Showing posts with label Sean McGurk. Show all posts
Showing posts with label Sean McGurk. Show all posts

Wednesday, June 28, 2017

NSA Partly Responsible For Latest Cyber Attack? OF Course!

"The N.S.A. Needs to take a leadership role....to address the plague that they've unleashed." - NY Times, today

Simpletons often see a temporary divergence from endorsing an agency, Bureau or person as a "contradiction" which probably harkens back to the old saw "a foolish consistency is the hobgoblin of little minds". So because I may have endorsed the NSA as part of the intel community that has exposed Russian hacking in the 2016 election, some may wonder why I'd now want to "attack" the NSA. But this is more in the way of a citizen's "pull yourself up!" mandate than attack.

I am referring, of course, to how the agency enabled and allowed a nasty worm to get loose some five years ago which has since been repurposed by "bad guys"  to attack our nation and others.  The guise is under a "ransomware" mode when the net user's computer turns into a 'brick'  unless he or she coughs up 300 Bitcoin bucks. So yeah, the NSA now bears responsibility - at least partial - for yesterday's global "Petya" attack, as it did last month's "Wannacry" attack. The most recent has one-upped the Wannacry attack in that no "kill switch" has yet been found."


Most would probably not recall the 60 Minutes episode from March 4, 2012, which sheds light on the current attacks.

In that episode, Gen. Michael Hayden (formerly of the NSA) was heard to say:

"We have entered into a new phase of conflict in which we use a cyberweapon to create physical destruction, and in this case, physical destruction in someone else's critical infrastructure. This was a good idea, alright? But I also admit this was a really big idea too. The rest of the world is looking at this and saying, 'Clearly someone has legitimated this kind of activity as acceptable international conduct.' The whole world is watching."

Following on, there appeared Sean McGurk - former head of cyber defense at The Department of Homeland Security, in charge of protecting critical infrastructure in the U.S. - who addressed Hayden's more or less glib patter:

"You can download the actual source code of Stuxnet now and you can repurpose it and repackage it and then, you know, point it back towards wherever it came from."

CBS' Steve Kroft then remarked: "Sounds a little bit like Pandora's box." To which McGurk responded, "Yes!"

McGurk added:

"They opened up the box. They demonstrated the capability. They showed the ability and the desire to do so. And it's not something that can be put back."

Kroft then pressed the issue, asking:

"If somebody in the government had come to you and said, "Look, we're thinking about doing this. What do you think?" What would you have told them?"

To which McGurk didn't hesitate in responding:

"I would have strongly cautioned them against it because of the unintended consequences of releasing such a code."

Kroft then surmised that one such "unintended consequence" is that this same code might be "re-purposed" and used against us. Perhaps against nuclear power plants or the power grid. Again, McGurk responded:"Yes", labeling the possible retributive cyber attack worm, "Son of Stuxnet".

But this was no laughing matter, certainly not five years ago and not now after obvious repurposed cyber attacks using NSA "exploits" have transpired.  As I noted in a post from 5 years ago:

"Because of the hubristic, belligerent and arrogant actions of an enclave of pointy-headed computer geeks at the Puzzle Palace, we're likely all in jeopardy (as we were with the Wall St. quants with the financial meltdown). These sort of reckless actions do not bode well, and although their creators and the guilty agency might argue they were done with the "best intentions" , i.e. to slow down Iranian processing of nuclear fuel, we know the road to Hell is paved with them."

In the case of Stuxnet, its malicious trail commenced in June of 2010, when it was first detected and isolated by a tiny company in Belarus after one of its clients in Iran complained about a software glitch. Subsequently, reports filtered in that Iran's centrifuges were somehow compromised, though they didn't let on that they were aware of the real culprits which I suspected at the time was the NSA, whose cryptological-computer-savvy 'fingerprints' were all over it.

Barely a month later, the FLAME virus was unleashed wreaking some havoc but not as much as Petya did yesterday with its ransomware attack.

An AP Report ('Digital Virus has Nations on Alert') noted at the time:

"Unlike a bullet or a missile fired at an enemy, a cyberweapon that spreads across the internet might circle back to infect computers it was never supposed to target. It's one of the unusual challenges facing the programmers who build such weapons."

According to the same AP report, Russian digital security provider Kaspersky Lab - which first identified the virus - stated that Flame's complexity and functionality 'exceeded those of all other cyber menaces know to date'"

Those words were enough to convince me that, like the Stuxnet worm, FLAME is a creature of the geeks at NSA.  Thus the AP report's ending "Yet FLAME's author remains unknown because there is no information in the code of the virus that would link it to a particular country" merely confirmed its place and source of origin.

