Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts
20170816
20170212
The Spy Revolt Against Trump Begins
In a recent column, I explained how the still-forming Trump administration is already doing serious harm to America’s longstanding global intelligence partnerships. In particular, fears that the White House is too friendly to Moscow are causing close allies to curtail some of their espionage relationships with Washington—a development with grave implications for international security, particularly in the all-important realm of counterterrorism.
Now those concerns are causing problems much closer to home—in fact, inside the Beltway itself. Our Intelligence Community is so worried by the unprecedented problems of the Trump administration—not only do senior officials possess troubling ties to the Kremlin, there are nagging questions about basic competence regarding Team Trump—that it is beginning to withhold intelligence from a White House which our spies do not trust.
That the IC has ample grounds for concern is demonstrated by almost daily revelations of major problems inside the White House, a mere three weeks after the inauguration. The president has repeatedly gone out of his way to antagonize our spies, mocking them and demeaning their work, and Trump’s personal national security guru can’t seem to keep his story straight on vital issues.
That’s Mike Flynn, the retired Army three-star general who now heads the National Security Council. Widely disliked in Washington for his brash personality and preference for conspiracy-theorizing over intelligence facts, Flynn was fired as head of the Defense Intelligence Agency for managerial incompetence and poor judgment—flaws he has brought to the far more powerful and political NSC...
http://observer.com/2017/02/donald-trump-administration-mike-flynn-russian-embassy/
Now those concerns are causing problems much closer to home—in fact, inside the Beltway itself. Our Intelligence Community is so worried by the unprecedented problems of the Trump administration—not only do senior officials possess troubling ties to the Kremlin, there are nagging questions about basic competence regarding Team Trump—that it is beginning to withhold intelligence from a White House which our spies do not trust.
That the IC has ample grounds for concern is demonstrated by almost daily revelations of major problems inside the White House, a mere three weeks after the inauguration. The president has repeatedly gone out of his way to antagonize our spies, mocking them and demeaning their work, and Trump’s personal national security guru can’t seem to keep his story straight on vital issues.
That’s Mike Flynn, the retired Army three-star general who now heads the National Security Council. Widely disliked in Washington for his brash personality and preference for conspiracy-theorizing over intelligence facts, Flynn was fired as head of the Defense Intelligence Agency for managerial incompetence and poor judgment—flaws he has brought to the far more powerful and political NSC...
http://observer.com/2017/02/donald-trump-administration-mike-flynn-russian-embassy/
20161204
Why Did Team Obama Try to Take Down Its NSA Chief?
At a recent town hall meeting at a National Security Agency facility in Texas, employees at the U.S. government’s biggest and most secretive intelligence bureau told their boss, Adm. Michael Rogers, that they were concerned about how the agency’s reorganization was upending their work lives.
“His response was that employees should ‘stop bitching’ and do their jobs,” a recently-retired NSA analyst told The Daily Beast. That remark produced a “small outcry” that was discussed on an internal NSA blogging site where employees are encouraged to share their views. And it became symbolic to some of the tensions that have grown in the two-and-a-half years Rogers has been in charge of NSA.
Major policy disagreements between Rogers and top Obama administration officials—including ones about how hard to go after ISIS—have exacerbated long-standing grievances among NSA rank-and-file employees about Rogers’s brusque and aloof management style. Now, those complaints are erupting on the surface in a manner that has surprised current and former officials.
Most recently, The Washington Post reported an effort by the Secretary of Defense and the nation’s top intelligence official to remove Rogers from his post, as well as from the command of U.S. Cyber Command, which conducts cyber warfare operations.
It’s highly unusual for these sorts of internal struggles to emerge into the open press. But it’s even more unusual for a serving officer to do what Rogers recently did—meet with the president-elect about a job without notifying the current secretary of defense or the White House. Rogers huddled with Donald Trump last Thursday and could be in line to be named director of national intelligence in the next administration, if the reports out of Trump Tower are to be believed...
“His response was that employees should ‘stop bitching’ and do their jobs,” a recently-retired NSA analyst told The Daily Beast. That remark produced a “small outcry” that was discussed on an internal NSA blogging site where employees are encouraged to share their views. And it became symbolic to some of the tensions that have grown in the two-and-a-half years Rogers has been in charge of NSA.
Major policy disagreements between Rogers and top Obama administration officials—including ones about how hard to go after ISIS—have exacerbated long-standing grievances among NSA rank-and-file employees about Rogers’s brusque and aloof management style. Now, those complaints are erupting on the surface in a manner that has surprised current and former officials.
Most recently, The Washington Post reported an effort by the Secretary of Defense and the nation’s top intelligence official to remove Rogers from his post, as well as from the command of U.S. Cyber Command, which conducts cyber warfare operations.
