Cybersecurity Mission Creep in the US

📡 Schneier on Security · 2026-07-02

Cybersecurity Mission Creep in the US

Cybersecurity Mission Creep in the US - Schneier on Security Schneier on Security Menu Blog Newsletter Books Essays News Talks Academic About Me Search Powered by DuckDuckGo Blog Essays Whole site Subscribe Home Blog Cybersecurity Mission Creep in the US Interesting paper: “ Cybersecurity Mission Creep .” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.” Before this reframing, these issues present as important but not existential. But once cybersecuritization positions the issues as threats intensified by their technological nature, they gain access to the politics and law of urgency and exceptionalism and invite troubling governance responses. Positioned as security threats, cybersecuritized issues become endowed with the apparent normative power to override countervailing considerations, oversimplifying the problem. Cybersecuritization’s oversimplification similarly risks unidimensional solutions and invites use of argumentative trump cards, like First Amendment challenges. Cybersecuritization also invites deference to purported specialists and their proposed solutions. Together, the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque. And this opacity can erode public trust and political legitimacy. This Article surfaces the phenomenon of cybersecuritization and offers a novel framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account also demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand. Confronting cybersecuritization is crucial. If we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity. This Article’s analysis and critique aim to help reclaim the hard work of governance for our hands. Tags: academic papers , cybersecurity , national security policy Posted on July 2, 2026 at 7:11 AM • 13 Comments Comments Clive Robinson • July 2, 2026 10:25 AM @ Bruce, ALL, From the article quote, “Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity.” It’s a form of inverse “dog whistle”. We all know and now despise politicians and others trotting out, “Think of the Children” Or similar which has given them the excuse to push “Online ID” through the back door of pretending it’s “Age Verification”. Likewise “Client Side Scanning” again by the pretence of “Protecting Children”. Then there is BLE Beaconing, brought in for “contact tracing” during C19, but I’ve never directly heard from anyone it did then any good. But now it’s in Apple and Google’s OS and I’m told will be in Microsoft’s Win11. All of it does not do what is written on the Political tin or legislation. But it sure does make mass surveillance now and long into the future easy and obligatory if you want to be a part of enforced modern society. Back when UK Prime Minister Tony Blair was in power there was the, “Number ten nudge unit” https://www.lightnet.co.uk/the-nudge-unit-is-still-active-here-is-what-it-is-working-on-right-now/ It’s a form of policy enforcment not by reason and due consideration but by psychological warfare on citizens. Thus making anything “cybersecurity” is a way to hang a label like “terrorism” on public disagreement with “policy”. You will see it ramp up, until enough people can see they are being conned or manipulated, then some new label / method will be used in the, “Do as we say, not do what is rational.” r • July 2, 2026 1:26 PM new way to repackage regulatory capture. it did an excellent job with our public schools, no books! lurker • July 2, 2026 2:26 PM Harrummph, it’s even on the site hosting the paper, ssrn[dot]com. For a second or two it shows a message “performing a security check on your broser” What it actually means is it’s checking you have cookies and javascript enabled. So if they want to track their readers, OK. It’s the lying about it that I can’t stand … KC • July 2, 2026 4:25 PM Last year, Professor Fidler gave a talk on her exploration of ‘Cybersecurity Mission Creep’. There’s a good Q & A. From an audience member: “Another point that’s interesting is that for the past 10 or 15 years, we’ve been trying to tell everybody like cyber security is everywhere. And you’re telling us cyber security isn’t everywhere. But I mean, we’re talking about like it’s in your, you know, your DVD player and in your thermostat and stuff like that and it’s in your water treatment facility.” Professor Fidler: “That may be true, but it is not in your kids’ social lives. I don’t know.” […] In her published work she does talk about child social media use. She points out what she would call maximalist rhetoric from legislators about its dangers, adding social media has upsides too. To be honest, I’m not exactly sure what cyber-securitization means in this case. The urgent, existential – unnuanced and partially derailed? – focus on an internet