Showing posts with label US cybersecurity. Show all posts
Showing posts with label US cybersecurity. Show all posts

Monday, June 17, 2013

America, Land of the Eerie and Home of the Afraid

Geez.  There's a reason why sales of 1984 have skyrocketed.  Here's a roundup.
h/t Mark Shea.
Mark Steyn has a series of pieces of awesome.

First:
...The other day the Boston Globe ran a story on how the city’s police and other agencies had spent months planning a big training exercise for last weekend involving terrorists planting bombs hidden in backpacks left downtown. Unfortunately, the Marathon bombers preempted them, and turned the coppers’ hypothetical scenario into bloody reality.

What a freaky coincidence, eh? But it’s the differences between the simulation and the actual event that are revealing. In humdrum reality, the Boston bombers were Chechen Muslim brothers with ties to incendiary imams and jihadist groups in Dagestan. In the far more exciting Boston Police fantasy, the bombers were a group of right-wing militiamen called “Free America Citizens,” a name so suspicious (involving as it does the words “free,” “America,” and “citizens”) that it can only have been leaked to them by the IRS. What fun the law-enforcement community in Massachusetts had embroidering their hypothetical scenario: The “Free America Citizens” terrorists even had their own little logo — a skull’s head with an Uncle Sam hat. Ooh, scary! The Boston PD graphics department certainly knocked themselves out on that.

Meanwhile, back in the real world, Tamerlan Tsarnaev was training in Dagestan, posting terrorist videos on YouTube, and getting fingered by the Russians to the FBI. Who did nothing.

...We’re told that universal surveillance has prevented all kinds of atrocities we can never hear about — an answer straight out of Orwell. Yet oddly, in the ones we do hear about, the perps are hiding in plain sight (Major Hasan with “Soldier of Allah” on his business card), the intelligence services do nothing (the Pantybomber known to the CIA but still permitted to board the plane), and the digital superstate is useless (the Tsarnaev photo rang no bells with the facial-recognition software, but was identified by friends who saw it on TV).

And thus, the bozo leviathan blunders on. Big Politically Correct Brother sees everything . . . and nothing.
Second:
...When the IRS is accused of “targeting,” don’t assume they’re speaking metaphorically. From Politico:
As chairman of the House Homeland Security oversight subcommittee, [Jeff] Duncan (R-S.C.) toured a federal law enforcement facility in late May and noticed agents training with the semi-automatic weapons at a firing range. They identified themselves as IRS, he said.
“When I left there, it’s been bugging me for weeks now, why IRS agents are training with a semi-automatic rifle AR-15, which has stand-off capability,” Duncan told POLITICO. “Are Americans that much of a target that you need that kind of capability..?
“I think Americans raise eyebrows when you tell them that IRS agents are training with a type of weapon that has stand-off capability. It’s not like they’re carrying a sidearm and they knock on someone’s door and say, ‘You’re evading your taxes,’” Duncan said.
A bureaucracy is bad. A politicized bureaucracy is worse. A paramilitary politicized bureaucracy is nuts. And, in fact, evil. There is no reason in a civilized society why the Deputy Assistant Commissioner of Paperwork should have his own SEAL Team Six. As I wrote in the magazine last year:
By the way, I use the word “agents” rather than “officials” because, in the developed world, the paramilitarized bureaucracy is uniquely American. This is the only G7 government whose education minister has his own SWAT team — for policing student-loan compliance. The other day, the Gibson guitar company settled with the feds over an arcane infraction of a law on rare-wood importation — after their factories were twice raided by “agents” bearing automatic weapons. Like the man said, don’t bring a knife to a guitar fight. Do musical-instrument manufacturers have a particular reputation for violence?
The Gibson raid looks a little different in light of recent revelations. Oh, well. Could have been worse. Its chief executive — a Republican donor — might have been shot for “resisting arrest,” right?...
Third:
...Over 4 million people hold US security clearances: That’s the equivalent of giving security clearances to the entire population of New Zealand. According to the U.S. Director of National Intelligence, a total of 642,831 people were approved for Confidential, Secret, and Top Secret clearances in FY 2010 alone (scroll down to page five)...
How seriously do you think those two-thirds-of-a-million people were looked at? The report seems to suggest a turnover of about 600,000 in a typical year, which means that the actual number of Americans with some kind of security clearance from the last half-decade alone could be closer to seven million.
Even more amazing are the words immediately preceding that:
The number of clearances approved could not be obtained for FY 2009 . . .
So the same government that presumes the right to know my phone calls, my emails and my MasterCard purchases doesn’t know how many security clearances it issued in a given year.
The rationale given by defenders of this system over the last few days — oh, relax; there are over 300 million of us; the government doesn’t have time to comb through all the stuff it’s got on you — would seem to apply here: When 4 million people have security clearances, and another 1,800 people are getting new security clearances every day, the government doesn’t even have time to comb through them before it lets them comb through you.
Over at Powerline, Scott Johnson writes of Mr Snowden:
Read the Guardian profile and the Post articles and you will see that Snowden professes no loyalty to the United States. He conceives of himself as a citizen of the world, or of the realm of Digitalia. He does not sound like anyone to be trusted with an assessment on our behalf the costs and benefits of the course of action he has undertaken.
Just so. One reason for the citizenry not to entrust its personal information to the government is that the big, bloated, blundering government is stupid enough to entrust it to Edward Snowden, as it was previously stupid enough to entrust it to Bradley Manning (the Wikileaks leaker)....
And here we have an interesting, different way of looking at where we are now (h/t Mark Shea). Excerpts:
This is satire. Although the news is real, very little actual reporting was done for this story and the quotes are imagined. It is the first installment of an ongoing series that examines the language journalists use to cover foreign countries. What if we wrote that way about the United States?

