Showing posts with label National Security Agency. Show all posts
Showing posts with label National Security Agency. Show all posts

Tuesday, June 6, 2017

Leaker Reality Winner Is No Winner At Leaking!

Reality Winner poses in a photo from her Instagram account.
Reality Winner before being busted by Feds for leaking classified documents.

As the self-righteous Right's paper patriots and Trumpies go bananas over the arrest of NSA leaker Reality Leigh Winner it is well to consider this:  the winsome young Millennial was not the sharpest knife in the drawer. At least when it came to the actual method of her accessing the document she leaked.  Ax reported now by numerous news sources with access to the documents, Russian intelligence agents hacked a US voting systems manufacturer in the weeks leading up to last year’s presidential election, according to the Intercept, citing what it said was "a highly classified National Security Agency (NSA) report".  (This was the selfsame report Winner leaked).

Any other savvy NSA contractor, or Edward Snowden, could have told her you do not use an NSA-tagged printer to run off anything you plan to leak.  That's like begging to be caught or wearing a sign on your back in 8 inch letters reading: "I'm the leaker! Catch me!"

But pardon me for saying that this lack of attention to detail is often a byproduct of the idealistic Millennial generation. Their hearts are certainly in the right place - and Winner's clearly was (she was also a Bernie supporter) but their heads are often in the clouds and not processing real world details, such as how to get NSA files out into the public.

Now that Ms. Winner has failed in that, the whole anti-leaker world is in high dudgeon calling for even more heads to roll. But roll they won't because I doubt any will be as dumb as Winner - who is no winner at the leaking game.  Besides, would be leakers will now be even more on their guard, taking more precautions.

Winner, 25, was arrested Saturday in Augusta, GA.  She held a top secret clearance at a government facility where she worked as a contractor - like Edward Snowden. Her contract company was Pluribus International Corporation. The DOJ alleges that Winner printed out the classified document, dated May 5th, and she admitted to removing, retaining and mailing it.

Contrast this with Edward Snowden's putative method (depicted in the movie, 'Snowden') whereby he carefully and sequentially first downloaded the files (XKeyscore, PRISM etc.)  onto an SD card, and then hid it within a tile of a  Rubik's cube. He then, on exiting the Oahu NSA Center, avoids running the Rubik's cube through security by tossing it by tossing it to a security guard who then plays with it - no remote idea it contains hidden files on an SD card. Meanwhile, Snowden - clean as a whistle - passes through the security screening without a hitch.

Had Winner seen the Oliver Stone movie, she'd have processed the extreme precautions needed to smuggle anything out of an NSA facility. Now, to be sure, the depiction in the film was just that - a fictional portrayal - and Snowden has never described how he actually did it. (Director Oliver Stone told The Daily Beast that he doesn’t actually know how Snowden smuggled out the information.) Never mind, we do have two items to work with:

1) Snowden did use a Rubik’s Cube to identify himself when he first met with Guardian journalist Glenn Greenwald. If he had possession of it then he could well have used it earlier.

2)  Though otherwise tight -lipped, Snowden himself hinted that there may be some truth behind the portrayal.

Most techie sites I've consulted do regard it as feasible, especially if carried out as portrayed in the film.  In any case, Snowden  - if informed of Winner's plan before she did it, would have told her in no uncertain terms to avoid using open access devices like printers. NO! NO! NO! You dummy!

Another dummy lapse: using her freaking work computer email  to make contact with the Intercept. Did she not know, or process, that all email systems on NSA - linked computers (not to mention those of most large corporations) are monitored?   My take is she may not be as stupid as her actions appear, and may simply have acted impetuously - without fully thinking her leak plan through.  This is very sad indeed, because she will now "repent at leisure", facing up to ten years in prison.

At the same time, her reckless folly has unleashed the screeching demons and harpies of the Right and the most odious, chest-pounding  Repukes (like Jason Chaffetz: "I want people in handcuffs and I want to see people behind bars!"). We will now have to listen to them as well as Trump bragging how they finally bagged a leaker(never mind an incautious one) and plan to grab many more.

The good aspect to this 'catch' of an abysmally clueless and careless leaker is that it is more than likely a one off.   Given the vile nature of the Trump presidency we need the leaks to continue now more than ever to expose these vipers as the vermin they are.  Reality Winner's foolish lapses didn't help, but I don't believe they will hurt other leaks in the long run.


Monday, July 7, 2014

Is No One Prepared to Collar the NSA and Its Zealous Overeach?

Photo: Edward Snowden receives his ACLU card.
Edward Snowden, a true patriot, receives his ACLU card from Anthony Romero.