In yesterday's manifestation of the latest virus reincarnation (as the 'Petya' ransomware), the origin appeared to be in the Ukraine, where officials reported the country's power grid as well as banks and government offices were affected.    Subsequently, Russia's Rosneft oil company also reported falling victim - but avoided major damage owing to a quick response - as did Danish shipping giant A.P. Moller-Maersk.  According to Anders Rosendahl, a spokesman for the shipping group:

"We're talking about a cyber attack. It has affected all branches of our business, at home and abroad."

The cyber attack rapidly snowballed into a world wide crisis, which also affected U.S. companies, as well as a hospital in Pennsylvania where surgeries had to be cancelled because the computers were down.

The worst aspect of this latest attack? It was "self spreading". That is, it possessed the capability to spread across networks without any human interactions. Such self-propagating software is called by the name "worms" because of the similarity to the way worm infestation diseases spread.  This is exactly the character of the original Stuxnet.

Let's bear in mind in the wake of the recent attacks that both Wannacry and Petya have managed to spread rapidly using break in tools originally created by the National Security Agency. Also, these tools were recently released to the Web. So yes, the NSA bears more than a little responsibility to try to get the cyber plague "evil genie" back into the "bottle."

Some bottle. Any bottle.  And then, think - really hard  and long - before unleashing the next cyber weapon that could boomerang back on the rest of us.



Tuesday, July 2, 2013

Robert J. Samuelson Wants to "Repeal" the Internet - It's Too Dangerous!

Robert J. Samuelson, resident Neoliberal hack at the WaPo, usually blabbers on to defend the Neoliberal, free market imperative in his columns. You know the usual line: we need to cut "entitlements" because too many old people are already too rich and - hey!- if they run out of $ they can move in with their kids, the military merits no cuts or minor spending cuts compared to Social Security, Medicare, and those who need money either need to work longer or invest better.

Anyway, seems like Samuelson has developed a new shtick in his most recent column, which is that the internet has become "too dangerous". He writes (7/1):

"If I could, I would repeal the Internet. It is the technological marvel of the age, but it is not — as most people imagine — a symbol of progress. Just the opposite. We would be better off without it. I grant its astonishing capabilities: the instant access to vast amounts of information, the pleasures of YouTube and iTunes, the convenience of GPS and much more. But the Internet’s benefits are relatively modest compared with previous transformative technologies, and it brings with it a terrifying danger: cyberwar."

Samuelson then goes on to terrify the more weak kneed sort by raising all kinds of possible horrific outcomes and catastophes, including the "capacity of groups" (he doesn't name them)  to "attack, disrupt and possibly destroy the institutions and networks that underpin everyday life". He warns us these could well be "power grids, pipelines, communication and financial systems, business record-keeping and supply-chain operations, railroads and airlines, databases of all types (from hospitals to government agencies)."

Wow! I'm losing sleep already and I haven't even finished this blog post!  But as one goes further the natural reaction is to inquire as to exactly where the purported threats are emanating from?  He doesn't give any hard examples or cites and merely babbles on about how it's  "unclear how 'infrastructure' systems (electricity grids and the like) have been penetrated and, on command, might be compromised."  In other words, we can't really discriminate as to whether the threats he raises are any worse than those from a central meridian CME (coronal mass ejection), e.g. http://www.brane-space.blogspot.com/2012/06/cme-that-you-dont-want-to-see.html

But then one must remember this is Samuelson, who already has raised so many bollocks-inundated stories it's hard to take him seriously anymore - but some in high places might, like they do Bob Woodward. I mean, who can forget how he tried to blame the current trend to accept deficits and go into parlous debt on JFK! See: http://brane-space.blogspot.com/2012/07/thats-right-now-blame-60s-jfk-for.html

When Samuelson at last gets to the nitty gritty it's what one could call anticlimactic. He casually references “malware” that infected an estimated 30,000 computers of Aramco, Saudi Arabia’s oil company and noted "business operations suffered, but oil production and delivery continued."   Then, only in passing does he cite Stuxnet: "More powerful was the Stuxnet virus, reportedly developed by the United States and Israel to disrupt Iran’s nuclear program. "

Only here, at this point, does he come close to indicating the real threat, and which I discussed in an earlier blog, http://brane-space.blogspot.com/2012/03/stupidity-of-stuxnet.html   citing Sean McGurk - former head of cyber defense at The Department of Homeland Security- who when asked by '60 Minutes' Steve Kroft asked if it sounded "a little bit like Pandora's box."    replied:

"Yes! They opened up the box. They demonstrated the capability. They showed the ability and the desire to do so. And it's not something that can be put back."