BOSTON, Mass. — Human rights activists say revelations that the US regime has expanded its domestic surveillance program to private phone carriers is more evidence of the North American country’s pivot toward authoritarianism.

The Guardian, a British newspaper, reported this week that a wing of the country’s feared intelligence and security apparatus ordered major telecommunications companies to hand over data on phone calls made by private citizens.

“The US leadership in Washington continues to erode basic human rights,” said one activist, who asked to remain anonymous, fearing that speaking out publicly could endanger his organization. “If the US government is unwilling to change course, it’s time the international community considered economic sanctions.”

Over the last decade, the United States has passed a series of emergency laws that give security forces sweeping powers to combat “terrorism.” But foreign observers say the authorities abuse those laws, using them instead to monitor ordinary Americans...
And Shea proceeds to sum up the situation, citing a piece from Conor Friedorsdorff in the process. Excerpts:
...The purpose of the State is *supposed* to be the defense of the common good.  The reality is that American state, at any rate is devolving into a vast apparatus of surveillance and oppression of its citizens in the name of Safety.  Between the two of them, Bush and Obama (and their parties) have created all the infrastructure any tyrant will ever need to turn the US into an Orwellian police state:
What we know is that the people in charge will possess the capacity to be tyrants — to use power oppressively and unjustly — to a degree that Americans in 1960, 1970, 1980, 1990, or 2000 could’ve scarcely imagined. To an increasing degree, we’re counting on having angels in office and making ourselves vulnerable to devils. Bush and Obama have built infrastructure any devil would lust after. Behold the items on an aspiring tyrant’s checklist that they’ve provided their successors:
  • A precedent that allows the president to kill citizens in secret without prior judicial or legislative review
  • The power to detain prisoners indefinitely without charges or trial
  • Ongoing warrantless surveillance on millions of Americans accused of no wrongdoing, converted into a permanent database so that data of innocents spied upon in 2007 can be accessed in 2027
  • Using ethnic profiling to choose the targets of secret spying, as the NYPD did with John Brennan’s blessing
  • Normalizing situations in which the law itself is secret — and whatever mischief is hiding in those secret interpretations
  • The ability to collect DNA swabs of people who have been arrested even if they haven’t been convicted of anything
  • A torture program that could be restarted with an executive order
Even if you think Bush and Obama exercised those extraordinary powers responsibly, what makes you think every president would? How can anyone fail to see the huge potential for abuses?

I am not saying no one would resist a tyrant. Perhaps Congress would assert itself. Perhaps the people would rise up. Then again, perhaps it would be too late by the time the abuses were evident. (America has had horrific abuses of power in the past under weaker executives who were less empowered by technology; and numerous other countries haven’t recognized tyrants until it was too late.) Part of the problem is how much the Bush-Obama paradigm permits the executive to do in secret. Take that paradigm, add another successful 9/11-style attack, even after many years of very little terrorism, and who knows what would happen?
Part of the way We the People can make ourselves smart about this stuff is to stop buying into the dumb game of imagining that That Tribe Over There are the Bad Guys and our Tribal Elders care about us and oppose this stuff.
No.  It’s not Left vs. Right on this.  It’s Our Ruling Class vs. the rest of us...