It’s highly unusual for these sorts of internal struggles to emerge into the open press. But it’s even more unusual for a serving officer to do what Rogers recently did—meet with the president-elect about a job without notifying the current secretary of defense or the White House. Rogers huddled with Donald Trump last Thursday and could be in line to be named director of national intelligence in the next administration, if the reports out of Trump Tower are to be believed...
20161025
AT&T Is Spying on Americans for Profit, New Documents Reveal
On Nov. 11, 2013, Victorville, California, sheriff’s deputies and a coroner responded to a motorcyclist’s report of human remains outside of town.
They identified the partially bleached skull of a child, and later discovered the remains of the McStay family who had been missing for the past three years. Joseph, 40, his wife Summer, 43, Gianni, 4, and Joseph Jr., 3, had been bludgeoned to death and buried in shallow graves in the desert.
Investigators long suspected Charles Merritt in the family’s disappearance, interviewing him days after they went missing. Merritt was McStay’s business partner and the last person known to see him alive. Merritt had also borrowed $30,000 from McStay to cover a gambling debt, a mutual business partner told police. None of it was enough to make an arrest.
They identified the partially bleached skull of a child, and later discovered the remains of the McStay family who had been missing for the past three years. Joseph, 40, his wife Summer, 43, Gianni, 4, and Joseph Jr., 3, had been bludgeoned to death and buried in shallow graves in the desert.
Investigators long suspected Charles Merritt in the family’s disappearance, interviewing him days after they went missing. Merritt was McStay’s business partner and the last person known to see him alive. Merritt had also borrowed $30,000 from McStay to cover a gambling debt, a mutual business partner told police. None of it was enough to make an arrest.
Even after the gravesite was discovered and McStay’s DNA was found inside Merritt’s vehicle, police were far from pinning the quadruple homicide on him.
Until they turned to Project Hemisphere.
Hemisphere is a secretive program run by AT&T that searches trillions of call records and analyzes cellular data to determine where a target is located, with whom he speaks, and potentially why.
“Merritt was in a position to access the cellular telephone tower northeast of the McStay family gravesite on February 6th, 2010, two days after the family disappeared,” an affidavit for his girlfriend’s call records reports Hemisphere finding (PDF). Merritt was arrested almost a year to the date after the McStay family’s remains were discovered, and is awaiting trial for the murders.
In 2013, Hemisphere was revealed by The New York Times and described only within a Powerpoint presentation made by the Drug Enforcement Administration. The Times described it as a “partnership” between AT&T and the U.S. government; the Justice Department said it was an essential, and prudently deployed, counter-narcotics tool.
http://www.thedailybeast.com/articles/2016/10/25/at-t-is-spying-on-americans-for-profit.html
Until they turned to Project Hemisphere.
Hemisphere is a secretive program run by AT&T that searches trillions of call records and analyzes cellular data to determine where a target is located, with whom he speaks, and potentially why.
“Merritt was in a position to access the cellular telephone tower northeast of the McStay family gravesite on February 6th, 2010, two days after the family disappeared,” an affidavit for his girlfriend’s call records reports Hemisphere finding (PDF). Merritt was arrested almost a year to the date after the McStay family’s remains were discovered, and is awaiting trial for the murders.
In 2013, Hemisphere was revealed by The New York Times and described only within a Powerpoint presentation made by the Drug Enforcement Administration. The Times described it as a “partnership” between AT&T and the U.S. government; the Justice Department said it was an essential, and prudently deployed, counter-narcotics tool.
http://www.thedailybeast.com/articles/2016/10/25/at-t-is-spying-on-americans-for-profit.html
20161023
PRIVATE EYES: The Little-Known Company That Enables Worldwide Mass Surveillance
IT WAS A POWERFUL piece of technology created for an important customer. The Medusa system, named after the mythical Greek monster with snakes instead of hair, had one main purpose: to vacuum up vast quantities of internet data at an astonishing speed.
The technology was designed by Endace, a little-known New Zealand company. And the important customer was the British electronic eavesdropping agency, Government Communications Headquarters, or GCHQ.
Dozens of internal documents and emails from Endace, obtained by The Intercept and reported in cooperation with Television New Zealand, reveal the firm’s key role helping governments across the world harvest vast amounts of information on people’s private emails, online chats, social media conversations, and internet browsing histories.
The leaked files, which were provided by a source through SecureDrop, show that Endace listed a Moroccan security agency implicated in torture as one of its customers. They also indicate that the company sold its surveillance gear to more than half a dozen other government agencies, including in the United States, Israel, Denmark, Australia, Canada, Spain, and India.
Some of Endace’s largest sales in recent years, however, were to the United Kingdom’s GCHQ, which purchased a variety of “data acquisition” systems and “probes” that it used to covertly monitor internet traffic.
