Can Technology Protect Americans from International Cybercriminals?
Total Page:16
File Type:pdf, Size:1020Kb
CAN TECHNOLOGY PROTECT AMERICANS FROM INTERNATIONAL CYBERCRIMINALS? JOINT HEARING BEFORE THE SUBCOMMITTEE ON OVERSIGHT & SUBCOMMITTEE RESEARCH AND TECHNOLOGY COMMITTEE ON SCIENCE, SPACE, AND TECHNOLOGY HOUSE OF REPRESENTATIVES ONE HUNDRED THIRTEENTH CONGRESS SECOND SESSION MARCH 6, 2014 Serial No. 113–67 Printed for the use of the Committee on Science, Space, and Technology ( Available via the World Wide Web: http://science.house.gov U.S. GOVERNMENT PRINTING OFFICE 88–137PDF WASHINGTON : 2014 For sale by the Superintendent of Documents, U.S. Government Printing Office Internet: bookstore.gpo.gov Phone: toll free (866) 512–1800; DC area (202) 512–1800 Fax: (202) 512–2104 Mail: Stop IDCC, Washington, DC 20402–0001 COMMITTEE ON SCIENCE, SPACE, AND TECHNOLOGY HON. LAMAR S. SMITH, Texas, Chair DANA ROHRABACHER, California EDDIE BERNICE JOHNSON, Texas RALPH M. HALL, Texas ZOE LOFGREN, California F. JAMES SENSENBRENNER, JR., DANIEL LIPINSKI, Illinois Wisconsin DONNA F. EDWARDS, Maryland FRANK D. LUCAS, Oklahoma FREDERICA S. WILSON, Florida RANDY NEUGEBAUER, Texas SUZANNE BONAMICI, Oregon MICHAEL T. MCCAUL, Texas ERIC SWALWELL, California PAUL C. BROUN, Georgia DAN MAFFEI, New York STEVEN M. PALAZZO, Mississippi ALAN GRAYSON, Florida MO BROOKS, Alabama JOSEPH KENNEDY III, Massachusetts RANDY HULTGREN, Illinois SCOTT PETERS, California LARRY BUCSHON, Indiana DEREK KILMER, Washington STEVE STOCKMAN, Texas AMI BERA, California BILL POSEY, Florida ELIZABETH ESTY, Connecticut CYNTHIA LUMMIS, Wyoming MARC VEASEY, Texas DAVID SCHWEIKERT, Arizona JULIA BROWNLEY, California THOMAS MASSIE, Kentucky MARK TAKANO, California KEVIN CRAMER, North Dakota ROBIN KELLY, Illinois JIM BRIDENSTINE, Oklahoma RANDY WEBER, Texas CHRIS COLLINS, New York VACANCY SUBCOMMITTEE ON OVERSIGHT HON. PAUL C. BROUN, Georgia, Chair F. JAMES SENSENBRENNER, JR., DAN MAFFEI, New York Wisconsin ERIC SWALWELL, California BILL POSEY, Florida SCOTT PETERS, California KEVIN CRAMER, North Dakota EDDIE BERNICE JOHNSON, Texas LAMAR S. SMITH, Texas SUBCOMMITTEE ON RESEARCH AND TECHNOLOGY HON. LARRY BUCSHON, Indiana, Chair STEVEN M. PALAZZO, Mississippi DANIEL LIPINSKI, Illinois MO BROOKS, Alabama FEDERICA WILSON, Florida RANDY HULTGREN, Illinois ZOE LOFGREN, California STEVE STOCKMAN, Texas SCOTT PETERS, California CYNTHIA LUMMIS, Wyoming AMI BERA, California DAVID SCHWEIKERT, Arizona DEREK KILMER, Washington THOMAS MASSIE, Kentucky ELIZABETH ESTY, Connecticut JIM BRIDENSTINE, Oklahoma ROBIN KELLY, Illinois CHRIS COLLINS, New York EDDIE BERNICE JOHNSON, Texas LAMAR S. SMITH, Texas (II) C O N T E N T S March 6, 2014 Page Witness List ............................................................................................................. 2 Hearing Charter ...................................................................................................... 3 Opening Statements Statement by Representative Paul C. Broun, Chairman, Subcommittee on Oversight, Committee on Science, Space, and Technology, U.S. House of Representatives .................................................................................................... 9 Written Statement ............................................................................................ 9 Statement by Representative Dan Maffei, Ranking Minority Member, Sub- committee on Oversight, Committee on Science, Space, and Technology, U.S. House of Representatives ............................................................................ 10 Written Statement ............................................................................................ 10 Statement by Representative Larry Bucshon, Chairman, Subcommittee on Research and Technology, Committee on Science, Space, and Technology, U.S. House of Representatives ............................................................................ 11 Written Statement ............................................................................................ 11 Statement by Representative Daniel Lipinski, Ranking Minority Member, Subcommittee on Research and Technology, Committee on Science, Space, and Technology, U.S. House of Representatives ............................................... 12 Written Statement ............................................................................................ 12 Written statement by Representative Eddie Bernice Johnson, Ranking Mem- ber, Committee on Science, Space, and Technology, U.S. House of Rep- resentatives ........................................................................................................... 13 Witnesses: Dr. Charles H. Romine, Director, Information Technology Laboratory, Na- tional Institute of Standards and Technology Oral Statement ................................................................................................. 