threat? Personally, looking at the extensive integration of internet platforms in our lives, I don’t find the perspective or debate totally terrible. KC • July 2, 2026 4:33 PM The link to the Q & A. https://www.youtube.com/watch?v=nmiSIseCQgQ&t=2853s KInderGarten Level Investigating Skills • July 3, 2026 12:36 AM According to the Idaho Rules of Evidence: https://isc.idaho.gov/rules-procedure/ire#rule-1002 “An original writing, recording, or photograph is required in order to prove its content unless these rules or a statute provides otherwise. (Adopted March 26, 2018, effective July 1, 2018.)” The videos that the fake victim’s sister had supplied to the Prosecuting Attorney in the criminal case against me were in .MOV format. Arlo company, in 2021, was storing all videos in their could (on their servers) in .MP4 format ONLY. IT WAS DISCLOSED ON THEIR WEBSITE! The videos found here s h o r t u r l . at / MDvFx which are titled/captioned “JLKC0083” AND “JFLN6474” ARE BOTH IN .MOV FORMAT! T A M P E R E D WITH! If you feed both of these videos into a program called MediaInfo https://en.wikipedia.org/wiki/MediaInfo and look for details on both of them the program will show that both of them were originally ARLO CLOUD VIDEOS, thus in MP4 format and it will even give you the ARLO CLOUD ID ON BOTH OF THEM. Both videos being in Arlo Cloud and in MP4 format, WERE ACCESSED VIA Apple’s iPhone and the 10-second snippets were CUT-OUT AND SAVED ON THE iPhone in .MOV format and then submitted to the prosecutor AND USED AS SUCH AT MY JURY TRIAL. The rest of the footage that remained on Arlo’s servers, in the cloud, THE ORIGINALS WHICH SHOE THE FAKE VICTIM ATTEMPTING TO MURDER ME – THOSE WERE DELETED FROM ARLO CLOUD. Nice try MUDDIES and officers Matt Hudson, Damir Subasic, Trent Schneider, Ed Pieczonka, Chad Wigington, and prosecutor Brittany Ford. BETTER LUCK WITH YOUR NEXT VICTIM! Clive Robinson • July 3, 2026 3:03 AM @ KC, ALL, Your comment, “Last year, Professor Fidler gave a talk on her exploration of ‘Cybersecurity Mission Creep’.” A lot of things have moved on since then, but somethings remain fairly constatnt, 1, Evil goes, where Evil is allowed. 2, To succeed in a resource constrained competitive you have to ensure that rarely is a win fair gained. It forms a vicious downwards spiral. The problem people have to consider is why is “cybersecurity legislation” 1, So broad in scope. 2, So draconian in appliance. The simple fact is if you go back to the Obama era not just the general populous but nearly all legislators knew next to nothing about cybersecurity they were “running scared” because of the, “If it bleeds it leads” Yellow journalism of the MSM and idiot talking heads on 24 hour news channels, looking to create sensationalism thus feeding frenzy profits. Thus idiot politicians were happy to nod nonsense through so they appeared to be doing something. And that was the equivalent of opening the door to a vampire. But also consider the part “private prisons” play… They only make real money when they are over crowded and under staffed. Which is why it’s not really surprising that they’ve been repeatedly found to be inducing prosecutors and judges into giving out much longer sentences to what are seen as non-violent thus docile/compliant offenders. Whilst finding reasons to keep violent offenders that riot etc and need way higher thus costly staffing levels out. Because both overcrowding and minimal staff improve the profit line greatly. But as a recent new report showed having only three staff on duty for a private 90 bed “jail” overnight was the reason that the guards could he overpowered and a riot could happen, ‘https://www.witn.com/2026/07/02/sheriffs-we-dont-run-bertie-martin-regional-jail/ ‘https://apnews.com/article/jail-inmate-uprising-north-carolina-edd316a039c60ec788a93276c1c567e5 As the old saying has it, “You reep what you sow” Rontea • July 3, 2026 10:33 AM Re: “The most critical infrastructure is our cognitive infrastructure“ Our cognitive infrastructure is the foundation of every decision, every defense, and every innovation we create. If we fail to secure the way we think, analyze, and process information, all other infrastructure becomes fragile. Protecting the integrity and resilience of our minds is as critical as protecting networks and power grids, because the first breach always happens in thought. lurker • July 3, 2026 2:26 PM @Rontea “Protecting the integrity and resilience of our minds is as critical as protecting networks and power grids, because the first breach always happens in thought.” This is a fact of life. Who teaches it to our children? r • July 4, 2026 10:29 AM “if you’re a hammer everything looks like a nail.” ResearcherZero • July 5, 2026 2:44 AM Politicians should deal with cleaning up their own house, rather than weaken their own internal