Documents from the National Security Agency whistleblower Edward Snowden, previously disclosed by The Intercept, have shown how GCHQ dramatically expanded its online surveillance between 2009 and 2012. The newly obtained Endace documents add to those revelations, shining light for the first time on the vital role played by the private sector in enabling the spying.
Stuart Wilson, Endace’s CEO, declined to answer questions for this story. Wilson said in a statement that Endace’s technology “generates significant export revenue for New Zealand and builds important technical capability for our country.” He added: “Our commercial technology is used by customers worldwide … who rely on network recording to protect their critical infrastructure and data from cybercriminals, terrorists, and state-sponsored cybersecurity threats.”...
https://theintercept.com/2016/10/23/endace-mass-surveillance-gchq-governments/
The technology was designed by Endace, a little-known New Zealand company. And the important customer was the British electronic eavesdropping agency, Government Communications Headquarters, or GCHQ.
Dozens of internal documents and emails from Endace, obtained by The Intercept and reported in cooperation with Television New Zealand, reveal the firm’s key role helping governments across the world harvest vast amounts of information on people’s private emails, online chats, social media conversations, and internet browsing histories.
The leaked files, which were provided by a source through SecureDrop, show that Endace listed a Moroccan security agency implicated in torture as one of its customers. They also indicate that the company sold its surveillance gear to more than half a dozen other government agencies, including in the United States, Israel, Denmark, Australia, Canada, Spain, and India.
Some of Endace’s largest sales in recent years, however, were to the United Kingdom’s GCHQ, which purchased a variety of “data acquisition” systems and “probes” that it used to covertly monitor internet traffic.
Documents from the National Security Agency whistleblower Edward Snowden, previously disclosed by The Intercept, have shown how GCHQ dramatically expanded its online surveillance between 2009 and 2012. The newly obtained Endace documents add to those revelations, shining light for the first time on the vital role played by the private sector in enabling the spying.
Stuart Wilson, Endace’s CEO, declined to answer questions for this story. Wilson said in a statement that Endace’s technology “generates significant export revenue for New Zealand and builds important technical capability for our country.” He added: “Our commercial technology is used by customers worldwide … who rely on network recording to protect their critical infrastructure and data from cybercriminals, terrorists, and state-sponsored cybersecurity threats.”...
https://theintercept.com/2016/10/23/endace-mass-surveillance-gchq-governments/
20160929
20160911
EmailGate and the Mystery of the Missing GAMMA
Last week’s Federal Bureau of Investigation release of materials relating to their investigation of Hillary Clinton has reignited the political firestorm surrounding EmailGate. How the Democratic nominee mishandled her emails while she was secretary of state is again front-page news, which is bad news for Hillary. Particularly because the FBI’s data dump demonstrates clearly that Clinton is either dumb or dishonest—and perhaps both.
Although Team Clinton has responded in their customary fashion, with lawyerly lies and evasions—nothing was “marked” classified, this is really about over-classification, classification is too complex for anybody to understand anyway—the FBI’s assessment has thoroughly debunked all of them. Hillary’s professed inability to even recognize classified information, thinking the “C” (for Confidential) meant alphabetical order, will now enter the pantheon of laughable Clinton infamy, alongside her husband’s debating the meaning of “is” while under oath.
The Bureau’s assessment establishes once and for all that there was classified information—and lots of it—on Hillary’s email server and bunches of Blackberries, many of which she lost. In fact, the FBI concluded that roughly 2,000 of her “unclassified” emails included information that was Confidential, the lowest level of classification.
The FBI examined 81 Clinton email chains, determining that they included classified information relating to the CIA, the FBI, the Pentagon, NSA, and the National Geospatial Intelligence Agency or NGA. In other words, Hillary compromised classified materials representing the full range of American espionage: human intelligence or HUMINT from CIA, signals intelligence or SIGINT from NSA, and imagery intelligence or IMINT from NGA...
http://observer.com/2016/09/emailgate-and-the-mystery-of-the-missing-gamma/
Although Team Clinton has responded in their customary fashion, with lawyerly lies and evasions—nothing was “marked” classified, this is really about over-classification, classification is too complex for anybody to understand anyway—the FBI’s assessment has thoroughly debunked all of them. Hillary’s professed inability to even recognize classified information, thinking the “C” (for Confidential) meant alphabetical order, will now enter the pantheon of laughable Clinton infamy, alongside her husband’s debating the meaning of “is” while under oath.
The Bureau’s assessment establishes once and for all that there was classified information—and lots of it—on Hillary’s email server and bunches of Blackberries, many of which she lost. In fact, the FBI concluded that roughly 2,000 of her “unclassified” emails included information that was Confidential, the lowest level of classification.
