Congress puts the head of LimeWire back in the hot seat

By Scott M. Fulton, III | Published April 22, 2009, 7:20 PM

During Congressional hearings back in July 2007, legislators were astounded by high-profile testimony from former NATO Supreme Commander Gen. Wesley Clark, revealing that federal employees who had installed the P2P software LimeWire on their computers inadvertently shared classified government materials with other LimeWire users, in many cases without those users even requesting the material.

But sidestepping the entire question of why P2P file-sharing software was installed on government computers in the first place, Rep. Darrell Issa (R - Calif.), the ranking member of the House Oversight and Government Reform Committee, quizzed Lime Group Chairman Mark Gorton about his personal responsibility for the security breaches. Calling him the "elephant in the room," Rep. Issa asked, "Are you prepared here today to say you're going to make significant changes in the software to help prevent this in the future?" Gorton responded, "Absolutely, and we have some in the works right now."

In light of reports since last July, some on local TV newscasts, about newly alleged security breaches believed to involve P2P software, Issa and Rep. Edolphus Towns (D - N.Y.), who now chairs the Committee, sent Gorton a questionnaire on Monday (PDF available here) asking whether LimeWire was involved in these latest incidents, and if so, when and why.

"It appears that nearly two years after your commitment to make significant changes in the software, LimeWire and other P2P providers have not taken adequate steps to address this critical problem," the Congressmen wrote. "A recent string of press reports indicates the continued availability of highly sensitive private and government information on P2P networks like LimeWire."

A check of the LimeWire changelog lists literally dozens of feature improvements and version updates for the open source P2P software since the July 2007 hearings. Last January, the team's first betas for version 5.0 began public distribution, with features that appear to improve the user interface and change the way users are shown how to manage shared folders. Version 5.1 entered beta just last month. Many of the improvements listed here could be said to address the original problem that Gen. Clark noted in his testimony: that users who didn't know what they were doing could share sensitive government files with people who didn't know they were being shared with them.

But the security breaches Reps. Towns and Issa listed center around intentional malicious use, which any number of improvements to LimeWire may not be able to fix. Nevertheless, the Congressmen pre-empted any possible response from Gorton, by sending letters to the Chairman of the Federal Trade Commission (PDF available here) and the Attorney-General (PDF available here) on the very same day, citing the same news reports and advising him that the Committee is formally reopening its investigation into LimeWire's activities.

As an aside, however, the Congressmen did think to ask the FTC Chairman, "What has the FTC done to minimize the risk of inadvertent P2P file sharing?" just in case it may have made some progress there also.

Comments

View comments by with a score of at least

Limewire & Kazaa is so low rent.

Score: 0

|

Eh?
So because a couple of employees are fat-fingered enough to have selected every bloody drive on their computer to share it is suddenly the fault of the guy making the software.

What the **** is he supposed to do about it exactly?
"Are you sure you meant to do that?"
"Are you sure?"
"Are you really ****ing sure?"
"Absolutely, positively sure?"

Score: 0

|
Below viewing threshold. Show

As usual, Paul, you miss the fundamental point which was stated with "But sidestepping the entire question of why P2P file-sharing software was installed on government computers in the first place", as such 3rd party software installation is prhibited by policy...

How they configured it utterly misses the point - as did the idiot legislators.

Score: -4

|

@foxfyre: I didn't miss the point at all. Perhaps you should look at how many people have voted down your comment to see how pointless your comment was.

I'm amused by them not only ignoring security policy of not installing Limewire (or other 3rd party apps) but then having the barefaced cheek to say it's Limewire's fault.

Score: 0

|

Why was the response to a security breach, that P2P providers didn't fix the problem. Why are we sharing government documents on a third-party client anyways? I wish I knew the department in question because I am looking for a job, looks like a position is going to open up soon.

Score: 0

|

Is stupidity a necessary qualification for election to congress?

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.