Choosing a safe conferencing tool in the era of mass telework – Federal News Network
Best listening experience is on Chrome, Firefox or Safari. Subscribe to Federal Drives daily audio interviews onApple PodcastsorPodcastOne.
Tom Temin: Mr. Ziring, good to have you on.
Neal Ziring:Thanks, Tom, its good to be here.
Tom Temin: Is it correct to say that even the NSA does have people teleworking? I know a lot of people need to be in the SCIFs and so forth in the intelligence community, but you do have some teleworking going on also?
Neal Ziring:Well, I cant go into detail on that, Tom. But you know, were having to react to this crisis like everyone else, and both ourselves and everyone across the national security community that we serve is trying their best to keep their workforce safe while continuing to do their vital national security missions. And collaboration is always a part of that.
Tom Temin: Sure. So lots of federal agencies from the least secure to the most secure are using all kinds of collaboration tools. Give us what are the big security requirements and considerations for these types of tools?
Neal Ziring:Sure, you know, we were watching this, we were supporting all sorts of DoD workforce efforts. And we noticed there was a vacuum in terms of guidance to help people use collaboration services securely. So, you know, we have a great deal of deep expertise here in our workforce on this. So we put together what we thought were core requirements that individuals who maybe were suddenly trying to work from home or from some remote location could pick up and use to choose a collaboration service that would meet their own security needs. For example, does it use good encryption? Does it have ability to use multi factor authentication, can the user see and control who connects? These are all very important requirements for selecting a service that youre going to use for government work.
Tom Temin: Because you have a list of about seven cybersecurity aspects of these encryption, two different levels of encryption and so on, and theres a yes or no according to each one are there any particular characteristics that if they get a no at, that product would be just simply ruled out all together?
Neal Ziring:Well, we didnt want to go there. We didnt want to be prescriptive because the needs of different agencies vary widely. We wanted to inform folks across the national security spectrum of which requirements they should consider. I dont think any of them are sort of showstoppers in that sense. Theyre all reasonably important, and theyre going to vary between different folks. For example, there are some folks in DoD I know where the authentication is a very important concern for them. So for them, criterion number three use a multi-factor authentication will be vital. And we just wanted to inform them and have a representative list of products its not a comprehensive list showing what they should consider and what they should ask of the products that they start to use.
Tom Temin: Basically, it looks like the only thing that doesnt encrypt or use multi factor authentication or do anything is plain old SMS text, which is not really a brand, but thats what everybodys got on their phones.
Neal Ziring:Yeah, we threw that in as a comparison. Were really hoping people will choose to use more secure means than their SMS.
Tom Temin: And then coming up with the list and the different ratings for the different yes or no answers on the different aspects of security on these products, did you just get that from the product literature? Or did you test them?
Neal Ziring:For the most part, we got it from the product literature, because we noticed this vacuum. We had received multiple sort of time sensitive requests from customers across Dod and other national security establishments saying, Hey, we need some help here. So we got together a team of folks. We did some testing and a whole lot of reading of product literature under conditions emulating what a teleworking user would face. And then we put these together and we invite the folks who maintain these systems, if they spot an inaccuracy in what weve published then they can write to us, and we will correct it. Weve already gone through one round of revision.
Tom Temin: Got it. Were speaking with Neal Ziring, the technical director of the Cybersecurity Directorate at the National Security Agency. And have you heard from any agencies that said, Hey, this happened to us with this particular product, you better be aware of that potential?
Neal Ziring:No, we havent received reports of actual incidents. We have had several national security organizations write to us and say the guidance is helpful and asking additional technical questions. Thats pretty standard for us.
Tom Temin: Sure. And I have a question about these products, too. Suppose someone in a national security situation is teleworking and collaborating over these and lets postulate that no data is being exchanged. Say no documents or something would be exchanged back and forth in that manner. Because it may be against the rules, and depending on the sensitivity of the data, but people are talking. If they were to be talking about something that could be classified or make a reference is one of the issues that voice could be somehow obtained by a third party thats not authorized?
Neal Ziring:Yeah, thats certainly a concern for this category of product, right. Now, we do caution folks to think about what theyre saying over these systems. These are unclassified systems. And so they shouldnt be talking classified over them in any case. But yeah, thats why criterion number one is important, for example, right? Is this something that employs encryption, so that if theres somebody who can see that traffic, then theyre not going to see anything but ciphertext. Thats a very important part of selecting a secure collaboration service.