The FBI examined 81 Clinton email chains, determining that they included classified information relating to the CIA, the FBI, the Pentagon, NSA, and the National Geospatial Intelligence Agency or NGA. In other words, Hillary compromised classified materials representing the full range of American espionage: human intelligence or HUMINT from CIA, signals intelligence or SIGINT from NSA, and imagery intelligence or IMINT from NGA...
http://observer.com/2016/09/emailgate-and-the-mystery-of-the-missing-gamma/
20160907
The cypherpunk revolution
Punk is resistance. During the 1980s and ’90s, the subculture was resistance of a special kind: heavy on fashion and light on politics. Punk generated eccentric hairstyles, tattoos, boots and leather outfits, drug habits, and hard-core music that oozed being against stuff. Yet fashion trumped direct action. Punk was aesthetic anarchy.
When computers and networks were added to the mix, cyberpunk was born. The 1990s were a time of extraordinary hope. The decade came barging right through Brandenburg Gate, with the Berlin Wall crashing down in the background. The end of the Cold War and the peaceful collapse of the Soviet Union released an intoxicating sense of optimism, at least in the West. Washington debated the “end of history,” with liberal market economies coming out triumphant. In the Persian Gulf War of 1991, perhaps America’s shortest and most successful ground war operation to date, the Pentagon overcame the mighty Iraqi army — and with it the lingering Vietnam hangover.
Silicon Valley and America’s technology startup scene, still bathing in the crisp utopian afterglow of the 1980s, watched the rise of the New Economy, with vertigo-inducing growth rates. Entrepreneurs rubbed their hands in anticipation. Intellectuals were inebriated by the simultaneous emergence of two revolutionary forces: personal computers and the internet. More and more PC owners connected their machines to the fast-growing global computer network, first with clunky, screeching modems, then with faster and faster broadband connections.
But amid the hype and a slowly but steadily growing economic bubble, it dawned on a number of users that something was missing: privacy and secure communications. History, thankfully, was gracious. Even more than that: nature itself was generous to humans in front of plastic keyboards. Unrelated to either PCs or the internet, cryptographers had made a third and no less far-reaching discovery in the 1970s. They didn’t just invent a technology; more like explorers than innovators, they discovered an algorithm based on a beautiful mathematical truth. That truly revolutionary technology was finally unleashed for widespread public use in June 1991: asymmetric encryption, also known as public-key cryptography.
When free crypto was added to the computer underground, “crypto anarchy” emerged. Now people with mirror shades, modems, and PCs could be against stuff. And even better, despite the decade’s spirit for unrestrained optimism, they had found something concrete to be against: the government’s attempts to regulate ciphers. And so cypherpunk was born, a pun on “cyberpunk.” The ideology was powerful — far more powerful and durable than those whimsical and short-lived names implied...
http://passcode.csmonitor.com/cypherpunk
When computers and networks were added to the mix, cyberpunk was born. The 1990s were a time of extraordinary hope. The decade came barging right through Brandenburg Gate, with the Berlin Wall crashing down in the background. The end of the Cold War and the peaceful collapse of the Soviet Union released an intoxicating sense of optimism, at least in the West. Washington debated the “end of history,” with liberal market economies coming out triumphant. In the Persian Gulf War of 1991, perhaps America’s shortest and most successful ground war operation to date, the Pentagon overcame the mighty Iraqi army — and with it the lingering Vietnam hangover.
Silicon Valley and America’s technology startup scene, still bathing in the crisp utopian afterglow of the 1980s, watched the rise of the New Economy, with vertigo-inducing growth rates. Entrepreneurs rubbed their hands in anticipation. Intellectuals were inebriated by the simultaneous emergence of two revolutionary forces: personal computers and the internet. More and more PC owners connected their machines to the fast-growing global computer network, first with clunky, screeching modems, then with faster and faster broadband connections.
But amid the hype and a slowly but steadily growing economic bubble, it dawned on a number of users that something was missing: privacy and secure communications. History, thankfully, was gracious. Even more than that: nature itself was generous to humans in front of plastic keyboards. Unrelated to either PCs or the internet, cryptographers had made a third and no less far-reaching discovery in the 1970s. They didn’t just invent a technology; more like explorers than innovators, they discovered an algorithm based on a beautiful mathematical truth. That truly revolutionary technology was finally unleashed for widespread public use in June 1991: asymmetric encryption, also known as public-key cryptography.
When free crypto was added to the computer underground, “crypto anarchy” emerged. Now people with mirror shades, modems, and PCs could be against stuff. And even better, despite the decade’s spirit for unrestrained optimism, they had found something concrete to be against: the government’s attempts to regulate ciphers. And so cypherpunk was born, a pun on “cyberpunk.” The ideology was powerful — far more powerful and durable than those whimsical and short-lived names implied...
http://passcode.csmonitor.com/cypherpunk
20160817
NSA Hacked? 'Shadow Brokers' Crew Claims Compromise Of Surveillance Op
In 2015, researchers at Russian security company Kaspersky Lab revealed a highly-advanced arsenal of hacking tools used by the Equation campaign. They were believed to have been the work of the NSA as the code was linked with previous, allegedly US-sponsored hacks, including the infamous Regin and Stuxnet attacks. That link, however, was never definitively proven nor admitted by the signals intelligence body.
