Re: The Cybersecurity Act of 2009 (was: SCADA)
Chris Blask <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Steven M. Bellovin <[email protected]> > I wrote a long analysis of the bill in my blog; see > http://www.cs.columbia.edu/~smb/blog/2009-04/2009-04-12.html Hey Steve, Thanks for the link. The Moose is much more a political than a technical audience so my commentary there reflects that but - in short - I share many of your technical concerns. There is a fair bit of technical specificity that doesn't really seem to either belong in a law or seem likely to actually work. I suppose the best thing in my view about this bill is that it pushes the discussion sooner rather than later. I think we may have reached a point of diminishing returns in waving our hands and drawing on whiteboards in front of politicians. As awkward as it may be, it is possible that trying to struggle through crafting and implementing legislation could be what it takes to clarify the realm of possibilities for all parties (and, heck, we could even find that some of our assumptions were incorrect, too). I will restrain myself by sheer force of will from debating most of the fine points (Identity!) at the moment. More interesting for the purpose of this list atm is to see what level of general consternation and/or agreement our fellow fellows have with it. -chris