governance, backslide on anti-corruption, gut departments charged with upholding public safety and good governance, replace employees with loyalists in the justice and law enforcement space, and ingratiate themselves with slime balls offering up payment. Laws, sanctions and enforcement to fight, deter and prevent corruption play an essential role in preventing the further spread of corruption, which undermines public safety and national security. Once police and justice are compromised, the doors are wide open. ‘https://www.justsecurity.org/138302/corruption-sanctions-flaws-impose/ Lawsuit alleges cronyism led to White House accepting $2M from man posing as CIA agent. https://www.ndtv.com/world-news/trump-run-kennedy-center-took-2-million-from-fake-cia-operative-claims-lawsuit-11598723 The fake spy convinced government officials to let him run operations and steal millions. https://www.independent.co.uk/news/world/americas/niels-troost-fake-spy-lawsuit-russian-oil-b2899880.html ResearcherZero • July 5, 2026 2:47 AM @lurker Donald Trump. Every moment with “the Don” is a teachable moment. 😉 Clive Robinson • July 5, 2026 11:23 AM @ ResearcherZero, lurker, With regards, “Every moment with “the Don” is a teachable moment.” But a few things have to be considered, two of which are, 1, Who determines what is taught. 2, How do they teach it to the masses. Historically these two issues have caused considerable harm, and have usually failed within a couple of lifetimes. The exception appears to be part of the ages old “King Game”. A thug sets themselves up by various methods, that usually involves “Guard Labour” that is promised wealth and power and thus kept “on side”. At some point the thug or their advisors realise that the only organisation that can do the “teaching to the masses” is “the Church” and all it’s willing supplicants, in every village, town and city. So a very unholy alliance is reached in essence the church promotes the thug/king as a conduit to their deity, hence the thug becomes the “Godhead”. In return the thug gives various concessions. However the one that is most important is “succession” the thug ensures some form of continuity through “the blood” of inheritance. Ensuring control of the land and the national wealth via the Treasury goes to a close relative. In the church however succession is all about what we would call “Politics”. Thus giving even the lowest born the ability to rise to a place of power. Part of this has always been about the control of “ideas” selectively. Even today there are religions that are better called Cults. Where power over resources and fertility are granted to the leader and closest ring of advisors only. It’s why religion takes a great deal of care to keep women in a subservient place as “breaders” and indoctrinating their young whilst their minds are incapable of withstanding it… Subscribe to comments on this entry Leave a comment Cancel reply Blog moderation policy Login Name Email URL: Remember personal info? Fill in the blank: the name of this blog is Schneier on ___________ (required): Comments: Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/ Notify me of follow-up comments by email. Notify me of new posts by email. Δ ← Papa Johns Surveillance-Based Advertising Flock Cameras Can Surveil Cars Without License Plates → Sidebar photo of Bruce Schneier by Joe MacInnis. Powered by WordPress Hosted by Pressable About Bruce Schneier I am a public-interest technologist , working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998. I'm a fellow and lecturer at Harvard's Kennedy School , a board member of EFF , and the Chief of Security Architecture at Inrupt, Inc. This personal website expresses the opinions of none of those organizations. Contact Info Related Entries Anthropic's Fable and the State of AI Hacking Meta's AI Chatbot The Intersection of Encryption and AI Vulnerability Disclosure in the Age of AI CISA Security Leak Featured Essays Four Ways AI Is Being Used to Strengthen Democracies Worldwide The CrowdStrike Outage and Market-Driven Brittleness How Online Privacy Is Like Fishing How AI Will Change Democracy Seeing Like a Data Structure LLMs’ Data-Control Path Insecurity AI and Trust The Value of Encryption The Eternal Value of Privacy Terrorists Don't Do Movie Plots More Essays Blog Archives Archive by Month 100 Latest Comments Blog Tags 3d printers 9/11 A Hacker's Mind Aaron Swartz academic academic papers accountability ACLU activism Adobe advanced persistent threats advertising adware AES Afghanistan AI air marshals air travel airgaps al Qaeda alarms algorithms alibis Amazon Android anonymity Anonymous antivirus Apache Apple More Tags Latest Book More Books Blog Newsletter Books Essays News Talks Academic About Me


📌 来源: Schneier on Security | 📅 2026-07-02

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)