Two days ago, on August 13, a group calling themselves The Shadow Brokers released files on Github, claiming they came from the Equation Group. The files included code allegedly designed to exploit firewalls from American manufacturers Cisco, Juniper and Fortinet . One Chinese company, Topsec, was also an Equation target, according to the leaks. None of the manufacturers had responded to requests for comment at the time of publication.
The hackers released 60 per cent of the files they claimed to have taken from the Equation Group. The Shadow Brokers said they would release the remaining data to the highest bidder in a Bitcoin auction (they’ve received two bids so far). If they received an extraordinary 1,000,000 Bitcoins, worth roughly $560 million, they would release all the files.
“We follow Equation Group traffic. We find Equation Group source range. We hack Equation Group. We find many many Equation Group cyber weapons,” the hacker collective wrote (grammar errors theirs). “We give you some Equation Group files free, you see. This is good proof no? You enjoy!!! You break many things. You find many intrusions. You write many words. But not all, we are auction the best files...
20160613
The rise of the meta-criminal
Trevor Timm of the Electronic Freedom Frontier dug up a very interesting nugget. It was embedded in the heralded December 2013 White House task force report on spying and snooping.
Under Recommendations, #31, section 2, he found this:
“Governments should not use their offensive cyber capabilities to change the amounts held in financial accounts or otherwise manipulate financial systems.”
Timm quite rightly wondered: why were these warnings in the report?
Were the authors just anticipating a possible crime? Or were they reflecting the fact that the NSA had already been engaging in the crime?
If this was just a bit of anticipation, why leave it naked in the report? Why not say there was no current evidence the NSA had been manipulating financial systems?
Those systems would, of course, include the stock market, and all trading markets around the world.
Well, there is definite evidence of other NSA financial snooping. From Spiegel Online, “‘Follow the Money’: NSA Spies on International Payments,” 9/15/13:
“The National Security Agency (NSA) widely monitors international payments, banking and credit card transactions, according to documents seen by SPIEGEL.”
“The NSA’s Tracfin data bank also contained data from the Brussels-based Society for Worldwide Interbank Financial Telecommunication (SWIFT), a network used by thousands of banks to send transaction information securely…the NSA spied on the organization on several levels, involving, among others, the [NSA] agency’s ‘tailored access operations’ division…”
https://jonrappoport.wordpress.com/2016/05/24/the-rise-of-the-meta-criminal/
Under Recommendations, #31, section 2, he found this:
“Governments should not use their offensive cyber capabilities to change the amounts held in financial accounts or otherwise manipulate financial systems.”
Timm quite rightly wondered: why were these warnings in the report?
Were the authors just anticipating a possible crime? Or were they reflecting the fact that the NSA had already been engaging in the crime?
If this was just a bit of anticipation, why leave it naked in the report? Why not say there was no current evidence the NSA had been manipulating financial systems?
Those systems would, of course, include the stock market, and all trading markets around the world.
Well, there is definite evidence of other NSA financial snooping. From Spiegel Online, “‘Follow the Money’: NSA Spies on International Payments,” 9/15/13:
“The National Security Agency (NSA) widely monitors international payments, banking and credit card transactions, according to documents seen by SPIEGEL.”
“The NSA’s Tracfin data bank also contained data from the Brussels-based Society for Worldwide Interbank Financial Telecommunication (SWIFT), a network used by thousands of banks to send transaction information securely…the NSA spied on the organization on several levels, involving, among others, the [NSA] agency’s ‘tailored access operations’ division…”
https://jonrappoport.wordpress.com/2016/05/24/the-rise-of-the-meta-criminal/
20160524
20160523
20160516
Everything We Know About How the FBI Hacks People
RECENT HEADLINES WARN that the government now has greater authority to hack your computers, in and outside the US. Changes to federal criminal court procedures known as Rule 41 are to blame; they vastly expand how and whom the FBI can legally hack. But just like the NSA’s hacking operations, FBI hacking isn’t new. In fact, the bureau has a long history of surreptitiously hacking us, going back two decades.
That history is almost impossible to document, however, because the hacking happens mostly in secret. Search warrants granting permission to hack get issued using vague, obtuse language that hides what’s really happening, and defense attorneys rarely challenge the hacking tools and techniques in court. There’s also no public accounting of how often the government hacks people. Although federal and state judges have to submit a report to Congress tracking the number and nature of wiretap requests they process each year, no similar requirement exists for hacking tools. As a result, little is known about the invasive tools the bureau, and other law enforcement agencies, use or how they use them. But occasionally, tidbits of information do leak out in court cases and news stories.
