Last week, the Senate Intelligence Committee reported a bill that would require the government to disclose information about the intrusion detection system for government computers that has been dubbed, “Einstein.” Section 340 of the Intelligence Committee’s Intelligence Authorization Act for FY 2010 (S. 1494) would require the government to report to Congress about privacy impact of Einstein, the legal authority supporting it, and about any audits that have been conducted on its operations. The bill, and recent press accounts, prompt CDT to ask the Administration to reveal more about Einstein.
There’s no doubt that the government needs better cybersecurity immediately. Malicious code has been found in the computers that run the electric power grid, and terabytes of data about the Pentagon’s $300 billion F-35 Joint Strike Fighter jet were recently stolen by computer spies.
Einstein is designed to partially meet this need for civilian government computer networks. It operates to detect malicious code in communications with the government. The latest iteration – Einstein 3 – reportedly can scan the content of such communications and, using technology based on a National Security Agency system called “Tutelage,” can intercept the malicious computer code before it even reaches the government system.
But the Einstein intrusion detection system raises a whole host of questions: what is the scope of the NSA’s role? What is done with the intrusion reports Einstein generates and shares with law enforcement and intelligence agencies? How are people notified that their communications with government officials, and their surfing of government websites, are being monitored for threatening code? CDT poses these and other questions about Einstein in a new report released today.
The Department of Homeland Security did a Privacy Impact Assessment on the first two versions of the Einstein intrusion detection systems, and they reveal a lot of information. But, critical pieces to the puzzle are still missing, and a new version of the system that ups the privacy stakes is being developed.
Secrecy can undermine the effectiveness of a cybersecurity program, particularly one that relies, as Einstein 3 does, on the cooperation of private sector communications service providers. It’s time for the Obama Administration to chart a new course by being more open about Einstein.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.