14 Written Statement ............................................................................................ 17 Mr. Bob Russo, General Manager, Payment Card Industry Security Standards Council, LLC Oral Statement ................................................................................................. 26 Written Statement ............................................................................................ 28 Mr. Randy Vanderhoof, Executive Director, Smart Card Alliance Oral Statement ................................................................................................. 35 Written Statement ............................................................................................ 37 Mr. Justin Brookman, Director, Consumer Privacy, Center for Democracy & Technology Oral Statement ................................................................................................. 51 Written Statement ............................................................................................ 54 Mr. Steven Chabinsky, Senior Vice President of Legal Affairs, CrowdStrike, Inc.; Former Deputy Assistant Director, Federal Bureau of Investigation – Cyber Division Oral Statement ................................................................................................. 65 Written Statement ............................................................................................ 67 Discussion ................................................................................................................. 75 (III) IV Page Appendix I: Answers to Post-Hearing Questions Dr. Charles H. Romine, Director, Information Technology Laboratory, Na- tional Institute of Standards and Technology ................................................... 86 Mr. Bob Russo, General Manager, Payment Card Industry Security Standards Council, LLC ......................................................................................................... 91 Mr. Randy Vanderhoof, Executive Director, Smart Card Alliance ...................... 97 Mr. Justin Brookman, Director, Consumer Privacy, Center for Democracy & Technology ........................................................................................................ 107 Mr. Steven Chabinsky, Senior Vice President of Legal Affairs, CrowdStrike, Inc.; Former Deputy Assistant Director, Federal Bureau of Investigation – Cyber Division ................................................................................................... 112 CAN TECHNOLOGY PROTECT AMERICANS FROM INTERNATIONAL CYBERCRIMINALS? THURSDAY, MARCH 6, 2014 HOUSE OF REPRESENTATIVES, SUBCOMMITTEES ON OVERSIGHT & RESEARCH AND TECHNOLOGY COMMITTEE ON SCIENCE, SPACE, AND TECHNOLOGY, Washington, D.C. The Subcommittees met, pursuant to call, at 9:36 a.m., in Room 2318 of the Rayburn House Office Building, Hon. Paul Broun [Chairman of the Subcommittee on Oversight] presiding. (1) 2 3 4 5 6 7 8 9 Chairman BROUN. Good morning, everyone. This joint hearing of the Subcommittee on Oversight and the Subcommittee on Research and Technology will come to order. Again, good morning and welcome to today’s joint hearing. In front of you are packets containing the written testimony, biog- raphies, and truth-in-testimony disclosures for today’s witnesses. Before we get started, since this is a joint hearing involving two Subcommittees, I want to explain how we will all operate proce- durally so all Members understand how the question-and-answer period will be handled. We will recognize those Members present at the gavel in order of seniority on the full Committee, and those coming in after the gavel will be recognized in order of arrival. Now, for the sake of time, in lieu of giving my statement, I will enter it into the record at this point. [The prepared statement of Mr. Broun follows:] PREPARED STATEMENT OF SUBCOMMITTEE ON OVERSIGHT CHAIRMAN PAUL BROUN Good morning. Let me begin by extending a warm welcome to our witnesses and thank you all for appearing. I especially appreciate everyone’s patience and flexi- bility—witnesses and Members alike—in making themselves available today given the weather interruption earlier this week. Today’s hearing is titled ‘‘Can Technology Protect Americans from International Cybercriminals?’’ I hope you can all help us more fully answer that question and explore what specifically is being done to secure U.S. IT infrastructure. On the one hand, we are here this morning to review what appears to be a rash of recent attacks and successful breaches of American IT infrastructure and com- puter networks: Target; Neiman Marcus; Easton Sports; Michaels Stores; the Uni- versity of Maryland; Blue Cross Blue Shield in New Jersey; and now maybe even Sears!