Chesterton remarked:

If there is one fact we really can prove, from the history that we really do know, it is that despotism can be a development, often a late development and very often indeed the end of societies that have been highly democratic. A despotism may almost be defined as a tired democracy. As fatigue falls on a community, the citizens are less inclined for that eternal vigilance which has truly been called the price of liberty; and they prefer to arm only one single sentinel to watch the city while they sleep...
...[W]e’ve asked Caesar to take over yet another task typically handled by God: seeing all that we do, hearing all that we say, and judging it. In payment, Caesar customarily demands that we begin addressing him as “Divine Caesar”. The first Christians declined, and kicked off a revolution that, with time, put Caesar in his place and brought the liberty of Christ to the world. We still have that option. But we have to face the possibility that, as with them, it may cost us our lives.
We begin that revolution, of course, in the heart and mind by listening to St Paul:

I appeal to you therefore, brethren, by the mercies of God, to present your bodies as a living sacrifice, holy and acceptable to God, which is your spiritual worship. Do not be conformed to this world but be transformed by the renewal of your mind, that you may prove what is the will of God, what is good and acceptable and perfect. (Romans 12:1-2)
h/t Mark Shea

Thursday, December 23, 2010

The Wonders of Amazon.com

They can do what...well, most the rest of the world can't!
The website-attacking group "Anonymous" tried and failed to take down Amazon.com on Thursday. The group's vengeance horde quickly found out something techies have known for years: Amazon, which has built one of the world's most invincible websites, is almost impossible to crash.

Amazon has famously massive server capacity in order to handle the December e-commerce rush. That short holiday shopping window is so critical, and so intense, that even a few minutes of downtime could cost Amazon millions. So Amazon has spent years creating and refining an "elastic" infrastructure, called EC2, designed to automatically scale to handle giant traffic spikes. The company has so much spare server capacity, in fact, that it runs a sideline business hosting other websites...
As the Dark Lord Sheavius has observed:
Amazon mystifies me. They ran for years without turning a profit, they seem to sell everything to everyone, and they are better prepared for cyber-terror than the Feds. I have this theory that they are a vast corporate cyberstate that is preparing to assume control of Planet Earth. Our new World State Holy Scripture will be the Ferengi Rules of Acquisition (available for purchase from Amazon.com!).

Wednesday, December 15, 2010

We Live in Novel

Dear Lord:
...The U.S. Department of Defense says it is aware of the WikiLeaks insurance file, but has been unable to establish its contents. It has been available for download since July.

Assange has warned he can divulge the classified documents in the insurance file and similar backups if he is detained or the WikiLeaks website is permanently removed from the internet. He has suggested the contents are unredacted, posing a possible security risk for coalition partners around the world.

Assange warned: “We have over a long period of time distributed encrypted backups of material we have yet to release. All we have to do is release the password to that material, and it is instantly available.”

The “doomsday files” are part of a contingency plan drawn up by Assange and his supporters as they face a legal threat. He is wanted in Sweden over sexual assault allegations, and the US administration is reviewing the possibility of legal action after the release of 250,000 diplomatic cables.

Ben Laurie, a London-based computer security expert who has advised WikiLeaks, said: “Julian’s a smart guy and this is an interesting tactic. He will hope it deters anyone from acting against him.”

Nigel Smart, professor of cryptology at the U.K.'s Bristol University, said even powerful military computers would be unable to crack the encryption. He said: “This isn’t something that can be broken with a modern computer. You need the key to open it...”
Well, I'm glad they managed to interview someone Smart.

But really--we've got no ability to crack this thing? I think the net has just moved outside mainstream control. Add Stuxnet into this, and I don't know quite what to call what we're seeing.

Sometimes They Really Are Watching You

Yay for the digital age!
Federal law enforcement agencies have been tracking Americans in real-time using credit cards, loyalty cards and travel reservations without getting a court order, a new document released under a government sunshine request shows.

The document, obtained by security researcher Christopher Soghoian, explains how so-called “Hotwatch” orders allow for real-time tracking of individuals in a criminal investigation via credit card companies, rental car agencies, calling cards, and even grocery store loyalty programs. The revelation sheds a little more light on the Justice Department’s increasing power and willingness to surveil Americans with little to no judicial or Congressional oversight.

For credit cards, agents can get real-time information on a person’s purchases by writing their own subpoena, followed up by a order from a judge that the surveillance not be disclosed. Agents can also go the traditional route — going to a judge, proving probable cause and getting a search warrant — which means the target will eventually be notified they were spied on.

The document suggests that the normal practice is to ask for all historical records on an account or individual from a credit card company, since getting stored records is generally legally easy. Then the agent sends a request for “Any and all records and information relating directly or indirectly to any and all ongoing and future transactions or events relating to any and all of the following person(s), entitities, account numbers, addresses and other matters…” That gets them a live feed of transaction data...
How does this work with the Constitutional protection against unwarranted searches and seizures?