Does the NSA even understand the meaning of the 4th amendment? Does Congress? Especially the weasel rats that signed onto the FISA Amendments Act of 2008  which ratified and expanded the warrantless surveillance program originating under Bush Jr. But rather than adhering to their sworn oaths to protect and defend the Constitution , these vermin rats legalized Bush's transgressions - thereby setting the stage for the latest outrages.

For those who may not have been paying attention, a 4-month investigation by the WaPo has found that ordinary Internet users, American and non-American alike, far outnumber legally targeted foreigners in the communications intercepted by the National Security Agency from U.S. digital networks. In other words, the so-called protective surveillance is merely an extended fishing expedition that often scarfs up incidental private material of average Americans.

Most pertinent: Nine of 10 internet account holders found in a large cache of intercepted conversations, which former NSA contractor Edward Snowden provided in full to The Post, were not the intended surveillance targets but were caught in a net the agency had cast for somebody else.

What sort of stuff was caught? According to the Post:


"Medical records sent from one family member to another, résumés from job hunters and academic transcripts of schoolchildren. In one photo, a young girl in religious dress beams at a camera outside a mosque.   Scores of pictures show infants and toddlers in bathtubs, on swings, sprawled on their backs and kissed by their mothers. In some photos, men show off their physiques. In others, women model lingerie, leaning suggestively into a webcam or striking risque poses in shorts and bikini tops."


Can this even be believed? I mean, this is insight into an agency gone rogue and even crazy!

Taken together, the files offer an unprecedented vantage point on the changes wrought by Section 702 of the FISA amendments, which enabled the NSA to make freer use of methods that for 30 years had required probable cause and a warrant from a judge. One program, code-named PRISM, extracts content stored in user accounts at Yahoo, Microsoft, Facebook, Google and five other leading Internet companies. Another, known inside the NSA as Upstream, intercepts data on the move as it crosses the U.S. junctions of global voice and data networks. According to the Post:

"No government oversight body, including the Justice Department, the Foreign Intelligence Surveillance Court, intelligence committees in Congress or the president’s Privacy and Civil Liberties Oversight Board, has delved into a comparably large sample of what the NSA actually collects — not only from its targets but also from people who may cross a target’s path."


Let's also reference here the basis of how this crap evolved, and make reference here to Jim Sensenbrenner who co-authored the Patriot Act (with Patrick Leahy). In the Summer 2014 issue of the ACLU STAND magazine, Sensenbrenner writes:

"Section 215 was intended to give the government the ability to secure 'any tangible thing' connected to specific terrorism investigations. As is now common knowledge, the Bush and Obama administrations took the limited power Congress intended and went rogue. If we had known during any subsequent re-authorizations what we now know about Section 215's blatant misinterpretation, Congress would have allowed it to sunset.  And if it's not fixed by the 2015 re-authorization, Congress will.

The basic idea behind the American search and seizure law is that you can't investigate unless you can first provide at least some articulable reason to do so. Investigations just can't be arbitrary. The government's definition, on the other hand, is the very definition of arbitrary. "


Thus Snowden's revelations have consistently shown the extent of overreach by the NSA in its illegal mass surveillance, via assorted programs including PRISM, XKeyscore and MUSCULAR. Congress refuses to act in a substantial and coherent way (with the exception of the USA Freedom Act- which trolls like Feinstein have vowed to gut) because they see an advantage in looking the other way. Besides, most are cowards and don't want to be criticized as "unpatriotic" by the FOXite orbit.


By law, the NSA may “target” only foreign nationals located overseas unless it obtains a warrant based on probable cause from a special surveillance court. For collection under PRISM and Upstream rules, analysts must state a reasonable belief that the target has information of value about a foreign government, a terrorist organization or the spread of nonconventional weapons.

But the indiscriminate NSA net discloses "warrants based on probable cause" are mostly a contrived fiction. Most  of the people caught up in those programs were not the targets and would not lawfully qualify as such. “Incidental collection” of third-party communications is inevitable in many forms of surveillance, but in other contexts the U.S. government works harder to limit and discard irrelevant data. In criminal wiretaps, for example, the FBI is supposed to stop listening to a call if a suspect’s wife or child is using the phone. Why does the NSA get a pass or take a pass? Because as Sensenbrenner notes: "the Bush and Obama administrations took the limited power Congress intended and went rogue".


Worse, many congress critters and Senators have since signed on to this perfidy and encouraged even stronger surveillance.  Recall back in November, Feinstein tabled her own bill to counter the USA Freedom Act of Sensenbrenner and Leahy. It basically codified the ability of the National Security Agency to search its troves of foreign phone and email communications for Americans’ information, and permit law enforcement agencies to search the vast databases as well. In effect, it would both make permanent a loophole permitting the NSA to search for Americans’ identifying information without a warrant – and, formalize an ambiguity that might allow the FBI, the DEA and other law enforcement agencies to do the same thing.


