key server. A third would be to have the mail server function as the key server and extend SMTP to request the key.

Interoperability

parrot

You mean like, WhatsApp talking to Signal, talking to iMessage, talking to Telegram? That sort of interoperability?

That would be real choice… For everyone.

Re: Interoperability

Tom Chiverton 1

Already happening, thanks to the EU : https://engineering.fb.com/2024/03/06/security/whatsapp-messenger-messaging-interoperability-eu/

By golly, I'm beginning to think Linux really *is* the best thing since
sliced bread.
-- Vance Petree, Virginia Power