Cybersecurity Community Must Not Remain Silent On Executive Order Attacking Former CISA Director

1 month 1 week ago

Cybersecurity professionals and the infosec community have essential roles to play in protecting our democracy, securing our elections, and building, testing, and safeguarding government infrastructure. It is critically important for us to speak up to ensure that essential work continues and that those engaged in these good faith efforts are not maligned by an administration that has tried to make examples of its enemies in many other fields. 

President Trump has targeted the former Director of the government’s Cybersecurity and Infrastructure Security Agency (CISA), Chris Krebs, with an executive order cancelling the security clearances of employees at SentinelOne, where Krebs is now the Chief Intelligence and Public Policy Officer, and launching a probe of his work in the White House. President Trump had previously fired Krebs in 2020 when, in his capacity as CISA Director, Krebs released a statement calling that election, which Trump lost, "the most secure in American history.” 

The executive order directed a review to “identify any instances where Krebs’ or CISA’s conduct appears to be contrary to the administration’s commitment to free speech and ending federal censorship, including whether Krebs’ conduct was contrary to suitability standards for federal employees or involved the unauthorized dissemination of classified information.” Krebs was, in fact, fired for his public stance. 

We’ve seen this playbook before: In March, Trump targeted law firm Perkins Coie for its past work on voting rights lawsuits and its representation of the President’s prior political opponents in a shocking, vindictive, and unconstitutional executive order. After that order, many in the legal profession, including EFF, pushed back, issuing public statements and filing friend of the court briefs in support of Perkins Coie, and other law firms challenging executive orders against them. This public support was especially important in light of the fact that a few large firms capitulated to Trump rather than fight the orders against them.

It is critical that the cybersecurity community now join together to denounce this chilling attack on free speech and rally behind Krebs and SentinelOne rather than cowering because they fear they will be next

The White House must not be given free reign to turn cybersecurity professionals into political scapegoats. EFF regularly defends the infosec community, protecting researchers through education, legal defense, amicus briefs, and involvement in the community with the goal of promoting innovation and safeguarding their rights, and we call on its ranks to join us in defending Chris Krebs and SentinelOne. An independent infosec community is fundamental to protecting our democracy, and to the profession itself.

Jason Kelley

【例会お知らせ】問題あり!開発企業優先で進む旧横j浜市庁舎の跡地利用 4月26日(土)午後2時から4時 かながわ県民センター=JCJ神奈川支部

1 month 1 week ago
 シックな外観が市民に愛された旧横浜市庁舎。近代建築で有名な村野藤吾氏が設計した歴史的な建造物です。ここを三井不動産に売却して、星野リゾートがホテルとして利用するという計画は大きく報道されました。しかし、関内駅前の一等地が77年間にわたり年2億円で貸し出さること、本来の賃料の相場は5億円を超えることなどは殆ど知られていません。しかも市庁舎の建物費7700万円と15億円以上になる改修費は、賃料から差し引かれます。 また隣には三井不動産が高層ビルを建てています。関内地区は高さ制限..
JCJ

[B] 「半年ぶりに国連西サハラ特使の安保理報告」「西サハラ最新情報」  平田伊都子

1 month 1 week ago
ガザ、レバノン、シリア、スーダン、コンゴ、、国連安保理は毎日、血まみれの戦争対応に追われています。 安保理の命を受けたスタファン・デ・ミストラ国連西サハラ事務総長個人特使は、2年前から、安保理メンバーに西サハラの窮状を訴える好機を狙ってきました。 が、安保理は、イスラエルとアメリカが次から次へと撃ちだす魔弾に翻弄され、ますます西サハラから遠のいてきました。 そんな中、安保理に義務付けられた半年に一度の報告をするため、デ・ミストラ国連西サハラ事務総長個人特使は、現地巡りをしました。 <西サハラ紛争>非公開協議は、4月14日午前9時に予定されています。 が、緊急事態が生じたら、予定は未定になります。
日刊ベリタ

【報告】被団協ノーベル平和賞受賞式 証言の重み伝える責任 取材記者囲み報告集会=田中伸武(広島支部)

1 month 1 week ago
            参加者が核・平和報道のあり方を意見交換した。 JCJ広島支部は2月24日、広島市内で「ノーベル平和賞 現地取材記者による報告―これからのヒロシマ報道を考える」と題した集会を開いた。日本被団協の授賞式(12月10日・オスロ)に同行した広島の若手新聞・放送記者ら4人が「現地行事を追いながら田中熙巳代表委員のスピーチの重みや報じる責任をかみしめた」などと語った。マスコミ関係者や高校新聞部員を含む約40人が参加。核・平和報道の在り方をめぐっても意見交換し、交流..
JCJ

レイバーネット第213回放送「むらの貧困とまちの貧困をつなぐー「令和の百姓一揆」を世直しに」を見て/黒鉄好

1 month 1 week ago
今回の放送は、私としては珍しく、生で始めから終わりまで見ました。レイバーネットTVの放送がある水曜日は、職場がノー残業デーのため、いろいろな私用が入ることが多く、生で見られるときは多くありません。ただ、私にとって農業・農政問題は公共交通、原発と並んで「3大重点分野」。生視聴しないわけにいきませんでした。令和の百姓一揆での菅野芳秀さんのスピーチ動画は、あちこちにアップされています。それを聴いて私は、今ではほとんど死語になってしまった感のある「篤農」という言葉を思い出しました。パルシステム生協と提携し「先に販路を開拓しておいてから、安全なものを高く買ってもらう」という菅野さんたち山形・置賜農民の農薬空中散布反対運動の話は、「大義を振りかざしては負けてばかりいる」「清く正しく美しく闘いさえすれば、散ってもいいのだ」といわんばかりの昨今の市民運動をどう変えていけばいいかについて、極めて示唆的な回答となるものでした。(黒鉄好)

Certbot 4.0: Long Live Short-Lived Certs!

1 month 1 week ago

When Let’s Encrypt, a free certificate authority, started issuing 90 day TLS certificates for websites, it was considered a bold move that helped push the ecosystem towards shorter certificate life times. Beforehand, certificate authorities normally issued certificate lifetimes lasting a year or more. With 4.0, Certbot is now supporting Let’s Encrypt’s new capability for six day certificates through ACME profiles and dynamic renewal at:

  • 1/3rd of lifetime left
  • 1/2 of lifetime left, if the lifetime is shorter than 10 days

There’s a few, significant reasons why shorter lifetimes are better:

  • If a certificate's private key is compromised, that compromise can't last as long.
  • With shorter life spans for the certificates, automation is encouraged. Which facilitates robust security of web servers.
  • Certificate revocation is historically flaky. Lifetimes 10 days and under prevent the need to invoke the revocation process and deal with continued usage of a compromised key.

There is debate on how short these lifetimes should be, but with ACME profiles you can have the default or “classic” Let’s Encrypt experience (90 days) or start actively using other profile types through Certbot with the --preferred-profile and --required-profile flags. For six day certificates, you can choose the “shortlived” profile.

These new options are just the beginning of the modern features the ecosystem can support and we are glad to have dynamic renewal times to start leveraging a more agile web that facilitates better security and flexible options for everyone. Thank you to the community and the Certbot team for making this happen!

UPDATE (05/02/2025): To clear up any confusion, Certbot offers support for these profiles but Let's Encrypt plans to have this feature fully available by the end of this year.

Love ♥️ Certbot as much as us? Donate today to support this work.

Alexis Hancock