In other words, it's surveillance on PCP plus crack. Multiplied "warrants" issued, all without proper cause, since such cause (under the 4th) must be attached to individual warrants. You simply cannot extract individual cause or guilt from mass, warrantless search. Once you cross that boundary you go over the precipice and become - if not already - a fascist surveillance state.  According to Michelle Richardson, the surveillance lobbyist for the ACLU:

"For the first time, the statute would explicitly allow the government to proactively search through the NSA data troves of information without a warrant.   It may also expand current practices by allowing law enforcement to directly access US person information that was nominally collected for foreign intelligence purposes. This fourth amendment back door needs to be closed, not written into stone.”


And yet, fellow citizens, that is what we are on the verge of, unless courageous people dedicated to the Constitution act and stand up on principle.

The problem is that as the hysteria over the ISIS group in Iraq increases, and "national security" again instills fear in too many, more congress critters may prefer to opt for "security" than civil liberty. In other words, another round of terrorist fear may well spark even more draconian national security dragnets with more Americans caught up in the web.

Obviously, many Americans are simply too lame or dumb to care.  And probably see nothing wrong in the Post's revelations. Wives picked up in skimpy Victoria's Secret lingerie  posing on their beds, or toddlers frolicking in bathtubs? No problem! These mock  'Muricans will simply lay down like dogs and say 'I  just wanna  be made safe from Baghdadi and ISIS, so do it some more!"   Which shows they have no grasp of the 4th amendment and probably don't deserve liberty in any case. They are an affront to what my Revolutionary War ancestor Conrad Brumbaugh fought for.

Worse, they are like the 'good Germans' who looked the other way as Hitler's Gestapo collected information on all their friends and neighbors - and they even provided extra help. Sadly, we have to share the country with these security lap dogs, as we do Neoliberal traitors to the Constitution like Dianna Feinstein and Lindsey Graham.

The true citizen can only hope that at some stage a real patriot -  or preferably patriots - stands with Edward Snowden to help collar the NSA nuts gone wild, and steer this nation back to surveillance sobriety and temperance. If not, the last vestiges of privacy will soon be a long lost memory never to be resurrected again. We will then be on our way to mutating to a full fascist state.
 
 

See also:
http://www.smirkingchimp.com/thread/robert-scheer/56797/hillary-clinton-flaunts-her-surveillance-state-baggage

Monday, March 5, 2012

The Stupidity of STUXNET

Anyone who watched the first segment of '60 Minutes' last night, would have been treated to the news (kept seemingly well concealed hitherto) of one of the most malicious pieces of software ever conceived - a worm called "Stuxnet". According to the 60 Minutes' piece, the noisome behavior of this worm eventually drew the attention of Liam O Murchu, an operations manager for Symantec, one of the largest antivirus companies in the world. As he noted in the interview:

"As soon as we saw it, we knew it was something completely different. And red flags started to go up straightaway."

Those red flags included the way this worm specifically singled out computing command and control operations protocols to take over sophisticated robotic -run systems and divert them subtly toward perdition - to the extent no one running any plant operations (mainly at Iran's nuclear processing plants) would be any the wiser. Thus the worm could carry on its destruction undetected.

In the case of Stuxnet, its malicious trail commenced in June of 2010, when it was first detected and isolated by a tiny company in Belarus after one of its clients in Iran complained about a software glitch. Subsequently, reports filtered in that Iran's centrifuges were somehow compromised, though they didn't let on that they were aware of the real culprits (which I suspect was the NSA, whose cryptological-computer-savvy 'fingerprints' are all over this. )

Meanwhile, also featured on the 60 Minutes' piece was Retired General Michael Hayden, a former head of the National Security Agency. As he talked about the damage inflicted by the worm he damned near gloated with self-satisfaction as he babbled:

"We have entered into a new phase of conflict in which we use a cyberweapon to create physical destruction, and in this case, physical destruction in someone else's critical infrastructure. This was a good idea, alright? But I also admit this was a really big idea too. The rest of the world is looking at this and saying, 'Clearly someone has legitimated this kind of activity as acceptable international conduct.' The whole world is watching."

Indeed, but WAS IT a "good idea" to bring this genie out of the bottle and introduce it to the world? Especially when the initiator -attacker nation - obviously the hubristic U.S. - believes itself beyond the range of retribution? This is the question that must be asked, especially when we have a creaky power grid that just barely functions efficiently in periods of high demand - such as this summer promises to be, what with global warming continuing its ramping up!