Tom Temin: Let me ask you this. If you could design a ideal product in terms of cybersecurity for collaboration, what would it look like?
Neal Ziring:Oh, I think it would, it would look a lot Like some of the commercial products that are out there, now, theres some really good ones. It should implement strong encryption, and that encryption should meet published encryption standards. It should support multi-factor authentication. A really important aspect is transparency, the service should let you see who is connected, see where its connecting through. Allow you to see what data you have stored in the service and delete it. And also whether the service provider is going to be sharing data about you or your usage with any third parties. Thats a concern as well.
Tom Temin: And one of the criteria is whether the source code is shared, the public source code is shared. What is the consideration there? Why is that important?
Neal Ziring:Yeah, that is that is criterion number seven. And thats an aspect of transparency, right that lets reviewers or potentially someone like NSA, examine how the product is implementing its security and see that that is being done correctly.
Tom Temin: Theres probably some good guidance for the vendors. Theres one here called Signal which Im not familiar with, but it gets yess on all of the criteria, except FedRAMP. It seems like that company ought to go for its FedRAMP certification.
Neal Ziring:Well, I would encourage any companies that want to provide service of this kind to the federal government to consider FedRAMP. I was there when they started FedRAMP. I think its a great program. FedRAMP is important because in gaining a FedRAMP certification, a company needs to thoroughly document how their security works and how its provided. And then the federal government can have more faith or more assurance when theyre utilizing that service.
Tom Temin: With respect to video, does video add cybersecurity risk in general to the use of these products?
Neal Ziring:I dont think it adds risks in and of itself. For some of the products, using video may affect whether you get to use encryption or not. So thats an important consideration but no, otherwise, go ahead and do the video. Its fine.
Tom Temin: All right. Neal Ziring is technical director of the Cybersecurity Directorate at the National Security Agency. Thanks so much for joining me.
Neal Ziring:Thank you, Tom.
Continue reading here:
Choosing a safe conferencing tool in the era of mass telework - Federal News Network
- NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity - National Security Agency (.gov) - September 2nd, 2026 [September 2nd, 2026]
- NSA and FBI Warn Chinese Hackers Are Actively Targeting US Critical Infrastructure - LinkedIn - September 2nd, 2026 [September 2nd, 2026]
- UP firecracker blast toll climbs to 13; NSA invoked against accused - Daily Pioneer - September 2nd, 2026 [September 2nd, 2026]
- Man Accused of Impersonating Chief Justice Roberts, NSA Agent - Bloomberg Law News - August 25th, 2026 [August 25th, 2026]
- I Worked For The NSA For Years. Here's What Happened To My Life After Donald Trump And DOGE Showed Up Last Year. - HuffPost - August 25th, 2026 [August 25th, 2026]
- NSA isnt complying with federal laws on whistleblower protections, IG finds - Federal News Network - August 25th, 2026 [August 25th, 2026]
- NSA Doval says India-China ties 'returning to normalcy' as he holds key talks with Wang Yi on border issue - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- 4 Ways Tim Kosiba and the NSA Are Countering the Chinese Intelligence Threat - GovCon Wire - August 25th, 2026 [August 25th, 2026]
- Man charged with forging Chief Justice John Robertss signature, impersonating NSA agent - Yahoo - August 25th, 2026 [August 25th, 2026]
- NSA Doval to visit China on Monday to attend Special Representatives talks with FM Wang - The Economic Times - August 25th, 2026 [August 25th, 2026]
- Audit Finds Lack of Oversight of NDAs at NSA - FEDweek - August 25th, 2026 [August 25th, 2026]
- Redefining India-China Relations: NSA Dovals Visit to Beijing May Provide the Breakthrough - Raksha Anirveda - August 25th, 2026 [August 25th, 2026]
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology - The Record from Recorded Future News - August 25th, 2026 [August 25th, 2026]