That "they' btw, is the U.S. gov't as in NSA and its Israeli allies, not any al Qaeda operatives. In other words, this worm they created had the capability for full unintended consequences of biting the original dispatchers on the ass as well as the rest of us.  Kroft then surmised in that 60 Minutes segment that one such "unintended consequence" is that the same code might be "re-purposed" and used to attack us. Perhaps against nuclear power plants or the power grid.

Again, McGurk responded:"Yes", labeling the possible retributive cyber attack worm, "Son of Stuxnet".

So, again, if we are fair and judicious we need to acknowledge that the worst cyber attacks,  if they do manifest, will likely have emerged from the verminous code our own alleged "protectors" developed to thwart Iranian nuclear power initiatives. We also call that ominous potential "blowback". Will we ever learn? I doubt it! We are too hubristic a nation now, believing we're above the law, given "might makes right" and we are the only superpower after all. Ask the Germans who just discovered NSA was also bugging their offices in New York and in Belgium!  The NSA response: "Hey, everyone does it! Besides, you guys aren't covered under the 4th amendment."

Actually, this bozo needs to read the Constitution again, because the writers directed its inherent rights to cover ALL people not just U.S. persons, citizens. At least that is what we were taught in American History back in the 60s at Monsignor Pace High - but maybe they no longer teach that.

Anyway, Samuelson did get one thing right when he cited a James Andrew Lewis, an Internet expert at the Center for Strategic and International Studies. Lewis believes if the U.S. was so virulently stupid to attack Iran's nuclear facilities, "it would retaliate with cyberattacks against banks and electricity networks. Press stories report that Iran has already increased its attacks. There’s a race between cyber offense and defense."

Yes, yes, Mr. Samuelson! But that doesn't ipso facto make the internet something to fear in and of itself- only those who would try to exploit it in dastardly ways to try to harm or corrupt other nations and their people's systems - inviting them to do the same to us!

Monday, March 5, 2012

The Stupidity of STUXNET

Anyone who watched the first segment of '60 Minutes' last night, would have been treated to the news (kept seemingly well concealed hitherto) of one of the most malicious pieces of software ever conceived - a worm called "Stuxnet". According to the 60 Minutes' piece, the noisome behavior of this worm eventually drew the attention of Liam O Murchu, an operations manager for Symantec, one of the largest antivirus companies in the world. As he noted in the interview:

"As soon as we saw it, we knew it was something completely different. And red flags started to go up straightaway."

Those red flags included the way this worm specifically singled out computing command and control operations protocols to take over sophisticated robotic -run systems and divert them subtly toward perdition - to the extent no one running any plant operations (mainly at Iran's nuclear processing plants) would be any the wiser. Thus the worm could carry on its destruction undetected.

In the case of Stuxnet, its malicious trail commenced in June of 2010, when it was first detected and isolated by a tiny company in Belarus after one of its clients in Iran complained about a software glitch. Subsequently, reports filtered in that Iran's centrifuges were somehow compromised, though they didn't let on that they were aware of the real culprits (which I suspect was the NSA, whose cryptological-computer-savvy 'fingerprints' are all over this. )

Meanwhile, also featured on the 60 Minutes' piece was Retired General Michael Hayden, a former head of the National Security Agency. As he talked about the damage inflicted by the worm he damned near gloated with self-satisfaction as he babbled:

"We have entered into a new phase of conflict in which we use a cyberweapon to create physical destruction, and in this case, physical destruction in someone else's critical infrastructure. This was a good idea, alright? But I also admit this was a really big idea too. The rest of the world is looking at this and saying, 'Clearly someone has legitimated this kind of activity as acceptable international conduct.' The whole world is watching."

Indeed, but WAS IT a "good idea" to bring this genie out of the bottle and introduce it to the world? Especially when the initiator -attacker nation - obviously the hubristic U.S. - believes itself beyond the range of retribution? This is the question that must be asked, especially when we have a creaky power grid that just barely functions efficiently in periods of high demand - such as this summer promises to be, what with global warming continuing its ramping up!

Evidently, Sean McGurk - former head of cyber defense at The Department of Homeland Security, in charge of protecting critical infrastructure in the U.S. - doesn't believe so. WHen interviewed last night, he pointed out (alarmingly):

"You can download the actual source code of Stuxnet now and you can repurpose it and repackage it and then, you know, point it back towards wherever it came from."