Evidently, Sean McGurk - former head of cyber defense at The Department of Homeland Security, in charge of protecting critical infrastructure in the U.S. - doesn't believe so. WHen interviewed last night, he pointed out (alarmingly):

"You can download the actual source code of Stuxnet now and you can repurpose it and repackage it and then, you know, point it back towards wherever it came from."

CBS' Steve Kroft then remarked: "Sounds a little bit like Pandora's box." To which McGurk responded, "Yes!"

McGurk added:

"They opened up the box. They demonstrated the capability. They showed the ability and the desire to do so. And it's not something that can be put back."

Kroft then pressed the issue, asking:

"If somebody in the government had come to you and said, "Look, we're thinking about doing this. What do you think?" What would you have told them?"

To which McGurk didn't hesitate in responding:

"I would have strongly cautioned them against it because of the unintended consequences of releasing such a code."

Kroft then surmised that one such "unintended consequence" is that this same code might be "re-purposed" and used against us. Perhaps against nuclear power plants or the power grid. Again, McGurk responded:"Yes", labeling the possible retributive cyber attack worm, "Son of Stuxnet".

But this is no laughing matter! Because of the hubristic, belligerent and arrogant actions of an enclave of pointy-headed computer geeks at the Puzzle Palace, we're likely all in jeaopardy (as we were with the Wall St. quants inventing insane credit derivatives using the Gaussian Copula formula before the financial meltdown). These sort of reckless actions do not bode well, and although their creators and the guilty agency might argue they were done with the "best intentions" , i.e. to slow down Iranian processing of nuclear fuel, we know the road to Hell is paved with them.

More than 15 years ago such malicious and aggressive cyber-actions were forecast by author Winn Schwartau in his book: 'Information Warfare:Chaos on the Electronic Superhighway', 1995, Thunder's Mouth Press. As Schwartau noted ( p. 297):

"At the pinnacle of the Information Army is what the military calls C3I: Command, Control, Communications and Intelligence (some military planners now call it C4I, adding computers into the equation) - and what business calls 'the board of directors.' This is where strategic plans are made and directives for tactical support are calculated."

Schwartau also noted that "all money comes through C3I" (or C4I as the case may be), and much may emerge from "black budgets" or off the books funded operations to retain maximal security. Such levels of security are not as typical with the CIA or DIA (Defense Intelligence Agency) but they are with the grandaddy of spookhood, the NSA, which oversees all others. (Two of the best exposes of this bunch based at Ft. Meade, MD and their methods appeared in James Bamford's book, Body of Secrets (2001), and the Baltimore Sun series: 'No Such Agency: America's Fortress of Spies', by Scott Shane and Tom Bowman, Dec. 3-15, 1995)

The different echelons of information warrior, in the Class III (global) arena include(op. cit. 298-311):

- 'Communications or C-group' - responsibility for all communications, networking aspects, including encryption schemes. They may even "use the Global Network to achieve anonymity and privacy". Also "to make interception and traffic analysis of their activities much more
difficult, convoluted routing of communications paths all over the country and the world will require C-group to be multinational."

- 'Mappers' - as the name implies, those who chart cyberspace, showing how all the connections occur - and the critical points - for future targeting of attacks.

- 'Crackers' - use special software tools to decipher passwords, or break encryption schemes, say trhereby allowing a "worm" or virus to penetrate firewalls.

- 'Sniffers' - e.g. 'sniff' out passwords using sophisticated programs, or install 'taps' to eavesdrop or monitor selected targets.

- 'Readers' - Monitor emanations from computer screens/monitors using Van Eck radiation detectors. A person can park in a specially outfitted truck (often made to look like the local phone service) and 'read' everything on your monitor screen from up to a half mile away.

- Software Development group - "duplicate field conditions reported by a mapper or cracker and then develop a reliable means to compromise it".

- 'Moles' "deploy malicious software, garner confidential information from the target, or provide valuable inside information to C3I (or C4I)."

- Analysts - as the name implies, responsible for sifting through the vast reams of information made available and separating 'signal' from 'noise'. These eggheads would've been able to assess the extent of damage inflicted by Stuxnet to the Iranian centrifuges.

- 'Public Relations Group' -will feed information to the press on a selective basis."

Readers interested in seeing the '60 Minutes' segment can find it here:

http://www.cbsnews.com/video/watch/?id=7400904n&tag=contentBody;storyMediaBox

Sadly, this reckless and pre-emptive cyber attack, obviously initiated by our country (despite all the cloak and dagger BS), may well pave the way for a much less secure world affecting all of us. Let us hope if the Russians, Chinese or anyone else - run of the mill terrorists - mount their own attacks using "Son of Stuxnet" or an even worse variant, we are prepared and it doesn't lead to mass chaos!