A look at a few of these cases offers a glimpse at how FBI computer intrusion techniques have developed over the years. Note that the government takes issue with the word “hacking,” since this implies unauthorized access, and the government’s hacking is court-sanctioned. Instead it prefers the terms “remote access searches” and Network Investigative Techniques, or NIT. By whatever name, however, the activity is growing...
https://www.wired.com/2016/05/history-fbis-hacking/
That history is almost impossible to document, however, because the hacking happens mostly in secret. Search warrants granting permission to hack get issued using vague, obtuse language that hides what’s really happening, and defense attorneys rarely challenge the hacking tools and techniques in court. There’s also no public accounting of how often the government hacks people. Although federal and state judges have to submit a report to Congress tracking the number and nature of wiretap requests they process each year, no similar requirement exists for hacking tools. As a result, little is known about the invasive tools the bureau, and other law enforcement agencies, use or how they use them. But occasionally, tidbits of information do leak out in court cases and news stories.
A look at a few of these cases offers a glimpse at how FBI computer intrusion techniques have developed over the years. Note that the government takes issue with the word “hacking,” since this implies unauthorized access, and the government’s hacking is court-sanctioned. Instead it prefers the terms “remote access searches” and Network Investigative Techniques, or NIT. By whatever name, however, the activity is growing...
https://www.wired.com/2016/05/history-fbis-hacking/
The NSA’s stunning 9/11 failure: How big-money contractors made us more vulnerable to attack
On September 12, 2001, Bill Binney snuck back into work at the NSA dressed like cleaning staff so he could try to help understand who had attacked the United States. A top NSA mathematician, Binney had rolled out a sophisticated metadata analysis system called ThinThread, only to have it canceled less than a month before 9/11. Top executives at the agency had decided a clunky program called Trailblazer, contracted out to the intelligence contractor giant SAIC, would be NSA’s future, not the cheaper, more effective and privacy-protective ThinThread.
While NSA Director General Michael Hayden had sent most NSA staffers home on 9/11 and the day after —hence Binney’s disguise — the contractors were hard at work. As Binney describes in “A Good American“ — a documentary about Binney due for wider release in September — some contractors working in his unit had gotten a warning. “While I was in there trying to look at the material on my computer, the president of the contracting group that I had working on ThinThread came over to me and said that he’d just been in a contractor meeting” with a former top SAIC official who moved back to NSA, supporting Trailblazer. The contractors, it turns out, were warned not to embarrass companies like SAIC, which (the implication is) had just failed to warn about the biggest attack on the United States since Pearl Harbor. “Do not embarrass large companies,” the former SAIC manager, according to Binney, said to the other contractor. “You do your part, you’ll get your share, there’s plenty for everybody.” Stay quiet about the failures that led to 9/11, and you’ll be financially rewarded.
It turns out there was plenty for SAIC and the NSA executives who had backed them to be embarrassed about. Binney and a bunch of close associates quit NSA when the Administration rolled out a new, illegal wiretap program called Stellar Wind in the weeks after 9/11. But another senior NSA official, Thomas Drake — an ally of Binney’s — decided to run the data already in NSA’s possession against ThinThread some months later to see whether ThinThread could reveal anything about the attack. Let’s “find out if there’s any information of the 9/11 attack that we should have known about but didn’t,” in Drake’s words.
There was...
http://www.salon.com/2016/05/12/the_nsas_stunning_911_failure_how_big_money_contractors_made_us_more_vulnerable_to_attack/
While NSA Director General Michael Hayden had sent most NSA staffers home on 9/11 and the day after —hence Binney’s disguise — the contractors were hard at work. As Binney describes in “A Good American“ — a documentary about Binney due for wider release in September — some contractors working in his unit had gotten a warning. “While I was in there trying to look at the material on my computer, the president of the contracting group that I had working on ThinThread came over to me and said that he’d just been in a contractor meeting” with a former top SAIC official who moved back to NSA, supporting Trailblazer. The contractors, it turns out, were warned not to embarrass companies like SAIC, which (the implication is) had just failed to warn about the biggest attack on the United States since Pearl Harbor. “Do not embarrass large companies,” the former SAIC manager, according to Binney, said to the other contractor. “You do your part, you’ll get your share, there’s plenty for everybody.” Stay quiet about the failures that led to 9/11, and you’ll be financially rewarded.