- NSA Doval meets Chinese Vice President Han Zheng ahead of border talks - The Tribune - August 25th, 2026 [August 25th, 2026]
- India-China ties normalised by peace on border, says NSA Doval at talks with Wang Yi - Firstpost - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds 25th India-China border talks with Wang Yi - timesofindia.indiatimes.com - August 25th, 2026 [August 25th, 2026]
- NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs - Security Affairs - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval arrives in Beijing, set for border talks with Chinas Wang Yi on August 25 - The Hindu - August 25th, 2026 [August 25th, 2026]
- NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs - finance.biggo.com - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds talks with Chinese FM Wang Yi on boundary issue - News On AIR - August 25th, 2026 [August 25th, 2026]
- NSA Doval in Beijing for Talks with Chinese FM - Kashmir Observer - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold India-China boundary talks with Wang Yi in Beijing - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold border talks with Chinese Foreign Minister Wang on Tuesday - The Tribune - August 25th, 2026 [August 25th, 2026]
- Ayitey Powers Arrested Over Alleged Death Threat Against NSA Boss - Modern Ghana - August 25th, 2026 [August 25th, 2026]
- NSA Doval arrives in Beijing for talks with Chinese FM Wang Yi on boundary issue - ThePrint - August 25th, 2026 [August 25th, 2026]
- Police arrest former boxer Ayitey Powers over alleged death threat on NSA boss - Ghanaian Times - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval in Beijing for boundary talks - Awaz The Voice - August 25th, 2026 [August 25th, 2026]
- ID Based on Anonymous Informant, Sudden Reference to 2009 Home Ministry Notification: Why NSA Case Against Satyam Verma Is Unconvincing - TheWire.in - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval: India's Strength Infused with Tolerance Amid Military Actions - India News Network - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval Reveals Operation Sindoor Strategy in New Discovery Docuseries - Daily Pioneer - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval on Operation Sindoor: 'India can hit hard, irrespective of consequences' - wionews.com - August 16th, 2026 [August 16th, 2026]
- Indias generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Op Sindoor - The Tribune - August 14th, 2026 [August 14th, 2026]
- 'Don't mistake India's generosity with weakness': NSA Ajit Doval on Operation Sindoor - The Times of India - August 14th, 2026 [August 14th, 2026]
- India's generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Operation Sindoor - The Hindu - August 14th, 2026 [August 14th, 2026]
- Former NSA Chief Gen. Paul Nakasone: AI Is Changing the Cyber Battlefield - The Cipher Brief - August 14th, 2026 [August 14th, 2026]
- NSA Doval says Indias restraint should not be mistaken for weakness - Awaz The Voice - August 14th, 2026 [August 14th, 2026]
- NSA Ajit Doval says India can hit hard irrespective of consequences in first post-Sindoor interview - The Economic Times - August 14th, 2026 [August 14th, 2026]
- Man claiming to be undercover agent of NSA Ajit Doval arrested in Bihar - The Hindu - August 14th, 2026 [August 14th, 2026]
- Indias tolerance should not be mistaken for weakness; can take risks, hit hard: NSA Doval on Op Sindoor - The Kashmir Horizon - August 14th, 2026 [August 14th, 2026]
- Indias Tolerance Not a Sign of Weakness: NSA Ajit Doval on Operation Sindoor - The CSR Journal - August 14th, 2026 [August 14th, 2026]
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware - National Security Agency (NSA) (.gov) - August 12th, 2026 [August 12th, 2026]
- Your router is probably vulnerable to the same attacks the NSA just warned about - MakeUseOf - August 12th, 2026 [August 12th, 2026]
- Trump has to accept hes going to lose Iran war: Former deputy NSA - MS NOW - August 12th, 2026 [August 12th, 2026]
- NSA installs DHS lawyer as new general counsel - The Record from Recorded Future News - August 12th, 2026 [August 12th, 2026]
- Manipur to invoke NSA against NH extortionists: Min - The Times of India - August 12th, 2026 [August 12th, 2026]
- Spymaster United States Joshua Rudd, US special forces officer nursing NSA back to health - Intelligence Online - July 7th, 2026 [July 7th, 2026]