Tuesday, December 14, 2010

We're So Screwed

I'm sorry, but when I read this:
It will take several more years for the government to fully install high-tech systems to block computer intrusions, a drawn-out timeline that enables criminals to become more adept at stealing sensitive data, experts say.

As the Department of Homeland Security moves methodically to pare down and secure the approximately 2,400 network connections used every day by millions of federal workers, experts suggest that technology already may be passing them by...
Well, facepalm doesn't even begin to cover it. Everyone--the moment you get online, your system is being probed by hackers. The TSA? Pikers, compared to the sort of software that roams the net as a matter of course.

Bleah.
..."This is a continuing arms race and we're still way behind," said Stewart Baker, former Homeland Security undersecretary for policy.

The WikiLeaks breach affected the government's classified military network and was as much a personnel gap as a technological failure. Officials believe the sensitive documents were stolen from secure Pentagon computer networks by an Army intelligence analyst.

The changes sought by Homeland Security on the government's nonmilitary computers would be wider and more systemic than the immediate improvements ordered recently by the Departments of Defense and State as a result of the WikiLeaks releases. Those changes included improving the monitoring of computer usage and making it harder to move material onto a portable computer flash drive or CD.

"There are very few private sector actors who depend on information security who think that installing intrusion prevention systems is sufficient protection against the kinds of attacks that we're seeing," Baker said.

True--there are some elements that are perennial. But they're perennial. As in, we're supposed to have some preexisting ability to protect against them...right? Yes, they'll always be problems, but...

Again. Bleah.

Monday, December 6, 2010

WikiLeaks and Journalistic Ethics

An interesting post, especially this excerpt from a Reason magazine article:
...The existence of WikiLeaks is a good thing. You can’t be in favor of democracy—and you certainly can’t be a journalist—if you don’t believe that the potential for exposure of wrongdoings helps keep those in positions of power accountable. However, just because something can be published doesn’t mean it should be. Privacy is not the same as “secretive” or “clandestine” or “obfuscating.” As a society, we benefit from the Internet’s unrivaled ability to blast infinite information freely. But that ability does not mean everything ought to be shared. If we have a “right to know” the contents of Hillary Clinton’s private communications with her staff, do we have a right to see photos of her showering, to hear tapes of her snoring, to read stolen letters she wrote to her parents?...

Thursday, December 2, 2010

Cybermissile of Incredible Sophistication

and nobody seems to know who fired it:
...The construction of the worm was so advanced, it was “like the arrival of an F-35 into a World War I battlefield,” says Ralph Langner, the computer expert who was the first to sound the alarm about Stuxnet. Others have called it the first “weaponized” computer virus.

Simply put, Stuxnet is an incredibly advanced, undetectable computer worm that took years to construct and was designed to jump from computer to computer until it found the specific, protected control system that it aimed to destroy: Iran’s nuclear enrichment program.

The target was seemingly impenetrable; for security reasons, it lay several stories underground and was not connected to the World Wide Web. And that meant Stuxnet had to act as sort of a computer cruise missile: As it made its passage through a set of unconnected computers, it had to grow and adapt to security measures and other changes until it reached one that could bring it into the nuclear facility.

When it ultimately found its target, it would have to secretly manipulate it until it was so compromised it ceased normal functions.

And finally, after the job was done, the worm would have to destroy itself without leaving a trace.

That is what we are learning happened at Iran's nuclear facilities -- both at Natanz, which houses the centrifuge arrays used for processing uranium into nuclear fuel, and, to a lesser extent, at Bushehr, Iran's nuclear power plant...
The whole piece is incredible.

Wednesday, December 1, 2010

Levant on Wikileaks

A different perspective on Assange:
...His obsession is to embarrass the world’s freest countries — the U.S. and U.K. And as to repressive regimes, well, put it this way, Assange says U.S. forces must remember “shooting the Taliban is shooting the Afghan people.”

He’s not anti-war. He’s on the other side.

Assange published the names of Afghan human rights activists and others who have co-operated with the U.S. — giving out names of villages and GPS coordinates.

That’s not journalism. That’s not whistleblowing. That’s setting up “deadly revenge attacks,” says Reporters Without Borders.

Zabihullah Mujahid is grateful. He’s a Taliban spokesman who says “we know how to punish them.”

Assange published details about technology used to stop improvised explosive devices (IEDs) from being detonated. WikiLeaks calls roadside bombs a “rebel investment,” proudly pointing out for every dollar spent by the terrorists, the U.S. and Canada have to spend a thousand to defend against them. So Assange published those anti-IED details online.