It turns out there was plenty for SAIC and the NSA executives who had backed them to be embarrassed about. Binney and a bunch of close associates quit NSA when the Administration rolled out a new, illegal wiretap program called Stellar Wind in the weeks after 9/11. But another senior NSA official, Thomas Drake — an ally of Binney’s — decided to run the data already in NSA’s possession against ThinThread some months later to see whether ThinThread could reveal anything about the attack. Let’s “find out if there’s any information of the 9/11 attack that we should have known about but didn’t,” in Drake’s words.
There was...
http://www.salon.com/2016/05/12/the_nsas_stunning_911_failure_how_big_money_contractors_made_us_more_vulnerable_to_attack/
THE SECRET NSA DIARY OF AN ABU GHRAIB INTERROGATOR
AFTER WORKING AS an interrogator for a U.S. military contractor in Iraq, Eric Fair took a job as an analyst for the National Security Agency. When he went to the NSA, Fair was reckoning with the torture of Iraqi prisoners, torture he had witnessed and in which he had participated.
Fair would go on to write a memoir detailing his experiences in Iraq; the book, Consequence, was published last month to strong notices, including not one but two positive reviews in the New York Times. But Fair actually wrote about his time as an interrogator more than a decade earlier in an internal NSA publication.
One of the publication’s editors asked him to contribute a piece about “how my experience as an interrogator influences my work at the NSA,” as he put it in Consequence. Fair submitted an article in which “I question the efficacy of certain intelligence-gathering techniques and wonder whether, for the sake of morality, it might be best to sacrifice some level of tactical knowledge.”
“I was asked rewrite this section. I cut it completely. Instead, I wrote about how my experience in the interrogation booths had familiarized me with the overall intelligence cycle.”
Fair’s article for the NSA publication is among the files provided by former agency contractor Edward Snowden. It appeared in SIDtoday, a newsletter for the NSA’s Signals Intelligence Directorate, or SID, and is being released by The Intercept...
https://theintercept.com/2016/05/11/the-secret-nsa-diary-of-an-abu-ghraib-interrogator/
Fair would go on to write a memoir detailing his experiences in Iraq; the book, Consequence, was published last month to strong notices, including not one but two positive reviews in the New York Times. But Fair actually wrote about his time as an interrogator more than a decade earlier in an internal NSA publication.
One of the publication’s editors asked him to contribute a piece about “how my experience as an interrogator influences my work at the NSA,” as he put it in Consequence. Fair submitted an article in which “I question the efficacy of certain intelligence-gathering techniques and wonder whether, for the sake of morality, it might be best to sacrifice some level of tactical knowledge.”
“I was asked rewrite this section. I cut it completely. Instead, I wrote about how my experience in the interrogation booths had familiarized me with the overall intelligence cycle.”
Fair’s article for the NSA publication is among the files provided by former agency contractor Edward Snowden. It appeared in SIDtoday, a newsletter for the NSA’s Signals Intelligence Directorate, or SID, and is being released by The Intercept...
https://theintercept.com/2016/05/11/the-secret-nsa-diary-of-an-abu-ghraib-interrogator/
20160508
NSA Silent on Spies’ Child Porn Problem
The government’s cyber spying outfit has an ‘unbelievable’ child porn problem. But the NSA can’t—or won’t—say how often it finds such criminal images on its workers’ computers.
Two senior U.S. intelligence officials said recently that defense and intelligence employees have an “unbelievable” amount of child pornography on their work computers and devices, and that child porn has been found on the systems of the National Security Agency, the country’s biggest intelligence organization.
But the NSA, which is responsible for keeping tabs on its own computers as well as military and intelligence agency networks, cannot say just how many times employees have been found to posesses or share child pornography, or how many times such cases have been referred to law enforcement for investigation and potential criminal prosecution.
An agency spokesperson was unable to provide The Daily Beast with statistics to elaborate on comments by Kemp Ensor, the NSA’s director of security, who said at a public conference in Virginia on April 28 that he had seen child porn on agency systems. Despite the fact that NSA employees know they work inside the most powerful surveillance organization on the planet, it doesn’t stop some from engaging in criminal behavior. “What people do [at work] is amazing,” Ensor said.
His comments were first reported by Nextgov.
“NSA is a professional foreign-intelligence and information-assurance organization with a highly disciplined workforce, serving around the clock in some of the world’s most dangerous areas,” an NSA spokesperson said in a written statement. “We set high professional standards for our personnel and any violations of the law are appropriately reported.”
But how many? How often? These are questions one might imagine the world’s premiere computer-monitoring agency could answer...
http://www.thedailybeast.com/articles/2016/05/06/nsa-won-t-say-how-many-spies-have-child-porn.html
Two senior U.S. intelligence officials said recently that defense and intelligence employees have an “unbelievable” amount of child pornography on their work computers and devices, and that child porn has been found on the systems of the National Security Agency, the country’s biggest intelligence organization.