- Capability, Not Compute: NSA Discretion in the Frontier AI EO - The Well News - July 7th, 2026 [July 7th, 2026]
- NSA partners with dog walking app to tackle livestock worrying - Agriland UK - July 1st, 2026 [July 1st, 2026]
- Youth Round Table Discussion: Youth round table discussion held at NSA - Myanmar International TV - July 1st, 2026 [July 1st, 2026]
- NSA welcomes Farming Roadmap 2050 and says farmers are ready to meet the challenge - Meat Management - July 1st, 2026 [July 1st, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - Yahoo Tech - June 22nd, 2026 [June 22nd, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - BeInCrypto - June 22nd, 2026 [June 22nd, 2026]
- Its more than Iran could have ever hoped for: Ex-US NSA John Bolton on US-Iran deal - Firstpost - June 22nd, 2026 [June 22nd, 2026]
- Manipur slaps NSA on youth already held under UAPA. Why HC quashed both cases, ordered his release - ThePrint - June 22nd, 2026 [June 22nd, 2026]
- Algorand Post-Quantum Security by 2027: 3 Years Ahead of NSA - The Cryptonomist - June 22nd, 2026 [June 22nd, 2026]
- China foreign minister set to attend Brics NSA meet in Delhi next week - The Times of India - June 22nd, 2026 [June 22nd, 2026]
- India to host BRICS NSA meet on June 2223: MEA - Awaz The Voice - June 22nd, 2026 [June 22nd, 2026]
- IDR Final Rule updates NSA dispute resolution | United States | Global law firm - Norton Rose Fulbright - June 16th, 2026 [June 16th, 2026]
- Where Is Edward Snowden Now? What to Know About the NSA Whistleblower's Life in Exile, 13 Years Later - People.com - June 16th, 2026 [June 16th, 2026]
- Former NSA official: 'Timing couldn't have been worse' for FISA 702 to expire - WBFF - June 16th, 2026 [June 16th, 2026]
- SHAREHOLDER ALERT: The M&A Class Action Firm Continues to Investigate the Merger--CZNL, NSA, CNBN, and ESQ - PR Newswire - June 16th, 2026 [June 16th, 2026]
- Training, teamwork, and quick action save a life at NSA Philadelphia - MilitaryNews.com - June 12th, 2026 [June 12th, 2026]
- NSA Insurance celebrates 100 years of selling a promise on the East End - The Suffolk Times - June 12th, 2026 [June 12th, 2026]
- Ex Pakistan NSA Moeed Yusuf says fixing ties with India key to economic revival, regional trade ambitions - ThePrint - June 12th, 2026 [June 12th, 2026]
- RSABI's Carol McLaren wins NSA Silver Salver for her work in the industry - The Scottish Farmer - June 12th, 2026 [June 12th, 2026]
- Anthropic's Mythos model is reportedly powering NSA offensive cyber ops against China and Iran - the-decoder.com - June 7th, 2026 [June 7th, 2026]
- NSA taps three officials for top cybersecurity positions - Nextgov/FCW - June 7th, 2026 [June 7th, 2026]
- Anthropic is blacklisted by the Pentagon and being used by the NSA at the same time - TechSpot - June 7th, 2026 [June 7th, 2026]
- NSA said to be readying Anthropics Mythos for use in cyber operations - TechCrunch - June 5th, 2026 [June 5th, 2026]
- Former NSA John Bolton to plead guilty to retaining classified info - MS NOW - June 5th, 2026 [June 5th, 2026]
- Trump executive order on AI gives central role to NSA - Breaking Defense - June 5th, 2026 [June 5th, 2026]
- Anthropic Is Helping the NSA Hack China. It Also Wants Everyone to Pause AI - Yahoo - June 5th, 2026 [June 5th, 2026]
- NSA using Claude Mythos for 'offensive cyber operations,' report claims says 'half-a-dozen' Anthropic engineers embedded inside the agency - Tom's... - June 5th, 2026 [June 5th, 2026]
- NSA selects new leads for key cybersecurity posts - The Record from Recorded Future News - June 5th, 2026 [June 5th, 2026]
- NSA Joins CISA and Partners to Release Guidance on Hardening Automatic Tank Gauge Systems - National Security Agency (NSA) (.gov) - June 5th, 2026 [June 5th, 2026]
- FT: Anthropic staff helping the NSA use Mythos for offensive cyberattacks - Sherwood News - June 5th, 2026 [June 5th, 2026]
- Anthropic Is Helping the NSA Hack China. It Also Wants Everyone to Pause AI - Decrypt - June 5th, 2026 [June 5th, 2026]
- Anthropic Embeds Engineers at NSA to Deploy Mythos AI for Offensive Cyber Operations - MLQ.ai - June 5th, 2026 [June 5th, 2026]
- The NSA has all the equipment and technology needed to track bandits but lacks the political will to do so -Stephen alleges Watch full interview:... - June 5th, 2026 [June 5th, 2026]
- Anthropic aids NSA with Mythos to bolster offensive cyber operations - CHOSUNBIZ - Chosunbiz - June 5th, 2026 [June 5th, 2026]