This week, Assange started to publish 250,000 U.S. diplomatic messages, many marked secret. The fight against terrorism is being endangered.

Other members of WikiLeaks have complained about Assange’s anti-American obsession. But it’s his show now...

Thursday, September 23, 2010

Cyber Missiles--Away!

Well. Cyberwarfare just upped the ante:
Stuxnet surfaced in June and, by July, was identified as a hypersophisticated piece of malware probably created by a team working for a nation state, say cyber security experts. Its name is derived from some of the filenames in the malware. It is the first malware known to target and infiltrate industrial supervisory control and data acquisition (SCADA) software used to run chemical plants and factories as well as electric power plants and transmission systems worldwide. That much the experts discovered right away.
But what was the motive of the people who created it? Was Stuxnet intended to steal industrial secrets – pressure, temperature, valve, or other settings –and communicate that proprietary data over the Internet to cyber thieves?
By August, researchers had found something more disturbing: Stuxnet appeared to be able to take control of the automated factory control systems it had infected – and do whatever it was programmed to do with them. That was mischievous and dangerous.
But it gets worse. Since reverse engineering chunks of Stuxnet's massive code, senior US cyber security experts confirm what Mr. Langner, the German researcher, told the Monitor: Stuxnet is essentially a precision, military-grade cyber missile deployed early last year to seek out and destroy one real-world target of high importance – a target still unknown.
"Stuxnet is a 100-percent-directed cyber attack aimed at destroying an industrial process in the physical world," says Langner, who last week became the first to publicly detail Stuxnet's destructive purpose and its authors' malicious intent. "This is not about espionage, as some have said. This is a 100 percent sabotage attack."

Monday, December 28, 2009

The Great Strength and Weakness of the Digital Age

All things electronic are vulnerable to hacking:
Militants in Iraq have used $26 off-the-shelf software to intercept live video feeds from U.S. Predator drones, potentially providing them with information they need to evade or monitor U.S. military operations.

Senior defense and intelligence officials said Iranian-backed insurgents intercepted the video feeds by taking advantage of an unprotected communications link in some of the remotely flown planes' systems. Shiite fighters in Iraq used software programs such as SkyGrabber -- available for as little as $25.95 on the Internet -- to regularly capture drone video feeds, according to a person familiar with reports on the matter.

In some ways, this is terrible news. Our security is made vulnerable to all and sundry enemies, the US (according to my sources) is way behind in the "cyber-warfare" realm, and no data is totally secure. As evidenced by this man's ongoing saga:

SK: How did you go about trying to find the stuff you were looking for in Nasa, in the Department of Defense?

GM: Unlike the press would have you believe, it wasn't very clever. I searched for blank passwords...

SK: Were you the only hacker to make it past the slightly lower-than-expected lines of defence?

GM: Yes, exactly, there were no lines of defence. There was a permanent tenancy of foreign hackers. You could run a command when you were on the machine that showed connections from all over the world, check the IP address to see if it was another military base or whatever, and it wasn't.

The General Accounting Office in America has again published another damning report saying that federal security is very, very poor.

I'd rather the US had much better security, personally, and live in hope that the more dictatorial nations around the world shall forever be plagued by an inability to totally secure their systems. But still--the fact that information in this electronic age is so much harder to hide offers some hope of a more free, more open world.

Wednesday, December 16, 2009

Put the Freaky Stuff at the End

In this very interesting article on the modern digital age's erosion of privacy, they save the freaky for last:
...At the same time, he argued that individual privacy rights must also be weighed against the public good.

Citing the epidemic involving severe acute respiratory syndrome, or SARS, in recent years, he said technology would have helped health officials watch the movement of infected people as it happened, providing an opportunity to limit the spread of the disease.

“If I could have looked at the cellphone records, it could have been stopped that morning rather than a couple of weeks later,” he said. “I’m sorry, that trumps minute concerns about privacy.”

Indeed, some collective-intelligence researchers argue that strong concerns about privacy rights are a relatively recent phenomenon in human history.

“The new information tools symbolized by the Internet are radically changing the possibility of how we can organize large-scale human efforts,” said Thomas W. Malone, director of the M.I.T. Center for Collective Intelligence.

“For most of human history, people have lived in small tribes where everything they did was known by everyone they knew,” Dr. Malone said. “In some sense we’re becoming a global village. Privacy may turn out to have become an anomaly.”
Savor that for a moment. Consider what is being said here. Think of the implications. Then go and read the rest of the article in light of what's saved for last.

LinkWithin

Related Posts Plugin for WordPress, Blogger...