But the NSA, which is responsible for keeping tabs on its own computers as well as military and intelligence agency networks, cannot say just how many times employees have been found to posesses or share child pornography, or how many times such cases have been referred to law enforcement for investigation and potential criminal prosecution.
An agency spokesperson was unable to provide The Daily Beast with statistics to elaborate on comments by Kemp Ensor, the NSA’s director of security, who said at a public conference in Virginia on April 28 that he had seen child porn on agency systems. Despite the fact that NSA employees know they work inside the most powerful surveillance organization on the planet, it doesn’t stop some from engaging in criminal behavior. “What people do [at work] is amazing,” Ensor said.
His comments were first reported by Nextgov.
“NSA is a professional foreign-intelligence and information-assurance organization with a highly disciplined workforce, serving around the clock in some of the world’s most dangerous areas,” an NSA spokesperson said in a written statement. “We set high professional standards for our personnel and any violations of the law are appropriately reported.”
But how many? How often? These are questions one might imagine the world’s premiere computer-monitoring agency could answer...
http://www.thedailybeast.com/articles/2016/05/06/nsa-won-t-say-how-many-spies-have-child-porn.html
20160430
20160411
The Obama Administration Has Embraced Legal Theories Even Broader Than John Yoo’s
Unsurprisingly, Yoo’s memo is extremely broad and poorly reasoned — but we knew that much already, thanks to Jack Goldsmith and Jim Comey. Still, it would be a mistake to think of Yoo’s memo as just an historical artifact, full of long-repudiated legal arguments. In fact, many of the arguments Yoo made behind closed doors in 2002 continue to appear in the Obama administration’s briefs defending warrantless surveillance under Section 702 of FISA today. And, in at least one key respect, the Obama administration’s arguments are even broader than the ones that Yoo felt he could justify.
Like Yoo, the Obama administration has argued that Americans have a “greatly reduced” expectation of privacy in their international communications — so diminished, in fact, that no warrant is necessary for the government to intercept and search those communications. That might come as a surprise to the millions of Americans who regularly engage in personal or confidential communications with family, friends, business associates, and others overseas. When you pick up the phone to call a family member abroad, there is no reason to believe that your communication is any less private than calling a friend across town. The Supreme Court has certainly never said any such thing. Indeed, Yoo eventually admitted in his memo that the case law did not support the suspicionless interception of “the contents of telephone or other electronic communication[s]” — though he then proceeded to ignore his own conclusion.
But that has not stopped the government from making the same claims in the Section 702 cases now moving through the courts. The government has embraced Yoo’s position, arguing that the privacy interests of US persons in international communications are “significantly diminished, if not completely eliminated,” when those communications are sent to or from foreigners abroad...
https://www.justsecurity.org/30460/obama-administration-embraced-legal-theories-broader-john-yoos/
20160312
Inside “Eligible Receiver”
Excerpted from Dark Territory: The Secret History of Cyber War by Fred Kaplan. Out now from Simon & Schuster. On Wednesday, March 9, Kaplan will discuss his book in New York; for more information and to RSVP, visit the New America website.
On June 9, 1997, 25 officials of the National Security Agency—members of a security squad known as the “Red Team”—hacked into the computer networks of the Department of Defense, using only commercially available equipment and software. It was the first high-level exercise testing whether the U.S. military’s leaders, facilities, and global combatant commands were prepared for a cyber attack. And the outcome was alarming.
The simulated hack was the brainchild of the NSA director, Lt. Gen. Kenneth Minihan, who, before coming to the agency, had been commander of the Air Force Information Warfare Center in San Antonio, Texas. The center’s tech crews had been detecting frequent hackings of U.S. military computer networks, and had come up with ways to counter them—but few senior officers took notice or cared.
Each year, the Pentagon’s Joint Staff held an exercise called Eligible Receiver—a simulation or war game designed to highlight some threat or opportunity on the horizon. Minihan wanted the next exercise to test the vulnerability of the U.S. military’s networks to a cyber attack. The most dramatic way to do this, he proposed, was to launch a realattack on those networks. He’d heard about small-scale exercises of this sort, against battalions or air wings of the Army or Air Force. In these war games, he’d been told, the hackers always succeeded. The NSA Red Team was part of the Information Assurance Directorate, the defensive side of the agency, stationed in FANEX, a drab brick building out near Friendship Airport, a 20-minute drive from NSA headquarters at Fort Meade, Maryland. During its most sensitive drills, the Red Team worked out of a chamber called the Pit, which was so secret that few people at NSA knew it existed, and even they couldn’t enter without first passing through two combination-locked doors. In its workaday duties, the Red Team probed for vulnerabilities in new hardware or software that had been designed for the Defense Department, sometimes for the NSA itself. These systems had to clear a high bar to be deemed secure enough for government purchase and installation. The Red Team’s job was to test that bar.
Subscribe to:
Posts (Atom)