CBS' Steve Kroft then remarked: "Sounds a little bit like Pandora's box." To which McGurk responded, "Yes!"

McGurk added:

"They opened up the box. They demonstrated the capability. They showed the ability and the desire to do so. And it's not something that can be put back."

Kroft then pressed the issue, asking:

"If somebody in the government had come to you and said, "Look, we're thinking about doing this. What do you think?" What would you have told them?"

To which McGurk didn't hesitate in responding:

"I would have strongly cautioned them against it because of the unintended consequences of releasing such a code."

Kroft then surmised that one such "unintended consequence" is that this same code might be "re-purposed" and used against us. Perhaps against nuclear power plants or the power grid. Again, McGurk responded:"Yes", labeling the possible retributive cyber attack worm, "Son of Stuxnet".

But this is no laughing matter! Because of the hubristic, belligerent and arrogant actions of an enclave of pointy-headed computer geeks at the Puzzle Palace, we're likely all in jeaopardy (as we were with the Wall St. quants inventing insane credit derivatives using the Gaussian Copula formula before the financial meltdown). These sort of reckless actions do not bode well, and although their creators and the guilty agency might argue they were done with the "best intentions" , i.e. to slow down Iranian processing of nuclear fuel, we know the road to Hell is paved with them.

More than 15 years ago such malicious and aggressive cyber-actions were forecast by author Winn Schwartau in his book: 'Information Warfare:Chaos on the Electronic Superhighway', 1995, Thunder's Mouth Press. As Schwartau noted ( p. 297):

"At the pinnacle of the Information Army is what the military calls C3I: Command, Control, Communications and Intelligence (some military planners now call it C4I, adding computers into the equation) - and what business calls 'the board of directors.' This is where strategic plans are made and directives for tactical support are calculated."

Schwartau also noted that "all money comes through C3I" (or C4I as the case may be), and much may emerge from "black budgets" or off the books funded operations to retain maximal security. Such levels of security are not as typical with the CIA or DIA (Defense Intelligence Agency) but they are with the grandaddy of spookhood, the NSA, which oversees all others. (Two of the best exposes of this bunch based at Ft. Meade, MD and their methods appeared in James Bamford's book, Body of Secrets (2001), and the Baltimore Sun series: 'No Such Agency: America's Fortress of Spies', by Scott Shane and Tom Bowman, Dec. 3-15, 1995)

The different echelons of information warrior, in the Class III (global) arena include(op. cit. 298-311):

- 'Communications or C-group' - responsibility for all communications, networking aspects, including encryption schemes. They may even "use the Global Network to achieve anonymity and privacy". Also "to make interception and traffic analysis of their activities much more
difficult, convoluted routing of communications paths all over the country and the world will require C-group to be multinational."

- 'Mappers' - as the name implies, those who chart cyberspace, showing how all the connections occur - and the critical points - for future targeting of attacks.

- 'Crackers' - use special software tools to decipher passwords, or break encryption schemes, say trhereby allowing a "worm" or virus to penetrate firewalls.

- 'Sniffers' - e.g. 'sniff' out passwords using sophisticated programs, or install 'taps' to eavesdrop or monitor selected targets.

- 'Readers' - Monitor emanations from computer screens/monitors using Van Eck radiation detectors. A person can park in a specially outfitted truck (often made to look like the local phone service) and 'read' everything on your monitor screen from up to a half mile away.

- Software Development group - "duplicate field conditions reported by a mapper or cracker and then develop a reliable means to compromise it".

- 'Moles' "deploy malicious software, garner confidential information from the target, or provide valuable inside information to C3I (or C4I)."

- Analysts - as the name implies, responsible for sifting through the vast reams of information made available and separating 'signal' from 'noise'. These eggheads would've been able to assess the extent of damage inflicted by Stuxnet to the Iranian centrifuges.

- 'Public Relations Group' -will feed information to the press on a selective basis."

Readers interested in seeing the '60 Minutes' segment can find it here:

http://www.cbsnews.com/video/watch/?id=7400904n&tag=contentBody;storyMediaBox

Sadly, this reckless and pre-emptive cyber attack, obviously initiated by our country (despite all the cloak and dagger BS), may well pave the way for a much less secure world affecting all of us. Let us hope if the Russians, Chinese or anyone else - run of the mill terrorists - mount their own attacks using "Son of Stuxnet" or an even worse variant, we are prepared and it doesn't lead to mass chaos!